Framework library · Risk management and assessment

Operational risk management

Operational risk is the risk of loss from failed processes, people and systems, or from external events. The usual tool is the risk and control self-assessment: each process owner rates the risks in their process, names the key control and says whether it works. What makes it useful is testing those ratings against what actually happened, because self-assessed controls tend to look better than they are.

LevelIntermediate
TimeAn hour per process with its owner, or a day or two to cover a business unit
Who to involveEach process owner for their own process, the risk or compliance lead to challenge the ratings, and whoever keeps the incident and loss log.
Also calledrisk and control self-assessment, RCSA, ORM, operational risk assessment, op risk

Use it when

  • You run many repeatable processes (ordering, provisioning, change, billing, field work) and need to know where they are most likely to fail.
  • A regulator, auditor or enterprise customer asks how operational risk is assessed and controlled.
  • Incidents keep recurring and you want to know whether the controls meant to stop them work.
  • You need a baseline before automating or outsourcing a process.

Avoid it when

  • The risks are strategic or market-driven, such as a competitor's entry. Use a risk register and enterprise risk management.
  • You need to set how much risk each category may carry. That is enterprise risk management. Operational risk management works within those limits.
  • One process needs a detailed failure analysis, step by step. FMEA goes deeper.
  • There is no incident or loss log. Start one first: without it the self-assessment cannot be tested.

How to run it

  1. List the processes

    The processes that deliver and bill the service, such as order to activate, change management, network monitoring, billing and third-party access. One row per significant risk event in each.

  2. Write each risk event with its cause

    What happens and why, tagged by cause: people, process, systems or external events. The cause decides the fix; a training course will not fix a systems cause.

  3. Score the inherent risk

    Likelihood and impact from 1 to 5, as if the key control did not exist.

  4. Rate the key control

    Effective, partly effective, ineffective or not yet tested. Effective takes the score down by 60% and partly effective by 30%. An untested control counts for nothing, so the residual equals the inherent score.

  5. Check the rating against losses

    Enter the loss events or incidents from the last 12 months. A control rated effective while losses continue is flagged for challenge.

  6. Set indicators for what remains

    For each residual risk of 10 or more, set a key risk indicator with a threshold, such as the number of changes made without a second approver, so the next review starts from data.

Work through it

Answer the questions below, or load the worked example to see a finished one. The drawing updates as you type. Export the result as a PowerPoint deck, a Word document, an Excel workbook, a PDF or plain text.

What you type stays in this browser, so you can close the page and come back to it. It is not sent to Blue Prysm or anyone else, and the exports are made here, on your device. Privacy policy.

Mistakes to avoid

  • Rating controls effective because they exist. Effective means tested and shown to work. Most first self-assessments are optimistic.
  • Recording the cause as "human error". Ask what made the error easy: a missing check, a confusing screen, a target that rewarded speed.
  • Leaving out external causes that sit with suppliers, such as a wholesale provider's repair times. Outsourcing the work does not outsource the risk.
  • Running the assessment once a year and filing it. Losses and indicators should change the ratings between reviews.

Where it comes from

The standard definition comes from banking supervision. The Basel Committee on Banking Supervision defines operational risk as the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events, and brought it into capital rules in Basel II (June 2004). Its Principles for the Sound Management of Operational Risk (2011, revised March 2021) list risk and control self-assessment among the tools for identifying and assessing it. Source.

Use it with

Work through it with us

The frameworks here are free to use as they stand. If you would rather work through the question behind this one with us, these are the ways an engagement starts.