CISI CFC — CISI Combating Financial Crime Quick Review

Quick Review for Chartered Institute for Securities & Investment CISI Combating Financial Crime (CISI CFC) candidates covering AML, sanctions, bribery, fraud, controls, red flags, and practice focus.

Quick Review purpose

This Quick Review is for candidates preparing for the Chartered Institute for Securities & Investment CISI Combating Financial Crime exam, code CISI CFC. It is an independent companion review designed to help you refresh the major ideas before moving into topic drills, mock exams, and detailed explanations.

Use it to check whether you can:

  • Recognise the main forms of financial crime and how they interact.
  • Apply a risk-based approach to customers, products, jurisdictions, delivery channels, and transactions.
  • Distinguish identification, verification, screening, monitoring, escalation, and reporting duties.
  • Spot exam traps around suspicion, sanctions, beneficial ownership, PEPs, bribery, fraud, and tipping off.
  • Practise scenario-based judgement with original practice questions rather than relying only on memorised definitions.

High-yield exam mindset

The CISI CFC exam is likely to test both knowledge and judgement. Many questions are not asking “what is the definition?” but “what should a firm or employee do next?”

If the question asks about…Think first about…Common wrong move
A new clientCDD, risk assessment, beneficial ownership, sanctions/PEP screeningOpening the account before completing core checks
Unusual activityExpected profile, source of funds, suspicion threshold, escalationWaiting for proof of a crime
Sanctions hitStop, investigate, escalate, follow firm proceduresTreating it like ordinary AML risk
PEP relationshipEnhanced scrutiny and senior approval where required by policy/lawAssuming all PEPs are prohibited
Gift or hospitalityIntent, value, timing, transparency, public official riskAssuming “customary” always means acceptable
Fraud warning signsMotive, opportunity, deception, controls, reportingTreating fraud only as an external threat
Third-party introducerReliance rules, due diligence, accountabilityOutsourcing responsibility entirely
Tipping-off riskConfidentiality after suspicion/reportingAsking the customer questions that reveal a report may be made

Core financial crime map

Financial crime topics overlap. In exam scenarios, identify the primary risk, but stay alert to secondary risks.

AreaCore ideaTypical red flagsControl response
Money launderingDisguising criminal proceeds so they appear legitimateComplex structures, unexplained wealth, rapid movement of funds, third-party paymentsCDD, EDD, monitoring, internal reporting, recordkeeping
Terrorist financingMoving or using funds to support terrorism; funds may be legitimate or criminalSmall repeated transfers, high-risk locations, charities misused, unusual cash patternsCTF screening, monitoring, escalation, sanctions checks
Sanctions breachDealing with prohibited persons, entities, sectors, goods, services, or jurisdictionsName match, ownership/control link, unusual routing, trade with restricted locationScreening, match review, freezing/blocking where applicable, escalation
Bribery and corruptionOffering, giving, receiving, or soliciting improper advantagePublic official involvement, excessive hospitality, vague consultancy fees, success feesABC controls, approvals, gifts register, third-party due diligence
FraudDishonest deception for gain or to cause lossInvoice changes, identity inconsistencies, pressure tactics, override requestsSegregation of duties, verification, investigation, reporting
Market abuse / insider dealingMisuse of inside information or market manipulationTrading before announcements, false rumours, suspicious order patternsInformation barriers, surveillance, escalation
Tax evasion facilitationHelping another person evade tax, depending on jurisdictional rulesArtificial structures, false invoices, unexplained offshore arrangementsDue diligence, escalation, refusal where appropriate
Cyber-enabled crimeUse of technology to steal data, funds, or credentialsPhishing, malware, business email compromise, account takeoverCyber controls, authentication, incident response

The practical control cycle

Most financial crime frameworks follow a cycle. If you can place the scenario into this cycle, you can usually narrow the answer choices quickly.

  1. Identify the customer, counterparty, product, transaction, employee, or third party involved.
  2. Assess risk using relevant factors: customer type, geography, product, delivery channel, transaction pattern, and adverse information.
  3. Prevent misuse through policies, CDD, screening, approvals, limits, and training.
  4. Detect unusual or suspicious behaviour through monitoring, alerts, reconciliations, and staff vigilance.
  5. Escalate and report internally, and externally where required through the appropriate officer or process.
  6. Record and review decisions, evidence, rationale, and control effectiveness.

Exam shortcut: when the scenario contains uncertainty, the best answer is often not “ignore,” “close immediately,” or “accuse the customer.” It is usually to pause, gather appropriate information, escalate internally, and follow procedure.

AML and CTF essentials

Money laundering stages

StageWhat happensExample
PlacementCriminal proceeds enter the financial systemCash deposits, purchase of monetary instruments
LayeringTransactions obscure source and ownershipTransfers through multiple accounts or jurisdictions
IntegrationFunds appear legitimate and are used openlyInvestment in property, securities, business assets

Exam trap: not every scenario fits neatly into one stage. If funds are being moved through multiple entities or jurisdictions to hide origin, the exam often points to layering.

Terrorist financing versus money laundering

FeatureMoney launderingTerrorist financing
Primary concernSource of funds is criminalUse or destination of funds supports terrorism
Fund originUsually illicitMay be illicit or legitimate
Transaction sizeCan be large, complex, or structuredMay involve small amounts
Key question“Where did the money come from?”“Where is the money going and why?”

Common mistake: assuming terrorist financing always involves large or obviously criminal funds. Small-value transactions can matter if the destination, pattern, or purpose is suspicious.

Customer due diligence review

CDD is not just collecting a passport or company document. It is the process of understanding who the customer is, who controls them, and whether the relationship makes sense.

CDD elementWhat to know for review
IdentificationObtain identifying information about the customer.
VerificationCheck identity using reliable, independent sources where required.
Beneficial ownershipIdentify natural persons who ultimately own or control a legal entity or arrangement.
Purpose and natureUnderstand why the account or relationship is being established and expected activity.
Risk assessmentClassify risk using customer, geography, product, delivery channel, and transaction factors.
ScreeningCheck sanctions, PEP status, and adverse information according to firm procedures.
Ongoing monitoringKeep the relationship under review; CDD is not a one-time event.
RecordkeepingRetain evidence of checks, decisions, and updates as required by policy and law.

Simplified, standard, and enhanced due diligence

Due diligence levelWhen it may applyKey point
Simplified due diligenceLower-risk situations, where permittedNot “no due diligence”; still requires enough understanding to justify lower risk.
Standard due diligenceNormal risk relationshipsBaseline identity, verification, risk assessment, and monitoring.
Enhanced due diligenceHigher-risk customers, products, jurisdictions, PEPs, complex structures, adverse informationMore evidence, senior approval where required, deeper source-of-wealth/source-of-funds work, closer monitoring.

Source of funds versus source of wealth

TermMeaningExample question to answer
Source of fundsOrigin of the specific money used in a transaction“Where did this transfer or deposit come from?”
Source of wealthHow the customer accumulated overall wealth“How did this person become wealthy?”

Exam trap: a bank statement may help evidence source of funds, but it may not explain source of wealth.

Beneficial ownership and control

Legal ownership is not always the same as true control. Financial criminals may use companies, trusts, nominees, family members, or intermediaries to hide ownership.

High-yield points:

  • A beneficial owner is generally the natural person who ultimately owns or controls the customer or on whose behalf a transaction is conducted.
  • Complex structures are not automatically illegal, but unexplained complexity is a red flag.
  • If a customer refuses to provide ownership information, that is not merely an administrative delay; it may be a risk indicator.
  • Firms should understand control through voting rights, ownership interests, management influence, powers of appointment, or other arrangements.
  • Reliance on another party does not usually remove the firm’s responsibility to manage its own financial crime risk.

Politically exposed persons

A politically exposed person, or PEP, presents higher corruption and bribery risk because of public function or influence. The risk may extend to family members and close associates, depending on applicable rules and firm policy.

PEP issueReview point
PEP statusNot a crime and not automatically a reason to reject.
RiskHigher potential for bribery, corruption, embezzlement, and abuse of office.
ControlsEnhanced due diligence, source-of-wealth review, senior management approval where required, ongoing monitoring.
Time factorFormer PEPs may still present risk depending on role, influence, jurisdiction, and firm policy.
Common trapTreating a domestic or lower-profile PEP as risk-free without assessment.

Sanctions quick review

Sanctions are different from general AML risk. A sanctioned party may not simply be “high risk”; dealing may be prohibited or restricted.

Sanctions conceptExam focus
List-based sanctionsScreening names against sanctions lists.
Sectoral sanctionsRestrictions on certain sectors, activities, securities, services, or financing.
Geographic sanctionsRestrictions connected to countries, regions, or territories.
Ownership/controlA non-listed entity may still be restricted if owned or controlled by a sanctioned person or entity.
False positiveA possible match that is cleared after investigation.
True matchA confirmed match requiring escalation and action under policy/law.
Ongoing screeningSanctions status can change after onboarding.

Sanctions decision rules

When a question gives a possible sanctions match:

  1. Do not ignore it because the customer is profitable or long-standing.
  2. Do not process the transaction first and investigate later.
  3. Check whether it is a false positive using identifiers such as date of birth, address, registration number, nationality, ownership, and transaction details.
  4. Escalate according to firm procedure if the match cannot be cleared.
  5. Preserve records of the review and decision.
  6. Avoid tipping off or improper disclosure where confidentiality rules apply.

Common trap: applying normal risk appetite to sanctions. A firm may accept higher AML risk with controls, but sanctions restrictions may prohibit activity entirely.

Bribery and corruption

Bribery risk often appears through gifts, hospitality, introducers, consultants, public officials, procurement, charitable donations, sponsorships, and facilitation payments.

Risk indicatorWhy it matters
Public official involvementHigher risk of improper influence or abuse of office.
Excessive gift or hospitalityMay be intended to influence a decision.
Payment to offshore consultantMay hide a bribe or improper commission.
Vague service descriptionNo clear legitimate business purpose.
Success fee tied to licence/contractIncentivises improper influence.
Urgent payment before awardTiming suggests inducement.
Refusal to document servicesIndicates lack of transparency.
Facilitation paymentOften high risk and may be illegal under relevant law/policy.

ABC controls to remember

  • Clear anti-bribery and corruption policy.
  • Gifts, hospitality, donations, and sponsorship registers.
  • Approval thresholds and independent review.
  • Third-party due diligence.
  • Contract clauses and audit rights.
  • Training for high-risk employees.
  • Whistleblowing and escalation channels.
  • Monitoring of payments, invoices, and expense claims.

Exam trap: assuming a small payment cannot be a bribe. The issue is improper advantage, intent, context, and applicable rules, not just size.

Fraud and cyber-enabled financial crime

Fraud is deception for gain or to cause loss. In financial services, fraud often overlaps with AML because the proceeds of fraud may then need to be laundered.

Fraud typeRed flagsControls
Identity fraudInconsistent documents, synthetic identity, mismatched address/historyIdentity verification, document checks, device/IP checks
Account takeoverChanged contact details, unusual login, urgent payment requestsStrong authentication, call-backs, behavioural monitoring
Internal fraudOverride of controls, unusual employee access, unexplained lifestyleSegregation of duties, access controls, audit trails
Invoice fraudNew bank details, urgent supplier request, slight email/domain changeIndependent verification, dual approval
Investment fraudGuaranteed returns, pressure tactics, unregulated promoterDue diligence, investor warnings, escalation
Cyber fraudPhishing, malware, social engineering, business email compromiseSecurity awareness, incident response, payment controls

Fraud triangle

A common way to analyse fraud risk is:

  • Pressure: financial stress, targets, addiction, performance pressure.
  • Opportunity: weak controls, poor supervision, excessive access.
  • Rationalisation: “I deserve it,” “I will repay it,” “everyone does it.”

Exam use: if the question asks how to reduce fraud risk, focus on reducing opportunity through controls, oversight, and accountability.

Market abuse and inside information

Depending on the scenario, financial crime can include misuse of markets and confidential information.

ConceptReview point
Inside informationNon-public, price-sensitive information relating to issuers or instruments.
Insider dealingTrading or encouraging trading while in possession of inside information.
Improper disclosureSharing inside information without proper reason.
Market manipulationCreating false or misleading signals about supply, demand, or price.
Information barriersControls that restrict flow of confidential information.
SurveillanceMonitoring orders, trades, communications, and patterns.

Common trap: believing market abuse requires a successful profit. Attempted manipulation, improper disclosure, or suspicious behaviour may still require escalation.

Risk-based approach

The risk-based approach means allocating effort where risk is higher. It is not a permission to ignore low-risk areas.

Risk factorHigher-risk examples
CustomerPEPs, cash-intensive businesses, complex ownership, charities in high-risk areas, money service businesses
GeographyJurisdictions with higher corruption, weak AML controls, sanctions exposure, conflict or terrorism concerns
Product/servicePrivate banking, correspondent banking, trade finance, high-value transfers, anonymity-enhancing products
Delivery channelNon-face-to-face onboarding, intermediaries, digital channels without strong controls
TransactionUnusual size, frequency, routing, purpose, third-party involvement, rapid in/out movement

Good exam answers usually show proportionality:

  • Low risk: appropriate simplified or standard controls if permitted.
  • Medium risk: standard CDD and monitoring.
  • High risk: enhanced due diligence, senior review where required, more frequent monitoring, stronger evidence.
  • Unacceptable risk: decline, exit, block, freeze, or report as appropriate.

Suspicion, escalation, and reporting

The exam often tests the difference between a concern, an unusual transaction, and a suspicion.

StageMeaningGood response
UnusualActivity differs from expected profileReview, ask appropriate questions, check records
UnexplainedCustomer explanation is weak, inconsistent, or unsupportedEscalate for further review
SuspiciousThere is a reasonable basis to suspect financial crimeInternal report according to procedure
Confirmed/prohibitedSanctions true match or confirmed criminal activityStop/hold where required, escalate, follow legal and firm process

Suspicion does not require proof

A frequent candidate mistake is looking for courtroom-level evidence. Financial crime reporting is generally triggered by suspicion or knowledge, not proof beyond doubt. The employee’s role is usually to recognise red flags and escalate through the firm’s process, not to conduct an unauthorised investigation.

Tipping off

Tipping off risk arises when a customer or third party is alerted that a report, investigation, or suspicion exists in a way that may prejudice an investigation.

Practical exam rules:

  • Do not tell the customer that a suspicious activity report has been or will be made.
  • Do not invent false reasons; follow firm procedures.
  • You may ask ordinary due diligence questions where appropriate, but avoid revealing suspicion.
  • Escalate uncertainty to the appropriate internal function.

Governance and internal controls

Financial crime prevention is a firm-wide responsibility, not only a compliance department task.

Control areaWhat good looks like
Senior management oversightClear accountability, risk appetite, resources, management information
Policies and proceduresWritten, current, practical, aligned to risk
TrainingRole-specific, refreshed, tested, documented
ScreeningCustomer, counterparty, employee, transaction, and sanctions screening as relevant
MonitoringRules, alerts, typologies, manual review, quality control
Independent testingAudit or assurance review of control design and effectiveness
RecordkeepingEvidence of CDD, risk decisions, approvals, reports, investigations
WhistleblowingSafe channels for raising concerns
RemediationFix control gaps and track actions to closure

Exam trap: choosing a control that sounds strong but is not targeted. For example, more training may help awareness, but it will not replace sanctions screening, segregation of duties, or transaction monitoring where those are the actual control gap.

Third parties, introducers, and outsourcing

Third parties can create major financial crime exposure because they may interact with customers, officials, or payments outside the firm’s direct view.

Third-party riskCandidate focus
IntroducersWho is the customer? Who performed CDD? Can the firm rely on it?
Agents/consultantsWhat service is provided? Is payment proportionate and transparent?
OutsourcingThe task may be outsourced, but accountability and oversight remain important.
Correspondent relationshipsHigher exposure to another institution’s customers and controls.
SuppliersFraud, bribery, sanctions, and cyber risks.

Red flags include unclear ownership, refusal to provide due diligence, unusual commission structures, connections to public officials, use of offshore accounts, and pressure to bypass onboarding.

Trade finance and proliferation risk

Trade finance scenarios can combine AML, sanctions, fraud, and proliferation financing risk.

Red flagWhy it matters
Goods inconsistent with customer businessPossible disguise of true transaction purpose
Dual-use goodsMay have civilian and military applications
Unusual shipping routePotential sanctions evasion or diversion
Inconsistent documentsFraud or concealment
Over- or under-invoicingValue transfer or trade-based money laundering
Last-minute changes to counterpartiesPossible sanctions or ownership concealment
High-risk destination or transshipment pointDiversion, sanctions, or proliferation concern

Exam approach: trade finance questions often require checking the full chain: buyer, seller, goods, vessel, ports, insurers, banks, ownership, documentation, and payment flow.

Common red flags to memorise

Customer red flags

  • Reluctance to provide identification or beneficial ownership information.
  • Complex structure with no clear commercial rationale.
  • Use of nominees, shell companies, or opaque trusts.
  • Adverse media involving fraud, corruption, sanctions, tax crime, or organised crime.
  • Customer’s wealth or activity inconsistent with known profile.
  • Frequent changes in ownership, address, or directors.

Transaction red flags

  • Rapid movement of funds in and out with little economic purpose.
  • Transactions just below reporting or review thresholds.
  • Third-party payments without clear rationale.
  • Payments to or from high-risk jurisdictions.
  • Round-dollar or repetitive transfers.
  • Unusual cash activity.
  • Early repayment, cancellation, or surrender inconsistent with customer profile.

Behavioural red flags

  • Urgency or pressure to bypass controls.
  • Unwillingness to explain transaction purpose.
  • Overly defensive or inconsistent explanations.
  • Use of multiple advisers to avoid scrutiny.
  • Attempts to influence staff or offer inducements.

Common candidate traps

TrapBetter reasoning
“The customer is long-standing, so new checks are unnecessary.”Existing customers require ongoing monitoring and updates when risk changes.
“No conviction means no suspicion.”Suspicion can exist before proof or conviction.
“A PEP must always be rejected.”PEPs usually require enhanced risk management, not automatic rejection.
“Sanctions screening is only for onboarding.”Screening should also address changes, transactions, and updated lists as relevant.
“Beneficial owner means the company on the register.”The focus is the natural person who ultimately owns or controls.
“Small transactions are low risk.”Structuring and terrorist financing may involve small amounts.
“If another firm did CDD, we have no responsibility.”Reliance and outsourcing require oversight and do not remove accountability.
“Asking more questions is always best.”After suspicion arises, questions may create tipping-off risk.
“Complexity is proof of crime.”Complexity is a red flag; assess rationale and evidence before concluding.
“Training alone fixes control failures.”Controls must match the risk: screening, monitoring, approvals, audit trails, and escalation.

Scenario-answer technique

When using the question bank, practise reading each scenario in this order:

  1. Identify the financial crime risk AML, CTF, sanctions, bribery, fraud, market abuse, cyber, tax, or mixed risk.

  2. Identify the trigger New customer, transaction alert, adverse media, sanctions hit, employee concern, whistleblowing report, third-party issue, or monitoring review.

  3. Locate the control point Onboarding, CDD refresh, screening, EDD, monitoring, escalation, reporting, recordkeeping, or exit.

  4. Apply proportionality Is the risk low, normal, high, prohibited, or suspicious?

  5. Avoid extreme answers unless justified Immediate closure, customer accusation, processing despite a hit, or ignoring a red flag are usually wrong unless the facts clearly support them.

  6. Choose the answer that preserves control Stop or pause where needed, escalate, document, and follow procedure.

Rapid review tables

“What should happen next?”

Scenario clueLikely next step
Possible sanctions matchPause activity, investigate match, escalate if unresolved
Customer refuses beneficial ownership detailsDo not proceed normally; escalate and assess relationship
Transaction inconsistent with known profileReview expected activity and seek appropriate explanation
Explanation inconsistent or implausibleEscalate suspicion internally
Staff member offered expensive gift during tenderDecline/report according to gifts and ABC policy
New agent requests commission to offshore accountConduct enhanced third-party due diligence and escalate
PEP identified after onboardingReassess risk, apply EDD, obtain approvals where required
Employee suspects launderingReport internally through the required channel
Customer asks whether they are being investigatedAvoid tipping off; follow internal guidance
Trade documents inconsistentInvestigate, verify, and escalate if unresolved

Key distinctions

DistinctionRemember
Identification vs verificationCollecting identity details vs checking them against reliable evidence.
Source of funds vs source of wealthSpecific transaction money vs overall wealth origin.
Unusual vs suspiciousDifferent from expected vs reasonable basis for suspicion.
Sanctions risk vs AML riskSanctions may prohibit activity; AML risk may be managed if acceptable.
Bribe vs giftA bribe involves improper advantage; a gift may be legitimate only if transparent, proportionate, and policy-compliant.
Outsourcing vs accountabilityA firm may outsource tasks, not responsibility for oversight.
False positive vs true matchCleared possible match vs confirmed sanctions concern.
Fraud prevention vs AML reportingPreventing loss vs detecting/reporting proceeds or suspicious activity; both may apply.

How to use original practice questions effectively

After this Quick Review, move into independent companion practice with a deliberate plan:

  • Start with topic drills for AML/CTF, sanctions, bribery, fraud, and controls.
  • For each missed question, write down the decision rule you failed to apply.
  • Use detailed explanations to compare why the correct answer is better than the tempting distractor.
  • Revisit mixed scenarios, because real exam questions often combine sanctions, AML, fraud, and governance issues.
  • Finish with timed mock-style sets to practise speed and judgement.

Final readiness check

Before sitting the CISI Combating Financial Crime exam, confirm that you can explain without notes:

  • The stages of money laundering and how terrorist financing differs.
  • How CDD, EDD, beneficial ownership, PEP controls, and ongoing monitoring fit together.
  • What to do with sanctions matches and why sanctions are not just “high-risk AML.”
  • The red flags for bribery, corruption, fraud, market abuse, and trade-based financial crime.
  • When to escalate suspicion and how to avoid tipping off.
  • How governance, training, monitoring, recordkeeping, and independent testing support an effective control framework.

Next step: use the question bank for targeted topic drills, then review every missed item with detailed explanations until you can identify the risk, control point, and correct escalation step quickly.

Browse Certification Practice Tests by Exam Family