Operational risk is defined by the Basel Committee as "the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events." It explicitly excludes strategic and reputational risk, but otherwise covers a wide spectrum: fraud, processing errors, system failures, legal risk, and physical damage. In a bank's markets business, operational risk is pervasive — the high volume of complex transactions, the reliance on technology, and the involvement of human judgment at every stage of the trade lifecycle create numerous points of potential failure.

Basel II/III Operational Risk Framework

The Basel Committee first introduced a specific capital charge for operational risk in Basel II (2004), recognising that the industry's losses from operational events were material and not captured by existing market and credit risk frameworks. Basel III refined the framework; the final Basel III package (sometimes called Basel IV) standardised the operational risk capital calculation through the Standardised Approach, moving away from the complexity of internal model-based approaches.

The Standardised Approach calculates the operational risk capital charge as a function of the bank's Business Indicator Component (BIC) — a measure of the size and activity of the bank derived from income statement items — scaled by the bank's Internal Loss Multiplier (ILM), which adjusts the charge based on the bank's own historical operational loss experience. Banks with large historical operational losses face higher capital charges, creating a direct financial incentive to invest in operational risk management.

The Seven Basel Event Type Categories

Basel categorises operational loss events into seven types:

  • Internal fraud: Unauthorised activity or theft by employees, including rogue trading (concealing positions, manipulating valuations) and misappropriation of assets.
  • External fraud: Theft or fraud by external parties, including cyber attacks, phishing, and payment fraud.
  • Employment practices and workplace safety: Losses arising from employment law violations, discrimination claims, or health and safety failures.
  • Clients, products, and business practices: Losses from failure to meet professional obligations to clients, including mis-selling, market manipulation, and benchmark rigging (e.g. LIBOR). This category has generated some of the largest regulatory fines in banking history.
  • Damage to physical assets: Losses from natural disasters, terrorism, or other events damaging physical premises.
  • Business disruption and system failures: Losses from technology failures, power outages, and IT system disruptions that affect market operations.
  • Execution, delivery, and process management: Losses from failed transactions, booking errors, settlement failures, and documentation problems. This is the most frequent category of operational loss in a markets business, though individual events are typically small.

Rogue Trader Events: Case Studies

Rogue trader events are among the most dramatic operational risk manifestations and have shaped the industry's approach to controls and oversight.

Nick Leeson and Barings Bank (1995)

Nick Leeson was a derivatives trader at Barings Bank in Singapore who accumulated large unauthorised positions in Nikkei futures, hiding losses in an error account (account 88888) that he also controlled — a critical control failure where one individual had responsibility for both trading and back-office reconciliation. The 1995 Kobe earthquake caused the Nikkei to plunge, crystallising losses of approximately £830 million and forcing Barings into administration. The episode led to significant changes in segregation of duties requirements across the industry.

Jérôme Kerviel and Société Générale (2008)

Kerviel was a Delta One trader at Société Générale who built up directional equity futures positions with a notional value of approximately €50 billion — far exceeding his authorised limits — by exploiting his knowledge of the bank's back-office systems (gained from his previous role in operations) to disguise the positions with fictitious offsetting trades. When the positions were unwound in January 2008, the loss reached €4.9 billion. The episode highlighted the risks of inadequate limit monitoring, insufficient escalation of limit breaches, and the dangers of allowing personnel to move from operations to front office without appropriate controls being updated.

Knight Capital (2012)

Knight Capital's $440 million loss in 45 minutes on 1 August 2012 was an operational risk event of a different type: a technology failure rather than deliberate fraud. The firm deployed new trading software that accidentally activated a dormant algorithm, causing it to buy and sell millions of shares at unfavourable prices before the error could be stopped. The event demonstrated the operational risks of automated trading systems, the importance of pre-deployment testing, and the need for kill switches capable of halting algorithmic activity rapidly.

Risk and Control Self-Assessment (RCSA)

The Risk and Control Self-Assessment (RCSA) is the primary tool through which a markets business identifies and assesses its operational risks. In an RCSA exercise, business managers and operational risk officers systematically identify the risks inherent in each business activity, assess the controls in place to mitigate those risks, evaluate the residual risk remaining after controls are applied, and identify gaps where additional controls are needed.

A well-run RCSA process in a markets business will cover: trade booking and confirmation; market risk limits and monitoring; settlement and reconciliation; valuation and P&L production; technology systems and cyber risk; conduct and conflicts of interest. The RCSA is not a one-time exercise — it is reviewed regularly and updated when business activities or control environments change.

Key Risk Indicators

Key Risk Indicators (KRIs) are metrics that provide early warning signals of increasing operational risk. In a markets business, common KRIs include: the number of failed trades (settlement failures) per day; the number of limit breaches; the volume of outstanding trade confirmations beyond agreed deadlines; the number of P&L explain items above threshold; system downtime; and staff turnover in key control functions. KRIs are tracked over time and reported to senior management; deteriorating trends trigger management attention and investigation.

Loss Data Collection

Banks are required to collect data on operational loss events — recording the date, amount, business line, event type, and recovery — and to use this data in their operational risk capital calculations and risk management processes. Loss data collection is operationally demanding: distinguishing operational losses from credit losses (e.g. a settlement failure that results in a credit loss when the counterparty defaults), capturing near-misses (events that could have resulted in a loss but did not), and ensuring completeness of reporting across a large and complex organisation requires disciplined processes and a culture where staff feel comfortable reporting errors without fear of blame.

Key Terms

Operational Risk
The risk of loss resulting from inadequate or failed internal processes, people, and systems or from external events. Carries a dedicated regulatory capital charge under Basel III.
Standardised Approach (Basel OpRisk)
The Basel III standardised method for calculating operational risk capital, based on the Business Indicator Component (bank size) scaled by the Internal Loss Multiplier (historical loss experience).
RCSA (Risk and Control Self-Assessment)
A structured process through which business managers identify, assess, and document operational risks and controls in their activities, resulting in a residual risk rating for each identified risk.
Key Risk Indicator (KRI)
A metric providing early warning of increasing operational risk — for example, the volume of failed trades, outstanding confirmations, or P&L exceptions above threshold.
Segregation of Duties
The organisational principle of separating the functions of trading, booking, and reconciliation so that no single individual can execute a transaction, record it, and verify it without oversight.
Delta One
A trading desk dealing in instruments with delta-one exposure — instruments whose value moves approximately one-for-one with the underlying: ETFs, total return swaps, futures, forward contracts. The desk involved in the Kerviel case at Société Générale.