Practice Exams:

Governance & Compliance

ACAMS CAMS: Writing Useful Suspicious Activity Reports

A suspicious activity report is not the place to reproduce an investigation file verbatim. Its job is to give the receiving authority a clear, concise, fact-based explanation of the suspicious activity and the context needed to understand why it matters. The narrative should help a reader reconstruct the pattern without guessing which transactions or relationships drove the decision. Within AML operations, SAR writing sits at the end of a chain that begins with customer understanding and monitoring. A strong report depends on evidence gathered during alert triage, investigation, and escalation….

Read More

ACAMS CAMS: Transaction Monitoring Alert Triage

This certification-study article presents a concise conceptual overview for readers who need context before consulting implementation documentation. It is intentionally non-procedural and focuses on terminology, responsibilities, tradeoffs, governance, and review questions.Use it as an orientation point for study, architecture discussion, governance, and operational planning. Product-specific configuration and execution details should be taken from the relevant vendor documentation and organizational standards.

Read More

ACAMS CAMS: Sanctions Screening False Positives

Sanctions screening systems deliberately cast a wide net. Names can be transliterated in multiple ways, data can be incomplete, aliases can overlap with ordinary customers, and automated matching must tolerate spelling and formatting differences. The result is a recurring operational problem: many alerts that resemble a listed party but are not true matches. Within AML operations, false positives are not merely an efficiency issue. Excessive noise consumes analyst time, delays onboarding or payments, and can hide important cases in a large queue. The goal is to reduce predictable noise without…

Read More

ACAMS CAMS: Risk-Based AML Programs in Practice

A risk-based AML program is built around a simple idea: not every customer, product, geography, transaction, or delivery channel creates the same exposure. The difficult part is turning that idea into consistent operating decisions. Institutions need a documented way to identify risk, rank it, apply proportionate controls, monitor whether those controls work, and adjust when new evidence changes the picture. The framework belongs at the center of AML operations because due diligence, screening, transaction monitoring, quality assurance, investigations, and reporting all depend on risk decisions. ACAMS certifications emphasize this connection…

Read More

ACAMS CAMS: Customer Due Diligence Beyond Checklists

Customer due diligence is often implemented as a sequence of forms, identity checks, ownership questions, and approval fields. Those steps are necessary, but the real purpose is to build a defensible understanding of who the customer is, why the relationship exists, what activity should be expected, and what risk factors deserve continued attention. A completed checklist without that understanding creates the appearance of control without the substance. Within AML operations, customer information is the context used by screening, transaction monitoring, investigation, escalation, and periodic review. The current CAMS body of…

Read More

ISACA CISA: Testing Access Controls in an Audit

Access-control audits fail when they treat identity as a list of accounts instead of a lifecycle of authorization decisions. An effective test asks who received access, why it was granted, how privileges changed as responsibilities changed, what technical enforcement exists, and whether the organization can remove access when the business justification ends. The current CISA scope places identity and access management within protection of information assets while audit execution includes sampling, evidence collection, analytics, and reporting. Within security governance, those disciplines come together in a test that connects entitlement data…

Read More

ISACA CISA: Reporting Audit Findings Clearly

This certification-study article presents a concise conceptual overview for readers who need context before consulting implementation documentation. It is intentionally non-procedural and focuses on terminology, responsibilities, tradeoffs, governance, and review questions.Use it as an orientation point for study, architecture discussion, governance, and operational planning. Product-specific configuration and execution details should be taken from the relevant vendor documentation and organizational standards.

Read More

ISACA CISA: IT Audit Scoping That Finds Real Risk

Audit scoping is where much of an engagement’s value is decided. A scope that is too broad produces shallow checklist coverage, while a scope that is too narrow can miss the dependency or control boundary where the material risk actually sits. Risk-based scoping creates a defensible connection between business objectives, technology, threats, control history, and the work the audit team will perform. Within Security Governance & Assurance, scoping should begin with the outcome the organization needs to protect. Systems, cloud accounts, vendors, applications, data stores, identities, and operational processes are…

Read More

ISACA CISA: Evidence Quality in IT Audits

An audit conclusion is only as strong as the evidence supporting it. Large quantities of screenshots, exported reports, policy documents, and interview notes can create the appearance of rigor while still failing to prove that a control operated as described across the relevant period and population. Within Security Governance & Assurance, evidence quality depends on relevance, reliability, completeness, timing, source, and the relationship between the artifact and the audit objective. The auditor should know what claim each piece of evidence supports and what uncertainty remains after reviewing it. Good evidence…

Read More

ISACA CISA: Auditing Cloud Environments

Cloud audits are difficult when reviewers treat the cloud as either someone else’s infrastructure or a long list of provider settings. The audit has to connect the provider’s control environment with the customer’s architecture, identity model, data handling, configuration, monitoring, and resilience responsibilities. Within Security Governance & Assurance, the first task is to identify the business services and data that depend on the cloud environment. Only then can the auditor decide which shared-responsibility boundaries, technical controls, provider attestations, and operational practices are relevant to the risk being assessed. A useful…

Read More

ISACA CISA: Auditing Change Management

Change management is designed to let organizations modify production systems without turning every release into an uncontrolled experiment. An audit therefore needs to evaluate more than whether a request was logged. It should test whether changes are authorized, assessed, implemented, reviewed, and recoverable in a way that preserves business service objectives. Within Security Governance & Assurance, change is a control chain that connects governance, development, operations, incident response, and business ownership. A technically successful deployment can still represent a control failure if it bypassed approval, lacked testing, or introduced risk…

Read More

IAPP AIGP: Managing Third-Party AI Risk

Third-party AI risk is difficult because the organization depends on a system it does not fully control. A vendor can change models, subprocessors, security controls, training practices, pricing, retention, geographic processing, or service limits while the customer continues to depend on the same business workflow. Governance therefore has to manage both the AI behavior and the dependency relationship. The current AIGP framework treats deployment and lifecycle governance as broader than internal development. That is important because many organizations consume AI through SaaS products, embedded copilots, APIs, and enterprise platforms rather…

Read More

IAPP AIGP: Data Governance for AI Systems

AI governance is often discussed as model governance, but many production failures originate in the data around the model. Training datasets, evaluation sets, retrieval indexes, prompts, user feedback, tool outputs, logs, and generated records all have different owners, permissions, retention needs, and quality expectations. Data governance gives the organization a way to manage those differences across the AI lifecycle. The current AIGP body of knowledge explicitly includes governing the collection and use of data in training and testing AI systems. That scope matters because responsible deployment depends on more than…

Read More

IAPP AIGP: Building an AI Risk Register

An AI risk register should help teams decide what to change, not become a catalog of everything that could theoretically go wrong with artificial intelligence. The most useful entries connect a concrete scenario to an affected objective, owner, evidence, control plan, and residual exposure. If a risk cannot influence a design, approval, monitoring threshold, contract, or operating decision, the register is probably too abstract. The current AIGP materials emphasize governance across the AI lifecycle, which means risk identification cannot stop at model development. Deployment context, data, users, vendors, monitoring, human…

Read More

IAPP AIGP: AI Transparency That Users Can Understand

AI transparency is useful only when the intended audience can understand what the information means for a real decision. A model card, technical paper, disclosure notice, and user-interface explanation all serve different purposes. Publishing more detail does not automatically make a system more transparent if the people affected cannot tell when AI is involved, what it is doing, what information it uses, or how to challenge an outcome. The current AIGP framework treats responsible AI governance as a lifecycle responsibility that includes communicating organizational expectations and governing deployment and use….

Read More