Knight Capital deployed code to eight production servers on August 1, 2012. One server received the wrong code and started routing test orders into live markets. Forty-five minutes later, the firm had lost $440 million and would be sold within the year. The deployment process had no automated check that all eight servers ran the same release. A single key risk indicator on deployment-version drift would have flagged the problem in seconds. The exam tests whether you can name the metric and design the control.
Internal loss data is the foundation of every quantitative op-risk model. Banks log every event above a reporting threshold (typically $10,000 or $20,000) into a central database with a fixed schema: date, business line, Basel category, gross loss, recovery, root cause, and remediation status.
The threshold matters. Set it too high and you miss the body of the distribution. Set it too low and you bury the team in nuisance events that distort frequency estimates.
Common mistakes
- Confusing KRI with KPI. A trade settlement same-day rate of 99.4% is a KPI: it measures past performance. The number of trades requiring manual intervention is a KRI: it predicts elevated likelihood of future error. Trap: a question gives a metric and asks for the type.
- Computing OR-gate probability as the maximum. OR gates sum probabilities (with overlap correction); they do not take the max. Trap: a question gives three independent root causes at probabilities 0.04, 0.01, 0.005 and offers 0.04 as choice C: that is the largest, not the OR. The right answer is approximately 0.055.
- Using inherent risk to set capital. Capital is sized to residual risk after controls, not inherent risk. A red inherent score with a green residual score is a normal outcome of strong controls.
Bottom line
- RCSA is the workhorse bottom-up tool: each business unit scores inherent risk before controls and residual risk after, on likelihood and impact heatmaps that drive committee escalation.
- KRI vs KPI vs KCI: KRI is forward-looking risk, KPI is backward-looking performance, KCI is control effectiveness. Each has a distinct threshold and escalation path.
- Swiss cheese model views safety as layers of defenses with holes; an event happens when holes align. The fix is to add layers or shrink holes, not eliminate either.
- Bowtie diagrams map causes on the left, the central event in the middle, and consequences on the right, with preventive controls left and recovery controls right.
Exam shortcut
When a question gives a metric and asks for the indicator type, ask whether the metric predicts future risk (KRI), describes past performance (KPI), or measures control effectiveness (KCI). The trap answer always swaps two of the three. For fault trees, AND multiplies, OR sums (with a small-overlap correction). For RCSA, the heatmap color drives action: green accepts, yellow monitors, red remediates.
The full lesson (about 3,330 words, 22 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
- 21
- 22
- 23
- 24
Browse all free FRM Part II lessons or jump into free FRM Part II practice questions.