← University
Operational Risk Reporting for Boards and Executives (Faculty of Governance lens)
0 of 4

A mid-sized credit union headquartered in Red Deer, with 37 branches spread across central and northern Alberta, experienced a catastrophic technology failure on March 15, 2024. The incident began shortly after 9:00 AM when branch managers started reporting erratic behaviour in the core banking system, with some transactions processing normally while others were inexplicably rejected. Within 90 minutes, a routine backup procedure triggered an unexpected cascade failure that brought the entire digital infrastructure to a standstill. Members attempting to access accounts through online banking received error messages, debit card transactions at point-of-sale terminals throughout the province declined randomly, and tellers at physical branches found themselves unable to process even the simplest deposits or withdrawals.

The credit union's chief executive officer spent the morning fielding calls from branch managers while the information technology team worked to identify the source of the failure. By early afternoon, the organization had activated its business continuity protocols, but the damage to member confidence and operational capacity was already substantial. The board of directors received its first notification of the incident several hours after the initial reports from branch managers, and the information that reached them was fragmentary and inconsistent with what frontline staff were experiencing.

In the weeks following the incident, the board undertook a review of the circumstances that had led to the failure and the organizational response. That review revealed that warning signs had existed in the weeks and months prior to March 15. System performance metrics had shown gradual degradation, vendor support tickets had accumulated, and information technology staff had expressed concerns about infrastructure capacity in internal communications. None of this information had reached the board in a form that would have enabled meaningful oversight or intervention. The operational risk reports that the board had been receiving focused on a different set of concerns entirely and did not include the indicators that might have signalled the impending failure.

The credit union now faces a series of questions about how operational risk information flows through the organization. The board requires a reporting framework that provides visibility into the threats most likely to disrupt organizational objectives, without overwhelming directors with operational detail that obscures rather than illuminates. Management must determine which metrics and indicators capture meaningful risk exposure and how to present that information in formats that support governance rather than compliance theatre. Most critically, the organization must establish clear thresholds for escalation — criteria that determine which risks warrant board attention and which can be managed at lower levels of the organization without creating liability gaps or governance failures.

Building Risk Dashboards That Illuminate Rather Than Obscure Threats

A compliance officer at a mid-sized credit union headquartered in Red Deer reviews the quarterly risk dashboard prepared for the upcoming board meeting and finds herself troubled by what she sees, or more precisely by what she does not see. The document before her contains thirty-two separate metrics arranged across four pages, each one carefully colour-coded according to a traffic light system that assigns green to anything within tolerance and red to anything exceeding defined thresholds. On this particular afternoon in late February 2024, every single indicator glows a reassuring green, and yet she knows from conversations with the information technology team that the core banking system has been exhibiting increasingly erratic behaviour during peak transaction periods. She knows that vendor support tickets have nearly doubled over the past quarter and that three experienced technicians have expressed serious concerns about infrastructure capacity in emails she has seen circulated internally. None of this reality appears anywhere in the document that will reach the board in ten days, and she struggles to articulate precisely why the dashboard fails to capture what the organization actually needs to know.

The challenge she confronts is not unique to this credit union, nor is it a product of any individual's negligence or bad faith. Risk dashboards across Alberta's regulated financial institutions routinely suffer from the same fundamental defect: they measure what can be easily quantified rather than what genuinely matters, and in doing so they create an illusion of comprehensive oversight that may actually increase organizational vulnerability. When the core banking system collapsed on March 15, 2024, bringing thirty-seven branches to a standstill and undermining member confidence across central and northern Alberta, the board discovered that months of green indicators had concealed a mounting infrastructure crisis. The question that emerged from the subsequent review was not simply why warning signs had failed to reach the board, but how the organization's entire approach to risk visualization had been structured in a way that made meaningful early warning functionally impossible.

That’s the free preview

You’ve reached the end of what’s open to read. The rest of this lesson is part of a $79 course — purchasing unlocks it, or sign in if you already have access.