Equifax patched the Apache Struts vulnerability for some servers in March 2017 but missed one. Attackers found the unpatched server in May, exfiltrated 147 million consumer records over 76 days, and the company waited six weeks after detection before disclosing. The technical failure was one missed patch. The governance failure was that no one owned end-to-end resilience for the consumer-data service. The exam tests both halves and asks which BCBS principle each maps to.
ERM is the governance umbrella that integrates market, credit, operational, liquidity, and strategic risk. The point is to surface risks that no single silo would catch. A new product might pass market-risk approval, credit-risk approval, and operational-risk approval separately but combine into a large concentrated exposure that no individual function flagged.
A sound ERM framework has four elements. Risk governance defines who decides what: a board risk committee, a CRO reporting to that committee, executive risk committees by risk type, and business-line risk owners.
The ERM framework's value is most visible when a single event hits multiple risk types: a cyber attack causes operational loss, regulatory fine, customer attrition, and equity selloff in one...
Common mistakes
- Treating regulatory capital as the only number that matters. Banks hold the maximum of regulatory and economic capital, and economic capital is usually higher because it targets a higher confidence level. Trap: a question asks "how much capital does the bank hold?" and offers the regulatory number: that is the floor, not the held amount.
- Confusing reverse stress testing with regular stress testing. Regular stress tests apply a scenario and compute the loss. Reverse stress tests start from "what scenario causes failure" and back into the variables.
- Tipping off a customer about a SAR. SARs are confidential. The bank cannot tell the customer one was filed, even when closing the account. Tipping off is a criminal offense. Trap: choice C says "the bank should explain to the customer why the account is being closed": that risks tipping off and is wrong.
Bottom line
- ERM framework integrates governance, appetite, and culture across all risk types so trade-offs surface. Risk appetite cascades from board to business-unit limits, catching cross-silo concentrations.
- Regulatory capital is rule-based (Basel, conservative parameters); economic capital is bank-specific (internal model, empirical). Banks hold the maximum of the two.
- Stress testing complements VaR with plausible-but-severe scenarios; reverse stress testing starts from failure and backs into causes, most valuable for tail-risk discovery.
- BCBS Cyber 2018 organizes eleven principle areas: governance, identification, protection, detection, response, testing, situational awareness, learning, third-party, communication, metrics.
Exam shortcut
When a case study asks which BCBS cyber principle was breached, expect multi-mapping: most real failures touch governance, identification, protection, AND detection at minimum. Pick the most direct fit and the one or two adjacent principles, not just one. For AML questions, the litmus test is whether the bank applied home-regulator standards group-wide; the trap answer always lets the local subsidiary off the hook.
The full lesson (about 3,461 words, 23 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
- 21
- 22
- 23
- 24
Browse all free FRM Part II lessons or jump into free FRM Part II practice questions.