Skip to content

FRM Part II · FRM Exam Part II · Risk Identification

A bank is about to migrate its payments platform to a new vendor system. Which approach best reflects sound operational risk identification for this change initiative?

The best approach is a forward-looking risk assessment before approval and during the project, covering process, people, system and third-party impacts, with operational risk involved in go-live decisions. Reactive review after losses, sole reliance on vendors, or IT-only review would leave change risks unidentified.

  1. AWait until post-implementation loss events occur and then update the risk register
  2. BPerform a risk assessment before approval and during the project, covering process, people, system and third-party impacts, with operational risk input into go-live decisionsCorrect
  3. CRely on the vendor's assurance report as the sole assessment of risks
  4. DLimit the review to IT staff since the change affects only technology

Explanation

Sound practice is to identify and assess risks from change proactively, before and throughout implementation, across processes, people, systems and vendors, and to involve the risk function in approval. Waiting for losses is reactive, and relying solely on a vendor or only on IT leaves risks unidentified.

Did you get it right without looking?

One question tells you little. A timed set on Risk Identification shows your real accuracy, how long you take and where you lose marks.

More Risk Identification questions