The COSO Framework for Internal Control
February 12, 2025
Incentive is an act or promise for greater action. It is also called as a stimulus to greater action. Incentives are something which are given in addition to wagers. It means additional remuneration or benefit to an employee in recognition of achievement or better work. Incentives provide a spur or zeal in the employees for […]
Why Senior Leaders are Expected to be above Reproach and Role Models for Others Senior Leaders are supposed to be role models for the rest of the organization to follow and emulate. Moreover, they are the ones who articulate the organizational vision and actualize the mission for the Middle and Lower level employees and hence, […]
Negotiations can be called as a way of resolving disputes. It is considered as being synonymous to settlement, agreement, collaboration and bargaining. It takes place almost in all spheres of life – be it is business, personal circumstances (married life, parenting, etc.), legal procedures, government matters, etc. Negotiation can be defined as a channel of […]
A good quality resume is a prime tool to apply for a job and what to do when you have no work experience to show? You don’t have to panic as everyone has to start from somewhere. A fresh college graduate out of college and looking for a suitable job will of course not have […]
Success in the workplace depends on your ability to build a team, as well as to interact with others on that team. Together, people are able to accomplish what one person alone can not. This is known as synergy. Following are the characteristics of a Good/Effective team: A clear, elevating goal: This is a goal […]
In the previous few articles, we have studied about the concepts of risk management in general. However, merely understanding general risk management is not enough for modern-day risk professionals. The challenging environment of today requires people to specialize in the different types of risk management. Out of all the different types of risks that are commonly studied, the organization has the maximum control over operational risk. Hence, in the next few articles, we will try to understand what operational risk really is and how it impacts the decision-making within the organization.
For many years, there was no agreed-upon definition of operational risk. This meant that all organizational risks were classified into market risks and credit risks. The risks which could not be classified as either was often included in the category of operational risks. Obviously, this categorization was wrong and hence has faced severe criticism over the years. Over time, a new more acceptable definition for operational risks was arrived at. The same has been mentioned below.
Operational risk is defined as the potential loss which can occur because an organization has failed or inadequate processes, inadequate or failed systems, and/or incompetent people in the organization. It is important to note that the financial loss from the risk consists of any operational loss that may arise as well as any costs involving litigation. Reputational risks and brand management have been categorically excluded from the definition of operational risk since they are considered separately within the risk paradigm.
The above definition makes it clear that there are four major causes of operational risk. They are as follows:
Many organizations have faced loss because of operational risks. Most of the time the losses are small. Hence, they are not reported in the media. As a result, awareness about these losses is not increased. However, in some cases, the losses are quite significant and hence end up being reported in the media. Some examples of these high profile adverse events related to operational risk are as follows:
There have been several financial frauds such as Enron, Worldcom, Bernie Maddoff scam, or the scam involving Raj Rajaratnam. These are all premier examples of how a group of incompetent or dishonest people is able to cause grievous loss to their organizations. Sometimes the loss is so severe that these organizations cease to exist as a result! The recent scam involving Facebook and Cambridge Analytica can also be included here because here too the actions of some contractors ended up harming the organization.
There are many examples wherein the systems of organizations have failed and as a result, the organization has suffered significant losses. For instance, many technology companies have been victims of cyber attacks in the recent past. Companies like Adobe, eBay, Equifax, and even LinkedIn have been found themselves at the center of many data leaks. This is also the case with many banks and financial institutions. Since data is vital to the performance of business activities in this organization, these data breaches have significantly impacted the business of these companies.
Lastly, there are many examples wherein processes set by organizations have failed. For instance, companies like Renault and Hyundai have been in the news. This is because some of their internal checks and balances failed. Their quality assurance team was not able to properly classify vehicles. As a result, faulty vehicles were sold. The end result was that these faulty vehicles had to be recalled and the organization had to suffer significant operational harm even if the reputational harm is not considered.
The bottom line is that there a clear and concise definition of operational risk which is in place. The drivers and causes of operational risk are also well known. It is this knowledge that enables the measurement and management of operational risks in the organization.
Your email address will not be published. Required fields are marked *