IIBF BFM Module B: Unit 8 - Operational Risk

Risk Based
Supervision (RBS)

Evaluating institutional efficacy through continuous health assessments and proactive oversight frameworks.

The Shift to Proactive Oversight

Unlike legacy systems that examine transactions in hindsight (Post-Mortem), RBS evaluates operational efficacy in both actual and projected environments. It shifts focus from discrete audits to continuous health assessment.

2026 Strategic Mandate

Per the April 2026 directives, the mandate has shifted toward **Operational Resilience** and **Forward-Looking Provisions (ECL)**, ensuring institutions maintain robust internal controls that identify and mitigate risk across all business layers on an ongoing basis.

RBS: 2026 Regulatory Directives & CAMELSC Framework

Deposit Insurance (RBP)

Effective April 1, 2026, the flat-rate premium is replaced by a Risk-Based Premium (RBP) framework. Banks are categorized A through D, with lower premiums for institutions exhibiting superior CAMELSC risk ratings.

Related Party & Group Risk

Banks must implement board-approved policies with strict materiality thresholds, real-time group entity exposure monitoring, and automated forensic fraud red-flag checks.

RBI CAMELSC Supervisory Evaluation Architecture
Pillar DimensionCore Supervisory Assessment FocusPrudential Benchmark Target
C — Capital AdequacyLoss absorption capacity, CET1 capital, and Tier 1 leverage buffers.CRAR ≥ 11.5%, CET1 ≥ 8.0%
A — Asset QualityGross NPA slippages, Provision Coverage Ratio (PCR), and Stage 2 SICR assets.GNPA < 3.0%, PCR ≥ 70%
M — Management QualityBoard oversight, 3 Lines of Defence efficacy, and Fit & Proper compliance.Robust Internal Controls
E — Earnings QualityReturn on Assets (RoA), Net Interest Margin (NIM), and Non-interest income.RoA ≥ 1.0%, NIM > 3.0%
L — Liquidity ResilienceLiquidity Coverage Ratio (LCR), NSFR, and dynamic ALM maturity mismatches.LCR ≥ 100%, NSFR ≥ 100%
S — Systems & Cyber ControlsIT infrastructure resilience, CSIRT incident readiness, and fraud analytics.Zero Critical Cyber Breaches
C — Conduct & ComplianceStatutory compliance, AML/CFT surveillance, and consumer protection charters.100% RBI Circular Adherence

Basle Committee: Drivers of Systemic Failure

The Basle Committee has identified several critical bottlenecks that consistently lead to institutional fragility:

01
Stagnant Assessments

Failure to recalibrate risk metrics when global or local business conditions shift significantly.

02
Oversight Deficits

Lack of a pervasive control culture and ambiguous management accountability structures.

03
Process Absence

Inadequate segregation of duties, approvals, and automated reconciliations.

04
Information Silos

Critical communication gaps between senior management and operational execution layers.

Fundamental Assessment Principles

Strategic Governance

  • Board Accountability: Strategic alignment and setting of Risk Appetite.
  • Senior Management Role: Operational implementation of board directives.
  • Ethical Standards: Promoting institutional integrity as a core control.

Operational Vigilance

  • Continuous Monitoring: Real-time assessment of environmental shifts.
  • Embedded Controls: Integration of safety checks into daily workflows.

Core Control Checklist

  • Segregation of Duties: Eliminating inherent conflicts of interest.
  • Data Integrity: Centralized operational and financial tracking.
  • Communication Flux: Bi-directional awareness across all levels.
  • Independent Audit: Unbiased evaluation by technical staff.
  • Deficiency Escalation: Rapid reporting and remediation of gaps.

Indian Market Context

The 2026 Supervisory Framework moves beyond traditional ratio-checks to deep-dive into business models and credit deployment patterns.

Modern challenges like **Cyber-Resiliency** mandates (requiring half-yearly vulnerability assessments) and **AI-Driven Fraud Detection** (MuleHunter.AI) have propelled RBS toward a tech-first approach.

Proactive Cyber Defense

"Regulatory expectations now demand 24/7 Security Operations Centers (SOCs) and annual penetration testing. In 2026, a bank's digital perimeter is its most critical risk domain."

Defining Modern Risk Management

A systematic approach to understanding, measuring, and controlling exposures. It is inherently Bank-specific and Activity-driven.

Credit Risk
Market Risk
Operational Risk

Welcome Back

Sign in to save reports and access premium credit tools.

or continue with
Don't have an account?