Study Guide

NISM Series XXIV AML/CFT Exam: Telling the Regimes Apart

Learn to separate CDD from EDD and STR from CTR for the NISM-Series-XXIV AML/CFT exam, with India-specific scenarios, a decision table, and a self-check rubric.

Updated September 202611 min readStudy GuideNISM Prep
Rachel Reynolds

Rachel Reynolds

NISM Prep Editorial Team

Prepare for the NISM-Series-XXIV AML/CFT exam by studying contrasts, not lists: KYC versus CDD, CDD versus EDD, and STR versus CTR each differ in trigger, actor, and required action. Work two decision scenarios per topic on paper, log every distinction you get wrong in a ledger, and re-test those distinctions until you can classify any fact pattern's correct obligation without hesitation. For registration, fees, and certificate validity, refer to NISM's official site, as this guide deliberately avoids restating administrative details.

Mapping Placement, Layering and Integration onto Securities Mechanisms

The classic laundering stages take securities-specific forms: placement through subscriptions funded with dubious cash, layering through rapid demat transfers and off-market trades, and integration through apparently legitimate investment returns. Recognise each stage by the market mechanism it exploits.

Start by anchoring the three stages in the Indian market context. Placement introduces criminal proceeds into the financial system, often as cash that funds a trading account or a collective investment subscription. Layering moves value through a chain of transactions to obscure origin, which in securities means rapid buy-sell cycles, transfers between demat accounts, off-market transfers, or movement across related accounts. Integration returns the funds as wealth that appears lawfully earned, such as dividends, redemption proceeds, or realised capital gains with documentation to support them.

Securities markets change how layering behaves compared with cash-based banking. Price movements and legitimate market volatility give transactions a plausible commercial explanation, which is precisely why trades are useful for obscuring trail. Beneficial ownership questions also surface differently here: shares can be held through companies, trusts, and foreign vehicles, so identifying who ultimately controls an account matters more than who signed the form. When you study red-flag lists, attach each flag to the stage it typically indicates rather than memorising flags as a flat catalogue.

Where KYC Ends and CDD Begins: Nested Obligations, Not Synonyms

KYC is the identification component: verifying who the customer is. CDD is broader, adding purpose, nature of the relationship, beneficial ownership, and ongoing monitoring. EDD is a heightened CDD tier for higher-risk situations under the risk-based approach.

Build your understanding as nested scopes. KYC answers identity questions: who is the person, verified against reliable documents. CDD wraps identity inside a wider obligation set prescribed under India's Prevention of Money Laundering Act framework and SEBI's AML requirements for intermediaries: understanding the purpose and intended nature of the relationship, identifying beneficial ownership where the client is a legal person or arrangement, and conducting ongoing due diligence throughout the relationship. If an exam item asks only for document verification, KYC is the precise term; if monitoring or purpose appears, CDD is the correct frame.

The risk-based approach determines which tier applies. For lower-risk situations, simplified measures may be acceptable; for higher-risk clients, including politically exposed persons, enhanced due diligence adds steps such as senior-level approval, deeper source-of-funds and source-of-wealth inquiry, and intensified ongoing monitoring. Distinguish source of funds (where the money for this transaction came from) from source of wealth (how the client accumulated total wealth); they are different questions with different evidence. Practise classifying a client profile into the correct tier and naming the extra EDD steps, not merely labelling the client 'high risk'.

STR versus CTR: Two Reporting Channels with Different Triggers

CTR responds to transactions crossing a prescribed cash threshold, regardless of suspicion. STR responds to suspicion that funds are proceeds of crime or linked to terrorist financing, regardless of amount. Trigger, not transaction type, defines each channel.

Keep the two channels separate by their tests. Threshold-based reporting to FIU-IND fires mechanically when transactions involving cash cross the prescribed value, and no suspicion is required; it is a volume-driven obligation. Suspicious transaction reporting fires on qualitative judgment: a transaction or attempted transaction that gives reason to believe funds derive from criminal activity or relate to terrorist financing. A small, odd-patterned trade can warrant an STR while a large cash deposit generates a CTR; the two can also be filed for the same transaction without one replacing the other.

Around the STR sits the tipping-off prohibition: a reporting entity or its staff must not disclose to the customer or any third party that a suspicious transaction report has been filed or is being contemplated, on pain of legal consequences. This shapes the correct operational script: continue handling the client normally while the internal escalation proceeds. Also link reporting to record keeping; the records supporting CDD and transactions exist so that reports and any subsequent investigations can be substantiated, and they must be retained for the period applicable rules prescribe.

The table below condenses the contrasts you should be able to reproduce from memory.

FeatureCTR (threshold report)STR (suspicion report)
TriggerPrescribed cash threshold crossedSuspicion of criminal proceeds or terrorist financing
Requires suspicion?NoYes
Size-sensitive?Yes, by designNo; small or attempted transactions can qualify
Judgment involvedMinimal; mechanical detectionSubstantial; evaluation and escalation
Client can be told?Not an issue in itselfNo; tipping-off is prohibited
Typical securities exampleCash-intensive account funding above the limitRapid demat churning inconsistent with client profile

Worked Scenario: Rapid Demat Churning as Layering

A new retail client buys and sells illiquid scrips within days, moving shares between demat accounts, with turnover far beyond stated income. The error is dismissing this as ordinary trading; the better decision is internal escalation and an STR evaluation without tipping off the client.

The facts: a recently opened account belonging to a student with modest stated income shows forty trades in low-liquidity scrips within three weeks, frequent off-market-looking transfers to accounts with common addresses, and immediate exit at near-flat prices. The plausible mistake is an operations view: 'clients trade, volatility explains everything, income statements get outdated anyway', so the activity is closed as market behaviour and nothing is recorded. That decision fails at two points; it ignores the mismatch with the customer profile, which is the core CDD monitoring test, and it leaves no documented rationale that a reviewer or auditor could later examine.

The better decision runs a three-step script. First, the concerned employee refers the case to the designated principal officer with the objective observations: turnover-to-profile mismatch, related counterparty accounts, quick round-tripping. Second, the principal officer evaluates whether the pattern suggests layering and files an STR if suspicion is formed, regardless of the modest amounts. Third, front office continues serving the client normally; asking the student why regulators were notified would constitute tipping off. Why it matters: layering in securities is designed to look like trading, so the profile-mismatch test, not the trade itself, is what detects it, and the paper trail of the escalation is itself a compliance obligation.

Worked Scenario: A Politically Exposed Person Requests an Off-Market Transfer

A client disclosed as a politically exposed person requests an off-market transfer of shares to a family trust. The error is running standard KYC; the better decision is EDD, including senior approval, source-of-funds checks, and enhanced ongoing monitoring, while processing lawfully.

The facts: onboarding review flags the client as a PEP under the applicable definition, and shortly after account opening he instructs a large off-market transfer to a trust whose settlors include his spouse. The plausible mistake is binary thinking in both wrong directions: either rejecting the request outright because 'PEPs are prohibited clients', which the framework does not say, or, worse, completing the standard KYC file because identity documents are in order. Both miss the actual requirement: PEP status elevates the diligence tier, it neither bans the client nor permits business as usual.

The better decision applies EDD deliberately. Obtain appropriate senior management approval before establishing or continuing the relationship; take reasonable steps to establish source of funds for this specific transfer and source of wealth for the client overall; identify the trust's beneficial owners rather than stopping at the entity's name; and apply enhanced ongoing monitoring to the account thereafter. If any element raises suspicion, the principal officer evaluates an STR through the escalation route from the previous section, again without informing the client of the report. Why it matters: this fact pattern stacks three named concepts; PEP classification, EDD steps, and beneficial ownership of a legal arrangement. An exam item on it is answered correctly only by ordering the steps properly: classify, approve at senior level, deepen diligence, monitor.

Internal Controls: Who Does What Between the Front Office and FIU-IND

Compliance operates through architecture, not just rules: a designated principal officer, a board-approved AML policy covering CDD, monitoring, reporting, and training, periodic independent review, and a documented escalation path from staff to reporting.

Learn the roles as a pipeline. Front-line staff apply CDD at onboarding and monitor conduct during the relationship, escalating anomalies upward. The principal officer, designated by the intermediary, owns the reporting function: evaluating escalations, filing STRs with FIU-IND, and acting as the interface with authorities. The board or senior management approves the AML policy and is responsible for the programme's adequacy. Mapping each obligation to its actor is exactly the kind of detail decision-based questions probe; a question asking who files the STR, who approves EDD, and who maintains the policy has three different correct actors.

The programme itself has named components worth memorising as a checklist: internal policies and procedures aligned to the risk-based approach, a compliance function with a designated principal officer, employee training on AML/CFT obligations and red flags, customer awareness measures such as anti-money-laundering messaging, and independent audit or review of the framework's effectiveness. Note that these are organisational obligations on the intermediary, distinct from the transaction-level duties in earlier sections; an intermediary can conduct perfect KYC and still fail the programme test if training and review are absent. In scenario questions, check whether the failure is at transaction level or programme level, because the remedial action differs.

A Distinctions-Ledger Routine with a Self-Check Rubric

Run a four-week cycle: build a distinctions ledger, write one decision scenario per topic daily, score yourself against a rubric, and schedule the exam only when classification errors stop recurring. Self-check scores are learning milestones, not pass predictions.

A sequence you can adapt to the time you have. Weeks one and two: read the syllabus themes in order; money laundering and terrorist financing concepts, the regulatory framework, CDD/KYC, reporting, internal controls, international cooperation and emerging trends, and after each theme write every distinction in a two-column ledger: concept versus its nearest neighbour, plus trigger, actor, and action. Weeks three and four: write one paper scenario daily in which two obligations could plausibly apply, decide which applies and why, and add any wrong calls back to the ledger. Close with full practice sets under timed conditions and re-drill only the ledger rows you still miss. Administrative details such as registration and validity live on NISM's official certification pages.

Score each daily scenario against this rubric and record the observations. A correct response names the triggering concept precisely, identifies the responsible actor, states the action and its order, and flags any prohibited step such as tipping off. Score four out of four for a week of consecutive scenarios on mixed topics, and note which distinctions needed correction. Readiness checks before the exam: you can reproduce the STR/CTR table from memory; you can list the EDD steps unprompted; you can trace a fact pattern from red flag to escalation to filing without skipping the principal officer role; and your ledger contains no distinction you have misclassified in the last three scenarios. Gaps on any check indicate which syllabus theme to revisit, not necessarily more volume of question practice.

  • Ledger row format: concept, nearest neighbour, trigger, actor, required action, prohibited action.
  • Scenario rubric, scored 0-4: concept named; actor identified; action and sequence correct; prohibited steps flagged.
  • Milestone: four consecutive mixed-topic scenarios at 4/4 before moving from drilling to full timed sets.
  • Readiness check: reproduce the STR-versus-CTR table and the EDD step list from memory, closed book.
  • Readiness check: no ledger distinction misclassified across your last three written scenarios.

References and further reading

Use these references to explore the concepts and check the latest information from the relevant organizations.

Continue your preparation

FAQ

Frequently Asked Questions

Practical answers to help you apply the guidance for NISM-Series-XXIV: AML and CFT Provisions in Securities Markets Certification Examination.

Does the tipping-off prohibition depend on whether the STR is later found justified?
No. The prohibition applies to disclosing that a suspicious transaction report has been or is being contemplated. The correctness of the underlying suspicion is assessed separately by the authorities; the reporting entity's duty is silence and normal handling of the client.
Is an STR required only when the transaction amount is large?
No. Suspicion, not size, triggers an STR; even attempted transactions can qualify. Threshold-based CTR is the channel that is size-sensitive, which is exactly why the two channels must be kept conceptually separate when answering classification questions.
Are beneficial ownership rules relevant for an individual retail client?
Beneficial ownership identification is central when the client is a legal person or arrangement such as a company, trust, or fund, where you must trace through to the natural persons who own or control it. For an individual acting for himself, the client is the beneficial owner, so the concept mainly changes how you treat entity and structure-based accounts.
Does identifying a client as a PEP mean the account must be refused?
No. PEP status triggers enhanced due diligence: senior management approval, deeper source-of-funds and source-of-wealth inquiry, and enhanced ongoing monitoring. The framework heightens scrutiny of politically exposed persons; it does not create an automatic bar, and treating it as one is a category error.
Does a CTR apply to securities transactions settled entirely by bank transfer?
Threshold reporting is aimed at cash transactions crossing the prescribed value, so fully non-cash settlements generally fall outside it. Suspicious non-cash activity would instead be evaluated under the STR channel, which is indifferent to settlement method and amount.

Keep Reading

Related Study Guides

Explore related guides and preparation topics.