Skip to content

FRM Part II · FRM Exam Part II

The Financial Stability Implications of Artificial Intelligence: formula sheet

Full chapter guide

Key formulas

Concentration share
Provider share = firms (or activity) served by provider ÷ total firms (or activity)
A simple way to describe how dependent the system is on one provider. No single threshold is a standard rule.
Herfindahl-Hirschman Index (HHI)
HHI = Σ (sᵢ)², where sᵢ is each provider's market share
With shares in decimals, HHI runs from near 0 to 1. With shares in percent, it runs up to 10,000. Higher means more concentrated. Use it only as an illustration of concentration.
Systemic vulnerability logic
Systemic impact ≈ criticality of service × degree of concentration × low substitutability
A qualitative rule, not a calculation. Risk is highest when all three are high.
Portfolio variance of two assets
σp² = w1²σ1² + w2²σ2² + 2·w1·w2·ρ·σ1·σ2
Higher correlation ρ raises portfolio risk. Herding pushes ρ up, so diversification benefit falls.
Perfect correlation limit
If ρ = 1, σp = w1σ1 + w2σ2
No diversification benefit. Used to show the worst case when everyone trades alike.
Herding causal chain
Common models/data → similar signals → synchronized trades → higher correlation → price impact → volatility and liquidity strain → feedback
Use this chain to structure any conceptual answer.
Threat-to-impact chain
Threat (AI-enabled) → Channel → Loss event → Contagion → Control
Use this to structure any case answer. Name each link rather than only the headline threat.
Cyber risk as a scenario
Expected annual loss = Frequency × Average severity
A simple operational-risk view. AI mainly raises frequency and success rate; systemic events raise severity through correlation. It is a framing, not a required calculation.
Systemic amplification rule
Common dependency (cloud/vendor/model) + speed of information = correlated losses
Concentration and herding explain why firm-level cyber risk becomes a financial stability issue.
Dual use principle
Same AI capability → attack benefit and defence benefit
Never claim AI only increases risk or only reduces it.
Model risk drivers
Model risk = f(model error, data error, misuse)
A conceptual rule, not a calculation. Use it to sort a case into design, data or use problems.
Out-of-sample performance check
Generalisation gap = in-sample performance − out-of-sample performance
A large positive gap signals overfitting. Test on held-out and out-of-time data.
Drift monitoring idea
Alert if monitored metric breaches its pre-set threshold
Metrics include accuracy, population stability and input distribution shifts. Thresholds must be set before deployment.
Proportionality rule
Validation depth rises with model materiality and complexity
High-impact, opaque models need the strongest validation and oversight.
FSB policy recommendations (sequence)
1) Close data and information gaps and monitor; 2) Assess adequacy of existing policy frameworks; 3) Enhance supervisory and regulatory capabilities
This is a framework, not a calculation. Learn the order and the logic: see, assess, strengthen.
Vulnerability to indicator match
Third-party concentration → provider shares and substitutability; Correlation → model, data and strategy similarity; Cyber → AI-enabled incidents; Model risk → explainability, data quality, governance
Use this to pick the indicator that fits a scenario.
Concentration check (generic)
Provider share = Firms' critical services from one provider ÷ Total critical services
A simple illustration of a concentration indicator. It is not a prescribed FSB formula.

Quick revision

  • AI adoption in finance is widespread in areas like customer support, risk management, fraud detection and compliance, with some use in trading and credit.
  • Third-party dependency risk arises when many firms rely on the same few providers for models, data or cloud services.
  • Concentration among providers creates a common point of failure that can affect many institutions at once.
  • Similar models, data and providers can lead to correlated decisions and herding in markets.
  • Herding can amplify price moves and stress, which can reduce market liquidity.
  • AI can help attackers through more convincing phishing, deepfakes and faster malware development.
  • AI systems can also widen the attack surface for firms that use them.
  • Model risk rises when models are opaque, hard to explain or hard to validate.
  • Poor data quality, bias and weak data governance can produce faulty model outputs at scale.
  • Good governance means clear accountability, validation, testing and human oversight.
  • Authorities should monitor AI use, dependencies and concentration, and may need to adapt existing frameworks.
  • Policy responses include better data collection, supervisory capacity and attention to third-party oversight.

Common mistakes

  • Treating all AI as generative AI Fix: Remember that most financial AI use is traditional ML for scoring, forecasting and detection. Generative AI is a newer, smaller part.
  • Saying AI removes the need for human oversight Fix: Regulators expect governance, validation and human accountability. Pick answers that keep humans responsible.
  • Treating third-party risk as only an individual bank's operational risk. Fix: Ask whether many firms share the provider. If yes, it is a financial stability issue as well.
  • Assuming multi-vendor sourcing removes concentration. Fix: Check for common fourth parties, such as the same cloud or chip supplier beneath different vendors. Also note switching costs and integration limits.
  • Treating herding and procyclicality as the same thing. Fix: Herding is many participants acting alike. Procyclicality is amplification of the cycle, often through rules or models that cut risk in downturns. They reinforce each other but are distinct.
  • Assuming herding needs participants to communicate or copy each other. Fix: In AI contexts herding often arises from independent use of the same models or data, with no coordination.
  • Treating AI-enabled fraud as only a firm-level operational loss. Fix: Always ask if many firms rely on the same provider, model or information source. If so, add the systemic channel.
  • Saying voice or face biometrics fully solve identity fraud. Fix: Recommend layered controls: multi-factor authentication, liveness checks and out-of-band call-back.
  • Treating explainability tools as proof that a model is correct. Fix: Remember that explanations are approximations. Validation still needs performance, stability and conceptual soundness testing.
  • Assuming removing protected attributes removes bias. Fix: Proxy variables and biased historical labels can still carry bias. Test outcomes across groups.

Exam tips

  • Expect applied scenarios where you match a function to its main risk, not definitions only.
  • Look for words like vendor, shared model or same provider. They signal concentration risk.
  • Be careful with absolute words such as always, eliminates or removes. They are usually wrong.
  • Know the six uses: trading, credit underwriting, risk management, fraud detection, customer service and compliance.
  • Look for 'same', 'few' or 'common' in the stem. That is the cue for concentration and systemic risk.
  • Prefer answers that mention visibility, substitutability or fourth parties over answers that only mention internal controls.
  • Separate provider-outage risk from shared-model herding risk. Questions often test whether you can tell them apart.
  • Be wary of absolute words such as 'eliminates' or 'fully transfers'. They are usually wrong.