APPROACHES TO OPERATIONAL RISK ASSESSMENT IN FINANCIAL INSTITUTIONS

Authors

DOI:

https://doi.org/10.31732/2663-2209-2026-82-253-266

Keywords:

operational risk, operational risk assessment, quantitative approaches, qualitative approaches, hybrid approaches

Abstract

The article examines approaches to assessing operational risk in financial institutions, with an emphasis on quantitative, qualitative and hybrid methods in the context of rising uncertainty driven by military, geopolitical, technological and regulatory factors. Theoretical foundations of traditional metrics (the product of probability and loss severity), contemporary statistical approaches (loss distribution modeling, Value at Risk) and a set of qualitative instruments (expert judgment, scenario analysis, root‑cause analysis, etc.) are considered, as well as their combinations within hybrid approaches for constructing a comprehensive risk profile of a financial institution. It is argued that the quantitative approach provides measurability and comparability of results but its applicability is constrained by the quality and sufficiency of historical data; the qualitative approach enables identification and assessment of specific risk events including non‑financial ones, but is inherently subjective; the hybrid approach combines the strengths of both, striking a balance between statistical precision and expert interpretation of results. The advantages and limitations of modern methods (LDA, VaR) are demonstrated, notably their capacity to quantify aggregate risk while offering limited direct support for decision‑making at the level of individual processes. The study concludes that effective operational risk management requires integration of quantitative, qualitative and hybrid approaches into the operational risk management framework: quantitative models provide a basis for measuring financial losses using historical data, qualitative methods fill gaps in historical records and reveal emerging risks, and hybrid approaches deliver consolidated, stakeholder‑comprehensible outputs that contextualize quantitative estimates within defined ranges. The paper recommends implementing integrated assessment practices, including data normalization and aggregation, model validation, sensitivity analysis and result visualization, to improve the quality of managerial decisions and enhance the resilience of financial institutions. Future research of operational risk assessment approaches in financial institutions should advance standardized approaches to data normalization and benchmarking, refine hybrid methodologies that balance statistical precision with expert interpretation, and conduct longitudinal studies on emerging risks and institutional resilience under geopolitical and technological transformation.

Downloads

Download data is not yet available.

Author Biography

Dmytro Koval, KROK University

Postgraduate student, Department of Management Technologies, KROK University, Kyiv, Ukraine

References

Євтушенко Г.В., Бабошко А.І., & Бушля Д.І. (2015). Євтушенко Г.В., Бабошко А.І., Бушля Д.І. Операційні ризики в системі банківської діяльності та нові шляхи їх попередження. http://global-national.in.ua/issue-5-2015/13-vipusk-5-traven-2015-r/821-evtushenko-g-v-baboshko-a-i-bushlya-d-i-operatsijni-riziki-v-sistemi-bankivskoji-diyalnosti-ta-novi-shlyakhi-jikh-poperedzhennya

Наумова, О., & Копил, А. (2025). РОЛЬ КАДРОВОГО АУДИТУ В СИСТЕМІ УПРАВЛІННЯ РИЗИКАМИ ОРГАНІЗАЦІЇ: ВПЛИВ НА ЛОЯЛЬНІСТЬ ПРАЦІВНИКІВ. Сталий розвиток економіки, (1 (52)), 288–296. https://doi.org/10.32782/2308-1988/2025-52-40

Національний банк України. (2018). Положення про організацію системи управління ризиками в банках України та банківських групах.

Соколовська, Н. (2022). ОПЕРАЦІЙНИЙ РИЗИК-МЕНЕДЖМЕНТ У БАНКАХ. Київський національний економічний університет імені Вадима Гетьмана.

Ashby, S. (2022). Fundamentals of Operational Risk Management: Understanding and Implementing Effective Tools, Policies and Frameworks. Kogan Page, Limited.

Basel Committee on Banking Supervision. (1998). Operational Risk Management.

Basel Committee on Banking Supervision. (2001). QIS 2—Operational Risk Loss Data.

BBC News. (2013). Target card heist hits 40 million. BBC News. https://www.bbc.com/news/technology-25447077

Bezshtanko, D. (2025). AI AND BANK’S OPERATIONAL RISK MANAGEMENT. Three Seas Economic Journal, 6(2), 22–27. https://doi.org/10.30525/2661-5150/2025-2-4

Chapelle, A. (2019). Operational risk management: Best practices in the financial services industry. John Wiley and Sons, Inc. https://doi.org/10.1002/9781119548997

Chapelle, A., Crama, Y., Hubner, G., & Peters, J.-P. (2005). Measuring and Managing Operational Risk in the Financial Sector: An Integrated Framework. SSRN Electronic Journal. https://doi.org/10.2139/ssrn.675186

Chaudhuri, A., & Ghosh, S. (2016). Probabilistic View of Operational Risk (Вип. 331, с. 47–73). https://doi.org/10.1007/978-3-319-26039-6_4

Jobst, A. (2007). Consistent Quantitative Operational Risk Measurement and Regulation: Challenges of Model Specification, Data Collection, and Loss Reporting. IMF Working Papers, 07(254), 1. https://doi.org/10.5089/9781451868173.001

Jung, J. C., & “Alison” Park, S. B. (2017). Case Study: Volkswagen’s Diesel Emissions Scandal. Thunderbird International Business Review, 59(1), 127–137. https://doi.org/10.1002/tie.21876

Kuczynski, J., Wang, C., & Hoffman, F. (2021). Boeing 737 MAX: A case study of failure in a supply chain using system of systems framework. Issues in Information Systems, 22, 51–62. https://doi.org/10.48009/1_iis_2021_51-62

Mullen, R. M., Jethro. (2017, Січень 30). Computer outage grounds Delta flights in U.S. | CNN Business. CNN. https://www.cnn.com/2017/01/29/news/delta-system-outage

Pescaroli, G., McMillan, L., Gordon, M., Aydin, N. Y., Comes, T., Maraschini, M., Palma Oliveira, J., Torresan, S., Trump, B., Pelling, M., & Linkov, I. (2025). Definitions and taxonomy for High Impact Low Probability (HILP) and outlier events. International Journal of Disaster Risk Reduction, 127, 105504. https://doi.org/10.1016/j.ijdrr.2025.105504

Pichet, E. (2008). What Governance Lessons Should be Learnt from the Société Générale’s Kerviel Affair? La revue Française de Gouvernance d’Entreprise, 3, 117–138.

Plachkinova, M., & Maurer, C. (2018). Teaching Case Security Breach at Target. Journal of Information Systems Education, 29(1). http://jise.org/Volume29/n1/JISEv29n1p11.html

Polleri, M. (2025). Fukushima and the Politics of Nuclear Disaster Recovery. Current History, 124, 216–221. https://doi.org/10.1525/curh.2025.124.863.216

Popov, G., Lyon, B. K., & Hollcroft, B. (2022). Risk assessment: A practical guide to assessing operational risks (Second edition). John Wiley & Sons, Inc. https://doi.org/10.1002/9781119798323

Samad-Khan, A. (2010). New approach of the operational risk management. Society of Actuaries. https://www.soa.org/globalassets/assets/files/research/projects/research-new-approach.pdf

Samad-Khan, A., Rheinbay, A., & Le Blevec, S. (2006). Fundamental Issues in OpRisk Management. OpRisk &Compliance. https://www.sbp.org.pk/bsrvd/pdf/KnowledgeSharing/Reading%20Material%20for%20workshop%20on%20ORM%20May%2018-22,%202009/General%20Articles/Fundamental%20Issues%20in%20OpRisk%20Management.pdf

Strategic Organizing Center. (2025). Failure to deliver—Amazon falls short on safety. Strategic Organizing Center. https://thesoc.org/resources/failure-to-deliver-amazon-falls-short-on-safety

Tattam, D. (Ed.). (2011). A short guide to operational risk. Gower.

Published

2026-05-30

How to Cite

Koval, D. (2026). APPROACHES TO OPERATIONAL RISK ASSESSMENT IN FINANCIAL INSTITUTIONS. Science Notes of KROK University, (2(82), 253–266. https://doi.org/10.31732/2663-2209-2026-82-253-266

Issue

Section

Chapter 2. Management and administration