FRM Part II · FRM Exam Part II · Risk Mitigation
A bank wants to reduce capital-relevant operational risk using an insurance program. Which feature of a policy would most weaken its recognition as an effective risk mitigant by a supervisor?
Short-notice cancellation rights or a very short residual term would most weaken recognition. They make the protection unreliable because cover could lapse when needed, whereas a strong insurer, aligned wording and a proper renewal process all support the mitigant's effectiveness.
- AA policy term of one year with a stated renewal process and notice of 90 days
- BAn insurer with a strong credit rating and a track record of paying claims
- CBroad coverage wording aligned to the bank's loss event types
- DCancellation rights allowing the insurer to terminate on short notice, such as 30 days, or a policy with a residual term under one year without renewal assuranceCorrect
Explanation
Mitigation must be reliable and durable. Short-notice cancellation or very short residual term creates a gap in protection, so recognition is reduced. The other options are features that support reliability.
Did you get it right without looking?
One question tells you little. A timed set on Risk Mitigation shows your real accuracy, how long you take and where you lose marks.
More Risk Mitigation questions
- Which contractual provision best supports a bank's ability to oversee an outsourced critical service on an ongoing basis?
- A bank's expected annual loss from a process is USD 4 million with an event frequency of 20 per year. A new control is projected to cut freq…
- A bank's security architecture assumes no user or device is trusted by default, even inside the corporate network, and requires continuous v…
- A bank's disaster recovery test shows that its trading system, supported by a secondary data center, recovers in 6 hours. The business conti…
- A bank's incident response plan is reviewed. Which element most improves its ability to limit damage during an actual cyber incident?
- A bank's cyber-risk manager wants to limit the damage if an attacker compromises one employee's credentials, so that the attacker cannot mov…