← University
Operational Risk: Definition, Sources, and Exposure
0 of 4

A mid-sized construction company headquartered in Calgary has operated for 14 years, growing from a residential renovation contractor into a commercial and industrial builder with approximately 85 employees spread across 3 active project sites. The company's founder serves as president and maintains direct involvement in project bidding and client relationships, while a general manager oversees day-to-day operations including site supervision, equipment management, and subcontractor coordination. Administrative functions run through a head office of 8 staff handling payroll, accounts payable and receivable, procurement, and safety compliance documentation.

The company's growth over the past 5 years has outpaced the formalization of its internal processes. Project managers at each site maintain their own methods for tracking labour hours, materials inventory, and safety inspections. The accounting system was implemented 9 years ago and has not been upgraded, requiring manual workarounds to generate reports for bonding companies and project owners. Employee onboarding varies by site, with some workers receiving comprehensive safety orientation while others are assigned to crews with minimal documentation of their qualifications or certifications.

External relationships add further complexity to the company's operations. The firm relies on a network of approximately 25 regular subcontractors for specialized trades including electrical, mechanical, and concrete work. Equipment financing arrangements with 2 different lenders carry distinct reporting obligations and covenant requirements. The company holds a surety bond program with aggregate capacity of $12 million, requiring quarterly financial reporting and ongoing demonstration of management competence to the surety provider. Insurance coverage spans commercial general liability, equipment floater, automobile, and umbrella policies, each with different renewal dates, exclusions, and reporting obligations.

Recent events have prompted the president and general manager to examine the company's risk profile more carefully. A subcontractor dispute on 1 project escalated into a lien claim that delayed payment from the project owner for 47 days. A payroll error resulted in incorrect deductions for 12 employees over a 3-month period, requiring correction and generating complaints to the head office. A ransomware attempt was blocked by the company's IT provider but exposed the absence of any documented data backup and recovery procedures. None of these incidents caused catastrophic harm, but together they prompted questions about what vulnerabilities exist across the organization, how different types of risk relate to one another, and whether current management practices adequately address the exposures the company actually faces.

Defining Operational Risk: People, Processes, Systems, and External Events

Operational risk sits at the heart of every organization, whether that organization is a multinational corporation with thousands of employees or a sole proprietor running a consulting practice from a home office in Halifax. Unlike market risk or credit risk, which tend to occupy the attention of financial institutions and investment professionals, operational risk affects every business, every non-profit, and every professional practice in Canada. It is the risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events. This definition, drawn from the Basel Committee on Banking Supervision's framework and adopted in various forms by regulators and standard-setting bodies around the world, captures something essential about how organizations actually function and fail. The Canadian Securities Administrators, the Office of the Superintendent of Financial Institutions, and provincial regulators across the country all incorporate operational risk considerations into their oversight frameworks, though the specific requirements vary by sector and jurisdiction. As of the date of authorship, the International Organization for Standardization's ISO 31000:2018 standard on risk management provides a widely referenced framework that Canadian organizations of all sizes can adapt to their circumstances, offering principles and guidelines that translate well across industries from resource extraction in northern Alberta to professional services firms in downtown Toronto.

Understanding operational risk requires grasping its four constituent categories, which together form a comprehensive taxonomy of what can go wrong in organizational operations. People risk encompasses everything related to human action and inaction within an organization, including errors, omissions, misconduct, inadequate training, insufficient staffing, and the departure of key personnel who hold critical knowledge. Process risk involves the design, implementation, and execution of business processes, including documentation practices, approval hierarchies, quality control mechanisms, and the handoffs between different functions within an organization. Systems risk relates to information technology infrastructure, software applications, data management, cybersecurity, and the integration of various technological components that modern organizations depend upon. External events risk captures those occurrences originating outside the organization's direct control, including natural disasters, regulatory changes, supplier failures, criminal acts, and broader economic or social disruptions. These four categories are not hermetically sealed compartments but rather overlapping dimensions that interact in complex ways during actual operational failures.

The reason operational risk matters so fundamentally to Canadian SMB owners, non-profit operators, and professionals is that it touches every aspect of daily operations in ways that more exotic risk categories simply do not. A construction company in Saskatoon faces market risk when commodity prices fluctuate and credit risk when clients delay payment, but the operational risks inherent in its project management processes, its equipment maintenance schedules, its worker safety protocols, and its reliance on specific subcontractors represent a far more immediate and tangible set of concerns. Similarly, a registered charity in Ottawa that provides services to vulnerable populations must certainly attend to its investment portfolio and its donor relationships, but the operational risks embedded in its volunteer screening procedures, its case management systems, its data privacy practices, and its dependence on government funding cycles are what determine whether the organization can actually deliver on its mission. Operational risk is where strategy meets reality, where policies confront human behaviour, and where the gap between what an organization intends to do and what it actually does becomes consequential.

Canadian organizations encounter operational risk in patterns that reflect both universal principles and distinctly Canadian circumstances. The geographic scale of the country means that many businesses operate across multiple time zones, rely on extended supply chains, and must coordinate activities among personnel who may rarely meet in person. A professional services firm with offices in Vancouver, Calgary, and Montreal must ensure that its service delivery processes function consistently despite differences in local practice, language, and legal frameworks, since Quebec's civil law tradition creates obligations and liabilities that differ in important respects from those in common law provinces. The seasonal nature of many Canadian industries, from agriculture to tourism to construction, creates cyclical operational pressures that concentrate risk in predictable but intense periods. The country's resource-dependent economy means that many organizations, even those not directly involved in extraction or processing, find their operations affected by the boom-and-bust dynamics of commodity markets. These distinctly Canadian features of the operating environment do not change the fundamental nature of operational risk, but they do shape how that risk manifests and what approaches to managing it prove most effective.

One common misunderstanding about operational risk is that it primarily concerns rare, catastrophic events, the spectacular failures that make headlines and prompt regulatory investigations. While such events certainly fall within the scope of operational risk, the more pervasive reality is that operational risk typically materializes through an accumulation of small failures, near-misses, and chronic inefficiencies that erode organizational performance over time. A healthcare clinic in Edmonton that experiences a major data breach involving patient records will rightly see that incident as an operational risk event, but the same clinic faces operational risk every day in the form of scheduling errors, miscommunications among staff, documentation gaps, and equipment malfunctions that never quite rise to the level of crisis but collectively degrade the quality of patient care and the efficiency of operations. Understanding operational risk means recognizing both the acute and the chronic dimensions, the sudden failures and the slow deteriorations, the events that demand immediate response and the conditions that require sustained attention.

Another misunderstanding concerns the relationship between operational risk and compliance. Many organizations, particularly smaller ones without dedicated risk management functions, tend to conflate operational risk management with regulatory compliance, assuming that if they meet all applicable legal and regulatory requirements they have adequately addressed their operational risks. This assumption is dangerously incomplete. Compliance represents a minimum threshold established by external authorities based on their assessment of what protections the public interest requires, but the operational risks specific to any particular organization extend far beyond what regulators can anticipate or address. A financial services firm in Toronto that maintains full compliance with all requirements imposed by the Ontario Securities Commission and the Investment Industry Regulatory Organization of Canada has not thereby eliminated its operational risks, because the regulations cannot possibly address every dimension of how that firm's people, processes, and systems might fail. Compliance is necessary but not sufficient, a floor rather than a ceiling, and organizations that treat regulatory requirements as the totality of their risk management obligations will inevitably find themselves unprepared for the operational failures that regulators never contemplated.

The interplay among the four categories of operational risk becomes particularly evident when examining how actual failures unfold. Consider a mid-sized manufacturing company based in Winnipeg that produces specialized components for the agricultural equipment industry. This company employs approximately one hundred and twenty people across its production facility, administrative offices, and small sales team, and it has operated successfully for nearly two decades. In late autumn of a recent year, the company experienced what initially appeared to be a straightforward systems problem when its enterprise resource planning software began generating inconsistent inventory reports. The production manager noticed that the system showed adequate stock of a critical raw material even though the physical warehouse clearly contained less than the reported quantity. This discrepancy emerged during a period of high demand when the company was working to fulfill orders before the winter slowdown in the agricultural sector, and the production schedule had little slack built into it.

What followed over the subsequent weeks illustrated how operational risk cascades across categories and compounds through organizational responses. The systems problem, it turned out, had originated several months earlier when a software update had been installed without adequate testing. The update had introduced a subtle bug affecting how the system processed certain inventory adjustments, and because the error occurred only under specific circumstances, it had gone undetected through normal operations. This systems risk had been amplified by a process risk, namely the company's informal approach to software updates, which relied on the judgment of the operations manager rather than following a documented testing and approval protocol. The operations manager, a trusted employee of fifteen years, had always handled technology matters competently, but his expertise was in production management rather than information technology, and he lacked the specialized knowledge to recognize the potential consequences of implementing updates without rigorous testing.

When the inventory discrepancy was discovered, the company faced immediate decisions about how to respond. The production manager escalated the issue to the plant director, who convened an emergency meeting that included the operations manager, the purchasing supervisor, and the company's chief financial officer. Under time pressure and with incomplete information, the group concluded that the most likely explanation was theft or diversion of materials, and they initiated an internal investigation focused on warehouse personnel. This response introduced a significant people risk element, as the investigation created anxiety and resentment among warehouse workers who felt unfairly suspected. Two experienced warehouse employees resigned within a week of the investigation's commencement, taking with them institutional knowledge about inventory management practices and creating additional operational strain during an already difficult period.

Meanwhile, the actual cause of the discrepancy remained undiagnosed. The company's reliance on a single employee for technology decisions meant that when the operations manager insisted the software was functioning correctly because the update had come from a reputable vendor, his assessment went largely unchallenged. It was only when an external accountant, conducting routine year-end work, noticed patterns in the inventory data that suggested a systematic rather than random error that attention shifted from personnel to systems. By that point, the company had lost two valuable employees, damaged morale among its remaining workforce, delayed several customer orders, and consumed considerable management time on an investigation that had been pursuing the wrong theory. The financial cost, when eventually calculated, exceeded two hundred thousand dollars in direct expenses and lost productivity, not including the harder-to-quantify costs of damaged customer relationships and diminished employee trust.

This scenario reveals several important truths about operational risk that apply across industries and organization types. First, operational failures rarely have single, simple causes. The Winnipeg manufacturer's problems arose from a convergence of systems risk, process risk, and people risk, with each category contributing to and amplifying the others. The software bug was a systems failure, but it became consequential only because of inadequate change management processes and excessive reliance on a single individual's judgment. The misdiagnosis of the problem as theft was a people failure, but it was enabled by process weaknesses in how the company handled incident investigation and root cause analysis. Second, the scenario demonstrates how operational risk often remains latent for extended periods before becoming visible. The software bug had been present for months before manifesting as a noticeable discrepancy, and during that time it was quietly corrupting inventory data in ways that would complicate future analysis. Organizations cannot assume that the absence of obvious problems indicates the absence of operational risk.

Third, the scenario illustrates how responses to operational failures can create new operational risks if not carefully managed. The decision to focus the investigation on warehouse personnel was understandable given the available information, but it was implemented in a way that damaged employee relations and led to resignations that compounded the original problem. Organizations facing operational failures must recognize that their response strategies carry their own risks and require the same careful consideration as any other operational decision. Fourth, the scenario shows the importance of external perspectives in identifying and diagnosing operational problems. The company's internal team, despite their competence and dedication, had developed blind spots that prevented them from seeing what an outside accountant noticed relatively quickly. This does not mean that external consultants should be involved in every operational decision, but it does suggest that organizations benefit from mechanisms that bring fresh eyes to entrenched problems.

For Canadian SMB owners, non-profit operators, and professionals, the practical implications of understanding operational risk begin with assessment. Every organization should undertake a systematic review of its operations through the lens of people, processes, systems, and external events, asking where failures could occur, what the consequences would be, and what controls currently exist to prevent or mitigate those failures. This assessment need not be elaborate or expensive, but it should be thorough and honest. The questions to ask include who performs each critical function and what happens if that person becomes unavailable, whether through illness, resignation, or simply being on vacation during a crisis. They include how each major process is documented, who is responsible for each step, and where the handoffs between functions create opportunities for miscommunication or error. They include what technology systems the organization depends upon, how those systems are maintained and updated, and what backup or recovery capabilities exist if a system fails. They include what external events could disrupt operations, from natural disasters to supplier failures to regulatory changes, and what preparations the organization has made for those contingencies.

Documentation represents a crucial element of operational risk management that smaller organizations often neglect. When processes exist only in the heads of the people who perform them, the organization faces acute vulnerability to personnel changes and limited ability to identify and correct inefficiencies. Documenting key processes serves multiple purposes, including providing guidance for staff, supporting training for new employees, enabling consistent performance measurement, and creating a foundation for process improvement. Documentation need not be bureaucratic or burdensome, and in fact overly elaborate documentation that no one reads or follows creates its own operational risks. The goal is to capture the essential elements of how work gets done in a form that is accessible, accurate, and actually used. For a sole proprietor, this might mean maintaining a simple reference guide to critical procedures and vendor contacts. For a larger organization, it might involve formal process maps and procedure manuals with defined update cycles.

The question of internal controls deserves particular attention in the context of operational risk. Controls are the mechanisms, whether preventive or detective, automated or manual, that reduce the likelihood or impact of operational failures. Segregation of duties, requiring different people to authorize and execute transactions, is a classic control against fraud and error. Reconciliation procedures, comparing records from different sources to identify discrepancies, provide detection capability that catches problems before they compound. Access controls, limiting who can perform certain system functions or approve certain decisions, reduce the opportunity for unauthorized or inappropriate actions. Supervisory review, having experienced personnel check the work of others, provides both quality assurance and training opportunity. Every organization, regardless of size, should be able to identify the controls that protect its critical operations and should periodically verify that those controls are functioning as intended.

External relationships constitute both a source of operational risk and a potential mitigation resource. Suppliers, service providers, technology vendors, professional advisors, and industry associations all play roles in how organizations manage operational risk. Due diligence in selecting these external partners, clear contractual provisions addressing performance standards and risk allocation, and ongoing monitoring of relationship performance are all elements of sound operational risk management. At the same time, external relationships can provide access to expertise, redundancy, and early warning that strengthen an organization's risk position. A construction firm in Calgary that maintains relationships with multiple subcontractors in critical trades has more operational resilience than one that depends entirely on a single subcontractor, even if the single subcontractor relationship is otherwise excellent.

The cultivation of organizational culture around operational risk represents perhaps the most challenging but also the most important dimension of management. An organization where people feel safe reporting errors, raising concerns, and challenging assumptions will identify and address operational risks far more effectively than one where such behaviours are discouraged or punished. The tone set by leadership, the behaviour modelled by managers, the responses to mistakes and near-misses, and the recognition given to employees who identify problems all contribute to whether the organizational culture supports or undermines operational risk management. For Canadian SMB owners and non-profit leaders who may not have formal risk management training, cultivating this culture may be the single most valuable investment they can make. It requires no specialized software, no expensive consultants, and no elaborate frameworks, only a consistent commitment to valuing awareness, honesty, and continuous improvement in how the organization operates.

Continue with University access

This lesson is part of a $79 course. Purchase the course or sign in with an active membership to keep reading.

See purchase options