Skip to content

FRM Exam Part II · Risk Identification

Operational Risk Framework and Taxonomy for FRM Part II

Updated 11 October 2026 · Fact-checked

Operational risk is the risk of loss from inadequate or failed internal processes, people and systems, or from external events. Basel includes legal risk but excludes strategic and reputational risk. You solve questions by matching the loss cause to one of seven Basel event types, then checking the framework and risk appetite.

Understand Operational Risk Framework and Taxonomy

Start with the Basel definition. Operational risk is the risk of loss resulting from inadequate or failed internal processes, people and systems, or from external events. The cause matters. A loss counts as operational because of how it arose, not because of its size.

The Basel definition includes legal risk, such as fines, penalties and settlements. It excludes strategic risk and reputational risk. A reputation hit can follow an operational event, but it is not itself the operational loss under this definition. Market risk and credit risk are different: they come from taking positions or lending, while operational risk comes from running the business. A trader who exceeds a limit and hides it creates an operational event (internal fraud), even though the loss shows up in trading P&L.

To organise the many ways things go wrong, Basel gives a taxonomy of seven level 1 event types. Use them as a checklist when identifying risks:

  • Internal fraud: intentional misreporting, theft, or bypassing rules by staff.
  • External fraud: theft, forgery or hacking by outsiders.
  • Employment practices and workplace safety: discrimination claims, pay disputes, unsafe workplaces.
  • Clients, products and business practices: mis-selling, breach of fiduciary duty, poor product design, market manipulation.
  • Damage to physical assets: fire, flood, terrorism, other disasters.
  • Business disruption and system failures: outages, software or telecom failures.
  • Execution, delivery and process management: data entry errors, missed deadlines, failed settlement, vendor mistakes.

A framework turns this taxonomy into practice. It sets policies, roles (including the three lines of defense), and tools for identifying, assessing, monitoring and reporting risk. A common taxonomy lets the firm tag every loss event, control and risk the same way, so data can be aggregated across business lines. The risk appetite statement says how much operational risk the board accepts. It is turned into limits, tolerances and indicators, which tell each unit what to identify and escalate.

Key formulas to remember

Basel definition of operational risk
Operational risk = loss from inadequate or failed processes, people, systems, or external events
Includes legal risk. Excludes strategic and reputational risk.
Seven Basel level 1 event types
Internal fraud | External fraud | Employment practices and workplace safety | Clients, products and business practices | Damage to physical assets | Business disruption and system failures | Execution, delivery and process management
Classify by the root cause of the event, not by where the loss appears.
Taxonomy purpose
Common taxonomy → consistent tagging → aggregation across business lines
Consistency is the point. Overlapping or vague categories weaken the data.
Risk appetite link
Board appetite → limits and tolerances → indicators and escalation
Appetite is set by the board and cascaded down. It is not set by the first line alone.

How to solve Operational Risk Framework and Taxonomy questions

Use this sequence for any question that asks you to classify an event, define the risk or link framework to identification.

  1. 1Read the scenario and find the root cause of the loss, not the line item where it is booked.
  2. 2Ask if the cause is a process, people, system or external event. If none fits, it may be market, credit, strategic or reputational risk.
  3. 3Check the exclusions. Strategic and reputational risk are not operational risk under Basel; legal risk is included.
  4. 4Match the cause to one of the seven event types. Decide if staff acted intentionally (internal fraud) or by error (execution, delivery and process management).
  5. 5Where the question is about the framework, name the element: taxonomy, risk appetite, governance, tools or reporting.
  6. 6Check the answer options against the exact Basel wording and discard options that stretch it.
  7. 7Choose the option that fits both the cause and the definition.

Quickest way: Cause-first triage

When to use it: Use it for MCQs with a short scenario and four event-type or definition options.

  1. Underline the cause word: fraud, error, outage, disaster, mis-selling, staff dispute.
  2. Ask: intentional or accidental? Insider or outsider?
  3. Map to the event type in one step: intentional insider is internal fraud, outsider is external fraud, accident in a process is execution.
  4. Eliminate any option that is strategic or reputational risk.
  5. Confirm and move on.

Common mistakes in Operational Risk Framework and Taxonomy

  • Treating reputational risk as part of Basel operational risk.

    Reputation damage often follows operational failures, so the two blur together.

    Fix: Remember the definition excludes strategic and reputational risk. Only the direct loss counts.

  • Excluding legal risk from the definition.

    Students link legal risk to compliance rather than loss.

    Fix: The Basel definition includes legal risk, such as fines and settlements.

  • Classifying a rogue trader loss as market risk.

    The loss appears in trading P&L, so it looks like a market move.

    Fix: Look at the cause. Unauthorised, concealed trading is internal fraud.

  • Confusing mis-selling with execution errors.

    Both involve customers and products.

    Fix: Mis-selling or poor product practice is clients, products and business practices. A wrong payment instruction is execution, delivery and process management.

  • Treating business disruption as the same as damage to physical assets.

    A flood may cause both a damaged building and an outage.

    Fix: Damage to the asset is physical assets. Loss of service from systems or telecom failure is business disruption and system failures. Split a mixed event by cause.

  • Thinking risk appetite is a number set by operations staff.

    Limits and indicators are used daily by the first line.

    Fix: The board approves appetite. Management turns it into limits, tolerances and indicators.

Worked examples

Example 1

A bank's payments clerk keys in USD 2,500,000 instead of USD 250,000 for a client transfer. The bank must cover the USD 2,250,000 difference after the recipient cannot return it. Which Basel event type applies?

Show the solution
  1. Cause: a data entry mistake in a payment process.
  2. The mistake was accidental, so it is not fraud.
  3. No outage or disaster occurred, so it is not business disruption or physical damage.
  4. Data entry errors fall under execution, delivery and process management.
  5. The loss amount is USD 2,500,000 − USD 250,000 = USD 2,250,000, which is a direct operational loss.

Answer: Execution, delivery and process management.

Example 2

A bank pays a regulatory fine after selling complex structured notes to retail clients who were not suited to them. The share price also falls on the news. Which part is operational risk loss under the Basel definition, and which event type applies?

Show the solution
  1. The fine is a legal loss from the bank's own practices, so it is included in operational risk.
  2. The share price fall is reputational and market reaction, which the definition excludes.
  3. The cause is unsuitable product sales to clients.
  4. That matches clients, products and business practices.

Answer: The fine is an operational risk loss, classed as clients, products and business practices. The share price fall is not counted.

Exam tips

  • Classify by root cause. Many options are tempting because of where the loss is booked.
  • Memorise the include and exclude list: legal included, strategic and reputational excluded.
  • Separate intentional from accidental. It decides between fraud and execution errors.
  • When a question mentions risk appetite, think board approval, then limits, tolerances and indicators.
  • Expect scenarios with two overlapping causes. Pick the primary cause named in the question.

Practice questions from Risk Identification

Operational Risk Framework and Taxonomy in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Operational Risk Framework and Taxonomy: frequently asked questions

What is the Basel definition of operational risk?

It is the risk of loss from inadequate or failed internal processes, people and systems, or from external events. It includes legal risk. It excludes strategic and reputational risk.

What are the Basel operational risk event types?

There are seven level 1 types: internal fraud, external fraud, employment practices and workplace safety, clients, products and business practices, damage to physical assets, business disruption and system failures, and execution, delivery and process management.

How is operational risk different from market and credit risk?

Market and credit risk arise from positions taken and lending decisions. Operational risk arises from failures in running the business, such as processes, people, systems or outside events. It is not usually taken on for a return.

Why does a firm need a risk taxonomy?

A common taxonomy lets every unit tag events, risks and controls the same way. This makes data comparable and allows aggregation across the firm. It also supports consistent reporting against risk appetite.