FRM Exam Part II · Case Study: Financial Crime and Fraud
Fraud Prevention, Detection and Controls for FRM Part II
Updated 11 October 2026 · Fact-checked
Fraud management combines preventive controls that stop fraud before it happens, detective controls that find it after it starts, and corrective actions that limit damage. Three lines of defence assign ownership. Segregation of duties, whistleblowing and analytics support them. In exams, match each control to its type and the gap it closes.
Understand Fraud Prevention, Detection and Controls
Fraud is deliberate deception for gain. Banks cannot remove it, so they build layers of control to cut the chance of fraud and to limit loss when it occurs. FRM questions test whether you can sort these controls and judge which one fits a scenario.
Preventive controls act before a transaction completes. Examples: segregation of duties, approval limits, access rights, dual authorisation, background checks, mandatory leave and customer authentication. They reduce likelihood.
Detective controls act after the event or during it, to find what slipped through. Examples: reconciliations, exception reports, audit reviews, transaction monitoring, surveillance, whistleblowing hotlines and data analytics. They shorten the time to discovery and so reduce loss. Many controls do both: mandatory leave deters fraud (preventive) and lets a replacement uncover it (detective). Corrective controls then fix the damage, for example freezing accounts, recovering funds, disciplining staff and repairing the control gap.
The three lines of defence give ownership. The first line is business management, which owns the risk and runs day-to-day controls. The second line is risk and compliance, which sets policy, provides challenge and monitors. The third line is internal audit, which gives independent assurance to the board. Independence matters: the third line must not design or run the controls it audits. The board and senior management set the tone and risk appetite.
Segregation of duties splits initiating, authorising, recording and custody of assets so no one person can commit and hide fraud alone. It fails under collusion, which is why rotation, mandatory leave and detective checks are added. Whistleblowing lets staff report concerns confidentially, with protection from retaliation and a channel outside the line manager. It works only if people trust it.
Analytics and technology scan large volumes for unusual patterns: rules, statistical outlier tests, link analysis, behavioural profiling and machine learning. Rules catch known schemes. Models can spot new ones but produce false positives and need validation, good data and human review. Analytics are mainly detective, though real-time scoring that blocks a payment is preventive.
Key formulas to remember
- Preventive vs detective
- Preventive = before the event, lowers likelihood. Detective = during or after, shortens discovery time and lowers loss.
- Ask: does it stop the act or find it?
- Three lines of defence
- 1st line = owns and manages risk. 2nd line = oversight, policy, challenge. 3rd line = independent assurance (internal audit).
- Audit must stay independent of operations.
- Segregation of duties
- Initiate ≠ Authorise ≠ Record ≠ Custody
- Defeated by collusion, so add detective controls.
- Analytics trade-off
- More sensitive alerts → more detections but more false positives
- Thresholds balance investigation capacity and missed fraud.
How to solve Fraud Prevention, Detection and Controls questions
Use this method for any scenario on fraud controls.
- 1Identify the fraud scheme and who could commit it (insider, outsider, collusion).
- 2Find the control failure: missing, badly designed or overridden.
- 3Classify the control in question as preventive, detective or corrective.
- 4Check the line of defence: who owns, who oversees, who assures.
- 5Pick the control that closes the specific gap, not a generic one.
- 6Consider limits: collusion, management override, false positives, data quality.
- 7Choose the option that is most direct and consistent with independence and escalation.
Quickest way: Timing and owner test
When to use it: For multiple-choice questions that ask which control or which line of defence applies.
- Timing: before the act is preventive, after is detective.
- Owner: runs it daily is line 1, sets policy or monitors is line 2, independently tests is line 3.
- Eliminate options that break independence or let one person control the whole process.
- Between two good options, choose the one aimed at the stated weakness.
Common mistakes in Fraud Prevention, Detection and Controls
Calling reconciliations preventive.
They feel like a safeguard.
Fix: They happen after transactions, so they are detective.
Assigning internal audit to design or run controls.
Audit is seen as the main control function.
Fix: Audit is the third line and gives independent assurance only.
Treating segregation of duties as collusion-proof.
Separation looks complete.
Fix: Collusion defeats it; add rotation, mandatory leave and monitoring.
Placing compliance monitoring in the first line.
Compliance staff sit close to business.
Fix: Compliance and risk oversight are second line; business owns the risk.
Assuming analytics prove fraud.
Alerts look conclusive.
Fix: Alerts are leads needing investigation; false positives are common.
Saying a whistleblowing line replaces controls.
Tips can uncover big frauds.
Fix: It is one detective channel and needs protection from retaliation and trust.
Worked examples
Example 1
A bank's treasury clerk can both enter and approve payments to new beneficiaries. A fraud occurs. Which is the best response: (A) monthly reconciliation of payments, (B) dual authorisation with separate maker and checker, (C) an annual internal audit, (D) a whistleblowing hotline?
Show the solution
- The failure is one person controlling initiation and approval, a segregation-of-duties gap.
- The best fix stops the act before it happens, so a preventive control is needed.
- Reconciliation and audit are detective and after the fact; a hotline depends on others reporting.
- Maker-checker splits initiation from approval directly.
Answer: B. Dual authorisation with separate maker and checker closes the gap preventively.
Example 2
A fraud analytics model flags many payments, most legitimate. Management wants to cut alerts. What trade-off should a risk manager explain, and which line of defence should validate the model?
Show the solution
- Raising the alert threshold cuts false positives and investigation workload.
- But it also raises the chance of missing real fraud, which is a cost of undetected losses.
- So set thresholds by balancing investigation capacity against fraud loss, and test with back-testing on known cases.
- Model validation is independent challenge: the second line (model risk) validates, and internal audit may give assurance on the process.
Answer: Tightening thresholds lowers false positives but risks missing fraud; calibrate on loss versus capacity, with independent validation by the second line and assurance from the third.
Exam tips
- Always label timing first: preventive, detective or corrective.
- Check independence in line-of-defence questions; audit never runs controls.
- Pick the control that targets the described weakness, not the most sophisticated tool.
- Expect trade-off wording on analytics: false positives against missed fraud.
- Link fraud to the fraud triangle: controls reduce opportunity.
Practice questions from Case Study: Financial Crime and Fraud
- A compliance officer notices a customer making many cash deposits of just under the reporting threshold across several branches in one week,…
- A trading desk's head of operations also approves the booking of trades and signs off on the reconciliation of the desk's profit and loss. O…
- After a rogue-trading incident, a bank requires all front-office traders to take at least ten consecutive business days of leave each year, …
- Which indicator would a fraud risk assessor classify as a rationalization-related warning sign rather than a pressure or opportunity sign?
- A bank's fraud-risk committee evaluates several controls for a card-not-present fraud problem. Which combination best reflects a layered, de…
Fraud Prevention, Detection and Controls in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Fraud Prevention, Detection and Controls: frequently asked questions
What is the difference between preventive and detective controls?
Preventive controls stop a fraud before it happens, such as dual approval or access limits. Detective controls find it after or while it occurs, such as reconciliations and monitoring. Good programmes use both.
Who does what in the three lines of defence for fraud?
The first line owns the risk and runs controls. The second line, risk and compliance, sets policy and monitors. The third line, internal audit, independently assures the board.
How is data analytics used to detect fraud in banks?
Banks use rules, statistical outlier tests, link analysis and machine learning to spot unusual transactions or behaviour. Alerts go to investigators. Models need good data, tuning and validation.
Why is whistleblowing important?
Insiders often see fraud before controls do. A confidential channel with protection from retaliation helps surface concerns outside the normal management chain.