A Fraud Risk Assessment Matrix (FRAM) is a structured register used to map, evaluate, and prioritize an organization’s specific fraud exposures. Unlike a standard operational risk register, a FRAM assumes the presence of an active, intelligent adversary who is intentionally attempting to circumvent existing controls and conceal their illicit activities. [1]
Inherent Fraud Score = Inherent Probability Rating * Inherent Impact Valuation

Residual Fraud Exposure = Inherent Fraud Score * ( 1 - Control Mitigation Factor )

The FRAM documents fraud risks by breaking them down into specific technical components:

Fraud Scheme Reference Detailed Scenario Description Key Preventative Control Design Assessment Residual Exposure
FR-Procure-01 An inventory clerk sets up a fake vendor profile and approves unauthorized payments to their personal bank account. Automated configuration locks on the vendor master database, requiring independent dual-authorization. Pass: The control design prevents unauthorized database modifications. Low: System configurations mitigate the inherent risk.
FR-Treasury-04 A treasury manager executes an unauthorized international wire transfer by overriding transaction verification rules. A manual review of transaction logs performed monthly by an executive committee. Fail: The detective control operates after the funds have left the organization. High: The control design does not prevent asset flight.

Â