← University
Operational Risk Reporting for Boards and Executives (Faculty of Governance lens)
0 of 4

A mid-sized credit union headquartered in Red Deer, with 37 branches spread across central and northern Alberta, experienced a catastrophic technology failure on March 15, 2024. The incident began shortly after 9:00 AM when branch managers started reporting erratic behaviour in the core banking system, with some transactions processing normally while others were inexplicably rejected. Within 90 minutes, a routine backup procedure triggered an unexpected cascade failure that brought the entire digital infrastructure to a standstill. Members attempting to access accounts through online banking received error messages, debit card transactions at point-of-sale terminals throughout the province declined randomly, and tellers at physical branches found themselves unable to process even the simplest deposits or withdrawals.

The credit union's chief executive officer spent the morning fielding calls from branch managers while the information technology team worked to identify the source of the failure. By early afternoon, the organization had activated its business continuity protocols, but the damage to member confidence and operational capacity was already substantial. The board of directors received its first notification of the incident several hours after the initial reports from branch managers, and the information that reached them was fragmentary and inconsistent with what frontline staff were experiencing.

In the weeks following the incident, the board undertook a review of the circumstances that had led to the failure and the organizational response. That review revealed that warning signs had existed in the weeks and months prior to March 15. System performance metrics had shown gradual degradation, vendor support tickets had accumulated, and information technology staff had expressed concerns about infrastructure capacity in internal communications. None of this information had reached the board in a form that would have enabled meaningful oversight or intervention. The operational risk reports that the board had been receiving focused on a different set of concerns entirely and did not include the indicators that might have signalled the impending failure.

The credit union now faces a series of questions about how operational risk information flows through the organization. The board requires a reporting framework that provides visibility into the threats most likely to disrupt organizational objectives, without overwhelming directors with operational detail that obscures rather than illuminates. Management must determine which metrics and indicators capture meaningful risk exposure and how to present that information in formats that support governance rather than compliance theatre. Most critically, the organization must establish clear thresholds for escalation — criteria that determine which risks warrant board attention and which can be managed at lower levels of the organization without creating liability gaps or governance failures.

Board Notification Delays During the March 2024 Core Banking Collapse

The call came through to the board chair's mobile phone at 3:47 PM on March 15, 2024, nearly seven hours after the first branch manager in Stettler had reported that the core banking system was rejecting routine deposit transactions. By that point, the chief executive officer of the Red Deer-based credit union had already spent the better part of the day in crisis mode, coordinating with the information technology team, fielding increasingly urgent calls from thirty-seven branch managers across central and northern Alberta, and attempting to reassure commercial members whose payroll transfers had failed to process on a Friday afternoon. The board chair learned of the incident not through the formal escalation channels the organization had painstakingly documented in its enterprise risk management framework, but through a hurried telephone conversation that conveyed urgency without providing the context necessary for the board to understand what had actually occurred or what governance decisions might be required in response. The delay was not the product of malice or deliberate concealment; it was the predictable result of an organizational structure that had never clearly defined when operational disruption crossed the threshold from management problem to governance concern.

The information that eventually reached the board that afternoon was fragmentary in a way that illustrates a common failure mode in operational risk reporting. The board chair was told that a system outage had occurred, that the technology team was working on restoration, and that business continuity protocols had been activated. What the board chair was not told—because the chief executive officer did not yet have a complete picture—was that the cascade failure had been triggered by a routine backup procedure that the vendor had flagged as potentially problematic six weeks earlier, that system performance metrics had shown degradation patterns consistent with infrastructure strain for at least three months, and that the information technology department had submitted two separate budget requests for hardware upgrades that had been deferred to the following fiscal year. The board was receiving notification of an outcome without any of the antecedent information that would have allowed directors to assess whether the organization's risk management processes had functioned appropriately or whether governance intervention might have prevented the failure entirely.

That’s the free preview

You’ve reached the end of what’s open to read. The rest of this lesson is part of a $79 course — purchasing unlocks it, or sign in if you already have access.