CAMS · Question #918
A compliance manager at a virtual asset service provider (VASP) is evaluating its business and its impact on AML policies. Which of the following features of the VASP's business would be of greatest…
The correct answer is A. Allowing clients lo transact anonymity-enhanced tokens B. Onboardlng of clients who are residents abroad. Including those with politically exposed person D. Offering services to VASPs established in jurisdictions that are not FATF compliant F. Lack of adequate IP address tracking capabilities. VASPs face heightened AML risk from privacy-enhancing tokens, PEP clients, non-FATF-compliant counterparty jurisdictions, and gaps in transaction monitoring capabilities.
Question
A compliance manager at a virtual asset service provider (VASP) is evaluating its business and its impact on AML policies. Which of the following features of the VASP's business would be of greatest concern? (Select Four.)
Options
- AAllowing clients lo transact anonymity-enhanced tokens
- BOnboardlng of clients who are residents abroad. Including those with politically exposed person
- CEnabling transfer of tokens from one blockchain to another
- DOffering services to VASPs established in jurisdictions that are not FATF compliant
- EOperating a network of crypto ATMs charging high fees
- FLack of adequate IP address tracking capabilities
How the community answered
(34 responses)- A85% (29)
- C3% (1)
- E12% (4)
Why each option
VASPs face heightened AML risk from privacy-enhancing tokens, PEP clients, non-FATF-compliant counterparty jurisdictions, and gaps in transaction monitoring capabilities.
Anonymity-enhanced tokens such as Monero or Zcash obscure transaction trails and beneficial ownership, making it technically impossible to perform required AML tracing under FATF's Travel Rule and related guidance. These assets are explicitly flagged by FATF as high-risk virtual assets requiring enhanced controls or outright restrictions.
Onboarding PEP clients residing abroad compounds both geographic risk and the inherently elevated risk of PEP relationships, requiring enhanced due diligence that is significantly harder to perform across jurisdictions. FATF guidance requires VASPs to apply enhanced measures to PEP relationships, including those involving foreign politically exposed persons.
Cross-chain token transfers carry some obfuscation risk but are a standard interoperability function and are not among the highest-concern features compared to privacy coins, PEP exposure, non-compliant jurisdictions, or monitoring capability gaps.
Providing services to VASPs domiciled in non-FATF-compliant jurisdictions exposes the business to counterparties operating without adequate AML and CFT controls, creating a high risk of layering through complicit or poorly supervised intermediaries. FATF Recommendation 16 requires VASPs to assess and restrict relationships with counterparty VASPs in non-compliant jurisdictions.
High fees at crypto ATMs are primarily a consumer protection concern and do not represent a primary AML red flag in the way anonymity features or jurisdictional deficiencies do.
Lack of IP address tracking removes a key data point for geolocation, sanctions screening, and identifying users potentially located in restricted jurisdictions, directly undermining the VASP's ability to fulfill KYC and transaction monitoring obligations.
Concept tested: VASP AML risk factors under FATF guidance
Source: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Guidance-rba-virtual-assets-2021.html
Topics
Community Discussion
No community discussion yet for this question.