Member Blog, Member News

Operational risk management: How to reduce risk and strengthen business performance


By Carrie Connell

When businesses manage risks, they often focus on specific vulnerabilities, such ascybersecurity. But since your business faces multiple types of threats, your operations need to be more resilient overall.

Developing an operational risk management strategy can help achieve that resilience. Keep reading to learn the keys to managing operational risk to protect your business.

Defining operational risk management

Operational risk management is the practice of making your business operations more resilient against disruption. This typically involves examining how your business operates, identifying threats and implementing controls to mitigate them and help your business keep operating if something does go wrong.

No matter the industry or size, all organizations are exposed to operational risk, which can disrupt normal business operations. Examples of these risks include:

• Cyberattacks

• Data inaccuracies

• Key leaders leaving without a succession plan in place

There isn’t a way to prevent all operational risks. But a well-thought-out operational risk management strategy can prioritize which risks to prepare for and defend against. This will better position your business to handle an incident with minimal financial, operational or reputational consequences.

Operational risk management: Why it matters

Operational risk management matters because it can help prevent operational disruptions and other risk-related challenges that could harm your business. Potential damage includes increased costs, lost revenue, missed opportunities, slow growth, poor decisions, reputational damage, regulatory action and more.

Operational risk is financial risk

Reduced or ineffective operations come with a financial cost. Failure to serve your market or gain accurate visibility into your business will hit your bottom line.

This hit may appear as a dramatic, one-time event, such as a ransomware attack, that can lock you out of your core systems and even force you to pay a ransom to regain access. That’s an expensive problem to solve.

But operational risk isn’t always easy to spot. Over time, it can cause reputational damage because you’re not able to effectively serve your customers. Bad decisions often cause you to slowly lose ground to your competitors.

Operational holes result in less visibility into your business

You don’t want your leaders making business decisions based on poor information. If AI is becoming more embedded into your daily operations without a data foundation and effective governance in place, you risk getting inaccurate AI outputs that result in bad information flowing up to your C-suite.

While this isn’t an immediate crisis, it could hamper your growth by making it harder to understand your customers or what your business needs to thrive.

Managing operational risk creates a path to growth and resilience

Taking action to manage your operational risk helps you fill gaps in your operations that can impede growth. Assessing your risks and establishing controls helps you better understand how your business functions and typically identifies process improvements or inefficiencies you can address.

Actively managing operational risk creates a more resilient business, meaning an incident is less likely to knock you off course because your team and systems are better prepared to handle it.

What creates operational risk?

Operational risk can be created by one or a combination of these factors:

Growth

Growth often requires a higher level of operational risk. Adding new customers, people or offerings can strain existing systems and controls. Mergers or acquisitions can magnify this risk, as rapid changes from merging with another organization can create new risk exposure faster than you can develop a management plan.

Fraud

Internal malfeasance, such as fraud, can result from loose controls that make it easier for bad actors to manipulate your systems. Fraud is one of the more common reasons organizations take action to manage operational risk; however, it often occurs only after fraud is discovered rather than as a preventive measure. 

Poor controls

Poor controls provide less visibility into what’s happening inside your business, fewer buffers against errors and fewer means to prevent bad behavior by either internal or external actors. This can lead to highly visible triggering events or low-level issues that build up over time.

AI

Businesses integrating AI more deeply into their operations face additional risks. Without proper governance and policies, AI can create data privacy concerns, cyberthreats, bias and regulatory challenges, reputational damage, low-quality information and hallucinations.

Technology

Digital transformation is essential for most businesses to compete in today’s marketplace, but this shift comes with risks. These can range from having to eat the cost of an ineffective ERP implementation to regulatory complications around switching core systems, to not implementing proper controls as you transition from on-prem to cloud-based technology. 

Cybersecurity

Cybersecurity threats are constant and carry costly consequences. Ransomware, malware, business email compromise, data theft and other cyber incidents can cause short-term operational disruptions and longer-term effects that damage productivity.

Vendor management

As your business works with more third-party vendors, such as SaaS companies, new sources of risk exposure emerge. Any data you share with a third-party vendor is at risk if your vendor’s systems are breached. If the vendor that supports one of your core systems gets attacked, you could lose the ability to use that system until the attack is resolved.

Personnel

A key executive or employee leaving the organization poses an additional source of operational risk. If your CFO suddenly departs or the only person who knows how your bookkeeping really works abruptly resigns, that can throw a wrench in your operations in ways that are difficult to quickly iron out.

Building an operational risk management framework

Most businesses outside of highly regulated industries don’t have an official operational risk management framework. When creating a framework, here are some steps to take:

1. Conduct a risk assessment

Analyze your systems, processes, controls and financials to determine which potential operational disruptions could have the biggest impact on your business. Consider hiring a third-party risk advisor to conduct the assessment for an independent perspective.

2. Identify your highest-priority risks

Based on your risk assessment, determine which risks require the most attention. You can’t tackle all risks at once, so focus on the ones that pose the greatest potential for harm.

3. Build a roadmap

Design a plan aligned with your risk priorities to establish new controls and improve processes to mitigate these risks. Consider whether you need to expand your staff to help do this. Measuringthe potential financial consequences of a specific risk can help you determine how much money is worth investing.

4. Install new controls

Start executing your roadmap by implementing new controls, better processes and additional risk mitigation measures. Be thoughtful in this process, because an overcontrolled environment can harm your business too.

5. Continuous monitoring

Risk management is never a set-it-and-forget-it effort. It is an ongoing process that involves monitoring and regular reassessments to evaluate how your risks have changed and how you need to adapt.

How internal controls impact operational risk management

Internal controls are a foundational element of operational risk management. Controls can be processes, procedures or policies that help reduce your risks by establishing protective guardrails around your business’s risk areas.

• For example, a control to reduce the risk of fraudulent purchase orders could require a designated member of your accounting team to approve every purchase made, as well as confirm that the purchased item was delivered. To further strengthen that control, consider requiring a second approval from a manager.

• Once implemented, that control makes it harder for any employee to treat fraudulent purchases as a normal operational expense, reducing financial loss risks.

How operational resilience is bolstered by strong controls

Strong controls make your business more resilient to threats by reducing the likelihood of incidents. They can also minimize an incident’s impact and create fail-safes that allow you to maintain operations or recover more quickly after a disruption.

Controls also help you better understand your business. When you identify gaps and establish new controls, you’ll get a clearer picture of how your business functions. When effective controls are in place, you’ll be more confident that your financial and operational data is accurate.

Your leadership team can breathe easier knowing you’re making decisions based on what’s really happening, not on incomplete or inaccurate data. 

Follow these operational risk management best practices

Develop a risk management strategy that fits your needs, circumstances and risk appetite using these best practices:

• Segregate duties: Require multiple layers of approval for sensitive activities like purchases, payroll or financial transfers.

• Prioritize automated controls: Opt for automated controls over manual ones, for less risk of human error and more efficiency.

• Access controls: Only give access to your systems, facilities or assets to those who really need it. If you do need to give broad access, establish procedures to ensure an independent team member reviews all actions taken by those individuals.

• Don’t get carried away with your control count: Don’t make your control environmentmore complicated than they need to be. Too many controls or overly complex controls will slow down your operations to the point that they create more risks.

• Expect change: The way you did something in the past isn’t necessarily the way you’ll do it in the future. Risk management is about making your business more adaptable to faceemerging challenges, not old ones.

How a strong organizational risk management model will benefit your business

Quantifying the value of avoiding risks is difficult. But implementing an effective organizational risk management strategy will deliver visible, concrete benefits for your business, including:

• Smarter decisions: More accurate information on the state of your business enablessmarter, more data-driven decisions.

• Faster processes: Assessing your processes to identify risks and control gaps will reveal valuable data about how your business works, so you can integrate silos and make process improvements.

• Cut down on organizational redundancies: A controls review can expose operationalinefficiencies or unnecessary redundancies.

• Easier audits: When your financial statement auditor has greater confidence in your controls, financial statement audits are simpler and less expensive.

• Grow with confidence: When operational risk is managed, it’s easier to align your operations with your growth needs and prevent roadblocks that can slow growth.

Wipfli specializes in helping businesses manage operational risk. Reach out to learn more about how they can help make your business stronger and more resilient.