Building an Operational Risk Framework from Scratch

An attempt to deep dive into creating a Operational Risk Framework, integrating all learnings from the designation

7/11/202615 min read

The roadmap presented in this article is a conceptual approach to designing an Operational Risk Management Framework (ORMF). It draws upon established industry guidance, including the Basel Committee's Principles for the Sound Management of Operational Risk, the COSO Enterprise Risk Management Framework, and the Institute of Internal Auditors' Three Lines Model. In practice, every organization should tailor its framework to its size, complexity, business model, and regulatory environment.

What is an Operational Risk Management Framework?

An operational risk management framework is a system that helps organizations identify, assess, analyze, and mitigate or reduce operational risks that can affect their business. It provides the governance, policies, methodologies, tools, and reporting mechanisms through which an organization manages operational risk throughout its lifecycle—from identification and assessment to monitoring, mitigation, reporting, and continuous improvement.

Ultimately, the purpose of an ORMF is not to eliminate operational risk—which is impossible—but to ensure that risks are understood, managed within the organization's risk appetite, and escalated appropriately when they exceed acceptable levels. An ORMF should not be viewed as a collection of independent tools. Components such as governance, RCSAs, KRIs, incident management, scenario analysis, and risk reporting reinforce one another. As the framework matures, outputs from one component continuously improve the effectiveness of the others, creating a cycle of continuous risk management rather than a linear process.

The roadmap presented here divides implementation into four progressive phases that reflect increasing organizational maturity. While organizations may not move through these phases sequentially, each represents capabilities that collectively contribute to a mature operational risk function. As shown in the image above, the four phases are as follows: Foundation, Framework Development, Embedding & Continuous Improvement and Enterprise Integration.

Phase 1: Foundation

The primary objective of this phase is establish governance, roles and common language. Let's delve deeper into each area this phase deals with.

Governance: It is the base on which the entire framework is built. Consider it equivalent to laying the foundation for a high-rise building. The stronger & well entrenched the foundation, the higher and stable the building can be. Governance defines who owns risk, who oversees risk, who provides independent assurance, and how operational risk decisions are escalated throughout the organization.

The Board of Directors (BoD) are primarily responsible for driving and owing ORF as in accordance with Basel Norms. BoDs set the tone for building not just ORF but the organization's risk culture, it's policies and procedures, and appetite. As per the Basel Norms, the responsibilities are divided as follows:

Board of Directors:

  • Establishing strong risk management culture and code of conduct

  • Approving the Operational Risk Management Framework

  • Appointing Chief Risk Officer (CRO)

  • Establishing roles and responsibilities, delegation authority and ownership

  • Establishing Risk Committees

  • Mapping Hierarchy and reporting lines

  • Approving the establishment of an effective risk management infrastructure, including risk teams including Operational Risk teams (2nd line) and independent audit teams (3rd line)

  • Approving Policies and Procedures including that of compensation and ethics.

Senior Management:

  • Implementation of ORF into specific policies and procedures

  • Ensure that staff have the necessary experience, technical capabilities, and resources to manage risk effectively

  • Providing appropriate operational risk training at all levels of the organization

  • Develop a robust governance structure for Board approval, ensuring transparent lines of responsibility across the organization.

Chief Risk Officer:

  • Oversee the second-line operational risk function and the implementation of the Operational Risk Framework.

  • Lead development of the Operational Risk Appetite for approval by Senior Management and the Board.

  • Risk and governance-related reporting is accurate and produced in a timely manner

The Three Lines Model:

The organization should establish clear responsibilities under the Three Lines Model, ensuring that:

  • Management owns and manages risk.

  • The Operational Risk function provides oversight, challenge, and guidance.

  • Internal Audit provides independent assurance.

More on the three lines model in a separate blog as linked.

Policies and Procedures:

The documentation is best created in the following hierarchy: Regulations, Policies (mandatory), Procedures, Standards, Guidelines (should). The documents can be segregated into an overarching layer consisting of definitions and standards, a risk function layer consisting of individual risk (credit, ops, market) and finally process guide layer or "how-to" documents.

The documents must be written in simple language and then set up for annual reviews. The documents must also include exception management to tackle exception approvals.

Risk Culture and Code of Conduct:

Culture is often tied with conduct risk. BoDs ensure that incentives are aligned with risk culture. Aim is to encourage staff to self-raise issues, tackle root causes instead of encouraging blame game and try to ensure personal values of employees and aligned with company values. Risk culture should be measured periodically through staff surveys, conduct indicators, whistleblowing statistics, employee turnover, and thematic reviews.

Training & Awareness:

Business (first-line) must undertake trainings to sensitize with Ops risks. The training must include incident reporting, policies and procedures, escalation and governance. Trainings must also include mapping risk and controls, indicators and reporting and should be role-based instead of being generic. Tools such as blogs, company-wide guidance mails, marketing and use test can be used for this purpose.

Building Loss Data:

Loss data consists of Internal loss data and external loss data. Starting of building a repository of internal loss data can be challenging, but can be built using the following existing sources (not exhaustive):

  • Loss Accounts - Incident mapping, General Ledger

  • Customer Complaint Data

  • IT call logs, BO Logs

  • Legal and Regulatory fines and provisions

  • Press/Media reviews

For external loss data, the firm can subscribe to industry databases or consortium data that maintain Ops loss events like OpEx, IBM case studies, etc to gauge and map their risk profiles with those of firms similar in nature of businesses. These help in benchmarking and risk identification and predict expected losses trend. External data should be normalized before comparison, as organizations differ significantly in size, business model, and control environments.

The loss data can be further enriched if data such as near-misses, recoveries, root causes as well as potential losses can also be incorporated.

Business Processes Mapping:

This step helps in mapping and understanding business processes that can feed into future RCSAs, help gauge risk profiles and inherent risks. The tasks may include creating workflows, SOP documents, accountability, noting control and performance indicators, capacity, etc. This step also helps to identify similar processes, inter-linkage and dependencies and upstream/downstream processes building a holistic picture of business. This step also helps identify critical processes and key applications that can be fed into Operational Resilience and Business Continuity frameworks later.

Stakeholder and Accountability Mapping:

This step involves mapping stakeholders for each area and persons with authority. Similar to process mapping above, this step brings clarity with respect to who to reach out to/or is responsible for particular area like ICT, HR, Finance, Ops, Compliance, etc. It can help in later stages when RCSAs are to be conducted or action items are to be implemented.

Risk Appetite Statement Principles:

The BoDs initially lays out principles surrounding the organization's risk appetite in an initial draft statement. The statement is drafted based upon organization's strategy, vision and mission and is qualitative in nature. The statement is essentially high level because at this stage the organization is yet to determine it's risk profile. This statement acts as a guidance to business units to then profile and measure their unit's risks and related controls. Once the risk profile is in place, the BoDs can then periodically review, quantify and refine risk appetite statement.

For ex. at this stage the board can layout that organization has moderate appetite for innovation related risks, or very low appetite for customer complaints or zero appetite for regulatory breaches.

Phase 2: Framework Development

The primary objective of this phase is to identify, assess and monitor operational risks. This phase is where the crux of the framework gets built. This can be equivalent to the columns of the building that are now built over the foundation laid earlier. Each column is equally important for the building's strength. If even one column is weak, it can significantly impact the overall strength of the building, and in organization's case, the risk profile and risk management capabilities. Let's delve deeper into each area this phase deals with.

Risk Taxonomy:

The aim is to establish a common Operational Risk taxonomy to ensure consistent identification and classification of risks throughout the organization. A commonly implemented taxonomy can be as per Basel committee guidance as below, wherein operational risks can be classified into following types:

  • Internal Fraud

  • External Fraud

  • Employment Practices & Workplace Safety

  • Clients, Products & Business Processes

  • Execution, Delivery & Process Management

  • Business Disruption & Systems Failure

  • Damage to Physical Assets

  • *Third Party and Vendor Management

  • * Information & Communication Technology (ICT) & Cyber Risk

  • * Data Protection

* While these three are not part of the official Basel guidance, increasing percolation of systems, cyber, automations and increasing regulations in these areas mean that organizations can start to track these risks and related events separately. Thus, classifying them under different categories.

Determining Risk Profile:

This stage marks the transition from governance design to active risk management. Using structured tools such as RCSAs, KRIs, scenario analysis, and operational loss data, the organization begins to understand the nature, magnitude, and concentration of its operational risks. Let's look into each one of them at a deeper level.

Risk and Control Self Assessments:

This is a "bottom-up" approach tool where each business unit maps the risks in their processes. The primary aim is to determine inherent risks in the processes, then map controls related to each inherent risk, and then evaluate residual risks in the process. Once the residual risk is quantified, it then helps the senior management to determine how to deal with the residual risk. The decision involves either one of, or combination of, to 1) Accept 2) Avoid 3) Transfer 4) Mitigate. More on RCSAs in the linked article. The main role of Operational Risk team is to constructively challenge the impact and frequency scores stated by business units who are the owners of the risk. RCSAs should be conducted periodically and whenever significant process, technology, regulatory, or organizational changes occur.

Key Risk Indicators:

Once RCSAs are in place, the next step is to identify key indicators that can help the organization track risks either inherent or residual or both. The indicators must be leading i.e must inform the organization before the event happens. For each indicator, thresholds must be quantified into RAG framework (Red-Amber-Green), with escalation directives in place as per policy for any breaches. The indicators established during this phase form the foundation of the organization's future Operational Risk reporting and Board dashboards, discussed in Phase 3. As a responsibility of second line operational risk team, controls must also be tested for design and operating effectiveness.

Risk Register:

RCSAs and KRIs feed directly into creation of a risk register. It can be viewed as central repository for all risks the organization is exposed to along with the controls tracking these risks. A well-detailed risk register contains list of all risks, their controls, ownership teams, thresholds and is exhaustive. Operational Risk teams (2nd line) tracks and maintains the register. As the framework matures, the Risk Register becomes a primary source of information for management reporting and governance. Once operational risks have been identified and documented, the organization can begin assessing the impact of extreme but plausible events through Scenario Analysis.

Scenario Analysis:

In this step, with inferences from RCSAs, the organization determines the severe but plausible risk events the organization is exposed to. These are low frequency high impact events that consume organization's capital and can even threaten it's existence. Each probable event is rated for frequency and impact in terms of probabilities and the organization tracks these events to be better prepared and capitalised to face them. Scenario Analysis is conducted by Ops Risk team at senior management and business unit heads level and aim to cater to macro risks.

Capital Assessment & Allocation:

Once risk profile is in place, the organization moves towards determining the capital required to cover Ops risks. While Basel III directives is rather straight forward in helping banks calculate Ops Risk capital using "Standardized Measurement Approach (SMA)", organizations can compare whether their assessments of risks match their business profile in line with Basel III capital requirement. The most important part of SMA is linked to historical loss data, and a robust loss data repository helps in reaching accurate capital allotments.

Action Items & Tracking:

Since risk profile is determined using above tools, there can be action items linked to these exercises like: Introduction and Tracking of new KRIs, Decisions on Residual risk, Observations on controls and processes, etc. which the Ops risk team tracks and follows up to closure. In case of any delay or timeline breaches, the items are escalated basis governance policies.

Independent Assurance:

The audit team (3rd line) now undertakes a detailed audit of the framework, including policies and procedures, risk tools, appetite, taxonomy, capital and risk data. Any observations thus are also including in the action item tracking and taken to closure. Internal Audit evaluates the design and operating effectiveness of the Operational Risk Framework but does not own or operate it.

Draft Operational Risk Appetite Statement:

Finally, using the risk profile determined, the BoDs, suggested by CRO and senior management then refine and formalize the Operational Risk Appetite Statement, which then quantifies the principles in place earlier. This appetite is then translated to individual business unit level by CRO and risk teams and then fed back into the next RCSA and SA exercises.

The components described in this phase are not standalone activities. RCSAs identify and assess risks, KRIs provide ongoing monitoring, the Risk Register consolidates the organization's exposure, Scenario Analysis evaluates severe but plausible events, and Capital Assessment translates the residual operational risk profile into financial resilience. Together, these capabilities form the analytical core of the Operational Risk Management Framework.

Phase 3: Embedding & Continuous Improvement

While Phase 2 establishes the core components of the Operational Risk Management Framework, Phase 3 focuses on embedding these components into day-to-day decision-making. The emphasis shifts from designing the framework to operating, monitoring, and continuously improving it. As operational events occur, new products are introduced, regulations evolve, and the organization gains experience, the framework becomes progressively more mature, data-driven, and resilient.

Organizations typically transition from reactive risk management to proactive risk management during this phase. Rather than responding only after events occur, they begin identifying emerging trends, monitoring leading indicators, strengthening resilience, and continuously improving controls before significant losses materialize.

Here the organization then focuses on Risk Reporting, Incident Management, Operational Resilience and continuous improvement. Let's delve deeper into each of this aspects.

Incident Management:

Here the approach stops being reactive to every incident and instead moves onto proactive management of incidents that organization faces. A well-thought incident management framework is created that emphasizes on stability, communication, assessment incl. root cause analysis, Ops loss, customer impact, etc. and then documentation through "lessons learned": effectiveness of controls, updating risk registers, RCSAs, tracking remediation actions and reporting the incident and key learning to risk committees. Every significant incident should trigger a reassessment of the associated risks, controls, KRIs, and scenario assumptions to ensure that lessons learned are embedded into the framework.

Risk Reporting:

Here the approach is to provide senior management and the Board with a consolidated view of the organization's operational risk profile. Typical reporting elements include: KRIs, Loss Events, RCSA heat maps, appetite breaches, scenario outcomes and action status. The focus is also to create real-time dashboards that help monitor above elements, in a sustainable way. The objective of risk reporting is not simply to present information, but to enable timely decision-making by management and the Board through meaningful trends, emerging issues, and early warning indicators.

Business Continuity Management (BCM):

As a part of ORMF, the focus now shifts to resilience. The objective of BCM is to restore critical business operations within predefined Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) following a disruption. The focus is on recovery, crisis response, recovery plans and testing, disaster recovery, etc. The output is Business Continuity Plans (BCP), Recovery time and point objectives and crisis management plans with well-thought out governance and responsibilities.

Operational Resilience:

The focus shifts from recovery to assessing if the organization can continue to deliver important business services (IBS) even while disruption is occurring. Business Process & Stakeholder Mapping from phase 1 becomes important here as it helps in identifying critical services, systems, processes and personnel. The aim is to also access impact tolerances, dependencies, severe but plausible scenarios and cross-functional resilience.

Business Continuity Management and Operational Resilience are complementary but distinct disciplines. BCM focuses on recovering operations after a disruption through contingency planning, disaster recovery, and crisis response. Operational Resilience builds upon these capabilities by ensuring that the organization can continue delivering its Important Business Services within defined impact tolerances, even during severe but plausible disruption scenarios. In this sense, BCM forms a critical building block of an organization's broader Operational Resilience capability.

Continuous Improvement:

As data and reporting mature, organization can then focus on continuous improvement. Data can help feed trend analysis, vulnerable processes, threshold breaches amongst others which then can inform the business and senior management for the requirement of improvements. It can be process improvements, control enhancements, emerging issues. This analysis also help feed into subsequent RCSAs, Scenarios as evidence to challenge assessments and monitor decisions. Continuous improvements can also be achieved through customer complaints, technology upgrades, industry events, automation, etc.

Regulatory Compliance:

The organization now can continuously monitor compliance with evolving regulatory requirements, address gaps, assess compliance risk and industry requirements. The compliance can be assessed against Local regulations (central bank directives), banking compliance (Basel guidelines), Cyber and ICT (For ex. DORA in Europe), Data Protection (GDPR guidelines), etc.

Risk Committees & Escalations:

While escalations is part of each and every step, a governance body such as risk committee must track and consolidate escalations, action items, observations, etc. across the board. It helps identify common causes, inter-process dependencies as well as exposures and helps form a holistic view of risk profile. Risk committee must undertake regular reviews, drive ORMF, monitor risk data and events and ultimately ensure risk profile is within organization's appetite and tolerances. The committee also prioritizes remediation activities based on severity, regulatory expectations, customer impact, and alignment with the organization's risk appetite.

Phase 3 transforms the Operational Risk Framework from a collection of individual tools into an integrated management system. Information generated through incidents, KRIs, regulatory reviews, operational resilience exercises, and management reporting continuously feeds back into RCSAs, Scenario Analysis, Risk Appetite, and Governance, ensuring that the framework evolves alongside the organization.

Phase 4: Enterprise Integration & Strategic Risks

The previous phases focused on establishing, developing, and embedding the Operational Risk Management Framework. In this final phase, operational risk evolves from a functional governance capability into a strategic business enabler. Rather than simply preventing losses, the framework now supports better decision-making, more resilient operations, and sustainable value creation by integrating with enterprise-wide risk management and business strategy.

Risk Measurement:

The risk measurement is increasingly forward looking instead of backward looking (i.e historical loss data, KRI, near misses, etc). Here organization deploys advanced analytics, predictive analytics, forecasting to gauge risk and study its impact on capital. It combines historical trends, leading indicators, scenario outputs and expert judgement to identify emerging risk concentrations.

Integration of Legal & Reputation Risks:

Both these risks are actively considered to be part of operational risk framework, but Reputation risk is difficult to quantify directly because it often materializes as a consequence of failures in other risk categories, and therefore, comes into the picture once ORMF is embedded. Similarly for legal risk and litigation, the organization stops treating it in silos and instead looks to integrate it within the framework, as much litigations are somewhere driven through operational issues. It monitors brand value, customer trust (using tools like NPS score), social media to ensure brand is protected. Likewise Operational events are increasingly assessed for their potential legal, regulatory and reputational consequences rather than being treated as isolated incidents.

Emerging & Strategic Risks:

Organizations establish structured horizon scanning processes that monitor technological developments, regulatory change, geopolitical events, environmental factors, and evolving customer behavior to identify risks before they become material. The organization and the ORMF itself must be agile and pre-empt for any new regulations, compliance directives that may arise in these new fields.

For ex. banks now have to separately declare how they go about determining and managing climate change related risks in their yearly disclosures.

Data & Technology:

Mature organizations have already started deploying technology and tools to better manage their overall risk and governance. It involves automating various aspects of risk frameworks from real-time KRIs monitoring to alerts on thresholds breaches, to conducting RCSAs and Scenario Analyses online. Organizations are also working towards reducing duplication of work either between different risk verticals or between 2nd and 3rd lines that better improves productivity and efficiency. A lot of business related activities like RCSA are conducted in one go for all types of risks (Ops, finance, legal, HR) instead of each team driving separate analysis.

For ex. Some large financial institutions, such as BNP Paribas through its Op360 platform, have invested in integrated GRC solutions that centralize operational risk activities while progressively incorporating resilience, emerging risks and enterprise governance capabilities.

Integration with ERM & Business Strategy:

At this stage, the Operational Risk Management Framework becomes fully integrated with the organization's Enterprise Risk Management framework. Here, risk profile, appetite and capital is aligned in coherence with business strategy, planning and performance. The aim here is that ERM adds value to the organization, that it lets organization gain better risk-adjusted returns on the business it undertakes, and the direction that business wants to take to succeed in its goals.

For ex. Before launching a new product, organizations assess operational, legal, compliance, technology, cyber, conduct and reputational risks alongside commercial opportunities. This enables informed decision-making and helps ensure that innovation remains aligned with the organization's risk appetite and strategic objectives.

From Risk Management to Strategic Value

The key questions each phase should answer as evident from above:

Phase 1: Foundation: Who owns and governs operational risk?

Foundation phase therefore establishes governance

Phase 2: Framework Development: What operational risks do we face, and how do we assess them?

This phase therefore deals with risk identification, assessment and capital allocation

Phase 3: Embedding & Continuous Improvement: How do we monitor, learn from, and improve our management of operational risk?

This phase delves into risk monitoring and operational resilience.

Phase 4: Enterprise Integration: How does operational risk influence strategic decision-making and enterprise resilience?

This phase integrates the framework with enterprise strategy and decision making.

In conclusion, a mature Operational Risk Management Framework should not be viewed as a control mechanism designed solely to prevent losses. By improving governance, enabling informed decision-making, strengthening resilience, supporting regulatory compliance, and enhancing stakeholder confidence, the framework contributes directly to sustainable value creation. Organizations with mature operational risk capabilities are generally better positioned to innovate confidently, respond to disruption, and achieve their strategic objectives.

Building an Operational Risk Management Framework is not a one-time implementation project but an ongoing organizational capability. As governance matures, operational experience accumulates, and new risks emerge, the framework must evolve alongside the business. Organizations that successfully embed operational risk into decision-making are better positioned to pursue innovation, respond to disruption, and create sustainable value while remaining within their risk appetite.

References:

- Chapelle, Ariane. Operational Risk Management: Best Practices in the Financial Services Industry.

- Crouhy, Michel, Galai, Dan, and Mark, Robert. The Essentials of Risk Management, Second Edition.

- Girling, Philippa X. Operational Risk Management: A Complete Guide for Banking and Fintech.

-Grimwade, Michael. Ten Laws of Operational Risk: Understanding its Behaviours to Improve Its Management.

- Howitt, Jonathan (Ed), Professional Risk Managers’ Handbook Series: Risk Management Frameworks and Operational Risk, Volume III, Book 1

- D515, Revisions to the Principles for the Sound Management of Operational Risk , Basel Committee on Banking Supervision, March 2021.

- COSO Internal Control - Integrated Framework, Executive Summary

Portfolio

Showcasing my skills, education, and experiences online.

Connect

shubhamghotankar@gmail.com

+32 0465 86 03 92

© 2025. All rights reserved.