Exam Overview and Format
The ACAMS Certified Anti-Money Laundering Specialist (CAMS) certification is positioned by ACAMS as the global standard of competency for AML expertise, with modular learning that spans AML/CFT risks, typologies, technology, and best practices. The official format is 120 questions in 210 minutes with a passing score of 75. Because appointment rules, fees, and language availability can change, confirm every booking detail directly with ACAMS before scheduling.
What separates prepared candidates from those who narrowly miss 75 is rarely definitional knowledge. Most CAMS candidates already work in compliance, audit, KYC, or transaction monitoring. The exam's difficulty lives in boundary questions: when an indicator becomes a conclusion, when a FATF standard becomes a legal obligation, when a control that looks adequate on paper is actually ineffective in operation, and which action is best when the facts are incomplete. This guide concentrates on those decision points.
- Format: 120 questions, 210 minutes, passing score of 75.
- Audience fit: second-line compliance teams, risk managers, internal auditors, KYC and transaction monitoring leaders.
- Editorial focus: high-yield, syllabus-aligned distinctions, not an encyclopedic beginner guide.
Full Syllabus Map
The CAMS syllabus covers four domains. The table below maps every topic you are expected to command, together with the applied practice focus that exam scenarios tend to probe. Treat the right-hand column as your self-test: if you cannot perform that action on an unlabeled fact pattern, the topic is not yet exam-ready.
| Domain | Topics in Scope | Applied Practice Focus |
|---|---|---|
| 1. Understanding Risks and Methods of Financial Crime | Definitions and consequences across AML/CFT, sanctions, fraud, anti-bribery and corruption, and tax evasion; predicate offences; sector, customer, product, jurisdiction, and channel risks; banking, MSBs, VASPs, gambling, real estate, gatekeepers, and other high-risk sectors | Separate a red flag from a conclusion, identify the underlying typology, and connect risk indicators to proportionate controls |
| 2. Global AFC Frameworks, Governance, and Regulations | FATF and FSRBs; UN sanctions; regulators, law enforcement, and FIUs; mutual evaluations and risk assessments; US, EU, and jurisdiction-specific rules; information sharing, privacy, ethics, financial inclusion, and public-private partnerships | Distinguish standards from laws, technical compliance from effectiveness, and permitted information sharing from prohibited disclosure |
| 3. Building an AFC Compliance Program | Enterprise-wide risk assessment; CDD and EDD; policies and controls; three lines of defence; training, independent testing, board reporting, recordkeeping, and remediation | Design a coherent program and select proportionate controls for customer, product, geography, and channel risk |
| 4. Tools and Technologies to Fight Financial Crime | Transaction monitoring; watchlist screening; SAR/STR case management; data quality; model tuning; analytics; digital identity; automation and AI controls | Evaluate alert quality, evidence, technology limits, and escalation choices in scenario questions |
CAMSExam Recommended Study Emphasis by Domain (not an official exam weighting)
The Hardest Boundary Distinctions
Red flag versus conclusion. The single most valuable habit for this exam is refusing to let an indicator masquerade as a finding. A customer who wires funds to a high-risk jurisdiction, structures cash deposits, or uses a gatekeeper is exhibiting behavior consistent with several typologies, including legitimate ones. A structuring pattern is a red flag; it becomes a conclusion only when the fact pattern excludes innocent explanations and the evidence supports a specific typology. Exam items reward the candidate who asks, "What else could explain this?" before selecting the answer that names an offence. Never treat a red flag as proof of wrongdoing, and never present a jurisdiction-specific threshold or reporting rule as universal.
Standard versus law. FATF Recommendations are international standards, not directly enforceable laws. They bind countries, which then transpose them into domestic statutes, regulations, and supervisory expectations. When a scenario asks what an institution must do, look for the domestic legal hook; when it asks what represents good practice or an international expectation, FATF is the right frame. The FATF Recommendations were last updated in October 2025, and a February 2025 update reinforced proportionality and simplified measures in lower-risk scenarios under the risk-based approach, so expect scenarios where simplified CDD is the correct, defensible answer rather than a compliance failure.
Inherent versus residual risk. An enterprise-wide risk assessment must measure exposure before controls (inherent) and after controls (residual). A common exam trap presents a strong control environment and asks about the institution's risk profile; strong controls reduce residual risk but do not erase inherent exposure from, say, a cross-border correspondent portfolio or a VASP customer base. If a scenario asks where to focus remediation, the answer usually follows the highest residual risk, not the loudest inherent risk.
Design versus operating effectiveness. A policy can be well designed and still fail in operation. Independent testing, a core program element, exists to test both: does the program address the institution's actual risks, and does it work as executed? A transaction monitoring scenario with documented rules but stale tuning, unreviewed alerts, or incomplete data feeds is an operating failure even though the design documents look pristine. When a scenario describes an audit or regulatory finding, classify it before answering.
Data quality versus model performance. In the technology domain, candidates habitually blame the model when the data is the problem. Missing beneficiary fields, unpopulated country codes, and duplicate customer records degrade alert quality regardless of how well a scenario's rules are tuned. Before choosing "retune the model" in a scenario about false positives, check whether the fact pattern describes data defects. Conversely, a model that never fires on a documented typology points to coverage gaps in scenario design, not data hygiene.
Evidence versus intelligence. A SAR/STR case file must contain the evidence that supports the suspicion: transaction records, screening results, CDD documentation, and the analyst's reasoned narrative. Intelligence, such as a typology alert or an unverified tip, can justify enhanced attention but is not itself evidence. Scenarios that ask what to include in a report reward the evidentiary answer; scenarios that ask what triggered a review can accept intelligence.
Mini-Scenarios and Decision Traps
Scenario 1: The real estate deposits. A real estate firm's client purchases three commercial properties in eight months, each funded by wires from three different offshore entities, and the client insists on expedited closings. The compliance officer is asked what to do first. Best next step: conduct enhanced due diligence on the client and the offshore funding entities, and document the source-of-funds analysis. Why the tempting alternative fails: filing a SAR/STR immediately is premature, because the pattern is a red flag consistent with layering, not a conclusion; the institution must first establish what EDD reveals and whether the file can be explained. Escalation to the board or exit of the relationship is even more overbroad at this stage.
Scenario 2: The screening backlog. A watchlist screening tool generates a 40 percent spike in alerts after a sanctions list update. The head of monitoring proposes disabling fuzzy matching until the backlog clears. Best next step: keep full screening coverage, quantify the backlog, and add temporary review capacity with prioritization by match quality and customer risk. Why the tempting alternative fails: weakening a control to manage workload is a design change that creates exposure exactly when the risk changed; the proportionate response addresses throughput, not coverage. This is also a board-reporting moment: a material control disruption belongs in governance reporting.
Scenario 3: The information-sharing request. A correspondent bank in another jurisdiction emails your institution's FIU liaison, asking for the CDD file on a shared customer to "speed up their investigation." Best next step: route the request through legal and compliance to determine whether a lawful sharing channel, such as an FIU-to-FIU request or an authorized private-public arrangement, applies. Why the tempting alternative fails: sending the file directly may constitute prohibited disclosure, tipping off, or a privacy breach, depending on jurisdiction. The exam consistently rewards the candidate who distinguishes permitted information sharing from prohibited disclosure rather than assuming cooperation is always correct.
Scenario 4: The "effective" program. An institution has current policies, annual training with 98 percent completion, and a risk assessment completed two years ago. A regulator's mutual evaluation style question asks whether the program is effective. Best answer: technical compliance is present, but effectiveness is doubtful, because the risk assessment predates significant changes and nothing in the fact pattern demonstrates useful outcomes, such as quality SARs or identified control gaps remediated. Why the tempting alternative fails: pointing to documentation and training metrics measures form, not effectiveness. FinCEN's April 2026 proposed rule on AML/CFT programs emphasizes risk assessments, incorporation of national priorities, and useful outcomes, which sharpens this distinction for US-focused scenarios.
A Six-Week Study Plan
This plan allocates effort in line with the CAMSExam preparation emphasis shown above: heaviest on financial crime risks and program building, steady on frameworks and technology. Adjust pacing to your own weak areas, but keep the applied practice focus of each domain at the center of every session.
How the Concepts Apply on the Job
CAMS is not an academic exercise; every distinction in this article maps to a recurring workplace decision. The grid below connects the exam's applied practice focus to the roles where it pays off daily.
Primary Sources to Verify
Anchor your study to primary sources rather than summaries, and re-verify anything time-sensitive before your exam date. Start with the ACAMS CAMS certification page for format, eligibility, and booking rules. For the international framework, use the FATF Recommendations and the February 2025 standards update on proportionality. For US priorities and program expectations, review the FinCEN national AML/CFT priorities and the FinCEN AML/CFT program proposed rule. For the EU supervisory landscape, see the EU Anti-Money Laundering Authority. For digital identity controls relevant to the technology domain, consult NIST SP 800-63-4.
Frequently Asked Questions
What is the CAMS exam format and passing score?
The official format is 120 questions in 210 minutes with a passing score of 75. ACAMS may adjust administrative details over time, so verify appointment rules, fees, and language availability directly with ACAMS before booking.
Are the study emphasis percentages in this guide official exam weightings?
No. The 30/20/30/20 split is a CAMSExam editorial preparation emphasis based on the syllabus's recommended study emphasis, not an official exam blueprint published by ACAMS. Do not treat any percentage as a guarantee of how many questions come from each domain.
What is the most common reasoning error on scenario questions?
Treating a red flag as a conclusion. A structuring pattern, an offshore wire, or a gatekeeper relationship is an indicator consistent with multiple typologies, some innocent. The exam rewards the candidate who selects the proportionate next step, such as EDD or documentation, rather than jumping to filing, exiting the customer, or naming an offence the facts do not yet support.
How do I distinguish FATF standards from actual legal obligations?
FATF Recommendations are international standards that bind countries, not institutions directly. They become legal obligations when transposed into domestic law and regulation. If a scenario asks what an institution must do, look for the domestic legal requirement; if it asks about international expectations or good practice, FATF is the correct frame. Mutual evaluations assess how effectively a country implements the standards, which is separate from any single institution's obligations.
Why does the risk-based approach sometimes make simplified measures the right answer?
Because proportionality is central to the risk-based approach. FATF's February 2025 standards update reinforced simplified measures for lower-risk scenarios. A scenario describing a low-risk customer, product, or channel where the answer choice applies simplified CDD can be correct, provided the institution's risk assessment supports it and the situation does not match an exclusion or higher-risk trigger.
When should I blame data quality instead of model tuning in a technology scenario?
Look at the facts describing inputs versus rules. Missing or malformed fields, duplicate records, and unpopulated risk indicators point to data quality, which degrades alert performance no matter how well scenarios are tuned. A documented typology that never generates alerts points to a coverage or design gap. A surge of low-quality alerts after a rule change points to tuning thresholds. Classify the defect before selecting the fix.
What belongs in a SAR/STR case file: evidence or intelligence?
Evidence carries the suspicion: transaction records, screening results, CDD documentation, and a reasoned narrative. Intelligence such as typology alerts or unverified tips can justify opening a review, but it is not itself evidence and should be labeled as such. A case file built on intelligence without supporting evidence is weak; exam scenarios reward the answer that identifies what documentation substantiates the suspicion.
How do design effectiveness and operating effectiveness differ in program questions?
Design effectiveness asks whether the program's policies, controls, and risk assessment address the institution's actual risks. Operating effectiveness asks whether they work as executed in practice. A program can have current policies, high training completion, and documented procedures, yet fail operationally because tuning is stale, alerts go unreviewed, or the risk assessment predates significant changes. Independent testing must address both dimensions, and a scenario's facts usually reveal which one is broken.
Is information sharing with other institutions always the cooperative, correct choice?
No. Sharing is only correct through a lawful channel. Jurisdiction-specific rules, privacy law, and tipping-off prohibitions constrain what can be shared, with whom, and when. Permitted channels include FIU-mediated requests and authorized public-private or institution-to-institution arrangements where the law allows them. The safe exam answer routes an informal request through legal and compliance rather than releasing customer files directly.