FRM Part II · FRM Exam Part II
The Financial Stability Implications of Artificial Intelligence: formula sheet
Key formulas
- Concentration share
- Provider share = firms (or activity) served by provider ÷ total firms (or activity)
- A simple way to describe how dependent the system is on one provider. No single threshold is a standard rule.
- Herfindahl-Hirschman Index (HHI)
- HHI = Σ (sᵢ)², where sᵢ is each provider's market share
- With shares in decimals, HHI runs from near 0 to 1. With shares in percent, it runs up to 10,000. Higher means more concentrated. Use it only as an illustration of concentration.
- Systemic vulnerability logic
- Systemic impact ≈ criticality of service × degree of concentration × low substitutability
- A qualitative rule, not a calculation. Risk is highest when all three are high.
- Portfolio variance of two assets
- σp² = w1²σ1² + w2²σ2² + 2·w1·w2·ρ·σ1·σ2
- Higher correlation ρ raises portfolio risk. Herding pushes ρ up, so diversification benefit falls.
- Perfect correlation limit
- If ρ = 1, σp = w1σ1 + w2σ2
- No diversification benefit. Used to show the worst case when everyone trades alike.
- Herding causal chain
- Common models/data → similar signals → synchronized trades → higher correlation → price impact → volatility and liquidity strain → feedback
- Use this chain to structure any conceptual answer.
- Threat-to-impact chain
- Threat (AI-enabled) → Channel → Loss event → Contagion → Control
- Use this to structure any case answer. Name each link rather than only the headline threat.
- Cyber risk as a scenario
- Expected annual loss = Frequency × Average severity
- A simple operational-risk view. AI mainly raises frequency and success rate; systemic events raise severity through correlation. It is a framing, not a required calculation.
- Systemic amplification rule
- Common dependency (cloud/vendor/model) + speed of information = correlated losses
- Concentration and herding explain why firm-level cyber risk becomes a financial stability issue.
- Dual use principle
- Same AI capability → attack benefit and defence benefit
- Never claim AI only increases risk or only reduces it.
- Model risk drivers
- Model risk = f(model error, data error, misuse)
- A conceptual rule, not a calculation. Use it to sort a case into design, data or use problems.
- Out-of-sample performance check
- Generalisation gap = in-sample performance − out-of-sample performance
- A large positive gap signals overfitting. Test on held-out and out-of-time data.
- Drift monitoring idea
- Alert if monitored metric breaches its pre-set threshold
- Metrics include accuracy, population stability and input distribution shifts. Thresholds must be set before deployment.
- Proportionality rule
- Validation depth rises with model materiality and complexity
- High-impact, opaque models need the strongest validation and oversight.
- FSB policy recommendations (sequence)
- 1) Close data and information gaps and monitor; 2) Assess adequacy of existing policy frameworks; 3) Enhance supervisory and regulatory capabilities
- This is a framework, not a calculation. Learn the order and the logic: see, assess, strengthen.
- Vulnerability to indicator match
- Third-party concentration → provider shares and substitutability; Correlation → model, data and strategy similarity; Cyber → AI-enabled incidents; Model risk → explainability, data quality, governance
- Use this to pick the indicator that fits a scenario.
- Concentration check (generic)
- Provider share = Firms' critical services from one provider ÷ Total critical services
- A simple illustration of a concentration indicator. It is not a prescribed FSB formula.
Quick revision
- AI adoption in finance is widespread in areas like customer support, risk management, fraud detection and compliance, with some use in trading and credit.
- Third-party dependency risk arises when many firms rely on the same few providers for models, data or cloud services.
- Concentration among providers creates a common point of failure that can affect many institutions at once.
- Similar models, data and providers can lead to correlated decisions and herding in markets.
- Herding can amplify price moves and stress, which can reduce market liquidity.
- AI can help attackers through more convincing phishing, deepfakes and faster malware development.
- AI systems can also widen the attack surface for firms that use them.
- Model risk rises when models are opaque, hard to explain or hard to validate.
- Poor data quality, bias and weak data governance can produce faulty model outputs at scale.
- Good governance means clear accountability, validation, testing and human oversight.
- Authorities should monitor AI use, dependencies and concentration, and may need to adapt existing frameworks.
- Policy responses include better data collection, supervisory capacity and attention to third-party oversight.
Common mistakes
- Treating all AI as generative AI Fix: Remember that most financial AI use is traditional ML for scoring, forecasting and detection. Generative AI is a newer, smaller part.
- Saying AI removes the need for human oversight Fix: Regulators expect governance, validation and human accountability. Pick answers that keep humans responsible.
- Treating third-party risk as only an individual bank's operational risk. Fix: Ask whether many firms share the provider. If yes, it is a financial stability issue as well.
- Assuming multi-vendor sourcing removes concentration. Fix: Check for common fourth parties, such as the same cloud or chip supplier beneath different vendors. Also note switching costs and integration limits.
- Treating herding and procyclicality as the same thing. Fix: Herding is many participants acting alike. Procyclicality is amplification of the cycle, often through rules or models that cut risk in downturns. They reinforce each other but are distinct.
- Assuming herding needs participants to communicate or copy each other. Fix: In AI contexts herding often arises from independent use of the same models or data, with no coordination.
- Treating AI-enabled fraud as only a firm-level operational loss. Fix: Always ask if many firms rely on the same provider, model or information source. If so, add the systemic channel.
- Saying voice or face biometrics fully solve identity fraud. Fix: Recommend layered controls: multi-factor authentication, liveness checks and out-of-band call-back.
- Treating explainability tools as proof that a model is correct. Fix: Remember that explanations are approximations. Validation still needs performance, stability and conceptual soundness testing.
- Assuming removing protected attributes removes bias. Fix: Proxy variables and biased historical labels can still carry bias. Test outcomes across groups.
Exam tips
- Expect applied scenarios where you match a function to its main risk, not definitions only.
- Look for words like vendor, shared model or same provider. They signal concentration risk.
- Be careful with absolute words such as always, eliminates or removes. They are usually wrong.
- Know the six uses: trading, credit underwriting, risk management, fraud detection, customer service and compliance.
- Look for 'same', 'few' or 'common' in the stem. That is the cue for concentration and systemic risk.
- Prefer answers that mention visibility, substitutability or fourth parties over answers that only mention internal controls.
- Separate provider-outage risk from shared-model herding risk. Questions often test whether you can tell them apart.
- Be wary of absolute words such as 'eliminates' or 'fully transfers'. They are usually wrong.