ABA · CAFP
The ABA CAFP certifies financial professionals in anti-money laundering and fraud prevention within U.S. banking institutions. It validates expertise across assessment, investigation, reporting, and remediation of financial crimes.
Practice Questions
750
≈ 5 practice exams
Duration
180 minutes
Passing Score
500/800
Difficulty
ProfessionalLast Updated
Mar 2026
Use this CAFP practice exam to prepare for Certified AML and Fraud Professional (CAFP) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 750 questions for ABA CAFP, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as BSA/AML Compliance, Fraud Detection and Prevention, Financial Crimes Assessment, Investigations, and Regulatory Reporting. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The ABA Certified AML and Fraud Professional (CAFP) is an advanced-level credential issued by the American Bankers Association (ABA) that validates a financial professional's expertise in anti-money laundering (AML) and fraud prevention within U.S. banking institutions. The certification tests competency across the full lifecycle of financial crimes response: assessing risk and identifying suspicious activity, conducting thorough investigations, fulfilling regulatory reporting obligations, and executing remediation strategies. It is grounded in U.S. laws and regulations, including the Bank Secrecy Act (BSA), the USA PATRIOT Act, and federal fraud statutes.
The CAFP was developed by an advisory board of financial crimes practitioners to reflect real-world job tasks performed by competent professionals in the field. It covers traditional AML and fraud disciplines as well as emerging threats such as cyber-enabled financial crimes. The credential signals to employers that a professional possesses both the theoretical knowledge and practical application skills required to protect banking institutions from money laundering, fraud, terrorist financing, and related financial crimes.
The CAFP is designed for experienced financial crimes professionals employed within U.S. banking institutions. Suitable candidates include BSA/AML compliance officers, fraud investigators, financial crimes analysts, risk managers, internal auditors, compliance consultants, and state or federal bank examiners and law enforcement personnel working with financial institutions. The certification is also relevant for professionals in legal, operations, and cyber units who deal with financial crimes detection or response.
Candidates are expected to have hands-on, U.S.-based banking experience in BSA/AML compliance, fraud detection, or cyber-enabled financial crimes. Because the exam is grounded in U.S. laws and regulations, it is specifically suited to professionals operating within the U.S. banking regulatory environment, rather than general financial services or international practitioners.
ABA requires candidates to meet one of three eligibility pathways before sitting for the CAFP exam. The first pathway requires a minimum of two years of qualifying U.S. banking financial crimes experience plus completion of at least one approved BSA/AML or fraud training program. The second pathway requires a minimum of two years of qualifying experience plus current holding of at least one approved professional certification (such as CAMS, CFE, CRCM, CIA, or CBAP). The third pathway is available to candidates with five or more years of qualifying financial crimes experience, with no additional training or certification requirement.
All candidates must have direct experience in BSA/AML compliance, fraud detection, and/or cyber-enabled financial crimes within a U.S. banking context. Non-U.S. experience does not satisfy the eligibility criteria. Candidates must also agree to the ABA Professional Certifications Code of Ethics upon application. ABA reviews applications and notifies candidates of approval or denial within approximately two weeks of submission.
The CAFP exam consists of 150 multiple-choice questions to be completed within 180 minutes (3 hours). The exam is scored on a scale with a passing score of 500 out of 800. Calculators are provided at testing sites. Exams are administered through Meazure Learning either at physical U.S. test sites or via live remote proctoring (LRP) through the ProctorU platform, which allows candidates to test from a private location with a live remote proctor, provided they meet the technical requirements.
The exam is offered during a defined testing window (for example, July 1–31 of a given year), and candidates must apply by the published application deadline. For most computer-based exams taken at test sites, candidates receive an instant Pass/Fail result upon completion. Official score reports are delivered via email within six weeks after the close of the exam window. The exam fee is $575 USD, and a non-refundable $100 application fee is retained if an application is denied.
Earning the CAFP positions professionals for advancement into senior financial crimes roles such as BSA Officer, AML Program Manager, Fraud Director, Chief Compliance Officer, or Financial Crimes Consultant. The designation demonstrates a validated, practitioner-level competency in a specialized and increasingly regulated domain, differentiating holders from peers who rely solely on general compliance or audit credentials. Employers in the U.S. banking sector — including commercial banks, credit unions, and federal regulatory agencies — actively seek professionals who can demonstrate this level of expertise as financial crimes compliance obligations intensify.
The credential is issued by the American Bankers Association, the principal trade association for U.S. banks, lending it strong industry recognition among domestic banking employers and regulators. Holding the CAFP alongside or in place of related credentials such as CAMS (ACAMS) or CFE (ACFE) can broaden a professional's appeal, as CAFP is uniquely focused on the intersection of both AML and fraud within the U.S. banking regulatory framework. Continuing education requirements for renewal ensure that certified professionals maintain current knowledge, reinforcing the credential's long-term value to employers.
5 sample questions with answers and explanations. The full bank has 750 questions, enough for 5 full-length practice exams.
Preview — answers shown1. Fabrikam Trust Bank's internal audit team is evaluating the effectiveness of the bank's three lines of defense model. The audit committee wants to understand which line is responsible for developing and maintaining the bank's AML/CFT policies and overseeing the transaction monitoring system. Which line of defense holds this responsibility? (Select one!)
Explanation
The second line of defense — compliance and risk management functions — is responsible for developing AML/CFT policies, overseeing transaction monitoring systems, managing SAR oversight, and designing training programs. The second line provides risk oversight and sets the policy framework that the first line implements. The first line (business units and front office) is responsible for executing KYC/CDD procedures, identifying and escalating suspicious activity, and maintaining customer records — they own the risk but do not set the policies. The third line (internal audit) provides independent assurance by evaluating the effectiveness of both the first and second lines and reports findings to the board or audit committee. While the board holds ultimate responsibility for the BSA program, it does not directly develop policies or manage monitoring systems — that operational responsibility belongs to the second line.
2. Northwind Regional Bank's risk management team is reviewing the three lines of defense model to ensure proper organizational structure. The bank's BSA/AML officer currently reports to the Chief Operating Officer, who also oversees the retail banking division. A regulatory examiner raises concerns about this reporting structure. Which principle of the three lines of defense model is most directly at risk? (Select one!)
Explanation
The second line of defense, which includes compliance and risk management functions such as the BSA/AML officer, must maintain independence from business line operations to provide effective oversight. When the BSA/AML officer reports to the Chief Operating Officer who also oversees retail banking, a conflict of interest exists because the same executive controls both the business activities being monitored and the compliance function doing the monitoring. This undermines the independence necessary for the second line to effectively challenge business line decisions. The first line's KYC/CDD implementation is a separate concern from the reporting structure issue. Internal audit constitutes the third line and provides independent assurance but does not supervise the BSA/AML officer. Requiring all three lines to report to the same executive would actually violate the model's principles of independence and segregation.
3. Adatum Heritage Bank's compliance department is reviewing whether a longtime customer qualifies for a CTR exemption. The customer is a locally owned hardware store that has maintained an account for four years and typically makes cash deposits exceeding $10,000 about eight times per year. The store is incorporated under state law. Under which CTR exemption phase does this customer potentially qualify? (Select one!)
Explanation
The hardware store qualifies as a potential Phase II exempt person under 31 CFR 1020.315. Phase II exemptions apply to non-listed businesses that meet three criteria: the business has maintained a transaction account at the bank for at least two months, it frequently engages in reportable currency transactions (generally five or more per year), and it is incorporated or organized under U.S. federal or state law. The hardware store meets all three criteria — four years as a customer, eight reportable cash transactions per year, and state incorporation. Phase I exemptions are reserved for banks, government agencies, NYSE/NASDAQ/NYSE American-listed entities, and their 51%+ owned subsidiaries — a local hardware store does not qualify for Phase I. Retail businesses are not categorically excluded from Phase II exemptions. Phase II requires filing a Designation of Exempt Person form and conducting annual reviews.
4. Northwind Federal Bank's compliance team is reviewing the penalties associated with the Corporate Transparency Act (CTA) for beneficial ownership information reporting violations. A reporting company willfully provides false beneficial ownership information to FinCEN. What are the maximum criminal penalties the company could face? (Select one!)
Explanation
Under the Corporate Transparency Act (31 USC §5336), criminal penalties for willfully providing false or fraudulent beneficial ownership information to FinCEN include fines of up to $10,000 and/or imprisonment for up to 2 years. The $500 per day amount refers to civil penalties for violations, not criminal penalties. The $50,000 and $250,000 fine amounts with longer imprisonment terms are not the penalties specified under the CTA for beneficial ownership reporting violations. The CTA also imposes civil penalties of up to $500 per day for non-willful violations, which is a separate penalty structure from the criminal provisions.
5. Litware Savings Bank is updating its BSA/AML compliance program after an internal audit. The auditors noted that the bank's Customer Identification Program (CIP) record retention practices do not meet regulatory requirements. Under 31 CFR 1020.220, how long must a bank retain identifying information collected during the CIP process after an account is closed? (Select one!)
Explanation
Under Section 326 of the USA PATRIOT Act and its implementing regulation 31 CFR 1020.220, banks must retain identifying information collected during the CIP process for 5 years after an account is closed. This includes the four minimum data elements — name, date of birth, address, and identification number. Verification records must be retained 5 years after creation. Three years is insufficient under the regulation. Seven and ten years exceed the regulatory requirement and would impose unnecessary retention burdens.
Certified IRA Services Professional (CISP)
CISP · 700 questions
Certified Regulatory Compliance Manager (CRCM)
CRCM · 700 questions
Certified Trust and Fiduciary Advisor (CTFA)
CTFA · 699 questions
Certified Enterprise Risk Professional (CERP)
CERP · 749 questions
Certified Financial Marketing Professional (CFMP)
CFMP · 750 questions
$17.99
One-time access to this exam