FRM Exam Part I · Operational Risk
Operational Risk Identification and Assessment Tools: RCSA, KRI and Scenarios
Updated 11 October 2026 · Fact-checked
Operational risk identification and assessment tools help a firm find, measure and rank risks from people, processes, systems and external events. The main tools are RCSA, key risk indicators, scenario analysis, loss event databases and risk maps. You solve questions by matching the tool to its purpose: forward-looking, backward-looking, or ranking.
Understand Risk Identification and Assessment Tools
Operational risk is the risk of loss from inadequate or failed internal processes, people and systems, or from external events. You cannot manage it until you can see it. The tools in this topic are different ways of looking at the same risks.
Risk and control self-assessment (RCSA) asks business units to identify their own risks and rate them. For each risk, the unit rates inherent risk (before controls) and residual risk (after controls), and also rates how well the controls work. It is forward-looking and judgmental. Its weakness is bias: managers may rate their own area too kindly.
Key risk indicators (KRIs) are metrics that signal changing risk exposure. Examples are staff turnover, number of failed trades, system downtime and the count of overdue audit actions. A good KRI is measurable, predictive and has a threshold that triggers escalation. A KPI measures how well performance is going against a goal. A KRI measures how risky things are becoming. Some metrics can serve as both, but the purpose is different.
Loss event databases record actual losses: date, amount, business line, event type, cause and recoveries. They are backward-looking and objective. They are weak on rare, severe events because few of them have happened. External databases (industry consortia, public sources) help fill the gap. Scenario analysis asks experts to describe plausible severe events and estimate their frequency and impact. It is forward-looking and covers tail events that no history shows. Its weakness is subjectivity and anchoring.
Risk mapping places risks by business line, process or event type, and often on a likelihood-versus-impact grid (a heat map). It shows where risk concentrates and where controls are thin. Banks combine all tools: loss data gives a factual base, RCSA and scenarios add a forward view, and KRIs give ongoing monitoring.
Key formulas to remember
- Residual risk
- Residual risk = Inherent risk − Effect of controls
- A conceptual relationship, not a precise calculation. Rated qualitatively or on a scale in RCSA.
- Expected annual loss for a risk
- Expected annual loss = Frequency per year × Average severity
- Used in scenario analysis and risk ranking. Assumes the frequency and severity estimates are for the same event type.
- Tool orientation
- Loss data = backward-looking; RCSA, scenarios, KRIs = forward-looking
- The most tested distinction. Loss data is objective but weak on rare events; scenarios cover the tail but are subjective.
- KRI versus KPI
- KRI = signals rising risk; KPI = signals performance against target
- A KRI should have thresholds that trigger escalation.
How to solve Risk Identification and Assessment Tools questions
Most questions ask you to choose a tool, spot a weakness or interpret an output. Use this order.
- 1Read the stem and decide what the firm needs: finding risks, measuring past losses, monitoring changes, or estimating rare severe events.
- 2Classify the need as backward-looking (what happened) or forward-looking (what could happen).
- 3Match the tool: loss database for history, RCSA for control self-rating, KRI for monitoring, scenario analysis for tail events, risk map for ranking and concentration.
- 4Check for bias or data limits in the stem: self-rating bias, few observations, subjective estimates, stale thresholds.
- 5If numbers are given, compute frequency × severity or compare inherent with residual risk.
- 6Eliminate options that swap the strengths of two tools, then choose the best fit.
Quickest way: Match the tool to the keyword
When to use it: Use when time is short and the question asks which tool fits a situation.
- Spot the keyword: 'actual losses' means loss database; 'self-assessment' or 'controls' means RCSA.
- 'Early warning' or 'threshold' means KRI.
- 'Plausible severe event' or 'no history' means scenario analysis.
- 'Heat map' or 'concentration' means risk map.
- Reject any option that calls a loss database forward-looking or a KRI a performance measure.
Common mistakes in Risk Identification and Assessment Tools
Treating KRIs and KPIs as the same thing.
Both are metrics and some overlap, such as system uptime.
Fix: Ask what the metric signals. A KRI warns about rising risk and has escalation triggers. A KPI tracks performance against a target.
Calling loss event data forward-looking.
Students assume data on losses predicts future ones automatically.
Fix: Loss data is historical. It is objective but thin on rare, severe events, so scenarios and external data supplement it.
Confusing inherent and residual risk.
The terms sound similar.
Fix: Inherent is before controls; residual is after controls. Weak controls leave residual close to inherent.
Saying RCSA is purely quantitative and objective.
It produces scores and heat maps that look precise.
Fix: RCSA is judgmental and prone to bias and optimism. Challenge from the second line and cross-checks with loss data reduce the bias.
Assuming scenario analysis relies on past data only.
Mixing it up with loss databases or historical simulation.
Fix: Scenario analysis uses expert judgment to build plausible severe events, often informed by external loss data and near misses.
Worked examples
Example 1
A bank's scenario workshop estimates that a major payment system outage happens once every 5 years, with an average loss of USD 12 million. Another scenario, a large internal fraud, is estimated at once every 20 years with an average loss of USD 40 million. Which scenario has the higher expected annual loss, and what is it?
Show the solution
- Outage frequency = 1 ÷ 5 = 0.20 per year.
- Outage expected annual loss = 0.20 × 12 = USD 2.4 million.
- Fraud frequency = 1 ÷ 20 = 0.05 per year.
- Fraud expected annual loss = 0.05 × 40 = USD 2.0 million.
- Compare: 2.4 is greater than 2.0.
Answer: The payment outage has the higher expected annual loss, USD 2.4 million, against USD 2.0 million for fraud.
Example 2
A bank has few internal losses from cyber attacks but worries about a severe breach. Which tool is best suited to assess this risk, and why? (A) Loss event database only (B) Scenario analysis (C) KPI dashboard (D) Inherent risk rating of unrelated units
Show the solution
- The concern is a rare, severe event with little internal history.
- A loss database is backward-looking and has few data points here, so (A) is weak.
- A KPI dashboard measures performance, not risk exposure, so (C) is wrong.
- (D) uses unrelated units and does not address cyber risk.
- Scenario analysis builds a plausible severe breach, estimates frequency and impact, and can use external data, so (B) fits.
Answer: (B) Scenario analysis.
Exam tips
- Expect questions that ask for the strength or weakness of a tool. Memorise one strength and one weakness for each.
- Know the inherent versus residual risk order: controls reduce inherent risk to residual risk.
- For KRI questions, look for thresholds, escalation and predictive power. Lagging metrics are weaker KRIs.
- For numeric items, the arithmetic is simple: frequency × severity. Check that units and time period match.
- Remember that a risk map ranks and shows concentration; it does not by itself produce a capital number.
Practice questions from Operational Risk
- A bank's operational risk team asks each business line manager to score the likelihood and impact of key risks on a 1-to-5 scale, then plots…
- A bank's operational risk function wants a tool that traces the stages of a payments process to find where errors, delays or control gaps co…
- A bank has a stable operational loss database. After a new product launch, the business argues that because internal loss data show no large…
- Under the Basel framework, operational risk is defined as the risk of loss resulting from inadequate or failed internal processes, people an…
- Under the Basel framework, operational risk is defined as the risk of loss resulting from inadequate or failed internal processes, people an…
Risk Identification and Assessment Tools in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Risk Identification and Assessment Tools: frequently asked questions
What is RCSA in operational risk?
RCSA stands for risk and control self-assessment. Business units identify their risks, rate them before and after controls, and assess how well controls work. It is forward-looking but subjective, so it is usually challenged by the risk function.
What is the difference between a KRI and a KPI?
A KRI signals rising risk, such as growing staff turnover or failed trades, and has thresholds that trigger escalation. A KPI measures performance against a business goal, such as revenue or processing speed. Some metrics can be used as both, but the purpose differs.
Why is scenario analysis used if loss data exists?
Loss data is historical and has few observations of rare, severe events. Scenario analysis uses expert judgment to estimate such events, often informed by external data. It fills the tail gap but is subjective.
Are loss event databases forward-looking?
No. They record actual past losses with details such as amount, cause and business line. They are objective, but they are weak at showing risks that have not yet occurred.