ACAMS AML/CFT Risk Assessment 2 — Questions and Answers
Question 1: In the FATF risk-based approach, what are the three primary risk categories that institutions must assess?
- Credit risk, market risk, and operational risk
- Country/geographic risk, customer risk, and product/service/transaction risk (Correct answer)
- Regulatory risk, reputational risk, and legal risk
- Inherent risk, residual risk, and control risk
Correct answer: Country/geographic risk, customer risk, and product/service/transaction risk
The FATF risk-based approach requires financial institutions to assess three primary AML risk categories: country/geographic risk (jurisdictions with higher ML/TF risk), customer risk (types of customers and their risk profiles), and product/service/transaction risk (financial services that may be more vulnerable to abuse).
Under the FATF risk-based approach (RBA): Country/geographic risk considers FATF blacklist/greylist status, corruption indices, narcotics production, and weak AML regimes; Customer risk considers PEPs, high-risk industries, complex ownership structures, and prior suspicious activity; Product/service risk considers cash-intensive services, correspondent banking, private banking, trade finance, and new technologies. Institutions calculate inherent risk in each category, apply control effectiveness ratings, and arrive at residual risk levels that determine the intensity of AML controls.
Question 2: Which document provides the most authoritative assessment of a country's AML/CFT regime for use in geographic risk assessments?
- The World Bank Doing Business report
- FATF Mutual Evaluation Reports (MERs) (Correct answer)
- The Transparency International Corruption Perceptions Index
- The CIA World Factbook
Correct answer: FATF Mutual Evaluation Reports (MERs)
FATF Mutual Evaluation Reports provide the most comprehensive, authoritative assessment of a country's AML/CFT legal framework, institutional effectiveness, and compliance with FATF standards.
FATF Mutual Evaluation Reports (MERs) assess countries on two dimensions: (1) Technical compliance — whether laws and regulations meet FATF Recommendations; (2) Effectiveness — whether the system actually works. Each country receives ratings (Compliant, Largely Compliant, Partially Compliant, Non-Compliant) for 40 Recommendations, and effectiveness ratings (High, Substantial, Moderate, Low) for 11 Immediate Outcomes. Institutions use MERs alongside FATF's high-risk and monitored jurisdictions list, Basel AML Index, Transparency International CPI, and INCSR (State Department narcotics reports) for geographic risk scoring.
Question 3: What is 'residual risk' in the context of an AML risk assessment?
- The risk that remains after applying AML controls (Correct answer)
- The risk before any mitigating controls are applied
- The risk associated with residual cash in ATMs
- The aggregate risk across all business lines
Correct answer: The risk that remains after applying AML controls
Residual risk is the level of risk that remains after the institution's AML controls and mitigating measures have been applied to the inherent risk. It represents the actual exposure the institution faces.
In AML risk assessment: Inherent risk = the risk before any controls are applied, based on the institution's business model, customers, products, and geographies; Control effectiveness = how well the institution's AML program mitigates those risks; Residual risk = inherent risk adjusted for control effectiveness. If inherent risk is high but controls are strong, residual risk may be medium. Institutions must ensure residual risk is within their risk appetite. Regulators review risk assessments to verify that inherent risk identification is comprehensive, control ratings are realistic, and residual risk is appropriately managed.
Question 4: Which of the following customer types typically carries the HIGHEST inherent AML risk?
- A salaried government employee opening a savings account
- A domestic retail customer with direct deposit payroll
- A non-resident alien operating a cash-intensive business with no explained source of wealth (Correct answer)
- A publicly traded company with audited financials
Correct answer: A non-resident alien operating a cash-intensive business with no explained source of wealth
Non-resident aliens operating cash-intensive businesses with unexplained wealth combine multiple high-risk indicators: foreign status, cash-intensive industry, and lack of transparent financial history — all of which elevate inherent AML risk significantly.
High-risk customer factors include: PEP status or close associates of PEPs; high-risk jurisdictions (FATF blacklist/greylist countries); cash-intensive businesses (convenience stores, car washes, restaurants); non-resident aliens or foreign nationals; complex ownership structures or beneficial ownership opacity; prior suspicious activity or SAR history; unexplained wealth or lifestyle inconsistent with known income; businesses with no clear economic purpose; and legal professionals with client fund accounts. When multiple risk factors are present, the combined risk profile escalates significantly and requires enhanced due diligence.
Question 5: In a risk-based approach, when is Enhanced Due Diligence (EDD) required?
- For every new customer regardless of risk
- For customers identified as high-risk, such as PEPs, correspondent banks, or those from high-risk jurisdictions (Correct answer)
- Only when a SAR has previously been filed on the account
- Whenever a customer's transaction exceeds $5,000
Correct answer: For customers identified as high-risk, such as PEPs, correspondent banks, or those from high-risk jurisdictions
EDD is required for high-risk customers identified through the risk assessment process, including politically exposed persons, correspondent banking relationships, customers from high-risk jurisdictions, and others presenting elevated money laundering risk.
Under the BSA/AML framework and FATF standards, EDD measures must be applied when standard CDD is insufficient given the customer's risk profile. EDD typically includes: obtaining additional information about the customer's source of funds and wealth; more frequent account reviews; senior management approval for the relationship; enhanced transaction monitoring with lower alert thresholds; obtaining beneficial ownership information beyond standard requirements; and ongoing media and adverse news searches. Mandatory EDD applies to: PEPs and their close associates; correspondent banking relationships; private banking customers; and customers from FATF-listed high-risk jurisdictions.
Question 6: What is the purpose of a 'risk appetite statement' in an institution's AML program?
- To document the types of food vendors approved for staff cafeterias
- To define the level and type of AML/CFT risk the institution is willing to accept in pursuing its business objectives (Correct answer)
- To set minimum transaction monitoring thresholds for all accounts
- To establish the budget allocated to the compliance department
Correct answer: To define the level and type of AML/CFT risk the institution is willing to accept in pursuing its business objectives
A risk appetite statement defines the boundaries of acceptable AML/CFT risk for the institution, guiding decisions about which customers, products, and geographies are within acceptable risk tolerance.
A risk appetite statement in AML context: defines the types and levels of ML/TF risk the institution will accept; provides guidance for front-line staff and compliance on acceptable vs. unacceptable business; aligns with the institution's overall enterprise risk management framework; is approved by the board and senior management; is distinct from the risk assessment (which measures current risk levels) as it sets the desired risk level; and informs customer onboarding decisions, product design, and market entry. Institutions operating outside their stated risk appetite must either strengthen controls or exit the business activity.
In the FATF risk-based approach, what are the three primary risk categories that institutions must assess?