Operational Risk
What is Operational Risk?
The risk of loss resulting from inadequate or failed internal processes, people, systems, or external events in day-to-day business operations.
Terms that appear alongside operational risk
Each of these is named in at least one of the same controls as operational risk. The number is how many controls name both.
- governance 13 shared controls
- resilience 12 shared controls
- compliance 12 shared controls
- business continuity 9 shared controls
- operational resilience 9 shared controls
- risk appetite 8 shared controls
- risk management framework 8 shared controls
- risk assessment 7 shared controls
Frameworks that govern operational risk
What the standards actually require on operational risk
Requirements naming operational risk across 6 standards, quoted from the control text.
The Board is ultimately accountable for oversight of the entity operational risk management, including business continuity and the management of service provider arrangements.
CPS230-13 · Board Accountability for Operational Risk Management →Plan, implement, and control risk management processes within operational planning.
AS9100D-8.1.2 · Operational Risk Management →HKMA SPM Operational Risk + Resilience + Recovery + Outsourcing modules. OR OPERATIONAL RISK MANAGEMENT: (1) OR-1 Operational Risk Management - sound operational risk governance + risk identification + assessment + mitigation + monitoring + reporting + RCSA +...
HKMA-SPM-OR-RR-SA-OperationalResilience · HKMA SPM Operational Risk (OR-1), Operational Resilience (OR-2), Recovery Planning (RR-1), Outsourcing (SA-2) →Calculate operational risk capital using the single standardised approach based on the Business Indicator Component and (at supervisory discretion) an Internal Loss Multiplier derived from historical operational loss experience.
BASEL3-OPE-1 · Operational Risk - Standardised Approach →Identify, track, and demonstrate compliance with applicable laws, regulations, contractual obligations, and industry standards relevant to the services delivered to the client.
SIG-L-01 · Compliance and Operational Risk →The IRM Risk Architecture + Strategy + Protocols (RASP) framework defines the governance + structural + behavioural enabling elements of effective enterprise risk management.
IRM-Architecture-Strategy-Protocols-Appetite-Culture-Board-Audit-Committee-CRO-Three-Lines · IRM RASP - Risk Architecture + Strategy + Protocols + Risk Appetite Statement + Risk Culture + Board + Audit Committee + Chief Risk Officer + Three Lines of Defence + Tone at the Top →Questions people ask about operational risk
What is Operational Risk?
Why is Operational Risk important for compliance?
Which compliance frameworks address Operational Risk?
Where can I learn more about Operational Risk?
See how Operational Risk applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.