Operational Risk Reporting
Purpose
This document defines the Bank's framework for operational risk reporting. Effective operational risk reporting enables the identification of emerging risks, supports informed decision-making by senior management, and ensures compliance with regulatory expectations regarding risk transparency and governance.
Scope
This framework applies to all operational risk events occurring across the Bank's operations, including but not limited to process failures, system outages, human errors, fraud incidents, legal and compliance breaches, and external events. It covers all business lines, branches, and support functions.
Definitions
| Term | Definition |
|---|---|
| Operational Risk Event | An event arising from inadequate or failed internal processes, people, systems, or from external events, that has resulted in or could have resulted in a financial loss or reputational damage. |
| Near Miss | An operational risk event that did not result in a loss but had the potential to do so. |
| Key Risk Indicator (KRI) | A metric that provides an early warning signal of increasing risk exposure in a particular area. |
| Loss Event | An operational risk event that has resulted in a quantifiable financial loss to the Bank. |
Risk Event Categories
Operational risk events are classified using the Basel II event type taxonomy:
- Internal Fraud
- External Fraud
- Employment Practices and Workplace Safety
- Clients, Products, and Business Practices
- Damage to Physical Assets
- Business Disruption and System Failures
- Execution, Delivery, and Process Management
Reporting Procedure
Step 1: Event Detection and Initial Reporting
- Any staff member who becomes aware of an operational risk event (including near misses) must report it to their line manager within two (2) hours of detection.
- The line manager logs the event in the Operational Risk Management System (ORMS) within four (4) hours of notification, capturing: event description, date and time, business line, estimated loss (if applicable), root cause (preliminary), and immediate remedial actions taken.
Step 2: Impact Assessment
- The Operational Risk team reviews each logged event and assigns an impact classification:
| Impact Level | Financial Loss Threshold | Additional Criteria |
|---|---|---|
| Level 1 — Minor | Below USD 10,000 | No regulatory impact, no reputational exposure |
| Level 2 — Moderate | USD 10,000 – USD 100,000 | Potential regulatory interest, limited reputational exposure |
| Level 3 — Significant | USD 100,001 – USD 1,000,000 | Regulatory reporting required, moderate reputational exposure |
| Level 4 — Severe | Above USD 1,000,000 | Mandatory regulatory notification, significant reputational exposure, Board notification |
Step 3: Investigation and Root Cause Analysis
- Level 1 events are investigated by the responsible business line, with findings documented in ORMS within ten (10) business days.
- Level 2 and Level 3 events are investigated jointly by the business line and the Operational Risk team, with a formal Root Cause Analysis (RCA) report completed within fifteen (15) business days.
- Level 4 events trigger an immediate investigation led by the Head of Operational Risk, with regular status updates to the Chief Risk Officer (CRO) and the Board Risk Committee.
Step 4: Remediation
- Each investigation concludes with a set of remedial actions, assigned to specific owners with defined completion dates.
- Remedial actions are tracked in ORMS and reviewed monthly by the Operational Risk Committee (ORC).
- Overdue remedial actions are escalated to the CRO.
Key Risk Indicators (KRIs)
The following KRIs are monitored monthly and reported to the ORC:
| KRI | Threshold (Amber) | Threshold (Red) |
|---|---|---|
| Number of operational risk events | >50 per month | >100 per month |
| Total operational losses | >USD 500,000 per month | >USD 2,000,000 per month |
| SLA breach rate | >5% | >10% |
| System availability (Core Banking) | <99.5% | <99.0% |
| Overdue remedial actions | >10 items | >25 items |
Reporting Calendar
| Report | Frequency | Audience |
|---|---|---|
| Operational Risk Dashboard | Monthly | Operational Risk Committee |
| Loss Event Summary | Monthly | CRO, COO |
| KRI Report | Monthly | Operational Risk Committee |
| Quarterly Operational Risk Report | Quarterly | Board Risk Committee |
| Regulatory Operational Risk Return | Quarterly / As required | Central Bank / Regulator |
Related Documents
- Incident Escalation Matrix
- Business Continuity Plan Overview
- Third-Party Risk Assessment
- Internal Audit Charter