FRM Part II · FRM Exam Part II
Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector: formula sheet
Key formulas
- Systemic channel logic
- Shared dependency + many users + limited substitutes → correlated failure
- A reasoning rule, not a calculation. Use it to explain why third-party concentration is systemic.
- Concentration share
- Provider share = (Firms or activity served by provider) ÷ (Total in market) × 100%
- A simple way to describe concentration. A high share means high substitution difficulty. It is not an official regulatory ratio.
- Operational resilience objective
- Impact of disruption ≤ impact tolerance for each important business service
- Firms set a tolerance for maximum acceptable disruption and test whether they can stay within it.
- Systemic cyber event chain
- Shock → Channel → Amplifier → Impact on stability
- A framework, not a calculation. Use it to structure any scenario question.
- Cyber risk vs operational risk
- Cyber risk ⊂ Operational risk
- Cyber is a subset. Operational risk also covers fraud, process failure, people and physical events.
- Individual vs systemic test
- Systemic if impact spreads beyond the firm through shared dependencies, links or confidence
- Size of the firm alone does not make an event systemic.
- Resilience objective
- Recovery time ≤ Impact tolerance
- Impact tolerance is the maximum disruption to a critical service you can accept before intolerable harm.
- Concentration share (simple measure)
- Provider share = Services or workloads on provider ÷ Total services or workloads
- A high share for one provider signals firm-level concentration. Use it as an indicator, not a rule with a fixed threshold.
- Herfindahl-Hirschman Index (HHI)
- HHI = Σ (sᵢ)², where sᵢ is each provider's market share
- With shares as fractions, HHI ranges from 1/N to 1. Higher means more concentrated. Four equal providers give 0.25.
- Systemic dependency logic
- Systemic impact ≈ Number of firms affected × Criticality of service × Difficulty of substitution
- A conceptual rule, not a regulatory formula. It explains why critical providers are singled out.
- Resilience logic
- Critical operations → map dependencies → set tolerance → test severe but plausible scenarios → respond and recover → learn
- This sequence is the backbone of Basel, DORA and FSB material. Use it to place any answer option.
- Operational risk vs operational resilience
- Risk: reduce likelihood and loss. Resilience: limit disruption to critical services and recover within tolerance.
- Resilience is outcome focused and service focused, not loss focused.
- DORA pillars
- ICT risk management; incident reporting; resilience testing; third-party risk; information sharing
- Five pillars. Threat-led penetration testing sits under testing.
- Tolerance check
- Actual recovery time ≤ impact tolerance (maximum tolerable disruption)
- A breach means the firm failed its own tolerance, even if no capital loss occurred.
- Micro vs macro focus
- Microprudential = safety of the individual firm; Macroprudential = stability of the whole system
- Digital risk becomes macro when many firms share the same dependency or when stress spreads.
- Tool-to-channel matching
- Solvency loss → capital buffers; Cash and payment disruption → liquidity buffers and intraday monitoring; Common dependency → concentration and third-party oversight; Unknown scenarios → stress tests and scenario analysis
- Use this as a memory rule, not a law. Tools often overlap.
- Scenario loss logic
- Stressed loss = direct losses + recovery and remediation costs + losses from knock-on effects, compared with available capital and liquidity
- This is a framework, not a regulatory formula. The knock-on piece is what makes it systemic.
- Net retained loss after insurance
- Retained loss = Gross loss − Insurance recovery, where Recovery = min(max(Gross loss − Deductible, 0), Policy limit)
- Check sub-limits and exclusions first. Apply deductible, then cap at the limit. The firm bears the deductible plus any excess over the limit.
- Insurability test (rule of thumb)
- Risk is more insurable when losses are measurable, accidental and not highly correlated across policyholders
- Cyber scores poorly on correlation and measurability. This is a guide, not a strict law.
- Aggregate exposure check
- Insurer aggregate exposure = Σ policy limits for policyholders exposed to the same event
- Used to see whether one common event, such as a cloud outage, could exceed insurer capital.
Quick revision
- Digital resilience means preventing, absorbing, recovering from and adapting to digital disruption.
- Operational and cyber events become systemic when many firms are hit at once or critical services stop.
- Concentration risk arises when many firms rely on the same few cloud or ICT providers.
- A third-party failure can hit all its clients together, so firm-level controls alone do not remove it.
- Outsourcing a function does not outsource accountability; the firm stays responsible.
- Resilience frameworks focus on continuing critical services, not only on preventing every incident.
- Macroprudential tools aim at system-wide risk, unlike microprudential tools that focus on single firms.
- Capital buffers absorb financial losses but do little to stop an outage; match the tool to the risk.
- Information sharing helps firms spot common threats faster, but needs trust and legal clarity.
- Crisis coordination needs agreed roles across authorities and firms, often across borders.
- Cyber insurance can transfer some loss but faces limits from correlated losses and hard-to-model events.
- Cyber outages can cause liquidity stress and loss of confidence, linking to other risk types.
Common mistakes
- Treating a cloud outage as only a firm-level operational risk. Fix: Ask how many institutions use the same provider. If many, the same event is a systemic risk.
- Assuming using several vendors always removes concentration risk. Fix: Check whether the vendors share the same underlying cloud or subcontractor. Hidden fourth-party links can keep the dependency.
- Treating cyber risk and operational risk as separate, unrelated categories. Fix: Remember that cyber is a subset of operational risk by cause, though its systemic reach can be larger.
- Assuming a cyber event is systemic only if a large bank is hit. Fix: Look at shared dependencies. A small provider used by many firms can be a systemic point.
- Saying outsourcing transfers the risk to the provider. Fix: Remember accountability stays with the firm's board and management. Only the activity is outsourced.
- Treating concentration as only a firm-level issue. Fix: Also consider the market view: many firms on the same few providers create systemic risk that no single firm can fix.
- Treating operational resilience as the same as operational risk management. Fix: Remember the difference: risk reduces likelihood and loss; resilience keeps critical services within tolerance when failure occurs.
- Saying the Basel operational resilience principles set a capital charge. Fix: These are supervisory principles on governance, mapping, testing, third parties and incident management. Operational risk capital is a separate framework.
- Saying higher capital solves cyber risk. Fix: Say capital absorbs losses but does not prevent attacks or restore services. Pair it with resilience and liquidity tools.
- Treating cyber risk as purely microprudential. Fix: Look for shared providers, interconnection and contagion. These make it a system-wide issue.
Exam tips
- Scenario questions usually hinge on one word: shared, common, single or concentrated. Look for it first.
- Know the difference between firm-level resilience and system-level stability. Options often mix them.
- For policy questions, choose tools aimed at the dependency itself, such as oversight of critical providers and exit strategies, over generic capital increases.
- Beware absolute wording. Digitalisation brings both benefits and new risks, and no single measure removes risk.
- This topic sits in the 2026 Current Issues area on digital resilience, so expect applied reasoning rather than calculations.
- Expect scenario stems. Write shock, channel, amplifier next to the question before reading options.
- Watch for absolute words such as always, only or eliminates. They are usually wrong in this topic.
- Questions often ask which risk types a single cyber event touches. Remember operational, liquidity and sometimes market impacts together.