Skip to content

FRM Part II · FRM Exam Part II

Sound Management of Risks Related to Money Laundering and Financing of Terrorism: formula sheet

Full chapter guide

Key formulas

Three stages of money laundering
Placement → Layering → Integration
Placement enters funds into the system; layering obscures the trail; integration returns funds as apparently legitimate.
ML vs TF source of funds
ML: illegal source → legitimate appearance. TF: legal or illegal source → illegal use
Use this contrast to answer any difference question.
Risks arising from ML/FT for a bank
Operational + Legal/Compliance + Reputational + Concentration
These are the risk channels the Basel guidelines highlight; do not label it only as credit or market risk.
Core pillars of the Basel approach
Risk assessment → Customer acceptance and due diligence → Ongoing monitoring → Governance and group-wide implementation
Risk-based approach; stronger controls for higher-risk customers and products.
Residual risk logic
Residual risk = Inherent risk − Effect of controls
A conceptual relationship, not a numerical formula. Risk is assessed before controls, then after controls.
Inherent risk categories
Customers + Products/services + Delivery channels + Geographies
The four standard lenses for an enterprise-wide ML/FT assessment.
Three lines of defence
1st: business units | 2nd: compliance / chief AML officer | 3rd: internal audit
First line owns and manages the risk, second oversees and advises, third gives independent assurance.
Board and senior management split
Board: approve and oversee | Senior management: implement and resource
Board does not run daily controls. It sets direction and checks it is followed.
Four elements of CDD
Identify and verify customer + identify and verify beneficial owner + understand purpose and nature + ongoing due diligence
Use this as a checklist when an option claims CDD is complete.
Risk-based approach
Higher ML/FT risk → enhanced measures; lower risk → simplified measures
Simplified CDD is never an exemption from monitoring and reporting of suspicion.
EDD for PEPs
Identify PEP + senior management approval + source of wealth and funds + enhanced ongoing monitoring
Applies to family members and close associates as well.
Beneficial owner
Natural person who ultimately owns or controls the customer, or on whose behalf a transaction is conducted
A legal entity or nominee shareholder is not a beneficial owner.
Failure to complete CDD
CDD incomplete → do not open account or transact; consider filing an STR
Exam answers favour refusal plus escalation, not proceeding with a promise to verify later.
Suspicious transaction reporting
Alert → internal review → escalate to compliance/MLRO → STR to FIU if suspicion remains
Reporting is triggered by suspicion, not proof, and no tipping off.
Responsibility rule for third parties
Ultimate CDD responsibility = relying bank (always)
Reliance or outsourcing never transfers accountability to the introducer or provider.
Conditions for reliance
Third party regulated and supervised + CDD and record-keeping in place + data available without delay + country risk assessed
If any condition fails, the bank should do its own CDD.
Correspondent banking approach
Enhanced due diligence on respondent + senior management approval + documented responsibilities
Applies to cross-border relationships in particular; assess respondent's AML/CFT controls and supervision.
Shell bank rule
Shell bank = no physical presence + no regulated group affiliation → relationship prohibited
Also ensure the respondent does not serve shell banks.
Payable-through accounts
Respondent's customers have direct access → respondent must have done CDD and provide data on request
Treat as higher risk.
Wire transfer information
Originator: name, account number, address/ID. Beneficiary: name, account number. Information must accompany the transfer.
Ordering institution must verify originator information. Intermediary institutions pass the information along. Beneficiary institution checks for missing data.
Group-wide standard rule
Standard applied abroad = stricter of (home standard, host standard), to the extent host law allows
If host law prevents the home standard, tell the home supervisor and add controls.
Record retention minimum (FATF)
Retention ≥ 5 years after end of relationship (CDD records) or after transaction (transaction records)
Local law may require longer. The five years is a minimum, not a maximum.
Information flow principle
Group functions ⇄ branches and subsidiaries: customer, account and transaction data for ML/FT risk management
Subject to confidentiality and data-use safeguards.
Supervisory toolkit
Assess → Cooperate → Sanction (proportionate and dissuasive)
Sanctions can target the institution and, in some cases, directors and senior management.

Quick revision

  • ML/FT risk should be managed inside the bank's overall risk management framework.
  • A risk-based approach means controls are stronger where risk is higher.
  • The bank must first identify and assess its own ML/FT risks.
  • The board and senior management are responsible for the ML/FT risk framework.
  • Business units are the first line of defence and own the risk day to day.
  • Compliance and risk functions form the second line, and internal audit is the third.
  • Customer due diligence covers identification, verification and understanding the customer's activity.
  • Higher-risk customers need enhanced due diligence and senior approval.
  • Ongoing monitoring checks that transactions fit what the bank knows about the customer.
  • When using a third party, the bank stays ultimately responsible for due diligence.
  • Correspondent banking is higher risk and needs careful assessment of the respondent bank.
  • Wire transfers should carry accurate originator and beneficiary information.
  • Group-wide policies should apply consistently, with information shared across the group's entities.

Common mistakes

  • Saying terrorist financing always uses illegal money. Fix: Remember TF can use legal funds. The defining feature is the purpose, not the source.
  • Mixing up layering and integration. Fix: Layering hides the trail through complexity. Integration is when the money re-emerges as legitimate wealth.
  • Treating the compliance officer as the owner of ML/FT risk. Fix: The first line owns and manages the risk. Compliance is second line and oversees, advises and monitors. Ultimate accountability stays with the board and senior management.
  • Placing internal audit in day-to-day controls such as customer screening. Fix: Internal audit is the third line. It independently assesses the framework and controls and does not operate them.
  • Treating a PEP as a customer the bank must refuse. Fix: PEPs are higher risk, not banned. The answer is EDD, senior management approval, source of wealth and funds, and enhanced monitoring.
  • Accepting a company's name as the end of beneficial ownership checks. Fix: Look through to the natural persons who own or control it. Legal entities and nominees are not beneficial owners.
  • Believing responsibility moves to the introducer once it performs CDD. Fix: Remember that the relying bank remains ultimately responsible for CDD.
  • Treating reliance and outsourcing as the same thing. Fix: Reliance uses a supervised third party with its own customer relationship. Outsourcing uses an agent working under the bank's own policies.
  • Applying the host-country standard when it is weaker than the group standard. Fix: Remember the group applies the stricter standard where host law permits.
  • Saying a bank can ignore group-wide sharing because of secrecy laws. Fix: The bank must inform its home supervisor and apply additional measures to manage the risk.

Exam tips

  • Expect scenario questions: classify the stage of ML or the risk channel from a short story.
  • Know the ML versus TF contrast cold. It is a favourite distractor test.
  • Look for the phrase 'risk-based approach'. It is usually the right answer on control design.
  • Reject options that assign responsibility only to the compliance team; board and senior management are accountable.
  • Name the risk channel precisely: operational, legal, reputational or concentration.
  • Memorise the three lines and one verb for each: own and manage, oversee and advise, independently assure.
  • Watch for independence traps, where one unit both performs and tests a control.
  • Questions often hinge on the board versus senior management: approve and oversee versus implement and resource.