CISI CFC — CISI Combating Financial Crime Cheat Sheet

Cheat sheet: CISI CFC reference for AML, CTF, sanctions, bribery, fraud, CDD, risk controls, reporting, and exam traps.

Use the tables for a quick pre-exam check. Expand a topic’s notes for explanations, examples, and additional distinctions.

Scope and study context
  • Recognise the main forms of financial crime and how they interact.
  • Apply a risk-based approach to customers, products, jurisdictions, delivery channels, and transactions.
  • Distinguish identification, verification, screening, monitoring, escalation, and reporting duties.
  • Spot exam traps around suspicion, sanctions, beneficial ownership, PEPs, bribery, fraud, and tipping off.
  • Practise scenario-based judgement with original practice questions rather than relying only on memorised definitions.

After this Cheat Sheet, move into independent companion practice with a deliberate plan:

  • Start with topic drills for AML/CTF, sanctions, bribery, fraud, and controls.
  • For each missed question, write down the decision rule you failed to apply.
  • Use detailed explanations to compare why the correct answer is better than the tempting distractor.
  • Revisit mixed scenarios, because real exam questions often combine sanctions, AML, fraud, and governance issues.
  • Finish with timed mock-style sets to practise speed and judgement.

Core financial crime map

AreaWhat the criminal wantsTypical firm exposureHigh-yield exam distinction
Money launderingMake criminal proceeds appear legitimateAccounts, securities trading, funds, payments, private wealth, trade financeFocus is proceeds of crime and concealment of origin
Terrorist financingMove or store value for terrorist purposesSmall payments, charities, remittances, cash, crypto, tradeFunds may be lawful or unlawful; purpose is key
Proliferation financingSupport WMD-related goods, technology, or networksTrade finance, dual-use goods, shipping, sanctions evasionOften overlaps with sanctions, trade controls, shell companies
Sanctions breach/evasionAccess restricted funds, markets, goods, or servicesOnboarding, payments, securities, custody, trade, beneficial ownershipScreening alone is not enough; ownership/control matters
Bribery and corruptionObtain improper advantageGifts, hospitality, introducers, procurement, government interactionIncludes indirect bribes through agents or third parties
FraudGain through deceptionAccount takeover, false instructions, investment scams, internal fraudVictim may be the firm, customer, market, or third party
Tax evasion facilitationHelp another evade taxOffshore structures, advisers, complex ownership, false declarationsDistinguish lawful tax planning from dishonest evasion
Market abuseDistort market integrity or misuse informationTrading, research, order handling, disclosuresConduct may be abusive even without classic laundering
Notes and examples

Core financial crime map

Financial crime topics overlap. In exam scenarios, identify the primary risk, but stay alert to secondary risks.

AreaCore ideaTypical red flagsControl response
Money launderingDisguising criminal proceeds so they appear legitimateComplex structures, unexplained wealth, rapid movement of funds, third-party paymentsCDD, EDD, monitoring, internal reporting, recordkeeping
Terrorist financingMoving or using funds to support terrorism; funds may be legitimate or criminalSmall repeated transfers, high-risk locations, charities misused, unusual cash patternsCTF screening, monitoring, escalation, sanctions checks
Sanctions breachDealing with prohibited persons, entities, sectors, goods, services, or jurisdictionsName match, ownership/control link, unusual routing, trade with restricted locationScreening, match review, freezing/blocking where applicable, escalation
Bribery and corruptionOffering, giving, receiving, or soliciting improper advantagePublic official involvement, excessive hospitality, vague consultancy fees, success feesABC controls, approvals, gifts register, third-party due diligence
FraudDishonest deception for gain or to cause lossInvoice changes, identity inconsistencies, pressure tactics, override requestsSegregation of duties, verification, investigation, reporting
Market abuse / insider dealingMisuse of inside information or market manipulationTrading before announcements, false rumours, suspicious order patternsInformation barriers, surveillance, escalation
Tax evasion facilitationHelping another person evade tax, depending on jurisdictional rulesArtificial structures, false invoices, unexplained offshore arrangementsDue diligence, escalation, refusal where appropriate
Cyber-enabled crimeUse of technology to steal data, funds, or credentialsPhishing, malware, business email compromise, account takeoverCyber controls, authentication, incident response

Fast decision model

    flowchart TD
	A[Customer, transaction, employee, or counterparty event] --> B{Financial crime risk indicator?}
	B -- No --> C[Proceed under normal controls and monitoring]
	B -- Yes --> D{Can risk be understood and mitigated?}
	D -- Yes --> E[Apply CDD/EDD, approvals, monitoring, restrictions]
	D -- No --> F[Decline, exit, freeze, reject, or escalate as applicable]
	E --> G{Suspicion formed?}
	F --> G
	G -- No --> H[Document rationale and continue monitoring]
	G -- Yes --> I[Internal report to MLRO/nominated officer]
	I --> J[Consider external SAR/STR, sanctions report, law enforcement, regulator, or FIU route]
	J --> K[Do not tip off; preserve evidence]

Money laundering, terrorist financing, and proliferation financing

Laundering stages

StagePractical meaningExamplesExam trap
PlacementIntroduce criminal value into the financial systemCash deposits, money service businesses, prepaid cards, crypto purchaseNot always cash; securities or digital assets can be placement routes
LayeringCreate distance from source using complexityMultiple transfers, cross-border movements, shell companies, back-to-back tradesComplex activity with no commercial rationale is a key cue
IntegrationReintroduce value as apparently legitimate wealthProperty, investments, loans, dividends, luxury assetsIntegration often looks like normal wealth unless source is challenged
Notes and examples

AML / CTF / proliferation distinction

QuestionMoney launderingTerrorist financingProliferation financing
Source of fundsUsually criminal proceedsLawful or unlawfulLawful, unlawful, state-linked, or front-company funds
Main concernConcealing origin/ownershipIntended use for terrorismSupport for restricted goods, technology, or networks
Transaction sizeCan be large or structuredOften small and frequent, but not alwaysMay involve trade, shipping, procurement, or high-value goods
Common red flagsShells, nominees, unexplained wealthCharities/NPO misuse, high-risk regions, unusual remittancesDual-use goods, vague invoices, unusual shipping routes
Control emphasisCDD, EDD, monitoring, SARCDD, monitoring, sanctions, SARSanctions, trade finance due diligence, end-use/end-user checks

Risk-based approach

Risk equation for exam thinking

Use this as a conceptual model, not a precise calculation:

\[ \text{Residual risk} = \text{Inherent risk} - \text{Control effectiveness} \]
Risk layerExamplesCandidate action in a scenario
Customer riskPEP, non-resident, complex company, cash-intensive business, charity, crypto exchangeIdentify whether standard CDD is enough or EDD is required
Product/service riskPrivate banking, correspondent banking, trade finance, virtual assets, bearer-like instrumentsAsk whether product enables anonymity, speed, complexity, or cross-border movement
Geography riskSanctioned, conflict, secrecy, corruption, weak AML controls, tax haven indicatorsDo not assume nationality alone is risk; connect geography to exposure
Channel riskNon-face-to-face onboarding, intermediaries, introducers, digital-onlyLook for impersonation, weak verification, reliance risk
Transaction riskUnusual size, speed, source, purpose, counterparties, circularityCompare to known profile and stated purpose
Delivery/third-party riskAgents, consultants, finders, distributors, payment processorsConsider bribery, CDD reliance, outsourcing oversight
Notes and examples

Risk-based approach

The risk-based approach means allocating effort where risk is higher. It is not a permission to ignore low-risk areas.

Risk factorHigher-risk examples
CustomerPEPs, cash-intensive businesses, complex ownership, charities in high-risk areas, money service businesses
GeographyJurisdictions with higher corruption, weak AML controls, sanctions exposure, conflict or terrorism concerns
Product/servicePrivate banking, correspondent banking, trade finance, high-value transfers, anonymity-enhancing products
Delivery channelNon-face-to-face onboarding, intermediaries, digital channels without strong controls
TransactionUnusual size, frequency, routing, purpose, third-party involvement, rapid in/out movement

Good exam answers usually show proportionality:

  • Low risk: appropriate simplified or standard controls if permitted.
  • Medium risk: standard CDD and monitoring.
  • High risk: enhanced due diligence, senior review where required, more frequent monitoring, stronger evidence.
  • Unacceptable risk: decline, exit, block, freeze, or report as appropriate.

CDD, EDD, and ongoing monitoring

Customer due diligence decision table

SituationLikely controlWhat to verify or understandTypical escalation
Low-risk, transparent customerStandard CDD or simplified measures where permittedIdentity, purpose, expected activityNormal approval
Higher-risk customerEDDSource of wealth, source of funds, ownership/control, senior approvalCompliance/MLRO review
PEP or close associate/family linkEDDPublic function, influence, SoW/SoF, corruption exposureSenior management approval where required
Complex corporate structureEnhanced ownership reviewBeneficial owners, controllers, nominees, rationale for structureEscalate if opaque or unverifiable
Trust/foundation/SPVLegal arrangement reviewSettlor/founder, trustees/directors, protectors, beneficiaries, controllersEscalate if control is hidden
Intermediary-introduced customerReliance/outsourcing controlsWho performed CDD, access to evidence, accountabilityDo not outsource responsibility blindly
Existing customer with new unusual activityTrigger-event reviewUpdated KYC, transaction purpose, source of fundsSAR/STR consideration
Sanctions matchSanctions investigationIdentity match, ownership/control, transaction nexusFreeze/reject/report as applicable
Notes and examples

CDD evidence reference

CDD elementMeaningEvidence examplesCommon weakness
IdentityCustomer is who they claim to beGovernment ID, registry extract, verified digital IDCollecting a document without verifying authenticity
VerificationIndependent confirmation of identity/detailsReliable independent sources, databases, certified documentsRelying only on customer statements
Beneficial ownershipNatural persons who ultimately own or controlShare registers, corporate filings, ownership chart, trust deedStopping at a company rather than natural persons
Purpose and intended natureWhy the relationship exists and expected activityAccount rationale, investment mandate, business modelGeneric explanations such as “investment purposes”
Source of fundsOrigin of the specific money used in a transactionSale contract, bank statement, dividend record, inheritance documentConfusing SoF with general wealth
Source of wealthHow total wealth was accumulatedBusiness sale, salary history, audited accounts, asset saleAccepting broad claims without plausibility testing
Ongoing monitoringActivity remains consistent with profileAlerts, periodic reviews, event-driven updatesTreating onboarding as one-time only

Source of funds vs source of wealth

TermFocusExample questionGood exam cue
Source of fundsWhere this transaction’s money came from“Where did the £2m subscription money originate?”Specific transaction trail
Source of wealthHow the customer became wealthy overall“How did the customer build net worth?”Lifetime or business wealth narrative
Proof of fundsEvidence money exists and is available“Is the balance present in an account?”Existence is not the same as legitimate source

Customer due diligence review

CDD is not just collecting a passport or company document. It is the process of understanding who the customer is, who controls them, and whether the relationship makes sense.

CDD elementWhat to know for review
IdentificationObtain identifying information about the customer.
VerificationCheck identity using reliable, independent sources where required.
Beneficial ownershipIdentify natural persons who ultimately own or control a legal entity or arrangement.
Purpose and natureUnderstand why the account or relationship is being established and expected activity.
Risk assessmentClassify risk using customer, geography, product, delivery channel, and transaction factors.
ScreeningCheck sanctions, PEP status, and adverse information according to firm procedures.
Ongoing monitoringKeep the relationship under review; CDD is not a one-time event.
RecordkeepingRetain evidence of checks, decisions, and updates as required by policy and law.

Simplified, standard, and enhanced due diligence

Due diligence levelWhen it may applyKey point
Simplified due diligenceLower-risk situations, where permittedNot “no due diligence”; still requires enough understanding to justify lower risk.
Standard due diligenceNormal risk relationshipsBaseline identity, verification, risk assessment, and monitoring.
Enhanced due diligenceHigher-risk customers, products, jurisdictions, PEPs, complex structures, adverse informationMore evidence, senior approval where required, deeper source-of-wealth/source-of-funds work, closer monitoring.

Source of funds versus source of wealth

TermMeaningExample question to answer
Source of fundsOrigin of the specific money used in a transaction“Where did this transfer or deposit come from?”
Source of wealthHow the customer accumulated overall wealth“How did this person become wealthy?”

Exam trap: a bank statement may help evidence source of funds, but it may not explain source of wealth.

Beneficial ownership and control

Entity typeWho to identifyWhat can go wrongHigher-risk cue
Private companyNatural-person owners and controllersNominee shareholders, bearer-like arrangements, layered offshore entitiesNo clear economic rationale for structure
Listed companyEntity and relevant controllers under local rulesAssuming listed status removes all riskSuspicious transaction still requires review
PartnershipPartners, controllers, beneficial ownersInformal control by non-partnerUnusual capital contributions
TrustSettlor, trustees, protector, beneficiaries/classes, controllersDiscretionary beneficiaries used to hide interestHigh-risk settlor or opaque protector
FoundationFounder, council/board, beneficiaries, controllersControl hidden through bylaws or protectorsSecrecy jurisdiction with asset-holding purpose
Charity/NPOTrustees/directors, controllers, donors where relevant, beneficiaries/activityDiversion of funds, false humanitarian purposeConflict zone links or poor expenditure evidence
Fund/investment vehicleFund, manager, administrator, investors where requiredNominee platforms obscure investor riskUnusual redemptions/subscriptions or side letters
Notes and examples

Beneficial ownership and control

Legal ownership is not always the same as true control. Financial criminals may use companies, trusts, nominees, family members, or intermediaries to hide ownership.

High-yield points:

  • A beneficial owner is generally the natural person who ultimately owns or controls the customer or on whose behalf a transaction is conducted.
  • Complex structures are not automatically illegal, but unexplained complexity is a red flag.
  • If a customer refuses to provide ownership information, that is not merely an administrative delay; it may be a risk indicator.
  • Firms should understand control through voting rights, ownership interests, management influence, powers of appointment, or other arrangements.
  • Reliance on another party does not usually remove the firm’s responsibility to manage its own financial crime risk.

PEPs, close associates, and adverse media

ConceptMeaningRequired exam reaction
PEPPerson entrusted with prominent public functionHigher corruption risk; apply enhanced scrutiny
Domestic PEPPEP in the same jurisdiction as the firm/customer contextStill risk-based; not automatically low risk
Foreign PEPPEP from another jurisdictionOften higher-risk due to cross-border corruption exposure
International organisation PEPSenior role in an international bodyConsider access to public funds or influence
Family memberClose family connection to a PEPRisk may derive from access or asset holding
Close associateBusiness or personal association with PEPWatch for nominee ownership or unexplained wealth
Adverse mediaNegative public informationValidate source quality, relevance, recency, and connection
Notes and examples

PEP exam traps

  • A PEP is not automatically a criminal or prohibited customer.
  • EDD is about understanding risk, not simply collecting more documents.
  • Close associates and family members can carry risk even without public office.
  • Former PEPs may still pose influence risk depending on role, jurisdiction, and timing.
  • Source of wealth is especially important for corruption-risk cases.

Sanctions quick reference

Sanctions types and controls

Sanctions typeRestriction focusFirm controlScenario cue
Asset freeze/blockingFunds or economic resources of designated persons/entitiesScreen, freeze/block, stop dealing, report as applicableName match, ownership/control link
Trade sanctionsGoods, services, technology, sectorsTrade finance checks, goods/end-use reviewDual-use goods, unusual shipping route
Sectoral sanctionsSpecific sectors, debt/equity, services, technologyProduct-level restriction checksEnergy, finance, defence, technology exposure
Arms embargoMilitary goods/servicesGoods classification, end-user reviewMilitary end user or broker
Travel banMovement of individualsUsually less direct for financial firmsCan support risk assessment
Comprehensive country restrictionsBroad dealings with a territory or stateGeolocation, counterparty, ownership, transaction screeningCountry/territory nexus
Notes and examples

Sanctions screening process

StepWhat to doCommon error
Screen customer and related partiesCustomer, beneficial owner, controller, signatory, director, trustee, counterpartyScreening only the account holder
Screen transactionsOriginator, beneficiary, banks, vessels, goods, ports, messagesIgnoring free-text fields or trade documents
Investigate possible matchCompare identifiers: DOB, address, nationality, ID, aliases, ownershipClearing a match based only on name spelling
Consider ownership/controlIdentify whether a sanctioned person owns or controls an entityTreating non-listed entity as safe despite control link
Decide actionProceed, reject, freeze/block, exit, report, seek licence where relevantContinuing while “waiting for more comfort”
Document rationaleKeep audit trail of match decision and escalationNo evidence of why false positive was cleared

Sanctions red flags

Red flagWhy it matters
Counterparty recently changed name, directors, or ownershipPossible evasion after designation
Payments split across multiple banks or jurisdictionsObscures sanctioned nexus
Goods description is vague or inconsistent with customer businessTrade sanctions/proliferation risk
Use of intermediaries in unrelated countriesHides origin, destination, or control
Customer resists providing end-user/end-use informationConcealment risk
Vessel route, transshipment point, or port seems illogicalSanctions evasion or trade-based laundering
Address matches sanctioned entity locationPotential direct or indirect nexus
Beneficial owner just below a disclosed thresholdPossible structuring to avoid detection

Sanctions quick review

Sanctions are different from general AML risk. A sanctioned party may not simply be “high risk”; dealing may be prohibited or restricted.

Sanctions conceptExam focus
List-based sanctionsScreening names against sanctions lists.
Sectoral sanctionsRestrictions on certain sectors, activities, securities, services, or financing.
Geographic sanctionsRestrictions connected to countries, regions, or territories.
Ownership/controlA non-listed entity may still be restricted if owned or controlled by a sanctioned person or entity.
False positiveA possible match that is cleared after investigation.
True matchA confirmed match requiring escalation and action under policy/law.
Ongoing screeningSanctions status can change after onboarding.

Sanctions decision rules

When a question gives a possible sanctions match:

  1. Do not ignore it because the customer is profitable or long-standing.
  2. Do not process the transaction first and investigate later.
  3. Check whether it is a false positive using identifiers such as date of birth, address, registration number, nationality, ownership, and transaction details.
  4. Escalate according to firm procedure if the match cannot be cleared.
  5. Preserve records of the review and decision.
  6. Avoid tipping off or improper disclosure where confidentiality rules apply.

Common trap: applying normal risk appetite to sanctions. A firm may accept higher AML risk with controls, but sanctions restrictions may prohibit activity entirely.

Customer red flags

  • Reluctance to provide identification or beneficial ownership information.
  • Complex structure with no clear commercial rationale.
  • Use of nominees, shell companies, or opaque trusts.
  • Adverse media involving fraud, corruption, sanctions, tax crime, or organised crime.
  • Customer’s wealth or activity inconsistent with known profile.
  • Frequent changes in ownership, address, or directors.

Transaction red flags

  • Rapid movement of funds in and out with little economic purpose.
  • Transactions just below reporting or review thresholds.
  • Third-party payments without clear rationale.
  • Payments to or from high-risk jurisdictions.
  • Round-dollar or repetitive transfers.
  • Unusual cash activity.
  • Early repayment, cancellation, or surrender inconsistent with customer profile.

Behavioural red flags

  • Urgency or pressure to bypass controls.
  • Unwillingness to explain transaction purpose.
  • Overly defensive or inconsistent explanations.
  • Use of multiple advisers to avoid scrutiny.
  • Attempts to influence staff or offer inducements.

Suspicion, escalation, and reporting

Suspicion decision cues

ObservationWeak explanationStronger suspicion cue
Unusual transaction size“Customer is wealthy”Size inconsistent with known profile and no credible source
Complex structure“Tax planning”No commercial rationale; control hidden through nominees
Frequent round-number payments“Business activity”Repeated, structured, no invoices or weak documentation
Customer refuses information“Privacy concerns”Refusal prevents required CDD or transaction understanding
Rapid in/out movement“Investment strategy”No market rationale, third-party funds, circular transfers
Adverse media“Only an article”Credible, recent, connected to customer or funds
Notes and examples

SAR/STR workflow

StageKey actionExam caution
DetectionEmployee, system, audit, customer contact, third-party alertA single red flag may be enough to investigate
Internal escalationReport to MLRO/nominated officer or designated functionDo not investigate in a way that alerts the customer
AssessmentReview facts, KYC, activity, explanations, intelligenceSuspicion does not require proof beyond doubt
External reportFile SAR/STR or equivalent where requiredFollow jurisdictional and firm procedures
Post-report handlingRestrict, continue, delay, exit, or seek consent/defence where applicableAvoid tipping off and preserve confidentiality
RecordkeepingDocument reasons, decisions, evidence, timestampsPoor records undermine defensibility

Tipping off and confidentiality

ActionRisk
Telling customer “we filed a SAR”Clear tipping-off risk
Asking neutral CDD questionsUsually acceptable if not revealing suspicion
Closing account immediately after suspicious query without planMay alert customer and disrupt investigation
Sharing details only with need-to-know internal staffAppropriate confidentiality control
Discussing suspicion casually with relationship manager networkBreach of confidentiality and control weakness

Suspicion, escalation, and reporting

The exam often tests the difference between a concern, an unusual transaction, and a suspicion.

StageMeaningGood response
UnusualActivity differs from expected profileReview, ask appropriate questions, check records
UnexplainedCustomer explanation is weak, inconsistent, or unsupportedEscalate for further review
SuspiciousThere is a reasonable basis to suspect financial crimeInternal report according to procedure
Confirmed/prohibitedSanctions true match or confirmed criminal activityStop/hold where required, escalate, follow legal and firm process

Suspicion does not require proof

A frequent candidate mistake is looking for courtroom-level evidence. Financial crime reporting is generally triggered by suspicion or knowledge, not proof beyond doubt. The employee’s role is usually to recognise red flags and escalate through the firm’s process, not to conduct an unauthorised investigation.

Tipping off

Tipping off risk arises when a customer or third party is alerted that a report, investigation, or suspicion exists in a way that may prejudice an investigation.

Practical exam rules:

  • Do not tell the customer that a suspicious activity report has been or will be made.
  • Do not invent false reasons; follow firm procedures.
  • You may ask ordinary due diligence questions where appropriate, but avoid revealing suspicion.
  • Escalate uncertainty to the appropriate internal function.

Bribery and corruption

Bribery risk table

Risk areaRed flagsControls
Gifts and hospitalityExcessive value, poor timing, linked to tender or approvalLimits, approvals, registers, conflict checks
Agents/intermediariesSuccess fees, vague services, offshore payment requestsDue diligence, written contracts, service evidence
Public officialsFacilitation request, permit/visa/customs pressureProhibition/approval rules, escalation, training
ProcurementSole-source award, inflated invoices, related-party supplierSegregation, tender controls, conflict declarations
Political donationsDonation near business decision, third-party routingSenior approval, transparency, legal review
Sponsorship/charityBenefit to official’s preferred charityDue diligence, purpose testing, monitoring
Recruitment/internshipsCandidate linked to client or officialConflict review and documented merit process
Notes and examples

Bribery exam distinctions

ConceptDistinction
BribeImproper advantage offered, promised, given, requested, or received
Facilitation paymentSmall payment to speed routine action; often high-risk or prohibited by firm policy
HospitalityCan be legitimate if proportionate and transparent; risky if intended to influence
KickbackSecret return of part of a payment as reward for business
Third-party briberyFirm may be exposed through agents, consultants, distributors, or introducers
Adequate procedures/controlsRisk assessment, due diligence, communication, training, monitoring, senior commitment

Bribery and corruption

Bribery risk often appears through gifts, hospitality, introducers, consultants, public officials, procurement, charitable donations, sponsorships, and facilitation payments.

Risk indicatorWhy it matters
Public official involvementHigher risk of improper influence or abuse of office.
Excessive gift or hospitalityMay be intended to influence a decision.
Payment to offshore consultantMay hide a bribe or improper commission.
Vague service descriptionNo clear legitimate business purpose.
Success fee tied to licence/contractIncentivises improper influence.
Urgent payment before awardTiming suggests inducement.
Refusal to document servicesIndicates lack of transparency.
Facilitation paymentOften high risk and may be illegal under relevant law/policy.

ABC controls to remember

  • Clear anti-bribery and corruption policy.
  • Gifts, hospitality, donations, and sponsorship registers.
  • Approval thresholds and independent review.
  • Third-party due diligence.
  • Contract clauses and audit rights.
  • Training for high-risk employees.
  • Whistleblowing and escalation channels.
  • Monitoring of payments, invoices, and expense claims.

Exam trap: assuming a small payment cannot be a bribe. The issue is improper advantage, intent, context, and applicable rules, not just size.

Fraud reference

Fraud typeHow it appearsControl focus
Identity fraudFake or stolen identity, synthetic identityIdentity verification, device checks, document validation
Account takeoverChange of email, phone, password, payment destinationStrong authentication, call-back, anomaly detection
Authorised push payment scamCustomer instructed to send funds to fraudsterPayment warnings, payee verification, scam education
Investment scamUnrealistic returns, pressure, fake platformCustomer warnings, transaction monitoring, staff escalation
Invoice redirectionSupplier bank details changedIndependent verification of changes
Internal fraudEmployee misuse of access or fundsSegregation, access reviews, surveillance, whistleblowing
Market manipulation fraudFalse orders, rumours, pump-and-dumpSurveillance, order/trade monitoring
Cyber-enabled fraudPhishing, malware, business email compromiseCyber controls, incident response, fraud monitoring
ConductMeaningIndicators
Insider dealingTrading using inside informationTrading before announcement, linked accounts, unusual profit
Unlawful disclosureImproperly sharing inside informationLeaks, selective disclosure, informal tips
Market manipulationCreating false or misleading market impressionSpoofing, layering, wash trades, marking the close
Misleading statementsFalse or deceptive information affecting marketRumours, false research, misleading announcements
Front runningTrading ahead of client/order informationEmployee or proprietary trading before large client order
Pump-and-dumpInflate price then sellSocial media hype, thinly traded securities, sudden volume
Notes and examples

Market abuse vs AML

QuestionMarket abuseAML
Main harmMarket integrity and fair informationLegitimacy of funds and ownership
Typical evidenceOrders, trades, information flow, timingFunds flow, ownership, source, layering
Reporting routeMarket surveillance/compliance/regulator processMLRO/FIU/SAR route as applicable
OverlapCriminal proceeds from abuse may later be launderedSuspicious trading profits can trigger AML review

Trade-based financial crime

Red flagPossible issueReview action
Invoice price far above/below marketValue transfer, laundering, tax evasionCompare to market, prior invoices, quantity
Goods inconsistent with customer businessFront company or sanctions evasionValidate commercial purpose
Repeated amendments to letters of creditManipulation or concealmentReview rationale and counterparties
Multiple intermediaries with no roleLayering or briberyMap parties and services
Unusual shipping routeSanctions/proliferation evasionCheck ports, vessels, destination
Vague goods descriptionDual-use or restricted goods riskRequest precise classification and end use
Same address for unrelated partiesShell networkInvestigate ownership/control
Payment from unrelated third partyLaundering or fraudVerify relationship and purpose

Virtual assets and digital channels

RiskWhy it mattersControl cue
PseudonymityWallets may not directly show natural personLink wallet, customer, source, and purpose
Mixers/tumblersObscure transaction trailTreat as higher-risk; investigate source
Chain hoppingMovement across different tokens/chainsUse blockchain analytics where available
Privacy coinsReduced traceabilityEnhanced scrutiny or restriction
High-risk exchangeWeak AML controls or sanctioned exposureCounterparty risk assessment
Scam proceedsFraud victims send funds to walletsFraud and AML escalation
Rapid fiat-crypto-fiat movementLayering indicatorTransaction monitoring and SoF review

Governance and control framework

Control layerResponsibilitiesEvidence examiners expect in scenarios
Board/senior managementRisk appetite, culture, oversight, resourcesApproved policies, MI review, challenge
First lineOwn customer and transaction riskCDD quality, escalation, adherence to procedures
Compliance/financial crime functionPolicies, advisory, monitoring, testingRisk assessment, controls, guidance
MLRO/nominated officerSuspicion assessment and reporting oversightSAR/STR decisions, confidentiality, audit trail
Operations/screening teamsAlert handling, sanctions/payment controlsTimely investigation, documented decisions
Internal auditIndependent assuranceFindings, remediation tracking
HR/trainingVetting, competence, conductRole-specific training and attestations
IT/dataSystems, rules, data quality, accessAccurate screening, monitoring, access controls
Notes and examples

Financial crime policy components

ComponentWhat it should cover
Risk assessmentCustomer, product, geography, channel, transaction, third-party risks
CDD standardsIdentification, verification, beneficial ownership, purpose, ongoing monitoring
EDD triggersPEPs, sanctions exposure, high-risk jurisdictions, complex structures
Sanctions controlsScreening scope, alert handling, ownership/control, reporting
SAR/STR processInternal escalation, MLRO assessment, external reporting, confidentiality
RecordkeepingEvidence, decisions, approvals, monitoring, reports
TrainingRole-based, refreshed, tested, documented
Independent testingCompliance monitoring and audit review
RemediationIssue ownership, deadlines, validation
WhistleblowingSafe reporting of internal misconduct

Governance and internal controls

Financial crime prevention is a firm-wide responsibility, not only a compliance department task.

Control areaWhat good looks like
Senior management oversightClear accountability, risk appetite, resources, management information
Policies and proceduresWritten, current, practical, aligned to risk
TrainingRole-specific, refreshed, tested, documented
ScreeningCustomer, counterparty, employee, transaction, and sanctions screening as relevant
MonitoringRules, alerts, typologies, manual review, quality control
Independent testingAudit or assurance review of control design and effectiveness
RecordkeepingEvidence of CDD, risk decisions, approvals, reports, investigations
WhistleblowingSafe channels for raising concerns
RemediationFix control gaps and track actions to closure

Exam trap: choosing a control that sounds strong but is not targeted. For example, more training may help awareness, but it will not replace sanctions screening, segregation of duties, or transaction monitoring where those are the actual control gap.

Alert and investigation handling

Investigation stepGood practiceWeak practice
Define alertState what triggered review“System alert” with no detail
Gather factsKYC, transactions, counterparties, documents, open sourceAsking customer leading questions first
Compare to profileExpected vs actual activityLooking at transaction in isolation
Test explanationIs it plausible, evidenced, and consistent?Accepting generic explanation
Decide and escalateClear rationale: close, monitor, EDD, SAR, exit, freezeNo conclusion or owner
Preserve evidenceTimestamped notes, document copies, audit trailEditing or deleting records
Avoid contaminationNeed-to-know access, confidentialityBroad internal circulation

High-yield red flags by dimension

DimensionRed flags
CustomerReluctant to provide CDD, uses nominees, unexplained wealth, inconsistent occupation, links to adverse media
CorporateLayered offshore entities, frequent ownership changes, no employees/web presence, shared addresses, bearer-like control
TransactionRound amounts, rapid movement, third-party payments, circular flows, inconsistent purpose, early redemption
SecuritiesWash trades, pre-arranged trades, uneconomic trading, concentration in illiquid stocks, trading before news
GeographySanctions nexus, conflict zones, corruption exposure, secrecy jurisdiction, weak AML supervision
ProductHigh mobility, anonymity, transferability, early surrender, overpayment/refund risk
ChannelNon-face-to-face, introducer-led, remote document certification, unusual IP/device
BehaviourPressure, secrecy, inconsistent answers, refusal to document, sudden urgency
EmployeeOverride of controls, unusual lifestyle, close client relationships, reluctance to take leave
Third partyAgent lacks expertise, offshore success fee, related party, no service evidence

Scenario decision matrix

Scenario cueLikely issueBest response
New customer is a minister’s sibling using offshore companyPEP associate, ownership, corruption riskEDD, SoW/SoF, senior approval, ownership mapping
Payment to listed sanctioned personSanctions matchStop/freeze/reject/report as applicable; do not process
Customer says funds came from “business profits” but has no recordsWeak SoFRequest evidence; consider EDD and suspicion
Large trade finance invoice for goods outside customer’s sectorTrade-based laundering/proliferationValidate goods, end use, counterparties, pricing
Employee accepts luxury trip from broker during mandate awardBribery/conflictEscalate, gift/hospitality review, conflict controls
Multiple small transfers to conflict region charityCTF/NPO misuse riskReview charity, purpose, counterparties; escalate if suspicious
Customer asks whether account is “under investigation”Tipping-off riskProvide neutral response; avoid revealing suspicion
Insider’s relative trades before takeover announcementMarket abuseEscalate to surveillance/compliance; preserve evidence
Customer rapidly buys and sells assets with no economic rationaleLayering/market abuseInvestigate, compare profile, consider SAR
Company owned by non-sanctioned entity controlled by sanctioned personSanctions ownership/controlTreat as sanctions risk; escalate and act under procedures

Common exam traps

TrapCorrect exam mindset
“Suspicion requires proof”Suspicion is lower than proof; document reasonable grounds and escalate
“CDD ends after onboarding”Monitoring is ongoing and event-driven
“A sanctions list screen is enough”Also consider beneficial ownership, control, goods, geography, and transactions
“PEPs are prohibited”PEPs require risk-based EDD; prohibition depends on law/policy
“Beneficial owner means account signatory”Signatory may act on behalf of the true owner/controller
“Source of funds equals source of wealth”SoF is transaction-specific; SoW explains total wealth
“Outsourcing CDD transfers responsibility”A firm may outsource tasks, but accountability usually remains
“Low-value transactions are low risk”Terrorist financing and structuring may use small amounts
“Adverse media always means exit”Assess credibility, relevance, recency, and risk appetite
“If customer explains it, risk is solved”Explanation must be plausible and evidenced
“Sanctions risk only concerns customers”Counterparties, banks, vessels, goods, owners, and locations matter
“Tax avoidance and evasion are the same”Lawful planning differs from dishonest evasion or facilitation
“Compliance owns all financial crime risk”First line owns risk; compliance provides oversight and challenge
Notes and examples

Common candidate traps

TrapBetter reasoning
“The customer is long-standing, so new checks are unnecessary.”Existing customers require ongoing monitoring and updates when risk changes.
“No conviction means no suspicion.”Suspicion can exist before proof or conviction.
“A PEP must always be rejected.”PEPs usually require enhanced risk management, not automatic rejection.
“Sanctions screening is only for onboarding.”Screening should also address changes, transactions, and updated lists as relevant.
“Beneficial owner means the company on the register.”The focus is the natural person who ultimately owns or controls.
“Small transactions are low risk.”Structuring and terrorist financing may involve small amounts.
“If another firm did CDD, we have no responsibility.”Reliance and outsourcing require oversight and do not remove accountability.
“Asking more questions is always best.”After suspicion arises, questions may create tipping-off risk.
“Complexity is proof of crime.”Complexity is a red flag; assess rationale and evidence before concluding.
“Training alone fixes control failures.”Controls must match the risk: screening, monitoring, approvals, audit trails, and escalation.

Last-week revision checklist

  • Rehearse the difference between AML, CTF, proliferation financing, sanctions, bribery, fraud, tax evasion, and market abuse.
  • Memorise the practical differences between CDD, EDD, SoF, SoW, beneficial ownership, and ongoing monitoring.
  • Practise identifying the first escalation point in scenarios: MLRO, sanctions team, surveillance, senior management, or fraud team.
  • For each red flag, ask: what is unusual, what evidence is missing, and what control should be applied?
  • In reporting questions, remember: document, escalate, avoid tipping off, preserve evidence.
  • In sanctions questions, remember: do not rely only on exact name matches; assess ownership/control and transaction nexus.
  • In bribery questions, look for improper advantage, timing, third parties, public officials, and weak service evidence.
  • In fraud questions, separate customer victim fraud, firm victim fraud, internal fraud, and market-facing fraud.
  • In market abuse questions, focus on inside information, misleading impression, order behaviour, and timing.

High-yield exam mindset

The CISI CFC exam is likely to test both knowledge and judgement. Many questions are not asking “what is the definition?” but “what should a firm or employee do next?”

If the question asks about…Think first about…Common wrong move
A new clientCDD, risk assessment, beneficial ownership, sanctions/PEP screeningOpening the account before completing core checks
Unusual activityExpected profile, source of funds, suspicion threshold, escalationWaiting for proof of a crime
Sanctions hitStop, investigate, escalate, follow firm proceduresTreating it like ordinary AML risk
PEP relationshipEnhanced scrutiny and senior approval where required by policy/lawAssuming all PEPs are prohibited
Gift or hospitalityIntent, value, timing, transparency, public official riskAssuming “customary” always means acceptable
Fraud warning signsMotive, opportunity, deception, controls, reportingTreating fraud only as an external threat
Third-party introducerReliance rules, due diligence, accountabilityOutsourcing responsibility entirely
Tipping-off riskConfidentiality after suspicion/reportingAsking the customer questions that reveal a report may be made

The practical control cycle

Most financial crime frameworks follow a cycle. If you can place the scenario into this cycle, you can usually narrow the answer choices quickly.

  1. Identify the customer, counterparty, product, transaction, employee, or third party involved.
  2. Assess risk using relevant factors: customer type, geography, product, delivery channel, transaction pattern, and adverse information.
  3. Prevent misuse through policies, CDD, screening, approvals, limits, and training.
  4. Detect unusual or suspicious behaviour through monitoring, alerts, reconciliations, and staff vigilance.
  5. Escalate and report internally, and externally where required through the appropriate officer or process.
  6. Record and review decisions, evidence, rationale, and control effectiveness.

Exam shortcut: when the scenario contains uncertainty, the best answer is often not “ignore,” “close immediately,” or “accuse the customer.” It is usually to pause, gather appropriate information, escalate internally, and follow procedure.

AML and CTF essentials

Money laundering stages

StageWhat happensExample
PlacementCriminal proceeds enter the financial systemCash deposits, purchase of monetary instruments
LayeringTransactions obscure source and ownershipTransfers through multiple accounts or jurisdictions
IntegrationFunds appear legitimate and are used openlyInvestment in property, securities, business assets
Notes and examples

Exam trap: not every scenario fits neatly into one stage. If funds are being moved through multiple entities or jurisdictions to hide origin, the exam often points to layering.

Terrorist financing versus money laundering

FeatureMoney launderingTerrorist financing
Primary concernSource of funds is criminalUse or destination of funds supports terrorism
Fund originUsually illicitMay be illicit or legitimate
Transaction sizeCan be large, complex, or structuredMay involve small amounts
Key question“Where did the money come from?”“Where is the money going and why?”

Common mistake: assuming terrorist financing always involves large or obviously criminal funds. Small-value transactions can matter if the destination, pattern, or purpose is suspicious.

Politically exposed persons

A politically exposed person, or PEP, presents higher corruption and bribery risk because of public function or influence. The risk may extend to family members and close associates, depending on applicable rules and firm policy.

PEP issueReview point
PEP statusNot a crime and not automatically a reason to reject.
RiskHigher potential for bribery, corruption, embezzlement, and abuse of office.
ControlsEnhanced due diligence, source-of-wealth review, senior management approval where required, ongoing monitoring.
Time factorFormer PEPs may still present risk depending on role, influence, jurisdiction, and firm policy.
Common trapTreating a domestic or lower-profile PEP as risk-free without assessment.

Fraud and cyber-enabled financial crime

Fraud is deception for gain or to cause loss. In financial services, fraud often overlaps with AML because the proceeds of fraud may then need to be laundered.

Fraud typeRed flagsControls
Identity fraudInconsistent documents, synthetic identity, mismatched address/historyIdentity verification, document checks, device/IP checks
Account takeoverChanged contact details, unusual login, urgent payment requestsStrong authentication, call-backs, behavioural monitoring
Internal fraudOverride of controls, unusual employee access, unexplained lifestyleSegregation of duties, access controls, audit trails
Invoice fraudNew bank details, urgent supplier request, slight email/domain changeIndependent verification, dual approval
Investment fraudGuaranteed returns, pressure tactics, unregulated promoterDue diligence, investor warnings, escalation
Cyber fraudPhishing, malware, social engineering, business email compromiseSecurity awareness, incident response, payment controls
Notes and examples

Fraud triangle

A common way to analyse fraud risk is:

  • Pressure: financial stress, targets, addiction, performance pressure.
  • Opportunity: weak controls, poor supervision, excessive access.
  • Rationalisation: “I deserve it,” “I will repay it,” “everyone does it.”

Exam use: if the question asks how to reduce fraud risk, focus on reducing opportunity through controls, oversight, and accountability.

Market abuse and inside information

Depending on the scenario, financial crime can include misuse of markets and confidential information.

ConceptReview point
Inside informationNon-public, price-sensitive information relating to issuers or instruments.
Insider dealingTrading or encouraging trading while in possession of inside information.
Improper disclosureSharing inside information without proper reason.
Market manipulationCreating false or misleading signals about supply, demand, or price.
Information barriersControls that restrict flow of confidential information.
SurveillanceMonitoring orders, trades, communications, and patterns.

Common trap: believing market abuse requires a successful profit. Attempted manipulation, improper disclosure, or suspicious behaviour may still require escalation.

Third parties, introducers, and outsourcing

Third parties can create major financial crime exposure because they may interact with customers, officials, or payments outside the firm’s direct view.

Third-party riskCandidate focus
IntroducersWho is the customer? Who performed CDD? Can the firm rely on it?
Agents/consultantsWhat service is provided? Is payment proportionate and transparent?
OutsourcingThe task may be outsourced, but accountability and oversight remain important.
Correspondent relationshipsHigher exposure to another institution’s customers and controls.
SuppliersFraud, bribery, sanctions, and cyber risks.

Red flags include unclear ownership, refusal to provide due diligence, unusual commission structures, connections to public officials, use of offshore accounts, and pressure to bypass onboarding.

Trade finance and proliferation risk

Trade finance scenarios can combine AML, sanctions, fraud, and proliferation financing risk.

Red flagWhy it matters
Goods inconsistent with customer businessPossible disguise of true transaction purpose
Dual-use goodsMay have civilian and military applications
Unusual shipping routePotential sanctions evasion or diversion
Inconsistent documentsFraud or concealment
Over- or under-invoicingValue transfer or trade-based money laundering
Last-minute changes to counterpartiesPossible sanctions or ownership concealment
High-risk destination or transshipment pointDiversion, sanctions, or proliferation concern

Exam approach: trade finance questions often require checking the full chain: buyer, seller, goods, vessel, ports, insurers, banks, ownership, documentation, and payment flow.

Scenario-answer technique

When using the question bank, practise reading each scenario in this order:

  1. Identify the financial crime risk AML, CTF, sanctions, bribery, fraud, market abuse, cyber, tax, or mixed risk.

  2. Identify the trigger New customer, transaction alert, adverse media, sanctions hit, employee concern, whistleblowing report, third-party issue, or monitoring review.

  3. Locate the control point Onboarding, CDD refresh, screening, EDD, monitoring, escalation, reporting, recordkeeping, or exit.

  4. Apply proportionality Is the risk low, normal, high, prohibited, or suspicious?

  5. Avoid extreme answers unless justified Immediate closure, customer accusation, processing despite a hit, or ignoring a red flag are usually wrong unless the facts clearly support them.

  6. Choose the answer that preserves control Stop or pause where needed, escalate, document, and follow procedure.

Rapid review tables

“What should happen next?”

Scenario clueLikely next step
Possible sanctions matchPause activity, investigate match, escalate if unresolved
Customer refuses beneficial ownership detailsDo not proceed normally; escalate and assess relationship
Transaction inconsistent with known profileReview expected activity and seek appropriate explanation
Explanation inconsistent or implausibleEscalate suspicion internally
Staff member offered expensive gift during tenderDecline/report according to gifts and ABC policy
New agent requests commission to offshore accountConduct enhanced third-party due diligence and escalate
PEP identified after onboardingReassess risk, apply EDD, obtain approvals where required
Employee suspects launderingReport internally through the required channel
Customer asks whether they are being investigatedAvoid tipping off; follow internal guidance
Trade documents inconsistentInvestigate, verify, and escalate if unresolved
Notes and examples

Key distinctions

DistinctionRemember
Identification vs verificationCollecting identity details vs checking them against reliable evidence.
Source of funds vs source of wealthSpecific transaction money vs overall wealth origin.
Unusual vs suspiciousDifferent from expected vs reasonable basis for suspicion.
Sanctions risk vs AML riskSanctions may prohibit activity; AML risk may be managed if acceptable.
Bribe vs giftA bribe involves improper advantage; a gift may be legitimate only if transparent, proportionate, and policy-compliant.
Outsourcing vs accountabilityA firm may outsource tasks, not responsibility for oversight.
False positive vs true matchCleared possible match vs confirmed sanctions concern.
Fraud prevention vs AML reportingPreventing loss vs detecting/reporting proceeds or suspicious activity; both may apply.

Final readiness check

Before sitting the CISI Combating Financial Crime exam, confirm that you can explain without notes:

  • The stages of money laundering and how terrorist financing differs.
  • How CDD, EDD, beneficial ownership, PEP controls, and ongoing monitoring fit together.
  • What to do with sanctions matches and why sanctions are not just “high-risk AML.”
  • The red flags for bribery, corruption, fraud, market abuse, and trade-based financial crime.
  • When to escalate suspicion and how to avoid tipping off.
  • How governance, training, monitoring, recordkeeping, and independent testing support an effective control framework.

Next step: use the question bank for targeted topic drills, then review every missed item with detailed explanations until you can identify the risk, control point, and correct escalation step quickly.

Put the review into practice

Browse Practice Tests & Interview Prep