What is Operational Risk?



Operational risk is the risk of loss arising from inadequate or failed internal processes, personnel, systems, or of events occurring in the external environment, irrespective of whether such loss results from acts, omissions, errors, misconduct, deficiencies, disruptions, or failures attributable to the entity itself or to third parties acting on its behalf.

For regulatory compliance, operational risk includes legal risk, the risk of loss arising from the exposure to legal uncertainty, defective or unenforceable contractual arrangements, failures of documentation, breach of statutory or regulatory obligations, administrative or judicial proceedings, regulatory sanctions, fines, penalties, damages, settlements, adverse judgments, and any other legal consequences arising from non compliance with applicable law or from the conduct of the institution or persons acting for it.

Operational risk includes losses from failures or breakdowns of corporate governance, control functions, reporting mechanisms, decision making, or oversight arrangements, including failures to implement or maintain adequate internal control systems, compliance frameworks, risk management processes, segregation of duties, audit mechanisms, or escalation procedures.

It also includes losses arising from internal fraud, external fraud, cyber incidents, data breaches, unauthorised activities, manipulation of systems or records, failures of technological infrastructure, business continuity disruptions, failures of models, misprocessing of transactions, and any defect or interruption that impairs the institution’s ability to operate in accordance with law, regulation, contractual obligations, or supervisory expectations.

Operational risk extends to losses arising from external events that adversely affect the functioning of the institution, including natural catastrophes, criminal acts, geopolitical challenges, and failures or disruptions of utilities or market infrastructures, where such events prevent, impair, or materially disrupt the performance of the institution’s activities or obligations.

Where an institution relies on outsourcing, delegation, or the use of third-party or intra-group service providers, operational risk includes the risk of loss arising from the acts, omissions, failures, insolvency, or unavailability of such service providers, and the regulated entity shall remain fully responsible for managing, monitoring, and mitigating these risks, and for complying with all regulatory obligations governing such arrangements.

Operational risk exists irrespective of the business line, product, service, delivery channel, or technological modality through which the institution conducts its activities, and applies whether the institution performs such activities directly or through an agent, intermediary, subsidiary, branch, or outsourced provider.

For prudential regulation, operational risk is a regulatory capital relevant risk category. Regulated entities are required to identify, measure, manage, monitor, and control operational risk in accordance with binding statutory provisions, regulations, technical standards, supervisory guidelines, and internal governance obligations.

Operational risk must be quantified for capital adequacy purposes through a regulatory measurement methodology, and the institution shall at all times maintain own funds sufficient to absorb losses arising from operational risk exposures.

Operational risk must be understood as a legally defined and supervisory enforced category of prudential risk arising from the manner in which the institution organises, governs, operates, controls, documents, supports, processes, and executes its activities, interacts with clients, counterparties, and third parties, and complies with applicable legal, regulatory, and contractual obligations, together with the risks arising from the external environment when such risks impair or disrupt the institution’s operations.

Legal risk is the risk of loss to a regulated entity arising from the violation of laws, rules or regulations, from the failure to comply with supervisory expectations or binding standards, from defective, unenforceable, or inadequately documented contractual arrangements, from adverse judgments or legal proceedings, from breaches of duties imposed by statute or contract, and from any legal consequences resulting from the conduct of the institution, its employees, agents, or third-party service providers.

In simple words, for legal risk, there are four main reasons that lead to losses:

1. Non-compliance with legal or regulatory obligations.

2. Contractual deficiencies or unenforceability.

3. Litigation, enforcement, or dispute resolution outcomes.

4. Legal defects in governance, documentation, disclosures, or representations.

Regulators intentionally place legal risk under operational risk, because legal failures originate in inadequate internal processes, people, and systems. A breach of law is not treated as a separate category of uncertainty. It is treated as a failure of governance, compliance, documentation, or oversight. This classification has three main consequences.

1. Legal risk is capital relevant. Losses from regulatory fines, litigation settlements, contract failures, and supervisory sanctions feed into operational loss data and influence capital requirements. For institutions under the Standardised Measurement Approach, legal losses shape the loss component and thereby the operational risk capital charge.

2. Legal risk is a governance challenge. Supervisors expect institutions to establish and maintain a risk and compliance management framework as a core part of operational risk management. Weaknesses in risk management can trigger qualitative measures, capital add-ons, or enforcement action.

3. Legal risk has systemic and prudential significance. Large conduct fines, AML/CTF breaches, sanctions violations, misselling scandals, and litigation exposures have historically destabilised institutions. Embedding legal risk within operational risk enables supervisors to treat these failures as threats to the safety and soundness of institutions.


The evolution of operational risk.

This is a story of gradual recognition, formalisation, and institutionalisation within the global prudential framework.

Credit and market risk have long histories. Operational risk emerged much later as a distinct regulatory category. Its evolution reflects a series of crises, scandals, legislative responses, and shifts in the understanding of how financial institutions fail.

Before the 1970s, operational risk was not recognised as a separate risk type. Losses from internal errors, fraud, system breakdowns, or external disruptions were generally categorised as operational problems or business mishaps. Internal processes and systems were treated as managerial concerns, not prudential risks. The regulatory environment assumed the relative stability of internal operations. They believed that banks primarily failed because of poor lending decisions or liquidity shortages, not because of internal failures or external shocks affecting their operations.

This assumption began to change in the 1970s and 1980s, when the financial sector experienced rapid technological, organisational, and market change. Increasingly complex payment systems, electronic trading mechanisms, globalised operations, and early forms of financial automation made institutions dependent on systems and processes that were far more fragile than what was initially understood.

High-profile system outages, settlement failures, rogue trading incidents, and significant internal control weaknesses began to expose the reality that operational failures could produce substantial losses. At this stage, the regulatory approach was still fragmented. Operational weaknesses were addressed through guidelines on internal controls, supervisory expectations for sound management, or ad-hoc enforcement, but not through capital requirements or formal risk recognition.

The turning point came in the 1990s, when several events like the collapse of Barings Bank demonstrated that failures of internal processes and governance could destroy even long established, well capitalised institutions. Although Barings collapsed because of unauthorised trading, the root cause was not market movement but the absence of effective oversight, segregation of duties, reporting mechanisms, and risk controls.

Supervisors recognised that traditional capital frameworks were blind to an entire dimension of risk, the possibility that operational failures could lead to insolvency just as easily as poor credit decisions or adverse price movements. This recognition created the conceptual space for operational risk to be treated as a discrete prudential category.

The Basel Committee’s development of the Basel II framework was the first global codification of operational risk as a capital relevant risk type. Basel II adopted the definition of operational risk as the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events, and explicitly incorporated legal risk.

In this definition, the Basel Committee excluded strategic and reputational risks, not simply because they are difficult to measure (this has often been heard in presentations). There are other main reasons.

1. They are outside the prudential capital perimeter. When operational risk was formally defined under Basel II, regulators made a deliberate decision. Operational risk should be the category of risks that can be tied to internal process, system, governance, legal, or human failures, risks that can be controlled, mitigated, and capitalised. Strategic and reputational risks fail this test. They do not arise from failures in processes, systems, people or external operational events. They arise from strategic business decisions made intentionally, market perception, investor confidence, media reporting, changes in competitive position, shifts in public trust, or political pressure.

2. Strategic and reputational risks have no definable maximum loss, no clear loss horizon, and no coherent way to construct a probability distribution. Operational risk capital requires a definable universe of loss events, thresholds, and frequency/severity distributions. Strategic and reputational risks cannot meet these requirements.

3. They are not caused by failures in the institution’s processes, systems, or governance (the legal trigger for operational risk). Strategic risks and reputational risks do not normally arise from failure. They arise from deliberate choices or external perception. A bank choosing to expand into a new market, misjudge demand, or target a wrong segment is not experiencing a failure of process. It is experiencing a business misjudgment. Rreputational damage may occur due to macro events, political shifts, media narratives, or consumer sentiment, factors that are not failures within the meaning of prudential law.

4. Capital is not the right tool to address these risks. Capital is designed to absorb losses from identifiable events. Strategic and reputational risks are handled in the Supervisory Review and Evaluation Process (SREP), not through capital.

Reputational and strategic risks become capital relevant only when they crystalise through operational events. This is an important point. Regulators exclude strategic and reputational risk as independent categories, but include their consequences when they arise from an operational failure.

Example: A mis-selling scandal causes reputational damage. The reputational damage itself is not capitalised. But the litigation, fines, compensation payouts, and legal costs are operational losses.

Reputational and strategic risks become operational risks only when they lead to recognisable, measurable loss events.

When the Basel Committee was drafting Basel II, banks actively lobbied to broaden the definition of operational risk so that it would include strategic and reputational risks. But why banks wanted strategic and reputational risks included?

Banks wanted to avoid a separate regime for business model risk. Supervisors considered, at one stage, whether strategic risk or reputational risk should become separate regulatory categories. Banks strongly opposed this because strategic decisions (expansion, mergers, product launches, restructuring) are core functions of management. Banks did not want supervisors to be involved in business strategy.

By insisting that strategic and reputational risks should fall under the operational umbrella, banks hoped that regulators would abandon the idea of managing them separately.

Banks were deeply concerned that if strategic or reputational risks became explicit regulated categories, regulators would gain authority to assess the bank’s business model, and will gain influence over strategic planning decisions.

Supervisors decided that if they included strategic and reputational risks in operational risk, this would affect the precision of the operational risk definition, and it will undermine capital comparability and obscure true operational failures.

For the first time in regulatory history, operational risk was given quantitative substance through three capital methods in Basel II: The Basic Indicator Approach, the Standardised Approach, and the Advanced Measurement Approaches (AMA). The AMA was particularly innovative, as it allowed banks to model operational risk using internal loss data, scenario analysis, key risk indicators and business environment factors, under strict supervisory approval conditions.

Despite its sophistication, Basel II’s treatment of operational risk was soon tested in real world conditions. The financial crisis of 2007–2008 revealed systemic weaknesses not only in credit and market risk models but also in operational resilience. Major losses emerged from conduct failures, inadequate documentation, failures to manage complex securitisation structures, inadequate model governance, and widespread control deficiencies.

Post crisis investigations showed that many catastrophic losses were operational in nature, including misselling, LIBOR manipulation, foreclosure processing failures, and major litigation settlements. These events demonstrated that operational risk was not a peripheral concern but a central driver of systemic instability and supervisory intervention.

In response, the Basel Committee reassessed the AMA and concluded that internal models produced inconsistent, opaque, and often insufficient capital levels. Supervisors also noted a disconnect between operational loss experience and the capital outcomes generated by complex modelling frameworks.

In the finalisation of Basel III, the Basel Committee replaced the AMA and multi tiered standardised methods with a single Standardised Measurement Approach (SMA). This reform reflected a philosophical shift. Operational risk capital should be less dependent on proprietary modelling and more tightly linked to empirical loss experience, while retaining proportionality.

An important development is the integration of conduct risk into operational risk. As jurisdictions imposed increasingly stringent rules on market conduct, consumer protection, anti money laundering, sanctions compliance, and data protection, financial institutions faced legal and supervisory expectations.

The role of operational risk disclosure also evolved significantly. Pillar 3 requirements now demand extensive qualitative information about governance, frameworks, and loss experience. Supervisors use operational risk outcomes (large losses, frequent incidents, or systemic control failures) as indicators of weaknesses in management, culture, oversight, or risk appetite. This evolution transformed operational risk from a capital challenge into a core supervisory lens for evaluating the quality of an institution’s governance and internal control environment.

Today, operational risk is a major component of prudential regulation. It is recognised in banking, insurance, asset management, payment services, market infrastructures, and cross-sectoral frameworks. It is integrated into capital rules, governance expectations, disclosure obligations, and enforcement regimes. It serves as the legal and regulatory category for capturing failures of internal organisation, behaviour, technology, controls, and external disruptions. It is also the foundation of the emerging operational resilience doctrine, which extends the concept beyond loss prevention to safeguarding critical functions and financial stability.


Learning from the Annual Reports

Operational risk, important parts from the Annual Report, Wells Fargo & Company

Operational risk, which in addition to those discussed in this section, includes compliance risk and model risk, is the risk resulting from inadequate or failed internal processes, people and systems, or from external events.

The Board’s Risk Committee has primary oversight responsibility for all aspects of operational risk, including significant supporting programs and/or policies regarding the Company’s business resiliency and disaster recovery, data management, information security, technology, and third-party risk management. As part of its oversight responsibilities, the Board’s Risk Committee reviews and approves significant operational risk policies and oversees the Company’s operational risk management program.

At the management level, Operational Risk Management, which is part of IRM, has oversight responsibility for operational risk. Operational Risk Management reports to the CRO and provides periodic reports related to operational risk to the Board’s Risk Committee. Operational Risk Management’s oversight responsibilities include change management risk, human capital risk, technology risk, third-party risk, information management risk, information security risk, data management risk, and fraud risk.

Information security is a significant operational risk for financial institutions such as Wells Fargo and includes the risk arising from unauthorized access, use, disclosure, disruption, modification, or destruction of information or information systems. The Board is actively engaged in the oversight of the Company’s information security risk management and cyber defense programs.

The Board’s Risk Committee has primary oversight responsibility for information security risk and approves the Company’s information security program, which includes the information security policy and the cyber defense program. A Technology Subcommittee of the Risk Committee assists the Risk Committee in providing oversight of technology, information security, and cybersecurity risks as well as data management risk. The Technology Subcommittee reviews and recommends to the Risk Committee for approval any significant programs and/or policies supporting information security risk (including cybersecurity risk), technology risk, and data management risk.

Wells Fargo and other financial institutions, as well as their third- party service providers, continue to be the target of various evolving and adaptive cyber attacks, including malware, ransomware, other malicious software intended to exploit hardware or software vulnerabilities, phishing, credential validation, and distributed denial-of-service, in an effort to disrupt the operations of financial institutions, test their cybersecurity capabilities, commit fraud, or obtain confidential, proprietary or other information.

Cyber attacks have also focused on targeting online applications and services, such as online banking, as well as cloud-based and other products and services provided by third parties, and have targeted the infrastructure of the internet causing the widespread unavailability of websites and degrading website performance. As a result, information security and the continued development and enhancement of our controls, processes and systems designed to protect our networks, computers, software and data from attack, damage or unauthorized access remain a priority for Wells Fargo.

Wells Fargo is also proactively involved in industry cybersecurity efforts and working with other parties, including our third-party service providers and governmental agencies, to continue to enhance defenses and improve resiliency to cybersecurity and other information security threats. See the “Risk Factors” section in this Report for additional information regarding the risks associated with a failure or breach of our operational or security systems or infrastructure, including as a result of cyber attacks.


OPERATIONAL, STRATEGIC AND LEGAL RISKS

A failure in or breach of our operational or security systems, controls or infrastructure, or those of our third-party vendors and other service providers, could disrupt our businesses, damage our reputation, increase our costs and cause losses.

As a large financial institution that serves customers through numerous physical locations, ATMs, the internet, mobile banking and other distribution channels across the U.S. and internationally, we depend on our ability to process, record and monitor a large number of customer transactions on a continuous basis. As our customer base and locations have expanded throughout the U.S. and internationally, as we have increasingly used the internet and mobile banking to provide products and services to our customers, as customer, public, legislative and regulatory expectations regarding operational and information security have increased, and as cyber and other information security attacks have become more prevalent and complex, our operational systems, controls and infrastructure must continue to be safeguarded and monitored for potential failures, disruptions and breakdowns.

Our business, financial, accounting, data processing systems or other operating systems and facilities may stop operating properly, become insufficient based on our evolving business needs, or become disabled or damaged as a result of a number of factors including events that are wholly or partially beyond our control.

For example, there have been and could in the future be sudden increases in customer transaction volume; electrical or telecommunications outages; degradation or loss of internet, website or mobile banking availability; natural disasters such as earthquakes, tornados, and hurricanes; disease pandemics; events arising from local or larger scale political or social matters, including terrorist acts; and, as described below, cyber attacks or other information security breaches. Furthermore, enhancements and upgrades to our infrastructure or operating systems may be time-consuming, entail significant costs, and create risks associated with implementing new systems and integrating them with existing ones.

Due to the complexity and interconnectedness of our systems, the process of enhancing our infrastructure and operating systems, including their security measures and controls, can itself create a risk of system disruptions and security issues. Similarly, we may not be able to timely recover critical business processes or operations that have been disrupted, which may further increase any associated costs and consequences of such disruptions. Although we have business continuity plans and other safeguards in place to help provide operational resiliency, our business operations may be adversely affected by significant and widespread disruption to our physical infrastructure or operating systems that support our businesses and customers.

For example, on February 7, 2019, we experienced system issues caused by an automatic power shutdown at one of our main data center facilities. Although applications and related workloads were systematically re-routed to back-up data centers throughout the day, certain of our services, including our online and mobile banking systems, certain mortgage origination systems, and certain ATM functions, experienced disruptions that delayed service to our customers.

As a result of financial institutions and technology systems becoming more interconnected and complex, any operational incident at a third party may increase the risk of loss or material impact to us or the financial industry as a whole. Furthermore, third parties on which we rely, including those that facilitate our business activities or to which we outsource operations, such as exchanges, clearing houses, financial intermediaries or vendors that provide services or security solutions for our operations, could continue to be sources of operational risk to us, including from information breaches or loss, breakdowns, disruptions or failures of their own systems or infrastructure, or any deficiencies in the performance of their responsibilities.

We are also exposed to the risk that a disruption or other operational incident at a common service provider to those third parties could impede their ability to provide services or perform their responsibilities for us. In addition, we must meet regulatory requirements and expectations regarding our use of third-party service providers, and any failure by our third-party service providers to meet their obligations to us or to comply with applicable laws, rules, regulations, or Wells Fargo policies could result in fines, penalties, restrictions on our business, or other negative consequences.

Disruptions or failures in the physical infrastructure, controls or operating systems that support our businesses and customers, failures of the third parties on which we rely to adequately or appropriately provide their services or perform their responsibilities, or our failure to effectively manage or oversee our third-party relationships, could result in business disruptions, loss of revenue or customers, legal or regulatory proceedings, compliance and other costs, violations of applicable privacy and other laws, reputational damage, or other adverse consequences, any of which could materially adversely affect our results of operations or financial condition.

A cyber attack or other information security breach could have a material adverse effect on our results of operations or financial condition. Information security risks for large financial institutions such as Wells Fargo have generally increased in recent years in part because of the proliferation of new technologies, the use of the internet, mobile devices, and cloud technologies to conduct financial transactions, and the increased sophistication and activities of organized crime, hackers, terrorists, activists, and other external parties, including foreign state-sponsored parties.

Those parties also may continue to attempt to misrepresent personal or financial information to commit fraud, obtain loans or other financial products from us, or attempt to fraudulently induce employees, customers, or other users of our systems to disclose confidential information in order to gain access to our data or that of our customers. As noted above, our operations rely on the secure processing, transmission and storage of confidential information in our computer systems and networks.

Our banking, brokerage, investment advisory, and capital markets businesses rely on our digital technologies, computer and email systems, software, hardware, and networks to conduct their operations. In addition, to access our products and services, our customers may use personal smartphones, tablets, and other mobile devices that are beyond our control systems.

Our technologies, systems, software, networks, and our customers’ devices are likely to continue to be the target of cyber attacks or other information security breaches, which could materially adversely affect us, including as a result of fraudulent activity, the unauthorized release, gathering, monitoring, misuse, loss or destruction of Wells Fargo’s or our customers’ confidential, proprietary and other information, or the disruption of Wells Fargo’s or our customers’ or other third parties’ business operations.

For example, various retailers have reported they were victims of cyber attacks in which large amounts of their customers’ data, including debit and credit card information, was obtained. In these situations, we generally incur costs to replace compromised cards and address fraudulent transaction activity affecting our customers. We are also exposed to the risk that an employee or other person acting on behalf of the Company fails to comply with applicable policies and procedures and inappropriately circumvents controls for personal gain or other improper purposes.

Due to the increasing interconnectedness and complexity of financial institutions and technology systems, an information security incident at a third party may increase the risk of loss or material impact to us or the financial industry as a whole. In addition, third parties on which we rely, including those that facilitate our business activities or to which we outsource operations, such as internet, mobile technology, hardware, software, and cloud service providers, could continue to be sources of information security risk to us. If those third parties fail to adequately or appropriately safeguard their technologies, systems, networks, hardware, and software, we may suffer material harm, including business disruptions, losses or remediation costs, reputational damage, legal or regulatory proceedings, or other adverse consequences.

Our risk and exposure to cyber attacks or other information security breaches remains heightened because of, among other things, the persistent and evolving nature of these threats, the prominent size and scale of Wells Fargo and its role in the financial services industry, our plans to continue to implement our digital and mobile banking channel strategies and develop additional remote connectivity solutions to serve our customers when and how they want to be served, our geographic footprint and international presence, the outsourcing of some of our business operations, and the current global economic and political environment.

For example, Wells Fargo and other financial institutions, as well as their third-party service providers, continue to be the target of various evolving and adaptive cyber attacks, including malware, ransomware, other malicious software intended to exploit hardware or software vulnerabilities, phishing, credential validation, and distributed denial-of-service, in an effort to disrupt the operations of financial institutions, test their cybersecurity capabilities, commit fraud, or obtain confidential, proprietary or other information.

Cyber attacks have also focused on targeting online applications and services, such as online banking, as well as cloud-based and other products and services provided by third parties, and have targeted the infrastructure of the internet, causing the widespread unavailability of websites and degrading website performance. As a result, information security and the continued development and enhancement of our controls, processes and systems designed to protect our networks, computers, software and data from attack, damage or unauthorized access remain a priority for Wells Fargo. We are also proactively involved in industry cybersecurity efforts and working with other parties, including our third-party service providers and governmental agencies, to continue to enhance defenses and improve resiliency to cybersecurity and other information security threats.

As these threats continue to evolve, we expect to continue to be required to expend significant resources to develop and enhance our protective measures or to investigate and remediate any information security vulnerabilities or incidents. Because the investigation of any information security breach is inherently unpredictable and would require time to complete, we may not be able to immediately address the consequences of a breach, which may further increase any associated costs and consequences. Moreover, to the extent our insurance covers aspects of information security risk, such insurance may not be sufficient to cover all losses associated with an information security breach.

Cyber attacks or other information security breaches affecting us or third parties on which we rely, including those that facilitate our business activities or to which we outsource operations, or security breaches of the networks, systems or devices that our customers use to access our products and services, could result in business disruptions, loss of revenue or customers, legal or regulatory proceedings, compliance, remediation and other costs, violations of applicable privacy and other laws, reputational damage, or other adverse consequences, any of which could materially adversely affect our results of operations or financial condition.


Operational risk, important parts from the Annual Report, Royal Bank of Canada

Operational risk is the risk of loss or harm resulting from people, inadequate or failed internal processes, controls and systems or from external events. Operational risk is inherent in all of our activities and third-party activities and failure to manage operational risk can result in direct or indirect financial loss, reputational impact or regulatory scrutiny and proceedings in the various jurisdictions where we operate.

Our management of operational risk follows the three lines of defence governance model, encompassing the organizational roles and responsibilities for a coordinated enterprise-wide approach. For further details, refer to the Risk management – Enterprise risk management section.

Operational risk framework

We have an Enterprise Operational Risk Framework which sets out the processes to identify, assess, monitor, measure, report and communicate on operational risk. The processes are established through the following:

• Risk identification and assessment tools, including the collection and analysis of risk event data, help risk owners understand and proactively manage operational risk exposures. Risk assessments are intended to ensure alignment between risk exposures and efforts to manage them. Management uses outputs of these tools to make informed risk decisions.

• Risk monitoring tools alert management to changes in the operational risk profile. When paired with escalation and monitoring triggers, risk monitoring tools can identify risk trends, warn management of risk levels that approach or exceed defined limits, as well as prompt actions and mitigation plans to be undertaken.

• Risk capital measurement provides credible estimation of potential risk exposure, including surfaces risk vulnerabilities, and informs strategic and capital planning decisions, which are ultimately intended to ensure that the bank is sufficiently resilient to withstand operational risk losses both in normal times and under stress situations.

• Risk reporting and communication processes ensure that relevant operational risk information is made available to management in a timely manner to support risk-informed business decisions.

Conclusions from our operational risk programs enable learning based on what has happened to us, whether it could happen elsewhere in the organization, and what controls we need to amend or implement. These conclusions support the articulation of our operational risk appetite and are used to inform the overall level of operational risk exposure which thereby defines our operational risk profile. This profile includes significant operational risk exposures, potential new and emerging exposures and trends, and overall conclusions on the control environment and risk outlook. We proactively identify and investigate corporate insurance opportunities to mitigate and reduce potential future impacts of operational risk.

We consider the potential risks and rewards of our decisions to strike a balance between accepting potential losses versus incurring costs of mitigation, the expression of which is in the form of our operational risk appetite. Our operational risk appetite is established at the Board level and cascaded throughout each of our business segments.

Management reports have been implemented at various levels to support proactive management of operational risk and transparency of risk exposures. These reports are provided to senior management on a regular basis and provide detail on the main drivers of the risk status and trend for each of our business segments and the bank overall. In addition, changes to the operational risk profile that are not aligned to our business strategy or operational risk appetite are identified and discussed at GRC and the Risk Committee of the Board.

Operational risks

Cybersecurity risk

Cybersecurity risk is the risk to the business associated with cyber-attacks initiated to disrupt or disable our operations or to expose or damage data. We have a dedicated team of technology and cybersecurity professionals that manage a comprehensive program to help protect the organization against breaches and other incidents by ensuring appropriate security and operational controls are in place.

We continue to strengthen our cyber-control framework and to improve our resilience and cybersecurity capabilities including 24 hour monitoring, cyber intelligence analysis of internal and external threats and alerting of potentially suspicious security events and incidents. Throughout the year, we continued to invest in our cybersecurity program, and multiple scenarios, assessments and simulations were conducted to test our resiliency strategy.

Data management and privacy risk

Data management risk is the risk of failing to manage information appropriately throughout its lifecycle due to inadequate processes and controls, resulting in legal or regulatory consequences, reputational damage or financial loss.

Privacy risk is the risk of improper creation or collection, use, disclosure, retention or destruction of information. The collection, use and sharing of data, as well as the management and governance of data, are increasingly important as we continue to invest in digital solutions and innovation, as well as, expanding our business activities. This is also reflected through regulatory developments relating to data privacy.

The Chief Privacy Office and the Chief Data Office partner with cross-functional teams to develop and implement enterprisewide standards and practices that describe how data is used, protected, managed and governed.

Money laundering and terrorist financing risk

Money laundering and Terrorist financing risk is the risk that our products and services are used to facilitate the laundering of proceeds of crime, including the financing of terrorist activity. We maintain an enterprise-wide program designed to deter, detect and report suspected money laundering and terrorist financing activities across our organization, while seeking to ensure compliance with the laws and regulations of the various jurisdictions in which we operate.

Our Global AML Compliance Group is dedicated to the continuous development and maintenance of robust policies, guidelines, training and risk-assessment tools and models to help our employees deal with ever-evolving money laundering and terrorist financing risks. The global anti-money laundering/anti-terrorist financing program is regularly evaluated in an effort to ensure it remains aligned with industry standards, best practices and all applicable laws, regulations and guidance. Risks of non-compliance include enforcement actions, criminal prosecutions and reputational damage.

Third-party risk

Third-party risk is the risk of failure to effectively manage third parties which may expose us to service disruptions, regulatory action, financial loss, litigation or reputational damage. We have a risk-based enterprise-wide program designed to provide oversight for third-party relationships that enables us to respond effectively to events that can cause service disruptions, financial loss or various other risks that could impact us.

Our approach to third-party risk mitigation is outlined in policies and standards that establish the minimum requirements for identifying and managing risks throughout the engagement with a third party, while ensuring compliance with global regulatory expectations. We monitor third-party providers that we consider critical to our operations for any impact on their ability to deliver services to us, including vendors of our third-party providers.

Business continuity risk

Business continuity risk is the risk of being unable to maintain, continue or restore essential business operations during and/or after an event that prevents us from conducting business in the normal course. Exposure to disruptive operational events interrupts the continuity of our business operations and could negatively impact our financial results, reputation, client outcomes and/or result in harm to our employees. These operational events could result from the impact of severe weather, pandemics, failed processes, technology failures or cyber threats.

Our risk-based enterprise-wide business continuity management program considers multiple scenarios to address the consequences of a disruption and its effects on the availability of our people, processes, facilities, technology, and third-party arrangements. Our approach to business continuity management is outlined in policies and standards embedded across the organization and the related risks are regularly measured, monitored, reported and integrated in our operational risk management and control framework.

Operational risk capital

Requirements for operational risk capital are determined in accordance with OSFI issued guidelines. Currently, our operational risk capital is assessed using the Standardized Approach (TSA) which is a formula-based calculation predicated on gross income. Upon implementation of final Basel III reforms, OSFI will require deposit-taking institutions to adopt a new Standardized Approach (SA) for measurement of operational risk capital. The SA methodology is based on the Business Indicator Component (BIC), which is a financial statement-based proxy for operational risk, and the Internal Loss Multiplier, a scaling factor that is based on the historical internal loss average relative to the BIC. Once implemented, SA will replace TSA. For further details on operational risk capital, refer to the Capital management section.


You may also visit:

Frontier Risk

Emerging Risk

Hybrid Risk

Cognitive Risk

Artificial Superintelligence Risk

AI-Human Hybridization Risk

Political Risk

Strategic Risk

Systemic Risk

Climate Risk

Conduct Risk

Reputation Risk

Liquidity Risk

Cyber Risk

Credit Risk

Market Risk

Operational Risk


Membership and certification

RR

In the Reading Room (RR) of the association you can find our newsletter. Our Reading Room

Contact IARCP

Contact Us

Lyn Spooner
lyn@risk-compliance-association.com

George Lekatis
President of the IARCP
1200 G Street NW, Suite 800, Washington, DC 20005, USA
(202) 449-9750
lekatis@risk-compliance-association.com

Privacy, legal, impressum