Skip to content

FRM Part II · FRM Exam Part II · Case Study: Financial Crime and Fraud

A regional bank's internal audit team finds that one employee in the payments department can create a new vendor record, approve invoices for that vendor, and release the payment. Which control weakness does this most directly represent, and which fix addresses it?

This is a segregation of duties failure, because one employee can create a vendor, approve invoices and release payment. The right fix is to divide these functions among different people so that no single person can complete a fraudulent payment alone.

  1. ALack of segregation of duties; separate the creation, approval and release functions among different peopleCorrect
  2. BWeak tone at the top; issue a revised code of conduct
  3. CInadequate data backup; increase backup frequency
  4. DPoor detective monitoring; add a quarterly review of the vendor list

Explanation

One person controlling initiation, authorization and payment is the classic segregation of duties failure, which allows fabricated vendors to be paid without any second check. Splitting the functions is the preventive fix. A quarterly review is detective and after the fact, so it does not remove the structural weakness.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Financial Crime and Fraud shows your real accuracy, how long you take and where you lose marks.

More Case Study: Financial Crime and Fraud questions