Skip to content

FRM Exam Part II · The Financial Stability Implications of Artificial Intelligence

Monitoring AI Vulnerabilities and Policy Recommendations

Updated 11 October 2026 · Fact-checked

The FSB says authorities should first close data and information gaps on AI use, then monitor indicators of AI-related vulnerabilities such as third-party concentration, market correlation, cyber risk, and model risk and data quality. They should also assess whether existing financial policy frameworks are adequate, and strengthen supervisory capacity, including AI skills and tools.

Understand Monitoring Vulnerabilities and Policy Recommendations

AI can improve efficiency in finance, but it can also create or amplify vulnerabilities across the system. The FSB (November 2024) groups the main ones into four: third-party dependencies and service provider concentration, market correlations, cyber risk, and model risk, data quality and governance. Monitoring and policy work are built around these four.

Start with the problem: authorities cannot manage what they cannot see. Many firms use AI through a few cloud, model and data providers. Supervisors often lack data on which firms use which models, for what, and how critical the service is. So the first recommendation is to address data and information gaps and build a monitoring approach.

The FSB suggests indicators that cover each vulnerability. For third-party risk, look at the share of critical services from a small set of providers and how substitutable they are. For correlation, look at the use of similar models, data and strategies, which can drive herding and amplify shocks in stress. For cyber risk, look at AI-enabled attacks and incidents. For model risk, look at explainability, data quality and governance of models used in important decisions.

The second recommendation is to assess whether current policy frameworks are sufficient to address these risks. Many existing rules are technology-neutral, so the question is whether there are gaps, for example for third-party oversight or model risk. The third is to enhance supervisory and regulatory capabilities, including the skills, tools and cross-border cooperation needed to oversee AI.

In the exam, expect scenario questions. You are given a risk (for example, many banks rely on one AI vendor) and must pick the matching indicator or the matching policy response. Keep the logic simple: identify the vulnerability, then match the indicator, then match the response.

Key formulas to remember

FSB policy recommendations (sequence)
1) Close data and information gaps and monitor; 2) Assess adequacy of existing policy frameworks; 3) Enhance supervisory and regulatory capabilities
This is a framework, not a calculation. Learn the order and the logic: see, assess, strengthen.
Vulnerability to indicator match
Third-party concentration → provider shares and substitutability; Correlation → model, data and strategy similarity; Cyber → AI-enabled incidents; Model risk → explainability, data quality, governance
Use this to pick the indicator that fits a scenario.
Concentration check (generic)
Provider share = Firms' critical services from one provider ÷ Total critical services
A simple illustration of a concentration indicator. It is not a prescribed FSB formula.

How to solve Monitoring Vulnerabilities and Policy Recommendations questions

Use this method for any question on AI monitoring indicators or policy responses.

  1. 1Read the scenario and name the vulnerability: third-party concentration, market correlation, cyber risk, or model risk, data quality and governance.
  2. 2Ask what authorities cannot currently see. If the issue is missing information, the answer is about data gaps and monitoring.
  3. 3Match the indicator to the vulnerability, such as provider concentration for third-party risk or similarity of models for herding.
  4. 4Decide whether the question is about monitoring, policy adequacy, or supervisory capacity. Use the three-part sequence.
  5. 5Prefer answers that are proportionate and evidence-based: assess existing frameworks before adding new rules.
  6. 6Eliminate options that are extreme, such as banning AI, or that claim AI risk is only operational or only a firm-level matter.
  7. 7Check the answer speaks to financial stability (system-wide), not just one firm's performance.

Quickest way: Vulnerability, indicator, response in 20 seconds

When to use it: Use for scenario MCQs where four options mix indicators, policies and unrelated measures.

  1. Label the risk in two words, for example vendor concentration.
  2. Pick the option that measures or addresses that exact risk.
  3. If the stem says authorities lack information, choose data collection or monitoring.
  4. If it says rules may not cover a risk, choose assessing policy frameworks.
  5. If it says supervisors lack expertise, choose building skills and tools.

Common mistakes in Monitoring Vulnerabilities and Policy Recommendations

  • Treating the FSB recommendations as a call to ban or tightly restrict AI.

    Students assume risk work means prohibition.

    Fix: Remember the approach is to monitor, assess existing frameworks for gaps, and build supervisory capacity.

  • Matching the wrong indicator to a vulnerability, such as using cyber incident counts for herding.

    The four vulnerabilities overlap in real life.

    Fix: Tie each risk to its main indicator: concentration to provider shares, correlation to model and data similarity.

  • Skipping data gaps and jumping to new regulation.

    Policy answers sound more decisive.

    Fix: Data and monitoring come first, because policy gaps cannot be judged without evidence.

  • Treating AI risk as only a firm-level model risk issue.

    Model risk is familiar from earlier chapters.

    Fix: Focus on system-wide channels: common providers, correlated behaviour and shared cyber exposure.

  • Assuming new AI-specific rules are always needed.

    The topic is new, so students expect new law.

    Fix: The FSB asks whether existing, often technology-neutral, frameworks are sufficient and where gaps remain.

Worked examples

Example 1

Several large banks use the same external provider for AI credit-decision models. Supervisors have no data on how many critical services depend on this provider. Which response best fits the FSB approach? A) Ban external AI providers; B) Collect data on provider dependencies and monitor concentration; C) Raise all banks' capital ratios by a fixed amount; D) Wait for an incident before acting.

Show the solution
  1. Vulnerability: third-party dependency and service provider concentration.
  2. Gap: supervisors cannot see the dependency, so this is a data and information gap.
  3. Indicator: share of critical services from one provider and how easily it can be replaced.
  4. Option A is extreme and not recommended. C does not address the visibility gap. D is reactive.
  5. Option B matches the first recommendation: close data gaps and monitor.

Answer: B) Collect data on provider dependencies and monitor concentration.

Example 2

Many asset managers use similar AI models trained on the same data to trade. Which vulnerability is this, and which indicator would authorities monitor? A) Cyber risk; similarity of models and data across firms; B) Market correlation; similarity of models, data and strategies across firms; C) Model risk only; number of staff in risk teams; D) Third-party risk; number of customer complaints.

Show the solution
  1. Similar models and data lead firms to act alike, so trades are correlated.
  2. This is the market correlation and herding vulnerability, which can amplify shocks in stress.
  3. The matching indicator is the degree of similarity in models, data and strategies.
  4. A names the wrong risk. C and D use indicators unrelated to the described risk.

Answer: B) Market correlation; similarity of models, data and strategies across firms.

Exam tips

  • Learn the four vulnerabilities and the three recommendations as two short lists, then practise matching them.
  • Questions are usually conceptual scenarios, not calculations. Read for the keyword: vendor, similar models, attack, or explainability.
  • Prefer the proportionate answer: monitor, assess, build capacity. Reject bans and do-nothing options.
  • Always link the answer to system-wide financial stability, not one firm's profit.

Practice questions from The Financial Stability Implications of Artificial Intelligence

Monitoring Vulnerabilities and Policy Recommendations: frequently asked questions

What does the FSB recommend on AI and financial stability?

It recommends closing data and information gaps and monitoring AI developments, assessing whether current policy frameworks are adequate, and strengthening supervisory and regulatory capabilities. The aim is to catch system-wide vulnerabilities early.

Which indicators help monitor AI vulnerabilities?

Indicators should match the vulnerability. Examples are provider concentration and substitutability for third-party risk, similarity of models and data for correlation, AI-enabled incidents for cyber risk, and explainability and data quality for model risk.

Do regulators need entirely new AI rules?

Not necessarily. The FSB asks authorities to assess whether existing frameworks, many of which are technology-neutral, cover AI-related risks, and to find gaps. New or adjusted measures may follow where gaps are found.

Why are data gaps so important here?

Authorities cannot judge risk or policy adequacy without knowing how AI is used and who provides it. Better data lets them track concentration and interconnections across the system.