Operational risk: fundamentals, controls, and decisions
Six lessons, 24 questions, and eight operational-risk cases: RCSA, controls, incidents, indicators, acceptance, providers, and resilience.
Objectives and progression
Independent professional pathway for applying operational-risk fundamentals to IT projects, APS, and financial services. Six modules connect accountability, RCSA, control evidence, near misses, response, indicators, temporary exceptions, change, external dependencies, and resilience. Includes 24 questions and eight original cases with explanations for every option. Internal assessment of 26 decisions in 60 minutes. BCBS, IIA, NIST, FSB, ECB, and AWS sources with explicit versions and limits. Distinguishes task execution, control effectiveness, and authorized acceptance of exposure. This is not external certification or institutional compliance validation.
Audience: IT project managers, APS and RUN teams, L3 support, and professionals collaborating with risk, control, and audit.
Prerequisites: Basic IT project and operations knowledge. Cases use synthetic limits and require no banking data or reporting-system access.
270 estimated study minutes
- Describe operational exposure and assign execution, oversight, and decisions to the correct roles.
- Distinguish inherent risk, demonstrated controls, and residual exposure with explicit uncertainty.
- Preserve facts and learn from losses, failures, and prevented events.
- Use indicators that reveal exposure and support decisions with owners and deadlines.
- Assess change lifecycle, provider concentration, and continuity and exit horizons.
- Demonstrate recoverable service and turn exercises into verifiable actions.
Modules
- Scope, governance, and accountability
- Risk assessment and control effectiveness
- Events, near misses, and response
- Indicators, reporting, and acceptance
- Change and external dependencies
- Resilience, scenarios, and improvement
Continue learning
- Banking infrastructure: professional fundamentals assessment
- Incident Management
- Change Management
- Disaster Recovery
- PMI-RMP — Risk Management Professional
References and version
DR operational risk professional assessment2026.10
- Revisions to the principles for the sound management of operational risk · 2026-10-01
- Operational risk principles publication status · 2026-10-01
- Three Lines Model: Assurance and Advice in Support of Effective Governance · 2026-10-01
- Statements of Position · 2026-10-01
- Guide for Conducting Risk Assessments · 2026-10-01
- SP800-30 Revision1 publication · 2026-10-01
- Incident Response Recommendations and Considerations for Cybersecurity Risk Management · 2026-10-01
- SP800-61 Revision3 publication · 2026-10-01
- Enhancing Third-Party Risk Management and Oversight: A toolkit · 2026-10-01
- Final report on enhancing third-party risk management and oversight · 2026-10-01
- Principles for operational resilience · 2026-10-01
- ECB Guide on outsourcing cloud services · 2026-10-01
- OPS7 Operational readiness · 2026-10-01
- NIST SP800-40 Revision4 · 2026-10-01
What you will explore
0 / 6Scope, governance, and accountability
Describe operational exposure and assign execution, oversight, and decisions to the correct roles.
Risk assessment and control effectiveness
Distinguish inherent risk, demonstrated controls, and residual exposure with explicit uncertainty.
Events, near misses, and response
Preserve facts and learn from losses, failures, and prevented events.
Indicators, reporting, and acceptance
Use indicators that reveal exposure and support decisions with owners and deadlines.
Change and external dependencies
Assess change lifecycle, provider concentration, and continuity and exit horizons.
Resilience, scenarios, and improvement
Demonstrate recoverable service and turn exercises into verifiable actions.