| Sr. No | Event Type | Acronym | Examples | Metrics | |
|---|---|---|---|---|---|
| Frequency | Severity | ||||
| 1 | Internal fraud | IF | Fraud and unauthorized activities by employees | 2% | 2% |
| 2 | External fraud | EF | Theft and fraud, hacking damage | 30% | 9% |
| 3 | Employment practices and workplace safety | EWPS | Contract termination issues, discrimination, employer’s liability | 15% | 5% |
| 4 | Clients, products, and business practices | CPBP | Client misinformation, complaints, and discounts due to errors, product misspecification | 22% | 52% |
| 5 | Damage to physical assets | DPA | Destruction of equipment, natural disasters, losses | 1% | 1% |
| 6 | Business disruption and system failures | BDSF | IT breakdown, outages | 2% | 5% |
| 7 | Execution, delivery, and process management | EDPM | Processing errors, missing documentation, vendor disputes | 28% | 27% |
Risk management cycle: Four actions of risk management.
| Category | Description |
|---|---|
| Heterogenous | Operational risk is a set of eclectic risks, with different causes, consequences, and distributions of losses. Even within a risk category, operational risk events can be very different. External fraud incidents range from stolen credit cards to ransomware. Internal fraud incidents include cash theft and rogue trading. |
| Idiosyncratic | Operational risk types such as EDPM are driven or mitigated by the quality of a firm’s processes and systems. Others such as DPA are often caused by external events. Largely though, operational risk can be mitigated or elevated by a firm’s ability and willingness to manage it. However, even for very risk-averse organizations, operational risk cannot be entirely eliminated through avoidance, hedging, or insurance. |
| Heavy tailed | Operational risk materializes, for most event types, in a multitude of small losses, and a small number of large losses several orders of magnitude bigger than the median of the distribution. |
| Interconnected | Despite heterogeneity, the different types of operational risk are partially correlated because several of them share common internal causes, such as weaknesses in certain controls, human errors, or poor risk culture; or common external causes, such as economic, political, and environmental events. |
| Dynamic | The nature and intensity of the many operational risk exposures depend on the activities of an organization or industry, and they evolve with these activities. The evolution of operational risk follows the development of the industry itself. |
Operational risk has unique characteristics which make it particularly challenging to manage and complex to model –
Note – This entire part on operational resilience has been taken from “Building the UK financial sector’s operational resilience”, which is discussed in the next slide.
| Resilience principles category | Banks should… |
|---|---|
| 1. Governance | Utilize their existing governance structure |
| 2. Operational risk management | Leverage their respective functions for the management of operational risk. |
| 3. Business Continuity planning and testing | Have business continuity plans in place. |
| 4. Mapping interconnections and interdependencies | Map the internal and external interconnections and interdependencies that are necessary for the delivery of critical operations. |
| 5. Third party dependency management | Manage their dependencies on relationships, to, third parties or intragroup entities. |
| 6. Incident management | Develop and implement response and recovery plans to manage incidents that could disrupt the delivery of critical operations. |
| 7. ICT including cybersecurity | Ensure resilient ICT including cybersecurity. |
Operational risk refers to losses resulting from inadequate internal processes, human error, system failures, or external events. It excludes market and credit risks but covers issues like fraud, cyberattacks, and regulatory fines.
An Operational Risk Management (ORM) framework is a structured approach to identifying, assessing, managing, and reporting operational risks within an organization, focusing on risk detection, evaluation, and mitigation.
Operational resilience focuses on adapting to emerging threats and maintaining critical services, whereas traditional business continuity primarily focuses on recovery from physical events like natural disasters.
Basel II outlines seven categories: Internal fraud, External fraud, Employment practices, Clients/products/business practices, Physical asset damage, Business disruption/system failures, and Execution/delivery/process management.
Legal risk involves potential financial losses due to breaches of laws or contracts, and it can occur across many operational risk categories, especially in employment practices and process management.
Reputational risk arises from operational failures and can cause long-term damage to a company's public image, impacting customer trust and market value, making it a key consideration despite regulatory exclusions.
Governance ensures that a company has a clear structure for managing risks, assigning roles and responsibilities, and overseeing risk management activities to maintain operational resilience.
Regulators like the FCA focus on ensuring firms maintain resilience by managing critical business services, defining impact tolerance levels, and adapting to disruptions in a way that protects customers and market integrity.
The Basel Committee on Banking Supervision (BCBS) emphasizes integrating operational resilience with existing ORM functions, ensuring business continuity, and managing third-party dependencies for critical operations.
Third-party dependency management involves monitoring and managing risks related to external suppliers or intragroup entities to ensure the continuity of critical business services and prevent operational disruptions.