ACAMS - Association of Certified Anti-Money Laundering Specialists AML/CFT Risk Assessment Questions and Answers 1 — Questions and Answers
Question 1: According to best practices, an enterprise-wide AML/CFT risk assessment should, at a minimum, consider which of the following core risk categories?
- Employee Training, Independent Audit, and Senior Management Oversight.
- Data Security, Business Continuity, and Fraud Prevention.
- Customers, Products/Services, Geographies, and Delivery Channels. (Correct answer)
- Transaction Monitoring Scenarios, SAR Filing Quality, and Law Enforcement Cooperation.
Correct answer: Customers, Products/Services, Geographies, and Delivery Channels.
An effective AML/CFT risk assessment is built upon evaluating the specific risks posed by the institution's customers, the products and services it offers, the geographic locations it operates in or serves, and the channels through which it delivers its products. The other options list important components of an overall AML program or broader operational risks, but not the core categories of the risk assessment itself.
Question 2: A credit union has traditionally served only local individual members. It plans to launch a new online platform to offer business accounts to international import/export companies. From a risk assessment perspective, what is the MOST significant change the credit union must address?
- The need to update employee training on the new platform's user interface.
- The introduction of new, higher-risk customer types and geographic exposures. (Correct answer)
- The marketing budget required to attract the new business clients.
- The increase in transaction volume and server capacity requirements.
Correct answer: The introduction of new, higher-risk customer types and geographic exposures.
The primary change is the fundamental shift in the risk profile. The credit union is moving from a low-risk, domestic, individual customer base to a high-risk base involving international trade, corporate structures which can obscure ownership, and cross-border transactions. This introduces significantly higher inherent risks related to customer type and geography that must be assessed and mitigated.
Question 3: Which of the following best describes the primary objective of an AML/CFT risk assessment?
- To eliminate all potential exposure to money laundering and terrorist financing.
- To create a definitive list of high-risk customers for account closure.
- To enable the institution to understand its risk profile and apply appropriate mitigating controls. (Correct answer)
- To satisfy regulators by completing a mandatory annual exercise.
Correct answer: To enable the institution to understand its risk profile and apply appropriate mitigating controls.
The core purpose of a risk assessment is to identify and understand the specific ML/TF risks an institution faces so it can implement a tailored, risk-based AML/CFT program. The goal is not to eliminate risk entirely, which is impossible, but to manage it effectively by applying controls proportionate to the identified risks.
Question 4: In the context of an AML/CFT risk assessment, 'residual risk' is best defined as:
- The total level of risk present before any controls are considered.
- The specific risk associated with politically exposed persons (PEPs).
- The risk of regulatory fines for non-compliance with AML laws.
- The risk that remains after mitigating controls have been implemented. (Correct answer)
Correct answer: The risk that remains after mitigating controls have been implemented.
The risk assessment process first identifies 'inherent risk' (the risk before controls). Then, the effectiveness of the institution's internal controls is evaluated. The risk that remains after these controls are applied is the 'residual risk.' This is the institution's actual ongoing risk exposure that management must accept or mitigate further.
Question 5: A bank's risk assessment identifies its private banking division as having the highest inherent AML risk. Which action is the most direct and appropriate response to this finding?
- Immediately closing all private banking accounts from high-risk jurisdictions.
- Lowering the transaction monitoring thresholds for the retail banking division.
- Implementing a standardized, uniform due diligence process for all bank customers.
- Allocating resources for enhanced due diligence (EDD) and specialized training for private banking staff. (Correct answer)
Correct answer: Allocating resources for enhanced due diligence (EDD) and specialized training for private banking staff.
The risk-based approach dictates that controls should be proportionate to the risks identified. Since the private banking division is identified as high-risk, the appropriate response is to apply stronger, more targeted controls, such as EDD and specialized training, to that specific area. The other options are either too extreme (de-risking), irrelevant, or contrary to the risk-based approach.
Question 6: When conducting a periodic AML/CFT risk assessment, a financial institution should always ensure that the methodology and findings are:
- Kept confidential from the board of directors to avoid undue alarm.
- Static and unchanged from year to year to ensure consistency.
- Based solely on publicly available information from sources like the FATF.
- Formally documented, approved by senior management, and used to inform the AML program. (Correct answer)
Correct answer: Formally documented, approved by senior management, and used to inform the AML program.
A risk assessment is a critical governance tool. For it to be effective, its methodology, data, analysis, and conclusions must be thoroughly documented. It requires approval from senior management and/or the board to ensure accountability, and its findings must be used to make tangible updates to the institution's AML/CFT policies, procedures, and controls.
According to best practices, an enterprise-wide AML/CFT risk assessment should, at a minimum, consider which of the following core risk categories?