FRM Part II · FRM Exam Part II
Case Study: Financial Crime and Fraud for FRM Part II
This chapter covers how fraud and financial crime arise, how major cases failed, and how firms respond. You learn fraud types, the fraud triangle, AML, KYC and sanctions frameworks, controls, and recovery. To solve questions, identify the fraud type, the failed control, and the best fix or regulatory consequence.
What this chapter covers
This chapter treats financial crime and fraud as an operational risk problem with legal, reputational and financial consequences. You study the types of crime, such as internal and external fraud, money laundering, bribery and sanctions breaches. You then learn why people commit fraud and how real cases unfolded.
The second half is about defence. You cover AML, KYC and sanctions compliance, then prevention, detection and controls. Last comes resilience: how a firm responds after an event and what regulators can do to it.
The chapter links to the rest of FRM Part II in clear ways. It sits within Operational Risk and Resilience, and it uses ideas on governance, control assessment and incident response. It also touches credit risk (fraudulent borrowers), market risk (rogue trading), liquidity risk (loss of confidence after a scandal) and Current Issues topics such as digital assets and AI-enabled fraud. Expect applied, case-like questions that mix these areas.
Part II has 80 equally weighted multiple-choice questions in 4 hours, so every topic area rewards clear, fast judgement. Case-style questions in this chapter are often won by recognising a pattern: which fraud type, which control failed, which framework applies. That skill is learnable and does not need heavy calculation, so it is a good place to secure marks that other chapters make harder. The ideas also carry into operational risk and current issues questions, so effort here pays off more than once.
Case Study: Financial Crime and Fraud: topics in the order to study them
- 1Types of Financial Crime and FraudYou need the vocabulary first: internal versus external fraud, money laundering, bribery, sanctions evasion and cyber-enabled crime.
- 2Fraud Risk Drivers and the Fraud TriangleOnce you know the types, you learn why they happen: pressure, opportunity and rationalisation.
- 3Case Study Lessons from Major Fraud EventsCases make the drivers concrete and show which controls failed, so study them after the theory.
- 4AML, KYC and Sanctions Compliance FrameworksCases often end in compliance failures, so you now learn the formal frameworks that firms must follow.
- 5Fraud Prevention, Detection and ControlsWith the failures and frameworks clear, you can map each control to the risk it is meant to address.
- 6Resilience, Response and Regulatory ConsequencesThis closes the loop: what a firm does after an event, and the penalties and supervisory actions that follow.
How to prepare Case Study: Financial Crime and Fraud
Aim to recognise patterns, not memorise stories. Most questions give a short scenario and ask what went wrong or what should happen next.
- Read each topic once in study order and write a one-line definition for every fraud and crime type.
- Build a simple table in your notes: fraud type, typical driver, likely control failure, best control. Use it as your core revision sheet.
- For each case study, note four things: what happened, the driver, the failed control, and the lesson. Keep it to four lines per case.
- Learn the AML, KYC and sanctions steps as a sequence: customer identification, due diligence, ongoing monitoring, reporting of suspicious activity. Know how risk-based approaches change the intensity.
- Separate preventive, detective and corrective controls, then practise labelling controls in scenarios.
- Do scenario MCQs in timed sets. For every miss, write which clue you overlooked.
- In the final week, revisit only your table, case notes and mistakes list.
Common mistakes in Case Study: Financial Crime and Fraud
Confusing the three parts of the fraud triangle or treating them as the same thing.
Fix: Attach one example to each: a debt problem is pressure, weak oversight is opportunity, and 'I will repay it' is rationalisation.
Mixing up money laundering with fraud.
Fix: Fraud is the deception that creates gains. Laundering hides the origin of illegal funds. A case can include both.
Choosing a detective control when the question asks for prevention.
Fix: Underline the verb in the question. Ask whether the control stops the event or only finds it.
Memorising case details instead of the lesson.
Fix: Store each case as driver, failed control and lesson. Exam options test the lesson.
Treating KYC as a one-time onboarding step.
Fix: Remember that monitoring continues through the relationship and that risk ratings can change.
Ignoring the response and regulatory side.
Fix: Study response steps and consequences as a full topic, since scenario questions often ask what the firm should do next.
Last-day revision: Case Study: Financial Crime and Fraud
- The fraud triangle has three elements: pressure, opportunity and rationalisation.
- Internal fraud involves staff; external fraud comes from outsiders such as customers or hackers.
- Money laundering is commonly described in three stages: placement, layering and integration.
- KYC covers customer identification, due diligence and ongoing monitoring.
- Enhanced due diligence applies to higher-risk customers, such as politically exposed persons.
- A risk-based approach puts more effort where risk is higher.
- Sanctions screening checks customers and transactions against official lists.
- Preventive controls stop events; detective controls find them; corrective controls fix damage.
- Segregation of duties and mandatory leave reduce opportunity for insider fraud.
- Weak tone from the top and ignored red flags recur in major fraud cases.
- Regulatory consequences can include fines, restrictions on business and personal accountability.
- A strong response plan covers investigation, communication, remediation and learning.
Case Study: Financial Crime and Fraud practice questions
- Following a major internal fraud, which post-incident action best supports long-term resilience and reduces regulatory risk of repeat failur…
- A regional bank's internal audit finds that one employee can create a new vendor in the payables system, approve invoices from that vendor, …
- A bank's fraud analytics team tests a transaction-monitoring rule on 10,000 alerts over a quarter. Of these, 400 are confirmed fraud. The ru…
- An investment firm has a fund whose manager also serves as the chief executive, chief compliance officer and custodian-liaison. The auditor …
- A bank's compliance officer is reviewing the onboarding of a new corporate client whose ownership runs through three layers of holding compa…
- A risk analyst reviews a case in which a firm's finance team inflated reported revenue by recording sales before delivery to meet analyst ex…
- A bank estimates that internal fraud events occur with a Poisson frequency of 4 per year. Severity is a fixed USD 2.5 million per event. Aft…
- A trading desk supervisor at a bank also approves the settlement and reconciliation of the same desk's trades. A trader hides losses through…
Case Study: Financial Crime and Fraud in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Case Study: Financial Crime and Fraud: frequently asked questions
Is this chapter calculation heavy?
No. It is mostly conceptual and scenario-based. You need to identify fraud types, control gaps and the right regulatory or compliance response.
Which part of the chapter should I study first?
Start with the types of financial crime and fraud, then the fraud triangle. Those give you the language for the case studies and controls that follow.
How do I remember the case studies?
Summarise each in four lines: what happened, the driver, the failed control and the lesson. Focus on patterns across cases rather than detailed timelines.
Does this chapter connect to Current Issues?
Yes. Themes such as digital assets, AI and digital resilience raise new fraud and financial crime risks, so link them to the controls and response ideas here.