FRM Part II · FRM Exam Part II · Sound Management of Risks Related to Money Laundering and Financing of Terrorism
A bank's internal audit reviews AML controls and finds that the second-line compliance function approved a new high-risk correspondent product, then also performed the quality assurance testing of the screening controls for that same product. The business head argues this is efficient. Which assessment is most appropriate under the three lines of defence model?
Compliance's approving the product and then testing its controls undermines objectivity. Testing should be performed by someone independent of the approval, while internal audit provides separate assurance over the whole AML framework. Moving approval to internal audit or relying on business sign-off would worsen independence.
- ACompliance's dual role weakens independence; testing should be done by a party independent of the approval, with internal audit separately assessing the whole frameworkCorrect
- BAcceptable, since compliance as the second line is expected to own both approval and all control testing
- CAcceptable, provided the business head signs off on the testing results
- DInternal audit should take over the approval of new products to restore independence
Explanation
Approving a product and then testing its controls puts the same function in the position of marking its own work, which weakens the objectivity of the second line. Testing should be separated, and internal audit, as the third line, provides independent assurance over the framework. Business head sign-off would reintroduce first-line influence, and audit approving products would compromise its independence.
Did you get it right without looking?
One question tells you little. A timed set on Sound Management of Risks Related to Money Laundering and Financing of Terrorism shows your real accuracy, how long you take and where you lose marks.
More Sound Management of Risks Related to Money Laundering and Financing of Terrorism questions
- A bank's AML policy allows it to rely on an introducer to perform customer due diligence (CDD) on new clients. Under the Basel Committee gui…
- A bank performs an enterprise-wide ML/FT risk assessment. It first identifies inherent risk across customers, products, geographies and deli…
- The chief AML officer of a bank reports only to the head of a major revenue-generating business line, and the compliance budget is set by th…
- Which describes the expected role of group-level AML/CFT compliance with respect to information sharing across a banking group's branches an…
- An intermediary bank receives a cross-border wire transfer that lacks the required originator information. Which response is most consistent…
- Under the Basel Committee's guidelines on sound management of ML/FT risks, which statement best describes the role of the board of directors…