Resources

Competency catalog

Operational risk competency

Operational risk identifies and reduces process risks through proportionate controls, monitoring, and escalation. This catalog progresses from applying established controls, to independently assessing a workflow, to shaping risk practices across connected operations.

Published by Peasy HRPublished 18 Aug 2026Updated 18 Aug 2026

Short answer

Operational risk identifies and reduces process risks through proportionate controls, monitoring, and escalation. This catalog progresses from applying established controls, to independently assessing a workflow, to shaping risk practices across connected operations.

About Operational risk

Identifies and reduces process risks using proportionate controls, monitoring, and escalation. Effective operational risk work connects plausible failure events to their consequences and makes ownership, response, and remaining exposure explicit.

Use this competency for

  • Roles that identify process failures and design, monitor, or improve controls.
  • Work where operational decisions must account for likelihood, consequence, and remaining exposure.

Do not use this competency for

  • Roles that only follow controls and are not expected to assess risk or respond to control evidence.

Important distinctions

Quality management

Quality management checks whether recurring outputs meet standards. Operational risk addresses uncertain process failures and their potential consequences.

Business continuity

Operational risk reduces the likelihood or consequence of process failures. Business continuity prepares the response needed when disruption occurs.

Expectations by level

IC1

Applies defined controls

Applies established controls and monitoring steps with guidance. Records evidence, identifies clear departures, and escalates operational risks within their own work.

Observable behaviors

  • Performs a defined control at the required point in the process.
  • Records control evidence and any departure found.
  • Escalates a risk or failed control through the documented path.

Examples

  • Finds that required approval evidence is missing and pauses the next step for review.
  • Records a failed control with enough context for the process owner to assess the exposure.

IC2

Assesses workflow risk

Independently assesses operational risks in a team or workflow. Evaluates causes and consequences, proposes proportionate controls, and monitors whether treatment works as intended.

Observable behaviors

  • Describes a risk as a plausible event with causes and consequences.
  • Evaluates existing controls using available process evidence.
  • Designs treatment that is proportionate to the exposure.
  • Reviews monitoring evidence and changes treatment when needed.

Examples

  • Identifies a single-person dependency in a critical approval and introduces a documented backup path.
  • Finds that a control is performed too late to prevent the consequence and moves it earlier in the workflow.

IC3

Shapes cross-team risk practice

Leads operational risk work across connected teams or ambiguous processes. Aligns risk ownership, evaluates combined exposure and control tradeoffs, and establishes practices others use.

Observable behaviors

  • Frames risks that cross process or team boundaries.
  • Aligns owners on accountability for controls and remaining exposure.
  • Identifies control gaps, duplication, and unintended operational burden.
  • Creates reusable assessment, monitoring, and escalation practices.

Examples

  • Finds that separate team controls leave an unowned risk at the handoff and establishes one accountable owner.
  • Reviews overlapping controls across a process and removes duplication while preserving the intended protection.

Build your competency framework

Add operational risk to a Function, adjust the level expectations, and make risk evidence fair to assess.

Open the free builder

Common questions

What evidence supports an operational risk rating?

Use risk assessments, control designs, monitoring records, escalation decisions, incident learning, and evidence that treatment changed the exposure.

Does an incident prove weak operational risk work?

Not by itself. Some risks remain after treatment. Assess whether the risk was reasonably identified, owned, monitored, escalated, and learned from.

Should more controls mean a higher rating?

No. Controls should be proportionate and effective. Unnecessary or duplicated controls can add failure points and burden without reducing meaningful exposure.

Related resources

Competency catalog

Logistics coordination competency

Logistics coordination manages the timely movement of goods or resources across parties, locations, and constraints. This catalog progresses from tracking defined movements, to independently coordinating routes and exceptions, to improving multi-party logistics flows.

View competency

Competency catalog

Business continuity competency

Business continuity prepares and tests practical responses that keep critical work operating through disruption. This catalog progresses from following and maintaining plans, to owning continuity for a workflow, to coordinating responses across interdependent services.

View competency

Function template

Operations competency framework template

This Operations Function defines communication, ownership, process reliability, and cross-team coordination with evidence a manager can cite. Use it as a starting draft, then edit names, levels, and examples to match how your team actually works.

View template
Operational risk competency | Peasy HR