Skip to content

FRM Part II · FRM Exam Part II

Risk Identification: formula sheet

Full chapter guide

Key formulas

Basel definition of operational risk
Operational risk = loss from inadequate or failed processes, people, systems, or external events
Includes legal risk. Excludes strategic and reputational risk.
Seven Basel level 1 event types
Internal fraud | External fraud | Employment practices and workplace safety | Clients, products and business practices | Damage to physical assets | Business disruption and system failures | Execution, delivery and process management
Classify by the root cause of the event, not by where the loss appears.
Taxonomy purpose
Common taxonomy → consistent tagging → aggregation across business lines
Consistency is the point. Overlapping or vague categories weaken the data.
Risk appetite link
Board appetite → limits and tolerances → indicators and escalation
Appetite is set by the board and cascaded down. It is not set by the first line alone.
Residual risk (conceptual)
Residual risk = Inherent risk after the effect of controls
A qualitative relationship, not a precise calculation. Better controls lower residual risk. Inherent risk itself does not change.
Risk score (common scoring convention)
Risk score = Likelihood score × Impact score
One common convention. Some firms use matrices or add instead. Use the method the question gives.
Control effectiveness
Overall control effectiveness = judgement of design effectiveness and operating effectiveness together
A control must be both well designed and working in practice to be rated effective.
Control reduction (illustrative)
Residual score = Inherent score × (1 − control effectiveness %)
Illustrative only. Many firms apply this style of adjustment but it is not a prescribed Basel formula.
Expected annual loss from a scenario
Expected annual loss = frequency per year × average severity per event
Use it to compare scenarios. Frequency is the expected number of events per year, not a probability, when events can repeat.
Frequency from a return period
Annual frequency ≈ 1 ÷ return period in years
A 1-in-20-year event has frequency about 0.05. Approximate for rare events.
Scenario process order
Preparation → Workshop → Quantification → Validation and challenge → Use and review
Know the sequence and what each stage controls.
Net loss
Net loss = Gross loss − Recoveries
Record both. Gross loss is the amount before any recovery, including insurance. Recoveries are tracked separately.
Traffic-light KRI rule
Green: value within appetite | Amber: value ≥ early-warning threshold | Red: value ≥ limit
For metrics where higher is worse. Reverse the inequalities when lower is worse, for example the percentage of controls tested on time.
KRI versus KPI test
KPI: performance against a goal | KRI: exposure to risk of missing it or losing
Classify by purpose, not by the metric name.
Leading versus lagging
Leading = predicts future risk | Lagging = reports past outcomes
Loss counts are lagging. Staff vacancies or backlog sizes are usually leading.
Rate-based KRI
KRI rate = number of exceptions ÷ total volume
Use rates rather than raw counts when volumes change, so trends are comparable.
Critical operation mapping chain
Critical operation → processes → resources (people, technology, data, facilities, third parties) → dependencies and single points of failure
Map end to end, then test against the impact tolerance. A map that stops at the firm's boundary misses third-party risk.
Impact tolerance
Maximum tolerable disruption to a critical operation, set before testing
It is set by the harm to customers and to the firm or market, not by how fast IT thinks it can recover.
New product review trigger
New or materially changed product, process, system, market or outsourcing → pre-launch review and sign-off by control functions
Be ready to say which functions review and why. A post-implementation review follows.
Third-party criticality ranking
Criticality = importance of the service supplied + difficulty of substitution + data or access held
This is a qualitative ranking, not a numeric formula. It decides the depth of due diligence and monitoring.
Emerging risk register fields
Description, driver, possible impact, time horizon, owner, trigger indicators, review date
Emerging risks are tracked through indicators, as they often cannot be quantified yet.

Quick revision

  • Risk identification comes before measurement: you cannot assess a risk you have not found.
  • A common taxonomy gives consistent language so risks can be compared and aggregated across the firm.
  • RCSA relies on staff judgement about risks and controls, so it is exposed to bias and optimism.
  • RCSA looks at inherent risk, control effectiveness and residual risk.
  • Scenario analysis explores severe but plausible events, including ones that have not happened to the firm.
  • Stress testing applies extreme conditions to see the effect on the firm.
  • KRIs are forward-looking metrics with thresholds that trigger escalation when breached.
  • A good KRI is measurable, predictive and tied to a specific risk or control.
  • Loss event data is backward looking and has few observations for rare, severe events.
  • External loss data helps cover events the firm has not yet experienced.
  • Process mapping shows where steps, handoffs and dependencies create risk or control gaps.
  • Change and new products bring new risks, so review them before launch and after.

Common mistakes

  • Treating reputational risk as part of Basel operational risk. Fix: Remember the definition excludes strategic and reputational risk. Only the direct loss counts.
  • Excluding legal risk from the definition. Fix: The Basel definition includes legal risk, such as fines and settlements.
  • Rating inherent risk after considering controls Fix: Rate inherent risk first as if no controls existed. Only then apply controls to reach residual risk.
  • Treating a control as effective because it exists Fix: Always test both design and operating effectiveness. A control that is not performed gives little risk reduction.
  • Confusing anchoring with availability. Fix: Anchoring is fixation on a reference number. Availability is overestimating what is easy to recall, like a recent or dramatic event.
  • Treating scenario analysis as the same as historical loss data analysis. Fix: Scenarios are forward-looking and expert-based. Loss data is backward-looking. Scenarios cover events not yet seen.
  • Treating KRIs and KPIs as the same thing Fix: Ask what the metric tells you. Goal achievement is a KPI. Exposure to failure or loss is a KRI.
  • Calling loss data a leading indicator Fix: Loss data is lagging because it records past events. It informs models and trends, but it does not warn in real time.
  • Treating a process map as a control test. Fix: A map identifies steps, hand-offs and dependencies. Controls are then assessed on the map, for example through RCSA or testing.
  • Stopping the dependency map at the firm's own systems. Fix: Include vendors, their subcontractors (fourth parties) and shared infrastructure. Check for concentration.

Exam tips

  • Classify by root cause. Many options are tempting because of where the loss is booked.
  • Memorise the include and exclude list: legal included, strategic and reputational excluded.
  • Separate intentional from accidental. It decides between fraud and execution errors.
  • When a question mentions risk appetite, think board approval, then limits, tolerances and indicators.
  • Expect scenarios with two overlapping causes. Pick the primary cause named in the question.
  • Read whether the question asks for inherent or residual risk before doing anything else.
  • Expect cases where a control exists but is not working. The answer is usually a higher residual risk.
  • For limitations questions, name subjectivity, bias, inconsistent scales and lack of independent challenge.