
| Main Components of Operational Risk Reporting | |
|---|---|
| 1. | Top-10 risks and risk outlook |
| 2. | Heatmap and risk register |
| 3. | Risk appetite metrics |
| 4. | KRIs and issue monitoring |
| 5. | Incidents and near misses |
| 6. | Action plans and follow-up |
| 7. | Emerging risks and horizon scan findings |
| KRI type | KRI Name | Threshold | Value | Value (t-1) | Score | Comment |
|---|---|---|---|---|---|---|
| Loss events KRIs | # events above tolerated threshold | 3 | 2 | 2 | G | |
| # of events without completed action plans | 3 | 4 | 4 | A | Delays in action plans following risk events in retail banking | |
| # repeated losses | 5 | 6 | 4 | G | ||
| Total value of losses | 1M | 500K | 400K | G | ||
| Total number of losses | 200 | 80 | 75 | G | ||
| Overdues | Overdue high- / medium-risk audit recommendations | 2 | 0 | 0 | G | |
| Overdue high-risk action plans | 0 | 0 | 0 | G | ||
| People Risk | % vacancies per team | 10 | 20 | 20 | A | Recruitment challenges and war for talent |
| % vacancies > 3M | 10 | 0 | 20 | G | ||
| (1-% of high performers) | 50 | 45 | 45 | G | ||
| % engagement score | 80 | 75 | 82 | A | Reorganization project impacts morale | |
| KRIs related to activities and controls | % weak controls | 10 | 20 | 30 | A | Situation improving and expected to be solved soon |
| % controls not tested | 20 | 15 | 20 | G | ||
| # issues raised | 10 | 10 | 20 | G |

| Reporting with Averages | Hidden Concentrations and Outliers |
|---|---|
| Uptime = 99.4% | Maximum Downtime = 3 hours 10 minutes |
| Sick days = 2.1 days/ staff | 3 burn-outs (absences of >90 days) 80% of absenteeism is absences of 1 or 2 days |
| Customer complaints = 285/quarter | 95% of complaints coming from 16% of the customers |
| Operational loss = $5,286 /incident | Max loss = $297,000 Mass loss < $700 (93%) |
| Average risk assessment for suppliers – Yellow (moderate risk) | One supplier – Red (high risk) |

| Risk Assessment Units (risk type or assessment scope) | First line review (assessment, testing, attestation) | Second line review (oversight, deep dive, testing) | Third line review (internal audit) |
|---|---|---|---|
| Cyber risk | |||
| Compliance | no data | ||
| Operational resilience | |||
| Fraud | |||
| Legal | |||
| Third-party management and outsourcing | |||
| Business Unit 1 | no data | ||
| Business Unit 2 | |||
| Legal entity A | no data | ||
| Legal entity B | |||
| Project 1 | no data | ||
| Project 2 | no data |
Operational risk reporting involves documenting and communicating an organization’s risk exposures, control weaknesses, incidents, and mitigation strategies to internal and external stakeholders.
Risk reporting helps decision-makers assess and manage operational risks, ensures compliance with regulatory requirements, and aligns risk management practices with the organization's risk appetite.
Audiences include the board's risk committee, executive committee, central operational risk function (CORF), business-line managers, and external stakeholders like regulators, clients, and suppliers.
A comprehensive report includes top risks, a heatmap or risk register, key risk indicators (KRIs), incidents, near misses, action plans, emerging risks, and a risk outlook.
The risk committee oversees the organization's risk management framework, ensuring that operations remain within the risk appetite, and addressing any control issues or significant incidents.
A risk heatmap visually represents operational risks based on their likelihood and impact, helping organizations prioritize risks and focus on mitigation efforts.
KRIs provide measurable data on risk exposure, control effectiveness, and potential incidents, allowing for proactive risk management and trend analysis.
The "reporting cake" divides risk information into tiers, providing varying levels of detail for different stakeholders, with the most important information presented to upper management.
Challenges include managing asymmetry in loss data, handling large volumes of small incidents, ensuring accurate escalation of major risk events, and aggregating qualitative risk data.
External risk reporting involves disclosing operational risks and incidents to regulators and investors, ensuring transparency and maintaining trust while complying with regulatory requirements.