Skip to content

FRM Part II · FRM Exam Part II

Case Study: Financial Crime and Fraud: formula sheet

Full chapter guide

Key formulas

Internal vs external test
Insider involved → Internal Fraud; outsider only → External Fraud
Basel internal fraud needs at least one internal party. Collusion between an employee and an outsider is internal fraud.
Money laundering stages
Placement → Layering → Integration
Placement puts cash into the system. Layering obscures the trail. Integration returns funds as apparently legitimate wealth.
Fraud triangle
Pressure + Opportunity + Rationalisation
Three conditions that tend to be present when fraud occurs. Controls mainly reduce opportunity.
Cyber-enabled fraud mapping
Technology = method; actor decides the event type
Do not create a separate Basel category for cyber fraud.
Fraud triangle
Fraud = Pressure + Opportunity + Rationalization
A conceptual model, not a calculation. All three are usually present together. Removing one side reduces risk.
Fraud diamond
Fraud = Pressure + Opportunity + Rationalization + Capability
Adds capability: the skills, position and confidence to commit and conceal the fraud.
Control focus by side
Opportunity → preventive and detective controls; Pressure and Rationalization → culture, incentives, tone at the top
Opportunity is the side a firm can reduce most directly.
Basel event types for fraud
Internal fraud vs External fraud
Internal fraud involves at least one internal party. External fraud is by third parties without internal involvement.
Fraud triangle
Fraud = Pressure + Opportunity + Rationalisation
Controls mainly remove opportunity. Culture and incentives address pressure and rationalisation.
Unauthorised position loss
Loss ≈ Hidden exposure × Adverse price move
Simple approximation. Hidden exposure grows as the trader doubles down to recover losses, so loss grows faster than the first error.
Core control rule: segregation of duties
Front office ≠ Middle office ≠ Back office
No one person should initiate, record, confirm and settle the same trade.
Three lines of defence
1st: business owns risk | 2nd: risk and compliance oversee | 3rd: internal audit assures
Case failures usually show one or more lines not working, not a missing line.
Typical rogue trading red flags
Unusually high profit + low reported risk + no leave + resists change in role
Also look for large unexplained funding needs, cancelled or amended trades, and unconfirmed counterparties.
Basel event type for these cases
Rogue trading, Ponzi = Internal fraud | Mis-selling, sales abuse = Clients, products and business practices
Use the event type to anchor your answer.
Stages of money laundering
Placement → Layering → Integration
Placement enters cash into the system, layering hides the trail, integration returns funds as apparently legitimate.
KYC and CDD relationship
KYC programme ⊃ CDD (identify, verify, beneficial owner, purpose, ongoing monitoring)
CDD is a core component of KYC. Add EDD for higher-risk customers.
Risk-based approach
Higher ML/FT risk → enhanced due diligence and closer monitoring; lower risk → simplified measures
Simplified measures are never an exemption from monitoring and reporting suspicion.
Alert funnel
Alerts → Investigation → Escalation → SAR filed (if suspicion remains)
Most alerts are false positives. Filing needs suspicion, not proof of crime.
Alert precision
Precision = alerts leading to SARs ÷ total alerts
Low precision means high false positives and heavy workload.
Preventive vs detective
Preventive = before the event, lowers likelihood. Detective = during or after, shortens discovery time and lowers loss.
Ask: does it stop the act or find it?
Three lines of defence
1st line = owns and manages risk. 2nd line = oversight, policy, challenge. 3rd line = independent assurance (internal audit).
Audit must stay independent of operations.
Segregation of duties
Initiate ≠ Authorise ≠ Record ≠ Custody
Defeated by collusion, so add detective controls.
Analytics trade-off
More sensitive alerts → more detections but more false positives
Thresholds balance investigation capacity and missed fraud.
Net operational loss
Net loss = Gross loss − Recoveries (insurance and other)
Recoveries count only when actually received or reliably certain. Gross loss is reported before recoveries.
Total cost of an event
Total cost = Direct loss + Fines and penalties + Remediation and legal costs + Reputational cost − Recoveries
Reputational cost is an estimate. Do not omit it when the question asks for total economic impact.
Response sequence
Detect → Contain → Preserve evidence → Escalate → Report → Recover → Remediate → Learn
Use this order to pick the best first action in a case question.
Resilience test
Recovery time ≤ Impact tolerance for critical services
If recovery time exceeds tolerance, resilience is inadequate even if losses are small.

Quick revision

  • The fraud triangle has three elements: pressure, opportunity and rationalisation.
  • Internal fraud involves staff; external fraud comes from outsiders such as customers or hackers.
  • Money laundering is commonly described in three stages: placement, layering and integration.
  • KYC covers customer identification, due diligence and ongoing monitoring.
  • Enhanced due diligence applies to higher-risk customers, such as politically exposed persons.
  • A risk-based approach puts more effort where risk is higher.
  • Sanctions screening checks customers and transactions against official lists.
  • Preventive controls stop events; detective controls find them; corrective controls fix damage.
  • Segregation of duties and mandatory leave reduce opportunity for insider fraud.
  • Weak tone from the top and ignored red flags recur in major fraud cases.
  • Regulatory consequences can include fines, restrictions on business and personal accountability.
  • A strong response plan covers investigation, communication, remediation and learning.

Common mistakes

  • Treating money laundering as a type of theft or fraud loss Fix: Laundering hides the source of funds. Fraud takes funds by deceit. They can be linked but are distinct.
  • Classifying a cyber attack as its own Basel event type Fix: Map by actor. Outsider theft is External Fraud; insider misuse of systems is Internal Fraud.
  • Treating rationalization as an external control weakness. Fix: Rationalization is the individual's internal excuse. Firms influence it through culture and tone, not through a control.
  • Saying the fraud triangle is a quantitative risk measure. Fix: It is a qualitative diagnostic model. Use it to classify causes, not to compute a number.
  • Blaming the fraudster alone and ignoring the control and cultural failures. Fix: Ask what allowed it and what should have caught it. The exam rewards the system failure, not the character of the person.
  • Choosing more capital or higher limits as the cure for a fraud. Fix: Capital absorbs losses but does not stop fraud. Pick controls that remove opportunity or detect it early.
  • Treating KYC and CDD as identical in every case. Fix: Remember KYC is the wider programme and CDD is its core process. If the question forces a distinction, KYC contains CDD.
  • Mixing up layering and integration. Fix: Layering obscures the trail through complexity. Integration is when funds re-emerge as legitimate assets or income.
  • Calling reconciliations preventive. Fix: They happen after transactions, so they are detective.
  • Assigning internal audit to design or run controls. Fix: Audit is the third line and gives independent assurance only.

Exam tips

  • Look for the actor first. Most questions turn on insider versus outsider.
  • Expect distractors that name the method, such as phishing, as the category.
  • Remember money laundering questions often test the three stages or the compliance consequence, not loss type.
  • Collusion cases are a favourite trap. One insider makes it Internal Fraud.
  • Expect scenario questions. Map each fact to pressure, opportunity or rationalization before looking at the options.
  • Know the diamond adds capability. A question may describe a senior person with unusual authority and technical skill.
  • Match the fix to the side. Controls fix opportunity. Incentives and culture fix pressure and rationalization.
  • Treat red flags as triggers for investigation, not proof. Distractors often overstate them.