CCA Anti-Money Laundering & Financial Crime in Crypto 2 โ Questions and Answers
Question 1: Which red flag is most indicative of potential structuring (smurfing) activity on a cryptocurrency exchange?
- Multiple deposits just below the $10,000 CTR threshold from the same customer across consecutive days (Correct answer)
- A single large deposit of $50,000 from a verified high-net-worth customer
- Frequent small purchases of fractional Bitcoin amounts by a retail customer
- Withdrawal of all funds after a single profitable trade
Correct answer: Multiple deposits just below the $10,000 CTR threshold from the same customer across consecutive days
Multiple deposits just below the CTR threshold from the same customer is the textbook definition of structuring, which is illegal under 31 U.S.C. ยง 5324 regardless of whether the underlying funds are licit.
Question 2: A blockchain analytics tool assigns a cryptocurrency transaction a 'risk score' of 85/100 based on exposure to darknet markets. What is the appropriate auditor response when reviewing a VASP's transaction monitoring program?
- Verify that the VASP has a documented procedure for investigating high-risk-scored transactions and filing SARs when appropriate (Correct answer)
- Immediately conclude the transaction is fraudulent and recommend account closure
- Note that the score alone proves a SAR filing was required
- Disregard the score as insufficient evidence without additional documentation
Correct answer: Verify that the VASP has a documented procedure for investigating high-risk-scored transactions and filing SARs when appropriate
A high risk score triggers a review obligation โ the auditor should verify the VASP has documented investigation procedures and appropriate SAR filing protocols, as the score is a flag requiring human investigation, not automatic proof of wrongdoing.
Question 3: Under FinCEN guidance, cryptocurrency exchanges operating as MSBs must retain records of customer identity verification for a minimum of how many years?
- 5 years (Correct answer)
- 3 years
- 7 years
- 10 years
Correct answer: 5 years
The BSA requires MSBs, including cryptocurrency exchanges, to retain customer identification records, transaction records, and SARs for a minimum of 5 years from the date the record was created.
Question 4: Privacy coins like Monero use which technology to make transaction tracing significantly more difficult than standard Bitcoin transactions?
- Ring signatures, stealth addresses, and RingCT that obscure sender, receiver, and amount simultaneously (Correct answer)
- Zero-knowledge proofs for all on-chain data
- Proof-of-stake consensus eliminating miner traceability
- Layer-2 off-chain transaction routing
Correct answer: Ring signatures, stealth addresses, and RingCT that obscure sender, receiver, and amount simultaneously
Monero combines ring signatures (obscuring the true sender), stealth addresses (one-time recipient addresses), and RingCT (hiding transaction amounts), making all three transaction elements โ who, to whom, and how much โ opaque by default.
Question 5: What is the primary AML concern with peer-to-peer (P2P) cryptocurrency trading platforms that operate without KYC requirements?
- They can be used to exchange illicit cryptocurrency for cash without identity verification, effectively acting as unregistered money transmitters (Correct answer)
- They are technically illegal under all U.S. state laws
- P2P platforms cannot handle large transaction volumes
- They are only used for tax evasion, not money laundering
Correct answer: They can be used to exchange illicit cryptocurrency for cash without identity verification, effectively acting as unregistered money transmitters
KYC-free P2P platforms allow users to convert illicit cryptocurrency to cash with no identity records created, functioning as unregistered money transmission services and providing a critical off-ramp for money launderers.
Question 6: A CCA auditor is reviewing a crypto exchange's Customer Due Diligence (CDD) program. Which customer type should trigger Enhanced Due Diligence (EDD) procedures?
- A politically exposed person (PEP) depositing $500,000 in cryptocurrency (Correct answer)
- A retail customer making their first $500 purchase
- A corporate customer in the technology sector making regular monthly purchases
- Any customer who uses a hardware wallet for withdrawals
Correct answer: A politically exposed person (PEP) depositing $500,000 in cryptocurrency
Politically exposed persons carry elevated corruption and bribery risk due to their position or connections, requiring EDD regardless of transaction size โ FinCEN's CDD rule explicitly highlights PEPs as higher-risk customers.
Which red flag is most indicative of potential structuring (smurfing) activity on a cryptocurrency exchange?