Is independence a virtue?
It is a truth universally acknowledged that the operational risk function shall be independent. But why? What does an operational risk manager do that requires independence? Is this yet another example of approaches to other types of risk simply being read across to operational risk without really analysing their relevance?
By John Thirlwell
Operational risk is different in its nature from other types of risk. Risks involving credit, market or insurance are fundamentally about transactions. As a result they can be easily found and analysed from within a firm's management information; they can be fully audited; they can be capped or limited. In general, that doesn't apply to operational risk. But the other significant difference is that risks such as credit, market and insurance are there to be taken. That's the whole point of a firm involved in lending, trading or insurance. Operational risk is there whether you like it or not. Apart from insourcing, it's a risk you don't assume voluntarily. It's one that you manage as best you can. You may have an appetite for how much you'd like to accept but, for most classes of risk, you can do little to prevent that appetite being exceeded. The skill lies in what you do when it happens.
Which brings us back to the nature of operational risk management. What, indeed, is it for? And just as operational risk itself is different from other risks, is its management also different from the management of other risks?
At a conference earlier this year, a number of heads of operational risk talked about the evolution of their jobs. Initially, once top management has decided that it wants to have an operational risk function, their job is fairly clear – to put in place an op risk framework and the toolkits that go with it. All agreed, though, that the task was to move responsibility for implementing and using the methodology to the various business line functions, leaving the core team to act as consultants to the firm, to train people both in the fundamentals of operational risk as well as the specific of their own firm's systems and to provide reports to the board and other interested parties. More of a policy role than an active management role. Indeed, at that and other conferences, many operational risk heads have made the point, with a wry smile, that they don't actually manage anything, so they'd rather that word wasn't in their title. Or, as one senior executive commented to me the other day about the operational risk function, "They seem to have more of an admin role".
Of course, in some firms, the job goes beyond that. It may involve two key aspects of operational risk mitigation – business continuity planning and insurance buying. (Sadly, it often doesn't have any responsibility for insurance, but that's another story.) It should involve some element of quality improvement.
But overall, there is no clear idea of what operational risk should do and, more importantly, how it adds value. The head of credit doesn't just set up a credit framework, but sanctions loans. He or she, like the person in charge of market risk and trading or the insurer, puts earning assets or liabilities on the balance sheet, and see that they are good. What they do is visible and easily understood in its effect on the balance sheet and bottom line. And because of the nature of their job and the importance of separating risk decisions from the sales function, it is right that these functions are 'independent'.
It's a different story with operational risk. Outsourcing and new products are legitimate areas involving operational risk. The head of operational risk or equivalent advises on them and other aspects of risk/reward decisions. But he or she doesn't make the outsourcing or new product decision. That's made by the relevant business line.
Of course, there's value in improving quality, in understanding better where your risks lie and having a framework by which to assess those risks and, importantly, your controls over those risks. A good framework of monitoring and reporting will reduce the risk of surprises, both for management as well as for external stakeholders.
But operational risk is really another word for business risk. As such, it's essential that the business lines take ownership of it and that it's ingrained, dare I say embedded, within them. If, as Andrew Smith at HBOS suggests, it's merely treated as something of a regulatory construct, a rather arbitrary bringing together of various acknowledged risk categories, then it will be little recognised. In fact, by its very nature, it's not only integral to the business, it considers the whole business. You donexpect the chief executive officer to be 'independent' of the business – any more than you should expect the operational risk function to be. OpRisk
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@risk.net or view our subscription options here: http://subscriptions.risk.net/subscribe
You are currently unable to print this content. Please contact info@risk.net to find out more.
You are currently unable to copy this content. Please contact info@risk.net to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@risk.net
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@risk.net
More on Risk management
Review of 2025: It’s the end of the world, and it feels fine
Markets proved resilient as Trump redefined US policies – but questions are piling up about 2026 and beyond
BofA urges horizontal CCP fix after CME outage, others demur
Analysts say clearing meltdown bolsters case for futures-for-futures exchange with FMX
One in five banks targets a 30-day liquidity survival horizon
ALM Benchmarking research finds wide divergence in liquidity risk appetites, even among large lenders
Bank ALM tech still dominated by manual workflows
Batch processing and Excel files still pervade, with only one in four lenders planning tech upgrades
Many banks ignore spectre of SVB in liquidity stress tests
In ALM Benchmarking exercise, majority of banks have no internal tests focusing on stress horizons of less than 30 days
Quant Finance Master’s Guide 2026
Risk.net’s guide to the world’s leading quant master’s programmes, with the top 25 schools ranked
ALM Benchmarking: explore the data
View interactive charts from Risk.net’s 46-bank study, covering ALM governance, balance-sheet strategy, stress-testing, technology and regulation
Staff, survival days, models – where banks split on ALM
Liquidity and rate risks are as old as banking; but the 46 banks in our benchmarking study have different ways to manage them