FRM Exam Part II · Risk Identification
Key Risk Indicators and Loss Event Data for FRM Part II
Updated 11 October 2026 · Fact-checked
A **key risk indicator (KRI)** is a metric that signals changes in risk exposure or control health before losses occur. **Loss event data** records losses and near misses that already happened. To answer questions, match the tool to the purpose: KRIs warn early, loss data confirms and quantifies, and thresholds trigger action.
Understand Key Risk Indicators and Loss Event Data
Operational risk is hard to see in advance. Two tools help you spot it. One looks forward. The other looks back.
A key risk indicator is a measurable metric that moves when risk exposure or control quality changes. Examples: staff turnover in a settlements team, number of failed trades, system downtime hours, overdue access reviews, number of unreconciled items, or volume of customer complaints. A good KRI is relevant to a specific risk, measurable, timely, and hard to manipulate. It should be easy to collect on a regular schedule.
KRIs are different from key performance indicators (KPIs). A KPI tells you how well you are meeting a business goal, such as revenue per trader. A KRI tells you how likely it is that a goal will be missed or a loss will occur. Some metrics can be both, so judge them by purpose. KRIs are also split into leading indicators (predict future risk, such as overtime hours) and lagging indicators (show what has already happened, such as the number of errors last month). Many programmes also separate control indicators (health of a control, such as percentage of patches applied on time) from risk indicators (level of exposure).
Each KRI needs thresholds. A common design is a traffic-light scale: green means within appetite, amber means early warning and needs review, red means the limit is breached and escalation is required. Thresholds should be linked to risk appetite and tolerance, calibrated using history, expert judgement and peer data, and reviewed regularly. If thresholds are too tight, you get constant false alarms. If they are too loose, they never fire. Every breach needs a named owner and a defined action.
Loss event data is the record of operational losses. Internal loss data comes from your own firm. It is relevant to your processes and controls, but it is usually thin for rare, severe events. External loss data comes from other firms, through consortia or public databases. It covers severe tail events your firm has never had, but it may be biased toward large, reported losses and may not fit your business, so it needs scaling and screening. Near misses are events that could have caused a loss but did not, or where the loss was avoided by luck. They cost nothing to learn from and show control weaknesses before real damage. A sound loss database records the event date, discovery date, accounting date, gross loss, recoveries, business line, event type and root cause. Data should be complete, consistent and reconciled to the general ledger. Use both tools together: loss data shows where losses came from, KRIs track the drivers, and trends in either help identify emerging risks.
Key formulas to remember
- Net loss
- Net loss = Gross loss − Recoveries
- Record both. Gross loss is the amount before any recovery, including insurance. Recoveries are tracked separately.
- Traffic-light KRI rule
- Green: value within appetite | Amber: value ≥ early-warning threshold | Red: value ≥ limit
- For metrics where higher is worse. Reverse the inequalities when lower is worse, for example the percentage of controls tested on time.
- KRI versus KPI test
- KPI: performance against a goal | KRI: exposure to risk of missing it or losing
- Classify by purpose, not by the metric name.
- Leading versus lagging
- Leading = predicts future risk | Lagging = reports past outcomes
- Loss counts are lagging. Staff vacancies or backlog sizes are usually leading.
- Rate-based KRI
- KRI rate = number of exceptions ÷ total volume
- Use rates rather than raw counts when volumes change, so trends are comparable.
How to solve Key Risk Indicators and Loss Event Data questions
Use this method on any KRI or loss data question.
- 1Identify what the question asks: choosing a KRI, setting a threshold, reading a breach, or judging data sources.
- 2Name the risk and its driver. A KRI must link to a specific risk or control.
- 3Decide if the metric is leading or lagging, a risk or control indicator, and a KRI or KPI.
- 4For thresholds, tie them to risk appetite, use history and expert judgement, and set amber before red.
- 5For loss data, decide if internal, external, or near miss data fits. Consider relevance, completeness and bias.
- 6State the action: escalate, assign an owner, investigate root cause, or recalibrate.
- 7Check the answer against the stem. Pick the option that is timely, measurable and actionable.
Quickest way: Purpose-matching shortcut
When to use it: Use when you have about a minute per question and the options look similar.
- Ask: does it warn early (KRI, leading) or confirm after (loss data, lagging)?
- If the stem says rare severe events, think external data.
- If the stem says firm-specific control weakness, think internal data and near misses.
- If the stem says thresholds, look for amber before red, owner and escalation.
- Eliminate options that treat a performance metric as risk or that rely on raw counts when volumes changed.
Common mistakes in Key Risk Indicators and Loss Event Data
Treating KRIs and KPIs as the same thing
Both are metrics reported monthly and some overlap.
Fix: Ask what the metric tells you. Goal achievement is a KPI. Exposure to failure or loss is a KRI.
Calling loss data a leading indicator
Loss data feels informative about the future.
Fix: Loss data is lagging because it records past events. It informs models and trends, but it does not warn in real time.
Using only internal data for tail risk
Internal data is accurate and familiar.
Fix: Internal data has few severe events. Add external data and scenarios, with scaling and relevance checks.
Ignoring near misses
No loss means no event in the database.
Fix: Near misses show control failures without cost. Capture them and analyse root causes.
Setting thresholds with no link to risk appetite
Teams pick round numbers or copy peers.
Fix: Anchor thresholds to appetite and tolerance, test against history, and add amber before red with defined actions.
Using raw counts when volumes change
Counts are simple to collect.
Fix: Use rates, such as failed trades per 1,000 trades, so a busy month does not look like deterioration.
Worked examples
Example 1
A bank's settlement team reports failed trades. In March there were 45 failed trades out of 30,000. In April there were 60 failed trades out of 50,000. The amber threshold is a fail rate of 0.15% and red is 0.25%. What is the April status and what does the trend show?
Show the solution
- March rate = 45 ÷ 30,000 = 0.15%.
- April rate = 60 ÷ 50,000 = 0.12%.
- March sits at the amber threshold (0.15%). April is below 0.15%, so it is green.
- The raw count rose from 45 to 60, but volume rose faster, so the rate improved.
- Judge the KRI by the rate, not the count.
Answer: April is green at 0.12%, down from 0.15% in March. The rise in raw count is a volume effect.
Example 2
A risk manager at a global bank wants to estimate exposure to a rare, severe fraud event. Internal data show only two small fraud losses in ten years. Which data should be added and what precaution is needed?
Show the solution
- Two small losses are too few to describe the tail.
- External loss data from industry consortia or public databases include severe events at other firms.
- External data may be biased toward large publicly reported losses and may not match your business size or controls.
- So screen events for relevance and scale them to your firm before use.
- Also use scenario analysis and capture near misses internally.
Answer: Add external loss data, screened for relevance and scaled to the bank, supported by scenarios and internal near misses.
Exam tips
- Read the stem for time: early warning points to KRIs, past events point to loss data.
- Watch for rates versus counts. Volume changes often hide the real trend.
- Expect questions on external data bias and the need to scale it.
- Remember that a good threshold set has amber and red levels, an owner and an escalation path.
- Near misses are valid data. Options that dismiss them are usually wrong.
Practice questions from Risk Identification
- A bank defines operational risk as the risk of loss resulting from inadequate or failed internal processes, people and systems, or from exte…
- An operational risk analyst builds an internal loss database. A fraud event is discovered in 2024, but the fraudulent activity occurred in 2…
- An operational risk manager wants to identify emerging risks that may not yet appear in the bank's loss data or risk taxonomy. Which approac…
- A bank's RCSA scores likelihood and impact on a 1-5 scale and multiplies them to give an inherent score. A control is rated as reducing the …
- A bank is launching a new retail payments product within three months under tight timelines. The head of operational risk asks that a risk a…
Key Risk Indicators and Loss Event Data: frequently asked questions
What is the difference between a KRI and a KPI?
A KPI measures performance against a business goal. A KRI measures exposure to risk or control weakness that could cause a loss or missed goal. The same figure can serve both roles, so classify it by what the decision-maker uses it for.
How do you set KRI thresholds?
Start from risk appetite and tolerance. Use historical data, expert judgement and peer comparison to place an amber early-warning level and a red limit. Assign owners and actions to each breach and review thresholds regularly to avoid false alarms or blind spots.
What is the difference between internal and external loss data?
Internal loss data comes from your own firm and reflects your controls but has few severe events. External data comes from other institutions and fills the tail, but may be biased and needs scaling and relevance checks.
Why are near misses important?
Near misses show control weaknesses without the cost of an actual loss. Capturing them gives more data points for root cause analysis and helps spot emerging risks earlier.