CAMS Risk Assessment and Management 1 — Questions and Answers
Question 1: What are the primary components typically assessed in a financial institution's AML risk assessment?
- Customer credit risk, market risk, and operational risk
- Customer/product/service risk, geographic risk, and channel/delivery risk (Correct answer)
- Reputational risk, legal risk, and strategic risk only
- Employee misconduct risk and third-party vendor risk exclusively
Correct answer: Customer/product/service risk, geographic risk, and channel/delivery risk
A comprehensive AML risk assessment evaluates the risks posed by the institution's customers (types, industries), products and services, geographic exposure (domestic and international), and delivery channels (branches, digital, correspondent).
Question 2: What is an 'inherent risk' in the context of an AML risk assessment?
- Risks that cannot be mitigated under any circumstances
- The level of risk present before any AML controls or mitigating measures are applied (Correct answer)
- Risks that are inherent to the financial services industry but not specific to the institution
- The residual risk remaining after controls are applied
Correct answer: The level of risk present before any AML controls or mitigating measures are applied
Inherent risk is the raw, uncontrolled risk an institution faces from its business activities (customers, products, geographies) before any AML controls are applied — it establishes the baseline against which control effectiveness is measured.
Question 3: What is 'residual risk' in an AML risk assessment?
- The risk that remains after all AML controls have been applied and any remaining risk must be accepted or transferred (Correct answer)
- The portion of risk that is too small to be worth controlling
- The risk from accounts closed due to suspicious activity
- The leftover risk from prior regulatory examinations that wasn't remediated
Correct answer: The risk that remains after all AML controls have been applied and any remaining risk must be accepted or transferred
Residual risk is the level of AML risk that remains after the institution's controls are applied to inherent risk — if residual risk is too high, the institution must either strengthen controls or reduce the underlying business activities creating the risk.
Question 4: Which risk factor would most significantly INCREASE a customer's AML risk rating?
- The customer is a publicly listed company with SEC filings available
- The customer is a long-established local business with a predictable transaction pattern
- The customer is a cash-intensive business in a high-risk industry located in an FATF grey-listed jurisdiction (Correct answer)
- The customer is a government employee with a fixed salary deposited monthly
Correct answer: The customer is a cash-intensive business in a high-risk industry located in an FATF grey-listed jurisdiction
Multiple compounding risk factors — cash-intensive business, high-risk industry, and high-risk geography (FATF grey-listed jurisdiction) — would significantly elevate a customer's AML risk rating and trigger EDD requirements.
Question 5: What is the purpose of a 'risk appetite statement' in AML compliance?
- A statement of how aggressively the institution intends to pursue new high-risk customers
- A formal statement of the level and types of AML risk the institution is willing to accept in pursuing its business objectives (Correct answer)
- An appetite for risk reduction targets expressed as percentage decreases in SAR filings
- A regulatory-required statement of what risks the institution will not accept under any circumstances
Correct answer: A formal statement of the level and types of AML risk the institution is willing to accept in pursuing its business objectives
A risk appetite statement defines the maximum level of AML risk the institution's board is willing to tolerate, guiding decisions about which customer types, products, and geographies to accept and at what control levels.
Question 6: How frequently should a financial institution update its AML risk assessment?
- Only when required by a regulatory examination finding
- At least annually, and whenever there are material changes to the institution's products, services, customers, or geographies (Correct answer)
- Every five years as part of a strategic planning cycle
- Only when the institution experiences a money laundering incident
Correct answer: At least annually, and whenever there are material changes to the institution's products, services, customers, or geographies
Best practices and regulatory guidance require risk assessments to be updated at least annually and whenever there are significant changes that could materially affect the institution's risk profile, such as new products, customer growth, or geographic expansion.
What are the primary components typically assessed in a financial institution's AML risk assessment?