Operational Risk | Benchmarking
Operational risk
Banks insure against cyber risk, but rarely claim
Risk Benchmarking study finds big banks aggressively negotiating on cost of cover, and seeking offsets to Pillar 2 capital
Four in five banks use AI to manage op risks
Risk Benchmarking: Cyber risk use cases growing; governance and ROI doubts give some pause
Build, or buy: banks still don’t love their GRC vendors
Risk Benchmarking study finds a record number of firms reviewing tech provision for top op risks, amid touted wave of AI-led self-builds
AI use fastest-growing area of op risk regulatory scrutiny
Risk Benchmarking study finds EU AI Act the dominant driver of nascent bank risk frameworks, even well beyond Europe’s borders
Explore the data
Bot's job?
81% of banks are using AI tools or techniques to support at least one operational risk area, according to Risk.net’s 2026 Op Risk Benchmarking. Adoption is strongest in cyber-related areas: information security shows 28% of banks using AI in production and 43% in pilots or limited use cases. Larger banks are furthest ahead: all 14 G‑Sibs answering said they use AI for infosec, and all but one reported use for IT disruption. One North American G‑Sib said it had “over 1,000” AI applications reviewed and deployed.
On cyber risk, tech debt is big banks’ top challenge
Risk Benchmarking: Fragmented stacks make identifying vulnerabilities harder; manual workarounds increase human errors
Half of banks use scenarios to set third-party Pillar 2 capital
Risk Benchmarking study finds resilience risk less widely covered than cyber and IT disruption, but more formalised where scenarios exist
Second line seeks to stamp its authority on AI risk
Risk Benchmarking study finds fragmented accountability for AI risk among banks, and most are short of controls to contain it
Op Risk Benchmarking 2026: explore the data
View interactive charts from Risk.net’s 61-bank study, covering risk appetite breaches, controls, scenario analysis, GRC tech and regulation
Appetite breaches climb for top op risks
Risk Benchmarking: Low tolerance and heightened threat environment combine to test banks’ limits for cyber, resilience, third-party risk
Op Risk Benchmarking: Banks seek a home for AI risk
Risk.net’s 2026 study sees record participation and collective unease, as banks race to incorporate AI into op risk frameworks
Banks curb frequency of GRC vendor reviews
Data shows drop in plans to pitch or switch vendors, amid tighter third-party rules – but TPRM bucks the trend
In more than 90% of banks, second line tackles cyber risk
But some regulators would still like to see more 2 LoD risk staffing for infosec and IT disruption
Almost all banks mandate cyber security training
And unlike other risks, information security coaching moves the internal confidence dial
Regional banks favour scenario analysis over op risk modelling
Domestic and smaller regional players favour scenarios to gauge tail exposure; G-Sibs stick to modelling, for now
Regulators zero in on third-party risk, resilience
In latest survey, 35% of banks say watchdogs have “significantly increased” focus on third-party risk, with reports of arduous inspections and growing resource strain
More than one-quarter of banks overhaul third-party KRIs
Op Risk Benchmarking data shows more flux – and less confidence – in indicators tracking vendors versus other risks
Ninety-one per cent of banks have specialist teams for resilience risk
Latest survey shows regulatory pressure is driving broader framing of resilience, beyond IT and cyber
More than half of banks manage change as an operational risk
Others are moving to incorporate it into risk taxonomies, although some now treat it as a cause, citing supervisory guidance
Risk appetite breaches test development banks
MDBs also more likely to change services or strategy to reduce risk exposure, survey shows
Algos shrugged: AI uptake still lagging in bank op risk
Risk managers acknowledge transformative potential of artificial intelligence – most, from a safe distance
FMIs create culture club for op risk
Exchanges and clearing houses seek to build risk resilience among front-line business, amid concerns of overreliance on second line of defence
Taking the sting out: exchanges and CCPs bolster scenario toolkits
As cyber threats ramp up, the world’s largest exchanges re-assume the worst
Technology is a double-edged sword for FMIs
Exchanges and clearing houses rely on third-party vendors for vital systems, but outsourcing can also lead to duplication and waste
Op Risk Benchmarking 2025: the FMIs
Exchanges and CCPs respond to regulatory scrutiny and evolving threats with tighter vendor management and scenario refreshes
Vendor oversight splinters across FMIs
Op Risk Benchmarking: firms grapple with “chaos” of third-party rule changes, amid growing recognition of cyber and resilience threats
On resilience risk, banks prepare to let the bad times roll
Lenders bolster first-line teams and upskill boards as compliance with new rules bites
For banks, change risk is inevitable; managing it, optional
Regional bank survey shows steady growth of dedicated change risk functions and adoption of leading indicators
As supplier risk grows, banks check their third-party guest lists
Dora forces rethink of KRI and appetite frameworks amid reappraisal of what constitutes a key counterparty
Regionals built first-line defences pre-CrowdStrike
In-business risk teams vary in size and reporting lines, but outage fears are a constant