Treasury Enforcement Agent Exam Risk Assessment & Management 3 — Questions and Answers
Question 1: A customer who is a politically exposed person (PEP) opens a new account at a bank. Under risk-based AML principles, the institution should:
- Decline the account automatically as PEPs are prohibited from US banking
- Apply standard due diligence identical to all other customers
- Apply enhanced due diligence and ongoing monitoring (Correct answer)
- Immediately file a SAR upon account opening
Correct answer: Apply enhanced due diligence and ongoing monitoring
PEPs present elevated corruption and bribery risks and therefore require enhanced due diligence (EDD) and continuous monitoring under risk-based AML frameworks.
Question 2: In the context of Treasury enforcement, 'de-risking' by financial institutions refers to:
- Eliminating all speculative investments from portfolios
- Terminating relationships with entire customer categories deemed high-risk (Correct answer)
- Applying advanced encryption to protect customer data
- Reducing the number of cross-border transactions processed
Correct answer: Terminating relationships with entire customer categories deemed high-risk
De-risking is the practice of financial institutions exiting entire customer segments or geographic markets rather than managing the associated risks on a case-by-case basis.
Question 3: Which document established the Bank Secrecy Act (BSA) recordkeeping and reporting requirements that Treasury enforcement agents primarily enforce?
- Gramm-Leach-Bliley Act of 1999
- Currency and Foreign Transactions Reporting Act of 1970 (Correct answer)
- Dodd-Frank Wall Street Reform Act of 2010
- USA PATRIOT Act of 2001
Correct answer: Currency and Foreign Transactions Reporting Act of 1970
The Currency and Foreign Transactions Reporting Act of 1970, commonly known as the Bank Secrecy Act, established the foundational CTR and recordkeeping requirements.
Question 4: A risk assessment reveals that a bank's wire transfer department has no dual-control procedures. This finding represents:
- A strategic risk requiring board-level approval to remediate
- An internal control weakness that increases operational and fraud risk (Correct answer)
- An acceptable gap that can be documented and ignored
- A credit risk requiring additional loan loss reserves
Correct answer: An internal control weakness that increases operational and fraud risk
The absence of dual-control procedures is an internal control weakness that exposes the institution to fraud, errors, and unauthorized transactions.
Question 5: When a Treasury agent identifies a 'high-risk' geographic location, which international body's guidance is most commonly referenced to define such areas?
- World Trade Organization (WTO)
- Financial Action Task Force (FATF) (Correct answer)
- International Monetary Fund (IMF)
- United Nations Security Council (UNSC)
Correct answer: Financial Action Task Force (FATF)
FATF publishes lists of jurisdictions with strategic deficiencies in their AML/CFT regimes, which Treasury enforcement agents use to classify geographic risk.
Question 6: A financial institution fails to file Currency Transaction Reports for two years. Under the BSA, this could result in:
- Only a written warning with no financial penalties
- Civil money penalties and potential criminal prosecution (Correct answer)
- Automatic license revocation with no further proceedings
- Mandatory merger with a compliant institution
Correct answer: Civil money penalties and potential criminal prosecution
Willful or negligent BSA violations can result in substantial civil money penalties and, in egregious cases, criminal prosecution of the institution and responsible individuals.
Question 7: In risk assessment, the term 'residual risk' refers to:
- Risk that existed before any controls were implemented
- Risk remaining after existing controls and mitigations have been applied (Correct answer)
- Risk transferred to a third-party vendor or partner
- Risk identified only after an adverse event has occurred
Correct answer: Risk remaining after existing controls and mitigations have been applied
Residual risk is the level of risk that remains after an organization's controls and mitigation measures have been accounted for.
A customer who is a politically exposed person (PEP) opens a new account at a bank.
Under risk-based AML principles, the institution should: