ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

A New Way Forward with Risk Operation Centers

July 23, 2020
Reading Time: 4 mins read
A New Way Forward with Risk Operation Centers

By Atul Vashistha

Although it’s unclear when the negative effects of COVID-19 will be fully played out, one thing is certain: The traditional third-party risk management, or TPRM, practices that financial institutions have relied on are inadequate going forward. Many current risk programs are reactionary in nature, thereby crippling effective risk mitigation. The problem is compounded by the fact that risk mitigation decisions rely on static data collected during point-in-time assessments.

In today’s rapidly changing risk environment, reactive responses and stale risk data are passé. Leading financial institutions are recognizing the need to reset their TPRM programs. Making the shift to investing in continuous risk monitoring through a proactive risk operations center enables effective risk anticipation to mitigate or even avoid costly business disruptions.

The shortcomings of today’s TPRM programs

For most financial services TPRM programs, the main risk focus occurs during the third-party selection process. Due diligence is performed at the point of onboarding to understand the risk associated with a new location or a new third party.

Assessments are performed periodically, usually once a year or every other year, to ascertain whether risk profiles have changed. Additional efforts are typically limited to reactively responding when a risk event has already occurred. The downfall of these practices results from the continuous, dynamic nature of risk. The time between assessments leaves financial institutions exposed and vulnerable to potentially significant disruptions.

The inadequacy of today’s programs stems from an underinvestment in risk due to a reliance on outdated risk models. For too long risks such as global pandemics have been considered high impact, but low probability. This isn’t logical when you consider both the frequency of recent disease outbreaks (four pandemics since 2002—SARS, H1N1, MERS, and COVID-19) and the hyper-connectivity of our global financial markets and travel. When financial institutions tested their disaster recovery and business continuity plans pre-COVID-19, few if any tested a scenario where 100 percent of employees would be forced to work from home or that all global operations would be affected at once. Today’s risk leaders need to challenge their assumptions on risk impact, frequency and worst-case scenario.

Operational disruptions result not only in lost revenue, but also reputational damage, customer churn, regulatory penalties, litigation, attrition, lost productivity of internal employees tasked with resolving the incident and often much more. When you evaluate the potentially astronomical cost of disruptions, it’s easy to see why investment in risk management is now being recognized as a competitive advantage.

Introducing a permanent risk operations center

Leading financial institutions will establish a permanent risk operations center to continuously monitor for changes, assess potential impact, identify risk mitigation actions, track incident resolution and identify risk trends. The competitive benefits realized are improved speed and quality of response to minimize or avoid disruptions and the related costs.

While permanent, an ROC can be staffed up or down as the risk environment requires. It is continuously monitoring, planning and proactively ready to act. Enterprises that wait to establish a risk operations center in a reactionary manner, once a crisis is declared, will miss out on key risk intelligence and valuable time to make effective risk mitigation or avoidance decisions.

The foundation for building an ROC

An ROC relies on four components: a monitoring post, a workflow tool, a response center and a feedback loop. The monitoring post continuously monitors risk across a broad framework of third-party and location-based risks to collect real-time risk intelligence. Traditionally, TPRM programs have been heavily focused on financial and cyber risks, but today’s business disruptions come from a wide spectrum of risk, such as compliance, sanctions, people, solutions maturity, client and location-based risks.

Relevant and validated risk intelligence is routed through a workflow tool. The response center, ideally divided into specialized workstreams like technology, facilities and workforce, will then assess the intelligence for relevance and risk level to the institution. From there, risk mitigation guidance and recommended actions, both internal and external, are provided to the relevant business functions. When action is taken, results are entered into the feedback loop to know what is working and when alternative actions are required. Risk events are then tracked to resolution.

Staffing an ROC for a financial services enterprise should be considered through the view of competencies needed. These functions can be covered through a combination of technology, tools, analytics and people. Data collected needs to be continuous and analyzed in real-time for relevancy and impact to produce risk intelligence that can be used for mitigation, trending and forecasting. As the response center team will need to work well with other business functions, they need skills related to relationship management and collaboration. Team members will need risk mitigation knowledge and the ability to look beyond the individual risk event to make connections to other possible related or cascading risks in a truly proactive fashion.

A new way forward

COVID-19 has highlighted that our current risk models and third-party risk practices are no longer adequate. Instead of focusing on risk management as an expense, financial enterprises should pivot to a new way forward with risk management as an investment. Making the proper investment in continuous risk monitoring through a proactive and permanent risk operations center, financial enterprises can reap the competitive advantages of business resilience, regulatory compliance and brand enhancement.

Atul Vashistha is a leading expert on globalization, governance, and risk. He has authored three best-selling books: The Offshore Nation, Globalization Wisdom and Outsourcing Wisdom. He is also founder and Chairman of Supply Wisdom, the real-time and continuous risk intelligence and monitoring solution.

Tags: CoronavirusRisk managementThird-party risk
ShareTweetPin

Related Posts

OCC’s Gould: Bank regulation should not distract banks from business challenges

Gould suggests easing bank resolution planning requirements

Compliance and Risk
January 16, 2026

Comptroller of the Currency Jonathan Gould said he sees no benefit in the FDIC continuing to require filings from large banks that detail their suggested orderly resolution in case of a bank failure, known as CIDI plans. He...

FHFA to create affordable housing advisory committee

HUD proposes to remove disparate impact from Fair Housing Act rule

Compliance and Risk
January 14, 2026

The Department of Housing and Urban Development is proposing to rescind three rules allowing the use of disparate impact in determining Fair Housing Act violations.

AI romance, ‘machine-to-machine’ scams among top 2026 fraud trends

AI romance, ‘machine-to-machine’ scams among top 2026 fraud trends

Compliance and Risk
January 14, 2026

Romance scams carried out by artificial intelligence and computers scamming other computers are among the top five fraud trends to watch out for in 2026, according to a new report by credit reporting agency Experian.

FinCEN proposes applying BSA requirements to investment advisers

G7 expert group releases cybersecurity ‘roadmap’ for post-quantum cryptography

Compliance and Risk
January 13, 2026

The G7 Cyber Expert Group released a “roadmap” to help the financial sector take steps to secure computer systems from cybersecurity risks arising from quantum computing.

Banking agencies: Shared National Credit quality remains moderate

Banking agencies release Shared National Credit Program report

Compliance and Risk
January 12, 2026

Credit risk associated with large, syndicated bank loans remains moderate, with credit risk trends reflecting the effects of borrowers' ability to manage higher interest expenses and other macroeconomic factors, three banking agencies said in their most recent Shared...

ABA urges FinCEN to reevaluate BOI collection burden on banks

Treasury issues order, alert to Minnesota institutions on alleged fraud rings

Compliance and Risk
January 9, 2026

FinCEN issued an alert urging financial institutions to identify and report fraud associated with federal child nutrition programs in Minnesota, and it released a geographic targeting order directing banks and money transmitters in two Minnesota counties to report...

NEWSBYTES

Democratic senators introduce bill to lower credit card late fee cap

January 16, 2026

Gould suggests easing bank resolution planning requirements

January 16, 2026

Survey: Merchants expand payment options, express interest in crypto

January 16, 2026

SPONSORED CONTENT

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

November 1, 2025
5 FedNow®  Service Developments You May Have Missed

5 FedNow® Service Developments You May Have Missed

October 31, 2025

Cash, Security, and Resilience in a Digital-First Economy

October 20, 2025
Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

October 1, 2025

PODCASTS

Podcast: A Lone Star banking perspective

January 15, 2026

Podcast: The incredible shrinking penny (circulation)

January 8, 2026

Podcast: Cybersecurity in a mobile-first banking landscape

December 18, 2025

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.