Due diligence, escalation, refusal where appropriate
Cyber-enabled crime
Use of technology to steal data, funds, or credentials
Phishing, malware, business email compromise, account takeover
Cyber controls, authentication, incident response
Fast decision model
flowchart TD
A[Customer, transaction, employee, or counterparty event] --> B{Financial crime risk indicator?}
B -- No --> C[Proceed under normal controls and monitoring]
B -- Yes --> D{Can risk be understood and mitigated?}
D -- Yes --> E[Apply CDD/EDD, approvals, monitoring, restrictions]
D -- No --> F[Decline, exit, freeze, reject, or escalate as applicable]
E --> G{Suspicion formed?}
F --> G
G -- No --> H[Document rationale and continue monitoring]
G -- Yes --> I[Internal report to MLRO/nominated officer]
I --> J[Consider external SAR/STR, sanctions report, law enforcement, regulator, or FIU route]
J --> K[Do not tip off; preserve evidence]
Money laundering, terrorist financing, and proliferation financing
Laundering stages
Stage
Practical meaning
Examples
Exam trap
Placement
Introduce criminal value into the financial system
Cash deposits, money service businesses, prepaid cards, crypto purchase
Not always cash; securities or digital assets can be placement routes
Account rationale, investment mandate, business model
Generic explanations such as “investment purposes”
Source of funds
Origin of the specific money used in a transaction
Sale contract, bank statement, dividend record, inheritance document
Confusing SoF with general wealth
Source of wealth
How total wealth was accumulated
Business sale, salary history, audited accounts, asset sale
Accepting broad claims without plausibility testing
Ongoing monitoring
Activity remains consistent with profile
Alerts, periodic reviews, event-driven updates
Treating onboarding as one-time only
Source of funds vs source of wealth
Term
Focus
Example question
Good exam cue
Source of funds
Where this transaction’s money came from
“Where did the £2m subscription money originate?”
Specific transaction trail
Source of wealth
How the customer became wealthy overall
“How did the customer build net worth?”
Lifetime or business wealth narrative
Proof of funds
Evidence money exists and is available
“Is the balance present in an account?”
Existence is not the same as legitimate source
Customer due diligence review
CDD is not just collecting a passport or company document. It is the process of understanding who the customer is, who controls them, and whether the relationship makes sense.
CDD element
What to know for review
Identification
Obtain identifying information about the customer.
Verification
Check identity using reliable, independent sources where required.
Beneficial ownership
Identify natural persons who ultimately own or control a legal entity or arrangement.
Purpose and nature
Understand why the account or relationship is being established and expected activity.
Risk assessment
Classify risk using customer, geography, product, delivery channel, and transaction factors.
Screening
Check sanctions, PEP status, and adverse information according to firm procedures.
Ongoing monitoring
Keep the relationship under review; CDD is not a one-time event.
Recordkeeping
Retain evidence of checks, decisions, and updates as required by policy and law.
Simplified, standard, and enhanced due diligence
Due diligence level
When it may apply
Key point
Simplified due diligence
Lower-risk situations, where permitted
Not “no due diligence”; still requires enough understanding to justify lower risk.
Standard due diligence
Normal risk relationships
Baseline identity, verification, risk assessment, and monitoring.
Enhanced due diligence
Higher-risk customers, products, jurisdictions, PEPs, complex structures, adverse information
More evidence, senior approval where required, deeper source-of-wealth/source-of-funds work, closer monitoring.
Source of funds versus source of wealth
Term
Meaning
Example question to answer
Source of funds
Origin of the specific money used in a transaction
“Where did this transfer or deposit come from?”
Source of wealth
How the customer accumulated overall wealth
“How did this person become wealthy?”
Exam trap: a bank statement may help evidence source of funds, but it may not explain source of wealth.
Trustees/directors, controllers, donors where relevant, beneficiaries/activity
Diversion of funds, false humanitarian purpose
Conflict zone links or poor expenditure evidence
Fund/investment vehicle
Fund, manager, administrator, investors where required
Nominee platforms obscure investor risk
Unusual redemptions/subscriptions or side letters
Notes and examples
Beneficial ownership and control
Legal ownership is not always the same as true control. Financial criminals may use companies, trusts, nominees, family members, or intermediaries to hide ownership.
High-yield points:
A beneficial owner is generally the natural person who ultimately owns or controls the customer or on whose behalf a transaction is conducted.
Complex structures are not automatically illegal, but unexplained complexity is a red flag.
If a customer refuses to provide ownership information, that is not merely an administrative delay; it may be a risk indicator.
Firms should understand control through voting rights, ownership interests, management influence, powers of appointment, or other arrangements.
Reliance on another party does not usually remove the firm’s responsibility to manage its own financial crime risk.
PEPs, close associates, and adverse media
Concept
Meaning
Required exam reaction
PEP
Person entrusted with prominent public function
Higher corruption risk; apply enhanced scrutiny
Domestic PEP
PEP in the same jurisdiction as the firm/customer context
Still risk-based; not automatically low risk
Foreign PEP
PEP from another jurisdiction
Often higher-risk due to cross-border corruption exposure
International organisation PEP
Senior role in an international body
Consider access to public funds or influence
Family member
Close family connection to a PEP
Risk may derive from access or asset holding
Close associate
Business or personal association with PEP
Watch for nominee ownership or unexplained wealth
Adverse media
Negative public information
Validate source quality, relevance, recency, and connection
Notes and examples
PEP exam traps
A PEP is not automatically a criminal or prohibited customer.
EDD is about understanding risk, not simply collecting more documents.
Close associates and family members can carry risk even without public office.
Former PEPs may still pose influence risk depending on role, jurisdiction, and timing.
Source of wealth is especially important for corruption-risk cases.
Sanctions quick reference
Sanctions types and controls
Sanctions type
Restriction focus
Firm control
Scenario cue
Asset freeze/blocking
Funds or economic resources of designated persons/entities
Screen, freeze/block, stop dealing, report as applicable
Name match, ownership/control link
Trade sanctions
Goods, services, technology, sectors
Trade finance checks, goods/end-use review
Dual-use goods, unusual shipping route
Sectoral sanctions
Specific sectors, debt/equity, services, technology
Identify whether a sanctioned person owns or controls an entity
Treating non-listed entity as safe despite control link
Decide action
Proceed, reject, freeze/block, exit, report, seek licence where relevant
Continuing while “waiting for more comfort”
Document rationale
Keep audit trail of match decision and escalation
No evidence of why false positive was cleared
Sanctions red flags
Red flag
Why it matters
Counterparty recently changed name, directors, or ownership
Possible evasion after designation
Payments split across multiple banks or jurisdictions
Obscures sanctioned nexus
Goods description is vague or inconsistent with customer business
Trade sanctions/proliferation risk
Use of intermediaries in unrelated countries
Hides origin, destination, or control
Customer resists providing end-user/end-use information
Concealment risk
Vessel route, transshipment point, or port seems illogical
Sanctions evasion or trade-based laundering
Address matches sanctioned entity location
Potential direct or indirect nexus
Beneficial owner just below a disclosed threshold
Possible structuring to avoid detection
Sanctions quick review
Sanctions are different from general AML risk. A sanctioned party may not simply be “high risk”; dealing may be prohibited or restricted.
Sanctions concept
Exam focus
List-based sanctions
Screening names against sanctions lists.
Sectoral sanctions
Restrictions on certain sectors, activities, securities, services, or financing.
Geographic sanctions
Restrictions connected to countries, regions, or territories.
Ownership/control
A non-listed entity may still be restricted if owned or controlled by a sanctioned person or entity.
False positive
A possible match that is cleared after investigation.
True match
A confirmed match requiring escalation and action under policy/law.
Ongoing screening
Sanctions status can change after onboarding.
Sanctions decision rules
When a question gives a possible sanctions match:
Do not ignore it because the customer is profitable or long-standing.
Do not process the transaction first and investigate later.
Check whether it is a false positive using identifiers such as date of birth, address, registration number, nationality, ownership, and transaction details.
Escalate according to firm procedure if the match cannot be cleared.
Preserve records of the review and decision.
Avoid tipping off or improper disclosure where confidentiality rules apply.
Common trap: applying normal risk appetite to sanctions. A firm may accept higher AML risk with controls, but sanctions restrictions may prohibit activity entirely.
Customer red flags
Reluctance to provide identification or beneficial ownership information.
Complex structure with no clear commercial rationale.
Use of nominees, shell companies, or opaque trusts.
Adverse media involving fraud, corruption, sanctions, tax crime, or organised crime.
Customer’s wealth or activity inconsistent with known profile.
Frequent changes in ownership, address, or directors.
Transaction red flags
Rapid movement of funds in and out with little economic purpose.
Transactions just below reporting or review thresholds.
Third-party payments without clear rationale.
Payments to or from high-risk jurisdictions.
Round-dollar or repetitive transfers.
Unusual cash activity.
Early repayment, cancellation, or surrender inconsistent with customer profile.
Behavioural red flags
Urgency or pressure to bypass controls.
Unwillingness to explain transaction purpose.
Overly defensive or inconsistent explanations.
Use of multiple advisers to avoid scrutiny.
Attempts to influence staff or offer inducements.
Suspicion, escalation, and reporting
Suspicion decision cues
Observation
Weak explanation
Stronger suspicion cue
Unusual transaction size
“Customer is wealthy”
Size inconsistent with known profile and no credible source
Complex structure
“Tax planning”
No commercial rationale; control hidden through nominees
Frequent round-number payments
“Business activity”
Repeated, structured, no invoices or weak documentation
Customer refuses information
“Privacy concerns”
Refusal prevents required CDD or transaction understanding
Rapid in/out movement
“Investment strategy”
No market rationale, third-party funds, circular transfers
Restrict, continue, delay, exit, or seek consent/defence where applicable
Avoid tipping off and preserve confidentiality
Recordkeeping
Document reasons, decisions, evidence, timestamps
Poor records undermine defensibility
Tipping off and confidentiality
Action
Risk
Telling customer “we filed a SAR”
Clear tipping-off risk
Asking neutral CDD questions
Usually acceptable if not revealing suspicion
Closing account immediately after suspicious query without plan
May alert customer and disrupt investigation
Sharing details only with need-to-know internal staff
Appropriate confidentiality control
Discussing suspicion casually with relationship manager network
Breach of confidentiality and control weakness
Suspicion, escalation, and reporting
The exam often tests the difference between a concern, an unusual transaction, and a suspicion.
Stage
Meaning
Good response
Unusual
Activity differs from expected profile
Review, ask appropriate questions, check records
Unexplained
Customer explanation is weak, inconsistent, or unsupported
Escalate for further review
Suspicious
There is a reasonable basis to suspect financial crime
Internal report according to procedure
Confirmed/prohibited
Sanctions true match or confirmed criminal activity
Stop/hold where required, escalate, follow legal and firm process
Suspicion does not require proof
A frequent candidate mistake is looking for courtroom-level evidence. Financial crime reporting is generally triggered by suspicion or knowledge, not proof beyond doubt. The employee’s role is usually to recognise red flags and escalate through the firm’s process, not to conduct an unauthorised investigation.
Tipping off
Tipping off risk arises when a customer or third party is alerted that a report, investigation, or suspicion exists in a way that may prejudice an investigation.
Practical exam rules:
Do not tell the customer that a suspicious activity report has been or will be made.
Do not invent false reasons; follow firm procedures.
You may ask ordinary due diligence questions where appropriate, but avoid revealing suspicion.
Escalate uncertainty to the appropriate internal function.
Bribery and corruption
Bribery risk table
Risk area
Red flags
Controls
Gifts and hospitality
Excessive value, poor timing, linked to tender or approval
Donation near business decision, third-party routing
Senior approval, transparency, legal review
Sponsorship/charity
Benefit to official’s preferred charity
Due diligence, purpose testing, monitoring
Recruitment/internships
Candidate linked to client or official
Conflict review and documented merit process
Notes and examples
Bribery exam distinctions
Concept
Distinction
Bribe
Improper advantage offered, promised, given, requested, or received
Facilitation payment
Small payment to speed routine action; often high-risk or prohibited by firm policy
Hospitality
Can be legitimate if proportionate and transparent; risky if intended to influence
Kickback
Secret return of part of a payment as reward for business
Third-party bribery
Firm may be exposed through agents, consultants, distributors, or introducers
Adequate procedures/controls
Risk assessment, due diligence, communication, training, monitoring, senior commitment
Bribery and corruption
Bribery risk often appears through gifts, hospitality, introducers, consultants, public officials, procurement, charitable donations, sponsorships, and facilitation payments.
Risk indicator
Why it matters
Public official involvement
Higher risk of improper influence or abuse of office.
Excessive gift or hospitality
May be intended to influence a decision.
Payment to offshore consultant
May hide a bribe or improper commission.
Vague service description
No clear legitimate business purpose.
Success fee tied to licence/contract
Incentivises improper influence.
Urgent payment before award
Timing suggests inducement.
Refusal to document services
Indicates lack of transparency.
Facilitation payment
Often high risk and may be illegal under relevant law/policy.
ABC controls to remember
Clear anti-bribery and corruption policy.
Gifts, hospitality, donations, and sponsorship registers.
Approval thresholds and independent review.
Third-party due diligence.
Contract clauses and audit rights.
Training for high-risk employees.
Whistleblowing and escalation channels.
Monitoring of payments, invoices, and expense claims.
Exam trap: assuming a small payment cannot be a bribe. The issue is improper advantage, intent, context, and applicable rules, not just size.
Financial crime prevention is a firm-wide responsibility, not only a compliance department task.
Control area
What good looks like
Senior management oversight
Clear accountability, risk appetite, resources, management information
Policies and procedures
Written, current, practical, aligned to risk
Training
Role-specific, refreshed, tested, documented
Screening
Customer, counterparty, employee, transaction, and sanctions screening as relevant
Monitoring
Rules, alerts, typologies, manual review, quality control
Independent testing
Audit or assurance review of control design and effectiveness
Recordkeeping
Evidence of CDD, risk decisions, approvals, reports, investigations
Whistleblowing
Safe channels for raising concerns
Remediation
Fix control gaps and track actions to closure
Exam trap: choosing a control that sounds strong but is not targeted. For example, more training may help awareness, but it will not replace sanctions screening, segregation of duties, or transaction monitoring where those are the actual control gap.
Alert and investigation handling
Investigation step
Good practice
Weak practice
Define alert
State what triggered review
“System alert” with no detail
Gather facts
KYC, transactions, counterparties, documents, open source
In sanctions questions, remember: do not rely only on exact name matches; assess ownership/control and transaction nexus.
In bribery questions, look for improper advantage, timing, third parties, public officials, and weak service evidence.
In fraud questions, separate customer victim fraud, firm victim fraud, internal fraud, and market-facing fraud.
In market abuse questions, focus on inside information, misleading impression, order behaviour, and timing.
High-yield exam mindset
The CISI CFC exam is likely to test both knowledge and judgement. Many questions are not asking “what is the definition?” but “what should a firm or employee do next?”
Asking the customer questions that reveal a report may be made
The practical control cycle
Most financial crime frameworks follow a cycle. If you can place the scenario into this cycle, you can usually narrow the answer choices quickly.
Identify the customer, counterparty, product, transaction, employee, or third party involved.
Assess risk using relevant factors: customer type, geography, product, delivery channel, transaction pattern, and adverse information.
Prevent misuse through policies, CDD, screening, approvals, limits, and training.
Detect unusual or suspicious behaviour through monitoring, alerts, reconciliations, and staff vigilance.
Escalate and report internally, and externally where required through the appropriate officer or process.
Record and review decisions, evidence, rationale, and control effectiveness.
Exam shortcut: when the scenario contains uncertainty, the best answer is often not “ignore,” “close immediately,” or “accuse the customer.” It is usually to pause, gather appropriate information, escalate internally, and follow procedure.
AML and CTF essentials
Money laundering stages
Stage
What happens
Example
Placement
Criminal proceeds enter the financial system
Cash deposits, purchase of monetary instruments
Layering
Transactions obscure source and ownership
Transfers through multiple accounts or jurisdictions
Integration
Funds appear legitimate and are used openly
Investment in property, securities, business assets
Notes and examples
Exam trap: not every scenario fits neatly into one stage. If funds are being moved through multiple entities or jurisdictions to hide origin, the exam often points to layering.
Terrorist financing versus money laundering
Feature
Money laundering
Terrorist financing
Primary concern
Source of funds is criminal
Use or destination of funds supports terrorism
Fund origin
Usually illicit
May be illicit or legitimate
Transaction size
Can be large, complex, or structured
May involve small amounts
Key question
“Where did the money come from?”
“Where is the money going and why?”
Common mistake: assuming terrorist financing always involves large or obviously criminal funds. Small-value transactions can matter if the destination, pattern, or purpose is suspicious.
Politically exposed persons
A politically exposed person, or PEP, presents higher corruption and bribery risk because of public function or influence. The risk may extend to family members and close associates, depending on applicable rules and firm policy.
PEP issue
Review point
PEP status
Not a crime and not automatically a reason to reject.
Risk
Higher potential for bribery, corruption, embezzlement, and abuse of office.
Controls
Enhanced due diligence, source-of-wealth review, senior management approval where required, ongoing monitoring.
Time factor
Former PEPs may still present risk depending on role, influence, jurisdiction, and firm policy.
Common trap
Treating a domestic or lower-profile PEP as risk-free without assessment.
Fraud and cyber-enabled financial crime
Fraud is deception for gain or to cause loss. In financial services, fraud often overlaps with AML because the proceeds of fraud may then need to be laundered.
Rationalisation: “I deserve it,” “I will repay it,” “everyone does it.”
Exam use: if the question asks how to reduce fraud risk, focus on reducing opportunity through controls, oversight, and accountability.
Market abuse and inside information
Depending on the scenario, financial crime can include misuse of markets and confidential information.
Concept
Review point
Inside information
Non-public, price-sensitive information relating to issuers or instruments.
Insider dealing
Trading or encouraging trading while in possession of inside information.
Improper disclosure
Sharing inside information without proper reason.
Market manipulation
Creating false or misleading signals about supply, demand, or price.
Information barriers
Controls that restrict flow of confidential information.
Surveillance
Monitoring orders, trades, communications, and patterns.
Common trap: believing market abuse requires a successful profit. Attempted manipulation, improper disclosure, or suspicious behaviour may still require escalation.
Third parties, introducers, and outsourcing
Third parties can create major financial crime exposure because they may interact with customers, officials, or payments outside the firm’s direct view.
Third-party risk
Candidate focus
Introducers
Who is the customer? Who performed CDD? Can the firm rely on it?
Agents/consultants
What service is provided? Is payment proportionate and transparent?
Outsourcing
The task may be outsourced, but accountability and oversight remain important.
Correspondent relationships
Higher exposure to another institution’s customers and controls.
Suppliers
Fraud, bribery, sanctions, and cyber risks.
Red flags include unclear ownership, refusal to provide due diligence, unusual commission structures, connections to public officials, use of offshore accounts, and pressure to bypass onboarding.
Trade finance and proliferation risk
Trade finance scenarios can combine AML, sanctions, fraud, and proliferation financing risk.
Red flag
Why it matters
Goods inconsistent with customer business
Possible disguise of true transaction purpose
Dual-use goods
May have civilian and military applications
Unusual shipping route
Potential sanctions evasion or diversion
Inconsistent documents
Fraud or concealment
Over- or under-invoicing
Value transfer or trade-based money laundering
Last-minute changes to counterparties
Possible sanctions or ownership concealment
High-risk destination or transshipment point
Diversion, sanctions, or proliferation concern
Exam approach: trade finance questions often require checking the full chain: buyer, seller, goods, vessel, ports, insurers, banks, ownership, documentation, and payment flow.
Scenario-answer technique
When using the question bank, practise reading each scenario in this order:
Identify the financial crime risk
AML, CTF, sanctions, bribery, fraud, market abuse, cyber, tax, or mixed risk.
Identify the trigger
New customer, transaction alert, adverse media, sanctions hit, employee concern, whistleblowing report, third-party issue, or monitoring review.
Locate the control point
Onboarding, CDD refresh, screening, EDD, monitoring, escalation, reporting, recordkeeping, or exit.
Apply proportionality
Is the risk low, normal, high, prohibited, or suspicious?
Avoid extreme answers unless justified
Immediate closure, customer accusation, processing despite a hit, or ignoring a red flag are usually wrong unless the facts clearly support them.
Choose the answer that preserves control
Stop or pause where needed, escalate, document, and follow procedure.
Rapid review tables
“What should happen next?”
Scenario clue
Likely next step
Possible sanctions match
Pause activity, investigate match, escalate if unresolved
Customer refuses beneficial ownership details
Do not proceed normally; escalate and assess relationship
Transaction inconsistent with known profile
Review expected activity and seek appropriate explanation
Explanation inconsistent or implausible
Escalate suspicion internally
Staff member offered expensive gift during tender
Decline/report according to gifts and ABC policy
New agent requests commission to offshore account
Conduct enhanced third-party due diligence and escalate
PEP identified after onboarding
Reassess risk, apply EDD, obtain approvals where required
Employee suspects laundering
Report internally through the required channel
Customer asks whether they are being investigated
Avoid tipping off; follow internal guidance
Trade documents inconsistent
Investigate, verify, and escalate if unresolved
Notes and examples
Key distinctions
Distinction
Remember
Identification vs verification
Collecting identity details vs checking them against reliable evidence.
Source of funds vs source of wealth
Specific transaction money vs overall wealth origin.
Unusual vs suspicious
Different from expected vs reasonable basis for suspicion.
Sanctions risk vs AML risk
Sanctions may prohibit activity; AML risk may be managed if acceptable.
Bribe vs gift
A bribe involves improper advantage; a gift may be legitimate only if transparent, proportionate, and policy-compliant.
Outsourcing vs accountability
A firm may outsource tasks, not responsibility for oversight.
False positive vs true match
Cleared possible match vs confirmed sanctions concern.
Fraud prevention vs AML reporting
Preventing loss vs detecting/reporting proceeds or suspicious activity; both may apply.
Final readiness check
Before sitting the CISI Combating Financial Crime exam, confirm that you can explain without notes:
The stages of money laundering and how terrorist financing differs.
How CDD, EDD, beneficial ownership, PEP controls, and ongoing monitoring fit together.
What to do with sanctions matches and why sanctions are not just “high-risk AML.”
The red flags for bribery, corruption, fraud, market abuse, and trade-based financial crime.
When to escalate suspicion and how to avoid tipping off.
How governance, training, monitoring, recordkeeping, and independent testing support an effective control framework.
Next step: use the question bank for targeted topic drills, then review every missed item with detailed explanations until you can identify the risk, control point, and correct escalation step quickly.