Skip to content

FRM Part II · FRM Exam Part II · Introduction to Operational Risk and Resilience

A ransomware attack by an external criminal group encrypts a bank's core systems for three days. Customers cannot transact, and the bank pays compensation and recovery costs. Which treatment is most consistent with the Basel taxonomy and good practice for loss data?

The event should be classified as business disruption and system failures, with all related costs, including customer compensation and recovery, aggregated to that one event. The external cause does not change the primary effect, which is a systems outage, and splitting the losses would distort the loss data.

  1. AClassify the event under business disruption and system failures, and record related costs, including compensation, against the single eventCorrect
  2. BClassify as external fraud only, since the attacker is external, and exclude the compensation
  3. CClassify as execution, delivery and process management because transactions failed
  4. DClassify as clients, products and business practices because customers were affected

Explanation

Basel's business disruption and system failures category covers the outage, even though the cause was external. Practice is to assign one primary event type by the root event and aggregate all related losses to it. External fraud is about theft or fraud by third parties, which fits poorly with a pure outage and does not exclude compensation costs.

Did you get it right without looking?

One question tells you little. A timed set on Introduction to Operational Risk and Resilience shows your real accuracy, how long you take and where you lose marks.

More Introduction to Operational Risk and Resilience questions