- | P a g e
CERTIFIED AML FINTECH COMPLIANCE
ASSOCIATE (CAFCA) NEWEST 2025 ACTUAL
EXAM COMPLETE 200 QUESTIONS AND
CORRECT DETAILED ANSWERS (VERIFIED
ANSWERS) |ALREADY GRADED A+
What are the three lines of defense in AML compliance? - ANSWER-The first line of defense is the line of business. The second line of defense is the compliance and internal control functions. The third line of defense is internal audit.
What is meant by a "four-eyes check" during onboarding? - ANSWER-To ensure proper checks are performed, a second person might review the file. This is also known as employing "dual controls."
What are dual controls? - ANSWER-In the prevention of financial crime, dual controls can be applied during CDD (customer due diligence) to ensure it is performed correctly.
Why is it important for the second line of defense to be independent from the business line? - ANSWER-To be empowered to obtain access to information throughout the 1 / 4
- | P a g e
organization, conduct investigations of possible breaches, and freely express and disclose findings to senior management.
Describe the responsibilities of the money laundering reporting officer (MLRO). - ANSWER-Ensuring that the organization's AML/CFT efforts are effectively designed and implemented, handling inquiries, determining whether SARs require reporting to authorities, and overseeing training.
For optimal effectiveness, who should perform an organization's audit? - ANSWER-The audit should be independent, that is, performed by people not involved with the organization's AML/CFT compliance staff. The audit team should report directly to the board of directors or a designated board committee of outside directors.
What is an organization's risk appetite? - ANSWER-Risk appetite determines the type of customer it will accept, the type of product it will offer, and the jurisdictions in which it will do business.
Why should customer risk assessments be dynamic and capable of revision over time? - ANSWER-Customer risk can change during the business relationship. Organizations need a current 2 / 4
- | P a g e
understanding of customer risk so they can apply due diligence and ongoing monitoring.
For any financial institution, who should receive ongoing AML training? - ANSWER-An organization's employees and third parties, such as contractors and agents.
How can a FinTech prepare for a successful audit? - ANSWER- Plan in advance, ensure staff availability, ensure documentation is correct and up to date, address potential issues on an ongoing basis throughout the year, and fully understand the audit scope.
What are two sources of internal risk in a FinTech? - ANSWER- The organization's employees and internal processes
Aside from the legal requirement, why is good recordkeeping important to FinTechs? - ANSWER-It could help to defend your organization against a money laundering or a terrorist financing offense. It also supports law enforcement agencies to fight financial crime.
With whom can financial institutions share customer data? - ANSWER-Data you hold about a customer should be shared 3 / 4
- | P a g e
only with others who need to know. Many jurisdictions have privacy and data security laws and regulations that apply to financial institutions.
What is the advantage of independently collecting customer information in addition to customer-completed digital forms? - ANSWER-It can be more reliable and less prone to fraud and manipulation.
Name some common red flags when onboarding customers. - ANSWER-Customers who are overly evasive, provide documents that appear to be false, are linked to high-risk or sanctioned jurisdictions, are PEPs or affiliated with PEPs, and are subjects of adverse media.
When does name screening typically take place? - ANSWER- Customers typically are screened at onboarding and on an ongoing basis. Some organizations continuously rescreen customers in real-time, and others do hourly or daily batch screening.
With regard to list management controls, how does a FinTech determine which lists to use? - ANSWER-The decision is based
- / 4