Skip to content

FRM Part II · FRM Exam Part II · Risk Identification

A risk manager is deciding how to structure an operational risk framework around cause, event and effect. A hacker exploits an unpatched server (cause), data is exfiltrated (event), and the bank pays regulatory fines and customer compensation (effect). Which statement best reflects sound use of this cause-event-effect structure?

Best practice separates the three elements: the event type is the security breach or external attack, the cause is the unpatched server, and the effects are fines and compensation. Keeping them distinct supports control analysis and avoids double counting.

  1. AClassify the loss by the effect, since the financial impact is the only measurable element
  2. BClassify the event by its cause, so the unpatched server defines the event type
  3. CRecord the event type as external fraud or a systems security breach, and capture the unpatched server as a cause and the fines and compensation as effectsCorrect
  4. DTreat the fines as a separate event of a new risk type independent of the data breach

Explanation

Event types describe what happened, causes describe why it was possible, and effects describe the consequences. Mixing these loses analytical value. Fines and compensation are effects linked to the same event, not separate events, and causes such as patching gaps should be recorded to guide control improvements.

Did you get it right without looking?

One question tells you little. A timed set on Risk Identification shows your real accuracy, how long you take and where you lose marks.

More Risk Identification questions