FRM Part II · Operational Risk and Resilience · Free Lesson

Risk Measurement, Mitigation, and Reporting

Free GARP FRM Part II lesson in Operational Risk and Resilience. 22 min read, ~3,330 words.

Knight Capital deployed code to eight production servers on August 1, 2012. One server received the wrong code and started routing test orders into live markets. Forty-five minutes later, the firm had lost $440 million and would be sold within the year. The deployment process had no automated check that all eight servers ran the same release. A single key risk indicator on deployment-version drift would have flagged the problem in seconds. The exam tests whether you can name the metric and design the control.

Internal loss data is the foundation of every quantitative op-risk model. Banks log every event above a reporting threshold (typically $10,000 or $20,000) into a central database with a fixed schema: date, business line, Basel category, gross loss, recovery, root cause, and remediation status.

The threshold matters. Set it too high and you miss the body of the distribution. Set it too low and you bury the team in nuisance events that distort frequency estimates.

Read the full lesson, free →
Worked examples and practice. Free with a free account, no card.

Common mistakes

Bottom line

Exam shortcut

When a question gives a metric and asks for the indicator type, ask whether the metric predicts future risk (KRI), describes past performance (KPI), or measures control effectiveness (KCI). The trap answer always swaps two of the three. For fault trees, AND multiplies, OR sums (with a small-overlap correction). For RCSA, the heatmap color drives action: green accepts, yellow monitors, red remediates.

The full lesson (about 3,330 words, 22 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.

Learning objectives

Browse all free FRM Part II lessons or jump into free FRM Part II practice questions.