Skip to content

FRM Exam Part II · Case Study: Financial Crime and Fraud

Resilience, Response and Regulatory Consequences After Financial Crime

Updated 11 October 2026 · Fact-checked

After a fraud or financial crime event, a bank must contain the incident, preserve evidence, assess losses, recover what it can, report to regulators and law enforcement, and fix control failures. Regulators may impose fines, remediation orders and restrictions. Reputational damage often costs more than the direct loss. Resilience means the firm keeps critical services running and learns from the event.

Understand Resilience, Response and Regulatory Consequences

A financial crime event is not only a loss. It is a test of how well a firm can respond. Regulators judge three things: how fast you detected it, how well you handled it, and whether the control failures were known or ignored.

The response has a clear order. First contain the incident: freeze accounts, block access, stop payments, isolate systems. Then preserve evidence so investigators and legal teams can use it. Then escalate to senior management, the board, legal, compliance and, where required, the regulator and law enforcement.

Loss recovery comes next. Routes include recalling or freezing payments, claims on insurance, legal action against perpetrators, and recovery from third parties that failed their duties. Recovery is often partial and slow. Do not book expected recoveries as certain. Record losses in the internal loss database with the correct event type, such as internal fraud or external fraud.

Regulatory consequences go beyond the fine. They can include monetary penalties, enforcement orders, mandatory remediation programmes, independent monitors, business restrictions, higher capital add-ons and personal accountability for senior managers. Penalties tend to be larger where failures were systemic, long-running, concealed or repeated, and smaller where the firm self-reported quickly and cooperated.

Reputational damage is an indirect cost. It shows up as customer attrition, deposit outflows, higher funding cost, lost clients and falling share price. It is hard to measure, so firms use scenario analysis and indicators. Financial crime can therefore link to liquidity and strategic risk.

Resilience is the ability to keep critical operations within impact tolerances through a disruption, and to recover. After an event, firms run root-cause analysis, fix controls, retrain staff, test again and report lessons to the board. The aim is not zero incidents. It is fast detection, limited impact and credible learning.

Key formulas to remember

Net operational loss
Net loss = Gross loss − Recoveries (insurance and other)
Recoveries count only when actually received or reliably certain. Gross loss is reported before recoveries.
Total cost of an event
Total cost = Direct loss + Fines and penalties + Remediation and legal costs + Reputational cost − Recoveries
Reputational cost is an estimate. Do not omit it when the question asks for total economic impact.
Response sequence
Detect → Contain → Preserve evidence → Escalate → Report → Recover → Remediate → Learn
Use this order to pick the best first action in a case question.
Resilience test
Recovery time ≤ Impact tolerance for critical services
If recovery time exceeds tolerance, resilience is inadequate even if losses are small.

How to solve Resilience, Response and Regulatory Consequences questions

Use this method for any case question on response, penalties or resilience after a financial crime event.

  1. 1Identify the event type: internal or external fraud, money laundering, sanctions breach, or cyber-enabled fraud.
  2. 2Find the stage of the response in the question: detection, containment, reporting, recovery or remediation.
  3. 3Choose the action that fits the stage. Containment and evidence preservation come before blame or public statements.
  4. 4Check reporting duties: prompt, honest escalation to the board, regulator and law enforcement is the expected answer.
  5. 5Separate direct loss, recoveries, fines, remediation cost and reputational impact before calculating.
  6. 6Judge regulatory consequence by severity, duration, repetition, concealment and cooperation.
  7. 7Link the root cause to a control or governance failure and select the fix: stronger controls, culture, accountability.
  8. 8Pick the option that restores critical services within tolerance and records lessons learned.

Quickest way: Order and root-cause shortcut

When to use it: Use when a question asks for the best next action or the main driver of a penalty.

  1. Ask: what stage are we at? Pick the action for that stage in the sequence.
  2. Eliminate options that delay reporting, hide the event or blame one individual only.
  3. Prefer answers showing governance and systemic fixes over one-off patches.
  4. For numbers, compute gross loss, subtract only confirmed recoveries, then add fines and costs.

Common mistakes in Resilience, Response and Regulatory Consequences

  • Treating the direct loss as the full cost of the event.

    Loss data tables show only the booked amount, so fines and reputation are forgotten.

    Fix: List all cost layers: direct loss, fines, remediation, legal, reputational. Subtract recoveries last.

  • Netting expected insurance or legal recoveries as if they were certain.

    Students want a clean net figure.

    Fix: Subtract only recoveries stated as received or confirmed. Otherwise show them separately.

  • Choosing public communication or disciplinary action as the first step.

    It feels like the visible, decisive move.

    Fix: Contain, preserve evidence and escalate first. Communication follows legal and regulatory advice.

  • Assuming self-reporting always removes penalties.

    Cooperation credit is confused with immunity.

    Fix: Say that prompt reporting and cooperation can reduce a penalty. It does not guarantee none.

  • Blaming a single rogue employee as the root cause.

    Case stories often name one fraudster.

    Fix: Look for the control, supervision and culture failures that allowed the act. Regulators target those.

  • Confusing resilience with prevention.

    Both appear in the same controls discussion.

    Fix: Prevention lowers the chance of an event. Resilience limits impact and speeds recovery after it occurs.

Worked examples

Example 1

A bank loses USD 40 million to an external payment fraud. It has recovered USD 6 million by freezing funds and expects USD 10 million from insurance, not yet confirmed. It pays a regulatory fine of USD 12 million and spends USD 5 million on remediation and legal costs. Estimate the cost to date using only confirmed recoveries.

Show the solution
  1. Gross loss = USD 40 million.
  2. Confirmed recoveries = USD 6 million. The USD 10 million insurance is unconfirmed, so exclude it.
  3. Net direct loss = 40 − 6 = USD 34 million.
  4. Add fine and remediation: 34 + 12 + 5 = USD 51 million.

Answer: USD 51 million, before any reputational cost and before insurance is confirmed.

Example 2

A bank finds staff ran unauthorised transfers for three years. Compliance had flagged alerts twice but they were closed without review. The regulator will set the penalty. Which factor most increases it, and what should the bank do first on discovery?

Show the solution
  1. Identify aggravating factors: three-year duration, ignored alerts, and weak supervision show systemic failure.
  2. The ignored alerts suggest known control weaknesses were not acted on, which regulators treat severely.
  3. First action: contain by stopping the transfers and securing access, then preserve evidence.
  4. Then escalate to the board and report to the regulator and law enforcement as required, and start root-cause review.

Answer: The most aggravating factor is the long duration combined with ignored alerts, showing systemic control and governance failure. First, contain the activity and preserve evidence, then escalate and report.

Exam tips

  • Questions usually ask for the best first or next step. Learn the response sequence cold.
  • When a case mentions a long-running failure, repeated findings or concealment, expect the higher penalty answer.
  • Watch for options that net unconfirmed recoveries or skip reputational and remediation costs.
  • Distinguish prevention, detection, response and resilience. Match the answer to the stage described.
  • Credit for cooperation and self-reporting reduces penalties but does not remove accountability.

Practice questions from Case Study: Financial Crime and Fraud

Resilience, Response and Regulatory Consequences: frequently asked questions

How should a bank respond to a fraud incident?

Contain it, preserve evidence and escalate to senior management and the board. Report to regulators and law enforcement as required, then pursue recovery and fix root causes. Record the loss accurately in the loss database.

What regulatory penalties can banks face for financial crime failures?

Fines, enforcement orders, mandatory remediation, independent monitors, business restrictions and personal accountability for senior managers. Severity, duration, repetition, concealment and cooperation shape the outcome.

Why is reputational risk from financial crime hard to measure?

Its effects appear as customer loss, higher funding costs and lost business over time, not as a single booked figure. Firms estimate it with scenarios and indicators.

What is operational resilience after a fraud event?

It is the ability to keep critical services running within impact tolerances and recover quickly. It also means learning from the event and strengthening controls.