Stay ahead with BCG insights on risk management and complianceManage Subscriptions

BCG’s Approach to Operational Risk and Resilience

Our take is simple: best-of-breed resilience risk management is a competitive advantage. It not only lets companies avoid disruption but also helps them streamline processes, improve operational resilience, and spark value—no easy feats. Successful resilience risk management requires the right governance, processes, roles, and culture. In short, it calls for an operating model for operational risk that is prepared to manage tomorrow’s uncertainty and enables the organization to innovate quickly.

To help companies, we have developed a unique operating model that combines deep experience in operational risk with expertise across functional and technical areas—everything fromorganization design togenerative AI. We work with organizations on every aspect of operational risk management, from risk taxonomy to end-to-end risk function transformation. It’s a holistic approach built around four steps.
Expand All
Embed operational risk management into the business strategy

Operational risk covers a lot of ground. It includes any risk arising from a company’s processes, people, and systems. It’s essential to understand where—and to what degree—perils lurk. We help clients develop a risk taxonomy, a set of relevant risk types, and use it to assess risks by probability and impact. This evaluation lets companies optimize their risk appetite—setting the right level of risk for every type of operational risk—and develop a risk strategy that aligns with their business strategy.

Establish operational risk governance and an organization structure

A key success factor in operational risk and resilience is having clarity on roles and responsibilities across the three lines of defense: managers on the ground, the risk function, and internal and external auditors. We help clients define decision rights and strike the right balance of delegation and control, so operational risk management can be effective without slowing down day-to-day business.

Implement a strong risk management framework

At the heart of an operating model for operational risk are the mechanisms for assessing, mitigating, and monitoring risk. We develop the processes, playbooks, reporting, and testing that help organizations zero in on potential and emerging risks—and take the right action at the right time. We identify where technology, such asrisk analytics andAI, can boost efficiency and effectiveness. And we create controls to ensure that the risk function runs as it should.

Leverage operational risk management enablers

People,technology, andculture are key ingredients—and potentially catalysts—in any risk management model. We help leaders set the tone from the top and establish a culture where operational resilience is a key strategic objective. And we unleash the power of data and AI to drive predictive analytics and fuel visual dashboards, so the right information gets before the right people at the right time—enabling faster, better decisions on operational risk.

Our Clients’ Success in Operational Risk and Resilience

~20%
cost reduction
Our operational risk consulting team reshaped the risk organization for a European bank, developing an action plan to boost effectiveness whilereducing costs by up to 20%. Key components included a new organization structure with defined responsibilities, governance that optimized interaction between the central risk group and the bank’s subsidiaries, and digital technologies that enhanced and simplified operational risk management.
11
new partners
We helped a fintech startupgrow its roster of partners from 14 to 25 and deploy three scorecards to assess customer profiles and risk, in only six months. We developed an end-to-end operational risk system, including structures and governance for its risk management function. BCG’s experts defined guardrails to expedite risk approvals, designed dashboards, and created rules for partnering with other fintechs.

Our Insights on Operational Risk and Operational Resilience

" "
As financial institutions become ever more reliant on technology, their tech teams must stay on top of key regulatory trends, including five that are critical today.
Reinventing Operations for What’s Next | BCG EDGE 2025
As costs swing and uncertainty grows, operational excellence is changing. Hear from BCG experts on how leaders reinvent operations for speed and flexibility.
Play Video
AI Related Risks_hero_rectangle.jpg
Operational risk management consulting experts debate how effectively organizations are adjusting risk management practices to govern AI.From MIT Sloan Management Review.
" "
Regulation of technology firms is increasing, especially in the AI arena. Tech leaders must build an effective compliance function that supports rather than hinders innovation.
 " "
Companies need a holistic strategy to coordinate requirements, clearly define responsibilities, and effectively use advanced technologies.
See more insights

Meet Our Operational Risk Consulting Team

Our risk management consulting leaders help clients manage operational risk and bolster operational resilience. Here are some of our experts.
meet more experts

Brian O'Malley

Managing Director & Partner
Minneapolis

Jeanne Kwong Bickford

Managing Director & Senior Partner
New York

Stefan Bochtler

Managing Director & Partner
Munich

Katharina Hefter

Managing Director & Partner
Berlin

Felix Hildebrand

Managing Director & Partner
Munich

Vanessa Lyon

Managing Director & Senior Partner
New York

Explore related services