15.3 Operational Risk

Key Takeaways

  • Operational risk is loss from inadequate or failed internal processes, people, and systems or from external events, including legal risk but typically excluding strategic and reputational risk as primary definitions
  • Basel evolved from BIA and Standardized Approach through AMA toward the Standardized Measurement Approach (SMA), which blends a business indicator with historical loss experience
  • Loss distribution approaches combine frequency and severity—often via Monte Carlo—to produce OpRisk capital; data scarcity and truncation make modeling fragile
  • RCSA, KRIs, scenario analysis, and training complement capital models; insurance can transfer risk but introduces moral hazard and adverse selection
  • Heavy tails and power-law severity behavior imply that rare operational events dominate capital—granular average losses understate true OpRisk
Last updated: August 2026

Operational Risk

Operational risk (OpRisk) is the risk of loss resulting from inadequate or failed internal processes, people, and systems or from external events. Basel’s definition includes legal risk and generally excludes strategic and reputational risk as primary categories (though reputation damage often follows OpRisk events). VRM–7 tests taxonomies, capital approaches, loss-distribution mechanics, non-model controls, and insurance pitfalls.

OpRisk Categories (Basel Event Types)

Supervisors and banks map losses into seven Level-1 event types:

Event typeIllustrative examples
Internal fraudUnauthorized trading, embezzlement, insider theft
External fraudCyber theft, payment fraud, forgery by outsiders
Employment practices & workplace safetyDiscrimination claims, employee injury
Clients, products & business practicesMis-selling, unsuitable advice, antitrust, disclosure failures
Damage to physical assetsFire, natural disaster damage to premises
Business disruption & system failuresOutages, utility failures, critical IT downtime
Execution, delivery & process managementFailed trade processing, data entry errors, vendor failures

Cross-border cyber events, model-implementation errors, and third-party cloud outages often sit in external fraud, systems, or process categories depending on root cause—exam stems reward precise classification.

BIA, Standardized Approach, and AMA

Under Basel II-era frameworks:

  1. Basic Indicator Approach (BIA) — capital = α × average positive annual gross income over a window (classically α = 15%). Simple, blunt, income-linked.
  2. Standardized Approach (SA) — split activities into business lines, each with a beta factor applied to gross income; sum across lines. Still income-based, slightly more granular.
  3. Advanced Measurement Approach (AMA) — banks use internal models (often LDA) subject to qualitative standards (use test, independent validation, scenario analysis, BEICF—business environment and internal control factors). AMA offered risk sensitivity but created comparability problems across banks.

Worked BIA sketch

If average relevant gross income = USD 2.0 billion and α = 15%, BIA capital = 0.15 × 2.0bn = USD 300 million. This number ignores whether the bank’s actual loss history is light or heavy—hence the push toward loss-sensitive measures.

SMA Rationale

The Standardized Measurement Approach (SMA) (Basel III finalization / Basel III endgame OpRisk reforms) replaces AMA for regulatory OpRisk capital in the standardized framework. Rationale:

  • Restore comparability and reduce model-driven capital variance across firms.
  • Link capital to a Business Indicator (BI) reflecting size/volume of business, adjusted by a Loss Component based on historical operational losses (with thresholds and averaging rules).
  • Reduce reliance on idiosyncratic internal models while still rewarding (to a degree) better loss experience versus pure income proxies.

SMA is not “zero modeling”—banks still need robust loss data collection for the loss component and for internal risk management beyond the regulatory number.

Frequency × Severity and Monte Carlo LDA

A loss distribution approach (LDA) models:

  • Frequency: how many OpRisk events occur in a period (often Poisson or negative binomial).
  • Severity: loss size given an event (lognormal, Pareto, or mixed distributions).

Annual loss = sum of severities over the random number of events. Because the convolution rarely has a closed form, banks use Monte Carlo:

  1. Draw N ~ frequency distribution.
  2. Draw N severities from the severity distribution.
  3. Sum to get one annual loss path.
  4. Repeat many times; read VaR/ES of the simulated annual loss for capital.

Worked LDA toy calculation

Suppose frequency ~ Poisson(λ = 4) per year and severity is fixed at USD 2 million for a stylized drill (unrealistic but exam-clear). Then expected annual loss = 4 × 2m = USD 8 million. With random Poisson frequency, variance of count is 4, so SD of annual loss = 2m × 2 = USD 4 million. In realistic models severity is highly skewed; a 99.9% OpRisk VaR can be tens of times EL because of rare large events.

If instead severity is lognormal with mean USD 2m and heavy right tail, Monte Carlo paths occasionally produce single events of USD 50–100m+, dominating the capital quantile. That is the economic message of OpRisk modeling: tails, not averages, set capital.

Data Issues

OpRisk data are ugly:

  • Sparse large losses — the events that matter for capital are rare.
  • Truncation and collection thresholds — small losses may be unreported; databases start above a threshold, biasing severity fits.
  • Reporting lag and classification error — root-cause coding drifts over time.
  • Heterogeneity — mixing retail process errors with mega legal settlements distorts a single severity fit.
  • External data and scaled industry data — needed for rare events but hard to scale to the firm’s size and controls.

Good practice: separate body and tail modeling, use scenario analysis for extreme cells, and document scaling assumptions.

Scenario Analysis

Scenario analysis elicits expert estimates of plausible severe losses (frequency and severity) for risk cells with thin data—e.g., “major cyber ransom shutting payments for a week,” “class-action mis-selling,” “building destruction at primary site.” Scenarios feed AMA-style models and remain essential under SMA for internal stress and contingency planning. Weaknesses: optimism bias, anchoring, and inconsistent facilitation. Strong programs use structured workshops, historical anchors, and independent challenge.

RCSA, KRIs, and Education

Capital is not the whole control framework:

  • Risk and Control Self-Assessment (RCSA) — business units identify risks, rate inherent/residual risk, and assess control effectiveness.
  • Key Risk Indicators (KRIs) — metrics such as system uptime, failed trade rates, overdue reconciliations, staff turnover in control functions, phishing click rates.
  • Training / education — reduces people-risk frequency (fraud awareness, conduct, cyber hygiene).

These tools improve the business environment and internal control factors that should, over time, show up in better loss experience.

Capital Allocation

Firm-wide OpRisk capital must be allocated to business units for accountability and pricing. Methods include proportion of BI or income, stand-alone LDA VaR with diversification haircuts, and Euler-style allocation on a firm model. Political sensitivity is high because OpRisk events are lumpy and often perceived as “someone else’s” failure. Transparent drivers (volume, complexity, control scores, loss history) reduce gaming.

Power Laws and Heavy Tails

Empirical OpRisk severities often exhibit power-law (Pareto-like) tails: P(Severity > x) ≈ C / x^α for large x. When the tail index α is low, mean severity may be finite while high quantiles explode, and sample means are unstable. Implication: ignoring the tail or fitting only a thin-tailed lognormal without a Pareto mixture understates capital. Exam cue: a few extreme legal or rogue-trading losses can dominate decades of small process losses.

Insurance: Moral Hazard and Adverse Selection

Banks buy insurance (BBB, cyber, property) to transfer OpRisk. Two classic incentive problems appear:

  1. Moral hazard — after buying cover, the insured may underinvest in controls or take more risk because losses are shifted to the insurer (subject to deductibles, exclusions, and claims friction).
  2. Adverse selection — firms with worse unobservable risk profiles may demand more cover; insurers respond with underwriting, exclusions, and pricing that can leave residual gaps precisely where risk is highest.

Insurance recoveries also have basis risk (policy wording versus actual loss), timeliness risk (slow pay), and counterparty risk (insurer credit). Regulators therefore limit how much insurance benefit can reduce OpRisk capital and require haircuts and documentation.

OpRisk on the FRM is equal parts taxonomy, capital evolution (BIA/SA/AMA → SMA), LDA mechanics, and governance—controls and incentives matter as much as the Monte Carlo engine.

Loading diagram...
Operational Risk LDA Monte Carlo Loop
Test Your Knowledge

Under a Basic Indicator Approach with average relevant gross income of USD 2.0 billion and α = 15%, OpRisk capital is:

A
B
C
D
Test Your Knowledge

A primary rationale for moving from AMA toward the Standardized Measurement Approach (SMA) for regulatory OpRisk capital is to:

A
B
C
D
Test Your Knowledge

In a frequency–severity LDA, why is Monte Carlo commonly used to estimate OpRisk capital?

A
B
C
D
Test Your Knowledge

After purchasing broad operational-risk insurance, a business unit cuts spending on reconciliations and access controls. This incentive problem is best labeled:

A
B
C
D