Blog

Mistakes to Avoid When Commissioning an Operational Risk Survey

At a glance
  • The costliest mistake is commissioning a generic checklist survey that maps controls on paper instead of testing the real business process.
  • Scope operational risk, fraud, cyber, business continuity and AI risk together; siloed surveys leave the process itself blind.
  • Demand named senior practitioners in the room — junior-staffed engagements produce findings no board can act on.
  • LT RISKMGMT applies its exclusive BPT method to examine the business process holistically for cyber, fraud and human-error exposure.
  • Define deliverables, owners and remediation deadlines in the statement of work before the first interview takes place.

Mistakes to Avoid When Commissioning an Operational Risk Survey

The most common mistakes to avoid when commissioning an operational risk survey are buying a generic control checklist instead of a process-level examination, splitting fraud, cyber and continuity exposure into separate unconnected reviews, accepting a team of juniors behind a senior name on the proposal, and signing off without agreed owners and deadlines for every finding. LT RISKMGMT approaches these engagements as examinations of the business process itself, staffed by consultants with decades of experience inside regulated organisations, precisely because paper-based risk oversight tends to miss the weaknesses that matter most.

What is an operational risk survey, and which commissioning mistakes cause the most damage?

An operational risk survey is a structured, evidence-based review of the non-financial risks embedded in a specific business process — and the commissioning mistakes that cause the most damage are almost always made before the first interview, not during fieldwork. This section narrows deliberately to the commissioning stage: the decisions a board, CRO, or internal auditor makes when defining and buying the survey.

In practice the term covers several deliverables that are often confused: input into the risk register (the organisation's ranked inventory of risks and controls), a control self-assessment or RCSA-linked questionnaire (Risk and Control Self-Assessment — where process owners rate their own controls), and a site risk survey covering physical and operational exposure at a branch, dealing room, or data centre. LT RISKMGMT scopes these reviews around the business process itself, which is where fraud risk, cyber risk, and human error converge rather than sitting in separate silos.

The highest-impact commissioning mistakes:

  • Buying a questionnaire instead of a survey — self-ratings with no independent walkthrough or sampling.
  • Leaving the scope of work undefined, so the deliverable cannot be tied to an audit finding or regulatory expectation.
  • Confusing inherent and residual risk, which inflates or deflates the whole heat map.
  • Commissioning without a stated risk appetite, leaving no threshold against which findings can be judged.
  • Accepting a junior team briefed on a template rather than practitioners who have carried the risk oversight mandate themselves.

Key attributes to specify in the mandate:

Attribute What to specify Why it matters
Scope of work Processes, systems, entities, time period Prevents scope drift and unusable findings
Sampling frame Population sampled and selection basis Determines whether conclusions generalise
Control owner Named individual accountable per control Without a name, remediation stalls
Inherent vs residual risk Exposure before vs after controls Drives control investment decisions
Risk appetite Board-approved tolerance levels Converts findings into decisions
Response bias Mitigation for self-favouring answers Protects survey credibility

Why does a vague scope and objective set undermine the whole survey?

A vague scope and a fuzzy objective are the most expensive errors in commissioning an operational risk survey, because everything downstream inherits the ambiguity. The logic is simple: if a survey exists to support a decision, then the objective must name that decision. It follows that when no decision-use statement exists — "this survey will inform the board's control investment plan for the trading desk" — the assessor cannot know which findings matter, and the report becomes a catalogue rather than a basis for action. The same holds for taxonomy: without an agreed risk taxonomy (a fixed vocabulary for non-financial risk, or NFR — operational, fraud, cyber, continuity and AI exposures), two reviewers will classify the same failure differently, and aggregation becomes meaningless.

Scope element What to fix in writing Consequence of omitting it
Risk categories / taxonomy Named NFR categories mapped to your event framework Findings cannot be aggregated or trended
Business units in scope Legal entities, desks, outsourced processes Blind spots at hand-off points between units
Time horizon Look-back period and forward exposure window Historic incidents mistaken for current exposure
Materiality thresholds Loss, downtime and customer-impact triggers Trivial and severe findings ranked alike
Deliverable format Heat map, control gaps, owners, remediation dates An unusable narrative document
Decision use The specific forum and decision it feeds No one accepts ownership of the output

Do this — but watch this:

  • Do narrow scope to material processes — watch out that narrowing does not exclude the interfaces where fraud and human error concentrate.
  • Do adopt a recognised structure such as ISO 31000 — watch out for importing generic categories that ignore local supervisory circulars.
  • Do demand fixed deliverables — watch out for rigidity that suppresses unexpected findings.

Highest-impact mitigation: sign a one-page scope charter before fieldwork. LT Risk Management assesses operational risk, fraud, cyber in the business process and business continuity within a single engagement scope, which is precisely what keeps one survey answerable to one decision.

How do sampling, coverage, and response-rate errors distort operational risk findings?

This depends on what you mean by "sampling" — the word carries two distinct meanings in an operational risk survey, and confusing them is where coverage gaps and response-rate problems begin. In the first sense, sampling means respondent sampling: which people are asked about a process. A survey circulated only to head-office control functions will describe the procedure as written — for example, a payments approval flow that "always" requires dual authorisation — while the branch or operations floor works around it under volume pressure. In the second sense, sampling means evidence sampling: which transactions, tickets, or access logs are examined. Pulling records only from a quiet month, or only from the system that exports easily, produces a clean picture of the wrong population. The more relevant meaning for commissioning is the first: respondent and process coverage drive everything, because weak evidence sampling is usually a symptom of a sampling frame that never reached the people who know where the records live.

Sampling or coverage error Distortion it produces Corrective action
Frame built from head-office respondents only Documented controls mistaken for operating reality Interview process owners and frontline executors of each critical process
Frontline, outsourced, and contractor populations excluded Blind spots in exactly the layers where fraud and human error concentrate Extend the frame to third parties with system access
Low response rate accepted without follow-up Findings rest on the most compliant, least time-pressured respondents Escalate through management and re-issue; report response levels openly
Non-response bias unexamined Highest-risk units appear low-risk because they never answered Compare responders and non-responders by unit and role
Convenience evidence sampling Peak-load and exception paths never tested Sample deliberately across peak periods and exception handling

Rather than chasing a headcount quota, LT Risk Management treats coverage as end-to-end completeness of each critical process, addressing cyber, fraud, and human error together in a single review.

Which question-design biases quietly corrupt operational risk data?

Question-design biases quietly corrupt operational risk data long before results reach a dashboard — usually through leading wording, undefined scales, and rating anchors that drift between respondents. A risk survey (a structured self-assessment used to map exposures across processes) measures perception; poor wording turns that perception into noise that boards then treat as fact.

The most damaging habits are predictable:

Do this But watch out for
Ask about observed behaviour, not opinion Respondents recalling only recent, vivid incidents
Define every likelihood and impact anchor in words Anchors that mean "serious" to Finance and "routine" to Operations
Split inherent risk (exposure before controls) from residual risk (exposure after controls) One blended question that hides whether controls actually work
Keep the questionnaire short and process-scoped Fatigue late in the form, where answers flatten to mid-scale
Guarantee anonymity for fraud-related items Losing the ability to follow up on a real red flag

Before/after rewrites make the difference concrete:

  • Before: "Do you agree that manual supplier payments create a serious risk?" After: "In the past year, how often was a supplier payment released without a second authoriser?"
  • Before: "Rate this risk 1–5." After: "Select the anchor that matches: not observed in recent memory / observed occasionally / observed most months."
  • Before: "How risky is this process?" After: two paired items — exposure assuming no controls, then exposure given controls as they actually operate today.

You may also be wondering about multi-site surveys: translated questionnaires drift, because terms like "escalation" or "exception approval" lack clean equivalents. Back-translate, and validate wording with a local process owner.

The highest-impact mitigation is a pilot with a handful of process owners before launch. This is arguably where most projects are lost — LT Risk Management anchors questions in the business process itself, where fraud, human error and control gaps actually surface, rather than in technology checklists alone.

Which survey methodology fits your organisation: qualitative, quantitative, or hybrid?

Which survey methodology fits your organisation depends less on vendor preference and more on how you weight seven evaluation criteria before you read a single proposal. Set the weighting first — otherwise the survey design is chosen for you by whoever writes the fastest quote.

How should you weight the criteria?

  • Cost and duration — matter most when a regulatory deadline or audit finding is already on the clock.
  • Respondent burden — the hours process owners must give up; heavy burden erodes answer quality in the second half of the exercise.
  • Statistical defensibility — whether the output can be reproduced and re-scored next cycle, not just narrated.
  • Auditor and regulator acceptance — whether internal audit and the supervisor recognise the method (ISO 31000-aligned scoring, documented RCSA evidence).
  • Granularity — control-level findings versus theme-level headlines.
  • Fit to size and risk maturity — a first-time survey needs different scaffolding than a fifth-cycle refresh.
Method Cost Duration Respondent burden Statistical defensibility Auditor / regulator acceptance Granularity Best fit
Qualitative interviews Moderate Short Low per person Weak — judgement-based Accepted as supporting evidence High on root causes Low maturity, first survey, sensitive fraud themes
Quantitative scored questionnaire Low per respondent Short Moderate, self-service Strong — repeatable scoring Strong, if scales are documented Broad but shallow Large populations, trend tracking across cycles
Workshop-based RCSA (Risk and Control Self-Assessment — owners rate their own risks and controls) Higher Longer High, calendar-heavy Moderate Strong, the supervisory default Control-level Regulated banks, insurers, credit companies
Hybrid Highest Phased Balanced Strong Strongest Process-level and enterprise-level Mid-size and maturing fintech or non-bank credit firms

A reasonable rule of thumb: single-method surveys optimise for the deliverable, hybrids optimise for the decision. LT RISKMGMT builds hybrid non-financial risk engagements covering cyber, fraud and human-error exposure together rather than in three separate reports, and can carry the function forward through its Risk Manager as a Service model when no full-time hire is planned.

Frequently Asked Questions

What is the most common mistake when commissioning an operational risk survey?

The most common mistake when commissioning an operational risk survey — a structured review that maps where a business process can fail through error, fraud, system outage or external shock — is treating it as a regulatory checkbox rather than a management decision tool. Boards approve a scope copied from a directive, receive a control inventory, and learn nothing about which processes actually break. Insist on deliverables you can act on: a ranked risk map, inherent versus residual risk after existing controls, named owners, and remediation deadlines. A survey that cannot change a single control next quarter was scoped wrongly.

How do you avoid buying a survey that juniors deliver?

Avoid the "juniors on site" trap by contracting for named people, not a firm logo. Ask who will personally interview the trading desk, the credit operations team and the outsourcing suppliers, and ask what those individuals ran before they consulted.

What is a BPT, and why is it not a technical penetration test?

A BPT (Business Penetration Test) is LT RISKMGMT's exclusive method for stress-testing the business process itself — the handoffs, approvals, exceptions and privileges inside a workflow — rather than the network perimeter. A technical penetration test (PT) probes systems and code; a BPT interrogates the process logic that surrounds them. The BPT starts where technological defence ends, giving one holistic answer to cyber exposure, embezzlement and human error in the same review — arguably the most underappreciated gap in risk oversight today: hardened infrastructure with a blind business process.

Why must AI risk be inside the survey scope in 2026?

Because the material failure modes increasingly sit in models, data and vendors that no legacy control library covers.

Which outcomes should a well-scoped survey actually produce?

A well-scoped review should shorten decision cycles, not lengthen reports. In LT RISKMGMT's engagement with a large financial institution in Israel, a reframing of fraud risk management cut the time to disconnect a suspicious client from the business platform from an average of two to five days to no more than two hours, alongside an estimated saving of roughly five headcount positions — figures the firm's owner presents as an internal estimate rather than publicly audited data. Ask candidate advisors for comparable cycle-time and control-efficiency outcomes before you sign.

Do we need a full-time risk manager, or is an outsourced one enough?

Mid-sized and governmental organisations frequently need the function without a full-time headcount. LT RISKMGMT offers Risk Manager as a Service, standing in as the position itself and scaling the volume of work to what the organisation actually requires — including business continuity planning (BCP), fraud prevention and operational exposure. For internal capability building, LT RISKMGMT's certification course for operational risk, cyber and AI managers runs about 40 academic hours with workshops and a visit to a leading SOC, and is recognised by the IRM (Institute of Risk Management). As a service commitment — not a contractual SLA — LT RISKMGMT aims to respond to initial inquiries within 24 hours.

Ready to get started?

See how LT RISKMGMT can help.

צרו קשר