
Best Practices For Assessing Operational Risks And Controls - Session 1 of 3
RiskSpotlight
Overview
This video introduces best practices for assessing operational risks and controls, emphasizing risk management as a business tool for strategic execution and objective achievement. It critiques current industry practices, highlighting that many risk assessments are perceived as mere compliance exercises, failing to provide current risk views or support business decisions. The session outlines key triggers for risk assessment, such as major decisions or strategic shifts, and advocates for a more granular, objective-linked approach to risk definition and measurement. It also touches upon the importance of defining risks at the right level of detail and connecting them to business objectives to enhance their practical value for the first line of defense.
Save this permanently with flashcards, quizzes, and AI chat
Chapters
- Risk management should be viewed as a business management tool to improve strategy and execution, not just a compliance requirement.
- Risk assessment is a measurement exercise to identify critical risks, inadequate controls, and areas needing close monitoring.
- The goal of risk assessment is to facilitate effective business management, helping achieve strategies and objectives, and protecting assets.
- A visual representation shows risks being identified, measured (with size indicating exposure), and then prioritized for escalation, remediation, or monitoring.
- Risk assessments should be triggered by significant events or decisions that could alter the organization's risk profile.
- Key triggers include making major decisions (e.g., outsourcing, new product launches), defining business strategy and objectives, and developing scenarios.
- Internal and external environment changes (e.g., senior executive resignations, increased threat levels) also necessitate risk reassessment.
- Periodic assessments (e.g., quarterly, annually) provide a point-in-time view, similar to annual car servicing, to take stock of current risk exposure.
- Current Risk and Control Self-Assessments (RCSAs) often fail to provide a current view of risk exposures.
- Many firms are moving towards a hybrid approach combining periodic and trigger-based assessments.
- RCSAs are frequently perceived as 'tick-box' exercises, not supporting business decision-making.
- There's a significant skill and training gap in the first line of defense regarding risk management.
- Some institutions are shifting focus from inherent risk to residual risk and control effectiveness to simplify assessments.
- Inadequate integration of risk management into core business activities and decision-making by senior leadership and the second line.
- A compliance-focused mentality, aiming for the bare minimum rather than value creation.
- Second line's focus on satisfying boards and risk committees rather than facilitating first-line risk management.
- Using a single, generalized risk assessment methodology for all risks, leading to inconsistent data.
- Human biases and a lack of motivation to learn from other industries or disciplines like complexity theory and decision science.
- Risks should be defined at a granular level, specific enough to assign clear ownership and facilitate meaningful assessment.
- High-level risks (e.g., 'Technology Risk') are difficult to own and assess accurately.
- Granular risks (e.g., 'Disruption to online banking IT system due to cyber attack') allow for precise ownership and assessment.
- Defining risks at the right granularity makes it easier for the first line to relate to and manage them.
- The TSB system disruption incident highlighted issues with generic risks in the register, hindering effective management.
- Risk management should be integrated with business objectives, as the first line focuses on achieving these objectives.
- The Basel definition of operational risk (processes, people, systems, external events) omits 'objectives', unlike ISO 31000 and COSO.
- ISO 31000 defines risk as the 'effect of uncertainty on objectives'.
- Linking risks to objectives helps the first line understand the impact of risk management on business success.
- A 'risk chain' tool, similar to a bow-tie diagram, can visualize objectives, events, causes, and impacts.
- Different risks require different measurement approaches; a one-size-fits-all method is ineffective.
- Assessment measures should allow for comparison of risk exposure across different business units or over time.
- Measures can include likelihood (left side of risk chain) and impacts like financial loss, regulatory fines, reputational damage, and operational disruption (right side).
- Common frameworks aggregate multiple specific impacts into broader categories (e.g., financial, reputational), which can lead to ambiguity.
- It's crucial to define clear rules for what constitutes a risk (specific to the firm, directly leading to impact) versus causes or controls.
Key takeaways
- Operational risk assessment is most effective when treated as a proactive business management tool, not just a compliance exercise.
- Risk assessments should be triggered by specific events and decisions that could impact the organization's risk profile.
- Current industry practices often result in risk assessments that are outdated, lack actionable insights, and fail to support business decisions.
- Defining risks at a granular level is essential for clear ownership and effective management by the first line of defense.
- Linking risks directly to business objectives makes risk management relevant and demonstrates its contribution to strategic success.
- A standardized, yet flexible, approach to defining and measuring risks is needed to ensure consistency and comparability.
- The effectiveness of risk assessment hinges on moving beyond a 'tick-box' mentality to a genuine integration into daily business activities.
Key terms
Test your understanding
- Why is it important to view risk management as a business tool rather than solely a compliance function?
- What are the key triggers that should prompt a reassessment of operational risks within an organization?
- How does defining risks at a granular level improve their management by the first line of defense?
- What is the significance of connecting operational risks directly to business objectives?
- What are the potential drawbacks of using overly generalized assessment measures for operational risks?