Free Questions › FRM › Operational Risk and Resilience
Free FRM Operational Risk and Resilience Practice Questions & Answers
400 exam-style Operational Risk and Resilience questions. Pick your answer, hit Check answer, and see the worked solution — free to start, no signup.
100% free · No login to startQuestion 1
What is the Basel definition of operational risk?
Select an option first.
Correct answer: B — The risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events — this definition includes legal risk but excludes strategic risk and reputational risk
Explanation: B is correct. Basel II/III definition: four causes — processes, people, systems, and external events. Legal risk (regulatory fines, litigation) is included. Excluded: strategic risk (wrong business decisions) and reputational risk (damage to brand). A is market/trading risk. C is capital adequacy risk. D is a broad catch-all that is incorrect.
Question 2
What are the seven Basel II event categories for classifying operational losses?
Select an option first.
Correct answer: B — Internal fraud, External fraud, Employment practices and workplace safety, Clients/products/business practices, Damage to physical assets, Business disruption and system failures, and Execution/delivery/process management
Explanation: B is correct. The seven Basel event type categories (Level 1): (1) Internal fraud — unauthorised activity, theft by employees; (2) External fraud — robbery, hacking, phishing; (3) Employment practices and workplace safety — HR disputes, discrimination; (4) Clients, products, business practices — mis-selling, fiduciary breaches; (5) Damage to physical assets — natural disasters, vandalism; (6) Business disruption and system failures — hardware failure, power outages; (7) Execution, delivery and process management — data entry errors, settlement failures. A and D are not the Basel categories. C describes market risk types.
Question 3
Give an example of an 'Internal Fraud' operational loss event.
Select an option first.
Correct answer: B — An employee who bypasses authorisation limits to hide trading losses, as in the Nick Leeson case at Barings Bank
Explanation: B is correct. Internal fraud: unauthorised activity by an employee (or colluding employees) that causes a loss. Nick Leeson at Barings Bank (1995): hid trading losses in a secret account, eventually causing the bank's collapse. Jérôme Kerviel at Société Générale (2008) is another example. A is a physical damage event. C is external fraud (the perpetrator is external). D is a system failure / execution event.
Question 4
Give an example of an 'External Fraud' operational loss event.
Select an option first.
Correct answer: B — A cybercriminal who uses phishing emails to steal customer login credentials and drain bank accounts
Explanation: B is correct. External fraud: fraudulent acts by a party external to the organisation. Examples: phishing attacks, card skimming, account takeover, cheque fraud, third-party theft. A is internal fraud. C is also internal fraud (employee doing it). D is an execution/process management or system failure event.
Question 5
What does 'Clients, Products and Business Practices' cover as an operational risk category?
Select an option first.
Correct answer: B — Losses arising from failure to meet professional obligations to clients, unsuitable products, or improper business practices — examples include mis-selling of products, market manipulation, antitrust violations, and fiduciary breaches
Explanation: B is correct. Clients, products, business practices: this is one of the largest categories by loss amount. Examples: PPI (Payment Protection Insurance) mis-selling in the UK (banks paid £50B+ in redress); LIBOR manipulation fines; antitrust penalties; unsuitable investment advice; money laundering failures. A is physical damage (different category). C is external fraud. D is credit risk.
Get the full FRM question bank — free
Drop your email and we'll send you fresh FRM practice questions, fully worked solutions and exam-deadline reminders. No spam — unsubscribe in one click.
Want to save your score and take a full mock exam? Create a free account →
Question 6
What is the 'Loss Distribution Approach' (LDA) in operational risk capital modelling?
Select an option first.
Correct answer: B — A statistical modelling approach that separately estimates the frequency distribution (how often losses occur) and severity distribution (how large losses are) for each risk cell, then combines them using Monte Carlo simulation to produce an aggregate annual loss distribution
Explanation: B is correct. LDA: the workhorse of advanced operational risk modelling. Frequency: typically modelled with a Poisson distribution. Severity: typically modelled with a heavy-tailed distribution (lognormal, Pareto, GPD). These are convolved (combined) using Monte Carlo simulation to produce the full loss distribution, from which percentile capital figures (99.9% VaR) are read. A is not the LDA. C describes the Basic Indicator Approach. D is capital allocation, not LDA.
Question 7
What is the 'frequency distribution' in the LDA and what is its typical shape?
Select an option first.
Correct answer: B — The distribution of the number of loss events occurring in a given time period (typically one year) — commonly modelled using a Poisson distribution, which is characterised by a single parameter λ (the expected number of events per year) and assumes events are independent and occur at a constant rate
Explanation: B is correct. Frequency distribution: Poisson(λ) — P(N=k) = e^(-λ) × λ^k / k!. Example: if λ = 5 losses per year, the distribution shows the probability of 0, 1, 2, ... losses in a year. Other models: Negative Binomial (if there is over-dispersion, meaning variance > mean). A describes the severity distribution. C is a threshold exceedance probability. D is not used.
Question 8
What is the 'severity distribution' in the LDA and why does it need a heavy tail?
Select an option first.
Correct answer: B — The distribution of individual loss amounts (given a loss occurs) — operational losses are heavy-tailed: most losses are small but occasionally very large losses occur (e.g., $1B+ rogue trading). Heavy-tailed distributions (lognormal, Pareto, Generalised Pareto Distribution/GPD) better capture this than the normal distribution
Explanation: B is correct. Severity distribution: heavy tails are critical because the 99.9th percentile capital is dominated by extreme losses, not average losses. Common distributions: Lognormal (ln(X) ~ Normal) — positively skewed, fat tail. Pareto — power law tail, used for very large losses. GPD — extreme value theory distribution, used for modelling tail losses specifically. Using normal would dramatically underestimate capital. A is wrong. C ignores heavy tails. D assumes normality incorrectly.
Question 9
What is 'Monte Carlo simulation' in the context of LDA operational risk modelling?
Select an option first.
Correct answer: B — A technique that generates thousands of simulated annual loss scenarios by: (1) drawing a random number of events from the frequency distribution; (2) for each event, drawing a random loss amount from the severity distribution; (3) summing them to get the annual aggregate loss. The full set of simulations produces the aggregate loss distribution from which capital is read at the 99.9th percentile
Explanation: B is correct. Monte Carlo for LDA: 100,000+ simulations are run. Each simulation: frequency draw (e.g., Poisson gives 7 events) → 7 severity draws (e.g., lognormal gives $50K, $12K, $2M, ...) → sum = $2.062M aggregate loss for that simulation year. After 100,000 simulations: a full loss distribution is obtained. The 99.9th percentile of this distribution gives the capital requirement. A is historical simulation. C is scenario analysis. D is qualitative review.
Question 10
What is the 'Basic Indicator Approach' (BIA) to operational risk capital under Basel II?
Select an option first.
Correct answer: B — Capital = 15% × average annual positive gross income over the previous three years — the simplest approach, used by small or less sophisticated banks. Gross income serves as a proxy for the scale of the bank's activities and therefore its operational risk exposure
Explanation: B is correct. BIA (Basel II, Pillar 1): OpRisk Capital = α × GI, where α = 15% and GI = average positive gross income over 3 years. Gross income = net interest income + net non-interest income. Simple but crude — doesn't distinguish between different risk profiles. Used by banks without sophisticated OpRisk modelling capabilities. A uses total assets (incorrect). C uses RWA (market/credit risk approach). D uses net income with wrong percentage.
Question 11
What is the 'Standardised Approach' (SA) to operational risk under Basel II and how does it differ from the BIA?
Select an option first.
Correct answer: B — It divides bank activities into eight standardised business lines, each with its own beta multiplier (12-18%) applied to gross income — rather than applying a single 15% to total gross income. This provides a slightly better risk differentiation by business line than the BIA
Explanation: B is correct. Standardised Approach (SA): 8 business lines — Corporate Finance (β=18%), Trading & Sales (18%), Retail Banking (12%), Commercial Banking (15%), Payment & Settlement (18%), Agency Services (15%), Asset Management (12%), Retail Brokerage (12%). Capital = Σ (GI_i × β_i) averaged over 3 years. Better risk sensitivity than BIA but still crude. A: still uses gross income. C is wrong. D is wrong.
Question 12
What is the 'Advanced Measurement Approach' (AMA) under Basel II and why was it phased out in Basel IV?
Select an option first.
Correct answer: B — A bank's own internal model for calculating operational risk capital, incorporating: internal loss data, external loss data, scenario analysis, and business environment and internal control factors (BEICAFs). Phased out by Basel IV (SA-only post-2023) due to excessive variability in capital outputs and difficulty in comparability between banks
Explanation: B is correct. AMA: the most sophisticated Basel II approach. Four data elements: internal loss data (ILD), external loss data (ELD), scenario analysis (SA), business environment and internal control factors (BEICAFs). Basel IV replaced AMA with the new Standardised Approach (SMA/SA) from 2023 because: wide variability in bank capital estimates using AMA made comparability impossible, and some banks were gaming models to reduce capital. A describes BIA. C is incomplete. D is SA, not AMA.
Question 13
What is the Basel IV 'Standardised Approach' (SA) for operational risk capital and how does it work?
Select an option first.
Correct answer: B — It calculates capital using a Business Indicator (BI) — a measure of revenue scale — multiplied by a Loss Component (LC) that incorporates the bank's actual historical loss experience. Capital = BI Component × (1 + ILM), where ILM is the Internal Loss Multiplier based on 10 years of internal loss data
Explanation: B is correct. Basel IV SA (effective 2023+): replaces both the BIA/SA/AMA with a single approach. The Business Indicator Component (BIC) = BI × αᵢ, where αᵢ varies by BI bucket (12-18%). The Internal Loss Multiplier (ILM) = ln(exp(1) − 1 + (LC/BIC)^0.8) reflects actual loss history for large banks. For small banks: ILM = 1 (loss history not required). This addresses the comparability issue of AMA while retaining some loss-sensitivity. A is BIA. C is a credit risk approach. D is AMA.
Question 14
What is the 'Business Indicator' (BI) in the Basel IV operational risk framework?
Select an option first.
Correct answer: B — A measure of a bank's income scale used in the Basel IV SA — calculated as the sum of three components: the Interest, Leases and Dividends component (ILDC), the Services component (SC), and the Financial component (FC). It replaces gross income as a more stable and robust revenue measure
Explanation: B is correct. Business Indicator: BI = ILDC + SC + FC. ILDC: |Net Interest Income| + |Net Lease Income| + Dividends. SC: Max(Fee Income, Fee Expenses) + Max(Other Operating Income, Other Operating Expenses). FC: |Net P&L in trading book| + |Net P&L in banking book|. The absolute values and maxima prevent banks from netting offsetting items to reduce BI. A is not BI. C is the SREP process. D is too narrow.
Question 15
What is 'internal loss data' (ILD) and what are the key requirements for using it in operational risk models?
Select an option first.
Correct answer: B — Historical records of actual operational loss events experienced by the bank — key requirements: minimum threshold (typically losses above €20,000 or €10,000 for large banks), minimum history (at least 5 years, ideally 10), data completeness (all qualifying events captured), accurate mapping to Basel event types and business lines, and validation of data quality and integrity
Explanation: B is correct. ILD quality requirements: capture threshold (losses below the threshold are excluded — typically €20K), completeness (no cherry-picking — all qualifying losses must be captured), classification (mapped to correct event type and business line), and data validation (reconciled to accounting records). Challenges: rare events create sparse data for tail modelling; the historical period may not reflect current risk profile. A is too broad. C is external data. D is scenario analysis.
Question 16
What is 'external loss data' (ELD) and why is it important in operational risk modelling?
Select an option first.
Correct answer: B — Operational loss data from industry-wide databases (e.g., ORX — Operational Riskdata eXchange) — important because large rare losses ('elephant losses') may not appear in a single bank's internal history. External data provides a richer sample of tail events but requires careful scaling to the bank's size and business mix
Explanation: B is correct. External loss data: ORX is the main industry consortium — member banks share anonymised loss data and receive pooled statistics. ELD addresses the sparse-data problem for tail modelling. Challenges: relevance (is a loss at another bank relevant to your risk profile?), scaling (large bank losses need to be scaled down for smaller banks), and selection bias (banks may not report small losses). A is the general description. C is regulatory data. D: the BCBS does not publish individual bank loss data.
Question 17
What is 'scenario analysis' in operational risk and what is its purpose?
Select an option first.
Correct answer: B — A forward-looking technique where risk experts and senior management assess the likelihood and potential impact of severe but plausible operational risk events that may not be captured in historical data — used to: populate the tail of the loss distribution (rare high-impact events), calibrate the OpRisk capital model, and inform risk management priorities
Explanation: B is correct. Scenario analysis: addresses the limitations of historical data for tail risk estimation. Process: facilitate workshops with business and risk experts → identify key scenarios (e.g., major cyber attack, large-scale fraud, regulatory fine) → estimate probability (1-in-50 year event?) and impact ($100M? $1B?) → use as model input. Scenarios are subjective — anchoring bias, availability bias, and group-think can distort estimates. Workshop facilitation skills are critical. A is historical analysis. C is market risk. D mixes concepts.
Question 18
What are 'Business Environment and Internal Control Factors' (BEICAFs) in the AMA framework?
Select an option first.
Correct answer: B — Qualitative and quantitative assessments of the risk environment and control quality that, under the AMA, were used to adjust the OpRisk capital estimate for current conditions — examples include: risk appetite scores, audit findings, KRI levels, process quality indicators, and control testing results. They allowed capital to reflect the current control environment, not just historical losses
Explanation: B is correct. BEICAFs: one of the four AMA data elements. They allow the capital estimate to be adjusted based on the current risk and control environment — if controls have improved (better KRIs, cleaner audit results), capital can be reduced; if the environment has deteriorated, capital increases. Challenge: calibrating the adjustment is highly subjective. This was one reason the AMA was phased out in Basel IV. A is an event category. C and D are different concepts.
Question 19
What is the 'Generalised Pareto Distribution' (GPD) and why is it used in operational risk modelling?
Select an option first.
Correct answer: B — A flexible heavy-tailed probability distribution used in extreme value theory (EVT) to model the tail of a loss distribution above a high threshold — the GPD is motivated by the Pickands-Balkema-de Haan theorem: for a wide class of distributions, losses exceeding a high threshold converge to GPD regardless of the underlying distribution shape
Explanation: B is correct. GPD in EVT: F(x|u) = 1 - (1 + ξ(x-u)/σ)^(-1/ξ), where u = threshold, ξ = shape (tail heaviness), σ = scale. ξ > 0: heavy tail (most financial loss data). ξ = 0: exponential tail. ξ < 0: bounded tail (rare in financial risk). Advantage: theoretically motivated, asymptotically correct for modelling the tail. Used in Peaks-over-Threshold (POT) method. A describes financial return distributions. C describes frequency, not severity. D describes a Pareto distribution (special case of GPD).
Question 20
What is 'Peaks-over-Threshold' (POT) methodology in extreme value theory?
Select an option first.
Correct answer: B — A method that models only losses exceeding a high threshold using the Generalised Pareto Distribution — fitting the GPD to the exceedances above the threshold to estimate the tail distribution, which is then used to compute high-quantile (99.9th percentile) capital estimates
Explanation: B is correct. POT: (1) Choose a threshold u (e.g., $1M); (2) Collect all losses exceeding u; (3) Fit a GPD to the excess losses (Xi - u); (4) Use the fitted GPD to extrapolate to the 99.9th percentile. Advantage over block maxima: uses more data (all exceedances vs only the block maximum). Challenge: threshold selection — too low includes non-extreme observations; too high leaves too few data points. A describes selection, not the method. C is about frequency. D is a naive approach.
Question 21
What is 'expected loss' (EL) vs 'unexpected loss' (UL) in operational risk capital?
Select an option first.
Correct answer: B — Expected loss: the average operational loss anticipated over a given period, typically covered by pricing (fees charged to business lines) and provisions. Unexpected loss: the volatility around expected loss — tail losses at high confidence levels (99.9% over 1 year). Capital is held against unexpected loss; EL should be covered by revenues and provisions
Explanation: B is correct. EL vs UL: EL = frequency × average severity — the 'budgeted' cost of operational risk that should be embedded in pricing. UL = P99.9 − EL (or sometimes just P99.9 depending on regulatory regime). Capital (economic or regulatory) covers UL. Under Basel, capital = 99.9th percentile VaR. If EL is already provisioned, some regulators allow capital = VaR − EL. A has a time-dimension error. C is wrong. D is wrong.
Question 22
What is a 'Loss Event Database' (LED) in operational risk management?
Select an option first.
Correct answer: B — A centralised repository where all operational loss events meeting the capture threshold are recorded — containing event details (date, description, business line, event type, financial impact, cause, and control failure). The LED is the foundation for: capital modelling (ILD), trend analysis, root cause analysis, and management reporting
Explanation: B is correct. LED: the operational risk equivalent of credit risk's loan loss database. Quality of the LED determines quality of the OpRisk capital model. Key fields: gross loss amount, recovery (insurance, legal), business unit, Basel event category, accounting date, discovery date, root cause, and risk control breakdown. The LED is confidential but banks share aggregated loss data through consortia like ORX. A is a credit risk database. C is ORX (external database). D is a market risk tool.
Question 23
What is the '10x Rule' used in scaling external loss data?
Select an option first.
Correct answer: B — A heuristic used to adjust external operational loss data to make it relevant for a bank of a specific size — scaling by (Own_BI / External_Bank_BI)^β, where β ≈ 0.7-0.8. Larger banks have larger losses but not proportionally larger (losses scale with revenue at less than 1:1)
Explanation: B is correct. Size-scaling external loss data: a $10B loss at a major bank does not equal a $10B expected loss for a smaller bank. The scaling factor uses the ratio of BI (or gross income) raised to a power β < 1 to account for sub-linear scaling. Other scaling methods: total assets, number of transactions, headcount. The choice of scaling method significantly affects the modelled loss. A and C are not the 10x rule. D is a data history requirement, not scaling.
Question 24
What is 'truncation' in operational risk data and how is it handled?
Select an option first.
Correct answer: B — The exclusion of small losses below the capture threshold from the internal loss dataset — when fitting severity distributions, truncation must be accounted for using truncated maximum likelihood estimation; otherwise the fitted distribution will underestimate loss frequency and overestimate average loss severity
Explanation: B is correct. Truncation: losses below the capture threshold (e.g., $10,000) are not recorded, truncating the lower tail of the severity distribution. Standard MLE without truncation adjustment produces biased parameters. Corrected MLE: condition the likelihood on the loss exceeding the threshold. Importance: the number of unrecorded losses below threshold also needs to be estimated (frequency correction). A is not truncation — outliers are a separate issue. C and D are different data management choices.
Question 25
What is 'fitting distributions' to operational loss data and what statistical test is commonly used?
Select an option first.
Correct answer: B — Using maximum likelihood estimation (MLE) to find the distribution parameters that best fit the observed data — the goodness-of-fit is typically tested using: Kolmogorov-Smirnov test (overall fit), Anderson-Darling test (weighted toward the tail — more relevant for OpRisk), or QQ-plots (visual)
Explanation: B is correct. Distribution fitting: (1) Choose candidate distributions (lognormal, Weibull, Pareto, GPD); (2) Estimate parameters via MLE; (3) Test goodness of fit. Anderson-Darling is preferred over K-S for operational risk because it gives more weight to the tail, which is most important for capital estimation. QQ-plots: compare theoretical vs empirical quantiles — deviations in the tail indicate poor tail fit. A is exploratory data analysis. C is regression. D is a categorical test not used for continuous distributions.
Question 26
What is 'dependency modelling' between operational risk cells and why does it matter?
Select an option first.
Correct answer: B — The modelling of correlations between different risk cells (business line × event type combinations) — if cells are independent, total capital = √(Σ capital_i²); if perfectly correlated, total capital = Σ capital_i. Most banks use a correlation matrix or copula to model the aggregation, producing a total capital between these extremes
Explanation: B is correct. Dependency/aggregation: when aggregating OpRisk capital across cells, the assumption about correlation matters enormously. Independence assumption: significantly reduces total capital (diversification benefit). Perfect correlation: no diversification benefit. Copulas: allow modelling of non-linear dependence — tail dependence (losses in different cells tend to occur simultaneously in extreme scenarios). Under Basel AMA, banks often used correlations of 0-1 — the choice significantly affects total capital. A and C are wrong. D is a control interdependency concept.
Question 27
What is 'operational risk appetite' and how is it expressed?
Select an option first.
Correct answer: B — The amount and type of operational risk an organisation is willing to accept in pursuit of its strategic objectives — expressed through: (1) qualitative statements ('we do not tolerate fraud'); (2) quantitative metrics (maximum acceptable annual operational loss as % of revenue; KRI thresholds; zero tolerance for specific event types)
Explanation: B is correct. Operational risk appetite: part of the wider risk appetite framework. OpRisk-specific elements: tolerance for fraud losses (zero tolerance for internal fraud is common), acceptable level of system downtime, maximum regulatory fine budget, cyber incident severity tolerance. Used to: drive control investment decisions, set KRI limits, and prioritise risk mitigation. A is a historical statistic. C is regulatory capital. D is a probability estimate.
Question 28
What is 'risk and control self-assessment' (RCSA) and what is its purpose?
Select an option first.
Correct answer: B — A structured process where business units systematically identify their key operational risks and assess the effectiveness of existing controls — typically conducted through workshops, questionnaires, or interviews. The output is a risk register or heat map showing inherent risk (before controls) and residual risk (after controls)
Explanation: B is correct. RCSA: a foundational tool of the operational risk management framework. Steps: (1) Identify key risks in each process; (2) Rate inherent risk (likelihood × impact before controls); (3) Assess existing controls (effectiveness rating); (4) Calculate residual risk. The gap between inherent and residual risk identifies control weaknesses. Limitations: self-assessment introduces bias — business units may underestimate risks or overrate their controls. A is external audit. C is KRI monitoring. D is SREP/supervisory review.
Question 29
What are 'Key Risk Indicators' (KRIs) and how do they differ from Key Performance Indicators (KPIs)?
Select an option first.
Correct answer: B — KRIs are forward-looking metrics that provide early warning signals of increasing operational risk exposure or control deterioration — e.g., staff turnover rate (people risk), system downtime hours, number of transaction errors, volume of exception approvals. KPIs measure performance outcomes (revenue, cost, customer satisfaction) rather than risk levels
Explanation: B is correct. KRI vs KPI: KRIs signal potential future losses before they occur — they're risk leading indicators. Examples: IT KRIs: patch compliance rate, system availability %; Fraud KRIs: rejected transaction rate, number of customer complaints about fraud; Process KRIs: reconciliation exceptions, late payments. The distinction from KPIs: KPIs measure business outcomes; KRIs measure risk health. A reverses them. C conflates them. D is incorrect — both can be quantitative or qualitative.
Question 30
What is a 'near miss' in operational risk management?
Select an option first.
Correct answer: B — An event that could have resulted in a financial loss but was caught before causing harm — equally important as actual loss events for risk management because they reveal process weaknesses and control vulnerabilities. Near misses should be captured in the loss database and trigger root cause analysis
Explanation: B is correct. Near miss capture: near misses (also called potential losses or foiled events) are valuable because they are more frequent than actual large losses and reveal where controls are fragile. Example: a payment that was queued for a wrong account but caught by a checker before execution. Near misses are subject to reporting bias (people may not report near misses). Encouraging near-miss reporting requires a psychologically safe, non-punitive culture. A is a customer impact concept. C is a threshold truncation issue. D is a scenario concept.
More free FRM topics
Ten questions in
- The ones you miss are saved as a drill you can repeat
- Your place is kept, on this device and any other
- A streak, if that is the thing that gets you back tomorrow
Every question on this page stays free and open either way.