Operational & IT Risk
Operational risk with the loss data to back it
Registers for operational and technology risk, departmental self-assessment on a cycle, and captured loss events with categories and root causes feeding back into scoring.
- Operational and IT risk programmes on the shared risk model
- RCSA cycles with department assessments, entries, and evidence
- Loss events with category, root cause, status, and attachments
- Risks linked to the assets, services, and processes they threaten
Stage 1 of 5
Open cycle
Scope and period set by the risk function
Loss events feed the same register, with category and root cause recorded.
Self-assessment
RCSA as a governed cycle
Cycles are opened, assigned to departments, completed with entries and evidence, and closed, rather than being a spreadsheet circulated once a year.
- Cycle status tracked from open through completion
- Per-department assessments with their own risk entries
- Evidence attached at entry level
- Results feed the register rather than sitting beside it
Level 3: Well Defined
A standard process is defined and followed across the organisation.
Every question in the control library carries its own written descriptor at each level.
Dependencies
Risk that knows what it touches
Operational risk is only meaningful in context, so risks carry typed links to assets, business processes, services, capabilities, controls, findings, and policies.
- Typed risk relationships, including risk-to-risk
- Links to assets, processes, services, and capabilities
- Control links with defined control roles
- Findings raised from risk carry the link back
Draft·asset-coordinator creates
Framework alignment
Works with your control frameworks
This module shares the platform control library. Map national frameworks and global standards alongside jurisdiction-specific authorities.
Solutions by role
Built for your team
See operational risk in your environment
A walkthrough scoped to your entities, your frameworks, and the way your programme is actually run.