ACAMS Conducting Investigations 2 — Questions and Answers
Question 1: What is the primary difference between an AML investigation and a standard audit?
- Audits are conducted by regulators while investigations are internal
- Investigations follow a specific suspicious transaction or pattern to determine if illegal activity occurred, while audits systematically evaluate the overall effectiveness of AML controls (Correct answer)
- Investigations only examine historical transactions while audits focus on future controls
- Audits must be reported to FinCEN while investigations are confidential
Correct answer: Investigations follow a specific suspicious transaction or pattern to determine if illegal activity occurred, while audits systematically evaluate the overall effectiveness of AML controls
An AML investigation is triggered by specific suspicious activity and aims to determine whether money laundering or financial crime occurred, while an AML audit systematically evaluates the overall design and effectiveness of the institution's AML compliance program.
AML investigations: are triggered by transaction monitoring alerts, customer complaints, or law enforcement inquiries; focus on specific suspicious transactions, accounts, or individuals; involve gathering evidence to determine if ML/TF has occurred; culminate in a SAR filing decision; and may result in account closure or law enforcement referral. AML audits: are planned in advance on a risk-based schedule; evaluate overall program adequacy against regulatory standards; identify control gaps and recommend improvements; may not be triggered by specific suspicious activity; and result in audit reports to management and the board. Both are essential components of an effective AML program but serve distinct purposes.
Question 2: What information should be gathered during the initial stage of an AML investigation triggered by a transaction monitoring alert?
- Only the transaction details that triggered the alert
- Customer identity information, account history, related party information, transaction patterns, and any prior SAR or alert history (Correct answer)
- Only the beneficial ownership information for the account
- External law enforcement reports and media searches only
Correct answer: Customer identity information, account history, related party information, transaction patterns, and any prior SAR or alert history
A thorough AML investigation requires gathering comprehensive information from multiple sources: customer identity and KYC file, full account and transaction history, related party connections, prior alert/SAR history, and external sources such as public records and adverse media.
Initial information gathering in an AML investigation should include: Customer identity: name, address, DOB, beneficial ownership, business purpose; Account information: opening date, account type, CDD/EDD documentation, relationship manager notes; Transaction history: historical patterns to compare against current activity, prior alerts, prior SAR filings; Related parties: joint account holders, authorized signers, beneficial owners, related corporate entities; External sources: public records (court filings, liens, judgments), adverse media searches, OFAC checks, law enforcement requests; and Internal bank systems: relationship manager knowledge, credit files, other product relationships. Documenting all research and conclusions is essential for SAR filing decisions.
Question 3: What does the legal term 'tipping off' mean in the AML context, and what is its consequence?
- Informing a supervisor about a colleague's suspicious behavior; it is encouraged
- Disclosing to a subject that a SAR has been filed or is being considered about them; it is a federal crime under 31 USC 5318(g)(2) (Correct answer)
- Providing anonymous tips to law enforcement; it is legally protected
- Sharing customer information with another financial institution; it may violate privacy laws
Correct answer: Disclosing to a subject that a SAR has been filed or is being considered about them; it is a federal crime under 31 USC 5318(g)(2)
Tipping off is the illegal act of notifying a customer or any person that they are the subject of a SAR investigation. Under 31 USC 5318(g)(2), tipping off is a federal crime that can result in imprisonment and fines.
The tipping off prohibition under 31 USC 5318(g)(2) makes it a federal crime for any financial institution or its officers, directors, employees, or agents to notify any person involved in a transaction for which a SAR has been filed or is being prepared that the transaction has been reported. The prohibition is absolute — there are no exceptions for inadvertent disclosure. Investigative procedures must ensure: investigative steps do not arouse suspicion; account closure decisions do not reveal SAR filing; employee communications are secured; and law enforcement subpoenas related to SAR filings are handled carefully. Violation can result in criminal penalties and termination. The prohibition coexists with the Safe Harbor, which protects institutions and individuals from civil liability for good-faith SAR filings.
Question 4: When conducting an AML investigation, how should investigators handle 'link analysis'?
- Link analysis involves examining hyperlinks in customer-submitted documents for malware
- Link analysis maps the connections between accounts, individuals, entities, and transactions to identify networks of related parties and hidden relationships that may indicate coordinated money laundering (Correct answer)
- Link analysis is a statistical technique for measuring transaction frequency
- Link analysis involves checking web links to verify customer business legitimacy
Correct answer: Link analysis maps the connections between accounts, individuals, entities, and transactions to identify networks of related parties and hidden relationships that may indicate coordinated money laundering
Link analysis in AML investigations involves visually mapping and analyzing connections between accounts, people, businesses, transactions, and addresses to uncover networks of related parties potentially engaged in coordinated financial crime.
Link analysis tools (such as i2 Analyst's Notebook, Palantir, or similar platforms) allow investigators to: visualize relationships between accounts, individuals, and entities; identify common addresses, phone numbers, or email addresses across multiple accounts; trace fund flows through multiple accounts and institutions; detect coordination among accounts opening at similar times or with similar characteristics; and identify previously unknown relationships that suggest organized ML schemes. In large investigations, link analysis may reveal money mule networks, layering schemes involving multiple entities, or previously unknown beneficial owners. The visual representation is also valuable for documenting investigations and presenting findings to law enforcement.
Question 5: What is the role of the 'BSA Officer' (BSAO) in an AML investigation?
- The BSAO only files CTRs and has no role in investigations
- The BSAO oversees the AML compliance program and typically makes or approves final SAR filing decisions, ensuring investigations are thorough and documented (Correct answer)
- The BSAO only communicates with regulators and has no operational investigation role
- The BSAO is responsible only for employee AML training programs
Correct answer: The BSAO oversees the AML compliance program and typically makes or approves final SAR filing decisions, ensuring investigations are thorough and documented
The BSA Officer (also called the AML Compliance Officer) is responsible for overseeing the AML program, which includes ensuring investigations are properly conducted, documented, and that SAR filing decisions are sound and well-supported.
The BSA Officer's role in investigations includes: establishing investigation procedures and escalation protocols; reviewing and approving SAR filing decisions; ensuring investigations are completed within required timeframes (generally 30 days after initial detection of suspicious activity, with up to 60 days if needed); maintaining confidentiality of SAR filings; responding to law enforcement requests related to SARs; training investigative staff; reviewing quality of alert disposition; and reporting investigation metrics to senior management and the board. The BSAO is personally accountable for the adequacy of the institution's AML program. Regulatory examinations scrutinize whether the BSAO has sufficient authority, resources, and expertise.
Question 6: What is the standard for determining whether a SAR should be filed after completing an AML investigation?
- The institution must be certain that money laundering has occurred
- The institution knows, suspects, or has reason to suspect that a transaction involves funds from illegal activity or is designed to evade BSA requirements, and involves at least $5,000 (Correct answer)
- The institution must have a court order or law enforcement request before filing
- SARs are only required for transactions involving more than $25,000
Correct answer: The institution knows, suspects, or has reason to suspect that a transaction involves funds from illegal activity or is designed to evade BSA requirements, and involves at least $5,000
The SAR filing threshold is met when the institution 'knows, suspects, or has reason to suspect' that a transaction involves criminal funds or evasion of BSA requirements — proof is not required, and the threshold is $5,000 for most institutions ($2,000 for MSBs).
Under 31 CFR 1020.320, banks must file SARs when they know, suspect, or have reason to suspect a transaction: involves funds from illegal activity; is designed to evade BSA reporting requirements; has no lawful purpose or is not the type of transaction the customer would normally conduct; involves use of the bank to facilitate criminal activity. The dollar threshold is $5,000 for depository institutions (transactions involving less may still be filed). The standard is intentionally lower than criminal proof — institutions should file when they cannot identify a legitimate explanation after reasonable investigation. Failure to file required SARs is itself a BSA violation. Institutions are protected from civil liability for good-faith SAR filings under the Safe Harbor provision.
What is the primary difference between an AML investigation and a standard audit?