hard · FRM Part 2 Operational Risk
A bank identifies a 'severe-but-plausible' scenario for its Mortgage Lending service where a malware infection destroys all processing data. The bank's Impact Tolerance for this service is 24 hours. The stress test shows that while the systems can be recovered in 12 hours (RTO), the most recent off-site backup is 36 hours old (RPO).
Does this scenario represent a breach of the impact tolerance?
- Yes, but only if the bank is using the Advanced Measurement Approach (AMA) for capital, which explicitly weights RPO higher than RTO.
- Yes, because the data loss (36 hours) exceeds the time-to-restore threshold, implying customers are harmed beyond the tolerable limit.
- No, as long as the bank can prove it can manually re-enter the missing 36 hours of data within a separate 48-hour window.
- No, because the RTO of 12 hours is well within the 24-hour impact tolerance.
Sign up free to see the explanation and track your rank →
More FRM Part 2 Operational Risk practice
- Which of the following describes the 'One Big Loss' principle for heavy-tailed (subexponen
- In the Bow-Tie analysis framework, where do 'Preventive Controls' sit relative to the oper
- A customer consistently deposits $9,800 in cash at three dif… — This behavior is a classic
- The Standardized Measurement Approach (SMA) formula is composed of two primary factors: th
- What is the regulatory treatment for 'Boundary Events' regarding capital requirements unde
- In the Standardized Measurement Approach (SMA), the Business Indicator (BI) serves as a pr
- Under a proper governance framework, 'Model Limitations' must be:
- If the bank had a poor loss history (LC > BIC), what is the impact on its capital?