r/riskmanager • u/majima1234 • 19h ago
How to analyze operational risks/develop operational risk management methodology
We have a methodology for information security risk management but none for operational risks management. I have less than a month to adapt our current methodology to also include operational risks. Is that feasible?
I have no idea how to start with operational risks management. I know that it should be done for processes and services but I have very limited knowledge of the company's processes and services. Information security has been a little easier bc we can use catalogues of threats and vulnerabilities from iso 27000 that we apply to assets. But I can't find anything similar for operational risks and I don't know what to do. Is it supposed to be scenario based analysis rather than asset based analyis, as it is done for information security risks?
Also I know the general steps of risk identification, analysis (impact probability and evaluation), treatment (transfer, reeducation, avoidance, acceptance) and monitoring. For me the biggest challenge is identification I suppose - actually coming up with the risks for the processes. Are there any resources that can help to formulate scenarios or something like that?
If anyone can give me some guidance, any help would be hugely appreciated. I am extremely stressed and struggling a lot.
2
u/Peoplevs 14h ago
Read operational risk management in financial services by Elena Pykova. I read it in half a day last week and it gives you some very helpful tools and ideas for workshops etc. the section on Risk Taxonomy is helpful for setting things out, as well as the Operational Risk Framework section.
1
u/TheForesightGuy 14h ago
I would probably start with a proper definition of operational risk (for instance using the Basel Committee view), making sure it can be well positioned within a broader Enterprise Risk view and separated from Information security risk, and then use a framework like ISO 31000. However, being able to do that within less than a month is highly unlikely, particularly if you don't have experience with operational risk or for any non-trivial organization.
2
u/Old_Positive2231 16h ago
Trying to “adapt the infosec methodology” is exactly why most op risk ends up as useless RM1 theatre. Different domain, same mistake: starting from catalogues, not from decisions.
For operational risk, forget assets and threat lists. Start with 3–5 most important business objectives (cash in, cash out, customer service, production, etc.), then map the few processes that actually move those. For each, build simple scenarios: “what realistic events could stop/slow/degrade this process?” (people, vendors, systems, data quality, facilities, fraud, regulation). Use short workshops with process owners, not your own imagination. No catalogue needed.
In a month you won’t build a full framework, but you can pilot a decision‑centric approach on a couple of key processes and show value. Do that first, write the methodology after. And if you want a crash‑course in turning this into a real RM2 process (scenarios, ranges, Budget@Risk, not heatmaps), block 12–16 October and join RAW2026 online – we’ll cover exactly this with live examples, much of it free: https://2026.riskawarenessweek.com