Operational Risk Management: Regulatory Framework and Operational Impact

  • Paola Leone
  • Pasqualina PorrettaEmail author
Part of the Palgrave Macmillan Studies in Banking and Financial Institutions book series (SBFI)


Banks must establish an independent Operational Risk Management function aimed at defining policies, procedures and methodologies for identifying, measuring, monitoring and controlling operational risks. In this perspective, this chapter analyses (a) the regulatory framework on the operational capital requirement; (b) the regulatory view on Operational Risk Management; and (c) the new Supervisory Review and Evaluation Process (SREP) in relation to operational risk. The chapter also attempts to propose an integrated approach able to defining, managing, monitoring and reporting operational losses together with capital planning, ICAAP (Internal Capital Adequacy Assessment Process), RAF (Risk Appetite Framework) and risk culture of financial intermediaries also in accordance with the new SREP perspective.


Operational regulatory framework Operational risk management Operational Risk Supervision New SREP 


  1. Bank of Italy. (2013). Circolare 285/2013. Disposizioni di vigilanza per le banche.
  2. BCBS. (1998). Operational Risk Management. Basel Committee on Banking Supervision.
  3. BCBS. (2001a). Operational Risk. Supporting Document to the New Basel Capital Accord. Basel Committee on Banking Supervision, Consultative Document.
  4. BCBS. (2001b). The Internal Ratings-Based Approach. Basel Committee on Banking Supervision, Consultative Document.
  5. BCBS. (2004). International Convergence of Capital Measurement and Capital Standards. Basel Committee on Banking Supervision.
  6. BCBS. (2006). International Convergence of Capital Measurement and Capital Standards: A Revised Framework. Comprehensive Version, Basel Committee on Banking Supervision.
  7. BCBS. (2009a). Observed Range of Practice in Key Elements of Advanced Measurement Approaches (AMA). Basel Committee on Banking Supervision.
  8. BCBS. (2009b). Results from the 2008 Loss Data Collection Exercise for Operational Risk. Basel Committee on Banking Supervision.
  9. BCBS. (2011a). Operational Risk—Supervisory Guidelines for the Advanced Measurement Approaches. Basel Committee on Banking Supervision.
  10. BCBS. (2011b). Principles for the Sound Management of Operational Risk. Basel Committee on Banking Supervision.
  11. BCBS. (2014). Operational Risk—Revisions to the Simpler Approaches. Basel Committee on Banking Supervision, Consultative Document.
  12. BCBS. (2016). Standardised Measurement Approach for operational Risk. Basel Committee on Banking Supervision, Consultative Document, March.
  13. Bee, M. (2005). On Maximum Likelihood Estimation of Operational Loss Distributions. University of Trento Department of Economics Working Paper, (2005-03).Google Scholar
  14. Birindelli, G., & Ferretti, P. (2009). Il rischio operativo nelle banche italiane. Modelli, gestione e disclosure. Bancaria editrice.Google Scholar
  15. Birindelli, G., & Ferretti, P. (2017). Operational Risk Management in Banks. Palgrave Macmillan.Google Scholar
  16. Borra, S., & Di Ciaccio, A. (2008). Statistica. Metodologie per le scienze economiche e sociali. McGraw-Hill.Google Scholar
  17. Cavallo, A., Rosenthal, B., Wang, X., & Yan, J. (2012). Treatment of the data collection threshold in operational risk: A case study with the lognormal distribution. The Journal of Operational Risk, 7(1), pp. 3–38.Google Scholar
  18. Chapelle. (2013). The Importance Preventive KRIs. Operational Risk & Regulation, No. 58.Google Scholar
  19. Cope, E. W., Mignola, G., Antonini, G., & Ugoccioni, R. (2009). Challenges and pitfalls in measuring operational risk from loss data. The Journal of Operational Risk, 4(4), No. 3, pp. 3–38.Google Scholar
  20. Cornalba, C., & Giudici, P. (2004). Statistical models for operational risk management. Physica A: Statistical Mechanics and its Applications, 338(1), pp. 166–172.Google Scholar
  21. Cosma, S. (2006). La misurazione del rischio operativo nelle banche: Basilea 2, regole nazionali ed europee, approcci, modelli e tecniche innovativi. Bancaria editrice.Google Scholar
  22. Cosma, S., Dell’Anna, L., & Salvadori, G. (2014). Dal Risk Self Assessment alla stima del Value-at-Risk operativo: una proposta metodologica. Bancaria, No. 11.Google Scholar
  23. Cruz, M. G. (2002). Modeling, Measuring and Hedging Operational Risk. Wiley-Finance.Google Scholar
  24. Cruz, M. G. (2004). Operational Risk Modelling and Analysis: Theory and Practice. London: Risk Books.Google Scholar
  25. Cruz, M., Peters, G., & Shevchenko, P. (2015). Fundamental Aspects of Operational Risk and Insurance Analytics: A Handbook of Operational Risk. USA: Wiley-Finance.Google Scholar
  26. De Polis, S. (2015). L’approccio di vigilanza alla funzione organizzazione nelle banche: tra business ed esigenze di governo. L’uscita dall’eclissi parziale. Banca d’Italia.
  27. EBA. (2014). Guidelines on Common Procedures and Methodologies for the Supervisory Review and Evaluation Process. European Banking Authority.
  28. EBA. (2015). RTS on AMA Assessment. European Banking Authority.
  29. EBA. (2016). Guidelines on ICAAP and ILAAP Information Collected for SREP Purposes. European Banking Authority.
  30. ECB. (2016). SSM SREP Methodology Booklet. European Central Bank.
  31. Embrechts, P., & Puccetti, G. (2008). Aggregating risk across matrix structured loss data: The case of operational risk. Journal of Operational Risk, 3(2), pp. 29–44.Google Scholar
  32. Embrechts, P., Furrer, H., & Kaufmann, R. (2003). Quantifying regulatory capital for operational risk. Derivatives Use, Trading and Regulation, 9(3), pp. 217–233.Google Scholar
  33. European Parliament and Council. (2013). Directive 2013/36/EU on access to the activity of credit institutions and the prudential supervision of credit institutions and investment firms, amending Directive 2002/87/EC.
  34. European Parliament and Council. (2013). Regulation (EU) No 575/2013 on prudential requirements for credit institutions and investment firms and amending Regulation (EU) No 648/2012.
  35. Figini, S., Gao, L., & Giudici, P. (2013). Bayesian operational risk models. Department of Economics and Management, University of Pavia, 47.Google Scholar
  36. Franzetti, C. (2016). Operational Risk Modelling and Management. CRC Press Book.Google Scholar
  37. Girling, P. X. (2013). Operational Risk Management: A Complete Guide to a Successful Operational Risk Framework. USA: Wiley-Finance.Google Scholar
  38. Giudici, P. (2004). Integration of qualitative and quantitative operational risk data: A Bayesian approach. Operational Risk Modelling and Analysis, Theory and Practice (pp. 131–138). London: RISK Books.Google Scholar
  39. Guegan, D., & Hassani, B. K. (2013). Operational risk: A Basel II step before Basel III. Journal of Risk Management in Financial Institutions, 6(1), pp. 37–53.Google Scholar
  40. Gustafsson, J., & Nielsen, J. P. (2008). A mixing model for operational risk. Journal of Operational Risk, 3(3), pp. 25–38.Google Scholar
  41. Hillson, D. A., & Hulett, D. T. (2004). Assessing risk probability: Alternative approaches. PMI Global Congress Proceeding (pp. 1–5). Czech Republic, Prague.Google Scholar
  42. Ieva, F., Paganoni, A. M., & Ziller, S. (2013). Operational risk management: A statistical perspective. Far East Journal of Mathematical Sciences, No. 23.Google Scholar
  43. Jarrow, R. A. (2008). Operational risk. Journal of Banking & Finance, 32(5), pp. 870–879.Google Scholar
  44. Jobst, A. (2007). Operational Risk: The Sting is Still in the Tail But the Poison Depends on the Dose. International Monetary Fund, pp. 7–239.Google Scholar
  45. King, J. L. (2001). Operational Risk: Measurements and Modelling. USA: Wiley.Google Scholar
  46. Lamanda, G. (2011). Regulation and practice of managing the banks operational risks. Ph.D. thesis, Budapest University of Technology and Economics.Google Scholar
  47. Lamanda, G., & Võneki, Z. T. (2015). Hungry for risk. A risk appetite framework for operational risks. Public Finance Quarterly, 60(2), pp. 212–225.Google Scholar
  48. Leadbetter, M. R. (1991). On a basis for peaks over threshold modeling. Statistics & Probability Letters, 12(4), pp. 357–362.Google Scholar
  49. Lopez, J. A. (2002). What is operational risk. FRBSF Economic Letter, 2, pp. 1–4.Google Scholar
  50. Moosa, I. A. (2007a). Operational risk: A survey. Financial Markets, Institutions & Instruments, 16(4), pp. 167–200.Google Scholar
  51. Moosa, I. A. (2007b). Misconceptions about operational risk. Journal of Operational Risk 1(Winter), pp. 97–104.Google Scholar
  52. Moosa, I. A. (2007c). Operational Risk Management. London: Palgrave.Google Scholar
  53. Moosa, I. A. (2007d). A Critique of the Advanced Measurement Approach to Regulatory Capital Against Operational Risk (Working paper). Monash University.Google Scholar
  54. Moscadelli, M. (2004). The modelling of operational risk: Experience with the analysis of the data collected by the Basel Committee. Bank of Italy, Economic Research and International Relations Area, No. 517.Google Scholar
  55. Neil, M., Häger, D., & Andersen, L. B. (2009). Modeling operational risk in financial institutions using hybrid dynamic Bayesian networks. The Journal of Operational Risk, 4(1), No. 3.Google Scholar
  56. Peters, G. W., Shevchenko, P. V., Hassani, B. K., & Chapelle, A. (2016). Standardized Measurement Approach for Operational risk: Pros and Cons. Université Panthéon-Sorbonne (Paris 1), Centre d’Economie de la Sorbonne, No. 16064.Google Scholar
  57. Robertson, D. (2016). Managing Operational Risk: Practical Strategies to Identify and Mitigate Operational Risk Within Financial Institutions. London, UK: Palgrave Macmillan.Google Scholar
  58. Rozenfeld, I. (2010). Using shifted distributions in computing operational risk capital. Available at SSRN:
  59. Shevchenko, P. V. (2011). Modelling Operational Risk Using Bayesian Inference. Springer Science & Business Media.Google Scholar
  60. Sklar, M. (1959). Fonctions de répartition à n dimensions et leurs marges. Université Paris, No. 8.Google Scholar
  61. SSG. (2009). Risk Management Lessons from the Global Banking Crisis of 2008. Senior Supervisors Group.
  62. Valová, I. (2011). Basel II approaches for the calculation of the regulatory capital for operational risk. Masaryk University, Faculty of Economics and Administration.Google Scholar
  63. Vinella, P., & Jin, J. (2005). A foundation for KPI and KRI. Operational Risk: Practical Approaches to Implementation (pp. 157–168).Google Scholar

Copyright information

© The Author(s) 2018

Authors and Affiliations

  1. 1.Sapienza University of RomeRomeItaly

Personalised recommendations