CAFS Sample Questions & Answers
Three equally weighted areas, building a fraud risk program, detection and analytics, and investigations with evidence gathering, carry most of the weight, with smaller portions on case studies and machine-learning tools used to fight fraud.
Launch the full CAFS simulator →Showing 6 of 12 free samples.
- Question 1Intermediate
Building a Fraud Risk Management Program · Fraud Prevention Controls
During a fraud risk assessment, an organization identifies that employees in the accounts payable department share passwords for the payment authorization system. This represents a failure in which type of control?
Show answer & explanation
Correct answer: A
Password management and access restrictions are Preventive Controls designed to stop fraud before it occurs. Sharing passwords undermines the preventive measure of authentication and accountability, making it impossible to enforce segregation of duties effectively.
- Question 2Intermediate
Building a Fraud Risk Management Program · Fraud Risk Management Framework
Which of the following statements best describes the concept of 'Fraud Risk Appetite'?
Show answer & explanation
Correct answer: D
Risk Appetite is a broad, strategic statement defining the amount of risk an organization is willing to accept to achieve its goals. It differs from Risk Tolerance, which is more granular and specific (e.g., specific dollar thresholds). Risk Appetite guides the overall strategy.
- Question 3IntermediateSelect 2
Building a Fraud Risk Management Program · Fraud Prevention Controls
A financial institution is updating its fraud policy. Which TWO elements are essential to include in a comprehensive fraud policy document? (Select TWO)
Show answer & explanation
Correct answers: B, C
Definition of what constitutes fraud and prohibited behavior: A fraud policy must clearly define what the organization considers fraud and explicitly state that such behavior is prohibited. This provides the legal and HR basis for action. Roles and responsibilities for reporting and investigating suspected fraud: The policy must clearly outline who is responsible for reporting suspicions (usually all employees) and who is authorized to investigate them, ensuring a structured response.
Definition of what constitutes fraud and prohibited behavior: A fraud policy must clearly define what the organization considers fraud and explicitly state that such behavior is prohibited. This provides the legal and HR basis for action. Roles and responsibilities for reporting and investigating suspected fraud: The policy must clearly outline who is responsible for reporting suspicions (usually all employees) and who is authorized to investigate them, ensuring a structured response.
- Question 4Beginner
Building a Fraud Risk Management Program · Fraud Prevention Controls
True or False: Segregation of Duties (SoD) is primarily a detective control designed to identify fraud after it has occurred.
Show answer & explanation
Correct answer: B
False. Segregation of Duties is a PREVENTIVE control. By ensuring that no single individual has control over all aspects of a transaction (e.g., authorizing and recording), it prevents fraud from happening or requires collusion, which is harder to orchestrate.
- Question 5Intermediate
Building a Fraud Risk Management Program · Fraud Prevention Controls
When establishing a 'Whistleblower' hotline as part of a fraud prevention program, which characteristic is MOST critical to ensure its effectiveness?
Show answer & explanation
Correct answer: A
The fear of retaliation is the primary barrier to reporting fraud. An effective whistleblower program must guarantee anonymity (or confidentiality) and have strict non-retaliation policies to encourage employees to come forward.
- Question 6Advanced
Building a Fraud Risk Management Program · Fraud Risk Management Framework
A multinational bank is conducting a Fraud Risk Assessment (FRA). What is the correct sequence of steps for this process?
Show answer & explanation
Correct answer: B
The standard FRA lifecycle involves: 1) Identifying inherent risks, 2) Assessing their likelihood and impact (Inherent Risk rating), 3) Mapping existing controls to those risks, and 4) Determining the Residual Risk based on control effectiveness.
flowchart LR ID[Identify Risks] --> Assess[Assess Inherent Risk] Assess --> Controls[Map Controls] Controls --> Residual[Determine Residual Risk]
Ready for the real thing?
The full CAFS simulator has every exam-style question, timed mode, and instant scoring.