Quick answer: Operational risk management addresses the risk of loss from failed internal processes, people, systems, or external events. Unlike market or credit risk, it is not about prices or counterparties but about the machinery of the business — and controlling it with strong controls, monitoring, and resilience protects the whole organization.
What is operational risk?
Operational risk is the risk of loss from breakdowns in processes, human error, system failures, or external events such as disasters and fraud. It is one of the four core exposures in financial risk management and often the hardest to quantify.
Where does operational risk arise?
Sources include process errors, failed settlements, technology outages, cyber incidents, human mistakes, and fraud. Because it spans the whole business, operational risk can appear anywhere operations touch money or data.
How is operational risk managed?
Management relies on strong internal controls, process design, monitoring, and resilience planning. Firms map key processes, track loss events, and build redundancy so failures are contained rather than catastrophic.
How does it fit into governance?
Operational risk requires clear ownership and reporting within the firm's risk governance framework, and a supportive risk culture where issues are surfaced rather than hidden. Mobius Risk Group's trade management and back-office services reduce operational risk in trading and settlement.
Frequently asked questions
What is operational risk?
The risk of loss from failed processes, people, systems, or external events — as opposed to losses from market prices or counterparty default.
What are examples of operational risk?
Process errors, failed settlements, system outages, cyber incidents, human error, and fraud.
How is operational risk controlled?
Through strong internal controls, sound process design, monitoring of loss events, and resilience planning that contains failures.
