Microsoft PowerPoint – OR 3 – Risk Identification (1)
| Examples of Exposures |
|---|
| Critical third parties |
| Key distribution channels |
| Important clients |
| Essential systems |
| Principal regulator |
| Main drivers of revenues |
| Sources of goodwill |
| Key persons |
| Examples of Vulnerabilities |
|---|
| Issues in control systems |
| Overdue resolutions of issues |
| Stand-alone systems |
| Revenue channels at risk |
| Unmonitored operations or people |
| Blind spots |
| Unmaintained systems |
| BCP overdue for testing |
| Systems overdue for updates |

| Event-Type Category (Level 1) | Definition |
|---|---|
| Internal fraud | Losses due to acts of a type intended to defraud, misappropriate property or circumvent regulations, the law or company policy, excluding diversity/discrimination events, which involves at least one internal party |
| External fraud | Losses due to acts of a type intended to defraud, misappropriate property or circumvent the law, by a third party |
| Employment Practices and Workplace Safety | Losses arising from acts inconsistent with employment, health or safety laws or agreements, from payment of personal injury claims, or from diversity/discrimination events |
| Clients, Products & Business Practices | Losses arising from an unintentional or negligent failure to meet a professional obligation to specific clients (including fiduciary and suitability requirements), or from the nature or design of a product |
| Damage to Physical Assets | Losses arising from loss or damage to physical assets from natural disaster or other events |
| Business disruption and system failures | Losses arising from disruption of business or system failures |
| Execution, Delivery & Process Management | Losses from failed transaction processing or process management, from relations with trade counterparties and vendors |
| Category (Level 1) | Category (Level 2) | Activity Examples |
|---|---|---|
| Internal Fraud | Unauthorized Activity | Transactions not reported (intentional); transaction type unauthorized (with monetary loss); mismarking of position (intentional) |
| Theft and Fraud | Fraud/credit fraud/worthless deposits; theft/extortion/embezzlement/robbery; misappropriation of assets, malicious destruction of assets; forgery; check kiting; smuggling; account takeover/impersonation/etc.; tax noncompliance/evasion (willful); bribes/kickbacks; insider trading (not on firm’s account) |
| Category (Level 1) | Category (Level 2) | Activity Examples |
|---|---|---|
| External Fraud | Theft and Fraud | Theft/robbery; forgery; check kiting |
| Systems Security | Hacking damage; theft of information (w/ monetary loss) |
| Category (Level 1) | Category (Level 2) | Activity Examples |
|---|---|---|
| Employment Practices and Workplace Safety | Employee relations | Compensation, benefit, termination issues; organized labor activity |
| Safe environment | General liability (e.g., slip and fall); employee health and safety rules events; workers compensation | |
| Diversity and discrimination | All discrimination types |
| Category (Level 1) | Category (Level 2) | Activity Examples |
|---|---|---|
| Clients, Products, and Business Practices | Suitability, Disclosure, and Fiduciary | Fiduciary breaches/guideline violation; suitability/disclosure issues (e.g., KYC); retail customer disclosure violations; breach of privacy; aggressive sales; account churning; misuse of confidential information; lender liability |
| Improper Business or Market Practices | Antitrust; improper trade/market practices; market manipulation; insider trading (on firm’s account); unlicensed activity; money laundering | |
| Product Flaws | Product defects (e.g., unauthorized); model errors | |
| Selection, Sponsorship, and Exposure | Failure to investigate client per guidelines; exceeding client exposure limits | |
| Advisory Activities | Disputes over performance of advisory activities |
| Category (Level 1) | Category (Level 2) | Activity Examples |
|---|---|---|
| Damage to physical assets | Disasters and other events | Natural disaster losses; human losses from external sources (e.g., terrorism, vandalism) |
EXAMPLE –
| Category (Level 1) | Category (Level 2) | Activity Examples |
|---|---|---|
| Business Disruption and System Failures | Systems | Hardware; software; telecommunications; utility outage/disruptions |
| Category (Level 1) | Category (Level 2) | Activity Examples |
|---|---|---|
| Execution, Delivery & Process Management | Transaction Capture, Execution and Maintenance | Miscommunication; data entry, maintenance or loading error; missed deadline or responsibility; model/system misoperation; accounting error/entity attribution error; other task misperformance; delivery failure; collateral management failure; reference data maintenance |
| Monitoring and Reporting | Failed mandatory reporting obligation; inaccurate external report (loss incurred) | |
| Customer Intake and Documentation | Client permissions/disclaimers missing; legal documents missing/incomplete | |
| Customer/Client Account Management | Unapproved access given to accounts; incorrect client records (loss incurred); negligent loss or damage of client assets | |
| Trade Counterparties | Nonclient counterparty misperformance; misc. nonclient counterparty disputes | |
| Vendors and Suppliers | Outsourcing; vendor disputes |
Microsoft PowerPoint – OR 3 – Risk Identification (1)
Microsoft PowerPoint – OR 3 – Risk Identification (1)
| Bank tier 1 – Level 1 – 2 risks | |
|---|---|
| Business Disruption | |
| Conflict of Interest (Market Abuses) | |
| Financial Crimes | |
| Financial Data Integrity Risk | |
| Financial Data Integrity Risk | |
| Improper Trading Practice (Market Manipulation) | |
| Improper Use of Information (Client and Firm) | |
| Inaccurate or Untimely Regulation or External Reporting | |
| Inadequate Supervision | |
| Inadequate Technology Resiliency | |
| Inadequate Third-party Management | |
| Ineffective Technology Change | |
| Internal Attack (Client and Firm) | |
| Transaction / Capture Validation Error | |
| Workforce Misconduct | |
| Payment firm – Level 1 – 2 risks | |
|---|---|
| Operations Risk (A) | Service Delivery Disruption |
| Inadequate Monitoring Tools | |
| System Capacity Gap | |
| Operational Delivery Errors | |
| Damage to Physical Assets | |
| Service Delivery Quality (Failure) | |
| Supplier Failures (Utilities or Others) | |
| Information Security Risk (C,I) | Accidental Data Loss or Corruption (Integrity) |
| Accidental Confidentiality Breach | |
| Malicious Data Corruption (Integrity) – Cybercrime | |
| Malicious Confidential Data Breach | |
| Malicious Act (Internal) & Internal Fraud | |
| Technology Vulnerabilities (Internal) Identified by an External Party | |
| Technology Risks | Technology Obsolescence |
| Maintenance Overdue (Hardware or Software) | |
| Technology Product Delivery Failure | |
| Hardware Systems and Technology Failures | |
| Software Systems and Technology Failures | |
| Testing Failures | |
| Compatibility / Integration Issues | |
| Discontinuity in IT Third-Party Supplier | |

The classification of controls is the final component of a risk taxonomy. Internal controls are often easier to categories since the practice of internal controls is well-developed, and the internal audit discipline has provided a lot of structure in the field. There are four major types of controls –
Risk identification is the process of recognizing potential threats that can affect an organization's operations, enabling management to take steps to mitigate or accept those risks.
Risk identification is crucial for preparedness, as it helps a company anticipate potential threats and determine the best strategies to mitigate or manage them.
The main steps are identifying the risks, assessing their impact, creating mitigation strategies, and monitoring the risks continuously.
Top-down risk identification starts from the executive level, focusing on strategic risks, while bottom-up identifies risks at the departmental or individual process level.
Risk assessment follows risk identification, evaluating the severity and likelihood of identified risks to prioritize how they should be managed.
Common tools include risk wheels, scenario analysis, process mapping, and event/loss data analysis.
An RCSA is a process where business units identify operational risks and assess the effectiveness of their current controls in managing these risks.
Vulnerabilities are weak points in a company's operations that could lead to significant losses, and identifying them helps mitigate risk exposure.
Operational risk taxonomy categorizes risks into levels, such as internal fraud, external fraud, and system failures, to better manage and assess risks.
Risk identification should be conducted annually or after significant changes in the business environment, with more frequent assessments for growing or technology-driven firms.