FRM Part II · FRM Exam Part II
Risk Identification for FRM Part II: Chapter Guide
Risk Identification is the Operational Risk and Resilience chapter on finding and describing risks before you measure them. You learn the taxonomy, RCSA, scenario analysis, stress testing, key risk indicators, loss event data, process mapping and emerging risk tools. Exam questions ask you to choose the right tool for a case and interpret its output.
What this chapter covers
This chapter sits in the Operational Risk and Resilience topic of FRM Part II. It covers how a firm finds its operational risks and describes them in a consistent way. You start with a framework and taxonomy, then move through the main identification tools: risk and control self-assessment (RCSA), scenario analysis and stress testing, key risk indicators (KRIs), loss event data, process mapping, and ways to spot change-related and emerging risks.
The tools fall into two groups. Some look backward, like internal and external loss event data. Others look forward, like scenarios, KRIs and emerging risk reviews. RCSA and process mapping sit in between, because they rely on staff judgement about current processes and controls. Exam questions often test whether you can match the tool to the situation and explain its strength and its weakness.
The chapter connects to the rest of the paper in three ways. Identified risks feed later work on measurement, capital and mitigation within operational risk. The same ideas of scenarios and stress testing appear in market, credit and liquidity risk. Newer risks such as AI, cyber, third-party dependence and digital resilience link to the Current Issues readings. Read this chapter as the base for those areas.
The paper has 80 equally weighted multiple-choice questions in 4 hours, and many are applied cases. Risk identification questions are usually conceptual and reward precise judgement: which tool fits, what a result means, what a weakness is. That makes them reliable marks if your definitions are clean. Weak candidates blur RCSA, KRIs and scenarios together and lose easy questions. Time spent here also improves your answers in other operational risk chapters and in Current Issues, because the vocabulary is shared.
Risk Identification: topics in the order to study them
- 1Operational Risk Framework and TaxonomyStart here because every other tool uses its definitions, categories and common language.
- 2Risk and Control Self-Assessment (RCSA)It is the core internal tool for identifying risks and judging controls, so it comes straight after the taxonomy it relies on.
- 3Key Risk Indicators and Loss Event DataStudy the data-based tools next to see how RCSA judgements are checked against metrics and actual losses.
- 4Scenario Analysis and Stress TestingScenarios extend past experience and fill gaps in loss data, so they make most sense once you know the data limits.
- 5Process Mapping, Change and Emerging Risk IdentificationFinish with the forward-looking and process-level methods, which pull the earlier tools together in case-style questions.
How to prepare Risk Identification
Aim to know what each tool is for, how it works, what it gives you and where it fails. Build this chapter as a comparison, not as separate lists.
- Read the taxonomy topic first and write a one-line definition for each main risk category and event type you meet.
- For each tool, note four things: purpose, inputs, output and main limitation.
- Build a one-page comparison of RCSA, scenarios, KRIs, loss data and process mapping, marking each as backward or forward looking.
- Practise short case questions. Read the situation, name the best tool, then say why the others fit less well.
- Learn the typical weaknesses: subjectivity and bias in RCSA, thin data for tail events, poor thresholds for KRIs, and gaps in scenario design.
- Link each emerging risk, such as AI, cyber, third-party dependence and change programmes, to the tool most likely used to spot it.
- In the last week, redo missed questions and reread your comparison sheet until you can recite it without notes.
Common mistakes in Risk Identification
Treating RCSA, KRIs and scenario analysis as interchangeable.
Fix: Remember the core idea: RCSA is judgement on risks and controls, KRIs are monitored metrics with thresholds, scenarios are structured what-if events.
Assuming loss event data gives a full view of risk.
Fix: State that it is backward looking and sparse for severe, rare events, so it needs scenarios and external data alongside it.
Picking a KRI answer that is a lagging outcome rather than a leading signal.
Fix: Ask whether the metric would move before a loss occurs. If it only reports losses after the fact, it is not a good KRI.
Ignoring bias and subjectivity in self-assessments.
Fix: Link RCSA to challenge, review by the risk function and comparison with data to reduce bias.
Skipping emerging and change risks as soft content.
Fix: Study them with cases. Link new technology, third parties and change programmes to the tools used to detect them.
Memorising lists without being able to apply them.
Fix: Practise short cases and always name the tool, the reason it fits and its limitation.
Last-day revision: Risk Identification
- Risk identification comes before measurement: you cannot assess a risk you have not found.
- A common taxonomy gives consistent language so risks can be compared and aggregated across the firm.
- RCSA relies on staff judgement about risks and controls, so it is exposed to bias and optimism.
- RCSA looks at inherent risk, control effectiveness and residual risk.
- Scenario analysis explores severe but plausible events, including ones that have not happened to the firm.
- Stress testing applies extreme conditions to see the effect on the firm.
- KRIs are forward-looking metrics with thresholds that trigger escalation when breached.
- A good KRI is measurable, predictive and tied to a specific risk or control.
- Loss event data is backward looking and has few observations for rare, severe events.
- External loss data helps cover events the firm has not yet experienced.
- Process mapping shows where steps, handoffs and dependencies create risk or control gaps.
- Change and new products bring new risks, so review them before launch and after.
Risk Identification practice questions
- Which of the following is the best example of a risk that falls within the commonly used definition of operational risk, which covers losses…
- A bank runs a stress test for operational risk that assumes a severe economic downturn. Which feature distinguishes this stress test from a …
- A bank sets a KRI for failed trade settlements with a green threshold below 20 fails per week, amber from 20 to 39, and red at 40 or more. W…
- A bank sets a KRI for failed trade settlements with a green threshold below 20 per month, an amber trigger at 20 to 39, and a red limit at 4…
- A bank's RCSA scores likelihood and impact each on a 1-5 scale, and the risk score is likelihood times impact. Controls reduce the score by …
- A bank's operational risk team is preparing to run scenario analysis workshops to identify severe but plausible loss events. Which of the fo…
- During a scenario workshop at a regional bank, business managers estimate the loss from a major payment system outage. The facilitator notic…
- A risk manager is deciding how to structure an operational risk framework around cause, event and effect. A hacker exploits an unpatched ser…
Risk Identification in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Risk Identification: frequently asked questions
What does the Risk Identification chapter cover in FRM Part II?
It sits in Operational Risk and Resilience. It covers the framework and taxonomy, RCSA, scenario analysis and stress testing, KRIs, loss event data, process mapping, and change and emerging risk identification.
Is this chapter calculation heavy?
No. It is mostly conceptual and applied. Expect questions that ask you to choose a tool, interpret an output or spot a weakness rather than long calculations.
How should I study this chapter if I am short of time?
Learn the taxonomy, then build a comparison of the identification tools covering purpose, output and limitation. Practise case questions on choosing the right tool.
How does this chapter link to Current Issues?
Emerging risks such as artificial intelligence, crypto and digital assets, and digital resilience are operational risk themes. The identification tools here are how firms would detect and assess them.