FRM Exam Part I · Enterprise Risk Management and Future Trends
Emerging Risks and Future Trends in Risk Management
Updated 11 October 2026 · Fact-checked
Emerging risks are new or fast-changing threats, such as climate change, cyber attacks, fintech disruption and AI model failures, that existing frameworks may not fully capture. To answer exam questions, identify the risk, link it to a classic risk type, name the transmission channel, and pick the right control.
Understand Emerging Risks and Future Trends in Risk Management
Emerging risks are threats that are new, changing quickly, or poorly measured. They rarely create a brand new risk type. Instead, they feed existing ones: credit, market, liquidity, operational and strategic risk. Your first job in any question is to map the emerging risk to a classic category.
Climate risk has two main parts. Physical risk comes from floods, storms, heat and sea-level rise that damage assets and disrupt business. Transition risk comes from the shift to a low-carbon economy: new regulation, carbon prices, technology change and shifts in customer preferences. Both can hit credit quality (borrowers lose income or collateral value), market prices (stranded assets) and insurance claims. Climate effects work over long horizons, so standard one-day or one-year VaR horizons fit them poorly. Scenario analysis and stress testing are the main tools. ESG factors extend the same logic to wider environmental, social and governance issues.
Cyber risk is an operational risk. It covers data breaches, ransomware, fraud and system outages. It matters because firms depend on shared technology and third-party vendors, so one failure can spread widely. Operational resilience means a firm can keep delivering critical services through a disruption. Key ideas are identifying critical services, setting tolerance for disruption, testing recovery plans, and managing third-party and concentration risk.
Fintech, AI and data analytics change how financial services are delivered and how risk is measured. Machine learning can improve credit scoring, fraud detection and monitoring. But it brings model risk: overfitting, bias in training data, poor explainability and weak validation. Other themes include digital assets, algorithmic trading, cloud dependence and data privacy. Regulators expect governance to keep pace: clear ownership, human oversight, validation and documentation.
The common thread is that risk management must become more forward-looking. Firms rely more on scenarios, richer data, and integrated, firm-wide views rather than backward-looking statistics alone.
How to solve Emerging Risks and Future Trends in Risk Management questions
This topic is conceptual. Use the same short method for any question on an emerging risk.
- 1Read the scenario and name the emerging risk: climate, cyber, fintech, AI, data or third-party.
- 2Map it to a classic risk type: credit, market, liquidity, operational or strategic.
- 3If climate, decide whether it is physical (damage, disruption) or transition (policy, technology, preferences).
- 4Identify the transmission channel: how does the risk reach the balance sheet or operations?
- 5Match the best response: scenario analysis, stress testing, validation, resilience testing, governance or diversification.
- 6Eliminate options that are absolute (always, never, eliminates) or that apply a backward-looking tool alone to a long-horizon risk.
- 7Check the answer against the question wording: is it asking for cause, impact or control?
Quickest way: Label, map, match
When to use it: Use when you have about a minute and the options are all plausible-sounding statements.
- Label the risk in three words, such as 'transition risk' or 'model risk'.
- Map it to credit, market, operational or strategic risk.
- Pick the option that is forward-looking, governance-based and not absolute.
- Reject options claiming the risk can be fully eliminated or measured precisely by historical VaR.
Common mistakes in Emerging Risks and Future Trends in Risk Management
Mixing up physical and transition climate risk.
Both are called climate risk and both hurt asset values.
Fix: Physical means damage from weather or climate events. Transition means losses from policy, technology or market change toward low carbon.
Treating emerging risks as separate from credit, market and operational risk.
New names suggest new categories.
Fix: Always ask which classic risk the emerging one drives, and through what channel.
Relying on historical VaR for climate risk.
VaR is the default tool in the syllabus.
Fix: Climate risk has little relevant history and a long horizon. Scenario analysis and stress testing fit better.
Believing machine learning removes model risk.
Complex models feel more accurate.
Fix: ML adds overfitting, bias and explainability issues. It still needs independent validation and governance.
Treating cyber risk as only an IT issue.
Cyber events look technical.
Fix: Cyber is an operational risk with business, legal, reputational and third-party consequences. It needs board and risk function oversight.
Choosing answers that say a risk can be eliminated.
Control language sounds strong.
Fix: Risks are mitigated, not eliminated. Prefer wording such as reduce, monitor, test and govern.
Worked examples
Example 1
A bank lends heavily to coal-fired power producers. A new carbon tax makes their operations unprofitable and their loans riskier. Which risk is this, and which risk type does it mainly drive? (A) Physical climate risk driving market risk (B) Transition climate risk driving credit risk (C) Cyber risk driving operational risk (D) Model risk driving liquidity risk
Show the solution
- The trigger is a carbon tax, which is a policy change toward low carbon.
- Policy change is transition risk, not physical risk.
- Borrowers' falling profitability raises default probability, which is credit risk.
- So the pairing is transition climate risk driving credit risk. The other options pair the wrong trigger or the wrong channel.
Answer: (B) Transition climate risk driving credit risk.
Example 2
A bank deploys a complex machine learning credit model that fits its training data almost perfectly but performs poorly on new applicants. What is the main issue and the best response? (A) Cyber risk; buy insurance (B) Overfitting model risk; independent validation with out-of-sample testing (C) Physical risk; relocate branches (D) Liquidity risk; raise deposits
Show the solution
- Near-perfect fit on training data with poor new-data performance is the signature of overfitting.
- Overfitting is a form of model risk, an operational and governance issue.
- The right response tests the model on data it was not trained on and has independent validation.
- Insurance, relocation and funding changes do not address model behaviour.
Answer: (B) Overfitting model risk; independent validation with out-of-sample testing.
Exam tips
- Expect conceptual multiple-choice questions. Learn definitions and distinctions cleanly rather than memorising numbers.
- Know physical versus transition risk well. It is the most testable climate distinction.
- Link every emerging risk to a classic risk type and a typical control.
- Watch for absolute wording. Options that say eliminate, guarantee or always are usually wrong.
- Connect AI and data topics to your machine learning and model risk study. Overfitting and validation recur.
Practice questions from Enterprise Risk Management and Future Trends
- A bank uses a scenario-analysis approach for climate risk over a 30-year horizon, whereas its standard credit models use a one-year horizon …
- A bank's ERM team is designing a climate stress test. It considers three scenarios over 30 years: an orderly transition, a disorderly (late …
- Within an ERM framework, which of the following is the primary role of a chief risk officer (CRO)?
- A bank relies on a single cloud provider for its core trading and risk systems. A regulator asks the bank to address concentration in its te…
- A bank considers expanding a lending business. The expansion is expected to generate net income of USD 9.6 million after expected losses, an…
Emerging Risks and Future Trends in Risk Management in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Emerging Risks and Future Trends in Risk Management: frequently asked questions
Is climate risk in the FRM Part I syllabus?
GARP revises the curriculum every year, so check the current Study Guide and Learning Objectives. Climate and related themes appear in risk management material, so learn the physical versus transition distinction and how climate risk feeds credit and market risk.
Is cyber risk a separate risk type?
It is usually treated as a form of operational risk. It can also create reputational, legal and liquidity effects. Operational resilience is the ability to keep critical services running through such events.
How is machine learning linked to risk management?
Machine learning is used for credit scoring, fraud detection and monitoring. It also creates model risk through overfitting, bias and poor explainability. Governance and independent validation are the expected controls.
Why is VaR a poor fit for climate risk?
Climate risk plays out over long horizons with limited relevant history. Historical statistics may not reflect future conditions. Scenario analysis and stress testing handle this better.