Risk Management
DETAIL

Basel Committee on Banking Supervision – Revisions to the Principles for the Sound Management of Operational Risk (March 2021)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

The Revisions to the Principles for the Sound Management of Operational Risk (PSMOR) were published by the Basel Committee on Banking Supervision on 31 March 2021. The document restates the Committee's twelve principles for operational risk management, which it first introduced in 2003 and revised in 2011 after the Great Financial Crisis, and defines operational risk as the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events, including legal risk but excluding strategic and reputational risk.

The Basel Committee is the primary global standard setter for the prudential regulation of banks, and its member authorities implement the principles through national supervisory rules and examinations. The principles cover governance, the risk management environment, information and communication technology, business continuity planning, and the role of disclosure, and the Committee recommends that banks apply them in proportion to the nature, size, complexity, and risk profile of their activities.

Banks implement the principles by building an operational risk management framework approved by the board, assigning first, second, and third line responsibilities, running risk and control self-assessments, key risk indicators, loss data collection, and change management reviews, and reporting operational risk profiles to senior management and the board. The 2021 revision aligns the principles with the finalized Basel III operational risk framework, updates guidance on change management and ICT, and improves clarity.

Why it Matters

The 2014 implementation review found that several principles had not been adequately implemented, especially risk identification tools, change management, the three lines of defence, and ICT risk, and the 2021 revision responds to those gaps. For banks, the principles are the reference point supervisors use when assessing an operational risk management framework.

Key benefits include:

  • Meet supervisory expectations

Align the operational risk management framework with the principles that national supervisors and internal auditors assess against.

  • Strengthen risk identification

Use risk and control self-assessments, key risk indicators, loss data, and business process mapping to understand operational exposures before they crystallize.

  • Control change

Assess new products, activities, processes, and systems for operational risk before launch and monitor them afterward.

  • Manage ICT and continuity risk

Run an ICT risk management programme and business continuity plans that are linked to the operational risk management framework.

  • Report with confidence

Give the board and senior management regular operational risk reports that support proactive management and public disclosure.

How it Works

The document sets out twelve principles grouped by theme. Principles 1 to 5 address governance: risk culture led by the board, an operational risk management framework that is fully integrated with overall risk management, board approval and periodic review of the framework, a board-approved risk appetite and tolerance statement for operational risk, and a governance structure established by senior management with clear lines of responsibility. Principles 6 to 9 cover the risk management environment: identification and assessment, change management, monitoring and reporting, and control and mitigation. Principle 10 covers ICT risk, Principle 11 business continuity planning, and Principle 12 the role of disclosure.

Banks implement the principles by documenting the operational risk management framework and its three lines of defence, running periodic risk and control self-assessments, maintaining internal and external loss event data, defining key risk indicators with thresholds, reviewing changes through a formal change management process, testing controls, and maintaining and exercising business continuity plans. Internal audit reviews the framework independently and the board approves the risk appetite and tolerance statement.

SmartSuite holds the twelve principles as a requirement set with linked controls, risk and control self-assessments, loss events, key risk indicators, change assessments, and continuity tests, so that the operational risk profile is assembled from live records with owners, due dates, and an audit trail for supervisory review.

Key Elements

  • Board-led risk culture and framework

The board takes the lead in establishing a strong risk management culture and approves and periodically reviews the operational risk management framework.

  • Risk appetite and tolerance

The board approves a risk appetite and tolerance statement for operational risk that articulates the nature, types, and levels of risk the bank is willing to assume.

  • Identification and assessment tools

Senior management ensures comprehensive identification and assessment of operational risk in all material products, activities, processes, and systems.

  • Change management

The bank's change management process is comprehensive, appropriately resourced, and articulated between the relevant lines of defence.

  • Monitoring, reporting, and control

Operational risk profiles and material exposures are monitored regularly, with reporting at board, senior management, and business unit levels and a strong control environment.

  • ICT risk and business continuity

Banks implement a robust ICT risk management programme and business continuity plans linked to the operational risk management framework.

  • Disclosure

Public disclosures allow stakeholders to assess the bank's approach to operational risk management and its operational risk exposure.

Framework Scope

The principles apply to banks and banking groups supervised by Basel Committee member authorities and are recommended by the Committee as sound practice for all banks. They cover the full operational risk management framework, from board governance and risk appetite to identification, change management, control, ICT risk, business continuity, and disclosure, and are applied in proportion to the nature, size, complexity, and risk profile of the bank.

Framework Objectives

The Committee published the 2021 revision to promote the effectiveness of operational risk management throughout the banking system.

Align the principles with the finalized Basel III operational risk framework.

Update the guidance on change management and information and communication technologies.

Enhance the overall clarity of the principles for banks and supervisors.

Close the implementation gaps identified in the 2014 review, including risk identification tools and the three lines of defence.

Integrate operational risk management with overall risk management, including operational resilience.

Support consistent supervisory assessment of operational risk management frameworks across jurisdictions.

Framework in Context

The PSMOR were published alongside the Basel Committee's Principles for Operational Resilience, which build on them, and they sit within the Basel III framework's operational risk capital requirements. National regimes such as APRA CPS 230, the PRA and FCA operational resilience rules, and the EU's DORA draw on the same governance, change management, ICT, and continuity themes, and the principles reference the three lines of defence that the IIA's Three Lines Model describes.

Common Framework Mappings

Banks map the twelve principles to their operational resilience obligations, prudential rules, risk management standards, and control frameworks so that one set of controls and evidence serves several supervisory expectations.

Mapped frameworks include:

BCBS Operational Resilience Principles

Basel III

IIA Three Lines Model

APRA CPS 230

PRA SS1/21

FCA SYSC 15A (PS21/3)

EU DORA

ISO 31000:2018

ISO 22301

COSO ERM 2017

NIST CSF 2.0

ISO 27001:2022

BCBS 239

At a Glance
Basel Committee on Banking Supervision – Revisions to the Principles for the Sound Management of Operational Risk (March 2021)
  • Classification
    Category
    Risk Management
    Domain
    Risk Management
    Framework Family
    Other
  • Regulatory Context
    Type
    Guidance
    Legal Instrument
    Supervisory Principles
    Sector
    Financial Sector
    Industry
    Financial Services
  • Region / Publisher
    Region
    Global
    Region Detail
    Global (Basel Committee)
    Publisher
    Basel Committee on Banking Supervision (BCBS)
  • Versioning
    Version
    March 2021 revision (supersedes the 2011 Principles)
    Effective Date
    March 31, 2021
    Issue Date
    March 31, 2021
  • Adoption
    Adoption Model
    Regulatory Compliance
    Implementation Complexity
    High
  • Official Reference
License Information

License included / downloadable: Yes

The principles are published free of charge by the Bank for International Settlements, and the twelve principles are included with the platform as a requirement set.

Framework text is licensed by its publisher and is included only where stated above.

Official Resources
BIS: Revisions to the Principles for the Sound Management of Operational Risk
The Basel Committee publication page for the March 2021 revision, with the summary and the PDF download.
PSMOR 2021 full text (PDF)
The 23-page document setting out the twelve principles for governance, the risk management environment, ICT, business continuity, and disclosure.
BIS: Principles for Operational Resilience
The companion March 2021 publication whose seven principles build on the revised PSMOR.
Basel Committee on Banking Supervision overview
The Committee's overview page describing its role as the global standard setter for the prudential regulation of banks.
SMARTSUITE

How SmartSuite Supports BCBS PSMOR

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

For the PSMOR, SmartSuite records the operational risk management framework, risk appetite statement, RCSAs, loss events, key risk indicators, change assessments, and continuity tests against each principle and reports the operational risk profile to the board.

Principles and Control Library

Hold the twelve principles as requirements with linked policies, controls, and the operational risk taxonomy in one structured record set.

Ownership, Cadence, and Accountability

Assign first, second, and third line owners to each principle and control, set review cycles, and track board approval of the framework and risk appetite statement.

Evidence Collection and Audit Trail

Attach RCSA results, loss event records, key risk indicator readings, and change assessments with timestamps and reviewers for supervisory review.

Control Testing and Continuity Exercises

Plan control tests and business continuity exercises, document results, and track remediation to closure.

Risk and Third-Party Alignment

Connect operational risks, ICT risks, and outsourced services to the principles and critical processes they affect.

Board and Supervisory Reporting

Produce operational risk profile dashboards and reports by principle, business line, and open issue for senior management, the board, and supervisors.

Related frameworks

BCBS Operational Resilience Principles

The Basel Committee's seven Principles for Operational Resilience set the international baseline for how banks deliver critical operations through disruption.

Basel III

Basel III is an international banking regulation framework that strengthens banks' capital, liquidity, and risk management to reduce systemic risk.

APRA CPS 230

CPS 230 is an APRA standard requiring banks, insurers, and superannuation funds to manage operational risks and ensure resilience.

PRA SS1/21

PRA SS1/21 sets the Prudential Regulation Authority's expectations for how UK banks and insurers identify important business services, set impact tolerances, and stay within them.

FCA SYSC 15A (PS21/3)

FCA PS21/3 and SYSC 15A require UK-regulated firms to identify important business services, set impact tolerances, map and test their resilience, and self-assess against them.

EU DORA

DORA is an EU regulation requiring financial firms to manage ICT risks, report incidents, test security, and oversee third-party providers.

ISO 31000:2018

ISO 31000 provides guidelines for identifying, assessing, and managing organizational risks to improve resilience and decision-making.

COSO ERM 2017

COSO ERM is a framework that helps organizations identify, assess, manage, and monitor enterprise risks to achieve objectives.

ONBOARDING FAQS

Frequently Asked Questions For BCBS PSMOR

What are the Principles for the Sound Management of Operational Risk?

They are twelve principles published by the Basel Committee on Banking Supervision that describe sound practice for governing, identifying, assessing, controlling, and reporting operational risk in banks. The Committee first issued them in 2003, revised them in 2011, and published the current revision on 31 March 2021.

How does the Basel Committee define operational risk?

Operational risk is the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events. The definition includes legal risk but excludes strategic and reputational risk.

What changed in the March 2021 revision?

The Committee aligned the principles with the finalized Basel III operational risk framework, updated the guidance on change management and information and communication technologies, and improved the overall clarity of the principles. The revision responds to gaps found in the 2014 implementation review.

Who has to apply the PSMOR?

The principles are addressed to banks supervised by Basel Committee member authorities, which implement them through national rules and supervisory review. The Committee considers them sound practice for all banks and expects proportionate application based on size, complexity, and risk profile.

How do the PSMOR relate to the Principles for Operational Resilience?

The Basel Committee published both documents on the same day in March 2021. The operational resilience principles build on the PSMOR, treating sound operational risk management as the foundation for delivering critical operations through disruption.

What tools do the principles expect banks to use?

The principles refer to risk and control self-assessments, key risk indicators, internal and external loss data, business process mapping, scenario analysis, comparative analysis, and monitoring of action plans, along with a formal change management process and business continuity planning.

How does SmartSuite support the PSMOR?

SmartSuite holds the twelve principles as a requirement set with linked controls, RCSAs, loss events, key risk indicators, change assessments, and continuity tests, each with owners, due dates, and an audit trail. Operational risk teams use it to assemble the operational risk profile and report to senior management, the board, and supervisors.

Operationalize BCBS PSMOR 2021 with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.