โ† All CCI Flashcard Decks

Cryptocurrency AML and Compliance Flashcards

6 cards from real CCI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Cryptocurrency AML and Compliance flashcards as text
  1. A compliance officer at a US-based cryptocurrency exchange notices a series of incoming transactions for a single customer over a 24-hour period. The transactions are all from different wallets, each just under the $10,000 threshold, and total approximately $45,000. This pattern is MOST indicative of which illicit activity?

    Answer: Structuring

    Structuring, also known as 'smurfing', is the act of breaking up large financial transactions into multiple smaller transactions to avoid triggering currency transaction reporting (CTR) thresholds, which in the U.S. is $10,000. This pattern is a classic red flag for money laundering.

  2. Which international standard requires Virtual Asset Service Providers (VASPs) to obtain, hold, and transmit required originator and beneficiary information for virtual asset transfers?

    Answer: The FATF 'Travel Rule'

    The Financial Action Task Force (FATF) 'Travel Rule' (Recommendation 16) requires VASPs to share specific customer information with recipient institutions during transactions to enhance transparency and mitigate money laundering and terrorist financing. It is analogous to the rules for traditional wire transfers.

  3. A U.S.-based Virtual Asset Service Provider (VASP) is building its AML compliance program. Which of the following is NOT considered one of the core pillars required by the Bank Secrecy Act (BSA)?

    Answer: Mandatory use of specific blockchain analytics software

    The five pillars of a BSA/AML compliance program are: (1) a designated compliance officer, (2) internal policies/controls, (3) ongoing training, (4) independent testing/auditing, and (5) customer due diligence (CDD). While using blockchain analytics software is a best practice and often part of internal controls, no specific software is mandated by the regulation itself.

  4. A user attempts to open an account at a cryptocurrency exchange from an IP address that geolocates to a comprehensively sanctioned jurisdiction. The VASP's compliance systems block the account creation. This action is a direct result of adhering to the requirements set by which U.S. agency?

    Answer: The Office of Foreign Assets Control (OFAC)

    The Office of Foreign Assets Control (OFAC) administers and enforces economic and trade sanctions. All U.S. persons and entities, including VASPs, are prohibited from transacting with individuals, entities, or entire jurisdictions on OFAC's sanctions lists. Using geolocation to block users from sanctioned regions is a key internal control for OFAC compliance.

  5. According to the Financial Action Task Force (FATF), which of the following would be considered a Virtual Asset Service Provider (VASP)?

    Answer: A crypto-to-fiat exchange that facilitates trades on behalf of its customers.

    FATF defines a VASP as any business that conducts activities like exchanging virtual assets for fiat, transferring virtual assets, or providing custody services on behalf of others. A crypto-to-fiat exchange clearly falls under this definition. Users and miners acting on their own behalf are generally not considered VASPs.

  6. A money services business (MSB) in the U.S. detects a series of transactions involving a customer sending funds to wallet addresses associated with a known darknet market. The total value of these transactions is $7,500. What is the MSB's primary reporting obligation in this situation?

    Answer: File a Suspicious Activity Report (SAR) because the transactions are linked to illicit activity.

    Under the Bank Secrecy Act, MSBs must file a Suspicious Activity Report (SAR) for any transaction they know, suspect, or have reason to suspect involves illicit activity and aggregates to at least $2,000. The connection to a darknet market is a clear red flag for suspicious activity, and the amount exceeds the $2,000 threshold for SARs, making this the correct action.