Framework library · Risk management and assessment
Operational risk management
Operational risk is the risk of loss from failed processes, people and systems, or from external events. The usual tool is the risk and control self-assessment: each process owner rates the risks in their process, names the key control and says whether it works. What makes it useful is testing those ratings against what actually happened, because self-assessed controls tend to look better than they are.
Use it when
- You run many repeatable processes (ordering, provisioning, change, billing, field work) and need to know where they are most likely to fail.
- A regulator, auditor or enterprise customer asks how operational risk is assessed and controlled.
- Incidents keep recurring and you want to know whether the controls meant to stop them work.
- You need a baseline before automating or outsourcing a process.
Avoid it when
- The risks are strategic or market-driven, such as a competitor's entry. Use a risk register and enterprise risk management.
- You need to set how much risk each category may carry. That is enterprise risk management. Operational risk management works within those limits.
- One process needs a detailed failure analysis, step by step. FMEA goes deeper.
- There is no incident or loss log. Start one first: without it the self-assessment cannot be tested.
How to run it
List the processes
The processes that deliver and bill the service, such as order to activate, change management, network monitoring, billing and third-party access. One row per significant risk event in each.
Write each risk event with its cause
What happens and why, tagged by cause: people, process, systems or external events. The cause decides the fix; a training course will not fix a systems cause.
Score the inherent risk
Likelihood and impact from 1 to 5, as if the key control did not exist.
Rate the key control
Effective, partly effective, ineffective or not yet tested. Effective takes the score down by 60% and partly effective by 30%. An untested control counts for nothing, so the residual equals the inherent score.
Check the rating against losses
Enter the loss events or incidents from the last 12 months. A control rated effective while losses continue is flagged for challenge.
Set indicators for what remains
For each residual risk of 10 or more, set a key risk indicator with a threshold, such as the number of changes made without a second approver, so the next review starts from data.
Work through it
Answer the questions below, or load the worked example to see a finished one. The drawing updates as you type. Export the result as a PowerPoint deck, a Word document, an Excel workbook, a PDF or plain text.
What you type stays in this browser, so you can close the page and come back to it. It is not sent to Blue Prysm or anyone else, and the exports are made here, on your device. Privacy policy.
Mistakes to avoid
- Rating controls effective because they exist. Effective means tested and shown to work. Most first self-assessments are optimistic.
- Recording the cause as "human error". Ask what made the error easy: a missing check, a confusing screen, a target that rewarded speed.
- Leaving out external causes that sit with suppliers, such as a wholesale provider's repair times. Outsourcing the work does not outsource the risk.
- Running the assessment once a year and filing it. Losses and indicators should change the ratings between reviews.
Where it comes from
The standard definition comes from banking supervision. The Basel Committee on Banking Supervision defines operational risk as the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events, and brought it into capital rules in Basel II (June 2004). Its Principles for the Sound Management of Operational Risk (2011, revised March 2021) list risk and control self-assessment among the tools for identifying and assessing it. Source.
Use it with
Work through it with us
The frameworks here are free to use as they stand. If you would rather work through the question behind this one with us, these are the ways an engagement starts.