Table of Contents
ACAMS CGSS
Explore source-grounded summaries, flashcards, reference tools and realistic mock practice.
Quick answer: Sanctions due diligence identifies who is involved, who owns or controls them, what is being supplied or paid for, where value moves, and who ultimately uses or benefits from it. The risk assessment measures inherent exposure, evaluates control effectiveness and records the residual risk and required action.
Screening is one control inside due diligence. A clean name result does not resolve an opaque owner, prohibited end use, restricted territory or deliberately incomplete transaction.
What a Sanctions Risk Assessment Measures
Inherent risk is the exposure before controls. Control effectiveness asks whether policies, data, screening, due diligence, escalation and testing are designed properly and actually work. Residual risk is what remains after those controls.
Relevant factors can include:
- customer and counterparty type;
- beneficial ownership and control;
- jurisdiction and geographic connections;
- product, service, technology or goods;
- delivery and payment channels;
- transaction purpose, value and frequency;
- intermediaries, distributors and other third parties; and
- end user and end use.
The assessment should explain the link between evidence and rating. A label such as “high risk country” without identifying the exposure, source and affected activity is difficult to defend.
Customer and Ownership Due Diligence
Identify the legal customer and every relevant owner, controller, director, signatory and connected party. Verify information through reliable sources, not only a customer declaration.
Trace indirect ownership when companies sit between the customer and ultimate owner. Assess control separately through voting, appointments, contracts, financing and actual decision-making. Apply the ownership and control definitions of the relevant sanctions regime.
The customer’s purpose and expected activity should make commercial sense. An entity formed recently, operating outside its stated sector or using unrelated payment parties may need further explanation, but each fact remains an indicator rather than proof.
Transaction, Product and End-Use Review
A transaction review should answer:
- Who are all relevant parties, including intermediaries and financial institutions?
- What goods, services, technology or value are involved?
- Where do they originate, transit and end?
- Who is the end user, and what is the stated end use?
- Do documents, payments and behavior support that explanation?
- Does a prohibition, licence, exemption or reporting duty apply?
Trade and supply-chain activity may require invoices, contracts, transport documents, product codes, certificates, routing and third-party information. Generic descriptions such as “equipment” or “consulting” may be insufficient when the sanctions risk depends on the specific item or service.
Free Topic Quiz & Key Practice Questions
Try 15 questions from Governance and Enforcement
This preview shows one part of the course. Try this short topic quiz and unlock the full course for complete mock exams and full coverage.
Which CGSS concept is most precisely described by the following statement? Restrictive measures imposed under a competent authority to influence conduct, protect security or pursue defined foreign-policy objectives.
When to Apply Enhanced Due Diligence
Enhanced due diligence should target the unresolved risk. If ownership is opaque, obtain and corroborate corporate records. If origin is unclear, reconcile trade and transport evidence. If a third party funds the deal, establish its relationship and commercial rationale.
More documents do not automatically mean better due diligence. Evidence should be relevant, reliable, current and consistent. A weak copy of the same unsupported assertion does not become strong because it appears in several customer-supplied files.
Possible outcomes include approval with controls, approval under licence conditions, monitoring, further information, escalation, rejection, blocking, reporting or exit. The correct action depends on law, risk, evidence and internal authority.
Periodic and Event-Driven Review
Periodic refresh frequency should reflect risk. Event-driven review matters when a party is designated, ownership changes, a new jurisdiction or product appears, activity departs from expectations, a licence changes or adverse information emerges.
List updates can require prompt rescreening. Corporate and vessel structures can change between scheduled reviews. Controls should identify which data changed, which population was affected, whether past activity needs review and who approved the outcome.
Document the sources, dates, reasoning, conditions and unresolved matters. A reviewer should be able to reconstruct why the organisation proceeded or stopped.
CGSS Exam Traps
- Screening equals due diligence: screening cannot replace ownership, purpose and end-use analysis.
- High risk equals prohibited: higher risk may trigger enhanced measures; prohibition depends on the applicable rule.
- More documents equals stronger evidence: relevance and reliability matter.
- One review lasts forever: use periodic and event-driven refresh.
- Third-party due diligence transfers responsibility: the organisation remains accountable for its decision.
- Residual risk is the same as inherent risk: assess controls before determining what remains.
Deepen the ownership analysis with beneficial ownership and control and connect the result to screening alert decisions. For all five domains, use the CGSS exam guide.
Frequently Asked Questions
1 What is sanctions due diligence?
Sanctions due diligence identifies relevant parties, ownership and control, jurisdictions, products, transactions, end users and end uses so an organisation can apply legal restrictions and manage exposure.
2 What is inherent sanctions risk?
Inherent risk is the exposure before controls are considered. It can arise from customers, jurisdictions, products, services, delivery channels, transactions and third parties.
3 What is residual sanctions risk?
Residual risk is the exposure remaining after considering whether relevant controls are properly designed and operating effectively.
4 When is enhanced sanctions due diligence needed?
Enhanced work is appropriate when risk is higher or ordinary information cannot resolve important questions. It should be proportionate and targeted to the ownership, control, geography, goods, transaction or end-use concern.
5 How often should sanctions due diligence be refreshed?
Use both risk-based periodic review and event-driven review when lists, ownership, control, counterparties, products, routes, behavior or other relevant facts change.
Keep learning
Related Insights
Sanctions Beneficial Ownership and Control: CGSS Guide
Distinguish ownership from control, trace direct and indirect interests and avoid applying one sanctions ownership threshold across every regime.
Sanctions Compliance Program Governance: CGSS Guide
Define board, senior management, sanctions officer and three-lines responsibilities, then measure whether a sanctions program works in practice.
Asset Freezing, Blocking and Rejecting: CGSS Guide
Distinguish asset freezing, blocking and rejecting, understand licence scope and choose the correct jurisdiction-specific sanctions response.
Ready to Prepare for ACAMS CGSS?
Use source-grounded study tools and realistic practice to build accurate recall and exam-day confidence.
Explore Course Preparation