Learning Objectives:

  • Define operational risk and its sources.

  • Understand conduct risk and its regulatory importance.

  • Apply operational risk management techniques.

5.1 Defining Operational Risk

Operational risk is the risk of loss from failed internal processes, people, systems, or external events. The University of Nottingham module covers “operational and conduct risk in banking” as a key topic . The BTRM programme includes “operational risk management” as part of its bank risk management curriculum . Sources of operational risk include:

  • Processes: Errors in transaction processing, settlement failures.

  • People: Human error, fraud, inadequate training.

  • Systems: IT failures, cybersecurity breaches.

  • External Events: Natural disasters, regulatory changes.

5.2 Managing Operational Risk

Key techniques for managing operational risk include:

  • Risk and Control Self-Assessment (RCSA): A process where operational managers identify risks and evaluate controls.

  • Key Risk Indicators (KRIs): Metrics used to monitor operational risk.

  • Business Continuity Planning (BCP): Ensuring the bank can continue operations during a disruption.

  • Internal Controls: Segregation of duties, authorisation limits.

5.3 Conduct Risk

Conduct risk is the risk of poor outcomes for customers due to a bank’s behaviour. The University of Nottingham module covers “operational and conduct risk” as a key topic . Conduct risk is a focus of regulators and includes:

  • Treating Customers Fairly (TCF): Ensuring customers are treated fairly.

  • Mis-Selling: Avoiding the sale of unsuitable products.

  • Market Abuse: Prohibiting insider trading and market manipulation.