SmartSuite for the Operational Risk Manager
The Operational Risk Manager manages the risks arising from people, processes, systems and external events for a department, function or business unit. They run RCSAs, evaluate the controls that mitigate operational risk, capture loss events and coordinate remediation with the business.
What you own
- Maintain the operational risk register for their business unit or function
- Run risk and control self-assessments (RCSA) with process owners
- Capture and analyse operational loss events and near misses
- Evaluate the design and effectiveness of controls that mitigate operational risk
- Monitor key risk indicators and escalate breaches
- Coordinate remediation with business teams and track closure
- Report operational risk posture to the risk function and business leadership
Where the role sits
Each name opens that role's page.
Reports to
Direct reports
Works closely with
GRC processes
The shared GRC process map, highlighted for this role.
Owns
accountable for the process
Touches
contributes or approves
Depends on
consumes its output
How SmartSuite helps, suite by suite
Each card is the persona record from that suite's Users tab.
How they use the Enterprise Risk Management suite
Localized risk review
Reviews risks impacting their department or business unit.
Control evaluation
Assesses effectiveness of controls supporting risk mitigation.
Business unit coordination
Collaborates with teams to address and remediate risks.
How they use SmartSuite
Suites that serve this role
How SmartSuite supports this role
Risk management. Provides department-level dashboards and automated reviews for localised risk review, with the unit's risks linked to the enterprise register.
Compliance management. Runs RCSA cycles with scored controls and evidence so control evaluation is structured and repeatable.
Operational resilience. Links operational risks to the business services and continuity plans they threaten.
Issues and actions. Coordinates remediation with business teams through assigned tasks, due dates and closure validation.
Reporting. Produces business-unit risk reports and KRI trends for the risk function and local leadership.
Industry reference
The Basel Committee's Principles for the Sound Management of Operational Risk (2021) define the discipline: risk and control self-assessments, loss event collection, key risk indicators and a three-lines structure. The Basel III standardised approach ties operational risk capital to loss history, which makes the loss database a regulated record. COSO ERM supplies the enterprise view.
Outside banking the same tools apply without the capital charge. Insurers model operational risk under Solvency II; healthcare providers track patient-safety and operational events through accreditation standards; public bodies use OMB Circular A-123; technology firms manage ICT operational risk under DORA when they serve EU financial entities.
In their words
Related roles
See SmartSuite for your role
Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.








