Basel Committee on Banking Supervision – Revisions to the Principles for the Sound Management of Operational Risk (March 2021)
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
The Revisions to the Principles for the Sound Management of Operational Risk (PSMOR) were published by the Basel Committee on Banking Supervision on 31 March 2021. The document restates the Committee's twelve principles for operational risk management, which it first introduced in 2003 and revised in 2011 after the Great Financial Crisis, and defines operational risk as the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events, including legal risk but excluding strategic and reputational risk.
The Basel Committee is the primary global standard setter for the prudential regulation of banks, and its member authorities implement the principles through national supervisory rules and examinations. The principles cover governance, the risk management environment, information and communication technology, business continuity planning, and the role of disclosure, and the Committee recommends that banks apply them in proportion to the nature, size, complexity, and risk profile of their activities.
Banks implement the principles by building an operational risk management framework approved by the board, assigning first, second, and third line responsibilities, running risk and control self-assessments, key risk indicators, loss data collection, and change management reviews, and reporting operational risk profiles to senior management and the board. The 2021 revision aligns the principles with the finalized Basel III operational risk framework, updates guidance on change management and ICT, and improves clarity.
Why it Matters
The 2014 implementation review found that several principles had not been adequately implemented, especially risk identification tools, change management, the three lines of defence, and ICT risk, and the 2021 revision responds to those gaps. For banks, the principles are the reference point supervisors use when assessing an operational risk management framework.
Key benefits include:
- Meet supervisory expectations
Align the operational risk management framework with the principles that national supervisors and internal auditors assess against.
- Strengthen risk identification
Use risk and control self-assessments, key risk indicators, loss data, and business process mapping to understand operational exposures before they crystallize.
- Control change
Assess new products, activities, processes, and systems for operational risk before launch and monitor them afterward.
- Manage ICT and continuity risk
Run an ICT risk management programme and business continuity plans that are linked to the operational risk management framework.
- Report with confidence
Give the board and senior management regular operational risk reports that support proactive management and public disclosure.
How it Works
The document sets out twelve principles grouped by theme. Principles 1 to 5 address governance: risk culture led by the board, an operational risk management framework that is fully integrated with overall risk management, board approval and periodic review of the framework, a board-approved risk appetite and tolerance statement for operational risk, and a governance structure established by senior management with clear lines of responsibility. Principles 6 to 9 cover the risk management environment: identification and assessment, change management, monitoring and reporting, and control and mitigation. Principle 10 covers ICT risk, Principle 11 business continuity planning, and Principle 12 the role of disclosure.
Banks implement the principles by documenting the operational risk management framework and its three lines of defence, running periodic risk and control self-assessments, maintaining internal and external loss event data, defining key risk indicators with thresholds, reviewing changes through a formal change management process, testing controls, and maintaining and exercising business continuity plans. Internal audit reviews the framework independently and the board approves the risk appetite and tolerance statement.
SmartSuite holds the twelve principles as a requirement set with linked controls, risk and control self-assessments, loss events, key risk indicators, change assessments, and continuity tests, so that the operational risk profile is assembled from live records with owners, due dates, and an audit trail for supervisory review.
Key Elements
- Board-led risk culture and framework
The board takes the lead in establishing a strong risk management culture and approves and periodically reviews the operational risk management framework.
- Risk appetite and tolerance
The board approves a risk appetite and tolerance statement for operational risk that articulates the nature, types, and levels of risk the bank is willing to assume.
- Identification and assessment tools
Senior management ensures comprehensive identification and assessment of operational risk in all material products, activities, processes, and systems.
- Change management
The bank's change management process is comprehensive, appropriately resourced, and articulated between the relevant lines of defence.
- Monitoring, reporting, and control
Operational risk profiles and material exposures are monitored regularly, with reporting at board, senior management, and business unit levels and a strong control environment.
- ICT risk and business continuity
Banks implement a robust ICT risk management programme and business continuity plans linked to the operational risk management framework.
- Disclosure
Public disclosures allow stakeholders to assess the bank's approach to operational risk management and its operational risk exposure.
Framework Scope
The principles apply to banks and banking groups supervised by Basel Committee member authorities and are recommended by the Committee as sound practice for all banks. They cover the full operational risk management framework, from board governance and risk appetite to identification, change management, control, ICT risk, business continuity, and disclosure, and are applied in proportion to the nature, size, complexity, and risk profile of the bank.
Framework Objectives
The Committee published the 2021 revision to promote the effectiveness of operational risk management throughout the banking system.
Align the principles with the finalized Basel III operational risk framework.
Update the guidance on change management and information and communication technologies.
Enhance the overall clarity of the principles for banks and supervisors.
Close the implementation gaps identified in the 2014 review, including risk identification tools and the three lines of defence.
Integrate operational risk management with overall risk management, including operational resilience.
Support consistent supervisory assessment of operational risk management frameworks across jurisdictions.
Framework in Context
The PSMOR were published alongside the Basel Committee's Principles for Operational Resilience, which build on them, and they sit within the Basel III framework's operational risk capital requirements. National regimes such as APRA CPS 230, the PRA and FCA operational resilience rules, and the EU's DORA draw on the same governance, change management, ICT, and continuity themes, and the principles reference the three lines of defence that the IIA's Three Lines Model describes.
Common Framework Mappings
Banks map the twelve principles to their operational resilience obligations, prudential rules, risk management standards, and control frameworks so that one set of controls and evidence serves several supervisory expectations.
Mapped frameworks include:
BCBS Operational Resilience Principles
Basel III
IIA Three Lines Model
APRA CPS 230
PRA SS1/21
FCA SYSC 15A (PS21/3)
EU DORA
ISO 31000:2018
ISO 22301
COSO ERM 2017
NIST CSF 2.0
ISO 27001:2022
BCBS 239
- ClassificationCategoryRisk ManagementDomainRisk ManagementFramework FamilyOther
- Regulatory ContextTypeGuidanceLegal InstrumentSupervisory PrinciplesSectorFinancial SectorIndustryFinancial Services
- Region / PublisherRegionGlobalRegion DetailGlobal (Basel Committee)PublisherBasel Committee on Banking Supervision (BCBS)
- VersioningVersionMarch 2021 revision (supersedes the 2011 Principles)Effective DateMarch 31, 2021Issue DateMarch 31, 2021
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
The principles are published free of charge by the Bank for International Settlements, and the twelve principles are included with the platform as a requirement set.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports BCBS PSMOR
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
For the PSMOR, SmartSuite records the operational risk management framework, risk appetite statement, RCSAs, loss events, key risk indicators, change assessments, and continuity tests against each principle and reports the operational risk profile to the board.
Principles and Control Library
Hold the twelve principles as requirements with linked policies, controls, and the operational risk taxonomy in one structured record set.
Ownership, Cadence, and Accountability
Assign first, second, and third line owners to each principle and control, set review cycles, and track board approval of the framework and risk appetite statement.
Evidence Collection and Audit Trail
Attach RCSA results, loss event records, key risk indicator readings, and change assessments with timestamps and reviewers for supervisory review.
Control Testing and Continuity Exercises
Plan control tests and business continuity exercises, document results, and track remediation to closure.
Risk and Third-Party Alignment
Connect operational risks, ICT risks, and outsourced services to the principles and critical processes they affect.
Board and Supervisory Reporting
Produce operational risk profile dashboards and reports by principle, business line, and open issue for senior management, the board, and supervisors.
Related frameworks

The Basel Committee's seven Principles for Operational Resilience set the international baseline for how banks deliver critical operations through disruption.

Basel III is an international banking regulation framework that strengthens banks' capital, liquidity, and risk management to reduce systemic risk.

CPS 230 is an APRA standard requiring banks, insurers, and superannuation funds to manage operational risks and ensure resilience.

PRA SS1/21 sets the Prudential Regulation Authority's expectations for how UK banks and insurers identify important business services, set impact tolerances, and stay within them.

FCA PS21/3 and SYSC 15A require UK-regulated firms to identify important business services, set impact tolerances, map and test their resilience, and self-assess against them.

DORA is an EU regulation requiring financial firms to manage ICT risks, report incidents, test security, and oversee third-party providers.
Frequently Asked Questions For BCBS PSMOR
They are twelve principles published by the Basel Committee on Banking Supervision that describe sound practice for governing, identifying, assessing, controlling, and reporting operational risk in banks. The Committee first issued them in 2003, revised them in 2011, and published the current revision on 31 March 2021.
Operational risk is the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events. The definition includes legal risk but excludes strategic and reputational risk.
The Committee aligned the principles with the finalized Basel III operational risk framework, updated the guidance on change management and information and communication technologies, and improved the overall clarity of the principles. The revision responds to gaps found in the 2014 implementation review.
The principles are addressed to banks supervised by Basel Committee member authorities, which implement them through national rules and supervisory review. The Committee considers them sound practice for all banks and expects proportionate application based on size, complexity, and risk profile.
The Basel Committee published both documents on the same day in March 2021. The operational resilience principles build on the PSMOR, treating sound operational risk management as the foundation for delivering critical operations through disruption.
The principles refer to risk and control self-assessments, key risk indicators, internal and external loss data, business process mapping, scenario analysis, comparative analysis, and monitoring of action plans, along with a formal change management process and business continuity planning.
SmartSuite holds the twelve principles as a requirement set with linked controls, RCSAs, loss events, key risk indicators, change assessments, and continuity tests, each with owners, due dates, and an audit trail. Operational risk teams use it to assemble the operational risk profile and report to senior management, the board, and supervisors.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

