Skip to content

FRM Exam Part II · Introduction to Operational Risk and Resilience

Operational Risk Event Types and the Basel Taxonomy

Updated 11 October 2026 · Fact-checked

The Basel taxonomy classifies operational losses into seven event types: internal fraud, external fraud, employment practices and workplace safety, clients products and business practices, damage to physical assets, business disruption and system failures, and execution delivery and process management. Match the cause and the actor in the scenario to one category.

Understand Operational Risk Event Types and Taxonomy

Operational risk is the risk of loss from inadequate or failed internal processes, people and systems, or from external events. Basel II definition includes legal risk but excludes strategic and reputational risk. To manage it, a bank needs a common language. A taxonomy gives that language.

Basel splits losses by event type, meaning what went wrong. There are seven. Each loss event goes to exactly one event type, based on its root cause. This lets a bank compare losses across desks, countries and years, and pool data with other banks.

The seven are: internal fraud (staff or insiders acting to defraud, misappropriate property or break rules, with at least one internal party); external fraud (third parties acting to defraud, such as theft, forgery or hacking); employment practices and workplace safety (discrimination, wrongful dismissal, unsafe conditions); clients, products and business practices (mis-selling, breach of fiduciary duty, improper trade or market practices, suitability failures); damage to physical assets (natural disasters, terrorism, vandalism); business disruption and system failures (hardware, software, telecom or utility outages); and execution, delivery and process management (data entry errors, missed deadlines, failed settlement, vendor disputes).

Basel also defines eight business lines for classifying where a loss occurred: corporate finance, trading and sales, retail banking, commercial banking, payment and settlement, agency services, asset management and retail brokerage. Together, the event type and business line form a grid. Each loss sits in one cell.

The key skill is separating the actor from the cause. A rogue trader hiding losses is internal fraud. A hacker stealing card data is external fraud. A staff member mistyping a trade amount is execution, delivery and process management, not fraud, because there was no intent.

Key formulas to remember

Operational risk definition (Basel)
Loss from inadequate or failed internal processes, people and systems, or from external events
Includes legal risk. Excludes strategic and reputational risk.
Seven event types
Internal fraud | External fraud | Employment practices and workplace safety | Clients, products and business practices | Damage to physical assets | Business disruption and system failures | Execution, delivery and process management
Memorise all seven in this form. Each loss is mapped by root cause.
Eight business lines
Corporate finance | Trading and sales | Retail banking | Commercial banking | Payment and settlement | Agency services | Asset management | Retail brokerage
Used to record where the loss arose. One loss maps to one business line and one event type.
Loss grid
Number of cells = 8 business lines × 7 event types = 56
Each cell holds frequency and severity data for that combination.

How to solve Operational Risk Event Types and Taxonomy questions

Use this sequence for any classification question on event types or business lines.

  1. 1Read the scenario and identify what actually happened and who caused it.
  2. 2Ask: was there intent to deceive or steal? If no, rule out both fraud categories.
  3. 3If there is intent, ask who acted. Any insider involved means internal fraud. Only outsiders means external fraud.
  4. 4If there is no intent, match the failure: people and employment law issues, product or client conduct, physical damage, technology outage, or process error.
  5. 5Check for keywords: mis-selling and suitability point to clients, products and business practices. Settlement or data entry errors point to execution, delivery and process management.
  6. 6Identify the business line from the activity: trading desk, retail branch, custody, advisory and so on.
  7. 7Choose the root cause, not the consequence. A fire causing an outage is damage to physical assets.
  8. 8State the event type and business line, and add one line of reasoning.

Quickest way: Intent, actor, then failure type

When to use it: Use when you have about a minute per question and the options list several event types.

  1. Intent? Yes means fraud. Pick internal if an employee is involved, else external.
  2. No intent: employee welfare or discrimination means employment practices.
  3. Client harm, mis-selling or fiduciary breach means clients, products and business practices.
  4. Physical event such as flood or terrorism means damage to physical assets.
  5. IT or utility outage means business disruption and system failures.
  6. Human error in a routine process means execution, delivery and process management.

Common mistakes in Operational Risk Event Types and Taxonomy

  • Classifying an employee's accidental error as internal fraud

    The word internal and an employee involvement trigger the fraud label.

    Fix: Fraud needs intent to deceive or misappropriate. Accidental errors belong to execution, delivery and process management.

  • Putting mis-selling under execution, delivery and process management

    Students see a failure in handling a transaction and assume process error.

    Fix: If the harm comes from improper product advice or suitability failures toward clients, use clients, products and business practices.

  • Treating a cyberattack that takes systems offline as business disruption only

    The visible effect is an outage.

    Fix: Classify by root cause. A hack by outsiders aiming to steal is external fraud. A non-malicious system crash is business disruption and system failures.

  • Including reputational and strategic risk in the operational risk definition

    Everyday usage of operational risk is broad.

    Fix: The Basel definition includes legal risk but excludes strategic and reputational risk.

  • Mixing up event types with business lines

    Both are lists used to label losses.

    Fix: Event type is what went wrong. Business line is where it happened. Every loss needs both.

  • Mapping one loss to several event types

    Many incidents have several contributing causes.

    Fix: Choose the primary root cause so the loss is recorded once and data is not double counted.

Worked examples

Example 1

A trader at a global bank books fictitious trades to hide losses, exceeding his limits for months. The bank loses USD 50 million when discovered. Classify by Basel event type and business line.

Show the solution
  1. Intent: he deliberately hid losses, so this is fraud.
  2. Actor: an employee, so an insider is involved. This is internal fraud.
  3. Activity: trading on the bank's own account falls under trading and sales.
  4. Root cause is the unauthorised and concealed activity, not the market move itself.

Answer: Internal fraud, in the trading and sales business line.

Example 2

A retail bank sells a complex structured product to elderly savers who need capital safety. Regulators fine the bank EUR 20 million for unsuitable sales. Another event: a clerk keys EUR 1,00,000 instead of EUR 10,000 in a payment and the bank cannot recover the excess. Classify each loss.

Show the solution
  1. First event: harm to clients from unsuitable product sales is a conduct issue.
  2. It maps to clients, products and business practices, and the business line is retail banking.
  3. Second event: no intent, just a data entry error in a payment.
  4. Data entry errors map to execution, delivery and process management.
  5. The business line is payment and settlement, since the loss arose in processing a payment.

Answer: Fine: clients, products and business practices (retail banking). Keying error: execution, delivery and process management (payment and settlement).

Exam tips

  • Expect short scenarios with four event types as options. Decide on intent and actor first.
  • Watch for traps where the effect (outage, fine) differs from the root cause.
  • Remember the Basel definition excludes strategic and reputational risk but includes legal risk.
  • Know both lists by heart: seven event types and eight business lines.
  • If an item is a data or process slip without intent, never choose fraud.

Practice questions from Introduction to Operational Risk and Resilience

Operational Risk Event Types and Taxonomy in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Operational Risk Event Types and Taxonomy: frequently asked questions

What are the seven Basel operational risk event types?

They are internal fraud, external fraud, employment practices and workplace safety, clients, products and business practices, damage to physical assets, business disruption and system failures, and execution, delivery and process management. Each loss is mapped to one by root cause.

What is the difference between internal and external fraud?

Internal fraud involves at least one insider, such as an employee hiding losses or stealing funds. External fraud is committed by third parties, such as forgery, card theft or hacking. Intent is needed in both.

How many business lines does Basel use?

Basel uses eight business lines: corporate finance, trading and sales, retail banking, commercial banking, payment and settlement, agency services, asset management and retail brokerage. They show where a loss arose.

Why does a bank need an operational risk taxonomy?

A taxonomy gives consistent labels so losses, risk assessments and controls can be compared across units and over time. It also supports loss data collection and reporting to regulators.