FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector
Macroprudential Policy Tools for Digital and Cyber Risk
Updated 11 October 2026 · Fact-checked
Macroprudential tools for digital risk aim to limit system-wide losses from cyber and technology failures, not just one firm's losses. Candidates include capital buffers, stress tests, liquidity measures, cyber scenario analysis and concentration limits. To answer questions, identify the transmission channel, match the tool, then state its limits.
Understand Macroprudential Policy Tools for Digital Risks
Microprudential supervision asks whether one firm is safe. Macroprudential policy asks whether the whole system can absorb a shock. Cyber and technology risk matters for both, because many firms use the same cloud providers, software and payment systems. One failure can hit many firms at once.
This chapter's theme is a quest for tools. Policymakers have well-known tools for credit and liquidity risk. For digital risk they are still searching. The reason is that cyber losses are hard to measure, data are scarce, threats keep changing, and losses can come from a shared outage and not from falling asset values.
Capital is the first tool people think of. Capital absorbs losses, so it can help after a cyber event. But capital cannot stop an outage, and it cannot fix a payment system that is down. Capital works on solvency. Many cyber shocks are about operational continuity and liquidity. A bank can be solvent but unable to send payments, and counterparties may then hoard cash.
Other tools fill gaps. Cyber stress tests and scenario analysis ask what happens if a critical provider fails or data are corrupted. Liquidity measures such as buffers and intraday liquidity monitoring address payment disruption. Concentration and third-party oversight address common dependencies. Information sharing and crisis coordination speed up response. No single tool is enough. Expect the best answer to combine tools and admit their limits.
Key formulas to remember
- Micro vs macro focus
- Microprudential = safety of the individual firm; Macroprudential = stability of the whole system
- Digital risk becomes macro when many firms share the same dependency or when stress spreads.
- Tool-to-channel matching
- Solvency loss → capital buffers; Cash and payment disruption → liquidity buffers and intraday monitoring; Common dependency → concentration and third-party oversight; Unknown scenarios → stress tests and scenario analysis
- Use this as a memory rule, not a law. Tools often overlap.
- Scenario loss logic
- Stressed loss = direct losses + recovery and remediation costs + losses from knock-on effects, compared with available capital and liquidity
- This is a framework, not a regulatory formula. The knock-on piece is what makes it systemic.
How to solve Macroprudential Policy Tools for Digital Risks questions
Use this method for any question on policy tools for digital risk.
- 1Read the scenario and decide whether the risk is firm-specific or system-wide. Look for shared providers, many firms affected, or payment disruption.
- 2Name the transmission channel: solvency loss, liquidity strain, loss of payment or market function, or loss of confidence.
- 3Match the tool to the channel: capital buffers, liquidity buffers, stress tests and scenario analysis, concentration limits, or information sharing.
- 4State what the tool can do and what it cannot. For example, capital absorbs losses but does not prevent outages.
- 5Check for data and modelling limits, such as scarce loss data, changing threats and hard-to-model correlations.
- 6Pick the answer that is system-wide, forward-looking and realistic. Reject options that promise to eliminate cyber risk.
Quickest way: Channel-first tool matching
When to use it: Use when a multiple-choice question asks which tool best addresses a described digital risk.
- Underline the harm: loss absorption, cash shortage, shared dependency, or unknown scenario.
- Map it: loss absorption to capital; cash shortage to liquidity; shared dependency to concentration or third-party oversight; unknown scenario to stress test.
- Eliminate options that are firm-only if the question says system-wide.
- Eliminate absolute words such as eliminates or guarantees.
- Choose the remaining option.
Common mistakes in Macroprudential Policy Tools for Digital Risks
Saying higher capital solves cyber risk.
Capital is the standard answer for most bank risks.
Fix: Say capital absorbs losses but does not prevent attacks or restore services. Pair it with resilience and liquidity tools.
Treating cyber risk as purely microprudential.
Firms manage their own cyber controls, so it looks like a firm issue.
Fix: Look for shared providers, interconnection and contagion. These make it a system-wide issue.
Ignoring liquidity and payment disruption.
Students focus on losses and forget that an outage can freeze cash flows.
Fix: Ask whether a solvent firm could still fail to pay. If so, liquidity and intraday tools matter.
Assuming cyber stress tests work like credit stress tests.
Credit tests have rich data and clear models.
Fix: Remember cyber tests rely on scenarios and judgement because loss data are limited and threats change.
Choosing an answer that claims a tool eliminates digital risk.
Policy language sounds confident.
Fix: Policy tools reduce or contain risk. Absolute claims are usually wrong.
Worked examples
Example 1
Many banks rely on one cloud provider. An outage stops several banks from processing payments for a day, though their capital is unaffected. Which macroprudential response best fits? (A) Raise risk-weighted capital ratios only (B) Cyber and operational scenario testing of provider failure with attention to concentration and liquidity (C) Cut dividend payouts at one bank (D) Ban all outsourcing
Show the solution
- The risk is system-wide, because many banks share one provider.
- The channel is loss of payment function and liquidity strain, not solvency, since capital is unaffected.
- Option A addresses solvency only, so it misses the channel.
- Option C is firm-specific. Option D is extreme and unrealistic.
- Option B tests the shared-dependency scenario and links to concentration and liquidity.
Answer: B
Example 2
A supervisor asks whether a bank-level cyber stress test is enough to judge system-wide risk. Give a sound answer.
Show the solution
- A bank-level test shows one firm's losses and recovery under a scenario.
- System-wide risk depends on how firms interact: shared providers, payment links and confidence effects.
- So the supervisor should run common scenarios across firms and examine knock-on effects, such as counterparties holding back liquidity.
- Limits remain: scarce loss data, changing threats and hard-to-model correlations, so results need judgement.
Answer: No. Bank-level tests are necessary but not sufficient. Use common, system-wide scenarios that capture interconnection and liquidity effects, and treat results with caution because of data limits.
Exam tips
- Always name the channel before the tool. Exam options are built around the wrong channel.
- Expect questions on why capital alone is insufficient for cyber risk.
- Look for words such as shared, common provider or interconnected to signal a macroprudential answer.
- Reject options that claim to eliminate risk.
- Link this topic to operational resilience, third-party concentration and information sharing in the same chapter.
Practice questions from Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector
- A risk manager at a payments firm must set an impact tolerance for an important business service. Which statement best describes the purpose…
- An insurer writes cyber policies with a 1,000 policy portfolio, each with a 4 million limit. It estimates an independent annual claim probab…
- A supervisor is assessing why the cyber insurance market may be unable to absorb systemic digital shocks. Which feature of cyber risk most d…
- Which feature best describes threat-led penetration testing as used in digital resilience frameworks?
- A regional bank's risk committee is reviewing why supervisors increasingly treat cyber incidents as a potential threat to financial stabilit…
Macroprudential Policy Tools for Digital Risks: frequently asked questions
Can capital requirements address cyber risk?
Partly. Capital helps a firm absorb losses after a cyber event. It does not prevent attacks or restore services, so it must be paired with resilience, liquidity and oversight tools.
How does cyber stress testing work for banks?
Supervisors or firms design a severe but plausible scenario, such as a critical provider failing or data being corrupted. They estimate direct costs, recovery needs and knock-on effects, then compare these with capital and liquidity. Scarce data mean judgement plays a large role.
Why is digital risk a financial stability issue?
Firms share providers, software and payment infrastructure. A single failure can hit many firms together and disrupt payments or confidence, which spreads stress across the system.
What is the main message of the quest for policy tools?
Tools for digital risk are still developing and no single tool is enough. A mix of capital, liquidity, stress tests, concentration oversight and information sharing is needed, each with limits.