Managing fraud risk requires a coordinated governance structure that defines clear roles and responsibilities across all operational levels of the enterprise, structured in accordance with the Three Lines Model. [1]
                      ┌─────────────────────────────────────────┐
                      │           BOARD OF DIRECTORS            │
                      │ • Approves Anti-Fraud Policy Framework  │
                      │ • Sets Corporate Risk Appetite Limits   │
                      └────────────────────▲────────────────────┘
                                           │
                                           │ (Oversight Reporting Line)
                                           │
                      ┌────────────────────┴────────────────────┐
                      │       FRAUD RISK MANAGEMENT UNIT        │
                      │ • Designs Analytical Monitoring Scans   │
                      │ • Manages Fraud Risk Registers (FRAM)  │
                      └─────────────────────────────────────────┘

The anti-fraud governance team operates across distinct functional layers: [1]
  • The Board of Directors and Audit Committee: Hold ultimate accountability for the organization’s fraud posture, approving anti-fraud policies, setting the tone at the top, and evaluating the overall effectiveness of the framework.
  • The Fraud Risk Management Unit (Line 2 Oversight): A specialized, independent team led by a designated Fraud Risk Officer. This unit designs the FRAM architecture, manages the central fraud registers, trains staff on behavioral red flags, and coordinates transaction monitoring programs.
  • Business Unit Managers (Line 1 Owners): Responsible for executing approved fraud controls within daily workflows, identifying processing anomalies, and ensuring staff comply with anti-fraud procedures. [1, 2]