Risk Management in Banking and Insurance · Operational Risk and Off-Balance Sheet Risk
Operational Risk Management Framework in Banks
Updated 11 October 2026 · Fact-checked
An operational risk management framework is the set of policies, roles and tools a bank uses to identify, assess, monitor and control losses from failed processes, people, systems or external events. To answer questions, walk through the cycle: identify, assess (RCSA), monitor (KRIs, loss data), control and report, under the three lines of defence.
Understand Operational Risk Management Framework
Operational risk is the risk of loss from inadequate or failed internal processes, people and systems, or from external events. It includes legal risk but excludes strategic and reputational risk. Think of a wrong payment, a cyber fraud, a system outage or a staff error.
A bank cannot remove this risk. It can only manage it in a planned way. That plan is the framework. It works as a cycle: identify the risks, assess them, monitor them, then control or mitigate them and report to the Board.
Three tools do most of the work. RCSA (Risk and Control Self-Assessment) is where each business unit lists its own risks and the controls in place, then rates the inherent risk, control strength and residual risk. Key risk indicators (KRIs) are measurable early-warning metrics, such as staff turnover, failed transactions, system downtime or pending reconciliation items. Loss data collection records actual events, with amount, date, cause and business line. The bank uses it to learn and to measure risk.
The three lines of defence assign responsibility. The first line is the business and operations units, which own and manage the risk daily. The second line is the independent risk and compliance function, which sets the framework, challenges the first line and monitors. The third line is internal audit, which gives independent assurance to the Board and Audit Committee that the first two lines work.
Control and mitigation options are: improve processes and internal controls, segregate duties, use business continuity and disaster recovery plans, train staff, strengthen IT security, outsource with oversight, and transfer part of the risk through insurance. The Board approves the policy and risk appetite, and senior management carries it out.
Key rules to remember
- Residual risk (qualitative RCSA)
- Residual risk = Inherent risk − effect of controls
- This is a concept, not an exact arithmetic formula. Rate inherent risk first, then adjust for control effectiveness.
- Risk rating score (common scoring approach)
- Risk score = Likelihood score × Impact score
- A usual scoring method in RCSA. The scales (such as 1 to 5) are set by each bank's policy.
- Net loss from an event
- Net loss = Gross loss − Recoveries
- Loss databases usually record both gross loss and recoveries (such as insurance recoveries).
- Framework cycle
- Identify → Assess → Monitor → Control/Mitigate → Report
- Use this as the skeleton for any descriptive answer.
- Three lines of defence
- 1st: business units own risk | 2nd: risk and compliance oversee | 3rd: internal audit assures
- Do not mix up roles. Audit is independent of both of the other lines.
How to solve Operational Risk Management Framework questions
Use the same structure for any descriptive or case question on the operational risk framework.
- 1Read the question and mark what is asked: define, explain a tool, assign roles, or recommend action on a case.
- 2Define operational risk in one line: loss from failed processes, people, systems or external events.
- 3Name the stage of the cycle the question relates to: identify, assess, monitor, control or report.
- 4Explain the relevant tool with its purpose: RCSA for assessment, KRIs for early warning, loss data for learning and measurement.
- 5Allocate roles using the three lines of defence and name the line responsible for each action.
- 6For a case, identify the specific failure (process, people, system or external), then give controls and mitigants linked to it.
- 7State board and senior management oversight, and reporting to them.
- 8End with a short conclusion or recommendation.
Quickest way: PRAM-L shortcut: Process, Risk tool, Accountability, Mitigation, Loop back
When to use it: Use it for 14-mark descriptive answers or case-based MCQs when time is short.
- Classify the event: process, people, system or external.
- Pick the tool: RCSA (forward-looking self-assessment), KRI (early warning), loss data (past events).
- Assign the line: owns the risk is the first line; oversees is the second; independently assures is the third.
- Give one control and one mitigant, such as dual authorisation and insurance.
- Close the loop: feed the event into loss data and update the RCSA and KRIs.
Common mistakes in Operational Risk Management Framework
Treating internal audit as part of the second line, or as the owner of risk.
Audit, compliance and risk all look like control functions.
Fix: Remember: business owns, risk and compliance oversee, audit assures independently.
Saying KRIs record losses that have already happened.
KRIs and loss data are both numbers about risk.
Fix: KRIs are forward-looking early-warning indicators. Loss data records actual past events.
Describing RCSA as an audit done by an outside party.
The word 'assessment' suggests an external review.
Fix: RCSA is a self-assessment done by the business units, then challenged by the second line.
Including strategic or reputational risk inside the definition of operational risk.
Many failures have reputational consequences.
Fix: Use the standard definition: it includes legal risk but excludes strategic and reputational risk.
Confusing inherent risk with residual risk.
Students forget that controls come in between.
Fix: Inherent risk is before controls. Residual risk is what remains after considering control effectiveness.
Writing a theory answer with no link to the case facts.
Students recall the framework but do not apply it.
Fix: Name the actual failure in the case and match each control and role to it.
Worked examples
Example 1
A branch of an Indian bank has seen a rise in failed NEFT transactions, pending reconciliation items and staff attrition over three months. Explain how the bank's operational risk framework should treat this, and name the responsible lines of defence.
Show the solution
- Classify: failed transactions point to process and system risk. Attrition and pending reconciliations point to people and process risk.
- These measures are the bank's key risk indicators. They are early warnings, since they show rising risk before large losses appear.
- Compare each KRI with its threshold. If a threshold is breached, escalate to senior management and the risk committee.
- First line: the branch and operations head investigate causes, clear reconciliation backlog, add staff or training, and fix the process.
- Second line: the operational risk function reviews the KRI breach, challenges the branch's action plan, updates the RCSA for the branch and reports to the Board's risk committee.
- Third line: internal audit independently checks whether KRI monitoring and escalation work, and reports to the Audit Committee.
- Record any actual loss from failed transactions in the loss database with cause and amount.
Answer: Treat the trends as KRI breaches: escalate them, have the first line fix processes and staffing, have the second line challenge, update RCSA and report to the Board, and have internal audit give independent assurance. Log any losses in the loss database.
Example 2
An RCSA scores a risk with Likelihood 4 and Impact 5 on a 1-5 scale. After controls, the bank rates likelihood at 2 and impact at 4. Compute the inherent and residual scores and comment. Also compute the net loss if a related event caused a gross loss of ₹12,00,000 and insurance recovered ₹5,00,000.
Show the solution
- Inherent score = Likelihood × Impact = 4 × 5 = 20.
- Residual score = 2 × 4 = 8.
- Reduction = 20 − 8 = 12 points, which is 12 ÷ 20 = 60% of the inherent score.
- This shows that controls are effective. The bank should check whether 8 lies within its risk appetite and decide whether more mitigation is needed.
- Net loss = Gross loss − Recoveries = ₹12,00,000 − ₹5,00,000 = ₹7,00,000.
- Record both gross loss and recovery in the loss database.
Answer: Inherent score 20, residual score 8 (a 60% reduction), so controls are effective if 8 is within appetite. Net loss is ₹7,00,000.
Exam tips
- Learn the three lines of defence as a one-line role each. Case MCQs often test which line does what.
- Keep the definition word-perfect, including that legal risk is included and strategic and reputational risk are excluded.
- In descriptive answers, structure with the cycle: identify, assess, monitor, control, report. It gives clear headings and easy marks.
- For numerical items, show likelihood × impact scoring and net loss clearly, and state the scale used.
- Always link your controls to the specific failure in the case. Generic lists score less.
Practice questions from Operational Risk and Off-Balance Sheet Risk
- A bank issues a guarantee for Rs 50 lakh where it is a direct credit substitute, and the applicable credit conversion factor is 100%. The co…
- A bank has issued a guarantee of Rs 50 crore in favour of a customer's supplier. The guarantee is a direct credit substitute carrying a cred…
- Under the Basel framework, which of the following is classified as an event-type category of operational risk loss?
- Which of the following off-balance sheet items of a bank is generally a contingent liability rather than a derivative contract?
- A bank's gross income for the last three years is Rs 200 crore, Rs 240 crore and Rs 280 crore, all positive. Under the Basic Indicator Appro…
Operational Risk Management Framework in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Operational Risk Management Framework: frequently asked questions
What is the difference between RCSA and KRI?
RCSA is a periodic self-assessment where a unit identifies risks and rates controls. A KRI is a metric tracked regularly that warns of rising risk. RCSA gives a structured view, while KRIs give continuous monitoring.
Why is loss data collection important?
It records actual events with amount, cause and business line. The bank uses it to find patterns, validate RCSA and KRIs, improve controls and support risk measurement.
Who is responsible for operational risk in a bank?
The first line, the business and operations units, owns it daily. The second line oversees and challenges, and internal audit provides independent assurance. The Board approves policy and risk appetite.
Is reputational risk part of operational risk?
By the standard definition, no. Operational risk includes legal risk but excludes strategic and reputational risk, though an operational failure can cause reputational damage.