Top 500 Essential AML Interview Questions & Answers
Practise 500 AML interview questions and answers — written the way strong candidates actually answer, not textbook definitions. Every question includes a model answer covering AML fundamentals, KYC/CDD, transaction monitoring, SAR/STR reporting, sanctions, typologies, investigations, crypto risk, FATF & regulations, and scenario judgement — the ten areas AML interviews are actually built from, whether you're interviewing for analyst, investigator, or compliance-officer roles.
Use the category filters to drill into your weak areas, search any topic, and — most importantly — practise saying your answers out loud. Reading prepares your memory; speaking prepares your interview. When you're ready, AGZIT's AI mock interview asks you these kinds of questions by voice and scores your answers — your first session is free.
500 questions · 10 categories · model answers included · free, no signup needed to read
AML Fundamentals & Concepts
Q1What is money laundering?▾
Money laundering is the process of disguising the criminal origin of funds so they appear legitimate. It typically moves through three stages — placement, layering, and integration — and it matters because it lets criminals enjoy and reinvest proceeds of crime through the legitimate financial system.
Q2Explain the three stages of money laundering.▾
Placement introduces illicit cash into the financial system, for example through deposits or cash-intensive businesses. Layering creates distance from the source through transfers, conversions, and complex transactions. Integration returns the funds to the criminal as apparently legitimate wealth, such as property, investments, or business income.
Q3What is the difference between money laundering and terrorist financing?▾
Money laundering disguises proceeds that are already criminal, working backwards from dirty money. Terrorist financing can use legitimate funds — donations or salaries — routed towards a future criminal purpose. In short: laundering hides the source; terrorist financing hides the destination. Controls overlap, but detection logic differs.
Q4What does AML mean and what does an AML programme contain?▾
AML — anti-money laundering — is the framework of laws, controls, and processes that prevent, detect, and report laundering. A sound programme includes risk assessment, internal policies, a designated compliance officer, customer due diligence, transaction monitoring, reporting, training, independent testing, and record-keeping.
Q5What is the role of an AML analyst?▾
An AML analyst reviews alerts and customer activity to identify potentially suspicious behaviour, investigates using KYC data and transaction records, documents findings, and escalates cases that may require a suspicious activity report. The role protects the institution from being used for financial crime and from regulatory breaches.
Q6What is a risk-based approach in AML?▾
A risk-based approach means allocating stronger controls where risk is higher rather than treating all customers identically. The institution assesses customer, product, channel, and geographic risk, then calibrates due diligence, monitoring intensity, and review frequency accordingly. It is the core principle of the FATF Recommendations.
Q7What is the predicate offence in money laundering?▾
A predicate offence is the underlying crime that generates the proceeds being laundered — for example drug trafficking, fraud, corruption, tax evasion, or human trafficking. Laundering charges generally require that funds derive from such an offence, and many regimes now define broad lists of predicates.
Q8What is smurfing or structuring?▾
Structuring — often called smurfing — is breaking large amounts into smaller transactions to stay under reporting or detection thresholds, frequently using multiple people, accounts, or branches. It is a classic placement technique and is itself an offence in many jurisdictions, regardless of the money's origin.
Q9What is the difference between tax evasion and tax avoidance in an AML context?▾
Tax evasion is the illegal non-payment or underpayment of tax and is a predicate offence for money laundering in most regimes. Tax avoidance uses legal means to reduce tax. AML teams care because proceeds of evasion moving through accounts are laundering risk, and aggressive avoidance structures can conceal evasion.
Q10What are the main consequences for a bank that fails at AML?▾
Regulatory fines that can reach billions, criminal liability for the institution and individuals, licence restrictions or loss, forced remediation programmes and monitors, correspondent banking de-risking, reputational damage, and share-price impact. Recent enforcement history shows failures also cost executives their careers.
Q11What is a shell company and why is it an AML risk?▾
A shell company has no significant operations, employees, or physical presence — it exists mainly on paper. Shells are misused to hide beneficial ownership, layer funds across jurisdictions, and issue fake invoices. They are legal in themselves, so the risk lies in opacity: who controls it and why.
Q12What is a front company and how does it differ from a shell?▾
A front company runs a genuine, visible business — a restaurant, salon, or trading firm — but is used to commingle illicit funds with legitimate revenue, making placement easier. Unlike a shell, it has real operations; the laundering hides inside plausible cash flow, which makes detection harder.
Q13What is beneficial ownership and why does it matter?▾
A beneficial owner is the natural person who ultimately owns or controls a customer or on whose behalf a transaction is conducted — typically defined by ownership thresholds such as 25% or by effective control. It matters because criminals hide behind legal entities; identifying the human behind the structure is central to AML.
Q14What is the placement stage's biggest vulnerability for banks?▾
Cash. Placement is where criminal funds first touch the system, so cash deposits, deposits via money mules, cash-intensive businesses, and currency exchanges are the main exposure points. Controls include cash thresholds, structuring detection, source-of-funds questions, and monitoring of sudden cash-heavy behaviour.
Q15What is layering in practice? Give examples.▾
Layering obscures the audit trail: rapid transfers between accounts and jurisdictions, converting cash to monetary instruments, buying and selling securities or crypto, over- and under-invoicing in trade, routing through shells and nominees, and moving funds through jurisdictions with weak transparency. The goal is distance and confusion.
Q16What is integration? Give examples.▾
Integration is the return of laundered funds to the criminal in apparently legitimate form — purchasing real estate or businesses, receiving 'loans' from offshore entities they secretly control, dividends from front companies, luxury assets, or fabricated consultancy income. At this stage funds look clean and are hardest to trace.
Q17What is de-risking and why is it controversial?▾
De-risking is terminating or avoiding whole categories of customers — such as money service businesses, charities, or correspondent clients in certain regions — instead of managing them case by case. Regulators discourage it because it pushes activity into less transparent channels and harms financial inclusion without genuinely reducing risk.
Q18What is a money mule?▾
A money mule moves illicit funds through their own account on behalf of criminals — sometimes knowingly, sometimes recruited through job scams or romance fraud. Mule networks are central to fraud and laundering placement. Red flags include incoming transfers rapidly forwarded on, activity inconsistent with profile, and new accounts with immediate flow-through.
Q19What is trade-based money laundering (TBML)?▾
TBML disguises criminal proceeds through trade transactions — over- or under-invoicing, multiple invoicing for the same goods, misdescribing quality or quantity, or phantom shipments. Value moves across borders inside apparently legitimate commerce, making it one of the hardest laundering methods to detect.
Q20What is the difference between AML and CFT?▾
AML targets the proceeds of crime being made to look legitimate; CFT — countering the financing of terrorism — targets funds, from any source, destined for terrorist activity. They share tools like CDD, monitoring, and reporting, but CFT focuses more on destination, networks, and often smaller transaction values.
Q21Why are PEPs considered higher risk?▾
Politically exposed persons hold or held prominent public functions, giving them access to public funds and influence that can be abused for bribery, embezzlement, and corruption. Their position also makes it easier to move funds through associates and family. Regulation therefore requires enhanced due diligence, senior approval, and closer monitoring.
Q22What is corruption's connection to money laundering?▾
Corruption generates proceeds — bribes, embezzled public funds, kickbacks — that must be laundered to be used, typically through offshore structures, real estate, and PEP-linked intermediaries. Grand corruption cases show public money moving through shells and luxury assets, which is why PEP controls and source-of-wealth checks exist.
Q23What does 'source of funds' versus 'source of wealth' mean?▾
Source of funds is where the money in a specific transaction or account came from — salary, a property sale, business revenue. Source of wealth is how the customer's overall net worth was accumulated — career, inheritance, investments. EDD often requires evidencing both, especially for PEPs and high-net-worth customers.
Q24What is a nominee arrangement and why is it a risk?▾
A nominee holds shares, directorships, or accounts in their name on behalf of the real owner. Legitimate uses exist, but nominees are widely abused to hide beneficial ownership and control from institutions and authorities. The risk is opacity: the person on paper is not the person in charge.
Q25What is a correspondent banking relationship?▾
Correspondent banking is one bank providing services — payments, clearing, accounts — to another bank, often across borders. It is high risk because the correspondent relies on the respondent's controls and cannot see the underlying customers, creating exposure to nested relationships and shell banks. Enhanced due diligence is mandatory.
Q26What is a shell bank and can you bank one?▾
A shell bank has no physical presence in any country and no affiliation with a regulated financial group. Under FATF standards and most national laws, institutions are prohibited from establishing or continuing correspondent relationships with shell banks and must ensure respondents do not permit shell-bank access.
Q27What is 'nesting' in correspondent banking?▾
Nesting is when a respondent bank's own downstream bank customers use the correspondent account, so the correspondent processes transactions for institutions it never onboarded. It multiplies opacity and risk. Controls include understanding the respondent's customer base and restricting or approving downstream usage.
Q28What is a payable-through account?▾
A payable-through account lets the respondent bank's customers transact directly on the correspondent account, effectively giving third parties direct access. It is high risk because the correspondent cannot properly know those end users, so regulations require identifying who has access and ensuring the respondent performs full CDD.
Q29What is willful blindness?▾
Willful blindness is deliberately avoiding knowledge of facts that would confirm wrongdoing — for example, an employee who suspects laundering but chooses not to ask questions. Courts treat it as equivalent to knowledge, so individuals and institutions cannot escape liability by intentionally not looking.
Q30What is tipping off?▾
Tipping off is disclosing to a customer — directly or indirectly — that a suspicious activity report has been filed or an investigation is underway, potentially prejudicing it. It is a criminal offence in most jurisdictions. Practically, analysts must handle exits and RFIs carefully so the customer cannot infer a report.
Q31What records must institutions keep for AML and for how long?▾
Typically customer identification and due-diligence records, account files, business correspondence, and transaction records sufficient to reconstruct individual transactions — retained for at least five years after the relationship ends or the transaction date, longer in some jurisdictions or on regulator request.
Q32Who is a compliance officer / MLRO and what do they do?▾
The money laundering reporting officer (or BSA/compliance officer) is the senior person responsible for the AML programme: receiving internal suspicion reports, deciding on external filings, liaising with regulators and law enforcement, maintaining policies, and reporting to the board. Independence, authority, and resources are essential.
Q33What are the three lines of defence in AML?▾
First line: the business and operations, who own risk and perform controls like onboarding checks. Second line: compliance and risk, who set policy, advise, and monitor. Third line: internal audit, providing independent assurance that the framework works. Clear separation prevents conflicts and control gaps.
Q34What is an enterprise-wide AML risk assessment?▾
A structured evaluation of the institution's inherent laundering and terrorist-financing risk across customers, products, channels, and geographies, the effectiveness of controls, and the resulting residual risk. It drives the risk-based approach — resourcing, monitoring calibration, and policy — and must be documented and refreshed regularly.
Q35What is residual risk versus inherent risk?▾
Inherent risk is the exposure before any controls — driven by who you bank, what you offer, where you operate. Residual risk is what remains after controls are applied. Risk assessments measure both; management decides whether residual risk sits within appetite or requires stronger controls or exit.
Q36What is KYC's relationship to AML?▾
KYC — knowing who your customer is and what activity to expect — is the foundation AML is built on. Without reliable identity, ownership, and expected-activity information, monitoring cannot distinguish normal from suspicious. KYC feeds the risk rating, which drives due-diligence depth and monitoring intensity.
Q37What makes cash-intensive businesses risky?▾
Their revenue is hard to verify, so illicit cash can be blended with sales — the classic front-company method. Restaurants, car washes, convenience stores, and casinos are examples. Controls include benchmarking declared turnover against similar businesses, monitoring deposit patterns, and scrutinising sudden changes in cash volume.
Q38What is a designated non-financial business or profession (DNFBP)?▾
DNFBPs are non-bank sectors exposed to laundering and covered by FATF standards: casinos, real-estate agents, dealers in precious metals and stones, lawyers, notaries, accountants, and trust and company service providers. They face CDD, record-keeping, and reporting obligations because criminals exploit their services for structuring and concealment.
Q39Why are lawyers and accountants attractive to launderers?▾
They can create companies and trusts, hold client funds in pooled accounts, add legitimacy to transactions, and are bound by confidentiality. Misused, they become professional enablers for layering and integration. That is why gatekeeper professions carry AML obligations in most regimes.
Q40What is a trust and why can it pose AML risk?▾
A trust separates legal ownership (trustee) from beneficial enjoyment (beneficiaries), often across jurisdictions. Legitimate for estate planning, trusts can also conceal who really controls assets, especially with discretionary beneficiaries, corporate trustees, and layered structures. AML teams must identify settlor, trustee, protector, and beneficiaries.
Q41What is round-tripping?▾
Round-tripping sends funds out of a country through one route and back through another disguised as foreign investment, loans, or export revenue — cleansing origin and often gaining tax or regulatory advantages. Watch for circular flows, offshore intermediaries with no substance, and 'investment' matching earlier outflows.
Q42What is commingling?▾
Commingling mixes illicit funds with legitimate business revenue so the criminal portion becomes indistinguishable — the operating method of front companies. Detection relies on comparing reported activity with realistic business benchmarks: sector margins, seasonal patterns, and cash-to-card ratios that do not fit the declared business.
Q43What is the difference between fraud and money laundering?▾
Fraud is a predicate crime that generates illicit proceeds by deception; laundering is what happens next — disguising those proceeds. Fraud teams chase the scheme and victim loss; AML teams chase the money trail. They increasingly work together because mule networks and cash-out patterns serve both.
Q44What is an underground or informal value transfer system (hawala)?▾
Hawala and similar systems move value through trusted broker networks without funds physically crossing borders — settlement happens through offsetting obligations. They are fast and cheap and serve legitimate remittances, but the absence of formal records makes them attractive for laundering and terrorist financing.
Q45What is black market peso exchange?▾
A trade-based scheme historically used for drug proceeds: a broker buys criminals' US cash at a discount, sells those dollars to importers who pay in local currency, and the importers use the dollars for legitimate-looking trade purchases. Proceeds return home as goods or business revenue, never crossing borders as cash.
Q46Why is real estate a popular laundering channel?▾
High values absorb large sums in single transactions; prices are subjective, enabling over- or under-valuation; ownership can hide behind companies and trusts; and in many markets intermediaries historically faced weak AML duties. Integration through property gives criminals stable, appreciating, usable assets.
Q47What are luxury goods' laundering risks?▾
Art, jewellery, watches, cars, and boats hold high value in portable form, prices are subjective, and sales can be private and cash-based. Criminals use them to store and move value and to integrate proceeds. Growing regulation targets dealers with thresholds, CDD, and reporting obligations.
Q48What is a politically exposed person's 'close associate'?▾
Someone with close business or personal ties to a PEP — joint beneficial ownership of entities, sole beneficial ownership of a vehicle set up for the PEP's benefit, or prominent social ties. Associates carry PEP-level risk because they are the classic conduit for a PEP's hidden funds.
Q49How long does PEP status last after leaving office?▾
FATF does not set a fixed period; the standard is risk-based. Many institutions apply a minimum of 12–24 months but continue treating individuals with continuing influence, senior former roles, or corruption indicators as PEPs indefinitely. 'Once a PEP, always a PEP' is a common conservative policy for foreign senior figures.
Q50What is adverse media and why screen for it?▾
Adverse media is negative news linking a customer to crime, sanctions, corruption, or regulatory action. Screening surfaces risk that databases and registries miss and often precedes formal designations. It feeds onboarding decisions, risk ratings, EDD triggers, and ongoing monitoring — with judgement needed on source credibility and identity matching.
Q51What is the role of the board in AML?▾
The board owns risk appetite and culture: approving the programme, ensuring resources and independence for compliance, receiving MI on risks, breaches, and filings, and holding management accountable. Regulators increasingly hold boards and senior managers personally responsible for systemic failures.
Q52What is AML training and who needs it?▾
Regular, role-relevant education on laundering risks, red flags, policy, and reporting duties. Everyone needs a baseline; higher-risk roles — onboarding, payments, relationship managers, trade finance, compliance — need targeted depth. Records of completion matter: regulators test whether training is real, current, and tracked.
Q53What is independent testing of an AML programme?▾
Periodic evaluation by internal audit or an external party of whether the programme is adequately designed and operating effectively — sampling files, testing monitoring, reviewing governance, and validating models. Findings go to the board with tracked remediation. It is a pillar requirement in most regimes.
Q54What is a lookback review?▾
A retrospective re-examination of past transactions or alerts — often regulator-mandated after control failures — to identify suspicious activity that was missed and file late reports. Lookbacks are resource-intensive, so they are also a warning: weak monitoring today becomes an expensive remediation tomorrow.
Q55What does 'proceeds of crime' include?▾
Any property derived directly or indirectly from criminal conduct — cash, accounts, assets bought with criminal money, and value that represents such proceeds even after conversion. Broad definitions mean handling, converting, or transferring such property can itself constitute laundering, regardless of who committed the predicate.
KYC, CDD & EDD
Q56What is KYC and why does it exist?▾
Know Your Customer is the process of verifying who a customer is, understanding their ownership and expected activity, and assessing their risk. It exists so institutions can prevent anonymous misuse of the financial system and so monitoring has a baseline: you cannot spot unusual activity without knowing what normal looks like.
Q57What is the difference between CDD and EDD?▾
Customer due diligence is the standard package — identify and verify the customer and beneficial owners, understand purpose of the relationship, and monitor. Enhanced due diligence applies deeper measures to higher-risk customers: source of wealth and funds, senior approval, more documentation, and intensified monitoring.
Q58When is EDD required?▾
When risk is elevated: foreign PEPs and their associates, correspondent banking, customers from high-risk jurisdictions, complex or opaque ownership structures, high-risk industries, unusual account purposes, adverse media, or wherever the institution's risk assessment dictates. Some triggers are mandatory by law; others are policy-driven.
Q59What is simplified due diligence and when is it allowed?▾
A lighter CDD level permitted where risk is demonstrably low — for example regulated financial institutions, listed companies on recognised exchanges, or certain public bodies, depending on jurisdiction. It reduces verification burden but never removes it entirely, and it cannot be applied when suspicion exists.
Q60Walk me through a typical corporate onboarding.▾
Collect legal name, registration details, and formation documents; verify existence via registries; map and verify ownership down to beneficial owners; identify directors and authorised signatories; understand the business, purpose of account, and expected activity; screen all parties for sanctions, PEP, and adverse media; risk-rate; obtain approvals; then set the monitoring baseline.
Q61How do you identify a beneficial owner in a layered structure?▾
Follow ownership upward through each layer, obtaining registers and documents at every level, until reaching natural persons meeting the threshold — commonly 25% — or exercising control through other means. If no owner qualifies, identify senior managing officials. Chart the structure and evidence every link.
Q62What if ownership is split so no one crosses the 25% threshold?▾
Thresholds are indicators, not the definition. Look for control by other means: voting agreements, veto rights, power to appoint directors, family acting in concert, or de facto control. If genuinely no beneficial owner exists, regulations typically require identifying senior managing officials — and documenting the analysis.
Q63What documents verify identity for individuals?▾
Government-issued photo identification — passport, national ID, driving licence — checked for validity and consistency, plus address verification such as utility bills or bank statements where required. Increasingly, digital identity verification with document authentication and biometric matching performs the same function with audit trails.
Q64What is expected activity and why capture it?▾
A statement of what the customer will do: transaction types, volumes, values, counterparties, and geographies. It is the baseline monitoring compares reality against. Vague expected activity produces weak alerts; specific, evidenced expectations make unusual behaviour visible.
Q65What is a periodic review?▾
A scheduled refresh of a customer's KYC — confirming identity data, ownership, activity, and risk rating remain accurate. Frequency is risk-based: commonly annual for high risk, three years for medium, five for low. Reviews also reconcile actual behaviour against expected activity.
Q66What is event-driven review?▾
A KYC refresh triggered by a change rather than a calendar: ownership changes, adverse media, sanctions updates, unusual transactions, new high-risk products, or regulatory requests. Event triggers keep files current between periodic cycles and are a regulatory expectation, not an optional extra.
Q67What is customer risk rating and what drives it?▾
A structured score — typically low, medium, high — combining customer type and profile, geography, products and services used, delivery channel, and behaviour. The rating drives due-diligence depth, review frequency, monitoring sensitivity, and approval levels. It must be recalibrated when circumstances change.
Q68What are red flags at onboarding?▾
Reluctance to provide information or documents; inconsistent or unverifiable details; unnecessarily complex structures with no commercial rationale; nominee shareholders or bearer arrangements; connections to high-risk jurisdictions; urgency and pressure; third parties directing the relationship; and business models that do not make economic sense.
Q69What is name screening and how does it work?▾
Checking customers and connected parties against sanctions lists, PEP databases, and adverse media using fuzzy matching that tolerates spelling variants, transliteration, and aliases. Hits are dispositioned as true or false matches based on identifiers — date of birth, nationality, address — with documented rationale.
Q70How do you disposition a possible sanctions match?▾
Compare all available identifiers — name variants, DOB, nationality, documents, addresses, associates — against the listing. If identifiers conflict, document a reasoned false-positive disposition. If they align or remain unresolved, escalate; funds may need freezing and reporting. Never dismiss a potential match for convenience.
Q71What is a UBO register and can you rely on it?▾
Government registers of beneficial ownership exist in many jurisdictions, but quality varies and self-reported data can be false or stale. They are a useful check, not sole verification: corroborate against documents, structure charts, and independent sources, especially for higher risk.
Q72What is source of funds verification in practice?▾
Evidence matching the money to a stated origin: payslips or contracts for salary, completion statements for property sales, audited accounts or invoices for business revenue, grant or inheritance documents. The test is plausibility and consistency — does the evidence realistically produce these amounts through these channels?
Q73How do you verify source of wealth for a HNWI?▾
Build a wealth narrative and corroborate it: career history with roles and employers, business ownership with accounts and valuations, investment records, inheritance or sale documents, public and media sources. Perfect documentation of every dollar is rare; the standard is a credible, evidenced explanation proportionate to risk.
Q74What is reliance on third parties for CDD?▾
Regulations often permit relying on regulated third parties — such as another bank or a professional intermediary — for elements of CDD, provided information is immediately obtainable and the relying institution retains responsibility. Reliance never transfers accountability; if the file is deficient, it is your deficiency.
Q75What is a pooled or omnibus account risk?▾
Intermediaries — law firms, brokers, payment firms — hold funds for many underlying clients in one account, hiding the end parties from the bank. Controls include understanding the intermediary's own AML framework, agreements on due diligence standards, and the ability to obtain underlying client information on request.
Q76What is non-face-to-face onboarding risk and mitigation?▾
Remote onboarding raises impersonation and forged-document risk. Mitigants: certified document verification, biometric liveness and matching, database and registry checks, device and geolocation intelligence, initial payment from an account in the customer's name, and calibrated limits until the profile is established.
Q77What are bearer shares and why are they a problem?▾
Bearer shares grant ownership to whoever physically holds the certificate, making ownership untraceable and transferable invisibly. Most jurisdictions have abolished or immobilised them. Encountering entities with bearer share capability demands either immobilisation evidence, conversion, or refusal — the opacity is rarely justifiable.
Q78What is a legal arrangement versus a legal entity in KYC?▾
Entities — companies, foundations — have legal personality; arrangements like trusts do not, existing through relationships between parties. KYC for arrangements means identifying settlor, trustees, protector, beneficiaries, and anyone exercising control, plus the deed. Arrangements demand more judgement because registries and standard documents may not exist.
Q79A customer refuses to explain a transaction. What do you do?▾
Document the request and refusal, assess the activity against the profile, and consider whether suspicion arises. Refusal alone may justify restriction, exit consideration, and a suspicious activity report depending on context. What I never do is process it quietly — unexplained plus unusual equals escalation.
Q80What is KYC remediation?▾
A programme to fix deficient customer files at scale — missing documents, unverified owners, stale data — usually after audits, regulatory findings, or acquisitions. It involves prioritising by risk, outreach, verification, re-rating, and exits where cooperation fails. Remediation quality is heavily scrutinised by regulators.
Q81What is perpetual or ongoing KYC (pKYC)?▾
Moving from calendar-based reviews to continuous updating driven by data: registry feeds, transaction behaviour, screening changes, and news trigger targeted refreshes in near real time. It promises current files and efficiency, but demands reliable data integration and strong governance over automated decisions.
Q82How does digital identity verification work?▾
Document capture with authenticity checks (fonts, holograms, MRZ), biometric selfie matching with liveness detection, and validation against issuing databases or trusted sources. Outputs feed the KYC file with audit trails. It is now mainstream, though fraud adaptation — deepfakes, synthetic identities — requires continuous vendor improvement.
Q83What is a synthetic identity?▾
An identity fabricated by combining real and fake attributes — for example a genuine national ID number with a fictitious name — cultivated over time to build credit and account history. Synthetics defeat naive verification because elements check out individually. Detection uses cross-attribute consistency and network analytics.
Q84What is customer exit and how should it be handled?▾
Terminating a relationship for risk reasons: closing accounts with notice per terms, returning funds to source where possible, avoiding tipping off, filing reports where suspicion exists, and recording rationale. Exits should follow governance — a documented decision, not an informal quiet closure.
Q85Why does geographic risk matter in CDD?▾
Jurisdictions differ in corruption levels, AML regime strength, sanctions exposure, secrecy, and conflict. Customer nationality, residence, business footprint, and transaction corridors inherit that risk. Geography feeds risk rating and can trigger EDD — including mandatory measures for FATF-listed high-risk jurisdictions.
Q86What is the FATF grey list's practical effect on CDD?▾
Grey-listed jurisdictions are under increased monitoring, so institutions apply heightened scrutiny to connected customers and flows — deeper due diligence, more questions on rationale, and closer monitoring — though not the countermeasures reserved for blacklisted regimes. Ratings and appetite often tighten as well.
Q87What is an introduced business risk?▾
Customers introduced by intermediaries or referral partners may arrive with incomplete or second-hand due diligence, and the introducer's incentives may not align with control quality. Manage through introducer due diligence, clear reliance agreements, sample testing of introduced files, and full screening regardless of source.
Q88What KYC applies to occasional transactions versus relationships?▾
Even without an ongoing relationship, CDD triggers at thresholds — classically USD/EUR 15,000, lower for wire transfers and some sectors — or whenever suspicion arises. Occasional-transaction KYC covers identification, verification, and purpose, with records retained as for customers.
Q89What is the purpose of a structure chart?▾
A visual map of the ownership and control chain from customer to beneficial owners — entities, percentages, jurisdictions, and roles. It exposes complexity, circularity, and gaps at a glance, supports verification planning, and is the artefact reviewers and regulators check first on complex files.
Q90How do you treat a customer that is a regulated financial institution?▾
Confirm licensing and regulatory status via the home regulator, assess the institution's AML framework and ownership, screen the entity and key principals, and consider jurisdiction strength. Regulation may permit simplified measures, but correspondent-style services demand the opposite — full enhanced due diligence.
Q91What is a certification or notarisation requirement for documents?▾
Where originals cannot be seen, copies may need certification by an approved person — notary, lawyer, banker — confirming they are true copies of originals seen. Requirements vary by jurisdiction and risk. The control matters because uncertified copies are easily forged or altered.
Q92What is 'purpose and intended nature' of a relationship?▾
A CDD requirement to understand why the customer wants the account and how they will use it — products, volumes, counterparties, geographies. It anchors risk assessment and monitoring. An account whose actual use departs from its stated purpose is a core escalation trigger.
Q93How do sanctions screening and PEP screening differ?▾
Sanctions screening is binary and legal: matches to designated parties require freezing and reporting, with no risk appetite override. PEP screening is risk-based: a true PEP match triggers EDD and approval, not prohibition. Confusing the two — treating PEPs as banned or sanctions as discretionary — is a classic error.
Q94What is a false positive rate and why does it matter in screening?▾
The share of alerts that are not true matches. High false-positive volumes consume analyst capacity and breed alert fatigue, increasing the chance real matches are missed. Tuning matching thresholds, enriching data with identifiers, and suppression rules with governance manage the trade-off between noise and misses.
Q95What would make you decline a prospect at onboarding?▾
Unresolvable identity or ownership opacity, sanctions exposure, credible adverse media on financial crime, refusal to provide reasonable information, business models outside appetite or that make no economic sense, and structures whose only apparent purpose is concealment. Declines are documented with rationale — and suspicion, where present, is reported.
Q96What is the difference between identification and verification?▾
Identification is collecting who the customer claims to be — name, date of birth, address, identifiers. Verification is testing those claims against reliable, independent sources: documents, databases, registries. Both are required; a file with identification but weak verification fails its purpose.
Q97How should trusts be onboarded?▾
Obtain and review the trust deed; identify and verify settlor, trustees, protector, beneficiaries or classes, and anyone with control; understand purpose, assets, and funding source; screen all parties; assess jurisdiction and structure risk; and set expected activity. Discretionary and layered trusts warrant enhanced treatment.
Q98What is a customer risk appetite statement's role in onboarding?▾
It defines which customer types, industries, jurisdictions, and structures the institution will accept, restrict, or refuse. Onboarding decisions must align with it, exceptions need documented approval at the right level, and it keeps individual judgement consistent with board-owned risk tolerance.
Q99What ongoing monitoring obligations attach to CDD?▾
Scrutinising transactions against the customer's profile and expected activity, keeping documents and data current, updating risk ratings on change, and re-screening against sanctions and PEP lists as lists and customers change. CDD is a lifecycle obligation, not an onboarding event.
Q100What is an alias or AKA and how is it handled?▾
Alternative names — maiden names, transliterations, nicknames, business names — under which a person may appear in records or lists. Capture known aliases during onboarding and ensure screening covers them; missed aliases are a common root cause of screening failures.
Q101How do you evidence a negative — that someone is NOT a PEP or sanctions match?▾
Through documented screening: the lists and databases checked, search parameters, date, and disposition rationale for any near-matches. Absence of hits plus recorded methodology is the evidence. Periodic and trigger-based re-screening keeps the negative current.
Q102What is a high-risk industry list?▾
Institution-defined sectors carrying elevated laundering exposure — money services, casinos and gambling, crypto firms, arms, precious metals, cash-intensive retail, extractives, adult entertainment, charities operating in conflict zones. Listing drives EDD, restrictions, or prohibition per risk appetite, with rationale documented.
Q103A long-standing customer suddenly changes behaviour. KYC implications?▾
Behavioural change is an event trigger: refresh the profile, understand the reason — new business line, ownership change, distress — update expected activity and risk rating, and consider enhanced monitoring. If explanation is absent or implausible, escalate; longevity is not a defence against suspicion.
Q104What is the role of KYC in fraud prevention?▾
Strong identity verification blocks impersonation and synthetic identities; understanding expected activity exposes account takeover and mule behaviour; beneficial-ownership clarity prevents shell-based scams. KYC and fraud teams increasingly share signals because the same weak files enable both crimes.
Q105What makes a KYC file 'audit ready'?▾
Complete, current documents; verified identity and ownership with a clear structure chart; documented screening and dispositions; risk rating with rationale; expected activity that is specific; approvals at the right level; and a record trail showing when, who, and why for every decision. A reviewer should reconstruct the story without asking you anything.
Transaction Monitoring & Red Flags
Q106What is transaction monitoring?▾
The ongoing analysis of customer transactions — automated and manual — to detect activity inconsistent with the customer's profile or indicative of laundering, terrorist financing, or other crime. Rules and models generate alerts, analysts investigate, and confirmed concerns escalate towards reporting.
Q107How does a rules-based monitoring system work?▾
Predefined scenarios encode typologies: thresholds, velocities, patterns like rapid in-out, structuring under limits, high-risk-geography flows. Transactions breaching a scenario generate alerts, prioritised and queued for review. Rules are transparent and tunable but need constant calibration against noise and evolving behaviour.
Q108What are common monitoring scenarios?▾
Structuring below reporting thresholds; rapid movement in and out (flow-through); high-risk jurisdiction transfers; unusual cash intensity; dormant account reactivation with large flows; activity inconsistent with profile; round-amount patterns; many-to-one or one-to-many fund flows typical of mule networks; and unusual cross-border remittance corridors.
Q109What is an alert versus a case versus a SAR?▾
An alert is a system flag that a rule tripped. A case is an investigation — one or more alerts plus customer context under analyst review. A SAR is the regulatory filing made when investigation establishes suspicion. Most alerts close without cases; most cases close without SARs.
Q110Walk me through your alert investigation process.▾
Understand why the alert fired; review the transactions in full context — history, counterparties, geography; check the KYC profile and expected activity; screen parties and look for adverse media; seek a legitimate explanation; document findings and reasoning; then disposition: close with rationale, request information, or escalate to a SAR decision.
Q111What is a flow-through or pass-through pattern?▾
Funds arriving and leaving quickly with little residual balance — the account acting as a conduit rather than serving a business purpose. Classic of layering and mule activity. Key questions: where from, where to, what changed, and does any commercial rationale explain the speed and route?
Q112What does structuring look like in monitoring data?▾
Multiple transactions just below a threshold — for example repeated 9,000-range deposits against a 10,000 trigger — across days, branches, accounts, or instruments, often by connected parties. The tell is the pattern's shape: amounts clustered under the line with no business reason for fragmentation.
Q113What are red flags in wire transfers?▾
Transfers to or from high-risk jurisdictions without rationale; mismatched originator/beneficiary details; incomplete payment information; round amounts repeated; sudden new corridors; third parties paying for goods; instructions to split payments; and beneficiaries that are shells or unrelated to the customer's business.
Q114What red flags suggest a money mule account?▾
New or dormant account suddenly receiving transfers from unrelated parties, rapidly forwarded onward or withdrawn as cash; activity wildly inconsistent with the holder's profile — a student moving tens of thousands; multiple unrelated senders; and script-like behaviour matching known mule-network patterns.
Q115What is a smurf network pattern in data?▾
Many individuals making similar sub-threshold cash deposits that converge into common accounts — many-to-one aggregation. Network analytics reveal shared beneficiaries, devices, addresses, or timing. Individually each deposit looks minor; the network view exposes coordination.
Q116What cash activity red flags matter most?▾
Cash volumes inconsistent with the stated business; deposits structured under thresholds; sudden shifts in cash-to-electronic ratios; deposits at multiple branches or ATMs the same day; large notes inconsistent with retail trade; and cash-intensive declared income that outpaces realistic sector benchmarks.
Q117What is unusual about round-amount transactions?▾
Genuine commerce produces messy figures — invoices, taxes, fees. Persistent round amounts (exactly 10,000, 50,000) suggest transfers of value rather than payment for goods and services, commonly seen in layering, loan-back schemes, and informal settlements. Context decides; the pattern prompts the question.
Q118What is velocity and why monitor it?▾
The speed and frequency of movement through an account. High velocity — funds out almost as fast as in, many transactions per day — signals conduit behaviour. Velocity changes against a customer's own baseline are often more telling than absolute values.
Q119How do you treat activity inconsistent with expected profile?▾
Quantify the deviation — new counterparties, geographies, volumes, products; seek explanations in the file or via RFI; consider legitimate causes like business growth or seasonality; update the profile if the explanation stands; escalate if it does not. The expected-activity baseline exists exactly for this comparison.
Q120What monitoring red flags arise in trade finance?▾
Prices materially off market (over/under-invoicing); goods descriptions vague or mismatched to the parties' business; shipment routes or ports making no commercial sense; documents inconsistent across the set; repeated amendments; phantom shipping indicators; and counterparties in high-risk or sanctioned jurisdictions.
Q121What are red flags in loan products?▾
Early repayment of large loans with unexplained funds; collateral of opaque origin; loan-backs — borrowing against criminally funded deposits or assets; third parties repaying; and loans to structures whose ownership cannot be established. Lending is an integration channel, not just credit risk.
Q122What insurance red flags exist?▾
Single-premium policies purchased with large cash sums; early surrender despite penalties; frequent policy loans; third-party premium payments; beneficiaries with no insurable interest; and churning across products. Cash value products can store and clean funds, so the AML lens applies.
Q123What securities/brokerage red flags exist?▾
Deposits of physical certificates followed by rapid sale and withdrawal; wash trades and matched orders creating fake activity; penny-stock pump patterns; journaling between unrelated accounts; free-riding of funds through settlement; and account funding from third parties or high-risk sources.
Q124What are red flags in remittance corridors?▾
Volumes or destinations inconsistent with the sender's profile; many senders remitting to one beneficiary; sub-threshold splitting across days or agents; corridors linked to trafficking or conflict; and agents with abnormal volume spikes. Corridor analytics — sender-beneficiary networks — reveal what individual transactions hide.
Q125How do you investigate a counterparty you don't know?▾
Registry and corporate database checks for existence, ownership, and directors; adverse media and sanctions screening; web presence versus claimed business; jurisdiction risk; relationship to your customer's declared activity; and transaction history across your book — is this counterparty a hub touching many customers?
Q126What is network or link analysis in monitoring?▾
Analysing relationships — shared counterparties, addresses, devices, phone numbers, beneficiaries — to reveal coordinated structures invisible at single-account level: mule rings, funnel accounts, shell clusters. Modern monitoring augments rules with graph analytics precisely because launderers operate as networks.
Q127What is a funnel account?▾
An account receiving deposits in many locations and rapidly disbursing in another region or account — geographically dispersed placement converging for onward movement, historically prominent in drug-proceeds corridors. Flags: multi-city deposits, immediate consolidation transfers, and holders with no footprint in deposit locations.
Q128How do thresholds get exploited and what's the answer?▾
Criminals learn fixed lines and sit beneath them — the structuring problem. Answers: behavioural baselines relative to each customer, fuzzy and randomized thresholds, aggregation across time, accounts, and channels, and network views that see coordinated sub-threshold activity as one scheme.
Q129What is alert tuning and why is it continuous?▾
Adjusting scenario parameters, segmentation, and suppression using outcome data — which alerts convert to SARs, which never do — to cut noise without losing detection. Behaviour, products, and typologies shift, so tuning is a governed cycle with testing, documentation, and validation, not a one-off.
Q130What is below-the-line testing?▾
Sampling transactions that did NOT alert — just under thresholds or outside scenarios — to test whether the system misses suspicious activity. It validates that tuning hasn't created blind spots and provides evidence to regulators that detection coverage, not just alert reduction, is managed.
Q131What is a segmentation strategy in monitoring?▾
Grouping customers by type and behaviour — retail, SME sectors, corporates, MSBs — so thresholds and scenarios fit each population. One-size thresholds over-alert on businesses and under-alert on individuals. Good segmentation is the foundation under any tuning effort.
Q132What role does machine learning play in monitoring?▾
Models score alerts or transactions by risk using many features, prioritising analyst attention and catching patterns rules miss; anomaly detection flags departures from learned baselines. Adoption requires explainability, validation, bias testing, and governance — regulators accept ML as augmentation with controls, rarely as an unexplained black box.
Q133How do you handle an alert on a high-profile or sensitive customer?▾
Exactly like any other, with confidentiality heightened: restricted case access, no informal conversations, documentation discipline, and escalation through designated senior channels. Sensitivity changes handling logistics, never the standard of investigation or the reporting obligation.
Q134What is an RFI to a customer and its risks?▾
A request for information seeking explanations or documents for reviewed activity. Risks: phrasing that tips off an investigation, and accepting glib answers. Mitigate with neutral business-as-usual wording, verifying responses against evidence, and deadlines with consequences for non-response.
Q135When does unusual become suspicious?▾
Unusual means inconsistent with expectation; suspicious means, after reasonable inquiry, there remains a possibility the activity involves proceeds of crime or prohibited purpose. The bridge is investigation: explanations sought and tested. Unexplained or implausibly explained unusual activity crosses the line.
Q136What is defensive filing and why is it a problem?▾
Filing SARs on weak or unanalysed grounds to offload risk. It buries FIUs in noise, degrades intelligence value, and signals weak investigation standards. The remedy is quality: documented analysis supporting each decision — including confident, reasoned closures.
Q137How do you document an alert closure?▾
State what fired and why; the evidence reviewed — transactions, KYC, screening, external sources; the explanation established and how it was verified; and the reasoned conclusion that suspicion is not present. The test: a reviewer reaching the same conclusion from the record alone.
Q138What monitoring differences apply to correspondent banking?▾
You see the respondent's flows, not its customers, so monitoring is corridor- and pattern-level: volume anomalies by respondent, nested activity indicators, unusual currency or corridor shifts, and RFIs to respondents for underlying detail. KYC on the respondent's controls substitutes for end-customer knowledge.
Q139What is SWIFT message data's role in monitoring?▾
Payment messages (MT103, MT202, and ISO 20022 equivalents) carry originator, beneficiary, and routing data monitoring depends on. Incomplete or manipulated fields — missing originators, cover-payment misuse — are themselves red flags, and message-level screening supports sanctions and wire-rule compliance.
Q140What is wire stripping?▾
Deliberately removing or altering names, addresses, or references in payment messages to evade sanctions or monitoring — historically at the centre of major enforcement actions. Controls: message integrity screening, repair-queue scrutiny, and zero tolerance in policy and training.
Q141What are indicators of human trafficking in transaction data?▾
Multiple individuals' income routed to one controller; lodging, transport, and food purchases in patterns suggesting controlled groups; late-night recurring merchant activity in high-risk sectors; wage-like inflows instantly swept; and cross-border remittances aligned with trafficking corridors. Financial data often reveals victims before law enforcement does.
Q142What are indicators of online child exploitation in payments?▾
Recurrent low-value payments to high-risk regions with messaging or streaming context; purchases of specific platform credits; transaction timing patterns; and counterparties flagged in typology intelligence. Filing quality matters enormously here — precise indicators materially help investigators.
Q143What does dormancy-then-activity signify?▾
Long-inactive accounts suddenly transacting heavily are takeover or mule risks: sold or compromised credentials, or a stored identity activated for a scheme. Verify control of the account, contact through independent channels, and treat the burst pattern with priority.
Q144What is transaction laundering (merchant-based)?▾
An undisclosed business processes card payments through another merchant's account — front-facing store, hidden real activity (often illegal goods or services). Flags: transaction profiles mismatching the declared merchant category, volume anomalies, and web intelligence showing linked hidden sites. It shifts monitoring onto acquirers and PSPs.
Q145How would you monitor a marketplace or platform business?▾
Understand the flow-of-funds model — who holds funds, when, for whom; monitor seller onboarding quality, payout patterns, refund and chargeback anomalies, collusion signals between buyer and seller accounts, and concentration risks. Platforms inherit money-transmission risk and need typology-specific scenarios.
Q146What alerts should dormant shell-like corporates raise?▾
Incorporation long before activity, then sudden large flows; no payroll, tax, or operational payments; counterparties that are also shells; and directors or addresses shared across many entities. The absence of business-shaped noise is itself the signal.
Q147What is first-party fraud versus mule activity in monitoring terms?▾
First-party fraud is the account holder abusing their own facilities — bust-out spending, false claims. Mule activity is third-party proceeds transiting the account. Data signatures differ: bust-outs show credit-line exhaustion and merchant patterns; mules show unrelated inbound transfers and rapid pass-through.
Q148What KPIs matter for a monitoring function?▾
Alert volumes and conversion rates to cases and SARs; false-positive rates by scenario; investigation cycle times and backlogs; quality-assurance scores; coverage of typologies and products; tuning cadence with validation status; and staffing capacity versus inflow. The theme is effectiveness evidence, not activity counts.
Q149What is a monitoring backlog and why do regulators care?▾
Unworked alerts aging beyond standards. Backlogs mean live suspicious activity going unexamined — enforcement actions repeatedly cite them. Response: risk-prioritised triage, surge resourcing, root-cause tuning, and transparent reporting; hiding or mass-closing backlogs converts a resourcing problem into misconduct.
Q150How do you investigate an unusual crypto-linked fiat flow?▾
Identify the exchange or VASP counterparty and its regulatory standing; check volumes against the customer's profile and stated involvement; use blockchain analytics where available for source or destination risk; ask for the customer's explanation and evidence; and weigh jurisdiction and typology context before disposition.
Q151What are red flags in charity/NPO transactions?▾
Donations flowing quickly onward to high-risk regions; payments to unverified intermediaries; cash-intensive collection with weak records; program spending inconsistent with declared operations; and links to sanctioned areas or entities. Balance vigilance with FATF's caution against blanket de-risking of legitimate charities.
Q152What is layered invoicing / re-invoicing through intermediaries?▾
Interposing an intermediary company that buys and resells the same goods at adjusted prices, shifting value across borders under trade cover. Flags: intermediary jurisdictions unrelated to goods flow, margin patterns without commercial logic, and common control across the chain.
Q153What is an internal escalation path for a suspicious finding?▾
Analyst documents and refers to a senior investigator or team lead; case proceeds to the MLRO or designated officer, who owns the filing decision; parallel controls — account restrictions, exit consideration — follow governance. Clear paths, defined SLAs, and no skipping levels protect both speed and defensibility.
Q154How do you balance customer experience against monitoring friction?▾
Precision over blanket friction: better data and segmentation so controls target genuine risk; use RFIs and holds proportionately; communicate through neutral service language; and measure both risk outcomes and customer impact. The goal is being hard to abuse while remaining easy to use legitimately.
Q155What monitoring lessons come from major enforcement cases?▾
Scale without controls fails: correspondent volumes with thresholds tuned for noise reduction rather than risk; ignored internal warnings; backlogs left to rot; and profitable customers shielded from scrutiny. The consistent lesson — capability must match risk appetite, and culture decides whether alerts matter.
Q156A scenario fires constantly with zero SAR yield. What do you do?▾
Analyse dispositions for the false-positive drivers; check segmentation fit and threshold logic; run below-the-line tests to ensure risk isn't sitting just outside; propose recalibration with impact analysis; document governance approval; and monitor post-change outcomes. Noise is a control defect — but so is deleting coverage without evidence.
Q157What is the role of QA in transaction monitoring?▾
Independent review of investigation samples for completeness, reasoning quality, and disposition accuracy; feedback loops into training and procedures; calibration sessions to align standards; and metrics fed to governance. QA turns individual judgement into a consistent, defensible standard.
Q158How should monitoring adapt to instant payments?▾
Real-time rails remove the settlement delay investigations relied on, so controls shift pre-execution: inline screening and risk scoring, holds on high-risk indicators, mule-network models on receiving side, and rapid recall cooperation. Speed of crime now sets the required speed of control.
Q159What data quality issues undermine monitoring?▾
Missing or stale KYC attributes breaking segmentation; unparsed payment fields hiding counterparties; duplicate or fragmented customer records splitting behaviour; inconsistent country and currency coding; and poor reference data for internal accounts. Monitoring output can never exceed input quality — data lineage is a control.
Q160What is peel-chain-style behaviour outside crypto?▾
Splitting a large sum along a chain of accounts, each passing most value onward while 'peeling' small amounts off for use — creating length and noise in the trail. In banking data it appears as sequential transfers of slightly decreasing amounts across related accounts; the decreasing pattern is the tell.
SAR/STR & Regulatory Reporting
Q161What is a SAR/STR?▾
A suspicious activity or suspicious transaction report is a confidential filing to the national financial intelligence unit when an institution knows, suspects, or has reasonable grounds to suspect that funds relate to criminal proceeds, laundering, or terrorist financing. It is intelligence for authorities, not an accusation.
Q162What is the legal standard of 'suspicion'?▾
Lower than proof and lower than belief: a possibility, based on articulable facts, that is more than fanciful. Courts describe it as a state of mind where you consider there is a real possibility of criminal property. The report explains those grounds; certainty is never required.
Q163Who decides whether to file — analyst or MLRO?▾
Analysts investigate and recommend; the MLRO or designated officer owns the decision and the filing. Internal reports flow to that officer, who applies judgement and records rationale either way. Concentrating the decision protects consistency, confidentiality, and legal accountability.
Q164What makes a high-quality SAR narrative?▾
The five Ws stated plainly: who is involved with identifiers, what activity occurred with amounts and dates, when and where it happened, why it is suspicious against the expected profile, and how it was conducted. Front-load the summary, reference supporting data, avoid jargon, and give investigators a usable lead.
Q165What are common SAR-writing mistakes?▾
Burying the suspicion under transaction dumps; conclusions without supporting facts; missing identifiers and account details; copying alert text instead of analysis; vague phrases like 'unusual activity' without specifics; and omitting what the customer said when asked. The reader knows nothing until you tell them.
Q166What are filing deadlines typically like?▾
Jurisdictions vary: the US expects filing within 30 days of detection (extendable to 60 to identify a subject); many regimes say 'promptly' or 'without delay' once suspicion forms; some require pre-transaction reporting with consent regimes. Know your regime — lateness is an enforcement staple.
Q167What happens after a SAR is filed?▾
The FIU analyses, links it with other intelligence, and may disseminate to law enforcement; most filers hear nothing, by design. The institution continues risk management — monitoring, restrictions, possibly exit — and files continuing reports if activity persists. Silence does not mean the report lacked value.
Q168What is a continuing activity SAR?▾
When reported behaviour continues, follow-up filings summarise activity over the review period — in the US, commonly on a rolling 90-day cycle with filings due within 120 days. It keeps the intelligence picture current and documents that the institution is still watching.
Q169Can you tell a customer a SAR was filed?▾
No. Confidentiality attaches to the report and usually to the fact of its consideration. Tipping off is a criminal offence in most regimes. Communications around restrictions, RFIs, or exit must use neutral commercial language that does not reveal or imply a report.
Q170What is a consent / DAML request regime?▾
In some jurisdictions (notably the UK), where a transaction would involve suspected criminal property, the institution requests a defence against money laundering from the FIU and must not proceed until consent is granted or the notice period lapses. It converts filing into a real-time control on specific transactions.
Q171How do you handle a customer transaction while a SAR decision is pending?▾
Follow your regime: some require holding or seeking consent; others allow proceeding while filing. Practical handling balances legal duties, tipping-off risk, and account restrictions under general commercial terms. Decisions and legal basis are documented — improvisation here creates offences.
Q172What is a currency transaction report (CTR)?▾
An objective, threshold-based report on large cash transactions — in the US, over $10,000 in currency in a day, aggregated per customer. Unlike SARs it requires no suspicion; it exists to create a paper trail on cash. Structuring to evade CTRs is itself reportable and criminal.
Q173What other objective reports exist besides CTRs?▾
Depending on jurisdiction: international funds transfer instructions, cross-border cash and instrument declarations (e.g., CMIRs), foreign account reports (FBAR), large-value or aggregated wire reporting, and sector-specific declarations such as casino or dealer reports. They complement suspicion-based reporting with systematic data.
Q174What is the difference between an internal SAR and an external one?▾
Staff who suspect must report internally to the MLRO — that duty is personal and satisfied by the internal report. The MLRO then evaluates and decides on the external filing to the FIU. Internal reports are recorded even when the officer reasonably declines to file externally.
Q175An investigator asks you informally about a customer. What do you do?▾
Route it formally: verify the request's authenticity and legal basis, engage compliance and legal, and respond through authorised channels with documented disclosures. Informal disclosure risks confidentiality, data protection, and tipping-off breaches — helpfulness must run through governance.
Q176What is a production order or subpoena response process?▾
Validate the order; scope precisely what is compelled; preserve records; gather with an audit trail; review with legal for privilege and scope; respond by deadline through authorised channels; and record everything. Confidentiality applies — the customer generally is not informed.
Q177What protections exist for SAR filers?▾
Safe-harbour provisions typically immunise good-faith filers from civil liability to customers for the report and its consequences. Protection assumes good faith and confidentiality; it does not cover malicious, knowingly false filings, or leaking the report.
Q178What is a joint or shared SAR consideration in group structures?▾
Group entities may share suspicion-relevant information for filing decisions where law permits, improving the intelligence picture across borders. Constraints: local confidentiality, data-protection, and tipping-off rules differ, so sharing frameworks require legal mapping and controlled channels.
Q179How do SARs relate to exiting a customer?▾
Filing and exit are separate decisions: exit manages the institution's risk; the SAR serves authorities. Exits must avoid tipping off — neutral notice, standard terms — and sometimes authorities request keeping the account open for intelligence, which is honoured through governed liaison.
Q180What is the FIU and what does it do?▾
The financial intelligence unit is the national centre receiving suspicious reports and financial disclosures, analysing them, and disseminating intelligence to law enforcement and partners. Examples: FinCEN (US), UKFIU within the NCA, FIU-IND (India), AUSTRAC (Australia). The Egmont Group links FIUs internationally.
Q181What does 'reasonable grounds to suspect' mean for thresholds of filing?▾
An objective test: would the facts you have lead a reasonable person in your role to suspect? It prevents wilful blindness from excusing non-filing. Document the facts and the reasoning; the standard judges the grounds, not your certainty.
Q182What is a SAR decision log?▾
The record of every internal referral and the officer's determination — filed or not — with rationale, dates, and evidence references. Declines with sound reasoning are legitimate; undocumented declines look like suppression. The log is a first-stop item in any regulatory review.
Q183How do you write suspicion when the customer gave an explanation?▾
Include the explanation and why it fails: inconsistent with documents, unverifiable, contradicted by transaction reality, or implausible against the profile. A narrative that ignores the customer's account is incomplete; one that rebuts it is persuasive.
Q184What quality metrics apply to a SAR programme?▾
Timeliness against detection dates; narrative quality scores from QA; feedback or usage indicators from the FIU where available; conversion consistency across teams; error and rejection rates on filings; and evidence that decisions—both filings and declines—withstand independent review.
Q185What is a batch or bulk filing risk?▾
Mass-produced SARs with templated narratives and minimal analysis — often from backlog clearance — degrade intelligence and expose weak investigation standards. Regulators read samples; identical filings signal a process problem. Volume is not a defence; usefulness is the measure.
Q186What information should never be missing from a SAR?▾
Subject identifiers (names, DOBs, identifiers, accounts), the activity's amounts, dates, and counterparties, the suspicion stated explicitly, the customer's expected profile for contrast, and filer contact for follow-up. Missing basics turn intelligence into noise.
Q187What is the relationship between SARs and law-enforcement outcomes?▾
SARs seed and support investigations — tracing assets, mapping networks, corroborating evidence — but filers rarely see outcomes due to confidentiality. Effectiveness reviews increasingly push FIUs to give feedback loops; meanwhile, quality filing is the institution's contribution regardless of visible results.
Q188Should you file on attempted transactions?▾
Yes — most regimes require reporting attempted suspicious transactions even when declined or abandoned. The attempt itself is intelligence: who tried, what they sought, and how they reacted. Capture attempts in procedures; front-line refusal without reporting loses the signal.
Q189What is aggregation in reporting thresholds?▾
Summing related transactions — same customer, same day, multiple branches or channels — to test threshold breaches, preventing evasion through splitting. Systems must aggregate across identifiers correctly; fragmentation of customer records is a classic root cause of missed CTRs.
Q190How does data protection interact with SAR confidentiality?▾
Subjects may exercise access rights, but SAR-related data is generally exempt from disclosure to avoid tipping off — regimes carve out crime-prevention exemptions. Handle through legal: respond to access requests without confirming or revealing reports.
Q191What is a geographic targeting order (GTO)?▾
A temporary FinCEN order imposing extra reporting or identification duties on specific sectors and regions — historically title companies in high-value real-estate markets, identifying beneficial owners behind cash purchases. GTOs show reporting regimes flexing toward observed typologies.
Q192What is the practical test you apply before recommending a SAR?▾
Can I articulate, in a few sentences, specific facts that make criminal property a real possibility — and have I tested the innocent explanations? If yes, recommend and let the narrative carry those facts. If I cannot articulate it, I keep investigating or close with documented reasoning.
Q193A colleague pressures you not to escalate a good client. What do you do?▾
Escalate anyway and document the pressure. Reporting duties are personal and protected; suppressing suspicion for commercial reasons is misconduct that has ended careers and driven enforcement actions. Raise the interference through compliance or whistleblowing channels — that pressure is itself a governance red flag.
Q194What is a whistleblowing channel's role in AML?▾
A protected route for staff to raise failures — suppressed reports, control overrides, resourcing games — outside line management, internally and to regulators. Strong programmes publicise it, protect users from retaliation, and treat reports as control intelligence. Several landmark AML cases began with whistleblowers.
Q195What is the FinCEN files lesson for filers?▾
Leaked SARs showed filings on vast flows while relationships continued unchanged — filing as a substitute for action. The lesson: reports do not launder responsibility. Filing must sit inside risk decisions — restrictions, exits, escalations — or the institution is documenting its own passivity.
Q196What are keywords or typology codes in filings?▾
Structured fields and standardized terms — human trafficking, elder abuse, ransomware, fentanyl — that FIUs use to route and analyse reports. Using advisories' recommended keywords materially improves intelligence value; free-text-only suspicion is harder to aggregate.
Q197What is an information-sharing regime like 314(b)?▾
Voluntary safe-harbour frameworks letting institutions share information with each other to identify laundering or terrorist financing — US 314(b) being the model. Participation expands the picture across institutions; usage requires registration, purpose limits, and confidentiality discipline.
Q198What is 314(a) by contrast?▾
A US mechanism where FinCEN, on law enforcement's behalf, canvasses institutions for accounts and transactions of named subjects; institutions must search records and respond within deadlines. It is compelled, subject-driven searching — distinct from voluntary peer sharing under 314(b).
Q199How should you treat activity already reported once it continues?▾
Maintain monitoring with heightened attention, file continuing reports on schedule, reassess risk and relationship decisions — restrictions or exit — and preserve records. Prior filing never immunises subsequent activity from fresh analysis; patterns evolve and so should the intelligence.
Q200What belongs in a SAR supporting file (not the narrative)?▾
The full evidence set: transaction listings, KYC extracts, screening results, RFI correspondence, analyst notes, approvals, and decision log entries. Regulators and law enforcement may request it; the narrative summarises, the file proves. Retention follows record-keeping rules.
Q201What is the risk of under-filing versus over-filing?▾
Under-filing means missed intelligence, legal breaches, and enforcement for suppressed suspicion. Over-filing means noise, wasted analyst capacity, and degraded FIU value — and it can mask under-investigation. The target is neither volume: it is decisions that match evidence, documented either way.
Q202How do cross-border groups handle filing for the same activity?▾
File where obligations arise — often multiple jurisdictions for one scheme — respecting each regime's confidentiality walls. Group intelligence functions coordinate within legal limits so entities neither duplicate blindly nor assume another affiliate filed. Legal mapping precedes process.
Q203What makes a filing 'timely' when suspicion formed gradually?▾
The clock runs from when suspicion crystallised — typically when investigation concluded, not when the first alert fired. Document that journey: alert dates, investigation milestones, decision date. Gaps between crystallisation and filing are what regulators challenge; the record defends reasonable diligence.
Q204What is your approach to writing the first line of a SAR?▾
State the suspicion and the headline facts immediately: who, how much, over what period, and why it looks like what. Example: 'Filer suspects Account X is operating as a funnel account for structured cash placement totalling $412,000 across 61 sub-threshold deposits in 40 days.' Everything after supports that sentence.
Q205What are FIU advisories and how should institutions use them?▾
Published guidance on emerging typologies — ransomware, trafficking, sanctions evasion — with red flags and reporting keywords. Institutions map advisories into scenarios, training, and screening focus, and cite advisory indicators in filings. They convert national intelligence back into front-line detection.
Sanctions & Screening
Q206What are economic sanctions?▾
Government or multilateral measures restricting dealings with designated countries, entities, individuals, vessels, or sectors to advance foreign-policy and security goals. For institutions they translate into prohibitions: no services, payments, or asset dealings for designated parties, enforced through screening, blocking, and reporting.
Q207What is the difference between sanctions and AML obligations?▾
Sanctions are strict-liability prohibitions — a breach is a breach regardless of intent or risk rating, and matches require freezing and reporting. AML is risk-based — controls scale with assessed risk and suspicion triggers reporting. Confusing the regimes causes both over-blocking and illegal processing.
Q208Name the major sanctions authorities and lists.▾
OFAC in the US (SDN and sectoral lists), the UN Security Council consolidated list, the EU consolidated list, and the UK's OFSI list — plus national regimes like those of Canada, Australia, and Japan. Institutions screen against all lists relevant to their currencies, footprint, and legal exposure.
Q209What is the SDN list versus sectoral sanctions?▾
SDN designation blocks parties entirely: assets frozen, all dealings prohibited. Sectoral sanctions (like SSI-style measures) restrict only specified activities — certain debt, equity, or energy dealings — with parties otherwise permissible. Screening must distinguish, because treatment differs fundamentally.
Q210What is the 50 percent rule?▾
OFAC's rule (mirrored with variations by the EU/UK) that entities owned 50% or more, directly or indirectly, individually or in aggregate, by blocked persons are themselves blocked — even if unlisted. It forces ownership analysis beyond list matching; screening alone cannot find these entities.
Q211What does 'blocking' or 'freezing' assets mean operationally?▾
Halting any dealing: credits to blocked accounts may be accepted into frozen status, but no debits, transfers, or services proceed. The institution segregates and reports the blocked property to the authority within deadlines, then maintains it pending licence or delisting.
Q212What is a sanctions licence?▾
Official authorisation permitting otherwise prohibited activity — general licences published for categories (humanitarian, wind-down, legal fees) and specific licences granted on application. Compliance means reading scope, conditions, and expiry precisely; acting outside licence terms is a breach.
Q213What is the difference between rejecting and blocking a payment?▾
Blocking freezes property in which a designated party has interest — funds are held. Rejecting refuses to process where prohibition applies but no blockable property interest exists (for example, certain sectoral or comprehensive-embargo payments). Regimes specify which response applies; both are typically reportable.
Q214What are comprehensive versus targeted sanctions?▾
Comprehensive programmes embargo virtually all dealings with a jurisdiction — like Iran, North Korea, Cuba (US), and Crimea-style regional embargoes. Targeted (smart) sanctions designate specific persons, entities, vessels, or sectors while general commerce remains lawful. Controls differ: geography screening versus party and activity screening.
Q215What is sanctions evasion and its common techniques?▾
Deliberate circumvention: front and shell companies, nominee ownership below thresholds, transshipment and false documentation, vessel identity manipulation (AIS gaps, flag hopping, ship-to-ship transfers), payment routing through third countries, and crypto channels. Detection blends screening, ownership analysis, trade data, and typology intelligence.
Q216How do you screen for ownership-based (50% rule) exposure?▾
Combine list screening with beneficial-ownership data: map customers' and counterparties' owners, aggregate designated holdings across the chain, and use vendor datasets flagging majority-owned entities. Trigger re-analysis on new designations — yesterday's clean counterparty may be blocked today through its parent.
Q217What is a fuzzy match and why is screening imperfect?▾
Matching tolerates spelling variants, transliteration, initials, and word order to catch aliases — inevitably producing false positives and, if mis-tuned, false negatives. Calibration balances the two, secondary identifiers disposition hits, and no configuration removes the need for competent human review.
Q218How do you clear a sanctions alert correctly?▾
Compare every identifier the list provides — DOB, nationality, documents, addresses, aliases — against your party data; seek additional data when inconclusive; document the reasoning for false-positive dispositions; and escalate genuine or unresolved matches immediately for blocking decisions. Never clear on name dissimilarity alone when identifiers are absent.
Q219What is real-time payment screening?▾
Screening messages against lists before execution — originators, beneficiaries, banks, and free-text fields — with hits diverted to review queues. It is the control that stops prohibited payments; effectiveness depends on message parsing, list currency, and repair-queue discipline.
Q220What fields in payment messages create screening risk?▾
Free-text fields — payment references, address lines, instructing party details — where sanctioned names, ports, or vessels hide; incomplete originator information; and cover payments splitting information across messages. Screening must read what rules-writers didn't structure.
Q221What is name screening versus payment screening?▾
Name (customer) screening runs parties — customers, owners, directors — against lists at onboarding and continuously as lists change. Payment screening runs transaction messages in flight. Both are required; a clean customer can still send a payment referencing a designated party.
Q222What triggers rescreening of the customer base?▾
List updates — daily deltas from authorities and vendors — plus customer-data changes: new names, owners, directors, or countries. Full-base rescreening on list changes is standard; the interval between designation and your detection is pure legal exposure.
Q223What are secondary sanctions?▾
Measures targeting non-US parties for dealings with designated actors even without US nexus — pressuring global institutions to avoid designated networks or lose US market access. They extend practical reach beyond jurisdiction and explain conservative global de-risking around certain regimes.
Q224What is a sanctions nexus analysis?▾
Determining whether a transaction touches a prohibition: parties, ownership, geography, currency (dollar clearing creates US nexus), goods and services involved, vessels and routes. Nexus decides which regimes apply — the same payment may be lawful in one currency and prohibited in another.
Q225What export-control overlap should AML teams know?▾
Dual-use goods and military items face licensing regimes (like EAR/ITAR); procurement networks launder both goods and payments. Red flags: mismatched end-users, transshipment hubs, technical goods to traders with no sector footprint. Sanctions, export control, and AML increasingly share typologies and cases.
Q226What are vessel-related red flags?▾
AIS transponder gaps in sensitive waters, ship-to-ship transfers, flag and name changes, documents inconsistent with tracked movements, ports in embargoed regions, and ownership through layered shipping shells. Trade and commodity finance teams screen vessels and voyages, not just parties.
Q227How do sanctions apply to crypto?▾
Designated wallet addresses appear on lists; blockchain analytics attribute clusters and exposure; VASPs must screen addresses and counterparties and block where interests of designated persons exist. Mixers and certain protocols have been designated themselves — dealing with them creates direct exposure.
Q228What is a sanctions risk assessment?▾
A documented evaluation of the institution's exposure — customers, geographies, products, currencies, channels — against sanctions regimes, mapping controls and residual risk. It drives screening scope, list selection, and resourcing, paralleling the AML risk assessment but for strict-liability exposure.
Q229What is over-compliance / over-blocking risk?▾
Rejecting lawful business through crude geography rules or unreviewed fuzzy hits — harming customers (often humanitarian flows) and breaching obligations in some jurisdictions. Precision matters both ways: regimes prohibit specified dealings, not everything near them.
Q230What is a delisting and how does it affect controls?▾
Removal of a designation after petition or policy change. Controls update with list deltas: unblocking frozen assets typically needs authority guidance or licence confirmation, and residual risk (ownership networks, successor entities) may keep a party high-risk after delisting.
Q231What happened conceptually in major sanctions enforcement cases?▾
Stripping payment data to hide designated parties, processing through non-US branches to launder US-dollar nexus, ignoring internal warnings, and systemic screening gaps — settled for billions. The pattern: intentional circumvention plus control failure, punished as both.
Q232What is an internal sanctions escalation like when a true match hits?▾
Immediate hold on the transaction or account; verification by the sanctions team; blocking or rejection per regime; regulatory report within deadline (often 10 business days for blockings); customer communications restricted to avoid tipping; and case record with legal involvement. Speed and precision, in that order.
Q233How do you screen beneficial owners, not just customers?▾
Screening scope includes owners, controllers, directors, and authorised parties captured in KYC — as data, not prose — so matching engines see them. Ownership screening is how the 50% rule and hidden designated interests become detectable; screening only account names misses the point.
Q234What list management governance is expected?▾
Documented list selection tied to nexus; automated feeds with delta monitoring; version and timing logs; testing that updates load correctly; and reconciliation controls. 'The vendor handles lists' is not governance — institutions own which lists, how fresh, and proof of both.
Q235What is a PEP list versus a sanctions list in screening terms?▾
Sanctions lists are legal prohibitions with mandatory outcomes. PEP lists are vendor-compiled risk data with no legal force — matches inform EDD, not blocking. Screening platforms run both, but disposition workflows, SLAs, and consequences must stay distinct.
Q236What is geographic screening and its limits?▾
Rules flagging countries, cities, ports, and regions in party and message data. Limits: geography hides — transshipment, mislabelled origins, free-text evasion — and over-broad rules block lawful flows. Geography works as one signal within party, vessel, goods, and ownership analysis.
Q237What are sectoral sanctions' operational challenges?▾
Permitting a party for most business while prohibiting specific instruments or maturities demands product-level controls: debt tenor checks, new-equity restrictions, activity classification. Screening says who; sectoral compliance also asks what — systems must carry both.
Q238What is wind-down authorisation?▾
General licences often grant limited windows to conclude pre-existing business with newly designated parties — receiving repayments, closing positions — under strict conditions. Compliance means precise reading: what activity, with whom, until when, and required reporting.
Q239What is your approach to a payment referencing a sanctioned port or vessel in free text?▾
Hold and investigate: confirm the reference (vessel IMO, port identity), map the underlying trade, apply the relevant regime's prohibitions, reject or block as required, report per rules, and review the customer relationship for pattern risk. Free-text hits are real hits until proven otherwise.
Q240What is sanctions screening model validation?▾
Independent testing of matching effectiveness: known-name seeding, transliteration and alias tests, threshold sensitivity analysis, field-coverage checks, and list-update timing verification — documented for governance. Regulators treat screening like a model: prove it catches what it must.
Q241How do sanctions and trade finance interact?▾
Letters of credit and documentary business expose banks to parties, goods, vessels, and routes across documents — each a screening surface. Controls include document screening, vessel tracking, goods classification against embargoes, and refusal where documentation cannot exclude prohibited nexus.
Q242What is designation risk for customers in near-sanctioned sectors?▾
Parties adjacent to designated networks — same sector, region, or partners — face elevated future-designation probability. Risk appetite may restrict exposure pre-designation; monitoring watches ownership and news; contingency plans cover sudden freezes mid-relationship.
Q243What are humanitarian exemptions and carve-outs?▾
Regimes increasingly carve out food, medicine, and humanitarian aid via general licences and UN resolutions. Institutions still struggle to bank such flows for de-risking reasons; correct practice applies the exemptions precisely rather than refusing categorically.
Q244What is the reporting duty when you block assets?▾
Prompt reports to the sanctions authority — commonly within about ten business days for blockings and rejections — plus periodic reports of blocked property held (like OFAC's annual report). Records must let the authority reconcile what is frozen where.
Q245What is name transliteration risk?▾
Names crossing scripts — Arabic, Cyrillic, Chinese — have many Latin renderings; designations may list some variants but not all. Screening must apply transliteration algorithms and alias libraries; exact-match screening in one script is a false-negative machine.
Q246How do you handle a customer designated mid-relationship?▾
Immediate freeze of accounts and property; halt services; regulatory blocking report within deadline; legal review of contractual and licensing position; controlled communications; and case governance for asset maintenance, licences, and eventual resolution. Speed on the freeze is the whole game — exposure runs by the hour.
Q247What is screening of employees, vendors, and counterparties beyond customers?▾
Sanctions exposure isn't customer-only: payroll, suppliers, correspondent and network partners, and securities issuers all create dealings. Mature programmes extend screening across these populations proportionately — a designated vendor paid monthly is a breach like any other.
Q248What crypto-specific sanctions controls exist at VASPs?▾
Address screening against designated wallets, blockchain-analytics exposure scoring for indirect risk, geo-controls (IP, KYC nationality) for embargoed jurisdictions, protocol and mixer restrictions, and travel-rule data screening. On-chain transparency enables controls banks cannot replicate — regulators expect their use.
Q249What does 'strict liability' mean for your daily work?▾
Intent doesn't matter: a processed prohibited payment is a violation even in good faith. Practically it means conservative holds when unsure, complete identifier work before clearing, current lists, and escalation cultures where 'probably fine' is not a disposition.
Q250What sanctions questions do you ask in onboarding high-risk trade clients?▾
Counterparty and end-user identities and ownership; goods classification and dual-use status; shipping routes, vessels, and ports; currencies and settlement paths; and presence in or adjacency to embargoed markets. The answers shape screening scope and appetite before the first transaction.
Q251What recent trend most changes sanctions compliance?▾
Scale and speed: sweeping multilateral packages, ownership-based exposure requiring data beyond lists, aggressive evasion networks, and enforcement extending to facilitation and crypto. Compliance shifted from list-matching to network analysis — screening is now an intelligence discipline.
Q252What is a false negative in screening and its consequence?▾
A designated party passing screening undetected — through transliteration gaps, data quality, or mis-tuned thresholds. Consequence: prohibited transactions processed, strict-liability violations, and enforcement. False negatives are why validation, alias coverage, and identifier-rich data matter more than alert-volume comfort.
Q253What is a sanctions compliance programme's five elements (OFAC framework)?▾
Management commitment; risk assessment; internal controls; testing and auditing; and training. OFAC's framework mirrors AML pillars but for strict-liability exposure — enforcement settlements repeatedly cite weaknesses against these five, making them the design template.
Q254What are designated mixers and why do they matter?▾
Sanctions authorities have designated cryptocurrency mixing services themselves — not just users — making any dealing with those protocols or addresses prohibited. It marks sanctions law reaching infrastructure: exposure analysis must cover services touched, not only counterparties.
Q255How do you evidence screening happened for an audit?▾
System logs tying each party and payment to the list version screened, timestamps, hit dispositions with reviewer identity and rationale, and reconciliation that all in-scope records passed through. Screening you cannot evidence is screening that, for audit purposes, didn't happen.
Typologies & Laundering Methods
Q256What is a typology in AML?▾
A recognised method or pattern criminals use to launder funds — structuring, trade mispricing, mule networks, casino chip-washing. Typologies published by FATF, FIUs, and industry translate case experience into detectable patterns, informing monitoring scenarios, training, and investigation focus.
Q257Explain trade-based money laundering techniques in detail.▾
Over-invoicing exports moves value into a country; under-invoicing moves it out; multiple invoicing bills the same shipment repeatedly; short/over-shipping mismatches goods to documents; phantom shipping documents trade that never happened; and misclassification disguises goods. Value crosses borders inside commerce, evading financial-flow monitoring.
Q258How does real-estate laundering typically work?▾
Purchase through companies or trusts hiding the beneficial owner, often with layered financing: criminal funds as 'loans' from controlled offshore entities, inflated or deflated prices to shift value, cash renovation spending, then resale producing apparently clean proceeds. Rental income adds an ongoing integration stream.
Q259Describe the loan-back scheme.▾
The criminal 'borrows' their own illicit money: funds placed with a controlled offshore entity return as a documented loan, sometimes secured on assets. Repayments and interest launder further value, and the loan explains wealth to banks and tax authorities. Flags: lender opacity, off-market terms, and circular fund origins.
Q260How do casinos get used for laundering?▾
Buying chips with illicit cash, minimal play, then redemption by cheque or account transfer as 'winnings'; using casino accounts to move value across borders through affiliated properties; third parties redeeming chips; and junket structures obscuring the true gambler. Controls: source-of-funds at buy-in, redemption matching, and junket due diligence.
Q261What is a funnel account typology?▾
Cash deposited by many parties across dispersed locations into one account, then rapidly consolidated and moved — placement distributed geographically to stay unremarkable, extraction centralised. Prominent in drug-proceeds movement; detection keys on multi-location deposits versus holder footprint.
Q262How are prepaid cards and stored value abused?▾
Loading illicit cash onto cards below thresholds, transporting value across borders in wallet-sized form, and cashing out elsewhere; fleets of cards under mule identities; and merchant-collusion redemption. Controls: load limits, identity requirements, geographic use analytics, and aggregation monitoring.
Q263What is invoice fraud's laundering role?▾
Fake or inflated invoices justify payments between controlled entities — moving criminal funds under commercial cover, creating deductible expenses, and building paper legitimacy. Common in professional-enabler schemes and corruption. Flags: services vague, pricing arbitrary, counterparties connected, and no delivery evidence.
Q264How does the securities market get abused?▾
Placement via cash purchases of instruments; layering through rapid trades, cross-border custody moves, and wash trading between controlled accounts; integration as portfolio wealth. Market abuse overlaps: pump-and-dump proceeds are predicate crime and laundering in one motion.
Q265What is mirror trading as a laundering method?▾
Simultaneous related trades — buying securities in one currency domestically while selling the same securities offshore for another currency — moving value across borders without a payment corridor. Made notorious by large-scale cases; flags: economically pointless paired trades, common clients both sides, and settlement patterns.
Q266Explain money laundering through insurance products.▾
Single-premium bonds bought with illicit funds and surrendered early — the penalty is a laundering cost; policy loans against cash value; overfunding then refund requests; and third-party premiums. The refund or surrender cheque arrives as clean institutional money.
Q267How do launderers use gold and precious metals?▾
Compact, high-value, globally liquid, and price-transparent: cash converts to bullion, crosses borders physically or through allocated accounts, and resells cleanly. Refiners and dealers face CDD duties because gold is effectively anonymous value storage; trade flags include origin opacity and pricing anomalies.
Q268What is the role of hawala in laundering typologies?▾
Value transfer without fund movement: a broker network settles through trust and offsetting, leaving minimal records. Legitimate for remittances, exploited for laundering and sanctions evasion. Financial-system touchpoints — settlement wires between brokers, cash consolidation — are where detection happens.
Q269Describe daigou / cash courier hybrid schemes.▾
Purchasing goods with illicit cash for resale abroad, or physically couriering currency across borders for placement in weaker-control jurisdictions — declaration evasion included. Controls: cross-border cash declaration regimes, retail purchase patterns, and courier interdiction intelligence feeding financial flags.
Q270What is a professional money laundering network?▾
Specialists laundering as a service for multiple criminal clients — controller-coordinated mule herds, shell factories, trade instruments, and crypto rails — taking a percentage. FATF highlights them because disrupting one network disables many predicate groups; indicators include infrastructure reuse across unrelated schemes.
Q271How do mule herders recruit and operate?▾
Recruitment via job scams ('payment agent'), social media, romance fraud, and student networks; mules receive, forward, or cash out funds for commission. Herders manage scripts, rotate accounts, and discard burned identities. Bank-side detection: cohort behaviour — similar new accounts, shared devices, synchronized flows.
Q272What is cuckoo smurfing?▾
Abusing legitimate expected payments: a customer awaits an international transfer; the launderer's local cash is deposited into that customer's account instead, while the overseas remitter's clean funds go to the criminal abroad. The innocent account holder sees the expected amount; banks see structured third-party cash deposits.
Q273How is the art market exploited?▾
Subjective pricing, privacy norms, freeports, and intermediaries: illicit funds buy works whose value is whatever parties claim; storage in freeports defers scrutiny; resale or collateralisation integrates. Regulation now extends AML duties to art market participants above thresholds.
Q274What are shell-company factory indicators?▾
Formation agents mass-producing entities: shared registered addresses hosting hundreds of companies, recurring nominee directors, sequential incorporation dates, boilerplate filings, and dormant accounts activating for burst flows. One factory's fingerprints often connect superficially unrelated cases.
Q275What is black-market currency exchange laundering?▾
Brokers exchange criminal proceeds in one currency for clean value in another via parallel markets — the peso exchange being the classic: importers buy discounted criminal dollars, pay in local currency, and the trade goods complete the cycle. Flags: third-party payments for imports and price anomalies.
Q276How do launderers exploit payroll and employment structures?▾
Ghost employees on front-company payrolls convert illicit funds into salaried legitimacy; inflated contractor invoices do the same for one-off value. Integration with tax records makes it durable. Flags: payroll inconsistent with business scale and employees lacking real-world footprints.
Q277What is the rent-a-bank-account economy?▾
Individuals selling account access — credentials, cards, and OTP cooperation — to launderers, distinct from deceived mules. Marketplaces price accounts by bank, age, and limits. Detection: device and behavioural changes on established accounts and known-marketplace intelligence.
Q278How is crowdfunding or online marketplaces abused?▾
Fake campaigns and self-purchases convert illicit funds into platform payouts; marketplace sellers 'sell' phantom goods to controlled buyer accounts, receiving clean settlement. Flags: buyer-seller collusion networks, refund abuse, and sales patterns detached from real demand.
Q279What is bust-out fraud's laundering dimension?▾
Building business credit with clean behaviour, then maxing facilities and disappearing — proceeds are predicate crime laundered onward through the same account infrastructure. Monitoring sees the pivot: sudden utilisation spikes, supplier changes, and outbound sweeps preceding default.
Q280How does gambling online differ from casinos for laundering?▾
Digital value-in/value-out: deposits from illicit sources, minimal-play wagering or player-to-player chip dumping (notably poker), and withdrawal as winnings — across licensing regimes of varying rigor. Controls: deposit source screening, play-pattern analytics, and closed-loop payment policies.
Q281What are peel chains (crypto) conceptually?▾
A large tainted balance moves through a chain of addresses, each hop 'peeling' a small amount to a service while forwarding the remainder — creating length and cash-out dispersion. Blockchain analytics detect the signature: sequential hops with small splits toward exchanges.
Q282What is chain-hopping?▾
Converting value across cryptocurrencies and blockchains — often via bridges, DEXs, or instant exchangers — to break analytic continuity. Each hop changes the ledger investigators must trace. Countermeasures: cross-chain analytics and VASP controls at fiat touchpoints.
Q283How are mixers and tumblers used?▾
Pooling many users' coins and redistributing them severs the on-chain link between source and destination. Criminal usage led to service designations and prosecutions. Exchange-side controls treat mixer exposure as high risk, demanding source explanations or refusing withdrawals.
Q284What laundering role do NFTs play?▾
Self-dealing at inflated prices between controlled wallets converts tainted crypto into 'sale proceeds'; subjectivity of value mimics the art market with instant settlement. Flags: wash-trade loops, price patterns detached from collections, and funding from high-risk sources.
Q285What is micro-structuring in the digital era?▾
Automation splits value into hundreds of tiny transfers across accounts, wallets, and P2P apps — each trivial, collectively substantial. Legacy thresholds never fire. Detection requires aggregation analytics across channels and network views of coordinated small flows.
Q286How is student and NGO visa-linked banking abused?▾
Accounts opened on genuine temporary status become mule infrastructure after the holder departs or sells access; tuition and living-expense corridors give cover for inbound value. Flags: post-visa-expiry activity, usage inconsistent with study patterns, and clustered account behaviour.
Q287What is the laundering risk in luxury vehicle exports?▾
Illicit cash buys vehicles domestically; export and resale abroad returns clean proceeds — price gaps and weak title tracing help. Flags: straw buyers, cash purchases inconsistent with profiles, rapid export after purchase, and dealer collusion patterns.
Q288What is invoice factoring abuse?▾
Selling fake receivables to factors converts fabricated 'sales' into immediate clean advances; controlled 'debtors' pay the factor with illicit funds, completing the wash. Flags: debtor concentration in connected parties, invoices without delivery evidence, and margins tolerating expensive factoring irrationally.
Q289How do launderers exploit legal-profession client accounts?▾
Funds parked in solicitor client accounts gain the firm's legitimacy; aborted transactions return 'clean' cheques; property completions route value. Gatekeeper regulation exists precisely for this: professional-account flags include funds without underlying legal work and rapid in-out through client ledgers.
Q290What is TBML's phantom shipping variant?▾
Documents — invoices, bills of lading, insurance — for shipments that never occurred support cross-border payments through banks' documentary channels. Detection: vessel-tracking gaps versus claimed voyages, container-number reuse, and port records contradicting paperwork.
Q291What are typology indicators of proceeds from ransomware?▾
Victim payments in crypto flow through peel chains, mixers, and high-risk exchanges toward cash-out; timing clusters follow attack campaigns; wallet intelligence links payments to strains. Fiat-side flags: companies making unusual urgent crypto purchases — the victims — and services facilitating conversions.
Q292How does laundering through payment service providers occur?▾
Nested merchants and aggregation: illicit businesses hide beneath a PSP's merchant portfolio, their flows blended into the PSP's settlement into banks. Bank-side controls: PSP programme due diligence, merchant transparency requirements, and monitoring the aggregate for typology signatures.
Q293What is the money-service-business corridor risk?▾
MSBs concentrate remittance flows through corridors with informal-economy overlap; agent networks vary in control quality; structuring across agents defeats naive thresholds. Bank controls: MSB programme reviews, corridor analytics, and agent-level anomaly detection rather than blanket exits.
Q294How are dormant companies weaponised?▾
Aged shelf companies with clean histories are bought to skip scrutiny that new entities attract — credit files, bank relationships, and registry age lend credibility to burst-mode laundering. Flags: ownership change followed by activity transformation and directors swapped to nominees.
Q295What is the connection between corruption proceeds and offshore structures?▾
Grand corruption converts public funds into private wealth through layers: offshore shells hold accounts and assets, nominees front ownership, and professional enablers document fictions. Leak-driven cases (Panama/Pandora-style) map the architecture; PEP controls and beneficial-ownership transparency are the countermeasures.
Q296What typologies target the insurance of trade credit or guarantees?▾
Fabricated trade supported by guarantees or credit insurance monetises fraud through claims or discounted instruments; laundering rides the documented 'commercial' flows. Flags: claims patterns across connected parties and instruments issued against unverifiable trade.
Q297What is smurfing's modern cross-channel form?▾
Structuring spread across channels — branch cash, ATMs, agents, P2P apps, prepaid loads — and across identities from mule networks, keeping each channel's totals unremarkable. Only entity-resolution and cross-channel aggregation reveal the scheme's true size.
Q298What typology risks attach to freeports and bonded warehouses?▾
High-value goods stored outside customs territory trade hands via paperwork while physically static — value moves, scrutiny doesn't. Art, gems, and collectibles dominate. Controls: beneficial-ownership transparency for stored assets and transaction reporting by operators.
Q299How does laundering intersect with human trafficking financially?▾
Victim earnings are collected by controllers, placed through funnel accounts and front businesses (salons, massage, hospitality), moved along remittance corridors, and integrated into property and businesses. Financial indicators often expose networks before physical evidence does — which is why FIU advisories emphasise them.
Q300What are indicators of wildlife-trafficking finance?▾
Payments linking source-country brokers, transit shippers, and destination buyers around seizure-correlated routes; trade cover via seafood, timber, or 'curios'; and cash-intensive intermediaries. FATF typologies map it as serious organised crime finance, not a niche environmental issue.
Q301What is 'laundering as integration through business acquisition'?▾
Buying operating businesses with layered illicit funds converts wealth into equity, salaries, dividends, and eventually sale proceeds — deep integration with governance cover. Flags: acquisition funding from opaque offshore sources and buyers without sector history.
Q302Why do typologies matter for an analyst's daily work?▾
They convert crime knowledge into recognition: an alert is a pattern fragment, and typologies supply the pattern library. Analysts who know typologies investigate with hypotheses — testing for funnel, mule, TBML shapes — rather than staring at transactions hoping meaning emerges.
Q303Where do you keep your typology knowledge current?▾
FATF reports and mutual evaluations, FIU advisories and annual reports, Egmont case collections, regulator enforcement actions, industry bodies and vendor threat research, and case debriefs inside the institution. Enforcement actions are especially rich — they document failures against real schemes.
Q304Pick one typology and explain how you'd detect it end-to-end.▾
Take funnel accounts: scenario logic flags multi-location cash deposits versus holder geography; network analytics link depositor clusters; investigation validates against profile and footprint; RFIs test explanations; SAR narrative maps the funnel with locations, totals, and beneficiaries; and the typology feeds back into tuning.
Q305What is a straw buyer or straw man typology?▾
A person lends their identity to transactions — property, vehicles, companies — concealing the true principal behind clean paperwork. Compensation is modest; exposure is theirs. Flags: purchases inconsistent with the buyer's finances, third parties funding completions, and rapid transfers of the asset's benefit.
Investigations & Case Handling
Q306What distinguishes an investigation from an alert review?▾
Alert review dispositions a system flag; investigation builds a case: aggregating alerts and accounts, reconstructing fund flows, profiling parties and networks, testing hypotheses against evidence, and producing a documented conclusion that supports reporting, restriction, or exit decisions.
Q307How do you plan a complex AML investigation?▾
Define the question and scope — parties, accounts, period; inventory available data: transactions, KYC, screening, communications, external sources; form typology hypotheses; sequence the work from cheap checks to deep analysis; set escalation triggers; and keep a decision log from the start.
Q308How do you reconstruct a flow of funds?▾
Trace chronologically: source credits, through-account movements, and destinations — mapping counterparties, amounts, dates, and channels into a flow diagram. Follow value across conversions and accounts, distinguish principal from noise, and annotate each hop with evidence references.
Q309What open-source intelligence (OSINT) do you use and how carefully?▾
Corporate registries, court records, sanction and PEP databases, quality media, and cautious social/web presence checks — always assessing source reliability, matching identity precisely, and recording capture dates. OSINT informs; it rarely proves. Note jurisdictional limits on certain data use.
Q310How do you assess adverse media credibility?▾
Source reputation and independence; specificity — names, dates, charges versus vague association; corroboration across outlets; recency and outcome (allegation, charge, conviction, acquittal); and identity certainty. A conviction in a reputable outlet outweighs ten recycled allegation blogs.
Q311What is entity resolution and why does it matter in cases?▾
Linking records that describe the same real-world party across systems — name variants, addresses, identifiers, devices — so behaviour aggregates correctly. Investigations fail when one actor appears as five customers; resolution reveals true exposure and network structure.
Q312How do you investigate a suspected mule network?▾
Start from the flagged account; pivot on shared attributes — devices, IPs, addresses, beneficiaries, timing signatures; map inbound victims/sources and outbound consolidation; classify roles (collector, distributor, controller); quantify flows; and package the network view for reporting and restriction decisions.
Q313What questions do you ask before contacting a customer in a live case?▾
Will contact tip off? Is the account safe to leave operational meanwhile? What exactly do I need that internal data cannot give? How do I phrase neutrally? Who approves? RFIs are investigative tools with legal edges — plan them, don't improvise.
Q314How do you evaluate a customer's documentary evidence?▾
Authenticity: format, metadata, issuer verification where possible; internal consistency — dates, amounts, parties aligning; external consistency against transactions and registries; and plausibility against commercial reality. Documents assert; corroboration convinces.
Q315What is a good case chronology and why keep one?▾
A dated record of events, findings, actions, and decisions built as you work. It structures analysis, exposes gaps, enables handover, and becomes the defensibility spine when regulators or courts later ask what you knew and when.
Q316How do you decide when an investigation is 'done'?▾
When the question is answered to the applicable standard: suspicion confirmed with articulable grounds, or reasonable inquiries exhausted with innocent explanation verified. Done is a documented judgement — further steps considered and reasonably declined — not fatigue.
Q317What escalation triggers should interrupt normal case flow?▾
Sanctions nexus; imminent transactions moving suspected proceeds; law-enforcement contact; insider involvement; media or political sensitivity; threats to staff; and evidence of active harm — trafficking, exploitation, fraud in progress. Each has a defined fast path bypassing queues.
Q318How do you handle insider (employee) involvement indicators?▾
Immediate, discreet escalation to designated channels — typically financial crime leadership, HR, and internal investigations — outside normal line reporting; access restrictions; evidence preservation; and strict need-to-know. Insider cases combine AML, fraud, and employment law — coordination first.
Q319What is the role of communications data (emails, chat) in cases?▾
Where lawfully accessible — internal channels, customer messages within relationship records — communications reveal intent, coordination, and knowledge that transactions imply. Use through governance: legal basis, privacy limits, and forensic-integrity handling.
Q320How do you quantify suspicious activity for a case?▾
Define inclusion rules — which transactions, period, direction; separate suspected proceeds from apparently legitimate flow; total by category with methodology stated; and reconcile figures across the narrative, exhibits, and filing. Numbers that don't reconcile undermine everything else.
Q321What is link analysis software actually good for?▾
Visualising networks — accounts, parties, attributes, flows — to reveal structure: hubs, bridges, clusters, and hidden intermediaries. It accelerates hypothesis generation and communicates findings powerfully. Garbage-in still applies: resolution quality and data completeness bound its value.
Q322How do you investigate trade-finance suspicion?▾
Assemble the documentary set; verify vessel, voyage, and container data against tracking sources; benchmark pricing against market references; check counterparties' existence, ownership, and sector fit; map payment flows against the trade story; and test the whole for commercial sense.
Q323What is your approach to source-of-funds verification in a case (not onboarding)?▾
Trace claimed origins through evidence: sale completions, payroll records, business accounts — matched to the actual credits in question by amount, date, and route. Onboarding accepts narratives proportionate to risk; investigations test them against transactional reality.
Q324How do you work a case with law enforcement in parallel?▾
Through authorised liaison only: validated requests, documented disclosures within legal gateways, deconfliction so bank actions (exits, RFIs) don't damage operations, and honouring keep-open requests via governance. Enthusiastic informal cooperation creates legal risk for everyone.
Q325What are common investigation quality failures?▾
Confirmation bias — building the file toward the first hypothesis; ignoring exculpatory evidence; identity assumptions without resolution; unquantified 'suspicious volumes'; missing customer explanations; broken evidence trails; and conclusions the documented facts don't actually support.
Q326How do you avoid confirmation bias in casework?▾
State competing hypotheses explicitly — including the innocent one — and evidence each; seek disconfirming checks deliberately; have conclusions peer-reviewed against the file; and write narratives that acknowledge and resolve contrary indicators rather than omitting them.
Q327What does a defensible case file contain?▾
The trigger and scope; evidence gathered with sources and dates; analysis linking evidence to findings; customer explanations and their testing; decisions with rationale and approvals; and the chronology. Test: a stranger reaches your conclusion — or identifies exactly where they diverge.
Q328How do you brief senior stakeholders on a major case?▾
Lead with the decision needed and the risk headline; give the scheme in one diagram and five sentences; quantify exposure; state options with recommendation; and keep the deep file behind the summary. Senior time buys judgement — package for it.
Q329What is a keep-open (law enforcement) request and its handling?▾
Authorities may ask the institution to maintain a suspect account to preserve intelligence. Handle through documented governance: validate the request, define monitoring and loss parameters, set review dates, and record the risk acceptance. It is cooperation with controls, not an exemption.
Q330How do you investigate activity involving another institution's customers?▾
Your visibility ends at your perimeter: analyse your side of flows, use information-sharing gateways (like 314(b)-style regimes) where available, direct RFIs to counterparty banks through proper channels, and file reports that give the FIU the cross-institution picture you cannot complete alone.
Q331What is the difference between intelligence and evidence in your work?▾
Intelligence guides — patterns, tips, analytics, unverified reports; evidence proves — records, documents, verified facts meeting applicable standards. Investigations run on intelligence but conclude on evidence; conflating them produces filings and decisions that collapse under scrutiny.
Q332How do you handle conflicting evidence?▾
Weigh source reliability and directness; seek tie-breaking checks; consider whether both can be true under a different hypothesis; document the conflict and resolution reasoning. Unresolved material conflict belongs in the narrative — pretending coherence is a quality failure.
Q333What time management approach works for heavy caseloads?▾
Risk-based triage — value, velocity, harm indicators first; timeboxing routine dispositions; templates for recurring analysis; escalating blockers early; and protecting deep-work blocks for complex cases. Backlogs are managed transparently, never by silent quality erosion.
Q334How do you keep investigations confidential internally?▾
Need-to-know access on case systems; no names in open channels; sanitized references in queues; clean-desk and screen discipline; and briefing lines that don't leak through relationship managers to customers. Confidentiality failures create tipping-off exposure from inside.
Q335What is a post-case feedback loop?▾
Routing findings into controls: typology to monitoring tuning, data gaps to KYC remediation, evasion methods to screening rules, and lessons to training. Cases are expensive intelligence — programmes that close files without loops keep buying the same lesson.
Q336How would you investigate a politically sensitive PEP case?▾
Standard rigor, hardened logistics: restricted access, senior oversight from the start, meticulous documentation anticipating scrutiny, legal involvement on disclosure questions, and communications discipline. The analysis must be indistinguishable from any other case — the handling cannot be.
Q337What role do you give analytics or scoring in prioritising your queue?▾
Scores rank attention, they don't decide outcomes: I take model priority as a hypothesis about risk, validate against the file, and remain alert to what models undervalue — novel typologies, low-score-high-harm patterns. Documented judgement sits above the score.
Q338What is asset tracing at institution level?▾
Following value from suspected origin to current form within your visibility — accounts, conversions, purchases — and flagging exit points (property, other banks, crypto) in reporting so authorities can continue with compulsory powers. You trace to your perimeter and hand off precisely.
Q339How do you test the innocent explanation properly?▾
Operationalise it: if the story is true, what records must exist and what patterns should the data show? Request and check exactly those. Explanations that survive specific, falsifiable testing close cases credibly; explanations tested only by plausibility close nothing.
Q340What makes network cases harder than single-account cases?▾
Scale and identity: dozens of accounts, resolution uncertainty, role differentiation between witting and unwitting parties, cross-institution blindness, and packaging complexity for filings. The craft is decomposition — proving the pattern on strong nodes while mapping the whole.
Q341How do you write findings when suspicion is NOT confirmed?▾
With the same rigor: what prompted review, inquiries made, evidence obtained, explanations verified, and why suspicion is not present. Closures protect the institution only when they demonstrate diligence — 'reviewed, nothing found' is not a finding.
Q342What is your relationship with the fraud team on overlapping cases?▾
Structured collaboration: shared indicators (mules serve both), deconflicted customer contact, joint network views, and clear ownership per case with defined handoffs. Fraud chases loss and recovery; AML chases proceeds and reporting — the data is the same crime seen twice.
Q343How do you handle a case where the customer is another employee's relative?▾
Declare the conflict immediately; the case moves to an unconflicted investigator; access for the connected employee is restricted; and handling is documented. Conflicts managed openly are routine; discovered later, they poison every conclusion in the file.
Q344What is proportionality in investigative effort?▾
Depth matching risk: a small structured-deposit case doesn't need forensic accounting; a multi-jurisdiction network justifies it. Proportionality is documented judgement — what was done, what was reasonably not, and why — protecting both effectiveness and capacity.
Q345What external databases or tools do you rely on?▾
Corporate registries and aggregators, sanctions/PEP/adverse-media platforms, court and insolvency records, vessel and trade data, blockchain analytics for crypto legs, and news archives. Tool output is input — the analysis, identity matching, and conclusions remain human responsibilities.
Q346How do you prepare a case for possible legal proceedings?▾
Evidence integrity from day one: provenance recorded, originals preserved, exports hashed or logged, chronology maintained, opinions separated from facts, and privilege managed with legal. You rarely know in advance which case ends in court — file every serious case as if it might.
Q347What does 'follow the money' mean as a discipline?▾
Letting flows, not narratives, lead: value's actual path exposes control, beneficiaries, and purpose more honestly than any document or explanation. Names lie, structures obscure — movement patterns betray. The discipline is tracing before theorising.
Q348A case implicates a profitable corporate client's subsidiary. Pressure arrives. Your move?▾
The analysis proceeds untouched; findings go through standard governance with the pressure documented and reported upward. Commercial weight is a fact about consequences, never about evidence. Institutions fail publicly when revenue edits investigations — I won't be the edit point.
Q349What professional development keeps an investigator sharp?▾
Typology and enforcement reading as routine; certifications that structure knowledge; case debriefs and peer review; cross-training in fraud, sanctions, and crypto; courtroom and FIU feedback where available; and writing practice — because investigation quality ultimately ships as prose.
Q350Describe your ideal investigation summary in three sentences.▾
Who did what, quantified, over when: the scheme in one sentence. Why the evidence supports that conclusion over innocent alternatives: the reasoning in one sentence. What we did and recommend — filing, restriction, exit: the decision in one sentence. Everything else is appendix.
Crypto & Emerging Tech Risk
Q351What is a VASP?▾
A virtual asset service provider — any business exchanging virtual assets and fiat or virtual assets with each other, transferring virtual assets, providing custody, or participating in issuance services. FATF's definition brings exchanges, custodians, and similar businesses inside AML/CFT obligations.
Q352How does blockchain transparency change AML work?▾
Public ledgers record every transaction permanently, so analytics can trace flows, cluster addresses into entities, and score exposure to illicit sources — visibility banks never had. The flip side: identity sits off-chain, so tracing ends where attribution and VASP KYC begin.
Q353What is the FATF Travel Rule for crypto?▾
Obligated VASPs must obtain, hold, and transmit originator and beneficiary information with virtual-asset transfers above thresholds — mirroring wire-transfer rules. It closes the anonymity gap between VASPs; implementation challenges include protocol interoperability and counterparty VASP due diligence.
Q354What is an unhosted (self-custody) wallet risk?▾
Wallets controlled by individuals without an intermediary: no KYC attaches to the address itself. Risk is contextual — self-custody is legitimate — so controls focus on the VASP touchpoints: source/destination analytics, thresholds and enhanced measures for unhosted transfers, and behavioural context.
Q355How does blockchain analytics attribution work?▾
Clustering heuristics (common-input ownership, change patterns) group addresses into wallets; ground truth — exchange deposits, seizures, leaks, undercover transactions — labels clusters as entities; propagation scores exposure hops away. Confidence varies; attribution is probabilistic evidence, strongest at service-level labels.
Q356What are direct versus indirect exposure in analytics?▾
Direct exposure: funds received straight from an illicit address or service. Indirect: illicit value arriving through intermediary hops, weighted by distance and proportion. Policies set thresholds per category — sanctioned direct exposure may mandate freezing; distant darknet exposure may only raise EDD.
Q357What are mixers, and what is their compliance status?▾
Services or protocols pooling and redistributing coins to break traceability. Compliance status has hardened: major mixers have been sanctioned and prosecuted; VASP policies typically treat mixer-derived funds as high-risk or refusable, and dealing with designated mixers is itself prohibited.
Q358What are privacy coins and how do VASPs handle them?▾
Assets with protocol-level anonymity (like Monero or shielded Zcash) resist chain analytics. Handling ranges from delisting (common under regulatory pressure) to enhanced controls on entry/exit points. Where supported, compliance leans entirely on fiat-edge KYC and behavioural monitoring.
Q359What is chain-hopping and how do you counter it?▾
Rapid conversion across assets and blockchains via DEXs, bridges, and instant swappers to fragment the trail. Counters: cross-chain analytics stitching bridges, monitoring for hop-pattern signatures, and controls at fiat off-ramps where the value must eventually surface.
Q360What is DeFi's AML challenge?▾
Protocols execute financial services through smart contracts without an intermediary to obligate — no natural KYC point. Regulatory focus shifts to points of control: developers and DAOs with governance power, front-end operators, and the CeFi on/off-ramps users still need. Analytics still trace the flows.
Q361What is a peel chain and its detection signature?▾
A tainted balance moves address-to-address, each hop peeling a small amount toward services while forwarding the remainder — dispersing cash-out over time. Analytics detect the sequential small-split pattern converging on exchange deposit addresses.
Q362How do ransomware payment flows look on-chain?▾
Victim payments hit campaign wallets, consolidate, pass through mixers or chain-hops, and exit via high-risk exchanges or OTC brokers. Wallet intelligence ties addresses to strains; exchanges screen deposits against these clusters; advisories require specific reporting.
Q363What is crypto ATM (kiosk) risk?▾
Cash-to-crypto conversion with historically weak identification enables placement and scam cash-out — romance and impersonation fraud victims are directed to kiosks. Controls tightening: registration, KYC thresholds, transaction limits, and blockchain monitoring of kiosk clusters.
Q364What are P2P exchange risks?▾
Trades settle directly between users (with escrow), so counterparty KYC may be minimal and payments route through personal bank accounts — creating bank-side mule-like patterns and platform-side laundering channels. Flags: trading volumes inconsistent with profiles and payment references citing platforms.
Q365How do sanctions apply on-chain?▾
Designated addresses are listed; dealing with them — or with property in which designated persons hold interest — is prohibited regardless of ledger. Analytics extend reach to clusters and indirect exposure. Protocol-level designations (mixers) prohibit interaction with the service itself.
Q366What is proof of reserves and its AML relevance?▾
Attestations that a custodian holds assets matching liabilities. Primarily solvency transparency, it intersects AML through custody integrity and misuse of client assets — collapses driven by commingling showed custody failure and financial crime travelling together.
Q367What is an OTC desk risk in crypto?▾
Over-the-counter brokers settle large trades off order books, historically with lighter onboarding — attractive for converting large illicit sums. Red flags: counterparties fronting for third parties, funds from high-risk clusters, and settlement through networks of personal accounts.
Q368What is address screening at a VASP in practice?▾
Pre-transaction: outbound destinations screened against designated and high-risk addresses; inbound deposits scored for source exposure; policy engines block, hold, or escalate per category and threshold; and cases document dispositions with analytics evidence attached.
Q369What KYC differences exist at crypto firms versus banks?▾
Core duties match — identification, verification, risk rating, monitoring — but context differs: global-by-default customer bases, wallet linkage as profile data, on-chain behavioural monitoring alongside fiat, and travel-rule counterparty due diligence replacing correspondent-style knowledge.
Q370What is a smart-contract exploit's laundering aftermath?▾
Stolen protocol funds move fast: swaps to stable or liquid assets, bridge hops, mixer passes, and staged cash-outs. Defenders race attribution — public tracing, exchange freezes, negotiated returns. For compliance teams, exploit-linked clusters become instant high-risk screening entries.
Q371What are stablecoins' specific risks?▾
Fiat-pegged value with crypto rails: fast, borderless, and increasingly the settlement asset of choice in illicit markets. Centralised issuers can freeze — an enforcement lever — so typologies shift toward chains and issuers with weaker intervention. Monitoring treats large stablecoin corridors as payment infrastructure.
Q372What is the difference between custodial and non-custodial services for AML obligations?▾
Custodial services control client assets — squarely VASPs with full obligations. Non-custodial software (self-hosted wallets, some interfaces) historically sat outside, though regulatory perimeter debates continue. Obligation follows control of value, which is why classification analysis matters per business model.
Q373How do NFT platforms face laundering risk?▾
Subjective pricing enables self-dealing washes converting tainted crypto to 'proceeds'; royalties and mints add layering surfaces. Platform controls: KYC thresholds, wash-trade detection between linked wallets, and source-of-funds screening on high-value settlement.
Q374What is a bridge and why do launderers use them?▾
Infrastructure moving value between blockchains, often by locking assets on one chain and minting representations on another. Launderers use bridges to fragment analytic continuity; bridges themselves have been exploited for thefts. Cross-chain analytics increasingly stitch these paths.
Q375What crypto red flags should a bank monitor for?▾
Customer volumes to/from exchanges inconsistent with profile or declared involvement; rapid fiat-crypto-fiat cycles; payments to kiosk operators; scam-consistent patterns (urgent purchases by unlikely demographics); and counterparties that are unregistered or high-risk VASPs.
Q376What is the regulatory landscape trend for crypto AML?▾
Convergence on FATF standards: VASP registration/licensing, travel-rule enforcement, stablecoin and market frameworks (like MiCA in the EU), aggressive enforcement on unregistered operators, and sanctions extending to protocols. The perimeter keeps widening toward wherever control and value concentrate.
Q377What is wallet clustering's failure mode?▾
Heuristics misfire: services batching many users (exchange hot wallets) can blend identities; privacy techniques (coinjoin) break common-input assumptions; and stale labels misattribute. Treat cluster attribution as confidence-weighted evidence — corroborate before consequential decisions.
Q378What is source-of-funds analysis for a crypto-wealth client?▾
Reconstruct the on-chain story: acquisition era and method (mining, early purchase, income), wallet history consistency, disposal events matching claimed proceeds — corroborated by exchange records, tax filings, and contemporaneous documentation. 'Early adopter' claims are testable on-chain; test them.
Q379What are darknet market flows like?▾
Purchases flow to market escrow wallets, vendors withdraw through mixing and consolidation, and cash-out disperses via exchanges, P2P, and OTC. Market takedowns publish address sets; exposure screening then identifies historical counterparties across the industry.
Q380What is the compliance role of blockchain intelligence vendors?▾
They supply attribution datasets, exposure scoring, tracing tools, and typology research the industry standardises on. Institutions own the decisions: vendor labels are inputs requiring governance — coverage limits, confidence levels, and validation — like any critical model.
Q381What is 'travel rule sunrise' as a problem?▾
Jurisdictions implemented the rule at different times, so compliant VASPs face counterparties with no framework — transmit to whom, verify what? Interim controls: counterparty VASP due diligence, risk-based holds, and protocol solutions bridging unevenly regulated corridors.
Q382How does AI change financial crime on both sides?▾
Offense: deepfake identities defeating verification, generated documents, automated social engineering, and laundering orchestration at scale. Defense: better anomaly detection, entity resolution, narrative drafting, and alert triage. The arms race raises the premium on adaptive controls and human judgement over static rules.
Q383What is a deepfake onboarding attack?▾
Synthetic video/voice defeating liveness and document checks to open accounts under stolen or fabricated identities. Counters: hardware-level liveness signals, injection-attack detection, document forensics, cross-channel consistency checks, and step-up verification on risk signals.
Q384What monitoring exists for on-chain behaviour at a VASP?▾
Beyond screening: velocity and pattern rules on deposits/withdrawals, structuring detection across addresses, exposure-change alerts on customer wallets, peer-group anomaly models, and case tooling that pairs on-chain traces with off-chain KYC — one investigation surface.
Q385What is the FATF 'sunset' concern about unhosted transfers?▾
Pressure to apply enhanced measures — data collection, limits, or verification — to VASP transfers with self-hosted wallets, balancing traceability against privacy and practicality. Institutions implement risk-based tiers rather than blanket prohibition, documenting the rationale.
Q386What are money-laundering risks in gaming and metaverse economies?▾
In-game currencies and tradable items convert value across borders with entertainment cover: buying assets with illicit funds and cashing out through marketplaces. Flags: purchase/sale loops without play, RMT (real-money-trading) platforms, and payment patterns detached from gaming behaviour.
Q387What is an approval or allowance exploit in token laundering?▾
Abusing token approval mechanics — draining wallets that granted permissions to malicious contracts. Stolen assets then launder conventionally on-chain. Compliance relevance: exploit clusters become screening entries, and victim-support flows (recoveries, negotiations) need careful handling.
Q388How do you evaluate a counterparty VASP's quality?▾
Licensing and registration status; jurisdiction and regime strength; ownership and management screening; published compliance posture; analytics reputation of its clusters (illicit exposure ratios); travel-rule capability; and enforcement history. This is correspondent-style due diligence, crypto edition.
Q389What is the fiat off-ramp's strategic importance?▾
Illicit crypto value must eventually reach spendable form — exchanges, OTC, kiosks, P2P, cards. Off-ramps concentrate detection opportunity: strong KYC and analytics there choke monetisation even when on-chain layering succeeds. Regulation prioritises ramps for exactly this reason.
Q390What crypto knowledge should a traditional AML analyst build first?▾
How transactions and wallets actually work; reading a block explorer; exchange/VASP business models; analytics concepts — clustering, exposure, labels; core typologies (mixers, peel chains, chain-hopping); and the travel rule. Enough to investigate the crypto leg of ordinary cases confidently.
Q391What is address poisoning or dusting in compliance terms?▾
Attackers send tiny amounts from lookalike or tainted addresses to trick users or to 'taint' wallets analytically. Compliance handling: recognise dust as non-consensual exposure, weight scoring accordingly, and avoid penalising customers for value they never solicited or used.
Q392What is the enforcement trend against unregistered crypto businesses?▾
Regulators pursue operating-without-registration aggressively — money transmission charges, AML programme failures, travel-rule breaches — alongside sanctions actions. The message: the perimeter applies regardless of technology labels, and 'decentralised' marketing doesn't immunise controlled businesses.
Q393How would you investigate a customer's deposit flagged for mixer exposure?▾
Quantify the exposure — direct or indirect, proportion, hops; review the customer's profile and history for context; request source explanation with evidence; check for pattern versus one-off; apply policy thresholds for hold, refusal, or filing; and document the analytics evidence with the disposition.
Q394What is the single biggest misconception about crypto and crime?▾
That crypto is untraceably anonymous. Public ledgers made tracing industrial: attribution, clustering, and cross-chain analytics routinely unwind schemes cash would have hidden. The honest statement: pseudonymous rails with permanent records — often better evidence than traditional finance produces.
Q395Where is crypto AML heading in the next few years?▾
Deeper travel-rule interoperability, DeFi perimeter definitions settling on points of control, stablecoin issuer obligations expanding, AI-assisted tracing and typology detection, and convergence of bank and VASP standards as institutions custody digital assets. The specialism is becoming core AML literacy.
Regulations, FATF & Frameworks
Q396What is the FATF?▾
The Financial Action Task Force is the intergovernmental standard-setter for AML/CFT: it issues the 40 Recommendations, evaluates countries' compliance through mutual evaluations, maintains the grey and black lists, and publishes typologies and guidance. National laws worldwide implement its standards.
Q397What are the FATF 40 Recommendations broadly?▾
The global AML/CFT framework: criminalising laundering and terrorist financing; preventive measures for financial institutions and DNFBPs (CDD, record-keeping, reporting); beneficial-ownership transparency; powers for FIUs, law enforcement, and supervisors; international cooperation; and targeted financial sanctions implementation.
Q398What is a FATF mutual evaluation?▾
Peer review assessing a country's technical compliance with the Recommendations and — decisively since the current round — effectiveness across eleven immediate outcomes. Reports drive national reforms; poor results feed the listing process and raise the country's risk profile for institutions.
Q399What are the FATF grey and black lists formally?▾
'Jurisdictions under Increased Monitoring' (grey) have strategic deficiencies with committed action plans; 'High-Risk Jurisdictions subject to a Call for Action' (black — Iran, North Korea, and Myanmar-level cases) trigger enhanced due diligence and, at the extreme, countermeasures. Institutions map both into risk models.
Q400What is the risk-based approach as FATF's core principle?▾
Countries and institutions must identify, assess, and understand their ML/TF risks and apply resources and controls proportionate to them — stronger where risk is higher, permitting simplification where demonstrably lower. It replaced checkbox compliance as the organising philosophy of the entire framework.
Q401What is the BSA in the United States?▾
The Bank Secrecy Act is the foundational US AML statute: it mandates AML programmes, CTRs, SARs, record-keeping, and identification requirements, administered by FinCEN with sector regulators examining compliance. Subsequent statutes — notably the PATRIOT Act and the AML Act of 2020 — build on it.
Q402What did the USA PATRIOT Act add to AML?▾
Post-9/11 expansion: mandatory customer identification programmes (Section 326), correspondent and private-banking due diligence (312), prohibition of shell-bank correspondents (313), special measures against primary laundering concerns (311), and information-sharing mechanisms (314a/b).
Q403What is the AML Act of 2020's significance?▾
The largest US reform in decades: beneficial-ownership reporting through the Corporate Transparency Act, expanded whistleblower incentives, higher penalties, modernisation mandates for FinCEN, effectiveness-focused programme expectations, and extended reach over foreign institutions' records.
Q404What is the Corporate Transparency Act (CTA)?▾
US legislation requiring covered companies to report beneficial owners to FinCEN's registry — attacking anonymous shells at formation. Implementation has seen scope adjustments and litigation, but the direction is clear: ownership transparency as infrastructure, with institution access for CDD.
Q405What are the EU's AML Directives in one view?▾
Successive directives (4AMLD through 6AMLD) harmonised EU rules: risk-based CDD, beneficial-ownership registers, PEP measures, virtual-asset coverage, expanded predicate offences, and criminal-liability harmonisation. The framework now transitions to a directly applicable Regulation with a central supervisor.
Q406What is AMLA (the EU authority)?▾
The new EU Anti-Money Laundering Authority: directly supervising the riskiest cross-border financial institutions, coordinating national supervisors and FIUs, and enforcing the single rulebook under the AML Regulation. It centralises what fragmented national supervision handled unevenly.
Q407What is the EU single rulebook (AMLR)?▾
A directly applicable regulation replacing directive-based divergence: uniform CDD, beneficial-ownership, and reporting rules across member states, plus measures like cash payment limits and harmonised high-risk treatment. For institutions it means one standard instead of twenty-seven interpretations.
Q408What is the UK's AML architecture?▾
The Proceeds of Crime Act (POCA) criminalises laundering with its consent/DAML regime; the Money Laundering Regulations set preventive duties; the FCA and HMRC supervise sectors; the NCA hosts the UKFIU; and OFSI administers financial sanctions. Failure-to-prevent and corporate liability reforms continue tightening it.
Q409What is POCA's practical importance for staff?▾
It creates the principal laundering offences, the personal duty to report suspicion in the regulated sector, tipping-off offences, and the authorised-disclosure (consent) mechanism that governs handling suspect transactions. Front-line obligations in UK institutions trace directly to POCA sections.
Q410What is FinCEN and its counterpart concept globally?▾
FinCEN is the US financial intelligence unit and BSA administrator — receiving reports, issuing rules and advisories, and applying special measures. Every jurisdiction has an FIU counterpart (UKFIU, TRACFIN, AUSTRAC, FIU-IND); the Egmont Group connects them for cross-border intelligence exchange.
Q411What is the Egmont Group?▾
The international network of FIUs enabling secure information exchange, standards, and capacity-building between members. For investigations spanning borders, Egmont channels move intelligence FIU-to-FIU where formal mutual legal assistance would be slower.
Q412What is the Basel Committee's role in AML?▾
Basel issues supervisory guidance integrating ML/TF risk into prudential frameworks — sound management of AML risks, correspondent banking guidance, and expectations that supervisors assess financial-crime controls as part of safety and soundness. It aligns prudential and AML supervision.
Q413What is the Wolfsberg Group?▾
An association of major international banks publishing industry standards: correspondent banking questionnaires (the CBDDQ), guidance on sanctions screening, payment transparency, and programme effectiveness. Not law, but de facto benchmarks regulators and counterparties expect.
Q414What are targeted financial sanctions under FATF Recommendation 6/7?▾
Obligations to freeze without delay assets of persons designated under UN terrorism and proliferation regimes and prohibit making funds available — implemented nationally. They bind AML frameworks to the sanctions machinery, with effectiveness tested in mutual evaluations.
Q415What is proliferation financing?▾
Funding the development or acquisition of weapons of mass destruction — addressed through UN designations (North Korea, Iran programmes) and FATF standards requiring risk assessment and controls. Typologies feature front companies, dual-use goods trade, and deceptive shipping — overlapping heavily with sanctions evasion.
Q416How do data protection laws interact with AML obligations?▾
AML processing has legal bases carved into regimes like GDPR, but tension persists: retention limits versus record-keeping, access rights versus tipping-off, cross-border transfers versus group intelligence sharing. Compliance means mapping both frameworks — 'AML made me' is not an automatic override.
Q417What is the difference between rules-based and principles-based regulation in AML?▾
Rules prescribe specifics — thresholds, timelines; principles state outcomes — 'effective systems and controls' — leaving design to institutions with accountability for results. Modern regimes blend both; the practical skill is evidencing effectiveness, not just rule-checklist completion.
Q418What is an examination or supervisory review like?▾
Regulators test programme reality: risk assessment quality, governance, file sampling across CDD and alerts, SAR decisions, screening validation, data integrity, and remediation of prior findings. Outcomes range from findings letters to enforcement. Preparation is continuous evidence discipline, not pre-visit theatre.
Q419What are 'pillars' of an AML programme in US terms?▾
Internal controls; a designated BSA/AML officer; ongoing training; independent testing; and — the fifth pillar — risk-based customer due diligence including beneficial ownership. Examinations structure findings around these, making them the design skeleton for programmes.
Q420What is Section 311 / special measures?▾
FinCEN authority to designate foreign jurisdictions, institutions, or account types as primary money laundering concerns and impose graduated measures — up to prohibiting US correspondent accounts. It functions as a targeted quarantine, effectively cutting designees off from dollar clearing.
Q421What is the travel rule in traditional payments?▾
Funds-transfer rules requiring originator (and increasingly beneficiary) information to accompany wires above thresholds and persist through the chain — enabling tracing and screening. FATF Recommendation 16 sets the standard; crypto's travel rule extends the same logic to virtual assets.
Q422What are beneficial ownership registry models?▾
Approaches vary: public registers (parts of Europe historically), authority-access registers (the US CTA model), and hybrid regimes — with litigation shaping access balance against privacy. For institutions, registries assist verification but never replace independent CDD.
Q423What is the difference between AML law and regulation and guidance?▾
Law sets offences and core duties; regulation operationalises them with binding detail; guidance interprets expectations without direct force but heavy evidential weight in enforcement. Programmes must track all three layers — 'the guidance isn't law' rarely survives an examination argument.
Q424What is extraterritoriality in AML/sanctions enforcement?▾
Conduct abroad reaching another regime through nexus — dollar clearing, correspondent accounts, nationals, or listed instruments. US enforcement history shows foreign banks penalised for offshore conduct with US touchpoints. Global institutions therefore build to the strictest applicable standard.
Q425What are cash declaration regimes at borders?▾
Travellers must declare currency and instruments above thresholds (commonly ~10,000); non-declaration risks seizure and prosecution. They attack physical placement and courier networks, generating reports FIUs match against financial intelligence.
Q426What is the regulatory view of reliance and outsourcing?▾
Functions can be outsourced; accountability cannot. Institutions must govern providers — due diligence, contracts, oversight, audit rights, exit plans — and regulators examine outsourced KYC/monitoring as if in-house. 'The vendor failed' reads as 'your control failed' in findings.
Q427What is a consent order or DPA in AML enforcement?▾
Settlement instruments: consent orders impose remediation, restrictions, and sometimes monitors; deferred prosecution agreements suspend charges against compliance undertakings and penalties. Both publish detailed failure narratives — free case studies in what regulators punish.
Q428What is an independent compliance monitor?▾
An external overseer imposed by settlement to verify remediation — reviewing programmes, testing, and reporting to authorities for years. Monitorships are costly and intrusive; their prevalence in AML settlements signals how little regulators trust self-certified reform after major failures.
Q429What are FATF's 'immediate outcomes'?▾
Eleven effectiveness measures mutual evaluations score — from risk understanding and international cooperation to supervision, preventive measures, transparency of legal persons, ML investigation and confiscation, and TF/PF sanctions implementation. They shifted evaluation from laws-on-paper to results-in-practice.
Q430What is de-risking from a regulatory perspective?▾
Supervisors and FATF discourage wholesale exit of categories (charities, MSBs, correspondent regions) as risk-management failure displacing rather than reducing risk — harming inclusion and transparency. Expectation: case-by-case risk management with documented decisions, not category refusal.
Q431What global instrument addresses corruption alongside AML?▾
The UN Convention against Corruption (UNCAC) — criminalisation, prevention, asset recovery, and cooperation — complementing AML frameworks: corruption proceeds are core predicate flows, and asset-recovery chapters drive the tracing and repatriation practice PEP controls feed.
Q432What is the Vienna and Palermo convention lineage?▾
The 1988 Vienna Convention criminalised drug-proceeds laundering internationally; the 2000 Palermo Convention (UNTOC) extended laundering offences to organised crime broadly, adding cooperation frameworks. Modern national AML laws descend from these foundations plus FATF standards.
Q433How does terrorist financing regulation differ structurally?▾
Criminalisation targets provision or collection of funds for terrorist acts, organisations, or individuals — regardless of source legality; targeted financial sanctions (UN 1267/1373 lineage) require immediate freezing; and reporting extends to TF suspicion. Detection emphasises networks and destination over origin.
Q434What is Recommendation 8 about?▾
Non-profit organisations: countries must apply focused, proportionate measures to NPOs at demonstrated TF risk — without disrupting legitimate charity. It was revised specifically to curb blanket de-risking; institutions should mirror that proportionality in NPO banking.
Q435What are supervisory expectations on AML technology (models)?▾
Model risk management applies: documented design, validation, tuning governance, data quality controls, and explainability proportionate to use. Regulators encourage innovation — analytics, AI triage — while holding institutions accountable for outcomes and for understanding their own systems.
Q436What is a national risk assessment (NRA)?▾
A country's documented analysis of its ML/TF threats and vulnerabilities — feeding policy, supervision priorities, and institutions' own risk assessments, which are expected to reflect NRA findings. Mutual evaluations test whether risk understanding actually drives action.
Q437What is the difference between suspicion-based and threshold-based reporting regimes?▾
Threshold reports (CTRs, transfer reports) are objective and automatic; suspicion reports require judgement about criminal-property possibility. Mature regimes run both: thresholds generate systematic data trails; suspicion filings contribute analysed intelligence. Institutions need distinct processes and quality standards for each.
Q438What is 'effectiveness' as the current regulatory demand?▾
Evidence that controls change outcomes: risks understood and covered, detection converting to useful intelligence, files enabling action, and feedback improving the system — versus activity metrics like alert counts. Programmes now build measurement to answer 'does it work,' not 'does it exist.'
Q439What laws govern asset freezing versus confiscation?▾
Freezing preserves assets pending process — sanctions or court orders; confiscation permanently deprives via criminal conviction or, increasingly, non-conviction-based forfeiture and unexplained wealth orders. Institutions execute freezes and respond to orders; understanding the sequence aids cooperation and customer handling.
Q440What is an unexplained wealth order (UWO)?▾
A civil instrument (notably UK) compelling persons — often PEPs — to explain the lawful source of specified assets; failure enables recovery proceedings. For AML teams, UWO news is potent adverse media, and the instrument validates source-of-wealth discipline.
Q441How should an institution track regulatory change?▾
Horizon-scanning ownership within compliance: mapped sources (regulators, FATF, FIUs, legislatures), impact assessment against current controls, implementation planning with accountable owners, and governance reporting. Regulatory change management is itself an examinable control.
Q442What is the interplay between prudential and AML supervision?▾
Financial-crime failure is increasingly treated as safety-and-soundness failure: capital and licensing consequences, fit-and-proper actions against executives, and coordinated examinations. The era of AML as a siloed compliance topic is over — boards answer for it as core risk.
Q443What jurisdictional feature most raises AML risk in your assessment?▾
Opacity plus weak enforcement: secrecy in ownership, limited registry access, non-cooperation with information exchange, and low mutual-evaluation effectiveness scores. Formal laws matter less than whether authorities can and do act — effectiveness ratings capture that better than statutes.
Q444What is the practical difference between FATF standards and local law for your daily work?▾
Local law binds you — offences, thresholds, deadlines, and consent mechanics come from national statute. FATF explains the architecture and predicts where local law is heading. I work to the letter of my jurisdiction while reading FATF to understand the why and the next.
Q445A regulator asks why your programme is 'effective.' Your answer structure?▾
Risk assessment shows we know our exposure; control mapping shows coverage against it; outcome evidence shows detection converting to quality filings, remediation, and exits; testing and QA show independent verification; and feedback loops show the system learning. Then I hand over the metrics pack that proves each sentence.
Q446What is MiCA and why does it matter beyond the EU?▾
The EU's Markets in Crypto-Assets Regulation licenses crypto-asset service providers and stablecoin issuers with conduct, prudential, and AML-adjacent duties. It matters globally because it is the first comprehensive regime major firms structure around — a de facto template other jurisdictions benchmark.
Q447What is the difference between an FIU disclosure and mutual legal assistance (MLA)?▾
FIU-to-FIU exchange (via Egmont) moves intelligence quickly for analysis; MLA moves evidence through formal treaty channels for use in prosecution — slower, compelled, and admissible. Investigations often start on FIU intelligence and convert to MLA when cases head to court.
Q448What are 'gatekeeper' reforms in AML regulation?▾
Extending obligations to professionals who enable structures — lawyers, accountants, company formation agents, and increasingly investment advisers — closing the gap where enablers faced lighter duties than banks. Recent US and EU reforms both move this direction.
Q449What is the practical effect of a country being FATF-blacklisted for your institution?▾
Mandatory enhanced due diligence on all connected business, likely countermeasures — restrictions or prohibitions per national implementation, appetite decisions often barring new exposure, and heightened monitoring of any residual flows. Practically, business with such jurisdictions becomes exceptional and heavily governed.
Q450How do you answer 'which regulation matters most' in an interview?▾
The one governing the role's jurisdiction — I anchor on local law (BSA/POCA/PMLA as applicable), then show architecture awareness: FATF standards above it, sanctions regimes beside it, and sector guidance beneath it. Depth locally, fluency globally is the combination employers want.
Scenarios & Judgement
Q451A customer deposits $9,500 cash three days in a row. Walk me through your thinking.▾
The pattern sits just under the $10,000 reporting line — classic structuring shape. I'd check the profile: does cash of this scale fit their business or income? Review history for similar bursts, look for related accounts doing the same, and escalate toward a SAR if no legitimate explanation emerges. Structuring is reportable regardless of the funds' origin.
Q452A student account receives $40,000 from an unknown company and forwards it within hours. What do you do?▾
This is textbook mule behaviour: profile mismatch, unknown remitter, rapid pass-through. I'd restrict pending review, examine the source and destination, check device and login changes suggesting account sale or takeover, screen counterparties, and escalate for filing. Speed matters — the account is likely mid-scheme.
Q453A restaurant's card revenue is flat but cash deposits doubled. Your analysis?▾
Cash growth without matching business signals — same hours, staff costs, card mix — suggests commingling. I'd benchmark against sector norms, compare seasonal history, review deposit denominations and timing, and ask for an explanation via a neutral RFI. If growth can't be evidenced, this is front-company placement and I escalate.
Q454A long-standing corporate suddenly starts wiring to a new jurisdiction weekly. Reaction?▾
New corridor plus new counterparty is an event trigger, not automatically suspicion. I'd verify the business rationale — new supplier, expansion — against documentation like contracts or invoices, screen the counterparty, check the jurisdiction's risk, and update expected activity if verified. Unverifiable or implausible rationale escalates.
Q455You find a sanctions true match on an outgoing payment already in the queue. Steps?▾
Stop the payment immediately — the hold outranks everything. Confirm the match on full identifiers with the sanctions team, block or reject per the regime, file the regulatory report within deadline, review the customer's other activity and accounts for exposure, and manage communications carefully to avoid tipping.
Q456A relationship manager asks you to 'go easy' on a VIP's alerts. Response?▾
I investigate exactly as I would any customer and document the approach — then I report the interference itself, because pressure to soften scrutiny is a governance red flag regulators specifically look for. Protecting the VIP pipeline is not my job; protecting the institution is.
Q457Mid-review, the customer calls asking why their transfer is delayed. What do you say?▾
Neutral service language only: the payment is undergoing standard processing checks and we'll update them shortly. I never mention reviews, compliance, or reports — tipping off is a criminal offence. Then I note the contact in the case, since urgency or probing can itself be an indicator.
Q458You inherit a backlog of 300 aged alerts. Day-one plan?▾
Triage by risk, not age alone: sanctions-adjacent and high-value flow-through first, dormant low-value noise last. Quantify and report the backlog honestly, request surge support, identify the scenarios generating the noise for tuning, and set documented daily throughput. Hiding or bulk-closing a backlog converts a resourcing problem into misconduct.
Q459An alert closes cleanly, but something feels off. What do you do with a hunch?▾
Interrogate it: a hunch is usually a pattern I haven't articulated yet. I'd expand the review window, pull counterparty networks, and check adjacent accounts. If the facts still support closure, I close with full documentation. If the hunch converts to articulable facts, it escalates. Feelings don't file SARs — but they do justify one more look.
Q460A charity sends funds to a conflict-adjacent region. How do you balance vigilance and fairness?▾
FATF explicitly warns against de-risking legitimate NPOs, so I assess this charity, not the category: programme records, local partners' identities, delivery evidence, and whether flows match declared operations. Vigilance means verifying the specifics; fairness means not punishing geography alone.
Q461Your monitoring system misses a pattern a journalist later exposes. What now?▾
Immediate lookback on the exposed pattern, late filings where suspicion stands, root-cause analysis — scenario gap, data gap, or tuning error — remediation with governance visibility, and honest regulator engagement. The failure is survivable; concealing it is not.
Q462A new fintech partner will bring 50,000 customers via API onboarding. Concerns?▾
Whose CDD standard applies and can I evidence it? I'd review the partner's onboarding controls, sample their files, define reliance contractually with audit rights, ensure screening runs on our side too, and monitor the cohort distinctly at launch. Growth through partners imports their control quality — verify before scale.
Q463Two customers, unrelated on paper, share a device and beneficiary. Significance?▾
Shared infrastructure is network evidence: possible mule cohort or synthetic identities under one controller. I'd expand the link analysis — addresses, IPs, timing patterns — treat them as one investigation, and quantify the combined flows. Individually innocent-looking accounts often become obvious as a set.
Q464The business wants to launch instant payments in 6 weeks. Compliance ask?▾
Pre-launch: inline screening capability, real-time risk scoring for holds, mule-detection on receiving accounts, recall procedures, and a scenario set adapted to zero-settlement-delay. If controls can't be ready, I say so with specifics — launching crime-speed rails with batch-speed controls is a known enforcement pattern.
Q465A customer's explanation is plausible but unverifiable. Decision time.▾
Plausibility without evidence gets weighed against risk: amount, pattern, profile fit, and history. For low-risk activity, documented plausibility may suffice. For high-risk patterns, unverifiable means unresolved — I'd restrict or escalate rather than accept. The standard is reasonable grounds, and I document which side this falls on and why.
Q466You spot a colleague overriding screening hits without documentation. Action?▾
Raise it immediately through compliance or whistleblowing channels with specifics — dates, cases, patterns. Undocumented overrides are how sanctions breaches and suppressed suspicion happen, and staying silent makes me part of the control failure. I'd do it factually, not accusatorially: the record speaks.
Q467An exam is next month and your team's files have known gaps. Approach?▾
No backfilling theatre: prioritise genuine remediation of the riskiest gaps, document honestly what's fixed and what's in flight with dates, and prepare the narrative — root cause, plan, progress. Examiners forgive found-and-fixing; they punish concealment and surprise.
Q468A payment references 'consulting services' between two shells you can't verify. Call?▾
Vague services plus opaque parties equals classic layering cover. I'd attempt verification — registries, web presence, contracts via RFI — and absent substance, treat the invoice as decorative: escalate with the pattern documented. 'Consulting' explains nothing when neither consultant nor client demonstrably exists.
Q469Your model flags 3x more alerts after an update. First moves?▾
Diagnose before drowning: compare rule-level volumes pre/post, identify which scenarios spiked, sample the new alerts for quality, and check whether a data change — not behaviour — drove it. Then either fix the defect or resource the genuine increase. Silently absorbing bad tuning creates tomorrow's backlog.
Q470How would you exit a suspected mule without tipping them off?▾
Standard commercial closure: notice per terms, neutral reason codes, funds handled per policy and legal advice, no reference to reviews or reports. File the SAR first or in parallel, record the exit rationale internally, and flag identifiers for re-onboarding prevention. The customer experiences an ordinary closure; the record shows the truth.
Q471A regulator RFI asks about a customer you exited last year. Confidence check.▾
This is where file quality pays: I'd retrieve the case — chronology, evidence, filing decision, exit rationale — and respond within scope through authorised channels. If the record is complete, the answer writes itself. If gaps exist, I say what we know, what we don't, and what we've changed.
Q472New corridor: your bank enters a high-risk market for remittances. Programme changes?▾
Corridor-specific risk assessment first, then: tightened agent/partner due diligence, corridor-tuned scenarios and thresholds, sender-beneficiary network analytics, enhanced sampling early, and defined triggers for re-evaluation. Enter with controls designed for the corridor's actual typologies, not the generic set.
Q473A customer asks which transactions trigger your reports. Answer?▾
I don't disclose control specifics — thresholds, scenarios, or reporting logic — ever. Externally that's polite deflection: we apply regulatory requirements and can't discuss internal processes. Disclosing detection logic is a roadmap for evasion and can constitute tipping off.
Q474Funds hit your bank from an exchange hack, three hops away. Obligations?▾
Three hops is indirect exposure: quantify proportion and path via analytics, check whether any leg touches designated addresses (that changes everything), review the receiving customer's story and profile, and decide on freeze, return, filing, or clearance per policy and legal advice. Distance dilutes but doesn't erase the question.
Q475Your scenario library hasn't changed in three years. Risk?▾
Criminal method drift: instant payments, mule industrialisation, crypto ramps, and AI-enabled fraud all postdate the library. I'd run a coverage assessment against current typologies and advisories, below-the-line test for blind spots, and establish a governed refresh cycle. Static detection is decaying detection.
Q476Board asks: 'Are we safe from a big AML fine?' Your honest answer shape?▾
No absolute assurances — I'd present residual risk honestly: where our controls are strong, where gaps and remediation stand, how we compare to enforcement patterns, and what investment changes the curve. Boards are safest when told the truth with a plan, not comforted into surprise.
Q477A politically sensitive PEP requests onboarding with excellent documents. Proceed?▾
Documents being excellent is neutral — PEP onboarding is a senior-approval, EDD decision: source of wealth corroborated independently, adverse media in depth, purpose and expected activity nailed down, and appetite consulted. If everything verifies, proceed with enhanced monitoring; prominence alone isn't a bar, and glossy paperwork alone isn't a pass.
Q478Alert volume drops 60% after a data migration. Good news?▾
Suspicious news. I'd verify pipeline integrity first: are transactions, customer attributes, and mappings flowing correctly? Compare scenario-level volumes, run known-pattern test cases, and below-the-line sample. Migrations that 'improve' metrics usually broke the feed — celebrate only after proving detection still works.
Q479You disagree with your MLRO's decision not to file. Options?▾
Make my case once more with the specific facts, in writing. The decision is theirs by design — if they maintain it with documented rationale, that's governance working. If I believe the decline is improper or pressured, escalation and whistleblowing channels exist. What I don't do is silently disown my own analysis.
Q480A vendor pitches an AI tool promising 80% alert reduction. Questions?▾
Reduction of what — noise or detection? I'd ask for validation methodology, false-negative testing, explainability for regulators, data requirements versus our quality, model governance fit, and reference outcomes. Alert reduction is trivially achievable by missing crime; the number that matters is risk coverage.
Q481Cash-intensive client refuses digital records citing 'tradition.' Judgement?▾
Tradition explains preference, not opacity at scale. I'd assess verifiability by other means — tax filings, supplier records, site visits — and whether declared volumes hold together. Cooperation matters: partial verification with good faith may sustain the relationship under enhanced monitoring; refusal that defeats due diligence heads toward exit.
Q482You receive a keep-open request but the account keeps receiving fraud proceeds. Tension?▾
Real tension: cooperation versus facilitating harm and losses. I'd honour the request through governance with strict parameters — monitoring intensity, loss thresholds, victim-impact review, defined checkpoints — and escalate back to the requesting agency when parameters breach. Cooperation has documented limits, not blank cheques.
Q483A merger lands you 20,000 unremediated KYC files. Strategy?▾
Risk-tier the book fast using available data; remediate high-risk first with hard deadlines; interim controls — monitoring intensity, restrictions — for the unremediated tail; honest regulator communication with the plan; and exit paths for non-cooperators. Acquired risk is owned risk from day one; the plan proves control.
Q484An internal auditor challenges your alert closures as too brief. Response?▾
I'd review their sample openly — if reasoning lives in my head but not the record, they're right, and I'd tighten documentation standards. If the files do support the closures, I'd walk them through the methodology. Audit friction is cheap; the same finding from a regulator is expensive.
Q485A customer's crypto exchange deposits spike during a bull market. Suspicious?▾
Market context is a legitimate explanation hypothesis — retail activity rises in rallies. I'd test proportionality: does scale fit their declared involvement and wealth? Are counterpart exchanges regulated? Any high-risk exposure in analytics? Bull markets explain enthusiasm, not source-of-funds anomalies.
Q486Payments flow in from dozens of elderly senders to one 'consultant.' Reading?▾
Reads as romance/investment scam consolidation — the account holder is either perpetrator or first-hop mule. I'd map the sender network and amount patterns, look for scripted references, restrict pending review, and file with fraud-team coordination. Victim-pattern inflows are among the most consequential filings we make.
Q487Your institution wants to bank a licensed casino. Programme implications?▾
Appetite decision plus tailored controls: the casino's own AML programme quality becomes my due diligence subject — chip/redemption controls, junket exposure, source-of-funds practices. Ongoing monitoring watches settlement patterns against declared volumes. High-risk sectors are bankable when the customer's controls and our oversight both hold.
Q488One transaction is fine; a thousand like it aren't. Explain.▾
Individually explainable behaviour becomes a scheme through aggregation — the structuring principle. A single sub-threshold deposit is a Tuesday; hundreds across accounts with shared attributes is placement infrastructure. It's why entity resolution and network views matter: crime hides in the sum, not the unit.
Q489What would you do in your first 30 days in this AML role?▾
Learn the risk assessment, policies, and appetite; sit with the systems — scenarios, screening, case tools; sample recent cases and filings to absorb the quality bar; map escalation paths and stakeholders; and take a starter caseload with review. Goal: contributing safely by week two, credibly by week four.
Q490Your biggest strength and weakness for AML work?▾
Strength: pattern discipline — I follow flows and document as I go, so my conclusions survive review. Weakness: I can over-investigate borderline cases; I've learned to timebox, state the decision standard early, and escalate rather than perfect. The role needs judgement under uncertainty, not certainty.
Q491Why AML, genuinely?▾
It's investigative work with stakes: the money trails connect to trafficking, fraud victims, and corruption, and good analysis actually feeds enforcement. I like that the craft is defensible reasoning — evidence to conclusion in writing — and that the field keeps evolving through crypto, sanctions, and AI. It rewards curiosity with consequence.
Q492Describe a time you handled ambiguity under deadline (frame for AML).▾
Structure beats panic: define the decision needed, gather what's obtainable in the window, state assumptions explicitly, decide at the standard required — reasonable grounds, not certainty — and document what would change the call. Then revisit when the missing facts arrive. Interviewers want the method, not heroics.
Q493How do you handle repetitive alert work without quality decay?▾
Systems over willpower: checklists that force the full review path, self-QA sampling of my own closures, rotation across scenario types, and treating each alert's narrative as practice for the SAR that might follow. Boredom is a control risk — I manage it like one.
Q494An interviewer asks you to critique their public enforcement action. Approach?▾
Respectfully and specifically: summarise the failure pattern the action documents — say, monitoring thresholds tuned for noise over risk — then what I'd have flagged earlier and which controls prevent recurrence. It shows I read enforcement as curriculum, which is exactly what the role rewards.
Q495Salary aside, what makes you stay in an AML team long-term?▾
Casework that reaches conclusions, tuning influence so findings improve detection, management that defends escalations, investment in tooling and training, and visible impact — filings that matter, exits that stick. Analysts leave theatres; they stay where the work is real.
Q496A scenario: everything checks out, but the business model makes no economic sense. Weight?▾
Heavy weight. Documentation can be manufactured; economics can't be faked indefinitely. If the declared margins, volumes, or purpose don't survive commercial logic — why would anyone run this business this way? — that's grounds to dig regardless of clean paperwork. Absence of sense is presence of risk.
Q497Final scenario: you must explain 'why AML matters' to a new graduate in one minute.▾
Every laundered dollar is a crime that paid: trafficking, fraud, corruption made profitable. Our controls decide whether the financial system is the crime's obstacle or its instrument. The work is following money with evidence and judgement — and when it's done well, real investigations start from what we write.
Q498How do you prepare for an AML interview itself?▾
Master the fundamentals cold — stages, CDD/EDD, SAR standards, sanctions versus AML; rehearse scenario answers aloud in the investigate-decide-document structure; know the employer's sector typologies; and prepare two intelligent questions about their programme. Then practise delivery under pressure — knowing and articulating are different skills.
Q499What question should we have asked you, and answer it.▾
'What would you fix first in most AML programmes?' Data quality. Monitoring, screening, and analytics all inherit their ceilings from customer and transaction data — fixing attributes, resolution, and lineage lifts every control at once. It's unglamorous, which is exactly why it's usually the highest-return gap.
Q500Give your 30-second pitch for an AML analyst role.▾
I investigate with structure: profile first, flows second, hypotheses tested against evidence, and conclusions written so a reviewer reaches them independently. I know the typologies, respect the legal edges — tipping off, confidentiality, strict-liability sanctions — and I close or escalate with documented reasoning. And I practise the craft out loud, not just on paper.
How to prepare for an AML interview with these questions
AML interviews follow a predictable arc: concepts → process → judgement. Interviewers open with fundamentals (the three stages, AML vs CFT, red flags), move into your process (how you investigate an alert, when unusual becomes suspicious, how you write a SAR), and finish with scenarios that test decision-making under ambiguity. The 500 questions above are organised to match that arc — and the scenario category at the end is where offers are won or lost.
A preparation plan that actually works
Week 1: Fundamentals, KYC/CDD, and Monitoring — these carry most entry and mid-level interviews. Week 2: SAR/STR, Sanctions, and Typologies — where candidates separate themselves; interviewers love the sanctions-versus-AML distinction and SAR narrative quality. Week 3: Investigations, Crypto, Regulations, and Scenarios — then rehearse answers aloud, timed to 45–60 seconds each. Structure every scenario answer the same way: investigate → decide → document.
By role: what to emphasise
AML/Transaction Monitoring Analyst: monitoring red flags, alert investigation process, structuring, mule patterns, alert-closure documentation. Investigator/EDD: flow-of-funds reconstruction, typologies, OSINT, case files, testing the innocent explanation. Sanctions roles: the 50% rule, blocking vs rejecting, screening dispositions, strict liability. Compliance Officer/MLRO track: programme pillars, risk assessments, SAR decision governance, regulator conversations, effectiveness.
AML interview questions: FAQs
How should I use these 500 questions?
Category by category, weak areas first. Read the model answer, then practise your own version out loud in 30–60 seconds — spoken fluency is what interviews measure.
Is this suitable for freshers?
Yes — Fundamentals, KYC/CDD, and Monitoring cover entry-level interviews, while Investigations, Sanctions, Crypto, and Scenarios serve experienced candidates. Behavioural questions are included in the Scenarios category.
What do AML interviews focus on most?
The three stages, KYC/CDD/EDD, monitoring red flags, SAR standards, sanctions-vs-AML — plus at least one judgement scenario like the classic “$9,500 deposits three days running.”
How is an AI mock interview different from reading Q&As?
Reading builds knowledge; speaking under pressure builds performance. The AI interview asks by voice, scores your spoken structure and content, and shows where delivery loses marks — before a real interviewer sees it.
Now practise these answers out loud — with an AI interviewer
AGZIT's AI voice interview asks you real AML questions, listens to your answers, and scores your structure, content, and clarity — so you find your weak spots here, not in the real interview. Your first AI mock interview is free.
Start your free AI mock interview →No card needed for your first session · 20-minute voice interview · instant scorecard
