FRM Part II · FRM Exam Part II
Sound Management of Risks Related to Money Laundering and Financing of Terrorism: formula sheet
Key formulas
- Three stages of money laundering
- Placement → Layering → Integration
- Placement enters funds into the system; layering obscures the trail; integration returns funds as apparently legitimate.
- ML vs TF source of funds
- ML: illegal source → legitimate appearance. TF: legal or illegal source → illegal use
- Use this contrast to answer any difference question.
- Risks arising from ML/FT for a bank
- Operational + Legal/Compliance + Reputational + Concentration
- These are the risk channels the Basel guidelines highlight; do not label it only as credit or market risk.
- Core pillars of the Basel approach
- Risk assessment → Customer acceptance and due diligence → Ongoing monitoring → Governance and group-wide implementation
- Risk-based approach; stronger controls for higher-risk customers and products.
- Residual risk logic
- Residual risk = Inherent risk − Effect of controls
- A conceptual relationship, not a numerical formula. Risk is assessed before controls, then after controls.
- Inherent risk categories
- Customers + Products/services + Delivery channels + Geographies
- The four standard lenses for an enterprise-wide ML/FT assessment.
- Three lines of defence
- 1st: business units | 2nd: compliance / chief AML officer | 3rd: internal audit
- First line owns and manages the risk, second oversees and advises, third gives independent assurance.
- Board and senior management split
- Board: approve and oversee | Senior management: implement and resource
- Board does not run daily controls. It sets direction and checks it is followed.
- Four elements of CDD
- Identify and verify customer + identify and verify beneficial owner + understand purpose and nature + ongoing due diligence
- Use this as a checklist when an option claims CDD is complete.
- Risk-based approach
- Higher ML/FT risk → enhanced measures; lower risk → simplified measures
- Simplified CDD is never an exemption from monitoring and reporting of suspicion.
- EDD for PEPs
- Identify PEP + senior management approval + source of wealth and funds + enhanced ongoing monitoring
- Applies to family members and close associates as well.
- Beneficial owner
- Natural person who ultimately owns or controls the customer, or on whose behalf a transaction is conducted
- A legal entity or nominee shareholder is not a beneficial owner.
- Failure to complete CDD
- CDD incomplete → do not open account or transact; consider filing an STR
- Exam answers favour refusal plus escalation, not proceeding with a promise to verify later.
- Suspicious transaction reporting
- Alert → internal review → escalate to compliance/MLRO → STR to FIU if suspicion remains
- Reporting is triggered by suspicion, not proof, and no tipping off.
- Responsibility rule for third parties
- Ultimate CDD responsibility = relying bank (always)
- Reliance or outsourcing never transfers accountability to the introducer or provider.
- Conditions for reliance
- Third party regulated and supervised + CDD and record-keeping in place + data available without delay + country risk assessed
- If any condition fails, the bank should do its own CDD.
- Correspondent banking approach
- Enhanced due diligence on respondent + senior management approval + documented responsibilities
- Applies to cross-border relationships in particular; assess respondent's AML/CFT controls and supervision.
- Shell bank rule
- Shell bank = no physical presence + no regulated group affiliation → relationship prohibited
- Also ensure the respondent does not serve shell banks.
- Payable-through accounts
- Respondent's customers have direct access → respondent must have done CDD and provide data on request
- Treat as higher risk.
- Wire transfer information
- Originator: name, account number, address/ID. Beneficiary: name, account number. Information must accompany the transfer.
- Ordering institution must verify originator information. Intermediary institutions pass the information along. Beneficiary institution checks for missing data.
- Group-wide standard rule
- Standard applied abroad = stricter of (home standard, host standard), to the extent host law allows
- If host law prevents the home standard, tell the home supervisor and add controls.
- Record retention minimum (FATF)
- Retention ≥ 5 years after end of relationship (CDD records) or after transaction (transaction records)
- Local law may require longer. The five years is a minimum, not a maximum.
- Information flow principle
- Group functions ⇄ branches and subsidiaries: customer, account and transaction data for ML/FT risk management
- Subject to confidentiality and data-use safeguards.
- Supervisory toolkit
- Assess → Cooperate → Sanction (proportionate and dissuasive)
- Sanctions can target the institution and, in some cases, directors and senior management.
Quick revision
- ML/FT risk should be managed inside the bank's overall risk management framework.
- A risk-based approach means controls are stronger where risk is higher.
- The bank must first identify and assess its own ML/FT risks.
- The board and senior management are responsible for the ML/FT risk framework.
- Business units are the first line of defence and own the risk day to day.
- Compliance and risk functions form the second line, and internal audit is the third.
- Customer due diligence covers identification, verification and understanding the customer's activity.
- Higher-risk customers need enhanced due diligence and senior approval.
- Ongoing monitoring checks that transactions fit what the bank knows about the customer.
- When using a third party, the bank stays ultimately responsible for due diligence.
- Correspondent banking is higher risk and needs careful assessment of the respondent bank.
- Wire transfers should carry accurate originator and beneficiary information.
- Group-wide policies should apply consistently, with information shared across the group's entities.
Common mistakes
- Saying terrorist financing always uses illegal money. Fix: Remember TF can use legal funds. The defining feature is the purpose, not the source.
- Mixing up layering and integration. Fix: Layering hides the trail through complexity. Integration is when the money re-emerges as legitimate wealth.
- Treating the compliance officer as the owner of ML/FT risk. Fix: The first line owns and manages the risk. Compliance is second line and oversees, advises and monitors. Ultimate accountability stays with the board and senior management.
- Placing internal audit in day-to-day controls such as customer screening. Fix: Internal audit is the third line. It independently assesses the framework and controls and does not operate them.
- Treating a PEP as a customer the bank must refuse. Fix: PEPs are higher risk, not banned. The answer is EDD, senior management approval, source of wealth and funds, and enhanced monitoring.
- Accepting a company's name as the end of beneficial ownership checks. Fix: Look through to the natural persons who own or control it. Legal entities and nominees are not beneficial owners.
- Believing responsibility moves to the introducer once it performs CDD. Fix: Remember that the relying bank remains ultimately responsible for CDD.
- Treating reliance and outsourcing as the same thing. Fix: Reliance uses a supervised third party with its own customer relationship. Outsourcing uses an agent working under the bank's own policies.
- Applying the host-country standard when it is weaker than the group standard. Fix: Remember the group applies the stricter standard where host law permits.
- Saying a bank can ignore group-wide sharing because of secrecy laws. Fix: The bank must inform its home supervisor and apply additional measures to manage the risk.
Exam tips
- Expect scenario questions: classify the stage of ML or the risk channel from a short story.
- Know the ML versus TF contrast cold. It is a favourite distractor test.
- Look for the phrase 'risk-based approach'. It is usually the right answer on control design.
- Reject options that assign responsibility only to the compliance team; board and senior management are accountable.
- Name the risk channel precisely: operational, legal, reputational or concentration.
- Memorise the three lines and one verb for each: own and manage, oversee and advise, independently assure.
- Watch for independence traps, where one unit both performs and tests a control.
- Questions often hinge on the board versus senior management: approve and oversee versus implement and resource.