GARP FRM Part II Operational Risk Operational Resilience Cyber Risk Basel III

GARP FRM Part II Operational Risk and Resilience Study Guide

Study FRM Part II Operational Risk and Resilience through governance, controls, cyber risk, third parties, model risk, stress testing, capital and Basel reforms.

Updated
Table of Contents

GARP FRM Part II Operational Risk and Resilience

Explore source-grounded summaries, flashcards, reference tools and realistic mock practice.

GARP FRM Part II Operational Risk and Resilience Study Guide

Quick answer: Study the 24 chapters in four blocks: the operational-risk management cycle; cyber, financial-crime and third-party focus areas; model risk and stress testing; and economic capital plus Basel regulation. In every question, separate the cause, event, impact, control, owner and residual risk before choosing an answer.

The GARP FRM Part II Operational Risk and Resilience book tests how risk management works in real organizations. Definitions matter, but the difficult questions usually place governance, controls, data, incentives, dependencies and capital beside one another. The right answer depends on identifying which layer is being tested.

This is one printed Part II book. Complete it as an operational-risk unit, then combine it with the other Part II books and Current Issues for full-exam practice.

Block 1: The Operational-Risk Management Cycle

Chapters 1–7 form one connected process: define scope, govern risk, identify exposure, assess it, respond, report and integrate it with enterprise decisions.

Start with the Basel definition: operational risk is loss resulting from inadequate or failed internal processes, people and systems, or external events, and includes legal risk. Do not automatically classify every reputational or strategic consequence as the initiating operational event. Write the scenario as cause → event → impact.

Operational resilience adds a different question. Risk management tries to reduce the likelihood and severity of failure. Resilience assumes disruption can still occur and asks whether an important service can remain within its impact tolerance. This requires mapping people, process, technology, data, facilities and third parties.

Governance then assigns accountability:

  • the board approves the framework and appetite and oversees implementation;
  • senior management converts those decisions into policies, resources and escalation;
  • the first line owns and manages risk;
  • independent functions challenge and oversee;
  • internal audit provides independent assurance.

Risk identification uses both directions. Top-down work begins with strategy, objectives, important services and severe scenarios. Bottom-up work examines processes, tasks, systems, events and controls. A taxonomy supplies common language, but it is not a substitute for a firm-specific inventory.

Assessment methods answer different questions. RCSA compares inherent risk, control effectiveness and residual risk. KRIs show changing exposure or weakness. Scenario analysis helps with rare severe events. A loss distribution approach combines frequency and severity to estimate aggregate loss, but sparse tail data and changing controls make its assumptions important.

For mitigation, classify the response as avoid, reduce, transfer or accept. Then classify the control as preventive, detective, corrective or directive. Insurance may transfer specified financial loss; it does not transfer regulatory accountability, service dependency or every secondary consequence.

Block 2: Cyber, Financial Crime and Third Parties

Chapters 8–14 apply the core framework to major operational-risk areas.

Cyber resilience can be organized through identify, protect, detect, respond and recover. A firm needs asset and dependency visibility before it can manage vulnerabilities or test recovery. Security metrics should show risk and service impact, not merely activity counts. The Equifax case is useful because it joins a known vulnerability with asset visibility, patch governance and response failures.

Financial-crime chapters require a risk-based sequence: assess enterprise and customer risk, identify the customer and beneficial owner, understand purpose and expected activity, monitor actual behavior and escalate suspicion through the formal process. Avoid tipping off. For fraud, distinguish the actor’s conduct from the opportunity and control environment that allowed concealment.

Outsourcing has one rule worth memorizing exactly: the activity can be outsourced; accountability cannot. Assess criticality, provider capability, data access, concentration and substitutability. Contracts should cover service levels, security, audit, incidents, continuity, subcontracting, termination and regulatory access. Monitoring must continue through the relationship, and exit plans need realistic time, data and replacement capacity.

Investor-protection cases follow the same logic. Identify the client or market duty, the conflict or incentive, the control failure and the harmed stakeholder. Disclosure is not always enough; some conflicts must be prevented or otherwise managed.

Interactive Playground

Explore our interactive learning tools below

Sample Question 1 of 10

Which statement correctly explains Board risk reporting?

This is just a taste — the full course includes far more

Block 3: Model Risk and Stress Testing

Chapters 15–17 move from operational frameworks into decision models.

Model risk is the potential for adverse consequences from incorrect or misused output. A sound lifecycle covers development, implementation and use. Validation then addresses conceptual soundness, ongoing monitoring and outcomes analysis. Vendor models still require firm-level assessment, and a mathematically sound model can fail through data, coding, interface or use.

The case studies make those distinctions concrete:

  • the Gaussian-copula example highlights dependence and tail assumptions;
  • the spreadsheet example highlights uncontrolled logic, scope and review;
  • the Mars Orbiter example highlights inconsistent units and interfaces.

In each case, identify the decision, model boundary, technical failure, detection opportunity and governance response. “More review” is too vague unless the reviewer, evidence and required challenge are defined.

Bank stress testing links scenario design with losses, revenues, balance sheet and capital. State whether the balance sheet is static or dynamic. Project PPNR consistently with the scenario. Treat management actions as assumptions that must be feasible in timing, law and market conditions—not automatic relief.

Block 4: Economic Capital and Basel Regulation

Chapters 18–24 connect operational risk with capital allocation and the regulatory framework.

RAROC compares risk-adjusted earnings with allocated risk capital. The numerator should consistently reflect revenue, operating cost and expected loss; the denominator should be economic capital allocated to the activity. Comparisons require aligned horizons, confidence levels, transfer pricing and PIT or TTC default assumptions.

Economic-capital questions require precise tail language. VaR gives a loss percentile. Expected shortfall gives the average loss beyond the selected percentile. Aggregation can use summation, variance-covariance, copulas or full simulation, but diversification is only as reliable as the dependence assumptions—and normal-period relationships may fail in stress.

The regulation sequence is easier when each reform is tied to its problem:

  1. Basel I: broad credit-risk weights and limited risk sensitivity.
  2. Basel II: standardized and IRB credit approaches, operational-risk capital and three pillars.
  3. Basel 2.5: stronger trading-book treatment through stressed VaR and incremental risk charge.
  4. Basel III: stronger capital quality, leverage backstop, buffers, liquidity and resolution planning.
  5. Final Basel III reforms: model constraints, revised standardized methods, CVA changes, operational-risk standardization and the output floor.

For operational-risk capital, preserve the calculation order: identify the Business Indicator, map it to the Business Indicator Component, then apply the relevant Internal Loss Multiplier treatment. Keep gross loss, recoveries and net loss separate. An unusual loss is not automatically excludable.

A Direct Revision Routine

Use one page for every chapter and write these seven lines:

  1. Object: process, important service, customer, model, provider or capital measure.
  2. Cause: the condition that creates exposure.
  3. Event: the uncertain failure or misconduct.
  4. Impact: financial, service, legal, customer or systemic consequence.
  5. Owner: board, management, first line, independent function or audit.
  6. Response: control, resilience capability, transfer, capital or acceptance.
  7. Residual risk: what remains after the response.

Then practise the close pairs: operational risk versus consequence; prevention versus resilience; inherent versus residual risk; KRI versus control; design versus operating effectiveness; outsourcing versus accountability; development testing versus independent validation; sensitivity versus scenario; VaR versus expected shortfall; regulatory versus economic capital; PIT versus TTC; and Business Indicator versus BIC.

Move to full Part II practice when you can explain each pair without notes and connect risk identification to RCSA, controls to residual risk, important services to impact tolerances, providers to concentration, models to validation, stress scenarios to capital and Basel reforms to the weakness each one addresses. Continue through the remaining books from the GARP FRM exam-preparation hub.

Frequently Asked Questions

1 Is Operational Risk and Resilience the complete FRM Part II curriculum?

No. It is one of five printed Part II books. Candidates also need the other printed books and the required Current Issues readings before treating their preparation as full Part II coverage.

2 What does the Operational Risk and Resilience book cover?

The supplied book has 24 chapters covering governance, identification, measurement, controls, reporting, cyber resilience, financial crime, third parties, model risk, stress testing, economic capital and Basel reforms.

3 What is the official FRM Part II exam format?

GARP describes Part II as 80 equally weighted multiple-choice questions completed in four hours across all Part II domains.

4 Why do the book-level mocks allow 60 minutes?

Twenty questions in 60 minutes preserves the official Part II pace of three minutes per question. These are topical book-level papers, not full Part II exams.

5 Is 70% the official GARP pass mark?

No. GARP reports FRM results on a pass/fail basis and does not publish a fixed percentage pass mark. The course uses 70% only as an internal book-level mastery target.

Keep learning

View all insights

Ready to Prepare for GARP FRM Part II Operational Risk and Resilience?

Use source-grounded study tools and realistic practice to build accurate recall and exam-day confidence.

Explore Course Preparation