CCI - Certified Cryptocurrency Investigator Cryptocurrency AML and Compliance Questions and Answers — Questions and Answers
Question 1: A compliance officer at a US-based cryptocurrency exchange notices a series of incoming transactions for a single customer over a 24-hour period. The transactions are all from different wallets, each just under the $10,000 threshold, and total approximately $45,000. This pattern is MOST indicative of which illicit activity?
- Insider trading
- Structuring (Correct answer)
- Market manipulation
- A 51% attack
Correct answer: Structuring
Structuring, also known as 'smurfing', is the act of breaking up large financial transactions into multiple smaller transactions to avoid triggering currency transaction reporting (CTR) thresholds, which in the U.S. is $10,000. This pattern is a classic red flag for money laundering.
Question 2: Which international standard requires Virtual Asset Service Providers (VASPs) to obtain, hold, and transmit required originator and beneficiary information for virtual asset transfers?
- The Bank Secrecy Act (BSA)
- OFAC Sanctions Compliance
- The FATF 'Travel Rule' (Correct answer)
- The FinCEN Customer Due Diligence (CDD) Rule
Correct answer: The FATF 'Travel Rule'
The Financial Action Task Force (FATF) 'Travel Rule' (Recommendation 16) requires VASPs to share specific customer information with recipient institutions during transactions to enhance transparency and mitigate money laundering and terrorist financing. It is analogous to the rules for traditional wire transfers.
Question 3: A U.S.-based Virtual Asset Service Provider (VASP) is building its AML compliance program. Which of the following is NOT considered one of the core pillars required by the Bank Secrecy Act (BSA)?
- A designated BSA Compliance Officer
- Ongoing, relevant employee training
- Independent testing of the AML program
- Mandatory use of specific blockchain analytics software (Correct answer)
Correct answer: Mandatory use of specific blockchain analytics software
The five pillars of a BSA/AML compliance program are: (1) a designated compliance officer, (2) internal policies/controls, (3) ongoing training, (4) independent testing/auditing, and (5) customer due diligence (CDD). While using blockchain analytics software is a best practice and often part of internal controls, no specific software is mandated by the regulation itself.
Question 4: A user attempts to open an account at a cryptocurrency exchange from an IP address that geolocates to a comprehensively sanctioned jurisdiction. The VASP's compliance systems block the account creation. This action is a direct result of adhering to the requirements set by which U.S. agency?
- The Financial Crimes Enforcement Network (FinCEN)
- The Office of Foreign Assets Control (OFAC) (Correct answer)
- The Securities and Exchange Commission (SEC)
- The Commodity Futures Trading Commission (CFTC)
Correct answer: The Office of Foreign Assets Control (OFAC)
The Office of Foreign Assets Control (OFAC) administers and enforces economic and trade sanctions. All U.S. persons and entities, including VASPs, are prohibited from transacting with individuals, entities, or entire jurisdictions on OFAC's sanctions lists. Using geolocation to block users from sanctioned regions is a key internal control for OFAC compliance.
Question 5: According to the Financial Action Task Force (FATF), which of the following would be considered a Virtual Asset Service Provider (VASP)?
- An individual who mines cryptocurrency for their own account.
- A software developer who writes the code for an open-source, non-custodial wallet.
- A crypto-to-fiat exchange that facilitates trades on behalf of its customers. (Correct answer)
- An individual who uses cryptocurrency to purchase goods online.
Correct answer: A crypto-to-fiat exchange that facilitates trades on behalf of its customers.
FATF defines a VASP as any business that conducts activities like exchanging virtual assets for fiat, transferring virtual assets, or providing custody services on behalf of others. A crypto-to-fiat exchange clearly falls under this definition. Users and miners acting on their own behalf are generally not considered VASPs.
Question 6: A money services business (MSB) in the U.S. detects a series of transactions involving a customer sending funds to wallet addresses associated with a known darknet market. The total value of these transactions is $7,500. What is the MSB's primary reporting obligation in this situation?
- File a Currency Transaction Report (CTR) because the activity is criminal.
- File a Suspicious Activity Report (SAR) because the transactions are linked to illicit activity. (Correct answer)
- No report is needed because the amount is below the $10,000 CTR threshold.
- Report the activity directly to the Federal Bureau of Investigation (FBI).
Correct answer: File a Suspicious Activity Report (SAR) because the transactions are linked to illicit activity.
Under the Bank Secrecy Act, MSBs must file a Suspicious Activity Report (SAR) for any transaction they know, suspect, or have reason to suspect involves illicit activity and aggregates to at least $2,000. The connection to a darknet market is a clear red flag for suspicious activity, and the amount exceeds the $2,000 threshold for SARs, making this the correct action.
A compliance officer at a US-based cryptocurrency exchange notices a series of incoming transactions for a single customer over a 24-hour period.
The transactions are all from different wallets, each just under the $10,000 threshold, and total approximately $45,000.
This pattern is MOST indicative of which illicit activity?