FRM Exam Part II · Risk Identification
Process Mapping, Change and Emerging Risk Identification
Updated 11 October 2026 · Fact-checked
Risk identification finds risks before they cause loss. You map processes and dependencies to see where failure can occur, review new products and changes before launch, and use horizon scanning to spot emerging and third-party risks. In the exam, match each risk to the right tool and then judge its impact.
Understand Process Mapping, Change and Emerging Risk Identification
Risk identification comes first in the operational risk cycle. You cannot assess, control or monitor a risk you have not found. Banks use several tools together because each one sees a different part of the picture.
Process mapping draws a process step by step, from trigger to outcome. It shows who does what, which systems are used, where data moves, where hand-offs happen and where controls sit. Risks tend to sit at hand-offs, manual steps, spreadsheets and points with no control. A map also shows dependencies: the systems, data, people, premises and third parties that a process needs.
For operational resilience, you map end to end the critical operations, meaning the services whose disruption would harm customers or the firm's safety and soundness or financial stability. You then link them to the resources they depend on. The aim is to find single points of failure and to test whether the firm can stay within its impact tolerance for disruption.
Change risk arises when something new is introduced: a product, system, process, market, outsourcing deal or acquisition. A new product approval process (NPAP) requires the business to document the change, and the control functions (risk, compliance, legal, finance, technology, operations) to review it before launch. Good practice sets clear criteria for what counts as new or materially changed, requires sign-off, and includes a post-implementation review.
Horizon scanning looks forward for emerging risks: risks that are new or changing, with uncertain size and timing. Sources include regulatory publications, incident reports, industry forums, supplier news and scenario workshops. Emerging risks should be logged, assigned an owner, and reviewed regularly. Third-party risk identification works the same way. You list vendors, rank them by criticality, and trace fourth parties and concentration, such as many services sitting with one cloud provider.
Key formulas to remember
- Critical operation mapping chain
- Critical operation → processes → resources (people, technology, data, facilities, third parties) → dependencies and single points of failure
- Map end to end, then test against the impact tolerance. A map that stops at the firm's boundary misses third-party risk.
- Impact tolerance
- Maximum tolerable disruption to a critical operation, set before testing
- It is set by the harm to customers and to the firm or market, not by how fast IT thinks it can recover.
- New product review trigger
- New or materially changed product, process, system, market or outsourcing → pre-launch review and sign-off by control functions
- Be ready to say which functions review and why. A post-implementation review follows.
- Third-party criticality ranking
- Criticality = importance of the service supplied + difficulty of substitution + data or access held
- This is a qualitative ranking, not a numeric formula. It decides the depth of due diligence and monitoring.
- Emerging risk register fields
- Description, driver, possible impact, time horizon, owner, trigger indicators, review date
- Emerging risks are tracked through indicators, as they often cannot be quantified yet.
How to solve Process Mapping, Change and Emerging Risk Identification questions
Use this method on any question about mapping, change or emerging risk identification.
- 1Read the scenario and name the trigger: an existing process, a new or changed product, or a forward-looking threat.
- 2Pick the tool that fits: process mapping for current process weaknesses, dependency mapping for resilience, NPAP for change, horizon scanning for emerging risk.
- 3Identify the risk source: people, process, systems, external events or third parties.
- 4Look for weak points: manual hand-offs, missing controls, single points of failure, concentration in one provider, or a change launched without review.
- 5Check who should act: the first line owns the risk, the second line reviews and challenges, and the board sets appetite.
- 6Choose the answer that acts before the loss, identifies risks end to end, and records them with an owner.
- 7Reject options that rely only on past loss data, that skip control-function review, or that ignore fourth parties.
Quickest way: Tool-to-trigger matching
When to use it: Use it when options list several plausible tools and time is short.
- Ask: is it today's process, a change, or the future?
- Today's process: process map or RCSA. Resilience: critical operations and dependency map.
- Change: new product approval with pre-launch sign-off and later review.
- Future or external: horizon scanning, scenario workshops, emerging risk register.
- Pick the option that is proactive, end to end and owned.
Common mistakes in Process Mapping, Change and Emerging Risk Identification
Treating a process map as a control test.
Both look at processes, so they blur together.
Fix: A map identifies steps, hand-offs and dependencies. Controls are then assessed on the map, for example through RCSA or testing.
Stopping the dependency map at the firm's own systems.
Internal assets are easier to list.
Fix: Include vendors, their subcontractors (fourth parties) and shared infrastructure. Check for concentration.
Relying on loss data to find emerging risks.
Loss data feels objective.
Fix: Loss data looks backward. Emerging risks need horizon scanning, scenarios and indicators.
Letting the business sign off its own new product.
The business knows the product best.
Fix: The business proposes, but independent control functions review and approve before launch.
Setting impact tolerance from recovery capability.
Candidates mix up tolerance and recovery time targets.
Fix: Set tolerance from the harm of disruption, then test whether recovery can meet it.
Worked examples
Example 1
A bank plans to launch a digital loan product using a new scoring vendor and a changed onboarding workflow. Which review best identifies the operational risks before launch? (A) Review of past loss data only (B) New product approval with input from risk, compliance, legal, technology and operations, plus a process and dependency map (C) Approval by the product head alone (D) A post-launch audit after one year
Show the solution
- The trigger is a new product with a new vendor and a changed process, so it is a change risk.
- The fitting tool is the new product approval process, covering all control functions.
- Process and dependency mapping will show the vendor reliance and hand-offs.
- A is backward-looking, C lacks independent review, and D comes after launch.
Answer: B
Example 2
A bank maps its payments service as a critical operation. The map shows that all payment processing relies on one cloud provider, which itself uses one data centre operator. What has the mapping revealed, and what should the bank do?
Show the solution
- The map traces the service to resources: one cloud provider and its subcontractor.
- This is a single point of failure and a concentration risk that includes a fourth party.
- The bank should check this against the impact tolerance for payments.
- Actions: obtain information on the fourth party, set exit and failover plans, and test a severe but plausible outage scenario.
- The risk should be logged with an owner and reported to senior management.
Answer: Mapping revealed a single point of failure and third and fourth-party concentration risk. The bank should test against its impact tolerance, build failover and exit plans, and assign ownership.
Exam tips
- Match the tool to the trigger first. Most wrong options use the right idea at the wrong time.
- Prefer answers that are proactive, end to end and independently reviewed.
- For resilience questions, look for the words critical operations, impact tolerance and dependencies.
- Watch for fourth parties and concentration in third-party stems.
- Emerging risk answers usually involve scenarios, indicators and an owner rather than a numeric estimate.
Practice questions from Risk Identification
- A bank's RCSA scores likelihood and impact on a 1-5 scale and multiplies them to give an inherent score. A control is rated as reducing the …
- A bank discovers that a trader deliberately concealed losses by booking fictitious trades, bypassing system controls. Under the Basel event-…
- A bank sets a KRI for failed trade settlements per 1,000 trades with a green zone below 4, an amber zone from 4 to 7 inclusive, and a red zo…
- A bank's payments division runs an annual Risk and Control Self-Assessment. Business line managers rate inherent risk, control effectiveness…
- A bank's process map of its wire transfer process shows 6 manual handoffs between teams. Historical review indicates that each manual handof…
Process Mapping, Change and Emerging Risk Identification: frequently asked questions
What is process mapping in operational risk?
It is drawing a process step by step, including systems, people, data and controls. You use it to find hand-offs, manual steps and missing controls where failures may occur.
What is horizon scanning?
It is a forward-looking review of regulation, technology, markets and external events to spot emerging risks early. The results go into a register with owners and indicators.
Why do banks review new products before launch?
New products bring new risks that no control yet covers. Independent review before launch lets risk, compliance, legal and operations challenge the plan and set controls first.
How do you identify third-party risk dependencies?
List all vendors, rank them by criticality, and map which critical operations rely on each. Then trace fourth parties and look for concentration in one provider or location.