FRM Part II · FRM Exam Part II · Risk Identification
A risk manager is deciding how to structure an operational risk framework around cause, event and effect. A hacker exploits an unpatched server (cause), data is exfiltrated (event), and the bank pays regulatory fines and customer compensation (effect). Which statement best reflects sound use of this cause-event-effect structure?
Best practice separates the three elements: the event type is the security breach or external attack, the cause is the unpatched server, and the effects are fines and compensation. Keeping them distinct supports control analysis and avoids double counting.
- AClassify the loss by the effect, since the financial impact is the only measurable element
- BClassify the event by its cause, so the unpatched server defines the event type
- CRecord the event type as external fraud or a systems security breach, and capture the unpatched server as a cause and the fines and compensation as effectsCorrect
- DTreat the fines as a separate event of a new risk type independent of the data breach
Explanation
Event types describe what happened, causes describe why it was possible, and effects describe the consequences. Mixing these loses analytical value. Fines and compensation are effects linked to the same event, not separate events, and causes such as patching gaps should be recorded to guide control improvements.
Did you get it right without looking?
One question tells you little. A timed set on Risk Identification shows your real accuracy, how long you take and where you lose marks.
More Risk Identification questions
- A bank's operational risk team is preparing to run scenario analysis workshops to identify severe but plausible loss events. Which of the fo…
- During a scenario workshop at a regional bank, business managers estimate the loss from a major payment system outage. The facilitator notic…
- A bank maps its customer onboarding process and finds 12 steps. Five are manual, and three of those manual steps rely on a single employee w…
- A bank's operational risk function is building a taxonomy to classify loss events consistently across business lines. Which of the following…
- A bank sets a KRI for failed trade settlements with a green threshold below 20 fails per week, amber from 20 to 39, and red at 40 or more. W…
- A bank's operational risk team wants an indicator that signals rising risk exposure before losses are recorded in the loss database. Which o…