← University
Operational Risk Reporting for Boards and Executives
0 of 4

A mid-sized credit union headquartered in Red Deer, with 37 branches spread across central and northern Alberta, experienced a catastrophic technology failure on March 15, 2024. The incident began shortly after 9:00 AM when branch managers started reporting erratic behaviour in the core banking system, with some transactions processing normally while others were inexplicably rejected. Within 90 minutes, a routine backup procedure triggered an unexpected cascade failure that brought the entire digital infrastructure to a standstill. Members attempting to access accounts through online banking received error messages, debit card transactions at point-of-sale terminals throughout the province declined randomly, and tellers at physical branches found themselves unable to process even the simplest deposits or withdrawals.

The credit union's chief executive officer spent the morning fielding calls from branch managers while the information technology team worked to identify the source of the failure. By early afternoon, the organization had activated its business continuity protocols, but the damage to member confidence and operational capacity was already substantial. The board of directors received its first notification of the incident several hours after the initial reports from branch managers, and the information that reached them was fragmentary and inconsistent with what frontline staff were experiencing.

In the weeks following the incident, the board undertook a review of the circumstances that had led to the failure and the organizational response. That review revealed that warning signs had existed in the weeks and months prior to March 15. System performance metrics had shown gradual degradation, vendor support tickets had accumulated, and information technology staff had expressed concerns about infrastructure capacity in internal communications. None of this information had reached the board in a form that would have enabled meaningful oversight or intervention. The operational risk reports that the board had been receiving focused on a different set of concerns entirely and did not include the indicators that might have signalled the impending failure.

The credit union now faces a series of questions about how operational risk information flows through the organization. The board requires a reporting framework that provides visibility into the threats most likely to disrupt organizational objectives, without overwhelming directors with operational detail that obscures rather than illuminates. Management must determine which metrics and indicators capture meaningful risk exposure and how to present that information in formats that support governance rather than compliance theatre. Most critically, the organization must establish clear thresholds for escalation — criteria that determine which risks warrant board attention and which can be managed at lower levels of the organization without creating liability gaps or governance failures.

What Boards and Executives Need to Know About Operational Risk

The morning of March 15, 2024, began like any other at Westbrook Financial Services, a mid-sized credit union headquartered in Red Deer with thirty-seven branches spread across central and northern Alberta. By 9:15 AM, the organization's chief executive officer had already fielded three calls from branch managers reporting that the core banking system was behaving erratically, processing some transactions while mysteriously rejecting others. By 10:30 AM, the situation had escalated dramatically when a routine backup procedure triggered an unexpected cascade failure that brought the entire digital infrastructure to a standstill. Members attempting to access their accounts through online banking received error messages, debit card transactions at point-of-sale terminals throughout the province were declining randomly, and tellers at physical branches found themselves unable to process even the simplest deposits or withdrawals. The chief executive, recognizing the severity of the situation, immediately contacted the board chair to inform her of the developing crisis, only to discover that she was already receiving concerned calls from board members who had heard about the outage through their own community networks.

What unfolded over the next seventy-two hours at Westbrook Financial Services illustrates precisely why boards and executives must possess a sophisticated understanding of operational risk rather than delegating such concerns entirely to technical specialists or middle management. The system failure was eventually traced to a combination of factors that, in isolation, seemed manageable but in combination proved devastating. A software update deployed three weeks earlier had introduced a subtle timing conflict with the backup system. Simultaneously, a key infrastructure specialist who understood the intricacies of the legacy integration layer had retired six months prior, and the institutional knowledge necessary to recognize early warning signs had departed with her. Additionally, the credit union's disaster recovery plan, last comprehensively tested in 2019, contained assumptions about system dependencies that no longer reflected the actual architecture of the organization's technology environment. Each of these factors represented an operational risk that had been documented somewhere within the organization, but none had been synthesized into a coherent picture that reached the board level with sufficient clarity to prompt preventive action.

That’s the free preview

You’ve reached the end of what’s open to read. The rest of this lesson is part of a $79 course — purchasing unlocks it, or sign in if you already have access.