The operational monitoring of an enterprise is managed through a tiered network of Executive Risk Committees. The primary operational body is the Group Operational Risk Committee (ORC), a cross-functional executive panel that meets monthly to review the organization’s risk profile.
                      ┌─────────────────────────────────┐
                      │    BOARD RISK COMMITTEE (BRC)   │
                      └─────────────────▲───────────────┘
                                        │ (Escalations)
                      ┌─────────────────┴───────────────┐
                      │ GROUP OPERATIONAL RISK COMM.    │
                      │ (Chaired by Chief Risk Officer) │
                      └─▲───────────────▲─────────────▲─┘
                        │               │             │
        ┌───────────────┴─┐     ┌───────┴───────┐   ┌─┴───────────────┐
        │ Technology Risk │     │ Third-Party   │   │ Business Line   │
        │ Sub-Committee   │     │ Sub-Committee │   │ Risk Committees │
        └─────────────────┘     └───────────────┘   └─────────────────┘

The ORC is chaired by the Chief Risk Officer (CRO) and includes senior executives from business operations, information technology, legal, compliance, human resources, and business continuity. This broad representation ensures that operational risk discussions address interdependencies across different units, such as a major technology update impacting compliance workflows or customer service channels.
The committee operates under formal charters that define voting majorities, quorum metrics, and clear escalation paths. If a Key Risk Indicator (KRI) breaches a critical red threshold, or if a major operational vulnerability remains unmitigated past its target completion date, the issue is automatically escalated to the ORC. The committee then reviews the corrective action plan and, if necessary, reports the exposure to the Board Risk Committee.