FRM Exam Part II · Case Study: Financial Crime and Fraud
Resilience, Response and Regulatory Consequences After Financial Crime
Updated 11 October 2026 · Fact-checked
After a fraud or financial crime event, a bank must contain the incident, preserve evidence, assess losses, recover what it can, report to regulators and law enforcement, and fix control failures. Regulators may impose fines, remediation orders and restrictions. Reputational damage often costs more than the direct loss. Resilience means the firm keeps critical services running and learns from the event.
Understand Resilience, Response and Regulatory Consequences
A financial crime event is not only a loss. It is a test of how well a firm can respond. Regulators judge three things: how fast you detected it, how well you handled it, and whether the control failures were known or ignored.
The response has a clear order. First contain the incident: freeze accounts, block access, stop payments, isolate systems. Then preserve evidence so investigators and legal teams can use it. Then escalate to senior management, the board, legal, compliance and, where required, the regulator and law enforcement.
Loss recovery comes next. Routes include recalling or freezing payments, claims on insurance, legal action against perpetrators, and recovery from third parties that failed their duties. Recovery is often partial and slow. Do not book expected recoveries as certain. Record losses in the internal loss database with the correct event type, such as internal fraud or external fraud.
Regulatory consequences go beyond the fine. They can include monetary penalties, enforcement orders, mandatory remediation programmes, independent monitors, business restrictions, higher capital add-ons and personal accountability for senior managers. Penalties tend to be larger where failures were systemic, long-running, concealed or repeated, and smaller where the firm self-reported quickly and cooperated.
Reputational damage is an indirect cost. It shows up as customer attrition, deposit outflows, higher funding cost, lost clients and falling share price. It is hard to measure, so firms use scenario analysis and indicators. Financial crime can therefore link to liquidity and strategic risk.
Resilience is the ability to keep critical operations within impact tolerances through a disruption, and to recover. After an event, firms run root-cause analysis, fix controls, retrain staff, test again and report lessons to the board. The aim is not zero incidents. It is fast detection, limited impact and credible learning.
Key formulas to remember
- Net operational loss
- Net loss = Gross loss − Recoveries (insurance and other)
- Recoveries count only when actually received or reliably certain. Gross loss is reported before recoveries.
- Total cost of an event
- Total cost = Direct loss + Fines and penalties + Remediation and legal costs + Reputational cost − Recoveries
- Reputational cost is an estimate. Do not omit it when the question asks for total economic impact.
- Response sequence
- Detect → Contain → Preserve evidence → Escalate → Report → Recover → Remediate → Learn
- Use this order to pick the best first action in a case question.
- Resilience test
- Recovery time ≤ Impact tolerance for critical services
- If recovery time exceeds tolerance, resilience is inadequate even if losses are small.
How to solve Resilience, Response and Regulatory Consequences questions
Use this method for any case question on response, penalties or resilience after a financial crime event.
- 1Identify the event type: internal or external fraud, money laundering, sanctions breach, or cyber-enabled fraud.
- 2Find the stage of the response in the question: detection, containment, reporting, recovery or remediation.
- 3Choose the action that fits the stage. Containment and evidence preservation come before blame or public statements.
- 4Check reporting duties: prompt, honest escalation to the board, regulator and law enforcement is the expected answer.
- 5Separate direct loss, recoveries, fines, remediation cost and reputational impact before calculating.
- 6Judge regulatory consequence by severity, duration, repetition, concealment and cooperation.
- 7Link the root cause to a control or governance failure and select the fix: stronger controls, culture, accountability.
- 8Pick the option that restores critical services within tolerance and records lessons learned.
Quickest way: Order and root-cause shortcut
When to use it: Use when a question asks for the best next action or the main driver of a penalty.
- Ask: what stage are we at? Pick the action for that stage in the sequence.
- Eliminate options that delay reporting, hide the event or blame one individual only.
- Prefer answers showing governance and systemic fixes over one-off patches.
- For numbers, compute gross loss, subtract only confirmed recoveries, then add fines and costs.
Common mistakes in Resilience, Response and Regulatory Consequences
Treating the direct loss as the full cost of the event.
Loss data tables show only the booked amount, so fines and reputation are forgotten.
Fix: List all cost layers: direct loss, fines, remediation, legal, reputational. Subtract recoveries last.
Netting expected insurance or legal recoveries as if they were certain.
Students want a clean net figure.
Fix: Subtract only recoveries stated as received or confirmed. Otherwise show them separately.
Choosing public communication or disciplinary action as the first step.
It feels like the visible, decisive move.
Fix: Contain, preserve evidence and escalate first. Communication follows legal and regulatory advice.
Assuming self-reporting always removes penalties.
Cooperation credit is confused with immunity.
Fix: Say that prompt reporting and cooperation can reduce a penalty. It does not guarantee none.
Blaming a single rogue employee as the root cause.
Case stories often name one fraudster.
Fix: Look for the control, supervision and culture failures that allowed the act. Regulators target those.
Confusing resilience with prevention.
Both appear in the same controls discussion.
Fix: Prevention lowers the chance of an event. Resilience limits impact and speeds recovery after it occurs.
Worked examples
Example 1
A bank loses USD 40 million to an external payment fraud. It has recovered USD 6 million by freezing funds and expects USD 10 million from insurance, not yet confirmed. It pays a regulatory fine of USD 12 million and spends USD 5 million on remediation and legal costs. Estimate the cost to date using only confirmed recoveries.
Show the solution
- Gross loss = USD 40 million.
- Confirmed recoveries = USD 6 million. The USD 10 million insurance is unconfirmed, so exclude it.
- Net direct loss = 40 − 6 = USD 34 million.
- Add fine and remediation: 34 + 12 + 5 = USD 51 million.
Answer: USD 51 million, before any reputational cost and before insurance is confirmed.
Example 2
A bank finds staff ran unauthorised transfers for three years. Compliance had flagged alerts twice but they were closed without review. The regulator will set the penalty. Which factor most increases it, and what should the bank do first on discovery?
Show the solution
- Identify aggravating factors: three-year duration, ignored alerts, and weak supervision show systemic failure.
- The ignored alerts suggest known control weaknesses were not acted on, which regulators treat severely.
- First action: contain by stopping the transfers and securing access, then preserve evidence.
- Then escalate to the board and report to the regulator and law enforcement as required, and start root-cause review.
Answer: The most aggravating factor is the long duration combined with ignored alerts, showing systemic control and governance failure. First, contain the activity and preserve evidence, then escalate and report.
Exam tips
- Questions usually ask for the best first or next step. Learn the response sequence cold.
- When a case mentions a long-running failure, repeated findings or concealment, expect the higher penalty answer.
- Watch for options that net unconfirmed recoveries or skip reputational and remediation costs.
- Distinguish prevention, detection, response and resilience. Match the answer to the stage described.
- Credit for cooperation and self-reporting reduces penalties but does not remove accountability.
Practice questions from Case Study: Financial Crime and Fraud
- After a payments fraud, a bank's board asks the operational risk function how to demonstrate resilience rather than just recovery. Which met…
- A bank's fraud analytics team tests an alert model on 10,000 transactions, of which 200 are truly fraudulent. The model flags 160 of the fra…
- A bank's internal fraud analysis of a past unauthorized-trading event finds: (1) the trader's limit breaches were reclassified as 'temporary…
- A trading desk at a bank reports consistently smooth profits with very low volatility, despite operating in volatile markets. The desk head …
- A bank estimates that, without controls, expected annual fraud loss on a product is USD 4.0 million. A preventive control reduces the probab…
Resilience, Response and Regulatory Consequences: frequently asked questions
How should a bank respond to a fraud incident?
Contain it, preserve evidence and escalate to senior management and the board. Report to regulators and law enforcement as required, then pursue recovery and fix root causes. Record the loss accurately in the loss database.
What regulatory penalties can banks face for financial crime failures?
Fines, enforcement orders, mandatory remediation, independent monitors, business restrictions and personal accountability for senior managers. Severity, duration, repetition, concealment and cooperation shape the outcome.
Why is reputational risk from financial crime hard to measure?
Its effects appear as customer loss, higher funding costs and lost business over time, not as a single booked figure. Firms estimate it with scenarios and indicators.
What is operational resilience after a fraud event?
It is the ability to keep critical services running within impact tolerances and recover quickly. It also means learning from the event and strengthening controls.