Skip to content

FRM Part II · FRM Exam Part II · Sound Management of Risks Related to Money Laundering and Financing of Terrorism

A bank's internal audit reviews AML controls and finds that the second-line compliance function approved a new high-risk correspondent product, then also performed the quality assurance testing of the screening controls for that same product. The business head argues this is efficient. Which assessment is most appropriate under the three lines of defence model?

Compliance's approving the product and then testing its controls undermines objectivity. Testing should be performed by someone independent of the approval, while internal audit provides separate assurance over the whole AML framework. Moving approval to internal audit or relying on business sign-off would worsen independence.

  1. ACompliance's dual role weakens independence; testing should be done by a party independent of the approval, with internal audit separately assessing the whole frameworkCorrect
  2. BAcceptable, since compliance as the second line is expected to own both approval and all control testing
  3. CAcceptable, provided the business head signs off on the testing results
  4. DInternal audit should take over the approval of new products to restore independence

Explanation

Approving a product and then testing its controls puts the same function in the position of marking its own work, which weakens the objectivity of the second line. Testing should be separated, and internal audit, as the third line, provides independent assurance over the framework. Business head sign-off would reintroduce first-line influence, and audit approving products would compromise its independence.

Did you get it right without looking?

One question tells you little. A timed set on Sound Management of Risks Related to Money Laundering and Financing of Terrorism shows your real accuracy, how long you take and where you lose marks.

More Sound Management of Risks Related to Money Laundering and Financing of Terrorism questions