Loading markets…
Get in touch

Risk Toolkit Operational Risk

🧩

Risk Toolkit · Controls

Operational Risk

The risk of loss from failed processes, people or systems rather than market moves — a risk you aren’t paid to take, so the goal is control, not optimisation.

01Process & people02Three lines of defence03Loss-event data04Controls

01Overview

Operational risk is the risk of loss from failed processes, people or systems rather than market moves. This hub covers control frameworks and the three-lines-of-defence model that firms use to keep operational risk in check.

How it works

Operational risk is the risk of loss from inadequate or failed internal processes, people and systems, or from external events — think settlement errors, fraud, cyber incidents, legal failures and rogue trading. It differs from market and credit risk in that it is largely internal and not taken deliberately for return; you are not paid to bear it, so the goal is control rather than optimisation. It is inherently hard to quantify because losses are infrequent but can be severe (a single control failure can be existential), making loss-event data, near-miss reporting and scenario analysis central.

The three lines of defence — who owns, who challenges, who assures

Governing body — Board & Risk Committee 1ST LINE Business owns & managesits own risk 2ND LINE Risk & Compliance set policy,oversee & challenge 3RD LINE Internal Audit independentassurance External audit & regulators — assurance from outside
Schematic. Each line is independent of the one it oversees: the business runs the controls, the second line challenges them, and internal audit assures the whole — with the board above and regulators outside.

In practice

Governance follows the three lines of defence: the business owns and manages its risks (first line), independent risk and compliance functions set policy and challenge (second line), and internal audit provides assurance (third line), with the board and regulators above. For bank capital, Basel’s 2017 standardised approach sizes the charge from a Business Indicator Component scaled by an Internal Loss Multiplier tied to a firm’s own loss history — directly rewarding good controls and a clean track record.

02Key methods

Three lines of defence

Business owns the risk; risk & compliance set policy and challenge; internal audit provides independent assurance.

RCSA & KRIs

Risk-and-control self-assessment plus key risk indicators to spot control weakness before losses occur.

Loss-event data

Recording internal losses and near-misses — the backbone of measurement for an infrequent, severe risk.

Scenario analysis

Structured what-ifs for rare but existential events (fraud, cyber, rogue trading).

§
How bank capital is sized

Basel’s 2017 standardised approach sizes the charge from a Business Indicator Component scaled by an Internal Loss Multiplier tied to a firm’s own loss history — directly rewarding good controls and a clean track record.

Sources & credits

Standard-setting and primary sources. Links open the original publication.

  1. Principles for the Sound Management of Operational Risk Standard-setter: The foundational operational-risk principles · bis.org
  2. Operational risk standardised approach — Executive Summary Primary: Official summary of the 2017 approach · bis.org
  3. The "four lines of defence model" for financial institutions Authoritative: On governance and assurance models · bis.org
Editorial Sourced from standard-setters & primary texts Reviewed: 8 Jul 2026

See the wider framework

Operational risk sits inside enterprise risk management — see Frameworks & Governance.

Open the tools →