Taxonomy of causes, risks, controls and impacts for a tier 2 retail bank

The Chief Risk Officer of a Tier 2 retail bank in Belgium contacted us to help him redefine the different categories of their operational risks. Alongside the new risk definitions, the client also wished to develop taxonomies for causes, controls and impact. 

The request came in a context of the CRO wanting to upgrade its operational risk management practise to the ones of Tier 1, mature banks in the industry. 

Having a revised taxonomy would better reflect both the exposure of the banks’ activities to the different risks but also summarise the key controls, causes and impacts. This would help the risk management function reorganise both their risk assessment and risk reporting. 

Challenge

The client needed our experience to act as a sounding board for the internal reflection. Together, we would come to a concise, yet comprehensive repertoire of key controls related to the main causes of operational risk failures. These would come from processes, systems, people and external events.  

We adopted a taxonomy that followed the main causes of operational risk and used the Basel categories as a starting point. Which the bank and its staff were already familiar with.  

The project went smoothly because of the strong support from senior management and a real personal involvement of the CRO in the process. 

BDO’s tailored approach & solutions 

Understanding the client 

In every consulting project, understanding the client needs, its constrains and its objectives is an essential first step. We knew this particular client through other projects, so it was relatively simple to assess the speed and scope of the work they wanted to get done. As well as the time limit allocated for this mission.  

Methodology  

To come up with the most relevant categories, we used the history of the bank’s incidents, the results of their risk & control self-assessments, and input from the internal control team.  

We then sat down with the team in brainstorming workshops to determine the different types of registers. 

Reporting 

Finally, we tested the relevance of the new taxonomy by recategorising the previous incidents to the updated risk categories. We tagged the controls that were in place and the causes of incidents to assess whether these were repeating causes. If so, this could signal a weakness in the risk mitigation environment.  

Taxonomy of Causes, Risks, Controls and Impacts for a Tier 2 Retail Bank

Impact & results

The new comprehensive and structured CRIC taxonomy allowed the client to: 

  • streamline its risk reporting; 

  • increase the insights from the analysis of incidents; 

  • establish systematic action plans to address any recurrent causes of operational incidents.  

 By improving their risk reporting process, the client achieved better results with less complexity. 

Risk Colleagues

Check out our full Risk Blueprint video series

This video series delivers tons of expertise and knowledge on the essentials of risk management.
Go watch our video series