Operational Risk
Operational risk is the potential for loss caused by breakdowns in an organization's day-to-day operations, whether from flawed internal processes, human error, or failing systems. It also includes losses driven by external events outside the organization's direct control. In a third-party context, these same failures can originate within a supplier or service provider and flow back to the organization that relies on them.
Operational risk is the risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events. Managing it is typically approached as a continual, recurring process of identifying, assessing, mitigating, and monitoring these loss exposures rather than a point-in-time exercise. This category is distinct from, though it can intersect with, financial, strategic, and reputational risk; when assessing external parties, operational risk covers process, personnel, systems, and external-event exposures within the third party's operations and does not by itself encompass the organization's own broader risk portfolio.
Why it matters
Operational risk sits at the core of third-party and supply chain programs because a supplier's day-to-day failures do not stay contained within that supplier. When a service provider's internal process breaks down, its personnel make errors, or its systems fail, the resulting loss can flow directly back to the organization that depends on it. A payroll processor that misfires, a logistics partner whose systems go down, or a vendor whose staffing gaps interrupt service all translate into operational exposure for the relying organization, even though the originating failure occurred outside its own walls.
What makes operational risk demanding to manage is that it spans multiple loss sources at once: process, people, systems, and external events. These categories interact, and a single incident can implicate several of them. Because operational risk is distinct from financial, strategic, and reputational risk, treating it as a standalone concern can leave blind spots; conversely, treating it as identical to those categories can overstate what an operational assessment actually covers. In a third-party context, assessing a supplier's operational risk speaks to exposures within that supplier's operations and does not, by itself, capture the organization's own broader risk portfolio.
A further practical challenge is that operational risk is dynamic. A supplier's processes, workforce, and systems change over time, so a favorable finding at onboarding can become stale. Programs that treat operational risk as a point-in-time judgment rather than an ongoing exposure risk missing degradation that occurs between assessments.
Who it's relevant to
Inside Operational Risk
Common questions
Answers to the questions practitioners most commonly ask about Operational Risk.
