CAFS Practice Questions
Prepare for CAFS with more than an answer.
- Exam fee
- $1995 USD
- Level
- Specialist
- Valid for
- 3 years
Domains covered on the exam 5
- Building a Fraud Risk Management Program25%
- Fraud Detection and Analytics25%
- Fraud Investigations25%
- Technologies to Combat Fraud10%
- Fraud Case Studies and Applied Knowledge15%
- 1
Regarding 'Fraud Risk Tolerance', which of the following statements is correct?
Show answer details
Correct answer: C
Risk Tolerance is the acceptable variation from the goal. For example, if the goal is zero fraud, the tolerance might be 'losses under $10,000 per quarter'. It is more tactical and granular than Risk Appetite.
- 2
What is the primary function of a 'Gap Analysis' in the context of a Fraud Risk Management Program?
Show answer details
Correct answer: D
A Gap Analysis compares 'where we are' (current controls) with 'where we need to be' (requirements/best practices) to identify missing controls or weaknesses that need remediation.
- 3
In fraud analytics, what is the primary difference between Supervised and Unsupervised machine learning models?
Show answer details
Correct answer: D
Supervised learning uses a 'target' variable (labels like 'Fraud' or 'Legitimate') to train the model to recognize known patterns. Unsupervised learning has no labels; it clusters data to find outliers or anomalies that deviate from the norm, making it useful for discovering new, unknown fraud schemes.
- 4
A regional bank is designing a new Fraud Risk Management Program. According to the COSO framework and ACAMS best practices, which component serves as the foundation for all other components of internal control, influencing the fraud consciousness of the organization?
Show answer details
Correct answer: A
The Control Environment is the foundation of the COSO framework. It sets the tone of the organization, influencing the control consciousness of its people. It includes governance, integrity, ethical values, and the operating style of management. Without a strong control environment, other components (like risk assessment or monitoring) cannot function effectively.
- 5
In the context of the 'Three Lines of Defense' model for fraud risk management, which of the following responsibilities belongs primarily to the First Line of Defense?
Show answer details
Correct answer: B
The First Line of Defense consists of business unit management and operational staff who own and manage risks day-to-day. They are responsible for implementing corrective actions and maintaining effective internal controls. The Second Line (Risk/Compliance) establishes frameworks, and the Third Line (Audit) provides independent assurance.
flowchart TD L1[First Line: Business Operations] -->|Owns Risk| Risk{Risk Mgmt} L2[Second Line: Risk & Compliance] -->|Monitors| Risk L3[Third Line: Internal Audit] -->|Audits| Risk - 6
A fraud risk manager is calculating the Residual Risk of a specific loan product. The Inherent Risk is rated as 'High' due to the product's online availability. The Control Effectiveness of the identity verification system is rated as 'Strong'. How should the Residual Risk be conceptualized?
Show answer details
Correct answer: D
Residual Risk is the risk that remains after management has implemented internal controls to mitigate the Inherent Risk. In this scenario, a High Inherent Risk mitigated by Strong controls would likely result in a Low or Medium Residual Risk. It is calculated as: Inherent Risk - Control Effectiveness = Residual Risk.
