Risk Assessment and Management Flashcards
6 cards from real CAMS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Risk Assessment and Management flashcards as text
What are the primary components typically assessed in a financial institution's AML risk assessment?
Answer: Customer/product/service risk, geographic risk, and channel/delivery risk
A comprehensive AML risk assessment evaluates the risks posed by the institution's customers (types, industries), products and services, geographic exposure (domestic and international), and delivery channels (branches, digital, correspondent).
What is an 'inherent risk' in the context of an AML risk assessment?
Answer: The level of risk present before any AML controls or mitigating measures are applied
Inherent risk is the raw, uncontrolled risk an institution faces from its business activities (customers, products, geographies) before any AML controls are applied — it establishes the baseline against which control effectiveness is measured.
What is 'residual risk' in an AML risk assessment?
Answer: The risk that remains after all AML controls have been applied and any remaining risk must be accepted or transferred
Residual risk is the level of AML risk that remains after the institution's controls are applied to inherent risk — if residual risk is too high, the institution must either strengthen controls or reduce the underlying business activities creating the risk.
Which risk factor would most significantly INCREASE a customer's AML risk rating?
Answer: The customer is a cash-intensive business in a high-risk industry located in an FATF grey-listed jurisdiction
Multiple compounding risk factors — cash-intensive business, high-risk industry, and high-risk geography (FATF grey-listed jurisdiction) — would significantly elevate a customer's AML risk rating and trigger EDD requirements.
What is the purpose of a 'risk appetite statement' in AML compliance?
Answer: A formal statement of the level and types of AML risk the institution is willing to accept in pursuing its business objectives
A risk appetite statement defines the maximum level of AML risk the institution's board is willing to tolerate, guiding decisions about which customer types, products, and geographies to accept and at what control levels.
How frequently should a financial institution update its AML risk assessment?
Answer: At least annually, and whenever there are material changes to the institution's products, services, customers, or geographies
Best practices and regulatory guidance require risk assessments to be updated at least annually and whenever there are significant changes that could materially affect the institution's risk profile, such as new products, customer growth, or geographic expansion.