Operational Risk Management
What is OR?
▪ Applies to all firms (financial and non-financial)
▪ Used to be a catch-all phrase for non-financial risks
▪ Current Basel II definition is “the risk of loss resulting
from inadequate or failed internal processes, people
and systems or from external events”
➢ Includes both internal and external event risk
➢ Legal risk is also included, but strategic, reputational and
systemic risks are not
➢ Direct losses are included, but indirect losses (opportunity
costs) and near misses are not
− How many of the costs associated with 9/11 would be captured?
Examples of OR Loss Events
Types of OR* Examples
▪ Unauthorized transaction resulting in monetary loss
Internal Fraud
▪ Embezzlement of funds
▪ Branch robbery
External Fraud
▪ Hacking damage (systems security)
Employment Practices ▪ Employee discrimination issues
& Workplace Safety ▪ Inadequate employee health or safety rules
Clients, Products & ▪ Money laundering
Business Practices ▪ Lender liability from disclosure violations or aggressive sales
Damage to Physical ▪ Natural disasters, e.g. earthquakes
Assets ▪ Terrorist activities
Business Disruption
▪ Utility outage (e.g. blackout)
and System Failures
▪ Data entry error
Execution, Delivery &
▪ Incomplete or missing legal documents
Process Management
▪ Disputes with vendors/outsourcing
* Based on Basel Committee’s OR loss event classification – see Appendix for details.
Major OR Characteristics
▪ Partly endogenous
➢ Unwanted by-product of corporate activity
➢ Positively related to complexity of operations
▪ Highly idiosyncratic
➢ OR events tend to be less correlated to each other and to
other risk types
➢ Less directly linked to business cycles
▪ In principle (partially) controllable ex ante
▪ Trade-off is mostly risk vs. cost of avoidance, not
risk vs. return
Key Drivers of Interest in OR
Recent ▪ High-profile cases and related negative publicity
Experience
▪ Examples include Allfirst, Barings, Enron etc.
Regulatory
Pressure ▪ Basel II’s explicit capital requirements for OR
▪ Additional complexity brought about by
Market
Developments automation, outsourcing, large volume service
provision, deregulation, M&A, risk transfer etc.
Firm-wide
▪ Next frontier in enterprise risk management and
Risk Management business applications, e.g. capital allocation,
pricing, performance measurement etc.
OBJECTIVE AND GOALS
MAXIMUM
CAPABILITY
CONSERVE
PERSONNEL &
RESOURCES
PREVENT OR ADVANCE OR
MITIGATE LOSSES OPTIMIZE GAIN
EVALUATE AND EVALUATE AND
MINIMIZE RISKS MAXIMIZE GAIN
IDENTIFY, CONTROL, IDENTIFY, CONTROL,
AND DOCUMENT AND DOCUMENT
HAZARDS OPPORTUNITIES
4 KEY ORM
PRINCIPLES
1. Accept no unnecessary risks.
2. Make risk decisions at the appropriate
level.
3. Accept risks when benefits outweigh
costs.
4. Integrate ORM into doctrine and
planning at all levels.
1. Accept No Unnecessary Risks
BUT.... NOBODY TAKES
“UNNECESSARY” RISKS?
If all the hazards that could have been
detected have not been detected then
unnecessary risks are being accepted.
The single greatest advantage of ORM over
traditional risk management is the consistent
detection of 50%+ more hazards.
2. Make Risk Decisions at the
Appropriate Level
Factors below become basis of a decision-
making system to guide leaders
• Who will answer in the event of a mishap?
• Who is the senior person at the scene?
• Who possesses best insight into the full benefits and costs of a
risk?
• Who has the resources to mitigate the risk?
• What level makes the most operational sense?
• What level makes these types of decisions in other activities?
• Who will have to make this decision in combat operations?
3. Accept Risks When Benefits
Outweigh Costs.
WHAT HAPPENS WHEN AN ORGANIZATION
STOPS TAKING RISKS?
WEBSTER: “BUREAUCRACY: A system of administration
characterized by lack of initiative and flexibility, by indifference
to human needs or public opinion, and by a tendency to defer
decisions to superiors or to impede action with red tape.”
MAINTAINING A BOLD, RISK-TAKING
ORGANIZATION IS ALWAYS A CHALLENGE
WHEN YOUR UNIT IS NOT ON A MISSION.
ORM HELPS.
4. Integrate ORM Into Doctrine and
Planning At All Levels.
Loss Control
This is the one we
Staff Injects
Operational want!!
Leaders Add-On
Operational
Process
Operational Operational
Process Process Loss Control
Occurs Within
The Process
WHAT IS AN
“OPERATIONAL PROCESS”?
Operational Securing Building
Maintaining Supplying
Planning
and all their sub-processes
ORM IS BASED ON SYSTEMS
MANAGEMENT CONCEPTS
Management
5M Model
Mission
Man Machine
Media
THE ORM 6-STEP
PROCESS
6. Supervise 1. Identify
and Review the Hazards
5. Risk Control 2. Assess
Implement the Risks
4. Make 3. Analyze
Control Risk Control
Decisions Measures
1. Identify
Step 1 - Identify the
the Hazards
6. Supervise
and Review
2. Assess
5. Risk Control the Risks
Implementation
Hazard
3. Analyze
4. Make
Risk Control
Control
Measures
Decisions
Process: Emphasize hazard ID
tools. Adds rigor and early
detection.
Output: Significant (50%+)
improvement in the detection of
hazards.
7 Primary Hazard ID Tools
BROAD RANGE OF APPLICATION
AT ANY LEVEL
• Operations Analysis/Flow Diagram
• Preliminary Hazard Analysis
• What If
• Scenario
• Logic Diagrams
• Change Analysis
• Cause and Effect
Specialized and Advanced
Hazard ID Tools
• Specialized tools accomplish specific ORM
objectives.
Map analysis, interface analysis, mission
protection tools, training realism, opportunity
assessment
• Advanced tools are used by specialists and
professionals to add depth to ORM
applications
EXAMPLE:
THE DRIVE TO WORK
WHAT IF ANALYSIS
• What if the car catches fire.
•What if a carjack is attempted.
•What if I have to take an unknown detour.
•What if I run out of gas.
•What if another car rear ends me.
1. Identify
6. Supervise the Hazards
and Review
2. Assess
Step 2 - Assess the Risk
5. Risk Control the Risks
Implementation
3. Analyze
4. Make Risk Control
Control Measures
Decisions
Process: All hazards evaluated for total
impact on mission or activity. Root
causes determined and risk levels
assigned (EH, H, M, L)
Output: Personnel throughout the
organization know the priority risk
issues of the command and of their
function.
THE ASSESSMENT TOOLS ADD
OBJECTIVITY TO THE
EVALUATION OF RISK
• Risk assessment matrix: Requires
specific evaluations of severity,
probability, and when necessary,
exposure
• Totem pole: Induces the
prioritization of risk issues across
functions and across the organization
THE RISK ASSESSMENT MATRIX
KEY TOOL FOR RISK ASSESSMENT
Probability
Frequent Likely Occasional Seldom Unlikely
A B C D E
S Catastrophic I Extremely
E
V
E
Critical II High High
R
I Moderate III Mediu
T m
Y Negligible IV Low
Risk Levels
Step 3 - Analyze Risk 6. Supervise
and Review
5. Risk Control
Implementation
1. Identify
the Hazards
2. Assess
the Risks
Control Measures 4. Make
Control
Decisions 3. Analyze
Risk Control
Measures
Process: Comprehensive risk control
options are developed for risks based on a
worst-first basis.
Output: A full range of cost effective,
mission supportive, risk controls for the
consideration of the decision maker.
The Risk Control Option Tools
Add Scope & Depth
• Basic or “macro” risk control options:
Reject, Avoid, Delay, Transfer, Spread,
Accept, Compensate, Reduce
• Risk control options matrix: 46 specific
“reduce-focused” control options -
applicable at up to four levels in the
organization
Step 4 - Make Control
1. Identify
6. Supervise the Hazards
and Review
2. Assess
5. Risk Control the Risks
Implementation
Decisions
3. Analyze
Risk Control
4. Make Measures
Control
Decisions
Process: A decision-making system gets risk
decisions to the right person, at the right
time, with the right support.
Output: Personnel know their decision-
making authority and limitations and take
necessary risks.
ORM Uses Proven
Decision-making Tools
• Decision-making systems get the decision to the
right person, at the right time, with the right
support
• Basic cost benefit and return on investment
analysis assure maximum benefit for the risk
control $
• Decision-making matrices and other modern
decision-making tools improve decision quality
• The leader question list induces better staff inputs
Step 5 - Risk Control
1. Identify
6. Supervise the Hazards
and Review
2. Assess
5. Risk Control the Risks
Implementation
Implementation
3. Analyze
4. Make Risk Control
Control Measures
Decisions
Process: Leaders lead, operators are
involved, all are accountable.
Output: ORM initiatives always have
positive mission impact.
ORM Implementation Tools &
Guidelines Help Controls Click
with Operators
• The involvement continuum guides the high
degree of operator input to ORM actions
• The leader involvement actions list and the
leader opportunity job aid help assure effective
leader influence
• The motivation model makes application of
modern behavior management techniques easier
6. Supervise
1. Identify
and Review
the Hazards
Step 6 - Supervise and Review 5. Risk Control
Implementation
4. Make
Control
2. Assess
the Risks
3. Analyze
Risk Control
Measures
Decisions
Process: Progress measured through
increased mission effectiveness, mishap
results and direct indicators of risk.
Output: ORM performance status
determined real time.
Review and Feedback Procedures
Measure & Leverage ORM Results
• Eliminate invalid statistical uses of mishap
rates and numbers
• Refocus measurement on direct measures of
risk (critical behaviors, knowledge,
conditions, etc.)
• Radically improve the effectiveness of
feedback systems through modern data and
communications systems
USING THE 6-STEP PROCESS
THE RISK MANAGEMENT
CONTINUUM
PLANNING OPERATIONS AFTER-ACTION
Deliberate ORM Largely Time-critical Assess indicators
Detailed Hazard ID Change Analysis Deliberate ORM
Integration Real Time Integration
Highly Decentralized Feedback to Planning
We try to get But continue the
most ORM done process here and
here here
USING THE 6-STEP PROCESS
LEVELS OF EFFORT
TIME CRITICAL DELIBERATE STRATEGIC
Little Lot of
Time Time
Resources Resources
Risk Risk
SELECTED PRIMARY SPECIALIZED ADVANCED
PRIMARY
Integrating the ORM Process
Overview
• Why integration is critical?
• 12 Strategies for ORM integration.
• The importance of pace.
WHY INTEGRATION IS
CRITICAL?
Integration:
• Forces balancing of loss control and other mission
needs
• Captures more of the knowledge and experience of large
numbers of operators
• Reduces the number and diversity of references needed
to do the job right
• Eliminates redundancy and gaps between loss control
functions
• Strengthens accountability
• Reduces costs and workloads (in plans, materiel
development cycles, etc.)
THE TWELVE STRATEGIES
FOR
PROGRAM INTEGRATION
1. Accountability 7. Employee Activities
2. Teaming 8. Process Integration
3. Partnership 9. Direct Change
4. Integrate in Training 10. Gain a Champion
5. Risk Decision Points 11. Integrate in Strategic
6. Organization & Planning
Policy Structure 12. Integrate into
Measurement
ORM STRATEGY
Miscellaneous Initiatives
• Automated “Tools”
• Doctrine Integration
• Crosstell
• NEWS Release(s)
• Video(s)
The leader’s role will be
a decisive factor in the
success or failure of
ORM
ORM Leadership
Opportunities
1. Commit to Breakthrough Improvement
Objectives: Put improvement of risk performance
(control-opportunity) on a competitive level with other
important mission concerns.
2. Set Goals & Objectives
Objectives: Establish periodic ORM performance
and programmatic goals.
ORM Leadership
Opportunities Continued
3. Set a Personal Example
Objectives: To assure credibility of the ORM
process through personal behavior.
4. Build an Aggressive Opportunity
Mindset in the Organization
Objectives: Create an organization as conscious
of the opportunity aspects of ORM as it is the risk
reduction
ORM Leadership
Opportunities Continued
5. Induce Loss Control Community
Functional Integration
Objectives: Build increasing cooperation and
integration of the loss control community
6. Establish an ORM Management Structure
Objectives: Provide the necessary leadership and
staff resources to adequately guide the ORM process
ORM Leadership
Opportunities Continued
7. Resource ORM Activities
Objectives: Allocate resources to ORM (control-
opportunity) at a level it can competitively justify
8. Heat Shield Subordinates
Objectives: Protect subordinates who have taken
prudent, mission supportive risks, but experienced
severe losses, from negative consequences.
ORM Leadership
Opportunities Continued
9. Detect & Correct Gambling
Objectives: Develop an organization in
which risk “gambling” is deterred even
when the gambler “wins”.
10. Use the Power of Question
Objectives: Use pointed ORM questions
to induce ORM activity and culture change.
ORM Leadership
Opportunities Continued
11. Regularly Monitor ORM Progress
Objectives: Periodically assess a set of data
that effectively monitors organization ORM
status
12. Exploit the ORM Value of Major
Mishap Reviews
Objectives: Consistently induce
consideration of the ORM implications of
mishaps
QUESTIONS?
THINK SAFETY