SD-14.1 — Enterprise & Operational Risk Management
Business Domain: BD-14 Enterprise Risk, Control & Assurance (Cross-cutting — corporate) · Applies: BOTH
Purpose
Manages the risk of running the firm — the enterprise risk the institution carries as a business, and the operational risk in its processes, people, systems and third parties. SD-14.1 is the Chief Risk Officer’s function: it sets the firm-level risk appetite, maintains the enterprise risk register, runs the operational-risk discipline — risk-and-control self-assessment, loss-event capture, key risk indicators — and escalates risk events to governance. Operational risk is the risk of running the firm, not the risk in the portfolio. It is not investment risk — BD-07 measures the risk in the portfolio — and it is not compliance or financial crime, which are SD-14.2 and SD-14.3; the three are the firm’s plural second line, not one function.
Service Operations
- Set and maintain risk appetite — define the firm’s enterprise risk appetite and the risk-appetite framework.
- Maintain the enterprise risk register — identify, assess and track the firm-level risks the institution carries.
- Run operational-risk assessment — operate the risk-and-control self-assessment across the firm’s processes, by the operational-risk taxonomy (process, people, systems, fraud, third-party).
- Capture loss events and key risk indicators — maintain the operational-loss-event database and the key-risk-indicator set.
- Run risk scenarios and escalate — run enterprise and operational-risk scenarios, and escalate risk events and emerging risks to risk governance and the board.
Inputs and outputs
- Inputs: the firm’s processes and risks; loss events and control failures from across the model (for example reconciliation-control evidence from SD-12.10); the resilience picture from SD-14.6; the third-party risk from SD-17.8.
- Outputs: the risk appetite, the enterprise risk register, the operational-risk assessment and the risk reporting — consumed by the governing bodies, SD-14.8 Internal Audit, SD-14.7 and the regulators.
Entities
- Consumes: the firm’s process, control and loss-event records; the SD-12.10 loss events and control failures from across the model; the SD-14.6 resilience picture; the SD-17.8 third-party risk; E-36 Oversight Exception (from SD-12.16 — the operational-risk events the administrator-oversight discipline surfaces).
- Owns: the enterprise risk register and the operational-loss-event record — a process artefact; an Operational Risk Event entity is an open extension.
Standards
- COSO ERM — Integrating with Strategy and Performance and ISO 31000.
- The Three Lines Model — enterprise and operational risk as a second-line function.
- The GARP Buy Side Risk Managers Forum Risk Principles for Asset Managers — which structures the field as three peer sections, Governance / Investment Risk / Operational Risk; the operational-risk section is SD-14.1’s, the investment-risk section is BD-07’s.
Open extensions
- An Operational Risk Event entity.
- The risk-and-control-self-assessment and key-risk-indicator sub-model.
- The boundary with BD-07 — the risk of the firm versus the risk in the portfolio.