| Guidelines This chapter sets out principles for the management of operational risk. The principles cover the following areas: (i) governance; (ii) risk management environment; (iii) information and communication technology; (iv) business continuity and planning; and (v) role of disclosure. The contents of this chapter are based on: |
| Related standards |
| Related guidelines
|
| Other related publications
|
Operational risk is inherent in all banking products, activities, processes and systems, and the effective management of operational risk is a fundamental element of a bank's risk management programme. Sound operational risk management is a reflection of the effectiveness of the board of directors and senior management in administering their portfolio of products, activities, processes and systems.
Although operational risk management and operational resilience address different goals, they are closely interconnected. An effective operational risk management system and a robust level of operational resilience work together to reduce the frequency and the impact of operational risk events.
The following terms are used throughout this chapter and have the meaning given below:
| 1 | See FSB, Principles for an effective risk appetite framework, November 2013. |
Banks’ governance; risk management environment; information and communication technology; business continuity planning; and disclosure practices should not be viewed in isolation; rather, they are integrated components of the operational risk management framework (ORMF) and the overall risk management framework (including operational resilience) of the bank.
Sound internal governance forms the foundation of an effective ORMF. Governance of operational risk management has similarities but also differences relative to the management of credit or market risk. Banks' operational risk governance function should be fully integrated into their overall risk management governance structure.
Banks’ ORMF should adequately and proportionally apply the three lines of defence model to manage all operational risk subcategories, including ICT risk. These three lines of defence consist of: (i) business unit management; (ii) an independent corporate operational risk management function (CORF); and (iii) independent assurance.
Banks should ensure that each line of defence:
If in one business unit there are functions of both the first and second line of defence, then banks should document and distinguish the responsibilities of such functions in the first and second line of defence, emphasising the independence of the second line of defence.
Banks should have a policy that defines clear roles and responsibilities in relevant business units. The responsibilities of an effective first line of defence in promoting a sound operational risk management culture should include:
The responsibilities of an effective second line of defence should include:
The degree of independence of the CORF may differ among banks. At small banks, independence may be achieved through separation of duties and independent review of processes and functions. In larger banks, the CORF should have a reporting structure independent of the risk-generating business units and be responsible for the design, maintenance and ongoing development of the ORMF within the bank. The CORF typically engages relevant corporate control groups (eg Compliance, Legal, Finance and IT) to support its assessment of the operational risks and controls. Banks should have a policy which defines clear roles and responsibilities of the CORF, reflective of the size and complexity of the organisation.
An effective third line of defence should include:
Because operational risk management is evolving and the business environment is constantly changing, senior management should ensure that the ORMF's policies, processes and systems remain sufficiently robust to manage and ensure that operational losses are adequately addressed in a timely manner. Improvements in operational risk management depend heavily on senior management's willingness to be proactive and also act promptly and appropriately to address operational risk managers' concerns. Where appropriate, strategic and reputational risks should be considered by banks' operational risk management.
Supervisors should regularly assess banks' ORMF by evaluating banks' policies, processes and systems related to operational risk. Supervisors should ensure that there are appropriate mechanisms in place allowing them to remain apprised of banks' operational risk developments.
Supervisory evaluations of operational risk should include all areas described in these Principles. Where banks are part of a financial group, supervisors should ensure that there are processes in place to ensure that operational risk is managed in an appropriate and integrated manner across the group. In assessing banks' ORMF, cooperation and exchange of information with other supervisors, in accordance with established procedures, may be necessary.2 In certain circumstances, supervisors may choose to use external auditors in these assessment processes.3
Supervisors should take steps to ensure that banks address deficiencies identified through the supervisory review of banks' ORMF. Supervisors should use the tools most suited to the particular circumstances of banks and their operating environment. To ensure that supervisors receive current information on operational risk, supervisors may wish to establish reporting mechanisms directly with banks and external auditors (eg internal bank management reports on operational risk could be made routinely available to supervisors).
Supervisors should encourage banks' ongoing internal development efforts by monitoring, comparing and evaluating banks' recent improvements and plans for prospective developments.
The Committee believes that the Principles reflect good practices relevant to all banks. Nonetheless, it recommends that banks should take account of the nature, size, complexity and risk profile of their activities when implementing the Principles.
The board of directors should take the lead in establishing a strong risk management culture, implemented by senior management. The board of directors and senior management should establish a corporate culture guided by strong risk management, set standards and incentives for professional and responsible behaviour, and ensure that staff receives appropriate risk management and ethics training.
Banks with a strong culture of risk management and ethical business practices are less likely to experience damaging operational risk events and are better placed to effectively deal with those events that occur. The actions of the board of directors and senior management as well as the bank's risk management policies, processes and systems provide the foundation for a sound risk management culture.
The board of directors should establish a code of conduct or an ethics policy to address conduct risk. This code or policy should be applicable to both staff and board members, set clear expectations for integrity and ethical values of the highest standard, identify acceptable business practices, and prohibit conflicts of interest or the inappropriate provision of financial services (whether wilful or negligent). The code or policy should be regularly reviewed and approved by the board of directors and attested by employees; its implementation should be overseen by a senior ethics committee, or another board-level committee, and should be publicly available (eg on the bank's website). A separate code of conduct may be established for specific positions in the bank (eg treasury dealers, senior management).
Management should set clear expectations and accountabilities to ensure bank staff understands their roles and responsibilities for risk management, as well as their authority to act.
Senior management should ensure that an appropriate level of operational risk training is available at all levels throughout the organisation, such as heads of business units, heads of internal controls and senior managers. Training provided should reflect the seniority, role and responsibilities of the individuals for whom it is intended.
Strong and consistent board of directors and senior management support for operational risk management and ethical behaviour convincingly reinforces codes of conduct and ethics, compensation strategies, and training programmes.
Banks should develop, implement and maintain an operational risk management framework that is fully integrated into the bank's overall risk management processes. The ORMF adopted by an individual bank will depend on a range of factors, including the bank's nature, size, complexity and risk profile.
The board of directors and bank management should understand the nature and complexity of the risks inherent in the portfolio of bank products, services, activities, and systems, which is a fundamental premise of sound risk management. This is particularly important for operational risk, given operational risk is inherent in all business products, activities, processes and systems.
The components of the ORMF should be fully integrated into the overall risk management processes of the bank by the first line of defence, adequately reviewed and challenged by the second line of defence, and independently reviewed by the third line of defence. The ORMF should be embedded across all levels of the organisation including group and business units as well as new business initiatives' products, activities, processes and systems. In addition, results of the bank's operational risk assessment should be incorporated into the bank's overall business strategy development process.
The ORMF should be comprehensively and appropriately documented in board of directors approved policies and include definitions of operational risk and operational loss. Banks that do not adequately describe and classify operational risk and loss exposure may significantly reduce the effectiveness of their ORMF.
ORMF documentation should clearly:
| 4 | An inconsistent taxonomy of operational risk terms may increase the likelihood of failure to identify and categorise risks, or failure to allocate responsibility for the assessment, monitoring, control and mitigation of risks. For the particular case of cyber risk, see FSB, Cyber Lexicon, April 2023. |
The board of directors should approve and periodically review the operational risk management framework, and ensure that senior management implements the policies, processes and systems of the operational risk management framework effectively at all decision levels.
The board of directors should:
Strong internal controls are a critical aspect of operational risk management. The board of directors should establish clear lines of management responsibility and accountability for implementing a strong control environment. Controls should be regularly reviewed, monitored, and tested to ensure ongoing effectiveness. The control environment should provide appropriate independence/separation of duties between operational risk management functions, business units and support functions.
The board of directors should approve and periodically review a risk appetite and tolerance statement for operational risk that articulates the nature, types and levels of operational risk the bank is willing to assume.
The risk appetite and tolerance statement for operational risk should be developed under the authority of the board of directors and linked to the bank's short- and long-term strategic and financial plans. Considering the interests of the bank's customers and shareholders as well as regulatory requirements, an effective risk appetite and tolerance statement should:
The board of directors should approve and regularly review the appropriateness of limits and the overall operational risk appetite and tolerance statement. This review should consider current and expected changes in the external environment (including the regulatory context across all jurisdictions where the institution provides services); ongoing or forthcoming material increases in business or activity volumes; the quality of the control environment; the effectiveness of risk management or mitigation strategies; loss experience; and the frequency, volume or nature of limit breaches. The board of directors should monitor management adherence to the risk appetite and tolerance statement and provide for timely detection and remediation of breaches.
Senior management should develop for approval by the board of directors a clear, effective and robust governance structure with well-defined, transparent and consistent lines of responsibility. Senior management is responsible for consistently implementing and maintaining throughout the organisation policies, processes and systems for managing operational risk in all of the bank's material products, activities, processes and systems consistent with the bank's risk appetite and tolerance statement.
Senior management is responsible for establishing and maintaining robust challenge mechanisms and effective issue resolution processes. These should include systems to report, track and, when necessary, escalate issues to ensure resolution. Banks should be able to demonstrate that the three-lines-of-defence approach is operating satisfactorily and to explain how the board of directors, independent audit committee of the board, and senior management ensure that this approach is implemented and operating in an appropriate manner.
Senior management should translate the ORMF approved by the board of directors into specific policies and procedures that can be implemented and verified within the different business units. Senior management should clearly assign authority, responsibility and reporting relationships to encourage and maintain accountability, and to ensure the necessary resources are available to manage operational risk in line with the bank's risk appetite and tolerance statement. Moreover, senior management should ensure that the management oversight process is appropriate for the risks inherent in a business unit's activity.
Senior management should ensure that staff responsible for managing operational risk coordinate and communicate effectively with staff responsible for managing credit, market, and other risks, as well as with those in the bank who are responsible for the procurement of external services such as insurance risk transfer and other third-party arrangements (including outsourcing). Failure to do so could result in significant gaps or overlaps in a bank's overall risk management programme.
The managers of the CORF should be of sufficient stature within the bank to perform their duties effectively, ideally evidenced by a title that is commensurate with other risk management functions such as credit, market and liquidity risk.
Senior management should ensure that bank activities are conducted by staff with the necessary experience, technical capabilities and access to resources. Staff responsible for monitoring and enforcing compliance with the institution's risk policy should have authority independent from the units they oversee.
When designing the operational risk governance structure, a bank should take the following into consideration:
Senior management should ensure the comprehensive identification and assessment of the operational risk inherent in all material products, activities, processes and systems to make sure the inherent risks and incentives are well understood.
Risk identification and assessment are fundamental characteristics of an effective operational risk management system, and directly contribute to operational resilience capabilities. Effective risk identification considers both internal factors and external factors. Sound risk assessment allows the bank to better understand its risk profile and allocate risk management resources and strategies most effectively.
Examples of tools used for identifying and assessing operational risk include, but are not limited to, the following and may vary in sophistication depending on the analysis:
Banks should ensure that the operational risk assessment tools' outputs are:
These operational risk assessment tools can also directly contribute to a bank's operational resilience approach, in particular event management, self-assessment and scenario analysis procedures, as they allow banks to identify and monitor threats and vulnerabilities to their critical operations. Banks should use the outputs of these tools to improve their operational resilience controls and procedures.
Senior management should ensure that the bank's change management process is comprehensive, appropriately resourced and adequately articulated between the relevant lines of defence.
In general, a bank's operational risk exposure evolves when a bank initiates change, such as engaging in new activities or developing new products or services; entering into unfamiliar markets or jurisdictions; implementing new or modifying business processes or technology systems; and/or engaging in businesses that are geographically distant from the head office. Change management should assess the evolution of associated risks across time, from inception to termination (eg throughout the full life cycle of a product).5
| 5 | The life cycle of a product or service encompasses various stages from the development, ongoing changes, grandfathering and closure. Indeed, the level of risk may escalate for example when new products, activities, processes, or systems transition from an introductory level to a level that represents material sources of revenue or business-critical operations. |
A bank should have policies and procedures defining the process for identifying, managing, challenging, approving and monitoring change on the basis of agreed objective criteria. Change implementation should be monitored by specific oversight controls. Change management policies and procedures should be subject to independent and regular review and update, and clearly allocate roles and responsibilities in accordance with the three-lines-of-defence model, in particular:
A bank should have policies and procedures for the review and approval of new products, activities, processes and systems. The review and approval process should consider:
The review and approval process should include ensuring that appropriate investment has been made for human resources and technology infrastructure before changes are introduced. Changes should be monitored, during and after their implementation, to identify any material differences to the expected operational risk profile and manage any unexpected risks.
Banks should maintain a central record of their products and services to the extent possible (including the outsourced ones) to facilitate the monitoring of changes.
Senior management should implement a process to regularly monitor operational risk profiles and material operational exposures. Appropriate reporting mechanisms should be in place at the board of directors, senior management, and business unit levels to support proactive management of operational risk.
A bank should ensure that its reports are comprehensive, accurate, consistent and actionable across business units and products. To this end, the first line of defence should ensure reporting on any residual operational risks, including operational risk events, control deficiencies, process inadequacies, and non-compliance with operational risk tolerances. Reports should be manageable in scope and volume by providing an outlook on the bank's operational risk profile and adherence to the operational risk appetite and tolerance statement; effective decision-making is impeded by both excessive amounts and paucity of data.
Reporting should be timely and a bank should be able to produce reports in both normal and stressed market conditions.6 The frequency of reporting should reflect the risks involved and the pace and nature of changes in the operating environment. The results of monitoring activities should be included in regular management and board reports, as should assessments of the ORMF performed by the internal/external audit and/or risk management functions. Reports generated by or for supervisory authorities should also be reported internally to senior management and the board of directors, where appropriate.
Operational risk reports should describe the operational risk profile of the bank by providing internal financial, operational, and compliance indicators, as well as external market or environmental information about events and conditions that are relevant to decision making. Operational risk reports should include:
Data capture and risk reporting processes should be analysed periodically with the goal of enhancing risk management performance as well as advancing risk management policies, procedures and practices.
Banks should have a strong control environment that utilises policies, processes and systems; appropriate internal controls; and appropriate risk mitigation and/or transfer strategies.
Internal controls should be designed to provide reasonable assurance that a bank will have efficient and effective operations; safeguard its assets; produce reliable financial reports; and comply with applicable laws and regulations. A sound internal control programme consists of four components that are integral to the risk management process: risk assessment, control activities, information and communication, and monitoring activities.
Control processes and procedures should include a system for ensuring compliance with policies, regulations and laws. Examples of principle elements of a policy compliance assessment are:
Controls processes and procedures should address how the bank ensures operational resilience is maintained in both normal circumstances and in the event of disruption, reflecting respective functions' due diligence, consistent with the bank's operational resilience approach.
An effective control environment also requires appropriate segregation of duties. Assignments that establish conflicting duties for individuals or a team, without dual controls (eg a process that uses two or more separate entities (usually persons) operating in concert to protect sensitive functions or information) or other countermeasures, may result in concealment of losses, errors or other inappropriate actions. Therefore, areas where conflicts of interest may arise should be identified, minimised, and be subject to careful independent monitoring and review.
In addition to segregation of duties and dual controls, banks should ensure that other traditional internal controls are in place, as appropriate, to address operational risk. Examples of these controls are:
Effective use and sound implementation of technology can contribute to the control environment. For example, automated processes are less prone to error than manual processes. However, automated processes introduce risks that must be addressed through sound technology governance and infrastructure risk management programmes.
The use of technology related products, activities, processes and delivery channels exposes a bank to operational risk and the possibility of material financial loss. Consequently, a bank should have an integrated approach to identifying, measuring, monitoring and managing technology risks along the same precepts as operational risk management.
While recourse to entities such as, but not limited to, third-party service providers can help manage costs, provide expertise, expand product offerings, and improve services, it also introduces risks that management should address. The board of directors and senior management are responsible for understanding the operational risks associated with outsourcing arrangements and ensuring that effective risk management policies and practices are in place to manage the risk in outsourcing activities. Amongst others, the concentration of risk and the complexity of outsourcing should be considered. Third-party risk policies (as a part of the ORMF's policies) and risk management activities should encompass:
In those circumstances where internal controls do not adequately address risk and exiting the risk is not a reasonable option, management can complement controls by seeking to transfer the risk to another party such as through insurance. The board of directors should determine the maximum loss exposure the bank is willing and has the financial capacity to assume, and should perform an annual review of the bank's risk and insurance management programme. While the specific insurance or risk transfer needs of a bank should be determined on an individual basis, many jurisdictions have regulatory requirements that must be considered.
Because risk transfer is an imperfect substitute for sound controls and risk management programmes, banks should view risk transfer tools as complementary to, rather than a replacement for, thorough internal operational risk control. Having mechanisms in place to quickly identify, recognise and rectify distinct operational risk errors - or specific legal risk exposure - can greatly reduce exposures. Careful consideration also needs to be given to the extent to which risk mitigation tools such as insurance truly reduce risk, transfer the risk to another business sector or area, or create a new risk (eg counterparty risk).
Banks should have unified classification, methodology, and procedures of operational risk management established by the CORF.
Banks should implement a robust ICT risk management programme in alignment with their operational risk management framework.
Effective ICT performance and security are paramount for a bank to conduct its business properly. The appropriate use and implementation of sound ICT risk management contributes to the effectiveness of the control environment and is fundamental to the achievement of a bank's strategic objectives. A bank's ICT risk assessment should ensure that its ICT fully supports and facilitates its operations. ICT risk management should reduce a bank's operational risk exposure to direct losses, legal claims, reputational damage, ICT disruption and misuse of technology in alignment with its risk appetite and tolerance statement.
ICT risk management includes:
To ensure data and systems' confidentiality, integrity and availability, the board of directors should regularly oversee the effectiveness of the bank's ICT risk management and senior management should routinely evaluate the design, implementation and effectiveness of the bank's ICT risk management. This requires regular alignment of the business, risk management and ICT strategies to be consistent with the bank's risk appetite and tolerance statement as well as with privacy and other applicable laws. Banks should continuously monitor its ICT and regularly report to senior management on ICT risks, controls and events.
ICT risk management together with complementing processes set by the banks should:
Banks should develop approaches to ICT readiness for stressed scenarios from disruptive external events, such as the need to facilitate the implementation of wide-scale remote-access, rapid deployment of physical assets and/or significant expansion of bandwidth to support remote user connections and customer data protection. Banks should ensure that:
Banks should have business continuity plans in place to ensure their ability to operate on an ongoing basis and limit losses in the event of a severe business disruption. Business continuity plans should be linked to the bank's operational risk management framework.
Sound and effective governance of banks' business continuity policy requires:
Banks should prepare forward-looking business continuity plans (BCP) with scenario analyses associated with relevant impact assessments and recovery procedures:
A bank should periodically review its business continuity plans and policies to ensure that contingency strategies remain consistent with current operations, risks and threats. Training and awareness programmes should be customised based on specific roles to ensure that staff can effectively execute contingency plans. Business continuity procedures should be tested periodically to ensure that recovery and resumption objectives and timeframes can be met. Where possible, a bank should participate in business continuity testing with key service providers. Results of formal testing and review activities should be reported to senior management and the board of directors.
A bank's public disclosures should allow stakeholders to assess its approach to operational risk management and its operational risk exposure.
A bank's public disclosure of relevant operational risk management information can lead to transparency and the development of better industry practice through market discipline. The amount and type of disclosure should be commensurate with the size, risk profile and complexity of a bank's operations, and evolving industry practice.
Banks should disclose relevant operational risk exposure information to their stakeholders (including significant operational loss events), while not creating operational risk through this disclosure (eg description of unaddressed control vulnerabilities).28,29 A bank should disclose its ORMF in a manner that allows stakeholders to determine whether the bank identifies, assesses, monitors and controls/mitigates operational risk effectively.
Banks should have a formal disclosure policy that is subject to regular and independent review and approval by the senior management and the board of directors. The policy should address the bank's approach for determining what operational risk disclosures it will make and the internal controls over the disclosure process. In addition, banks should implement a process for assessing the appropriateness of their disclosures and disclosure policy.
This module describes expectations to combat money laundering and terrorist financing.
This module describes expectations and practices relating to capital adequacy.
This module describes expectations for corporate governance.
This module describes expectations for credit risk and counterparty credit risk management.
This module describes expectations for external audit and sets out references related to public disclosure.
This module describes expectations for banks’ internal audit and compliance functions.
This module describes expectations for liquidity risk management.
This module sets out references related to market risk and interest rate risk.
This module describes expectations for the management of operational risk and operational resilience.
This module describes expectations for the management of problem assets and expected credit losses.
This module describes the application of proportionality in prudential regulation and supervision.
This module describes expectations for risk management.
This module describes the nature and application of prudential supervision.