FRM Exam Part II · Case Study: Financial Crime and Fraud
Case Study Lessons from Major Fraud Events in FRM Part 2
Updated 11 October 2026 · Fact-checked
Fraud case studies show how weak controls let one person or one scheme cause huge losses. To answer them, name the fraud type, find the root cause, spot the failed controls, and link each to a fix such as segregation of duties, independent verification, escalation of red flags and a speak-up culture.
Understand Case Study Lessons from Major Fraud Events
A fraud case study is a real event used to teach what went wrong. The exam does not ask you to memorise stories. It asks you to read a short case and recognise the pattern: who committed the fraud, how it was hidden, which controls failed and what should change.
Most large cases share the same few causes. One person controlled both trading and settlement. Reports were not checked by someone independent. Warning signs, such as unusual profits, large cash or funding requests, or unexplained limit breaches, were explained away instead of challenged. Management rewarded results and did not ask how they were achieved. This is why the fraud triangle (pressure, opportunity, rationalisation) and the three lines of defence appear in almost every answer.
Know a few anchor cases. Barings (1995): a trader in Singapore ran both trading and back office, and hid losses in an error account (88888); the bank failed, with losses widely reported at about £827 million. Société Générale (2008): a trader built large unauthorised positions and hid them with fictitious offsetting trades; losses were widely reported at about €4.9 billion. UBS (2011): a trader used fictitious hedges to conceal unauthorised positions; losses were widely reported at about $2.3 billion. Madoff: a Ponzi scheme, with no real trading, run by a firm with weak independent oversight and outside investors who failed to do due diligence. Wells Fargo (2016): pressure from sales targets led to accounts opened without customers' consent, which is a conduct and incentive failure, not a rogue trader. Punjab National Bank (2018): fraudulent guarantees (letters of undertaking) were issued through the payments messaging system without being recorded in the core banking system.
Treat the figures as approximate and as widely reported. The exam rewards the pattern, not the decimal. Regulatory responses also follow a pattern: fines, tougher supervision, stronger rules on governance, conduct and incentives, and calls for better independent checks.
Finally, link each case to the Basel operational risk event types. Rogue trading and Ponzi schemes are mostly internal fraud. Sales-practice scandals are clients, products and business practices. Knowing the label helps you pick the right answer fast.
Key formulas to remember
- Fraud triangle
- Fraud = Pressure + Opportunity + Rationalisation
- Controls mainly remove opportunity. Culture and incentives address pressure and rationalisation.
- Unauthorised position loss
- Loss ≈ Hidden exposure × Adverse price move
- Simple approximation. Hidden exposure grows as the trader doubles down to recover losses, so loss grows faster than the first error.
- Core control rule: segregation of duties
- Front office ≠ Middle office ≠ Back office
- No one person should initiate, record, confirm and settle the same trade.
- Three lines of defence
- 1st: business owns risk | 2nd: risk and compliance oversee | 3rd: internal audit assures
- Case failures usually show one or more lines not working, not a missing line.
- Typical rogue trading red flags
- Unusually high profit + low reported risk + no leave + resists change in role
- Also look for large unexplained funding needs, cancelled or amended trades, and unconfirmed counterparties.
- Basel event type for these cases
- Rogue trading, Ponzi = Internal fraud | Mis-selling, sales abuse = Clients, products and business practices
- Use the event type to anchor your answer.
How to solve Case Study Lessons from Major Fraud Events questions
Use the same method on any fraud case question. It keeps you from being drawn in by the story.
- 1Read the last line of the question first so you know whether it asks for the cause, the failed control, the red flag, the loss driver or the remedy.
- 2Name the fraud type: internal fraud such as unauthorised trading, a Ponzi scheme, external fraud, or a conduct and incentive failure.
- 3Find the root cause in the story: one person with too much control, no independent verification, weak data, or pressure from targets.
- 4List the control failures by line of defence. Ask what the front office, risk and compliance, and audit each should have caught.
- 5Spot the ignored warning signs, such as outsized profits, repeated limit breaches, or unanswered questions from control staff.
- 6Match the remedy to the failure: segregation of duties, independent confirmations, mandatory leave, reconciliation, escalation rules, better incentives.
- 7Check the options against your own answer before reading them, then remove any option that fixes the wrong problem.
- 8If the question asks about a response or consequence, think fines, supervisory action, management change and stronger rules.
Quickest way: Cause, control, cure in 30 seconds
When to use it: Use for a short scenario question where you have about two minutes.
- Underline the one fact that stands out, such as a trader who handles his own settlement or profits that look too good.
- Say the cause in five words, for example one person controls everything.
- Name the missing control that matches it, such as segregation of duties or independent verification.
- Pick the option that adds that control. Reject options that only add reporting, training or more capital.
- Be wary of any option with the words always or only. Fraud has several causes.
Common mistakes in Case Study Lessons from Major Fraud Events
Blaming the fraudster alone and ignoring the control and cultural failures.
The stories are told as one person's wrongdoing, so students answer at that level.
Fix: Ask what allowed it and what should have caught it. The exam rewards the system failure, not the character of the person.
Choosing more capital or higher limits as the cure for a fraud.
Students carry habits from market and credit risk questions.
Fix: Capital absorbs losses but does not stop fraud. Pick controls that remove opportunity or detect it early.
Mixing up cases, for example calling Madoff a rogue trader.
Case names blur together when you only memorise losses.
Fix: Keep one line per case: Barings and Société Générale are unauthorised trading, Madoff is a Ponzi scheme, Wells Fargo is sales incentives, PNB is fraudulent guarantees.
Treating fictitious offsetting trades as a market risk problem.
The trades look like hedges, so students think the position was hedged.
Fix: The hedge was fake, so true exposure was unhedged. It is an operational and control failure that produced market risk.
Overlooking ignored warning signs and focusing only on the missing control.
Students assume controls were absent, when often they existed but were overridden or not acted on.
Fix: Look for alerts, queries and audit findings that were noted but not followed up. Say that escalation and challenge failed.
Quoting loss figures as exact or inventing numbers.
Students try to show detail to look prepared.
Fix: Use only well-known approximate figures and treat them as context. Questions test reasoning and give any numbers they need.
Worked examples
Example 1
A bank's equity trader also approves his own trade confirmations. He books fictitious offsetting trades so that his reported net risk looks small, while a large unauthorised position builds. His desk shows steady, unusually high profits. Which action would have been most effective at detecting the problem early?
A) Raising the bank's regulatory capital
B) Independent confirmation and reconciliation of trades by operations staff outside the front office
C) Increasing the trader's bonus deferral period only
D) Replacing the trading limit with a larger one
Show the solution
- Identify the fraud type: internal fraud through unauthorised trading hidden by fake trades.
- Root cause: the trader controls confirmation of his own trades, so there is no segregation of duties.
- The fictitious offsets only work because no independent party checks them against the real counterparty.
- Option A absorbs losses but does not detect fraud. Option C changes incentives but would not expose fake trades. Option D worsens the exposure.
- Option B removes the opportunity and creates detection through independent verification.
Answer: B. Independent confirmation and reconciliation outside the front office, which restores segregation of duties and exposes fictitious trades.
Example 2
A hedge fund reports steady annual returns with very little volatility in all market conditions. It is run by one firm that also acts as its own broker-dealer and custodian, and its auditor is a very small unknown firm. Which is the best conclusion for a risk manager at an investor?
A) The fund is low risk and should have its allocation increased
B) The fund shows operational and governance red flags consistent with possible fraud, so due diligence should be escalated before any further investment
C) Only the strategy needs review, since operations do not affect investment risk
D) The auditor size is irrelevant if returns are stable
Show the solution
- List the red flags: returns that are too smooth in all markets, a lack of independent custody, and weak independent audit.
- Compare with the known Ponzi pattern: no real trading, and no independent party verifying assets.
- Smooth returns are not evidence of low risk when the strategy cannot explain them.
- Option A ignores the flags. Option C is wrong because operational risk caused the largest losses. Option D wrongly dismisses a key control.
- Option B calls for escalated operational due diligence, such as verifying assets with independent custodians and checking the auditor and service providers.
Answer: B. These are classic Ponzi-type red flags, so escalate due diligence before investing more.
Exam tips
- Practise the cause, control, cure chain until it is automatic. Most options are built to test it.
- Learn one sentence per case: type of fraud, how it was hidden, which control failed. That is enough for most questions.
- When two options both sound sensible, choose the one that removes opportunity or detects fraud early, not the one that only absorbs the loss.
- Watch for culture clues such as targets, bonuses or a star performer who is not challenged. They signal a conduct or governance failure.
- Link answers to Basel terms: internal fraud, clients, products and business practices, and the three lines of defence.
Practice questions from Case Study: Financial Crime and Fraud
- A bank's risk function wants to lower fraud risk by acting on the opportunity side of the fraud triangle. Which action most directly targets…
- After a payments fraud, a bank's board asks the operational risk function how to demonstrate resilience rather than just recovery. Which met…
- A bank's fraud analytics team tests an alert model on 10,000 transactions, of which 200 are truly fraudulent. The model flags 160 of the fra…
- A bank's internal fraud analysis of a past unauthorized-trading event finds: (1) the trader's limit breaches were reclassified as 'temporary…
- A trading desk at a bank reports consistently smooth profits with very low volatility, despite operating in volatile markets. The desk head …
Case Study Lessons from Major Fraud Events: frequently asked questions
Do I need to remember exact loss figures for fraud cases in FRM Part II?
No. Know the rough scale and, more importantly, the pattern of the failure. Questions usually give the numbers they need and test your reasoning about causes and controls.
Which fraud cases should I know for the exam?
Know the rogue trading cases at Barings, Société Générale and UBS, the Madoff Ponzi scheme, and conduct and incentive failures such as Wells Fargo. Also be able to explain the Punjab National Bank guarantee fraud as an example of weak system integration and controls.
How do I answer a case study question quickly?
Identify the fraud type, then the root cause, then the control that failed, then pick the remedy that fixes exactly that failure. Reject options that only add capital, training or reporting unless the case points to those gaps.
Are these cases credit, market or operational risk?
The loss may show up as market or credit loss, but the root cause is operational: internal fraud, weak controls or poor governance. Basel groups them under operational risk event types.