Short answer
Operational risk identifies and reduces process risks through proportionate controls, monitoring, and escalation. This catalog progresses from applying established controls, to independently assessing a workflow, to shaping risk practices across connected operations.
About Operational risk
Identifies and reduces process risks using proportionate controls, monitoring, and escalation. Effective operational risk work connects plausible failure events to their consequences and makes ownership, response, and remaining exposure explicit.
Use this competency for
- Roles that identify process failures and design, monitor, or improve controls.
- Work where operational decisions must account for likelihood, consequence, and remaining exposure.
Do not use this competency for
- Roles that only follow controls and are not expected to assess risk or respond to control evidence.
Important distinctions
Quality management
Quality management checks whether recurring outputs meet standards. Operational risk addresses uncertain process failures and their potential consequences.
Business continuity
Operational risk reduces the likelihood or consequence of process failures. Business continuity prepares the response needed when disruption occurs.
Expectations by level
IC1
Applies defined controls
Applies established controls and monitoring steps with guidance. Records evidence, identifies clear departures, and escalates operational risks within their own work.
Observable behaviors
- Performs a defined control at the required point in the process.
- Records control evidence and any departure found.
- Escalates a risk or failed control through the documented path.
Examples
- Finds that required approval evidence is missing and pauses the next step for review.
- Records a failed control with enough context for the process owner to assess the exposure.
IC2
Assesses workflow risk
Independently assesses operational risks in a team or workflow. Evaluates causes and consequences, proposes proportionate controls, and monitors whether treatment works as intended.
Observable behaviors
- Describes a risk as a plausible event with causes and consequences.
- Evaluates existing controls using available process evidence.
- Designs treatment that is proportionate to the exposure.
- Reviews monitoring evidence and changes treatment when needed.
Examples
- Identifies a single-person dependency in a critical approval and introduces a documented backup path.
- Finds that a control is performed too late to prevent the consequence and moves it earlier in the workflow.
IC3
Shapes cross-team risk practice
Leads operational risk work across connected teams or ambiguous processes. Aligns risk ownership, evaluates combined exposure and control tradeoffs, and establishes practices others use.
Observable behaviors
- Frames risks that cross process or team boundaries.
- Aligns owners on accountability for controls and remaining exposure.
- Identifies control gaps, duplication, and unintended operational burden.
- Creates reusable assessment, monitoring, and escalation practices.
Examples
- Finds that separate team controls leave an unowned risk at the handoff and establishes one accountable owner.
- Reviews overlapping controls across a process and removes duplication while preserving the intended protection.