← University
Operational Risk: Definition, Sources, and Exposure
0 of 4

A mid-sized construction company headquartered in Calgary has operated for 14 years, growing from a residential renovation contractor into a commercial and industrial builder with approximately 85 employees spread across 3 active project sites. The company's founder serves as president and maintains direct involvement in project bidding and client relationships, while a general manager oversees day-to-day operations including site supervision, equipment management, and subcontractor coordination. Administrative functions run through a head office of 8 staff handling payroll, accounts payable and receivable, procurement, and safety compliance documentation.

The company's growth over the past 5 years has outpaced the formalization of its internal processes. Project managers at each site maintain their own methods for tracking labour hours, materials inventory, and safety inspections. The accounting system was implemented 9 years ago and has not been upgraded, requiring manual workarounds to generate reports for bonding companies and project owners. Employee onboarding varies by site, with some workers receiving comprehensive safety orientation while others are assigned to crews with minimal documentation of their qualifications or certifications.

External relationships add further complexity to the company's operations. The firm relies on a network of approximately 25 regular subcontractors for specialized trades including electrical, mechanical, and concrete work. Equipment financing arrangements with 2 different lenders carry distinct reporting obligations and covenant requirements. The company holds a surety bond program with aggregate capacity of $12 million, requiring quarterly financial reporting and ongoing demonstration of management competence to the surety provider. Insurance coverage spans commercial general liability, equipment floater, automobile, and umbrella policies, each with different renewal dates, exclusions, and reporting obligations.

Recent events have prompted the president and general manager to examine the company's risk profile more carefully. A subcontractor dispute on 1 project escalated into a lien claim that delayed payment from the project owner for 47 days. A payroll error resulted in incorrect deductions for 12 employees over a 3-month period, requiring correction and generating complaints to the head office. A ransomware attempt was blocked by the company's IT provider but exposed the absence of any documented data backup and recovery procedures. None of these incidents caused catastrophic harm, but together they prompted questions about what vulnerabilities exist across the organization, how different types of risk relate to one another, and whether current management practices adequately address the exposures the company actually faces.

Defining Operational Risk: People, Processes, Systems, and External Events

Operational risk sits at the heart of every organization, whether that organization is a multinational corporation with thousands of employees or a sole proprietor running a consulting practice from a home office in Halifax. Unlike market risk or credit risk, which tend to occupy the attention of financial institutions and investment professionals, operational risk affects every business, every non-profit, and every professional practice in Canada. It is the risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events. This definition, drawn from the Basel Committee on Banking Supervision's framework and adopted in various forms by regulators and standard-setting bodies around the world, captures something essential about how organizations actually function and fail. The Canadian Securities Administrators, the Office of the Superintendent of Financial Institutions, and provincial regulators across the country all incorporate operational risk considerations into their oversight frameworks, though the specific requirements vary by sector and jurisdiction. As of the date of authorship, the International Organization for Standardization's ISO 31000:2018 standard on risk management provides a widely referenced framework that Canadian organizations of all sizes can adapt to their circumstances, offering principles and guidelines that translate well across industries from resource extraction in northern Alberta to professional services firms in downtown Toronto.

That’s the free preview

You’ve reached the end of what’s open to read. The rest of this lesson is part of a $79 course — purchasing unlocks it, or sign in if you already have access.