ACAMS CAMS Certification Exam β Questions and Answers
Question 1: A bank is onboarding a family trust as a new client. Who should be identified as the beneficial owner?
- Only the trustee named on the trust document
- The largest beneficiary only
- The settlor, trustee(s), protector (if any), beneficiaries, and any other natural person exercising ultimate effective control (Correct answer)
- The attorney who drafted the trust document
Correct answer: The settlor, trustee(s), protector (if any), beneficiaries, and any other natural person exercising ultimate effective control
For trusts, beneficial ownership extends to all parties exercising control or ownership over trust assets, including settlors, trustees, protectors, and beneficiaries, to ensure true ownership is transparent.
Question 2: In addition to identifying equity owners, FinCEN's beneficial ownership rule also requires identification of which individual?
- All directors of the company
- The entity's registered agent
- The entity's largest creditor
- A single person with significant responsibility to control, manage, or direct the entity (Correct answer)
Correct answer: A single person with significant responsibility to control, manage, or direct the entity
The CDD Rule's two-prong approach requires identifying equity owners at 25%+ and one control person with significant responsibility for managing or directing the entity.
Question 3: Which of the following is NOT an essential element that should be included in the narrative of a well-written Suspicious Activity Report (SAR)?
- An explanation of why the activity is considered suspicious (Why).
- The investigator's personal opinion on the suspect's guilt. (Correct answer)
- The names of the individuals or entities involved (Who).
- A clear and chronological description of the suspicious activity.
Correct answer: The investigator's personal opinion on the suspect's guilt.
A SAR narrative should be factual, objective, and concise. It must describe the who, what, when, where, and why of the suspicious activity. Including personal opinions, speculations, or legal conclusions about the subject's guilt is inappropriate and detracts from the factual basis of the report. The focus should be on presenting the observed facts and the reasons for suspicion.
Question 4: Which financial product is most frequently exploited in TBML schemes due to its document-based nature?
- Letters of credit (Correct answer)
- Prepaid cards
- Certificates of deposit
- Wire transfers
Correct answer: Letters of credit
Letters of credit are document-based instruments where banks rely on presented paperwork rather than physical inspection, making them vulnerable to TBML through falsified trade documents.
Question 5: In the FATF risk-based approach, what are the three primary risk categories that institutions must assess?
- Country/geographic risk, customer risk, and product/service/transaction risk (Correct answer)
- Inherent risk, residual risk, and control risk
- Regulatory risk, reputational risk, and legal risk
- Credit risk, market risk, and operational risk
Correct answer: Country/geographic risk, customer risk, and product/service/transaction risk
The FATF risk-based approach requires financial institutions to assess three primary AML risk categories: country/geographic risk (jurisdictions with higher ML/TF risk), customer risk (types of customers and their risk profiles), and product/service/transaction risk (financial services that may be more vulnerable to abuse).
Question 6: What is the role of a Financial Intelligence Unit (FIU) in the national AML framework?
- FIUs are law enforcement agencies that conduct criminal investigations and make arrests
- FIUs receive, process, analyze, and disseminate financial intelligence (including SAR/STR reports) to competent authorities to support AML/CFT investigations and prosecutions (Correct answer)
- FIUs are regulatory bodies that license and supervise financial institutions
- FIUs set national AML policy and issue binding regulations on financial institutions
Correct answer: FIUs receive, process, analyze, and disseminate financial intelligence (including SAR/STR reports) to competent authorities to support AML/CFT investigations and prosecutions
Financial Intelligence Units are national agencies that collect financial intelligence (SAR/STR filings), analyze it for patterns and connections, and disseminate actionable intelligence to law enforcement, prosecutors, and foreign FIUs to support AML/CFT investigations.
Question 7: Under FATF Recommendation 12, for how long after an individual leaves a prominent public position should enhanced due diligence measures continue?
- Six months
- One year
- PEP status ends immediately upon leaving office
- A risk-based period, often cited as 12β18 months or longer (Correct answer)
Correct answer: A risk-based period, often cited as 12β18 months or longer
FATF recommends applying a risk-based approach for former PEPs, and many jurisdictions and industry guidance suggest monitoring for at least 12β18 months or longer depending on risk.
Question 8: What is the 'Vienna Convention' (1988 UN Convention Against Illicit Traffic in Narcotic Drugs) and why is it foundational to international AML law?
- The first major international treaty requiring countries to criminalize drug money laundering and establish mechanisms for asset confiscation, laying the foundation for global AML cooperation (Correct answer)
- A UN convention establishing the FIU network and mandatory STR filing requirements
- A bilateral treaty between the U.S. and EU establishing mutual legal assistance in AML matters
- The first international treaty requiring all countries to adopt AML regulations for all financial crimes
Correct answer: The first major international treaty requiring countries to criminalize drug money laundering and establish mechanisms for asset confiscation, laying the foundation for global AML cooperation
The 1988 Vienna Convention was the first major international instrument requiring signatory states to criminalize drug-related money laundering and establish asset confiscation frameworks β establishing the conceptual and legal foundation for the global AML system that followed.
Question 9: A compliance officer reviewing trade finance should be most concerned when the price of exported goods is compared to what?
- International commodity prices or trade databases (Correct answer)
- The buyer's credit score
- The freight cost of the shipment
- The exporter's annual revenue
Correct answer: International commodity prices or trade databases
Comparing invoice prices against international commodity databases or trade pricing benchmarks helps detect over/under-invoicing indicative of TBML.
Question 10: What is 'proliferation financing' (PF) and when did FATF formally add it to its standards?
- Financing of money laundering networks that proliferate across multiple jurisdictions; added in 2003
- Financing excessive growth of the AML compliance industry; added in 2019
- The unauthorized distribution of financial licenses to unregulated institutions; added in 2001
- The provision of funds or financial services used for the development, acquisition, or deployment of weapons of mass destruction in violation of international sanctions; formally integrated into FATF's standards through Recommendation 7 in 2012 and strengthened in 2020 (Correct answer)
Correct answer: The provision of funds or financial services used for the development, acquisition, or deployment of weapons of mass destruction in violation of international sanctions; formally integrated into FATF's standards through Recommendation 7 in 2012 and strengthened in 2020
Proliferation financing refers to financial support for WMD development and delivery β nuclear, chemical, biological, and radiological weapons. FATF added Recommendation 7 on targeted financial sanctions for proliferation financing in 2012 and significantly strengthened its guidance with a 2020 report requiring risk-based controls.
Question 11: What is a 'nominee director' and why is it relevant to beneficial ownership risk?
- A government-appointed regulator overseeing corporate governance
- A director elected by minority shareholders
- A temporary director appointed during corporate restructuring
- A person who appears as a director in public records but acts on behalf of an undisclosed third party, obscuring true control (Correct answer)
Correct answer: A person who appears as a director in public records but acts on behalf of an undisclosed third party, obscuring true control
Nominee directors appear on public corporate records while the actual controlling person remains hidden, a common technique used to obscure beneficial ownership in shell company structures.
Question 12: Which technique involves routing cryptocurrency through multiple wallets or intermediary addresses to obscure the transaction trail?
- Smurfing across exchanges
- Layering via blockchain fragmentation
- Cryptocurrency mixing or tumbling (Correct answer)
- Chain hopping between networks
Correct answer: Cryptocurrency mixing or tumbling
Mixing or tumbling services pool multiple users' cryptocurrency together and redistribute equivalent amounts, breaking the transaction trail and making it difficult to trace the original source of funds.
Question 13: How does 'machine learning' differ from rule-based transaction monitoring in detecting suspicious activity?
- Machine learning is only effective for detecting sanctions violations, not money laundering
- Machine learning is less accurate than rules-based monitoring and is not used in AML
- Machine learning eliminates the need for human review of transaction monitoring alerts
- Machine learning models can identify complex, non-linear patterns and previously unknown suspicious behaviors that may not be captured by predefined rules, using historical data to train models that evolve as patterns change (Correct answer)
Correct answer: Machine learning models can identify complex, non-linear patterns and previously unknown suspicious behaviors that may not be captured by predefined rules, using historical data to train models that evolve as patterns change
Machine learning can detect novel and complex patterns across large datasets that rule-based systems miss β learning from historical suspicious activity to identify similar but previously unknown behaviors, and adapting as criminal typologies evolve.
Question 14: When conducting an AML investigation, how should investigators handle 'link analysis'?
- Link analysis involves examining hyperlinks in customer-submitted documents for malware
- Link analysis involves checking web links to verify customer business legitimacy
- Link analysis maps the connections between accounts, individuals, entities, and transactions to identify networks of related parties and hidden relationships that may indicate coordinated money laundering (Correct answer)
- Link analysis is a statistical technique for measuring transaction frequency
Correct answer: Link analysis maps the connections between accounts, individuals, entities, and transactions to identify networks of related parties and hidden relationships that may indicate coordinated money laundering
Link analysis in AML investigations involves visually mapping and analyzing connections between accounts, people, businesses, transactions, and addresses to uncover networks of related parties potentially engaged in coordinated financial crime.
Question 15: A bank's risk assessment identifies its private banking division as having the highest inherent AML risk. Which action is the most direct and appropriate response to this finding?
- Lowering the transaction monitoring thresholds for the retail banking division.
- Implementing a standardized, uniform due diligence process for all bank customers.
- Immediately closing all private banking accounts from high-risk jurisdictions.
- Allocating resources for enhanced due diligence (EDD) and specialized training for private banking staff. (Correct answer)
Correct answer: Allocating resources for enhanced due diligence (EDD) and specialized training for private banking staff.
The risk-based approach dictates that controls should be proportionate to the risks identified. Since the private banking division is identified as high-risk, the appropriate response is to apply stronger, more targeted controls, such as EDD and specialized training, to that specific area. The other options are either too extreme (de-risking), irrelevant, or contrary to the risk-based approach.
Question 16: A key element of developing a customer risk profile as part of the CDD process involves:
- Limiting the number of transactions the customer can perform.
- Understanding the customer's political affiliation.
- Requiring the customer to maintain a minimum account balance.
- Understanding the nature and purpose of the customer relationship. (Correct answer)
Correct answer: Understanding the nature and purpose of the customer relationship.
A fundamental component of Customer Due Diligence is understanding the nature and purpose of the customer relationship. This allows the financial institution to develop a customer risk profile and anticipate the types of transactions the customer is likely to conduct. This baseline is essential for ongoing monitoring to detect activity that is unusual or inconsistent with the customer's profile.
Question 17: What is a 'legal entity customer' under FinCEN's CDD Rule, and what are the primary exemptions from the beneficial ownership requirement?
- A corporation, LLC, partnership, or other entity formed by filing with a state; exemptions include publicly listed companies, government entities, regulated financial institutions, and certain pooled investment vehicles (Correct answer)
- Any business entity regardless of size; there are no exemptions
- Any entity registered for tax purposes; exemptions include non-profit organizations
- Only privately held companies with revenues over $10 million; exemptions include sole proprietorships
Correct answer: A corporation, LLC, partnership, or other entity formed by filing with a state; exemptions include publicly listed companies, government entities, regulated financial institutions, and certain pooled investment vehicles
Legal entity customers are entities formed by filing with state or federal authorities. Key exemptions from beneficial ownership requirements include publicly traded companies (registered with the SEC), government entities, federally regulated financial institutions, and certain SEC-registered investment vehicles.
Question 18: In the context of AML, what does 'layering' primarily aim to achieve?
- Disguising the audit trail between illicit funds and their source (Correct answer)
- Reintroducing funds into the legitimate economy
- Identifying the beneficial owner of an account
- Converting cash into other asset types
Correct answer: Disguising the audit trail between illicit funds and their source
Layering is the second stage of money laundering, designed to create a complex web of financial transactions that obscures the audit trail and makes tracing funds back to their criminal origin extremely difficult.
Question 19: What is the purpose of a 'risk appetite statement' in an institution's AML program?
- To document the types of food vendors approved for staff cafeterias
- To define the level and type of AML/CFT risk the institution is willing to accept in pursuing its business objectives (Correct answer)
- To establish the budget allocated to the compliance department
- To set minimum transaction monitoring thresholds for all accounts
Correct answer: To define the level and type of AML/CFT risk the institution is willing to accept in pursuing its business objectives
A risk appetite statement defines the boundaries of acceptable AML/CFT risk for the institution, guiding decisions about which customers, products, and geographies are within acceptable risk tolerance.
Question 20: Which TBML red flag relates to a significant discrepancy between the type of business and the goods being traded?
- Volume mismatch
- Price discrepancy
- Commodity inconsistency (Correct answer)
- Geographic anomaly
Correct answer: Commodity inconsistency
Commodity inconsistencyβwhere a business trades in goods unrelated to its stated business purposeβis a key TBML red flag because it suggests the trade is structured to move funds rather than for genuine commerce.
Question 21: When conducting a periodic AML/CFT risk assessment, a financial institution should always ensure that the methodology and findings are:
- Kept confidential from the board of directors to avoid undue alarm.
- Based solely on publicly available information from sources like the FATF.
- Formally documented, approved by senior management, and used to inform the AML program. (Correct answer)
- Static and unchanged from year to year to ensure consistency.
Correct answer: Formally documented, approved by senior management, and used to inform the AML program.
A risk assessment is a critical governance tool. For it to be effective, its methodology, data, analysis, and conclusions must be thoroughly documented. It requires approval from senior management and/or the board to ensure accountability, and its findings must be used to make tangible updates to the institution's AML/CFT policies, procedures, and controls.
Question 22: What is the significance of 'SAR continuations' (continuing activity SARs)?
- SARs filed when law enforcement requests an update on a previously filed SAR
- SARs filed when a customer's account is closed due to suspicious activity
- SARs filed to correct errors in previously submitted reports
- SARs filed to report that suspicious activity previously reported is continuing, typically filed every 90 days as long as the suspicious activity persists (Correct answer)
Correct answer: SARs filed to report that suspicious activity previously reported is continuing, typically filed every 90 days as long as the suspicious activity persists
Continuing activity SARs are filed approximately every 90 days to report that suspicious activity that was the subject of a prior SAR is still occurring. They maintain a current record with FinCEN and help law enforcement track ongoing criminal activity.
Question 23: Which category of virtual asset is specifically designed to raise proliferation financing risk due to its direct association with sanctioned jurisdictions' attempts to evade restrictions?
- Stablecoins pegged to major fiat currencies
- Utility tokens used for software platform access
- State-sponsored or government-issued virtual currencies from sanctioned nations (Correct answer)
- Non-fungible tokens (NFTs) on public blockchains
Correct answer: State-sponsored or government-issued virtual currencies from sanctioned nations
State-sponsored cryptocurrencies issued by sanctioned nations (e.g., Venezuela's Petro, or North Korea's crypto activities) are specifically flagged as proliferation financing risks as they are designed to circumvent international sanctions.
Question 24: What are the four pillars of a BSA/AML compliance program as required by U.S. regulators?
- Internal controls, a designated compliance officer, training, and independent testing (Correct answer)
- Policies, training, auditing, and customer service
- Board oversight, legal review, IT systems, and staff certification
- KYC, transaction monitoring, SAR filing, and customer segmentation
Correct answer: Internal controls, a designated compliance officer, training, and independent testing
U.S. regulators require AML programs to have written internal controls, a BSA/AML officer, ongoing training, and independent audits.
Question 25: What is 'mutual legal assistance' (MLA) and why is it important for international AML investigations?
- Formal legal mechanisms (treaties and agreements) allowing countries to request and provide investigative assistance β including sharing evidence, executing search warrants, and seizing assets β across national borders (Correct answer)
- Bilateral agreements between financial institutions to share customer information across borders
- Technical assistance provided by developed countries to help developing countries build AML programs
- The FATF peer review process for evaluating member country AML programs
Correct answer: Formal legal mechanisms (treaties and agreements) allowing countries to request and provide investigative assistance β including sharing evidence, executing search warrants, and seizing assets β across national borders
Mutual legal assistance treaties (MLATs) and agreements allow countries to formally request investigative assistance from each other β gathering evidence, executing judicial orders, and sharing financial intelligence β which is essential for prosecuting cross-border money laundering cases.
Question 26: An AML analyst reviews transactions for a registered charity that solicits online donations for humanitarian aid in a conflict zone. The analyst notes that a significant portion of the charity's funds are wired to a newly established logistics company in a neighboring high-risk country for 'transportation services,' with vague supporting documentation. Which terrorist financing risk is most prominent in this scenario?
- Structuring of cash deposits to avoid reporting thresholds.
- Use of trade-based money laundering through over-invoicing.
- Self-funding by foreign terrorist fighters.
- Abuse of Non-Profit Organizations (NPOs) to divert funds. (Correct answer)
Correct answer: Abuse of Non-Profit Organizations (NPOs) to divert funds.
The scenario describes classic red flags for the abuse of NPOs. Terrorist organizations may exploit legitimate charities by diverting funds raised for purported humanitarian causes to support their operations, often using front companies or complicit vendors in high-risk areas to obscure the ultimate destination of the money.
Question 27: Which sector is considered most vulnerable to exploitation for integration β the final stage of money laundering?
- Luxury goods, real estate, and casino industries (Correct answer)
- Payroll processing companies
- Credit unions under $100 million in assets
- Non-profit organizations focused on domestic causes
Correct answer: Luxury goods, real estate, and casino industries
Luxury goods, real estate, and casinos are prime integration vehicles because high-value purchases can legitimize large sums of money, and these industries have historically had less rigorous AML oversight.
Question 28: What are the 'five pillars' of an effective BSA/AML compliance program under U.S. federal requirements?
- Board oversight, senior management accountability, technology systems, legal review, and regulatory liaison
- SAR filing, CTR filing, record retention, risk assessment, and OFAC screening
- Policies, procedures, internal controls, risk assessment, and training
- Internal controls, a designated compliance officer, employee training, independent testing, and customer due diligence (Correct answer)
Correct answer: Internal controls, a designated compliance officer, employee training, independent testing, and customer due diligence
FinCEN and banking regulators require BSA/AML programs to have five pillars: (1) internal controls, (2) a designated BSA/AML compliance officer, (3) ongoing employee training, (4) independent testing/audit, and (5) customer due diligence (added as the fifth pillar by FinCEN's 2016 CDD Rule).
Question 29: A financial institution is onboarding a new corporate customer. According to the FATF Recommendations, identifying and verifying the identity of which of the following is a mandatory part of Customer Due Diligence?
- The corporation's largest supplier.
- All senior managers of the corporation.
- The beneficial owner(s) of the corporation. (Correct answer)
- The customer's primary legal counsel.
Correct answer: The beneficial owner(s) of the corporation.
The Financial Action Task Force (FATF) Recommendations state that a key component of Customer Due Diligence (CDD) is identifying the beneficial owner and taking reasonable measures to verify their identity. This ensures that the financial institution knows who ultimately owns or controls the legal entity customer, which is crucial for assessing risk.
Question 30: Which typology involves using third parties to purchase monetary instruments on behalf of another person to avoid identification?
- Placement through offshore bank accounts
- Structuring with the use of nominees or 'smurfs' (Correct answer)
- Integration via luxury asset purchases
- Layering through real estate transactions
Correct answer: Structuring with the use of nominees or 'smurfs'
Using nominees or smurfs involves recruiting individuals to conduct transactions below reporting thresholds to conceal the identity of the actual owner of funds.
Question 31: Under FATF Recommendation 13, what specific AML measures must correspondent banks apply?
- Limit correspondent relationships to banks in FATF member countries only
- Require respondent banks to post collateral equal to 10% of annual transaction volume
- Gather sufficient information about respondent banks, assess their AML controls, obtain senior management approval, and document respective AML/CFT responsibilities (Correct answer)
- File a SAR for every wire transfer involving respondent banks
Correct answer: Gather sufficient information about respondent banks, assess their AML controls, obtain senior management approval, and document respective AML/CFT responsibilities
FATF Recommendation 13 requires correspondent banks to: assess the respondent's AML/CFT controls; document respective responsibilities; obtain senior management approval for new relationships; and be satisfied the respondent is not a shell bank.
Question 32: What is 'crowdfunding' as a TF risk and how should financial institutions manage this risk?
- A risk only relevant to cryptocurrency exchanges, not traditional banks
- A method used exclusively by domestic extremist groups, not international terrorist organizations
- The use of online platforms to solicit small donations from a large number of contributors, which can be exploited for TF by using misleading campaign descriptions, routing funds through third-party processors, and collecting via cryptocurrency β managed through enhanced monitoring of high-risk payment processors and social media awareness (Correct answer)
- A legitimate fundraising method with no TF risk if used by registered non-profit organizations
Correct answer: The use of online platforms to solicit small donations from a large number of contributors, which can be exploited for TF by using misleading campaign descriptions, routing funds through third-party processors, and collecting via cryptocurrency β managed through enhanced monitoring of high-risk payment processors and social media awareness
Crowdfunding platforms can be exploited for TF through campaigns with false or misleading humanitarian descriptions, enabling small dispersed donations that individually fall below monitoring thresholds. Financial institutions must monitor payment flows to and from high-risk crowdfunding platforms and maintain awareness of flagged campaigns.
Question 33: What is a 'shell bank' under U.S. law and why are they prohibited from having correspondent accounts at U.S. financial institutions?
- A foreign bank with no physical presence in any country and unaffiliated with a regulated financial group; they provide no accountability or AML oversight (Correct answer)
- A bank entirely owned by a government; they create conflicts of interest
- A bank that primarily trades in foreign currencies; they create exchange rate volatility
- A bank that operates only through ATMs; they lack human oversight
Correct answer: A foreign bank with no physical presence in any country and unaffiliated with a regulated financial group; they provide no accountability or AML oversight
A shell bank has no physical presence (no office, employees, or records) in the country where it is licensed, and is not affiliated with a regulated financial group. U.S. law (USA PATRIOT Act Section 313) prohibits U.S. banks from opening or maintaining correspondent accounts for shell banks because they offer no accountability or AML compliance.
Question 34: What are the key components of a well-documented SAR investigation file?
- Only the transaction data that triggered the alert and the SAR filing date
- Documentation of the alert trigger, research conducted (internal and external), timeline of suspicious activity, analysis of the activity, the filing decision rationale, and records of any law enforcement communications (Correct answer)
- Customer identity documents only, with a brief notation that suspicious activity occurred
- Only the SAR filing confirmation number and the compliance officer's signature
Correct answer: Documentation of the alert trigger, research conducted (internal and external), timeline of suspicious activity, analysis of the activity, the filing decision rationale, and records of any law enforcement communications
A complete SAR investigation file must document the entire investigation lifecycle: the triggering event, all research steps, the analytical findings, the SAR filing decision rationale, and all communications with law enforcement β providing a clear, defensible record.
Question 35: What is the role of the 'BSA Officer' (BSAO) in an AML investigation?
- The BSAO only communicates with regulators and has no operational investigation role
- The BSAO is responsible only for employee AML training programs
- The BSAO only files CTRs and has no role in investigations
- The BSAO oversees the AML compliance program and typically makes or approves final SAR filing decisions, ensuring investigations are thorough and documented (Correct answer)
Correct answer: The BSAO oversees the AML compliance program and typically makes or approves final SAR filing decisions, ensuring investigations are thorough and documented
The BSA Officer (also called the AML Compliance Officer) is responsible for overseeing the AML program, which includes ensuring investigations are properly conducted, documented, and that SAR filing decisions are sound and well-supported.
Question 36: What is the purpose of a 'compliance testing' function within an AML program, distinct from audit?
- Compliance testing and AML audit are identical functions that should be combined
- Compliance testing is ongoing quality assurance conducted by the compliance function itself to identify and remediate control weaknesses before formal audit reviews, providing first-line feedback on program effectiveness (Correct answer)
- Compliance testing reviews individual employee performance for disciplinary purposes
- Compliance testing is only required after a regulatory examination finds deficiencies
Correct answer: Compliance testing is ongoing quality assurance conducted by the compliance function itself to identify and remediate control weaknesses before formal audit reviews, providing first-line feedback on program effectiveness
Compliance testing (also called compliance monitoring or quality assurance) is a second-line function that proactively tests whether AML controls are operating effectively, identifying weaknesses before formal audit and supporting continuous improvement.
Question 37: Which of the following best characterizes the "layering" stage in money laundering?
- Withdrawing funds from structured deposits in several geographic regions
- Using complicated financial transactions to conceal the origin of the cash (Correct answer)
- Integrating laundered monies into the economy using lawful transactions
- Introducing illegal funds into the financial system via a respectable source
Correct answer: Using complicated financial transactions to conceal the origin of the cash
The 'layering' stage in money laundering is best characterized by using complicated financial transactions to conceal the origin of the cash. After placement, criminals move funds through multiple accounts, jurisdictions, and complex financial instruments to obscure the audit trail and separate the illicit money from its criminal source. This makes it extremely difficult for authorities to trace the funds back to their illegal origins.
Question 38: What are common transaction monitoring 'red flags' for potential human trafficking proceeds?
- Large investment account transfers to foreign mutual funds
- Frequent currency exchanges between major world currencies
- Large commercial real estate purchases through LLC structures
- Multiple individuals sharing an address depositing cash with identical amounts, frequent hotel-related charges, purchases at adult entertainment venues, and cash-intensive activity inconsistent with employment or stated income (Correct answer)
Correct answer: Multiple individuals sharing an address depositing cash with identical amounts, frequent hotel-related charges, purchases at adult entertainment venues, and cash-intensive activity inconsistent with employment or stated income
Human trafficking red flags in financial transactions include: multiple individuals at the same address making similar cash deposits, patterns of hotel, motel, and adult entertainment spending, activity inconsistent with stated employment, and use of prepaid cards or multiple controlled accounts.
Question 39: Which of the following is the best course of action for a specific account when the institution reports suspicious activity?
- Inform the client that the transaction has been reported.
- Immediately close the account.
- Keep all supporting documents. (Correct answer)
- Freeze the cash unless the appropriate authorities notifies you otherwise.
Correct answer: Keep all supporting documents.
When an institution reports suspicious activity, the best course of action for that specific account is to keep all supporting documents. This ensures that a complete audit trail is preserved for law enforcement investigations. Freezing funds or informing the client could be considered 'tipping off' and might impede an ongoing investigation, while immediately closing the account might also disrupt investigative efforts.
Question 40: What is the 'no tipping off' rule and how does it affect account management decisions after a SAR is filed?
- Financial institutions must immediately close accounts for which a SAR has been filed
- The rule prevents law enforcement from notifying suspects that they are under investigation
- Financial institutions cannot notify a customer that a SAR has been filed or is being considered about them, which means account closure decisions and customer communications must be managed carefully to avoid revealing SAR-related concerns (Correct answer)
- The rule prevents compliance staff from telling front-line employees about customer risk ratings
Correct answer: Financial institutions cannot notify a customer that a SAR has been filed or is being considered about them, which means account closure decisions and customer communications must be managed carefully to avoid revealing SAR-related concerns
The tipping off prohibition means institutions must handle any account management actions β including account closures, product restrictions, or customer inquiries β in ways that do not reveal or suggest that a SAR has been filed.
Question 41: An investigator identifies a customer making frequent cash deposits in amounts just under the $10,000 reporting threshold across several different branches on the same day. This pattern is inconsistent with the customer's stated business profile. This activity is a classic red flag for:
- Terrorist financing.
- Structuring. (Correct answer)
- Correspondent banking risk.
- Trade-based money laundering.
Correct answer: Structuring.
Structuring is the act of breaking down a large transaction into smaller, individual transactions to evade currency reporting requirements. Making multiple cash deposits below the reporting threshold is a common method used to structure transactions and is a significant red flag for money laundering that requires investigation.
Question 42: When a financial institution is conducting a risk assessment of a potential respondent bank for a new correspondent relationship, which of the following factors is LEAST likely to be a primary driver of the inherent AML risk rating?
- The purpose of the account and the anticipated types and volume of transactions.
- The respondent bank's customer base and the geographic markets it serves.
- The respondent bank's most recently published annual marketing budget. (Correct answer)
- The quality and effectiveness of banking supervision in the respondent bank's home country.
Correct answer: The respondent bank's most recently published annual marketing budget.
While a bank's financial health is relevant, its annual marketing budget is not a primary factor in assessing its inherent AML/CFT risk. The core elements of a correspondent banking risk assessment focus on the respondent's business profile (customers, geography, products), the regulatory environment of its home country, and the nature of the services it will use through the correspondent account.
Question 43: How should an institution handle a FinCEN 314(a) inquiry for a customer who has a current SAR investigation open?
- Respond to the 314(a) inquiry as required (confirm or deny the match), continue the internal investigation, and ensure confidentiality is maintained for both the SAR and the 314(a) response (Correct answer)
- Halt the internal SAR investigation and wait for law enforcement to contact the institution directly
- Notify the customer that they have been identified in a law enforcement inquiry
- Immediately close the customer's account to avoid liability
Correct answer: Respond to the 314(a) inquiry as required (confirm or deny the match), continue the internal investigation, and ensure confidentiality is maintained for both the SAR and the 314(a) response
Institutions must respond to 314(a) inquiries confirming or denying whether the named individual has current accounts or conducted transactions, while simultaneously maintaining confidentiality of both the SAR investigation and the 314(a) response β they are separate, confidential processes.
Question 44: What information should be gathered during the initial stage of an AML investigation triggered by a transaction monitoring alert?
- Customer identity information, account history, related party information, transaction patterns, and any prior SAR or alert history (Correct answer)
- External law enforcement reports and media searches only
- Only the transaction details that triggered the alert
- Only the beneficial ownership information for the account
Correct answer: Customer identity information, account history, related party information, transaction patterns, and any prior SAR or alert history
A thorough AML investigation requires gathering comprehensive information from multiple sources: customer identity and KYC file, full account and transaction history, related party connections, prior alert/SAR history, and external sources such as public records and adverse media.
Question 45: Under the ACAMS framework, what is the recommended first step in developing an enterprise-wide AML risk assessment?
- Filing SARs for all high-risk customers identified in prior years
- Training all front-line staff on recognizing suspicious transactions
- Establishing a compliance committee and drafting AML policies
- Identifying inherent risks across products, customers, geographies, and delivery channels (Correct answer)
Correct answer: Identifying inherent risks across products, customers, geographies, and delivery channels
A sound risk assessment begins with identifying inherent risks across all business dimensions before applying controls or determining residual risk.
Question 46: An AML investigator is reviewing a corporate account for a company that imports electronics. The account shows several large, round-figure wire transfers to a new supplier in a high-risk jurisdiction, which is inconsistent with the company's established payment patterns. The investigator has already reviewed all internal customer due diligence (CDD) information. What is the most appropriate next step to gather more context?
- Contact the customer directly to inquire about the purpose of the new payments.
- Close the account immediately to mitigate the financial institution's risk.
- Immediately file a Suspicious Activity Report (SAR) based on the red flags.
- Conduct open-source intelligence (OSINT) research on the new supplier and review public records. (Correct answer)
Correct answer: Conduct open-source intelligence (OSINT) research on the new supplier and review public records.
The most appropriate next step is to gather more information discreetly. Open-source intelligence (OSINT) allows the investigator to research the new supplier, check for adverse media, verify its business legitimacy, and look for any connections to sanctioned or high-risk entities without alerting the customer. Filing a SAR may be premature without further context. Contacting the customer could lead to tipping off, and closing the account is an action taken after a risk decision is made, not typically as an investigative step.
Question 47: What is the 'Palermo Convention' (2000 UN Convention Against Transnational Organized Crime) and how did it expand the AML criminalization framework?
- It established the FATF and its 40 Recommendations
- It created the first international anti-corruption framework requiring confiscation of bribery proceeds
- It extended mandatory criminalization of money laundering beyond drug proceeds to the proceeds of all 'serious crimes,' as defined by the convention, significantly broadening the predicate offense base for AML laws worldwide (Correct answer)
- It established mutual legal assistance requirements specific to cybercrime-related money laundering
Correct answer: It extended mandatory criminalization of money laundering beyond drug proceeds to the proceeds of all 'serious crimes,' as defined by the convention, significantly broadening the predicate offense base for AML laws worldwide
The Palermo Convention extended the money laundering criminalization obligation from drug proceeds (Vienna Convention, 1988) to the proceeds of all serious crimes (defined as offenses punishable by four or more years of imprisonment), dramatically broadening the predicate offense base for AML laws worldwide.
Question 48: During an internal investigation, an AML analyst gathers information from multiple sources to build a comprehensive picture of the suspicious activity. Which of the following would be considered an internal source of information?
- Publicly available corporate registries.
- Adverse media reports from news websites.
- Law enforcement requests for information.
- Customer Identification Program (CIP) and due diligence records. (Correct answer)
Correct answer: Customer Identification Program (CIP) and due diligence records.
Internal sources of information are those held within the financial institution itself. This includes the data collected during onboarding, such as CIP information, account opening documentation, and ongoing due diligence records, as well as the customer's transaction history. Law enforcement requests, public records, and media reports are all valuable external sources of information.
Question 49: Which category of PEP is defined as 'domestic PEP' under US AML rules?
- Senior officials of US federal, state, or local government entrusted with prominent public functions (Correct answer)
- Relatives of foreign PEPs residing in the US
- Any US citizen who works for a foreign government
- Senior officials of foreign governments only
Correct answer: Senior officials of US federal, state, or local government entrusted with prominent public functions
Domestic PEPs are individuals entrusted with prominent public functions within the US, such as senior elected or appointed government officials.
Question 50: How are online platforms and social media used in terrorist financing?
- Terrorist networks use encrypted messaging apps, crowdfunding platforms, gaming platforms, and social media to solicit donations, recruit financiers, coordinate fundraising, and move small amounts that fall below traditional monitoring thresholds (Correct answer)
- Only established terrorist organizations with large budgets use online platforms; lone wolves always self-finance
- Social media financing only applies to politically motivated domestic extremism, not international terrorism
- Online terrorist financing is easily detected through existing bank transaction monitoring systems
Correct answer: Terrorist networks use encrypted messaging apps, crowdfunding platforms, gaming platforms, and social media to solicit donations, recruit financiers, coordinate fundraising, and move small amounts that fall below traditional monitoring thresholds
Modern terrorist financing increasingly exploits digital platforms β encrypted communications, crowdfunding, online gaming, and social media β to solicit donations and move funds in small amounts that evade traditional bank monitoring, often in cryptocurrencies.
Question 51: What is the purpose of AML 'policies and procedures' and how should they be maintained?
- Policies are for external reporting only; procedures are for internal staff reference
- AML policies only need to be updated when a new BSA regulation takes effect
- Policies establish the institution's high-level AML framework and risk appetite, while procedures provide specific, actionable guidance for implementing the policies; both must be regularly reviewed and updated to reflect regulatory changes and lessons learned (Correct answer)
- Policies are set by regulators and cannot be customized; procedures are entirely flexible
Correct answer: Policies establish the institution's high-level AML framework and risk appetite, while procedures provide specific, actionable guidance for implementing the policies; both must be regularly reviewed and updated to reflect regulatory changes and lessons learned
AML policies establish the institution's overall approach and risk appetite, while procedures provide detailed operational guidance. Both must be current, risk-based, accessible to relevant staff, and regularly reviewed and updated to reflect regulatory changes, examination findings, and evolving risks.
Question 52: What enhanced due diligence measures are specifically required for Politically Exposed Persons (PEPs) under FATF Recommendation 12?
- PEPs are only subject to EDD if they are from high-risk jurisdictions
- Senior management approval for the relationship, reasonable measures to establish the source of wealth and funds, and enhanced ongoing monitoring (Correct answer)
- PEPs must be refused all banking services under FATF standards
- PEPs need only standard CDD since their public role makes them lower risk
Correct answer: Senior management approval for the relationship, reasonable measures to establish the source of wealth and funds, and enhanced ongoing monitoring
FATF Recommendation 12 requires that for PEPs, institutions must: obtain senior management approval; take reasonable measures to establish source of wealth and funds; and conduct enhanced ongoing monitoring of the business relationship.
Question 53: Which category of customer typically requires Enhanced Due Diligence (EDD) measures?
- Students opening basic savings accounts
- Non-profit organizations in low-risk jurisdictions
- Salaried employees with direct deposit
- Politically Exposed Persons (PEPs) (Correct answer)
Correct answer: Politically Exposed Persons (PEPs)
PEPs present elevated corruption and money laundering risk due to their access to public funds and political influence, necessitating EDD.
Question 54: Which situation should be reported as possibly suspicious activity?
- A convenience store's daily deposits and withdrawals are mostly in cash.
- A retail chain transfers cash into many operational accounts before consolidating the funds into a single account.
- A domestic business account gets a wire transfer from an overseas company with no prior history of such activity or business demands. (Correct answer)
- A corporate account receives substantial cheques and wire transfers on a regular basis from current customers.
Correct answer: A domestic business account gets a wire transfer from an overseas company with no prior history of such activity or business demands.
A domestic business account receiving a wire transfer from an overseas company with no prior history of such activity or business demands should be reported as possibly suspicious. This scenario lacks a clear legitimate business purpose and could indicate an attempt to introduce illicit funds into the financial system. The unexpected nature and international origin raise immediate red flags for potential money laundering.
Question 55: Which of the following represents the financial stage of money laundering?
- placement (Correct answer)
- structuring
Correct answer: placement
Placement is the first financial stage of money laundering, where illegally obtained cash is introduced into the legitimate financial system. This often involves breaking up large sums of cash into smaller, less conspicuous amounts and depositing them into bank accounts or converting them into monetary instruments. Structuring is a technique used during the placement stage to avoid reporting thresholds.
Question 56: What is 'nostro reconciliation' and why is it important from an AML perspective?
- Reconciling a bank's accounts held at correspondent banks (nostro accounts) to ensure all transactions are accounted for and identify unrecognized entries that may indicate fraud or unauthorized transactions (Correct answer)
- Reconciling foreign currency positions; reduces exchange rate risk
- Reconciling interest payments on interbank loans; ensures accurate P&L reporting
- Reconciling customer loan payments; detects fraud
Correct answer: Reconciling a bank's accounts held at correspondent banks (nostro accounts) to ensure all transactions are accounted for and identify unrecognized entries that may indicate fraud or unauthorized transactions
Nostro reconciliation involves matching a bank's internal records against the statements of its accounts held at correspondent banks. From an AML perspective, unrecognized or unexplained entries may indicate fraudulent transactions, unauthorized access, or money laundering activity.
Question 57: What is the primary purpose of a financial institution's AML training program?
- To document that the institution has conducted annual compliance reviews
- To satisfy regulatory examination requirements and avoid penalties
- To educate customers on the risks of financial crime
- To ensure employees can identify, report, and escalate potential money laundering activity (Correct answer)
Correct answer: To ensure employees can identify, report, and escalate potential money laundering activity
Effective AML training equips employees to recognize red flags and understand their reporting obligations, making them the institution's frontline defense.
Question 58: An AML program's policies, procedures, and internal controls should be MOST influenced by which of the following?
- The personal preferences of the Chief Executive Officer.
- The AML programs of competing financial institutions.
- The results of the institution's enterprise-wide risk assessment. (Correct answer)
- The number of employees in the compliance department.
Correct answer: The results of the institution's enterprise-wide risk assessment.
The foundation of a risk-based AML program is the enterprise-wide risk assessment. The results of this assessment, which identifies the specific ML/TF risks the institution faces from its customers, products, services, and geographies, should directly inform the design and implementation of its policies, procedures, and controls.
Question 59: What are 'money service businesses' (MSBs) and why do they require enhanced due diligence?
- Large commercial banks providing international wire services; they are lower risk due to strong regulation
- Broker-dealers registered with FINRA; they are subject to securities rather than BSA regulation
- Non-bank financial institutions (check cashers, money transmitters, currency exchangers, prepaid card issuers) that process large volumes of cash or value transfers and are frequently targeted by money launderers (Correct answer)
- Community development financial institutions; they serve underbanked populations
Correct answer: Non-bank financial institutions (check cashers, money transmitters, currency exchangers, prepaid card issuers) that process large volumes of cash or value transfers and are frequently targeted by money launderers
MSBs are non-bank financial businesses that handle currency, money orders, wire transfers, and similar instruments. They require EDD because their cash-intensive, high-volume operations and often anonymous customers create significant ML/TF exposure.
Question 60: When a financial institution identifies a discrepancy in beneficial ownership information provided by a customer, what is the appropriate response?
- Immediately file a SAR without further investigation
- Close the account immediately
- Conduct additional due diligence to resolve the discrepancy; escalate and file a SAR if suspicion remains (Correct answer)
- Accept the customer's explanation without documentation
Correct answer: Conduct additional due diligence to resolve the discrepancy; escalate and file a SAR if suspicion remains
FinCEN guidance requires institutions to conduct additional due diligence when discrepancies arise, and to file a SAR if the discrepancy cannot be satisfactorily resolved and suspicion of illicit activity remains.
Question 61: Which of the following situations would mandate a financial institution to conduct customer due diligence (CDD) measures, according to FATF Recommendation 10?
- Only when establishing a new business relationship.
- Only when a transaction exceeds a very high, pre-defined internal threshold set by the bank's board.
- When there is a suspicion of money laundering, regardless of any transaction threshold. (Correct answer)
- Only when a customer requests to open an account for a trust or legal arrangement.
Correct answer: When there is a suspicion of money laundering, regardless of any transaction threshold.
FATF Recommendation 10 states that CDD must be performed in several circumstances, including: when establishing business relations; when carrying out occasional transactions above the designated threshold; when there is a suspicion of money laundering or terrorist financing; or when the institution has doubts about the veracity of previously obtained customer identification data. A suspicion of ML/TF triggers the CDD requirement irrespective of any threshold.
Question 62: What does the legal term 'tipping off' mean in the AML context, and what is its consequence?
- Informing a supervisor about a colleague's suspicious behavior; it is encouraged
- Providing anonymous tips to law enforcement; it is legally protected
- Sharing customer information with another financial institution; it may violate privacy laws
- Disclosing to a subject that a SAR has been filed or is being considered about them; it is a federal crime under 31 USC 5318(g)(2) (Correct answer)
Correct answer: Disclosing to a subject that a SAR has been filed or is being considered about them; it is a federal crime under 31 USC 5318(g)(2)
Tipping off is the illegal act of notifying a customer or any person that they are the subject of a SAR investigation. Under 31 USC 5318(g)(2), tipping off is a federal crime that can result in imprisonment and fines.
Question 63: Which of the following is a primary purpose of the independent testing (or audit) component of an AML program?
- To replace the need for ongoing employee training.
- To set the risk appetite and tolerance for the financial institution.
- To discipline employees who fail to meet their compliance obligations.
- To ensure the program is functioning as designed and is effective in mitigating ML/TF risks. (Correct answer)
Correct answer: To ensure the program is functioning as designed and is effective in mitigating ML/TF risks.
The independent testing or audit function is a critical component of an AML program. Its primary purpose is to provide an objective evaluation of the program's adequacy and effectiveness, ensuring that policies are being followed and that the program is appropriately mitigating money laundering and terrorist financing risks.
Question 64: What should an effective AML training program include to meet regulatory expectations?
- AML training only for employees in the compliance department
- Training only for new hires during their onboarding process
- A single annual training module covering all BSA topics for all employees
- Risk-based training tailored to employees' roles and responsibilities, covering relevant AML regulations, red flags specific to their business line, SAR filing obligations, and training on current typologies and schemes (Correct answer)
Correct answer: Risk-based training tailored to employees' roles and responsibilities, covering relevant AML regulations, red flags specific to their business line, SAR filing obligations, and training on current typologies and schemes
Effective AML training must be risk-based and role-specific β front-line tellers receive different training than private bankers or trade finance officers β and must be regularly updated to cover current typologies, schemes, and regulatory developments.
Question 65: What is 'alert disposition' in a transaction monitoring system and what documentation is required?
- The technical process of routing alerts to the correct compliance analyst
- An automated system that closes alerts without human review if no prior SAR history exists
- The process of reviewing transaction monitoring alerts and documenting the outcome β either closing the alert with documented rationale or escalating to a full investigation β required to demonstrate the appropriateness of AML decisions to regulators (Correct answer)
- The process of adjusting alert thresholds based on false positive rates
Correct answer: The process of reviewing transaction monitoring alerts and documenting the outcome β either closing the alert with documented rationale or escalating to a full investigation β required to demonstrate the appropriateness of AML decisions to regulators
Alert disposition is the analyst review of each transaction monitoring alert, resulting in either a documented close (with clear rationale why the activity is not suspicious) or escalation to a formal investigation. All dispositions must be documented to support regulatory examination.
Question 66: What is the Financial Action Task Force's (FATF) mandate and membership structure?
- FATF is a UN agency with 193 member countries that issues binding resolutions
- FATF is a World Bank initiative that provides technical assistance to developing countries on AML compliance
- FATF is an NGO funded by private banks to develop voluntary AML best practices
- FATF is an intergovernmental policy-making body established in 1989 with 39 members (37 member jurisdictions plus the European Commission and Gulf Co-operation Council) that sets AML/CFT standards and assesses compliance (Correct answer)
Correct answer: FATF is an intergovernmental policy-making body established in 1989 with 39 members (37 member jurisdictions plus the European Commission and Gulf Co-operation Council) that sets AML/CFT standards and assesses compliance
FATF is an intergovernmental body established at the G7 Paris Summit in 1989. It has 39 members (37 jurisdictions plus the European Commission and GCC) and sets global AML/CFT standards through its 40 Recommendations.
Question 67: A global bank is conducting its annual review of its correspondent banking relationships. To align with international best practices for collecting due diligence information, which standardized tool, developed by a major industry group, would be most appropriate to use?
- The Basel Committee's Core Principles for Effective Banking Supervision
- The Egmont Group's Secure Web System
- The FATF Public Statement on High-Risk Jurisdictions
- The Wolfsberg Group's Correspondent Banking Due Diligence Questionnaire (CBDDQ) (Correct answer)
Correct answer: The Wolfsberg Group's Correspondent Banking Due Diligence Questionnaire (CBDDQ)
The Wolfsberg Group, an association of global financial institutions, developed the Correspondent Banking Due Diligence Questionnaire (CBDDQ) to provide a standardized, reasonable, and enhanced due diligence tool for correspondent banking relationships. It is considered a global standard for managing financial crime risks in this area.
Question 68: What is 'round-tripping' in the context of TBML?
- A customs process for inspecting returned goods
- Issuing multiple invoices for one shipment
- Sending funds overseas and repatriating them as foreign investment or trade proceeds (Correct answer)
- Shipping goods from a country and returning them to the same country as different goods
Correct answer: Sending funds overseas and repatriating them as foreign investment or trade proceeds
Round-tripping involves moving money out of a country and bringing it back disguised as legitimate foreign investment or export proceeds to give illicit funds a lawful appearance.
Question 69: What specific information should be included in a SAR narrative to maximize its utility to law enforcement?
- A brief description of the activity and a reference to the transaction monitoring scenario that triggered the alert
- Only the account number, transaction dates, and total suspicious dollar amount
- The account holder's credit score and employment history
- The full context of the suspicious activity including who, what, when, where, why it is suspicious, how the scheme operates, all involved parties and accounts, prior SAR history, and any law enforcement contacts or legal process received (Correct answer)
Correct answer: The full context of the suspicious activity including who, what, when, where, why it is suspicious, how the scheme operates, all involved parties and accounts, prior SAR history, and any law enforcement contacts or legal process received
An effective SAR narrative answers the five W's plus how: who is involved (all parties and entities), what activity occurred (specific transactions), when (dates and timeline), where (accounts, locations), why it is suspicious (specific reasons), and how the scheme works β providing law enforcement with a complete, actionable intelligence report.
Question 70: Which approach does FATF recommend for applying beneficial ownership and PEP controls?
- A standardized rule-based approach applying identical controls to all customers
- A zero-tolerance policy treating all customers as high risk
- A tiered fee-based approach where higher-risk customers pay more for due diligence
- A risk-based approach, applying enhanced measures proportional to the level of assessed risk (Correct answer)
Correct answer: A risk-based approach, applying enhanced measures proportional to the level of assessed risk
FATF's core principle is the risk-based approach: institutions should apply enhanced measures to higher-risk customers and relationships (including PEPs and complex ownership structures) proportionate to assessed risk.
Question 71: According to the FATF 40 Recommendations, the cornerstone of an effective AML/CFT system, which allows for the flexible and efficient allocation of resources, is known as what?
- The Checklist-Based Model
- The Prescriptive Compliance Framework
- The Risk-Based Approach (RBA) (Correct answer)
- The Transactional Limitation System
Correct answer: The Risk-Based Approach (RBA)
FATF Recommendation 1 explicitly calls for countries and financial institutions to identify, assess, and understand their money laundering and terrorist financing risks and apply a corresponding set of AML/CFT measures. This is the definition of the Risk-Based Approach (RBA), which is considered the foundation for the effective implementation of all other FATF Recommendations.
Question 72: What is the difference between Customer Identification Program (CIP) and Customer Due Diligence (CDD)?
- CIP applies to individuals while CDD applies to legal entities
- CIP is the minimum identity verification process at account opening (name, address, DOB, ID number), while CDD is the broader ongoing program that includes risk profiling, beneficial ownership, and transaction monitoring (Correct answer)
- CIP is required by FinCEN while CDD is only a best practice recommendation
- CIP and CDD are interchangeable terms for the same regulatory requirement
Correct answer: CIP is the minimum identity verification process at account opening (name, address, DOB, ID number), while CDD is the broader ongoing program that includes risk profiling, beneficial ownership, and transaction monitoring
CIP is the foundational identity verification requirement at account opening (collecting and verifying name, date of birth, address, and identification number). CDD is the broader, ongoing program that encompasses CIP plus risk profiling, beneficial ownership identification, understanding the business relationship, and ongoing monitoring.
Question 73: How should financial institutions handle CDD for customers who claim to be acting on behalf of an undisclosed principal?
- Require the undisclosed principal to appear in person before any account activity
- Refuse all such customers without exception as they pose automatic ML risk
- Accept the claim and proceed with only the agent's identification
- Treat this as a significant red flag, attempt to identify and verify the undisclosed principal, and consider whether to file a SAR if the principal cannot be identified (Correct answer)
Correct answer: Treat this as a significant red flag, attempt to identify and verify the undisclosed principal, and consider whether to file a SAR if the principal cannot be identified
Customers acting for undisclosed principals raise significant AML concerns because the true beneficial owner is hidden. Institutions should attempt to identify the principal, treat the opacity as a high-risk indicator, and consider whether suspicious activity reporting is warranted.
Question 74: Which of the following is a key red flag indicating potential money laundering through real estate?
- Property is purchased with all-cash from a shell company with no apparent business purpose (Correct answer)
- Transaction is conducted through a licensed real estate agent
- Buyer requests a title insurance policy
- Buyer uses a mortgage from a licensed lender
Correct answer: Property is purchased with all-cash from a shell company with no apparent business purpose
All-cash purchases through opaque shell companies are a classic real estate money laundering indicator, as they allow criminals to obscure the true beneficial owner and inject illicit funds without bank scrutiny.
Question 75: Which international body has issued guidance specifically addressing TBML typologies and red flags?
- World Customs Organization (WCO) alone
- Financial Action Task Force (FATF) (Correct answer)
- International Monetary Fund (IMF)
- World Trade Organization (WTO)
Correct answer: Financial Action Task Force (FATF)
FATF issued a landmark report on TBML in 2006 and subsequent guidance identifying key typologies, red flags, and recommended controls.
Question 76: What is 'source of funds' vs. 'source of wealth' in the context of PEP due diligence?
- They are identical concepts requiring the same documentation
- Source of funds refers to the origin of the specific funds in a transaction or account, while source of wealth refers to how the customer accumulated their total net worth (Correct answer)
- Source of wealth is only required for customers with over $1 million in assets
- Source of funds applies to businesses while source of wealth applies to individuals
Correct answer: Source of funds refers to the origin of the specific funds in a transaction or account, while source of wealth refers to how the customer accumulated their total net worth
Source of funds identifies where the specific money in a particular transaction came from (salary, sale of property, inheritance), while source of wealth examines how the customer accumulated their overall net worth over their lifetime.
Question 77: What is a 'sanctions risk assessment' and what factors should it include for a global financial institution?
- A legal review of the institution's sanctions policies for technical accuracy
- A review of OFAC's annual enforcement statistics to benchmark against industry peers
- A due diligence process for acquiring other financial institutions
- An evaluation of the institution's exposure to sanctions risks across its customer base, products, geographies, and transaction types, used to calibrate sanctions controls and monitoring (Correct answer)
Correct answer: An evaluation of the institution's exposure to sanctions risks across its customer base, products, geographies, and transaction types, used to calibrate sanctions controls and monitoring
A sanctions risk assessment evaluates the institution's total exposure to sanctions violations across its business β identifying high-risk customers, products, geographies, and transaction types to ensure controls are appropriately designed and resourced.
Question 78: Under the Corporate Transparency Act (CTA), effective January 2024 in the US, who is responsible for reporting beneficial ownership information?
- Covered reporting companies (most small corporations and LLCs) directly to FinCEN (Correct answer)
- Banks and financial institutions on behalf of their customers
- Registered agents of corporations
- State secretaries of state offices
Correct answer: Covered reporting companies (most small corporations and LLCs) directly to FinCEN
The CTA requires most small corporations, LLCs, and similar entities to file beneficial ownership information directly with FinCEN's Beneficial Ownership Secure System (BOSS), shifting the reporting obligation to the companies themselves.
Question 79: What is the role of the 'board of directors' in overseeing the BSA/AML compliance program?
- The board approves the AML program and policies, receives regular reports on AML program performance, and is ultimately accountable for ensuring the institution maintains effective AML controls (Correct answer)
- The board only becomes involved when a regulatory enforcement action is initiated
- The board's only role is to approve the AML budget annually
- The board has no AML responsibility β that rests entirely with the compliance officer
Correct answer: The board approves the AML program and policies, receives regular reports on AML program performance, and is ultimately accountable for ensuring the institution maintains effective AML controls
The board of directors bears ultimate accountability for BSA/AML compliance. The board approves the AML program and policies, receives regular compliance reports, ensures adequate resources are allocated, and is held responsible by regulators for the effectiveness of the program.
Question 80: Hawala is best described as which type of money transfer system?
- A formal remittance service licensed in all 50 U.S. states
- An informal value transfer system based on trust and a network of brokers (Correct answer)
- A cryptocurrency exchange platform used for cross-border payments
- An electronic interbank wire transfer system regulated by the Fed
Correct answer: An informal value transfer system based on trust and a network of brokers
Hawala operates outside the formal banking system, transferring value through a network of brokers (hawaladars) using a code or token rather than physical movement of funds.
Question 81: A financial institution is reviewing its AML program's effectiveness. Which of the following elements is considered a fundamental pillar, often referred to as one of the 'five pillars' of an effective AML program?
- A designated compliance officer with day-to-day responsibility for the AML program. (Correct answer)
- A marketing department trained to identify high-risk jurisdictions.
- An annual bonus structure for employees who report the most suspicious activities.
- A policy of declining all cash transactions exceeding $5,000.
Correct answer: A designated compliance officer with day-to-day responsibility for the AML program.
An effective AML program is built on several core components. Globally recognized standards, such as those from the Financial Action Task Force (FATF) and implemented by various jurisdictions, consistently require a designated AML compliance officer. This individual or department must have the authority and resources to implement and manage the AML program.
Question 82: What is a '314(b) information sharing request' and how does it support AML investigations?
- A process for banks to request law enforcement records about specific customers
- A voluntary program under the USA PATRIOT Act allowing financial institutions to share information with each other about potential money laundering or terrorist financing activity (Correct answer)
- A FinCEN regulation requiring banks to share customer data with the IRS
- A mandatory reporting requirement for transactions involving shell companies
Correct answer: A voluntary program under the USA PATRIOT Act allowing financial institutions to share information with each other about potential money laundering or terrorist financing activity
Section 314(b) of the USA PATRIOT Act created a voluntary information-sharing program allowing financial institutions that have registered with FinCEN to share information with each other about individuals, entities, and transactions suspected of money laundering or terrorist financing.
Question 83: How should AML compliance programs be structured when an institution operates in multiple countries?
- Allow each country operation to establish entirely independent AML programs without headquarters oversight
- Apply only the home country's AML standards globally and ignore local requirements
- Only apply AML requirements in countries where FATF membership applies
- Establish a global minimum standard based on the most rigorous applicable requirements, with local country-specific additions to meet host country laws; coordinate global risk assessments while adapting controls for local market conditions (Correct answer)
Correct answer: Establish a global minimum standard based on the most rigorous applicable requirements, with local country-specific additions to meet host country laws; coordinate global risk assessments while adapting controls for local market conditions
Multinational institutions must meet the strictest applicable requirements across all jurisdictions β typically establishing a global minimum standard and layering local requirements on top β while maintaining enterprise-wide visibility through coordinated risk management.
Question 84: An AML analyst is reviewing a customer's account and notes a pattern of frequent cash deposits in different branches, all just under the $10,000 reporting threshold. This activity is immediately followed by wire transfers to a high-risk jurisdiction. This pattern is a classic red flag for which of the following?
- Refining.
- Structuring. (Correct answer)
- Integration stage of money laundering.
- Terrorist financing.
Correct answer: Structuring.
Structuring is the act of breaking down a large financial transaction into a series of smaller transactions to avoid triggering currency transaction reporting (CTR) requirements. The scenario describes a customer intentionally keeping deposits below the $10,000 threshold, which is a hallmark of structuring.
Question 85: What is 'regulatory examination management' and why is it an important AML program component?
- The process of preparing for, managing, and responding to regulatory examinations of the AML program, including organizing documentation, coordinating staff responses, addressing findings promptly, and implementing corrective action plans (Correct answer)
- Scheduling examinations at times that minimize business disruption
- Lobbying regulators to reduce AML requirements
- Hiring former regulators to lead the compliance department
Correct answer: The process of preparing for, managing, and responding to regulatory examinations of the AML program, including organizing documentation, coordinating staff responses, addressing findings promptly, and implementing corrective action plans
Regulatory examination management ensures the institution is always examination-ready, that examiners have efficient access to required documentation, and that findings are addressed promptly through documented corrective action plans.
Question 86: What is the 'hawala' system and why does it present challenges for TF monitoring?
- A cryptocurrency-based payment system popular in South Asia
- A formal wire transfer system regulated by central banks in the Middle East
- A microfinance system for small businesses in developing countries
- An informal value transfer system based on a network of brokers (hawaladars) who settle transactions through trust and offsetting without physically moving money, creating minimal documentation and bypassing regulated financial channels (Correct answer)
Correct answer: An informal value transfer system based on a network of brokers (hawaladars) who settle transactions through trust and offsetting without physically moving money, creating minimal documentation and bypassing regulated financial channels
Hawala is an informal value transfer system where brokers (hawaladars) transfer value through offsetting obligations without physical money movement. It leaves minimal paper trail and bypasses regulated financial institutions, making it attractive for TF and difficult to monitor.
Question 87: An investigator is analyzing an alert on a customer's account involving structured cash deposits followed by an outgoing wire transfer. The investigator has reviewed account opening documents, transaction history, and notes from the relationship manager. Which of the following represents the next logical step of gathering *external* information?
- Reviewing security camera footage of the deposits being made.
- Performing a public internet search on the beneficiary of the wire transfer. (Correct answer)
- Interviewing the teller who accepted the cash deposits.
- Checking the institution's central database for other accounts linked to the customer.
Correct answer: Performing a public internet search on the beneficiary of the wire transfer.
Options A, C, and D all represent the gathering of *internal* information that is already within the financial institution's possession or accessible through its staff and systems. Performing a public internet search on the wire beneficiary is a classic example of using external, open-source intelligence (OSINT) to add context to the investigation, such as verifying the beneficiary's business or looking for adverse information.
Question 88: After filing a SAR on a customer, what is the most appropriate next step for the financial institution regarding the customer's account?
- Continue to monitor the account, potentially under enhanced due diligence, and report any further suspicious activity. (Correct answer)
- Immediately freeze all assets in the account pending law enforcement action.
- Cease all monitoring of the account as the responsibility has been transferred to the FIU.
- Inform the customer that a SAR has been filed to maintain transparency.
Correct answer: Continue to monitor the account, potentially under enhanced due diligence, and report any further suspicious activity.
Filing a SAR does not end the institution's AML obligations. The institution must not 'tip off' the customer about the SAR filing. It should continue to monitor the customer's activity, applying enhanced due diligence as appropriate, and file supplemental SARs for any new suspicious transactions. Account closure decisions should be made based on the institution's risk appetite and policies, but monitoring must continue as long as the account is open.
Question 89: Which of the following best describes 'de-risking' and what is the primary concern with this practice?
- Improving AML controls; banks over-invest in compliance
- Financial institutions exiting entire categories of customers or correspondent relationships rather than managing risk; it may exclude legitimate customers from the financial system (Correct answer)
- Reducing investment risk in trading portfolios; it reduces profitability
- Automating transaction monitoring; it generates too many false positives
Correct answer: Financial institutions exiting entire categories of customers or correspondent relationships rather than managing risk; it may exclude legitimate customers from the financial system
De-risking occurs when banks terminate or restrict services to entire categories of customers (e.g., money service businesses, non-profit organizations, correspondent banks in developing countries) rather than managing individual risk. The concern is that it can exclude legitimate users and push transactions outside the regulated system.
Question 90: What is the role of 'senior management' in BSA/AML compliance, distinct from the compliance officer and the board?
- Senior management has no defined AML role β all responsibility lies with the compliance officer
- Senior management only becomes involved when a SAR is filed against a customer
- Senior management's role is limited to approving the annual AML training curriculum
- Senior management is accountable for implementing the board-approved AML program within their business lines, ensuring adequate resources, and creating a culture of compliance that supports effective AML controls (Correct answer)
Correct answer: Senior management is accountable for implementing the board-approved AML program within their business lines, ensuring adequate resources, and creating a culture of compliance that supports effective AML controls
Senior management is responsible for implementing the AML program within their business lines, allocating necessary resources, supporting the compliance function's authority, and fostering a culture of compliance that makes AML effective in practice.
Question 91: When an AML investigator concludes an investigation and decides *not* to file a Suspicious Activity Report (SAR), what is a critical component that must be included in the investigation file?
- The exact date the account is scheduled for its next periodic CDD review.
- A detailed justification for the decision, including the specific factors and evidence reviewed. (Correct answer)
- A copy of the customer's most recent government-issued photo identification.
- An attestation signed by the relationship manager confirming the customer's good standing.
Correct answer: A detailed justification for the decision, including the specific factors and evidence reviewed.
Auditors and regulators will scrutinize the rationale for not filing a SAR. The investigation file must contain a clear and detailed justification explaining why the activity, although initially flagged, was determined not to be suspicious upon review. This demonstrates a sound and defensible decision-making process. While not always a strict regulatory requirement, it is a widely accepted best practice. The other options are either part of the standard customer file or are not directly relevant to documenting the conclusion of a specific investigation.
Question 92: How has FATF's Recommendation 13 on correspondent banking been strengthened in recent years?
- FATF now requires all correspondent relationships to be reported to the IMF
- FATF clarified that enhanced due diligence must be applied to all cross-border correspondent relationships, with greater emphasis on assessing the effectiveness (not just existence) of respondent AML controls (Correct answer)
- FATF now requires correspondent banks to physically audit respondent bank branches annually
- FATF eliminated the distinction between shell banks and licensed respondent banks
Correct answer: FATF clarified that enhanced due diligence must be applied to all cross-border correspondent relationships, with greater emphasis on assessing the effectiveness (not just existence) of respondent AML controls
FATF's 2016 clarifications to Recommendation 13 strengthened requirements by emphasizing that correspondent banks must assess the effectiveness of respondent AML controls, not merely confirm that policies exist, and must apply enhanced due diligence to all cross-border correspondent relationships.
Question 93: What does the term 'unhosted wallet' (also called 'self-hosted' or 'non-custodial wallet') mean in the context of VASP regulation?
- A wallet hosted on a regulated exchange that the user cannot directly access
- A cryptocurrency wallet controlled directly by the user without a third-party custodian (Correct answer)
- A wallet that has been frozen by a government authority pending investigation
- A shared wallet used by multiple businesses under a single compliance program
Correct answer: A cryptocurrency wallet controlled directly by the user without a third-party custodian
An unhosted (non-custodial) wallet is one where the individual holds their own private keys without relying on a third-party VASP, posing AML challenges because regulators cannot easily impose KYC requirements on transfers to or from these wallets.
Question 94: A blockchain explorer is most useful in an AML investigation for which purpose?
- Automatically freezing suspicious wallets
- Tracing the flow of funds across publicly visible transaction records (Correct answer)
- Filing Suspicious Activity Reports with FinCEN
- Determining the legal identity of a wallet owner
Correct answer: Tracing the flow of funds across publicly visible transaction records
Blockchain explorers display the publicly recorded transaction history on a given blockchain, allowing investigators to trace fund flows between wallet addresses, though they do not by themselves reveal real-world identities.
Question 95: Which international standard specifically addresses beneficial ownership transparency for legal persons and legal arrangements?
- Basel Committee Core Principle 9
- Wolfsberg Correspondent Banking Principles
- FATF Recommendation 24 (legal persons) and Recommendation 25 (legal arrangements) (Correct answer)
- FATF Recommendation 10 (customer due diligence) only
Correct answer: FATF Recommendation 24 (legal persons) and Recommendation 25 (legal arrangements)
FATF Recommendations 24 and 25 specifically require countries to ensure adequate, accurate, and timely information on beneficial ownership is available for legal persons and legal arrangements such as trusts.
Question 96: When a legal entity customer is a publicly traded company on a US exchange, how does FinCEN's CDD Rule treat beneficial ownership requirements?
- Covered financial institutions may exclude these entities from beneficial ownership identification requirements (Correct answer)
- The exchange provides all required beneficial ownership data
- Full beneficial ownership documentation is still required
- Only the CEO must be identified
Correct answer: Covered financial institutions may exclude these entities from beneficial ownership identification requirements
FinCEN's CDD Rule provides exclusions for certain regulated entities, including companies listed on US stock exchanges, because their ownership is already subject to SEC disclosure requirements.
Question 97: For PEP relationships, FATF Recommendation 12 requires which specific additional measure beyond standard CDD?
- Limiting PEP accounts to domestic transactions only
- Obtaining government approval to maintain the account
- Reporting all PEP transactions to financial intelligence units
- Senior management approval for establishing or continuing the business relationship (Correct answer)
Correct answer: Senior management approval for establishing or continuing the business relationship
FATF Recommendation 12 requires senior management approval for establishing or continuing business relationships with PEPs, in addition to enhanced due diligence measures.
Question 98: A credit union has traditionally served only local individual members. It plans to launch a new online platform to offer business accounts to international import/export companies. From a risk assessment perspective, what is the MOST significant change the credit union must address?
- The marketing budget required to attract the new business clients.
- The increase in transaction volume and server capacity requirements.
- The need to update employee training on the new platform's user interface.
- The introduction of new, higher-risk customer types and geographic exposures. (Correct answer)
Correct answer: The introduction of new, higher-risk customer types and geographic exposures.
The primary change is the fundamental shift in the risk profile. The credit union is moving from a low-risk, domestic, individual customer base to a high-risk base involving international trade, corporate structures which can obscure ownership, and cross-border transactions. This introduces significantly higher inherent risks related to customer type and geography that must be assessed and mitigated.
Question 99: Under FinCEN's Customer Due Diligence Rule (31 CFR 1010.230), what are the four core elements of CDD?
- Customer identification, beneficial ownership identification, understanding the customer's business, and ongoing monitoring (Correct answer)
- Identification, verification, monitoring, and reporting
- KYC, EDD, SAR filing, and CTR filing
- Account opening, transaction approval, risk scoring, and annual review
Correct answer: Customer identification, beneficial ownership identification, understanding the customer's business, and ongoing monitoring
FinCEN's 2016 CDD Rule established four core elements: (1) identifying and verifying the customer's identity; (2) identifying and verifying beneficial owners of legal entity customers; (3) understanding the nature and purpose of the relationship; and (4) conducting ongoing monitoring and updating customer information.
Question 100: What is a primary challenge for financial institutions in detecting the financing of 'low-cost' or self-funded terrorist attacks?
- The transactions typically involve large, complex wire transfers to multiple offshore accounts.
- The perpetrators exclusively use complex trade-based money laundering schemes.
- The funds are always provided directly by state sponsors of terrorism.
- The financial activity often consists of small, legitimate-looking transactions that do not stand out from normal spending patterns. (Correct answer)
Correct answer: The financial activity often consists of small, legitimate-looking transactions that do not stand out from normal spending patterns.
Self-funded or low-cost attacks often rely on personal funds from salaries, savings, or small personal loans. These transactions are typically small in value and appear entirely normal, making them extremely difficult for financial institutions to distinguish from legitimate financial activity and flag as suspicious.
ACAMS CAMS Certification Exam
The ACAMS CAMS exam certifies anti-money laundering specialists with 100 questions over 3.5 hours, covering AML/CFT risks, compliance programs, customer due diligence, investigations, and global sanctions.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong β answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds