Course overview
Operational risk is the exposure that arises from doing the work: a process that fails, a system that goes down, a person who makes an error, a supplier who stops delivering, an event nobody planned for. In a large enterprise it is diffuse by nature, which is why it is the hardest category to govern. There is no single desk that owns it and no single number that measures it.
This course covers operational risk across twelve units: the nature of the exposure, frameworks and standards, identification and categorization, internal controls, governance, mitigation, continuity, digital tools, sustainability, monitoring and reporting, global practice, and an integrated closing case.
The problem of scale
In a company of two hundred people, operational risk is managed by conversation. In a company of thirty thousand, it has to be managed by system: a taxonomy everyone uses, loss event data that is actually captured, indicators that are monitored, and a control library that maps to real exposures. Without those, the enterprise learns about its operational risks from incidents.
Two failures recur. Loss data is not collected, because reporting an incident is career-negative, so the organization has no evidence base and argues about anecdotes. And risk and control self-assessment becomes a form-filling exercise, in which every business unit rates its own controls as effective and the aggregate picture is worthless.
Course objectives
By the end of the course, participants will be able to:
- Categorize operational events the same way in every division.
- Capture loss and near-miss data worth analyzing later.
- Self-assess honestly enough that the results are believed.
- Resource control testing against exposure, not against volume.
- Bound operational exposure at a level the board has agreed.
- Absorb what insurance and contract terms will not cover.
- Withstand disruption and restore the services that matter first.
- Outsource without concentrating exposure in one cloud or supplier.
- Track aggregated exposure on data the board can rely on.
- Model a severe loss from climate, safety or supply failure.
- Trigger escalation to a named person when exposure has no owner.
- Compare enterprise practice against mature external benchmarks.
Course outline
Unit 1: Introduction to operational risk in large enterprises
- Categories of process, systems, people and external events.
- Diffuse ownership and the absence of one single measure.
- Enterprise failures and the control weaknesses behind them.
- The cost of operational risk beyond the direct loss.
Unit 2: Operational risk frameworks and standards
- Operational exposure taken without any expected return.
- Basel operational risk categories used outside banking.
- The ownership, challenge and assurance layers at scale.
- Framework components from taxonomy through to reporting.
Unit 3: Risk identification and categorization
- A taxonomy precise enough for two divisions to agree.
- Loss event and near-miss capture people will actually use.
- Risk and control self-assessment across hundreds of teams.
- Scenario analysis for severe events not yet experienced.
Unit 4: Internal controls and oversight
- COSO control components applied to operational processes.
- Key controls that carry most of the exposure.
- Control testing and deficiencies that become material.
- Automated controls and the technology they rest on.
Unit 5: Governance and compliance integration
- Risk that nobody in the business will put a name to.
- Risk appetite expressed as operational tolerances.
- Alignment with compliance and internal audit coverage.
- Escalation routes that work across a large hierarchy.
Unit 6: Risk mitigation strategies
- Redesign and error-proofing before adding more controls.
- Control enhancement, redundancy and capacity buffers.
- Insurance and contractual transfer with hidden exclusions.
- Spend on mitigation, and where it stops paying back.
Unit 7: Business continuity and resilience
- Services the business cannot run without, and for how long.
- Recovery targets the systems and staff can meet.
- Third-party concentration in cloud and critical suppliers.
- Coordination of business continuity across many sites.
Unit 8: Digital tools for operational risk management
- Risk platforms and what they assume is already fixed.
- Control automation across a large process estate.
- Analytics on incident and loss data for root causes.
- Data quality as the binding constraint on every dashboard.
Unit 9: ESG and sustainability in operational risk
- Environmental incidents, emissions data and disclosure.
- Health and safety as operational risk with human cost.
- Supply chain conduct: labor practices and sanctions.
- Physical climate risk to sites and critical infrastructure.
Unit 10: Monitoring and reporting operational risks
- Key risk indicators that move before the loss arrives.
- Aggregating divisional exposure without losing the detail.
- Board reporting on loss experience and what is still open.
- Reporting bad news early, and the culture that allows it.
Unit 11: Global best practices in operational risk
- Embedding ownership in the business, not the risk team.
- Loss data consortiums and external event data as evidence.
- Peer comparison with a mature operational risk function.
- Turnaround priorities in a weak risk function.
Unit 12: Capstone case study
- Building the group taxonomy, register and control map.
- Analyzing loss data for concentrations nobody has noticed.
- Designing controls and continuity for the top exposures.
- Tracing one loss event from the desk to the annual report.
How the course is delivered
The course uses documented material: loss event data, incident reviews, self-assessment outputs, control libraries and board risk reports that participants analyze and rebuild in discussion. Worked examples take indicator design and loss analysis step by step. There is no software environment. The course is educational and does not certify participants or assess any organization. Those who want the control design discipline in depth should look at Internal Controls and Risk Mitigation Strategies.
Who should attend
- Operational risk managers and analysts in large organizations.
- Business unit leaders who own operational exposure.
- Internal auditors and compliance officers covering operational risk.
- Continuity, quality and process improvement professionals.
About EuroQuest International Training
EuroQuest International Training was founded in 2015 by a team with more than 25 years of experience in professional development. We deliver over 1,000 courses and have trained more than 15,000 participants, from our head office in Bratislava, Slovakia, with hubs in Dubai, London, Barcelona, Istanbul, Vienna, Paris and Geneva. Courses are developed and reviewed by practitioners from the fields they teach.
Frequently asked questions
Is this course only for financial institutions?
No. Basel categories are used because they are well developed, but the framework applies across manufacturing, energy, healthcare, logistics and the public sector, and the examples reflect that.
Our people do not report incidents. Where do we start?
With the response to the first report, which sets the precedent. The course treats loss data culture as a leadership problem rather than a system problem, because that is what it is.
Does the course include a live lab?
No. There is no software environment. Risk platforms and analytics are examined through their outputs and design implications.
Related courses
- Enterprise Risk Management Strategies
- Strategic Risk Planning and Business Continuity
- Measuring and Benchmarking Risk Performance
- Insurance and Risk Transfer Mechanisms
Register for this course
Choose a city and date from the schedule above to register, or contact EuroQuest about in-house delivery for an operational risk function.
All Course Dates & Locations
18 dates · 16 cities · Oct 2026 – Jul 2027