CISI CFC — CISI Combating Financial Crime Quick Review
Quick Review for Chartered Institute for Securities & Investment CISI Combating Financial Crime (CISI CFC) candidates covering AML, sanctions, bribery, fraud, controls, red flags, and practice focus.
Quick Review purpose
This Quick Review is for candidates preparing for the Chartered Institute for Securities & Investment CISI Combating Financial Crime exam, code CISI CFC. It is an independent companion review designed to help you refresh the major ideas before moving into topic drills, mock exams, and detailed explanations.
Use it to check whether you can:
- Recognise the main forms of financial crime and how they interact.
- Apply a risk-based approach to customers, products, jurisdictions, delivery channels, and transactions.
- Distinguish identification, verification, screening, monitoring, escalation, and reporting duties.
- Spot exam traps around suspicion, sanctions, beneficial ownership, PEPs, bribery, fraud, and tipping off.
- Practise scenario-based judgement with original practice questions rather than relying only on memorised definitions.
High-yield exam mindset
The CISI CFC exam is likely to test both knowledge and judgement. Many questions are not asking “what is the definition?” but “what should a firm or employee do next?”
| If the question asks about… | Think first about… | Common wrong move |
|---|---|---|
| A new client | CDD, risk assessment, beneficial ownership, sanctions/PEP screening | Opening the account before completing core checks |
| Unusual activity | Expected profile, source of funds, suspicion threshold, escalation | Waiting for proof of a crime |
| Sanctions hit | Stop, investigate, escalate, follow firm procedures | Treating it like ordinary AML risk |
| PEP relationship | Enhanced scrutiny and senior approval where required by policy/law | Assuming all PEPs are prohibited |
| Gift or hospitality | Intent, value, timing, transparency, public official risk | Assuming “customary” always means acceptable |
| Fraud warning signs | Motive, opportunity, deception, controls, reporting | Treating fraud only as an external threat |
| Third-party introducer | Reliance rules, due diligence, accountability | Outsourcing responsibility entirely |
| Tipping-off risk | Confidentiality after suspicion/reporting | Asking the customer questions that reveal a report may be made |
Core financial crime map
Financial crime topics overlap. In exam scenarios, identify the primary risk, but stay alert to secondary risks.
| Area | Core idea | Typical red flags | Control response |
|---|---|---|---|
| Money laundering | Disguising criminal proceeds so they appear legitimate | Complex structures, unexplained wealth, rapid movement of funds, third-party payments | CDD, EDD, monitoring, internal reporting, recordkeeping |
| Terrorist financing | Moving or using funds to support terrorism; funds may be legitimate or criminal | Small repeated transfers, high-risk locations, charities misused, unusual cash patterns | CTF screening, monitoring, escalation, sanctions checks |
| Sanctions breach | Dealing with prohibited persons, entities, sectors, goods, services, or jurisdictions | Name match, ownership/control link, unusual routing, trade with restricted location | Screening, match review, freezing/blocking where applicable, escalation |
| Bribery and corruption | Offering, giving, receiving, or soliciting improper advantage | Public official involvement, excessive hospitality, vague consultancy fees, success fees | ABC controls, approvals, gifts register, third-party due diligence |
| Fraud | Dishonest deception for gain or to cause loss | Invoice changes, identity inconsistencies, pressure tactics, override requests | Segregation of duties, verification, investigation, reporting |
| Market abuse / insider dealing | Misuse of inside information or market manipulation | Trading before announcements, false rumours, suspicious order patterns | Information barriers, surveillance, escalation |
| Tax evasion facilitation | Helping another person evade tax, depending on jurisdictional rules | Artificial structures, false invoices, unexplained offshore arrangements | Due diligence, escalation, refusal where appropriate |
| Cyber-enabled crime | Use of technology to steal data, funds, or credentials | Phishing, malware, business email compromise, account takeover | Cyber controls, authentication, incident response |
The practical control cycle
Most financial crime frameworks follow a cycle. If you can place the scenario into this cycle, you can usually narrow the answer choices quickly.
- Identify the customer, counterparty, product, transaction, employee, or third party involved.
- Assess risk using relevant factors: customer type, geography, product, delivery channel, transaction pattern, and adverse information.
- Prevent misuse through policies, CDD, screening, approvals, limits, and training.
- Detect unusual or suspicious behaviour through monitoring, alerts, reconciliations, and staff vigilance.
- Escalate and report internally, and externally where required through the appropriate officer or process.
- Record and review decisions, evidence, rationale, and control effectiveness.
Exam shortcut: when the scenario contains uncertainty, the best answer is often not “ignore,” “close immediately,” or “accuse the customer.” It is usually to pause, gather appropriate information, escalate internally, and follow procedure.
AML and CTF essentials
Money laundering stages
| Stage | What happens | Example |
|---|---|---|
| Placement | Criminal proceeds enter the financial system | Cash deposits, purchase of monetary instruments |
| Layering | Transactions obscure source and ownership | Transfers through multiple accounts or jurisdictions |
| Integration | Funds appear legitimate and are used openly | Investment in property, securities, business assets |
Exam trap: not every scenario fits neatly into one stage. If funds are being moved through multiple entities or jurisdictions to hide origin, the exam often points to layering.
Terrorist financing versus money laundering
| Feature | Money laundering | Terrorist financing |
|---|---|---|
| Primary concern | Source of funds is criminal | Use or destination of funds supports terrorism |
| Fund origin | Usually illicit | May be illicit or legitimate |
| Transaction size | Can be large, complex, or structured | May involve small amounts |
| Key question | “Where did the money come from?” | “Where is the money going and why?” |
Common mistake: assuming terrorist financing always involves large or obviously criminal funds. Small-value transactions can matter if the destination, pattern, or purpose is suspicious.
Customer due diligence review
CDD is not just collecting a passport or company document. It is the process of understanding who the customer is, who controls them, and whether the relationship makes sense.
| CDD element | What to know for review |
|---|---|
| Identification | Obtain identifying information about the customer. |
| Verification | Check identity using reliable, independent sources where required. |
| Beneficial ownership | Identify natural persons who ultimately own or control a legal entity or arrangement. |
| Purpose and nature | Understand why the account or relationship is being established and expected activity. |
| Risk assessment | Classify risk using customer, geography, product, delivery channel, and transaction factors. |
| Screening | Check sanctions, PEP status, and adverse information according to firm procedures. |
| Ongoing monitoring | Keep the relationship under review; CDD is not a one-time event. |
| Recordkeeping | Retain evidence of checks, decisions, and updates as required by policy and law. |
Simplified, standard, and enhanced due diligence
| Due diligence level | When it may apply | Key point |
|---|---|---|
| Simplified due diligence | Lower-risk situations, where permitted | Not “no due diligence”; still requires enough understanding to justify lower risk. |
| Standard due diligence | Normal risk relationships | Baseline identity, verification, risk assessment, and monitoring. |
| Enhanced due diligence | Higher-risk customers, products, jurisdictions, PEPs, complex structures, adverse information | More evidence, senior approval where required, deeper source-of-wealth/source-of-funds work, closer monitoring. |
Source of funds versus source of wealth
| Term | Meaning | Example question to answer |
|---|---|---|
| Source of funds | Origin of the specific money used in a transaction | “Where did this transfer or deposit come from?” |
| Source of wealth | How the customer accumulated overall wealth | “How did this person become wealthy?” |
Exam trap: a bank statement may help evidence source of funds, but it may not explain source of wealth.
Beneficial ownership and control
Legal ownership is not always the same as true control. Financial criminals may use companies, trusts, nominees, family members, or intermediaries to hide ownership.
High-yield points:
- A beneficial owner is generally the natural person who ultimately owns or controls the customer or on whose behalf a transaction is conducted.
- Complex structures are not automatically illegal, but unexplained complexity is a red flag.
- If a customer refuses to provide ownership information, that is not merely an administrative delay; it may be a risk indicator.
- Firms should understand control through voting rights, ownership interests, management influence, powers of appointment, or other arrangements.
- Reliance on another party does not usually remove the firm’s responsibility to manage its own financial crime risk.
Politically exposed persons
A politically exposed person, or PEP, presents higher corruption and bribery risk because of public function or influence. The risk may extend to family members and close associates, depending on applicable rules and firm policy.
| PEP issue | Review point |
|---|---|
| PEP status | Not a crime and not automatically a reason to reject. |
| Risk | Higher potential for bribery, corruption, embezzlement, and abuse of office. |
| Controls | Enhanced due diligence, source-of-wealth review, senior management approval where required, ongoing monitoring. |
| Time factor | Former PEPs may still present risk depending on role, influence, jurisdiction, and firm policy. |
| Common trap | Treating a domestic or lower-profile PEP as risk-free without assessment. |
Sanctions quick review
Sanctions are different from general AML risk. A sanctioned party may not simply be “high risk”; dealing may be prohibited or restricted.
| Sanctions concept | Exam focus |
|---|---|
| List-based sanctions | Screening names against sanctions lists. |
| Sectoral sanctions | Restrictions on certain sectors, activities, securities, services, or financing. |
| Geographic sanctions | Restrictions connected to countries, regions, or territories. |
| Ownership/control | A non-listed entity may still be restricted if owned or controlled by a sanctioned person or entity. |
| False positive | A possible match that is cleared after investigation. |
| True match | A confirmed match requiring escalation and action under policy/law. |
| Ongoing screening | Sanctions status can change after onboarding. |
Sanctions decision rules
When a question gives a possible sanctions match:
- Do not ignore it because the customer is profitable or long-standing.
- Do not process the transaction first and investigate later.
- Check whether it is a false positive using identifiers such as date of birth, address, registration number, nationality, ownership, and transaction details.
- Escalate according to firm procedure if the match cannot be cleared.
- Preserve records of the review and decision.
- Avoid tipping off or improper disclosure where confidentiality rules apply.
Common trap: applying normal risk appetite to sanctions. A firm may accept higher AML risk with controls, but sanctions restrictions may prohibit activity entirely.
Bribery and corruption
Bribery risk often appears through gifts, hospitality, introducers, consultants, public officials, procurement, charitable donations, sponsorships, and facilitation payments.
| Risk indicator | Why it matters |
|---|---|
| Public official involvement | Higher risk of improper influence or abuse of office. |
| Excessive gift or hospitality | May be intended to influence a decision. |
| Payment to offshore consultant | May hide a bribe or improper commission. |
| Vague service description | No clear legitimate business purpose. |
| Success fee tied to licence/contract | Incentivises improper influence. |
| Urgent payment before award | Timing suggests inducement. |
| Refusal to document services | Indicates lack of transparency. |
| Facilitation payment | Often high risk and may be illegal under relevant law/policy. |
ABC controls to remember
- Clear anti-bribery and corruption policy.
- Gifts, hospitality, donations, and sponsorship registers.
- Approval thresholds and independent review.
- Third-party due diligence.
- Contract clauses and audit rights.
- Training for high-risk employees.
- Whistleblowing and escalation channels.
- Monitoring of payments, invoices, and expense claims.
Exam trap: assuming a small payment cannot be a bribe. The issue is improper advantage, intent, context, and applicable rules, not just size.
Fraud and cyber-enabled financial crime
Fraud is deception for gain or to cause loss. In financial services, fraud often overlaps with AML because the proceeds of fraud may then need to be laundered.
| Fraud type | Red flags | Controls |
|---|---|---|
| Identity fraud | Inconsistent documents, synthetic identity, mismatched address/history | Identity verification, document checks, device/IP checks |
| Account takeover | Changed contact details, unusual login, urgent payment requests | Strong authentication, call-backs, behavioural monitoring |
| Internal fraud | Override of controls, unusual employee access, unexplained lifestyle | Segregation of duties, access controls, audit trails |
| Invoice fraud | New bank details, urgent supplier request, slight email/domain change | Independent verification, dual approval |
| Investment fraud | Guaranteed returns, pressure tactics, unregulated promoter | Due diligence, investor warnings, escalation |
| Cyber fraud | Phishing, malware, social engineering, business email compromise | Security awareness, incident response, payment controls |
Fraud triangle
A common way to analyse fraud risk is:
- Pressure: financial stress, targets, addiction, performance pressure.
- Opportunity: weak controls, poor supervision, excessive access.
- Rationalisation: “I deserve it,” “I will repay it,” “everyone does it.”
Exam use: if the question asks how to reduce fraud risk, focus on reducing opportunity through controls, oversight, and accountability.
Market abuse and inside information
Depending on the scenario, financial crime can include misuse of markets and confidential information.
| Concept | Review point |
|---|---|
| Inside information | Non-public, price-sensitive information relating to issuers or instruments. |
| Insider dealing | Trading or encouraging trading while in possession of inside information. |
| Improper disclosure | Sharing inside information without proper reason. |
| Market manipulation | Creating false or misleading signals about supply, demand, or price. |
| Information barriers | Controls that restrict flow of confidential information. |
| Surveillance | Monitoring orders, trades, communications, and patterns. |
Common trap: believing market abuse requires a successful profit. Attempted manipulation, improper disclosure, or suspicious behaviour may still require escalation.
Risk-based approach
The risk-based approach means allocating effort where risk is higher. It is not a permission to ignore low-risk areas.
| Risk factor | Higher-risk examples |
|---|---|
| Customer | PEPs, cash-intensive businesses, complex ownership, charities in high-risk areas, money service businesses |
| Geography | Jurisdictions with higher corruption, weak AML controls, sanctions exposure, conflict or terrorism concerns |
| Product/service | Private banking, correspondent banking, trade finance, high-value transfers, anonymity-enhancing products |
| Delivery channel | Non-face-to-face onboarding, intermediaries, digital channels without strong controls |
| Transaction | Unusual size, frequency, routing, purpose, third-party involvement, rapid in/out movement |
Good exam answers usually show proportionality:
- Low risk: appropriate simplified or standard controls if permitted.
- Medium risk: standard CDD and monitoring.
- High risk: enhanced due diligence, senior review where required, more frequent monitoring, stronger evidence.
- Unacceptable risk: decline, exit, block, freeze, or report as appropriate.
Suspicion, escalation, and reporting
The exam often tests the difference between a concern, an unusual transaction, and a suspicion.
| Stage | Meaning | Good response |
|---|---|---|
| Unusual | Activity differs from expected profile | Review, ask appropriate questions, check records |
| Unexplained | Customer explanation is weak, inconsistent, or unsupported | Escalate for further review |
| Suspicious | There is a reasonable basis to suspect financial crime | Internal report according to procedure |
| Confirmed/prohibited | Sanctions true match or confirmed criminal activity | Stop/hold where required, escalate, follow legal and firm process |
Suspicion does not require proof
A frequent candidate mistake is looking for courtroom-level evidence. Financial crime reporting is generally triggered by suspicion or knowledge, not proof beyond doubt. The employee’s role is usually to recognise red flags and escalate through the firm’s process, not to conduct an unauthorised investigation.
Tipping off
Tipping off risk arises when a customer or third party is alerted that a report, investigation, or suspicion exists in a way that may prejudice an investigation.
Practical exam rules:
- Do not tell the customer that a suspicious activity report has been or will be made.
- Do not invent false reasons; follow firm procedures.
- You may ask ordinary due diligence questions where appropriate, but avoid revealing suspicion.
- Escalate uncertainty to the appropriate internal function.
Governance and internal controls
Financial crime prevention is a firm-wide responsibility, not only a compliance department task.
| Control area | What good looks like |
|---|---|
| Senior management oversight | Clear accountability, risk appetite, resources, management information |
| Policies and procedures | Written, current, practical, aligned to risk |
| Training | Role-specific, refreshed, tested, documented |
| Screening | Customer, counterparty, employee, transaction, and sanctions screening as relevant |
| Monitoring | Rules, alerts, typologies, manual review, quality control |
| Independent testing | Audit or assurance review of control design and effectiveness |
| Recordkeeping | Evidence of CDD, risk decisions, approvals, reports, investigations |
| Whistleblowing | Safe channels for raising concerns |
| Remediation | Fix control gaps and track actions to closure |
Exam trap: choosing a control that sounds strong but is not targeted. For example, more training may help awareness, but it will not replace sanctions screening, segregation of duties, or transaction monitoring where those are the actual control gap.
Third parties, introducers, and outsourcing
Third parties can create major financial crime exposure because they may interact with customers, officials, or payments outside the firm’s direct view.
| Third-party risk | Candidate focus |
|---|---|
| Introducers | Who is the customer? Who performed CDD? Can the firm rely on it? |
| Agents/consultants | What service is provided? Is payment proportionate and transparent? |
| Outsourcing | The task may be outsourced, but accountability and oversight remain important. |
| Correspondent relationships | Higher exposure to another institution’s customers and controls. |
| Suppliers | Fraud, bribery, sanctions, and cyber risks. |
Red flags include unclear ownership, refusal to provide due diligence, unusual commission structures, connections to public officials, use of offshore accounts, and pressure to bypass onboarding.
Trade finance and proliferation risk
Trade finance scenarios can combine AML, sanctions, fraud, and proliferation financing risk.
| Red flag | Why it matters |
|---|---|
| Goods inconsistent with customer business | Possible disguise of true transaction purpose |
| Dual-use goods | May have civilian and military applications |
| Unusual shipping route | Potential sanctions evasion or diversion |
| Inconsistent documents | Fraud or concealment |
| Over- or under-invoicing | Value transfer or trade-based money laundering |
| Last-minute changes to counterparties | Possible sanctions or ownership concealment |
| High-risk destination or transshipment point | Diversion, sanctions, or proliferation concern |
Exam approach: trade finance questions often require checking the full chain: buyer, seller, goods, vessel, ports, insurers, banks, ownership, documentation, and payment flow.
Common red flags to memorise
Customer red flags
- Reluctance to provide identification or beneficial ownership information.
- Complex structure with no clear commercial rationale.
- Use of nominees, shell companies, or opaque trusts.
- Adverse media involving fraud, corruption, sanctions, tax crime, or organised crime.
- Customer’s wealth or activity inconsistent with known profile.
- Frequent changes in ownership, address, or directors.
Transaction red flags
- Rapid movement of funds in and out with little economic purpose.
- Transactions just below reporting or review thresholds.
- Third-party payments without clear rationale.
- Payments to or from high-risk jurisdictions.
- Round-dollar or repetitive transfers.
- Unusual cash activity.
- Early repayment, cancellation, or surrender inconsistent with customer profile.
Behavioural red flags
- Urgency or pressure to bypass controls.
- Unwillingness to explain transaction purpose.
- Overly defensive or inconsistent explanations.
- Use of multiple advisers to avoid scrutiny.
- Attempts to influence staff or offer inducements.
Common candidate traps
| Trap | Better reasoning |
|---|---|
| “The customer is long-standing, so new checks are unnecessary.” | Existing customers require ongoing monitoring and updates when risk changes. |
| “No conviction means no suspicion.” | Suspicion can exist before proof or conviction. |
| “A PEP must always be rejected.” | PEPs usually require enhanced risk management, not automatic rejection. |
| “Sanctions screening is only for onboarding.” | Screening should also address changes, transactions, and updated lists as relevant. |
| “Beneficial owner means the company on the register.” | The focus is the natural person who ultimately owns or controls. |
| “Small transactions are low risk.” | Structuring and terrorist financing may involve small amounts. |
| “If another firm did CDD, we have no responsibility.” | Reliance and outsourcing require oversight and do not remove accountability. |
| “Asking more questions is always best.” | After suspicion arises, questions may create tipping-off risk. |
| “Complexity is proof of crime.” | Complexity is a red flag; assess rationale and evidence before concluding. |
| “Training alone fixes control failures.” | Controls must match the risk: screening, monitoring, approvals, audit trails, and escalation. |
Scenario-answer technique
When using the question bank, practise reading each scenario in this order:
Identify the financial crime risk AML, CTF, sanctions, bribery, fraud, market abuse, cyber, tax, or mixed risk.
Identify the trigger New customer, transaction alert, adverse media, sanctions hit, employee concern, whistleblowing report, third-party issue, or monitoring review.
Locate the control point Onboarding, CDD refresh, screening, EDD, monitoring, escalation, reporting, recordkeeping, or exit.
Apply proportionality Is the risk low, normal, high, prohibited, or suspicious?
Avoid extreme answers unless justified Immediate closure, customer accusation, processing despite a hit, or ignoring a red flag are usually wrong unless the facts clearly support them.
Choose the answer that preserves control Stop or pause where needed, escalate, document, and follow procedure.
Rapid review tables
“What should happen next?”
| Scenario clue | Likely next step |
|---|---|
| Possible sanctions match | Pause activity, investigate match, escalate if unresolved |
| Customer refuses beneficial ownership details | Do not proceed normally; escalate and assess relationship |
| Transaction inconsistent with known profile | Review expected activity and seek appropriate explanation |
| Explanation inconsistent or implausible | Escalate suspicion internally |
| Staff member offered expensive gift during tender | Decline/report according to gifts and ABC policy |
| New agent requests commission to offshore account | Conduct enhanced third-party due diligence and escalate |
| PEP identified after onboarding | Reassess risk, apply EDD, obtain approvals where required |
| Employee suspects laundering | Report internally through the required channel |
| Customer asks whether they are being investigated | Avoid tipping off; follow internal guidance |
| Trade documents inconsistent | Investigate, verify, and escalate if unresolved |
Key distinctions
| Distinction | Remember |
|---|---|
| Identification vs verification | Collecting identity details vs checking them against reliable evidence. |
| Source of funds vs source of wealth | Specific transaction money vs overall wealth origin. |
| Unusual vs suspicious | Different from expected vs reasonable basis for suspicion. |
| Sanctions risk vs AML risk | Sanctions may prohibit activity; AML risk may be managed if acceptable. |
| Bribe vs gift | A bribe involves improper advantage; a gift may be legitimate only if transparent, proportionate, and policy-compliant. |
| Outsourcing vs accountability | A firm may outsource tasks, not responsibility for oversight. |
| False positive vs true match | Cleared possible match vs confirmed sanctions concern. |
| Fraud prevention vs AML reporting | Preventing loss vs detecting/reporting proceeds or suspicious activity; both may apply. |
How to use original practice questions effectively
After this Quick Review, move into independent companion practice with a deliberate plan:
- Start with topic drills for AML/CTF, sanctions, bribery, fraud, and controls.
- For each missed question, write down the decision rule you failed to apply.
- Use detailed explanations to compare why the correct answer is better than the tempting distractor.
- Revisit mixed scenarios, because real exam questions often combine sanctions, AML, fraud, and governance issues.
- Finish with timed mock-style sets to practise speed and judgement.
Final readiness check
Before sitting the CISI Combating Financial Crime exam, confirm that you can explain without notes:
- The stages of money laundering and how terrorist financing differs.
- How CDD, EDD, beneficial ownership, PEP controls, and ongoing monitoring fit together.
- What to do with sanctions matches and why sanctions are not just “high-risk AML.”
- The red flags for bribery, corruption, fraud, market abuse, and trade-based financial crime.
- When to escalate suspicion and how to avoid tipping off.
- How governance, training, monitoring, recordkeeping, and independent testing support an effective control framework.
Next step: use the question bank for targeted topic drills, then review every missed item with detailed explanations until you can identify the risk, control point, and correct escalation step quickly.