World Library  
Flag as Inappropriate
Email this Article

Operational risk management

Article Id: WHEBN0004240965
Reproduction Date:

Title: Operational risk management  
Author: World Heritage Encyclopedia
Language: English
Subject: Financial risk, Risk of ruin, Risk management, Investment management, Institute of Operational Risk
Collection: Financial Risk, Risk, Risk Management
Publisher: World Heritage Encyclopedia

Operational risk management

The term Operational Risk Management (ORM) is defined as a continual cyclic process which includes risk assessment, risk decision making, and implementation of risk controls, which results in acceptance, mitigation, or avoidance of risk. ORM is the oversight of operational risk, including the risk of loss resulting from inadequate or failed internal processes and systems; human factors; or external events.


  • Four principles of ORM 1
  • Three levels of ORM 2
  • ORM process 3
    • In depth 3.1
    • Deliberate 3.2
    • Time critical 3.3
  • Benefits of ORM 4
  • Chief Operational Risk Officer 5
  • ORM software 6
  • See also 7
  • References 8
    • General 8.1
    • Cited 8.2
  • External links 9

Four principles of ORM

The U.S. Department of Defense summarizes the principles of ORM as follows:[1]

  • Accept risk when benefits outweigh the cost.
  • Accept no unnecessary risk.
  • Anticipate and manage risk by planning.
  • Make risk decisions at the right level.

Three levels of ORM

In Depth
In depth risk management is used before a project is implemented, when there is plenty of time to plan and prepare. Examples of in depth methods include training, drafting instructions and requirements, and acquiring personal protective equipment.
Deliberate risk management is used at routine periods through the implementation of a project or process. Examples include quality assurance, on-the-job training, safety briefs, performance reviews, and safety checks.
Time Critical
Time critical risk management is used during operational exercises or execution of tasks. It is defined as the effective use of all available resources by individuals, crews, and teams to safely and effectively accomplish the mission or task using risk management concepts when time and resources are limited. Examples of tools used includes execution check-lists and change management. This requires a high degree of situational awareness.[1]

ORM process

In depth


  • The Institute of Operational Risk The institute provides professional recognition and enables members to maintain competency in the discipline of operational risk.
  • Operational Risk Institute An association of operational risk training professionals that renders key training on Op Risk related subjects including Business Continuity.
  • Operational Risk Management Software 5 Essential features must incorporate in ORM Software to avoid risks.

External links

  1. ^ a b c "Naval Safety Center ORM". Retrieved November 4, 2008. 
  2. ^ "Committee Draft of ISO 31000 Risk management". International Organization for Standardization. 2007-06-15. 
  3. ^ "Operational Risk Management - Time-Critical Risk Management". U.S. Navy. Retrieved 12 July 2009. 





See also

Forrester Research has identified 115 Governance, Risk and Compliance vendors that cover operational risk management projects. Active Agenda is an open source project dedicated to operational risk management.

The impact of the Enron failure and the implementation of the Sarbanes–Oxley Act has caused several software development companies to create enterprise-wide software packages to manage risk. These software systems allow the financial audit to be executed at lower cost.

ORM software

Most complex financial institutions have a Chief Operational Risk Officer. The position is also required for Banks that fall into the Basel II Advanced Measurement Approach "mandatory" category.

The role of the Chief Operational Risk Officer (CORO) continues to evolve and gain importance. In addition to being responsible for setting up a robust Operational Risk Management function at companies, the role also plays an important part in increasing awareness of the benefits of sound operational risk management.

Chief Operational Risk Officer

  1. Reduction of operational loss.
  2. Lower compliance/auditing costs.
  3. Early detection of unlawful activities.
  4. Reduced exposure to future risks.

Benefits of ORM

  • Mission Completion is a point where the exercise can be evaluated and reviewed in full.
  • Execute and Gauge Risk involves managing change and risk while an exercise is in progress.
  • Future Performance Improvements refers to preparing a "lessons learned" for the next team that plans or executes a task.

This is accomplished in three different phases:

4. Do and debrief. (Take action and monitor for change.)
  • Communicate hazards and intentions.
  • Communicate to the right people.
  • Use the right communication style. Asking questions is a technique to opening the lines of communication. A direct and forceful style of communication gets a specific result from a specific situation.
3. Communicate risks and intentions.
  • Balancing resources and options available. This means evaluating and leveraging all the informational, labor, equipment, and material resources available.
  • Balancing Resources verses hazards. This means estimating how well prepared you are to safely accomplish a task and making a judgement call.
  • Balancing individual verses team effort. This means observing individual risk warning signs. It also means observing how well the team is communicating, knows the roles that each member is supposed to play, and the stress level and participation level of each team member.

This refers to balancing resources in three different ways:

2. Balance your resources.
  • Task loading refers to the negative effect of increased tasking on performance of the tasks.
  • Additive factors refers to having a situational awareness of the cumulative effect of variables (conditions, etc.).
  • Human factors refers to the limitations of the ability of the human body and mind to adapt to the work environment (e.g. stress, fatigue, impairment, lapses of attention, confusion, and willful violations of regulations).

The three conditions of the Assess step are task loading, additive conditions, and human factors.

1. Assess the situation.

The U.S. Navy summarizes the time critical risk management process in a four-step model:[3]

Time critical

  1. Identify hazards
  2. Assess hazards
  3. Make risk decisions
  4. Implement controls
  5. Supervise (and watch for changes)

The U.S. Department of Defense summarizes the deliberate level of ORM process in a five-step model:[1]

Link between deliberate and time critical ORM process


This process is cyclic as any changes to the situation (such as operating environment or needs of the unit) requires re-evaluation per step one.

  1. Establish context
  2. Risk assessment
    • Risk identification
    • Risk analysis
    • Risk evaluation
  3. Risk treatment
  4. Monitor and review


This article was sourced from Creative Commons Attribution-ShareAlike License; additional terms may apply. World Heritage Encyclopedia content is assembled from numerous content providers, Open Access Publishing, and in compliance with The Fair Access to Science and Technology Research Act (FASTR), Wikimedia Foundation, Inc., Public Library of Science, The Encyclopedia of Life, Open Book Publishers (OBP), PubMed, U.S. National Library of Medicine, National Center for Biotechnology Information, U.S. National Library of Medicine, National Institutes of Health (NIH), U.S. Department of Health & Human Services, and, which sources content from all federal, state, local, tribal, and territorial government publication portals (.gov, .mil, .edu). Funding for and content contributors is made possible from the U.S. Congress, E-Government Act of 2002.
Crowd sourced content that is contributed to World Heritage Encyclopedia is peer reviewed and edited by our editorial staff to ensure quality scholarly research articles.
By using this site, you agree to the Terms of Use and Privacy Policy. World Heritage Encyclopedia™ is a registered trademark of the World Public Library Association, a non-profit organization.

Copyright © World Library Foundation. All rights reserved. eBooks from World eBook Library are sponsored by the World Library Foundation,
a 501c(4) Member's Support Non-Profit Organization, and is NOT affiliated with any governmental agency or department.