Operational Risk Management features explained
for Risk Management
Every feature we track for Operational Risk Management products, with a description of what each one means.
Action Planning & Issue Remediation
Functionality to manage and track plans designed to remediate identified risk issues.
- Action Plan Registration
- Creation of distinct, trackable action plans tied to risks or findings.
- Automated Task Tracking
- Automatic monitoring and status updates of task completion.
- Automatic Escalation Rules
- Escalation to higher management based on custom criteria.
- Integration with Email
- Automated email notifications and reminders tied to action items.
- Number of Concurrent Action Plans
- Maximum active remediation plans supported.
- Overdue Action Alerts
- System notifications for overdue remediation actions.
- Progress Dashboard
- Visual dashboard for quick status and progress overview.
- Remediation Workflow
- Structured process for documenting, assigning, reviewing, and completing remediation tasks.
- Task Assignment
- Assignable remediation actions to users, with due dates and statuses.
Compliance & Regulatory Support
Ensures the product is aligned with current banking regulations and compliance requirements (e.g., Basel III/IV, SOX, GDPR).
- Audit Readiness Score
- Generates a score or readiness level for upcoming audits.
- Audit Trail for Compliance Activities
- Record all compliance-related actions for audit purposes.
- Automated Regulatory Filings
- Prepare and file required regulatory documentation automatically.
- Built-in Basel III/IV Templates
- Standardized templates for operational risk under Basel rules.
- Compliance Checklist Tools
- In-built checklist templates for key compliance requirements.
- E-Signature for Compliance
- Support digital signatures on compliance suites.
- GDPR/Privacy Controls
- Specific features to support data privacy laws (data restriction, deletion).
- Regulatory Update Alerts
- Notifies users of relevant changes in the regulatory landscape.
- Regulatory Workflow Automation
- Automate compliance-related workflows (e.g., attestation).
- SOX Control Mapping
- Map system controls and features to Sarbanes-Oxley sections.
Configuration & Customization
Flexibility to configure the system (forms, fields, workflows, rules) to match bank-specific operational risk processes.
- Conditional Logic in Forms
- Enable or disable fields based on user input.
- Configurable Data Fields
- Ability to add custom fields with validation rules.
- Configurable Workflows
- Define bespoke workflows per risk type or business unit.
- Custom Risk Metrics
- Create new risk indicators, metrics, and formulas.
- Customizable Forms & Templates
- Drag and drop or code-based form/template modifications.
- Localization Support
- Support for multiple languages, currencies, and regional settings.
- Number of Supported Languages
- Maximum number of user interface languages supported.
- User-defined Dashboards
- Users can create personalized dashboard layouts.
- White-label Branding
- Ability to brand the UI with bank logos, colors, and style.
Control Management
Facilitates identification, documentation, evaluation, and testing of internal controls meant to mitigate operational risk.
- Automated Alerts for Control Failures
- Immediate notification if a control test fails.
- Automated Control Testing
- Tools to test controls automatically and record results.
- Control Documentation & Versioning
- Maintain records and change versions of control documentation.
- Control Effectiveness Assessment
- Facilitates regular evaluation of control performance.
- Control Library
- Central repository for all operational controls setup in the system.
- Control Mapping to Risks
- Ability to link controls directly to risks they mitigate.
- Control Owner Assignment
- Assign responsibility for specific controls.
- Evidence Capture for Control Tests
- Upload or auto-link evidence for control testing results.
- Key Control Identification
- Flag critical controls essential to the risk framework.
- Test Scheduling & Reminders
- Automated scheduling and reminders for control testing.
Control Management & Testing
Features for tracking, evaluating, and monitoring operational controls.
- Automated Control Testing
- Integration or toolset for automated control validation (e.g., data-driven checks).
- Control Change Management
- Audit trail and workflow for changes to control definitions.
- Control Design Assessment
- Evaluation of control design versus implementation effectiveness.
- Control Effectiveness Assessment
- Built-in tools for periodic control testing and review.
- Control Library
- Centralized registry of controls with descriptions and owners.
- Control Owner Assignment
- Designation of responsible individuals or teams for each control.
- Control-Process Mapping
- Mapping controls to specific business processes or risks.
- Deficiency Tracking
- Workflow to log, manage, and resolve failed control tests.
- Number of Controls
- Maximum controls supported in the library.
- Test Scheduling & Reminders
- Automated scheduling and reminders for future control tests.
Data Integrity & Audit Trails
Features to ensure data entered into the system is accurate, traceable, and tamper-proof, supporting accountability and compliance.
- Automated Data Backups
- System automatically backs up critical data on a scheduled basis.
- Change Tracking Granularity
- Level of detail for every change (field, user, timestamp).
- Comprehensive Audit Logs
- Detailed records of all system activity, changes, and data edits.
- Data Reconciliation Tools
- Ability to compare and reconcile internal data with external or legacy sources.
- Data Validation Rules
- Automated checks that validate data input against set business rules.
- Digital Signatures
- Support for cryptographic signing of records or transactions.
- Historical Data Versioning
- Ability to retrieve and review previous versions of data records.
- Immutable Data Storage
- Ensures data cannot be modified once written, supporting regulatory requirements.
- Tamper Alerts
- Detection and notification of unauthorized data changes.
- Time-stamping of Transactions
- Record the exact times for all key user actions.
Incident Management & Loss Event Capture
Tools for capturing, tracking, analyzing, and managing operational risk incidents and losses.
- Data Quality Checks
- Automated validation rules for ensuring incident data completeness.
- Drag-and-Drop Attachments
- Support for adding documents, images, or other files to incidents.
- Incident Capture Interface
- Intuitive interface for employees to report risk events or incidents.
- Incident Categorization
- Customizable categories and subcategories for classifying incidents.
- Incident Notification Rules
- Customizable automated notifications to stakeholders.
- Incident Severity Scoring
- Automated or manual assignment of incident severity levels.
- Incident Workflow Automation
- Configurable workflows for investigation, review, and closure.
- Loss Data Collection
- Capability to record actual and potential financial losses and recoveries.
- Regulatory Reporting Interface
- Direct output or uploads for regulatory bodies (e.g., Basel loss database).
- Root Cause Analysis Toolkit
- Tools to facilitate deep-dive analysis of incident causes.
- Time to Resolution Tracking
- Measured time from incident capture to closure.
Integration & Interoperability
Features to ensure the risk system connects and shares data securely with other critical banking, HR, and IT systems.
- API Access
- Secure REST or SOAP APIs for data ingestion and extraction.
- Custom ETL Tools
- Extract, transform, and load tools specifically for operational risk use-cases.
- Data Enrichment from External Sources
- Augment risk data automatically with additional context from external systems.
- Data Import/Export Scheduler
- Automate periodic data imports and exports.
- ERP/Core Banking System Integration
- Seamless transfer of data to/from main banking operational platforms.
- External Audit Tool Compatibility
- Direct interface for external auditors to pull necessary reports.
- Identity Provider Integration
- Works with enterprise identity and access management systems.
- Single Sign-On (SSO) Support
- Allows consistent logins across platforms with centralized security.
- Third-party Risk Data Integration
- Incorporate risk data feeds from external vendors.
- Webhooks for Notifications
- Push system alerts and events to other applications instantly.
Integration & Interoperability
Features supporting system integration, interoperability, and data exchange across the organization’s ecosystem.
- API Access (REST/SOAP)
- Secure, documented APIs for data exchange.
- Custom Field Mapping
- Flexible mapping for custom data fields in integrations.
- Data Import/Export Tools
- Bulk import/export tools for connecting with legacy systems.
- Flat File Uploads
- Support for uploading flat files in structured formats (e.g., CSV, XML).
- Integration Throughput
- Number of integration transactions per second supported.
- On-premises/Cloud Data Sync
- Works with both cloud and on-premises systems for data exchange.
- Pre-built Integrations
- Out-of-the-box connectors to common banking, HR, or GRC systems.
- Real-time Data Sync
- Support for on-the-fly synchronization with core banking or data warehouses.
Regulatory Compliance Management
Support compliance with global and regional operational risk regulations and frameworks.
- Audit Trail Maintenance
- Immutable, timestamped logs of all compliance-related actions.
- Automated Policy Distribution
- Distribution and acknowledgment workflows for updated policies.
- Compliance Calendar
- Scheduling and reminders for key compliance activities.
- Compliance Status Dashboard
- Visual overview of current compliance status.
- Document Repository
- Centralized compliance document storage with version control.
- Evidence Collection Tools
- Facilitates efficient attachment/upload of compliance evidence.
- Pre-configured Compliance Templates
- Standard templates for common regulatory directives (e.g., Basel, SOX, GDPR, DORA).
- Remediation Tracking
- Track issues identified during regulatory reviews and audits.
Reporting & Analytics
Powerful reporting engines to offer insights into the operational risk landscape, and support regulatory and internal reporting.
- Ad-hoc Report Builder
- Users can create customized reports using system data.
- Dashboard Visualization
- Visual dashboards providing at-a-glance status of key metrics.
- Data Retention Controls
- Configure how long historical reports and data are kept.
- Drill-down Analytics
- Click-through for detailed breakdowns of aggregate figures.
- Export to Excel/PDF/CSV
- Ability to export reports in multiple standard formats.
- Interactive Visualizations
- Users can manipulate charts and visuals to slice and dice data.
- Real-time Data Refresh
- Reports draw from live system data with fast refresh rates.
- Scheduled Reports
- Automate regular report delivery to users and stakeholders.
- Standard Regulatory Reports
- Pre-built templates for required compliance and regulatory reports.
- Trend Analysis
- Identify risk trends over time, including seasonality.
Reporting & Analytics
Robust analytics suite and flexible reporting tools for regulatory, management, and board reporting.
- Ad Hoc Query Capability
- Support for user-defined, on-the-fly data queries.
- Automated Risk Metric Calculation
- Built-in formulas and scripts for common operational risk metrics.
- Custom Report Builder
- Drag-and-drop or code-based custom report creation.
- Drill-down Analytics
- Ability to drill down from summary views to detailed records.
- Export Formats
- Supported formats for exports (e.g., PDF, Excel, XML, CSV).
- Interactive Dashboards
- Customizable, real-time dashboards with graphical visualizations.
- KRI/KPI Dashboards
- Key Risk and Key Performance Indicator dashboards.
- Number of Concurrent Report Users
- Maximum users who can simultaneously generate reports.
- Pre-built Regulatory Reports
- Templates and workflows for common risk management regulatory reports (e.g., Basel II/III, SOX).
- Predictive Analytics
- Advanced analytics for risk scoring and scenario forecasting.
- Scheduled Report Delivery
- Automated generation and delivery of reports per predefined schedules.
Risk & Incident Reporting
Functionality enables the timely identification, categorization, and escalation of operational risk events and near misses.
- Anonymous Reporting Capability
- Users can report incidents without disclosing their identity.
- Attachment & Evidence Uploads
- Allows supporting files to be attached to incident records.
- Automated Escalation
- System can route incidents to the appropriate level of management based on severity.
- Customizable Incident Taxonomy
- Ability to define and adjust categories for risk events.
- Event Timeline Visualization
- Timeline view of incident events and steps taken.
- Incident Severity Scoring
- Grading system to quickly assess and prioritize incidents.
- Incident Status Tracking
- Monitor progress of incidents from reporting to resolution.
- Management Commenting & Collaboration
- Enables managers to comment and collaborate on incident investigations.
- Real-time Incident Reporting
- Allows users to report incidents as soon as they occur.
- Root Cause Analysis Tools
- Built-in methods to help determine why an incident occurred.
Risk Assessment & Evaluation
Tools for periodic assessment of operational risks including risk identification, scoring, and management.
- Automated Risk Scoring
- Automatically updates risk scores based on input data and thresholds.
- Bulk Risk Assessment Uploads
- Import risk assessments in bulk from external files.
- Customizable Risk Scoring Matrix
- Ability to define framework for likelihood and impact scoring.
- Key Risk Indicator (KRI) Tracking
- Monitor and track key operational risk indicators.
- Mitigation Action Tracking
- Track progress of action plans to address operational risks.
- Periodic Review Scheduling
- Schedule and track completion of risk reviews.
- Residual Risk Calculation
- System calculates risk after controls are applied.
- Risk Appetite Setting
- Configure thresholds for acceptable risk across categories.
- Risk Heat Maps
- Visual representation of risk likelihood versus impact.
- Risk Register Management
- Centralized registry for all identified operational risks.
Risk Identification & Assessment
Features to identify, record, assess, score, and classify operational risks.
- Automated Risk Alerts
- System alerts for newly logged or updated risks based on defined criteria.
- Bulk Risk Import
- Ability to import risk data from external sources (e.g., CSV, Excel).
- Historical Risk Database
- Archive of resolved, closed, or past risks for analytics.
- Inherent & Residual Risk Calculation
- Ability to calculate and compare inherent and residual risk levels.
- Number of Risk Attributes
- Maximum customizable fields for risk attributes.
- Risk Assessment Frequency
- Frequency with which risks can be periodically re-assessed.
- Risk Mapping
- Visual mapping of risks to processes, departments, products, etc.
- Risk Register
- Centralized repository for all identified risks.
- Risk Scoring Model
- Built-in quantitative and qualitative risk scoring/calculation.
- Risk Taxonomy Customization
- Configurable categories/types of operational risk.
- Scenario Analysis Capability
- Supports what-if and scenario analysis for risk events.
Risk Notification & Escalation
Tools for ensuring timely alerts, notifications, and escalation of operational risk-related events to the right people.
- Custom Escalation Matrix
- Configurable rules for whom to notify and escalate at each risk threshold.
- Customizable Alert Templates
- Define alert content and appearance for various risk types.
- Email & SMS Alerts
- Critical risk events can generate email/SMS alerts based on severity.
- Escalation Tracking Log
- Historical logs indicate all escalations made and handled.
- Executive Dashboard Alerts
- High-severity risks appear prominently on executive dashboards.
- Integration with Incident Management
- Seamless transition from alert to incident management workflow.
- Mobile Push Notifications
- Send alerts to mobile devices of key personnel.
- Prioritized Alerting
- Alert urgency and delivery methods adjust by risk classification.
- Real-time System Notifications
- Instant, in-system notifications for key risk events.
- Redundancy Controls for Alerts
- Backup methods to ensure critical alerts are never missed.
Scalability, Performance & Support
Ensures the product can handle large volumes of data and users with high reliability; includes support services.
- Concurrent User Capacity
- Number of users who can actively use the system at once.
- Data Retention Policy Support
- Configurable support for long-term data retention based on bank requirements.
- Dedicated Customer Support Team
- Direct access to support engineers familiar with operational risk and banking.
- Disaster Recovery (DR) Capability
- Automated data backup and disaster recovery procedures.
- Incident Response SLA
- Maximum guaranteed time for support incident response.
- Mobile-responsive UI
- System accessibility from smartphones and tablets.
- Performance Monitoring Tools
- Built-in dashboards for tracking system health, latency, and capacity.
- Release Management
- Structured process for regular software updates and hotfixes.
- System Uptime Commitment
- Guaranteed percentage of uptime (availability) per year.
- Training Material Availability
- Availability of online or in-person user training resources.
Security & Reliability
Core technical features to ensure data is secure, system is reliable, and business continuity is maintained.
- Access Logging & Monitoring
- All access and actions are logged and monitored for anomalies.
- Average Recovery Time Objective (RTO)
- The typical time needed to restore system functionality after a disruption.
- Cybersecurity Incident Monitoring
- Real-time alerts and logs for suspicious activity.
- Disaster Recovery Planning
- Disaster recovery processes are defined, tested, and supported.
- Full Data Encryption
- Data is encrypted at rest and in transit.
- High Availability Architecture
- System design allows for minimal downtime and quick recovery.
- Penetration Testing Support
- Platform allows for or supports regular pen testing.
- Redundancy & Failover Mechanisms
- Systems in place to handle hardware or network failure automatically.
- Service Level Uptime
- Percentage of time the system is guaranteed to be available.
- Vulnerability Scanning
- Automatic scanning for security vulnerabilities.
User Access Controls
Mechanisms for managing, monitoring, and restricting access to sensitive data and functions. Essential for limiting operational risk from unauthorized actions.
- Access Request Workflow Automation
- Automates the process for users to request and obtain access based on workflows.
- Audit Trails on Access Changes
- Automatic logs of all changes made to user permissions and access rights.
- Failed Login Attempt Monitoring
- Records and alerts on multiple failed login attempts.
- Granular Permission Levels
- Ability to define very specific access rights at module, data, or transaction level.
- Multi-factor Authentication
- Requires multiple forms of verification before access is granted to the system.
- Real-time Access Revocation
- Ability to revoke user access instantly.
- Role-based Access Control
- Allocation of access permissions based on the user's role in the organization.
- Session Timeout Controls
- Automatic logoff users after a period of inactivity.
- Single Sign-On (SSO) Integration
- Enables users to access multiple applications with one set of credentials securely.
- User Access Review & Certification
- Periodic verification and re-certification of users’ access rights.
User Access and Security
Ensure secure, role-based access to the system and data, protecting sensitive financial and operational information.
- Audit Logging
- Comprehensive logs of all user actions and system changes.
- Change Management Workflow
- Structured workflow for reviewing and approving permission changes.
- Data Encryption at Rest
- All data is encrypted while stored.
- Data Encryption in Transit
- All transmitted data is encrypted.
- IP Whitelisting/Blacklisting
- Restriction or permission of access from specific IP addresses.
- Multi-factor Authentication
- Optional requirement for multi-factor user authentication.
- Number of User Profiles
- Maximum supported user accounts concurrently active.
- Password Policy Enforcement
- Customizable password strength and rotation policies.
- Role-based Access Control
- Ability to assign granular permissions to specific user roles (e.g., analyst, manager, auditor).
- Security Certification
- Holds industry security certifications (e.g., ISO 27001, SOC 2).
- Single Sign-On (SSO)
- Supports single sign-on with popular identity providers.
- User Session Timeout
- Automatic logoff after a set period of inactivity.
Workflow & Automation
Automate the risk management lifecycle, enforcing processes and improving efficiency.
- Approval Hierarchies
- Multi-level, role-based approval flows for key actions.
- Automated Notifications
- Email, SMS, or in-app notifications based on user-defined criteria.
- Custom Workflow Designer
- Graphical or code-based tool to create and update workflows.
- Escalation Rules
- Escalation paths and levels for unresolved issues.
- Event-driven Automation
- Triggers based on events (e.g., risk submission, incident closure) for automation.
- Integration APIs
- APIs for integration with HR, compliance, core banking, and third-party tools.
- Integration with Ticketing Tools
- Ability to send/receive tasks to systems like JIRA/ServiceNow.
- Number of Automated Workflows
- Maximum distinct automation workflows configured.
- Re-assignment Capabilities
- Easily reassign tasks or issues based on workload.
Workflow & Task Automation
Automate common processes and tasks in the operational risk management lifecycle to improve efficiency and consistency.
- Approval Workflow Customization
- Define multi-step approvals for key risk processes.
- Automated Escalation Paths
- Escalate overdue or critical tasks as per preset rules.
- Automated Notifications
- Automatic email, SMS, or in-application alerts for tasks and deadlines.
- Bulk Task Management
- Ability to manage and update tasks in bulk.
- Calendar Integration
- Seamless integration with corporate calendars for scheduling reviews, tasks, or meetings.
- Rule-driven Workflow Engine
- Automated routing/regulation of processes based on defined business rules.
- SLA Enforcement Mechanisms
- Monitor and enforce Service Level Agreements on process tasks.
- Task Assignment Automation
- Assign tasks to relevant parties based on workflow configuration.
- Task Completion Tracking
- Comprehensive tracking of task status and completions.
- Template-based Task Creation
- Create and deploy recurring tasks from templates.