Study Guide

CAFP Study Guide: Classifying AML and Fraud Scenarios

Learn to classify money laundering, fraud, and terrorist financing cases, map transactions to laundering stages, and practice exam-style scenarios for the CAFP.

Updated September 202610 min readStudy GuideLending Exam
Stephen Hamilton

Stephen Hamilton

Lending Exam Editorial Team

AML and fraud case scenarios are hard because the same transaction stream can carry several labels at once, and each label points to a different control, escalation path, and report narrative. This guide trains one skill in a deliberate order: classify first, then decide. You will separate money laundering from fraud and terrorist financing, map transaction patterns to laundering stages, anchor every judgment to a customer baseline, and practice writing the short rationales that case files demand. Work through both scenarios and the rubric below, then use the free practice bank to drill the same decision under time pressure.

Separating Money Laundering from Fraud and Terrorist Financing in Case Scenarios

Money laundering disguises criminal proceeds; fraud obtains assets through deception; terrorist financing moves funds toward violence regardless of their origin. Which label you assign determines which indicators, controls, and narrative language apply to the case.

The three crime types answer different questions. Money laundering is about the source of funds: proceeds are already criminal, and the goal is to make them appear legitimate. Fraud is about how assets were acquired: deception produced the transfer, so the origin may be an otherwise clean account. Terrorist financing is about purpose: funds can be entirely lawful in origin, which is why a laundering-stage analysis finds nothing, because there is no dirty money to place, layer, or integrate.

Hybrid cases appear throughout AML and fraud work, which is why single-label memorization breaks down. A business email compromise pays stolen money into a mule account that then wires it onward: the theft is fraud, the onward movement by the mule resembles laundering, and classification applies per account role. Train a three-question order for every stem: how did the funds originate, what is their intended use, and who controls each account in the chain. Then confirm your label against the comparison below before choosing any control.

DimensionMoney launderingFraudTerrorist financing
Core questionIs the source of funds criminal?Was the transfer obtained by deception?Is the purpose of funds violent activity?
Early indicator typeCash intensity, layered movement, opaque ownershipChanged credentials, urgency, new payees, pressure tacticsStructuring with clean funds, front entities or charities
Matching controlSource inquiry, pattern review, diligence escalationCredential review, payee verification, victim contactPurpose-of-funds inquiry, network review
Narrative focusHow proceeds moved and were disguisedWho deceived whom and how access was gainedIntended use and the supporting network

Matching Transaction Patterns to Placement, Layering, and Integration

Placement, layering, and integration describe where funds sit in a laundering cycle, and each stage produces different observable patterns. Attaching a stage label to the wrong pattern weakens both your analysis and any written rationale you produce from it.

Placement means criminal cash first enters the financial system: repeated cash deposits by multiple individuals, inflated receipts at a cash-intensive business, or deposits spread across branches and days. Layering is movement designed to obscure the trail: rapid transfers between related entities, round-amount wires across borders, or trade-based schemes using over- and under-invoiced shipments. Integration is re-entry as apparently legitimate wealth: a loan repaid by a shell company, an asset bought and resold, or invested funds returned as business income.

The confusion worth drilling is that fast movement is not automatically layering. Movement patterns describe a laundering cycle only when the origin is criminal proceeds; stolen funds leaving a compromised account quickly are simply theft proceeds exiting, and there may be no laundering cycle at all. When you practice, label each stage only after confirming the origin question from Section 1. A reliable drill: take five short transaction lists, write the stage you see, then force yourself to write one sentence explaining what makes it that stage rather than the adjacent one.

Deciding When Unusual Becomes Suspicious: Building a Customer Baseline

Unusual means inconsistent with the customer's expected profile; suspicious means you can articulate why that inconsistency, in context, suggests possible criminal activity. The baseline built during due diligence is the measuring stick for both judgments.

A usable baseline records the customer's stated occupation and income source, the products and channels they were opened for, and the expected volume, frequency, and geography of activity. A florist who deposits substantial cash is plausible; a florist who suddenly wires weekly to unfamiliar high-risk counterparties is not, but only because the baseline says so. Without the expectation on record, unusual and suspicious collapse into the same vague impression, and your justification rests on gut feel rather than stated facts.

This distinction is trainable through a four-part writing habit: state the expectation, state the deviation, state the context that makes the deviation meaningful, and state the next decision with its owner. If you cannot fill in the expectation line, you have not finished the analysis, whatever conclusion you reached. In scenario practice, apply the same structure to every option before selecting one, because a conclusion drawn without the baseline step rests on impression rather than stated facts.

Choosing the Right Level of Diligence: KYC, CDD, and EDD Triggers

KYC verifies identity at onboarding; customer due diligence builds ongoing understanding of activity and risk; enhanced due diligence applies deeper scrutiny when risk factors demand it. Practice choosing the proportionate level for each fact pattern rather than defaulting to the deepest one.

The risk-based approach means diligence scales with assessed risk rather than being uniform. Enhanced review is typically reserved for relationships carrying higher risk, such as politically exposed persons, complex or opaque ownership structures, and geographies elevated by your institution's own risk assessment. Applying enhanced measures everywhere looks thorough but fails a proportionality test, and applying only basic measures to a clearly elevated relationship fails a sufficiency test. Practice recognizing which side of that line a case sits on and stating why in one sentence.

Keep the outputs of each level distinct in your head, because the outputs are easy to mix up when you are deciding quickly. Identity verification produces verified identity documents and a customer record; standard due diligence produces a risk rating and an expected activity profile; enhanced diligence produces additional source-of-funds and source-of-wealth evidence plus senior approval where your framework requires it. Use the table to check yourself, then drill trigger-recognition: given a short customer fact pattern, name the level you would apply and the single risk factor that justifies it.

LevelCore questionTypical triggersTypical outputs
KYCWho is this customer, verified?New account or relationshipVerified identity and customer record
CDDWhat activity is this customer expected to have?Ongoing relationship monitoringRisk rating and expected activity profile
EDDDoes elevated risk require deeper evidence?PEP status, complex ownership, higher-risk geographies, unexplained profile changesSource-of-funds and source-of-wealth evidence, senior review, tighter monitoring

Worked Scenario One: Sub-Threshold Cash Deposits That Look Innocent Alone

When deposits are individually small but patterned to stay under a reporting threshold, the decision rests on aggregation and pattern analysis rather than any single transaction. The predictable error is closing the alert because no one deposit appears to qualify.

The case: a retail customer whose baseline shows a salaried income deposits between roughly eight and nine and a half thousand in cash on six consecutive days, spread across four different branches, with no business rationale on file to explain cash volume. The weaker decision reviews each deposit in isolation, notes that none crosses the reporting threshold, and marks the alert as no reportable activity. The stronger decision aggregates across days and branches, compares the total to the documented baseline, inquires about the source of the cash, records the answers, and escalates per policy if the explanation does not resolve the pattern.

Why it matters: structuring is defined by the pattern and by apparent intent to evade a reporting or recordkeeping duty, so threshold rules exist to create records in the first place, and evading them is itself the signal. A caution on numbers: specific thresholds, aggregation windows, and filing deadlines are jurisdiction-specific and change over time, so learn the aggregation principle and the pattern-recognition reasoning, and confirm current figures through the regulator and issuer rather than memorized amounts. Administrative details for this credential live with the issuer at aba.com.

Worked Scenario Two: A Rapid Withdrawal Case That Is Fraud, Not Laundering

An account emptied within hours of a credential change is most plausibly account takeover fraud rather than laundering. Treating it as laundering sends the case down a stages-and-typologies path that delays the victim-focused actions the situation calls for.

The case: a long-standing customer's email and phone contact details were changed two days ago, a new device then logs in, a new payee is added, and the balance is moved out the same day. The weaker response writes a laundering narrative using layering language, which misframes the case because the funds originated from the customer's own legitimate balance and no laundering cycle exists. The stronger response classifies attempted or completed unauthorized transactions, preserves login and device evidence, initiates contact attempts through previously verified channels, reviews and holds the new payee where the framework allows, and files an internal fraud record stating who, what, when, and how access was gained.

Why the classification matters: it determines the downstream playbook. A fraud case triggers victim contact, credential resets, and possible recall of transfers; a laundering case triggers source inquiries and pattern review of the wrong party. Real cases do combine the crimes, since mule accounts receiving fraud proceeds connect both, but the classification applies per account role: the victim's account is a fraud case, the receiving mule account may be a laundering case. Practice stating that split explicitly whenever a single fact pattern touches multiple accounts.

A Practice Routine and Self-Check Rubric for Scenario Readiness

Build readiness with a four-step cycle: concept mapping, timed scenario drills, written rationales, and an error log reviewed weekly. Score every practice case against the rubric below, and treat the scores as learning milestones rather than predictions of any exam outcome.

An adaptable sequence over roughly two weeks: days one to three, draw concept maps covering the three crime types, the three laundering stages, and the three diligence levels, connecting each concept to one indicator and one control. Days four to ten, drill scenarios from the practice bank, untimed first and then timed, recording your classification and decision for each. Days eleven to fourteen, write five-sentence rationales for the same cases using the expectation-deviation-context-decision structure, then redo every case you scored below standard before moving on.

The core exercise: pick five transaction lists of increasing complexity. For each, record the stage or crime type, two indicators tied to a stated baseline, your decision with an escalation path, and one material fact the scenario does not tell you. This mirrors real analytical work, where the deliverable is a defensible rationale, not just a label. Your error log should have one line per miss: what you classified, what the classification should have been, and which question you failed to ask first, then review the log before every subsequent session.

  • Classification correct and reasoned: 2 points
  • Two indicators, each tied to a stated baseline expectation: 2 points
  • Decision stated with a specific escalation path and owner: 2 points
  • One material missing fact identified: 1 point
  • Milestone: 7 out of 7 across five consecutive cases before timed drills
  • Final readiness checks: classify a ten-case mixed set within your target time; write one rationale from memory; name the EDD trigger you would cite for three different fact patterns

References and further reading

Use these references to explore the concepts and check the latest information from the relevant organizations.

Continue your preparation

FAQ

Frequently Asked Questions

Practical answers to help you apply the guidance for Certified AML and Fraud Professional (CAFP).

Do I need to memorize specific reporting thresholds and filing deadlines?
Learn the principles: aggregation across transactions, days, and accounts, and why pattern analysis matters more than any single amount. The specific figures and deadlines are jurisdiction-specific and change over time, so confirm current rules through the regulator's own materials rather than a study guide.
How is the CAFP different from other AML certifications such as CAMS?
Treat them as adjacent but separate credentials: each issuer defines its own outline, eligibility, and emphasis, so do not assume content from one transfers to the other. Compare the published outlines side by side and prepare against the outline for the credential you are actually sitting.
How should I split study time between definitions and scenarios?
Use definitions as vocabulary only, since the stages, levels, and crime types are tools rather than the deliverable. Spend the majority of your repetitions on classification drills and written rationales, because that is the skill the scenarios in this guide rehearse and the one that improves with deliberate practice.
What should I do when a scenario leaves key facts unstated?
State your assumptions explicitly and choose the decision consistent with them, then name the missing fact. Strong practice answers identify what additional information would change the decision, and building that habit in drills carries directly into any case-based question format.

Keep Reading

Related Study Guides

Explore related guides and preparation topics.