FRM Part II · FRM Exam Part II
Case Study: Financial Crime and Fraud: formula sheet
Key formulas
- Internal vs external test
- Insider involved → Internal Fraud; outsider only → External Fraud
- Basel internal fraud needs at least one internal party. Collusion between an employee and an outsider is internal fraud.
- Money laundering stages
- Placement → Layering → Integration
- Placement puts cash into the system. Layering obscures the trail. Integration returns funds as apparently legitimate wealth.
- Fraud triangle
- Pressure + Opportunity + Rationalisation
- Three conditions that tend to be present when fraud occurs. Controls mainly reduce opportunity.
- Cyber-enabled fraud mapping
- Technology = method; actor decides the event type
- Do not create a separate Basel category for cyber fraud.
- Fraud triangle
- Fraud = Pressure + Opportunity + Rationalization
- A conceptual model, not a calculation. All three are usually present together. Removing one side reduces risk.
- Fraud diamond
- Fraud = Pressure + Opportunity + Rationalization + Capability
- Adds capability: the skills, position and confidence to commit and conceal the fraud.
- Control focus by side
- Opportunity → preventive and detective controls; Pressure and Rationalization → culture, incentives, tone at the top
- Opportunity is the side a firm can reduce most directly.
- Basel event types for fraud
- Internal fraud vs External fraud
- Internal fraud involves at least one internal party. External fraud is by third parties without internal involvement.
- Fraud triangle
- Fraud = Pressure + Opportunity + Rationalisation
- Controls mainly remove opportunity. Culture and incentives address pressure and rationalisation.
- Unauthorised position loss
- Loss ≈ Hidden exposure × Adverse price move
- Simple approximation. Hidden exposure grows as the trader doubles down to recover losses, so loss grows faster than the first error.
- Core control rule: segregation of duties
- Front office ≠ Middle office ≠ Back office
- No one person should initiate, record, confirm and settle the same trade.
- Three lines of defence
- 1st: business owns risk | 2nd: risk and compliance oversee | 3rd: internal audit assures
- Case failures usually show one or more lines not working, not a missing line.
- Typical rogue trading red flags
- Unusually high profit + low reported risk + no leave + resists change in role
- Also look for large unexplained funding needs, cancelled or amended trades, and unconfirmed counterparties.
- Basel event type for these cases
- Rogue trading, Ponzi = Internal fraud | Mis-selling, sales abuse = Clients, products and business practices
- Use the event type to anchor your answer.
- Stages of money laundering
- Placement → Layering → Integration
- Placement enters cash into the system, layering hides the trail, integration returns funds as apparently legitimate.
- KYC and CDD relationship
- KYC programme ⊃ CDD (identify, verify, beneficial owner, purpose, ongoing monitoring)
- CDD is a core component of KYC. Add EDD for higher-risk customers.
- Risk-based approach
- Higher ML/FT risk → enhanced due diligence and closer monitoring; lower risk → simplified measures
- Simplified measures are never an exemption from monitoring and reporting suspicion.
- Alert funnel
- Alerts → Investigation → Escalation → SAR filed (if suspicion remains)
- Most alerts are false positives. Filing needs suspicion, not proof of crime.
- Alert precision
- Precision = alerts leading to SARs ÷ total alerts
- Low precision means high false positives and heavy workload.
- Preventive vs detective
- Preventive = before the event, lowers likelihood. Detective = during or after, shortens discovery time and lowers loss.
- Ask: does it stop the act or find it?
- Three lines of defence
- 1st line = owns and manages risk. 2nd line = oversight, policy, challenge. 3rd line = independent assurance (internal audit).
- Audit must stay independent of operations.
- Segregation of duties
- Initiate ≠ Authorise ≠ Record ≠ Custody
- Defeated by collusion, so add detective controls.
- Analytics trade-off
- More sensitive alerts → more detections but more false positives
- Thresholds balance investigation capacity and missed fraud.
- Net operational loss
- Net loss = Gross loss − Recoveries (insurance and other)
- Recoveries count only when actually received or reliably certain. Gross loss is reported before recoveries.
- Total cost of an event
- Total cost = Direct loss + Fines and penalties + Remediation and legal costs + Reputational cost − Recoveries
- Reputational cost is an estimate. Do not omit it when the question asks for total economic impact.
- Response sequence
- Detect → Contain → Preserve evidence → Escalate → Report → Recover → Remediate → Learn
- Use this order to pick the best first action in a case question.
- Resilience test
- Recovery time ≤ Impact tolerance for critical services
- If recovery time exceeds tolerance, resilience is inadequate even if losses are small.
Quick revision
- The fraud triangle has three elements: pressure, opportunity and rationalisation.
- Internal fraud involves staff; external fraud comes from outsiders such as customers or hackers.
- Money laundering is commonly described in three stages: placement, layering and integration.
- KYC covers customer identification, due diligence and ongoing monitoring.
- Enhanced due diligence applies to higher-risk customers, such as politically exposed persons.
- A risk-based approach puts more effort where risk is higher.
- Sanctions screening checks customers and transactions against official lists.
- Preventive controls stop events; detective controls find them; corrective controls fix damage.
- Segregation of duties and mandatory leave reduce opportunity for insider fraud.
- Weak tone from the top and ignored red flags recur in major fraud cases.
- Regulatory consequences can include fines, restrictions on business and personal accountability.
- A strong response plan covers investigation, communication, remediation and learning.
Common mistakes
- Treating money laundering as a type of theft or fraud loss Fix: Laundering hides the source of funds. Fraud takes funds by deceit. They can be linked but are distinct.
- Classifying a cyber attack as its own Basel event type Fix: Map by actor. Outsider theft is External Fraud; insider misuse of systems is Internal Fraud.
- Treating rationalization as an external control weakness. Fix: Rationalization is the individual's internal excuse. Firms influence it through culture and tone, not through a control.
- Saying the fraud triangle is a quantitative risk measure. Fix: It is a qualitative diagnostic model. Use it to classify causes, not to compute a number.
- Blaming the fraudster alone and ignoring the control and cultural failures. Fix: Ask what allowed it and what should have caught it. The exam rewards the system failure, not the character of the person.
- Choosing more capital or higher limits as the cure for a fraud. Fix: Capital absorbs losses but does not stop fraud. Pick controls that remove opportunity or detect it early.
- Treating KYC and CDD as identical in every case. Fix: Remember KYC is the wider programme and CDD is its core process. If the question forces a distinction, KYC contains CDD.
- Mixing up layering and integration. Fix: Layering obscures the trail through complexity. Integration is when funds re-emerge as legitimate assets or income.
- Calling reconciliations preventive. Fix: They happen after transactions, so they are detective.
- Assigning internal audit to design or run controls. Fix: Audit is the third line and gives independent assurance only.
Exam tips
- Look for the actor first. Most questions turn on insider versus outsider.
- Expect distractors that name the method, such as phishing, as the category.
- Remember money laundering questions often test the three stages or the compliance consequence, not loss type.
- Collusion cases are a favourite trap. One insider makes it Internal Fraud.
- Expect scenario questions. Map each fact to pressure, opportunity or rationalization before looking at the options.
- Know the diamond adds capability. A question may describe a senior person with unusual authority and technical skill.
- Match the fix to the side. Controls fix opportunity. Incentives and culture fix pressure and rationalization.
- Treat red flags as triggers for investigation, not proof. Distractors often overstate them.