Exam Overview and Scope
The Certified Anti-Fraud Specialist (CAFS), offered by ACAMS, targets professionals who build, run, and investigate within fraud programs at banks and non-bank financial institutions. Per ACAMS, the certification covers fraud risk management, fraud detection and analytics, fraud investigations, and the technology used to combat fraud. Two scope boundaries matter for preparation: CAFS addresses authorized push payment (APP) fraud and first-, second-, and third-party fraud, not accounting fraud, and it assumes you already work in or adjacent to fraud operations rather than teaching the field from scratch.
For planning purposes, the CAMSExam practice configuration uses 100 questions over 175 minutes with a 75 percent target pass mark. That configuration is a study aid, not an official statement of the live exam; verify current appointment rules, fees, and format with ACAMS before booking.
What makes CAFS difficult is not vocabulary. It is judgment under incomplete facts. Exam-style questions tend to present a product, a channel, a customer segment, and a threat, then ask which control, model adjustment, or investigative step is most defensible. Candidates who memorize definitions without practicing that selection logic tend to struggle, because several answer options are usually plausible and only one fits the specific profile described.
Syllabus Map
The syllabus divides into three domains. Note how each domain ends in an applied practice focus: the exam rewards candidates who can choose, tune, and sequence actions, not just recall terms.
| Domain | Scope | Applied Practice Focus |
|---|---|---|
| 1. Building a Fraud Risk Management Program | Fraud risk appetite, governance, fraud risk assessment, controls, policies, response planning, remediation, continuous improvement, and enabling technology | Select controls that fit a specific product, channel, customer, and threat profile |
| 2. Fraud Detection and Analytics | Fraud indicators and typologies; APP fraud; account takeover; first-, second-, and third-party fraud; data preparation; models; thresholds; false positives and false negatives | Analyze competing data points and tune detection without creating unsupported customer friction |
| 3. Fraud Investigations | Triage, evidence preservation, case chronology, internal and external data, interviewing, reporting, recovery, and post-investigation control feedback | Choose the next defensible investigative step while respecting evidence, privacy, and escalation constraints |
CAMSExam Recommended Study Emphasis by Domain
The Hardest Distinctions CAFS Candidates Get Wrong
Inherent versus residual risk. Inherent fraud risk is exposure before controls; residual risk is what remains after controls operate. The exam trap is treating the gap between them as automatic. A control can reduce one exposure while creating another: step-up authentication cuts account takeover losses but adds a social-engineering surface where fraudsters coach customers through the step-up. Residual risk can also exceed inherent risk in a narrow category when a control concentrates activity, such as routing all high-value transfers through a single review queue that becomes a bottleneck and a single point of failure. When a question asks you to assess residual risk, ask whether the described control actually operates as designed against the described threat, not whether it exists on paper.
Design versus operating effectiveness. A well-designed control that fails in operation is a live vulnerability, and exam scenarios test whether you notice the difference. A device-binding control is well designed against credential stuffing but operates poorly against a customer who voluntarily hands their phone to a coercive relative. The correct response to an operating failure is usually targeted remediation and monitoring, not a full redesign, and questions often include a redesign option as the overbroad distractor.
Red flag versus conclusion. This is the single most exam-relevant habit. An indicator, a typology match, or an alert is a trigger for inquiry, never proof of wrongdoing. A customer logging in from a new country at 3 a.m. is a data point; it is also a vacation, a VPN, or a shared family device. Never select an answer that treats a red flag as established fraud, and never select one that closes a case solely because a single indicator resolved. The defensible middle is documented inquiry with proportionate escalation.
First-, second-, and third-party fraud boundaries. First-party fraud involves the account holder or applicant themselves deceiving the institution, including first-party misuse where a genuine customer dishonestly disputes a legitimate transaction. Second-party fraud involves a genuine customer knowingly allowing another person to use their account or credentials for fraud. Third-party fraud involves an external actor, with account takeover as the canonical example. The boundaries blur in practice, and the exam exploits that: a coerced customer is not a second-party fraudster, and a chargeback filed by a genuine customer who lied is first-party even though it looks like a dispute. Classify by who benefits and who holds the account, then re-check against the facts given.
APP fraud and the reimbursement boundary. APP fraud is a push-payment scam where the victim authorizes the transfer themselves. The detection challenge is that the transaction is technically authorized, so traditional unauthorized-transaction controls miss it. If your exam reading includes UK context, the Payment Systems Regulator's reimbursement protections, in force from 7 October 2024, include a five-business-day reimbursement expectation, stop-the-clock assessment for additional information, treatment of vulnerable customers, an optional excess, and an 85,000 pound claim limit. These are jurisdiction-specific rules, not universal standards, and answers that apply them globally are wrong. The transferable concept is behavioral: effective warnings, vulnerability handling, and the distinction between a scam payment and an authorized-but-coerced one.
Data quality versus model performance. Detection questions often present a model with poor results and ask for the best next step. The tempting answer is retraining or threshold adjustment. The defensible first step is usually data preparation: label accuracy, feature leakage, class imbalance, and coverage of the affected segment. A model trained on mislabeled first-party disputes will underperform no matter how you tune thresholds. Conversely, threshold questions are trade-off questions: lowering a threshold reduces false negatives at the cost of false positives and customer friction, and the exam expects you to justify which error is more costly in the specific scenario, such as irreversible push payments versus reversible card charges.
Evidence versus intelligence. In investigations, internal transaction data, device data, and call recordings are evidence you control and must preserve with documented chronology and chain of handling. External data, consortium signals, and vendor intelligence are context. They can direct an investigation but rarely close one on their own, and privacy constraints govern how you may collect, store, and share both categories. When a scenario offers a slick external data shortcut as the next step, check whether it is defensible under the stated privacy and escalation constraints before choosing it.
Standard versus law. NIST SP 800-63 Revision 4, finalized in July 2025, expands fraud-related identity-proofing requirements, adds controls for injection attacks and forged media, and integrates syncable authenticators such as passkeys. It is authoritative guidance, not statute, and exam answers should treat it as a benchmark for control design. FinCEN's national AML/CFT priorities, issued June 30, 2021, include fraud alongside cybercrime, corruption, and other threats; they orient risk assessment and information-sharing expectations in the U.S. AML/CFT context rather than dictating fraud program requirements. Candidates who blur guidance, regulation, and law pick overbroad answers.
Mini-Scenarios and Decision Traps
Scenario 1: The product launch. Your institution plans a real-time P2P transfer product with instant irrevocability. Leadership proposes reusing the existing card-fraud rule set and launching in ninety days. Best next step: a product-specific fraud risk assessment covering the new threat profile, irreversibility, APP exposure, and the customer segments most targeted by push-payment scams, then a control set sized to that assessment. Why the tempting alternative fails: copying card controls is premature because the loss mechanics differ. Card fraud has chargeback rails and authorization checks; push payments rely on pre-transaction behavioral controls and effective warnings. A control set that fits one product can leave the other's dominant loss type uncovered, and the residual risk you accept silently is the exam's real subject.
Scenario 2: The tuning dilemma. Your detection model's false-negative rate on account takeover has risen, and the fraud team proposes lowering the alert threshold across all channels. Best next step: segment the misses, verify label quality on recent ATO cases, and tune within the affected segment, such as new-device logins followed by payee addition and immediate transfer, before any global change. Why the tempting alternative fails: a global threshold cut creates unsupported friction for the entire customer base and floods analysts with false positives, which degrades triage and can worsen detection in practice. The exam consistently rewards targeted tuning justified by data quality checks over blunt sensitivity changes.
Scenario 3: The ambiguous dispute. A long-tenured customer disputes three transfers to a new payee, claiming they were scammed. The device and location match the customer's history, and the payee account has appeared in two other cases. Best next step: preserve evidence, build the case chronology, apply any applicable vulnerability assessment, and investigate the payee account across cases while keeping the customer's claim open, because a consistent device match does not exclude coercion, and third-party fraudsters routinely operate from the victim's own device. Why the tempting alternative fails: closing the case as first-party fraud based on the device match converts an indicator into a conclusion. It is also premature to reimburse in full before completing the assessment. The defensible path is documented inquiry with proportionate escalation, and the cross-case payee link is intelligence that directs, but does not by itself prove, the investigation.
Scenario 4: The operating failure. Step-up authentication was implemented correctly, but losses rose because fraudsters coach elderly customers through the step-up by phone. Best next step: targeted remediation, such as coaching-resistant challenge design and vulnerability-aware handling for the affected segment, plus monitoring to confirm the fix operates. Why the tempting alternative fails: replacing the control assumes a design failure when the facts describe an operating failure, and doing nothing assumes the control's existence equals its effectiveness. The exam wants you to match the remediation to the failure mode.
Six-Week Study Plan
This plan allocates effort according to the CAMSExam recommended emphasis: roughly 40 percent on fraud risk management, 30 percent on detection and analytics, and 30 percent on investigations. Adjust to your own weak areas after a diagnostic attempt.
Where CAFS Skills Apply
CAFS is positioned for specialists, not generalists. The applied skills below map directly to the syllabus's practice focus areas and to roles where hiring managers test exactly these judgment calls.
Sources and Verification
Verify all exam logistics, fees, and booking rules with ACAMS directly, and treat regulatory details as jurisdiction-specific. Key sources used for this article: ACAMS CAFS certification page for scope and core topics; UK Payment Systems Regulator APP fraud reimbursement protections for the UK reimbursement framework from 7 October 2024; NIST SP 800-63-4 Digital Identity Guidelines for identity-proofing and authentication control guidance finalized in July 2025; and FinCEN's national AML/CFT priorities for the U.S. context linking fraud to broader financial crime priorities.
FAQ
What is the difference between first-, second-, and third-party fraud, and why does CAFS emphasize it?
First-party fraud involves the account holder deceiving the institution themselves, including first-party misuse such as dishonest disputes of legitimate transactions. Second-party fraud involves a genuine customer knowingly letting someone else use their account for fraud. Third-party fraud involves an external actor, with account takeover as the classic case. ACAMS lists these categories, along with APP fraud, as core CAFS topics. The classification matters operationally because detection signals, controls, and recovery paths differ by party type, and exam scenarios test whether you classify correctly under ambiguous facts, such as coercion, which is not second-party fraud.
Does CAFS cover accounting fraud?
No. Per ACAMS, CAFS covers APP fraud and first-, second-, and third-party fraud rather than accounting fraud. Candidates coming from audit or financial-statement fraud backgrounds should not expect their existing material to transfer directly and should focus on payments, identity, and operational fraud typologies instead.
Are the UK PSR APP reimbursement rules testable globally?
Treat them as jurisdiction-specific. The PSR framework, in force from 7 October 2024, includes a five-business-day reimbursement expectation, stop-the-clock assessment, vulnerable-consumer treatment, an optional excess, and an 85,000 pound claim limit. These apply in the UK. The transferable exam value is the underlying logic: effective warnings, vulnerability handling, and the distinction between scam-authorized and genuinely unauthorized payments. Never select an answer that applies UK thresholds or timelines as if they were universal.
How should I decide between lowering a detection threshold and improving data preparation?
Check data quality first. If labels are wrong, features are leaking, or the affected segment is underrepresented, threshold changes will not fix the model and may create unsupported friction across the whole customer base. Threshold tuning is legitimate once the data supports it, and it is always a trade-off: fewer false negatives means more false positives. The defensible answer on the exam is the intervention justified by the specific failure mode described, usually segment-level tuning rather than a global sensitivity change.
What does 'defensible next step' mean in an investigations question?
It means the action that preserves options, respects evidence and privacy constraints, and does not convert an indicator into a conclusion. Typically that means preserving evidence, building a chronology, gathering internal data, and using external or cross-case intelligence to direct, not decide, the investigation. Premature case closure, premature reimbursement or denial, and sharing data beyond permitted purposes are the common wrong answers.
Is the 40/30/30 split an official exam weighting?
No. The 40 percent emphasis on fraud risk management and 30 percent each on detection and investigations is the CAMSExam recommended study emphasis for preparation, not a published ACAMS exam blueprint. Use it to allocate study time, and verify any official weighting or format details with ACAMS.
What is the exam format and pass mark?
The CAMSExam practice configuration is 100 questions in 175 minutes with a 75 percent target pass mark. This describes the practice environment, not necessarily the live exam. Appointment rules, fees, question counts, and passing standards can change, so confirm current details with ACAMS before booking.
How do NIST SP 800-63-4 and FinCEN's priorities fit into CAFS study?
NIST SP 800-63 Revision 4, finalized in July 2025, is authoritative guidance for identity proofing and authentication controls, including new requirements around injection attacks, forged media, and syncable authenticators such as passkeys. Use it as a benchmark when evaluating control design questions. FinCEN's June 30, 2021 national AML/CFT priorities, which include fraud alongside cybercrime and other threats, provide U.S. context for how fraud programs connect to broader financial crime obligations. Both are guidance and context, not universal law, and exam answers should treat them accordingly.
What is the most common reasoning error on CAFS-style questions?
Treating a red flag as a conclusion. A new device, an unusual transfer, or a typology match is a trigger for inquiry, not proof of fraud. The mirror error is equally costly: dismissing a case because one indicator resolved. Strong candidates hold both errors in view and select the documented, proportionate inquiry step, which is what the applied practice focus in every syllabus domain is really asking for.