ACAMS CGSS Cheat Sheet

Cheat sheet: sanctions screening, risk, evasion, and controls reference for ACAMS CGSS exam preparation.

Use the tables for a quick pre-exam check. Expand a topic’s notes for explanations, examples, and additional distinctions.

Scope and study context

The CGSS exam rewards applied judgment: identifying sanctions risk, choosing controls, interpreting alert facts, recognizing evasion, and understanding how global sanctions regimes differ.

If you have…Best use of this pageThen practice
10 minutesReview the decision rules, alert handling table, and final checklistMixed CGSS questions in Finance Prep
30 minutesWork through governance, screening, ownership/control, and evasion sectionsOne topic drill from your weakest area
One study sessionRead the tables, write a short error log, then answer sample exam questionsFree CGSS Practice Exam
A weak mock scoreMatch each missed question to the topic map belowThe matching Finance Prep topic drill

Best use: read one section, then answer original practice questions on that topic. CGSS questions usually test sequence and judgment: identify the sanctions risk signal, decide what evidence matters, choose the correct escalation or disposition step, and document the rationale.

Sanctions mental model

Sanctions compliance is not only list screening. A strong answer usually considers:

  1. Who is involved: customer, beneficial owner, director, vessel owner, counterparty, intermediary bank, agent.
  2. What is involved: funds, goods, services, technology, securities, insurance, shipping, digital assets.
  3. Where the activity touches: jurisdiction of parties, origin/destination, transit points, booking location, currency, clearing route.
  4. Why the activity is occurring: legitimate purpose, humanitarian need, wind-down, license, evasion pattern.
  5. How the institution controls it: screening, due diligence, escalation, blocking/freezing/rejecting, reporting, testing.

Core sanctions terms and traps

TermPractical meaningExam trap
SanctionsLegal or regulatory restrictions targeting countries, governments, entities, individuals, sectors, activities, or goodsDo not treat sanctions as identical to AML; overlap exists, but sanctions often require immediate interdiction
EmbargoBroad restriction on trade or activity with a country, region, or sector“Comprehensive” restrictions are broader than list-based sanctions
Asset freeze / blockingRestriction preventing access, movement, transfer, or use of targeted property or interestsA blocked asset is not simply returned to the sender unless law permits
RejectRefusing or declining a transaction without taking control of the property“Reject” and “block/freeze” are not interchangeable
Designated personIndividual or entity named on a sanctions listRisk can extend to owned or controlled entities not explicitly listed
OwnershipA sanctions target’s direct or indirect equity interest in an entityThresholds and aggregation rules differ by jurisdiction
ControlAbility to direct actions, management, policy, assets, or decisionsControl can create risk even where ownership is below a numeric threshold
Primary sanctionsRestrictions applying to persons subject to the issuing jurisdictionDo not assume only local residents are affected; jurisdiction can arise through currency, clearing, branches, or nexus
Secondary sanctionsMeasures that can target non-jurisdictional persons for certain dealings with sanctioned parties or sectorsSecondary sanctions risk is often strategic and reputational, not just a screening question
Sectoral sanctionsRestrictions on certain activities, debt/equity, services, or industries rather than full blockingA party may be listed but not fully blocked under every program
General licensePre-authorized permission for a category of activity if conditions are metConditions, parties, time period, and reporting matter
Specific licenseCase-specific authorization from a competent authorityApplication pending is usually not authorization
ExemptionActivity carved out by law or regulationExemption scope may be narrow and jurisdiction-specific
Wind-downLimited permission to exit existing activityWind-down is not permission to expand business
FacilitationAssisting or approving prohibited activity by othersA non-sanctioned affiliate may still create facilitation risk
Circumvention / evasionStructuring activity to avoid sanctions restrictions or detectionEvasion red flags can exist even when no list hit appears
False positiveAlerted party is not the sanctions targetMust be documented; repeated false positives may suggest tuning/data issues
True matchAlerted party is the sanctions target or prohibited partyRequires escalation and jurisdiction-specific disposition
Possible matchInsufficient information to clear or confirmDo not process as normal until resolved under policy

Major sanctions authorities and roles

Authority / actorTypical role in sanctions ecosystemCandidate focus
United Nations Security CouncilIssues UN sanctions measures implemented by member statesUN lists often create global baseline obligations through domestic implementation
United States OFACAdministers and enforces many U.S. economic sanctions programsUnderstand blocking, list-based programs, general/specific licenses, ownership concepts, and U.S. nexus
European UnionAdopts EU restrictive measures implemented across member statesEU sanctions often include asset freezes, sectoral measures, trade restrictions, and ownership/control analysis
United Kingdom OFSI / UK authoritiesImplements and enforces UK financial sanctionsRecognize UK asset freeze, reporting, licensing, and ownership/control considerations
National competent authoritiesIssue guidance, licenses, penalties, and local implementation rulesAlways identify which jurisdiction’s law applies
Financial regulatorsExpect risk-based sanctions compliance programsWeak controls can create supervisory issues even without a completed prohibited transaction
Law enforcement / intelligence agenciesInvestigate evasion, proliferation, corruption, terrorism, cyber activityTypologies and red flags often come from enforcement patterns
Export control authoritiesRestrict controlled goods, software, technology, and end usesExport controls and sanctions overlap but are not the same
Institution board/senior managementOwn risk appetite and resourcingGovernance failures are common enforcement themes
Compliance / sanctions teamDesigns screening, escalation, reporting, testing, and trainingExam scenarios often test escalation and documentation discipline

Sanctions types: what is restricted?

Sanctions typeTypical targetWhat to check
List-based financial sanctionsNamed individuals, entities, vessels, aircraftCustomer/counterparty screening, ownership/control, payment messages, aliases
Country or territory restrictionsJurisdictions, regions, governmentsOrigin, destination, residence, citizenship, branch location, shipment route
Sectoral sanctionsEnergy, defense, finance, mining, technology, maritime, other sectorsActivity type, maturity/tenor restrictions, services provided, financing structure
Trade sanctionsImports, exports, reexports, brokering, goodsProduct classification, end user, end use, shipping documents, transshipment
Arms embargoWeapons, defense articles, military servicesDual-use goods, military end users, brokers, logistics
Proliferation sanctionsWMD, nuclear, missile, dual-use procurement networksFront companies, technical goods, unusual shipping, scientific institutes
Human rights / corruption sanctionsIndividuals or entities linked to abuse or corruptionPEP exposure, state-owned entities, intermediaries
Cyber sanctionsHackers, ransomware actors, crypto wallets, infrastructureDigital asset addresses, ransomware payments, incident response
Maritime sanctionsVessels, owners, operators, cargo, portsIMO number, AIS gaps, ship-to-ship transfers, flag changes
Capital markets restrictionsSecurities, debt, equity, investment servicesIssuer, maturity, derivative exposure, custodians, investment funds
Services restrictionsProfessional, technical, accounting, trust, IT, insurance, maritime servicesService scope, location of benefit, end recipient
Travel bansIndividualsLess central for many financial institutions but relevant to comprehensive sanctions understanding

Sanctions vs AML/CFT

DimensionSanctionsAML/CFT
Primary questionIs this party, activity, jurisdiction, or property prohibited or restricted?Is the activity suspicious or linked to illicit proceeds or financing?
TimingOften real-time interdiction before processingOften monitoring before and after transactions
ActionBlock/freeze, reject, decline, report, license, escalateInvestigate, file suspicious activity report where required, exit or monitor
Risk toleranceFrequently zero tolerance for prohibited activityRisk-based; suspicious does not always mean prohibited
Data needNames, aliases, IDs, ownership, control, geography, vessel/goods dataBehavior, source of funds, expected activity, typologies
Common overlapTerrorism, proliferation, corruption, narcotics, cyber, evasionSanctions evasion may also be money laundering

Risk assessment reference

Inherent sanctions risk factors

Risk categoryHigher-risk indicatorsLower-risk indicators
CustomerPEPs, state-owned entities, import/export firms, money services, crypto firms, defense/energy entities, charities in conflict zonesLocal retail customers with simple profiles and verified identity
GeographySanctioned or high-conflict regions, transshipment hubs, border areas, offshore secrecy jurisdictionsDomestic-only activity in lower-risk jurisdictions
ProductsCorrespondent banking, trade finance, private banking, securities, custody, crypto, insurance, maritime financeLow-value, domestic, non-cross-border products
ChannelsNon-face-to-face onboarding, third-party introducers, nested relationships, complex agentsDirect customer relationship with verified documentation
TransactionsCross-border wires, vague remittance data, unusual currencies, rapid movement, no economic rationaleRecurring, transparent payments consistent with profile
OwnershipComplex layers, bearer shares, trusts, nominee directors, recent ownership changesTransparent ownership with verifiable control structure
Screening dataPoor names, missing DOB/ID, non-Latin scripts, unstructured payment messagesStandardized identifiers, complete customer records
Prior issuesPrevious sanctions alerts, adverse media, regulatory findings, control failuresStable history, cleared alerts with strong documentation
Notes and examples

Residual risk and controls

ControlReduces which risk?Evidence exam answers should mention
Customer due diligenceHidden sanctioned ownership/control, false identityBeneficial ownership, management, source of funds, business purpose
Real-time screeningProhibited transactions before executionPayment interdiction, sanctions list updates, alert audit trail
Batch screeningExisting customer/list changesPeriodic rescreening, event-triggered rescreening
Trade document reviewGoods, end-use, vessel, port, route evasionInvoices, bills of lading, HS/product description, shipping route
Geolocation controlsCountry/territory exposureIP, address, phone, port, origin/destination, branch data
Technology tuningFalse positives/false negativesThreshold testing, model governance, sample validation
Independent testingProgram effectivenessAudit findings, remediation tracking
Escalation governanceInconsistent decisioningClear levels, legal review, sanctions officer approval
TrainingHuman error and missed red flagsRole-based sanctions training
Reporting processRegulatory breach handlingTimely internal escalation, competent authority reporting where required

Sanctions compliance program components

ComponentWhat good looks likeWeak answer to avoid
GovernanceBoard/senior management oversight, defined risk appetite, accountable sanctions officer“Compliance owns everything”
Policies and proceduresWritten, current, jurisdiction-aware, product-specificGeneric AML policy with one sanctions paragraph
Risk assessmentEnterprise-wide, refreshed for products, customers, geographies, transactions, third partiesOne-time checklist with no action plan
Screening programCustomer, transaction, trade, vessel, securities, and third-party screening as applicableOnly screening new customers at onboarding
Data managementComplete, standardized, quality-controlled dataOverreliance on incomplete names
Alert managementRisk-ranked queues, documented disposition, escalation, QAClosing alerts without rationale
Licensing processTracks scope, conditions, expiration, approvals, reportingTreating a license as blanket approval
Block/reject processClear decision rules, segregation, asset controls, reportingReturning funds automatically
TrainingTailored to front office, operations, trade, compliance, senior managementSame annual slide deck for all roles
Independent testingTests design and operating effectivenessOnly checking that a policy exists
Change managementResponds to new programs, list updates, system changes, acquisitionsNo process for rapid sanctions changes
Third-party oversightVendor screening, data providers, correspondent banks, agentsOutsourcing without accountability
Notes and examples

Building a Sanctions Compliance Program

A sanctions compliance program should be risk-based, documented, tested, and connected to actual business activity.

Program Elements

Program elementWhat strong practice should make you decideWeak answer pattern
Risk assessmentWhich customers, products, geographies, intermediaries, goods, and transaction types need stronger controls?Same screening depth for every business line
Policies and proceduresWhat must staff do when screening produces a possible match, true match, or evasion red flag?Policy says “screen” but does not define escalation or holds
Screening controlsWhich data fields, lists, thresholds, timing points, and rescreening events matter?One-time onboarding screening only
Alert handlingIs the alert a false positive, possible match, true match, or prohibited activity?Clearing by name similarity alone
Trade and payment reviewDo goods, route, parties, ownership, payment messages, or documents create sanctions risk?Treating trade documents as automatically reliable
TrainingWhich employees need role-based sanctions training based on exposure?Generic annual training with no operational relevance
Independent testingAre controls designed well, operating as intended, and remediated after failures?No test of alert quality, overrides, or backlog aging
Management informationAre risk, alert, backlog, escalation, and issue trends visible to governance?Senior management sees only volume, not control quality
DocumentationCan the firm explain why it cleared, escalated, blocked, rejected, or continued review?Decision field says “OK” with no rationale

Trap: A policy that exists on paper is not enough. The question often asks whether the control is actually applied, documented, monitored, and escalated.

Risk Assessment Review

Risk factorHigher-risk indicatorsStrong control response
CustomerShell companies, nominees, PEPs, state-owned entities, complex ownership, money services businesses, high-risk trade customersEnhanced ownership review, source of funds/purpose checks, closer monitoring
GeographySanctioned jurisdictions, border regions, weak controls, transshipment hubs, conflict zonesCountry risk scoring, routing review, restrictions, escalation
Product/serviceTrade finance, correspondent banking, virtual assets, shipping, insurance, securities, commodity financeProduct-specific screening and document review
TransactionVague payment messages, round-dollar wires, third-party payments, unusual route, altered instructionsPayment hold, context review, escalation
Vendor/third partyAgents, brokers, freight forwarders, distributors, resellers, consultantsThird-party due diligence and sanctions clauses
Data qualityMissing date of birth, incomplete addresses, poor transliteration, stale ownership dataData remediation, manual review, rescreening

Control Quality Questions

Before you choose an answer, ask:

  • Is the control preventive, detective, or corrective?
  • Does the control happen before the firm creates prohibited exposure?
  • Does the reviewer have enough information to clear the issue?
  • Is a legal or sanctions specialist needed?
  • Is the decision documented well enough for a later examiner?
  • Does the program learn from failures, backlogs, overrides, and false positives?

Screening universe: who and what to screen

AreaScreen these data pointsCommon miss
Customer onboardingLegal name, aliases, trade names, DOB, ID, nationality, address, registration numberScreening only the applicant, not beneficial owners/controllers
Beneficial ownershipDirect and indirect owners, intermediate entities, trustees, settlors, protectors, beneficiaries where relevantIgnoring aggregate ownership by multiple sanctioned parties
Management/controlDirectors, senior managers, authorized signers, powers of attorneyFocusing only on shareholders
Existing customersCustomer file, periodic changes, trigger events, list updatesNo rescreening after new sanctions designation
PaymentsOriginator, beneficiary, banks, intermediaries, remittance text, addresses, countriesScreening only names in structured fields
Trade financeBuyer, seller, banks, carriers, vessels, ports, goods, insurers, freight forwardersIgnoring documents because no customer name matches
SecuritiesIssuer, counterparty, custodian, broker, underlying exposure, fund holdingsMissing sanctioned issuer exposure through funds or derivatives
MaritimeVessel name, IMO number, MMSI, flag, owner, operator, manager, charterer, cargo, portsRelying on vessel name only; names change
Digital assetsCustomer, wallet address, exchange, blockchain exposure, ransomware indicatorsTreating crypto as outside sanctions screening
Vendors/third partiesAgents, suppliers, consultants, distributors, introducersNot screening non-customer relationships
EmployeesNew hires, contractors, payroll beneficiaries where relevantOverlooking employment or payroll restrictions

Name screening logic

IssueWhy it mattersPractical control
Exact matchFast, high-confidence for unique identifiersUse legal name plus identifiers
Fuzzy matchCaptures misspellings, transliteration, reordered namesCalibrate thresholds by risk and language
TransliterationArabic, Cyrillic, Chinese, Persian, Korean, and other scripts vary widelyUse aliases, phonetics, native script where available
Common namesHigh false positivesRequire DOB, passport, address, nationality, ID, relationship context
Aliases / AKAsSanctions targets often use multiple namesInclude known aliases and weak aliases with appropriate weighting
AbbreviationsCorporate names may use initials or local suffixesNormalize legal entity suffixes and punctuation
Data qualityMissing DOB, registration number, or address increases uncertaintyRemediate source data, do not just lower thresholds
Threshold tuningToo low creates noise; too high misses riskValidate using samples, known test cases, and QA
Suppression rulesCan reduce repeat false positivesMust be controlled, justified, reviewed, and not suppress real changes
List updatesNew designations require prompt rescreeningMaintain list update controls and audit logs

Alert disposition decision path

    flowchart TD
	    A[Alert generated] --> B{Sufficient data to compare?}
	    B -- No --> C[Request data / hold or pause activity per policy]
	    B -- Yes --> D{Identity match?}
	    D -- No --> E[False positive: document rationale]
	    D -- Yes --> F{Party or activity prohibited/restricted?}
	    F -- No --> G[No prohibition found: document legal/program basis]
	    F -- Yes --> H{License, exemption, or authorization applies?}
	    H -- Yes --> I[Verify scope, conditions, parties, dates, reporting]
	    H -- No --> J{Required disposition}
	    J --> K[Block/freeze]
	    J --> L[Reject/decline]
	    J --> M[Escalate/report to authority where required]
Notes and examples

Alert handling checklist

StepKey questionEvidence to capture
IdentifyWho or what triggered the alert?Name, list, program, field, transaction, timestamp
CompareDoes the customer/counterparty match the listed party?DOB, ID, address, nationality, registration, ownership, vessel IMO
ContextualizeIs there jurisdictional nexus or restricted activity?Currency, clearing route, branch, location, service type
Ownership/controlIs an unlisted entity owned or controlled by sanctioned persons?Ownership chart, control rights, directors, voting, contracts
License/exemptionIs activity permitted under defined conditions?License text, legal review, conditions, approvals
DecideBlock/freeze, reject, decline, clear, or escalate?Decision maker, rationale, policy reference
ReportIs regulator or authority notification required?Internal escalation record and reporting evidence
RemediateDoes the alert reveal a control weakness?Data fix, tuning, training, relationship review

Screening and Alert Handling

Screening is a decision workflow, not a button press.

Screening Lifecycle

StepPractical questionEvidence to review
Collect usable dataAre names, aliases, dates, addresses, ownership, vessels, goods, and identifiers complete enough?Customer files, KYC, trade docs, payment fields, vendor records
Normalize and screenAre aliases, transliteration, abbreviations, spelling variants, and local naming conventions handled?Screening configuration, fuzzy logic, list sources, data quality
Compare identifiersDo identifiers support a true match, false positive, or unresolved possible match?DOB, incorporation date, address, passport, national ID, registration number
Check ownership/controlIs a non-listed customer owned or controlled by a sanctioned party?Ownership chart, registries, corporate documents, voting/control rights
Review transaction contextDo routing, goods, jurisdictions, counterparties, or payment purpose change the risk?SWIFT/payment message, invoice, bill of lading, contract, end-user certificate
DispositionIs the right action clear, or does it require escalation?Policy, legal guidance, sanctions procedure, escalation notes
Document and monitorWould another reviewer understand the decision from the record?Rationale, evidence, approver, date, follow-up actions

Trap: A false-positive process is not a shortcut. Weak documentation can make even a reasonable decision look indefensible.

Alert Disposition Table

Alert outcomeWhat it meansBetter response
Clear false positiveIdentifiers show the party is not the sanctioned partyDocument facts and rationale; proceed under policy
Possible matchEvidence is incomplete or conflictingHold or pause action as policy requires, gather facts, escalate
True matchParty, owner, vessel, or relevant interest matches a sanctions targetFollow blocking, rejection, reporting, and escalation requirements
Ownership/control concernDirect party is not listed but listed party may own/control/benefitEscalate and review ownership/control before proceeding
Sectoral or activity restrictionParty is not blocked but activity may be restrictedLegal/sanctions review; assess restrictions and permitted activity
Evasion red flagFacts suggest avoidance of sanctions controlsEscalate, investigate, document, and consider reporting/restriction
Data-quality failureScreening cannot be reliable because inputs are weakRemediate data before clearing; do not treat “no hit” as proof

AML Monitoring vs. Sanctions Screening

TopicAML suspicious activity monitoringSanctions screening
Main questionIs activity suspicious or inconsistent with profile?Is there a prohibited, restricted, or sanctioned party/activity?
TimingOften ongoing and post-activity, depending on productOften before onboarding, before transactions, and when lists/data change
EvidenceCustomer profile, behavior, typologies, source of fundsList match, ownership/control, goods, route, identifiers, restrictions
OutputInvestigate, escalate, report if suspicion threshold is metClear, hold, escalate, block, reject, report, or restrict
Common trapFiling solely because an alert firedClearing solely because the direct customer is not listed

Ownership and control: high-yield distinctions

ConceptExam-ready interpretation
Direct ownershipSanctioned party directly owns shares or equity in an entity
Indirect ownershipOwnership passes through one or more intermediate entities
Aggregate ownershipMultiple sanctioned parties’ ownership interests may need to be combined under some regimes
Control without ownershipSanctioned party can direct decisions, appoint management, control assets, or influence policy
Listed parentSubsidiaries may be restricted depending on ownership/control rules
Listed subsidiaryParent is not automatically sanctioned solely because a subsidiary is listed, but relationship risk is high
Minority stakeMay still matter if control rights exist or sectoral restrictions apply
Nominees/frontsFormal ownership may hide actual sanctioned control
Jurisdiction differenceOFAC commonly uses a 50 percent or greater aggregate ownership concept for blocked persons; EU and UK analysis can place significant weight on ownership and control facts
Best exam answerDo not rely only on list name. Analyze direct/indirect ownership, aggregate interests, control, and applicable jurisdiction

Blocking, freezing, rejecting, and exiting

ActionGeneral meaningWhen it may appear in scenarios
Block / freezeRestrict access to property or funds and prevent movementTrue match to blocked person; asset freeze obligation
Reject / declineRefuse to process without taking control of propertyTransaction prohibited but no blocking obligation under applicable rule
ReturnSend funds backNot always allowed; do not assume without legal basis
Exit relationshipTerminate customer relationshipMay be necessary for risk management, but consider blocked property and reporting obligations
Hold / suspendPause while investigatingAppropriate for possible match or missing data
License requestSeek authorization from competent authorityPotentially lawful activity but no existing authorization
Continue with conditionsProceed only if license/exemption fully appliesMust verify conditions and document rationale

Licensing and authorization

ItemWhat to verifyCommon trap
PartiesAll parties are within authorization scopeLicense covers one entity but not affiliates or owners
ActivityExact activity is permittedA humanitarian license does not permit unrelated commercial activity
Goods/servicesItems match scopeDual-use or restricted technology may need separate review
GeographyCovered jurisdictions and transit pointsShipment transits restricted territory not considered
TimeEffective period or wind-down windowExpired authorization relied upon
ConditionsReporting, payment route, recordkeeping, value limits if applicableIgnoring conditions turns permitted activity into a breach
CounterpartiesBanks, carriers, insurers, brokers also allowedPayment cannot be completed because intermediary is restricted
DocumentationApproval retained and linked to transaction“Legal said OK” without record

Payments and correspondent banking

Payment elementSanctions relevance
OriginatorCustomer or third party may be sanctioned or linked to sanctioned ownership
BeneficiaryUltimate recipient may be target, front company, or controlled entity
Originating bankBank may be located in high-risk jurisdiction or subject to restrictions
Intermediary bankCreates jurisdictional nexus and screening exposure
Beneficiary bankCould be listed, sectorally restricted, or located in embargoed territory
Remittance informationFree text may reveal sanctioned goods, vessels, locations, or purpose
Address dataCity/country clues can identify restricted geography
CurrencyCertain currencies create clearing nexus through specific jurisdictions
Nested activityRespondent bank may process for hidden downstream banks or clients
Payable-through accountsThird-party access increases transparency and sanctions risk
Notes and examples

Payment red flags

Red flagWhy it matters
Vague payment purpose such as “consulting,” “services,” or “goods”May hide restricted activity
Sudden change in route, bank, or counterpartyPossible attempt to avoid screening
Use of shell entities with no clear businessMay conceal sanctioned ownership
Payments just below review thresholdsPossible structuring
Instructions to omit names, countries, vessels, or goodsDirect evasion indicator
High-risk jurisdiction address with unrelated customer profileGeographic inconsistency
Multiple intermediaries without business rationaleObscures counterparties and funds flow
Repeated false-positive-like names with incomplete dataMay indicate intentional ambiguity

Trade finance and export-control overlap

TopicSanctions angleExam focus
GoodsGoods may be banned, restricted, dual-use, luxury, energy-related, military, or technology-sensitiveDo not stop at party screening
End userFinal recipient may differ from buyerIdentify ultimate consignee and beneficial user
End useCivilian goods can support restricted military, nuclear, cyber, or surveillance programsAsk whether use is consistent with customer profile
RouteTransshipment can conceal sanctioned destinationReview ports, carriers, freight forwarders, and route changes
DocumentsInvoices, bills of lading, packing lists, certificates may conflictInconsistencies are red flags
FinancingLetters of credit, guarantees, collections, insurance may be restricted servicesScreen all parties and activity
PricingOver/under-invoicing can mask value transferLinks sanctions evasion and trade-based money laundering
Brokers/agentsIntermediaries may be fronts for sanctioned buyersIdentify role and compensation
Product classificationExport controls may apply even without sanctions designationEscalate to trade/export specialists where needed
Notes and examples

Trade document red flags

Red flagWhat it suggests
Goods description vague or inconsistent across documentsConcealment of restricted goods
Customer lacks experience in product categoryPossible procurement front
Unusual routing through known transshipment hubsDestination concealment
Last-minute change of vessel, port, consignee, or bankSanctions avoidance
End-use certificate generic or unverifiableWeak assurance
Freight forwarder refuses to provide routing detailsTransparency issue
Shipment inconsistent with destination economyDiversion risk
Dual-use goods shipped to research, military, aerospace, or energy-linked entityProliferation or sectoral risk

Maritime sanctions reference

IndicatorRisk signalControl response
AIS disabled or gaps near high-risk waters“Dark activity” to hide locationReview voyage history and satellite/maritime intelligence where available
Ship-to-ship transferCargo origin/destination may be concealedCheck locations, counterpart vessels, cargo documents
Frequent flag changesAttempt to avoid scrutinyReview flag history and registry credibility
Vessel name changesHiding prior designation or adverse mediaUse IMO number, not name alone
Complex ownershipSanctioned owner/operator may be hiddenScreen owner, operator, manager, charterer
Port calls near restricted jurisdictionsPossible sanctions exposureCompare stated route to AIS/port data
Inconsistent cargo documentsConcealment or diversionEscalate trade investigation
Aged vessel with opaque insuranceHigher evasion riskReview insurer, P&I club, classification society
Unusual charter structureControl may sit with sanctioned partyReview charterer and beneficial ownership
Commodity mismatchOil, coal, arms, dual-use, or luxury goods risksApply product-specific restrictions

Securities, investment, and capital markets

ScenarioSanctions issue
Listed issuer is sanctionedTrading, custody, dividends, corporate actions may be restricted
Issuer is owned by sanctioned partyUnlisted entity restrictions may apply
Sectoral debt/equity restrictionSecurity may be restricted even if issuer is not fully blocked
Fund holds sanctioned securitiesInvestor exposure may require divestment, blocking, or restrictions depending on law
Derivative references sanctioned issuerEconomic exposure may be restricted
Corporate actionRights issue, dividend, coupon, conversion, redemption can involve prohibited dealing
Custody accountHolding assets may be permitted or frozen depending on regime; movement may be restricted
Investment adviserAdvice or facilitation may be restricted even if adviser does not hold assets

Digital assets and sanctions

TopicSanctions relevance
Wallet screeningSanctions lists may identify digital currency addresses
Exchange exposureDirect or indirect exposure to sanctioned exchange, mixer, ransomware wallet, or darknet market
Chain hoppingMovement across assets or chains can obscure origin
Mixers/tumblersMay indicate obfuscation and sanctions evasion
RansomwarePayment may involve sanctioned actors or wallets
DeFi protocolsCounterparty identification can be difficult; smart contracts do not remove sanctions risk
Travel rule dataWhere available, supports originator/beneficiary transparency
GeolocationIP, device, and residency data may show restricted jurisdiction nexus

Evasion typologies

TypologyRed flagsControls
Shell/front companyNo website, nominee directors, shared address, recent incorporationEnhanced due diligence, ownership verification
TransshipmentGoods routed through unrelated third countryRoute review, end-use checks, document consistency
Name manipulationMisspellings, initials, reordered namesFuzzy screening, alias matching, manual review
Ownership restructuringSanctioned owner transfers shares to relatives/associatesHistorical ownership review, adverse media
Use of family/associatesPayments to close associates of designated personRelationship mapping
Vessel deceptionAIS gaps, name/flag changes, ship-to-ship transfersMaritime screening and voyage analytics
Document falsificationConflicting invoices, altered bills of ladingDocument authentication and escalation
Nested bankingHidden downstream respondent activityCorrespondent due diligence and payment transparency
Use of cash/cryptoHarder traceabilityWallet analytics, source-of-funds review
Humanitarian coverClaimed aid with high-value unrelated goodsVerify license/exemption and goods scope
Professional enablersLawyers, agents, accountants, trust providers obscure controlThird-party due diligence
Dual-use procurementSmall orders, technical goods, academic/research frontsEnd-use/end-user review

Proliferation financing focus

IndicatorWhy high-yield
Dual-use goodsOrdinary commercial items can support military or WMD programs
Small procurement ordersNetworks may buy components in low quantities to avoid attention
Academic or research frontTechnical end users may support restricted programs
Freight forwarders in transshipment hubsConceals destination and end user
Payment from unrelated third partyMasks true buyer
Inconsistent technical specificationsBuyer may not understand goods or may hide application
Links to sanctioned vessels, ports, or state entitiesElevates sanctions and proliferation risk
Refusal to provide end-use detailsStrong escalation trigger

Humanitarian activity: permitted does not mean uncontrolled

QuestionWhy it matters
Is there a general license, exemption, or specific authorization?Humanitarian intent alone is not enough
Are all parties covered?NGOs, banks, suppliers, carriers, and local partners must be checked
Are goods/services within scope?Food and medicine may differ from equipment, vehicles, or technology
Is there diversion risk?Sanctioned government, militia, or intermediary may capture goods
Are payments routed through restricted banks?Payment chain can create separate sanctions issue
Are records sufficient?Institutions need evidence of basis for processing

Investigation file essentials

File elementPurpose
Alert detailsShows what triggered review and when
Party identifiersSupports match or false-positive rationale
Screening list/programIdentifies applicable sanctions regime
Ownership/control analysisDocuments indirect risk review
Transaction/activity descriptionShows scope of potential restriction
Jurisdictional nexusExplains why a regime applies
License/exemption analysisSupports permitted activity conclusion
Decision and approverCreates accountability
Reporting recordShows required internal/external action
QA/remediation notesCaptures control improvement

Common CGSS scenario traps

Scenario wordingLikely trapBetter approach
“No exact list match”Evasion, alias, ownership, or control may still existReview identifiers, aliases, UBOs, and activity
“Customer is not in sanctioned country”Counterparty, goods, vessel, payment route, or beneficial owner may create exposureAnalyze the full transaction chain
“General license exists”Conditions may not be metVerify parties, activity, dates, goods, reporting
“Funds should be returned”Block/freeze may be requiredDetermine required disposition under applicable regime
“False positives are high”Lowering thresholds may increase false negativesTune with testing, not convenience
“Trade is humanitarian”Diversion or payment chain may be prohibitedConfirm scope and counterparties
“Entity is not listed”Owned/controlled entity may be restrictedPerform ownership/control analysis
“Foreign branch processed it”Parent, currency, clearing, or jurisdictional nexus may matterMap applicable legal nexus
“Screening vendor handles sanctions”Accountability remains with institutionRequire oversight, testing, and governance
“Customer has long relationship history”New sanctions or ownership changes can alter riskRescreen and refresh due diligence

Scenario decision matrix

If the facts show…Most defensible exam action
Exact match to blocked person and no authorizationEscalate, stop activity, block/freeze or reject as required, report where required
Possible match with missing DOB/IDPause activity under policy and gather more identifiers
False positive with strong identifier mismatchClear with documented rationale and QA trail
Entity owned by sanctioned personsTreat as restricted if applicable ownership/control rules are met
Activity potentially covered by licenseConfirm license scope and conditions before processing
Sanctioned country appears only in shipping routeReview trade, transit, port, and service restrictions before clearing
Goods are dual-use and end user is opaqueEscalate to sanctions/export-control review
Payment message omits expected counterparty dataRequest clarification; consider evasion risk
Repeated alerts for same customerReview customer risk rating and data quality, not only individual alerts
New sanctions issued affecting existing customersRescreen impacted population and review pending transactions

Last-week review checklist

  • Know the difference between blocking/freezing, rejecting, returning, and declining.
  • Practice ownership/control analysis, including direct, indirect, aggregate, and control scenarios.
  • Review sanctions screening data fields beyond customer name: UBOs, vessels, goods, banks, ports, remittance text.
  • Be able to explain why a license is conditional and not blanket permission.
  • Distinguish sanctions, AML/CFT, export controls, and proliferation financing.
  • Memorize major evasion patterns: shell companies, transshipment, AIS gaps, document manipulation, third-party payments.
  • In scenarios, identify the applicable jurisdictional nexus before deciding.
  • Do not assume “not listed” means “not restricted.”
  • For trade finance, always ask: goods, end user, end use, route, vessel, banks, and documents.
  • For alerts, document the decision path: match analysis, legal/program basis, escalation, disposition, reporting.

Cheat Sheet for CGSS Candidates

This quick review is for candidates preparing for the ACAMS Certified Global Sanctions Specialist (CGSS) exam. Use it to refresh high-yield sanctions concepts before moving into topic drills, mock exams, and detailed explanations in Finance Prep.

This page is independent review support. It is not affiliated with ACAMS and does not replace the official exam materials, current candidate guidance, or applicable laws and regulations in your jurisdiction.

Finance Prep currently has 756 original CGSS practice questions for sanctions practice. Use this page as a fast consolidation tool, then use topic drills and mixed practice to test whether you can choose the defensible sanctions-control step in a scenario.

Notes and examples

Common CGSS Candidate Mistakes

MistakeBetter approach
Treating sanctions as only name matchingReview ownership/control, sectoral restrictions, geography, goods, services, and evasion signals
Clearing a match because one identifier differsCompare all relevant identifiers and document the conclusion
Ignoring indirect benefitAsk who owns, controls, receives, benefits, or directs the activity
Choosing account closure too quicklyFirst classify the issue, escalate, and follow legal/policy requirements
Assuming software makes the decisionScreening tools create alerts; people and policy disposition them
Treating every red flag as proofRed flags require investigation, evidence, and escalation where needed
Forgetting data qualityBad data can make screening ineffective
Overlooking trade documentsSanctions risk often appears in goods, route, vessel, consignee, or end user facts
Missing facilitation riskAdvising a customer how to route around controls can create exposure
Writing weak notesA defensible decision needs facts, reasoning, approver, and follow-up

High-Yield CGSS Review Map

AreaWhat to know coldCommon exam trap
Sanctions frameworksSanctions can target countries, sectors, persons, entities, vessels, goods, services, and ownership interestsTreating every sanctions issue as a simple name-list match
GovernanceSenior oversight, risk appetite, documented accountability, independent testing, and control ownership matterAssuming screening software alone is the sanctions program
Risk assessmentCustomer, geography, product, channel, transaction, ownership, and third-party exposure shape control strengthApplying the same screening and review depth to every relationship
ScreeningName, payment, customer, vendor, vessel, geography, and goods screening require match disposition and documentationClearing alerts only because the name is common
Ownership and controlSanctioned-party interests can flow through ownership, control, voting rights, or indirect benefitStopping at the direct customer name and ignoring beneficial ownership
EscalationPotential true matches, high-risk ambiguity, blocked/rejected activity, and evasion indicators need escalationLetting front-line staff resolve sanctions ambiguity without review
InvestigationsBuild the facts before deciding: parties, identifiers, routing, goods, documents, purpose, and historyJumping to a report or clearance without enough evidence
Evasion typologiesFront companies, transshipment, dual-use goods, altered documents, ownership opacity, and routing changes are key red flagsTreating one clean document as proof that the transaction is safe
Reporting and post-decision controlsBlocking, rejection, reporting, account restrictions, and senior/legal escalation depend on facts and jurisdictionChoosing a generic report or account closure without first classifying the issue

The Core CGSS Decision Model

Most sanctions scenarios reduce to a practical chain:

  1. Identify all parties and interests. Customer, beneficial owner, controller, vessel, aircraft, wallet, intermediary, bank, vendor, consignee, end user, and beneficiary.
  2. Identify the restriction type. List-based, ownership/control, sectoral, geographic, goods/end-use, service, financing, facilitation, or evasion concern.
  3. Assess the evidence. Names, aliases, identifiers, ownership documents, trade documents, payment messages, shipment route, goods description, and customer history.
  4. Choose the control response. Clear, continue review, escalate, block, reject, restrict, report, or decline depending on facts and law/policy.
  5. Document the rationale. The file should show the facts reviewed, decision-maker, date, conclusion, and follow-up.
    flowchart TD
	    A[Customer, payment, trade, vendor, or counterparty activity] --> B[Identify parties, owners, controllers, goods, route, and purpose]
	    B --> C[Screen lists and review sanctions risk indicators]
	    C --> D{Possible match, prohibited exposure, or evasion signal?}
	    D -- No --> E[Document rationale and proceed under policy]
	    D -- Yes --> F[Pause or hold action under policy]
	    F --> G[Gather identifiers, ownership, trade, payment, and context evidence]
	    G --> H{Facts resolve the issue?}
	    H -- False positive --> I[Document clearance and monitor if needed]
	    H -- Possible or true issue --> J[Escalate to sanctions/legal/compliance]
	    J --> K{Required action?}
	    K -- Block/reject/report/restrict --> L[Execute required action and preserve records]
	    K -- More review --> M[Request documentation and continue investigation]
Notes and examples

Exam point: The best answer is usually the next defensible control step. Avoid answers that ignore evidence, skip escalation, or treat every concern as either harmless or automatically criminal.

Quick Decision Map

If the scenario shows…Better first response
Weak fuzzy-name match with inconsistent identifiersDocument false-positive rationale if policy supports clearance.
Possible true match with unresolved identifiersEscalate and pause action pending specialist review.
Listed party or sanctioned ownership/controlFollow blocking, rejection, reporting, and escalation requirements.
Clean party name but high-risk trade route or goodsReview end use, documents, counterparties, and evasion indicators.
Customer asks how to avoid screening or change routing after a hitTreat as an evasion red flag and escalate.
Program audit finds alert backlogs and undocumented clearancesRemediate control failure, document decisions, and strengthen oversight/testing.
Frontline staff want to release funds while review is pendingHold or restrict action under policy until sanctions review is complete.
Senior manager wants to override an alert for a valuable customerFollow escalation, legal review, and governance controls; do not clear without rationale.
Data is too incomplete to screen reliablyObtain or remediate data before relying on the result.
High false-positive volume creates backlogTune rules carefully, improve data quality, and monitor control effectiveness.

Sanctions Frameworks and Governance: Fast Distinctions

Sanctions questions often test whether you can separate the legal restriction from the operational control.

Types of Sanctions Exposure

Exposure typeWhat to identifyCommon exam angle
List-based sanctionsWhether a person, entity, vessel, aircraft, wallet, or beneficial owner appears on a sanctions listMatch quality, identifiers, aliases, and false-positive documentation
Ownership/controlWhether a listed party owns, controls, directs, or benefits from a non-listed partyDirect customer looks clean, but ownership or benefit is unresolved
Sectoral restrictionsWhether activity involves restricted sectors, debt/equity, services, technology, or financingParty is not blocked, but the activity may still be restricted
Country or region measuresWhether geography, origin, destination, routing, or beneficiary creates exposureShipment or payment touches a restricted location
Trade and export controlsWhether goods, software, technology, end use, or end user create restrictionsDual-use goods, military end user, altered documents, or suspicious routing
Facilitation riskWhether the firm or employee helps another party do what the firm cannot do directlyAdvice, routing changes, payment rewriting, or indirect support
Evasion riskWhether facts suggest a person is trying to avoid sanctions controlsFront companies, new intermediaries, vague goods, or sudden ownership changes
Notes and examples

Governance Roles

ParticipantCore responsibilityExam trap
Board or senior managementSet risk appetite, support resources, oversee program effectivenessAssuming senior leaders do daily alert disposition
First line businessOwn sanctions risk in customers, products, payments, trade, and vendorsTreating compliance as the only risk owner
Sanctions compliance functionSet standards, advise, review escalations, monitor controls, support decisionsTreating policy writing as the whole program
LegalInterpret legal obligations and advise on complex restrictions or reportingAsking frontline staff to resolve legal ambiguity alone
OperationsApply screening, holds, payment processing, and documentation proceduresReleasing a transaction before review is complete
Internal audit or independent testingTest design and operating effectivenessLetting the same team test its own work without independence

Exam point: CGSS practice is rarely about memorizing one list. It is usually about applying sanctions risk logic to a messy customer, payment, trade, or ownership fact pattern.

Ownership, Control, and Indirect Exposure

CGSS scenarios often turn on what the candidate does after the direct party looks clean.

High-Yield Ownership and Control Cues

  • A listed person owns or controls part of the customer, vendor, vessel, trust, or intermediary.
  • The direct party is new, thinly capitalized, or recently changed ownership.
  • A payment or shipment benefits a sanctioned party even if that party is not named as the customer.
  • A corporate structure has nominees, layered entities, or unexplained offshore ownership.
  • A customer changes routing, counterparty, documents, or goods descriptions after a sanctions concern appears.
Notes and examples

Exam point: Do not assume a clean first-level name screen ends the analysis when beneficial ownership, control, or benefit is unresolved.

Ownership/Control Review Table

Fact patternWhy it mattersBetter exam response
Listed person owns a minority interest but has veto rightsControl may exist without majority ownershipEscalate for ownership/control analysis
Customer is owned by several companies in different jurisdictionsLayering may obscure a sanctioned beneficial ownerBuild ownership chart and verify controllers
Trust has sanctioned settlor or protector influenceControl or benefit may not sit with legal ownerReview trust roles and escalation requirements
New intermediary appears after a sanctions concernCould be an attempt to reroute through a frontTreat as evasion signal and investigate
Payment benefits a listed party indirectlySanctions exposure can arise through benefit, not just named partyEscalate before processing
Ownership documents are stale or inconsistentScreening result may be unreliableRefresh information and document rationale

Direct, Indirect, and Beneficial Exposure

ExposurePractical question
Direct partyIs the customer, vendor, bank, vessel, or counterparty listed or restricted?
Beneficial ownerDoes a listed person ultimately own or benefit from the party?
ControllerDoes a listed person direct decisions through voting, management, contract, or influence?
IntermediaryIs a broker, agent, freight forwarder, distributor, or bank creating sanctions exposure?
Goods/end userAre the goods, technology, destination, or end user restricted?
Payment pathDoes the payment route, bank, message, or beneficiary indicate prohibited exposure?

Detecting and Investigating Evasion

Sanctions evasion questions reward careful fact gathering before final disposition.

Red flagReview focus
Transshipment through unusual routesCompare goods, ports, counterparties, and economic rationale.
Dual-use or restricted goodsReview end user, end use, licensing, documentation, and routing.
Altered or inconsistent documentsCompare invoices, bills of lading, certificates, contracts, and payment instructions.
Front or shell companiesReview ownership, business purpose, transaction history, and adverse media.
Sudden counterparty changesAsk why the customer changed the party, routing, vessel, or payment path.
Payments just below thresholdsReview whether structuring or control avoidance is plausible.
Clean customer but sanctioned beneficiaryReview indirect benefit, ownership/control, and facilitation risk.
Vague payment referencesCompare payment message to contract, invoice, goods, and counterparties.
Use of new agents or brokersReview commercial rationale, due diligence, and sanctions exposure.
Notes and examples

Trap: The best answer is often not immediate closure or immediate clearance. It may be escalation, additional documentation, enhanced review, blocking, rejection, or reporting depending on the facts and local requirements.

Trade and Payment Evasion Patterns

PatternHow it appears in a questionWhat to do first
TransshipmentShipment routes through a third country with no commercial reasonCompare route, goods, end user, and documents
MisdescriptionGoods are described generically or inconsistentlyRequest detail, review end use, and escalate if unresolved
Dual-use goodsItem can have civilian and military/restricted useReview end user, end use, licensing, and sanctions/export controls
Third-party paymentUnrelated party pays or receives fundsEstablish relationship and commercial rationale
Document alterationInvoice, bill of lading, or certificate conflicts with other recordsDo not rely on one document; compare all evidence
Shipping switchVessel, carrier, consignee, or port changes after review beginsTreat as a potential evasion indicator
Message strippingPayment references remove obvious sanctioned informationEscalate because concealment may indicate facilitation/evasion

Investigation Workflow

StepWhat good looks like
Define the issueIs the concern a list match, ownership/control concern, restricted activity, or evasion signal?
Preserve the activityHold, pause, or restrict action according to policy while review is pending.
Gather factsParties, owners, controllers, goods, end user, route, purpose, documents, payment path, and history.
Compare evidenceCheck whether documents, messages, routes, and parties tell the same story.
Seek explanation carefullyUse approved procedures and avoid tipping off or helping evade controls.
EscalateBring unresolved or high-risk matters to sanctions/legal/compliance specialists.
DecideClear, block, reject, report, restrict, decline, or continue review based on facts and law/policy.
DocumentRecord facts, rationale, decision-maker, date, and follow-up actions.

Quality Documentation

Good sanctions documentation answers:

  • What triggered the alert or investigation?
  • Which parties, owners, controllers, goods, jurisdictions, and payment paths were reviewed?
  • Which sanctions lists, restrictions, or policies were relevant?
  • Which identifiers or documents supported the decision?
  • Why was the issue cleared, escalated, blocked, rejected, or kept under review?
  • Who made or approved the decision?
  • What follow-up monitoring, remediation, or reporting is required?

Trap: “No sanctions issue found” is not enough if the file does not show why the match, ownership concern, route, or evasion signal was resolved.

Proliferation Financing and Dual-Use Goods

CGSS questions may blend sanctions, export controls, and proliferation financing. The key is to look beyond the customer name and test whether the transaction supports restricted procurement or restricted end users.

Common Proliferation-Financing Indicators

IndicatorWhy it matters
Dual-use goods, software, or technologyCivilian items may support military, nuclear, missile, or restricted programs
Unusual procurement chainMultiple brokers or front companies may hide the true end user
Inconsistent end-user certificateDocumentation may be altered or incomplete
Shipment through transshipment hubsRoute may be designed to conceal destination
Customer lacks technical capacityThe buyer does not appear able to use the goods legitimately
Payment from unrelated third partyMay hide sponsor, beneficial owner, or restricted beneficiary
Goods inconsistent with business modelProduct does not fit customer profile or prior activity
Notes and examples

What to Review

  • End user and end use.
  • Goods description and technical specifications.
  • Licensing or authorization requirements where relevant.
  • Shipping route, ports, freight forwarders, and vessel history.
  • Counterparties, brokers, distributors, and payment parties.
  • Public adverse information and sanctions proximity.

Virtual Assets, Securities, and Nonbank Exposure

Sanctions risk is not limited to bank wires. CGSS candidates should be ready for scenarios involving virtual assets, securities, insurance, fintech platforms, trade finance, charities, and third-party service providers.

ChannelSanctions risk angleControl focus
Virtual assetsWallet exposure, mixers, sanctioned wallets, ransomware, chain hoppingBlockchain analytics, wallet screening, VASP due diligence
SecuritiesIssuer, investor, broker, custodian, beneficial owner, market restrictionCustomer and issuer screening, ownership/control review
InsurancePolicyholder, beneficiary, insured asset, vessel, cargo, claims paymentParty, asset, and claims screening
Trade financeGoods, route, vessel, end user, invoice, financing bankDocument comparison and goods/end-use review
Charities and nonprofitsDiversion to sanctioned regions or entitiesPurpose, beneficiaries, partners, geography, monitoring
Third-party agentsDistributor, consultant, broker, freight forwarder, resellerThird-party due diligence and contract controls

“Best Next Step” Exam Strategy

When two answers seem plausible, choose the one that best reflects:

  1. Legal and policy compliance.
  2. Risk-based evidence gathering.
  3. Proper escalation.
  4. Holds or restrictions where required.
  5. Clear documentation.
  6. No facilitation or tipping-off behavior.

Words That Often Signal a Wrong Answer

Be cautious when an answer says:

  • “Ignore” a hit because the customer is profitable.
  • “Process first and review later.”
  • “Tell the customer how to avoid the restriction.”
  • “Clear because only the direct customer is screened.”
  • “No need to document.”
  • “Use a different bank to complete the payment.”
  • “Delete the sanctioned country reference.”
  • “Assume the intermediary checked everything.”
  • “Close the alert because the name is common” without identifiers.
  • “Skip legal/compliance because timing is urgent.”
Notes and examples

Words That Often Signal a Better Answer

Look for actions such as:

  • Verify identifiers.
  • Review ownership and control.
  • Hold or pause under policy.
  • Gather trade/payment documents.
  • Escalate to sanctions, legal, or compliance.
  • Block, reject, report, or restrict where required.
  • Remediate data or control weakness.
  • Document rationale.
  • Continue monitoring.
  • Refuse facilitation.

Rapid Final Review Checklist

Before CGSS practice questions, make sure you can explain:

  • Why sanctions exposure can exist even when the direct customer is not listed.
  • The difference between list-based, sectoral, geographic, trade, and ownership/control restrictions.
  • Why governance requires oversight, risk assessment, policies, training, testing, and remediation.
  • What makes a screening alert a false positive, possible match, or true match.
  • Which identifiers matter when reviewing a name match.
  • Why ownership, control, indirect benefit, and facilitation matter.
  • How trade documents can reveal transshipment, dual-use goods, or restricted end users.
  • Why a payment message change can be an evasion signal.
  • How sanctions screening differs from AML suspicious activity monitoring.
  • When to escalate to sanctions/legal/compliance specialists.
  • Why independent testing should evaluate control quality, not just alert volume.
  • What a defensible clearance note should include.

Rapid Review: If You Have 30 Minutes

10-Minute Framework Review

Focus on:

  • List-based sanctions are only one part of the analysis.
  • Country, sector, goods, service, ownership, and benefit restrictions can matter.
  • Governance sets accountability; operations apply controls; compliance/legal review ambiguity.
  • Risk assessment drives screening, due diligence, escalation, and monitoring strength.

10-Minute Scenario Review

Practice spotting:

  • Possible true matches.
  • Beneficial ownership issues.
  • Front or shell companies.
  • Transshipment and unusual routing.
  • Dual-use goods and restricted end users.
  • Vague or altered trade documents.
  • Payment-message stripping.
  • High-risk intermediaries.
  • Backlogs, overrides, and weak documentation.

10-Minute Question-Bank Review

Use original practice questions to test:

  • “What should the analyst do next?”
  • “Which fact is most important?”
  • “Which control failed?”
  • “Which issue requires escalation?”
  • “Which evidence best resolves the alert?”
  • “Which response avoids facilitation?”

Review the detailed explanations for both correct and incorrect options. The tempting wrong answers often reveal the exam’s favorite traps: fast clearance, missing ownership/control, weak documentation, and failure to escalate.

Practice Next

After this review, use CGSS topic drills to test whether you can apply sanctions rules under time pressure. Finance Prep’s CGSS bank has 756 original practice questions with topic drills, timed mock exams, and detailed explanations.

Need to sharpen…Use
Sanctions regimes, governance, risk appetite, and oversightMatching topic drill in Finance Prep
Program design, screening controls, procedures, training, and testingMatching topic drill in Finance Prep
Alert review, investigations, ownership/control, and evasion typologiesMatching topic drill in Finance Prep
Mixed exam-style practiceFree CGSS Practice Exam

For each missed practice question, write down:

  • The sanctions issue tested.
  • The fact that should have changed your answer.
  • The control or escalation rule you missed.
  • Why the correct answer is more defensible than the tempting answer.

Your next step: practice scenario-based questions until you can consistently identify the sanctions exposure, the evidence needed, the right escalation or disposition, and the documentation that makes the decision defensible.

Put the review into practice