Welcome to the World of Operational Risk!

In your FRM Part I journey, you’ve spent a lot of time looking at Market Risk (changes in prices) and Credit Risk (people not paying you back). But what happens when the computer system crashes, an employee commits fraud, or a natural disaster hits the office? That is Operational Risk.

Think of it as the "risk of doing business." It is often called the "everything else" category, but it is just as dangerous as market or credit risk. In this chapter, we will learn how to define it, categorize it, and figure out how much capital a bank needs to set aside to cover it. Don't worry if it seems a bit broad at first—we'll break it down piece by piece!


1. What Exactly is Operational Risk?

According to the official Basel Committee definition, Operational Risk is the risk of loss resulting from inadequate or failed internal processes, people, and systems or from external events.

Important Note: This definition includes legal risk, but it specifically excludes strategic risk and reputational risk. This is a common trap on the exam!

Prerequisite Concept: What's excluded?

- Strategic Risk: Making a bad business decision (e.g., launching a product no one wants).
- Reputational Risk: People thinking poorly of your brand (though an operational failure often leads to reputational damage, the damage itself isn't "Operational Risk" under the formal definition).

Quick Review: If a lawyer sues the bank for a contract error, that's Operational Risk. If the CEO makes a bad 5-year plan, that is Strategic Risk (Not Operational Risk).


2. The Seven Event Categories

To make this manageable, regulators have split operational risk into seven specific categories. You should be familiar with these for the exam:

1. Internal Fraud: Employees stealing or lying (e.g., insider trading, rogue trading).
2. External Fraud: People outside the firm stealing (e.g., hacking, forged checks).
3. Employment Practices and Workplace Safety: Worker’s comp claims, discrimination lawsuits.
4. Clients, Products, and Business Practices: Mis-selling products to customers (e.g., the Wells Fargo "fake accounts" scandal).
5. Damage to Physical Assets: Terrorism, floods, fires, or earthquakes hitting the building.
6. Business Disruption and System Failures: IT crashes, software bugs, utility outages.
7. Execution, Delivery, and Process Management: Data entry errors, missing a deadline with a vendor, or failing to file a regulatory report.

Memory Aid: "I Eat Every Cookie During Business Exams"
(Internal, External, Employment, Clients, Damage, Business, Execution)


3. Frequency and Severity: The Two Pillars of Loss

When we talk about losses, we care about two things: How often they happen and how much they cost. Operational risk is unique because most of its losses fall into two extremes:

A. High-Frequency, Low-Impact (HFLI): These are like "paper cuts." They happen every day (like small credit card processing errors), they don't cost much individually, and we can predict them easily. We usually just treat these as a cost of doing business.

B. Low-Frequency, High-Impact (LFHI): These are the "black swans." They almost never happen, but when they do, they can bankrupt a firm (like a massive cyber-attack or a rogue trader losing billions). These are the ones that keep Risk Managers awake at night!

Key Takeaway: Operational Risk management focuses heavily on the "Tail Risk"—the very rare but very expensive events.


4. Modeling Operational Risk

To calculate how much money we need to set aside (Capital), we need to model the total loss. We do this by combining two different distributions:

Step 1: Loss Frequency (The "How Often")

We usually use the Poisson Distribution for this. Why? Because the Poisson distribution is designed to count the number of times an event occurs in a fixed interval of time.

The formula for the probability of having \(n\) events is:
\(P(n) = \frac{e^{-\lambda} \lambda^n}{n!}\)
Don't panic! Usually, you just need to know that \(\lambda\) (lambda) is the average number of events.

Step 2: Loss Severity (The "How Much")

We usually use the Lognormal Distribution for this. Why? Because dollar losses can't be negative, and the lognormal distribution has a "long tail" to the right, which perfectly represents those rare, massive losses we talked about earlier.

Step 3: Total Loss Distribution

When we combine Frequency and Severity, we get the Aggregate Loss Distribution. We use a technique called Monte Carlo Simulation or Convolution to do this. The goal is to find the 99.9% Value at Risk (VaR)—the amount of money we are 99.9% sure will cover our losses over a year.

Did you know? Unlike Market Risk, where we use 1-day or 10-day VaR, Operational Risk is almost always calculated over a 1-year time horizon.


5. Regulatory Capital: How Banks Calculate the "Safety Buffer"

In the "Valuation and Risk Models" section, it's vital to know how the Basel rules have evolved for calculating operational risk capital.

The Old Methods (Historical Context)

1. Basic Indicator Approach (BIA): Capital = 15% of the average Gross Income over the last 3 years.
2. The Standardized Approach (TSA): The bank is split into 8 business lines, and each line has its own percentage (12% to 18%) of Gross Income.

The New Method: The Standardized Measurement Approach (SMA)

Because the old methods were too simple and the internal models were too complex (and sometimes manipulated by banks), the regulators moved to the SMA. This is the current focus of the curriculum.

The SMA capital is calculated based on two components:
1. The Business Indicator (BI): A proxy for the bank's size based on its financial statements.
2. The Internal Loss Multiplier (ILM): This adjusts the capital based on the bank's actual history of losses over the last 10 years. If you have a history of being "accident-prone," your capital requirement goes UP!

Quick Review:
- Small Losses: Expected, predictable, handled by the business budget.
- Large Losses: Unexpected, unpredictable, handled by Economic Capital.


6. Common Mistakes to Avoid

- Mixing up Legal and Strategic Risk: Remember, Legal = Operational. Strategic = NOT Operational.
- Forgetting the Time Frame: Operational risk capital is usually calculated on a 1-year basis, whereas Market Risk is often much shorter.
- Assuming Normal Distribution: Never assume operational losses follow a Normal Distribution. They are "fat-tailed" and skewed (hence why we use Lognormal for severity).


7. Summary Key Points

- Definition: Risk from failed people, processes, systems, or external events.
- Categories: 7 levels (Internal Fraud, External Fraud, etc.).
- Frequency: Modeled by Poisson.
- Severity: Modeled by Lognormal.
- HFLI vs LFHI: High-frequency/Low-impact is common; Low-frequency/High-impact is the dangerous tail risk.
- Capital: Moving toward the Standardized Measurement Approach (SMA) which combines bank size (BI) with loss history (ILM).

Keep going! Operational Risk is a qualitative-heavy topic, but understanding these core quantitative concepts like the Poisson/Lognormal relationship will give you a major edge on the exam.