ACAMS CAMS Cheat Sheet

Cheat sheet: independent review for ACAMS Certified Anti-Money Laundering Specialist (CAMS) candidates: AML lifecycle, CDD/EDD, sanctions, typologies, investigations, and exam traps.

Use the tables for a quick pre-exam check. Expand a topic’s notes for explanations, examples, and additional distinctions.

Scope and study context
ItemDetail
Vendor/providerACAMS
Official exam titleACAMS Certified Anti-Money Laundering Specialist (CAMS)
Official exam codeCAMS
Page purposeIndependent Cheat Sheet for final review and practice support; not an official ACAMS document.

AML/CFT Core Framework

Money Laundering Lifecycle

StageWhat HappensCommon ExamplesExam Trap
PlacementCriminal proceeds enter the financial systemCash deposits, currency exchange, casino chips, prepaid cards, funnel accountsPlacement is not always cash, but cash-intensive methods are classic.
LayeringTransactions obscure origin, ownership, or audit trailWire transfers, shell companies, trade transactions, crypto mixing, securities tradesLayering is often the most complex stage and may involve legitimate-looking activity.
IntegrationFunds appear legitimate and re-enter economyReal estate, luxury goods, business investment, loans, dividendsIntegration is about apparent legitimacy, not just spending.
Notes and examples

Terrorist Financing vs. Money Laundering

AreaMoney LaunderingTerrorist Financing
Primary concernConcealing proceeds of crimeFunding terrorist activity
Source of fundsUsually illicit, but may be mixedMay be illicit or legitimate
Transaction sizeCan be large or structuredOften small, routine-looking transactions
Direction of analysisFollow proceeds back to predicate crimeFollow funds toward intended use
Key exam distinctionCriminal origin is centralIntended use is central

Proliferation Financing

ConceptCheat Sheet
MeaningFinancing, facilitation, or support connected to weapons of mass destruction proliferation or sanctioned programs.
Common exposure pointsTrade finance, dual-use goods, shipping, correspondent banking, sanctions evasion, front companies.
Key controlsSanctions screening, trade document review, end-user/end-use checks, vessel and routing review, customer due diligence.
Exam trapIt may look like ordinary trade activity; the risk often appears in goods, counterparties, routes, and sanctions connections.

Risk-Based Approach

Risk-Based Program Logic

StepPractical QuestionOutput
Identify riskWho are the customers, products, geographies, channels, and intermediaries?Risk universe
Assess riskWhat is the likelihood and impact of misuse?Inherent risk
Control riskWhat policies, systems, staffing, and monitoring reduce risk?Control design
Test effectivenessAre controls operating as intended?Residual risk
AdjustAre typologies, sanctions, products, or customer profiles changing?Updated program

Inherent vs. Residual Risk

TermMeaningCAMS Exam Clue
Inherent riskRisk before controlsHigh-risk customer, high-risk geography, complex product
Control effectivenessStrength of mitigationCDD, monitoring, sanctions screening, training, audit
Residual riskRisk after controlsWhat management must accept, reduce, or exit

A simple risk model is:

\[ \text{Residual Risk} = \text{Inherent Risk} - \text{Control Effectiveness} \]

Use the formula conceptually. Actual scoring models vary by institution and jurisdiction.

Notes and examples

The Risk-Based Approach

The risk-based approach is central to CAMS. Controls should be proportionate to risk.

Inherent Risk, Controls, and Residual Risk

TermMeaningExample
Inherent riskRisk before controlsPrivate banking for high-net-worth foreign clients
ControlsMeasures used to reduce riskCDD, EDD, screening, monitoring, training
Residual riskRisk remaining after controlsRisk after the firm applies due diligence and monitoring

A practical risk assessment asks:

  1. Who are the customers?
  2. Where are they located or transacting?
  3. What products and services are used?
  4. How are services delivered?
  5. What transaction types and volumes are expected?
  6. What controls exist?
  7. What residual risk remains?

Core Risk Categories

Risk categoryHigher-risk indicatorsControl response
CustomerPEPs, shell companies, cash-intensive businesses, complex ownership, nonresident customers, high-net-worth clients, MSBs, charities/NPOsEDD, ownership verification, source of funds/wealth review
GeographySanctions exposure, corruption, weak AML controls, secrecy jurisdictions, conflict zones, high-crime regionsCountry risk scoring, enhanced review, sanctions controls
Product/serviceWire transfers, correspondent banking, trade finance, prepaid access, private banking, virtual assetsProduct-specific monitoring and limits
ChannelNon-face-to-face onboarding, intermediaries, agents, digital-only activityStrong identity verification, device/IP controls, agent oversight
TransactionUnusual volume, structuring, rapid movement, round-dollar transfers, no business rationaleAlerts, investigation, escalation

Risk-Based Does Not Mean

  • Ignoring low-risk customers.
  • Accepting all high-risk customers.
  • Applying the same controls to everyone.
  • Replacing judgment with a risk score.
  • Treating documentation as optional.

It means the institution uses documented judgment to apply stronger or different controls where the risk is greater.

AML Program Components

ComponentPurposeKey Evidence
Policies and proceduresSet expectations and required stepsAML policy, CDD procedures, escalation playbooks
Designated compliance officer/functionOwns program oversight and escalationRole description, committee reports, issue tracking
TrainingMakes staff able to detect and escalate riskRole-based training records, testing, refreshers
Independent testing/auditChallenges program design and operationAudit reports, remediation plans, validation
Customer due diligenceUnderstand customer identity, activity, and riskKYC files, beneficial ownership, risk ratings
Transaction monitoringDetect unusual or suspicious activityAlerts, cases, scenarios, tuning records
Suspicious activity reportingNotify relevant authority when requiredSAR/STR decision memo, filing record, confidentiality controls
Sanctions screeningPrevent prohibited dealingsScreening logs, alert dispositions, list update controls
RecordkeepingPreserve evidence and audit trailAccount records, transaction records, investigation files
Notes and examples

AML Program Governance

A sound AML program is not just software. It requires governance, accountability, controls, testing, and culture.

Core AML Program Elements

ElementPurposeWhat to remember
Board/senior management oversightSet risk appetite and support complianceTone from the top matters
Policies and proceduresTranslate law and risk appetite into operating rulesMust be practical and kept current
AML compliance officer/functionCoordinates program and escalationNeeds authority, independence, and resources
Risk assessmentIdentifies and measures AML/CFT riskDrives control design
CDD and EDDUnderstand customers and riskOngoing, not one-time
Transaction monitoringDetect unusual and suspicious activityScenarios must match risk
Sanctions screeningPrevent prohibited dealingsRequires quality data and escalation
TrainingHelps staff detect and escalate issuesRole-based training is stronger
Independent testing/auditEvaluates design and effectivenessShould be independent of the process tested
Recordkeeping and reportingPreserves evidence and regulatory complianceDocumentation is critical

Three Lines of Defense

LineTypical roleAML example
First lineOwns and manages risk in the businessRelationship managers collect CDD and identify unusual activity
Second lineOversight, policy, advisory, monitoringAML compliance sets standards and reviews escalations
Third lineIndependent assuranceInternal audit tests AML program effectiveness

Trap: The first line cannot outsource all responsibility to compliance. Business units own the risk they generate.

Independent Testing

Independent testing should assess whether controls are designed well and operating effectively. It may review:

  • Customer risk scoring.
  • CDD and EDD files.
  • Beneficial ownership documentation.
  • Sanctions screening disposition.
  • Transaction monitoring alert quality.
  • Suspicious activity investigations.
  • Reporting timeliness and quality, where applicable.
  • Training completion and relevance.
  • Governance and management information.
  • Prior issue remediation.

CDD, KYC, and EDD

CDD Workflow

    flowchart TD
	    A[Customer onboarding or event trigger] --> B[Identify customer]
	    B --> C[Verify identity using reliable information]
	    C --> D[Identify beneficial owners/controllers where applicable]
	    D --> E[Understand purpose and expected activity]
	    E --> F[Assign customer risk rating]
	    F --> G{Higher risk?}
	    G -- No --> H[Standard monitoring and periodic refresh]
	    G -- Yes --> I[Enhanced due diligence and approval]
	    I --> J[Enhanced monitoring and review]
Notes and examples

CDD Decision Table

SituationStandard CDD FocusEDD Trigger Indicators
Individual customerIdentity, address, occupation/source of funds as relevant, expected activityPEP status, unusual wealth, high-risk geography, adverse media, nominee use
Legal entityLegal existence, ownership/control, business purpose, expected activityComplex ownership, shell indicators, offshore secrecy, bearer-share-like risk, unexplained control structure
Nonprofit/charityPurpose, leadership, funding sources, beneficiaries, geographiesConflict zones, cash-intensive donations, opaque beneficiaries, links to sanctioned regions
Correspondent bankingRespondent bank profile, ownership, license, supervision, AML controlsNested relationships, payable-through access, weak jurisdiction, shell bank concerns
MSB/payment firmLicenses/registration as applicable, agent network, products, AML programHigh cash volume, cross-border remittance corridors, agent control weakness
Private bankingClient identity, source of wealth, source of funds, relationship purposePEP, complex vehicles, secrecy requests, rapid movement of large funds
Trade finance customerNature of trade, goods, counterparties, shipping routesDual-use goods, inconsistent pricing, unusual routes, sanctions exposure
Virtual asset exposureWallet/service provider risk, purpose, source of fundsMixers/tumblers, darknet links, sanctions exposure, chain-hopping

CDD vs. EDD vs. Ongoing Monitoring

ControlWhen UsedMain Question
CDDAt onboarding and refreshDo we know who the customer is and what activity is expected?
EDDHigher-risk customers or situationsDo we have enough additional information to understand and manage elevated risk?
Ongoing monitoringThroughout relationshipIs actual activity consistent with expected activity and risk profile?
Event-driven reviewTriggered by change or red flagHas the customer’s risk materially changed?

Source of Funds vs. Source of Wealth

TermMeaningExample
Source of fundsOrigin of specific funds used in a transaction or relationshipSalary deposit, sale of property, business revenue
Source of wealthOverall origin of customer’s total net worthBusiness ownership, inheritance, investment gains
Exam trapDo not treat a bank statement showing current balance as full source-of-wealth evidence.Balance proves possession, not necessarily origin.

Beneficial Ownership and Control

ConceptCheat Sheet
Beneficial ownerNatural person who ultimately owns or controls a legal entity or arrangement.
Control personPerson with significant responsibility to control, manage, or direct the entity.
NomineePerson listed on paper but acting for another party.
Shell companyEntity with little or no independent operations/assets; can be legitimate or abused.
Shelf companyPre-existing inactive company; risk rises when used to obscure history or ownership.
Front companyOperating business used to disguise illicit activity.
Notes and examples

Beneficial Ownership Red Flags

Red FlagWhy It Matters
Ownership chain includes many entities without clear business reasonMay hide true control.
Entities in secrecy or high-risk jurisdictionsMay limit transparency.
Nominee directors/shareholders appear repeatedlyMay indicate professional concealment.
Customer refuses ownership informationCDD cannot be completed.
Control exercised by someone not listed as ownerHidden beneficial ownership risk.
Frequent ownership changes without rationalePotential layering or sanctions evasion.

Sanctions, PEPs, and Adverse Media

High-Yield Distinctions

TopicMeaningKey ControlExam Trap
SanctionsLegal/economic restrictions against persons, entities, vessels, sectors, or countriesScreening, blocking/rejecting/escalation per applicable rulesSanctions compliance is not the same as AML monitoring, although they overlap.
PEPPolitically exposed person with potential corruption/bribery riskRisk-based EDD and senior review where required by policy/lawPEP status alone does not prove criminal activity.
Adverse mediaNegative public information suggesting financial crime, corruption, fraud, or sanctions riskInvestigation, corroboration, risk-rating updateMedia must be assessed for reliability, relevance, and recency.
Watchlist/internal listInstitution-created list from prior concernsInternal screening and escalationNot the same as an official sanctions list.
Notes and examples

Sanctions Screening Decision Path

    flowchart TD
	    A[Potential match from screening] --> B[Compare identifiers]
	    B --> C{Clearly not same party?}
	    C -- Yes --> D[False positive; document rationale]
	    C -- No --> E{Strong or possible match?}
	    E -- Possible --> F[Escalate for review; gather more identifiers]
	    E -- Strong --> G[Apply hold/block/reject/escalate per policy and applicable law]
	    F --> H[Final disposition and audit trail]
	    G --> H

Screening Quality Factors

FactorWhy It Matters
Data qualityPoor names, dates, addresses, and IDs increase false positives and missed matches.
List updatesScreening must reflect current applicable lists and internal rules.
Fuzzy matchingHelps identify spelling variations but can increase alert volume.
TransliterationNames may appear differently across alphabets and systems.
Alert documentationReviewers must show why an alert was cleared or escalated.
Payment screening timingScreening too late can allow prohibited activity to proceed.

Sanctions and Screening

Sanctions compliance and AML monitoring are related but not the same.

TopicAML suspicious activity monitoringSanctions screening
Main questionIs activity suspicious or inconsistent?Is there a prohibited or restricted party, country, vessel, good, or interest?
TimingOften ongoing and post-transaction, depending on productOften at onboarding and before/around transaction processing
OutputAlert, investigation, possible reportHit disposition, block/reject/escalate per law and policy
EvidenceCustomer profile, behavior, typologiesList match, ownership/control, identifiers
Main riskFacilitating laundering or financial crimeDealing with sanctioned parties or prohibited activity

Screening Match Review

A screening match is not automatically a true hit. Review:

  • Name similarity and aliases.
  • Date of birth or incorporation.
  • Address and nationality.
  • Identification numbers.
  • Ownership and control.
  • Vessel, aircraft, wallet, or other identifiers.
  • Transaction counterparties and intermediaries.
  • Geographic links.
  • Quality of data and transliteration issues.

Sanctions Evasion Red Flags

  • Use of shell or front companies.
  • Sudden changes in trade routes.
  • Vague goods descriptions.
  • Payments routed through unrelated third parties.
  • Use of intermediaries in high-risk jurisdictions.
  • Ownership changes shortly before transactions.
  • Avoidance of obvious references in payment messages.
  • IP, shipping, or documentation inconsistencies.
  • Links to dual-use goods or restricted sectors.

Customer and Product Risk Matrix

Risk CategoryLower-Risk IndicatorsHigher-Risk Indicators
Customer typeSalaried individual, transparent ownership, local operating businessPEP, cash-intensive business, offshore vehicle, shell company, MSB, arms-related business
GeographyStrong AML supervision, transparent registries, low corruptionSanctioned/high-risk regions, secrecy jurisdictions, conflict zones, corruption exposure
Product/serviceLow-value, traceable, limited transferabilityPrivate banking, correspondent banking, trade finance, prepaid access, virtual assets
Delivery channelFace-to-face onboarding, verified documentsNon-face-to-face onboarding, intermediaries, agents, remote-only relationship
Transaction behaviorConsistent with profile, documented purposeRapid movement, no economic rationale, unusual counterparties, structuring
OwnershipClear natural-person ownership/controlLayered entities, nominee arrangements, trusts without clear rationale
Source of fundsVerifiable salary/business revenueCash, third-party funding, unexplained wealth, high-risk counterparties

Typologies and Red Flags

Cash and Structuring

Red FlagPossible Concern
Multiple cash deposits below reporting or internal review thresholdsStructuring/smurfing
Cash activity inconsistent with business typePlacement of illicit proceeds
Deposits at many branches or ATMs into one accountFunnel account activity
Rapid cash deposit followed by wire outPlacement followed by layering
Customer nervous or coached during transactionPossible third-party control
Notes and examples

Wire Transfers and Correspondent Banking

Red FlagPossible Concern
Wires to/from high-risk jurisdictions without business reasonLayering, sanctions evasion, fraud
Funds pass through account quickly with little retentionPass-through activity
Same-day incoming and outgoing wires in similar amountsLayering
Payment details vague or inconsistentConcealment of purpose
Nested correspondent activity not disclosedHidden respondent/customer risk
Use of shell banks or unregulated institutionsSevere AML and sanctions risk

Trade-Based Money Laundering

Red FlagPossible Concern
Over- or under-invoicingValue transfer outside normal payment channels
Multiple invoices for same goodsDuplicate financing or laundering
Goods inconsistent with customer businessFalse trade activity
Unusual shipping route or transshipmentSanctions evasion or concealment
Phantom shipments or vague goods descriptionsFabricated trade
Price inconsistent with marketValue manipulation
Dual-use goods with high-risk end userProliferation financing risk

Securities, Insurance, and Investment Products

Red FlagPossible Concern
Early surrender of policy despite penaltiesLaundering through insurance product
Third-party premium paymentsHidden source of funds
Securities trades with no apparent investment rationaleLayering
Wash-like activity or offsetting tradesCreating artificial movement/value
Rapid liquidation after fundingIntegration or fraud proceeds
Funds from unrelated jurisdictionsConcealed beneficial owner or source

Real Estate and High-Value Assets

Red FlagPossible Concern
Purchase through complex entities without clear rationaleBeneficial ownership concealment
All-cash purchase by high-risk customerIntegration
Use of nominee buyerHidden owner
Price materially above/below marketValue transfer
Rapid resale without economic reasonLayering/integration
Third-party funding or repaymentHidden source of funds

Virtual Assets

Red FlagPossible Concern
Use of mixers/tumblersObscuring origin or destination
Darknet marketplace exposureCriminal proceeds
Chain-hopping across assetsLayering
Transfers involving sanctioned wallet/serviceSanctions breach risk
Rapid in/out movement with no stated purposePass-through activity
Privacy-enhancing coins or anonymity toolsIncreased traceability risk

Correspondent Banking

Correspondent banking allows one financial institution to provide services to another, often across borders. It is high risk because the correspondent may have limited visibility into the respondent bank’s customers.

Key Risks

  • Nested relationships.
  • Payable-through accounts.
  • Weak respondent AML controls.
  • High-risk jurisdictions.
  • Shell banks.
  • Poor transparency over originators and beneficiaries.
  • Sanctions exposure.

Due Diligence Focus

QuestionWhy it matters
Who owns and controls the respondent bank?Ownership may create sanctions, corruption, or secrecy risk
Where is it licensed and supervised?Regulatory quality affects risk
What is its customer base?Indirect exposure can be significant
What AML controls does it have?Correspondent relies partly on respondent controls
Does it permit nested access?Hidden third-party banks increase risk
Are payable-through services offered?Customers may transact directly through correspondent account
What geographies and products are involved?Drives EDD and monitoring

Trap: A correspondent bank must understand the respondent relationship; it usually cannot identify every underlying customer in normal correspondent activity, but it must manage the risk appropriately.

Trade-Based Money Laundering

Trade-based money laundering uses trade transactions to move value and disguise proceeds.

Common TBML Methods

MethodDescriptionRed flags
Over-invoicingPrice is inflated to move extra valuePrice inconsistent with market
Under-invoicingPrice is reduced to shift value to buyerUnusually low declared value
Multiple invoicingSame goods invoiced multiple timesDuplicate documents or financing
Over/under-shipmentQuantity differs from documentationWeight or volume mismatch
Phantom shipmentDocuments show goods that were not shippedNo shipping evidence
MisdescriptionGoods described falselyVague or inconsistent product detail
Third-party paymentsUnrelated party pays or receivesNo clear commercial rationale

TBML Review Clues

  • Goods inconsistent with customer business.
  • Unusual shipping route.
  • Inconsistent invoice, bill of lading, and payment data.
  • Newly formed companies with high trade volume.
  • Use of free trade zones without clear need.
  • Dual-use goods or sanctioned-sector exposure.
  • Repeated amendments to letters of credit.
  • Payments from or to unrelated offshore entities.

Suspicious Activity Investigation and Reporting

Investigation Workflow

    flowchart TD
	    A[Alert, referral, subpoena, media hit, or law enforcement request] --> B[Initial triage]
	    B --> C{Reasonable concern?}
	    C -- No --> D[Close with documented rationale]
	    C -- Yes --> E[Gather customer, transaction, CDD, and external information]
	    E --> F[Analyze against expected activity and typologies]
	    F --> G{Suspicion remains?}
	    G -- No --> H[Close; update risk rating if needed]
	    G -- Yes --> I[Escalate for SAR/STR decision]
	    I --> J[File/report per applicable rules and preserve confidentiality]
	    J --> K[Continue monitoring or exit decision]
Notes and examples

Alert vs. Case vs. SAR/STR

ItemMeaningKey Evidence
AlertSystem or manual trigger requiring reviewScenario hit, referral, screening match
CaseInvestigative file opened to analyze activityNarrative, documents, transaction analysis
SAR/STR decisionDetermination whether reporting is required/appropriateDecision memo, approval trail
SAR/STR filingReport to relevant financial intelligence unit or authorityFiling confirmation, confidentiality controls

Strong Investigation File Characteristics

CharacteristicPractical Standard
Clear issue statementWhat triggered the review?
Customer profile comparisonWhy is activity normal or unusual for this customer?
Transaction timelineShows sequence, amounts, counterparties, and jurisdictions.
Evidence retainedCDD, statements, wires, invoices, media, screening results.
Typology linkageExplains why activity resembles laundering, fraud, sanctions evasion, etc.
Decision rationaleSupports filing or no-filing decision.
ConfidentialityAvoids improper disclosure to the customer or unauthorized parties.

SAR/STR Narrative Checklist

IncludeAvoid
Who is involvedUnsupported accusations
What happenedGeneric boilerplate only
When activity occurredIrrelevant background
Where funds movedUnexplained acronyms
Why activity is suspiciousConclusions without facts
How activity was conductedRevealing reporting to customer

Tipping Off and Confidentiality

ConceptPractical Meaning
Tipping offImproperly informing a customer or third party that a suspicious activity report/investigation exists or may be filed.
Safe staff responseAsk ordinary business questions needed for CDD or transaction clarification without revealing suspicion.
Internal sharingShare on a need-to-know basis under policy and applicable law.
Exam trapRefusing to ask any customer questions can weaken investigations; the issue is revealing the report/investigation, not routine inquiry.

Law Enforcement, Regulators, and Information Requests

Request TypeAML Team Response
Regulator examinationProvide records, program documentation, testing results, remediation evidence.
Law enforcement inquiryFollow legal process and internal escalation; preserve confidentiality.
Subpoena/court orderRoute to legal/compliance; produce responsive records as required.
Search warrantContact legal/compliance immediately; do not obstruct authorized search.
Informal requestVerify authority and follow policy before disclosure.
Account closure requestConsider legal, law enforcement, risk, and operational impacts before exiting.

Internal Controls, Audit, and Governance

Three Lines Model

LineTypical RoleAML/CFT Responsibility
First lineBusiness operations, relationship managers, branch/payment staffOwn customer risk, perform procedures, escalate red flags.
Second lineCompliance, financial crime risk, sanctions teamSet policy, advise, monitor, investigate, report.
Third lineInternal audit/independent testingIndependently evaluate design and effectiveness.
Notes and examples

Governance Evidence

EvidenceWhy It Matters
Board/senior management reportingShows oversight of AML risk and issues.
Risk assessment methodologyDemonstrates structured risk-based approach.
Issue trackingShows deficiencies are identified, owned, and remediated.
Model/scenario tuning recordsSupports monitoring effectiveness.
Training completion and role mappingShows staff receive relevant AML instruction.
Independent audit reportsConfirms challenge and validation.

Common Control Weaknesses

WeaknessRisk
Incomplete CDD filesCustomer risk cannot be understood.
Unreviewed transaction monitoring alertsSuspicious activity may not be escalated.
Poor data qualityScreening and monitoring fail.
Overreliance on manual controlsInconsistent outcomes and weak audit trail.
No documented rationale for decisionsRegulators/auditors cannot validate judgment.
Stale risk assessmentProgram no longer reflects current risk.
Training not role-specificStaff miss risks relevant to their function.

Transaction Monitoring

Monitoring Scenario Reference

ScenarioDetectsTuning Considerations
Cash structuringMultiple smaller cash transactionsCustomer type, cash norms, aggregation logic
Rapid movementFunds quickly enter and leaveTime window, percentage of funds moved
High-risk geographyActivity involving risky jurisdictionsCountry risk list, customer business rationale
Dormant account reactivationSudden activity after inactivityDormancy period, activity size
Round-dollar transactionsPatterned or artificial activityProduct type, customer profile
Unusual counterpartiesNew or unrelated payeesRelationship history, geography, occupation/business
Trade anomaliesInconsistent invoices or routesGoods type, pricing, shipping data
Virtual asset exposureTransfers to/from VASPs or walletsBlockchain analytics, sanctions indicators
Notes and examples

Good Alert Disposition

Required ElementExample of Strong Rationale
Facts reviewed“Reviewed 90 days of account activity, CDD profile, wire details, and invoices.”
Expected activity comparison“Customer is an importer; wires to supplier are consistent with declared business.”
Explanation“Invoices and shipping documents support purpose and counterparties.”
Decision“Close as not suspicious; maintain current risk rating.”
Escalation if needed“Escalate due to unexplained third-party wires and adverse media.”

Unusual vs. Suspicious

TermMeaningRequired response
Unusual activityActivity not expected for the customer or peer groupReview, investigate, seek explanation
Suspicious activityActivity with facts suggesting possible money laundering, terrorism financing, sanctions evasion, fraud, or other crimeEscalate and report as required by law/policy

Exam trap: An alert is not the same as suspicion. Alerts require investigation and disposition.

Investigation Workflow

    flowchart TD
	    A[Alert, referral, subpoena, adverse media, or law enforcement request] --> B[Gather customer profile and expected activity]
	    B --> C[Review transaction details and counterparties]
	    C --> D[Compare activity to customer risk and known typologies]
	    D --> E{Reasonable explanation?}
	    E -->|Yes| F[Document rationale and close or monitor]
	    E -->|No or unresolved| G[Escalate to AML compliance / investigations]
	    G --> H{Suspicion threshold met under policy/law?}
	    H -->|Yes| I[File required report and maintain confidentiality]
	    H -->|No| J[Document no-file rationale and consider ongoing monitoring]
	    I --> K[Consider account restrictions, exit, or enhanced monitoring]
	    J --> K

Common Suspicious Activity Red Flags

PatternPossible concernKey context to check
Structuring/smurfingAvoiding reporting or detection thresholdsRepeated cash activity below thresholds; related parties
Rapid in-and-out movementLayering or pass-through activityNo business purpose; funds leave quickly
Round-dollar wiresPossible scripted or noncommercial transfersCustomer type and transaction history
Third-party paymentsConcealed beneficial ownership or fraudRelationship among parties
Unusual cash depositsPlacement of illicit proceedsBusiness model and cash revenue
Dormant account reactivationAccount takeover or launderingCustomer contact, source of new funds
Multiple accounts with similar activityNetwork behaviorShared addresses, phones, IPs, signers
High-risk geography movementSanctions, corruption, trafficking, terrorism financingCounterparty, goods, purpose
Inconsistent occupation/incomeFalse profile or mule activityPayroll, tax, employment, account use
Use of funnel accountsGeographic layeringDeposits in many locations, withdrawals elsewhere

Suspicious Activity Reporting Principles

Jurisdiction-specific requirements vary, but the exam commonly tests these principles:

  • Escalate internally according to policy.
  • Do not tip off the customer.
  • File required reports when the applicable suspicion threshold is met.
  • Document the facts, analysis, and decision.
  • Keep reports and related information confidential.
  • Continue monitoring if the relationship remains open.
  • Consider whether account restrictions, exit, or enhanced controls are appropriate.
  • Cooperate with competent authorities through approved legal and internal channels.

FATF-Style Concepts Commonly Tested

ConceptCheat Sheet
Risk-based approachAllocate stronger controls to higher risks instead of treating all risk equally.
Customer due diligenceIdentify/verify customer and understand relationship purpose.
Beneficial ownership transparencyIdentify natural persons who ultimately own/control entities.
Financial intelligence unitReceives and analyzes suspicious activity reports and related information.
Mutual legal assistanceCooperation mechanism between jurisdictions for investigations/proceedings.
Targeted financial sanctionsRestrictions directed at designated persons/entities or defined sanctions programs.
Correspondent banking controlsDue diligence on respondent banks and nested/payable-through risks.
New technologiesAssess risks before launching new products, delivery channels, or technology.
DNFBPsNonfinancial businesses/professions that can be abused, such as casinos, real estate, dealers in precious metals/stones, lawyers/accountants in certain activities.

High-Yield Vocabulary

TermMeaning
Predicate offenseCrime that generates proceeds laundered through the financial system.
SmurfingUse of multiple people or transactions to break up funds.
StructuringDesigning transactions to avoid reporting or detection thresholds.
Funnel accountAccount receiving deposits from many locations and moving funds elsewhere.
MulePerson or account used to move illicit funds, sometimes knowingly, sometimes not.
NomineePerson/entity acting on behalf of another to hide true control.
Correspondent bankBank providing services to another financial institution.
Respondent bankFinancial institution receiving correspondent services.
Payable-through accountAccount allowing respondent’s customers direct or indirect access through correspondent relationship.
Nested relationshipRespondent bank provides access to other institutions through its correspondent account.
Shell bankBank with no physical presence and not affiliated with a regulated financial group.
Front companyBusiness used to commingle or disguise illicit proceeds.
GatekeeperProfessional or intermediary who may facilitate access to financial system.
PEPPerson with prominent public function, plus risk-relevant associates/family depending on policy/law.
De-riskingExiting or restricting categories of customers rather than managing risk individually.
False positiveScreening/monitoring hit that is not a true match or not suspicious after review.
False negativeMissed risk event that should have been detected.
TypologyPattern or method used to launder money or finance illicit activity.
Adverse mediaNegative information relevant to customer or counterparty risk.

Scenario Decision Rules

If the Question Says…Think…Likely Best Action
Customer refuses to provide required CDDCannot understand/manage riskDo not onboard or escalate/exit per policy.
Activity is unusual but explainable with documentsNot automatically suspiciousDocument review and rationale; update risk if needed.
PEP with legitimate transparent source of wealthHigher risk, not prohibited by defaultApply risk-based EDD and approvals.
Possible sanctions matchMust not casually clearEscalate and compare identifiers; act under policy/law.
Employee suspects SAR/STR may be neededConfidentiality mattersEscalate internally; do not tell customer.
Law enforcement asks to keep account openRisk and legal coordination neededEscalate to legal/compliance; document decision.
Monitoring model produces too many poor alertsControl effectiveness issueTune, validate, improve data/scenarios.
Complex entity has no clear business purposeBeneficial ownership concernObtain more information; consider EDD/escalation.
Trade documents conflict with payment detailsTBML concernInvestigate invoices, goods, route, counterparties.
High-risk customer has weak CDD fileProgram deficiencyRemediate CDD before relying on monitoring alone.
Notes and examples

Exam Decision Rules

Use these practical rules when answering scenario questions.

If the Scenario Shows a Red Flag

Do not jump straight to “file a report” unless the facts meet the suspicious reporting threshold in the scenario. The usual best answer is often:

  1. Investigate.
  2. Gather context.
  3. Compare to customer profile.
  4. Escalate internally if unresolved.
  5. File/report if suspicion is established under policy and law.
  6. Document the rationale.

If the Customer Is High Risk

High risk usually means apply EDD and monitoring, not automatic rejection. Exit or decline may be appropriate if:

  • Identity or beneficial ownership cannot be verified.
  • Activity lacks a lawful or reasonable purpose.
  • Sanctions or prohibited exposure exists.
  • Required information is refused.
  • Risk exceeds the institution’s risk appetite.
  • The institution cannot manage the risk.

If the Question Mentions Tipping Off

The safe principle is confidentiality. Staff should not tell the customer that a suspicious activity report has been or will be filed. Customer contact, if needed, should be handled carefully and according to policy.

If the Question Mentions Senior Management

Senior management and the board are responsible for oversight, risk appetite, resources, and culture. They do not usually perform day-to-day alert investigations, but they must ensure the program is effective.

If the Question Mentions Audit

Independent audit/testing evaluates the AML program. It should be independent from the activity being tested and should report findings for remediation.

If the Question Mentions “Best Next Step”

Look for the answer that is:

  • Risk-based.
  • Documented.
  • Escalated through proper channels.
  • Consistent with policy and law.
  • Protective of confidentiality.
  • Focused on facts rather than assumptions.

Common Exam Traps

TrapCorrect Approach
Treating high risk as automatically illegalHigh risk requires stronger controls, not automatic rejection unless prohibited by law/policy.
Confusing PEP screening with sanctions screeningPEPs require risk-based EDD; sanctions may prohibit or restrict activity.
Assuming small transactions are low riskTerrorist financing and structuring may involve small amounts.
Equating documentation volume with qualityEvidence must answer identity, ownership, purpose, source, and activity questions.
Forgetting beneficial owners are natural personsLegal entities may be in the chain, but the goal is ultimate natural-person ownership/control.
Closing alerts without explaining normal activityA good closure compares activity to expected profile and evidence.
Filing SAR/STR based only on a system alertAlerts require investigation and judgment.
Ignoring geography in trade financeRoute, origin, destination, transshipment, and end user matter.
Thinking AML is only compliance’s jobFirst line owns risk; compliance oversees; audit tests.
Overlooking data qualityBad customer or transaction data undermines screening and monitoring.

Final Review Checklist

AreaCan You Do This Quickly?
AML lifecycleDistinguish placement, layering, and integration in scenarios.
CFTExplain why legitimate funds can still create terrorist financing risk.
CDD/EDDSelect standard vs. enhanced due diligence based on risk.
Beneficial ownershipIdentify hidden ownership/control red flags.
SanctionsDistinguish false positive, possible match, and true match escalation.
PEPsApply risk-based controls without assuming criminality.
SAR/STRDescribe investigation, decision, filing, and confidentiality steps.
MonitoringMatch typologies to detection scenarios and alert review evidence.
TBMLSpot invoice, goods, route, and counterparty anomalies.
GovernanceExplain roles of business, compliance, and audit.
Audit trailKnow what evidence supports a defensible AML decision.
Notes and examples

Rapid Final Review Checklist

Before practice questions, make sure you can explain:

  • The difference between placement, layering, and integration.
  • Why terrorist financing can involve legitimate funds.
  • How inherent risk, controls, and residual risk relate.
  • The main components of a risk-based AML program.
  • What CDD is designed to establish.
  • When EDD is appropriate.
  • How beneficial ownership differs from legal ownership.
  • Why PEP status is a risk factor, not an accusation.
  • The difference between unusual and suspicious activity.
  • Why tipping off is prohibited or restricted.
  • How sanctions screening differs from transaction monitoring.
  • What makes correspondent banking higher risk.
  • How trade-based money laundering manipulates value.
  • How virtual assets can be used to layer funds.
  • What good investigation documentation includes.
  • How independent testing supports program effectiveness.

Cheat Sheet for CAMS Candidates

This quick review is for candidates preparing for the ACAMS Certified Anti-Money Laundering Specialist (CAMS) exam, code CAMS, offered by ACAMS. Use it to refresh high-yield concepts before moving into topic drills, mock exams, and detailed explanations.

This page is independent review support. It is not affiliated with ACAMS and does not replace the official exam materials, current candidate guidance, or applicable laws and regulations in your jurisdiction.

Notes and examples

High-Yield CAMS Review Map

AreaWhat to know coldCommon exam trap
Money laundering processPlacement, layering, integration; purpose of each stageAssuming every laundering scheme shows all three stages clearly
Terrorist financingFunds may be legal or illegal; focus is support of terrorismTreating terrorist financing as identical to profit-driven laundering
Risk-based approachHigher risk gets stronger controls; lower risk may receive simplified controls where allowedBelieving risk-based means “ignore low risk”
Customer due diligenceIdentify and verify customers; understand ownership, purpose, expected activity; monitor over timeTreating CDD as a one-time onboarding task
Enhanced due diligenceApplied to higher-risk customers, products, geographies, or behaviorAssuming EDD always means automatic account closure
Beneficial ownershipIdentify natural persons who own or control legal entities or arrangementsStopping at the company name or nominee
PEPsPolitically exposed persons require risk-sensitive review and controlsAssuming all PEPs are criminals or must be rejected
Sanctions screeningList screening, ownership/control issues, escalation, documentationConfusing AML suspicious activity monitoring with sanctions screening
Transaction monitoringDetect unusual activity compared with profile, peers, and known typologiesFiling solely because an alert fired without investigation
Suspicious activity reportingEscalate, document rationale, preserve confidentiality, avoid tipping offTelling the customer a report was or will be filed
AML governanceBoard/senior management oversight, compliance function, training, independent testingThinking compliance alone “owns” all AML risk
InvestigationsGather facts, analyze context, decide, document, escalate/report as requiredIgnoring negative findings because customer is profitable

Common CAMS Candidate Mistakes

MistakeBetter approach
Memorizing definitions without applying themPractice scenario-based questions and explain the decision
Treating every red flag as proof of crimeRed flags require investigation and context
Confusing CDD, EDD, and monitoringCDD identifies and understands; EDD deepens review; monitoring tests activity over time
Assuming PEPs must be rejectedPEPs require risk assessment and often EDD
Ignoring beneficial ownershipAlways look for natural persons who own or control
Equating sanctions hits with AML alertsSanctions hits require list-match analysis and legal/policy action
Forgetting terrorist financing can use legal fundsFocus on destination, network, and purpose
Missing the role of documentationA decision is only defensible if documented
Choosing “close account” too quicklyInvestigate, escalate, and consider legal/reporting implications
Overlooking the first line of defenseBusiness units own customer and product risk

Core AML, CFT, and CPF Concepts

Money Laundering Stages

StageGoalTypical activityDetection focus
PlacementIntroduce illicit value into the financial systemCash deposits, casino activity, money services, purchases of monetary instrumentsCash activity, structuring, unusual source of funds
LayeringObscure origin, ownership, or audit trailMultiple transfers, shell companies, cross-border movement, crypto hops, trade manipulationComplex movement without clear business purpose
IntegrationReintroduce funds as apparently legitimateReal estate, luxury goods, investments, loans, business revenueSource of wealth, asset purchases, inconsistent income
Notes and examples

Exam point: Placement is often easiest to detect because cash enters regulated channels. Layering is often the most complex. Integration gives criminal proceeds an appearance of legitimacy.

Terrorist Financing vs. Money Laundering

ConceptMoney launderingTerrorist financing
Primary objectiveConceal illegal origin and enjoy proceedsFund terrorist activity or organizations
Source of fundsUsually criminal proceedsMay be legal, illegal, or mixed
Transaction sizeCan be large, complex, or structuredMay involve small amounts
Detection challengeTrace criminal proceedsIdentify purpose, network, destination, and behavior
Key controlsCDD, monitoring, reporting, law enforcement cooperationCDD, sanctions, watchlists, monitoring, nonprofit/charity controls

Trap: Terrorist financing can involve clean money moving for an illicit purpose. Do not focus only on criminal source.

Proliferation Financing

Proliferation financing involves providing funds or financial services connected to weapons proliferation, restricted goods, sanctioned actors, or prohibited procurement networks. High-yield clues include:

  • Dual-use goods.
  • Complex shipping routes.
  • Front companies.
  • Sanctioned jurisdictions or entities.
  • Unusual trade documentation.
  • Transshipment through high-risk locations.
  • Payments inconsistent with the stated business.

Customer Due Diligence Cheat Sheet

CDD Objectives

CDD is designed to help the institution know who the customer is, who controls or benefits from the relationship, what activity is expected, and whether activity remains consistent with the customer profile.

CDD componentPurposeCandidate reminder
Identify the customerEstablish who is seeking the relationshipIncludes individuals and legal entities
Verify identityUse reliable information or documentsRequirements vary by jurisdiction and institution
Understand purpose and natureKnow why the account or service is neededExpected activity supports monitoring
Identify beneficial ownersLook through legal entities to natural personsDo not stop at nominees or shell entities
Ongoing monitoringCompare actual behavior to expected behaviorCDD continues after onboarding
Update informationRefresh when risk or facts changeTriggered by events, reviews, or unusual activity
Notes and examples

Beneficial Ownership

Beneficial ownership focuses on the natural persons who ultimately own, control, or benefit from a legal entity or arrangement.

High-yield points:

  • Legal ownership and beneficial ownership may differ.
  • A nominee, trustee, or corporate director may not be the true controller.
  • Complex structures can be legitimate but require understanding.
  • Control may exist through ownership, voting rights, management authority, contractual control, or other influence.
  • If ownership is opaque, the risk is higher and may require escalation.

Enhanced Due Diligence Triggers

EDD is commonly associated with:

  • PEPs and close associates or family members.
  • High-risk jurisdictions.
  • Complex or opaque ownership.
  • Unusual source of wealth or source of funds.
  • High-risk products such as private banking, correspondent banking, trade finance, or virtual assets.
  • Adverse media or criminal allegations.
  • Activity inconsistent with the customer profile.
  • Sanctions proximity or heightened geopolitical risk.

EDD may include:

  • Senior management approval where required by policy or regulation.
  • More detailed source of funds and source of wealth analysis.
  • Additional identity, ownership, and control documentation.
  • More frequent reviews.
  • Lower thresholds for alerting.
  • Review of public records, adverse media, litigation, or regulatory history.
  • Clear documentation of rationale.

Source of Funds vs. Source of Wealth

ConceptMeaningExample question
Source of fundsOrigin of the specific funds used in a transaction or accountWhere did this wire deposit come from?
Source of wealthHow the customer accumulated overall wealthHow did this customer become wealthy?

Trap: A bank statement may support source of funds, but it may not explain source of wealth.

PEPs, High-Risk Customers, and Special Customer Types

Politically Exposed Persons

A PEP is a person who holds or has held a prominent public function. Risk can also extend to close family members and close associates.

Key review points:

  • PEP status is a risk factor, not proof of wrongdoing.
  • Domestic, foreign, and international organization PEPs may be treated differently depending on law and policy.
  • Risk depends on role, jurisdiction, access to public funds, corruption risk, products used, and transaction behavior.
  • EDD often focuses on source of wealth, source of funds, expected activity, and ongoing monitoring.
Notes and examples

High-Risk Customer Types

Customer typeWhy risk may be higherReview focus
Cash-intensive businessEasier to mix illicit cash with legitimate receiptsCash patterns, revenue reasonableness, tax/business records
Shell companyMay obscure ownership or purposeBeneficial ownership, business rationale, transaction purpose
Trust or legal arrangementControl and benefit may be separatedSettlor, trustee, protector, beneficiaries, control powers
Money services businessHigh transaction volume, remittances, agentsLicensing/registration where applicable, agent oversight, monitoring
Nonprofit or charityPotential diversion or abuse for terrorism financingPurpose, beneficiaries, geography, governance, payments
Private banking clientHigh value, complex services, confidentiality expectationsSource of wealth, PEP/adverse media, complex structures
Correspondent banking customerIndirect access to foreign bank customersRespondent bank AML controls, payable-through risk
Virtual asset businessSpeed, pseudonymity, cross-border movementWallet exposure, blockchain analytics, sanctions risk

International AML Standards and Bodies

FATF Concepts

The Financial Action Task Force, often referenced in AML study, is central to international AML/CFT/CPF standards.

ConceptWhy it matters
FATF RecommendationsGlobal framework for AML/CFT/CPF controls
Risk-based approachCountries and institutions should identify, assess, and mitigate risk
Mutual evaluationsAssess national AML/CFT systems
High-risk and monitored jurisdictionsAffect geographic risk assessment
Beneficial ownership transparencyHelps prevent misuse of legal persons and arrangements
Targeted financial sanctionsSupports counter-terrorism and counter-proliferation controls
FIUsReceive and analyze suspicious transaction/activity reports
Notes and examples

Other Commonly Tested Concepts

Concept/bodyReview point
Financial Intelligence UnitNational center for receiving and analyzing suspicious reports
Egmont GroupNetwork for cooperation among FIUs
Basel CommitteeBanking supervision standards and risk management principles
Wolfsberg GroupIndustry guidance, especially for correspondent banking and financial crime controls
UN sanctionsInternational sanctions measures implemented through national systems
Mutual legal assistanceFormal cooperation between jurisdictions in investigations
Regulatory supervisionExaminers assess program adequacy and compliance

Virtual Assets and Emerging Payment Risk

Virtual assets are high-yield because they combine speed, cross-border reach, pseudonymity, and evolving regulation.

Key Concepts

TermReview point
Virtual assetDigital representation of value that can be transferred or used for payment/investment
VASPBusiness providing virtual asset services, depending on local definitions
WalletAddress or tool used to hold/send/receive virtual assets
Hosted walletCustodian controls or manages access
Unhosted walletUser controls wallet directly
Blockchain analyticsHelps identify exposure to illicit wallets, mixers, darknet markets, sanctions, scams
Mixer/tumblerObscures transaction trail
Chain hoppingMoving value across different cryptoassets or blockchains
Notes and examples

Virtual Asset Red Flags

  • Exposure to darknet markets, ransomware wallets, scams, or sanctioned wallets.
  • Use of mixers or privacy-enhancing services without clear rationale.
  • Rapid conversion from fiat to crypto and out again.
  • Multiple wallets controlled by the same customer without business purpose.
  • Activity inconsistent with customer age, occupation, or wealth.
  • IP addresses, device data, or geolocation inconsistent with profile.
  • Structuring deposits to buy virtual assets.
  • Use of high-risk exchanges or weakly controlled platforms.

Investigation and Evidence Handling

Strong Investigation Habits

StepWhat good looks like
Define the issueIdentify why the alert or referral matters
Collect factsCustomer profile, account history, transaction details, counterparties
Analyze contextCompare activity to expected behavior and known typologies
Seek explanationUse available records and approved customer contact procedures
Review negative informationAdverse media, sanctions proximity, law enforcement requests
DecideClose, monitor, escalate, restrict, or report
DocumentFacts, reasoning, evidence, decision-maker, date
Protect confidentialityLimit access and avoid tipping off

Quality Documentation

Good documentation answers:

  • What happened?
  • Why was it unusual?
  • What facts were reviewed?
  • What explanation was found?
  • Why was the activity considered suspicious or not suspicious?
  • Who approved the decision?
  • What follow-up action is required?

Trap: A conclusion without reasoning is weak. “No suspicious activity found” is not enough unless the file explains why.

Common AML Typologies

TypologyTypical indicatorsControl focus
Drug trafficking proceedsCash deposits, structuring, funnel accounts, high-risk locationsCash monitoring, geographic analysis
Human traffickingMultiple hotel/transport payments, payroll anomalies, third-party control, unusual cashBehavioral patterns, victim indicators
Corruption/briberyPEP links, consulting fees, government contract payments, offshore entitiesPEP EDD, source of wealth, third-party payments
Fraud/scamsIncoming victim payments, rapid withdrawals, mule accountsAccount behavior, complaints, law enforcement requests
Tax evasionOffshore structures, undeclared income patterns, nominee ownershipBeneficial ownership and source of funds
Sanctions evasionFront companies, trade route changes, vague payment messagesScreening, ownership/control, trade review
Terrorist financingSmall transfers, high-risk regions, NPO abuse, network linksCFT monitoring, sanctions, charity due diligence
Cybercrime/ransomwareCrypto flows, exchanges, mixers, darknet linksBlockchain analytics, VASP controls
Trade-based launderingInvoice manipulation, unusual goods/routes, third-party paymentsTrade document review and pricing checks

Practice-Ready Topic Drills

Use this quick review as a bridge into independent companion practice. For efficient review, drill these topics separately before taking full mock exams:

  1. AML/CFT fundamentals: stages, terrorist financing, proliferation financing.
  2. Risk-based approach: customer, geography, product, channel, transaction risk.
  3. CDD and EDD: beneficial ownership, PEPs, source of funds, source of wealth.
  4. Sanctions and screening: false positives, true hits, ownership/control, evasion.
  5. Monitoring and reporting: alerts, investigations, suspicious activity decisions.
  6. Governance: roles, policies, training, independent testing, three lines of defense.
  7. Typologies: trade-based laundering, virtual assets, corruption, trafficking, fraud.
  8. Scenario judgment: best next step, escalation, documentation, confidentiality.

For each missed question in your question bank, write down:

  • The issue tested.
  • The red flag or control concept.
  • The decision rule you should have applied.
  • Why the correct answer is better than the tempting answer.

Put the review into practice