Skip to main content
NFRisk Non-Financial Risk advisory Start a Conversation

Evidence-controlled external events

Risk events, converted into decision-useful scenarios.

Search documented operational and non-financial risk events by risk, topic, impact, sector, jurisdiction or period.

Each published case separates authoritative findings from the hypothetical scenario, framework relevance and NFRisk practitioner interpretation.

Explore the library

Find the scenario relevant to your decision.

18 approved scenarios currently published.

Additional developed cases remain private until they pass the same evidence controls.

NFR-0041 2024 Evidence-controlled

CrowdStrike / Delta Air Lines

What happens when a privileged security update fails at global scale?

Microsoft estimated that CrowdStrike's 19 July 2024 update affected 8.5 million Windows devices. CrowdStrike's technical RCA identified a 21-versus-20 input mismatch and an out-of-bounds read; Delta later reported approximately 7,000 flight cancellations over five days, a $380 million revenue impact and $170 million of additional operating expense.

Technology & Change Risk Third-Party & Concentration Risk Operational Resilience Third-party concentration
Open NFR-0041
NFR-0059 2023 Evidence-controlled

New York Stock Exchange

When a failed health check was marked successful, what remained untested?

An SEC order found that NYSE staff manually marked a failed disaster-recovery health check as successfully resolved without full investigation, escalation or approval. The next morning, 2,824 securities opened without their required auctions and more than 4,000 trades were later busted.

Operational Resilience Data & Control Integrity Technology & Change Risk Disaster recovery
Open NFR-0059
NFR-0037 2019 Evidence-controlled

Vastaamo

When missing logs prevent a sensitive-data breach from being reconstructed

Finland's Data Protection Ombudsman reported at least two unauthorised logins to Vastaamo's patient database and said insufficient logs prevented investigators from determining the exact breach timing, network addresses or methods. The regulator imposed a EUR 608,000 sanction in a decision it stated was not yet final.

Data & Control Integrity Operational Resilience Conduct & Governance Risk Sensitive data
Open NFR-0037
NFR-0073 2018 Evidence-controlled

Boeing 737 MAX

What changes when a safety-critical control can act on one sensor?

After two 737 MAX crashes killed 346 people, the FAA identified the original MCAS reliance on one angle-of-attack sensor among the safety issues that had to be addressed. The revised design uses both sensor inputs and disables MCAS for the flight when their difference exceeds a threshold.

Data & Control Integrity Technology & Change Risk Conduct & Governance Risk Automated decisioning
Open NFR-0073
NFR-0051 2018 Evidence-controlled

TSB Bank plc

When the data migrated successfully, was the platform ready?

The FCA and PRA found that TSB's data migrated successfully in April 2018, but the new platform failed immediately; disruption affected all branches and a significant proportion of 5.2 million customers, with £48.65 million in combined penalties.

Technology & Change Risk Operational Resilience Third-Party & Concentration Risk Change & release management
Open NFR-0051
NFR-0038 2017 Evidence-controlled

National Health Service in England

When patching gaps became front-line service disruption

WannaCry affected at least 80 of 236 NHS trusts in England and exposed gaps in patching, preparedness and national response coordination.

Operational Resilience Technology & Change Risk Cyber security
Open NFR-0038
NFR-0052 2012 Approved reference case

Royal Bank of Scotland, NatWest and Ulster Bank

When overnight processing failed, could the numbers still be trusted?

A 2012 software compatibility failure disrupted core banking processes, affected at least 6.5 million UK customers and resulted in £56 million of combined FCA and PRA penalties.

Technology & Change Risk Operational Resilience Data & Control Integrity Payments Risk
Open NFR-0052
NFR-0001 2006 Evidence-controlled

HSBC

What happens when a risk rating removes two-thirds of payment volume from automated monitoring?

The OCC found that HSBC Bank USA excluded wire transfers from 'standard' and 'medium' risk countries from automated BSA/AML monitoring, representing two-thirds of dollar volume for its payments business. The DOJ resolution included $1.256 billion of forfeiture and $665 million of civil penalties.

Financial Crime & Control Integrity Data & Control Integrity Conduct & Governance Risk Anti-money laundering
Open NFR-0001
NFR-0085 2006 Evidence-controlled

Volkswagen AG

When software could recognise the test, could certification still be trusted?

Volkswagen pleaded guilty in 2017 to three federal felonies after software distinguished emissions testing from normal driving; the US federal resolution totalled $4.3 billion and concerned approximately 590,000 diesel vehicles.

Conduct & Governance Risk Data & Control Integrity Physical, Safety & Environmental Risk System & back-out testing
Open NFR-0085
NFR-0003 2004 Evidence-controlled

BNP Paribas S.A.

When external warnings accumulated, could sanctions controls still be trusted?

BNP Paribas pleaded guilty in 2014 to conspiring to violate US sanctions law after moving more than $8.8 billion through the US financial system for sanctioned entities; the plea agreement imposed $8.9736 billion in total financial penalties.

Financial Crime & Control Integrity Data & Control Integrity Conduct & Governance Risk Sanctions
Open NFR-0003
NFR-0002 2002 Evidence-controlled

Wells Fargo

When misconduct signals reached leadership, why did the sales model remain?

Wells Fargo agreed to a $3 billion 2020 resolution over sales practices between 2002 and 2016. The DOJ statement of facts says leadership knew as early as 2002 that unlawful and unethical practices were increasing because of onerous goals and management pressure, while more than 23,000 employees were referred for investigation between 2011 and 2016.

Conduct & Governance Risk Data & Control Integrity Financial Crime & Control Integrity Conduct risk
Open NFR-0002
NFR-0044 1999 Evidence-controlled

Post Office Limited - Horizon

When system-generated shortfalls were treated as evidence, who tested the system?

The Court of Appeal found a material risk that apparent branch shortfalls were caused by Horizon bugs, errors or defects and quashed 39 appellants' convictions in 2021; legislation in 2024 then quashed qualifying convictions more broadly.

Data & Control Integrity Conduct & Governance Risk Data integrity Control assurance
Open NFR-0044

An important distinction

External scenarios are not NFRisk client case studies.

The named organisations in this library are documented external events. They are not presented as NFRisk clients. NFRisk Case Studies separately describe anonymised prior delivery experience; Insights provide longer-form analysis.

Apply the learning

Use a scenario to test a live control assumption.

The library is designed to support better questions. NFRisk can turn the relevant pattern into a focused diagnostic, risk architecture or delivery-assurance discussion.

Start a conversation