Skip to content

FRM Part II · FRM Exam Part II · Case Study: Financial Crime and Fraud

A bank's fraud-risk committee evaluates several controls for a card-not-present fraud problem. Which combination best reflects a layered, defence-in-depth approach that includes preventive, detective and responsive elements?

The first combination is best: two-factor authentication prevents fraud, real-time anomaly scoring detects it, and a rapid card-blocking and notification process responds to it. This covers preventive, detective and responsive layers, whereas the other sets cluster in one control type or act too slowly.

  1. ATwo-factor authentication at checkout, real-time behavioural anomaly scoring, and a documented process for rapid card blocking and customer notificationCorrect
  2. BTwo-factor authentication at checkout, a stronger password policy, and mandatory password rotation every 30 days
  3. CQuarterly internal audit sampling, annual staff fraud-awareness training, and an annual policy review
  4. DBehavioural anomaly scoring, post-month-end reconciliation, and quarterly management reports on fraud losses

Explanation

Authentication is preventive, behavioural scoring is detective and real time, and the blocking and notification process is a responsive control. The second set is all preventive and relies on authentication. The third is largely periodic and slow, and the fourth is detective and reporting with no preventive or rapid response element.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Financial Crime and Fraud shows your real accuracy, how long you take and where you lose marks.

More Case Study: Financial Crime and Fraud questions