← Operational risk: fundamentals, controls, and decisions
10 / 10 · 60 MIN

Treatment, exceptions, and risk acceptance

Turn mitigation proposals into executable, monitored decisions bounded by what has been demonstrated.

Connect response to the risk mechanism

Start with what the proposal changes. Blocking may reduce occurrence; faster recovery may reduce duration after failure has already happened. Insurance may compensate part of financial loss without executing the interrupted service. Avoiding an activity may remove an exposure source while affecting business objectives. NIST SP 800-39 describes risk response and monitoring in an information-security context. In this workshop, those concepts help structure original APS decisions. Do not assume that a label such as mitigate or transfer proves that the intended effect has been achieved. The proposed mechanism needs its own evidence.

Separate current residual from target

A funded change may not yet be installed, and an installation may not yet have been tested. Show current exposure, response in progress, and target residual separately. For each milestone, record an owner, dependencies, resources, and expected evidence. Reconciliation automation may reduce manual work while replicating an incorrect rule across every fund; assess reach, detection, recovery, and criteria before wider use. The plan should also include transition-period exposure. Reserved funding or an approved date does not replace effectiveness observation, and a favorable provider report does not remove dependencies excluded from its scope.

Define conditions that remain true

The teaching exception requires approval, service A, volume up to one hundred, active mitigation, and a time inside the window. Conditions are cumulative. An unexpired date does not permit volume 101 or service B. If the reconciliation team becomes unavailable, mitigation ceases to be demonstrated even with volume eighty. The model checks these fields to teach reasoning; it is not an authorization engine. An actual decision needs its own rules and authority. The record should identify who monitors conditions, which change triggers review, and which alternative will be proposed if promised capacity disappears.

Compare options with the right authority

Two equal scores can hide different exposure timelines. A limit exceeded tomorrow calls for different analysis from a funded correction planned for next month. Present consequences, constraints, costs, capacity, and alternatives without choosing only the easiest risk to close. The PM may coordinate work and recommend, but that does not grant acceptance beyond delegated authority. Prepare a clear decision: continue under conditions, restrict, defer, or choose another response. Record the reason and the next review point. Also identify commitments affecting other services so exposure is not displaced without becoming visible.

Monitor context changes

Do not wait for the monthly meeting when the condition supporting a response has ceased to exist. Volume, team, provider, configuration, or criticality can change the assessment. Monitoring should observe implementation, effect, and context. If the model predicted five hours with four reviewers and two were reassigned, recalculate and communicate impact before the deadline. If a report excludes the recovery subcontractor, retain the value of included scope and seek evidence for the missing part. Dependency analysis in the December 2023 FSB toolkit frames this care; it creates no universal minimum-provider-count rule.

Close with a reconstructible decision

In the workshop, prepare an English decision page containing outcome, exposure, options, assumptions, required evidence, authority, and a review trigger. Use the program to repeat calculations and explain limits. Its thirty-two checks show that defined examples produce expected results; they certify no controls and demonstrate no actual recovery. For treatment closure, compare observed effect against agreed criteria and present remaining exposure to the competent authority. The course reaches bank quantity lower targets after this expansion but still needs independent review and facilitated workshops. None of these cases describes BNP Paribas procedures.

OFICINA / WORKSHOP: 45 minutos / 45 minutes
Cenários fictícios, sem autorizar ações reais / Fictional scenarios, no authorization of real actions.
0-8: python3 run.py --output evidence.json
 Explicar o âmbito dos 32 checks / Explain the scope of the 32 checks.
8-18: timeline=15+20+40+25; target=90.
 improvement=5+10+40+20; slower_restore=70.
 Distinguir cálculo, hipótese e observação / Separate calculation, assumption, observation.
18-28: backlog=200; arrivals=20/h; reviewer=15/h; deadline=6h.
 Comparar três e quatro revisores / Compare three and four reviewers.
 Listar disponibilidade, competências, pausas e retrabalho a validar.
 List availability, skills, breaks, and rework requiring validation.
28-38: exception: service-A, volume<=100, active mitigation, start<=now<expires.
 Identificar efeito de volume=101, serviço B ou equipa indisponível.
 Identify effect of volume=101, service B, or unavailable team.
38-45: Redigir em inglês / Write in English:
 Required outcome / current exposure / response options / assumptions /
 evidence required / decision authority / review trigger / next checkpoint.
Não declarar o exercício como restauro real, previsão ou aceitação de risco.
Do not present the exercise as actual restoration, forecasting, or risk acceptance.
IN PRACTICE

Example: the exception retains a valid date and volume but loses the reconciliation team. Reporting requests a new decision on the mitigation condition.

Common pitfalls

Treating funding as effectiveness; ignoring a lost condition; promising capacity from roster names alone; accepting risk beyond assigned delegation.

Related topics: Risk assessment and control effectiveness · Change and external dependencies · Resilience, scenarios, and improvement

Take this idea with you

Treatment needs demonstrated effect, monitored conditions, and a competent decision on remaining exposure.

Create account

Reference: Managing Information Security Risk: Organization, Mission, and Information System View · BigSavant operational risk professional assessment2026.10