Operational risk exists in every organization, whether acknowledged or not. The difference between organizations that manage it well and those that do not often comes down to visibility. Boards and executives cannot govern what they cannot see, and they cannot see what has not been measured, tracked, and communicated in ways that make sense to decision-makers who are not immersed in day-to-day operations. This is the fundamental challenge of operational risk reporting: making the invisible visible without creating so much noise that the signal gets lost.
The practice of using metrics and indicators to surface operational risk has its roots in financial services, where regulatory requirements have long demanded quantitative approaches to risk measurement. The Basel framework, developed by the Basel Committee on Banking Supervision and implemented in Canada through guidelines issued by the Office of the Superintendent of Financial Institutions, established operational risk as a distinct category requiring its own measurement and capital allocation. As of the date of authorship, OSFI's Guideline E-21 on Operational Risk Management requires federally regulated financial institutions to maintain robust systems for identifying, measuring, monitoring, and controlling operational risk. While this guideline applies specifically to banks, trust companies, and insurance companies, its principles have influenced risk management practices across Canadian industries far beyond financial services.