Barings Bank had $1.4 billion in capital and 233 years of history. Nick Leeson lost it in three months from a single trading desk in Singapore. No counterparty defaulted. No interest rate moved against the firm. The loss came from inadequate segregation of duties between the front office and the back office. The exam tests whether you can name what failed and which line of defense should have caught it.
The Basel Committee defines operational risk narrowly. It is the risk of loss resulting from inadequate or failed internal processes, people, systems, or external events. The definition deliberately excludes strategic risk (the risk of choosing the wrong business) and reputational risk (the risk of customer flight after a scandal). Legal risk is included because lawsuits arise from process failures.
Operational risk has three features that distinguish it from market and credit risk. First, it does not generate revenue. There is no risk premium attached to operational losses, only cost. Banks accept market risk to earn spreads and credit risk to earn coupons.
Common mistakes
- Including reputational risk in the Basel definition. Basel explicitly excludes reputational risk and strategic risk. Legal risk IS included. Trap: a question lists "reputational damage from social media" as a Basel-category event: none of the seven categories captures it directly. The right answer is that reputational risk is a downstream consequence, not a Basel category.
- Confusing internal fraud with external fraud when an employee was deceived. If an external party tricks an employee, the perpetrator is external. The category is external fraud even if the employee made the operational error that allowed it. Trap: choice C labels a wire-spoofing loss as "internal fraud due to employee negligence": that is wrong.
- Treating the three lines of defense as a hierarchy. The lines are independent functions, not a chain of command. Internal audit (line three) reports to the audit committee of the board, not to the CRO (line two). A choice that says "line three reports to line two" is wrong.
Bottom line
- Basel definition: operational risk is loss from inadequate or failed internal processes, people, systems, or external events. Excludes strategic and reputational risk; legal risk is included.
- Seven Basel II event categories: internal fraud, external fraud, employment practices, clients and products, damage to physical assets, business disruption, execution and delivery.
- Three lines of defense: business owns risk, risk management oversees, internal audit assures. Lines are independent functions, not a hierarchy (audit reports to the board, not the CRO).
- Identification approaches: top-down (scenario analysis, ERM mapping) finds tail risk with no precedent; bottom-up (RCSA, process mapping) finds process drift. A mature framework uses both.
Exam shortcut
When a case study question asks for the Basel category, identify the perpetrator first (internal employee with intent → internal fraud; external party → external fraud; no intent → execution-and-delivery), then check whether physical assets or systems were the primary loss driver. The category determines reporting; the line-of-defense diagnosis determines remediation. Mixing the two costs you both halves of a typical compound question.
The full lesson (about 3,069 words, 20 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
- 21
- 22
- 23
- 24
Browse all free FRM Part II lessons or jump into free FRM Part II practice questions.