Skip to content

FRM Exam Part II · Case Study: Investor Protection and Compliance Risks in Investment Activities

Investor Protection Framework and Regulatory Objectives

Updated 11 October 2026 · Fact-checked

Investor protection is the set of laws, standards and supervisory actions that keep clients of investment firms from being misled, mis-sold or harmed. Regulators aim for fair, efficient and transparent markets and reduced systemic risk. To solve questions, identify the failure, match it to the objective, then name the control.

Understand Investor Protection Framework and Regulatory Objectives

Investors usually know less than the firms that advise them. The firm knows the product, its costs and its risks. The client does not. This information asymmetry, plus conflicts of interest, is why investor protection rules exist. Without them, clients lose trust and markets shrink.

IOSCO (the International Organization of Securities Commissions) sets the global reference. Its Objectives and Principles of Securities Regulation state three objectives: protecting investors, ensuring that markets are fair, efficient and transparent, and reducing systemic risk. National regulators then turn these into binding rules. Examples are the SEC and FINRA in the US, the FCA in the UK, ESMA and national authorities in the EU, and SEBI in India. Note that IOSCO sets principles; it is not a rule-making authority over firms.

These objectives shape what a firm must do. Typical conduct expectations are: act in the client's best interest, classify clients properly, assess suitability or appropriateness of products, disclose costs, risks and conflicts, handle complaints, keep client assets segregated, keep records, and treat clients fairly. Retail clients get stronger protection than professional or institutional clients.

Compliance risk is the risk of legal or regulatory sanctions, financial loss or reputational damage from failing to comply with laws, rules and standards. Conduct risk is the risk that the firm's behaviour, culture or incentives lead to poor outcomes for clients or markets, such as mis-selling. Conduct risk is about how the firm behaves. Compliance risk is about whether it breaks the rules. They overlap: poor conduct often causes a breach. But conduct can be harmful even when no specific rule is broken, and a technical breach may cause no client harm.

In the three lines of defence, business units own the risk, compliance and risk functions oversee it, and internal audit gives independent assurance. Good governance, fair incentives and a sound risk culture are what make the framework work in practice.

Key formulas to remember

IOSCO regulatory objectives
Protect investors + Fair, efficient, transparent markets + Reduce systemic risk
Three objectives. Learn all three; exam options often swap in a wrong one such as maximising firm profit.
Compliance risk
Risk of sanctions, loss or reputational damage from non-compliance with laws, rules and standards
Rule-focused. Test is: was a rule or standard breached?
Conduct risk
Risk of poor client or market outcomes from firm behaviour, culture or incentives
Outcome-focused. Can exist without a specific rule breach.
Suitability principle
Recommendation must fit the client's objectives, risk tolerance, knowledge and financial situation
Requires know-your-client information before advice.

How to solve Investor Protection Framework and Regulatory Objectives questions

Use this sequence for any case question on investor protection, conduct or compliance.

  1. 1Read the facts and identify who is harmed and how (client, market or the firm itself).
  2. 2Decide whether the problem is about rules broken (compliance), poor outcomes or behaviour (conduct), or both.
  3. 3Match the failure to a regulatory objective: investor protection, market fairness and transparency, or systemic risk.
  4. 4Identify the conduct expectation breached, such as suitability, disclosure, conflicts management, best interest or client asset segregation.
  5. 5Check the client type. Retail clients need more protection than professional ones.
  6. 6Name the control or governance fix: KYC, product governance, surveillance, incentive redesign, escalation, or line-of-defence roles.
  7. 7Pick the option that is precise and matches the exact definition. Reject options that overstate or mix concepts.

Quickest way: Three-question filter

When to use it: When you have about 90 seconds per question and the options look similar.

  1. Ask: was a specific rule broken? If yes, lean to compliance risk.
  2. Ask: did the client get a bad outcome because of behaviour or incentives? If yes, lean to conduct risk.
  3. Ask: which of the three IOSCO objectives does the answer serve? Eliminate options outside them.
  4. Prefer the option naming a concrete control over a vague statement.

Common mistakes in Investor Protection Framework and Regulatory Objectives

  • Treating conduct risk and compliance risk as identical.

    They overlap and both appear in the same case studies.

    Fix: Compliance is about breaching rules. Conduct is about harmful behaviour and outcomes. Decide which the question emphasises.

  • Listing the wrong IOSCO objectives, such as profit maximisation or price stability.

    Candidates mix IOSCO with central bank mandates.

    Fix: Remember the trio: investor protection, fair, efficient and transparent markets, and reduced systemic risk.

  • Saying IOSCO issues binding rules on firms.

    Its principles are widely cited as if they were law.

    Fix: IOSCO sets international standards. National regulators make and enforce the binding rules.

  • Applying the same protection level to every client.

    Candidates overlook client classification.

    Fix: Retail clients get the strongest protection. Professional and eligible counterparties get less.

  • Thinking disclosure alone satisfies suitability.

    Disclosure feels like full transparency.

    Fix: Suitability needs the firm to assess the client and recommend a fitting product. Disclosure supports it but does not replace it.

  • Assuming no rule breach means no risk.

    Compliance is seen as a tick-box exercise.

    Fix: Aggressive incentives can create mis-selling without any technical breach. That is conduct risk.

Worked examples

Example 1

An investment firm pays advisers bonuses based only on sales of a high-fee structured note. Many conservative retail clients buy it. No written rule has been breached so far. Which risk is most clearly present, and why?
A. Market risk
B. Conduct risk
C. Liquidity risk
D. Systemic risk

Show the solution
  1. Identify the facts: incentives reward sales, clients are conservative retail investors, and no rule is broken yet.
  2. Harm to clients arises from behaviour and incentives, not from a breach.
  3. That points to conduct risk, since conduct risk can exist without a rule breach.
  4. Market and liquidity risk concern asset values and funding, not the selling behaviour. Systemic risk is too broad for one firm's sales practice.

Answer: B. Conduct risk.

Example 2

A regulator fines a broker for failing to segregate client assets from its own funds, as a rule required. Which statement best describes the issue and the objective served by the rule?
A. Conduct risk only; the objective is market efficiency
B. Model risk; the objective is capital adequacy
C. Compliance risk; the objective is investor protection
D. Funding risk; the objective is reduced systemic risk

Show the solution
  1. A specific rule was breached and a sanction followed, so this is compliance risk.
  2. Segregation protects clients if the firm fails, so the objective is investor protection.
  3. Option A calls it conduct only and cites market efficiency, which does not fit.
  4. Options B and D name risks and objectives unrelated to the facts.

Answer: C. Compliance risk; the objective is investor protection.

Exam tips

  • Expect case-style questions that ask you to classify the failure, then pick the control or objective.
  • Memorise the three IOSCO objectives word for word; distractors often swap one.
  • When both conduct and compliance seem right, choose the one that matches whether a rule was broken or an outcome was harmful.
  • Watch for absolute words like always or only. Protection levels depend on client type.
  • Link answers to governance: three lines of defence, incentives and risk culture.

Practice questions from Case Study: Investor Protection and Compliance Risks in Investment Activities

Investor Protection Framework and Regulatory Objectives in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Investor Protection Framework and Regulatory Objectives: frequently asked questions

What is the investor protection framework?

It is the combination of laws, regulator rules, international standards and firm controls that protect clients of investment firms. It covers areas such as suitability, disclosure, conflicts of interest, client asset safety and complaints handling.

What are the IOSCO regulatory objectives?

IOSCO states three: protecting investors, ensuring fair, efficient and transparent markets, and reducing systemic risk. National regulators apply them through their own binding rules.

What is the difference between conduct risk and compliance risk?

Compliance risk is the risk of sanctions or loss from breaking laws, rules or standards. Conduct risk is the risk of poor client or market outcomes from firm behaviour, culture or incentives. They overlap but are not the same.

Why do retail clients get more protection than professionals?

Retail clients usually have less knowledge and less ability to absorb losses. Regulators therefore require stricter suitability, disclosure and complaint rules for them.