← University
Operational Risk: Definition, Sources, and Exposure
0 of 4

A mid-sized construction company headquartered in Calgary has operated for 14 years, growing from a residential renovation contractor into a commercial and industrial builder with approximately 85 employees spread across 3 active project sites. The company's founder serves as president and maintains direct involvement in project bidding and client relationships, while a general manager oversees day-to-day operations including site supervision, equipment management, and subcontractor coordination. Administrative functions run through a head office of 8 staff handling payroll, accounts payable and receivable, procurement, and safety compliance documentation.

The company's growth over the past 5 years has outpaced the formalization of its internal processes. Project managers at each site maintain their own methods for tracking labour hours, materials inventory, and safety inspections. The accounting system was implemented 9 years ago and has not been upgraded, requiring manual workarounds to generate reports for bonding companies and project owners. Employee onboarding varies by site, with some workers receiving comprehensive safety orientation while others are assigned to crews with minimal documentation of their qualifications or certifications.

External relationships add further complexity to the company's operations. The firm relies on a network of approximately 25 regular subcontractors for specialized trades including electrical, mechanical, and concrete work. Equipment financing arrangements with 2 different lenders carry distinct reporting obligations and covenant requirements. The company holds a surety bond program with aggregate capacity of $12 million, requiring quarterly financial reporting and ongoing demonstration of management competence to the surety provider. Insurance coverage spans commercial general liability, equipment floater, automobile, and umbrella policies, each with different renewal dates, exclusions, and reporting obligations.

Recent events have prompted the president and general manager to examine the company's risk profile more carefully. A subcontractor dispute on 1 project escalated into a lien claim that delayed payment from the project owner for 47 days. A payroll error resulted in incorrect deductions for 12 employees over a 3-month period, requiring correction and generating complaints to the head office. A ransomware attempt was blocked by the company's IT provider but exposed the absence of any documented data backup and recovery procedures. None of these incidents caused catastrophic harm, but together they prompted questions about what vulnerabilities exist across the organization, how different types of risk relate to one another, and whether current management practices adequately address the exposures the company actually faces.

Mapping Operational Risk: How to Identify Exposures Across the Organization

Operational risk does not announce itself with a single dramatic failure or a clear warning sign. It emerges from the accumulated interactions between people, processes, systems, and external forces that shape how an organization functions day to day. The previous lessons in this course established what operational risk means and where it originates. This lesson takes that foundation further by examining how organizations can systematically identify where operational risk exposures actually exist across their structures, activities, and relationships. Mapping these exposures is not an abstract exercise reserved for large corporations with dedicated risk departments. It is a practical discipline that any organization can adopt, whether a five-person professional services firm in Halifax, a mid-sized construction company in Calgary, or a community non-profit in Winnipeg. The process of mapping operational risk transforms vague concerns about what could go wrong into a structured understanding of where vulnerabilities concentrate and how they connect to one another.

The conceptual foundation for mapping operational risk rests on recognizing that every organization is a network of interdependent functions, each capable of generating or amplifying risk. Canadian standards and frameworks provide guidance on how to approach this mapping process systematically. The International Organization for Standardization's ISO 31000 Risk Management Guidelines, which Canadian organizations across sectors have widely adopted, establishes that risk identification should be comprehensive and should consider tangible and intangible sources of risk, causes and events, threats and opportunities, vulnerabilities, capabilities, and changes in the internal and external context. As of the date of authorship, ISO 31000 remains the predominant international framework referenced in Canadian risk management practice, and its principles apply regardless of organizational size or sector. The framework emphasizes that effective risk identification requires understanding how an organization's activities, functions, and relationships create conditions where adverse events become possible. This understanding comes from deliberate mapping rather than intuition alone.

That’s the free preview

You’ve reached the end of what’s open to read. The rest of this lesson is part of a $79 course — purchasing unlocks it, or sign in if you already have access.