FRM Part I · FRM Exam Part I
Operational Risk for FRM Part I: Chapter Guide
Operational risk is the risk of loss from inadequate or failed internal processes, people, systems, or external events. Basel's definition includes legal risk but excludes strategic and reputational risk. To solve questions, classify the event, identify the control or framework involved, and apply the Basel capital formula or loss-distribution arithmetic step by step.
What this chapter covers
This chapter covers losses that come from failed processes, people, systems and external events, rather than from markets or credit. You learn how to define and classify operational risk, how firms govern it, how they identify and measure it, how regulators set capital for it, and how banks model loss data.
The chapter links closely to the rest of Part I. Foundations of Risk Management gives you the governance language, such as the three lines of defense and risk appetite. Quantitative Analysis supplies the statistics behind loss distributions, frequency and severity, and percentiles. Financial Markets and Products and Valuation and Risk Models connect through VaR-style thinking, since operational risk capital uses high-confidence percentiles of loss.
Expect a mix of conceptual and numerical questions. Conceptual ones test definitions, event types, and which tool fits which situation. Numerical ones test capital calculations, expected loss, and simple aggregation of frequency and severity. Both can be handled with a clear framework and regular practice.
Operational risk is a smaller part of the paper than some other topics, but it is a dependable source of marks because most questions are definitional or use short calculations. Candidates who learn the Basel terms precisely, and can run a basic loss-model calculation, gain points that others lose to vague wording. The chapter also reinforces governance and quantitative ideas that appear across the 100 questions, so the effort pays back elsewhere in your 4-hour exam.
Operational Risk: topics in the order to study them
- 1Operational Risk Definition and CategoriesEverything else relies on the Basel definition and the event types, so learn these first.
- 2Operational Risk Governance and FrameworksOnce you know what the risk is, learn who owns it and how the firm organizes its management.
- 3Risk Identification and Assessment ToolsTools such as risk and control self-assessments and key risk indicators make sense only after the framework is clear.
- 4Operational Risk Capital: Basel ApproachesCapital rules build on the definition, business lines and the data produced by assessment tools.
- 5Loss Distribution Approach and ModelingThis is the most quantitative topic, so take it after the regulatory context is in place.
- 6Operational Risk Case Studies and MitigationCases pull all the earlier ideas together and are best used for revision and application.
How to prepare Operational Risk
Spend most of your time on precise definitions and a few repeatable calculations. Study in the order given, and test yourself after each topic.
- Write the Basel definition in your own words and list the event types with one example each. Check that you can say what is included and what is excluded.
- Learn the governance structure: board, senior management, the three lines of defense, and the role of risk appetite. Practice naming which line owns which task.
- Build a table on paper comparing each assessment tool by purpose, strength and weakness. Use it to match tools to scenarios.
- Learn the Basel capital approaches as a progression from simpler to more risk-sensitive, and note which inputs each one uses. Check the current curriculum for which approach is emphasized.
- Practice loss-model arithmetic: expected loss = frequency × average severity, then percentile-based capital. Work each step by hand and keep a calculator for roots and logs.
- Read each case study and note the failed control, the root cause and the mitigation. Then answer practice questions under timed conditions, about two and a half minutes each, and review every error.
Common mistakes in Operational Risk
Treating reputational or strategic losses as operational risk
Fix: Recall the Basel definition: legal risk is in, strategic and reputational risk are out.
Mixing up the three lines of defense
Fix: Remember: line 1 owns and manages the risk, line 2 oversees independently, line 3 gives independent assurance.
Choosing the wrong assessment tool for a scenario
Fix: Link each tool to what it measures, such as past losses, control quality or early warnings, and to its main weakness.
Confusing the Basel approaches and their inputs
Fix: Study the approaches as a progression, note each input, and follow the current GARP curriculum rather than old notes.
Applying normal-distribution thinking to operational losses
Fix: Remember that severity is skewed and fat-tailed, so averages understate tail risk, and frequency and severity are modeled separately.
Skipping case studies because they seem like stories
Fix: Use each case to practice identifying the event type, the control failure and the right mitigation, since questions test exactly that.
Last-day revision: Operational Risk
- Operational risk is loss from inadequate or failed processes, people, systems, or external events.
- Basel's definition includes legal risk but excludes strategic and reputational risk.
- Know the Basel event types, such as internal fraud, external fraud, and damage to physical assets.
- Three lines of defense: business units, independent risk function, internal audit.
- Risk appetite and tolerance are set by the board and shape limits and indicators.
- Key risk indicators are forward-looking signals; loss data is backward-looking.
- Risk and control self-assessments rely on business judgment and can be biased.
- Capital approaches move from simple formulas to more risk-sensitive measures; know the inputs of each.
- Expected loss for a period = expected frequency × expected severity.
- Frequency is usually modeled with a count distribution and severity with a fat-tailed one.
- Capital is based on a high percentile of the aggregate loss distribution, less expected loss where the rules allow.
- In case studies, find the control failure first, then match the mitigation.
Operational Risk practice questions
- Which statement best describes the main advantage of using external loss data when identifying and assessing operational risks?
- A firm buys insurance to cover operational losses. Its expected annual operational loss is USD 12 million. The policy covers 70% of any sing…
- A bank models annual operational losses in one business line with Poisson frequency of mean 12 events per year and independent severity with…
- A bank's data entry clerk mistakenly enters a settlement amount with an extra zero, causing a counterparty to receive a payment ten times to…
- A bank monitors the number of failed trade settlements per month and sets an amber threshold at 40 and a red threshold at 60. The indicator …
- A bank's simulated aggregate annual operational loss distribution has a mean of 8 million. In 100,000 simulated years, the 99.9th percentile…
- When fitting severity distributions to operational loss data, analysts often use a heavy-tailed distribution such as the generalized Pareto …
- Which statement best describes why extreme value theory (EVT), such as the peaks-over-threshold method with a generalized Pareto distributio…
Operational Risk in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Operational Risk: frequently asked questions
How is operational risk defined for FRM Part I?
It is the risk of loss from inadequate or failed internal processes, people and systems, or from external events. The Basel definition includes legal risk and excludes strategic and reputational risk.
Is operational risk calculation-heavy?
Not very. Most questions are conceptual, with some short calculations such as expected loss from frequency and severity or simple capital formulas. Practice these so they take under two minutes each.
Which Basel approach should I focus on?
Follow the approaches named in the current GARP Study Guide and Learning Objectives, since GARP revises the curriculum every year. Learn the inputs and logic of each so you can answer even if the emphasis shifts.
How do I remember the event types?
Group them by source: people (internal fraud, employment practices), outsiders (external fraud), clients and products, physical assets, system failures, and process execution. Then attach one real example to each.
How long should I spend on this chapter?
Give it a moderate share of your Part I time. Finish the first pass in a few focused sessions, then revisit it through practice questions rather than rereading.