top of page
1.png

SWIFT

INTELLECT

FRM Part 2 Operational Resilience: Cyber Risk, Third Parties and Business Continuity

1 day ago
3 min read
FRM Part 2 Operational Resilience: Cyber Risk, Third Parties and Business Continuity
FRM Part 2 Operational Resilience: Cyber Risk, Third Parties and Business Continuity

Operational resilience is an important part of the 2026 FRM Part II curriculum, especially as financial institutions become more dependent on technology, cloud services, external vendors, and interconnected systems.


For 2026, Operational Risk and Resilience represents 20% of FRM Part II. GARP's curriculum specifically includes cyber-resilience and operational resilience, third-party outsourcing risk, operational risk mitigation, governance, and risk reporting.

Candidates should understand how cyber risk, third-party dependencies, and business continuity fit together rather than studying them as completely separate subjects.


What Is Operational Resilience?


Operational resilience is broader than simply preventing operational failures.

The objective is for a financial institution to continue delivering important operations when disruption occurs and to respond, recover, and adapt effectively.


The Basel Committee's operational resilience framework covers governance, operational risk management, business continuity planning and testing, mapping critical dependencies, third-party dependency management, incident management, and resilient information and communication technology.


For exam purposes, think of operational resilience as:

Identify critical operations → understand dependencies → prepare for disruption → respond → recover → learn and improve.


Cybersecurity vs Cyber-Resilience


A common mistake is treating cybersecurity and cyber-resilience as identical.

Cybersecurity focuses heavily on protecting systems and information from cyber threats.

Cyber-resilience goes further. It considers whether the organization can continue operating and recover if a cyber incident actually succeeds.


The 2026 learning objectives for the required Cyber-resilience: Range of Practices reading require candidates to understand cyber-resilience, cyber-risk governance, testing, incident response, resilience metrics, information sharing, and the governance of interconnected third-party providers.


Imagine a bank suffers a ransomware attack.

Preventive controls such as access management and security testing belong to cyber-risk management. But once critical systems become unavailable, the questions change:

  • Can essential services continue?

  • How quickly can systems be restored?

  • Who manages the incident?

  • Are backup systems usable?

  • How should customers, regulators, and other stakeholders be informed?

Those are resilience questions.

Why Third-Party Risk Matters


Financial institutions often outsource technology, processing, compliance, data management, and other activities.


Outsourcing a service does not eliminate responsibility for the associated risk.

The Federal Reserve's outsourcing guidance states that using a service provider does not relieve a financial institution's board or senior management of responsibility for activities performed by that provider. Institutions are expected to conduct appropriate risk management and oversight.


The 2026 FRM curriculum includes both Guidance on Managing Outsourcing Risk and a Third-Party Risk Management case study.


Candidates should therefore recognize important controls such as:

Due diligence: Assess the provider before entering the relationship.

Contractual controls: Clearly establish responsibilities, service expectations, security requirements, and access rights.

Ongoing monitoring: A provider that was acceptable when selected may become riskier later.

Concentration risk: Heavy dependence on one technology, cloud provider, or vendor can create a single point of failure.

Exit planning: A firm needs alternatives if a critical provider becomes unavailable.


Business Continuity and Operational Resilience


Business continuity management is another concept candidates should distinguish from operational resilience.


A business continuity plan (BCP) establishes how the organization will maintain or restore important processes following disruption.


The 2026 learning objectives cover business continuity within operational risk identification and mitigation, including business impact analysis, contingency planning, recovery time objectives, and recovery point objectives.


Two terms are especially useful:

Recovery Time Objective (RTO): How quickly a service or process should be restored.

Recovery Point Objective (RPO): How much data loss can be tolerated, measured by the point to which data must be recovered.


A candidate should not confuse them:

RTO = acceptable downtime.RPO = acceptable data loss.

Business continuity therefore supports operational resilience, but resilience is wider because it also includes governance, dependencies, cyber capabilities, incident management, and learning from disruption.


How the Three Risks Connect FRM Part 2 Operational Resilience


Consider a bank that relies on an external cloud provider to operate its online banking platform. FRM Part 2 Operational Resilience

A cyberattack affects the provider.


That single scenario creates several layers of risk:

Cyber risk: The attack compromises systems.

Third-party risk: The affected infrastructure belongs to an external provider.

Business continuity risk: Customers may lose access to banking services.

Operational resilience: The bank must determine whether it can continue critical operations, recover within acceptable limits, communicate effectively, and prevent similar disruption in the future.


This interconnected thinking is particularly useful for FRM Part II because GARP describes the exam as emphasizing the application of risk-management tools and techniques, rather than isolated definitions. The exam contains 80 equally weighted multiple-choice questions and lasts four hours.


What to Remember for the 2026 FRM Part II Exam


When an operational-resilience scenario appears, ask four questions:

What critical operation is threatened? Who or what does it depend on? How will the organization continue or recover? Who is responsible for managing the risk?

The central idea is simple:

Operational resilience is not about assuming disruptions can always be prevented. It is about ensuring critical operations can withstand, respond to, and recover from disruption when prevention fails.

Comments


bottom of page