ACAMS CAMS Certification Exam β Questions and Answers
Question 1: What should an effective AML training program include to meet regulatory expectations?
- Risk-based training tailored to employees' roles and responsibilities, covering relevant AML regulations, red flags specific to their business line, SAR filing obligations, and training on current typologies and schemes (Correct answer)
- AML training only for employees in the compliance department
- Training only for new hires during their onboarding process
- A single annual training module covering all BSA topics for all employees
Correct answer: Risk-based training tailored to employees' roles and responsibilities, covering relevant AML regulations, red flags specific to their business line, SAR filing obligations, and training on current typologies and schemes
Effective AML training must be risk-based and role-specific β front-line tellers receive different training than private bankers or trade finance officers β and must be regularly updated to cover current typologies, schemes, and regulatory developments.
Question 2: What is the difference between a 'voluntary SAR' and a 'mandatory SAR'?
- All SAR filings by covered financial institutions are mandatory when the filing threshold is met; 'voluntary' SARs refer to filings below the mandatory threshold or by non-covered entities filing on a discretionary basis (Correct answer)
- Voluntary SARs are filed with FinCEN; mandatory SARs are filed with the relevant bank regulator
- Voluntary SARs are filed at the institution's discretion for any suspicious activity; mandatory SARs are required only for transactions over $10,000
- Mandatory SARs require law enforcement approval; voluntary SARs can be filed without review
Correct answer: All SAR filings by covered financial institutions are mandatory when the filing threshold is met; 'voluntary' SARs refer to filings below the mandatory threshold or by non-covered entities filing on a discretionary basis
Covered financial institutions are required to file SARs when the mandatory filing threshold and criteria are met. 'Voluntary' SARs are filed at an institution's discretion β either below the mandatory dollar threshold or by entities not legally required to file β as a good-faith disclosure of suspicious activity.
Question 3: What are FATF 'Immediate Outcomes' in its evaluation methodology and how many are there?
- FATF has 40 Immediate Outcomes corresponding to each of the 40 Recommendations
- FATF has 11 Immediate Outcomes measuring whether a country's AML/CFT system is actually effective at achieving specific real-world results, such as adequate risk understanding, FIU effectiveness, and ML prosecution rates (Correct answer)
- FATF has 15 Immediate Outcomes measuring whether AML regulations are technically compliant
- FATF has 7 Immediate Outcomes focused only on financial sector regulation and supervision
Correct answer: FATF has 11 Immediate Outcomes measuring whether a country's AML/CFT system is actually effective at achieving specific real-world results, such as adequate risk understanding, FIU effectiveness, and ML prosecution rates
FATF's 2013 evaluation methodology includes 11 Immediate Outcomes that assess whether the AML/CFT system produces real-world effectiveness results β moving beyond technical compliance to measure whether the system actually works.
Question 4: What is the purpose of an 'exit interview' when closing an account due to suspicious activity?
- There should be no exit interview β institutions should close the account without indicating that suspicious activity concerns are the reason, to avoid tipping off the customer (Correct answer)
- To negotiate repayment of any outstanding loan balances
- To warn the customer that a SAR has been filed so they can seek legal counsel
- To provide the customer with documentation of all transactions flagged as suspicious
Correct answer: There should be no exit interview β institutions should close the account without indicating that suspicious activity concerns are the reason, to avoid tipping off the customer
Institutions closing accounts due to suspicious activity must not reveal that AML concerns are the reason, as this would constitute tipping off under 31 USC 5318(g)(2). Account closures are typically handled without detailed explanation to avoid alerting the subject.
Question 5: A key component of a robust AML program is having a system of internal controls. This system should be designed to:
- Guarantee that no money laundering will ever occur at the institution.
- Provide daily reports to the board of directors on all customer transactions.
- Ensure the institution's profitability by minimizing compliance-related costs.
- Mitigate and manage the institution's identified ML/TF risks through policies, procedures, and processes. (Correct answer)
Correct answer: Mitigate and manage the institution's identified ML/TF risks through policies, procedures, and processes.
Internal controls are the policies, procedures, and systems put in place to mitigate the specific money laundering and terrorist financing (ML/TF) risks identified by the institution. This includes customer due diligence (CDD), transaction monitoring, and reporting requirements. The goal is to manage risk, not necessarily to guarantee its complete elimination.
Question 6: What is the Financial Action Task Force's (FATF) mandate and membership structure?
- FATF is an intergovernmental policy-making body established in 1989 with 39 members (37 member jurisdictions plus the European Commission and Gulf Co-operation Council) that sets AML/CFT standards and assesses compliance (Correct answer)
- FATF is a UN agency with 193 member countries that issues binding resolutions
- FATF is an NGO funded by private banks to develop voluntary AML best practices
- FATF is a World Bank initiative that provides technical assistance to developing countries on AML compliance
Correct answer: FATF is an intergovernmental policy-making body established in 1989 with 39 members (37 member jurisdictions plus the European Commission and Gulf Co-operation Council) that sets AML/CFT standards and assesses compliance
FATF is an intergovernmental body established at the G7 Paris Summit in 1989. It has 39 members (37 jurisdictions plus the European Commission and GCC) and sets global AML/CFT standards through its 40 Recommendations.
Question 7: A financial institution's risk assessment identifies that it facilitates a high volume of international trade finance for a variety of goods. Which money laundering method should be of PRIMARY concern when developing risk mitigation strategies for this line of business?
- Misuse of correspondent banking relationships.
- Trade-Based Money Laundering (TBML). (Correct answer)
- Structuring cash deposits below reporting thresholds.
- Smurfing through multiple third-party accounts.
Correct answer: Trade-Based Money Laundering (TBML).
Trade-Based Money Laundering (TBML) is a method of disguising criminal proceeds through the use of trade transactions. Given that the institution is heavily involved in international trade finance, it is directly exposed to risks such as over- and under-invoicing of goods, phantom shipments, and other schemes used to move value and legitimize illicit funds. While other methods are possible, TBML is the most direct and significant risk associated with this specific business activity.
Question 8: What is 'round-tripping' in the context of TBML?
- A customs process for inspecting returned goods
- Issuing multiple invoices for one shipment
- Sending funds overseas and repatriating them as foreign investment or trade proceeds (Correct answer)
- Shipping goods from a country and returning them to the same country as different goods
Correct answer: Sending funds overseas and repatriating them as foreign investment or trade proceeds
Round-tripping involves moving money out of a country and bringing it back disguised as legitimate foreign investment or export proceeds to give illicit funds a lawful appearance.
Question 9: Under FinCEN's Customer Due Diligence Rule (31 CFR 1010.230), what are the four core elements of CDD?
- Customer identification, beneficial ownership identification, understanding the customer's business, and ongoing monitoring (Correct answer)
- Identification, verification, monitoring, and reporting
- Account opening, transaction approval, risk scoring, and annual review
- KYC, EDD, SAR filing, and CTR filing
Correct answer: Customer identification, beneficial ownership identification, understanding the customer's business, and ongoing monitoring
FinCEN's 2016 CDD Rule established four core elements: (1) identifying and verifying the customer's identity; (2) identifying and verifying beneficial owners of legal entity customers; (3) understanding the nature and purpose of the relationship; and (4) conducting ongoing monitoring and updating customer information.
Question 10: What role does 'adverse media screening' play in an AML investigation?
- It is used to identify positive press coverage about customers
- It searches news databases and other public sources for negative information about a customer that may indicate financial crime, corruption, or sanctions exposure (Correct answer)
- It screens marketing materials for compliance with advertising regulations
- It monitors social media for customer complaints about banking services
Correct answer: It searches news databases and other public sources for negative information about a customer that may indicate financial crime, corruption, or sanctions exposure
Adverse media screening (also called negative news screening) searches public sources β news articles, court records, regulatory actions β for information that might indicate a customer poses elevated AML, sanctions, or reputational risk.
Question 11: Which insurance product is most prone to money laundering?
- Regulated pension
- Annuity (Correct answer)
- Casualty
- Collateral
Correct answer: Annuity
Annuities are highly susceptible to money laundering due to their ability to convert large lump-sum payments into legitimate-looking income streams or to be surrendered for cash value. Their complex structure and long-term nature can obscure the true source of funds, making them an attractive vehicle for criminals to clean illicit proceeds.
Question 12: What is the primary AML risk concern when onboarding a PEP as a customer?
- Greater likelihood of tax evasion
- Currency exchange rate exposure
- Elevated risk of bribery, corruption proceeds, or abuse of public office being laundered through the institution (Correct answer)
- Reputational risk from media attention only
Correct answer: Elevated risk of bribery, corruption proceeds, or abuse of public office being laundered through the institution
PEPs pose elevated AML risk because their public positions may give them access to state funds or opportunities for bribery and corruption, making them potential conduits for laundering illicit proceeds.
Question 13: What are the key components of a well-documented SAR investigation file?
- Documentation of the alert trigger, research conducted (internal and external), timeline of suspicious activity, analysis of the activity, the filing decision rationale, and records of any law enforcement communications (Correct answer)
- Only the SAR filing confirmation number and the compliance officer's signature
- Customer identity documents only, with a brief notation that suspicious activity occurred
- Only the transaction data that triggered the alert and the SAR filing date
Correct answer: Documentation of the alert trigger, research conducted (internal and external), timeline of suspicious activity, analysis of the activity, the filing decision rationale, and records of any law enforcement communications
A complete SAR investigation file must document the entire investigation lifecycle: the triggering event, all research steps, the analytical findings, the SAR filing decision rationale, and all communications with law enforcement β providing a clear, defensible record.
Question 14: How should financial institutions handle CDD for customers who claim to be acting on behalf of an undisclosed principal?
- Refuse all such customers without exception as they pose automatic ML risk
- Require the undisclosed principal to appear in person before any account activity
- Accept the claim and proceed with only the agent's identification
- Treat this as a significant red flag, attempt to identify and verify the undisclosed principal, and consider whether to file a SAR if the principal cannot be identified (Correct answer)
Correct answer: Treat this as a significant red flag, attempt to identify and verify the undisclosed principal, and consider whether to file a SAR if the principal cannot be identified
Customers acting for undisclosed principals raise significant AML concerns because the true beneficial owner is hidden. Institutions should attempt to identify the principal, treat the opacity as a high-risk indicator, and consider whether suspicious activity reporting is warranted.
Question 15: What specific information should be included in a SAR narrative to maximize its utility to law enforcement?
- The account holder's credit score and employment history
- Only the account number, transaction dates, and total suspicious dollar amount
- The full context of the suspicious activity including who, what, when, where, why it is suspicious, how the scheme operates, all involved parties and accounts, prior SAR history, and any law enforcement contacts or legal process received (Correct answer)
- A brief description of the activity and a reference to the transaction monitoring scenario that triggered the alert
Correct answer: The full context of the suspicious activity including who, what, when, where, why it is suspicious, how the scheme operates, all involved parties and accounts, prior SAR history, and any law enforcement contacts or legal process received
An effective SAR narrative answers the five W's plus how: who is involved (all parties and entities), what activity occurred (specific transactions), when (dates and timeline), where (accounts, locations), why it is suspicious (specific reasons), and how the scheme works β providing law enforcement with a complete, actionable intelligence report.
Question 16: What is 'chain hopping' in the context of cryptocurrency money laundering?
- Using multiple custodial wallets at the same VASP
- Repeatedly buying and selling the same cryptocurrency on one exchange
- Converting funds from one blockchain network to another to obscure the audit trail (Correct answer)
- Splitting a large cryptocurrency transaction into smaller ones on the same chain
Correct answer: Converting funds from one blockchain network to another to obscure the audit trail
Chain hopping involves converting cryptocurrency from one blockchain (e.g., Bitcoin) to another (e.g., Monero) to exploit gaps in cross-chain transaction monitoring and disrupt the investigative trail.
Question 17: Which AML risk factor is most associated with professional money laundering networks (PMLNs)?
- Reliance on a single jurisdiction for all transactions
- Conducting only small-value transactions
- Use of gatekeepers such as lawyers, accountants, and company formation agents (Correct answer)
- Exclusively using regulated financial institutions
Correct answer: Use of gatekeepers such as lawyers, accountants, and company formation agents
Professional money laundering networks frequently exploit gatekeepers β professionals such as lawyers, accountants, and corporate service providers β who can create complex corporate structures and move funds while providing a veneer of legitimacy.
Question 18: During an AML investigation, a relationship manager receives an inquiry from a customer asking why a recent transaction is being delayed. Which of the following responses by the relationship manager would most likely be considered illegal 'tipping off'?
- "There appears to be a standard processing delay in the payment system; we will notify you when it is complete."
- "Your transaction has been flagged by our AML system, and we must investigate it before deciding whether to report it to the authorities." (Correct answer)
- "We are conducting a routine compliance review as required for certain transactions."
- "To complete our processing, could you please provide the invoice related to this transaction?"
Correct answer: "Your transaction has been flagged by our AML system, and we must investigate it before deciding whether to report it to the authorities."
Tipping off is the act of informing a person who is the subject of a suspicious activity report (or is under investigation) in a way that could prejudice the investigation. Stating explicitly that the transaction was flagged by the AML system and that a report to authorities is being considered directly reveals the suspicion and the potential for law enforcement involvement. The other options provide plausible, non-alarming business reasons for a delay or a request for information.
Question 19: Which approach does FATF recommend for applying beneficial ownership and PEP controls?
- A standardized rule-based approach applying identical controls to all customers
- A zero-tolerance policy treating all customers as high risk
- A risk-based approach, applying enhanced measures proportional to the level of assessed risk (Correct answer)
- A tiered fee-based approach where higher-risk customers pay more for due diligence
Correct answer: A risk-based approach, applying enhanced measures proportional to the level of assessed risk
FATF's core principle is the risk-based approach: institutions should apply enhanced measures to higher-risk customers and relationships (including PEPs and complex ownership structures) proportionate to assessed risk.
Question 20: A compliance officer at a bank is reviewing a new corporate account application for 'ABC Trading Ltd.' The company lists a registered agent's address, has nominee directors, and its stated business purpose is 'general international trade.' Financial projections show anticipated high-volume wire transfers to and from various offshore jurisdictions with no clear business rationale. These characteristics are strong indicators of a potential:
- Shelf company.
- Front company.
- Subsidiary company.
- Shell company. (Correct answer)
Correct answer: Shell company.
A shell company is a legal entity that exists only on paper and has no significant assets or active operations. Key red flags include the use of a registered agent's address instead of a physical business location, nominee directors to obscure true ownership, a vague business purpose, and complex, high-volume international transactions without a clear economic reason. These are classic methods used to obscure ownership and move illicit funds.
Question 21: A bank's risk assessment identifies its private banking division as having the highest inherent AML risk. Which action is the most direct and appropriate response to this finding?
- Immediately closing all private banking accounts from high-risk jurisdictions.
- Implementing a standardized, uniform due diligence process for all bank customers.
- Lowering the transaction monitoring thresholds for the retail banking division.
- Allocating resources for enhanced due diligence (EDD) and specialized training for private banking staff. (Correct answer)
Correct answer: Allocating resources for enhanced due diligence (EDD) and specialized training for private banking staff.
The risk-based approach dictates that controls should be proportionate to the risks identified. Since the private banking division is identified as high-risk, the appropriate response is to apply stronger, more targeted controls, such as EDD and specialized training, to that specific area. The other options are either too extreme (de-risking), irrelevant, or contrary to the risk-based approach.
Question 22: What is the primary purpose of a 'shell company' in money laundering schemes?
- To enable legal tax avoidance strategies
- To provide employment for money launderers
- To facilitate legitimate cross-border trade
- To conceal the true beneficial owner of assets and transactions (Correct answer)
Correct answer: To conceal the true beneficial owner of assets and transactions
Shell companies β legal entities with no active business operations β are used primarily to obscure beneficial ownership, making it difficult for authorities to trace assets back to criminals.
Question 23: What is a 'look-back review' in the AML context and when is it typically required?
- A review of competitor AML programs to benchmark the institution's own controls
- An annual review of all SAR filings to assess quality and consistency
- A periodic review of customer accounts scheduled on a risk-based calendar
- A retrospective review of transactions and accounts covering a past period, typically triggered by discovery of a significant control failure or regulatory requirement to identify previously missed suspicious activity (Correct answer)
Correct answer: A retrospective review of transactions and accounts covering a past period, typically triggered by discovery of a significant control failure or regulatory requirement to identify previously missed suspicious activity
A look-back review involves retroactively examining transactions and accounts for a specified historical period to identify suspicious activity that should have been detected and reported under a functioning AML program, typically ordered following discovery of a serious control failure.
Question 24: A US bank notices a customer is receiving multiple payments from different overseas buyers for the same shipment of electronics. This is most indicative of which TBML red flag?
- Multiple invoicing (Correct answer)
- Round-tripping
- Black market peso exchange
- Phantom shipment
Correct answer: Multiple invoicing
Multiple invoicing involves issuing more than one invoice for a single shipment, enabling the seller to collect payment multiple times for the same goods.
Question 25: What is the significance of the 'tipping off' prohibition in AML regulations?
- It prohibits financial institutions from sharing customer data with tax authorities
- It prevents institutions from disclosing to subjects that a SAR has been or may be filed against them (Correct answer)
- It restricts law enforcement from informing suspects of ongoing investigations
- It bars employees from reporting suspicious activity to the media
Correct answer: It prevents institutions from disclosing to subjects that a SAR has been or may be filed against them
The tipping off prohibition makes it illegal to inform a customer or suspect that they are the subject of a SAR filing or related investigation.
Question 26: What is a 'voluntary self-disclosure' to OFAC and why might an institution choose to make one?
- A required annual certification of sanctions compliance
- A disclosure to FinCEN that the institution has identified a potential sanctions hit
- A proactive disclosure to OFAC by an institution that discovers it may have violated sanctions regulations, before OFAC initiates an enforcement action, which can significantly reduce civil penalties (Correct answer)
- A customer disclosure form required before processing international wires
Correct answer: A proactive disclosure to OFAC by an institution that discovers it may have violated sanctions regulations, before OFAC initiates an enforcement action, which can significantly reduce civil penalties
Voluntary self-disclosure to OFAC is a proactive step an institution takes when it discovers a potential sanctions violation. OFAC treats VSD as a significant mitigating factor and typically reduces civil penalties by 50% for fully cooperative self-disclosures.
Question 27: For PEP relationships, FATF Recommendation 12 requires which specific additional measure beyond standard CDD?
- Limiting PEP accounts to domestic transactions only
- Senior management approval for establishing or continuing the business relationship (Correct answer)
- Obtaining government approval to maintain the account
- Reporting all PEP transactions to financial intelligence units
Correct answer: Senior management approval for establishing or continuing the business relationship
FATF Recommendation 12 requires senior management approval for establishing or continuing business relationships with PEPs, in addition to enhanced due diligence measures.
Question 28: A compliance officer at a US bank finds that a trade client is conducting frequent low-value shipments that collectively equal large totals with no clear business rationale. This pattern most likely suggests:
- Normal import/export activity
- A legitimate high-volume retail business
- Structuring through trade transactions (Correct answer)
- A commodity price hedging strategy
Correct answer: Structuring through trade transactions
Breaking large trade transactions into multiple smaller ones to avoid detection thresholds is a form of structuring applied to TBML schemes.
Question 29: Which term describes the use of multiple financial institutions or accounts to conceal the source of illicit funds?
- Micro-structuring
- Currency arbitrage
- Cuckoo smurfing (Correct answer)
- Bulk cash smuggling
Correct answer: Cuckoo smurfing
Cuckoo smurfing is a technique where criminal proceeds are substituted for legitimate funds in cross-border transactions, so the money launderer's funds reach their destination while the legitimate customer's account appears to receive a normal transfer.
Question 30: What is the 'Vienna Convention' (1988 UN Convention Against Illicit Traffic in Narcotic Drugs) and why is it foundational to international AML law?
- A bilateral treaty between the U.S. and EU establishing mutual legal assistance in AML matters
- A UN convention establishing the FIU network and mandatory STR filing requirements
- The first international treaty requiring all countries to adopt AML regulations for all financial crimes
- The first major international treaty requiring countries to criminalize drug money laundering and establish mechanisms for asset confiscation, laying the foundation for global AML cooperation (Correct answer)
Correct answer: The first major international treaty requiring countries to criminalize drug money laundering and establish mechanisms for asset confiscation, laying the foundation for global AML cooperation
The 1988 Vienna Convention was the first major international instrument requiring signatory states to criminalize drug-related money laundering and establish asset confiscation frameworks β establishing the conceptual and legal foundation for the global AML system that followed.
Question 31: The FinCEN 314(a) program allows which of the following?
- Banks to share customer data with credit bureaus without consent
- Institutions to file joint SARs for shared customers
- Regulators to access real-time transaction data from all banks
- Law enforcement to request financial institutions to search records for named subjects (Correct answer)
Correct answer: Law enforcement to request financial institutions to search records for named subjects
Section 314(a) of the USA PATRIOT Act permits law enforcement to send requests to FinCEN, which then notifies financial institutions to search their records.
Question 32: What is the difference between 'primary sanctions' and 'secondary sanctions' in the U.S. sanctions framework?
- Primary sanctions apply to U.S. persons and transactions in U.S. jurisdiction; secondary sanctions target non-U.S. persons conducting significant transactions with sanctioned parties even without U.S. nexus (Correct answer)
- Primary sanctions apply to criminal violations; secondary sanctions apply to civil violations
- Primary sanctions require congressional approval; secondary sanctions can be imposed by executive order
- Primary sanctions are imposed by the UN Security Council; secondary sanctions are unilateral U.S. measures
Correct answer: Primary sanctions apply to U.S. persons and transactions in U.S. jurisdiction; secondary sanctions target non-U.S. persons conducting significant transactions with sanctioned parties even without U.S. nexus
Primary sanctions prohibit U.S. persons and U.S.-nexus transactions from dealing with sanctioned parties. Secondary sanctions target non-U.S. persons who conduct significant business with sanctioned countries or entities, threatening them with exclusion from the U.S. financial system.
Question 33: What enhanced due diligence measures are specifically required for Politically Exposed Persons (PEPs) under FATF Recommendation 12?
- PEPs are only subject to EDD if they are from high-risk jurisdictions
- Senior management approval for the relationship, reasonable measures to establish the source of wealth and funds, and enhanced ongoing monitoring (Correct answer)
- PEPs must be refused all banking services under FATF standards
- PEPs need only standard CDD since their public role makes them lower risk
Correct answer: Senior management approval for the relationship, reasonable measures to establish the source of wealth and funds, and enhanced ongoing monitoring
FATF Recommendation 12 requires that for PEPs, institutions must: obtain senior management approval; take reasonable measures to establish source of wealth and funds; and conduct enhanced ongoing monitoring of the business relationship.
Question 34: Which money laundering method involves purchasing multiple monetary instruments in amounts just below the Currency Transaction Report (CTR) threshold?
- Integration
- Smurfing
- Layering
- Structuring (Correct answer)
Correct answer: Structuring
Structuring (also known as 'smurfing') involves breaking up large cash transactions into smaller amounts specifically to avoid triggering CTR filing requirements. It is a federal crime under the Bank Secrecy Act.
Question 35: Under the FinCEN CDD Rule, who qualifies as a 'beneficial owner' of a legal entity customer?
- Any employee of the customer with signatory authority on the account
- Any individual who has conducted a transaction through the account in the past 12 months
- Each individual who owns, directly or indirectly, 25% or more of the equity interests of a legal entity, plus one individual who controls or manages the entity (Correct answer)
- Only the CEO and CFO of the legal entity customer
Correct answer: Each individual who owns, directly or indirectly, 25% or more of the equity interests of a legal entity, plus one individual who controls or manages the entity
The FinCEN CDD Rule defines beneficial owners using a two-prong test: the ownership prong (anyone owning 25% or more) and the control prong (one individual who controls or manages the entity, typically the CEO, COO, or equivalent).
Question 36: What is a 'law enforcement freeze request' and how must financial institutions respond?
- A request from the FBI to confiscate all cash held in a customer's safe deposit box
- A FinCEN directive to cease all transactions in an account pending a SAR review
- An automatic freeze of accounts for customers who have been arrested
- A request from law enforcement asking a financial institution to maintain an account and not alert the customer while an investigation is ongoing, typically supported by legal process such as a court order (Correct answer)
Correct answer: A request from law enforcement asking a financial institution to maintain an account and not alert the customer while an investigation is ongoing, typically supported by legal process such as a court order
Law enforcement may request that financial institutions keep suspicious accounts open and operational during ongoing investigations, supported by legal process, so that investigators can gather additional evidence while the subjects remain unaware.
Question 37: Enhanced Due Diligence (EDD) for a correspondent banking relationship would be most appropriate when the respondent bank:
- is located in a jurisdiction known for high levels of corruption and weak AML/CFT supervision. (Correct answer)
- requests to open an account denominated in a foreign currency.
- is a large, publicly traded institution in a major financial center.
- has been in operation for less than five years.
Correct answer: is located in a jurisdiction known for high levels of corruption and weak AML/CFT supervision.
The jurisdictional risk of the respondent bank is a critical factor. When a respondent bank is located in a country identified as having strategic AML/CFT deficiencies, high levels of corruption, or weak supervision, it presents a much higher risk. This requires the correspondent bank to apply Enhanced Due Diligence measures to mitigate the increased risk of illicit financial activity.
Question 38: When an AML investigator concludes an investigation and decides *not* to file a Suspicious Activity Report (SAR), what is a critical component that must be included in the investigation file?
- A detailed justification for the decision, including the specific factors and evidence reviewed. (Correct answer)
- The exact date the account is scheduled for its next periodic CDD review.
- A copy of the customer's most recent government-issued photo identification.
- An attestation signed by the relationship manager confirming the customer's good standing.
Correct answer: A detailed justification for the decision, including the specific factors and evidence reviewed.
Auditors and regulators will scrutinize the rationale for not filing a SAR. The investigation file must contain a clear and detailed justification explaining why the activity, although initially flagged, was determined not to be suspicious upon review. This demonstrates a sound and defensible decision-making process. While not always a strict regulatory requirement, it is a widely accepted best practice. The other options are either part of the standard customer file or are not directly relevant to documenting the conclusion of a specific investigation.
Question 39: After filing a SAR on a customer, what is the most appropriate next step for the financial institution regarding the customer's account?
- Cease all monitoring of the account as the responsibility has been transferred to the FIU.
- Inform the customer that a SAR has been filed to maintain transparency.
- Immediately freeze all assets in the account pending law enforcement action.
- Continue to monitor the account, potentially under enhanced due diligence, and report any further suspicious activity. (Correct answer)
Correct answer: Continue to monitor the account, potentially under enhanced due diligence, and report any further suspicious activity.
Filing a SAR does not end the institution's AML obligations. The institution must not 'tip off' the customer about the SAR filing. It should continue to monitor the customer's activity, applying enhanced due diligence as appropriate, and file supplemental SARs for any new suspicious transactions. Account closure decisions should be made based on the institution's risk appetite and policies, but monitoring must continue as long as the account is open.
Question 40: What is a 'trigger event' in the context of CDD ongoing monitoring, and can you provide three examples?
- An indicator that a customer is about to close their account; examples: declining balance, reduced transaction frequency, competitor promotional offers
- An event requiring a financial institution to review and potentially update a customer's CDD information; examples: significant changes in transaction patterns, adverse media, or customer-initiated changes to account information (Correct answer)
- A system alert requiring immediate account freeze; examples: OFAC match, court order, law enforcement request
- A transaction that triggers an automatic SAR filing; examples: transactions over $10K, foreign wire transfers, cash deposits
Correct answer: An event requiring a financial institution to review and potentially update a customer's CDD information; examples: significant changes in transaction patterns, adverse media, or customer-initiated changes to account information
Trigger events are circumstances that prompt a review and potential update of a customer's CDD file. Examples include significant changes in transaction activity, adverse media hits, changes to beneficial ownership, or requests for new high-risk products.
Question 41: A key element of developing a customer risk profile as part of the CDD process involves:
- Requiring the customer to maintain a minimum account balance.
- Understanding the customer's political affiliation.
- Understanding the nature and purpose of the customer relationship. (Correct answer)
- Limiting the number of transactions the customer can perform.
Correct answer: Understanding the nature and purpose of the customer relationship.
A fundamental component of Customer Due Diligence is understanding the nature and purpose of the customer relationship. This allows the financial institution to develop a customer risk profile and anticipate the types of transactions the customer is likely to conduct. This baseline is essential for ongoing monitoring to detect activity that is unusual or inconsistent with the customer's profile.
Question 42: What is the 'Wolfsberg Group' and what is its role in international AML standards?
- A UN committee setting mandatory AML requirements for all member states
- A group of 13 global financial institutions that develop voluntary AML/CFT guidance, principles, and best practice papers for the private sector, particularly in correspondent banking, private banking, and trade finance (Correct answer)
- An FATF working group responsible for evaluating high-risk jurisdictions
- An international association of bank regulators that sets examination standards for AML programs
Correct answer: A group of 13 global financial institutions that develop voluntary AML/CFT guidance, principles, and best practice papers for the private sector, particularly in correspondent banking, private banking, and trade finance
The Wolfsberg Group is a private-sector association of 13 major global banks that develops voluntary AML guidance and principles, particularly influential in areas such as correspondent banking due diligence, private banking, and anti-bribery standards.
Question 43: What is the primary purpose of the Bank Secrecy Act (BSA) in the United States?
- To regulate interest rates charged by commercial banks
- To ensure equal lending practices across all customer segments
- To require financial institutions to assist government agencies in detecting money laundering (Correct answer)
- To protect customer bank account information from disclosure
Correct answer: To require financial institutions to assist government agencies in detecting money laundering
The BSA requires U.S. financial institutions to maintain records and file reports that help identify, detect, and deter money laundering and other financial crimes.
Question 44: In addition to identifying equity owners, FinCEN's beneficial ownership rule also requires identification of which individual?
- A single person with significant responsibility to control, manage, or direct the entity (Correct answer)
- The entity's registered agent
- All directors of the company
- The entity's largest creditor
Correct answer: A single person with significant responsibility to control, manage, or direct the entity
The CDD Rule's two-prong approach requires identifying equity owners at 25%+ and one control person with significant responsibility for managing or directing the entity.
Question 45: What does a 'risk-based approach' to AML allow financial institutions to do that a purely rule-based approach does not?
- Exempt themselves from BSA reporting requirements
- Set their own SAR filing thresholds
- Allocate compliance resources proportional to the level of money laundering risk, applying more scrutiny where risk is higher (Correct answer)
- Eliminate all AML controls for low-risk customers
Correct answer: Allocate compliance resources proportional to the level of money laundering risk, applying more scrutiny where risk is higher
The risk-based approach allows institutions to concentrate their AML resources where money laundering risk is highest, rather than applying identical controls to all customers and transactions regardless of risk level.
Question 46: How does 'machine learning' differ from rule-based transaction monitoring in detecting suspicious activity?
- Machine learning is less accurate than rules-based monitoring and is not used in AML
- Machine learning is only effective for detecting sanctions violations, not money laundering
- Machine learning models can identify complex, non-linear patterns and previously unknown suspicious behaviors that may not be captured by predefined rules, using historical data to train models that evolve as patterns change (Correct answer)
- Machine learning eliminates the need for human review of transaction monitoring alerts
Correct answer: Machine learning models can identify complex, non-linear patterns and previously unknown suspicious behaviors that may not be captured by predefined rules, using historical data to train models that evolve as patterns change
Machine learning can detect novel and complex patterns across large datasets that rule-based systems miss β learning from historical suspicious activity to identify similar but previously unknown behaviors, and adapting as criminal typologies evolve.
Question 47: What is a 'National Risk Assessment' (NRA) and who typically conducts it?
- An annual audit of all SARs filed by a financial institution
- A review of a non-profit organization's fundraising activities by the IRS
- An assessment of a bank's AML program, conducted by the Federal Reserve
- A country-level evaluation of ML/TF risks conducted by the government, assessing threats, vulnerabilities, and consequences (Correct answer)
Correct answer: A country-level evaluation of ML/TF risks conducted by the government, assessing threats, vulnerabilities, and consequences
A National Risk Assessment is a government-led evaluation of the money laundering and terrorist financing risks facing an entire country, examining threats, vulnerabilities across sectors, and potential consequences.
Question 48: Which of the following is a key component of an effective Know Your Customer (KYC) program?
- Offering loyalty rewards to long-standing customers
- Collecting marketing preferences from customers at onboarding
- Establishing a Customer Identification Program (CIP) to verify identity (Correct answer)
- Reviewing customer credit history before approving transactions
Correct answer: Establishing a Customer Identification Program (CIP) to verify identity
CIP is a foundational KYC element requiring institutions to collect and verify identity information for each customer.
Question 49: What does 'source of funds' verification in CDD refer to?
- Verifying the customer's credit card issuer
- Checking that funds are denominated in the local currency
- Confirming where the bank wire originated technically
- Identifying the income or asset origin that funds a customer's transactions (Correct answer)
Correct answer: Identifying the income or asset origin that funds a customer's transactions
Source of funds verification establishes the legitimate origin of the money a customer is using, helping detect illicit proceeds.
Question 50: What does the legal term 'tipping off' mean in the AML context, and what is its consequence?
- Disclosing to a subject that a SAR has been filed or is being considered about them; it is a federal crime under 31 USC 5318(g)(2) (Correct answer)
- Providing anonymous tips to law enforcement; it is legally protected
- Informing a supervisor about a colleague's suspicious behavior; it is encouraged
- Sharing customer information with another financial institution; it may violate privacy laws
Correct answer: Disclosing to a subject that a SAR has been filed or is being considered about them; it is a federal crime under 31 USC 5318(g)(2)
Tipping off is the illegal act of notifying a customer or any person that they are the subject of a SAR investigation. Under 31 USC 5318(g)(2), tipping off is a federal crime that can result in imprisonment and fines.
Question 51: Which of the following is NOT an essential element that should be included in the narrative of a well-written Suspicious Activity Report (SAR)?
- The names of the individuals or entities involved (Who).
- The investigator's personal opinion on the suspect's guilt. (Correct answer)
- An explanation of why the activity is considered suspicious (Why).
- A clear and chronological description of the suspicious activity.
Correct answer: The investigator's personal opinion on the suspect's guilt.
A SAR narrative should be factual, objective, and concise. It must describe the who, what, when, where, and why of the suspicious activity. Including personal opinions, speculations, or legal conclusions about the subject's guilt is inappropriate and detracts from the factual basis of the report. The focus should be on presenting the observed facts and the reasons for suspicion.
Question 52: What role does 'transaction monitoring' play in an institution's AML risk assessment?
- It is one of the key controls used to detect suspicious activity that may indicate money laundering, and its effectiveness is factored into residual risk calculations (Correct answer)
- It eliminates the need to file Currency Transaction Reports
- It replaces the need for customer due diligence
- It is only required for transactions over $10,000
Correct answer: It is one of the key controls used to detect suspicious activity that may indicate money laundering, and its effectiveness is factored into residual risk calculations
Transaction monitoring systems are a critical AML control that identifies unusual patterns or activity potentially indicative of money laundering. The effectiveness of monitoring is a key factor in determining whether an institution's residual risk is appropriately managed.
Question 53: While both money laundering and terrorist financing involve concealing financial activity, a key distinction is that the source of funds in terrorist financing:
- Can originate from both legitimate and illegitimate sources. (Correct answer)
- Is always from criminal activities.
- Must pass through a correspondent banking relationship to be considered TF.
- Is always directly from state sponsors.
Correct answer: Can originate from both legitimate and illegitimate sources.
Unlike money laundering, which by definition deals with concealing the proceeds of crime, terrorist financing can be sourced from legal means (such as salaries, personal savings, and donations to legitimate-seeming organizations) as well as from criminal activities. The primary focus is on the illicit purpose for which the funds will be used, not necessarily their origin.
Question 54: Which of the following threats are not a direct effect of money laundering?
- Marketable risks (Correct answer)
- Reputational risks
- Concentration risks
- Operational risks
Correct answer: Marketable risks
Money laundering directly exposes financial institutions to several risks, including reputational risk (damage to public image), operational risk (breakdowns in internal processes), and concentration risk (over-reliance on certain clients or activities). Marketable risks, which relate to fluctuations in market prices or interest rates, are not a direct consequence of the act of money laundering itself. While money laundering can indirectly affect market stability, it's not a primary, direct risk category for institutions dealing with illicit funds.
Question 55: A bank is onboarding a family trust as a new client. Who should be identified as the beneficial owner?
- The attorney who drafted the trust document
- The settlor, trustee(s), protector (if any), beneficiaries, and any other natural person exercising ultimate effective control (Correct answer)
- The largest beneficiary only
- Only the trustee named on the trust document
Correct answer: The settlor, trustee(s), protector (if any), beneficiaries, and any other natural person exercising ultimate effective control
For trusts, beneficial ownership extends to all parties exercising control or ownership over trust assets, including settlors, trustees, protectors, and beneficiaries, to ensure true ownership is transparent.
Question 56: What is a '314(b) information sharing request' and how does it support AML investigations?
- A FinCEN regulation requiring banks to share customer data with the IRS
- A mandatory reporting requirement for transactions involving shell companies
- A voluntary program under the USA PATRIOT Act allowing financial institutions to share information with each other about potential money laundering or terrorist financing activity (Correct answer)
- A process for banks to request law enforcement records about specific customers
Correct answer: A voluntary program under the USA PATRIOT Act allowing financial institutions to share information with each other about potential money laundering or terrorist financing activity
Section 314(b) of the USA PATRIOT Act created a voluntary information-sharing program allowing financial institutions that have registered with FinCEN to share information with each other about individuals, entities, and transactions suspected of money laundering or terrorist financing.
Question 57: A country is undergoing an assessment by FATF to evaluate the implementation and effectiveness of its AML/CFT measures against the 40 Recommendations. This peer review process is officially known as a:
- Mutual Evaluation (Correct answer)
- Regulatory Compliance Audit
- National Risk Assessment
- Financial System Stability Assessment
Correct answer: Mutual Evaluation
The FATF assesses its members' compliance with the international AML/CFT standards through a peer review process called a Mutual Evaluation. These in-depth country reports analyze both technical compliance (laws and regulations in place) and the effectiveness of the country's AML/CFT system.
Question 58: Which red flag is most associated with trade-based money laundering (TBML)?
- Requesting online banking access for a new business account
- A customer requesting a wire transfer to a FATF-compliant jurisdiction
- A business customer depositing revenue consistent with its industry
- Over- or under-invoicing of goods and services in international trade transactions (Correct answer)
Correct answer: Over- or under-invoicing of goods and services in international trade transactions
TBML often involves manipulating trade invoice values to transfer value across borders, making over- or under-invoicing a key red flag.
Question 59: What is the role of the 'BSA Officer' (BSAO) in an AML investigation?
- The BSAO only files CTRs and has no role in investigations
- The BSAO oversees the AML compliance program and typically makes or approves final SAR filing decisions, ensuring investigations are thorough and documented (Correct answer)
- The BSAO only communicates with regulators and has no operational investigation role
- The BSAO is responsible only for employee AML training programs
Correct answer: The BSAO oversees the AML compliance program and typically makes or approves final SAR filing decisions, ensuring investigations are thorough and documented
The BSA Officer (also called the AML Compliance Officer) is responsible for overseeing the AML program, which includes ensuring investigations are properly conducted, documented, and that SAR filing decisions are sound and well-supported.
Question 60: At the conclusion of a complex money laundering investigation, the compliance officer has determined that a SAR must be filed. The investigation revealed a sophisticated network of shell companies moving funds. Which of the following is the most important element to include in the SAR narrative?
- A recommendation to law enforcement on which specific statutes may have been violated.
- The personal opinion of the investigator on the customer's character.
- A chronological and detailed description of the suspicious activity, covering the 'who, what, where, when, and why'. (Correct answer)
- An exhaustive list of every non-suspicious transaction in the account during the review period.
Correct answer: A chronological and detailed description of the suspicious activity, covering the 'who, what, where, when, and why'.
The primary purpose of the SAR narrative is to provide a clear, concise, and comprehensive account of the suspicious activity for law enforcement. Covering the 'who, what, where, when, why, and how' provides law enforcement with the actionable intelligence they need. Personal opinions are unprofessional, legal conclusions are the responsibility of law enforcement, and including non-suspicious activity clutters the report and obscures the key facts.
Question 61: Which category of PEP is defined as 'domestic PEP' under US AML rules?
- Senior officials of US federal, state, or local government entrusted with prominent public functions (Correct answer)
- Senior officials of foreign governments only
- Relatives of foreign PEPs residing in the US
- Any US citizen who works for a foreign government
Correct answer: Senior officials of US federal, state, or local government entrusted with prominent public functions
Domestic PEPs are individuals entrusted with prominent public functions within the US, such as senior elected or appointed government officials.
Question 62: What is 'mutual legal assistance' (MLA) and why is it important for international AML investigations?
- Bilateral agreements between financial institutions to share customer information across borders
- Technical assistance provided by developed countries to help developing countries build AML programs
- The FATF peer review process for evaluating member country AML programs
- Formal legal mechanisms (treaties and agreements) allowing countries to request and provide investigative assistance β including sharing evidence, executing search warrants, and seizing assets β across national borders (Correct answer)
Correct answer: Formal legal mechanisms (treaties and agreements) allowing countries to request and provide investigative assistance β including sharing evidence, executing search warrants, and seizing assets β across national borders
Mutual legal assistance treaties (MLATs) and agreements allow countries to formally request investigative assistance from each other β gathering evidence, executing judicial orders, and sharing financial intelligence β which is essential for prosecuting cross-border money laundering cases.
Question 63: The Black Market Peso Exchange (BMPE) primarily originated from which illicit industry?
- Arms trafficking
- Cybercrime
- Human smuggling
- Drug trafficking (Correct answer)
Correct answer: Drug trafficking
BMPE originated as a method for Colombian drug traffickers to convert US dollar proceeds into Colombian pesos without moving currency across borders directly.
Question 64: A bank determines that a new customer relationship presents a low risk of money laundering or terrorist financing. Under a risk-based approach, which level of due diligence would be most appropriate to apply at the start of the relationship?
- Simplified Due Diligence (SDD) (Correct answer)
- Enhanced Due Diligence (EDD)
- No due diligence is required for low-risk customers.
- Standard Customer Due Diligence (CDD)
Correct answer: Simplified Due Diligence (SDD)
Simplified Due Diligence (SDD) is a streamlined approach to CDD that is permitted when the risk of money laundering or terrorist financing is assessed as low. It allows for less intensive verification and monitoring measures but still requires the core components of CDD to be met. Standard CDD is for normal-risk customers, and Enhanced Due Diligence (EDD) is for high-risk customers.
Question 65: An immigrant who lives in the United States creates a bank account that contains a debit card. Several months later, the transactional monitoring system detects tiny payments into the account, which are followed by ATM withdrawals from a conflict-zone neighboring nation. What should be the bank's response?
- Launch an inquiry into the action (Correct answer)
- Contact the consumer if transaction activity persists
- Submit a suspicious transaction report
- Prevent any future activities
Correct answer: Launch an inquiry into the action
When a transactional monitoring system flags unusual activity, such as tiny payments followed by ATM withdrawals from a conflict-zone neighboring nation, the bank's initial response should be to launch an inquiry. This allows the bank to gather more information, assess the legitimacy of the transactions, and determine if the activity is truly suspicious before taking further action like filing a report or preventing future activities. It's a crucial step in the due diligence process.
Question 66: What is a 'legal entity customer' under FinCEN's CDD Rule, and what are the primary exemptions from the beneficial ownership requirement?
- Any business entity regardless of size; there are no exemptions
- Only privately held companies with revenues over $10 million; exemptions include sole proprietorships
- A corporation, LLC, partnership, or other entity formed by filing with a state; exemptions include publicly listed companies, government entities, regulated financial institutions, and certain pooled investment vehicles (Correct answer)
- Any entity registered for tax purposes; exemptions include non-profit organizations
Correct answer: A corporation, LLC, partnership, or other entity formed by filing with a state; exemptions include publicly listed companies, government entities, regulated financial institutions, and certain pooled investment vehicles
Legal entity customers are entities formed by filing with state or federal authorities. Key exemptions from beneficial ownership requirements include publicly traded companies (registered with the SEC), government entities, federally regulated financial institutions, and certain SEC-registered investment vehicles.
Question 67: An investigator is analyzing an alert on a customer's account involving structured cash deposits followed by an outgoing wire transfer. The investigator has reviewed account opening documents, transaction history, and notes from the relationship manager. Which of the following represents the next logical step of gathering *external* information?
- Performing a public internet search on the beneficiary of the wire transfer. (Correct answer)
- Reviewing security camera footage of the deposits being made.
- Checking the institution's central database for other accounts linked to the customer.
- Interviewing the teller who accepted the cash deposits.
Correct answer: Performing a public internet search on the beneficiary of the wire transfer.
Options A, C, and D all represent the gathering of *internal* information that is already within the financial institution's possession or accessible through its staff and systems. Performing a public internet search on the wire beneficiary is a classic example of using external, open-source intelligence (OSINT) to add context to the investigation, such as verifying the beneficiary's business or looking for adverse information.
Question 68: Which international body, primarily focused on banking supervision, works to strengthen the regulation and supervision of banks worldwide and has published guidelines on the sound management of AML/CFT risks that complement the FATF standards?
- The Egmont Group of Financial Intelligence Units
- The International Monetary Fund (IMF)
- The Wolfsberg Group
- The Basel Committee on Banking Supervision (BCBS) (Correct answer)
Correct answer: The Basel Committee on Banking Supervision (BCBS)
The Basel Committee on Banking Supervision (BCBS) is the primary global standard-setter for the prudential regulation of banks. It has issued guidelines, such as "Sound management of risks related to money laundering and financing of terrorism," which complement the FATF's broader AML/CFT standards and integrate them into the overall framework of banking supervision.
Question 69: In a risk-based approach, when is Enhanced Due Diligence (EDD) required?
- For customers identified as high-risk, such as PEPs, correspondent banks, or those from high-risk jurisdictions (Correct answer)
- Only when a SAR has previously been filed on the account
- Whenever a customer's transaction exceeds $5,000
- For every new customer regardless of risk
Correct answer: For customers identified as high-risk, such as PEPs, correspondent banks, or those from high-risk jurisdictions
EDD is required for high-risk customers identified through the risk assessment process, including politically exposed persons, correspondent banking relationships, customers from high-risk jurisdictions, and others presenting elevated money laundering risk.
Question 70: When reviewing trade finance for TBML risk, which factor is least relevant?
- Whether the counterparties are in high-risk jurisdictions
- The geographic routing of the shipment
- The creditworthiness of the exporter for the goods traded (Correct answer)
- Whether the commodity price matches market rates
Correct answer: The creditworthiness of the exporter for the goods traded
While creditworthiness matters for credit risk, TBML detection focuses on price accuracy, geographic risk, commodity appropriateness, and counterparty risk rather than the exporter's creditworthiness.
Question 71: What information should be gathered during the initial stage of an AML investigation triggered by a transaction monitoring alert?
- Customer identity information, account history, related party information, transaction patterns, and any prior SAR or alert history (Correct answer)
- External law enforcement reports and media searches only
- Only the beneficial ownership information for the account
- Only the transaction details that triggered the alert
Correct answer: Customer identity information, account history, related party information, transaction patterns, and any prior SAR or alert history
A thorough AML investigation requires gathering comprehensive information from multiple sources: customer identity and KYC file, full account and transaction history, related party connections, prior alert/SAR history, and external sources such as public records and adverse media.
Question 72: What is the '60-day rule' for SAR filing?
- Law enforcement has 60 days to respond to a filed SAR before an institution may close the account
- SARs must be filed within 60 days of account opening for all high-risk customers
- Institutions must retain SAR documentation for at least 60 days after filing
- SARs must be filed no later than 60 days after the date the financial institution initially detected the suspicious activity, with an option for an additional 30 days if needed to identify a subject (Correct answer)
Correct answer: SARs must be filed no later than 60 days after the date the financial institution initially detected the suspicious activity, with an option for an additional 30 days if needed to identify a subject
Under BSA regulations, SARs must generally be filed within 30 days of initial detection of suspicious activity. If additional time is needed to identify the subject involved, an extension of up to 60 days from initial detection is permitted, for a maximum of 60 days total.
Question 73: What is 'bulk cash smuggling' in the context of money laundering?
- Using multiple cash deposits under reporting thresholds
- Physically transporting large amounts of currency across borders to avoid financial reporting (Correct answer)
- Converting cash into precious metals for storage
- Electronically transferring large sums across borders
Correct answer: Physically transporting large amounts of currency across borders to avoid financial reporting
Bulk cash smuggling involves the physical movement of currency across international borders to avoid financial reporting requirements and law enforcement detection.
Question 74: What is the primary purpose of ongoing monitoring within a Customer Due Diligence (CDD) program?
- To ensure all customer data is encrypted.
- To detect transactions that are inconsistent with the customer's known profile and report suspicious activity. (Correct answer)
- To market new financial products to existing customers.
- To conduct annual performance reviews of compliance staff.
Correct answer: To detect transactions that are inconsistent with the customer's known profile and report suspicious activity.
Ongoing monitoring is a critical pillar of CDD. Its primary purpose is to scrutinize transactions to ensure they are consistent with the institution's knowledge of the customer, their business, and their risk profile. This allows the institution to identify potentially suspicious activity that may be indicative of money laundering or other financial crimes and report it as required.
Question 75: Which TBML red flag relates to a significant discrepancy between the type of business and the goods being traded?
- Price discrepancy
- Commodity inconsistency (Correct answer)
- Volume mismatch
- Geographic anomaly
Correct answer: Commodity inconsistency
Commodity inconsistencyβwhere a business trades in goods unrelated to its stated business purposeβis a key TBML red flag because it suggests the trade is structured to move funds rather than for genuine commerce.
Question 76: What are the FATF '40 Recommendations' and when were they last significantly updated?
- Voluntary guidelines for AML compliance, last updated in 2001
- UN Security Council resolutions establishing mandatory AML requirements, adopted in 1989
- The international AML/CFT standards that form the global framework for combating money laundering and terrorist financing, last significantly revised in 2012 and supplemented by targeted revisions through 2023 (Correct answer)
- EU directives applicable only to European Union member states, last updated in 2018
Correct answer: The international AML/CFT standards that form the global framework for combating money laundering and terrorist financing, last significantly revised in 2012 and supplemented by targeted revisions through 2023
The FATF 40 Recommendations are the recognized global AML/CFT standards applicable to FATF members and evaluated countries. Originally issued in 1990 and significantly revised in 2003 and 2012, they have been supplemented by targeted updates on virtual assets, beneficial ownership, and other areas.
Question 77: Which red signal should a compliance officer prioritize for further investigation?
- Several cross-border transactions are received and promptly wired to another recipient.
- A convenience shop cashes government cheques for clients worth less than $1,000 USD every day.
- A loan is paid off in full with cash following the sale of the car that served as security for the loan.
- A customer makes 20 repeating monthly purchases amounting less than $500 USD. (Correct answer)
Correct answer: A customer makes 20 repeating monthly purchases amounting less than $500 USD.
A customer making 20 repeating monthly purchases amounting to less than $500 USD is a significant red flag for microstructuring. This pattern suggests an attempt to evade detection by keeping individual transaction amounts below reporting thresholds, which is a common money laundering technique. While other options might warrant investigation, this specific pattern is a classic indicator of illicit activity designed to avoid scrutiny.
Question 78: Under the Corporate Transparency Act (CTA), effective January 2024 in the US, who is responsible for reporting beneficial ownership information?
- State secretaries of state offices
- Registered agents of corporations
- Banks and financial institutions on behalf of their customers
- Covered reporting companies (most small corporations and LLCs) directly to FinCEN (Correct answer)
Correct answer: Covered reporting companies (most small corporations and LLCs) directly to FinCEN
The CTA requires most small corporations, LLCs, and similar entities to file beneficial ownership information directly with FinCEN's Beneficial Ownership Secure System (BOSS), shifting the reporting obligation to the companies themselves.
Question 79: Which of the following best characterizes the "layering" stage in money laundering?
- Introducing illegal funds into the financial system via a respectable source
- Integrating laundered monies into the economy using lawful transactions
- Using complicated financial transactions to conceal the origin of the cash (Correct answer)
- Withdrawing funds from structured deposits in several geographic regions
Correct answer: Using complicated financial transactions to conceal the origin of the cash
The 'layering' stage in money laundering is best characterized by using complicated financial transactions to conceal the origin of the cash. After placement, criminals move funds through multiple accounts, jurisdictions, and complex financial instruments to obscure the audit trail and separate the illicit money from its criminal source. This makes it extremely difficult for authorities to trace the funds back to their illegal origins.
Question 80: What are the 'five pillars' of an effective BSA/AML compliance program under U.S. federal requirements?
- Internal controls, a designated compliance officer, employee training, independent testing, and customer due diligence (Correct answer)
- Board oversight, senior management accountability, technology systems, legal review, and regulatory liaison
- Policies, procedures, internal controls, risk assessment, and training
- SAR filing, CTR filing, record retention, risk assessment, and OFAC screening
Correct answer: Internal controls, a designated compliance officer, employee training, independent testing, and customer due diligence
FinCEN and banking regulators require BSA/AML programs to have five pillars: (1) internal controls, (2) a designated BSA/AML compliance officer, (3) ongoing employee training, (4) independent testing/audit, and (5) customer due diligence (added as the fifth pillar by FinCEN's 2016 CDD Rule).
Question 81: A compliance analyst at a fintech company is designing a new AML training program for front-line staff who handle customer onboarding. To be most effective, the training should include which of the following?
- A list of every sanctioned individual published by all global regulators.
- Complex legal analysis of international AML treaties.
- Role-specific examples of red flags and clear procedures for escalating suspicious activity. (Correct answer)
- A detailed history of the company's founding and its stock performance.
Correct answer: Role-specific examples of red flags and clear procedures for escalating suspicious activity.
Effective AML training should be tailored to the specific roles and responsibilities of the employees. For front-line staff, this means providing practical, actionable information, such as how to identify red flags relevant to their daily tasks (like customer onboarding) and the specific internal procedures for reporting any concerns.
Question 82: What is the 'correspondent banking concentration risk' and how should institutions manage it?
- Excessive reliance on a small number of correspondent banks or respondent banks for a significant portion of transaction volume, managed through relationship diversification and enhanced monitoring (Correct answer)
- The risk that correspondent fees are too concentrated in a single revenue stream, managed through fee diversification
- The risk that too many correspondent relationships exist with a single country, managed by diversifying geographically
- The regulatory risk of having too many active correspondent relationships, managed by reducing relationship count
Correct answer: Excessive reliance on a small number of correspondent banks or respondent banks for a significant portion of transaction volume, managed through relationship diversification and enhanced monitoring
Concentration risk in correspondent banking refers to over-reliance on a small number of banking relationships, which can create both operational risk (if a relationship is terminated) and elevated AML risk (if a single relationship channels a disproportionate volume of potentially suspicious activity).
Question 83: What is the purpose of 'independent testing' (AML audit) and what are the key attributes of an effective AML audit?
- An objective evaluation conducted by individuals independent of the AML function that assesses the adequacy and effectiveness of the AML program and its compliance with BSA requirements (Correct answer)
- A review of individual SAR filing decisions conducted by the BSA Officer
- The AML compliance team audits itself to identify self-improvement opportunities
- An annual IT security audit of the transaction monitoring system
Correct answer: An objective evaluation conducted by individuals independent of the AML function that assesses the adequacy and effectiveness of the AML program and its compliance with BSA requirements
Independent testing provides objective assurance that the AML program is adequate, effective, and compliant with BSA requirements. It must be conducted by parties independent of the compliance function, on a risk-based schedule, with results reported to the board.
Question 84: What is the recommended first step for a bank's trade finance unit when a TBML red flag is identified?
- Conduct enhanced due diligence and escalate to the AML compliance team for review (Correct answer)
- Immediately freeze the account and report to FinCEN
- Reject the transaction without investigation
- Notify the customer that the transaction is under review
Correct answer: Conduct enhanced due diligence and escalate to the AML compliance team for review
Upon identifying a TBML red flag, the appropriate response is to conduct enhanced due diligence, gather additional information, and escalate to AML compliance before deciding on any account action or SAR filing.
Question 85: Which of the following situations would mandate a financial institution to conduct customer due diligence (CDD) measures, according to FATF Recommendation 10?
- Only when a customer requests to open an account for a trust or legal arrangement.
- Only when a transaction exceeds a very high, pre-defined internal threshold set by the bank's board.
- When there is a suspicion of money laundering, regardless of any transaction threshold. (Correct answer)
- Only when establishing a new business relationship.
Correct answer: When there is a suspicion of money laundering, regardless of any transaction threshold.
FATF Recommendation 10 states that CDD must be performed in several circumstances, including: when establishing business relations; when carrying out occasional transactions above the designated threshold; when there is a suspicion of money laundering or terrorist financing; or when the institution has doubts about the veracity of previously obtained customer identification data. A suspicion of ML/TF triggers the CDD requirement irrespective of any threshold.
Question 86: What is the 'no tipping off' rule and how does it affect account management decisions after a SAR is filed?
- The rule prevents compliance staff from telling front-line employees about customer risk ratings
- The rule prevents law enforcement from notifying suspects that they are under investigation
- Financial institutions cannot notify a customer that a SAR has been filed or is being considered about them, which means account closure decisions and customer communications must be managed carefully to avoid revealing SAR-related concerns (Correct answer)
- Financial institutions must immediately close accounts for which a SAR has been filed
Correct answer: Financial institutions cannot notify a customer that a SAR has been filed or is being considered about them, which means account closure decisions and customer communications must be managed carefully to avoid revealing SAR-related concerns
The tipping off prohibition means institutions must handle any account management actions β including account closures, product restrictions, or customer inquiries β in ways that do not reveal or suggest that a SAR has been filed.
Question 87: Under FinCEN's Customer Due Diligence (CDD) Rule, what ownership threshold triggers beneficial ownership identification for legal entity customers?
- 51% or more
- 15% or more
- 10% or more
- 25% or more (Correct answer)
Correct answer: 25% or more
FinCEN's CDD Rule requires covered financial institutions to identify natural persons owning 25% or more of a legal entity customer and one person with significant managerial control.
Question 88: Which of the following best describes 'layering' in the money laundering process?
- Placing criminal proceeds into a bank account for the first time
- Conducting complex series of financial transactions to distance funds from their source (Correct answer)
- Filing false tax returns to legitimize unreported income
- Using illicit funds to purchase legitimate goods for resale
Correct answer: Conducting complex series of financial transactions to distance funds from their source
Layering involves moving and converting funds through multiple transactions or accounts to make tracing the original source extremely difficult.
Question 89: A mid-sized bank has recently expanded its services to include international wire transfers to several new countries. According to the risk-based approach, what is the MOST appropriate next step for the bank's AML compliance officer?
- Hire a third-party vendor to monitor all transactions, regardless of risk level.
- Immediately file suspicious activity reports on the first ten transfers to the new countries.
- Conduct an updated enterprise-wide risk assessment to evaluate the new products, services, and geographic exposures. (Correct answer)
- Implement a mandatory in-person training session for all 5,000 bank employees within one week.
Correct answer: Conduct an updated enterprise-wide risk assessment to evaluate the new products, services, and geographic exposures.
The risk-based approach requires financial institutions to identify, assess, and understand the money laundering risks they face and apply proportionate controls. When a bank introduces new products or expands into new geographic areas, it must update its risk assessment to identify new potential vulnerabilities and ensure its controls are adequate to mitigate those risks.
Question 90: Which of the following is considered a core requirement of a Customer Due Diligence (CDD) program according to the FinCEN CDD Final Rule?
- Reporting all cash transactions exceeding $5,000 to the board of directors.
- Conducting ongoing monitoring to identify and report suspicious transactions. (Correct answer)
- Obtaining a credit report for every new customer.
- Processing all customer transactions within 24 hours.
Correct answer: Conducting ongoing monitoring to identify and report suspicious transactions.
The FinCEN CDD Final Rule explicitly outlines four core requirements for CDD programs. These are: 1) identifying and verifying the identity of customers; 2) identifying and verifying the identity of beneficial owners of legal entity customers; 3) understanding the nature and purpose of customer relationships to develop a customer risk profile; and 4) conducting ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information.
Question 91: When a financial institution identifies a discrepancy in beneficial ownership information provided by a customer, what is the appropriate response?
- Close the account immediately
- Immediately file a SAR without further investigation
- Accept the customer's explanation without documentation
- Conduct additional due diligence to resolve the discrepancy; escalate and file a SAR if suspicion remains (Correct answer)
Correct answer: Conduct additional due diligence to resolve the discrepancy; escalate and file a SAR if suspicion remains
FinCEN guidance requires institutions to conduct additional due diligence when discrepancies arise, and to file a SAR if the discrepancy cannot be satisfactorily resolved and suspicion of illicit activity remains.
Question 92: How should AML compliance programs be structured when an institution operates in multiple countries?
- Only apply AML requirements in countries where FATF membership applies
- Establish a global minimum standard based on the most rigorous applicable requirements, with local country-specific additions to meet host country laws; coordinate global risk assessments while adapting controls for local market conditions (Correct answer)
- Allow each country operation to establish entirely independent AML programs without headquarters oversight
- Apply only the home country's AML standards globally and ignore local requirements
Correct answer: Establish a global minimum standard based on the most rigorous applicable requirements, with local country-specific additions to meet host country laws; coordinate global risk assessments while adapting controls for local market conditions
Multinational institutions must meet the strictest applicable requirements across all jurisdictions β typically establishing a global minimum standard and layering local requirements on top β while maintaining enterprise-wide visibility through coordinated risk management.
Question 93: What is the role of the 'board of directors' in overseeing the BSA/AML compliance program?
- The board's only role is to approve the AML budget annually
- The board approves the AML program and policies, receives regular reports on AML program performance, and is ultimately accountable for ensuring the institution maintains effective AML controls (Correct answer)
- The board has no AML responsibility β that rests entirely with the compliance officer
- The board only becomes involved when a regulatory enforcement action is initiated
Correct answer: The board approves the AML program and policies, receives regular reports on AML program performance, and is ultimately accountable for ensuring the institution maintains effective AML controls
The board of directors bears ultimate accountability for BSA/AML compliance. The board approves the AML program and policies, receives regular compliance reports, ensures adequate resources are allocated, and is held responsible by regulators for the effectiveness of the program.
Question 94: What are 'money service businesses' (MSBs) and why do they require enhanced due diligence?
- Large commercial banks providing international wire services; they are lower risk due to strong regulation
- Community development financial institutions; they serve underbanked populations
- Non-bank financial institutions (check cashers, money transmitters, currency exchangers, prepaid card issuers) that process large volumes of cash or value transfers and are frequently targeted by money launderers (Correct answer)
- Broker-dealers registered with FINRA; they are subject to securities rather than BSA regulation
Correct answer: Non-bank financial institutions (check cashers, money transmitters, currency exchangers, prepaid card issuers) that process large volumes of cash or value transfers and are frequently targeted by money launderers
MSBs are non-bank financial businesses that handle currency, money orders, wire transfers, and similar instruments. They require EDD because their cash-intensive, high-volume operations and often anonymous customers create significant ML/TF exposure.
Question 95: What is 'behavioral analytics' in the context of AML transaction monitoring and how does it complement rule-based detection?
- Analyzing competitor bank behaviors to benchmark monitoring effectiveness
- Monitoring customer behavior on digital banking platforms to prevent account takeover fraud only
- Analyzing employee behavior to detect internal fraud by compliance staff
- Establishing baseline transaction profiles for individual customers or peer groups, then detecting deviations from those baselines that may indicate suspicious activity β complementing rules by catching gradual behavioral shifts that fall below fixed alert thresholds (Correct answer)
Correct answer: Establishing baseline transaction profiles for individual customers or peer groups, then detecting deviations from those baselines that may indicate suspicious activity β complementing rules by catching gradual behavioral shifts that fall below fixed alert thresholds
Behavioral analytics establishes normal transaction patterns for each customer or peer group and alerts on deviations β catching gradual escalations, low-and-slow structuring, and behavioral shifts that fixed-threshold rules may miss.
Question 96: An AML program's policies, procedures, and internal controls should be MOST influenced by which of the following?
- The results of the institution's enterprise-wide risk assessment. (Correct answer)
- The number of employees in the compliance department.
- The personal preferences of the Chief Executive Officer.
- The AML programs of competing financial institutions.
Correct answer: The results of the institution's enterprise-wide risk assessment.
The foundation of a risk-based AML program is the enterprise-wide risk assessment. The results of this assessment, which identifies the specific ML/TF risks the institution faces from its customers, products, services, and geographies, should directly inform the design and implementation of its policies, procedures, and controls.
Question 97: Which of the following represents the financial stage of money laundering?
- placement (Correct answer)
- structuring
Correct answer: placement
Placement is the first financial stage of money laundering, where illegally obtained cash is introduced into the legitimate financial system. This often involves breaking up large sums of cash into smaller, less conspicuous amounts and depositing them into bank accounts or converting them into monetary instruments. Structuring is a technique used during the placement stage to avoid reporting thresholds.
Question 98: What is the significance of 'broken payment chains' or 'stripping' in sanctions evasion schemes?
- Broken payment chains refer to failed wire transfers requiring manual intervention by compliance staff
- Legitimate banks use chain-breaking to expedite wire transfers in time zones without coverage
- Stripping is an OFAC-approved technique for processing humanitarian payments to sanctioned countries
- Stripping involves removing or altering sanctioned party information from payment messages before they pass through U.S. correspondent banks, deliberately concealing sanctions violations from the processing bank (Correct answer)
Correct answer: Stripping involves removing or altering sanctioned party information from payment messages before they pass through U.S. correspondent banks, deliberately concealing sanctions violations from the processing bank
Stripping is the illegal practice of removing, altering, or replacing information identifying sanctioned parties in wire transfer messages so that the payment can pass through U.S. correspondent banks without triggering sanctions screening alerts.
Question 99: When should a financial institution conduct a periodic review of an existing customer's due diligence information?
- Whenever the customer's risk profile changes or on a scheduled basis based on risk tier (Correct answer)
- Only when the customer requests a product upgrade
- Exclusively at account closure
- Only if a SAR has already been filed on the customer
Correct answer: Whenever the customer's risk profile changes or on a scheduled basis based on risk tier
Ongoing due diligence requires refreshing customer information when risk factors change or on a risk-tiered schedule to ensure accuracy.
Question 100: What is 'proliferation financing' (PF) and when did FATF formally add it to its standards?
- The unauthorized distribution of financial licenses to unregulated institutions; added in 2001
- The provision of funds or financial services used for the development, acquisition, or deployment of weapons of mass destruction in violation of international sanctions; formally integrated into FATF's standards through Recommendation 7 in 2012 and strengthened in 2020 (Correct answer)
- Financing of money laundering networks that proliferate across multiple jurisdictions; added in 2003
- Financing excessive growth of the AML compliance industry; added in 2019
Correct answer: The provision of funds or financial services used for the development, acquisition, or deployment of weapons of mass destruction in violation of international sanctions; formally integrated into FATF's standards through Recommendation 7 in 2012 and strengthened in 2020
Proliferation financing refers to financial support for WMD development and delivery β nuclear, chemical, biological, and radiological weapons. FATF added Recommendation 7 on targeted financial sanctions for proliferation financing in 2012 and significantly strengthened its guidance with a 2020 report requiring risk-based controls.
ACAMS CAMS Certification Exam
The ACAMS CAMS exam certifies anti-money laundering specialists with 100 questions over 3.5 hours, covering AML/CFT risks, compliance programs, customer due diligence, investigations, and global sanctions.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong β answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds