Skip to content

FRM Exam Part II · Sound Management of Risks Related to Money Laundering and Financing of Terrorism

Three Lines of Defence and ML/FT Risk Assessment

Updated 11 October 2026 · Fact-checked

Under the Basel Committee's ML/FT guidelines, the board and senior management own ML/FT risk. Business units are the first line, the compliance function and chief AML officer the second, and internal audit the third. The bank first assesses its inherent risks, then sets policies and controls that match them.

Understand Risk Assessment, Governance and Three Lines of Defence

Money laundering and financing of terrorism (ML/FT) risk is the risk that a bank is used to hide criminal proceeds or fund terrorism. It leads to legal, reputational, operational and concentration risk. The Basel Committee treats it as a risk to be managed within the bank's overall risk framework, not a side task for one department.

The starting point is governance. The board approves the ML/FT risk strategy and policies and makes sure they are carried out. Senior management implements them, sets up a clear structure and gives staff the resources to do the work. Senior management also ensures that one senior person is the point of contact for the supervisor and the financial intelligence unit. Accountability sits at the top. It cannot be handed down to junior staff.

The three lines of defence split the work. The first line is the business units, such as front office and customer-facing teams. They know the customer, so they identify and assess ML/FT risk and carry out the policies and controls day to day. The second line is the chief AML officer and the compliance function. They set the standards, advise, monitor, and report to senior management and the board. The third line is internal audit. It independently tests whether the framework and the controls work, and it reports to the board or its audit committee. It must not be the one running the controls it tests.

Risk assessment comes before controls. The bank looks at inherent risk across customers, products and services, delivery channels and geographies. It then judges how strong its controls are. What remains is the residual risk. The assessment should be done at enterprise level, documented, kept up to date, and used to decide how much due diligence and monitoring each area needs. This is the risk-based approach: more effort where risk is higher, simplified measures where it is lower.

The assessment is not one-off. New products, new markets, new technology or a change in the customer base should trigger a review. Group-wide, the same standards apply to branches and subsidiaries, and the group's policies must be consistent even when local rules differ.

Key formulas to remember

Residual risk logic
Residual risk = Inherent risk − Effect of controls
A conceptual relationship, not a numerical formula. Risk is assessed before controls, then after controls.
Inherent risk categories
Customers + Products/services + Delivery channels + Geographies
The four standard lenses for an enterprise-wide ML/FT assessment.
Three lines of defence
1st: business units | 2nd: compliance / chief AML officer | 3rd: internal audit
First line owns and manages the risk, second oversees and advises, third gives independent assurance.
Board and senior management split
Board: approve and oversee | Senior management: implement and resource
Board does not run daily controls. It sets direction and checks it is followed.

How to solve Risk Assessment, Governance and Three Lines of Defence questions

Most questions give a short scenario and ask who is responsible, what is missing, or what the next step is. Use this routine.

  1. 1Identify the activity in the question: setting policy, running controls, monitoring, testing or assessing risk.
  2. 2Map the activity to a level: board, senior management, first, second or third line.
  3. 3Check independence: the party who tests a control should not be the one who performs it.
  4. 4If the question is about risk assessment, decide whether it is about inherent risk, controls or residual risk.
  5. 5Apply the risk-based approach: higher risk needs stronger measures, lower risk allows simplified ones.
  6. 6Look for triggers for review, such as a new product, market or customer type.
  7. 7Eliminate options that put accountability on junior staff or merge roles that need to be separate.
  8. 8Choose the option that matches the Basel guideline wording most precisely.

Quickest way: Who does what in 20 seconds

When to use it: Use for role-allocation questions where the options are all plausible-sounding duties.

  1. Ask: does it act on customers daily? That is the first line.
  2. Ask: does it set standards, advise or monitor the first line? That is the second line.
  3. Ask: does it test independently and report to the board? That is the third line.
  4. Ask: does it approve strategy or oversee? That is the board. Does it implement and resource? Senior management.
  5. Reject any option where the same unit performs and independently tests the same control.

Common mistakes in Risk Assessment, Governance and Three Lines of Defence

  • Treating the compliance officer as the owner of ML/FT risk.

    The title sounds like it carries all responsibility.

    Fix: The first line owns and manages the risk. Compliance is second line and oversees, advises and monitors. Ultimate accountability stays with the board and senior management.

  • Placing internal audit in day-to-day controls such as customer screening.

    Audit is seen as part of compliance work.

    Fix: Internal audit is the third line. It independently assesses the framework and controls and does not operate them.

  • Saying the board runs the AML programme.

    Students confuse oversight with execution.

    Fix: The board approves and oversees. Senior management implements the policies and provides resources.

  • Assessing risk only after controls are in place.

    Students jump to residual risk.

    Fix: Assess inherent risk first across customers, products, channels and geographies. Then judge controls and arrive at residual risk.

  • Treating the risk assessment as a one-time exercise.

    It looks like a document to complete.

    Fix: It must be documented and updated, especially when products, markets, technology or customer profiles change.

  • Applying identical due diligence to every customer.

    Uniform rules feel safer.

    Fix: The risk-based approach calls for enhanced measures for higher-risk cases and allows simplified measures for lower-risk ones.

Worked examples

Example 1

A bank's internal audit head is asked to approve each high-risk onboarding decision to speed up reviews. Which statement is best?
A. This is acceptable because audit knows the controls best.
B. This weakens the independence of the third line.
C. This moves responsibility to the board.
D. This is a second-line duty that audit may take over permanently.

Show the solution
  1. Approving onboarding is an operational control decision, which belongs to the first line, with second-line oversight.
  2. Internal audit is the third line and must independently test those controls.
  3. If audit approves decisions, it would later be testing its own work, so independence is lost.
  4. Option A ignores independence. Option C is wrong because the board does not approve cases. Option D wrongly makes audit a permanent second line.

Answer: B. It weakens the independence of the third line.

Example 2

A bank plans to launch a digital private banking product for non-resident customers in several new countries. What should the ML/FT risk team do first?
A. Wait for the next annual audit to identify issues.
B. Apply the existing customer due diligence unchanged.
C. Update the enterprise-wide risk assessment for the new customers, product, channel and geographies before launch.
D. Delegate the decision to branch staff.

Show the solution
  1. The product changes all four risk lenses: customer type, product, delivery channel and geography.
  2. A new product or market is a trigger to review the assessment.
  3. Inherent risk should be assessed first, then existing controls tested against it, giving residual risk.
  4. Controls and monitoring are then set in proportion to that risk. This is done before launch, not after an audit.
  5. Options A, B and D skip the assessment or move it to an unsuitable party.

Answer: C. Update the enterprise-wide risk assessment before launch.

Exam tips

  • Memorise the three lines and one verb for each: own and manage, oversee and advise, independently assure.
  • Watch for independence traps, where one unit both performs and tests a control.
  • Questions often hinge on the board versus senior management: approve and oversee versus implement and resource.
  • For risk assessment, remember the order: inherent risk, controls, residual risk.
  • Prefer answers that mention risk-based, documented and regularly updated assessments.

Practice questions from Sound Management of Risks Related to Money Laundering and Financing of Terrorism

Risk Assessment, Governance and Three Lines of Defence in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Risk Assessment, Governance and Three Lines of Defence: frequently asked questions

What are the three lines of defence in AML?

The first line is the business units that manage ML/FT risk day to day. The second line is the compliance function and chief AML officer, who set standards and monitor. The third line is internal audit, which gives independent assurance.

What does the board do in ML/FT risk management under Basel guidance?

The board approves the ML/FT risk strategy and policies and oversees that they are implemented. It is ultimately accountable, while senior management carries out the policies and provides resources.

How is an ML/FT enterprise-wide risk assessment done?

The bank identifies inherent risks across customers, products and services, delivery channels and geographies. It then evaluates its controls to reach residual risk. The assessment is documented and updated when circumstances change.

What does an AML compliance officer do at a bank?

The compliance officer is part of the second line. The role covers setting and maintaining AML policies, advising the business, monitoring controls, handling reporting to authorities and informing senior management and the board.