FRM Part II · FRM Exam Part II
Risk Identification: formula sheet
Key formulas
- Basel definition of operational risk
- Operational risk = loss from inadequate or failed processes, people, systems, or external events
- Includes legal risk. Excludes strategic and reputational risk.
- Seven Basel level 1 event types
- Internal fraud | External fraud | Employment practices and workplace safety | Clients, products and business practices | Damage to physical assets | Business disruption and system failures | Execution, delivery and process management
- Classify by the root cause of the event, not by where the loss appears.
- Taxonomy purpose
- Common taxonomy → consistent tagging → aggregation across business lines
- Consistency is the point. Overlapping or vague categories weaken the data.
- Risk appetite link
- Board appetite → limits and tolerances → indicators and escalation
- Appetite is set by the board and cascaded down. It is not set by the first line alone.
- Residual risk (conceptual)
- Residual risk = Inherent risk after the effect of controls
- A qualitative relationship, not a precise calculation. Better controls lower residual risk. Inherent risk itself does not change.
- Risk score (common scoring convention)
- Risk score = Likelihood score × Impact score
- One common convention. Some firms use matrices or add instead. Use the method the question gives.
- Control effectiveness
- Overall control effectiveness = judgement of design effectiveness and operating effectiveness together
- A control must be both well designed and working in practice to be rated effective.
- Control reduction (illustrative)
- Residual score = Inherent score × (1 − control effectiveness %)
- Illustrative only. Many firms apply this style of adjustment but it is not a prescribed Basel formula.
- Expected annual loss from a scenario
- Expected annual loss = frequency per year × average severity per event
- Use it to compare scenarios. Frequency is the expected number of events per year, not a probability, when events can repeat.
- Frequency from a return period
- Annual frequency ≈ 1 ÷ return period in years
- A 1-in-20-year event has frequency about 0.05. Approximate for rare events.
- Scenario process order
- Preparation → Workshop → Quantification → Validation and challenge → Use and review
- Know the sequence and what each stage controls.
- Net loss
- Net loss = Gross loss − Recoveries
- Record both. Gross loss is the amount before any recovery, including insurance. Recoveries are tracked separately.
- Traffic-light KRI rule
- Green: value within appetite | Amber: value ≥ early-warning threshold | Red: value ≥ limit
- For metrics where higher is worse. Reverse the inequalities when lower is worse, for example the percentage of controls tested on time.
- KRI versus KPI test
- KPI: performance against a goal | KRI: exposure to risk of missing it or losing
- Classify by purpose, not by the metric name.
- Leading versus lagging
- Leading = predicts future risk | Lagging = reports past outcomes
- Loss counts are lagging. Staff vacancies or backlog sizes are usually leading.
- Rate-based KRI
- KRI rate = number of exceptions ÷ total volume
- Use rates rather than raw counts when volumes change, so trends are comparable.
- Critical operation mapping chain
- Critical operation → processes → resources (people, technology, data, facilities, third parties) → dependencies and single points of failure
- Map end to end, then test against the impact tolerance. A map that stops at the firm's boundary misses third-party risk.
- Impact tolerance
- Maximum tolerable disruption to a critical operation, set before testing
- It is set by the harm to customers and to the firm or market, not by how fast IT thinks it can recover.
- New product review trigger
- New or materially changed product, process, system, market or outsourcing → pre-launch review and sign-off by control functions
- Be ready to say which functions review and why. A post-implementation review follows.
- Third-party criticality ranking
- Criticality = importance of the service supplied + difficulty of substitution + data or access held
- This is a qualitative ranking, not a numeric formula. It decides the depth of due diligence and monitoring.
- Emerging risk register fields
- Description, driver, possible impact, time horizon, owner, trigger indicators, review date
- Emerging risks are tracked through indicators, as they often cannot be quantified yet.
Quick revision
- Risk identification comes before measurement: you cannot assess a risk you have not found.
- A common taxonomy gives consistent language so risks can be compared and aggregated across the firm.
- RCSA relies on staff judgement about risks and controls, so it is exposed to bias and optimism.
- RCSA looks at inherent risk, control effectiveness and residual risk.
- Scenario analysis explores severe but plausible events, including ones that have not happened to the firm.
- Stress testing applies extreme conditions to see the effect on the firm.
- KRIs are forward-looking metrics with thresholds that trigger escalation when breached.
- A good KRI is measurable, predictive and tied to a specific risk or control.
- Loss event data is backward looking and has few observations for rare, severe events.
- External loss data helps cover events the firm has not yet experienced.
- Process mapping shows where steps, handoffs and dependencies create risk or control gaps.
- Change and new products bring new risks, so review them before launch and after.
Common mistakes
- Treating reputational risk as part of Basel operational risk. Fix: Remember the definition excludes strategic and reputational risk. Only the direct loss counts.
- Excluding legal risk from the definition. Fix: The Basel definition includes legal risk, such as fines and settlements.
- Rating inherent risk after considering controls Fix: Rate inherent risk first as if no controls existed. Only then apply controls to reach residual risk.
- Treating a control as effective because it exists Fix: Always test both design and operating effectiveness. A control that is not performed gives little risk reduction.
- Confusing anchoring with availability. Fix: Anchoring is fixation on a reference number. Availability is overestimating what is easy to recall, like a recent or dramatic event.
- Treating scenario analysis as the same as historical loss data analysis. Fix: Scenarios are forward-looking and expert-based. Loss data is backward-looking. Scenarios cover events not yet seen.
- Treating KRIs and KPIs as the same thing Fix: Ask what the metric tells you. Goal achievement is a KPI. Exposure to failure or loss is a KRI.
- Calling loss data a leading indicator Fix: Loss data is lagging because it records past events. It informs models and trends, but it does not warn in real time.
- Treating a process map as a control test. Fix: A map identifies steps, hand-offs and dependencies. Controls are then assessed on the map, for example through RCSA or testing.
- Stopping the dependency map at the firm's own systems. Fix: Include vendors, their subcontractors (fourth parties) and shared infrastructure. Check for concentration.
Exam tips
- Classify by root cause. Many options are tempting because of where the loss is booked.
- Memorise the include and exclude list: legal included, strategic and reputational excluded.
- Separate intentional from accidental. It decides between fraud and execution errors.
- When a question mentions risk appetite, think board approval, then limits, tolerances and indicators.
- Expect scenarios with two overlapping causes. Pick the primary cause named in the question.
- Read whether the question asks for inherent or residual risk before doing anything else.
- Expect cases where a control exists but is not working. The answer is usually a higher residual risk.
- For limitations questions, name subjectivity, bias, inconsistent scales and lack of independent challenge.