Skip to content

FRM Exam Part II · Risk Governance

Operational Risk Governance Framework for FRM Part II

Updated 11 October 2026 · Fact-checked

Operational risk governance is the structure of roles, committees, policies and culture that sets how a bank manages operational risk. The board approves the framework and risk appetite, senior management implements it, and the three lines of defense share the work. To answer questions, match each duty to the right body.

Understand Operational Risk Governance Framework

Operational risk is the risk of loss from inadequate or failed internal processes, people and systems, or from external events. Governance decides who owns that risk, who oversees it and who challenges it. Without clear ownership, controls drift and losses go unseen.

The board of directors sits at the top. It approves the operational risk framework, sets or approves the risk appetite and tolerance, and reviews the framework regularly. It does not run daily controls. It holds senior management to account and makes sure resources are adequate.

Senior management turns board direction into action. It develops clear policies, processes and systems, assigns responsibility and reporting lines, and makes sure the framework is applied consistently across the whole firm. It also ensures staff are competent and that incentives do not reward ignoring controls.

Most banks use the three lines of defense. The first line is business units, which own and manage the risks they create. The second line is an independent operational risk function that designs the framework, sets methods, monitors and challenges. The third line is internal audit, which independently assures that the framework works. Committees, such as a board risk committee and an executive operational risk committee, bring these groups together to review exposures, losses and action plans.

Risk culture is the shared attitude to risk and controls. A good culture shows in tone from the top, open reporting of incidents and pay that does not reward excess risk-taking. Policies put the framework in writing: definitions, taxonomy, roles, escalation rules and reporting requirements. Culture and policy together decide whether the structure works in practice.

How to solve Operational Risk Governance Framework questions

Governance questions are about assigning the right duty to the right party. Use this method on any scenario.

  1. 1Identify the failure or requirement in the question: weak oversight, unclear ownership, poor culture, missing policy or no independent challenge.
  2. 2Decide which level is involved: board, senior management, first line, second line or third line.
  3. 3Recall that board approves and oversees, management implements, first line owns risk, second line challenges, third line assures.
  4. 4Check whether the proposed action would break independence, for example the second line owning a business control or audit designing the framework.
  5. 5Look for culture signals such as tone from the top, incentives and incident reporting.
  6. 6Eliminate options that give the board day-to-day tasks or leave management with no accountability.
  7. 7Choose the option that fits the roles most precisely and matches the stated problem.

Quickest way: Role-matching shortcut

When to use it: Use when the question asks who is responsible for a duty or which option is the best governance fix.

  1. Underline the verb: approve, implement, own, challenge or assure.
  2. Map it: approve = board, implement = senior management, own = first line, challenge = second line, assure = third line.
  3. Pick the option that matches the verb and keeps lines independent.
  4. Reject any option that mixes two lines or pushes execution to the board.

Common mistakes in Operational Risk Governance Framework

  • Giving the board responsibility for daily operational controls.

    Students read 'ultimate responsibility' as 'hands-on responsibility'.

    Fix: Remember the board approves and oversees. Management runs the framework day to day.

  • Saying the operational risk function owns the risks.

    The name suggests it manages all operational risk.

    Fix: The first line owns and manages risk. The second line designs the framework and challenges.

  • Treating internal audit as part of daily risk management.

    Audit reviews controls, so it looks like a control function.

    Fix: Audit is the third line. It gives independent assurance and does not design or operate controls.

  • Treating risk culture as a soft topic with no governance link.

    Culture is hard to measure, so students skip it.

    Fix: Link culture to tone from the top, incentives and escalation. Exam cases often trace losses to culture failures.

  • Assuming a written policy alone proves good governance.

    Students equate documentation with practice.

    Fix: Look for evidence of implementation: reporting, monitoring, accountability and board review.

Worked examples

Example 1

A bank's business units say operational risk is the job of the central risk team, and they do not log incidents. Which governance weakness is this, and what is the best fix?
A. Weak third line; expand internal audit
B. First line not owning its risks; reinforce business-unit ownership and incident reporting
C. Board overreach; reduce board involvement
D. Excess policy detail; shorten the policies

Show the solution
  1. The problem is that business units deny ownership and do not report incidents.
  2. Ownership of risk belongs to the first line.
  3. The fix must address ownership and reporting inside the business units.
  4. Option A addresses assurance, not ownership. Option C and D do not match the facts.

Answer: B

Example 2

Which duty is most appropriately assigned to the board rather than senior management?
A. Approving the operational risk framework and risk appetite
B. Running daily loss data collection
C. Performing control self-assessments in each unit
D. Writing detailed process procedures

Show the solution
  1. Board duties are approval and oversight.
  2. Loss data collection, self-assessments and procedures are executed by management and business units.
  3. Only approving the framework and appetite is an approval duty.

Answer: A

Exam tips

  • Memorize the verb map: approve, implement, own, challenge, assure.
  • Expect case questions where a loss traces back to culture or unclear ownership; pick the governance fix, not a technical one.
  • Watch for options that break independence between lines.
  • Know that risk appetite is approved by the board and cascaded by management.
  • Use precise Basel-style wording: sound practice expects a documented, board-approved framework.

Practice questions from Risk Governance

Operational Risk Governance Framework in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Operational Risk Governance Framework: frequently asked questions

What is the board's role in operational risk governance?

The board approves the operational risk framework and risk appetite, and reviews them regularly. It oversees senior management and ensures resources are adequate. It does not run daily controls.

What is the difference between the second and third lines of defense?

The second line is an independent risk function that designs the framework, monitors and challenges the first line. The third line, internal audit, independently assures that the whole framework works.

Why does risk culture matter for governance?

Policies only work if people follow them and report problems. Tone from the top, sensible incentives and open escalation make the structure effective in practice.

Does governance include committees?

Yes. Board risk committees and executive operational risk committees review exposures, losses and action plans. They bring oversight and management together in a formal setting.