Financial Risk Management Operational Risk Management 2 — Questions and Answers
Question 1: The 'three lines of defense' model in operational risk management assigns risk management roles as:
- Board, senior management, and internal audit
- Front office, middle office, and back office
- Business units, risk and compliance functions, and internal audit (Correct answer)
- Credit, market, and operational risk departments
Correct answer: Business units, risk and compliance functions, and internal audit
The first line (business units) owns risk, the second line (risk/compliance) oversees it, and the third line (internal audit) independently assesses both.
Question 2: Which operational risk event type would a data breach involving customer information fall under?
- External fraud (Correct answer)
- Employment practices and workplace safety
- Clients, products, and business practices
- Execution, delivery, and process management
Correct answer: External fraud
A data breach resulting from an external cyberattack is classified as external fraud under Basel's seven operational risk event categories.
Question 3: Scenario analysis in operational risk is primarily used to:
- Replace internal loss data when historical losses are insufficient for tail estimation (Correct answer)
- Backtest the accuracy of operational risk VaR models
- Calculate the correlation between operational losses and market risk losses
- Determine regulatory capital under the Standardized Approach
Correct answer: Replace internal loss data when historical losses are insufficient for tail estimation
Scenario analysis captures low-frequency, high-severity tail risks where limited internal loss data exists, supplementing historical loss databases.
Question 4: What is 'model risk' in the context of operational risk?
- Market losses caused by incorrect pricing model assumptions
- The risk of adverse consequences from decisions based on flawed or misused models (Correct answer)
- The risk that quantitative analysts leave the firm, taking model expertise with them
- Regulatory risk arising from non-compliance with model validation requirements
Correct answer: The risk of adverse consequences from decisions based on flawed or misused models
Model risk arises when a model has errors, is used outside its intended scope, or produces outputs that are misinterpreted, leading to poor decisions.
Question 5: An operational risk loss that has a very low probability but extremely large magnitude is called:
- An expected loss event
- A high-frequency, low-severity (HFLS) event
- A low-frequency, high-severity (LFHS) event (Correct answer)
- A systemic risk event
Correct answer: A low-frequency, high-severity (LFHS) event
LFHS events, such as major fraud or catastrophic IT failures, are rare but can cause disproportionately large losses requiring capital buffer.
Question 6: Cyber risk is most commonly managed under which risk category in enterprise risk frameworks?
- Market risk, due to its effect on asset prices
- Credit risk, as cyberattacks can impair loan portfolios
- Operational risk, as it stems from failed systems and external events (Correct answer)
- Liquidity risk, as cyberattacks can trigger deposit outflows
Correct answer: Operational risk, as it stems from failed systems and external events
Cyber risk is classified as operational risk because it arises from technology system failures and malicious external events.
The 'three lines of defense' model in operational risk management assigns risk management roles as: