NoteTube

Best Practices For Assessing Operational Risks And Controls - Session 1 of 3
1:24:28

Best Practices For Assessing Operational Risks And Controls - Session 1 of 3

RiskSpotlight

7 chapters7 takeaways12 key terms5 questions

Overview

This video introduces best practices for assessing operational risks and controls, emphasizing risk management as a business tool for strategic execution and objective achievement. It critiques current industry practices, highlighting that many risk assessments are perceived as mere compliance exercises, failing to provide current risk views or support business decisions. The session outlines key triggers for risk assessment, such as major decisions or strategic shifts, and advocates for a more granular, objective-linked approach to risk definition and measurement. It also touches upon the importance of defining risks at the right level of detail and connecting them to business objectives to enhance their practical value for the first line of defense.

How was this?

Save this permanently with flashcards, quizzes, and AI chat

Chapters

  • Risk management should be viewed as a business management tool to improve strategy and execution, not just a compliance requirement.
  • Risk assessment is a measurement exercise to identify critical risks, inadequate controls, and areas needing close monitoring.
  • The goal of risk assessment is to facilitate effective business management, helping achieve strategies and objectives, and protecting assets.
  • A visual representation shows risks being identified, measured (with size indicating exposure), and then prioritized for escalation, remediation, or monitoring.
Understanding the fundamental purpose of risk assessment as a proactive business tool is crucial for aligning risk management efforts with strategic goals rather than treating it as a mere bureaucratic task.
Identifying 100 risks but focusing efforts on the critical 4 or 5 that require escalation or remediation.
  • Risk assessments should be triggered by significant events or decisions that could alter the organization's risk profile.
  • Key triggers include making major decisions (e.g., outsourcing, new product launches), defining business strategy and objectives, and developing scenarios.
  • Internal and external environment changes (e.g., senior executive resignations, increased threat levels) also necessitate risk reassessment.
  • Periodic assessments (e.g., quarterly, annually) provide a point-in-time view, similar to annual car servicing, to take stock of current risk exposure.
Knowing when to conduct a risk assessment ensures that risk management remains relevant and responsive to changes, preventing risks from becoming blind spots and allowing for timely adjustments.
Assessing risks before launching a new product or outsourcing an IT system to understand potential new risks or changes in existing ones.
  • Current Risk and Control Self-Assessments (RCSAs) often fail to provide a current view of risk exposures.
  • Many firms are moving towards a hybrid approach combining periodic and trigger-based assessments.
  • RCSAs are frequently perceived as 'tick-box' exercises, not supporting business decision-making.
  • There's a significant skill and training gap in the first line of defense regarding risk management.
  • Some institutions are shifting focus from inherent risk to residual risk and control effectiveness to simplify assessments.
Understanding the common shortcomings in current risk assessment practices highlights the need for improvement and guides the adoption of more effective methodologies.
A study found that over half of firms were moving to a hybrid RCSA approach, indicating dissatisfaction with purely periodic assessments.
  • Inadequate integration of risk management into core business activities and decision-making by senior leadership and the second line.
  • A compliance-focused mentality, aiming for the bare minimum rather than value creation.
  • Second line's focus on satisfying boards and risk committees rather than facilitating first-line risk management.
  • Using a single, generalized risk assessment methodology for all risks, leading to inconsistent data.
  • Human biases and a lack of motivation to learn from other industries or disciplines like complexity theory and decision science.
Identifying the root causes of ineffective risk assessment is essential for developing targeted solutions and fostering a culture where risk management is truly embedded in business operations.
Organizations often treat risk assessment as a mechanical process, overlooking the human elements that influence data input and interpretation.
  • Risks should be defined at a granular level, specific enough to assign clear ownership and facilitate meaningful assessment.
  • High-level risks (e.g., 'Technology Risk') are difficult to own and assess accurately.
  • Granular risks (e.g., 'Disruption to online banking IT system due to cyber attack') allow for precise ownership and assessment.
  • Defining risks at the right granularity makes it easier for the first line to relate to and manage them.
  • The TSB system disruption incident highlighted issues with generic risks in the register, hindering effective management.
Properly defining risk granularity ensures accountability and enables the first line of defense to actively participate in and benefit from the risk assessment process.
Moving from a high-level risk like 'IT System Disruption' to a more specific 'Disruption to online banking IT systems due to cyber attack' to enable clear ownership.
  • Risk management should be integrated with business objectives, as the first line focuses on achieving these objectives.
  • The Basel definition of operational risk (processes, people, systems, external events) omits 'objectives', unlike ISO 31000 and COSO.
  • ISO 31000 defines risk as the 'effect of uncertainty on objectives'.
  • Linking risks to objectives helps the first line understand the impact of risk management on business success.
  • A 'risk chain' tool, similar to a bow-tie diagram, can visualize objectives, events, causes, and impacts.
Connecting risks directly to business objectives makes risk management relevant to the first line, demonstrating how managing uncertainty contributes to achieving strategic goals.
Using a risk chain to show how a 'disruption to customer business processes due to unexpected branch closures' impacts objectives like customer satisfaction and market share.
  • Different risks require different measurement approaches; a one-size-fits-all method is ineffective.
  • Assessment measures should allow for comparison of risk exposure across different business units or over time.
  • Measures can include likelihood (left side of risk chain) and impacts like financial loss, regulatory fines, reputational damage, and operational disruption (right side).
  • Common frameworks aggregate multiple specific impacts into broader categories (e.g., financial, reputational), which can lead to ambiguity.
  • It's crucial to define clear rules for what constitutes a risk (specific to the firm, directly leading to impact) versus causes or controls.
Selecting appropriate and granular assessment measures ensures that risk evaluations are meaningful, comparable, and provide a clear basis for decision-making and challenge.
Measuring 'damage to assets due to man-made disaster' might involve assessing the cost of replacing assets and potential regulatory fines, while 'intentional misselling' would focus on regulatory fines, customer compensation, and negative publicity.

Key takeaways

  1. 1Operational risk assessment is most effective when treated as a proactive business management tool, not just a compliance exercise.
  2. 2Risk assessments should be triggered by specific events and decisions that could impact the organization's risk profile.
  3. 3Current industry practices often result in risk assessments that are outdated, lack actionable insights, and fail to support business decisions.
  4. 4Defining risks at a granular level is essential for clear ownership and effective management by the first line of defense.
  5. 5Linking risks directly to business objectives makes risk management relevant and demonstrates its contribution to strategic success.
  6. 6A standardized, yet flexible, approach to defining and measuring risks is needed to ensure consistency and comparability.
  7. 7The effectiveness of risk assessment hinges on moving beyond a 'tick-box' mentality to a genuine integration into daily business activities.

Key terms

Operational RiskRisk AssessmentRisk ControlsRisk ManagementFirst Line of DefenseSecond Line of DefenseRCSA (Risk and Control Self-Assessment)Trigger-based AssessmentGranularityResidual RiskRisk ChainBusiness Objectives

Test your understanding

  1. 1Why is it important to view risk management as a business tool rather than solely a compliance function?
  2. 2What are the key triggers that should prompt a reassessment of operational risks within an organization?
  3. 3How does defining risks at a granular level improve their management by the first line of defense?
  4. 4What is the significance of connecting operational risks directly to business objectives?
  5. 5What are the potential drawbacks of using overly generalized assessment measures for operational risks?

Turn any lecture into study material

Paste a YouTube URL, PDF, or article. Get flashcards, quizzes, summaries, and AI chat — in seconds.

No credit card required