FRM Part II · FRM Exam Part II · Risk Reporting
An internal audit review of a bank's operational risk reports finds that the format has not changed in six years, several metrics are no longer used in decisions, and recipients rarely read the appendices. What is the most appropriate recommendation regarding report review?
The bank should set up a periodic review of its risk reports to test relevance, accuracy and usefulness, drop metrics nobody uses and gather recipient feedback. Reports must evolve with the business and risks; simply adding metrics or freezing format reduces their value for decisions.
- ALeave the reports unchanged to preserve comparability of historical data
- BAdd further metrics to the reports so no risk is overlooked
- CEstablish a periodic review process to assess report relevance, accuracy and usefulness, retiring unused metrics and incorporating recipient feedbackCorrect
- DDelegate content decisions solely to the report preparers
Explanation
Reports should be reviewed regularly for fitness for purpose as the business, risks and user needs evolve. Removing unused metrics and gathering feedback improves clarity. Adding metrics worsens overload, and preparers alone cannot judge user needs.
Did you get it right without looking?
One question tells you little. A timed set on Risk Reporting shows your real accuracy, how long you take and where you lose marks.
More Risk Reporting questions
- A bank's internal audit reviews its BCBS 239 compliance. It notes: (1) reports reconcile to the general ledger, (2) the bank uses extensive …
- A bank's operational risk team distributes its monthly risk report by email to a broad list that has grown over several years. An internal r…
- A bank's head of operational risk wants to confirm that the board risk report is effective after distribution. Which action best reflects go…
- An operational risk manager wants to confirm that the quarterly risk report to senior management is timely and reliable. Which control best …
- A bank sets a reporting escalation protocol: any single operational loss event above USD 500,000 must reach the CRO within 24 hours; the mon…
- A bank sets a tolerance for its payments service of a maximum tolerable disruption of 4 hours. After a vendor outage, the service was unavai…