Operational risk does not announce itself with a single dramatic failure or a clear warning sign. It emerges from the accumulated interactions between people, processes, systems, and external forces that shape how an organization functions day to day. The previous lessons in this course established what operational risk means and where it originates. This lesson takes that foundation further by examining how organizations can systematically identify where operational risk exposures actually exist across their structures, activities, and relationships. Mapping these exposures is not an abstract exercise reserved for large corporations with dedicated risk departments. It is a practical discipline that any organization can adopt, whether a five-person professional services firm in Halifax, a mid-sized construction company in Calgary, or a community non-profit in Winnipeg. The process of mapping operational risk transforms vague concerns about what could go wrong into a structured understanding of where vulnerabilities concentrate and how they connect to one another.
The conceptual foundation for mapping operational risk rests on recognizing that every organization is a network of interdependent functions, each capable of generating or amplifying risk. Canadian standards and frameworks provide guidance on how to approach this mapping process systematically. The International Organization for Standardization's ISO 31000 Risk Management Guidelines, which Canadian organizations across sectors have widely adopted, establishes that risk identification should be comprehensive and should consider tangible and intangible sources of risk, causes and events, threats and opportunities, vulnerabilities, capabilities, and changes in the internal and external context. As of the date of authorship, ISO 31000 remains the predominant international framework referenced in Canadian risk management practice, and its principles apply regardless of organizational size or sector. The framework emphasizes that effective risk identification requires understanding how an organization's activities, functions, and relationships create conditions where adverse events become possible. This understanding comes from deliberate mapping rather than intuition alone.