Skip to main content
Case studyFortune 100: 80% less compliance workRead the Story
RiskWatch
Pillar guide · ~13 min read · Updated June 2026

Operational risk managementFramework, process, and examples

Operational risk management (ORM) is the discipline of identifying, assessing, controlling, and monitoring the risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events. It runs as a continuous cycle, built on RCSAs, key risk indicators, loss event data, and scenario analysis, and is governed through the three lines of defense.

Reading level
Practitioner
Anchor
Basel · COSO · ISO
Audience
Risk · GRC · Audit
Last reviewed
June 2026
01 · Definition

What is operational risk management?

Operational risk management is the discipline of identifying, assessing, controlling, and monitoring operational risk: the risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events. That definition comes from the Basel Committee on Banking Supervision and is the one most widely used across industries.

The definition deliberately spans four sources of loss, which is why operational risk reaches almost every corner of an organization. Under the Basel framing the definition includes legal risk but excludes strategic and reputational risk. In practice, operational risk is the everyday risk of running the business: the risk that the way work actually gets done will produce a loss. It is distinct from credit risk (a borrower failing to pay) and market risk (prices moving against you), and it is harder to model because it stems from how people and processes behave rather than from a market price.

Processes

A broken or inadequate internal process. A control that is missing, a procedure that is not followed, a handoff that drops the ball.

People

Human error or misconduct. A mistake, a skills gap, a key-person dependency, fraud, or a deliberate breach of policy.

Systems

A technology failure. An outage, a software defect, a failed integration, a capacity limit, or a data-integrity problem.

External events

Something outside the organization. A natural disaster, a third-party failure, an external fraud attempt, or a supplier disruption.

“The risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events.”

Basel Committee on Banking Supervision, definition of operational risk (bis.org)
02 · Why it matters

Why operational risk management matters

Operational risk is the one category every organization carries, because every organization runs processes, employs people, and depends on systems. Regulators have steadily formalized the expectation that it is managed deliberately rather than absorbed by accident.

In banking, the Basel Committee on Banking Supervision codified operational risk as a category that firms must identify, measure, monitor, and control, and its Principles for the Sound Management of Operational Risk set the supervisory baseline that national regulators build on.

In the United States, prudential supervisors such as the Office of the Comptroller of the Currency and the Federal Reserve examine operational risk management as part of safety and soundness, and the interagency FFIEC IT Examination Handbook sets expectations for the technology and process risks that sit inside it. In the European Union, the Digital Operational Resilience Act (DORA) places explicit obligations on financial entities to manage information and communication technology risk and to withstand disruption.

The pressure is not confined to financial services. Any organization that processes transactions, handles customer data, relies on suppliers, or runs critical systems is exposed to the same four sources of loss. Healthcare, energy, manufacturing, retail, and the public sector all run operational risk programs under their own rules and standards, even when they do not call the discipline by its Basel name. The common thread is that a structured program turns scattered, reactive firefighting into a managed, reportable picture of exposure that a board and a regulator can both follow.

03 · Taxonomy

The seven Basel event-type categories

The Basel framework groups operational risk into seven event-type categories. They give a program a common language for classifying losses and assessments, so risk from very different parts of the business can be rolled up and compared consistently.

  1. 1

    Internal fraud

    Losses from acts intended to defraud, misappropriate property, or circumvent regulations or company policy involving at least one internal party, such as unauthorized trading, theft, or intentional misreporting of positions.

  2. 2

    External fraud

    Losses from acts by a third party intended to defraud, misappropriate property, or circumvent the law, such as theft, forgery, check fraud, or computer hacking.

  3. 3

    Employment practices and workplace safety

    Losses from acts inconsistent with employment, health, or safety laws or agreements, including discrimination claims, workers' compensation, and general liability for employee safety.

  4. 4

    Clients, products, and business practices

    Losses from an unintentional or negligent failure to meet a professional obligation to clients, or from the nature or design of a product, such as fiduciary breaches, improper disclosure, market manipulation, or product defects.

  5. 5

    Damage to physical assets

    Losses from loss of or damage to physical assets from natural disasters or other events, including fire, flood, terrorism, and vandalism.

  6. 6

    Business disruption and system failures

    Losses from disruption of business or system failures, including hardware and software failures, telecommunication problems, and utility outages.

  7. 7

    Execution, delivery, and process management

    Losses from failed transaction processing or process management, and from relations with trade counterparties and vendors, such as data-entry errors, accounting errors, failed mandatory reporting, and negligent loss of client assets.

04 · Examples

Operational risk examples

These are illustrative examples, not real incidents. Each one maps to one of the seven Basel categories, which is exactly how a working program classifies a loss when it happens.

A wire-transfer settles to the wrong account because of a keying error

A process and people failure. The loss comes from how a routine transaction was handled, not from a market move or a credit default.

Basel category
Execution, delivery, and process management

A phishing email tricks a finance clerk into paying a fake invoice

An external party deceives the organization into a payment. The trigger is outside the firm, but the loss lands through an internal process.

Basel category
External fraud

A core banking system outage halts customer payments for hours

A systems failure that stops the business from operating. The cost is the disruption itself plus any downstream service or contractual breach.

Basel category
Business disruption and system failures

A product is mis-sold against its documented suitability rules

A failure to meet a professional obligation to a client. The loss arrives later as remediation, refunds, or a regulatory penalty.

Basel category
Clients, products, and business practices
A note on terminology

The term “operational risk management” here refers to the financial-services and enterprise discipline defined by Basel. It is not the same as the military “composite risk management” (CRM), the US Army doctrine for assessing and controlling hazards in operations and missions. The two share a risk-identification mindset but have different origins, scopes, and vocabularies, and they should not be conflated.

05 · The framework

The operational risk management framework

An operational risk management framework is the set of tools and governance that lets an organization identify, measure, monitor, and control operational risk on an ongoing basis. Four data-gathering tools form the core of most frameworks, and together they give a program both a backward-looking and a forward-looking view of exposure.

Risk and control self-assessment (RCSA)

A structured exercise in which each business unit identifies the operational risks it faces, assesses their likelihood and impact, and evaluates the controls meant to mitigate them. The RCSA is the bottom-up engine of an ORM program, surfacing where residual risk is highest after controls are accounted for.

Key risk indicators (KRIs)

Metrics that act as early-warning signals for rising operational risk, for example failed-transaction rates, system downtime, staff turnover, or the volume of open audit findings. KRIs are tracked against thresholds so a deteriorating trend prompts action before it becomes a loss.

Loss event data

A record of operational loss events that have actually occurred, including the event type, the amount, and the cause. Internal loss data shows where a program is bleeding, and external loss data from industry sources helps benchmark exposure to events that have not yet happened in-house.

Scenario analysis

A forward-looking exercise that estimates the impact of severe but plausible events that may sit outside the historical loss record, such as a major outage, a fraud ring, or a natural disaster. Scenario analysis fills the gap left by relying on past loss data alone.

06 · Accountability model

The three lines of defense

Most operational risk programs are governed through the three lines of defense model, which clarifies who owns risk, who oversees it, and who provides independent assurance. The Institute of Internal Auditors refreshed it as the Three Lines Model in July 2020.

First line: the business

Owns the risk

The operating units and process owners who take on and manage risk day to day. They own the controls and are accountable for the risks their activities create.

Second line: risk and compliance

Oversees and challenges

The operational risk management and compliance functions that set the framework, oversee the first line, challenge its assessments, and report aggregated risk to senior management.

Third line: internal audit

Independent assurance

Independent assurance that the first two lines are working as intended, reporting to the board or audit committee rather than to management.

07 · The process

The operational risk management process

The operational risk management process is the repeatable cycle a program runs to keep exposure under control. The steps are continuous rather than one-time: the output of monitoring feeds the next round of identification and assessment.

  1. Step 01

    Identify

    Map where operational risk lives across processes, people, systems, and external dependencies. RCSA workshops, process mapping, and loss event data feed this step.

  2. Step 02

    Assess and measure

    Rate each risk by likelihood and impact to establish an inherent rating, then assess the controls in place to arrive at a residual rating. KRIs and scenario analysis sharpen the measurement.

  3. Step 03

    Mitigate and control

    Decide how to treat each risk: accept it, reduce it with stronger controls, transfer it (for example through insurance), or avoid the activity. Assign an owner and a target date for every action.

  4. Step 04

    Monitor and report

    Track KRIs against thresholds, log new loss events, and report residual risk to management and the board. Monitoring closes the loop and keeps the risk picture current.

  5. Step 05

    Review and improve

    Revisit assessments on a defined cycle and after material events, update controls, and feed lessons learned back into the program so it improves over time.

Free template
Put the process to work with a free risk assessment template

Ready to move from theory to a first assessment? Our free risk assessment template gives you a structured way to identify risks, score likelihood and impact, and track controls and owners, the same backbone an operational risk program runs on. Pair it with the risk register template to keep the output current between cycles.

08 · Adjacent terms

ORM vs ERM and operational resilience

Operational risk management sits next to two terms it is often confused with: enterprise risk management above it, and operational resilience alongside it. Clear boundaries keep the program coherent.

ORM vs enterprise risk management (ERM)

Operational risk management focuses on one category of risk: the risk that internal processes, people, and systems, or external events, will produce a loss. Enterprise risk management is broader: the organization-wide discipline of identifying and managing all the major risks a business faces, including strategic, financial, market, credit, compliance, and operational risk together. Operational risk is one of the categories ERM oversees. A mature program runs ORM as a discipline in its own right, then rolls that view up into the enterprise risk picture the board sees.

ORM vs operational resilience and business continuity

Operational risk management is about reducing the chance and impact of loss events. Operational resilience is about keeping important business services running through a disruption and recovering quickly when one occurs. ORM identifies and treats the threats; resilience plans for how the business absorbs and recovers from the disruptions that get through. Business continuity planning is one of the main disciplines that delivers resilience in practice.

To go deeper on the broader discipline, see our guide to what risk management is and to enterprise risk management. On the resilience side, see business continuity planning and supply chain risk management. To see how a platform supports the whole program, look at risk management software.

09 · Frequently asked

Operational risk management, answered

Nine questions practitioners, board members, and new risk hires ask on the way to a working program.

What is operational risk management?
Operational risk management is the discipline of identifying, assessing, controlling, and monitoring the risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events. It uses tools such as risk and control self-assessments, key risk indicators, loss event data, and scenario analysis, governed through the three lines of defense, to keep that exposure under control.
What is the definition of operational risk?
The most widely used definition comes from the Basel Committee on Banking Supervision: operational risk is the risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events. Under the Basel framing this definition includes legal risk but excludes strategic and reputational risk.
What are examples of operational risk?
Illustrative examples include a wire-transfer settling to the wrong account because of a keying error (execution, delivery, and process management), a phishing email that tricks a clerk into paying a fake invoice (external fraud), a core-system outage that halts customer payments (business disruption and system failures), and a product mis-sold against its suitability rules (clients, products, and business practices). Each is a loss that comes from how the business runs rather than from a market move or a credit default.
What are the seven categories of operational risk?
The Basel framework groups operational risk into seven event-type categories: internal fraud; external fraud; employment practices and workplace safety; clients, products, and business practices; damage to physical assets; business disruption and system failures; and execution, delivery, and process management.
What is an operational risk management framework?
An operational risk management framework is the set of tools and governance an organization uses to manage operational risk on an ongoing basis. The core tools are risk and control self-assessment (RCSA), key risk indicators (KRIs), loss event data, and scenario analysis, governed through the three lines of defense, with the first line owning risk, the second line overseeing it, and the third line providing independent assurance.
What are the steps in the operational risk management process?
The process is a continuous cycle: identify operational risks, assess and measure them by likelihood and impact, mitigate and control them by accepting, reducing, transferring, or avoiding the risk, monitor and report on residual risk and key risk indicators, and review and improve the program over time.
Which statement best describes operational risk management?
The statement that best describes operational risk management is that it is the ongoing process of identifying, assessing, controlling, and monitoring the risk of loss from inadequate or failed internal processes, people, and systems, or from external events. It is not a one-time assessment and it is not limited to fraud or to technology; it is the everyday discipline of managing the risk of running the business, governed through the three lines of defense.
What is the difference between operational risk and operational resilience?
Operational risk management is about preventing and reducing the chance and impact of loss events. Operational resilience is about an organization's ability to keep delivering its important business services through a disruption and to recover quickly when one occurs. The two are closely linked: operational risk management identifies and treats the threats, while operational resilience plans for how the business absorbs and recovers from the disruptions that get through. Business continuity planning is one of the main disciplines that delivers operational resilience.
How is operational risk management different from enterprise risk management?
Operational risk management focuses on a single category of risk, the risk that internal processes, people, and systems, or external events, will cause a loss. Enterprise risk management is the broader, organization-wide discipline that manages all major risk types together, including strategic, financial, market, credit, compliance, and operational risk. Operational risk is one of the categories that enterprise risk management oversees.
From framework to live program

Run operational risk management in one platform.

RiskWatch turns RCSAs, key risk indicators, loss data, and controls into a managed program, with owners, automated review cycles, and risk roll-ups across the organization. Start a free trial or request a demo.

No credit card required · 30-day free trial · Cancel anytime

Request a Demo