This lesson explores the often-overlooked but critically important area of operational risk: the risk of loss from failed internal processes, people, systems, or external events.
6.1 Defining Operational Risk
Operational risk is defined by the Basel Committee as the risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events. This definition includes legal risk but excludes strategic and reputational risk . Operational risk is a core part of the Basel framework and is a key component of risk management curricula .
6.2 Sources of Operational Risk
The causes of operational losses are diverse and can be more difficult to predict than credit or market risk.
-
People: Human error, fraud, lack of training, or employee misconduct.
-
Processes: Flawed internal procedures, process execution failures, or model errors.
-
Systems: IT infrastructure failures, cybersecurity breaches, or software bugs.
-
External Events: Natural disasters, pandemics, regulatory changes, or terrorism.
6.3 The Three Lines of Defense Model
This is the industry standard model for organizing risk management and internal controls within a bank .
-
First Line of Defense (Operational Management): This is the front line. Operational managers own and manage risk on a day-to-day basis. They are responsible for implementing effective internal controls and following procedures. Examples include the loan origination team, the trading desk, or the IT helpdesk.
-
Second Line of Defense (Risk and Compliance Functions): This line oversees and supports the first line. It includes specialist risk management and compliance functions that set standards, monitor risks (e.g., through Risk and Control Self-Assessment – RCSA), and provide guidance.
-
Third Line of Defense (Internal Audit): This is the independent assurance function. Internal Audit provides objective and independent assurance to the board and senior management on the effectiveness of governance, risk management, and internal control processes .
6.4 Management and Mitigation
-
Risk and Control Self-Assessment (RCSA): A process used by operational managers (1st line) to identify, assess, and prioritize operational risks and the controls that mitigate them.
-
Key Risk Indicators (KRIs): Metrics used to monitor the level of operational risk. Examples include staff turnover rates, system downtime, or the number of failed trades .
-
Business Continuity Planning (BCP): Developing plans to ensure the bank can continue critical operations during and after a disruptive event .
Â