Skip to main content
V
Vanguard Professional AcademyCAMS Study Notes
Abridged Study Notes with LOS

CAMS and CGSS revision notes linked with learning outcomes.

Use these concise notes before practice. Each section explains the key exam focus, the learning outcomes, and the direct path back to the simulator.

How students should use this page

Selected LOS opened. Review the highlighted note below.

LOS Quick Links

Open a CAMS domain below. The notes are static and should open without depending on simulator login.

πŸ“– Updated 23 July 2026 β€” CAMS notes cross-checked against Study Guide v7.03; CGSS Domain 1 notes cross-checked against the CGSS Study Guide v2.0 source text.

Domain 1Risks and MethodsDomain 2Frameworks and GovernanceDomain 3Compliance ProgramDomain 4Tools and Technologies
CGSS Β· Domain 1Sanctions Frameworks and GovernanceCGSS Β· Domain 2Building a Sanctions Compliance ProgramCGSS Β· Domain 3Detecting and Investigating Sanctions Evasion
Domain 1

Risks and Methods

How financial crime occurs, where AML risk appears, and how typologies are recognized.

Domain 1 Topic Premium

Sector & Product Risks

Banking is inherently more vulnerable than other sectors because it touches all three ML stages. Four specific factors drive this: volume and scale (illicit funds blend into massive daily transaction counts), global reach (cross-border movement exploiting regulatory gaps), complex products (wire transfers, trade finance, correspondent banking), and customer-relationship pressure (relationship managers prioritizing retention over scrutiny).

Private banking and wealth management carries a distinct, testable risk: compensation structures based on assets under management can create a genuine conflict of interest, since relationship managers are financially incentivized to overlook warning signs in high-net-worth relationships. High-risk PBWM products specifically include trust funds, sovereign wealth funds (large sums, cross-border, PEP involvement), and high-value assets like fine art and precious metals. Corporate/investment banking adds its own named risks: front-running, tailgating, churning, and spoofing are all distinct market-manipulation techniques that can mask illicit fund movement.

A real, named case worth knowing: an Estonian bank branch's rapid growth in nonresident customers, combined with controls that didn't scale proportionally, became a systemic AML failure β€” the exam lesson is that rapid growth in a higher-risk customer segment demands controls that grow with it, not controls sized for the bank's original, smaller customer base.

Real Exam Concepts (Study Guide v7.03, Domain 1, pp.40, 58, 64)
  • Compensation tied to AUM is a named, testable conflict-of-interest risk in private banking β€” not a generic "trust" issue.
  • Confusing front-running (trading ahead of a customer order), tailgating (trading right after a large order), churning (excessive trading for commissions), and spoofing (fake orders to move price).
  • Treating "complex products" as risky in isolation rather than because of the specific vulnerabilities they create (opacity, cross-border reach).
Learning Outcomes
  • Identify the four specific factors driving banking-sector vulnerability.
  • Explain the AUM compensation conflict-of-interest risk in private banking.
  • Distinguish front-running, tailgating, churning, and spoofing.
  • Apply product-risk thinking to exam scenarios.
Exam tip: Market-manipulation questions test precise definitions β€” "trading based on advance knowledge of a pending order" is front-running specifically, not a generic term for any manipulation. (Study Guide v7.03, Domain 1, p.64)
Practise this topic β†’
Domain 1 Topic Premium

Predicate Crimes & Financial Crime Types

FATF has designated 21 specific categories of predicate offenses institutions must recognize β€” from organized crime and terrorism to human trafficking, drug trafficking, arms trafficking, corruption, fraud, counterfeiting, environmental crime, extortion, forgery, and insider trading. Jurisdictions don't always classify these identically; some don't recognize certain forms of exploitation as criminal, which complicates cross-border compliance.

Money laundering requires an underlying predicate offence β€” the proceeds must come from somewhere. Sanctions evasion itself is treated as a predicate offence too, and can be internal (aided by staff) or external, operating through payment-related methods (stripping identifying information from instructions), trade-related methods (transshipment, false licensing), or ownership-related methods (complex structures, proxies, bearer shares).

Real Exam Concepts (Study Guide v7.03, Domain 1, pp.9–12)
  • Not every jurisdiction recognizes the same 21 categories β€” cross-border compliance must reconcile differing predicate-offence lists.
  • Confusing the predicate crime (source of funds) with money laundering (the act of disguising them) β€” the exam often asks you to identify which one a scenario describes.
  • Sanctions evasion is itself a predicate offence, not just a standalone violation.
Learning Outcomes
  • Recall the scope of FATF's 21 predicate offence categories.
  • Identify predicate-generating activity in scenarios.
  • Distinguish payment-, trade-, and ownership-related sanctions evasion methods.
  • Distinguish predicate crime from the laundering act itself.
Exam tip: Don't confuse the predicate crime with the laundering act β€” the exam often asks you to identify which one a scenario is describing. (Study Guide v7.03, Domain 1, pp.9–11)
Practise this topic β†’
Domain 1 Topic Premium

Trusts, TCSPs & Legal Arrangements

A trust separates legal ownership (held by trustees, who must be natural persons) from beneficial control. The settlor transfers assets into the trust; trustees manage it for beneficiaries β€” and critically, the same person can be settlor, trustee, and beneficiary simultaneously, meaning a nominally independent trustee may simply follow the settlor's directions. In many jurisdictions trusts have no registration requirement at all β€” they're private arrangements with no public record, which FATF has specifically flagged as a concern given how easily such vehicles can be created and dissolved.

A concrete example from the Study Guide: a government official awarded a construction contract can't receive a bribe directly without raising suspicion β€” so the construction company instead pays an "advisory fee" to a company in another jurisdiction, whose ownership has been settled into a trust benefiting the official and his family. The trust becomes the final layer of secrecy in an otherwise traceable bribery scheme.

Real Exam Concepts (Study Guide v7.03, Domain 1, pp.60–61)
  • The same person can legally be settlor, trustee, and beneficiary β€” "independent" trustees may not be independent in substance.
  • Many jurisdictions have no trust registration requirement at all β€” this is a structural transparency gap, not a compliance failure.
  • Trusts are often the final layer added to an otherwise traceable scheme, not the starting point.
Learning Outcomes
  • Explain the settlor/trustee/beneficiary structure and how roles can overlap.
  • Identify the transparency gap created by unregistered trusts.
  • Recognize how trusts get layered onto bribery/corruption schemes.
  • Apply beneficial ownership identification principles.
Exam tip: When a scenario describes layered entities, ask "who ultimately benefits and who actually controls decisions?" β€” a trustee who simply follows the settlor's instructions isn't truly independent, regardless of title. (Study Guide v7.03, Domain 1, p.60)
Practise this topic β†’
Domain 1 Topic Premium

ML Stages, Typologies & Red Flags

Placement introduces "dirty money" into the financial system; layering moves it through transactions (transfers to holding companies, false invoices, private loans) to conceal its origin; integration lets the criminal use it to buy goods and services. The three stages don't always happen in strict sequence β€” sometimes two occur almost simultaneously.

Named techniques worth knowing precisely: structuring/smurfing (splitting large sums into small transactions across accounts to dodge reporting thresholds) and its digital cousin microstructuring; digital asset laundering via mixing services and privacy coins; money muling (recruiting intermediaries, often via job scams, to move funds); TBML (over/under-invoicing, phantom shipments); market-based laundering through securities and derivatives; and commodity-based laundering through gold, diamonds, and art. A real 2019 US case: Yamel Guevara Tamayo recruited 200+ money mules, deliberately structured deposits just under the US$10,000 threshold, then used microstructuring (deposits under US$1,000) β€” successfully laundering over US$700,000 before banks intervened.

Real Exam Concepts (Study Guide v7.03, Domain 1, pp.4–8)
  • The three stages aren't always sequential β€” some scenarios show simultaneous placement and layering.
  • Microstructuring is structuring's digital-asset-specific cousin, not a separate unrelated technique.
  • Money mules are often recruited without full awareness of the crime β€” recruitment via job scams is a real, tested pattern.
Learning Outcomes
  • Define placement, layering, and integration precisely.
  • Name and distinguish structuring, microstructuring, TBML, MBML, and commodity-based laundering.
  • Recognize money-mule recruitment patterns.
  • Apply typology recognition to scenario questions.
Exam tip: If a question asks "which stage is this," look for the verb β€” depositing suggests placement, moving between accounts suggests layering, investing or purchasing suggests integration. (Study Guide v7.03, Domain 1, pp.4–8)
Practise this topic β†’
Domain 1 Topic Premium

General AML/CFT Concepts

Financial crime's worldwide proceeds are estimated at up to 5% of global GDP β€” roughly US$2 trillion. Beyond the headline figure, a testable distinction: a regulated entity (banks, MSBs) falls under direct financial-regulator supervision, while an obliged entity is the broader category that also includes nonfinancial sectors (energy, real estate, logistics) expected to run risk assessments and controls even without direct financial-regulator oversight. An entity can be both.

Four specific risk types recur throughout the syllabus: operational risk (failed internal processes/systems), legal risk (penalties, unenforceable contracts), concentration risk (over-exposure to one customer or related group), and reputational risk (hard to quantify, slow to build, fast to lose). Individual accountability is real and scales with seniority β€” MLROs and BSA officers carry the greatest personal exposure, while first-line staff more often face administrative penalties unless intentional wrongdoing is shown.

Real Exam Concepts (Study Guide v7.03, Domain 1, pp.28–36)
  • Confusing regulated entity (direct financial-regulator supervision) with the broader obliged entity category.
  • Assuming individual accountability is uniform β€” it scales with seniority and role.
  • Treating reputational risk as easy to quantify β€” it's explicitly the hardest of the four to measure.
Learning Outcomes
  • Cite the scale of global financial crime (5% of GDP / US$2 trillion).
  • Distinguish regulated entities from the broader obliged entity category.
  • Identify operational, legal, concentration, and reputational risk.
  • Apply foundational concepts across scenario types.
Exam tip: If a scenario describes a nonfinancial business (real estate, logistics, energy) still expected to run AML risk assessments, that's testing the "obliged entity" concept, not "regulated entity." (Study Guide v7.03, Domain 1, p.30)
Practise this topic β†’
Domain 1 Topic Premium

Trade-Based Money Laundering

Beyond the classic over/under-invoicing and phantom shipments, the Study Guide lists specific TBML risk indicators worth recognizing precisely: trades booked remotely within a group of related entities; pre-arranged trading creating artificial volumes; third-party instructions adding layers; nonstandard settlement arrangements; uneconomic or irrational trading strategies; unusual patterns like counterparty concentration or flat/neutralizing activity; and misuse of factoring, forfaiting, and supply chain financing.

Three trade finance products are named as particularly exploitable: letters of credit (misused to create fictitious trade transactions), bills of exchange (manipulated to disguise transaction nature), and trade credit insurance (fraudulent claims used to launder money).

Real Exam Concepts (Study Guide v7.03, Domain 1, pp.53–54)
  • "Uneconomic or irrational trading strategies" is a specific, named red flag β€” not just generic suspicion.
  • Factoring and forfaiting can convert illicit receivables into legitimate-looking funds β€” a less obvious TBML channel.
  • Confusing which named product (letter of credit vs. bill of exchange vs. trade credit insurance) a scenario is describing.
Learning Outcomes
  • List the specific TBML risk indicators beyond basic invoicing manipulation.
  • Identify the three named high-risk trade finance products.
  • Explain how factoring and supply chain financing can be misused.
  • Apply TBML detection principles to scenarios.
Exam tip: "Uneconomic or irrational trading strategies" and "nonstandard settlement arrangements" are exact phrases from the Study Guide's TBML red-flag list β€” questions often test recognition of these specific indicators. (Study Guide v7.03, Domain 1, p.53)
Practise this topic β†’
Domain 1 Topic Premium

Real Estate & High-Value Assets

High-value assets (real estate, fine art, antiquities, luxury goods, precious metals) attract launderers for three reasons named in the Study Guide: substantial worth, potential for value appreciation, and relatively easy transfer of ownership. These assets are especially prominent in private banking and wealth management portfolios.

A specific technique worth knowing precisely: round tripping β€” moving funds into an offshore financial center (OFC) and back out again with no legitimate economic purpose, often disguised as reinvestment. OFC red flags include complex ownership structures, sudden large fund flows, rapid asset transfers between offshore entities, and PEP involvement β€” though the Study Guide is explicit that these can be legitimate business practices too, so a clear business rationale (or its absence) is what actually distinguishes risk from normal activity.

Real Exam Concepts (Study Guide v7.03, Domain 1, pp.59, 61)
  • Round tripping specifically means funds returning to their origin via an OFC β€” not just any offshore transfer.
  • OFC red flags aren't automatically suspicious β€” the Study Guide stresses a missing legitimate business purpose is what matters.
  • High-value asset risk stems from three specific properties: worth, appreciation potential, easy transfer β€” not just "expensive things are risky."
Learning Outcomes
  • Explain the three named reasons high-value assets attract laundering.
  • Define round tripping precisely.
  • Identify OFC red flags and the role of legitimate business purpose.
  • Apply source-of-funds scrutiny to asset purchases.
Exam tip: If a scenario shows funds leaving and returning to the same origin via an offshore center with no economic rationale, that's round tripping specifically β€” a named, testable term. (Study Guide v7.03, Domain 1, p.61)
Practise this topic β†’
Domain 1 Topic Premium

Virtual Assets, Crypto & VASPs

The Study Guide names digital asset laundering as a distinct technique: cryptocurrencies, NFTs, and DeFi allow pseudonymous cross-border transfers, with launderers using mixing services and privacy coins for anonymity, then cashing out through VASPs in jurisdictions with weak AML/CFT regulation. Microstructuring β€” structuring's digital-native cousin β€” splits illicit crypto proceeds into many small transactions specifically to evade monitoring thresholds.

Terrorist financiers use virtual assets distinctively too: numerous, seemingly unrelated small cryptocurrency deposits, quickly converted to stablecoins or fiat and withdrawn through a VASP in a weakly-regulated jurisdiction β€” a pattern worth recognizing as its own red flag, separate from money laundering typologies.

Real Exam Concepts (Study Guide v7.03, Domain 1, pp.5, 25)
  • Microstructuring is specifically the digital-asset analogue of structuring β€” not a separate, unrelated concept.
  • Mixing services and privacy coins are named techniques for obscuring transaction origin, distinct from simple pseudonymity.
  • A VASP operating in a weak-AML jurisdiction is itself a named risk factor, not just "crypto is risky."
Learning Outcomes
  • Explain digital asset laundering via mixing services and privacy coins.
  • Define microstructuring and distinguish it from standard structuring.
  • Recognize terrorist-financing-specific virtual asset patterns.
  • Apply enhanced due diligence concepts to virtual-asset scenarios.
Exam tip: If deposits are small, numerous, and quickly converted to stablecoins before cashing out via a poorly-regulated VASP, that pattern is described almost verbatim in the Study Guide as a terrorist-financing red flag. (Study Guide v7.03, Domain 1, p.25)
Practise this topic β†’
Domain 1 Topic Premium

Terrorist Financing & NPO Risk

A precise, testable distinction: money laundering's pathway is circular β€” the launderer expects to regain control of the funds at the end. Terrorist financing's pathway is linear β€” funds move outward to support terrorist activity with no expectation of return. Terrorist financing can also draw on entirely legitimate sources (business fronts, sympathetic donations) as easily as illegitimate ones (kidnapping, trafficking proceeds), which is why source-of-funds legitimacy alone doesn't rule out TF risk.

The Study Guide names specific movement channels: correspondent banking (nested transactions to unrelated third parties), prepaid cards (minimal KYC, purchasable with stolen credit or cash), cryptocurrencies and stablecoins (numerous small deposits, rapid conversion), and alternative remittance systems (deposits in one jurisdiction, immediate ATM withdrawal in another β€” a named red flag pattern).

Real Exam Concepts (Study Guide v7.03, Domain 1, pp.23–26)
  • Circular (ML) vs. linear (TF) fund pathway β€” a precise distinction the exam tests directly.
  • Legitimate-source funds can still be terrorist financing β€” source legitimacy doesn't rule out TF risk.
  • ARS deposit-in-one-jurisdiction/immediate-withdrawal-in-another is a named specific red flag, not generic "unusual activity."
Learning Outcomes
  • Distinguish the circular (ML) vs. linear (TF) fund pathway.
  • Explain how legitimate sources can still fund terrorism.
  • Identify TF-specific movement channels (correspondent nesting, prepaid cards, ARS).
  • Apply CFT risk indicators to scenarios.
Exam tip: If a question asks how to distinguish ML from TF conceptually, "circular vs. linear pathway" is the Study Guide's own precise framing β€” more testable than just "different purpose." (Study Guide v7.03, Domain 1, p.24)
Practise this topic β†’
Domain 1 Topic Premium

Money Services Businesses & Payment Services

An MSB is defined by function, not label β€” an entity is an MSB if it holds funds on behalf of another person, covering currency exchange, money transfers, money orders, stored-value products, and bill payment. Payment service providers (PSPs) are a distinct but related category, split into named types: payment aggregators, card issuers, payment processors, payment collectors, mobile wallet providers, alternative payment providers, and cross-border payment providers β€” each with different offerings and risk profiles.

A key structural risk distinction: for PSPs, customer risk is largely indirect (the PSP doesn't directly transact, but must still ensure controls are sound), while partnership risk is typically higher β€” PSPs depend operationally on banks, card networks, and third-party technology providers, and a partner's weak cybersecurity or compliance controls become the PSP's problem too.

Real Exam Concepts (Study Guide v7.03, Domain 1, pp.76–79)
  • PSP customer risk is indirect; partnership/vendor risk is typically the bigger exposure β€” a distinction the exam tests.
  • An entity qualifies as an MSB based on what it does (holding funds for others), not what it calls itself.
  • Confusing the specific PSP sub-types (aggregator vs. processor vs. collector) β€” each has a distinct function.
Learning Outcomes
  • Define MSB by function rather than label.
  • Distinguish PSP sub-types (aggregators, processors, collectors, mobile wallets).
  • Explain why PSP partnership risk typically exceeds direct customer risk.
  • Apply risk-based monitoring to payment-service scenarios.
Exam tip: If a scenario describes a PSP's own AML weakness stemming from a partner bank or technology vendor's poor controls, that's testing partnership risk specifically β€” the Study Guide flags this as typically higher than direct customer risk. (Study Guide v7.03, Domain 1, p.79)
Practise this topic β†’
Domain 1 Topic Premium

PEPs & Corruption Risk

FATF defines exactly three PEP types worth knowing precisely: foreign PEPs (prominent function in a foreign country), domestic PEPs (prominent function domestically), and international organization PEPs (senior roles like secretary general or executive director). Some institutions apply "once a PEP, always a PEP," reasoning the person may retain influence even after leaving office; others weight current influence and time elapsed since the role ended.

A precise distinction worth holding separately: bribery is a specific act β€” offering or receiving a benefit to misuse delegated power β€” while corruption is the broader category encompassing bribery, embezzlement, extortion, graft, and influence peddling. The UK Bribery Act 2010 is notably extraterritorial: it holds UK parent companies liable for bribery by subsidiaries regardless of where in the world the subsidiary operates, and it introduces strict liability for commercial entities unless they can demonstrate adequate anti-bribery safeguards.

Real Exam Concepts (Study Guide v7.03, Domain 1, pp.13, 44)
  • Bribery is one specific act; corruption is the broader category that includes it alongside embezzlement, graft, and extortion.
  • PEP status alone never justifies automatic rejection β€” it triggers risk-based enhanced due diligence.
  • The UK Bribery Act's extraterritorial reach makes a UK parent liable for a foreign subsidiary's bribery β€” a distinctly testable jurisdictional fact.
Learning Outcomes
  • Name FATF's three PEP categories precisely.
  • Distinguish bribery (a specific act) from corruption (the broader category).
  • Explain the UK Bribery Act's extraterritorial scope.
  • Apply enhanced due diligence principles to PEP scenarios.
Exam tip: If a question describes graft, embezzlement, or influence peddling specifically (not a direct exchange), that's still corruption broadly, even though it isn't bribery in the narrow sense. (Study Guide v7.03, Domain 1, p.13)
Practise this topic β†’
Domain 1 Topic Premium

Proliferation Financing

Proliferation financing supports the development or acquisition of weapons of mass destruction, often through front companies, dual-use goods trade, and sanctions evasion techniques.

This is the newest and most specialized of the four broad financial-crime categories tested on CAMS (alongside laundering, terrorist financing, and general financial crime), and FATF has steadily increased its emphasis on it, including requiring institutions to identify and assess proliferation-financing risk as part of their overall risk assessment. Dual-use goods β€” items with both civilian and military applications β€” are a recurring theme, since their legitimate trade use makes illicit diversion harder to spot.

Red Flags to Recognize
  • Trade in dual-use goods routed through front companies with no clear industrial purpose.
  • Transactions involving jurisdictions or entities subject to proliferation-related sanctions.
  • Complex payment structures designed to obscure the ultimate destination of goods or funds.
  • Shipping documentation inconsistent with the stated end-user or end-use of goods.
Learning Outcomes
  • Define proliferation financing and its distinct purpose.
  • Identify front-company and dual-use-goods red flags.
  • Explain the link between sanctions evasion and proliferation financing.
  • Apply proliferation-financing risk indicators to scenarios.
Exam tip: If a scenario mentions dual-use goods, sanctioned jurisdictions, and opaque payment routing together, proliferation financing is usually the intended answer β€” not standard trade-based laundering.
Practise this topic β†’
Domain 1 Topic

Suspicious Activity Reporting & Investigations

Full note under Domain 3 β€” this card covers the Domain 1 angle only.

In Domain 1, this topic focuses on recognizing which typologies and red flags should trigger suspicion in the first place, before the investigation and reporting workflow covered in Domain 3. A strong grasp of Domain 1's typologies (placement, layering, TBML, structuring) is what actually generates the "why" behind a Domain 3 escalation decision.

Learning Outcomes
  • Connect typology recognition to suspicion formation.
  • Identify which red flags most commonly justify escalation.
Practise this topic β†’
Domain 1 Topic

Sanctions Screening & Sanctions Evasion

Full note under Domain 2 β€” this card covers the Domain 1 angle only.

In Domain 1, sanctions evasion is treated as a laundering typology β€” how sanctioned parties disguise ownership or routing to move value despite restrictions. Name variation, front companies, and re-routing through non-sanctioned jurisdictions are the typical mechanics tested here.

Learning Outcomes
  • Identify sanctions-evasion typologies and red flags.
  • Connect sanctions risk to broader typology recognition.
Practise this topic β†’
Domain 1 Topic

CDD, KYC & Beneficial Ownership

Full note under Domain 3 β€” this card covers the Domain 1 angle only.

In Domain 1, weak CDD/KYC is treated as an enabling condition β€” a control gap that allows the risks and typologies discussed elsewhere in this domain to succeed. Most typology-based exam scenarios trace back to a point where better onboarding information would have prevented or flagged the activity earlier.

Learning Outcomes
  • Explain how CDD gaps enable typology risk.
  • Identify onboarding weaknesses linked to specific risk types.
Practise this topic β†’
Domain 1 Topic

Transaction Monitoring & Alert Management

Full note under Domain 4 β€” this card covers the Domain 1 angle only.

In Domain 1, monitoring is framed around which behavioural patterns and typologies should generate alerts, rather than the technology and workflow covered in Domain 4. Knowing the typology (structuring, layering, TBML) tells you what the monitoring rule should actually be looking for.

Learning Outcomes
  • Connect typology patterns to monitoring scenario logic.
  • Identify which risk behaviours justify an alert.
Practise this topic β†’
Domain 2

Frameworks, Governance and Regulations

How global standards, regulations, supervision, and cooperation shape AFC controls.

Domain 2 Topic Premium

AML/CFT Standards, Regulations & Cooperation

FATF groups its 40 Recommendations into seven categories: AML/CFT policies and coordination; money laundering and confiscation; terrorist financing and proliferation financing; preventive measures; transparency and beneficial ownership; powers of competent authorities; and international cooperation. Jurisdictions are expected to turn these into binding law, tailored to their own legal system β€” which is why the same FATF standard can look different from country to country in practice.

In the EU specifically, a testable distinction: a regulation is immediately, directly applicable across all member states, while a directive only sets principles and goals β€” each country must separately transpose it into domestic law by a deadline. The 2024 "Single Rulebook" combined both approaches (6AMLD as a directive, AMLR as a regulation) specifically to close the fragmentation gaps that caused earlier EU AML failures. Cooperation also happens through public-private partnerships β€” regulators, FIUs, and institutions sharing typology reports so institutions can proactively search their own client base for a pattern law enforcement has just identified.

Real Exam Concepts (Study Guide v7.03, Domain 2, pp.127–226)
  • Confusing a regulation (immediately binding EU-wide) with a directive (requires national transposition by each member state).
  • Assuming a FATF Recommendation applies identically in every jurisdiction β€” implementation is tailored to local legal systems.
  • Treating public-private typology sharing as optional rather than a genuine detection tool.
Learning Outcomes
  • Identify the seven categories of FATF Recommendations.
  • Distinguish an EU regulation from a directive.
  • Explain how public-private partnerships and typology reports strengthen detection.
  • Apply regulatory-framework concepts to scenarios.
Exam tip: If a question asks whether an EU AML rule needs national implementing legislation, check whether it's called a "regulation" (no, it's automatic) or a "directive" (yes, transposition required). (Study Guide v7.03, Domain 2, p.174)
Practise this topic β†’
Domain 2 Topic Premium

FATF Standards & Mutual Evaluations

A mutual evaluation rates a jurisdiction on two components: technical compliance (does the law exist?) and effectiveness, measured through 11 Immediate Outcomes covering risk understanding, international cooperation, supervision, preventive measures, legal-person transparency, financial intelligence use, prosecution, confiscation, and terrorist/proliferation financing controls β€” each rated low, moderate, substantial, or high. The process runs through seven stages (assessor training β†’ technical review β†’ scoping β†’ on-site visit β†’ draft report β†’ plenary adoption β†’ publication) and takes about 18 months.

Specific, testable criteria trigger grey-list ("Jurisdictions Under Increased Monitoring") or black-list ("High-Risk Jurisdictions Subject to a Call for Action") designation β€” for example, 20+ non-compliant/partially-compliant technical ratings, or low/moderate effectiveness on 9+ of the 11 Immediate Outcomes. Grey-listing isn't permanent: the UAE was grey-listed in 2022 and successfully removed by 2024 after tightening beneficial-ownership rules, creating a dedicated financial-crime court, and increasing enforcement frequency β€” a real example of the remediation pathway working.

Real Exam Concepts (Study Guide v7.03, Domain 2, pp.130–143)
  • Treating the 11 Immediate Outcomes as a rigid checklist β€” FATF explicitly says assessors use judgment, not box-ticking.
  • Assuming grey-listing is permanent β€” it's a monitoring status a jurisdiction can exit through remediation.
  • Confusing grey list (increased monitoring, working with FATF) with black list (call for countermeasures).
Learning Outcomes
  • Explain the role and structure of the FATF Recommendations.
  • Describe the mutual evaluation process, including technical compliance and the 11 Immediate Outcomes.
  • Distinguish grey-list from black-list designation and their triggers.
  • Apply FATF concepts to scenario questions.
Exam tip: Remember the distinction between technical compliance (law on paper) and effectiveness (real-world results, measured via the 11 Immediate Outcomes) β€” CAMS frequently tests whether you understand that both matter. (Study Guide v7.03, Domain 2, pp.132–141)
Practise this topic β†’
Domain 2 Topic Premium

International Standards & Correspondent Banking

FATF Recommendation 13 requires financial institutions to assess a respondent institution's own AML/CFT controls before establishing a correspondent relationship β€” understanding its business, reputation, and supervision quality, and obtaining senior management approval before proceeding. The Wolfsberg Group's Financial Crime Principles for Correspondent Banking (first published 2014, periodically updated) set out 11 specific risk indicators institutions should weigh β€” including jurisdiction, ownership structure, and regulatory compliance history β€” and call for stricter scrutiny of high-risk relationships such as shell banks or offshore financial centers.

A "nested" relationship occurs when a respondent bank lets other banks access the correspondent relationship through it, multiplying exposure to customers the correspondent never directly vetted. The BCBS's 1988 statement of principles (still foundational today) centers on customer identification, staff training, recordkeeping, and cooperation with law enforcement "to the extent permitted without breaching customer confidentiality" β€” a balance correspondent relationships test constantly.

Real Exam Concepts (Study Guide v7.03, Domain 2, pp.152–162)
  • Treating a respondent bank's own regulatory license as sufficient β€” FATF R.13 requires assessing its actual AML/CFT program.
  • A respondent bank unable to explain its own nested or downstream relationships.
  • Applying identical due diligence depth regardless of the respondent's jurisdiction or ownership structure.
Learning Outcomes
  • Explain FATF Recommendation 13's correspondent banking requirements.
  • Identify nested and payable-through account risks.
  • Describe the Wolfsberg Group's 11 correspondent-banking risk indicators (conceptually).
  • Apply cross-border standard-setting concepts to scenarios.
Exam tip: Correspondent banking due diligence isn't a one-time check at relationship setup β€” it requires ongoing assessment of the respondent's own program, not just its initial licensing status. (Study Guide v7.03, Domain 2, p.155)
Practise this topic β†’
Domain 2 Topic Premium

Sanctions Screening & Sanctions Evasion

UN sanctions derive their authority from Article 41 of Chapter VII of the UN Charter, and member states are legally obligated to carry out Security Council decisions. The EU calls its sanctions "restrictive measures" β€” the EU adopts (and can go beyond) UN sanctions via Council Decisions and Regulations, with member states responsible for enforcement. In the US, OFAC administers four distinct sanctions types worth knowing apart: jurisdiction-based (entire countries, e.g., North Korea, Iran, Cuba), list-based (specific individuals/entities on the SDN List), secondary sanctions (targeting non-US persons dealing with sanctioned counterparties), and sectoral sanctions (targeting whole economic sectors like energy or defense rather than named parties).

Enforcement is real and severe β€” Wells Fargo paid a US$67.8 million Federal Reserve fine in 2023 for a trade-finance platform enabling transactions with sanctioned parties, illustrating that sanctions liability doesn't require intent β€” insufficient policies and procedures were enough to trigger the penalty.

Real Exam Concepts (Study Guide v7.03, Domain 2, pp.173–194)
  • Confusing jurisdiction-based (whole country) with sectoral (whole industry, not whole country) sanctions.
  • Assuming secondary sanctions only affect US persons β€” they specifically target non-US persons dealing with sanctioned parties.
  • Treating "no direct link to a sanctioned party" as sufficient defense when policies/procedures were themselves inadequate.
Learning Outcomes
  • Explain the legal basis of UN, EU, and US sanctions regimes.
  • Distinguish jurisdiction-based, list-based, secondary, and sectoral sanctions.
  • Identify common sanctions-evasion techniques.
  • Apply sanctions-compliance concepts to scenarios.
Exam tip: If a question describes sanctions targeting an entire economic sector (not specific named parties, not an entire country), that's sectoral sanctions β€” a distinct category from jurisdiction-based. (Study Guide v7.03, Domain 2, pp.172–174)
Practise this topic β†’
Domain 2 Topic Premium

FIU Cooperation & Financial Intelligence

The Egmont Group, established in 1995, operationalizes FIU-to-FIU cooperation through three governing documents: the Egmont Charter (2013, sets purpose and structure), the Principles for Information Exchange (2013, governs bilateral/multilateral sharing), and Operational Guidance for FIUs (2013, binding operational rules for all members). Its core functions are information sharing, capacity building, collaboration with law enforcement, and standard-setting.

Each jurisdiction's FIU has a distinct name and model worth recognizing: FinCEN is the US FIU; the UKFIU sits within the National Crime Agency; STRO is Singapore's FIU (part of the Singapore Police Force); the Joint Financial Intelligence Unit serves Hong Kong; and Korea's FIU operates under the Financial Services Commission. Despite different institutional homes, the core function is identical everywhere: receive reports, add analytical value, and route actionable intelligence to law enforcement or international counterparts.

Real Exam Concepts (Study Guide v7.03, Domain 2, pp.153–195)
  • Assuming all FIUs share one organizational model β€” they vary (police-based, treasury-based, independent) even though their function is consistent.
  • Treating a filed SAR/STR as ending an institution's obligation β€” ongoing monitoring and cooperation continue.
  • Discussing a filed report's existence with the customer it concerns (tipping-off) β€” strictly prohibited everywhere.
Learning Outcomes
  • Explain the role and function of an FIU and the Egmont Group's governing documents.
  • Identify FIU models and names across major jurisdictions (FinCEN, UKFIU, STRO, JFIU).
  • Understand confidentiality and tipping-off obligations.
  • Apply FIU-cooperation concepts to scenarios.
Exam tip: Tipping-off questions usually test whether you understand that the confidentiality obligation applies even to the fact that a report was filed, not just its contents. (Study Guide v7.03, Domain 2, p.284)
Practise this topic β†’
Domain 2 Topic

General AML/CFT Concepts

Full note under Domain 1 β€” this card covers the Domain 2 angle only.

In Domain 2, foundational concepts are applied to how frameworks and regulation are structured, rather than how typologies work. The risk-based/proportionate approach from FATF's Recommendation 1 is the concept most tested from this angle.

Learning Outcomes
  • Connect foundational terms to regulatory framework design.
  • Identify how core concepts shape supervisory expectations.
Practise this topic β†’
Domain 2 Topic

Suspicious Activity Reporting & Investigations

Full note under Domain 3 β€” this card covers the Domain 2 angle only.

In Domain 2, SAR/STR filing is framed as a regulatory obligation with specific legal timelines and confidentiality requirements, rather than the internal investigation workflow. This is the angle exam questions about statutory deadlines and tipping-off law typically test.

Learning Outcomes
  • Identify statutory reporting obligations and timelines.
  • Explain the legal basis for confidentiality after filing.
Practise this topic β†’
Domain 2 Topic

CDD, KYC & Beneficial Ownership

Full note under Domain 3 β€” this card covers the Domain 2 angle only.

In Domain 2, CDD/KYC is framed as a regulatory minimum standard set by law and supervisory guidance, rather than the program design covered in Domain 3. Know which elements of CDD are legally mandated versus which are institutional best practice above the legal floor.

Learning Outcomes
  • Identify statutory CDD/KYC minimum requirements.
  • Explain the regulatory basis for enhanced due diligence.
Practise this topic β†’
Domain 2 Topic

Trusts, TCSPs & Legal Arrangements

Full note under Domain 1 β€” this card covers the Domain 2 angle only.

In Domain 2, TCSPs are treated as a regulated sector with specific registration, licensing, and beneficial-ownership disclosure obligations, reflecting the global push toward ownership transparency under FATF Recommendations 24 and 25.

Learning Outcomes
  • Identify TCSP-specific regulatory obligations.
  • Explain beneficial-ownership registry requirements.
Practise this topic β†’
Domain 2 Topic

Virtual Assets, Crypto & VASPs

Full note under Domain 1 β€” this card covers the Domain 2 angle only.

In Domain 2, VASPs are treated as a regulated category under evolving national frameworks and FATF's Travel Rule expectations β€” implementation levels still vary significantly by jurisdiction, which is itself a testable point.

Learning Outcomes
  • Explain VASP licensing and registration expectations.
  • Identify the purpose of the Travel Rule.
Practise this topic β†’
Domain 2 Topic

PEPs & Corruption Risk

Full note under Domain 1 β€” this card covers the Domain 2 angle only.

In Domain 2, PEP controls are framed as a specific regulatory requirement with defined enhanced due diligence obligations, distinguishing foreign PEPs (baseline EDD required) from domestic PEPs (risk-based approach).

Learning Outcomes
  • Identify statutory PEP due-diligence requirements.
  • Explain senior-management approval expectations for PEP relationships.
Practise this topic β†’
Domain 2 Topic

Transaction Monitoring & Alert Management

Full note under Domain 4 β€” this card covers the Domain 2 angle only.

In Domain 2, monitoring is framed as a regulatory expectation institutions must demonstrate to supervisors, rather than the technology itself. Examiners increasingly focus on whether tuning and testing are evidenced, not just whether a system exists.

Learning Outcomes
  • Identify the regulatory basis for monitoring obligations.
  • Explain what supervisors expect to see evidenced.
Practise this topic β†’
Domain 3

Building a Compliance Program

How institutions design, operate, test, and improve AML/CFT programs.

Domain 3 Topic Premium

Suspicious Activity Reporting & Investigations

Once suspicion is formed, institutions must document the rationale, escalate internally, investigate thoroughly, and file a suspicious activity/transaction report where required β€” all while preserving confidentiality. A strong SAR/STR narrative follows a specific structure: who is involved, what happened, when, where, why it's suspicious, and how it was carried out.

The investigation should build a documented narrative: what triggered the alert, what was reviewed, why the activity is or isn't suspicious, and what action followed. This documentation matters as much as the filing decision itself. A defensive SAR β€” filing mainly to protect the institution rather than because the facts support genuine suspicion β€” is treated as a real problem, not a safe habit: it burdens FIUs and weakens the quality of financial intelligence overall. Filing a SAR also does not automatically require closing the account β€” that decision is separate, risk-based, and sometimes made in coordination with law enforcement, who may actually prefer the account stay open.

Real Exam Traps (Study Guide v7.03, Domain 3, pp.314–355)
  • "File a SAR for every high-risk customer" β€” Wrong. SAR filing requires genuine suspicion or reasonable grounds, not just a high-risk rating.
  • "No SAR filed means no documentation needed" β€” Wrong. A no-filing decision must be documented and reasoned just as much as a filing decision.
  • "A SAR requires immediately closing the account" β€” Wrong. That's a separate, risk-based decision.
  • Alerts closed with no documented rationale, or investigations that stop at the surface transaction without reviewing related parties.
Learning Outcomes
  • Apply the SAR/STR narrative structure (who, what, when, where, why, how).
  • Distinguish a genuine SAR from a defensive SAR.
  • Explain why filing and account-closure are separate decisions.
  • Apply investigation judgment to case scenarios.
Exam tip: When a scenario asks "what should the analyst do next," documentation and escalation are usually safer answers than either ignoring the alert or filing defensively without genuine suspicion. (Study Guide v7.03, Domain 3, pp.337–350)
Practise this topic β†’
Domain 3 Topic Premium

AML/CFT Compliance Program Governance

FinCEN's five pillars anchor every AML program: internal policies and controls; a designated compliance officer; ongoing employee training; independent audit; and CDD. These map onto the three-lines-of-defense model β€” the first line (front-line, business development, operations) owns day-to-day risk and CDD; the second line (AFC compliance, led by the MLRO/BSA officer) sets policy, monitors, and stays independent from business units; the third line (internal audit) objectively tests whether the first two lines actually work.

Risk governance runs through committees, each with a formal terms-of-reference document: a board risk committee for strategic oversight, an AML governance committee (often second-line led) reviewing alert volumes and SAR trends, a high-risk customer review committee for PEPs and correspondent banks, and sometimes a separate sanctions oversight committee. A key distinction the exam tests: quality control (QC) checks the accuracy of outputs (e.g., is a KYC file complete?), while quality assurance (QA) evaluates whether the underlying process is being followed and is effective. Real enforcement cases (TD Bank's US$1.3B fine, RBC's CA$7.475M fine) both trace back to the same root cause: governance that didn't scale with the business, and policies treated as static rather than living documents.

Real Exam Concepts (Study Guide v7.03, Domain 3, pp.227–356)
  • Confusing QC (output accuracy) with QA (process effectiveness) β€” they test different things.
  • Treating vendor outsourcing as removing institutional accountability β€” it never does.
  • Policies reviewed only annually with no "horizon scanning" for emerging risk between cycles.
  • An MLRO or compliance officer without genuine independence or direct board access.
Learning Outcomes
  • Identify FinCEN's five pillars of an AML program.
  • Explain the distinct roles of the first, second, and third lines of defense.
  • Distinguish quality control from quality assurance.
  • Describe governance committee structures and their oversight role.
Exam tip: If a question describes checking whether a specific file is complete and accurate, that's QC. If it describes checking whether the overall process consistently works as designed, that's QA. (Study Guide v7.03, Domain 3, pp.227–251)
Practise this topic β†’
Domain 3 Topic Premium

CDD, KYC & Beneficial Ownership

KYC for a natural person starts with a Customer Identification Program (CIP): full legal name, DOB, nationality, address, and a government-issued ID. KYC for a legal person instead verifies registered business name, entity type, registration number, and β€” critically β€” the beneficial owners and UBOs behind it. Both then move through CDD (assessing risk, income, source of funds) and, for higher-risk customers, EDD (deeper source-of-wealth verification, more frequent review, senior approval).

A frequently tested distinction: the customer risk assessment (CRA) evaluates one customer's individual risk to decide the right level of due diligence, while the enterprise-wide risk assessment (EWRA) evaluates the institution's overall risk exposure to guide program design and resource allocation β€” they're related but answer different questions. Control effectiveness itself follows a specific formula: inherent risk βˆ’ control effectiveness = residual risk. If a PEP's inherent risk is high, applying EDD and enhanced monitoring can bring the residual risk down to medium or low.

Real Exam Concepts (Study Guide v7.03, Domain 3, pp.251–303)
  • Confusing CRA (individual customer risk) with EWRA (organization-wide risk) β€” different scope, different purpose.
  • Treating a KYC refresh as optional once a customer is onboarded β€” periodic and trigger-event reviews are required.
  • Forgetting that residual risk is a calculation (inherent risk minus control effectiveness), not a guess.
  • Applying identical due diligence to every customer regardless of risk rating β€” a direct risk-based-approach failure.
Learning Outcomes
  • Distinguish KYC requirements for a natural person vs. a legal person.
  • Differentiate customer risk assessment (CRA) from enterprise-wide risk assessment (EWRA).
  • Apply the residual risk formula (inherent risk βˆ’ control effectiveness).
  • Identify common KYC refresh trigger events.
Exam tip: If a question describes evaluating one specific customer's risk, that's CRA. If it describes evaluating the institution's overall exposure across all customers, products, and jurisdictions, that's EWRA β€” this distinction shows up often. (Study Guide v7.03, Domain 3, p.272)
Practise this topic β†’
Domain 3 Topic

Trusts, TCSPs & Legal Arrangements

Full note under Domain 1 β€” this card covers the Domain 3 angle only.

In Domain 3, handling trusts and legal arrangements is framed as part of program design β€” what CDD depth and ongoing monitoring these structures require, and how policies should define escalation triggers for opaque ownership chains.

Learning Outcomes
  • Identify program controls needed for complex structures.
  • Explain enhanced monitoring expectations for legal arrangements.
Practise this topic β†’
Domain 3 Topic

Transaction Monitoring & Alert Management

Full note under Domain 4 β€” this card covers the Domain 3 angle only.

In Domain 3, monitoring is framed as a program component β€” how rules, thresholds, and alert-handling procedures should be designed, approved, and governed as part of the compliance program's overall structure.

Learning Outcomes
  • Explain program design choices behind monitoring rules.
  • Identify governance expectations for alert handling.
Practise this topic β†’
Domain 3 Topic

Sanctions Screening & Sanctions Evasion

Full note under Domain 2 β€” this card covers the Domain 3 angle only.

In Domain 3, sanctions screening is framed as a program control that needs list management, escalation procedures, and periodic testing β€” including who owns the decision when a potential match is flagged.

Learning Outcomes
  • Identify program controls needed to operate screening.
  • Explain testing and calibration expectations for screening tools.
Practise this topic β†’
Domain 3 Topic

General AML/CFT Concepts

Full note under Domain 1 β€” this card covers the Domain 3 angle only.

In Domain 3, foundational concepts are applied to how a compliance program should be structured to address them β€” for example, how the risk-based approach translates into an actual documented risk assessment.

Learning Outcomes
  • Connect foundational concepts to program design choices.
  • Identify how core terms shape policy language.
Practise this topic β†’
Domain 3 Topic

PEPs & Corruption Risk

Full note under Domain 1 β€” this card covers the Domain 3 angle only.

In Domain 3, PEP handling is framed as a program requirement β€” approval workflows, source-of-wealth checks, and periodic review cycles that need to be documented and owned by someone senior enough to sign off.

Learning Outcomes
  • Identify program-level PEP approval workflows.
  • Explain periodic review requirements for PEP relationships.
Practise this topic β†’
Domain 3 Topic

Virtual Assets, Crypto & VASPs

Full note under Domain 1 β€” this card covers the Domain 3 angle only.

In Domain 3, virtual-asset exposure is framed as a program design question β€” whether and how to onboard VASP-related customers, and what enhanced controls to apply given the sector's evolving regulatory maturity.

Learning Outcomes
  • Identify program-level controls for virtual-asset exposure.
  • Explain risk-based decisions around VASP relationships.
Practise this topic β†’
Domain 4

Tools and Technologies to Fight Financial Crime

How data, technology, automation, and analytics support AML/CFT work.

Domain 4 Topic Premium

Technology, RegTech & AFC Analytics

AFC technology spans the full customer and transaction lifecycle: digital onboarding and identity verification, sanctions/PEP/adverse media screening, transaction monitoring, case management, network analysis, blockchain tracing, and data governance β€” plus supporting tools like RPA for repetitive tasks and OSINT for investigations.

Before adopting a tool, an institution should assess its current state, identify gaps, and choose build (customization, higher cost), buy-customized, or buy-off-the-shelf (fast, less flexible) based on its actual risk profile β€” not simply pick the newest or most advanced option. AI/ML can prioritize alerts, detect hidden patterns, and improve screening, but carries real limitations: bias in training data, model drift, weak explainability, and over-reliance by analysts. A parallel run alongside the existing system is the safer way to introduce an AI-based tool. Governance is one of the highest-yield areas here β€” the institution must be able to explain how a tool works, what data it uses, how it was tested, and who approved changes. Outsourcing to a vendor never outsources accountability.

Real CAMS Exam Traps (Study Guide v7.03, Domain 4)
  • "AI eliminates human judgment" β€” Wrong. AI supports judgment; accountability stays with the institution.
  • "A vendor is responsible if the AML tool fails" β€” Wrong. The institution remains responsible for selection, testing, and oversight.
  • "Choose the newest, most advanced tool" β€” Wrong. Choose what's proportionate to risk and governable.
  • "Digital onboarding is always unacceptable" β€” Wrong. It's manageable with reliable risk-based controls.
Learning Outcomes
  • Identify AFC technology categories across the customer/transaction lifecycle.
  • Explain the build vs. buy decision and risk-based tool selection.
  • Describe AI/ML capabilities and required governance (validation, explainability, drift monitoring).
  • Explain why vendor outsourcing doesn't transfer institutional accountability.
Exam tip: Every Domain 4 technology question is really asking one thing: is this control risk-based, data-driven, governed, tested, and supported by human judgment? If an answer choice skips any of those, it's usually wrong. (Study Guide v7.03, Domain 4, pp.357–388)
Practise this topic β†’
Domain 4 Topic Premium

Data Collection & Preparation

AFC technology is only as good as the data behind it. The Study Guide frames data quality across five dimensions: completeness, accuracy, consistency, timeliness, and validity β€” weak data on any of these causes false positives, false negatives, missed sanctions matches, and poor risk ratings.

A core distinction tested here is static data (who the customer is expected to be β€” name, DOB, ownership, source of wealth, collected through KYC) versus observed data (what the customer actually does β€” transaction behavior, device use, alert history). Data preparation moves through extraction, cleansing, transformation, validation, and loading (ETL), tracked via data lineage β€” backward lineage traces an output back to its source, forward lineage traces source data into downstream systems. Three related but distinct techniques matter for matching records: entity resolution decides whether multiple records refer to the same person or entity; blocking groups records by shared attributes (name, DOB, device, wallet) purely to make matching more efficient; clustering groups related records to reveal hidden networks like mule rings β€” but clustering only flags a pattern for investigation, it never proves criminal activity by itself.

Real CAMS Exam Traps (Study Guide v7.03, Domain 4)
  • "Clustering proves crime" β€” Wrong. It flags relationships that require investigation and context.
  • "Data issues are only IT issues" β€” Wrong. Compliance, business, data owners, and IT all share responsibility.
  • Confusing entity resolution with blocking β€” Resolution asks "is this the same entity?"; blocking just groups records to search more efficiently.
Learning Outcomes
  • Explain the five data quality dimensions and why each matters.
  • Distinguish static data from observed data.
  • Differentiate entity resolution, blocking, and clustering.
  • Describe data governance committee composition and role.
Exam tip: If a question describes grouping records to find a hidden network, that's clustering. If it asks whether two records are the same entity, that's entity resolution. Don't mix them up β€” the exam tests this distinction directly. (Study Guide v7.03, Domain 4, pp.446–476)
Practise this topic β†’
Domain 4 Topic Premium

Transaction Monitoring & Alert Management

The Study Guide draws a key distinction the exam tests directly: payment screening is preventive β€” it checks parties, payments, vessels, or goods before or during processing, mainly for sanctions/terrorist-financing/proliferation-financing risk. Transaction monitoring is detective β€” it reviews behavior after (or near) the transaction to spot patterns inconsistent with the customer's profile. Batch screening sits alongside both: it re-checks existing customers against updated lists to catch anyone who became risky after onboarding.

Scenario coverage must map to the institution's actual risks β€” products, customers, jurisdictions, typologies. Building a scenario means defining the typology, threshold, time window, and escalation logic, then calibrating and testing it. Turning off alerts because there are too many is treated as a control failure β€” the correct response is root-cause analysis and proper recalibration, not suppression. Once an alert becomes a case, investigation technology takes over: network analysis connects hidden relationships between accounts, devices, and counterparties; blockchain tracing follows wallet clusters and sanctioned addresses; case management preserves the evidence and audit trail. The guide's own memory line: network analysis connects the dots, case management preserves the proof, reporting completes the regulatory record.

Real CAMS Exam Traps (Study Guide v7.03, Domain 4)
  • "Lower alert volume proves better monitoring" β€” Wrong. Only true if genuine suspicious activity detection is preserved.
  • "Scenario tuning can remove workload" β€” Wrong. Tuning requires risk-based testing and documented approval, not shortcut suppression.
  • Confusing payment screening (preventive) with transaction monitoring (detective) β€” the exam tests this distinction directly.
Learning Outcomes
  • Distinguish payment screening (preventive) from transaction monitoring (detective).
  • Explain scenario development, calibration, and why alert suppression is a control failure.
  • Describe the role of network analysis, blockchain tracing, and case management in investigations.
  • Apply AI monitoring governance concepts (model drift, validation, human oversight).
Exam tip: If a scenario describes checking a payment or party BEFORE it processes, that's screening. If it describes reviewing behavior AFTER the fact for a pattern, that's monitoring. This exact distinction is one of the most testable facts in Domain 4. (Study Guide v7.03, Domain 4, pp.415–445)
Practise this topic β†’
Domain 4 Topic

Sanctions Screening & Sanctions Evasion

Full note under Domain 2 β€” this card covers the Domain 4 angle only.

In Domain 4, sanctions screening is framed around the technology itself β€” fuzzy matching, list management, and false-positive tuning are the mechanics tested, not the underlying legal requirement.

Learning Outcomes
  • Explain fuzzy-matching and list-management technology.
  • Identify tuning approaches for screening false positives.
Practise this topic β†’
Domain 4 Topic

Suspicious Activity Reporting & Investigations

Full note under Domain 3 β€” this card covers the Domain 4 angle only.

In Domain 4, this topic covers the case-management and workflow tools that support investigators from alert to filing β€” how technology organizes evidence, timelines, and audit trails for a defensible decision.

Learning Outcomes
  • Explain case-management workflow tools.
  • Identify how technology supports investigation documentation.
Practise this topic β†’
Domain 4 Topic

CDD, KYC & Beneficial Ownership

Full CDD/KYC program note under Domain 3 β€” this card covers the Domain 4 technology angle, which is substantial in its own right.

eKYC means digital verification of identity and KYC information β€” document capture, biometric checks, liveness detection, and automated risk scoring. Perpetual KYC (pKYC) is different from periodic review: it refreshes customer data continuously using trigger events (ownership change, new PEP status, adverse media hit, unusual behavior) rather than waiting for a fixed review date. Liveness detection itself splits into active (blink, turn head) and passive (system detects micro-movement and depth) methods, guarding against photo, video, and deepfake spoofing. On the screening side, fuzzy matching handles name variations and transliteration, but poor tuning creates either excessive false positives or dangerous false negatives β€” and whitelisting to suppress repeat false positives must always be governed, documented, and time-limited, never silent.

Learning Outcomes
  • Distinguish eKYC from perpetual KYC (pKYC) and know common pKYC trigger events.
  • Explain active vs. passive liveness detection.
  • Understand fuzzy matching, tuning, and governed whitelisting in screening technology.
Exam tip: "pKYC means no review" is a direct exam trap β€” wrong. It means review becomes risk-based and event-driven instead of purely calendar-based. (Study Guide v7.03, Domain 4, pp.389–414)
Practise this topic β†’
Domain 4 Topic

Virtual Assets, Crypto & VASPs

Full note under Domain 1 β€” this card covers the Domain 4 angle only.

In Domain 4, virtual-asset technology covers blockchain analytics, wallet clustering, and tools used to trace value across chains β€” the technical layer that turns raw on-chain data into an investigable transaction trail.

Learning Outcomes
  • Explain blockchain analytics and wallet-clustering basics.
  • Identify technology used to trace virtual-asset flows.
Practise this topic β†’
CGSS Β· Domain 1

Sanctions Frameworks and Governance

Why sanctions exist, who imposes them, how far their reach extends, and the legal architecture behind UN, EU, US and UK regimes.

CGSS Domain 1 Topic Premium

The Purpose and History of Sanctions

Sanctions are political decisions made as part of diplomatic efforts by countries, regional organizations, and international bodies β€” primarily a foreign policy and security tool, not a criminal-law one. At their core, every sanction is aimed at behavioral change through deterrence, prevention, or punishment; the specific objective (protecting national security, punishing military aggression, discouraging WMD proliferation, disrupting terrorist financing, diminishing a regime's power to commit human rights violations, or targeting corrupt officials) is just that underlying goal applied to a specific situation. Sanctions sit between diplomacy and war β€” a lower-cost, lower-risk intervention used either instead of military action or while military options are still being evaluated.

The practice is old: one of the first recorded uses dates to 5th-century BCE Athens, which barred citizens of Megara from its markets. The League of Nations (post-WWI) began the shift toward multilateral sanctions β€” multiple countries acting together β€” and the UN Charter formally recognized sanctions as a foreign policy tool in 1945. A precise, testable distinction worth holding onto: Counter-Proliferation Financing (CPF) targets WMD-related financing specifically (anchored in UNSCR 1540 and FATF Recommendation 7), while Countering the Financing of Terrorism (CFT) covers targeted financial sanctions, investigation, information sharing, and due diligence aimed at terrorist financing β€” related concepts, but distinct obligations.

Real Exam Concepts (CGSS Study Guide v2.0, Domain 1, pp.6–22)
  • Sanctions are fundamentally about changing behavior (deterrence/prevention/punishment) β€” not a punitive criminal-law mechanism in themselves.
  • CPF (proliferation financing, UNSCR 1540 / FATF R.7) and CFT (terrorist financing) are related but legally distinct obligation sets.
  • Multilateral sanctions can carry real, documented unintended humanitarian consequences (e.g., North Korea) even where the underlying policy goal is legitimate.
Learning Outcomes
  • Define sanctions and explain their core purpose.
  • Distinguish the main policy objectives sanctions are used to pursue.
  • Explain the CPF vs. CFT distinction.
  • Recognize that sanctions can produce unintended humanitarian consequences.
Exam tip: If a question asks "what are sanctions ultimately meant to achieve," the Study Guide's own framing is behavioral change through deterrence, prevention, or punishment β€” more precise than just "punishing bad actors." (CGSS Study Guide v2.0, Domain 1, p.9)
Practise this topic β†’
CGSS Domain 1 Topic Premium

Who Imposes Sanctions: UN, EU, US & UK Regimes

Sanctions come from three levels: multilateral (UN Security Council, binding on all member states), regional (the EU, applicable across member states), and unilateral (a single country acting alone, such as the US, UK, Canada, or Australia). The UN's authority derives from Article 41 of Chapter VII of its Charter; the Security Council's 15 members include five permanent members with veto power (Russia, US, UK, China, France β€” the "P5"), and at least 9 affirmative votes with no P5 objection are needed to pass a resolution. Once adopted, sanctions are legally binding under Articles 25 and 48, and the UN maintains the Consolidated List of all sanctioned persons and entities β€” though enforcement itself falls to member states, who must pass their own implementing legislation.

The EU calls its own sanctions "restrictive measures," prepared by the European External Action Service and adopted unanimously under its Common Foreign and Security Policy; it both implements UN sanctions (via Council Decisions/Regulations) and imposes autonomous ones. The US runs the most comprehensive framework globally β€” sanctions originate from the President (via Executive Orders under IEEPA/TWEA) or Congress (via statute, e.g., CAATSA), and are implemented mainly by OFAC (Treasury), which maintains the SDN List, alongside BIS (Commerce, export controls/EAR) and the State Department. The UK, post-Brexit, runs its own regime under the 2018 Sanctions and Anti-Money Laundering Act (SAMLA), with OFSI (financial sanctions/licensing), the FCA, the Department for Business and Trade, and the Home Office (travel bans) each holding a distinct piece.

Real Exam Concepts (CGSS Study Guide v2.0, Domain 1, pp.24–36)
  • UN sanctions require 9+ affirmative votes AND no P5 veto β€” a single P5 objection blocks the resolution entirely.
  • Confusing which US agency owns which list: OFAC (SDN List, financial/economic), BIS (Denied Persons List, Entity List, EAR export controls), State Department (Cuba Restricted List, Nonproliferation list).
  • Assuming UK sanctions still mirror EU sanctions post-Brexit β€” they diverge, and firms with a UK connection must monitor both separately.
Learning Outcomes
  • Distinguish multilateral, regional, and unilateral sanctions authority.
  • Explain the UN Security Council's voting and veto structure for sanctions resolutions.
  • Identify the key US agencies (OFAC, BIS, State) and their respective lists.
  • Describe the UK's post-Brexit sanctions architecture (SAMLA, OFSI, FCA).
Exam tip: If a scenario references the SDN List, that's OFAC; if it references the Entity List or Denied Persons List, that's BIS β€” the exam tests this agency/list pairing directly. (CGSS Study Guide v2.0, Domain 1, p.31)
Practise this topic β†’
CGSS Domain 1 Topic Premium

US Primary vs. Secondary Sanctions & OFAC

US primary sanctions apply where a "US nexus" exists β€” a US citizen or permanent resident (wherever located), any entity organized under US law, anyone physically present in the US, or (in some programs, like Iran and Cuba) a non-US entity owned/controlled by a US person. US secondary sanctions are different in kind, not just degree: they target non-US persons for transactions entirely outside the US, with no US nexus at all β€” used in a limited set of programs (Iran, North Korea, Russia), and made a far more prominent tool after CAATSA in 2017. Because no US connection is required, secondary sanctions don't impose fines for a "violation" the way primary sanctions do; instead, the non-US party risks being cut off from the US financial system or added to the SDN List themselves.

Determining secondary-sanctions exposure turns on whether a non-US person "knowingly" facilitated a "significant transaction" β€” OFAC weighs factors like transaction size/frequency, whether it fits a pattern, management's awareness, and any connection to a blocked person, explicitly on a case-by-case basis rather than a fixed threshold. OFAC itself sits inside Treasury and administers both targeted programs (e.g., Global Magnitsky, Counter Narcotics Trafficking) and comprehensive country programs (Iran, North Korea) β€” its core list, the Specially Designated Nationals and Blocked Persons (SDN) List, blocks the named person's assets and generally bars US persons from dealing with them at all.

Real Exam Concepts (CGSS Study Guide v2.0, Domain 1, pp.32–34, 46)
  • Primary sanctions require a US nexus; secondary sanctions explicitly do not β€” that absence of a nexus is the defining feature, not an edge case.
  • "Significant transaction" has no fixed legal definition β€” it's a case-by-case, multi-factor determination, not a bright-line dollar threshold.
  • Secondary sanctions don't produce fines for non-US persons the way primary sanctions do; the consequence is exclusion from the US financial system or SDN designation.
Learning Outcomes
  • Define "US person" and identify what triggers primary sanctions.
  • Distinguish primary from secondary sanctions and explain why secondary sanctions need no US nexus.
  • Identify the factors OFAC weighs in a "significant transaction" determination.
  • Explain OFAC's role and the function of the SDN List.
Exam tip: If a question describes a transaction between two non-US parties with zero US connection, and asks whether US sanctions could still apply, the answer almost always turns on secondary sanctions exposure, not primary. (CGSS Study Guide v2.0, Domain 1, p.32)
Practise this topic β†’
CGSS Domain 1 Topic Premium

Jurisdictional Reach & Extraterritoriality

Extraterritoriality is a state applying its laws to persons, property, or conduct beyond its own borders. The US is the primary jurisdiction that does this deliberately through its sanctions regimes; the EU considers the practice a violation of international law and does not apply its own restrictive measures extraterritorially β€” EU sanctions instead require an actual EU nexus (an EU national, an EU-incorporated entity, or activity conducted at least partly within the EU). This asymmetry is exactly what creates blocking regulations: EU/UK law that can prohibit EU/UK persons from complying with certain extraterritorial US sanctions, specifically to protect their own economic interests and foreign policy positions from being overridden by another country's law.

Two named, testable cases capture how this plays out in practice. In Cynergy Bank, a UK bank stopped paying loan interest to a Cyprus-based lender after the lender's ultimate beneficial owner (Russian oligarch Viktor Vekselberg) was designated an SDN β€” UK courts held that Cynergy was correctly complying with US secondary sanctions, even though Cynergy itself was never a "US person," because the underlying transaction involved an SDN-linked party. In the JCPOA case, when the US withdrew from the Iran nuclear deal in 2018 and reimposed sanctions, the EU stood up INSTEX β€” a special-purpose vehicle meant to let European exporters keep trading with Iran outside the reach of US secondary sanctions β€” but it struggled against financial-sector reluctance to risk US exposure and was ultimately liquidated in 2023, a real illustration of how hard blocking mechanisms are to make work in practice.

Real Exam Concepts (CGSS Study Guide v2.0, Domain 1, pp.40–44)
  • The EU requires an actual EU nexus for its sanctions to apply; the US does not require a US nexus for secondary sanctions β€” this asymmetry is the direct cause of blocking-regulation conflicts.
  • Cynergy Bank: complying with US secondary sanctions (by not paying) was found to be the correct, legally defensible action for a non-US bank β€” not a sanctions violation.
  • Blocking regulations don't force businesses to trade with sanctioned parties β€” they protect against being compelled to comply with a foreign country's extraterritorial sanctions, not create an obligation to defy them.
Learning Outcomes
  • Define extraterritoriality and contrast the US and EU approaches to it.
  • Explain how and why blocking regulations arise.
  • Apply the Cynergy Bank case to a UBO/SDN-designation scenario.
  • Explain what INSTEX was built to do and why it struggled.
Exam tip: If a scenario shows a non-US, non-UK, non-EU-connected entity avoiding a transaction specifically because a counterparty's UBO is an SDN, that's a Cynergy-Bank-style secondary sanctions exposure question β€” refusing the transaction is usually the correct, compliant answer. (CGSS Study Guide v2.0, Domain 1, p.41)
Practise this topic β†’
CGSS Domain 1 Topic Premium

Sanctions Targets & Facilitation

Everyone is subject to sanctions based on jurisdiction, but not everyone needs a formal sanctions compliance program β€” that obligation falls on organizations that are directly regulated for sanctions compliance, or whose risk exposure (nature, size, complexity of business) warrants one. Citizens and permanent residents must comply with their home jurisdiction's sanctions wherever they physically are, and separately must comply with the sanctions law of wherever they're physically located β€” both apply simultaneously, not one or the other. Two real limitations exist on who can be targeted: a country generally cannot sanction its own citizens without violating its own domestic law, and sanctions must respect human rights and humanitarian obligations.

Facilitation is a precisely defined, separately prohibited concept: making a sanctionable activity easier for a third party, even without directly engaging in the underlying transaction yourself β€” this covers providing personnel, software, technology, goods, services, financing, approvals, guarantees, or even referring a business opportunity to a foreign entity. OFAC prohibits US persons from facilitating; the EU has similar anti-circumvention rules. The named Alfa Laval case shows exactly how this plays out: a Middle East subsidiary of a US company falsified export documents to reroute oil-tank-cleaning equipment to Iran via Dubai, without informing the US parent β€” OFAC still penalized the responsible subsidiary over US$615,000, more than 30 times the shipment's value, illustrating how facilitation penalties are designed to deter, not merely recover losses.

Real Exam Concepts (CGSS Study Guide v2.0, Domain 1, pp.50–54)
  • Home-jurisdiction sanctions obligations and physical-location sanctions obligations both apply at once β€” being outside your home country doesn't suspend either one.
  • Facilitation covers referring a business opportunity alone β€” actual participation in the underlying transaction isn't required to violate it.
  • A US parent company's lack of direct knowledge did not prevent OFAC from penalizing facilitation carried out by a foreign subsidiary.
Learning Outcomes
  • Identify who must comply with sanctions vs. who must maintain a formal compliance program.
  • Explain the two limitations on eligible sanctions targets.
  • Define facilitation and list the activities it covers.
  • Apply the Alfa Laval case to a subsidiary-facilitation scenario.
Exam tip: If a scenario describes someone merely referring, approving, or arranging a deal with a sanctioned party β€” without directly transacting themselves β€” that's facilitation, a distinct violation from the underlying sanctionable transaction itself. (CGSS Study Guide v2.0, Domain 1, p.52)
Practise this topic β†’
CGSS Domain 1 Topic Premium

Types of Sanctions and Embargoes

Sanctions take several forms β€” financial/economic sanctions, trade sanctions (including arms embargoes and export controls), asset freezes, and travel bans β€” and separately can be either comprehensive (targeting an entire jurisdiction, like the Iraq sanctions after the 1990 Kuwait invasion, which triggered severe currency inflation and infrastructure collapse alongside their intended effect) or targeted/"smart" (focused on specific individuals to limit collateral damage to the broader population). The 2022 Magnitsky Act case is the textbook targeted-sanctions example: named after a Russian lawyer who died in custody after exposing a US$230 million fraud, the Act lets governments freeze assets and bar entry for human rights violators and corrupt officials specifically, anywhere in the world, without sanctioning their whole country.

Sectoral sanctions sit in between β€” they don't target a whole country or just named individuals, but a specific economic sector (finance, energy, defense). Russia's 2014 and 2022 sectoral sanctions are the most heavily tested example: a price cap on seaborne oil, bans on aircraft-part exports, mining-sector import restrictions, and β€” notably β€” removing designated Russian banks from SWIFT, which blocked their ability to send or receive international payments at all. Asset freezes are their own distinct tool: the Roman Abramovich case shows a freeze can coexist with a targeted license for narrow purposes (his Chelsea Football Club was licensed to keep playing matches and paying players even while his broader assets stayed frozen) β€” freezing and total prohibition are not the same thing.

Real Exam Concepts (CGSS Study Guide v2.0, Domain 1, pp.55–70)
  • Comprehensive sanctions target an entire jurisdiction; targeted/smart sanctions and sectoral sanctions are both narrower, but sectoral targets an industry, not named individuals.
  • Removal from SWIFT is a specific, real sectoral sanctions tool β€” not the same as a blanket trade ban.
  • A frozen asset can still be the subject of a general license permitting narrow, specific activity (Abramovich/Chelsea) β€” freezing isn't automatically absolute.
Learning Outcomes
  • Distinguish comprehensive, targeted, and sectoral sanctions.
  • Explain the Magnitsky Act's targeted human-rights sanctions model.
  • Describe how SWIFT removal functions as a sectoral sanctions tool.
  • Apply the Abramovich/Chelsea case to a licensed-activity-under-freeze scenario.
Exam tip: If a question names a specific economic sector (energy, defense, finance) rather than a whole country or a named person, that's sectoral sanctions β€” a distinct category the exam tests against comprehensive and targeted sanctions. (CGSS Study Guide v2.0, Domain 1, p.65)
Practise this topic β†’
CGSS Domain 1 Topic Premium

Sanctions Exceptions, Exemptions & Licensing

A license is written authorization permitting an activity that sanctions would otherwise prohibit β€” and there are two distinct types. A general license (called a derogation in the EU) authorizes a whole category of transactions for any qualifying person, with no individual application needed β€” typically covering humanitarian aid, legal services, or basic needs. A specific license is granted case-by-case, only after a written application demonstrating the activity meets the program's criteria, and approval is never guaranteed β€” OFAC can take months, and some categories carry a standing policy of denial. Both types come with real limits: a license authorizes only the specific activity and amount described, never unrestricted dealings with a sanctioned party, and a bank that helps move licensed funds still bears its own compliance obligations for enhanced monitoring, separate from the customer's own license.

The named Syria Property Ltd. case shows this concretely: a UK real estate firm's accounts were frozen once its Syrian parent became a designated entity, and even after obtaining a license to resume basic operating payments (payroll, utilities, insurance), the bank was still expected to actively monitor every withdrawal for license-scope compliance β€” obtaining a license doesn't end an institution's own due diligence duty. On the humanitarian side, the Study Guide's Taliban/Afghanistan example shows how narrow "general license" language really is: OFAC's General License 19 permitted education-related humanitarian transfers into Afghanistan, but explicitly did not authorize payments to any blocked person beyond specific categories like taxes, fees, or permits β€” a license's precise wording, not its general humanitarian purpose, defines what's actually allowed.

Real Exam Concepts (CGSS Study Guide v2.0, Domain 1, pp.63, 74–86)
  • A general license needs no application; a specific license does, and approval is never guaranteed even with a strong case.
  • Holding a license doesn't remove a bank's own obligation to monitor that the licensed activity stays within scope β€” Syria Property Ltd. is the exam's anchor case for this.
  • Assuming a general license's humanitarian purpose covers any related payment β€” GL 19 explicitly excluded most payments to blocked persons beyond narrow named categories.
Learning Outcomes
  • Distinguish general licenses/derogations from specific licenses/exceptions.
  • Explain why obtaining a license doesn't end a bank's monitoring obligation.
  • Apply the Syria Property Ltd. case to a frozen-account licensing scenario.
  • Identify common licensing errors (assuming past approvals apply, misreading scope, incomplete documentation).
Exam tip: If a scenario asks whether a bank can stop monitoring a customer's transactions once a license is granted, the answer is no β€” enhanced monitoring of licensed activity is an ongoing institutional obligation, not a one-time check. (CGSS Study Guide v2.0, Domain 1, p.79)
Practise this topic β†’
CGSS Domain 1 Topic Premium

Delisting

Delisting removes an entity, individual, or item from a sanctions list, and can happen for several distinct reasons: genuine behavior change (ending terrorism support, complying with an agreement), correcting an error (the person was listed by mistake), positive diplomatic developments, humanitarian necessity, or simple goodwill. Outside of automatic delisting on death or an entity's legal dissolution, every delisting decision is made case-by-case by the body that imposed the original sanction β€” at the UN, that means petitioning the Focal Point for Delisting (or, for ISIL/Al-Qaida-linked listings specifically, the Office of the Ombudsperson); the EU General Court hears direct challenges only for autonomous EU sanctions; the UK allows a ministerial review under SAMLA Section 23; and OFAC handles US petitions directly. A real, testable risk: jurisdictions can disagree β€” the EU delisting someone while OFAC keeps them listed creates a genuine legal and operational conflict, not just an administrative inconvenience.

Delisting does not end an institution's compliance obligations β€” this is the exam's most heavily tested angle. The GlobalTrade Corp. case shows the correct response: once a wrongly-sanctioned customer was cleared and delisted, the compliance officer still had to refresh KYC information, reassess (typically lower) the customer's risk rating, document the entire episode, notify internal stakeholders across risk/legal/relationship management, and recalibrate transaction-monitoring thresholds to match the new profile β€” delisting triggers a review, it doesn't close the file. Financial institutions may also choose to apply enhanced due diligence for a defined period after delisting, purely as a precaution against illicit activity resuming post-delisting.

Real Exam Concepts (CGSS Study Guide v2.0, Domain 1, pp.87–93)
  • Delisting is automatic only on death or entity dissolution β€” every other delisting is a case-by-case decision by the relevant sanctions authority.
  • A person delisted by one jurisdiction (e.g., the EU) can remain listed by another (e.g., OFAC) β€” creating real, practical compliance conflicts.
  • Delisting triggers a KYC refresh and risk-rating reassessment; it does not end monitoring or documentation obligations.
Learning Outcomes
  • Explain the reasons delisting can occur and which are automatic vs. case-by-case.
  • Identify the delisting process for the UN, EU, UK, and US.
  • Apply the GlobalTrade Corp. case to a post-delisting KYC scenario.
  • Explain why cross-jurisdictional delisting conflicts occur.
Exam tip: If a question asks what a compliance officer should do immediately after a customer is delisted, the correct answer bundles KYC refresh + risk-rating reassessment + documentation β€” "resume business as normal" is always the wrong answer. (CGSS Study Guide v2.0, Domain 1, p.91)
Practise this topic β†’
CGSS Domain 1 Topic Premium

Consequences of Noncompliance

Sanctions violations generally carry strict liability β€” an individual or organization can be held liable even without knowledge or intent to violate, and even where a genuinely risk-based compliance program was in place. For individuals, consequences range far beyond fines: frozen assets, blocked banking access, travel restrictions, criminal penalties (in the US, up to US$1 million and 20 years' imprisonment for willful violations), and lasting reputational and social damage. The Mikhail Fridman case shows how narrow post-sanctions life becomes even for a billionaire: UK courts limited him to roughly Β£760,000/year in living expenses and specific security costs, rejecting his request for materially more β€” sanctions relief for personal maintenance is licensed narrowly, not restored to pre-sanctions normalcy.

For organizations, strict liability means an entity can be penalized even when a subsidiary acted without the parent's knowledge β€” this is exactly what happened in the Oleg Deripaska/Rusal case, where sanctions on Rusal (tied to Deripaska's ownership) disrupted the entire global aluminum industry before OFAC lifted them once Deripaska's ownership stake dropped below 50%. Successor liability extends this further: an acquiring company inherits the sanctions-violation history of whatever it acquires, including subsidiaries β€” due diligence on a target's own past violations is not optional. Critically, self-reporting and remediation genuinely reduce penalties: OFAC's own enforcement framework weighs voluntary self-disclosure, cooperation, and remedial action (firing responsible staff, strengthening controls) as mitigating factors β€” the Study Guide's own worked scenario treats "take remedial action and self-report" as the textbook-correct response to discovering an accidental violation, not "confirm the vendor is liable instead."

Real Exam Concepts (CGSS Study Guide v2.0, Domain 1, pp.94–101)
  • Strict liability applies regardless of intent or knowledge β€” a compliance program's existence reduces penalties but never eliminates liability outright.
  • Organizations cannot shift sanctions liability to third parties, vendors, or distributors β€” the Study Guide states this explicitly.
  • Successor liability means an acquiring company inherits a target's sanctions-violation history, including that of its subsidiaries.
  • Self-disclosure and remediation are real, weighted mitigating factors in enforcement outcomes, not just goodwill gestures.
Learning Outcomes
  • Explain strict liability and why it applies regardless of intent.
  • Describe the individual consequences of sanctions designation using the Fridman case.
  • Explain successor liability in an acquisition context.
  • Identify the correct response to discovering an unintentional violation (remediate + self-report).
Exam tip: Any scenario ending in "what should the compliance officer do after discovering an unintentional violation" almost always resolves to strengthening controls and self-reporting to the regulator β€” never to shifting blame to a vendor or distributor. (CGSS Study Guide v2.0, Domain 1, p.95)
Practise this topic β†’
CGSS Domain 1 Topic Premium

Types of Sanctions Risk: Operational, Legal, Concentration & Reputational

Four risk types recur across the whole sanctions curriculum. Operational risk is loss from failed internal processes, people, or systems β€” human error causes most of it, but natural disasters, ransomware, and inadequate screening-software updates are named contributors too. Legal risk is the possibility of criminal penalties, lawsuits, or unenforceable contracts causing harm; the Arab Bank Plc. case is the anchor example β€” a US jury found the bank liable in 2014 for knowingly facilitating payments connected to Hamas, brought under the Anti-Terrorism Act by nearly 600 private plaintiffs (not a regulator), and even though the case was later dismissed on a technicality, the bank still lost its US operations and other banking relationships β€” legal risk can materialize as private litigation entirely separate from any regulatory enforcement action.

Concentration risk comes from over-exposure to a single customer, sector, or jurisdiction β€” the Fortum case shows this precisely: the Nordic energy company had over €6 billion concentrated in Russia through one subsidiary, and when Russia seized that subsidiary in 2023, Fortum recorded a €1.7 billion loss β€” roughly 20% of its total equity β€” from a single geographic/sector concentration. Reputational risk is the hardest to quantify but the fastest to materialize: the Clarita National Bank case shows how it compounds β€” a first sanctions-and-AML enforcement action (US$100 million in fines) was followed by a second media leak revealing further undisclosed violations, triggering depositor withdrawals, termination of correspondent banking relationships in three countries, a collapsed acquisition deal, and even the loss of a sports sponsorship β€” reputational damage from a compliance failure regularly extends well beyond the institution's direct banking relationships.

Real Exam Concepts (CGSS Study Guide v2.0, Domain 1, pp.102–115)
  • Legal risk can arise from private lawsuits (Arab Bank), not only from regulatory enforcement β€” the exam tests this distinction.
  • Concentration risk is about over-exposure to any single customer, sector, or jurisdiction β€” Fortum shows a sector/jurisdiction concentration, not just a customer one.
  • Reputational risk compounds: a second disclosed failure (Clarita National Bank) causes disproportionately larger damage than the first.
Learning Outcomes
  • Define operational, legal, concentration, and reputational risk.
  • Apply the Arab Bank Plc. case to a private-litigation legal-risk scenario.
  • Apply the Fortum case to a sector/jurisdiction concentration-risk scenario.
  • Explain how reputational risk compounds using the Clarita National Bank case.
Exam tip: If a question describes a lawsuit brought by private citizens or victims β€” not a regulator β€” that's testing legal risk via private litigation, exactly the Arab Bank Plc. pattern, not a standard enforcement-action scenario. (CGSS Study Guide v2.0, Domain 1, p.110)
Practise this topic β†’
CGSS Β· Domain 2

Building a Sanctions Compliance Program

How to assess sanctions risk, structure a program, run KYC and due diligence, calculate beneficial ownership, and build effective screening.

CGSS Domain 2 Topic Premium

Sanctions Risk Assessment

Every sanctions program starts with a risk appetite statement β€” the level of financial crime risk an organization will accept, set and periodically reviewed by the board, then allocated down to business units as specific risk limits. From there, a risk-based approach rates four categories of inherent risk β€” customer, jurisdiction, product, and channel β€” before any controls are applied. The exam's key formula: inherent risk βˆ’ control effectiveness = residual risk. Controls fall into three types (preventive, like CDD and recordkeeping; detective, like SAR filing; corrective, like exiting a relationship), built on five components β€” control environment, risk assessment, control activities, information/communication, and monitoring.

A high-quality sanctions risk assessment takes a genuinely holistic view β€” clients, products, supply chain, intermediaries, counterparties, transactions, and geography β€” not just the customer relationship in isolation. The Study Guide names concrete good practices (size-appropriate scope, documented methodology, both qualitative and quantitative analysis, consistent methodology across cycles, up-to-date due diligence) against equally concrete common failings (omitting third parties, working from outdated records, poor understanding of requirements). Risk assessments should be refreshed not just on a schedule but whenever the risk environment changes β€” new sanctions, or root causes uncovered by a violation.

Real Exam Concepts (CGSS Study Guide v2.03, Domain 2, pp.6–19)
  • The residual risk equation (inherent risk βˆ’ control effectiveness = residual risk) is a named, testable formula, not just a concept.
  • The four inherent risk categories are customer, jurisdiction, product, and channel β€” always these four, memorized in that order.
  • A genuinely comprehensive risk assessment covers supply chain, intermediaries, and counterparties β€” not just the direct customer relationship.
Learning Outcomes
  • Define risk appetite and explain the board's role in setting it.
  • Identify the four categories of inherent risk.
  • Apply the residual risk equation.
  • List good practices and common failings in sanctions risk assessments.
Exam tip: If a question gives you inherent risk and control effectiveness values, or asks what's left after controls are applied, that's testing the residual risk equation directly. (CGSS Study Guide v2.03, Domain 2, p.15)
Practise this topic β†’
CGSS Domain 2 Topic Premium

Sanctions Risk by Sector and Business Line

Risk profiles differ meaningfully by business line. Retail banking is exposed through its sheer diversity of products and customers β€” cross-border transfers and virtual currency use are named vulnerabilities, and red flags include inconsistencies between a customer's stated purpose and their actual jurisdictional footprint. Commercial and investment banking risk centers on complex ownership structures and intermediaries (special purpose vehicles in particular) that obscure who actually controls a counterparty β€” debt/equity financing restrictions (e.g., US sanctions barring certain Russian or Venezuelan entities from raising new capital) are a specifically named concern here.

Wealth management and private banking carries elevated risk because professional intermediaries β€” accountants, lawyers, art dealers β€” can be exploited to move assets discreetly through nontransparent structures; named red flags include shell companies used for wire transfers, sudden unexplained account growth, and attempted transactions with SWIFT-excluded institutions. Correspondent banking is structurally exposed because the correspondent bank cannot directly perform due diligence on the respondent's own customers β€” it must rely entirely on the respondent's own controls, a genuine, structural blind spot rather than a mere administrative gap.

Real Exam Concepts (CGSS Study Guide v2.03, Domain 2, pp.16–23)
  • Correspondent banking risk stems from a structural inability to directly vet the respondent's own customers β€” not from any specific transaction type.
  • Wealth management's professional-intermediary risk (lawyers, accountants, art dealers) is a distinctly named vulnerability, separate from the customer relationship itself.
  • Investment banking's debt/equity financing restrictions are sanctions-specific β€” separate from a general "high net worth = high risk" assumption.
Learning Outcomes
  • Identify the specific sanctions vulnerability of each major banking business line.
  • Explain why correspondent banking carries structural sanctions risk.
  • List wealth management's professional-intermediary red flags.
  • Apply sector-specific risk factors to a business-line scenario.
Exam tip: If a scenario centers on a bank being unable to directly verify a foreign bank's own customers, that's correspondent banking risk specifically β€” a structural feature of the relationship, not a control failure. (CGSS Study Guide v2.03, Domain 2, p.23)
Practise this topic β†’
CGSS Domain 2 Topic Premium

Sanctions Compliance Program Framework & Three Lines of Defense

A robust sanctions compliance program (SCP) rests on the same three lines of defense model used across AFC generally. The first line (front-line/business) implements policies and performs day-to-day CDD. The second line (AFC compliance, led by the sanctions compliance officer) sets policy, monitors, and must stay independent from business incentives β€” specifically barred from being compensated on a share of business profits, to avoid a conflict of interest. The third line (internal audit) independently tests whether the first two lines' controls actually work, reporting directly to the board's audit committee. The Fraser Corporation case shows what happens when this is skipped: a mid-sized tech company unknowingly dealt with a sanctioned supplier, triggering public backlash and regulatory scrutiny β€” its remediation was a full enterprise-wide risk assessment across all four inherent risk categories (customer, jurisdiction, product, channel), followed by properly resourcing the SCP itself.

The sanctions compliance officer (SCO) role is defined precisely: they must have a reputation for integrity, deep technical knowledge of global sanctions regimes, and β€” critically β€” sufficient time and authority to act independently. Their responsibilities span establishing the risk-assessment framework, keeping AFC policies current with regulatory change, monitoring control effectiveness, serving as the regulator/FIU contact point, and ensuring regular staff training. A single person can hold the SCO role alongside other senior AFC compliance titles β€” the exam doesn't require a dedicated headcount, but does require the independence and authority regardless of title.

Real Exam Concepts (CGSS Study Guide v2.03, Domain 2, pp.24–32)
  • Second-line staff must not be incentivized by a share of business profits β€” a specifically named conflict-of-interest rule, not a general "avoid bias" statement.
  • The Fraser Corporation case shows all four inherent risk categories need addressing together, not just the one that caused the incident.
  • An SCO needs independence and authority, not necessarily a standalone title β€” combining roles is acceptable as long as those two conditions hold.
Learning Outcomes
  • Describe the three lines of defense and each line's distinct role.
  • Explain the second line's independence requirement.
  • Apply the Fraser Corporation case to an SCP-remediation scenario.
  • List the SCO's core responsibilities.
Exam tip: If a question describes a compliance officer being compensated based on their business unit's revenue, that's a direct violation of second-line independence β€” regardless of how well they otherwise perform. (CGSS Study Guide v2.03, Domain 2, p.30)
Practise this topic β†’
CGSS Domain 2 Topic Premium

Sanctions Due Diligence & KYC Across the Customer Lifecycle

KYC operates across the full customer lifecycle β€” onboarding, ongoing monitoring, and offboarding β€” and is genuinely distinct from transaction monitoring (detective, reviewing activity after it happens) versus screening (preventive, checking names/payments/adverse media/PEP status both before onboarding and continuously afterward). The real Etoile Finance Groupe / Banque Etoile SA OFAC case shows what happens when the underlying data itself fails: a Lebanese branch processed US$15.6 million for entities 50%+ owned by SDN-listed terrorists, not because the screening software was faulty, but because beneficial-ownership records existed only on paper β€” never digitized, so they were structurally invisible to automated screening. The fix wasn't a new vendor or retraining alone; it was digitizing the underlying KYC records so ownership data could actually reach the screening system.

The InsureCo Limited case reinforces a separate lesson: its EU subsidiary, InsureCo Europe, issued Cuba travel insurance that violated no EU sanctions β€” but as a foreign subsidiary of a US parent, its US nexus made this a US sanctions violation regardless. Effective KYC research follows a four-step model β€” Assess (what you know and don't), Explore (fill the gaps), Organize (structure what matters), Present (document for every audience: regulators, law enforcement, internal monitoring staff, auditors) β€” and the steps loop, since organizing often reveals you need to explore further. Two hard boundaries apply throughout: never "tip off" a customer that they're under investigation (a criminal offense in many jurisdictions, though confirming public information like sanctions-list status is not tipping off), and data privacy laws like GDPR impose strict retention, consent, and cross-border transfer rules on everything collected.

Real Exam Concepts (CGSS Study Guide v2.03, Domain 2, pp.29–46)
  • Transaction monitoring is detective (after the fact); screening is preventive (before and ongoing) β€” the exam tests this distinction directly.
  • Banque Etoile SA's violation traced to undigitized paper KYC records, not screening software quality β€” the fix was data digitization, not a vendor change.
  • US sanctions can bind a foreign subsidiary purely through US parent ownership, even where the transaction violates no local (e.g., EU) sanctions β€” InsureCo Europe's Cuba insurance case.
  • Confirming a customer's presence on a public sanctions list is not tipping off; disclosing a SAR's existence or contents always is.
Learning Outcomes
  • Distinguish transaction monitoring from screening.
  • Apply the Banque Etoile SA case to a beneficial-ownership-data scenario.
  • Apply the InsureCo case to a foreign-subsidiary sanctions exposure scenario.
  • Describe the four-step KYC research model and the tipping-off boundary.
Exam tip: If a scenario's root cause is that beneficial ownership data existed but wasn't in a format the screening system could use, that's the Banque Etoile SA pattern β€” the fix is data digitization, not new software or more training. (CGSS Study Guide v2.03, Domain 2, p.34)
Practise this topic β†’
CGSS Domain 2 Topic Premium

Customer Identification & Enhanced Due Diligence

Three levels of due diligence apply by risk: simplified (SDD) for genuinely low-risk customers, standard (CDD) for most customers, and enhanced (EDD) for high-risk ones β€” requiring deeper source-of-wealth/funds verification and PEP-connection assessment. Basic identification differs by customer type: a natural person needs name, address, date of birth, and a tax/national ID number; a legal person needs company name, address, place of incorporation, and a government-issued ID number. The Alisher Uspanov case is the exam's anchor for name-matching judgment: a near-miss against OFAC's SDN entry for "Alisher Usmanov" (different spelling, different birth year, different address) was correctly investigated, correctly ruled a non-match β€” but the bank still declined the account for an unrelated reason (Uzbekistan being a high-risk jurisdiction) and still reported its findings to OFAC even after concluding there was no true match.

The Borrower X case shows EDD escalation done right: open-source intelligence suggested a loan applicant was a special-purpose vehicle for an OFAC-listed Indonesian oil firm β€” evidence the bank couldn't fully confirm, so it triggered EDD (verifying incorporation documents, cross-checking business location against the suspected parent) rather than either dismissing the tip or rejecting outright on unconfirmed suspicion; only after EDD confirmed high sanctions exposure was the customer rejected. The MarcoPolo Ltd. case extends this to ongoing monitoring: a trade-finance client was correctly EDD-rated at onboarding (30%-sanctioned major shareholder), passed initial checks β€” but four months later, a new counterparty with no offices, one employee, and a Russian national with a defense-industry background triggered a SAR filing and a full onboarding review. EDD isn't a one-time gate; it's triggered again whenever new counterparties or new information appear.

Real Exam Concepts (CGSS Study Guide v2.03, Domain 2, pp.43–56)
  • A near-match investigated and correctly ruled a non-match can still lead to declining the customer for an unrelated risk reason, and still gets reported to OFAC β€” Uspanov shows both outcomes coexisting.
  • Unconfirmed open-source suspicion should trigger EDD, not immediate rejection or dismissal β€” Borrower X shows the correct middle path.
  • EDD applies to new counterparties discovered mid-relationship, not just at onboarding β€” MarcoPolo's new Malta buyer triggered a fresh EDD cycle.
Learning Outcomes
  • Distinguish SDD, CDD, and EDD and when each applies.
  • List the basic identification requirements for natural vs. legal persons.
  • Apply the Uspanov case to a near-match name-screening scenario.
  • Apply the Borrower X and MarcoPolo cases to EDD-escalation scenarios.
Exam tip: If a scenario shows a near-match that's investigated and ruled a genuine non-match, don't assume the story ends there β€” the exam often still expects reporting to the regulator and considering unrelated risk factors, exactly as in the Uspanov case. (CGSS Study Guide v2.03, Domain 2, p.49)
Practise this topic β†’
CGSS Domain 2 Topic Premium

Beneficial Ownership: Identification & Risk

A beneficial owner is whoever has ultimate control over an account's funds β€” through ownership or other means β€” and most jurisdictions require identifying anyone owning 25%+ of a legal entity (as low as 10% for high-risk customers), per FATF Recommendations 24 and 25. Critically, an ultimate beneficial owner (UBO) is always a natural person, never another legal entity β€” regulators require tracing through however many corporate layers exist until you reach an actual human being, precisely because legal entities can be formed, restructured, and dissolved quickly while a human behind them cannot simply disappear. Where no UBO can genuinely be identified through ownership or control, most jurisdictions require recording a senior managing official instead β€” but an inability to identify any UBO at all is itself a red flag worth investigating on its own.

Legal arrangements like trusts are a named, higher-risk structure precisely because settlor, trustee, and beneficiary can legally be the same person in some jurisdictions β€” letting someone conceal their own beneficial ownership behind an apparently independent structure. The real Oligarch case shows this exploited deliberately: a sanctioned Russian oligarch, anticipating designation, had a professional service provider shift beneficiary status on his trust from himself to his own children β€” while the underlying holding structure (11 offshore companies, interest-free loans with no repayment obligation) had no legitimate business purpose beyond moving assets out of reach of seizure. Shell and shelf companies carry similar risk β€” the Hidden Ltd. case shows a Panama company opened one month after Russia's invasion, funded by a US$10 million "loan" from another opaque entity, ultimately traced (via a yacht's public ownership history) back to a sanctioned Russian oligarch using a young front-man as the declared owner.

Real Exam Concepts (CGSS Study Guide v2.03, Domain 2, pp.53–69)
  • UBOs are always natural persons β€” a legal entity can never itself be recorded as the final UBO.
  • A trust where settlor, trustee, and beneficiary can legally be the same person is a named structural risk, not an edge case.
  • The Oligarch case's beneficiary change (self β†’ children) timed right before anticipated sanctions is itself the red flag β€” the structure's complexity alone isn't proof, but the timing is.
  • An inability to identify any UBO at all is itself grounds for suspicion, not just an administrative gap to route around.
Learning Outcomes
  • Define beneficial owner vs. UBO and explain why a UBO must be a natural person.
  • Explain trust structures' beneficial-ownership risk (settlor/trustee/beneficiary overlap).
  • Apply the Oligarch case to a pre-emptive beneficiary-change scenario.
  • Apply the Hidden Ltd. case to a newly-formed shell company red-flag scenario.
Exam tip: If a scenario shows a beneficiary change timed just before an individual's expected sanctions designation, that's testing recognition of pre-emptive ownership restructuring β€” the Oligarch case's exact pattern. (CGSS Study Guide v2.03, Domain 2, p.64)
Practise this topic β†’
CGSS Domain 2 Topic Premium

Calculating Beneficial Ownership: The 50% Rules

Ownership has two distinct prongs: the ownership prong (formal, percentage-based) and the control prong (who actually directs the entity β€” directors, officers, or anyone exercising dominant influence) β€” and these can be different people entirely. For AML purposes, indirect ownership is calculated by multiplying stakes down each ownership chain (person owns 40% of a company that owns 30% of the target = 12% indirect stake) against a standard 25% threshold. For sanctions purposes, the math is different and stricter: each level of ownership is assessed separately, not multiplied β€” meaning a sanctioned person's company at any level in the chain can taint the entity below it even if their diluted indirect percentage would fall well under any AML threshold.

The OFAC 50% Rule considers only ownership (not control): if a sanctions target owns 50%+ of an entity, directly or in aggregate with other sanctioned owners, that entity is automatically sanctioned even without being individually listed β€” the Lion Corporation example shows two SDNs owning 39% and 16% respectively (55% combined) sanctioning the whole company, even though the non-sanctioned majority shareholder holds the remaining 45%. The EU and UK 50% rules differ in two ways: they consider both ownership and control, and their aggregate-ownership rule (EU: 50%+ combined; UK: more than 50%) now applies across all EU sanctions programs since mid-2024, not just the original Russia-specific regulation. The Turkish company case shows this timing distinction mattering in practice: identical ownership by two sanctioned nationals triggered an immediate US freeze (aggregate rule always applied under OFAC) but would only have triggered an EU freeze after the mid-2024 rule expansion. The Mr. Anderson case shows the ownership-vs-control distinction directly: a trust where he's merely the settlor escaped US sanctions (OFAC: ownership only) but was sanctioned under EU/UK rules (control: settlor + family connection to the protector/beneficiary counts as de facto control).

Real Exam Concepts (CGSS Study Guide v2.03, Domain 2, pp.66–82)
  • AML beneficial ownership calculation multiplies stakes down a chain; sanctions calculation assesses each level separately β€” using the wrong method produces the wrong answer.
  • OFAC's 50% rule considers ownership only; EU and UK rules consider both ownership and control β€” the same fact pattern can sanction an entity under one regime and clear it under another.
  • The EU aggregate-ownership rule only expanded beyond Russia-specific sanctions in mid-2024 β€” a timing detail the Turkish company case tests directly.
  • Settlor status alone doesn't trigger OFAC sanctions (no direct ownership) but can trigger EU/UK sanctions via de facto control β€” Mr. Anderson's exact fact pattern.
Learning Outcomes
  • Distinguish the ownership prong from the control prong.
  • Apply the correct calculation method (multiply for AML, separate-level for sanctions).
  • Apply the OFAC 50% rule (Lion Corporation) and the EU/UK 50%+ rule with aggregate ownership.
  • Apply the Mr. Anderson case to a settlor/control scenario across US vs. EU/UK jurisdictions.
Exam tip: Any question giving specific ownership percentages across multiple sanctioned parties is testing whether you add up the aggregate correctly against the 50% threshold β€” and whether you know OFAC ignores control while the EU/UK do not. (CGSS Study Guide v2.03, Domain 2, p.74)
Practise this topic β†’
CGSS Domain 2 Topic Premium

Sanctions Screening Policy, Lists & False Positives

Screening β€” checking names, payments, and adverse media against official lists β€” runs at three points: onboarding, ongoing (batch), and at time of payment. Lists split into mandatory (UN, EU, US, host-country β€” binding, must be screened) and supplementary (negative news, evasion-pattern lists β€” a discretionary risk-reduction extra). Trade-specific lists live separately with the US Bureau of Industry and Security: the Entity List imposes extra licensing requirements, the Denied Persons List bans exporting to a party entirely, and the Consolidated Screening List combines multiple export-control lists for one-stop screening β€” a genuinely important distinction, since the Entity List and DPL trigger different consequences for the same-looking alert.

Fuzzy logic lets a screening system catch misspellings, transliteration differences, and phonetic variants (e.g., "Katherine Navel" vs. "Catherine Naval") that an exact-match system would miss β€” but every fuzzy match is inherently a partial match requiring human judgment to resolve. A genuine false positive is when a filter (human or system) raises an alert that turns out to be nothing β€” common, unavoidable "noise" that must still be understood and documented before being cleared, never dismissed reflexively. The Study Guide's own worked scenario (the unnamed yacht "Serena") shows the correct escalation instinct: an ambiguous payment tied to a possibly-sanctioned yacht owner should trigger a request for information from the remitting bank first β€” not an immediate breach report (premature without confirmation) and not direct contact with a non-customer third party (inappropriate outreach).

Real Exam Concepts (CGSS Study Guide v2.03, Domain 2, pp.79–99)
  • Mandatory lists must be screened; supplementary lists are a discretionary risk-reduction choice β€” confusing the two misstates a compliance obligation.
  • BIS's Entity List (licensing requirement) and Denied Persons List (total export ban) are different consequences for what can look like a similar alert.
  • A fuzzy-logic partial match is not itself proof of anything β€” it's a trigger for human investigation, nothing more.
  • The correct first response to an ambiguous sanctions-adjacent alert is gathering more information (RFI) β€” not reporting a breach prematurely or contacting an uninvolved third party.
Learning Outcomes
  • Distinguish mandatory from supplementary sanctions lists.
  • Identify the BIS Entity List, Denied Persons List, and Consolidated Screening List and their distinct effects.
  • Explain fuzzy logic and partial matching.
  • Apply the "Serena" case to an ambiguous-alert escalation scenario.
Exam tip: If a question asks for the first step after an ambiguous alert involving an unnamed asset or unclear party, the correct answer is almost always "request more information" β€” not report, and not direct outreach to a non-customer. (CGSS Study Guide v2.03, Domain 2, p.84)
Practise this topic β†’
CGSS Domain 2 Topic Premium

Screening Process: Payments, SWIFT & Trade Activity

Screening produces four possible outcomes: target match (stop the transaction, review all related activity), escalate (needs more research), false positive (clear and document), and false negative (usually human input error β€” a genuinely dangerous outcome since it means a real match was missed). Payment screening happens ex-ante β€” before the transaction completes β€” as opposed to transaction monitoring's ex-post review; SWIFT is the dominant messaging network, and the shift to the ISO 20022 standard matters because its richer, more structured data fields materially improve screening accuracy compared to the older ISO 15022 format.

Trade activity screening extends beyond the buyer and seller to the vessel itself (name, registration, ownership, recent voyage history), the shipping company, routes, ports of call, and supporting documents (letters of credit, bills of lading, certificates of origin). The Study Guide's own "Unusual Transactions" case shows the red-flag pattern precisely: a company with a stable US$1 million letter-of-credit pattern suddenly shifted to multiple smaller purchases (~30% of normal size) from new sellers near high-risk jurisdictions, several paid in cash advance β€” a combination of behavior-pattern deviation, unusual seller geography, and payment-method shift, none alone conclusive but together a clear trigger for enhanced due diligence. Separately, dual-use goods (civilian/military applications β€” lasers, sensors, certain chemicals) are governed by control regimes like the Wassenaar Arrangement and the Missile Technology Control Regime; evasion tactics include fictitious end-users, re-export through a third jurisdiction, and vague cargo descriptions like "spare parts" to avoid extra scrutiny.

Real Exam Concepts (CGSS Study Guide v2.03, Domain 2, pp.96–107)
  • Payment screening is ex-ante (before completion); transaction monitoring is ex-post β€” the exam tests this timing distinction directly, distinct from the earlier screening-vs-monitoring concept card.
  • ISO 20022's richer data structure is a named, testable improvement over ISO 15022 for screening accuracy.
  • The "Unusual Transactions" case's red flag is the combination of pattern deviation + unusual geography + payment-method shift β€” no single element alone is conclusive.
  • Vague cargo descriptions like "spare parts" are a specifically named dual-use-goods evasion tactic.
Learning Outcomes
  • List the four sanctions screening outcomes and the correct response to each.
  • Explain ex-ante payment screening vs. ex-post transaction monitoring.
  • Apply the "Unusual Transactions" case to a trade-pattern-deviation scenario.
  • Identify dual-use goods evasion tactics.
Exam tip: If a trade scenario shows a sudden shift to smaller, more frequent transactions from new counterparties near high-risk jurisdictions, that's testing the "Unusual Transactions" red-flag pattern β€” the combination matters more than any single fact. (CGSS Study Guide v2.03, Domain 2, p.105)
Practise this topic β†’
CGSS Domain 2 Topic Premium

Sanctions Screening Technology & Analytics

Automated screening tools (ASTs) use weighted algorithms β€” down-weighting "noisy" words like "of" and "the," giving surnames more weight than forenames, and applying fuzzy logic for spelling variants β€” to generate ranked potential matches. Calibration matters enormously: the Study Guide's own worked scenario shows a vendor's software update silently resetting the name-match threshold from 90% to 70% and switching country-matching from "customer's jurisdiction only" to "global," tripling alert volume overnight with mostly-unrelated hits. The correct response was neither to keep working through the backlog unquestioned, nor to rush-clear the extra alerts, nor to escalate straight to senior management β€” it was to review the threshold change directly with the vendor and immediate supervisor, since an unexplained volume spike signals a system malfunction, not increased risk.

Beyond matching, modern AFC technology adds real capability: AI/machine learning reduces false positives versus purely rule-based systems by learning patterns rather than following fixed rules, though this comes at some cost to explainability. Robotic process automation (RPA) frees compliance staff from repetitive tasks for higher-risk analysis β€” but the Study Guide is explicit that GDPR prohibits fully automated decisions determining an individual's fate, meaning RPA can support a customer accept/reject decision but cannot make it alone. Network analysis maps shared identifiers (addresses, phone numbers, device IDs, IP addresses) across a customer base to reveal hidden connections β€” multiple customers sharing one address can indicate an organized group; multiple accounts funneling into one account can indicate a money-mule network. Proper data mapping (which payment-message field maps to which screening check) and ETL governance (extract, transform, load) are what keep all of this technology accurate β€” misconfigured field mapping, like screening a bank-identifier-code field against an entire sanctions list instead of just sanctioned BIC codes, is a named cause of excess false positives.

Real Exam Concepts (CGSS Study Guide v2.03, Domain 2, pp.104–125)
  • A sudden, unexplained spike in screening alert volume should trigger a threshold/configuration review with the vendor and supervisor β€” not continued normal processing, rushed clearing, or premature escalation to senior management.
  • GDPR bars fully automated accept/reject decisions about individuals β€” RPA and AI can inform the decision but a human must make it.
  • Field-mapping errors (e.g., screening a BIC field against the whole sanctions list instead of just sanctioned BICs) are a specifically named cause of excess false positives.
  • Network analysis links accounts via shared identifiers (address, phone, device ID) β€” a named tool for uncovering hidden connections between seemingly unrelated customers.
Learning Outcomes
  • Apply the AST-threshold case to an unexplained alert-volume-spike scenario.
  • Explain GDPR's limit on fully automated compliance decisions.
  • Describe network analysis and its use in uncovering hidden account connections.
  • Identify field-mapping and ETL governance as sources of screening accuracy or error.
Exam tip: If a screening officer suddenly sees a large, unexplained jump in alert volume, the correct first move is always to investigate the system configuration with the vendor and supervisor β€” never to assume risk has genuinely increased. (CGSS Study Guide v2.03, Domain 2, p.109)
Practise this topic β†’
CGSS Β· Domain 3

Detecting and Investigating Sanctions Evasion Techniques

How evasion actually happens β€” ownership, trade, maritime, and payments β€” and how to investigate, freeze assets, and manage the aftermath.

CGSS Domain 3 Topic Premium

Ownership Concealment: Names, Restructuring & Proxies

Detection ultimately depends on the customer relationship β€” knowing who a customer really is, and knowing your own employees too. Know Your Employee (KYE) matters because evasion can be internal (an employee overriding controls or whitelisting a blocked party) as well as external; the "four eyes" dual-control principle (two people independently verifying key actions) is the named defense. The real EuroCapital Alliance Bank (ECAB) OFAC case shows detection failing despite the data already existing: ECAB had KYC records clearly showing sanctioned-jurisdiction addresses, but its automated screening simply never flagged them β€” compliance only found the accounts during a routine periodic review, after ~300 transactions worth US$3 million had already processed. ECAB also missed that its biggest client's sanctioned oligarch owner divested 45% of his 75% stake to his wife on the very day of his designation β€” a still-controlling transfer, not a genuine exit.

Three distinct concealment vehicles matter: a shell company exists mostly on paper with no real operations; a front company has genuine physical operations (a car wash, a restaurant) that shield illicit activity behind a legitimate-looking business; a proxy is a person β€” often a relative, associate, or nominee director β€” standing in for the real owner. Financial criminals also conceal ownership through name variation (spelling changes, reordered names, generic institutional names like "Foreign Trade Bank" that don't obviously signal DPRK ties) and ownership restructuring β€” either sham divestments to associates who let the original owner keep real control, or deliberate dilution below the 50% aggregate-ownership threshold. The real SOGAZ case shows the latter precisely: after Bank Rossiya was sanctioned in 2014, it reduced its indirect stake in SOGAZ from 51% to 48.5% just before the sanction took effect β€” and reduced it further to 32.3% specifically after OFAC introduced the aggregate-ownership rule, keeping combined sanctioned ownership at 44.8%, just under the 50% threshold.

Real Exam Concepts (CGSS Study Guide v2.02, Domain 3, pp.6–17)
  • ECAB's failure wasn't missing data β€” the KYC information existed; the automated screening system simply never used it. A periodic manual review caught what automation missed.
  • Shell (no operations), front (real operations, shields something else), and proxy (a substitute person) are three distinct concealment vehicles, not interchangeable terms.
  • SOGAZ shows ownership restructuring timed precisely against regulatory thresholds β€” divesting just enough, just before a rule takes effect or right after a new rule is announced.
Learning Outcomes
  • Explain KYE and the four-eyes principle.
  • Apply the EuroCapital Alliance Bank case to a KYC-data-not-used scenario.
  • Distinguish shell companies, front companies, and proxies.
  • Apply the SOGAZ case to a threshold-driven ownership restructuring scenario.
Exam tip: If a scenario shows an ownership stake reduced to just below 50% right around a sanctions designation or rule change, that's testing recognition of deliberate threshold evasion β€” the SOGAZ pattern, not a coincidence. (CGSS Study Guide v2.02, Domain 3, p.16)
Practise this topic β†’
CGSS Domain 3 Topic Premium

Trade-Based Evasion: Concealment, Dual-Use Goods & Transshipment

Trade-based evasion typically works by concealing an end-user's true identity β€” falsifying buyer/seller names, routing through an intermediary jurisdiction for re-export, or falsifying an end-user certificate for controlled goods. Dual-use goods (civilian and military application) are frequently repackaged inside unregulated items β€” the Study Guide's own example is a missile-guidance sensor hidden inside a coffee maker β€” precisely because smaller, less-recognizable components are easiest to disguise this way. Transshipment (routing goods through an intermediate stop before final delivery) is often legitimate, but becomes evasion when used to switch cargo, obscure the true routing, or move goods through weakly-regulated jurisdictions. The real ACE/Iran case shows the full pattern: a Turkish "straw buyer" company with no trade history bought dual-use pressure transducers from a US manufacturer, claimed a Middle East freight-forwarder as the destination, then relabeled the shipment as "consumer electronics" for onward air/sea transit to Iran β€” layering a straw buyer, transshipment, and document falsification together.

The real Mutassim Gaddafi case (Bank of Valletta, Malta) shows front/shell company misuse at scale: the sanctioned son of Libya's former dictator used an alias and shell companies set up by a complicit local auditor to accumulate at least €60 million, ultimately spent on hotels, travel, and shopping β€” a court ultimately ordered ~€90 million returned to Libya. The MaxStar case shows how document inconsistencies reveal evasion even without a smoking-gun confession: a UAE trading company's sudden luxury-goods deal with a Kazakhstan buyer showed a 30%-below-market unit price, triple the normal shipping cost, a Russian carrier, and a Kazakhstan delivery address paired with a Russian-registered receiving party β€” none alone conclusive, but together enough to trigger investigation that confirmed MaxStar was a front for a Russian reseller.

Real Exam Concepts (CGSS Study Guide v2.02, Domain 3, pp.14–26)
  • A "straw buyer" with no trade history and unusual shipping instructions is a specifically named red flag pattern (the ACE/Iran case), not just generic suspicion.
  • Dual-use goods repackaging risk is highest for small, uncommon components β€” easier to disguise inside an unrelated everyday product.
  • The MaxStar case's red flags (price, shipping cost, carrier nationality, address/registrant mismatch) work together as a pattern β€” no single detail alone proves evasion.
Learning Outcomes
  • Explain end-user concealment and dual-use goods repackaging.
  • Define transshipment and distinguish legitimate use from evasion.
  • Apply the ACE/Iran case to a straw-buyer scenario.
  • Apply the MaxStar case to a trade-document-inconsistency scenario.
Exam tip: A new counterparty with no trade history, unusual shipping instructions to a freight-forwarder rather than the buyer's own address, is the exact ACE/Iran straw-buyer pattern β€” a strong exam signal for trade-based evasion. (CGSS Study Guide v2.02, Domain 3, p.21)
Practise this topic β†’
CGSS Domain 3 Topic Premium

Maritime Evasion & the Russian Oil Price Cap

Vessels are required to broadcast their location via AIS (Automatic Identification System) transponders. Two distinct evasion techniques exploit this: loitering (turning off the AIS entirely to hide in a high-risk area) and spoofing (continuing to transmit AIS data while manipulating it β€” altering the reported jurisdiction, route, or vessel identity, sometimes projecting a decoy vessel's location). Not every AIS gap is illicit β€” poor signal coverage or genuine security concerns near piracy zones are legitimate reasons β€” but red flags include scattered tracking lines, proximity to high-risk jurisdictions when the signal drops, and two vessels broadcasting the same AIS number. The real Jacoby Carrier case shows this precisely: a Mauritius-flagged vessel's AIS went dark for 36 hours near Japan, then reactivated broadcasting a different registration (Singapore instead of Mauritius) β€” satellite imagery later showed 10-15 unaccounted-for containers added mid-voyage from unmarked vessels, confirming a cargo swap with North Korea-linked ships.

The Russian oil price cap β€” a joint G-7/EU/Australia policy limiting the sale price of Russian crude β€” shows how sanctions evasion adapts to price-based (not just party-based) restrictions. OFAC's advisory flagged vague, unbroken-down pricing information on trade documents as a key red flag, since circumvention typically works by inflating intermediate costs (shipping, freight, insurance) that sit outside the capped price, or by falsely certifying Russian-origin oil as coming from elsewhere. A safe harbor β€” legal protection from liability β€” is available to service providers who apply genuine risk-based due diligence, including real scrutiny of a customer's self-attestations rather than accepting them automatically.

Real Exam Concepts (CGSS Study Guide v2.02, Domain 3, pp.23–30)
  • Loitering (AIS off) and spoofing (AIS on but manipulated) are two distinct techniques, not the same thing.
  • Not all AIS gaps are illicit β€” genuine piracy-avoidance or signal-coverage gaps exist β€” but a gap paired with reactivation showing a changed registration, as in Jacoby Carrier, is a strong red flag.
  • Oil price cap evasion typically inflates non-capped intermediate costs (shipping, insurance) rather than directly falsifying the oil's sale price itself.
Learning Outcomes
  • Distinguish loitering from spoofing.
  • Apply the Jacoby Carrier case to an AIS-gap investigation scenario.
  • Explain the Russian oil price cap policy and its evasion methods.
  • Explain the safe harbor concept for price cap compliance.
Exam tip: If a scenario shows a vessel's AIS reactivating with a different flag/registration than before it went dark, that's spoofing specifically β€” the Jacoby Carrier pattern β€” not simple loitering. (CGSS Study Guide v2.02, Domain 3, p.28)
Practise this topic β†’
CGSS Domain 3 Topic Premium

Payment Evasion: Stripping & U-Turn Payments

Stripping is the intentional removal or alteration of identifying information from a payment message specifically to defeat automated sanctions screening β€” motivations range from profit and business-relationship preservation to bribery or even political sympathy with a sanctioned party. It splits into internal stripping (an employee alters the message) and external stripping (a customer or third party does) β€” though the Study Guide notes that reported violations are rarely purely external, since an insider is almost always needed somewhere in the chain. The real Kenya correspondent bank case shows collusion in action: a Sudanese bank routed a payment through a bribed Kenyan correspondent, which replaced the Sudanese bank's own identifying details with those of a "respectable" Kenyan institution before forwarding to a US correspondent β€” the scheme was only caught when the beneficiary bank's own due diligence cross-checked the payment against the customer's supporting documents and found the discrepancy.

U-turn payments route a US-dollar transaction that both originates and ends outside the US through the US financial system via offshore banks β€” legal under a limited pre-2008 OFAC exemption for Iran-related transactions, revoked in 2008, but still exploited afterward by banks that stripped identifying terms to keep the payments flowing undetected. The real SociΓ©tΓ© GΓ©nΓ©rale case is the largest documented example: from 2003-2013, SG's Paris operations split payment instructions into two separate SWIFT messages β€” a full-detail MT103 sent directly to the sanctioned beneficiary's bank, and a stripped MT202 (with Iranian/Sudanese identifying details removed) sent to its own US branch β€” a deliberate architecture to keep the US branch technically "blind" to what it was really processing. The New York DFS fined SG US$325 million, tracing the root cause to no centralized sanctions function and policies that barely addressed US sanctions at all.

Real Exam Concepts (CGSS Study Guide v2.02, Domain 3, pp.27–39)
  • Reported stripping violations are rarely purely external β€” an insider is almost always involved somewhere, even in schemes initiated by an outside party.
  • The Kenya case's detection came from the beneficiary bank's own independent due diligence catching a discrepancy β€” not from the correspondent chain's screening, which the stripping successfully defeated.
  • SociΓ©tΓ© GΓ©nΓ©rale's two-message architecture (full MT103 to the beneficiary, stripped MT202 to its own US branch) was a deliberate structural choice, not a processing error β€” the exam tests recognizing this as intentional design.
Learning Outcomes
  • Define stripping and distinguish internal from external stripping.
  • Apply the Kenya correspondent bank case to a collusive-stripping scenario.
  • Explain U-turn payments and why the 2008 exemption revocation mattered.
  • Apply the SociΓ©tΓ© GΓ©nΓ©rale case to a split-message evasion scenario.
Exam tip: If a scenario shows two different SWIFT messages for the same payment, one detailed and one stripped, sent to different recipients, that's the SociΓ©tΓ© GΓ©nΓ©rale pattern β€” deliberate message separation, not a technical glitch. (CGSS Study Guide v2.02, Domain 3, p.38)
Practise this topic β†’
CGSS Domain 3 Topic Premium

Payment Evasion: SWIFT Manipulation, Nested Accounts & Crypto Risk

SWIFT messages come in specific formats: MT103 (single-customer credit transfer, with named fields for originator and beneficiary), MT202 (bank-to-bank transfer, historically vulnerable since its limited fields let key identifying information be omitted), and MT202 COV (introduced specifically to close that gap β€” its "sequence B" field must match the underlying MT103's originator/beneficiary data exactly). Message separation β€” sending an MT103 direct to the beneficiary while sending a stripped MT202 to an intermediary β€” was a real evasion technique before MT202 COV made it far harder; the shift to the richer ISO 20022/MX format aims to close remaining gaps further.

Nested accounts occur when a correspondent bank unknowingly serves a respondent's own customers β€” "a customer's customer" β€” losing visibility into who's really transacting. The real Halkbank case (Turkey's second-largest state bank) shows nested accounts used at massive scale: senior executives ran ~US$20 billion through nested accounts held in the names of Iranian state entities, disguised as food/medicine purchases to exploit OFAC's humanitarian exception β€” while senior management knew the transactions weren't actually humanitarian. Downstream services compound this risk further: a correspondent's own respondent can itself act as a correspondent for other banks, multiplying the upstream bank's exposure to parties it never directly vetted. On cryptoasset risk, the real BitCab case (a US-based Iran-linked payments platform) shows crypto's supposed anonymity failing in practice β€” US investigators traced the platform's operator through a linked US bank account, a VASP account funded with fiat currency, and an IP address, ultimately tracing over US$10 million moved to Iran despite the platform's own marketing claims of untraceability.

Real Exam Concepts (CGSS Study Guide v2.02, Domain 3, pp.36–51)
  • MT202 COV's "sequence B" field must match the underlying MT103 exactly β€” that requirement is specifically what closed the old message-separation loophole.
  • Halkbank's nested-account scheme was disguised as humanitarian trade specifically to exploit OFAC's own exception β€” a deliberate exploitation of a carve-out, not a gap in the rule itself.
  • BitCab shows cryptocurrency is genuinely traceable in practice β€” perceived anonymity failed against actual investigative techniques (linked bank accounts, IP addresses, KYC at VASPs).
Learning Outcomes
  • Distinguish MT103, MT202, and MT202 COV and explain why COV closed a real gap.
  • Explain nested accounts and downstream services risk.
  • Apply the Halkbank case to a humanitarian-exception-exploitation scenario.
  • Apply the BitCab case to a cryptoasset-traceability scenario.
Exam tip: If a scenario shows transactions falsely labeled as humanitarian (food, medicine) to exploit a sanctions carve-out, that's the Halkbank pattern β€” verify the underlying goods and end-user match the claimed humanitarian purpose, don't take the label at face value. (CGSS Study Guide v2.02, Domain 3, p.46)
Practise this topic β†’
CGSS Domain 3 Topic Premium

Investigating a Sanctions Breach: Sources & Leading an Investigation

When an alert reaches case level, the handoff itself matters β€” the investigator needs a complete package (what triggered the alert, supporting documents, account records) since the regulatory filing clock is already running. Investigation sources split into internal (KYC/transaction-monitoring escalations, internal hotlines, relationship-manager referrals) and external (adverse media, customer complaints, lawsuits, subpoenas, FIU requests, regulator recommendations). The real Faisal Nadeem case shows a properly escalated near-match: an analyst couldn't fully validate a potential SDN match using open sources alone, so escalated rather than guessing β€” the investigator who took over then requested additional information from both the ordering institution and the internal relationship manager before deciding the case's outcome, rather than closing it on incomplete data.

Leading an investigation well requires securing senior management's genuine commitment (not just sign-off), allocating resources by actual expertise, staying within legal boundaries, and documenting everything as you go. The four research steps (Assess, Explore, Organize, Present) apply directly here, and β€” critically β€” primary sources (government-issued legal documents, official watchlists like the SDN list, and an organization's own KYC records) are distinguished from secondary sources (corporate registries, third-party databases, media β€” not all equally reliable, and social media specifically flagged as manipulable and unreliable on its own). Communication with law enforcement or regulators must go through a designated contact (typically the MLRO/chief compliance officer), be formally documented even after an informal phone call, and follow the organization's own engagement protocols. The real Partial Match case (UK) shows this discipline: an MLRO filed a partial-match report to the FIU via the goAML system within the bank's own 24-hour internal deadline despite incomplete identifying data, froze the account pending guidance, then formally unfroze it only after the FIU's explicit instruction a week later β€” every step documented for audit.

Real Exam Concepts (CGSS Study Guide v2.02, Domain 3, pp.48–66)
  • Escalating an unconfirmed near-match (Faisal Nadeem) rather than guessing at a closure is the correct response when open sources can't fully validate a match.
  • Social media is explicitly named as unreliable on its own β€” useful for leads, not for confirmation, since it's easily manipulated by the subject under investigation.
  • The Partial Match case shows a bank acting on its own internal deadline (24 hours) even where the underlying data was incomplete β€” the deadline discipline matters as much as data completeness.
Learning Outcomes
  • Distinguish internal from external investigation sources.
  • Apply the Faisal Nadeem case to an unconfirmed-near-match escalation scenario.
  • Distinguish primary from secondary sources of information.
  • Apply the Partial Match case to a law-enforcement-communication scenario.
Exam tip: If a question asks how to treat social media information found during an investigation, the correct framing is always "a lead to pursue, not a fact to rely on" β€” the exam tests this reliability distinction directly. (CGSS Study Guide v2.02, Domain 3, p.60)
Practise this topic β†’
CGSS Domain 3 Topic Premium

Investigation Conclusion, Documentation & Self-Reporting

When existing sources run out, a Request for Information (RFI) is the next step β€” but it should be specific, targeted, and sent only after exhausting standard internal/external options first, per the Study Guide's own guidance to "not waste others' time." The real Golden Sun case shows this precisely: after KYC review found a near-match with genuinely ambiguous data (partial date-of-birth match, no company registration number on file), the investigator issued a targeted RFI asking specifically for the registration number and ownership disclosure β€” not a vague, open-ended request. Concluding an investigation requires weighing whether sufficient evidence exists for legal action versus whether all reasonable sources have been exhausted without result; premature conclusion is a real, named risk when records are missing, witnesses are unavailable, a lead proves inaccurate, or the customer simply exits.

The real AgriTech case shows a well-documented conclusion: a Spanish bank traced a payment from a Belarusian agricultural company to its chairman's EU sanctions designation via open-source and media research alone (company website, news photos with Belarus's president) β€” sufficient to reject the payment even without a formal ownership registry confirmation. Self-reporting a confirmed breach follows jurisdiction-specific processes (OFAC's online/PDF forms, OFSI's Compliance Reporting Form, Hong Kong's JFIU filings) and is genuinely weighted favorably in enforcement outcomes. The Loan Application case shows this in practice: a bank discovered post-onboarding that an SDN's ownership stake had grown from 30% to 53% β€” crossing the 50% threshold β€” and self-reported to OFAC with full documentation rather than waiting to be caught. The US Real Estate case shows a genuinely important related principle: file a SAR even without enough evidence to confirm an actual sanctions breach β€” the bank in that case couldn't verify a Russian oligarch's ownership of a real estate buyer, but filed anyway given the circumstantial evidence, correctly treating suspicion (not certainty) as the SAR-filing threshold.

Real Exam Concepts (CGSS Study Guide v2.02, Domain 3, pp.63–79)
  • An RFI should be specific and targeted, sent only after exhausting standard sources first β€” not a first resort or a vague, open-ended ask.
  • Golden Sun's investigator confirmed a match using open-source research alone where formal registry data wasn't available β€” a valid, sufficient conclusion basis.
  • The US Real Estate case's key lesson: a SAR can and should be filed on genuine suspicion even without evidence sufficient to confirm an actual sanctions breach β€” the two thresholds are different.
Learning Outcomes
  • Explain when and how to issue an RFI, using the Golden Sun case.
  • Identify factors that justify concluding an investigation, including premature conclusion.
  • Apply the AgriTech case to an open-source-based conclusion scenario.
  • Distinguish the self-reporting threshold from the SAR-filing threshold using the Loan Application and US Real Estate cases.
Exam tip: If a scenario asks whether to file a SAR when evidence is inconclusive, the correct answer is almost always yes β€” the US Real Estate case's exact lesson is that suspicion, not confirmed proof, is the SAR threshold. (CGSS Study Guide v2.02, Domain 3, p.78)
Practise this topic β†’
CGSS Domain 3 Topic Premium

Identifying, Freezing & Managing Frozen Assets

An asset freeze restricts access without changing ownership β€” the sanctioned party still legally owns the funds, but the institution cannot deal with them (move, alter, transfer, or use them to obtain anything) and generally must not make funds or resources available to the designated person even indirectly. "Assets" span both funds (cash, securities, letters of credit) and economic resources (real estate, vehicles, art, intellectual property β€” anything usable to obtain funds, goods, or services). Freezing must happen immediately to prevent asset flight (moving assets to another jurisdiction) or asset dissipation (spending/misallocating to escape obligations) β€” though jurisdictions differ on the exact trigger: the UK's standard is "reasonable cause to suspect," a genuinely lower bar than requiring certainty.

The real REPO Task Force case (G-7, European Commission, Australia, responding to Russia's invasion of Ukraine) shows freezing at massive coordinated scale: over 2,500 Russia-related SDN designations added in 2022-2023 alone, and roughly US$300 billion in Russian Central Bank assets frozen β€” a genuinely unprecedented multilateral action. The real OFSI case shows the correct operational sequence: a UK bank confirmed a DRC-program match, placed the customer's funds in a designated account, notified OFSI immediately, conducted EDD to find other connected sanctioned parties, and retained all records for five years β€” including submitting the required annual "Frozen Asset In-Year" return. Reporting timelines vary meaningfully by jurisdiction: the EU requires reporting "without delay," the UK "as soon as reasonably possible," and the US (OFAC) allows 10 business days β€” a genuinely testable distinction, not just a formality.

Real Exam Concepts (CGSS Study Guide v2.02, Domain 3, pp.75–93)
  • Freezing changes access, not ownership β€” the sanctioned party's legal ownership never transfers, unlike confiscation or seizure.
  • Reporting timelines genuinely differ: EU "without delay," UK "as soon as reasonably possible," US 10 business days β€” the exam tests recognizing which applies to which jurisdiction.
  • The UK's "reasonable cause to suspect" standard is a lower bar than requiring certainty β€” a bank should freeze on suspicion, not wait for proof.
Learning Outcomes
  • Distinguish asset freezing from confiscation/seizure/forfeiture.
  • Define asset flight and asset dissipation.
  • Apply the REPO Task Force case to a coordinated multilateral freeze scenario.
  • Apply the OFSI case's operational sequence and compare EU/UK/US reporting timelines.
Exam tip: If a question asks about the required timeline for reporting a newly frozen asset, remember the jurisdiction determines the answer β€” EU is immediate, UK is "as soon as reasonably possible," and US/OFAC allows 10 business days. (CGSS Study Guide v2.02, Domain 3, p.89)
Practise this topic β†’
CGSS Domain 3 Topic Premium

Managing Controls: Customer Exit, Account Maintenance & Ongoing Monitoring

De-risking β€” exiting a customer relationship that falls outside risk appetite β€” can be full (terminate everything) or partial (close specific accounts/products while retaining the broader relationship). The real Krandlehoff case shows partial de-risking done well: a bank kept its longstanding, profitable relationship with a maritime supplies company while fully exiting only its UAE subsidiary, which had sold export-controlled dual-use tape through a reseller with suspected sanctioned-entity ties β€” placing the retained parent relationship under enhanced monitoring rather than treating the whole relationship as tainted by one subsidiary's exposure. After filing a SAR, an institution isn't automatically required to close the account β€” the real Industrial Corporation case shows the alternative: a thorough investigation found no actual evidence of DPRK-linked sanctions evasion despite an alert, so the bank retained the customer but upgraded their risk rating and moved them to quarterly (not annual) relationship review β€” a proportionate response to genuine uncertainty rather than an overreaction or a dismissal.

Preventing an exited customer from simply reopening elsewhere requires a maintained internal blacklist plus genuine vigilance for identity variation (different address, using a family member's details, a related-but-differently-named entity). The real Allstone Ventures case shows this working as intended twice: the bank first caught Allstone attempting to reopen under a related company at the same office suite, blacklisted that too β€” then, in a later audit period, caught a *third* related entity ("Swirl Time," controlled by the same beneficial owner per KYC records) attempting to open an account, and correctly declined and blacklisted it as well. Ongoing transaction monitoring refreshes customer profiles on a risk-based schedule (low-risk customers reviewed as infrequently as every 3-4 years in permissive jurisdictions; high-risk customers annually or more often) β€” but specific trigger events (a SAR filing, a business-model change) refresh the schedule regardless of the standard cycle. The real sanctions-related intermediary case shows why this matters: a US$20 million crude-oil deal looked entirely legitimate (known US buyer, standard volume, apparently clean intermediary and supplier) until an *unrelated* SDN designation at the bank's own Middle East branch revealed the Hong Kong intermediary had been receiving disguised "revolving credit" transfers from that same designated party β€” the connection only surfaced because the bank proactively conducted a lookback review after the unrelated designation, not because the original transaction itself looked suspicious.

Real Exam Concepts (CGSS Study Guide v2.02, Domain 3, pp.90–103)
  • A SAR filing does not automatically require account closure β€” Industrial Corporation shows retention-with-enhanced-monitoring as a valid, proportionate alternative.
  • Blacklisting must account for identity variation, not just exact-name matches β€” Allstone Ventures shows evasion attempted twice through related entities with different names.
  • A transaction can look entirely clean in isolation and only become suspicious through an unrelated event (a separate SDN designation) triggering a lookback review β€” the sanctions-related intermediary case's key lesson.
Learning Outcomes
  • Distinguish full and partial de-risking, using the Krandlehoff case.
  • Explain the post-SAR account-maintenance decision, using the Industrial Corporation case.
  • Apply the Allstone Ventures case to a blacklist-evasion-attempt scenario.
  • Apply the sanctions-related intermediary case to a lookback-review scenario.
Exam tip: If a scenario shows a seemingly unrelated SDN designation triggering a lookback review that then reveals a connection to an existing customer's transaction, that's testing the sanctions-related intermediary pattern β€” proactive lookback reviews after any new designation, not just reactive screening. (CGSS Study Guide v2.02, Domain 3, p.102)
Practise this topic β†’