FRM Exam Part II · Introduction to Operational Risk and Resilience
Operational Risk Event Types and the Basel Taxonomy
Updated 11 October 2026 · Fact-checked
The Basel taxonomy classifies operational losses into seven event types: internal fraud, external fraud, employment practices and workplace safety, clients products and business practices, damage to physical assets, business disruption and system failures, and execution delivery and process management. Match the cause and the actor in the scenario to one category.
Understand Operational Risk Event Types and Taxonomy
Operational risk is the risk of loss from inadequate or failed internal processes, people and systems, or from external events. Basel II definition includes legal risk but excludes strategic and reputational risk. To manage it, a bank needs a common language. A taxonomy gives that language.
Basel splits losses by event type, meaning what went wrong. There are seven. Each loss event goes to exactly one event type, based on its root cause. This lets a bank compare losses across desks, countries and years, and pool data with other banks.
The seven are: internal fraud (staff or insiders acting to defraud, misappropriate property or break rules, with at least one internal party); external fraud (third parties acting to defraud, such as theft, forgery or hacking); employment practices and workplace safety (discrimination, wrongful dismissal, unsafe conditions); clients, products and business practices (mis-selling, breach of fiduciary duty, improper trade or market practices, suitability failures); damage to physical assets (natural disasters, terrorism, vandalism); business disruption and system failures (hardware, software, telecom or utility outages); and execution, delivery and process management (data entry errors, missed deadlines, failed settlement, vendor disputes).
Basel also defines eight business lines for classifying where a loss occurred: corporate finance, trading and sales, retail banking, commercial banking, payment and settlement, agency services, asset management and retail brokerage. Together, the event type and business line form a grid. Each loss sits in one cell.
The key skill is separating the actor from the cause. A rogue trader hiding losses is internal fraud. A hacker stealing card data is external fraud. A staff member mistyping a trade amount is execution, delivery and process management, not fraud, because there was no intent.
Key formulas to remember
- Operational risk definition (Basel)
- Loss from inadequate or failed internal processes, people and systems, or from external events
- Includes legal risk. Excludes strategic and reputational risk.
- Seven event types
- Internal fraud | External fraud | Employment practices and workplace safety | Clients, products and business practices | Damage to physical assets | Business disruption and system failures | Execution, delivery and process management
- Memorise all seven in this form. Each loss is mapped by root cause.
- Eight business lines
- Corporate finance | Trading and sales | Retail banking | Commercial banking | Payment and settlement | Agency services | Asset management | Retail brokerage
- Used to record where the loss arose. One loss maps to one business line and one event type.
- Loss grid
- Number of cells = 8 business lines × 7 event types = 56
- Each cell holds frequency and severity data for that combination.
How to solve Operational Risk Event Types and Taxonomy questions
Use this sequence for any classification question on event types or business lines.
- 1Read the scenario and identify what actually happened and who caused it.
- 2Ask: was there intent to deceive or steal? If no, rule out both fraud categories.
- 3If there is intent, ask who acted. Any insider involved means internal fraud. Only outsiders means external fraud.
- 4If there is no intent, match the failure: people and employment law issues, product or client conduct, physical damage, technology outage, or process error.
- 5Check for keywords: mis-selling and suitability point to clients, products and business practices. Settlement or data entry errors point to execution, delivery and process management.
- 6Identify the business line from the activity: trading desk, retail branch, custody, advisory and so on.
- 7Choose the root cause, not the consequence. A fire causing an outage is damage to physical assets.
- 8State the event type and business line, and add one line of reasoning.
Quickest way: Intent, actor, then failure type
When to use it: Use when you have about a minute per question and the options list several event types.
- Intent? Yes means fraud. Pick internal if an employee is involved, else external.
- No intent: employee welfare or discrimination means employment practices.
- Client harm, mis-selling or fiduciary breach means clients, products and business practices.
- Physical event such as flood or terrorism means damage to physical assets.
- IT or utility outage means business disruption and system failures.
- Human error in a routine process means execution, delivery and process management.
Common mistakes in Operational Risk Event Types and Taxonomy
Classifying an employee's accidental error as internal fraud
The word internal and an employee involvement trigger the fraud label.
Fix: Fraud needs intent to deceive or misappropriate. Accidental errors belong to execution, delivery and process management.
Putting mis-selling under execution, delivery and process management
Students see a failure in handling a transaction and assume process error.
Fix: If the harm comes from improper product advice or suitability failures toward clients, use clients, products and business practices.
Treating a cyberattack that takes systems offline as business disruption only
The visible effect is an outage.
Fix: Classify by root cause. A hack by outsiders aiming to steal is external fraud. A non-malicious system crash is business disruption and system failures.
Including reputational and strategic risk in the operational risk definition
Everyday usage of operational risk is broad.
Fix: The Basel definition includes legal risk but excludes strategic and reputational risk.
Mixing up event types with business lines
Both are lists used to label losses.
Fix: Event type is what went wrong. Business line is where it happened. Every loss needs both.
Mapping one loss to several event types
Many incidents have several contributing causes.
Fix: Choose the primary root cause so the loss is recorded once and data is not double counted.
Worked examples
Example 1
A trader at a global bank books fictitious trades to hide losses, exceeding his limits for months. The bank loses USD 50 million when discovered. Classify by Basel event type and business line.
Show the solution
- Intent: he deliberately hid losses, so this is fraud.
- Actor: an employee, so an insider is involved. This is internal fraud.
- Activity: trading on the bank's own account falls under trading and sales.
- Root cause is the unauthorised and concealed activity, not the market move itself.
Answer: Internal fraud, in the trading and sales business line.
Example 2
A retail bank sells a complex structured product to elderly savers who need capital safety. Regulators fine the bank EUR 20 million for unsuitable sales. Another event: a clerk keys EUR 1,00,000 instead of EUR 10,000 in a payment and the bank cannot recover the excess. Classify each loss.
Show the solution
- First event: harm to clients from unsuitable product sales is a conduct issue.
- It maps to clients, products and business practices, and the business line is retail banking.
- Second event: no intent, just a data entry error in a payment.
- Data entry errors map to execution, delivery and process management.
- The business line is payment and settlement, since the loss arose in processing a payment.
Answer: Fine: clients, products and business practices (retail banking). Keying error: execution, delivery and process management (payment and settlement).
Exam tips
- Expect short scenarios with four event types as options. Decide on intent and actor first.
- Watch for traps where the effect (outage, fine) differs from the root cause.
- Remember the Basel definition excludes strategic and reputational risk but includes legal risk.
- Know both lists by heart: seven event types and eight business lines.
- If an item is a data or process slip without intent, never choose fraud.
Practice questions from Introduction to Operational Risk and Resilience
- A bank's operational loss data show 40 events in a year. Of these, 10 are boundary events with market risk, and the bank's policy counts bou…
- A bank's fraud team discovers that a branch employee created fictitious customer accounts and diverted funds into them over two years. Under…
- Under the Basel III finalised framework, which approach is the only one banks use to calculate minimum regulatory capital for operational ri…
- Under the three lines model commonly used in operational risk governance, which activity belongs to the second line?
- Under the Basel definition used in operational risk frameworks, operational risk is the risk of loss resulting from inadequate or failed int…
Operational Risk Event Types and Taxonomy in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Operational Risk Event Types and Taxonomy: frequently asked questions
What are the seven Basel operational risk event types?
They are internal fraud, external fraud, employment practices and workplace safety, clients, products and business practices, damage to physical assets, business disruption and system failures, and execution, delivery and process management. Each loss is mapped to one by root cause.
What is the difference between internal and external fraud?
Internal fraud involves at least one insider, such as an employee hiding losses or stealing funds. External fraud is committed by third parties, such as forgery, card theft or hacking. Intent is needed in both.
How many business lines does Basel use?
Basel uses eight business lines: corporate finance, trading and sales, retail banking, commercial banking, payment and settlement, agency services, asset management and retail brokerage. They show where a loss arose.
Why does a bank need an operational risk taxonomy?
A taxonomy gives consistent labels so losses, risk assessments and controls can be compared across units and over time. It also supports loss data collection and reporting to regulators.