Skip to content

FRM Part II · FRM Exam Part II

Introduction to Operational Risk and Resilience for FRM Part II

Operational risk is the risk of loss from inadequate or failed internal processes, people and systems, or from external events. Operational resilience is the ability to keep delivering critical services through disruption. To solve questions, classify the event, name the control or governance layer involved, and link it to the capital or resilience concept.

What this chapter covers

This chapter is the entry point to the Operational Risk and Resilience topic in FRM Part II. It defines operational risk, sorts losses into event types, explains who owns risk in a bank, and shows the tools used to manage it. It then moves to operational resilience and regulatory capital.

The chapter is mostly conceptual. You will not do long calculations. You will be asked to apply definitions to short cases: a trading error, a cyber attack, a vendor failure. You must pick the right event type, the right line of defense, or the right tool.

It connects to the rest of the paper in three ways. Operational losses often sit next to market and credit events, for example a model error that causes a trading loss. Capital rules link to the wider Basel framework you meet in credit and market risk. Resilience and digital risk also connect to the Current Issues readings, such as artificial intelligence and digital resilience.

FRM Part II has 80 equally weighted questions across six topics, and Operational Risk and Resilience is one of them, so every question here counts the same as any other. Introductory chapters like this one supply the vocabulary used in all later operational risk readings. Questions are usually short and wording-driven, so candidates who know the precise definitions pick up marks quickly. Weak command of the terms costs marks that are easy to protect.

Introduction to Operational Risk and Resilience: topics in the order to study them

  1. 1Definition and Scope of Operational RiskStart here because every later topic depends on what is in scope and what is not, such as the usual exclusion of strategic and reputational risk in the Basel definition.
  2. 2Operational Risk Event Types and TaxonomyOnce the definition is clear, learn the Basel event categories so you can classify losses in case questions.
  3. 3Operational Risk Governance and Three Lines of DefenseNext, learn who owns, oversees and assures risk, since framework tools only make sense with these roles in place.
  4. 4Operational Risk Management Framework and ToolsWith roles known, study the tools: risk and control self-assessment, key risk indicators, loss data collection and scenario analysis.
  5. 5Operational Resilience PrinciplesResilience builds on the framework by shifting focus from preventing loss to keeping critical services running through disruption.
  6. 6Regulatory Capital for Operational RiskFinish with capital, which draws on loss data and the business indicator, so the earlier topics make it easier to follow.

How to prepare Introduction to Operational Risk and Resilience

Treat this chapter as a vocabulary and application exercise. Aim to recognise terms fast and apply them to a scenario.

  1. Read the definition of operational risk and write it from memory. Note what it includes (legal risk) and excludes (strategic and reputational risk).
  2. Build a one-page table of the Basel event types with a one-line real example for each. Quiz yourself by covering the examples.
  3. Draw the three lines of defense and write who does what: business owns risk, independent risk function oversees, internal audit gives independent assurance.
  4. List each management tool with its purpose and one weakness. For example, loss data is backward looking and scenarios are subjective.
  5. Compare prevention with resilience. Write down the key resilience ideas: critical operations, impact tolerance, mapping dependencies and testing.
  6. Learn the capital approach as GARP presents it, including what drives the requirement, and read the formulas twice before attempting practice.
  7. Do mixed practice questions and, for each miss, record whether the error was a definition, a classification or a role mix-up.

Common mistakes in Introduction to Operational Risk and Resilience

  • Including reputational or strategic risk in the operational risk definition.

    Fix: Memorise the Basel wording and its exclusions, and check each case against it.

  • Misclassifying events between internal fraud, external fraud and process failures.

    Fix: Ask who acted and what failed first. Staff action points to internal fraud; outsiders to external fraud; a broken workflow to execution and process management.

  • Mixing up the second and third lines of defense.

    Fix: Remember that the second line sets policy and challenges, while the third line, internal audit, gives independent assurance to the board.

  • Treating operational resilience as the same as business continuity planning.

    Fix: Think of resilience as broader: critical services, impact tolerance, dependencies and testing, not only recovery plans.

  • Thinking loss data alone gives a full picture of operational risk.

    Fix: Remember that loss data is backward looking and incomplete for rare events, so it is paired with scenarios and indicators.

  • Skipping the capital topic because it seems technical.

    Fix: Learn the main capital idea and its drivers as GARP presents them, so you can answer direct questions.

Last-day revision: Introduction to Operational Risk and Resilience

  • Operational risk is loss from inadequate or failed processes, people and systems, or external events.
  • The Basel definition includes legal risk but excludes strategic and reputational risk.
  • Know the Basel event types and match each to a short example.
  • Internal fraud involves staff; external fraud involves outsiders.
  • First line owns and manages risk; second line oversees and challenges; third line gives independent assurance.
  • Internal audit is the third line and does not manage day-to-day risk.
  • Risk and control self-assessment, key risk indicators, loss data and scenario analysis are core tools.
  • Loss data looks backward; scenario analysis looks forward but is judgmental.
  • Operational resilience focuses on delivering critical services through disruption, not only on avoiding loss.
  • Impact tolerance is the maximum disruption you can accept for a critical service.
  • Operational risk capital is part of the Basel regulatory capital framework.
  • In case questions, classify the event first, then pick the control or role.

Introduction to Operational Risk and Resilience practice questions

Introduction to Operational Risk and Resilience in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Introduction to Operational Risk and Resilience: frequently asked questions

Is Introduction to Operational Risk and Resilience calculation heavy?

No. It is mostly conceptual, with questions on definitions, classification, roles and tools. Expect some capital questions, but the focus is on applying ideas to short cases.

How should I order this chapter if I have little time?

Follow the order: definition, event types, governance, framework tools, resilience, then capital. Each step uses the vocabulary from the one before it.

How does this chapter link to Current Issues?

Digital resilience and artificial intelligence are both in the 2026 Current Issues readings. The resilience ideas here give you the base to answer those questions.

Does GARP publish a pass mark for FRM Part II?

No. FRM exams are pass/fail and GARP does not publish a pass mark or pass percentage. Aim to be solid on every topic rather than chasing a target score.