CFCS logo
Focused certification exam prep
Start practice

CFCS Domain 10: Regulatory Compliance Study Guide 2026

TL;DR
  • Domain 10 addresses regulatory compliance within a 135-question, scenario-based CFCS exam administered online via Kryterion OLP.
  • ACFCS does not publish per-domain percentage weights, so treat Domain 10 as inseparable from all 12 content areas.
  • Candidates must pass 88 of 135 questions (approximately 65%) to earn the CFCS credential.
  • Regulatory compliance knowledge is tested cross-domain - a sanctions question, for example, may hinge entirely on compliance program requirements.

What Domain 10 Actually Covers

When ACFCS designed the Certified Financial Crime Specialist examination, it made a deliberate architectural choice: regulatory compliance is not a standalone silo. Domain 10 - Regulatory Compliance - is the connective tissue that runs through every other domain on the exam. It addresses how financial institutions, corporations, and individual professionals translate the obligations imposed by law, rule, and regulatory guidance into operational programs that actually prevent and detect financial crime.

At its core, Domain 10 asks candidates to think like a compliance officer who must operationalize abstract legal requirements. That means understanding not just what the rules say, but how those rules get implemented across business lines, geographies, and risk typologies. Candidates who approach this domain as a pure memorization exercise will struggle. The scenario-based format of the CFCS rewards judgment over recall.

Domain 10: Regulatory Compliance

What candidates must understand: the architecture and components of effective financial crime compliance programs, the regulatory frameworks that govern them globally, and how to identify program gaps that create liability or enable financial crime.

  • AML/CFT program design, including risk-based approaches mandated by FATF recommendations
  • Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) obligations under FinCEN rules and global equivalents
  • The role of regulators - FinCEN, OCC, FCA, AUSTRAC, FINTRAC - and their enforcement mandates
  • Suspicious Activity Reports (SARs) and Currency Transaction Reports (CTRs): when, how, and why they are filed
  • Independent testing, internal audit, and the compliance officer's accountability framework
  • Consequences of compliance program failures, including enforcement actions, deferred prosecution agreements, and consent orders
  • Governance structures: board-level oversight, three lines of defense, and senior management accountability

Why Regulatory Compliance Is Central to the CFCS

The CFCS spans twelve content areas - from money laundering and fraud to human trafficking, sanctions, cybercrime, and terrorist financing. Every one of those domains lives inside a regulatory framework. When an examiner writes a question about sanctions evasion schemes (Domain 6), they may frame it through the lens of whether a compliance program had adequate screening controls. When a question tackles corruption (Domain 3), it may pivot on whether an institution had appropriate third-party due diligence policies required under the FCPA or UK Bribery Act.

This is why candidates who underinvest in Domain 10 tend to underperform across the entire exam. Regulatory compliance is not one of twelve equal boxes - it functions as the interpretive layer over everything else.

Cross-Domain Dependency: ACFCS structures the CFCS around real-world financial crime scenarios, not academic theory. In practice, almost every significant financial crime investigation or program failure has a regulatory compliance dimension. A CFCS candidate who cannot identify what a regulator would expect - and where a program falls short - will find scenario-based questions consistently difficult regardless of domain.

Understanding the CFCS Domain 10: Regulatory Compliance Study Guide 2026 is therefore not optional for high scorers - it is foundational preparation for the entire credential.

Core Topics Every Candidate Must Master

The Five Pillars of an AML Compliance Program

FinCEN's long-standing framework identifies five pillars for a compliant AML program: internal policies and controls, a designated compliance officer, ongoing employee training, independent testing, and - added formally in 2016 - customer due diligence requirements including beneficial ownership identification. CFCS candidates must be fluent in all five, and critically, must understand how failures in any single pillar cascade into regulatory exposure and criminal vulnerability.

Exam questions in this area test whether candidates can distinguish between a technically compliant program and an effective one. The CFCS is explicit about this distinction: a financial institution can have written policies that check every box and still have a fundamentally broken compliance program.

FATF Recommendations and the Risk-Based Approach

The Financial Action Task Force (FATF) Recommendations underpin regulatory compliance expectations globally. Domain 10 requires candidates to understand the FATF 40 Recommendations - not as a recitation exercise, but as a framework for evaluating whether a jurisdiction's AML/CFT regime is adequate. The risk-based approach (RBA) is central: institutions are not expected to apply identical controls to every customer and transaction, but they are expected to calibrate controls to risk in a documented, defensible way.

Candidates should be comfortable with concepts like National Risk Assessments, Mutual Evaluations, and the FATF grey list and black list - and what those designations mean for correspondent banking relationships, transaction monitoring, and EDD obligations.

Regulatory Reporting Obligations

Filing obligations appear throughout the CFCS exam in multiple domain contexts. From a Domain 10 perspective, candidates must understand SARs and CTRs at a structural level: who is required to file, what triggers a filing obligation, the consequences of willful failure to file, and the tipping-off prohibitions that restrict disclosure of a SAR filing to the subject. In international contexts, equivalent reports - Suspicious Transaction Reports (STRs) in many jurisdictions - operate under comparable frameworks with meaningful variations that exam scenarios may exploit.

Enforcement Mechanisms and Consequences

Domain 10 goes beyond program design into what happens when programs fail. CFCS candidates should have a working knowledge of the enforcement toolkit: civil monetary penalties, cease-and-desist orders, deferred prosecution agreements (DPAs), non-prosecution agreements (NPAs), and monitorships. Major enforcement actions - from HSBC to Wachovia to Deutsche Bank - are instructive not for their headline numbers but for the specific program failures they exposed.

Enforcement Intelligence: Reviewing publicly available consent orders and FinCEN enforcement actions is one of the highest-leverage preparation activities for Domain 10. These documents describe real compliance failures in specific, actionable language - exactly the kind of scenario framing the CFCS uses in its questions.

How Domain 10 Connects to Other CFCS Domains

Mapping Domain 10's intersections with the other eleven domains is a smart preparation strategy. Here is how the connections manifest in practice:

CFCS Domain Domain 10 Regulatory Compliance Connection
Domain 1: Money Laundering BSA/AML program obligations; transaction monitoring program design; layering detection controls
Domain 3: Anti-Corruption and Bribery FCPA and UK Bribery Act third-party due diligence; gifts and entertainment policies; government official identification
Domain 6: Sanctions OFAC compliance program expectations; screening system adequacy; voluntary self-disclosure frameworks
Domain 9: Terrorist Financing OFAC and UN-listed entity screening; 314(a) information sharing; de-risking decisions
Domain 12: Monitoring and Adjusting Ongoing program testing, KPI/KRI development, regulatory exam preparation, and response to regulatory feedback

This interconnectedness is why practicing with CFCS-format scenario questions across all domains simultaneously - rather than domain-by-domain in isolation - produces better exam outcomes. The exam is designed to test integrated judgment.

What Scenario-Based Questions Look Like in This Domain

The CFCS uses 135 scenario-based multiple-choice questions across its full scope. In Domain 10, scenarios typically present a described compliance program or a specific institutional situation and ask the candidate to evaluate it. Common question architectures include:

  • Gap identification: A bank's AML program is described in partial detail. Which element is missing or inadequate?
  • Priority decisions: A compliance officer faces multiple competing findings from an audit. Which should be escalated first, and why?
  • Regulatory outcome prediction: Given this specific program failure, what enforcement action or regulatory consequence is most likely?
  • Policy application: A new product is being launched with these characteristics. What additional CDD or monitoring controls are required?
  • Jurisdiction analysis: An institution's customer is in a FATF grey-listed jurisdiction. What does the risk-based approach require?

What makes these questions challenging is that the wrong answer choices are often defensible at a surface level. The CFCS tests whether candidates understand the best answer - the one most consistent with regulatory expectations and sound compliance practice - not just a technically plausible one.

Key Takeaway

For Domain 10 scenarios, always ask: what would a reasonable regulator expect a well-run compliance program to have done in this situation? That framing cuts through distractor answers consistently.

A Domain-by-Domain Scheduling Strategy

With 12 domains and a 12-month scheduling window after purchase, candidates have substantial flexibility. The structure below reflects the CFCS's cross-domain architecture rather than a generic study template - it prioritizes domains that build foundational regulatory knowledge early and uses later weeks to stress-test integration.

Weeks 1-2

Regulatory Foundation (Domains 10 + 1)

  • Map the five AML program pillars and FATF risk-based approach
  • Study Domain 1 (Money Laundering) in parallel - it is the most direct regulatory compliance application
  • Review one or two major enforcement actions (consent orders) for real-world context
Weeks 3-4

High-Enforcement Domains (Domains 6 + 3)

  • Domain 6 (Sanctions): OFAC compliance program structure; screening; voluntary disclosure
  • Domain 3 (Anti-Corruption): FCPA/UK Bribery Act compliance program design; third-party risk
  • Return to Domain 10 concepts to reinforce how program obligations differ by risk type
Weeks 5-6

Criminal Typology Domains (Domains 2, 4, 5, 7)

  • Fraud, Tax Evasion, Cybercrime, Human Trafficking - study for typology knowledge and red flags
  • Note where each domain creates specific compliance program obligations
Weeks 7-8

Investigations and Integration (Domains 8, 9, 11, 12)

  • Asset Recovery, Terrorist Financing, Investigations, Monitoring and Adjusting
  • Domain 12 is especially important as a capstone - it covers program adjustment and ongoing compliance review
Weeks 9-12

Full-Exam Practice and Weak Domain Remediation

Who Hires CFCS Holders for Compliance Roles

The CFCS is a cross-sector credential, which means the regulatory compliance domain is relevant to a wide range of employers. Financial institutions - retail banks, investment banks, credit unions, money services businesses - are the most obvious hirers, given their direct regulatory obligations under BSA/AML and OFAC frameworks. But the credential's scope is broader.

Consulting and advisory firms that conduct compliance program assessments, gap analyses, and monitorships actively recruit CFCS holders because the credential signals cross-domain literacy, not narrow specialization. Law firms with white-collar defense and regulatory investigation practices value it for the same reason. Cryptocurrency exchanges and fintech platforms increasingly face the same compliance expectations as traditional financial institutions and hire CFCS professionals to build programs from scratch.

Government agencies - including law enforcement, financial intelligence units, and regulatory bodies themselves - are reflected in the CFCS pricing structure: the exam is available at reduced rates of $750-$850 for government professionals, signaling ACFCS's explicit recognition of public-sector demand for the credential.

Within all of these organizations, Domain 10 knowledge is not just exam-relevant - it is the day-to-day language of the job. Compliance officers who can articulate program design principles, regulatory expectations, and enforcement risk in precise terms are more effective in every role the CFCS credential targets.

Registration, Format, and Exam Mechanics

Before sitting the CFCS, candidates must hold active ACFCS membership and have accumulated 40 earned credits across financial crime experience, education, training, and professional certifications. This prerequisite is not a formality - it reflects ACFCS's positioning of the CFCS as a practitioner credential, not an entry-level certification.

Exam fees depend on membership status: $1,195 for existing members, $1,395 bundled with a one-year membership, and $1,725 bundled with a three-year membership. Government rates range from $750 to $850. After purchase, candidates have a 12-month window to schedule through the Kryterion Online Proctored (OLP) network, which means the exam can be taken from home without traveling to a testing center.

Exam Format: 135 scenario-based multiple-choice questions in 4 hours. Passing requires 88 correct answers - approximately 65%. The exam is closed-book and online-proctored. ACFCS does not publish per-domain weighting, so candidates should treat all 12 domains as potentially material to their score.

For detailed scheduling steps - including how to configure your Kryterion environment, what system checks are required, and how to navigate rescheduling - review the CFCS Exam Schedule: How to Book Your Test in 2026. Candidates who leave scheduling to the last minute within their 12-month window often face limited appointment availability, which creates unnecessary pressure.

Once earned, the CFCS is valid for three years. Renewal requires 60 continuing education credits and maintenance of active ACFCS membership. Candidates working in regulatory compliance roles will generally find that ongoing professional development in their field satisfies most renewal requirements organically.

Use CFCS Exam Prep practice tests to simulate the closed-book, timed format before your actual appointment. Scenario-based questions reward preparation built on applied understanding - not last-minute cramming.

Frequently Asked Questions

Does Domain 10 appear as a distinct section in the CFCS exam?

No. The CFCS is not structured as twelve sequential domain sections. Questions are drawn from across all 12 content areas in a single 135-question exam. Domain 10 topics may appear in questions that are explicitly compliance-focused or may be embedded in scenarios anchored to other domains like sanctions or money laundering.

How much of the exam is regulatory compliance content?

ACFCS does not publish per-domain percentage weights. Candidates should prepare Domain 10 thoroughly not only for its direct question contribution but because compliance knowledge is implicitly tested in scenarios across most other domains. Treating it as a minor domain is a strategic mistake.

Are there specific regulatory frameworks I must know for the CFCS?

Yes. At minimum, candidates should be fluent in the U.S. Bank Secrecy Act and its implementing regulations, FATF Recommendations and the risk-based approach, OFAC sanctions compliance program expectations, and the FCPA. Global equivalents - the EU's AMLD series, UK Proceeds of Crime Act, and AUSTRAC requirements - are also relevant given the CFCS's international scope.

Can I sit the CFCS exam without working in compliance specifically?

Yes. The 40-credit prerequisite can be satisfied through a combination of experience, education, training, and professional certifications in financial crime and related fields broadly - not compliance specifically. Investigators, analysts, law enforcement professionals, and auditors all qualify through their respective backgrounds.

How soon after purchasing can I schedule my exam?

Immediately. Once your purchase and prerequisite verification are complete, you gain a 12-month scheduling window through the Kryterion OLP network and can book your appointment at any point during that window. The exam is available year-round with no fixed testing windows.

Ready to pass your CFCS exam?

Put this into practice with free CFCS questions across every exam domain.