Free CAMS Exam Flashcards
Memorize 50 essential terms and definitions for the CAMS - Certified Anti-Money Laundering Specialist. See the term, recall the definition, then flip to check yourself.
Placement
First of the three classic money laundering stages. Illicit cash first enters the financial system through deposits, currency exchanges, or purchases. Highest-risk stage for the launderer because cash is most visible to controls at this point.
Filter by Topic
Jump to Card
About These CAMS Flashcards
These 50 flashcards are designed to help you memorize key terms and definitions for the CAMS - Certified Anti-Money Laundering Specialist. Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.
Topics Covered
Complete Flashcard Reference
Review every term in this set. Open any term to reveal its definition.
Placement
First of the three classic money laundering stages. Illicit cash first enters the financial system through deposits, currency exchanges, or purchases. Highest-risk stage for the launderer because cash is most visible to controls at this point.
Layering
Second money laundering stage. Funds are moved through layers of accounts, jurisdictions, and instruments to sever the audit trail from the source. The goal is distance, not profit, which is why many layering transactions have no economic logic.
Integration
Third and final money laundering stage. Laundered funds re-enter the legitimate economy as apparent wealth - real estate, business equity, or luxury assets. Funds appear clean unless investigators connect them back to placement and layering.
Smurfing vs Structuring
Both break transactions to evade reporting thresholds. Smurfing uses multiple couriers (smurfs) to deposit small amounts across banks and days. Structuring is the broader pattern of splitting transactions and can be done by one person - smurfing is one technique within structuring.
Predicate Offense
The underlying criminal activity that produces illicit proceeds. Money laundering requires a predicate - without one, money is simply being moved, not laundered. Predicate lists differ by jurisdiction but commonly include drug trafficking, fraud, bribery, and tax evasion.
Specified Unlawful Activity (SUA)
The US statutory list of predicate crimes that trigger federal money laundering charges. Examples include narcotics trafficking, wire fraud, bribery, and certain terrorist financing. SUA status matters because laundered funds tied to an SUA can be forfeited.
WMD Proliferation Financing
Providing funds or financial services that support weapons of mass destruction programs. Treated as a distinct financial crime alongside money laundering and terrorist financing in FATF guidance and in targeted sanctions regimes.
KYC (Know Your Customer)
The broad process of identifying a customer, understanding their activity, and assessing their risk. KYC is the umbrella term - CDD is the regulatory mechanism that implements it. KYC is not a one-time form; it must remain current.
CDD (Customer Due Diligence)
The regulatory standard for knowing your customer. CDD has four FATF elements: identifying the customer, identifying the beneficial owner, understanding purpose and nature of the relationship, and ongoing monitoring. CDD applies to all customers, not only high-risk ones.
CIP (Customer Identification Program)
The US requirement under the USA PATRIOT Act for every financial institution to verify the identity of every customer at account opening. CIP is the identity-verification step that precedes broader CDD - it captures name, date of birth, address, and identification number.
Beneficial Ownership
The natural person who ultimately owns or controls a customer, even when the customer is a legal entity. FATF requires identifying any individual owning 25% or more. The point is to see past shell companies and nominee directors to the human at the end of the chain.
Customer Risk Rating
The output of segmenting customers by inherent risk (high, medium, low) to apply proportional controls. High-risk customers get EDD; low-risk get simplified due diligence. The rating drives monitoring frequency and escalation thresholds, so a wrong rating propagates risk downstream.
EDD (Enhanced Due Diligence)
A higher level of customer due diligence applied to high-risk customers such as PEPs, shell-bank relationships, and customers tied to high-risk jurisdictions. EDD means more information, senior approval, and ongoing review - not a one-time deep dive at onboarding.
PEP (Politically Exposed Person)
A person who holds or has held a prominent public function, plus their close associates and family. PEPs warrant EDD because their position creates opportunity for corruption and bribery. The risk does not end with the office; it diminishes over time but is not zero.
Shell Bank
A bank that has no physical presence in any country and is not regulated by an authority. US law prohibits domestic banks from maintaining correspondent accounts for shell banks. The risk is that shell banks have no supervisory check and act as conduits for anonymous funds.
Correspondent Banking Risk
A relationship where one bank provides services to another bank, often cross-border. Higher AML risk because the respondent bank's customers are not the correspondent bank's customers - the correspondent must rely on the respondent's due diligence, which may be weaker.
OFAC (Office of Foreign Assets Control)
The US Treasury agency that administers and enforces economic and trade sanctions. OFAC publishes the SDN list and other sanctions lists; US persons are prohibited from dealing with listed parties, and assets of listed parties must be blocked.
SDN List (Specially Designated Nationals)
OFAC's list of individuals and entities owned or controlled by sanctioned parties. A US financial institution must freeze the assets of an SDN and report the block to OFAC. Payment of any kind to an SDN is prohibited, even if the institution did not know the party was listed.
Embargoes
Comprehensive trade or financial restrictions imposed on an entire country or region. Unlike targeted sanctions on individuals, embargoes block broad categories of transactions and require screening against the country itself, not just named parties.
UN Sanctions Resolutions
Sanctions imposed by UN Security Council resolutions that bind all member states. They are the legal basis for many national sanctions programs and typically list individuals and entities tied to terrorism or proliferation.
Asset Freezing vs Seizure
Freezing prevents funds from being moved or used but does not transfer ownership. Seizure takes control of the asset, and forfeiture transfers title. AML programs trigger freezing when sanctions hit; seizure and forfeiture are law-enforcement acts that follow.
SAR vs STR
SAR (Suspicious Activity Report) is the US term filed with FinCEN; STR (Suspicious Transaction Report) is the international term used by FATF and most other jurisdictions. Same concept, different jurisdiction and filing portal.
30-Day SAR Filing Deadline
Under the Bank Secrecy Act, a bank must file a SAR within 30 calendar days of initial detection of facts that may form a basis for filing. The clock starts at detection, not at confirmation - delay beyond 30 days is a violation unless the no-suspect extension applies.
60-Day No-Suspect Extension
When no suspect is identified on the detection date, a bank may delay SAR filing up to 60 calendar days to identify a suspect. The extension is conditional - if no suspect is found, the SAR must still be filed by day 60, not abandoned.
Tipping-Off
Disclosing to a customer (or third party) that a SAR has been filed or that they are under investigation. Tipping-off is a criminal offense in most jurisdictions because it undermines the value of the report - the subject would simply change methods.
FinCEN 314(a) vs 314(b)
314(a) is a mandatory information request from law enforcement asking banks to search records for a named suspect; banks must respond. 314(b) is a voluntary information-sharing program between financial institutions about suspected terrorist financing or money laundering; participation is optional but provides safe harbor.
FATF (Financial Action Task Force)
The intergovernmental body that sets global AML, CFT, and CPF standards. FATF issues the 40 Recommendations, monitors compliance through mutual evaluations, and lists high-risk jurisdictions. It is not a regulator - it sets expectations that member countries implement.
FATF 40 Recommendations
The foundational global AML/CFT standards covering legal frameworks, supervisory regimes, preventive measures, and international cooperation. They are the source of the CDD, beneficial ownership, SAR, and risk-based approach expectations that national laws implement.
FATF Grey List vs Black List
The grey list (jurisdictions under increased monitoring) flags countries with strategic AML/CFT deficiencies that have committed to reform. The black list (call for action) names jurisdictions with serious deficiencies where enhanced due diligence applies. Both create reputational and access pressure, not legal bans per se.
Egmont Group
The network of Financial Intelligence Units (FIUs) that exchange operational information securely. It is the practical channel for cross-border SAR/STR cooperation - without Egmont, FIUs would rely on slower formal mutual legal assistance.
Wolfsberg Group
An association of global banks that develops industry guidance for AML, KYC, and counter-terrorist financing. Wolfsberg principles - such as the Principles for Correspondent Banking - are private-sector standards, not laws, but they shape bank practice and supervisory expectations.
Three Lines of Defense
The governance model for AML: first line is business owners who own the risk and apply controls; second line is compliance and risk management who set standards and challenge the first; third line is independent audit. Conflating them (e.g., audit setting policy) breaks the model.
BSA Officer / MLRO
The designated individual responsible for the AML program - the BSA Officer in the US, the Money Laundering Reporting Officer internationally. They file SARs, oversee training, report to the board, and are the contact point for regulators. The role requires sufficient authority and independence.
Risk Appetite
The amount and type of financial-crime risk an institution is willing to accept to pursue its strategy. Risk appetite is set by the board and cascaded into thresholds, customer acceptance rules, and monitoring sensitivity. Operations that exceed appetite must be escalated, not absorbed quietly.
Independent Audit
The third line of defense: a function independent of compliance and business lines that tests AML controls for design and operating effectiveness. Independent audit reports to the board or audit committee - reporting to the BSA Officer would create a conflict because audit is supposed to challenge them.
Board and Senior Management Reporting
AML programs must keep the board and senior management informed of risk, issues, SAR filings, and program effectiveness. Reporting is not informational only - the board approves the program, sets risk appetite, and is accountable when oversight fails.
Enterprise Risk Assessment (ERA)
The institution-wide assessment of inherent AML risk across products, customers, geographies, and channels. The ERA output drives the risk-based allocation of controls. An ERA that has not been updated in years is a finding, not a saved cost.
Risk-Based Approach
Allocating AML controls in proportion to assessed risk so that higher-risk customers and activity receive more scrutiny. FATF endorses the risk-based approach - it is not a permission to do less, it is the requirement to justify the level of controls by risk.
Inherent vs Residual Risk
Inherent risk is the gross risk before controls; residual risk is what remains after controls are applied. The gap between them measures control effectiveness. A program that reports only residual risk without inherent context hides whether controls are actually reducing risk or just keeping up appearances.
Transaction Monitoring
The system and process of reviewing customer transactions against rules, scenarios, and thresholds to detect activity inconsistent with expected behavior. Alerts are not findings - they are leads that must be investigated, escalated, or cleared with a documented rationale.
Look-Back Reviews
A scoped re-examination of historical transactions after a control failure, sanctions update, or methodology change. Look-backs identify missed SARs and quantify the gap - they are typically mandated by regulators but can be self-initiated after self-identification of a gap.
Suspicious Activity Investigation
The workflow of triaging an alert, gathering context, and deciding whether to file, close, or escalate. Quality turns on documentation: every cleared alert needs a rationale, not just a closure code. If the activity is suspicious and the threshold is met, file - do not assume someone else did.
Trade-Based Money Laundering (TBML)
Moving value through trade transactions by over- or under-invoicing goods across borders. TBML is hard to detect because each transaction looks like legitimate commerce - the laundering hides in the gap between invoice and true value.
Virtual Asset Laundering
Using crypto, virtual asset service providers (VASPs), and chain-hopping to move and obscure illicit value. The FATF Travel Rule extends messaging requirements to VASPs, and blockchain analytics tools screen addresses against sanctions and illicit-finance labels.
Real Estate Laundering
Using property purchases to place or integrate illicit funds, often through shell companies, loans from related parties, or cash-intensive down payments. Real estate is attractive because it stores large value in a tangible asset and registration opacity can mask ownership.
Cash-Intensive Business Risk
Businesses with naturally high cash volumes - restaurants, car washes, casinos, parking - can co-mingle illicit cash with legitimate receipts. The risk is not that the business exists; it is that cash volume becomes the laundering explanation, so controls must baseline expected cash receipts.
Blockchain Screening
Tools that match virtual asset addresses against sanctions lists, illicit-finance labels, and cluster attribution. Screening is not blockchain-wide enforcement - it identifies exposure at the touchpoint where virtual assets convert to fiat or move through a regulated VASP.
AI/ML in AML
Machine learning applied to alert generation, triage, and risk scoring. AI can reduce false positives and surface non-obvious patterns, but regulators expect model validation, explainability, and human oversight. A model that files fewer SARs without an auditable rationale is a liability, not a cost saving.
Model Validation
Independent testing of an AML model's conceptual soundness, data inputs, and ongoing performance. Validation must be performed by parties independent of model development - a developer marking their own homework fails the test. Findings must be remediated, not just noted.
Perpetual KYC
Continuous re-evaluation of customer risk and profile rather than a periodic refresh cycle. Triggered by events (adverse media, sanctions hit, behavior change) and fed by monitoring data. Perpetual KYC closes the gap where a static 3-year review misses changes happening between cycles.
Frequently Asked Questions
What is the format of the CAMS exam?
The current CAMS exam has 120 multiple-choice and multiple-selection questions and a 3.5-hour time limit. ACAMS states the passing score is 75 and that there is no penalty for guessing.
What are the four CAMS domains and their weights?
The current ACAMS handbook lists four domains: Understanding the Risks and Methods of Financial Crime (30%), Global AFC Frameworks, Governance, and Regulations (20%), Building an Anti-Financial Crime Compliance Program (30%), and Tools and Technologies to Fight Financial Crime (20%).
What are the eligibility requirements for CAMS?
ACAMS requires active membership and 40 eligibility credits before a candidate can sit. Credits can come from education, professional AFC/AML experience, and training. Candidates receive six months to schedule and sit after authorization.
How is the CAMS exam delivered and scored?
CAMS is delivered by Pearson VUE at a test center or through eligible online proctoring. Pass or fail results are given immediately at the conclusion; ACAMS does not release results by phone, fax, or email.
What is the CAMS retake policy?
Retake waiting periods are 30 days after a first failure, 60 days after a second failure, and 90 days after a third and subsequent failures. A retake authorization fee applies.
How long is the CAMS credential valid?
CAMS is valid for three years. Recertification requires maintaining active ACAMS membership and meeting the published continuing education and other recertification requirements.
Explore More ACAMS Financial Crime Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.