The current CAMS program is deliberately modular, and the most efficient study order follows the logic of anti-financial crime work. Begin with financial crime methods and risk exposure, then learn global frameworks and governance, build the compliance program, and finish with technology. The CAMS weighting—30/20/30/20—supports spending the largest blocks on risk/methods and program design.
Phase one: master financial crime definitions and predicate risk
Start with AML/CFT, sanctions, fraud, bribery/corruption, tax evasion and predicate crimes. Build contrast pairs so you can recognize where methods overlap but legal/regulatory responses differ.
Do not begin with transaction-monitoring tools before you understand the activity those tools are trying to detect.
Phase two: learn sector typologies through scenarios
Study banking, PEP/high-risk customers, MSBs/PSPs, virtual assets, insurance, gaming, real estate, gatekeepers and company-service structures. For each, identify products, typical customers, red flags and why criminals might prefer the sector.
Use fictional cases rather than memorized red-flag lists alone.
Phase three: build the global standards layer
Learn the role of FATF-style standards, major international bodies, governance expectations and regional/national regimes. Focus on how global guidance becomes local obligations.
Keep a table of universal principles versus jurisdiction-specific requirements so they do not blur together.
Phase four: understand AFC governance
Map board/senior management, first line, compliance/second line, internal audit/third line, regulators and law enforcement. Identify who owns risk, who operates controls and who independently tests them.
Scenario questions become easier when decision authority is clear.
Phase five: build an enterprise-wide risk assessment
Create a fictional institution and assess customer, product/service, geography and delivery-channel risk. Add controls and determine residual risk.
Then change one factor—such as launching virtual-asset services—and update the risk assessment and control framework.
Phase six: walk the customer lifecycle
Practice onboarding, identification, beneficial ownership, screening, CDD/EDD, risk rating, ongoing monitoring, periodic/perpetual KYC and exit. Define what information or event would trigger escalation at each stage.
This is the central operational bridge between risk assessment and transaction monitoring.
Phase seven: study monitoring and investigations
Follow alerts into cases. Review transaction context, counterparties, customer profile, prior activity and external information. Practice documenting why activity is explainable or suspicious.
Understand when law enforcement engagement or SAR/STR filing may arise under applicable regulation, without assuming one country’s rule applies everywhere.
Phase eight: add tools and data quality
Study digital onboarding, e-KYC, biometrics, geolocation, screening, adverse media, perpetual KYC, monitoring platforms, investigation tools and AI/ML. For each, identify the data it depends on and the governance needed.
Technology questions often test fit, privacy, data quality or oversight rather than vendor names.
Phase nine: practice scenario-based judgment
Use timed mixed sets that force you to choose the most appropriate next action. Ask whether the scenario belongs to risk identification, governance/regulation, program operation or technology.
The CAMS test-day approach should prioritize reading the facts carefully over racing through familiar terminology.
Finish with one end-to-end customer case
Take a high-risk customer from onboarding through beneficial ownership, risk rating, screening, transaction monitoring, investigation and exit. Add a technology failure and a regulatory question.
Keep one fictional financial institution throughout the plan, such as a bank that also offers payments and virtual-asset services. Reusing one institution lets customer, product, geography and channel risks evolve as you study regulations, controls and technology.
During Domain A, build a sector matrix rather than a red-flag list. For each sector, record products, customer types, possible financial-crime methods, typical red flags and what legitimate activity could look similar. This reduces the risk of treating every unusual behavior as suspicious.
Add a PEP and sanctions distinction exercise. A PEP relationship normally requires risk-based enhanced diligence, while sanctions restrictions can prohibit or freeze activity depending on the legal regime. The controls can overlap, but the legal implications differ.
During Domain B, create a hierarchy from global standard-setting body to regional/national law, regulator/supervisor, institution policy and frontline procedure. This makes it clear why FATF guidance and local filing rules should not be treated as the same legal source.
Add a governance chart with board/senior management, business first line, compliance second line and internal audit third line. Give each function one decision or responsibility. If compliance appears to own every operational action, rebalance the model.
During EWRA study, score one product before and after new controls. Distinguish inherent risk from residual risk and document assumptions. Then decide what management information should be reported if residual risk remains above tolerance.
During onboarding study, create two customers with different risk profiles and compare CDD/EDD depth. Use complex beneficial ownership, PEP exposure, high-risk geography or virtual assets as factors, but include legitimate business explanations so judgment remains balanced.
During screening study, work through false positive and true-match examples at a high level. Record identifiers used to resolve the case and when escalation to sanctions/legal specialists is appropriate. Name similarity alone is not a complete conclusion.
During transaction-monitoring study, map one scenario to the underlying risk. For example, rapid movement through multiple accounts could indicate layering but can also have legitimate explanations. The investigation should test the customer context rather than assume the scenario name proves suspicious activity.
During investigation study, practice a narrative that explains who, what, when, where, why and how. Avoid unsupported conclusions. Whether the result is “close as reasonable” or “escalate/report,” the file should show how evidence supported the decision.
During technology study, create a data lineage from onboarding source through customer master, screening and transaction-monitoring system into case management. Identify where one bad field could propagate into multiple controls. This demonstrates why data governance receives explicit blueprint attention.
Add an AI/ML governance exercise. Suppose a model prioritizes perpetual-KYC reviews. Define training data, performance measure, bias testing, override, human review and model-change approval. The goal is to understand operational governance, not build an algorithm.
Practice the 120-question/3.5-hour pace with mixed scenario sets. Flag ambiguous items and return if allowed by the testing interface, but do not leave questions unanswered unnecessarily. The current exam is long enough that concentration management matters.
Use the final week according to the 30/20/30/20 blueprint but adjust for weaknesses. If technology governance remains your lowest area after mocks, give it more time even though it is 20%. Published weighting is a starting allocation, not a reason to ignore evidence from practice.
Finish by explaining the current enhanced CAMS program to another compliance professional: four domains, how they connect, what technology changed and how a risk-based program moves from onboarding to monitoring/investigation. Teaching the flow is a strong final test of integration.
Add one sanctions-focused session inside Domain B and Domain C. Learn why screening lists, ownership/control rules, jurisdiction and transaction context matter, then practice a false positive versus potential true match. Keep legal interpretation within the applicable jurisdiction rather than applying one country’s sanctions regime universally.
Add one beneficial-ownership case with a multi-layer company structure. Identify natural persons who own or control the entity according to the applicable program rules, then compare the declared purpose with expected activity. Ownership transparency is central to both risk and onboarding.
Add one customer-risk re-rating exercise. Start with a medium-risk customer, then introduce a new PEP connection, adverse media or higher-risk geography. Decide what information must be refreshed and whether enhanced monitoring or approval is required.
Add one transaction-monitoring tuning exercise. A scenario produces too many false positives. Identify whether thresholds, segmentation, customer-risk data or transaction coding is the cause before suppressing alerts. Tuning should improve signal without creating a blind spot.
Add one quality-assurance review of investigation files. Check factual accuracy, evidence, decision rationale, escalation and narrative consistency. Convert repeated quality failures into procedure or training changes rather than correcting individual files forever.
Add one independent-testing tabletop. Select a control such as sanctions screening or KYC refresh and define what an independent reviewer would test: design, implementation, data completeness, sampling, exceptions and remediation. This distinguishes ongoing management from assurance.
Before exam day, recreate the four current domain names and 30/20/30/20 weights without notes. Then explain one technology example and one governance example for each. If a domain still feels like isolated vocabulary, return to an end-to-end customer scenario.
Add one adverse-media exercise. Give two articles about people with similar names and decide what identifiers, source credibility and recency are needed before escalating. This trains candidates to use external information as evidence while avoiding unsupported conclusions from name matches alone.
Add one data-quality audit. Sample customer records for missing beneficial ownership, inconsistent country codes, stale addresses and incomplete transaction metadata. Trace how each defect could affect screening, risk rating or monitoring. This makes Domain D relevant to the whole program.
Add one governance scenario where business and compliance disagree about a high-risk customer. Define escalation to the appropriate committee or senior owner, document residual risk and separate business acceptance from compliance’s advisory/control role. Clear authority matters when commercial pressure is high.
Add one program-metrics session. Compare activity counts such as alerts closed with effectiveness measures such as alert aging, QA failure rate, stale high-risk reviews or sanctions-screening coverage. Then identify what management action each metric should trigger.
Add one post-investigation feedback exercise. Suppose several cases reveal the same new typology. Update the enterprise risk assessment, monitoring logic, training and possibly onboarding questions. A mature AFC program learns from investigations rather than treating them as the end of the process.
Use final review to practice “best next step” questions without assuming more investigation is always correct. Sometimes the answer is escalate, refresh CDD, obtain approval, tune a control, preserve confidentiality or refer to legal/regulatory guidance. Place the scenario on the four-domain map first.
Within the ACAMS certification path, this end-to-end exercise is the best proof that the four domains have become one operating model rather than four memorized chapters.