FRM Part II · FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector
A reinsurer models a cyber catastrophe pool of 10 banks, each with a 2% annual probability of a vendor-driven loss of 50 million. Losses are independent in Model A. In Model B, a single vendor event with 2% probability hits all 10 banks at once. Which statement correctly compares the two models?
Expected annual loss is 10 million in both models (10×2%×50 and 2%×500). However, Model B concentrates loss into a single 500 million event, so its tail risk is far greater. Correlation from a common vendor raises tail risk without changing the mean.
- AExpected annual loss is 10 million in both models, but Model B has far greater tail riskCorrect
- BExpected annual loss is 10 million in A and 100 million in B
- CExpected annual loss is 1 million in both, with equal tail risk
- DExpected annual loss is 10 million in both, and Model A has greater tail risk
Explanation
Model A: 10 × 0.02 × 50 = 10 million. Model B: 0.02 × (10 × 50 = 500) = 10 million. Means are equal, but in B the 2% event costs 500 million, whereas in A the chance of several simultaneous losses is tiny. Correlation therefore fattens the tail without changing the expectation.
Did you get it right without looking?
One question tells you little. A timed set on Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector shows your real accuracy, how long you take and where you lose marks.
More Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector questions
- A risk analyst compares two ways of modelling extreme cyber losses for the financial sector. Historical data are scarce and incidents are hi…
- Which policy approach best addresses the systemic nature of cyber risk, as opposed to purely firm-level controls?
- A financial stability authority is designing a macroprudential framework for cyber risk. Which feature most distinguishes a macroprudential …
- A regional bank's security team detects a new malware strain and wants to share indicators of compromise with peer institutions. Its legal t…
- A risk officer argues that digital resilience policy should move beyond capital buffers. Which reasoning best supports this view?
- A regulator is designing a framework for operational resilience across the financial sector. Which design choice best reflects a sound macro…