Skip to content

FRM Part II · FRM Exam Part II · Risk Governance

Which feature most clearly distinguishes an effective operational risk governance framework from a purely compliance-driven one?

An effective framework embeds risk ownership and risk information into business decisions, backed by clear accountability and regular board-level reporting. A compliance-driven approach relies on static policy documents, and assigning everything to internal audit or only past losses would be insufficient.

  1. AIt is documented in a policy that is reviewed only when regulators request changes
  2. BIt embeds risk ownership and risk information in business decision-making, with clear accountability and board-level reportingCorrect
  3. CIt relies exclusively on historical loss data to identify future risks
  4. DIt assigns all operational risk responsibilities to the internal audit function

Explanation

Effective frameworks are embedded in the business: clear roles, accountability, use of risk information in decisions, and regular reporting to senior management and the board. Policy-only, loss-data-only, or audit-only approaches are static, backward-looking, or violate separation of duties.

Did you get it right without looking?

One question tells you little. A timed set on Risk Governance shows your real accuracy, how long you take and where you lose marks.

More Risk Governance questions