Platform
Enterprise & Operational Risk

Operational Risk

Manage the risks in people, process, systems and external events

Identify, assess and monitor operational risk — process failures, human error, system outages, fraud and external events — with risk-and-control self-assessment, loss-event capture and key-risk-indicator tracking that feeds the enterprise risk picture. OnyxOne Operational Risk turns scattered incident logs and standalone RCSA spreadsheets into one connected discipline where exposures, losses and indicators reinforce each other and roll up cleanly to enterprise risk and the board.

At a glance

How it works, visually

Risk assessment at a glanceIllustrative
51015202548121620369121524681012345Likelihood54321Impact12345LowModerateElevatedHighCritical

An illustrative 5×5 likelihood × impact heatmap — the kind of view risk teams work from. Values are an example.

The challenge

The problems this module solves

The operational realities that make this hard for compliance and risk teams today.

RCSA is a once-a-year spreadsheet exercise

Risk-and-control self-assessments are run annually, captured in spreadsheets, and shelved. The ratings are stale within weeks, the format differs by team, and the assessment has no connection to the losses and incidents that actually occur — so it describes a risk picture that no longer holds.

Loss events go uncaptured or unstructured

Operational losses and near-misses are recorded inconsistently, if at all — some in email, some in local logs, many not at all. Without a structured loss database, the firm cannot see where money and time actually leak, learn from near-misses, or build a credible internal loss history.

Indicators aren't linked to the risks they signal

Teams track operational metrics, but the numbers sit in dashboards disconnected from any risk. A rising error rate or a growing backlog is visible to the team that owns it and invisible to risk oversight, so early warnings are missed until they become incidents.

Operational risk doesn't roll up

Because operational risk is assessed differently in every unit, it cannot be aggregated. Leadership sees fragments — this team's RCSA, that team's incident log — but never a coherent enterprise view of where operational exposure concentrates.

Findings, incidents and risk live in silos

An audit finding, an operational incident and a risk assessment often describe the same underlying weakness in three different systems. Nothing connects them, so the same issue is worked three times and the true exposure is understated.

The approach

How OnyxOne addresses it

Structured, repeatable RCSA

Run risk-and-control self-assessments on a defined structure and cadence, with consistent scales and workflow across every unit. Assessments become comparable and repeatable rather than a bespoke annual spreadsheet, and each one links directly to the controls and indicators that keep it current between cycles.

A structured internal loss database

Capture loss events and near-misses in one structured register — gross and net loss, cause, event type, recovery, business line and root cause. The firm builds a credible internal loss history that informs scoring, reveals where exposure concentrates and turns near-misses into lessons rather than lost signals.

Key risk indicators linked to exposures

Define KRIs with thresholds and link each to the operational risks it signals. When an indicator crosses amber or red, the risk it points to is flagged and the owner is alerted — so a rising error rate or backlog is an early warning to oversight, not just a number on a team dashboard.

One taxonomy that rolls up

Operational risks use the shared enterprise taxonomy and scoring model, so they aggregate cleanly into the enterprise register and the board view. Leadership sees where operational exposure concentrates across the whole organisation, not disconnected local fragments.

Incidents, losses and findings connected to risk

Operational incidents, loss events and audit findings link back to the operational risks and controls they concern. The same weakness is worked once, residual risk reflects real events, and the picture of operational exposure is grounded in what actually happened.

Capabilities

What's in the module

Turn on what you need and add more as your programme scales.

Risk-and-control self-assessment

Structured, repeatable RCSA campaigns with consistent scales, workflow and ownership across every unit.

Internal loss database

Capture loss events and near-misses with gross/net loss, event type, cause, recovery and root cause in one register.

Key risk indicators

Define KRIs with thresholds, link them to the risks they signal and track movements with automatic breach alerts.

Shared risk taxonomy

Operational risks use the enterprise taxonomy and scoring model so they aggregate into the enterprise picture.

Risk & control mapping

Link operational risks to mitigating controls and derive residual risk from tested control effectiveness.

Scenario analysis

Assess low-frequency, high-impact scenarios and capture the assumptions and outcomes for challenge and reuse.

Root-cause analysis

Categorise the underlying cause of losses and incidents to distinguish symptoms from systemic weaknesses.

Action & remediation tracking

Capture remediation actions from assessments, losses and indicators with owners, milestones and target dates.

Near-miss capture

Record near-misses alongside realised losses so early signals are learned from rather than lost.

Immutable event history

Every assessment, loss, indicator movement and action is versioned and preserved for audit.

Dashboards

The views your team works from

Purpose-built dashboards and views, each answering a question a specific role needs to act on.

An executive viewIllustrative
ILLUSTRATIVE EXAMPLEOPEN CASES128SLA ADHERENCE96%SCREENING ALERTS1.2kOVERDUE REVIEWS14Cases by categoryAMLKYCFraudSanctionsConductOtherRisk mixby tierHighMediumLow

A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.

Operational risk register

Every operational risk by business line and event type, with inherent and residual scoring and linked controls, filterable across the hierarchy.

Loss database

Realised losses and near-misses with gross, net and recovery, event-type distribution and trend, so leakage is visible where it occurs.

KRI monitor

Live indicator values against thresholds, breaches highlighted, each linked to the risk it signals.

RCSA tracker

Assessment completion, ratings and coverage across units, with overdue campaigns surfaced for follow-up.

Remediation board

Open remediation actions from assessments, losses and breaches, by owner and due date, tracked to closure.

Automation

What the platform automates

Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.

Scheduled RCSA campaigns

Assessment cycles launch on their cadence with owners assigned, and outstanding assessments are chased automatically.

KRI threshold alerts

When an indicator crosses amber or red, the linked risk is flagged and the owner and oversight are alerted without manual monitoring.

Loss-to-action routing

A captured loss above a configured threshold automatically raises a root-cause and remediation task to the responsible owner.

Control-failure reassessment

When a linked control fails testing, the operational risks it supports are flagged for reassessment automatically.

Action reminders & escalation

Remediation actions are reminded before they fall due and escalated when they slip past their target date.

AI assistance

Where AI helps the analyst

Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.

Loss-event classification

Suggests event type, business line and likely root-cause category for a captured loss, which the analyst reviews and confirms before it is recorded.

Emerging-pattern surfacing

Highlights clusters of near-misses or losses that may point to a systemic weakness, prompting a person to investigate rather than concluding on its own.

RCSA narrative drafting

Drafts assessment rationale and remediation summaries from linked losses, indicators and control results, leaving the owner to edit and own the final text.

The workflow

The enterprise workflow

A defined, end-to-end process with clear ownership at every stage.

The workflow, step by stepSchematic
01Assess (RCSA)Business units run structured self-assessments of their operational risks and thecontrols that mitigate them, on a consistent scale and cadence.02Capture losses & near-missesLoss events and near-misses are recorded in the internal loss database with cause,event type and recovery, building a credible history.03Monitor indicatorsKey risk indicators are tracked against thresholds and linked to the risks theysignal, surfacing early warnings between assessments.04Analyse root causeLosses and incidents are examined for underlying cause, separating one-off symptomsfrom systemic weaknesses that need treatment.05RemediateActions arising from assessments, losses and indicator breaches are assigned toowners with milestones and tracked to closure.06Aggregate & reportOperational risk rolls up through the shared taxonomy into the enterprise registerand into committee and board reporting.

Every result, decision and override is captured against the record it belongs to.

01

Assess (RCSA)

Business units run structured self-assessments of their operational risks and the controls that mitigate them, on a consistent scale and cadence.

02

Capture losses & near-misses

Loss events and near-misses are recorded in the internal loss database with cause, event type and recovery, building a credible history.

03

Monitor indicators

Key risk indicators are tracked against thresholds and linked to the risks they signal, surfacing early warnings between assessments.

04

Analyse root cause

Losses and incidents are examined for underlying cause, separating one-off symptoms from systemic weaknesses that need treatment.

05

Remediate

Actions arising from assessments, losses and indicator breaches are assigned to owners with milestones and tracked to closure.

06

Aggregate & report

Operational risk rolls up through the shared taxonomy into the enterprise register and into committee and board reporting.

The value

What your team gains

Repeatable

RCSA that stays current

Consistent, scheduled assessments linked to controls and indicators replace the once-a-year spreadsheet with a discipline that reflects reality between cycles.

Evidenced

A credible internal loss history

A structured loss database shows where money and time actually leak and gives scoring a factual basis rather than an opinion.

Early warning

Indicators that pre-empt incidents

KRIs linked to risks turn rising error rates and backlogs into alerts oversight sees, not numbers buried on a team dashboard.

Aggregatable

One enterprise view of operational risk

A shared taxonomy means operational exposure rolls up cleanly, so leadership sees where it concentrates across the whole firm.

Symptoms told apart from systemic issues

Root-cause analysis distinguishes one-off events from recurring weaknesses, so remediation fixes causes rather than firefighting effects.

One issue worked once

Linking incidents, losses and findings to the same risk stops the same weakness being managed three times in three systems.

Built for

Industries it serves

Financial ServicesBankingInsuranceInvestment FirmsFintechAsset ManagementCorporate & Trust Service ProvidersRegulated EnterprisesGaming
Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.

Enterprise risk
  • Feeds operational risks, losses and indicators into the enterprise risk register through the shared taxonomy for a single aggregated view
Incidents & cases
  • Links to your incident and case systems so operational events flow into loss capture and root-cause analysis
Controls & audit
  • Connects to internal-controls and audit modules so residual operational risk reflects real control testing and findings
Operational systems & metrics
  • Ingests operational metrics from your existing systems to populate key risk indicators automatically
Collaboration & notification
  • Routes assessment tasks, indicator breaches and remediation actions through your existing email and messaging channels
Assurance

Security, compliance & reporting

Security & data handling

  • Operational risk, loss and indicator data are encrypted in transit and at rest, with access governed by granular, role-based permissions.
  • Loss events involving sensitive detail can be restricted to named roles and withheld from wider rollups where required.
  • Segregation of duties can prevent the same person from both owning and signing off an assessment where policy requires it.
  • Every assessment, loss record, indicator movement and remediation action is written to an append-only audit trail.
  • Data residency and retention for the loss database and assessments are configurable to your regulatory obligations.

Compliance support

  • Supports operational-risk management practice aligned to recognised frameworks such as Basel operational-risk expectations, COSO and ISO 31000
  • Underpins operational-resilience obligations for regulated firms
  • Provides internal loss and RCSA evidence expected in regulatory examination
  • Feeds the operational-risk view within a three-lines-of-defence model
  • Supplies documented, dated assessment and loss evidence for internal and external audit

Reports & exports

  • Operational risk register by business line and event type
  • Internal loss reports — gross, net and recovery — with trend analysis
  • Near-miss and event-type distribution reports
  • Key-risk-indicator dashboards and threshold-breach reports
  • RCSA completion, rating and coverage reports
  • Remediation-action status and overdue-action reports
Best practice

How to get the most from it

Capture near-misses, not just losses

A near-miss is a free lesson. Recording events that almost cost you surfaces weaknesses before they realise, and makes the loss database a predictive tool rather than a graveyard.

Link every KRI to a risk

An indicator with no risk behind it is just a metric. Tie each KRI to the exposure it signals so a breach means something to oversight and drives action.

Assess against real losses

Feed loss and incident history into RCSA so ratings reflect what actually happens. Assessments built on opinion alone drift away from reality between cycles.

Analyse root cause, then remediate

Fix the cause, not the symptom. Categorising underlying cause turns a stream of one-off fixes into structural improvement that reduces future losses.

FAQ

Questions, answered

How does OnyxOne handle RCSA?

Risk-and-control self-assessments run on a structured template with consistent scales and workflow across every unit, on a defined cadence. Each assessment links to the controls and indicators that keep it current between cycles, so it stays meaningful rather than becoming an annual snapshot.

Can we build an internal loss database?

Yes. Loss events and near-misses are captured in a structured register with gross and net loss, event type, cause, recovery and root cause, giving you a credible internal loss history that informs scoring and reveals where exposure concentrates.

How do key risk indicators work?

You define KRIs with amber and red thresholds and link each to the operational risks it signals. When an indicator crosses a threshold, the linked risk is flagged and the owner alerted, turning metrics into early warnings for oversight.

Does operational risk feed the enterprise picture?

Yes. Operational risks use the shared enterprise taxonomy and scoring model, so they aggregate cleanly into the enterprise risk register and board reporting rather than sitting in a disconnected silo.

How are incidents and losses connected to risk?

Operational incidents, loss events and audit findings link back to the operational risks and controls they concern, so the same weakness is worked once and residual risk reflects real events rather than assertion.

See Operational Risk in your programme

Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.