← University
Operational Risk: Definition, Sources, and Exposure
0 of 4

A mid-sized construction company headquartered in Calgary has operated for 14 years, growing from a residential renovation contractor into a commercial and industrial builder with approximately 85 employees spread across 3 active project sites. The company's founder serves as president and maintains direct involvement in project bidding and client relationships, while a general manager oversees day-to-day operations including site supervision, equipment management, and subcontractor coordination. Administrative functions run through a head office of 8 staff handling payroll, accounts payable and receivable, procurement, and safety compliance documentation.

The company's growth over the past 5 years has outpaced the formalization of its internal processes. Project managers at each site maintain their own methods for tracking labour hours, materials inventory, and safety inspections. The accounting system was implemented 9 years ago and has not been upgraded, requiring manual workarounds to generate reports for bonding companies and project owners. Employee onboarding varies by site, with some workers receiving comprehensive safety orientation while others are assigned to crews with minimal documentation of their qualifications or certifications.

External relationships add further complexity to the company's operations. The firm relies on a network of approximately 25 regular subcontractors for specialized trades including electrical, mechanical, and concrete work. Equipment financing arrangements with 2 different lenders carry distinct reporting obligations and covenant requirements. The company holds a surety bond program with aggregate capacity of $12 million, requiring quarterly financial reporting and ongoing demonstration of management competence to the surety provider. Insurance coverage spans commercial general liability, equipment floater, automobile, and umbrella policies, each with different renewal dates, exclusions, and reporting obligations.

Recent events have prompted the president and general manager to examine the company's risk profile more carefully. A subcontractor dispute on 1 project escalated into a lien claim that delayed payment from the project owner for 47 days. A payroll error resulted in incorrect deductions for 12 employees over a 3-month period, requiring correction and generating complaints to the head office. A ransomware attempt was blocked by the company's IT provider but exposed the absence of any documented data backup and recovery procedures. None of these incidents caused catastrophic harm, but together they prompted questions about what vulnerabilities exist across the organization, how different types of risk relate to one another, and whether current management practices adequately address the exposures the company actually faces.

Operational Risk vs. Strategic and Financial Risk: Why the Distinction Matters

Understanding the differences between operational risk, strategic risk, and financial risk represents one of the most consequential distinctions in organizational risk management. For Canadian business owners, non-profit operators, and professionals across the country, conflating these categories or failing to appreciate their boundaries can lead to misallocated resources, inadequate controls, and organizational blind spots that expose the enterprise to preventable harm. While all three categories of risk can ultimately affect an organization's financial position and long-term viability, they arise from fundamentally different sources, manifest through different mechanisms, and demand different management approaches. Recognizing where one category ends and another begins allows decision-makers to deploy appropriate tools, assign clear accountability, and build resilient organizations capable of navigating the full spectrum of threats they face.

Operational risk, as explored throughout this course, emerges from the internal workings of an organization. It encompasses the potential for loss arising from inadequate or failed internal processes, people, systems, or external events that disrupt operations. When a construction company in Edmonton experiences a workplace injury because safety protocols were not followed, that constitutes operational risk. When a professional services firm in Toronto suffers a data breach because its information technology systems lacked adequate security controls, operational risk has materialized. The distinguishing feature of operational risk is its connection to the execution of business activities rather than to decisions about which activities to pursue or how to finance them. The International Organization for Standardization, through ISO 31000:2018, provides a risk management framework that Canadian organizations widely adopt, and this framework emphasizes understanding risk context, which necessarily includes distinguishing between risks that arise from operations versus those that emerge from strategy or financial structure. As of the date of authorship, this standard remains the predominant international framework guiding Canadian risk management practice across both public and private sectors.

That’s the free preview

You’ve reached the end of what’s open to read. The rest of this lesson is part of a $79 course — purchasing unlocks it, or sign in if you already have access.