CAFCA Practice Questions
Prepare for CAFCA with more than an answer.
- Exam fee
- $1045 USD
- Level
- Associate
- Valid for
- 1 year
Domains covered on the exam 5
- Governance, Guidance, and Regulation20%
- Due Diligence Across Customer Types20%
- Payment Screening and Transaction Monitoring25%
- Investigations, Inquiries, and Reporting20%
- Scaling Anti-Financial Crime Strategies15%
- 1
A digital wallet provider uses 'Passive Liveness Detection' during its eKYC process. What is the primary advantage of this technology compared to 'Active Liveness Detection'?
Show answer details
Correct answer: D
Active liveness requires user action (nodding, blinking), which adds friction and drop-off risk. Passive liveness analyzes the selfie/video in the background (e.g., analyzing micro-reflections or depth) to confirm a real person is present without the user needing to act, improving conversion rates while maintaining security.
- 2
During the onboarding of a new corporate client, the compliance team notices that the IP address used for the application originates from a country different than the business registration and the director's residence. This is an example of which type of data discrepancy?
Show answer details
Correct answer: A
This is a geolocation mismatch. While legitimate reasons exist (VPN, travel), it is a red flag that requires investigation to ensure the applicant isn't spoofing their location to bypass jurisdictional restrictions.
- 3
Which of the following describes a 'Synthetic Identity' used in application fraud?
Show answer details
Correct answer: D
Synthetic identity fraud involves stitching together real data (like a legitimate SSN, often from a child or deceased person) with fake data (name, DOB) to create a 'Frankenstein' identity that has no credit history but looks real enough to pass basic checks.
- 4
A rapidly growing Neo-bank is preparing for a regulatory audit. The auditor requests evidence of the 'Three Lines of Defense' model implementation. Which of the following scenarios best demonstrates an effective separation of duties within this framework?
Show answer details
Correct answer: D
In the Three Lines of Defense model, the First Line (Business/Operations) owns and manages the risk (executing CDD). The Second Line (Compliance/Risk) oversees risk and sets policy. The Third Line (Audit) provides independent assurance. Mixing these roles, such as Compliance doing the initial checks, compromises the framework's integrity.
- 5
Which of the following data points collected by a FinTech during onboarding constitutes Sensitive Personally Identifiable Information (SPII) under regulations like GDPR, requiring stricter handling controls than standard PII?
Show answer details
Correct answer: D
Biometric data (facial scans, fingerprints) is classified as 'Special Category Data' or SPII under GDPR because it uniquely identifies a person based on physical characteristics and carries a higher risk if compromised. Address and email are standard PII.
- 6
A Payment Service Provider (PSP) is launching a 'Regulatory Sandbox' initiative to test a new cross-border remittance product using blockchain. What is the primary compliance objective of operating within this sandbox?
Show answer details
Correct answer: B
Regulatory sandboxes allow firms to test new technologies under regulator supervision with safeguards in place. It is not an exemption from compliance but a controlled testing ground to ensure the new method meets regulatory expectations before mass rollout.
