Best use: read one section, then answer original practice questions on that topic. CGSS questions usually test sequence and judgment: identify the sanctions risk signal, decide what evidence matters, choose the correct escalation or disposition step, and document the rationale.
Sanctions mental model
Sanctions compliance is not only list screening. A strong answer usually considers:
Who is involved: customer, beneficial owner, director, vessel owner, counterparty, intermediary bank, agent.
What is involved: funds, goods, services, technology, securities, insurance, shipping, digital assets.
Where the activity touches: jurisdiction of parties, origin/destination, transit points, booking location, currency, clearing route.
Why the activity is occurring: legitimate purpose, humanitarian need, wind-down, license, evasion pattern.
How the institution controls it: screening, due diligence, escalation, blocking/freezing/rejecting, reporting, testing.
Core sanctions terms and traps
Term
Practical meaning
Exam trap
Sanctions
Legal or regulatory restrictions targeting countries, governments, entities, individuals, sectors, activities, or goods
Do not treat sanctions as identical to AML; overlap exists, but sanctions often require immediate interdiction
Embargo
Broad restriction on trade or activity with a country, region, or sector
“Comprehensive” restrictions are broader than list-based sanctions
Asset freeze / blocking
Restriction preventing access, movement, transfer, or use of targeted property or interests
A blocked asset is not simply returned to the sender unless law permits
Reject
Refusing or declining a transaction without taking control of the property
“Reject” and “block/freeze” are not interchangeable
Designated person
Individual or entity named on a sanctions list
Risk can extend to owned or controlled entities not explicitly listed
Ownership
A sanctions target’s direct or indirect equity interest in an entity
Thresholds and aggregation rules differ by jurisdiction
Control
Ability to direct actions, management, policy, assets, or decisions
Control can create risk even where ownership is below a numeric threshold
Primary sanctions
Restrictions applying to persons subject to the issuing jurisdiction
Do not assume only local residents are affected; jurisdiction can arise through currency, clearing, branches, or nexus
Secondary sanctions
Measures that can target non-jurisdictional persons for certain dealings with sanctioned parties or sectors
Secondary sanctions risk is often strategic and reputational, not just a screening question
Sectoral sanctions
Restrictions on certain activities, debt/equity, services, or industries rather than full blocking
A party may be listed but not fully blocked under every program
General license
Pre-authorized permission for a category of activity if conditions are met
Conditions, parties, time period, and reporting matter
Specific license
Case-specific authorization from a competent authority
Application pending is usually not authorization
Exemption
Activity carved out by law or regulation
Exemption scope may be narrow and jurisdiction-specific
Wind-down
Limited permission to exit existing activity
Wind-down is not permission to expand business
Facilitation
Assisting or approving prohibited activity by others
A non-sanctioned affiliate may still create facilitation risk
Circumvention / evasion
Structuring activity to avoid sanctions restrictions or detection
Evasion red flags can exist even when no list hit appears
False positive
Alerted party is not the sanctions target
Must be documented; repeated false positives may suggest tuning/data issues
True match
Alerted party is the sanctions target or prohibited party
Requires escalation and jurisdiction-specific disposition
Possible match
Insufficient information to clear or confirm
Do not process as normal until resolved under policy
Major sanctions authorities and roles
Authority / actor
Typical role in sanctions ecosystem
Candidate focus
United Nations Security Council
Issues UN sanctions measures implemented by member states
UN lists often create global baseline obligations through domestic implementation
United States OFAC
Administers and enforces many U.S. economic sanctions programs
Understand blocking, list-based programs, general/specific licenses, ownership concepts, and U.S. nexus
European Union
Adopts EU restrictive measures implemented across member states
EU sanctions often include asset freezes, sectoral measures, trade restrictions, and ownership/control analysis
United Kingdom OFSI / UK authorities
Implements and enforces UK financial sanctions
Recognize UK asset freeze, reporting, licensing, and ownership/control considerations
National competent authorities
Issue guidance, licenses, penalties, and local implementation rules
Always identify which jurisdiction’s law applies
Financial regulators
Expect risk-based sanctions compliance programs
Weak controls can create supervisory issues even without a completed prohibited transaction
Tailored to front office, operations, trade, compliance, senior management
Same annual slide deck for all roles
Independent testing
Tests design and operating effectiveness
Only checking that a policy exists
Change management
Responds to new programs, list updates, system changes, acquisitions
No process for rapid sanctions changes
Third-party oversight
Vendor screening, data providers, correspondent banks, agents
Outsourcing without accountability
Notes and examples
Building a Sanctions Compliance Program
A sanctions compliance program should be risk-based, documented, tested, and connected to actual business activity.
Program Elements
Program element
What strong practice should make you decide
Weak answer pattern
Risk assessment
Which customers, products, geographies, intermediaries, goods, and transaction types need stronger controls?
Same screening depth for every business line
Policies and procedures
What must staff do when screening produces a possible match, true match, or evasion red flag?
Policy says “screen” but does not define escalation or holds
Screening controls
Which data fields, lists, thresholds, timing points, and rescreening events matter?
One-time onboarding screening only
Alert handling
Is the alert a false positive, possible match, true match, or prohibited activity?
Clearing by name similarity alone
Trade and payment review
Do goods, route, parties, ownership, payment messages, or documents create sanctions risk?
Treating trade documents as automatically reliable
Training
Which employees need role-based sanctions training based on exposure?
Generic annual training with no operational relevance
Independent testing
Are controls designed well, operating as intended, and remediated after failures?
No test of alert quality, overrides, or backlog aging
Management information
Are risk, alert, backlog, escalation, and issue trends visible to governance?
Senior management sees only volume, not control quality
Documentation
Can the firm explain why it cleared, escalated, blocked, rejected, or continued review?
Decision field says “OK” with no rationale
Trap: A policy that exists on paper is not enough. The question often asks whether the control is actually applied, documented, monitored, and escalated.
Include known aliases and weak aliases with appropriate weighting
Abbreviations
Corporate names may use initials or local suffixes
Normalize legal entity suffixes and punctuation
Data quality
Missing DOB, registration number, or address increases uncertainty
Remediate source data, do not just lower thresholds
Threshold tuning
Too low creates noise; too high misses risk
Validate using samples, known test cases, and QA
Suppression rules
Can reduce repeat false positives
Must be controlled, justified, reviewed, and not suppress real changes
List updates
New designations require prompt rescreening
Maintain list update controls and audit logs
Alert disposition decision path
flowchart TD
A[Alert generated] --> B{Sufficient data to compare?}
B -- No --> C[Request data / hold or pause activity per policy]
B -- Yes --> D{Identity match?}
D -- No --> E[False positive: document rationale]
D -- Yes --> F{Party or activity prohibited/restricted?}
F -- No --> G[No prohibition found: document legal/program basis]
F -- Yes --> H{License, exemption, or authorization applies?}
H -- Yes --> I[Verify scope, conditions, parties, dates, reporting]
H -- No --> J{Required disposition}
J --> K[Block/freeze]
J --> L[Reject/decline]
J --> M[Escalate/report to authority where required]
Trap: A false-positive process is not a shortcut. Weak documentation can make even a reasonable decision look indefensible.
Alert Disposition Table
Alert outcome
What it means
Better response
Clear false positive
Identifiers show the party is not the sanctioned party
Document facts and rationale; proceed under policy
Possible match
Evidence is incomplete or conflicting
Hold or pause action as policy requires, gather facts, escalate
True match
Party, owner, vessel, or relevant interest matches a sanctions target
Follow blocking, rejection, reporting, and escalation requirements
Ownership/control concern
Direct party is not listed but listed party may own/control/benefit
Escalate and review ownership/control before proceeding
Sectoral or activity restriction
Party is not blocked but activity may be restricted
Legal/sanctions review; assess restrictions and permitted activity
Evasion red flag
Facts suggest avoidance of sanctions controls
Escalate, investigate, document, and consider reporting/restriction
Data-quality failure
Screening cannot be reliable because inputs are weak
Remediate data before clearing; do not treat “no hit” as proof
AML Monitoring vs. Sanctions Screening
Topic
AML suspicious activity monitoring
Sanctions screening
Main question
Is activity suspicious or inconsistent with profile?
Is there a prohibited, restricted, or sanctioned party/activity?
Timing
Often ongoing and post-activity, depending on product
Often before onboarding, before transactions, and when lists/data change
Evidence
Customer profile, behavior, typologies, source of funds
List match, ownership/control, goods, route, identifiers, restrictions
Output
Investigate, escalate, report if suspicion threshold is met
Clear, hold, escalate, block, reject, report, or restrict
Common trap
Filing solely because an alert fired
Clearing solely because the direct customer is not listed
Ownership and control: high-yield distinctions
Concept
Exam-ready interpretation
Direct ownership
Sanctioned party directly owns shares or equity in an entity
Indirect ownership
Ownership passes through one or more intermediate entities
Aggregate ownership
Multiple sanctioned parties’ ownership interests may need to be combined under some regimes
Control without ownership
Sanctioned party can direct decisions, appoint management, control assets, or influence policy
Listed parent
Subsidiaries may be restricted depending on ownership/control rules
Listed subsidiary
Parent is not automatically sanctioned solely because a subsidiary is listed, but relationship risk is high
Minority stake
May still matter if control rights exist or sectoral restrictions apply
Nominees/fronts
Formal ownership may hide actual sanctioned control
Jurisdiction difference
OFAC commonly uses a 50 percent or greater aggregate ownership concept for blocked persons; EU and UK analysis can place significant weight on ownership and control facts
Best exam answer
Do not rely only on list name. Analyze direct/indirect ownership, aggregate interests, control, and applicable jurisdiction
Blocking, freezing, rejecting, and exiting
Action
General meaning
When it may appear in scenarios
Block / freeze
Restrict access to property or funds and prevent movement
True match to blocked person; asset freeze obligation
Reject / decline
Refuse to process without taking control of property
Transaction prohibited but no blocking obligation under applicable rule
Return
Send funds back
Not always allowed; do not assume without legal basis
Exit relationship
Terminate customer relationship
May be necessary for risk management, but consider blocked property and reporting obligations
Hold / suspend
Pause while investigating
Appropriate for possible match or missing data
License request
Seek authorization from competent authority
Potentially lawful activity but no existing authorization
Continue with conditions
Proceed only if license/exemption fully applies
Must verify conditions and document rationale
Licensing and authorization
Item
What to verify
Common trap
Parties
All parties are within authorization scope
License covers one entity but not affiliates or owners
Activity
Exact activity is permitted
A humanitarian license does not permit unrelated commercial activity
Goods/services
Items match scope
Dual-use or restricted technology may need separate review
Geography
Covered jurisdictions and transit points
Shipment transits restricted territory not considered
Time
Effective period or wind-down window
Expired authorization relied upon
Conditions
Reporting, payment route, recordkeeping, value limits if applicable
Ignoring conditions turns permitted activity into a breach
Counterparties
Banks, carriers, insurers, brokers also allowed
Payment cannot be completed because intermediary is restricted
Documentation
Approval retained and linked to transaction
“Legal said OK” without record
Payments and correspondent banking
Payment element
Sanctions relevance
Originator
Customer or third party may be sanctioned or linked to sanctioned ownership
Beneficiary
Ultimate recipient may be target, front company, or controlled entity
Originating bank
Bank may be located in high-risk jurisdiction or subject to restrictions
Intermediary bank
Creates jurisdictional nexus and screening exposure
Beneficiary bank
Could be listed, sectorally restricted, or located in embargoed territory
Remittance information
Free text may reveal sanctioned goods, vessels, locations, or purpose
Address data
City/country clues can identify restricted geography
Currency
Certain currencies create clearing nexus through specific jurisdictions
Nested activity
Respondent bank may process for hidden downstream banks or clients
Payable-through accounts
Third-party access increases transparency and sanctions risk
Notes and examples
Payment red flags
Red flag
Why it matters
Vague payment purpose such as “consulting,” “services,” or “goods”
May hide restricted activity
Sudden change in route, bank, or counterparty
Possible attempt to avoid screening
Use of shell entities with no clear business
May conceal sanctioned ownership
Payments just below review thresholds
Possible structuring
Instructions to omit names, countries, vessels, or goods
Direct evasion indicator
High-risk jurisdiction address with unrelated customer profile
Geographic inconsistency
Multiple intermediaries without business rationale
Obscures counterparties and funds flow
Repeated false-positive-like names with incomplete data
May indicate intentional ambiguity
Trade finance and export-control overlap
Topic
Sanctions angle
Exam focus
Goods
Goods may be banned, restricted, dual-use, luxury, energy-related, military, or technology-sensitive
Do not stop at party screening
End user
Final recipient may differ from buyer
Identify ultimate consignee and beneficial user
End use
Civilian goods can support restricted military, nuclear, cyber, or surveillance programs
Ask whether use is consistent with customer profile
Route
Transshipment can conceal sanctioned destination
Review ports, carriers, freight forwarders, and route changes
Documents
Invoices, bills of lading, packing lists, certificates may conflict
Inconsistencies are red flags
Financing
Letters of credit, guarantees, collections, insurance may be restricted services
Screen all parties and activity
Pricing
Over/under-invoicing can mask value transfer
Links sanctions evasion and trade-based money laundering
Brokers/agents
Intermediaries may be fronts for sanctioned buyers
Identify role and compensation
Product classification
Export controls may apply even without sanctions designation
Escalate to trade/export specialists where needed
Notes and examples
Trade document red flags
Red flag
What it suggests
Goods description vague or inconsistent across documents
Concealment of restricted goods
Customer lacks experience in product category
Possible procurement front
Unusual routing through known transshipment hubs
Destination concealment
Last-minute change of vessel, port, consignee, or bank
Sanctions avoidance
End-use certificate generic or unverifiable
Weak assurance
Freight forwarder refuses to provide routing details
Transparency issue
Shipment inconsistent with destination economy
Diversion risk
Dual-use goods shipped to research, military, aerospace, or energy-linked entity
Proliferation or sectoral risk
Maritime sanctions reference
Indicator
Risk signal
Control response
AIS disabled or gaps near high-risk waters
“Dark activity” to hide location
Review voyage history and satellite/maritime intelligence where available
In scenarios, identify the applicable jurisdictional nexus before deciding.
Do not assume “not listed” means “not restricted.”
For trade finance, always ask: goods, end user, end use, route, vessel, banks, and documents.
For alerts, document the decision path: match analysis, legal/program basis, escalation, disposition, reporting.
Cheat Sheet for CGSS Candidates
This quick review is for candidates preparing for the ACAMS Certified Global Sanctions Specialist (CGSS) exam. Use it to refresh high-yield sanctions concepts before moving into topic drills, mock exams, and detailed explanations in Finance Prep.
This page is independent review support. It is not affiliated with ACAMS and does not replace the official exam materials, current candidate guidance, or applicable laws and regulations in your jurisdiction.
Finance Prep currently has 756 original CGSS practice questions for sanctions practice. Use this page as a fast consolidation tool, then use topic drills and mixed practice to test whether you can choose the defensible sanctions-control step in a scenario.
Notes and examples
Common CGSS Candidate Mistakes
Mistake
Better approach
Treating sanctions as only name matching
Review ownership/control, sectoral restrictions, geography, goods, services, and evasion signals
Clearing a match because one identifier differs
Compare all relevant identifiers and document the conclusion
Ignoring indirect benefit
Ask who owns, controls, receives, benefits, or directs the activity
Choosing account closure too quickly
First classify the issue, escalate, and follow legal/policy requirements
Assuming software makes the decision
Screening tools create alerts; people and policy disposition them
Treating every red flag as proof
Red flags require investigation, evidence, and escalation where needed
Forgetting data quality
Bad data can make screening ineffective
Overlooking trade documents
Sanctions risk often appears in goods, route, vessel, consignee, or end user facts
Missing facilitation risk
Advising a customer how to route around controls can create exposure
Writing weak notes
A defensible decision needs facts, reasoning, approver, and follow-up
High-Yield CGSS Review Map
Area
What to know cold
Common exam trap
Sanctions frameworks
Sanctions can target countries, sectors, persons, entities, vessels, goods, services, and ownership interests
Treating every sanctions issue as a simple name-list match
Governance
Senior oversight, risk appetite, documented accountability, independent testing, and control ownership matter
Assuming screening software alone is the sanctions program
Risk assessment
Customer, geography, product, channel, transaction, ownership, and third-party exposure shape control strength
Applying the same screening and review depth to every relationship
Screening
Name, payment, customer, vendor, vessel, geography, and goods screening require match disposition and documentation
Clearing alerts only because the name is common
Ownership and control
Sanctioned-party interests can flow through ownership, control, voting rights, or indirect benefit
Stopping at the direct customer name and ignoring beneficial ownership
Escalation
Potential true matches, high-risk ambiguity, blocked/rejected activity, and evasion indicators need escalation
Letting front-line staff resolve sanctions ambiguity without review
Investigations
Build the facts before deciding: parties, identifiers, routing, goods, documents, purpose, and history
Jumping to a report or clearance without enough evidence
Evasion typologies
Front companies, transshipment, dual-use goods, altered documents, ownership opacity, and routing changes are key red flags
Treating one clean document as proof that the transaction is safe
Reporting and post-decision controls
Blocking, rejection, reporting, account restrictions, and senior/legal escalation depend on facts and jurisdiction
Choosing a generic report or account closure without first classifying the issue
The Core CGSS Decision Model
Most sanctions scenarios reduce to a practical chain:
Identify all parties and interests. Customer, beneficial owner, controller, vessel, aircraft, wallet, intermediary, bank, vendor, consignee, end user, and beneficiary.
Identify the restriction type. List-based, ownership/control, sectoral, geographic, goods/end-use, service, financing, facilitation, or evasion concern.
Assess the evidence. Names, aliases, identifiers, ownership documents, trade documents, payment messages, shipment route, goods description, and customer history.
Choose the control response. Clear, continue review, escalate, block, reject, restrict, report, or decline depending on facts and law/policy.
Document the rationale. The file should show the facts reviewed, decision-maker, date, conclusion, and follow-up.
flowchart TD
A[Customer, payment, trade, vendor, or counterparty activity] --> B[Identify parties, owners, controllers, goods, route, and purpose]
B --> C[Screen lists and review sanctions risk indicators]
C --> D{Possible match, prohibited exposure, or evasion signal?}
D -- No --> E[Document rationale and proceed under policy]
D -- Yes --> F[Pause or hold action under policy]
F --> G[Gather identifiers, ownership, trade, payment, and context evidence]
G --> H{Facts resolve the issue?}
H -- False positive --> I[Document clearance and monitor if needed]
H -- Possible or true issue --> J[Escalate to sanctions/legal/compliance]
J --> K{Required action?}
K -- Block/reject/report/restrict --> L[Execute required action and preserve records]
K -- More review --> M[Request documentation and continue investigation]
Notes and examples
Exam point: The best answer is usually the next defensible control step. Avoid answers that ignore evidence, skip escalation, or treat every concern as either harmless or automatically criminal.
Quick Decision Map
If the scenario shows…
Better first response
Weak fuzzy-name match with inconsistent identifiers
Document false-positive rationale if policy supports clearance.
Possible true match with unresolved identifiers
Escalate and pause action pending specialist review.
Listed party or sanctioned ownership/control
Follow blocking, rejection, reporting, and escalation requirements.
Clean party name but high-risk trade route or goods
Review end use, documents, counterparties, and evasion indicators.
Customer asks how to avoid screening or change routing after a hit
Treat as an evasion red flag and escalate.
Program audit finds alert backlogs and undocumented clearances
Remediate control failure, document decisions, and strengthen oversight/testing.
Frontline staff want to release funds while review is pending
Hold or restrict action under policy until sanctions review is complete.
Senior manager wants to override an alert for a valuable customer
Follow escalation, legal review, and governance controls; do not clear without rationale.
Data is too incomplete to screen reliably
Obtain or remediate data before relying on the result.
High false-positive volume creates backlog
Tune rules carefully, improve data quality, and monitor control effectiveness.
Sanctions Frameworks and Governance: Fast Distinctions
Sanctions questions often test whether you can separate the legal restriction from the operational control.
Types of Sanctions Exposure
Exposure type
What to identify
Common exam angle
List-based sanctions
Whether a person, entity, vessel, aircraft, wallet, or beneficial owner appears on a sanctions list
Match quality, identifiers, aliases, and false-positive documentation
Ownership/control
Whether a listed party owns, controls, directs, or benefits from a non-listed party
Direct customer looks clean, but ownership or benefit is unresolved
Sectoral restrictions
Whether activity involves restricted sectors, debt/equity, services, technology, or financing
Party is not blocked, but the activity may still be restricted
Country or region measures
Whether geography, origin, destination, routing, or beneficiary creates exposure
Shipment or payment touches a restricted location
Trade and export controls
Whether goods, software, technology, end use, or end user create restrictions
Dual-use goods, military end user, altered documents, or suspicious routing
Facilitation risk
Whether the firm or employee helps another party do what the firm cannot do directly
Advice, routing changes, payment rewriting, or indirect support
Evasion risk
Whether facts suggest a person is trying to avoid sanctions controls
Front companies, new intermediaries, vague goods, or sudden ownership changes
Notes and examples
Governance Roles
Participant
Core responsibility
Exam trap
Board or senior management
Set risk appetite, support resources, oversee program effectiveness
Assuming senior leaders do daily alert disposition
First line business
Own sanctions risk in customers, products, payments, trade, and vendors
Treating compliance as the only risk owner
Sanctions compliance function
Set standards, advise, review escalations, monitor controls, support decisions
Treating policy writing as the whole program
Legal
Interpret legal obligations and advise on complex restrictions or reporting
Asking frontline staff to resolve legal ambiguity alone
Operations
Apply screening, holds, payment processing, and documentation procedures
Releasing a transaction before review is complete
Internal audit or independent testing
Test design and operating effectiveness
Letting the same team test its own work without independence
Exam point: CGSS practice is rarely about memorizing one list. It is usually about applying sanctions risk logic to a messy customer, payment, trade, or ownership fact pattern.
Ownership, Control, and Indirect Exposure
CGSS scenarios often turn on what the candidate does after the direct party looks clean.
High-Yield Ownership and Control Cues
A listed person owns or controls part of the customer, vendor, vessel, trust, or intermediary.
The direct party is new, thinly capitalized, or recently changed ownership.
A payment or shipment benefits a sanctioned party even if that party is not named as the customer.
A corporate structure has nominees, layered entities, or unexplained offshore ownership.
A customer changes routing, counterparty, documents, or goods descriptions after a sanctions concern appears.
Notes and examples
Exam point: Do not assume a clean first-level name screen ends the analysis when beneficial ownership, control, or benefit is unresolved.
Ownership/Control Review Table
Fact pattern
Why it matters
Better exam response
Listed person owns a minority interest but has veto rights
Control may exist without majority ownership
Escalate for ownership/control analysis
Customer is owned by several companies in different jurisdictions
Layering may obscure a sanctioned beneficial owner
Build ownership chart and verify controllers
Trust has sanctioned settlor or protector influence
Control or benefit may not sit with legal owner
Review trust roles and escalation requirements
New intermediary appears after a sanctions concern
Could be an attempt to reroute through a front
Treat as evasion signal and investigate
Payment benefits a listed party indirectly
Sanctions exposure can arise through benefit, not just named party
Escalate before processing
Ownership documents are stale or inconsistent
Screening result may be unreliable
Refresh information and document rationale
Direct, Indirect, and Beneficial Exposure
Exposure
Practical question
Direct party
Is the customer, vendor, bank, vessel, or counterparty listed or restricted?
Beneficial owner
Does a listed person ultimately own or benefit from the party?
Controller
Does a listed person direct decisions through voting, management, contract, or influence?
Intermediary
Is a broker, agent, freight forwarder, distributor, or bank creating sanctions exposure?
Goods/end user
Are the goods, technology, destination, or end user restricted?
Payment path
Does the payment route, bank, message, or beneficiary indicate prohibited exposure?
Detecting and Investigating Evasion
Sanctions evasion questions reward careful fact gathering before final disposition.
Red flag
Review focus
Transshipment through unusual routes
Compare goods, ports, counterparties, and economic rationale.
Dual-use or restricted goods
Review end user, end use, licensing, documentation, and routing.
Altered or inconsistent documents
Compare invoices, bills of lading, certificates, contracts, and payment instructions.
Front or shell companies
Review ownership, business purpose, transaction history, and adverse media.
Sudden counterparty changes
Ask why the customer changed the party, routing, vessel, or payment path.
Payments just below thresholds
Review whether structuring or control avoidance is plausible.
Clean customer but sanctioned beneficiary
Review indirect benefit, ownership/control, and facilitation risk.
Vague payment references
Compare payment message to contract, invoice, goods, and counterparties.
Use of new agents or brokers
Review commercial rationale, due diligence, and sanctions exposure.
Notes and examples
Trap: The best answer is often not immediate closure or immediate clearance. It may be escalation, additional documentation, enhanced review, blocking, rejection, or reporting depending on the facts and local requirements.
Trade and Payment Evasion Patterns
Pattern
How it appears in a question
What to do first
Transshipment
Shipment routes through a third country with no commercial reason
Compare route, goods, end user, and documents
Misdescription
Goods are described generically or inconsistently
Request detail, review end use, and escalate if unresolved
Dual-use goods
Item can have civilian and military/restricted use
Review end user, end use, licensing, and sanctions/export controls
Third-party payment
Unrelated party pays or receives funds
Establish relationship and commercial rationale
Document alteration
Invoice, bill of lading, or certificate conflicts with other records
Do not rely on one document; compare all evidence
Shipping switch
Vessel, carrier, consignee, or port changes after review begins
Treat as a potential evasion indicator
Message stripping
Payment references remove obvious sanctioned information
Escalate because concealment may indicate facilitation/evasion
Investigation Workflow
Step
What good looks like
Define the issue
Is the concern a list match, ownership/control concern, restricted activity, or evasion signal?
Preserve the activity
Hold, pause, or restrict action according to policy while review is pending.
Gather facts
Parties, owners, controllers, goods, end user, route, purpose, documents, payment path, and history.
Compare evidence
Check whether documents, messages, routes, and parties tell the same story.
Seek explanation carefully
Use approved procedures and avoid tipping off or helping evade controls.
Escalate
Bring unresolved or high-risk matters to sanctions/legal/compliance specialists.
Decide
Clear, block, reject, report, restrict, decline, or continue review based on facts and law/policy.
Document
Record facts, rationale, decision-maker, date, and follow-up actions.
Quality Documentation
Good sanctions documentation answers:
What triggered the alert or investigation?
Which parties, owners, controllers, goods, jurisdictions, and payment paths were reviewed?
Which sanctions lists, restrictions, or policies were relevant?
Which identifiers or documents supported the decision?
Why was the issue cleared, escalated, blocked, rejected, or kept under review?
Who made or approved the decision?
What follow-up monitoring, remediation, or reporting is required?
Trap: “No sanctions issue found” is not enough if the file does not show why the match, ownership concern, route, or evasion signal was resolved.
Proliferation Financing and Dual-Use Goods
CGSS questions may blend sanctions, export controls, and proliferation financing. The key is to look beyond the customer name and test whether the transaction supports restricted procurement or restricted end users.
Common Proliferation-Financing Indicators
Indicator
Why it matters
Dual-use goods, software, or technology
Civilian items may support military, nuclear, missile, or restricted programs
Unusual procurement chain
Multiple brokers or front companies may hide the true end user
Inconsistent end-user certificate
Documentation may be altered or incomplete
Shipment through transshipment hubs
Route may be designed to conceal destination
Customer lacks technical capacity
The buyer does not appear able to use the goods legitimately
Payment from unrelated third party
May hide sponsor, beneficial owner, or restricted beneficiary
Goods inconsistent with business model
Product does not fit customer profile or prior activity
Notes and examples
What to Review
End user and end use.
Goods description and technical specifications.
Licensing or authorization requirements where relevant.
Shipping route, ports, freight forwarders, and vessel history.
Counterparties, brokers, distributors, and payment parties.
Public adverse information and sanctions proximity.
Virtual Assets, Securities, and Nonbank Exposure
Sanctions risk is not limited to bank wires. CGSS candidates should be ready for scenarios involving virtual assets, securities, insurance, fintech platforms, trade finance, charities, and third-party service providers.
Risk assessment drives screening, due diligence, escalation, and monitoring strength.
10-Minute Scenario Review
Practice spotting:
Possible true matches.
Beneficial ownership issues.
Front or shell companies.
Transshipment and unusual routing.
Dual-use goods and restricted end users.
Vague or altered trade documents.
Payment-message stripping.
High-risk intermediaries.
Backlogs, overrides, and weak documentation.
10-Minute Question-Bank Review
Use original practice questions to test:
“What should the analyst do next?”
“Which fact is most important?”
“Which control failed?”
“Which issue requires escalation?”
“Which evidence best resolves the alert?”
“Which response avoids facilitation?”
Review the detailed explanations for both correct and incorrect options. The tempting wrong answers often reveal the exam’s favorite traps: fast clearance, missing ownership/control, weak documentation, and failure to escalate.
Practice Next
After this review, use CGSS topic drills to test whether you can apply sanctions rules under time pressure. Finance Prep’s CGSS bank has 756 original practice questions with topic drills, timed mock exams, and detailed explanations.
Need to sharpen…
Use
Sanctions regimes, governance, risk appetite, and oversight
Matching topic drill in Finance Prep
Program design, screening controls, procedures, training, and testing
Matching topic drill in Finance Prep
Alert review, investigations, ownership/control, and evasion typologies
Why the correct answer is more defensible than the tempting answer.
Your next step: practice scenario-based questions until you can consistently identify the sanctions exposure, the evidence needed, the right escalation or disposition, and the documentation that makes the decision defensible.