Risk Toolkit › Operational Risk
Risk Toolkit · Controls
Operational Risk
The risk of loss from failed processes, people or systems rather than market moves — a risk you aren’t paid to take, so the goal is control, not optimisation.
01Overview
Operational risk is the risk of loss from failed processes, people or systems rather than market moves. This hub covers control frameworks and the three-lines-of-defence model that firms use to keep operational risk in check.
How it works
Operational risk is the risk of loss from inadequate or failed internal processes, people and systems, or from external events — think settlement errors, fraud, cyber incidents, legal failures and rogue trading. It differs from market and credit risk in that it is largely internal and not taken deliberately for return; you are not paid to bear it, so the goal is control rather than optimisation. It is inherently hard to quantify because losses are infrequent but can be severe (a single control failure can be existential), making loss-event data, near-miss reporting and scenario analysis central.
The three lines of defence — who owns, who challenges, who assures
In practice
Governance follows the three lines of defence: the business owns and manages its risks (first line), independent risk and compliance functions set policy and challenge (second line), and internal audit provides assurance (third line), with the board and regulators above. For bank capital, Basel’s 2017 standardised approach sizes the charge from a Business Indicator Component scaled by an Internal Loss Multiplier tied to a firm’s own loss history — directly rewarding good controls and a clean track record.
02Key methods
Business owns the risk; risk & compliance set policy and challenge; internal audit provides independent assurance.
Risk-and-control self-assessment plus key risk indicators to spot control weakness before losses occur.
Recording internal losses and near-misses — the backbone of measurement for an infrequent, severe risk.
Structured what-ifs for rare but existential events (fraud, cyber, rogue trading).
Basel’s 2017 standardised approach sizes the charge from a Business Indicator Component scaled by an Internal Loss Multiplier tied to a firm’s own loss history — directly rewarding good controls and a clean track record.
Sources & credits
Standard-setting and primary sources. Links open the original publication.
- Principles for the Sound Management of Operational Risk Standard-setter: The foundational operational-risk principles · bis.org
- Operational risk standardised approach — Executive Summary Primary: Official summary of the 2017 approach · bis.org
- The "four lines of defence model" for financial institutions Authoritative: On governance and assurance models · bis.org
See the wider framework
Operational risk sits inside enterprise risk management — see Frameworks & Governance.
