What Is Operational Risk?
Operational risk is the risk of loss from inadequate or failed internal processes, people and systems, or from external events. It is defined by exclusion — the losses that are neither market nor credit losses — which makes it the broadest and least measurable category.
Operational risk is what is left after market risk and credit risk have been named. That is genuinely how it is defined, and the residual turns out to contain some of the largest losses in financial history.
How it works
Four sources are conventionally named: internal processes, people, systems, and external events. A failure in any of them can produce a loss.
The definition is residual. If a loss was not caused by prices moving or a borrower failing, it lands in this category by default.
So it covers an enormous range. Fraud, a settlement error, a system outage, a mis-sold product, a natural disaster, a cyber attack and a data entry mistake are all the same category.
Why it is never compensated
Market risk pays a premium because the upside exists. A volatile asset can rise as well as fall, and the compensation is for accepting both.
Operational risk has no corresponding upside. No system has ever failed profitably, and no control weakness has ever produced a windfall.
Which makes the economics straightforward. Spending on controls is worthwhile whenever the cost is less than the expected loss avoided, with no premium foregone in the process.
A worked example
A trading firm has a position limit and a system enforcing it. The system fails to flag breaches for several weeks.
No loss occurs while the market is calm. The control was broken throughout and nothing revealed it, which is the normal state of a latent operational failure.
Then a position accumulates beyond the limit and the market moves against it. The loss will be recorded as a market loss, and its cause was operational.
That misattribution is routine. Most large operational losses appear in the accounts as something else, which is one reason the category is so badly measured.
Why the biggest losses are behavioural
Rogue trading incidents share a structure. Somebody with knowledge of the controls conceals positions, usually after an initial loss they expected to recover, and the concealment continues because the reported position is profitable.
The technical failure is rarely the point. Systems worked as designed; what failed was a person who understood them well enough to route around them, and a supervision culture that did not question good results.
Which is why control design focuses on separation of duties. Nobody should be able to both take a position and confirm it, because the combination is what enables concealment.
And why unusual profitability is itself a control signal. A desk consistently outperforming what its stated strategy should produce is a question, not a celebration — a lesson learned repeatedly and expensively.
The original data
On this site’s shared series 95% of bars sit below a prior peak, the maximum decline is 3.76%, and the longest below-peak stretch runs 73 bars. The largest bar is 2.338 against a median of 0.493.
Operational losses distribute completely differently. Many tiny incidents and a very small number of enormous ones, with almost no middle — which means an average is close to meaningless and the loss distribution is dominated by events nobody has a sample of.
And ordinary costs are the measurable comparison: a round trip costs 0.0098 here, about 2% of the median bar. Settlement errors and failed trades produce costs of exactly that kind, repeatedly, and they accumulate quietly in a way no single incident report captures.
How firms are required to handle it
Capital must be held against it. Banking regulation requires an operational risk capital charge, which forces the category to be quantified even though quantification is genuinely difficult.
Loss event databases are maintained. Firms record incidents and share anonymised data through consortia, because no single institution experiences enough large events to estimate anything.
Scenario analysis fills the gap. Where data is absent, experts estimate the plausible size of specific failures, which is a structured judgement rather than a measurement and is described as such in the methodologies.
And that honesty is appropriate. Operational risk capital is an informed estimate of an unmeasurable quantity, and treating the resulting number as precise would be a mistake that the regulation itself does not make.
The categories regulators actually use
Internal fraud and external fraud are separated, because the controls that address them differ entirely.
Employment practices, clients and products, and business disruption cover conduct failures, mis-selling and outages respectively.
Damage to physical assets and execution and delivery failures complete the standard set, the last being the largest by incident count and the smallest by value.
The taxonomy exists so that pooled loss data means something. Without a shared definition, firms cannot compare incidents or build the industry datasets that individual institutions lack the experience to produce alone.
When it fails
The characteristic failure is a control that everybody assumes is working. A reconciliation runs nightly, a report is produced, and nobody checks whether the report would actually show a problem. The control has been broken for months, no incident has tested it, and its apparent history of finding nothing is read as evidence that nothing is wrong. Controls fail silently by nature — an absence of alerts is equally consistent with everything being fine and with the alerting being broken, and only deliberate testing distinguishes them.
A second failure is misattributing the loss. Operational causes are recorded as market losses, so the category is understated.
A third is treating a clean record as evidence of strength. Most of the distribution is rare events that have not happened yet.
A fourth is concentrating duties in one person, which is the structure behind nearly every large fraud.
And a fifth is cutting controls during good periods, when their cost is visible and their value is not.
Related
Business risk covers the wider category of things that damage a company. Settlement risk covers one specific operational failure. And counterparty risk covers the exposure operational failures often reveal.
Every other risk in finance has a return attached. Nobody is paid to bear operational risk — there is no premium for having weak controls — which makes it the one category where spending money to reduce it is unambiguously correct.
— Michael Whitman
This page is educational, not financial advice. Test every idea on your own charts before risking money.