TrustCrypto Institute
TCCS Practice Questions
Indicative assessment items provided for familiarisation only. These are not representative of the full examination.
Version 1.0 • Effective 1 January 2026 • Last reviewed February 2026
TCCS Indicative Assessment Items
Sample Questions for Examination Familiarisation
Version: 2.3
Effective: 1 January 2026
For: TrustCrypto Certified Compliance Specialist (TCCS)
Important Notice
These examples are provided to familiarise candidates with assessment style and format.
These items do not:
- Reflect the full scope, weighting, or difficulty of the examination
- Constitute a representative sample of examinable content
- Guarantee coverage of all domains or learning outcomes
- Serve as a study guide or comprehensive preparation tool
The actual examination contains different questions. Candidates must prepare across all syllabus domains.
Multiple-Choice Questions (Indicative Examples)
Question 1 (Domain 1: AML/KYC Frameworks)
A UK-registered cryptoasset exchange onboards a new customer who wishes to deposit £50,000 worth of Bitcoin. The customer provides valid ID but cannot provide satisfactory source of funds documentation.
Which action is most appropriate under the Money Laundering Regulations 2017?
A) Accept the deposit and monitor the account for suspicious activity
B) Decline to onboard the customer
C) Onboard the customer but limit transaction amounts pending further verification
D) File a Suspicious Activity Report (SAR) before proceeding
Correct Answer: B
Rationale: Under Regulation 28(11), a firm must not establish a business relationship where it cannot complete Customer Due Diligence (CDD), which includes verification of source of funds for higher-risk customers or larger transactions. A is incorrect (insufficient without CDD). C is incorrect (partial onboarding does not satisfy CDD obligations). D may be appropriate in some scenarios, but the primary obligation is to decline the relationship where CDD cannot be completed.
Question 2 (Domain 2: Blockchain Forensics)
A compliance analyst traces Bitcoin from a suspicious wallet and identifies that funds were sent to a mixing service before being dispersed to multiple addresses. Which statement is most accurate?
A) The use of a mixer proves the funds are proceeds of crime
B) The mixer transaction breaks the audit trail and prevents further tracing
C) The mixer transaction is a red flag that warrants further investigation
D) Mixers are illegal under UK law and should be reported immediately
Correct Answer: C
Rationale: Use of a mixer is a red flag indicating potential obfuscation, but does not alone prove criminal activity (ruling out A). Modern blockchain analysis can often trace through mixers to some degree (ruling out B). Mixers themselves are not explicitly illegal in the UK, though their use may violate platform terms or indicate suspicious activity (ruling out D). C correctly identifies this as suspicious activity requiring further investigation rather than definitive evidence.
Question 3 (Domain 3: Risk Assessment)
A firm's risk appetite statement defines "Medium Risk" clients as those with annual crypto transactions between £10,000-£100,000. A client transacts £95,000 annually but exclusively uses regulated UK exchanges with full KYC.
How should the compliance team categorise this client?
A) Low Risk (due to use of regulated counterparties)
B) Medium Risk (per the stated transaction threshold)
C) High Risk (due to proximity to the upper threshold)
D) The categorisation requires additional factors beyond transaction volume
Correct Answer: D
Rationale: Risk assessment must be holistic and cannot rely on a single factor. While the transaction volume suggests Medium Risk under the stated framework, the exclusive use of regulated counterparties with full KYC is a mitigating factor. A proper risk assessment considers multiple dimensions: transaction volume, counterparty risk, geographic exposure, product complexity, and client behaviour. D correctly identifies that additional factors must inform the final categorisation.
Question 4 (Domain 4: Regulatory Compliance)
Which of the following activities requires FCA authorisation under current UK regulations?
A) Operating a crypto-to-fiat exchange for retail customers
B) Providing custody of unregulated cryptoassets
C) Advising on security tokens classified as specified investments
D) Operating a crypto ATM
Correct Answer: C
Rationale: Security tokens that meet the definition of specified investments (e.g., shares, debt securities) fall within the FCA regulatory perimeter and require authorisation for advice or dealing. A and D require registration under Money Laundering Regulations but not FCA authorisation (unless providing regulated payment services). B (custody of unregulated tokens) does not currently require FCA authorisation, though this may change with future regulations.
Question 5 (Domain 5: Ethics)
A compliance officer discovers that their firm's CEO holds a personal investment in a crypto project that the firm is currently onboarding as a client. The CEO has not disclosed this conflict. What is the compliance officer's primary obligation?
A) Report the matter to the FCA immediately
B) Raise the matter with the CEO privately and request disclosure
C) Escalate the matter to the Board or independent non-executive director
D) Document the conflict and monitor for signs of preferential treatment
Correct Answer: C
Rationale: Undisclosed conflicts of interest at senior management level represent a governance failure that requires escalation beyond the individual involved. B is insufficient (the CEO has already failed to disclose). D is inadequate (the conflict exists regardless of whether preferential treatment occurs). A may be appropriate in some circumstances, but internal escalation to independent governance (e.g., Board, Audit Committee, NEDs) is the first step. The compliance officer must maintain independence and cannot allow the matter to be resolved solely by the individual with the conflict.
Question 6 (Domain 1: AML/KYC - PEPs)
A customer is identified as a Politically Exposed Person (PEP) from a non-UK jurisdiction. The customer's son, who is not a PEP, wishes to open an account. How should the firm treat the son under the Money Laundering Regulations?
A) As a PEP (family member)
B) As a standard customer (not a PEP)
C) As a PEP for 12 months after the parent leaves political office
D) Enhanced due diligence is recommended but not mandatory
Correct Answer: A
Rationale: Under Regulation 35(14), family members of PEPs are themselves treated as PEPs and subject to enhanced due diligence. This includes children, spouses, and parents. The PEP status does not automatically expire when the individual leaves office (ruling out C) and enhanced due diligence is mandatory, not optional (ruling out D).
Question 7 (Domain 2: Blockchain Forensics - Evidence)
A compliance team identifies a suspicious transaction on the Ethereum blockchain and wishes to preserve evidence for potential regulatory or law enforcement use. Which step is most critical?
A) Screenshot the transaction details from a block explorer
B) Record the transaction hash, block number, and timestamp
C) Download the full blockchain node to preserve data locally
D) Request a certified report from a blockchain forensics vendor
Correct Answer: B
Rationale: The transaction hash, block number, and timestamp provide immutable, verifiable references to the on-chain data. This information can be independently verified by any party with blockchain access. A (screenshots) are not independently verifiable and can be altered. C is impractical and unnecessary. D may be useful for analysis but is not the critical first step for evidence preservation. The key is to record the immutable identifiers.
Question 8 (Domain 3: Risk Assessment - Escalation)
A firm's risk framework requires escalation to senior management for any customer transaction exceeding £500,000. A long-standing customer executes a £450,000 transaction, which is unusual for their profile but within the threshold. Should this be escalated?
A) No, escalation is only required above £500,000
B) Yes, unusual activity should be escalated regardless of thresholds
C) Escalation is at the discretion of the compliance analyst
D) Monitor for 30 days; escalate only if pattern continues
Correct Answer: B
Rationale: Risk frameworks should not be applied mechanically. Unusual activity that deviates significantly from a customer's established profile should trigger escalation regardless of whether it crosses a monetary threshold. Thresholds are guidelines, not substitutes for professional judgement. A applies the rule too rigidly. C is partially correct but understates the obligation—unusual activity should prompt escalation, not mere discretion. D delays action inappropriately.
Question 9 (Domain 4: Regulatory Compliance - Travel Rule)
The FATF Travel Rule requires Virtual Asset Service Providers (VASPs) to share originator and beneficiary information for transactions above a certain threshold. What is the current FATF threshold?
A) No threshold (applies to all transactions)
B) USD/EUR 1,000
C) USD/EUR 15,000
D) The threshold is set by individual jurisdictions
Correct Answer: B
Rationale: FATF Recommendation 16 (the "Travel Rule") applies to wire transfers and virtual asset transfers exceeding USD/EUR 1,000. However, candidates should note that implementation varies by jurisdiction, and some jurisdictions apply the rule to all transactions regardless of amount. D is partially true (jurisdictions set their own implementation), but the FATF guidance itself specifies USD/EUR 1,000.
Question 10 (Domain 5: Ethics - Whistleblowing)
A compliance analyst discovers that their line manager has instructed them to delay filing a Suspicious Activity Report (SAR) until after quarter-end to avoid impacting performance metrics. What is the analyst's obligation?
A) Follow the manager's instruction but document the delay
B) File the SAR immediately and report the instruction via the firm's whistleblowing channel
C) Escalate to the MLRO for guidance
D) File the SAR after quarter-end as instructed but note the delay in the report
Correct Answer: B
Rationale: Delaying a SAR for commercial or operational reasons is a serious breach. The analyst has a legal and professional duty to file the SAR without delay (tipping off provisions permitting). The instruction from the manager represents potential misconduct that must be reported via whistleblowing channels. A and D compound the breach. C is insufficient—the MLRO should be informed, but the analyst must not delay the SAR while awaiting guidance. The analyst is protected under whistleblowing legislation.
Scenario-Based Questions (Illustrative Examples)
Scenario 1: AML/KYC & Risk Assessment
Background:
Green Finance Ltd, a UK-registered cryptoasset exchange, receives an application from a corporate customer, "Overseas Ventures Ltd," incorporated in the British Virgin Islands. The Ultimate Beneficial Owner (UBO) is listed as Mr. Chen, a national of a high-risk jurisdiction per FATF.
The customer states they will deposit approximately £2 million in Bitcoin over the next 12 months for conversion to GBP. When asked for source of funds, the customer provides:
- A signed letter from the UBO stating the funds are from "personal savings and business profits"
- Bank statements showing large cash deposits from multiple jurisdictions
- No invoices, contracts, or business documentation
Your firm's AML policy requires Enhanced Due Diligence (EDD) for:
- PEPs
- High-risk jurisdictions
- Corporate customers with complex ownership structures
- Transactions above £500,000
Question:
(a) Identify three red flags in this scenario.
(b) What additional information should the firm request before onboarding this customer?
(c) If the customer refuses to provide further documentation, what action should the firm take?
Indicative Answer:
(a) Three red flags:
-
High-risk jurisdiction: The UBO is a national of a FATF high-risk jurisdiction, which presents elevated ML/TF risk.
-
Offshore corporate structure: BVI incorporation with limited transparency regarding the corporate structure and business activities raises concerns about potential layering or opacity.
-
Insufficient source of funds documentation: "Personal savings and business profits" is vague and unsupported. Large cash deposits from multiple jurisdictions without corresponding business documentation suggest potential structuring or unverified sources.
(b) Additional information required:
-
Detailed source of funds/wealth documentation: Invoices, contracts, employment records, tax returns, or audited financial statements demonstrating legitimate business activity.
-
Corporate ownership structure: Full details of all UBOs, directors, and shareholders, including proof of identity and address for each. Corporate registry documents from the jurisdiction of incorporation.
-
Business activity verification: Evidence of legitimate business operations (e.g., website, client contracts, business premises, trading history). Explanation for the high volume of cash deposits and their sources.
-
Purpose of account: Detailed explanation of why the customer needs to convert £2 million in Bitcoin to GBP and the intended use of funds.
(c) If customer refuses:
The firm must decline to onboard the customer under Regulation 28(11) of the Money Laundering Regulations 2017, which prohibits establishing a business relationship where Customer Due Diligence cannot be completed.
Additionally:
- Consider filing a Suspicious Activity Report (SAR) with the NCA if the refusal to provide documentation, combined with other red flags, raises suspicion of money laundering.
- Document the decision and rationale for future audit or regulatory review.
- Do not "tip off" the customer about any SAR filing.
Scenario 2: Blockchain Forensics & Regulatory Reporting
Background:
You are a compliance analyst at a UK crypto exchange. A customer, "Alice," has been using the platform for 18 months with typical monthly transactions of £5,000-£10,000.
On 15 March, Alice suddenly deposits £250,000 worth of Bitcoin and immediately converts it to GBP, requesting a fiat withdrawal to her UK bank account. Your blockchain analysis reveals:
- The Bitcoin originated from a wallet associated with a darknet marketplace (confirmed via Chainalysis)
- The funds passed through two mixer services before reaching Alice's deposit address
- Alice's previous deposits came from regulated exchanges with full KYC
When contacted, Alice states: "A friend sent me the Bitcoin as repayment for a loan. I don't know anything about where it came from originally."
Question:
(a) What regulatory obligations does the firm have in this scenario?
(b) Should the firm process Alice's withdrawal request? Explain your reasoning.
(c) Draft a brief outline of the key points you would include in a Suspicious Activity Report (SAR), if filing one.
Indicative Answer:
(a) Regulatory obligations:
-
Suspicious Activity Report (SAR): The firm must file a SAR with the National Crime Agency (NCA) if it knows or suspects that the funds represent proceeds of crime. The darknet marketplace origin and use of mixers create a reasonable suspicion.
-
Do not tip off: The firm must not inform Alice that a SAR has been filed or that her account is under investigation (Proceeds of Crime Act 2002, s.333A).
-
Consent regime (if applicable): Depending on the firm's assessment, it may need to seek consent from the NCA before processing the withdrawal (Proceeds of Crime Act 2002, s.335). If consent is required, the firm must wait for NCA approval or the expiry of the consent period (7 working days + potential 31-day moratorium).
-
Record-keeping: Document all findings, the blockchain analysis, customer communications, and the decision-making process for audit and regulatory review.
(b) Should the withdrawal be processed?
No, not immediately. The firm should:
-
Suspend the withdrawal pending further investigation and NCA consent (if required under the consent regime).
-
File a SAR and await NCA guidance. If the NCA grants consent or does not respond within the prescribed period, the firm may proceed. If the NCA refuses consent or imposes a moratorium, the funds must remain frozen.
-
Avoid tipping off: Communicate with Alice in a way that does not reveal suspicion (e.g., "We are conducting routine compliance checks on this transaction").
Processing the withdrawal immediately would risk the firm committing a money laundering offense under the Proceeds of Crime Act 2002 (arranging, acquiring, using, or possessing criminal property).
(c) Key points for SAR:
-
Customer details: Alice's full name, date of birth, address, and account details.
-
Suspicious transaction: £250,000 Bitcoin deposit on 15 March, followed by immediate conversion to GBP and withdrawal request. This is a significant deviation from her usual £5,000-£10,000 monthly activity.
-
Blockchain analysis findings:
- Source: Wallet associated with [Darknet Marketplace Name] per Chainalysis.
- Obfuscation: Funds passed through two mixer services before deposit.
- Previous deposits: From regulated exchanges (no prior red flags).
-
Customer explanation: Alice claims the Bitcoin was repayment for a loan from a friend. She denies knowledge of the original source. This explanation is inconsistent with the sophistication of the obfuscation techniques used (mixers).
-
Suspicion: Reasonable grounds to suspect the funds represent proceeds of crime given the darknet marketplace origin and use of mixers to obscure the trail.
-
Action taken: Withdrawal suspended pending NCA consent. Customer not informed of SAR filing.
Notes on Marking
Multiple-Choice Questions
- One mark per correct answer.
- No partial credit.
- Rationale is provided here for learning purposes but would not appear in the examination.
Scenario Questions
-
Marking allocates points for:
- Identification of relevant issues (AML/KYC red flags, regulatory obligations)
- Application of appropriate legal frameworks (MLRs, POCA, FATF guidance)
- Practical, defensible recommendations (risk-based decision-making)
- Demonstration of professional judgement in compliance contexts
-
Candidates are not expected to reproduce legislation verbatim.
-
Credit is awarded for structured reasoning and application to the scenario.
Disclaimer
These indicative items are for familiarisation only.
The actual TCCS examination:
- Contains different questions
- May test domains not represented here
- Includes greater complexity and nuance
- Assesses applied competence, not pattern recognition
Candidates who rely solely on these examples will not be adequately prepared.
Contact
Assessment enquiries: exams@trustcrypto.co.uk
TrustCrypto Institute
Version 2.3 | Effective 1 January 2026