FRM Exam Part II · Risk Identification
Operational Risk Framework and Taxonomy for FRM Part II
Updated 11 October 2026 · Fact-checked
Operational risk is the risk of loss from inadequate or failed internal processes, people and systems, or from external events. Basel includes legal risk but excludes strategic and reputational risk. You solve questions by matching the loss cause to one of seven Basel event types, then checking the framework and risk appetite.
Understand Operational Risk Framework and Taxonomy
Start with the Basel definition. Operational risk is the risk of loss resulting from inadequate or failed internal processes, people and systems, or from external events. The cause matters. A loss counts as operational because of how it arose, not because of its size.
The Basel definition includes legal risk, such as fines, penalties and settlements. It excludes strategic risk and reputational risk. A reputation hit can follow an operational event, but it is not itself the operational loss under this definition. Market risk and credit risk are different: they come from taking positions or lending, while operational risk comes from running the business. A trader who exceeds a limit and hides it creates an operational event (internal fraud), even though the loss shows up in trading P&L.
To organise the many ways things go wrong, Basel gives a taxonomy of seven level 1 event types. Use them as a checklist when identifying risks:
- Internal fraud: intentional misreporting, theft, or bypassing rules by staff.
- External fraud: theft, forgery or hacking by outsiders.
- Employment practices and workplace safety: discrimination claims, pay disputes, unsafe workplaces.
- Clients, products and business practices: mis-selling, breach of fiduciary duty, poor product design, market manipulation.
- Damage to physical assets: fire, flood, terrorism, other disasters.
- Business disruption and system failures: outages, software or telecom failures.
- Execution, delivery and process management: data entry errors, missed deadlines, failed settlement, vendor mistakes.
A framework turns this taxonomy into practice. It sets policies, roles (including the three lines of defense), and tools for identifying, assessing, monitoring and reporting risk. A common taxonomy lets the firm tag every loss event, control and risk the same way, so data can be aggregated across business lines. The risk appetite statement says how much operational risk the board accepts. It is turned into limits, tolerances and indicators, which tell each unit what to identify and escalate.
Key formulas to remember
- Basel definition of operational risk
- Operational risk = loss from inadequate or failed processes, people, systems, or external events
- Includes legal risk. Excludes strategic and reputational risk.
- Seven Basel level 1 event types
- Internal fraud | External fraud | Employment practices and workplace safety | Clients, products and business practices | Damage to physical assets | Business disruption and system failures | Execution, delivery and process management
- Classify by the root cause of the event, not by where the loss appears.
- Taxonomy purpose
- Common taxonomy → consistent tagging → aggregation across business lines
- Consistency is the point. Overlapping or vague categories weaken the data.
- Risk appetite link
- Board appetite → limits and tolerances → indicators and escalation
- Appetite is set by the board and cascaded down. It is not set by the first line alone.
How to solve Operational Risk Framework and Taxonomy questions
Use this sequence for any question that asks you to classify an event, define the risk or link framework to identification.
- 1Read the scenario and find the root cause of the loss, not the line item where it is booked.
- 2Ask if the cause is a process, people, system or external event. If none fits, it may be market, credit, strategic or reputational risk.
- 3Check the exclusions. Strategic and reputational risk are not operational risk under Basel; legal risk is included.
- 4Match the cause to one of the seven event types. Decide if staff acted intentionally (internal fraud) or by error (execution, delivery and process management).
- 5Where the question is about the framework, name the element: taxonomy, risk appetite, governance, tools or reporting.
- 6Check the answer options against the exact Basel wording and discard options that stretch it.
- 7Choose the option that fits both the cause and the definition.
Quickest way: Cause-first triage
When to use it: Use it for MCQs with a short scenario and four event-type or definition options.
- Underline the cause word: fraud, error, outage, disaster, mis-selling, staff dispute.
- Ask: intentional or accidental? Insider or outsider?
- Map to the event type in one step: intentional insider is internal fraud, outsider is external fraud, accident in a process is execution.
- Eliminate any option that is strategic or reputational risk.
- Confirm and move on.
Common mistakes in Operational Risk Framework and Taxonomy
Treating reputational risk as part of Basel operational risk.
Reputation damage often follows operational failures, so the two blur together.
Fix: Remember the definition excludes strategic and reputational risk. Only the direct loss counts.
Excluding legal risk from the definition.
Students link legal risk to compliance rather than loss.
Fix: The Basel definition includes legal risk, such as fines and settlements.
Classifying a rogue trader loss as market risk.
The loss appears in trading P&L, so it looks like a market move.
Fix: Look at the cause. Unauthorised, concealed trading is internal fraud.
Confusing mis-selling with execution errors.
Both involve customers and products.
Fix: Mis-selling or poor product practice is clients, products and business practices. A wrong payment instruction is execution, delivery and process management.
Treating business disruption as the same as damage to physical assets.
A flood may cause both a damaged building and an outage.
Fix: Damage to the asset is physical assets. Loss of service from systems or telecom failure is business disruption and system failures. Split a mixed event by cause.
Thinking risk appetite is a number set by operations staff.
Limits and indicators are used daily by the first line.
Fix: The board approves appetite. Management turns it into limits, tolerances and indicators.
Worked examples
Example 1
A bank's payments clerk keys in USD 2,500,000 instead of USD 250,000 for a client transfer. The bank must cover the USD 2,250,000 difference after the recipient cannot return it. Which Basel event type applies?
Show the solution
- Cause: a data entry mistake in a payment process.
- The mistake was accidental, so it is not fraud.
- No outage or disaster occurred, so it is not business disruption or physical damage.
- Data entry errors fall under execution, delivery and process management.
- The loss amount is USD 2,500,000 − USD 250,000 = USD 2,250,000, which is a direct operational loss.
Answer: Execution, delivery and process management.
Example 2
A bank pays a regulatory fine after selling complex structured notes to retail clients who were not suited to them. The share price also falls on the news. Which part is operational risk loss under the Basel definition, and which event type applies?
Show the solution
- The fine is a legal loss from the bank's own practices, so it is included in operational risk.
- The share price fall is reputational and market reaction, which the definition excludes.
- The cause is unsuitable product sales to clients.
- That matches clients, products and business practices.
Answer: The fine is an operational risk loss, classed as clients, products and business practices. The share price fall is not counted.
Exam tips
- Classify by root cause. Many options are tempting because of where the loss is booked.
- Memorise the include and exclude list: legal included, strategic and reputational excluded.
- Separate intentional from accidental. It decides between fraud and execution errors.
- When a question mentions risk appetite, think board approval, then limits, tolerances and indicators.
- Expect scenarios with two overlapping causes. Pick the primary cause named in the question.
Practice questions from Risk Identification
- A bank scores RCSA risks using inherent risk = likelihood x impact on 1-5 scales. For a process, likelihood is 4 and impact is 5. The key co…
- A bank's operational risk team wants to identify where errors, delays and control gaps could arise in its trade settlement activity. They do…
- Which of the following is the primary reason a firm would supplement its internal loss data with external loss data?
- During a scenario workshop, the first expert estimates a severe fraud loss at USD 40 million, and the senior executives then quickly agree w…
- A risk manager reviews RCSA results across 20 business units and notices that nearly all units rate their controls as 'Effective', yet loss …
Operational Risk Framework and Taxonomy in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Operational Risk Framework and Taxonomy: frequently asked questions
What is the Basel definition of operational risk?
It is the risk of loss from inadequate or failed internal processes, people and systems, or from external events. It includes legal risk. It excludes strategic and reputational risk.
What are the Basel operational risk event types?
There are seven level 1 types: internal fraud, external fraud, employment practices and workplace safety, clients, products and business practices, damage to physical assets, business disruption and system failures, and execution, delivery and process management.
How is operational risk different from market and credit risk?
Market and credit risk arise from positions taken and lending decisions. Operational risk arises from failures in running the business, such as processes, people, systems or outside events. It is not usually taken on for a return.
Why does a firm need a risk taxonomy?
A common taxonomy lets every unit tag events, risks and controls the same way. This makes data comparable and allows aggregation across the firm. It also supports consistent reporting against risk appetite.