A sound AML program is not just software. It requires governance, accountability, controls, testing, and culture.
Core AML Program Elements
Element
Purpose
What to remember
Board/senior management oversight
Set risk appetite and support compliance
Tone from the top matters
Policies and procedures
Translate law and risk appetite into operating rules
Must be practical and kept current
AML compliance officer/function
Coordinates program and escalation
Needs authority, independence, and resources
Risk assessment
Identifies and measures AML/CFT risk
Drives control design
CDD and EDD
Understand customers and risk
Ongoing, not one-time
Transaction monitoring
Detect unusual and suspicious activity
Scenarios must match risk
Sanctions screening
Prevent prohibited dealings
Requires quality data and escalation
Training
Helps staff detect and escalate issues
Role-based training is stronger
Independent testing/audit
Evaluates design and effectiveness
Should be independent of the process tested
Recordkeeping and reporting
Preserves evidence and regulatory compliance
Documentation is critical
Three Lines of Defense
Line
Typical role
AML example
First line
Owns and manages risk in the business
Relationship managers collect CDD and identify unusual activity
Second line
Oversight, policy, advisory, monitoring
AML compliance sets standards and reviews escalations
Third line
Independent assurance
Internal audit tests AML program effectiveness
Trap: The first line cannot outsource all responsibility to compliance. Business units own the risk they generate.
Independent Testing
Independent testing should assess whether controls are designed well and operating effectively. It may review:
Customer risk scoring.
CDD and EDD files.
Beneficial ownership documentation.
Sanctions screening disposition.
Transaction monitoring alert quality.
Suspicious activity investigations.
Reporting timeliness and quality, where applicable.
Training completion and relevance.
Governance and management information.
Prior issue remediation.
CDD, KYC, and EDD
CDD Workflow
flowchart TD
A[Customer onboarding or event trigger] --> B[Identify customer]
B --> C[Verify identity using reliable information]
C --> D[Identify beneficial owners/controllers where applicable]
D --> E[Understand purpose and expected activity]
E --> F[Assign customer risk rating]
F --> G{Higher risk?}
G -- No --> H[Standard monitoring and periodic refresh]
G -- Yes --> I[Enhanced due diligence and approval]
I --> J[Enhanced monitoring and review]
Notes and examples
CDD Decision Table
Situation
Standard CDD Focus
EDD Trigger Indicators
Individual customer
Identity, address, occupation/source of funds as relevant, expected activity
PEP status, unusual wealth, high-risk geography, adverse media, nominee use
Legal entity
Legal existence, ownership/control, business purpose, expected activity
Do we know who the customer is and what activity is expected?
EDD
Higher-risk customers or situations
Do we have enough additional information to understand and manage elevated risk?
Ongoing monitoring
Throughout relationship
Is actual activity consistent with expected activity and risk profile?
Event-driven review
Triggered by change or red flag
Has the customer’s risk materially changed?
Source of Funds vs. Source of Wealth
Term
Meaning
Example
Source of funds
Origin of specific funds used in a transaction or relationship
Salary deposit, sale of property, business revenue
Source of wealth
Overall origin of customer’s total net worth
Business ownership, inheritance, investment gains
Exam trap
Do not treat a bank statement showing current balance as full source-of-wealth evidence.
Balance proves possession, not necessarily origin.
Beneficial Ownership and Control
Concept
Cheat Sheet
Beneficial owner
Natural person who ultimately owns or controls a legal entity or arrangement.
Control person
Person with significant responsibility to control, manage, or direct the entity.
Nominee
Person listed on paper but acting for another party.
Shell company
Entity with little or no independent operations/assets; can be legitimate or abused.
Shelf company
Pre-existing inactive company; risk rises when used to obscure history or ownership.
Front company
Operating business used to disguise illicit activity.
Notes and examples
Beneficial Ownership Red Flags
Red Flag
Why It Matters
Ownership chain includes many entities without clear business reason
May hide true control.
Entities in secrecy or high-risk jurisdictions
May limit transparency.
Nominee directors/shareholders appear repeatedly
May indicate professional concealment.
Customer refuses ownership information
CDD cannot be completed.
Control exercised by someone not listed as owner
Hidden beneficial ownership risk.
Frequent ownership changes without rationale
Potential layering or sanctions evasion.
Sanctions, PEPs, and Adverse Media
High-Yield Distinctions
Topic
Meaning
Key Control
Exam Trap
Sanctions
Legal/economic restrictions against persons, entities, vessels, sectors, or countries
Screening, blocking/rejecting/escalation per applicable rules
Sanctions compliance is not the same as AML monitoring, although they overlap.
PEP
Politically exposed person with potential corruption/bribery risk
Risk-based EDD and senior review where required by policy/law
PEP status alone does not prove criminal activity.
Adverse media
Negative public information suggesting financial crime, corruption, fraud, or sanctions risk
Investigation, corroboration, risk-rating update
Media must be assessed for reliability, relevance, and recency.
Watchlist/internal list
Institution-created list from prior concerns
Internal screening and escalation
Not the same as an official sanctions list.
Notes and examples
Sanctions Screening Decision Path
flowchart TD
A[Potential match from screening] --> B[Compare identifiers]
B --> C{Clearly not same party?}
C -- Yes --> D[False positive; document rationale]
C -- No --> E{Strong or possible match?}
E -- Possible --> F[Escalate for review; gather more identifiers]
E -- Strong --> G[Apply hold/block/reject/escalate per policy and applicable law]
F --> H[Final disposition and audit trail]
G --> H
Screening Quality Factors
Factor
Why It Matters
Data quality
Poor names, dates, addresses, and IDs increase false positives and missed matches.
List updates
Screening must reflect current applicable lists and internal rules.
Fuzzy matching
Helps identify spelling variations but can increase alert volume.
Transliteration
Names may appear differently across alphabets and systems.
Alert documentation
Reviewers must show why an alert was cleared or escalated.
Payment screening timing
Screening too late can allow prohibited activity to proceed.
Sanctions and Screening
Sanctions compliance and AML monitoring are related but not the same.
Topic
AML suspicious activity monitoring
Sanctions screening
Main question
Is activity suspicious or inconsistent?
Is there a prohibited or restricted party, country, vessel, good, or interest?
Timing
Often ongoing and post-transaction, depending on product
Often at onboarding and before/around transaction processing
Output
Alert, investigation, possible report
Hit disposition, block/reject/escalate per law and policy
Evidence
Customer profile, behavior, typologies
List match, ownership/control, identifiers
Main risk
Facilitating laundering or financial crime
Dealing with sanctioned parties or prohibited activity
Screening Match Review
A screening match is not automatically a true hit. Review:
Name similarity and aliases.
Date of birth or incorporation.
Address and nationality.
Identification numbers.
Ownership and control.
Vessel, aircraft, wallet, or other identifiers.
Transaction counterparties and intermediaries.
Geographic links.
Quality of data and transliteration issues.
Sanctions Evasion Red Flags
Use of shell or front companies.
Sudden changes in trade routes.
Vague goods descriptions.
Payments routed through unrelated third parties.
Use of intermediaries in high-risk jurisdictions.
Ownership changes shortly before transactions.
Avoidance of obvious references in payment messages.
IP, shipping, or documentation inconsistencies.
Links to dual-use goods or restricted sectors.
Customer and Product Risk Matrix
Risk Category
Lower-Risk Indicators
Higher-Risk Indicators
Customer type
Salaried individual, transparent ownership, local operating business
PEP, cash-intensive business, offshore vehicle, shell company, MSB, arms-related business
Geography
Strong AML supervision, transparent registries, low corruption
Multiple cash deposits below reporting or internal review thresholds
Structuring/smurfing
Cash activity inconsistent with business type
Placement of illicit proceeds
Deposits at many branches or ATMs into one account
Funnel account activity
Rapid cash deposit followed by wire out
Placement followed by layering
Customer nervous or coached during transaction
Possible third-party control
Notes and examples
Wire Transfers and Correspondent Banking
Red Flag
Possible Concern
Wires to/from high-risk jurisdictions without business reason
Layering, sanctions evasion, fraud
Funds pass through account quickly with little retention
Pass-through activity
Same-day incoming and outgoing wires in similar amounts
Layering
Payment details vague or inconsistent
Concealment of purpose
Nested correspondent activity not disclosed
Hidden respondent/customer risk
Use of shell banks or unregulated institutions
Severe AML and sanctions risk
Trade-Based Money Laundering
Red Flag
Possible Concern
Over- or under-invoicing
Value transfer outside normal payment channels
Multiple invoices for same goods
Duplicate financing or laundering
Goods inconsistent with customer business
False trade activity
Unusual shipping route or transshipment
Sanctions evasion or concealment
Phantom shipments or vague goods descriptions
Fabricated trade
Price inconsistent with market
Value manipulation
Dual-use goods with high-risk end user
Proliferation financing risk
Securities, Insurance, and Investment Products
Red Flag
Possible Concern
Early surrender of policy despite penalties
Laundering through insurance product
Third-party premium payments
Hidden source of funds
Securities trades with no apparent investment rationale
Layering
Wash-like activity or offsetting trades
Creating artificial movement/value
Rapid liquidation after funding
Integration or fraud proceeds
Funds from unrelated jurisdictions
Concealed beneficial owner or source
Real Estate and High-Value Assets
Red Flag
Possible Concern
Purchase through complex entities without clear rationale
Beneficial ownership concealment
All-cash purchase by high-risk customer
Integration
Use of nominee buyer
Hidden owner
Price materially above/below market
Value transfer
Rapid resale without economic reason
Layering/integration
Third-party funding or repayment
Hidden source of funds
Virtual Assets
Red Flag
Possible Concern
Use of mixers/tumblers
Obscuring origin or destination
Darknet marketplace exposure
Criminal proceeds
Chain-hopping across assets
Layering
Transfers involving sanctioned wallet/service
Sanctions breach risk
Rapid in/out movement with no stated purpose
Pass-through activity
Privacy-enhancing coins or anonymity tools
Increased traceability risk
Correspondent Banking
Correspondent banking allows one financial institution to provide services to another, often across borders. It is high risk because the correspondent may have limited visibility into the respondent bank’s customers.
Key Risks
Nested relationships.
Payable-through accounts.
Weak respondent AML controls.
High-risk jurisdictions.
Shell banks.
Poor transparency over originators and beneficiaries.
Sanctions exposure.
Due Diligence Focus
Question
Why it matters
Who owns and controls the respondent bank?
Ownership may create sanctions, corruption, or secrecy risk
Where is it licensed and supervised?
Regulatory quality affects risk
What is its customer base?
Indirect exposure can be significant
What AML controls does it have?
Correspondent relies partly on respondent controls
Does it permit nested access?
Hidden third-party banks increase risk
Are payable-through services offered?
Customers may transact directly through correspondent account
What geographies and products are involved?
Drives EDD and monitoring
Trap: A correspondent bank must understand the respondent relationship; it usually cannot identify every underlying customer in normal correspondent activity, but it must manage the risk appropriately.
Trade-Based Money Laundering
Trade-based money laundering uses trade transactions to move value and disguise proceeds.
Common TBML Methods
Method
Description
Red flags
Over-invoicing
Price is inflated to move extra value
Price inconsistent with market
Under-invoicing
Price is reduced to shift value to buyer
Unusually low declared value
Multiple invoicing
Same goods invoiced multiple times
Duplicate documents or financing
Over/under-shipment
Quantity differs from documentation
Weight or volume mismatch
Phantom shipment
Documents show goods that were not shipped
No shipping evidence
Misdescription
Goods described falsely
Vague or inconsistent product detail
Third-party payments
Unrelated party pays or receives
No clear commercial rationale
TBML Review Clues
Goods inconsistent with customer business.
Unusual shipping route.
Inconsistent invoice, bill of lading, and payment data.
Newly formed companies with high trade volume.
Use of free trade zones without clear need.
Dual-use goods or sanctioned-sector exposure.
Repeated amendments to letters of credit.
Payments from or to unrelated offshore entities.
Suspicious Activity Investigation and Reporting
Investigation Workflow
flowchart TD
A[Alert, referral, subpoena, media hit, or law enforcement request] --> B[Initial triage]
B --> C{Reasonable concern?}
C -- No --> D[Close with documented rationale]
C -- Yes --> E[Gather customer, transaction, CDD, and external information]
E --> F[Analyze against expected activity and typologies]
F --> G{Suspicion remains?}
G -- No --> H[Close; update risk rating if needed]
G -- Yes --> I[Escalate for SAR/STR decision]
I --> J[File/report per applicable rules and preserve confidentiality]
J --> K[Continue monitoring or exit decision]
Notes and examples
Alert vs. Case vs. SAR/STR
Item
Meaning
Key Evidence
Alert
System or manual trigger requiring review
Scenario hit, referral, screening match
Case
Investigative file opened to analyze activity
Narrative, documents, transaction analysis
SAR/STR decision
Determination whether reporting is required/appropriate
Decision memo, approval trail
SAR/STR filing
Report to relevant financial intelligence unit or authority
Filing confirmation, confidentiality controls
Strong Investigation File Characteristics
Characteristic
Practical Standard
Clear issue statement
What triggered the review?
Customer profile comparison
Why is activity normal or unusual for this customer?
Transaction timeline
Shows sequence, amounts, counterparties, and jurisdictions.
“Reviewed 90 days of account activity, CDD profile, wire details, and invoices.”
Expected activity comparison
“Customer is an importer; wires to supplier are consistent with declared business.”
Explanation
“Invoices and shipping documents support purpose and counterparties.”
Decision
“Close as not suspicious; maintain current risk rating.”
Escalation if needed
“Escalate due to unexplained third-party wires and adverse media.”
Unusual vs. Suspicious
Term
Meaning
Required response
Unusual activity
Activity not expected for the customer or peer group
Review, investigate, seek explanation
Suspicious activity
Activity with facts suggesting possible money laundering, terrorism financing, sanctions evasion, fraud, or other crime
Escalate and report as required by law/policy
Exam trap: An alert is not the same as suspicion. Alerts require investigation and disposition.
Investigation Workflow
flowchart TD
A[Alert, referral, subpoena, adverse media, or law enforcement request] --> B[Gather customer profile and expected activity]
B --> C[Review transaction details and counterparties]
C --> D[Compare activity to customer risk and known typologies]
D --> E{Reasonable explanation?}
E -->|Yes| F[Document rationale and close or monitor]
E -->|No or unresolved| G[Escalate to AML compliance / investigations]
G --> H{Suspicion threshold met under policy/law?}
H -->|Yes| I[File required report and maintain confidentiality]
H -->|No| J[Document no-file rationale and consider ongoing monitoring]
I --> K[Consider account restrictions, exit, or enhanced monitoring]
J --> K
Common Suspicious Activity Red Flags
Pattern
Possible concern
Key context to check
Structuring/smurfing
Avoiding reporting or detection thresholds
Repeated cash activity below thresholds; related parties
Jurisdiction-specific requirements vary, but the exam commonly tests these principles:
Escalate internally according to policy.
Do not tip off the customer.
File required reports when the applicable suspicion threshold is met.
Document the facts, analysis, and decision.
Keep reports and related information confidential.
Continue monitoring if the relationship remains open.
Consider whether account restrictions, exit, or enhanced controls are appropriate.
Cooperate with competent authorities through approved legal and internal channels.
FATF-Style Concepts Commonly Tested
Concept
Cheat Sheet
Risk-based approach
Allocate stronger controls to higher risks instead of treating all risk equally.
Customer due diligence
Identify/verify customer and understand relationship purpose.
Beneficial ownership transparency
Identify natural persons who ultimately own/control entities.
Financial intelligence unit
Receives and analyzes suspicious activity reports and related information.
Mutual legal assistance
Cooperation mechanism between jurisdictions for investigations/proceedings.
Targeted financial sanctions
Restrictions directed at designated persons/entities or defined sanctions programs.
Correspondent banking controls
Due diligence on respondent banks and nested/payable-through risks.
New technologies
Assess risks before launching new products, delivery channels, or technology.
DNFBPs
Nonfinancial businesses/professions that can be abused, such as casinos, real estate, dealers in precious metals/stones, lawyers/accountants in certain activities.
High-Yield Vocabulary
Term
Meaning
Predicate offense
Crime that generates proceeds laundered through the financial system.
Smurfing
Use of multiple people or transactions to break up funds.
Structuring
Designing transactions to avoid reporting or detection thresholds.
Funnel account
Account receiving deposits from many locations and moving funds elsewhere.
Mule
Person or account used to move illicit funds, sometimes knowingly, sometimes not.
Nominee
Person/entity acting on behalf of another to hide true control.
Correspondent bank
Bank providing services to another financial institution.
Use these practical rules when answering scenario questions.
If the Scenario Shows a Red Flag
Do not jump straight to “file a report” unless the facts meet the suspicious reporting threshold in the scenario. The usual best answer is often:
Investigate.
Gather context.
Compare to customer profile.
Escalate internally if unresolved.
File/report if suspicion is established under policy and law.
Document the rationale.
If the Customer Is High Risk
High risk usually means apply EDD and monitoring, not automatic rejection. Exit or decline may be appropriate if:
Identity or beneficial ownership cannot be verified.
Activity lacks a lawful or reasonable purpose.
Sanctions or prohibited exposure exists.
Required information is refused.
Risk exceeds the institution’s risk appetite.
The institution cannot manage the risk.
If the Question Mentions Tipping Off
The safe principle is confidentiality. Staff should not tell the customer that a suspicious activity report has been or will be filed. Customer contact, if needed, should be handled carefully and according to policy.
If the Question Mentions Senior Management
Senior management and the board are responsible for oversight, risk appetite, resources, and culture. They do not usually perform day-to-day alert investigations, but they must ensure the program is effective.
If the Question Mentions Audit
Independent audit/testing evaluates the AML program. It should be independent from the activity being tested and should report findings for remediation.
If the Question Mentions “Best Next Step”
Look for the answer that is:
Risk-based.
Documented.
Escalated through proper channels.
Consistent with policy and law.
Protective of confidentiality.
Focused on facts rather than assumptions.
Common Exam Traps
Trap
Correct Approach
Treating high risk as automatically illegal
High risk requires stronger controls, not automatic rejection unless prohibited by law/policy.
Confusing PEP screening with sanctions screening
PEPs require risk-based EDD; sanctions may prohibit or restrict activity.
Assuming small transactions are low risk
Terrorist financing and structuring may involve small amounts.
Equating documentation volume with quality
Evidence must answer identity, ownership, purpose, source, and activity questions.
Forgetting beneficial owners are natural persons
Legal entities may be in the chain, but the goal is ultimate natural-person ownership/control.
Closing alerts without explaining normal activity
A good closure compares activity to expected profile and evidence.
Filing SAR/STR based only on a system alert
Alerts require investigation and judgment.
Ignoring geography in trade finance
Route, origin, destination, transshipment, and end user matter.
Thinking AML is only compliance’s job
First line owns risk; compliance oversees; audit tests.
Overlooking data quality
Bad customer or transaction data undermines screening and monitoring.
Final Review Checklist
Area
Can You Do This Quickly?
AML lifecycle
Distinguish placement, layering, and integration in scenarios.
CFT
Explain why legitimate funds can still create terrorist financing risk.
CDD/EDD
Select standard vs. enhanced due diligence based on risk.
Beneficial ownership
Identify hidden ownership/control red flags.
Sanctions
Distinguish false positive, possible match, and true match escalation.
PEPs
Apply risk-based controls without assuming criminality.
SAR/STR
Describe investigation, decision, filing, and confidentiality steps.
Monitoring
Match typologies to detection scenarios and alert review evidence.
TBML
Spot invoice, goods, route, and counterparty anomalies.
Governance
Explain roles of business, compliance, and audit.
Audit trail
Know what evidence supports a defensible AML decision.
Notes and examples
Rapid Final Review Checklist
Before practice questions, make sure you can explain:
The difference between placement, layering, and integration.
Why terrorist financing can involve legitimate funds.
How inherent risk, controls, and residual risk relate.
The main components of a risk-based AML program.
What CDD is designed to establish.
When EDD is appropriate.
How beneficial ownership differs from legal ownership.
Why PEP status is a risk factor, not an accusation.
The difference between unusual and suspicious activity.
Why tipping off is prohibited or restricted.
How sanctions screening differs from transaction monitoring.
What makes correspondent banking higher risk.
How trade-based money laundering manipulates value.
How virtual assets can be used to layer funds.
What good investigation documentation includes.
How independent testing supports program effectiveness.
Cheat Sheet for CAMS Candidates
This quick review is for candidates preparing for the ACAMS Certified Anti-Money Laundering Specialist (CAMS) exam, code CAMS, offered by ACAMS. Use it to refresh high-yield concepts before moving into topic drills, mock exams, and detailed explanations.
This page is independent review support. It is not affiliated with ACAMS and does not replace the official exam materials, current candidate guidance, or applicable laws and regulations in your jurisdiction.
Notes and examples
High-Yield CAMS Review Map
Area
What to know cold
Common exam trap
Money laundering process
Placement, layering, integration; purpose of each stage
Assuming every laundering scheme shows all three stages clearly
Terrorist financing
Funds may be legal or illegal; focus is support of terrorism
Treating terrorist financing as identical to profit-driven laundering
Risk-based approach
Higher risk gets stronger controls; lower risk may receive simplified controls where allowed
Believing risk-based means “ignore low risk”
Customer due diligence
Identify and verify customers; understand ownership, purpose, expected activity; monitor over time
Treating CDD as a one-time onboarding task
Enhanced due diligence
Applied to higher-risk customers, products, geographies, or behavior
Assuming EDD always means automatic account closure
Beneficial ownership
Identify natural persons who own or control legal entities or arrangements
Stopping at the company name or nominee
PEPs
Politically exposed persons require risk-sensitive review and controls
Assuming all PEPs are criminals or must be rejected
Sanctions screening
List screening, ownership/control issues, escalation, documentation
Confusing AML suspicious activity monitoring with sanctions screening
Transaction monitoring
Detect unusual activity compared with profile, peers, and known typologies
Filing solely because an alert fired without investigation
Suspicious activity reporting
Escalate, document rationale, preserve confidentiality, avoid tipping off
Telling the customer a report was or will be filed
Real estate, luxury goods, investments, loans, business revenue
Source of wealth, asset purchases, inconsistent income
Notes and examples
Exam point: Placement is often easiest to detect because cash enters regulated channels. Layering is often the most complex. Integration gives criminal proceeds an appearance of legitimacy.
Terrorist Financing vs. Money Laundering
Concept
Money laundering
Terrorist financing
Primary objective
Conceal illegal origin and enjoy proceeds
Fund terrorist activity or organizations
Source of funds
Usually criminal proceeds
May be legal, illegal, or mixed
Transaction size
Can be large, complex, or structured
May involve small amounts
Detection challenge
Trace criminal proceeds
Identify purpose, network, destination, and behavior
Key controls
CDD, monitoring, reporting, law enforcement cooperation
Trap: Terrorist financing can involve clean money moving for an illicit purpose. Do not focus only on criminal source.
Proliferation Financing
Proliferation financing involves providing funds or financial services connected to weapons proliferation, restricted goods, sanctioned actors, or prohibited procurement networks. High-yield clues include:
Dual-use goods.
Complex shipping routes.
Front companies.
Sanctioned jurisdictions or entities.
Unusual trade documentation.
Transshipment through high-risk locations.
Payments inconsistent with the stated business.
Customer Due Diligence Cheat Sheet
CDD Objectives
CDD is designed to help the institution know who the customer is, who controls or benefits from the relationship, what activity is expected, and whether activity remains consistent with the customer profile.
CDD component
Purpose
Candidate reminder
Identify the customer
Establish who is seeking the relationship
Includes individuals and legal entities
Verify identity
Use reliable information or documents
Requirements vary by jurisdiction and institution
Understand purpose and nature
Know why the account or service is needed
Expected activity supports monitoring
Identify beneficial owners
Look through legal entities to natural persons
Do not stop at nominees or shell entities
Ongoing monitoring
Compare actual behavior to expected behavior
CDD continues after onboarding
Update information
Refresh when risk or facts change
Triggered by events, reviews, or unusual activity
Notes and examples
Beneficial Ownership
Beneficial ownership focuses on the natural persons who ultimately own, control, or benefit from a legal entity or arrangement.
High-yield points:
Legal ownership and beneficial ownership may differ.
A nominee, trustee, or corporate director may not be the true controller.
Complex structures can be legitimate but require understanding.
Control may exist through ownership, voting rights, management authority, contractual control, or other influence.
If ownership is opaque, the risk is higher and may require escalation.
Enhanced Due Diligence Triggers
EDD is commonly associated with:
PEPs and close associates or family members.
High-risk jurisdictions.
Complex or opaque ownership.
Unusual source of wealth or source of funds.
High-risk products such as private banking, correspondent banking, trade finance, or virtual assets.
Adverse media or criminal allegations.
Activity inconsistent with the customer profile.
Sanctions proximity or heightened geopolitical risk.
EDD may include:
Senior management approval where required by policy or regulation.
More detailed source of funds and source of wealth analysis.
Additional identity, ownership, and control documentation.
More frequent reviews.
Lower thresholds for alerting.
Review of public records, adverse media, litigation, or regulatory history.
Clear documentation of rationale.
Source of Funds vs. Source of Wealth
Concept
Meaning
Example question
Source of funds
Origin of the specific funds used in a transaction or account
Where did this wire deposit come from?
Source of wealth
How the customer accumulated overall wealth
How did this customer become wealthy?
Trap: A bank statement may support source of funds, but it may not explain source of wealth.
PEPs, High-Risk Customers, and Special Customer Types
Politically Exposed Persons
A PEP is a person who holds or has held a prominent public function. Risk can also extend to close family members and close associates.
Key review points:
PEP status is a risk factor, not proof of wrongdoing.
Domestic, foreign, and international organization PEPs may be treated differently depending on law and policy.
Risk depends on role, jurisdiction, access to public funds, corruption risk, products used, and transaction behavior.
EDD often focuses on source of wealth, source of funds, expected activity, and ongoing monitoring.
Notes and examples
High-Risk Customer Types
Customer type
Why risk may be higher
Review focus
Cash-intensive business
Easier to mix illicit cash with legitimate receipts
Cash patterns, revenue reasonableness, tax/business records
Shell company
May obscure ownership or purpose
Beneficial ownership, business rationale, transaction purpose
Trust or legal arrangement
Control and benefit may be separated
Settlor, trustee, protector, beneficiaries, control powers
Money services business
High transaction volume, remittances, agents
Licensing/registration where applicable, agent oversight, monitoring
Nonprofit or charity
Potential diversion or abuse for terrorism financing
Use this quick review as a bridge into independent companion practice. For efficient review, drill these topics separately before taking full mock exams: