Skip to content

FRM Part II · FRM Exam Part II · Risk Identification

A bank uses a risk and control self-assessment (RCSA) alongside a taxonomy. A risk manager finds that the same incident, a vendor's data breach exposing client data, was recorded by one team as third-party risk, by another as cyber risk, and by a third as compliance risk, with the loss counted three times in aggregate reporting. What is the most appropriate remedy?

Assign each event one primary category, with secondary tags for other relevant risk types, and aggregate on the primary only. This keeps cross-cutting information while preventing the same loss being counted three times. Removing categories, summing duplicates, or using a high threshold would distort or hide data.

  1. AAssign each event a single primary risk category with secondary tags for other relevant categories, and aggregate only on the primaryCorrect
  2. BRemove cyber and compliance categories so only third-party risk remains
  3. CAllow each team to book the loss in its own category and sum the amounts for conservatism
  4. DRecord the event only when the loss exceeds the largest prior loss

Explanation

Events often cross categories, so a primary classification rule with secondary tags preserves information while avoiding double counting. Deleting categories loses granularity, summing duplicates overstates losses, and a threshold relative to the largest loss would hide events.

Did you get it right without looking?

One question tells you little. A timed set on Risk Identification shows your real accuracy, how long you take and where you lose marks.

More Risk Identification questions