FRM Part II · FRM Exam Part II
Sound Management of Risks Related to Money Laundering and Financing of Terrorism
This chapter covers the Basel Committee guidelines on managing money laundering and financing of terrorism (ML/FT) risk. You solve questions by naming the control that fits the case: risk assessment, customer due diligence, monitoring, third-party reliance, correspondent banking rules, wire transfer information, or group-wide sharing. Then you apply it to the facts given.
What this chapter covers
This chapter is about how a bank keeps itself from being used to launder money or move funds for terrorism. The Basel Committee treats ML/FT as a risk that must be managed inside the bank's normal risk framework, not as a separate compliance task. The guidelines tell banks to identify and assess the risk, set policies, apply customer due diligence, monitor activity, and share information across the group.
The five topics build on each other. You start with what ML/FT risk is and what the guidelines expect. Then you study governance and the three lines of defence. After that you move to customer-level controls: acceptance, due diligence and ongoing monitoring. Next come higher-risk channels such as third parties, correspondent banking and wire transfers. Last is group-wide implementation, information sharing and supervision.
This chapter links to the Operational Risk and Resilience topic, because weak controls cause compliance, legal and reputational losses. It also links to credit and liquidity topics, since customer onboarding and correspondent relationships affect the whole bank. Exam questions are usually short cases. You are given a bank, a customer or a transaction, and you pick the most appropriate control or response.
This chapter is mostly conceptual, so it is a good place to secure marks without heavy calculation. Questions test whether you can match a situation to the right control and say who is responsible. The same small set of ideas, risk-based approach, due diligence, escalation and group-wide consistency, appears again and again. If you learn them well, you can answer many questions quickly and save time for numerical topics elsewhere in the 4-hour exam.
Sound Management of Risks Related to Money Laundering and Financing of Terrorism: topics in the order to study them
- 1ML/FT Risk Overview and Basel Committee GuidelinesStart here to learn the vocabulary, the stages of ML/FT and the purpose of the guidelines that frame everything else.
- 2Risk Assessment, Governance and Three Lines of DefenceNext, learn how a bank identifies its risk and who owns it, since every later control rests on this assessment.
- 3Customer Acceptance, Due Diligence and Ongoing MonitoringThis applies the risk-based approach at customer level and is the most testable part, so study it once governance is clear.
- 4Use of Third Parties, Correspondent Banking and Wire TransfersThese are higher-risk channels that extend customer due diligence, so you need the basic customer controls first.
- 5Group-wide Implementation, Information Sharing and SupervisionFinish with how the framework works across a whole banking group and how supervisors oversee it, which ties the earlier topics together.
How to prepare Sound Management of Risks Related to Money Laundering and Financing of Terrorism
Treat this as a concepts chapter. Aim to explain each control in your own words and recognise it in a short case.
- Read the five topics in the given order and write a one-line purpose for each before you go deeper.
- Build a simple map of the risk-based approach: assess risk, set policy, apply controls in proportion to risk, monitor, review.
- Make a table of the three lines of defence for yourself: who owns the risk, who oversees it, who gives independent assurance.
- List the customer due diligence stages and note when enhanced measures apply, such as higher-risk customers or relationships.
- For third parties, correspondent banking and wire transfers, note what the bank must still do itself and what it cannot hand over.
- Practise short case questions. For each, name the risk, name the control, then say why other options fall short.
- Revise the group-wide topic last and link it back to governance and due diligence so you see one connected framework.
Common mistakes in Sound Management of Risks Related to Money Laundering and Financing of Terrorism
Treating ML/FT as only a compliance issue
Fix: Remember it is a bank-wide risk. The board, business lines, risk, compliance and audit all have roles.
Applying the same controls to every customer
Fix: Match the depth of due diligence to the risk. Choose enhanced measures for higher-risk cases and simpler ones for lower risk where permitted.
Thinking outsourcing due diligence transfers responsibility
Fix: State that the bank remains ultimately responsible and must be satisfied the third party's work is adequate.
Mixing up the three lines of defence
Fix: Link each line to one idea: own, oversee, assure independently. Check which line a case describes before answering.
Stopping at onboarding
Fix: Include ongoing monitoring and periodic review of customer information in any complete answer.
Ignoring the group dimension
Fix: Revise how group policies, information sharing and supervision apply across branches and subsidiaries, including in other countries.
Last-day revision: Sound Management of Risks Related to Money Laundering and Financing of Terrorism
- ML/FT risk should be managed inside the bank's overall risk management framework.
- A risk-based approach means controls are stronger where risk is higher.
- The bank must first identify and assess its own ML/FT risks.
- The board and senior management are responsible for the ML/FT risk framework.
- Business units are the first line of defence and own the risk day to day.
- Compliance and risk functions form the second line, and internal audit is the third.
- Customer due diligence covers identification, verification and understanding the customer's activity.
- Higher-risk customers need enhanced due diligence and senior approval.
- Ongoing monitoring checks that transactions fit what the bank knows about the customer.
- When using a third party, the bank stays ultimately responsible for due diligence.
- Correspondent banking is higher risk and needs careful assessment of the respondent bank.
- Wire transfers should carry accurate originator and beneficiary information.
- Group-wide policies should apply consistently, with information shared across the group's entities.
Sound Management of Risks Related to Money Laundering and Financing of Terrorism practice questions
- A bank's internal audit function is reviewing the AML/CFT programme. It finds that the compliance function itself performs the periodic test…
- A bank is preparing its enterprise-wide ML/FT risk assessment. Which approach is most consistent with the Basel Committee guidance?
- An intermediary bank receives a cross-border wire transfer that lacks the required originator information. Which response is most consistent…
- A bank's business line staff argue that they should own customer acceptance decisions without compliance involvement, since they know the cl…
- During ongoing monitoring, a bank notes that a small retail business account, historically showing monthly cash deposits near USD 8,000, sud…
- Under the Basel guidelines, how should supervisors of a cross-border banking group cooperate on ML/FT matters?
- A bank is considering onboarding a foreign politically exposed person (PEP). Which approach best aligns with the Basel guidance?
- A bank's transaction monitoring system flags a long-standing retail customer whose account, usually holding small salary credits, suddenly r…
Sound Management of Risks Related to Money Laundering and Financing of Terrorism in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Sound Management of Risks Related to Money Laundering and Financing of Terrorism: frequently asked questions
Is this chapter calculation-based in FRM Part II?
No. It is conceptual and case-based. You need to recognise the right control or responsibility in a short scenario, so clear understanding matters more than formulas.
How long should I spend on this chapter?
Because it is conceptual, it can usually be learned faster than the numerical topics. Give it a focused block, then revisit it in short sessions near the exam.
Which topic in this chapter is most important?
Customer acceptance, due diligence and ongoing monitoring is the core of the framework and links to every other topic. Know it thoroughly, but do not skip the others.
How does this chapter connect to the rest of FRM Part II?
It connects mainly to Operational Risk and Resilience, since control failures create legal, compliance and reputational losses. It also supports questions on governance and risk culture elsewhere in the paper.