Course overview
Operational risk is the exposure a business carries when a payment is processed twice, a supplier fails, a control is bypassed, or a data center goes dark. In a large enterprise, where thousands of staff run overlapping processes across many jurisdictions, these events compound quickly and rarely stay contained to one department. This course treats operational risk as its own discipline, separate from the credit, market, and liquidity exposures that dominate treasury discussions. The focus is on the Basel event categories, internal and external fraud, process failure, business disruption, and execution and delivery breakdowns, and on the governance needed to keep them visible to senior management and the board.
Participants work through the full operational risk cycle as it applies at scale: building a taxonomy of risks, running risk and control self-assessment (RCSA), setting key risk indicators (KRIs), collecting internal loss event data, and drawing on external loss databases such as ORX for context. The course connects these tools to the three lines of defense model, to operational resilience expectations, and to enterprise risk management (ERM), so that operational risk stops being a standalone spreadsheet and becomes part of how the organization is actually run and reported.
Why this matters
Some of the largest corporate losses of the past two decades came not from a bad market call but from an operational failure: rogue trading that slipped past reconciliation controls, mis-selling driven by weak process design, outages that stopped customers transacting for days, and third-party breaches that exposed millions of records. Regulators now expect large firms to demonstrate operational resilience, showing that important business services can keep running through disruption and recover inside defined tolerances. That expectation raises the stakes for anyone accountable for controls, continuity, and reporting.
Getting this right also protects reputation and capital. Firms with disciplined loss data, credible scenario analysis, and a genuine risk culture spot concentrations early and price the cost of control against the cost of failure. Because severe operational events so often turn into full crises, the discipline sits close to Crisis Management and Business Continuity, and the two are strongest when planned together rather than in isolation.
Course objectives
By the end of the course, participants will be able to:
- Classify losses consistently across divisions and jurisdictions.
- Collect internal loss event data above a usable threshold.
- Scale external loss data from a consortium of larger firms.
- Estimate exposure from risk and control self-assessment ratings.
- Tune key risk indicators against what actually happened next.
- Simulate a tail event that the loss history has never shown.
- Escalate a breach of the limits the board agreed to hold.
- Segment losses by the control and the provider behind them.
- Consolidate exposures across enterprise risk management reporting.
Course outline
Unit 1: Operational risk in complex, large-scale organizations
- Coding each loss to one Basel event category, not several.
- Sorting boundary losses from credit, market, and liquidity.
- How scale and jurisdictional spread thicken the loss tail.
- Reading a rogue-trading case for what the data missed.
Unit 2: Governance, risk appetite, and board oversight
- Naming who owns a figure and who may challenge it.
- Turning risk appetite into limits and escalation points.
- A loss that reached the board months after it happened.
- Holding loss data policy to Basel and internal standards.
Unit 3: Identification, assessment, and measurement
- Calibrating RCSA scores so ratings mean the same thing.
- Testing whether KRIs lead a loss or just arrive early.
- Scaling ORX external data to an internal loss population.
- Sizing a tail event in a scenario analysis workshop.
Unit 4: Controls, continuity, and third-party risk
- Counting the losses a preventive control did not stop.
- Impact tolerances in hours for important business services.
- Tracing a loss to a third-party or outsourcing provider.
- Proving an ISO 22301 plan meets a resilience tolerance.
Unit 5: Embedding risk culture and integrating with ERM
- Capturing near misses that cost nothing and go unlogged.
- Feeding operational loss data into the ERM picture.
- Aggregating hundreds of divisional entries into one figure.
- Resetting loss thresholds and KRI limits after an event.
How the course is delivered
The course runs as a mix of expert-led discussion, guided walkthroughs of documented operational loss cases, worked numerical examples using sample loss data, and structured group exercises that build RCSA entries and KRI sets from realistic enterprise scenarios. Participants compare approaches, question assumptions, and leave with reference material they can adapt to their own organization.
Who should attend
The course suits professionals who own, oversee, or support operational risk in a large or complex organization, including:
- Operational risk and compliance officers
- Internal auditors and control assurance staff
- Business continuity and operational resilience managers
- Operations, process, and shared-services leaders
- Governance, risk, and ERM specialists
- Senior managers accountable for controls and reporting
About EuroQuest International Training
Since 2015, EuroQuest International Training has worked from its Bratislava base to build a catalog exceeding 1,000 courses and a community of more than 15,000 past participants. Teaching takes place in London, Dubai, Istanbul, Geneva, Barcelona, Vienna and Paris, delivered by specialists with direct enterprise experience.
Frequently asked questions
What will participants receive once the course concludes?
Attendees leave with a certificate of completion from EuroQuest International Training that notes the course and the dates covered. It evidences learning and carries no weight as an external certification; the sessions are educational and do not certify an enterprise or its controls.
How is operational risk different from financial or market risk?
Financial and market risk arise from deliberate exposure to prices, rates, credit, and liquidity, where a firm expects a return for taking the position. Operational risk is the opposite: it is the loss potential inside people, processes, systems, and external events, such as fraud, process breakdowns, outages, and supplier failures, where nobody is being paid to take the risk. The course keeps that boundary clear while showing where the two categories interact.
Is the material relevant to firms outside banking and financial services?
Yes. Although much of the terminology grew up inside banking under Basel, the underlying methods apply to any large enterprise. RCSA, key risk indicators, loss data collection, scenario analysis, the three lines of defense, and continuity planning to ISO 22301 all translate directly to manufacturers, utilities, healthcare providers, technology firms, and public bodies.
Related courses
- Operations Risk Management and Quality Assurance
- ISO 31000: Risk Management Principles and Guidelines
- Enterprise Risk Management Strategies
- Enterprise-Wide Risk Governance Strategies
Register for this course
Reach EuroQuest on +421 911 803 183, or drop an email to info@euroqst.com, to hold a place on the next running of this course and to discuss group bookings.
All Course Dates & Locations
31 dates · 15 cities · Sep 2026 – Jul 2027