Study this exam by rehearsing decisions, not definitions. For every concept — laundering stages, CDD, risk rating, STR — practise attaching it to an IFSC-style scenario: a non-resident corporate customer, a cross-border funds flow, an ownership structure with layers. If you can name the concept but cannot decide which tier of diligence or which reporting step a situation calls for, keep drilling scenarios before the exam.
Why the IFSC setting changes how AML/CFT concepts apply
The GIFT IFSC is a cross-border financial hub supervised by IFSCA, a unified authority. AML/CFT ideas learned from a purely domestic banking angle must be re-anchored to non-resident counterparties, foreign-currency activity, and internationally aligned standards.
Before IFSCA was established in 2020 under the International Financial Services Centres Authority Act, 2019, business in the IFSC sat under multiple domestic regulators, including RBI, SEBI, PFRDA, and IRDAI. IFSCA now serves as the unified regulator for financial products, services, and institutions in the IFSC. This history matters when you reason about supervision: the question of who regulates a fund management entity or banking unit in the IFSC has a single correct authority, and mixing in the legacy sector regulators is the natural confusion to guard against.
Build the habit of reading every concept through the IFSC lens. A wire transfer is not a routine domestic payment; it is typically a cross-border flow. A customer is often a non-resident person or entity. Standards are designed to align with international expectations for global financial centres, so FATF-style concepts — risk-based approach, beneficial ownership, cooperation between authorities — carry direct weight here. When you review any topic, write one sentence explaining how it looks different in a cross-border, single-regulator centre, and test yourself against that framing.
Separating the three stages of laundering from terrorist financing behaviour
Money laundering moves criminal proceeds through placement, layering, and integration so illicit origin is concealed. Terrorist financing concerns the destination and purpose of funds, which may be entirely lawful in origin — so clean money can still finance terrorism.
Trace the laundering cycle with a concrete chain. Placement puts illegal cash into the financial system, for example through deposits or purchase of negotiable instruments. Layering obscures the trail through transfers between accounts, jurisdictions, or products. Integration returns the funds to the apparent criminal as legitimate-looking wealth, such as an investment or business receipt. Each stage suggests different red flags: large cash at placement, rapid structured movement at layering, investment activity with no credible commercial logic at integration. Knowing which stage a fact pattern describes tells you which red flags to look for.
Terrorist financing behaves differently in a critical way, and the difference is easy to miss because a clean source and modest size look innocuous. Its funds may come from lawful sources — salaries, donations, business profits — because the offence concerns using funds for terrorist purposes, not the tainted origin of the money. A transaction with a lawful origin can therefore still raise terrorism-financing concern if the intended use points that way. This means your analysis must run on two tracks: follow the origin of funds for laundering, and follow the purpose and destination for terrorist financing. Train yourself to state both conclusions explicitly for any scenario.
KYC versus CDD versus EDD: picking the diligence level a situation calls for
KYC is identifying who the customer is. CDD goes further: verifying identity, understanding the relationship's purpose, identifying beneficial ownership, and monitoring ongoing activity. EDD is the strengthened set of measures applied when risk is elevated.
The practical confusion is treating identification as the whole job. Collecting and verifying identity documents satisfies the KYC slice, but CDD additionally requires understanding the intended nature of the relationship and the source of funds, looking through corporate structures to the natural persons who ultimately own or control the customer — the beneficial owners — and keeping the picture current through ongoing monitoring. A fact pattern in which documents were collected but no beneficial owner was established is incomplete CDD, not completed onboarding.
EDD is triggered by elevated risk rather than by a fixed customer category: factors such as a customer linked to a higher-risk jurisdiction, an unusually complex or opaque ownership chain, a politically exposed connection, or activity inconsistent with the customer profile. Use the table below as a matching drill: given a scenario, first locate the trigger, then select the tier. When you evaluate any scenario after the fact, the correct diligence tier is the one whose components match the trigger — not necessarily the tier that happened to be performed.
| Level | Core components | Typical trigger | Scenario cue in a question |
|---|---|---|---|
| KYC | Identify and verify the customer's identity | Establishing any new relationship | The facts mention ID documents only |
| Standard CDD | KYC plus purpose and nature of relationship, beneficial ownership, ongoing monitoring | Normal-risk customer with an understandable profile | Ownership is simple and activity matches the stated business |
| EDD | Deeper verification of source of funds and ownership, senior-level involvement, tighter ongoing monitoring | Higher-risk jurisdiction links, opaque structures, PEP connections, unusual activity | Layered holding companies or funds flows with no clear commercial rationale |
Worked scenario: applying the risk-based approach to a layered corporate customer
The risk-based approach allocates stronger controls where risk is higher instead of treating all customers identically. Completeness of paperwork is not a risk assessment; the scenario below shows why the two must be judged separately.
Scenario: an IFSC entity onboards a trading company whose shares sit in a holding company in a jurisdiction with known secrecy practices; the declared business is commodity trading with several planned cross-border transfers soon after account opening. All requested documents were provided. A plausible mistake is concluding that the file is complete, so standard CDD suffices. That reasoning confuses documentary completeness with risk: a sealed, tidy file can still conceal the persons ultimately controlling the account.
The better decision is to escalate to enhanced due diligence: trace the chain to the natural-person beneficial owners, corroborate the source of funds behind the planned transfers, obtain appropriate internal approval for the higher-risk relationship, and apply intensified ongoing monitoring with a defined review point. Why it matters: the risk-based approach is the organising principle of modern AML supervision, so your analysis must allocate effort according to risk signals — jurisdiction, structure, purpose, expected activity — rather than according to whether the checklist was ticked. Rehearse stating the risk drivers before naming the response.
Worked scenario: deciding to report suspicion without tipping off the customer
Suspicion is judged against the customer's profile and the transaction's logic, not only its size. Once a report decision is in motion, disclosing that scrutiny to the customer — tipping off — is prohibited, and the report path runs through internal escalation.
Scenario: a customer whose profile describes modest consultancy income begins receiving multiple inward transfers from unrelated overseas senders, each quickly moved onward to a third party, with the amounts structured to stay individually unremarkable. A plausible two-part mistake occurs when a staff member both calls the customer to ask casually about the transfers and decides internally that no report is needed because each transfer is small. Both steps are wrong on different grounds.
The better course: the pattern — unexplained senders, rapid pass-through, structuring — is evaluated against the customer profile and points to suspicion; the matter goes through internal escalation for a suspicious transaction report, and the employee must not reveal the scrutiny to the customer, because tipping off can defeat the purpose of reporting regardless of the report's eventual outcome. Assessing whether facts amount to suspicion and knowing the conduct obligations that attach once suspicion exists are two separable skills; practise each explicitly. Rehearse the sequence in order: observe, compare with profile, escalate, report, stay silent.
Mapping the framework: PMLA, FATF, and IFSCA roles without mixing them up
Keep three layers distinct: FATF sets international AML/CFT standards and assesses countries; India's Prevention of Money Laundering Act, 2002 supplies the domestic legal offences and reporting machinery; IFSCA regulates and develops financial activity within the IFSC.
A workable mental map has a standards layer, a law layer, and a supervisor layer. FATF operates at the standards layer: its recommendations shape what jurisdictions are expected to do, and its mutual-evaluation process reviews how well they comply — which is why internationally oriented centres such as the IFSC design regimes aligned with those expectations. The Prevention of Money Laundering Act, 2002 operates at the law layer: it defines laundering offences, attaches to proceeds of crime, and underpins obligations such as record keeping and reporting to the designated financial intelligence authority.
IFSCA sits at the supervisor layer for the IFSC: it is the unified authority for regulating and developing financial products, services, and institutions in the centre, headquartered at GIFT City. The layers interact in practice — supervising an IFSC intermediary is IFSCA's job, while the reporting obligation traces back to the legal layer. The natural confusion is answering with a layer-adjacent name, such as citing a legacy sector regulator for an IFSC supervisory question. When you revise each framework element, attach to it one function, one layer, and one example of a question it would answer.
A preparation sequence and self-check drill you can run before exam day
Sequence your revision in three passes: concepts and distinctions first, the IFSC framework second, scenario drills last. Finish by scoring yourself on a short written drill; treat the score as a learning milestone, not a predicted result.
A realistic sequence for a working candidate: in pass one, build one-page notes for the core distinctions — laundering stages versus terrorist financing, KYC versus CDD versus EDD, rule-based versus risk-based thinking. In pass two, map the institutional framework: IFSCA's unified role, the PMLA's offence and reporting machinery, FATF's standards function, and how they connect. In pass three, drill scenarios daily: write a five-line customer fact pattern, then answer three questions in writing — risk level, diligence tier, and whether a report is warranted and why.
Run this self-check drill in the final week. Construct two profiles: a low-risk, plainly documented non-resident individual, and a layered corporate with a higher-risk jurisdiction link. Score each of your written answers against this rubric: named the correct diligence tier with its components (0–2); identified at least two specific risk drivers rather than generic unease (0–2); correctly stated the reporting conclusion and the no-tipping-off obligation where relevant (0–2); cited the correct authority or legal layer for the follow-up step (0–2). A total of six or more across both profiles signals concept-level readiness; lower totals tell you which pass to repeat. Readiness checks before booking: you can state each distinction unprompted, complete the drill within ten minutes per profile, and explain every row of the diligence table without looking.
- Pass one: one-page notes on the core concept distinctions, written from memory and then corrected.
- Pass two: an institutional map naming each authority's layer, function, and one example question it answers.
- Pass three: daily written scenario drills using the three-question format — risk, tier, report.
- Final week: run the two-profile drill, score against the rubric, and repeat the weakest pass.
References and further reading
Use these references to explore the concepts and check the latest information from the relevant organizations.
