CTMA Exam Overview and Format
The Certified Transaction Monitoring Associate (CTMA) from ACAMS is an associate-level credential aimed at the people who actually clear the alert queue: transaction monitoring analysts, alert investigators, AML operations staff, and KYC, fraud, and screening support roles. ACAMS positions the certification around building essential skills in transaction monitoring, alert investigation, documentation, escalation, and reporting outcomes — which maps directly onto the day-to-day decision of whether an alert is noise, a pattern, or a case.
The official exam format is 60 questions in 90 minutes, with 74 percent of scored items required to pass. That pass mark deserves attention: it leaves very little room for the kind of fuzzy reasoning that fails in real investigations. Questions that test whether a red flag is a conclusion, or whether an alert fits expected customer behavior, are exactly where partial understanding collapses.
One planning note: ACAMS does not list every language used by this site as an official exam language. Before booking, verify current language availability, scheduling, and any format details directly with ACAMS, since delivery arrangements can change. Localized study remains valuable for comprehension; just confirm the exam itself is offered in the language you intend to sit.
Full CTMA Syllabus Map
The syllabus divides into four domains. The table below is the complete map you should be able to reconstruct from memory before exam day, with the applied practice focus that exam questions are built around.
| Domain | Scope | Applied Practice Focus |
|---|---|---|
| 1. Transaction Monitoring Fundamentals (25%) | Purpose of monitoring, rule-based vs risk-based monitoring, alert generation, scenarios, thresholds, peer groups, customer profiles, data quality | Explain why an alert fired and whether it fits expected behavior |
| 2. Alert Investigation Process (30%) | Triage, review steps, evidence gathering, customer context, linked accounts, narrative notes, QA, closure rationale | Document a clear investigation path and avoid unsupported conclusions |
| 3. Suspicious Activity Identification (30%) | Structuring, layering, rapid movement, trade-based indicators, fraud proceeds, cyber-related typologies, mule networks, anomalies | Connect red flags to typologies and escalation decisions |
| 4. Escalation and Reporting (15%) | SAR/STR escalation, reasonable suspicion, tipping-off risk, case handoff, management information, quality assurance, control feedback | Determine when to close, monitor, escalate, or file based on evidence |
CAMSExam Recommended Study Emphasis by Domain
The Hardest Concept Boundaries on the CTMA
Most CTMA candidates do not fail because they never read about structuring. They fail at the seams between domains, where two concepts look interchangeable but demand different answers. These are the boundaries worth drilling.
Red flag versus conclusion. A red flag is an indicator that warrants inquiry; it is never, by itself, proof of money laundering. The exam repeatedly tests whether you can hold this line. A customer depositing cash just under a reporting threshold is a red flag. It becomes part of a suspicion only when combined with context: the customer's stated cash-intensive business, peer group behavior, and the pattern over time. An answer choice that jumps from indicator to conclusion — "the customer is structuring, so file immediately" — is almost always wrong when the scenario has not established the supporting context. The correct first step is usually to gather more evidence, not to decide the outcome.
Standard versus law. The FATF Recommendations, updated in October 2025, form the international framework, but they are recommendations — national law implements them with local thresholds, reporting forms, and timelines. The exam will not ask you to treat a jurisdiction-specific threshold as universal. When a scenario mentions a specific reporting rule, treat it as one jurisdiction's implementation, not a global constant. The transferable skill is knowing that suspicious transaction reporting obligations exist across the framework and that the analyst's job is escalation within their institution's program, not legal adjudication.
Data quality versus model performance. In the monitoring fundamentals domain, candidates confuse these constantly. If alerts are firing on stale customer profiles or miscoded transactions, that is a data quality problem — fixing the scenario logic will not help. If the scenario logic itself is generating noise because thresholds or peer groups are mis-set, that is a tuning or model design problem. The exam's applied focus — "explain why an alert fired" — requires you to trace the alert to its cause: which scenario, which threshold, which customer attribute, and whether the underlying data was even accurate. An alert that fired on a business customer still profiled as a low-risk individual is a profile defect, not a typology.
Evidence versus intelligence. In an investigation, evidence is what you can document from your institution's own records: transactions, KYC files, linked accounts, screening results, and the customer's stated purpose. Intelligence — typology reports, national priorities, law enforcement feedback — explains what a pattern might mean but is not itself proof about your customer. FinCEN's national AML/CFT priorities, issued June 30, 2021, cover corruption, cybercrime, terrorist financing, fraud, transnational criminal organizations, drug trafficking, human trafficking and smuggling, and proliferation financing. These priorities tell you where risk concentrates; they do not make your customer guilty of anything. Strong narratives cite the observed activity first, then reference the typology it resembles.
Close, monitor, escalate, or file. The escalation domain is small in study emphasis but dense in judgment. The four outcomes are not a ladder of increasing certainty — they are different responses to different evidence states. Close when the activity is explained and documented. Monitor when the activity is unusual but not yet suspicious and the pattern needs time to develop. Escalate when the evidence crosses into reasonable suspicion territory within your institution's process. File when the designated decision-maker confirms the suspicion meets the reporting standard. Choosing "file" when the scenario only supports "monitor" is as wrong as choosing "close" when the facts support escalation.
Tipping-off discipline. Once a report is filed or escalation is in motion, the customer must not be informed in a way that reveals the suspicion. The exam tests this through scenario answers that involve contacting the customer "to clarify" after escalation. Clarification questions belong in the investigation phase, before the escalation decision — not after.
Mini-Scenarios and Decision Traps
The following compact scenarios reflect the applied practice focus of each domain. Work through the best next step and, just as importantly, why the tempting alternative fails.
Scenario 1 — The threshold-adjacent cash deposits. A bakery owner deposits cash amounts that individually sit just below the local reporting threshold, across three branches in one week. The KYC file shows a legitimate cash-intensive business with seasonal revenue. Best next step: review the deposit pattern against the customer's historical cash activity and expected profile, and check linked accounts for offsetting transfers. The tempting alternative — treating the sub-threshold amounts as conclusive structuring and recommending a filing immediately — is premature. Sub-threshold deposits are a red flag, but the customer's profile and business type may fully explain the pattern. The investigation must establish whether the behavior deviates from the customer's own baseline before suspicion is reasonable.
Scenario 2 — The rapid in-and-out movement. A personal account receives a transfer from a new third party and, within 48 hours, sends nearly the same amount onward in smaller increments to four unrelated individuals. The customer's stated income is a modest salary. Best next step: gather evidence on the counterparties, the purpose of the inbound transfer, and any linked accounts, then assess the pattern against layering and mule-network typologies and escalate through the institution's process. The tempting alternative — closing the alert because each individual transaction is small and unremarkable — fails because the exam tests pattern recognition, not transaction-by-transaction review. Rapid movement of funds with no economic rationale is a recognized typology regardless of the size of each component transaction.
Scenario 3 — The stale-profile false positive. An alert fires on a customer flagged for activity inconsistent with a "low-risk individual" profile. Investigation shows the customer converted to a registered business account six months ago and the activity is entirely consistent with that business. Best next step: close the alert with a documented rationale that identifies the root cause as an outdated customer profile, and flag the profile defect for remediation through QA and control feedback channels. The tempting alternative — simply closing the alert as a false positive without noting the data defect — leaves the scenario generating noise indefinitely. The escalation domain explicitly includes control feedback: a closure that does not feed the root cause back into the monitoring system is an incomplete investigation.
Scenario 4 — The post-escalation customer call. An investigator escalates a case for potential SAR filing. The next day, the relationship manager suggests calling the customer to ask about the recent transactions "to help clear things up." Best next step: decline the customer contact and route the question through the escalation owner, because informing the customer of the basis for suspicion creates tipping-off risk. The tempting alternative — treating the call as routine due diligence — fails because the timing matters: the same questions asked during investigation are legitimate; asked after escalation, they can compromise the reporting process.
A Four-Week Study Plan
This plan allocates time roughly in line with the CAMSExam recommended study emphasis, front-loading the two 30 percent domains while reserving dedicated time for the judgment-heavy escalation domain.
How CTMA Skills Apply on the Desk
Every domain of the CTMA corresponds to a skill that AML operations teams are measured on in quality reviews and regulatory examinations. The credential is most valuable where these skills are weakest in practice.
Official Sources to Verify Before Exam Day
Always anchor your study to primary sources, and re-verify exam logistics with the provider before booking. The official ACAMS CTMA page describes the certification's skill scope (ACAMS CTMA Certification). For the international framework, consult the FATF Recommendations, last updated in October 2025. For U.S. context on where monitoring risk concentrates, review the FinCEN National AML/CFT Priorities issued June 30, 2021, and the FinCEN AML/CFT Program proposed rule from April 2026, which addresses risk assessments, priorities incorporation, and risk-based program expectations.
Frequently Asked Questions
What is the CTMA exam format and pass mark?
The official ACAMS format is 60 questions in 90 minutes, with 74 percent of scored items required to pass. Because the pass mark is high, partial understanding of boundary concepts — such as the difference between a red flag and a conclusion — is more costly than on exams with more forgiving thresholds. Confirm current logistics with ACAMS before booking, as delivery details can change.
Is the CTMA a beginner certification?
It is an associate-level credential, but associate does not mean trivial. It targets working analysts and early-career AFC professionals who need to demonstrate defensible judgment in alert investigation, documentation, and escalation. The applied focus assumes you can reason through incomplete facts, not just recall definitions.
How should I split my study time across the four domains?
The CAMSExam recommended emphasis is 25 percent on monitoring fundamentals, 30 percent on alert investigation, 30 percent on suspicious activity identification, and 15 percent on escalation and reporting. This is a preparation emphasis, not an official exam weighting. Note that the smallest domain, escalation, carries disproportionate judgment difficulty, so do not starve it of time.
What is the single most common conceptual error on this exam?
Treating a red flag as proof. A sub-threshold cash deposit, an unusual counterparty, or rapid fund movement is an indicator that warrants inquiry — not a conclusion. The exam rewards candidates who select the next investigative step that gathers evidence, and penalizes answers that leap from indicator to filing decision without established context.
Do I need to memorize specific reporting thresholds and SAR timelines?
No, and trying to is a mistake. The FATF framework sets international standards, but thresholds, forms, and timelines are jurisdiction-specific implementations. The exam tests whether you understand the concepts — structuring, reasonable suspicion, tipping-off — and whether you can recognize that a specific rule is one jurisdiction's law rather than a universal standard. Never present a jurisdiction-specific threshold as universal.
How does data quality affect transaction monitoring, and why does the exam care?
Alerts are only as good as the data behind them. Stale customer profiles, miscoded transactions, and missing linked-account relationships generate false positives that no amount of scenario tuning will fix. The exam's applied focus on explaining why an alert fired requires you to distinguish a data defect from a tuning defect from a genuine typology — three different problems with three different remediations.
What is the difference between closing an alert and monitoring a customer?
Closing means the activity is explained and the rationale is documented; the investigation is complete. Monitoring means the activity is unusual but does not yet meet the suspicion standard, and the pattern needs continued observation before a decision can be made. Monitoring is not a soft close — it is a deliberate holding state that should define what would trigger the next review.
How do the FinCEN national priorities relate to CTMA study?
FinCEN's June 30, 2021 priorities — including fraud, cybercrime, corruption, terrorist financing, and transnational criminal organizations, among others — describe where AML/CFT risk concentrates. They are intelligence context, not evidence about any specific customer. Use them to recognize which typologies matter and why institutions prioritize certain monitoring scenarios, but never treat a priority category as making a customer suspicious by association.
Is English an official exam language for the CTMA?
ACAMS does not list every language used by this site as an official exam language, so you should verify language availability directly with ACAMS before booking. Localized study materials remain valuable for building comprehension of difficult concepts, but the exam itself must be sat in a language ACAMS actually offers at the time of your appointment.