Skip to content

FRM Part II · FRM Exam Part II · Risk Measurement and Assessment

A bank's RCSA program uses a heat map for aggregation across business lines. The operational risk head notes that two risks both rated 'medium' (likelihood 'possible', impact 'major') are treated as equivalent for prioritization, although one is a high-frequency, low-severity risk and the other a low-frequency, extreme-severity cyber event whose impact is capped by the top rating category. What is the principal limitation of the approach that this illustrates?

The limitation is that coarse ordinal scales, especially with a capped top impact category, put risks with very different frequency and severity profiles into the same cell. This hides extreme tail exposures and distorts prioritization and aggregation across the bank.

  1. AOrdinal rating scales with capped impact categories compress very different risk profiles and understate tail severityCorrect
  2. BHeat maps cannot be used with qualitative data
  3. CHeat maps overstate the effect of controls on all risks
  4. DRCSA results cannot be compared with any internal loss data

Explanation

Ordinal scales with a capped top category group risks with very different severity into the same cell, hiding tail exposure and distorting prioritization and aggregation. Heat maps are in fact built on qualitative data, so the second option is wrong. Nothing here concerns control effects or the ability to compare with loss data.

Did you get it right without looking?

One question tells you little. A timed set on Risk Measurement and Assessment shows your real accuracy, how long you take and where you lose marks.

More Risk Measurement and Assessment questions