Operational Resilience

[OR] [RBI] [3] Three Lines of Defence for Management of Operational Risk

Written by Moh Heng Goh | Aug 9, 2024 6:36:20 AM

Three Lines of Defence for Operational Risk Management

Effective operational risk management requires a collaborative approach involving three lines of defence. Business units are responsible for identifying and managing operational risks.

The operational risk management function provides independent oversight, ensuring risks are adequately controlled. The audit function independently assesses the overall effectiveness of the risk management framework, assuring the board.

Principle 5: Comprehensive Three Lines of Defence for Management of Operational Risk

Effective operational risk management (ORM) relies on a robust three-lines-of-defence model.

Business Unit Management
First Line of Defence

The first line of defence is the business unit itself. It's responsible for identifying, assessing, and mitigating operational risks inherent in its operations.

This includes setting controls, monitoring risk profiles, and reporting operational losses and control deficiencies.

Organisational Operational Risk Management Function including Compliance Function
Second Line of Defence

The second line of defence is the organisational operational risk management function (OORF). It provides independent oversight and ensures that business units effectively manage operational risks.

The OORF develops policies, standards, and guidelines, challenges business unit assessments, and includes risk awareness training.

Audit Function
Third Line of Defence

The third line of defence is the audit function. It independently assesses the adequacy and effectiveness of the ORM framework. This involves validating risk quantification systems, verifying the design and implementation of ORM systems, and reporting findings to the board.

For the model to be effective, each line of defence must have clear roles, adequate resources, and strong communication. Ultimately, the seamless collaboration between these lines forms a robust shield against operational risks.

Note: This summary focuses on the core responsibilities of each line of defence. The original text provides more granular details and specific requirements.

 

More Information About Blended Learning OR-5000 [OR-5] or OR-300 [OR-3]

To learn more about the course and schedule, click the buttons below for the OR-3 Blended Learning OR-300 Operational Resilience Implementer course and the OR-5 Blended Learning OR-5000 Operational Resilience Expert Implementer course.

If you have any questions, click to contact us.