Skip to content

FRM Part II · FRM Exam Part II

Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector: formula sheet

Full chapter guide

Key formulas

Systemic channel logic
Shared dependency + many users + limited substitutes → correlated failure
A reasoning rule, not a calculation. Use it to explain why third-party concentration is systemic.
Concentration share
Provider share = (Firms or activity served by provider) ÷ (Total in market) × 100%
A simple way to describe concentration. A high share means high substitution difficulty. It is not an official regulatory ratio.
Operational resilience objective
Impact of disruption ≤ impact tolerance for each important business service
Firms set a tolerance for maximum acceptable disruption and test whether they can stay within it.
Systemic cyber event chain
Shock → Channel → Amplifier → Impact on stability
A framework, not a calculation. Use it to structure any scenario question.
Cyber risk vs operational risk
Cyber risk ⊂ Operational risk
Cyber is a subset. Operational risk also covers fraud, process failure, people and physical events.
Individual vs systemic test
Systemic if impact spreads beyond the firm through shared dependencies, links or confidence
Size of the firm alone does not make an event systemic.
Resilience objective
Recovery time ≤ Impact tolerance
Impact tolerance is the maximum disruption to a critical service you can accept before intolerable harm.
Concentration share (simple measure)
Provider share = Services or workloads on provider ÷ Total services or workloads
A high share for one provider signals firm-level concentration. Use it as an indicator, not a rule with a fixed threshold.
Herfindahl-Hirschman Index (HHI)
HHI = Σ (sᵢ)², where sᵢ is each provider's market share
With shares as fractions, HHI ranges from 1/N to 1. Higher means more concentrated. Four equal providers give 0.25.
Systemic dependency logic
Systemic impact ≈ Number of firms affected × Criticality of service × Difficulty of substitution
A conceptual rule, not a regulatory formula. It explains why critical providers are singled out.
Resilience logic
Critical operations → map dependencies → set tolerance → test severe but plausible scenarios → respond and recover → learn
This sequence is the backbone of Basel, DORA and FSB material. Use it to place any answer option.
Operational risk vs operational resilience
Risk: reduce likelihood and loss. Resilience: limit disruption to critical services and recover within tolerance.
Resilience is outcome focused and service focused, not loss focused.
DORA pillars
ICT risk management; incident reporting; resilience testing; third-party risk; information sharing
Five pillars. Threat-led penetration testing sits under testing.
Tolerance check
Actual recovery time ≤ impact tolerance (maximum tolerable disruption)
A breach means the firm failed its own tolerance, even if no capital loss occurred.
Micro vs macro focus
Microprudential = safety of the individual firm; Macroprudential = stability of the whole system
Digital risk becomes macro when many firms share the same dependency or when stress spreads.
Tool-to-channel matching
Solvency loss → capital buffers; Cash and payment disruption → liquidity buffers and intraday monitoring; Common dependency → concentration and third-party oversight; Unknown scenarios → stress tests and scenario analysis
Use this as a memory rule, not a law. Tools often overlap.
Scenario loss logic
Stressed loss = direct losses + recovery and remediation costs + losses from knock-on effects, compared with available capital and liquidity
This is a framework, not a regulatory formula. The knock-on piece is what makes it systemic.
Net retained loss after insurance
Retained loss = Gross loss − Insurance recovery, where Recovery = min(max(Gross loss − Deductible, 0), Policy limit)
Check sub-limits and exclusions first. Apply deductible, then cap at the limit. The firm bears the deductible plus any excess over the limit.
Insurability test (rule of thumb)
Risk is more insurable when losses are measurable, accidental and not highly correlated across policyholders
Cyber scores poorly on correlation and measurability. This is a guide, not a strict law.
Aggregate exposure check
Insurer aggregate exposure = Σ policy limits for policyholders exposed to the same event
Used to see whether one common event, such as a cloud outage, could exceed insurer capital.

Quick revision

  • Digital resilience means preventing, absorbing, recovering from and adapting to digital disruption.
  • Operational and cyber events become systemic when many firms are hit at once or critical services stop.
  • Concentration risk arises when many firms rely on the same few cloud or ICT providers.
  • A third-party failure can hit all its clients together, so firm-level controls alone do not remove it.
  • Outsourcing a function does not outsource accountability; the firm stays responsible.
  • Resilience frameworks focus on continuing critical services, not only on preventing every incident.
  • Macroprudential tools aim at system-wide risk, unlike microprudential tools that focus on single firms.
  • Capital buffers absorb financial losses but do little to stop an outage; match the tool to the risk.
  • Information sharing helps firms spot common threats faster, but needs trust and legal clarity.
  • Crisis coordination needs agreed roles across authorities and firms, often across borders.
  • Cyber insurance can transfer some loss but faces limits from correlated losses and hard-to-model events.
  • Cyber outages can cause liquidity stress and loss of confidence, linking to other risk types.

Common mistakes

  • Treating a cloud outage as only a firm-level operational risk. Fix: Ask how many institutions use the same provider. If many, the same event is a systemic risk.
  • Assuming using several vendors always removes concentration risk. Fix: Check whether the vendors share the same underlying cloud or subcontractor. Hidden fourth-party links can keep the dependency.
  • Treating cyber risk and operational risk as separate, unrelated categories. Fix: Remember that cyber is a subset of operational risk by cause, though its systemic reach can be larger.
  • Assuming a cyber event is systemic only if a large bank is hit. Fix: Look at shared dependencies. A small provider used by many firms can be a systemic point.
  • Saying outsourcing transfers the risk to the provider. Fix: Remember accountability stays with the firm's board and management. Only the activity is outsourced.
  • Treating concentration as only a firm-level issue. Fix: Also consider the market view: many firms on the same few providers create systemic risk that no single firm can fix.
  • Treating operational resilience as the same as operational risk management. Fix: Remember the difference: risk reduces likelihood and loss; resilience keeps critical services within tolerance when failure occurs.
  • Saying the Basel operational resilience principles set a capital charge. Fix: These are supervisory principles on governance, mapping, testing, third parties and incident management. Operational risk capital is a separate framework.
  • Saying higher capital solves cyber risk. Fix: Say capital absorbs losses but does not prevent attacks or restore services. Pair it with resilience and liquidity tools.
  • Treating cyber risk as purely microprudential. Fix: Look for shared providers, interconnection and contagion. These make it a system-wide issue.

Exam tips

  • Scenario questions usually hinge on one word: shared, common, single or concentrated. Look for it first.
  • Know the difference between firm-level resilience and system-level stability. Options often mix them.
  • For policy questions, choose tools aimed at the dependency itself, such as oversight of critical providers and exit strategies, over generic capital increases.
  • Beware absolute wording. Digitalisation brings both benefits and new risks, and no single measure removes risk.
  • This topic sits in the 2026 Current Issues area on digital resilience, so expect applied reasoning rather than calculations.
  • Expect scenario stems. Write shock, channel, amplifier next to the question before reading options.
  • Watch for absolute words such as always, only or eliminates. They are usually wrong in this topic.
  • Questions often ask which risk types a single cyber event touches. Remember operational, liquidity and sometimes market impacts together.