Skip to content

FRM Part II · FRM Exam Part II

Governance: formula sheet

Full chapter guide

Key formulas

Hierarchy of risk control
Risk capacity ≥ Risk appetite ≥ Risk tolerance ≥ Limits
Capacity is the maximum risk the bank can bear. Appetite is set below it. Limits are set so that breaches are caught before tolerance is exceeded.
Allocation of duties
Board: approves and oversees | Management: implements | Risk function: monitors and challenges | Audit: assures
Use this as a quick sort for any question asking who is responsible for what.
Three lines of defense
1st line: business owns risk | 2nd line: risk and compliance oversee | 3rd line: internal audit assures
The CRO belongs to the second line and needs independence and direct access to the board.
Limit utilisation
Utilisation = Current exposure ÷ Approved limit
A ratio above 100% is a limit breach and must be escalated under policy.
First line
Business units = risk ownership and day-to-day management
Originate, underwrite, monitor borrowers and stay within limits.
Second line
Independent risk management = framework, oversight and effective challenge
Sets policy, proposes limits, validates models, reports. Must be independent of revenue generation.
Third line
Internal audit = independent assurance to the board
Reviews both other lines. Reports to the board or audit committee. Does not own or manage risk.
Single-name limit utilisation
Utilisation = Current exposure ÷ Limit
Above 100% is a breach. Banks often set an early-warning trigger at a lower level, such as a set share of the limit.
Concentration as share of capital
Concentration ratio = Exposure to name, group or sector ÷ Tier 1 capital
Compare with the policy limit. The denominator is whatever capital measure the policy specifies, so read the question.
Excess over limit
Excess = Exposure − Limit (if positive)
A breach needs escalation and approval or a remedy plan. Do not treat it as a routine exception.
Aggregate exposure to a connected group
Group exposure = Σ exposure to each connected borrower
Connected borrowers are treated as one risk where one's problems would likely hurt the others. Add them before testing the limit.
Debt service coverage (common underwriting test)
DSCR = Cash flow available for debt service ÷ (Interest + Scheduled principal)
Below 1 means cash flow does not cover scheduled payments. Minimum levels vary by bank policy.
Accuracy ratio (Gini)
AR = 2 × AUC − 1
Measures discriminatory power. AUC of 0.5 gives AR = 0 (no power); AUC of 1 gives AR = 1 (perfect).
Binomial backtest of a grade PD
Expected defaults = N × PD; standard deviation = √(N × PD × (1 − PD))
Compare observed defaults with this range. It assumes independent defaults, so correlation makes it too strict (too many false alarms).
Calibration vs discrimination
Discrimination = ranking; Calibration = level of PD
A model can rank well yet have PDs that are too low. Check both.
SR 11-7 model risk sources
Model risk = fundamental errors + incorrect or inappropriate use
Validation needs independence, and effective challenge needs competence, influence and incentives.
Risk-adjusted performance (RAROC)
RAROC = (Revenue − Costs − Expected loss) ÷ Economic capital
Used to link pay and performance to risk taken. Pay on raw profit ignores the capital consumed.
Bonus adjustment mechanisms
Deferral + payment in equity or similar instruments + malus + clawback
Malus applies to unpaid (deferred) awards; clawback applies to amounts already paid.
Basel credit risk principle areas
Environment → Granting → Administration and monitoring → Controls → Supervisory role
A way to recall the structure: board and management set the environment, then sound credit granting, ongoing administration, adequate controls.
Lines of defence
1st: business owns risk; 2nd: independent risk and compliance; 3rd: internal audit
Culture failures often show up as a weak or overruled second line.

Quick revision

  • The board approves risk appetite and holds management accountable; it does not run daily credit decisions.
  • Risk appetite sets how much risk the bank is willing to take; limits turn that appetite into usable numbers.
  • First line owns and manages the risk it creates.
  • Second line, independent risk management, sets the framework, monitors and challenges the first line.
  • Third line, internal audit, gives independent assurance to the board on the other two lines.
  • Independence matters: those who approve or validate should not be rewarded purely for volume the business generates.
  • Underwriting standards define who qualifies for credit, on what terms and with what documentation.
  • Limits cover single names, sectors, countries and portfolios, and breaches need defined escalation.
  • Reporting must be timely, accurate and aimed at the right audience, with early warning indicators.
  • Model governance includes development standards, independent validation, ongoing monitoring and documentation.
  • Compensation tied only to short-term volume encourages excessive risk taking.
  • Strong risk culture means open challenge, clear accountability and escalation without fear.

Common mistakes

  • Saying the board approves individual loans. Fix: The board sets appetite and policy and oversees. Management and credit committees approve transactions within delegated authority.
  • Treating risk appetite and limits as the same thing. Fix: Appetite is the board-level amount and type of risk the bank accepts. Limits are the operational tools that keep activity inside it.
  • Saying risk management owns credit risk. Fix: The business unit owns the risk. The second line oversees and challenges it.
  • Putting internal audit in the second line. Fix: Audit is the third line. It gives independent assurance to the board and does not run daily oversight.
  • Treating risk appetite and credit policy as the same thing. Fix: Appetite is how much and what kind of risk the bank will accept. Policy is the rules for lending within it.
  • Testing a single-name limit without adding connected borrowers. Fix: Combine entities that are economically connected, then compare the total with the limit.
  • Confusing discrimination with calibration Fix: Discrimination is how well grades rank risk. Calibration is whether PD levels match realized defaults.
  • Letting developers validate their own model Fix: SR 11-7 expects validation independent of development and use, with ability to challenge.
  • Treating risk culture as a written policy or a training programme. Fix: Look for evidence in behaviour: challenge, escalation, consequences and rewards.
  • Confusing malus and clawback. Fix: Malus cuts unvested or deferred pay. Clawback recovers pay already received.

Exam tips

  • Most questions are role-allocation. Sort the duty by level before reading the options.
  • Watch for options that break independence, such as business heads controlling the risk function. These are usually wrong.
  • Know the difference between risk capacity, appetite, tolerance and limits, as questions test the order.
  • Expect case-style questions about weak governance in a failed bank. Look for missing escalation, poor incentives and an overpowered business line.
  • Use precise words: board oversight, management implementation, independent challenge, independent assurance.
  • Expect scenario questions where one line does another's job. Spot the conflict first.
  • Watch for words like owns, challenges, oversees and assures. They point to the line.
  • Independence is the most tested idea. Check reporting lines and incentives.