Top 10 Operational Risks in 2022

Top 10 Operational Risks in 2022

Hot off the press: Best Practice Operational Risk Forum, comprised of professionals from over 50 national and international organisations, met yesterday to examine industry top risk reports and consider the most prominent Operational risks financial services firms should have on their radar. Top 10 Risks are described below:

1.People?risk:?staff capacity and?capability. This refers to issues such as the Great Resignation, difficulties in obtaining talent, tax regime not adequate to support global home working and all the unknowns related to the longer-term impact of hybrid working arrangements.?

2.People?risk:?staff wellbeing?- burnout and depression, increased stress levels of both leaders and staff, escalating during the last two years.

3.Cyber crime:?complex threat landscape, highly coordinated, multi-step?attacks. The risk continues to top the chart in terms of impact and likelihood. ORX notes two out of the top 5 Operational risk losses last year were cyber-related (specifically, crypto-related).

4.Theft and Fraud:?external fraud (inc.?retail card fraud, money laundering); internal fraud (inc.?rogue trading); broad inherent risk in financial services which is expected to firmly remain in the top place.

5.Supply chain / third-party risk:?failures in the supply chain impacting service delivery; and concentration?risk, especially as it relates to cloud service providers. Became prominent as more services are moving to the cloud.

6.Legacy IT system / infrastructure:?system downtime/ failures of legacy technology / underinvestment in?technology leading to potential customer and market detriment.

7.Regulatory risk:?fines and penalties due to inability to timely identify and implement regulatory?requirements. Far from being new, and remains high on the agenda.

8.Climate action failure:?inability to adjust the product set and embed requirements beyond the regulatory minimum; as well as organisational and business model change triggered by climate change programs. Topical, however not yet seen by practitioners as high and urgent as people and cyber risks.

9.Data breaches:?acts of non-compliance with GDPR, given the amount of data continues to increase; this risk is also linked to and dependent on the legacy technologies. As noted in Forbes report, the frequency of data breaches are increasing and the types expanding.

10.Financial crises:?impacts on people, systems and processes; despite not being a classical Operational risk sub-type by definition, the impact of the disruption that started during the pandemic cannot be underestimated.

And a note on Emerging Operational Risks considered by the Best Practice Forum - majority are people related. Operational risk professionals have a crucial role to play in escalating People risk up the organisational agenda, to ensure it is recognised as a major risk in its own right, evaluated and mitigated, with firm and thoughtful actions.

No alt text provided for this image


Very helpful, Elena. Does this benchmark apply outside the financial services sector? Do you have any data you can share from other sectors?

回复
Janet Pruitt, CPA,CIA,CCUIA,CFIRS, and COSO IC Certified

Extensive Internal and external Audit, Operational and Enterprise Risk Management experience. Avid learner, passionate about risk mitigation and process improvement.

2 年

Very helpful - thanks for sharing.

回复
Paul Gibbons

Keynote speaker: AI and Future of Work; New Book Coming 2025: Leading AI: Ethics, Culture, Upskilling

2 年

Operational risk is going to take over from K-pop in its "meme-iness"

回复

要查看或添加评论,请登录

Elena Pykhova的更多文章

  • RCSAs: Industry study reveals a move towards drastic reduction in the number of entries

    RCSAs: Industry study reveals a move towards drastic reduction in the number of entries

    Best Practice Operational Risk Forum conducted a deep dive into the topic of Risk and Control Self-Assessments (RCSAs).…

    3 条评论
  • GenAI in Operational Risk Management: Use Cases

    GenAI in Operational Risk Management: Use Cases

    The Best Practice Operational Risk Forum members had a round table discussion to review the progress in adoption of…

    5 条评论
  • No more D in 3LOD

    No more D in 3LOD

    The three lines of defense (3LOD) model, which has its origins in military planning and sports management, is now…

    36 条评论
  • Top Operational Risk Priorities 2024

    Top Operational Risk Priorities 2024

    What is on your agenda this year? Best Practice Operational risk Forum members discussed and ranked top Operational…

    10 条评论
  • Top Operational Risks 2024

    Top Operational Risks 2024

    This year’s view of the risk landscape from Best Practice Operational Risk Forum; members ranked top Operational risks…

    12 条评论
  • 2023 Operational Risk Priorities

    2023 Operational Risk Priorities

    What’s on your agenda for 2023? Best Practice Operational Risk forum comprised of risk executives from 50 international…

    6 条评论
  • Top Operational Risks 2023

    Top Operational Risks 2023

    As always, new year brings a set of challenges, some new and others very familiar. This year’s view of the risk…

    30 条评论
  • 1st Line Risk Champions: Is there a magic number?

    1st Line Risk Champions: Is there a magic number?

    It is a common practice within the financial services firms to appoint 1st Line Operational Risk coordinators, or risk…

    9 条评论
  • Operational Risk Priorities 2022

    Operational Risk Priorities 2022

    What’s on your agenda for 2022? Best practice Operational Risk forum comprised of practitioners from over 50…

    5 条评论
  • Operational risk management: Importance of Celebrating Success

    Operational risk management: Importance of Celebrating Success

    Consciously pausing to acknowledge achievements and celebrate success of Operational risk management is the practice…

    2 条评论

社区洞察

其他会员也浏览了