top of page

Risk Management Operating Model

Expert-led, boutique advisory trusted by financial services, fintechs, and purpose-driven organisations.

Risk management operating model infographic showing how strategy, objectives, risk appetite and decisions connect to governance, roles, organisational structure, processes, people, technology and Risk Demand.

1. What Is a Risk Management Operating Model?

​

A risk management operating model translates an organisation’s risk strategy and risk management framework into the structures, roles, capabilities, processes and interactions through which risk is managed in practice.

​

It defines how risk management works across the organisation, not simply how it is documented. It connects accountability, decision-making, oversight and assurance with the people, information and technology needed to manage risk effectively.

​

A risk management operating model should provide clarity on:

  • who owns and manages risk;

  • how responsibilities are distributed across the First, Second and Third Lines;

  • where specialist risk capabilities should sit;

  • how Risk, Compliance, Internal Audit and other specialist functions interact with the business;

  • how risk information supports management and Board decision-making;

  • how risk activity is governed, challenged and assured; and

  • what people, capabilities, data and technology are required to make the model work.

 

The design will vary between organisations. Size, business model, regulatory obligations, risk profile, geographic footprint and organisational complexity can all influence how risk capabilities are structured. The objective is not to create a universal organisational structure, but to ensure that responsibilities and capabilities work together effectively.

​

What Does a Risk Management Operating Model Include?

​

An effective risk management operating model brings together six interconnected components. Weakness in one can affect the effectiveness of the others, which is why operating model design needs to consider the system as a whole rather than individual functions in isolation.

​

Governance & accountability

Governance establishes who is accountable for risk, where decisions are made and how oversight operates. Clear accountability helps ensure that risk ownership remains connected to the business decisions and activities that create or change risk.

​

Roles & responsibilities

Roles and responsibilities determine how risk management activity is distributed across management, embedded risk teams, specialist functions, Risk, Compliance and Internal Audit. This includes defining the respective responsibilities of the First, Second and Third Lines while avoiding unnecessary duplication or gaps between them.

​

Organisation & structure

Organisation and structure determine where risk capabilities sit and how they are organised. Depending on the organisation, this may include centralised, decentralised or federated functions, as well as 1.5 Line and embedded risk teams. Structure should support the required capability without obscuring ownership or creating unnecessary hand-offs.

 

Processes & interaction

A risk operating model also defines how activities connect across organisational boundaries. Risk identification, assessment, controls, monitoring, escalation, reporting, challenge and assurance may involve several teams. Their effectiveness therefore depends not only on individual processes, but on how those processes interact.

 

People & capability

Structures and frameworks cannot operate effectively without the right skills, capacity, authority and judgement. The operating model should consider what capabilities are required at different levels of the organisation and whether people have sufficient authority and information to fulfil their responsibilities.

 

Data & technology

Risk management increasingly depends on reliable information, systems and technology. Data should support timely monitoring, escalation and decision-making, while technology should make the operating model more effective rather than simply automate existing processes and administrative complexity.

​

These six components are closely connected. Changing where a risk function sits, for example, may have implications for accountability, capability, information flows, governance and assurance. Effective risk operating model design therefore looks beyond the organisational chart to understand how risk management actually operates across the business.​​​​

2. Risk Management Operating Model vs Risk Management Framework

​

A risk management framework and a risk management operating model are closely related, but they serve different purposes. The framework defines how the organisation approaches risk management. The operating model determines how the organisation is structured and equipped to make that approach work in practice.

​

The distinction matters because an organisation can have a well-designed risk management framework without having an effective operating model to support it. Policies, methodologies and governance requirements may be clearly documented, yet responsibilities can remain fragmented, capabilities duplicated, information disconnected or decision-making slow.

​

How Do Risk Strategy, the Risk Management Framework and the Operating Model Differ?

​

The three should work together rather than operate as separate layers.

​

Risk strategy defines what risk management needs to enable. It connects risk management to the organisation's strategy, objectives and the decisions required to achieve them.

​

Risk management framework establishes the principles, governance, methodologies and processes through which risks are identified, assessed, managed, monitored and reported.

​

Risk management operating model defines the roles, organisational structures, capabilities, interactions, information and technology required to put that framework into practice across the organisation.

​

In simple terms:

  • Risk strategy → what risk management needs to enable

  • Risk management framework → how risk will be managed

  • Risk management operating model → how the organisation makes it work

 

These elements are interdependent. Changing the framework can create new requirements for people, processes, data or governance. Equally, weaknesses in the operating model can prevent a sound framework from working as intended.

This is why reviewing a risk operating model should go beyond organisation charts and reporting lines. The question is not only where Risk sits, but whether the wider organisation has the accountability, capability, information and interactions required to manage risk effectively.​

​

3. Why Risk Management Operating Models Become Complex

 

Risk management operating models rarely become complex because of a single design decision. Complexity accumulates over time.

​

As organisations grow and change, their approach to managing risk needs to evolve with them. New products create new exposures. Regulatory change introduces additional obligations. Incidents lead to remediation. New technologies create different dependencies. Growth brings new teams, jurisdictions and third parties. Specialist risk capabilities develop as particular risks require greater expertise.

​

Each change can create a legitimate need for additional risk management activity.

​

Organisations may introduce:

  • new risk and compliance functions to address specialist risks;

  • additional controls in response to incidents, regulatory requirements or identified weaknesses;

  • new committees and governance forums to strengthen oversight;

  • additional reporting and management information;

  • further testing, monitoring and assurance;

  • new policies, standards and procedures;

  • specialist technology and data requirements;

  • additional approval, escalation and evidence requirements; and

  • new roles or organisational layers following growth, acquisitions or restructuring.

 

Most of these decisions can make sense individually. A new control may address a genuine weakness. A committee may improve oversight. Additional reporting may respond to an information gap. A specialist risk team may provide expertise the organisation previously lacked.

​

The challenge appears when these decisions are considered collectively.

​

When Individually Sensible Changes Create System-Wide Complexity

​

Risk management arrangements often develop incrementally rather than being redesigned as a complete system.

A new requirement may be added without removing an older one. A specialist function may introduce its own assessment while an existing assessment remains in place. An incident may generate new controls, reporting and assurance that continue long after the immediate remediation has been completed.

​

Over time, different parts of the organisation can therefore create overlapping requirements around the same business activity.

​

The result may be:

  • duplicated controls and assessments;

  • multiple teams requesting similar information;

  • overlapping governance and assurance;

  • unclear or fragmented accountability;

  • increasing numbers of hand-offs and approvals;

  • growing reporting and evidence requirements; and

  • more management time spent navigating risk processes.

 

This does not necessarily mean that any individual risk function or governance process is poorly designed. The problem can exist at the level of the operating model as a whole.

​

That distinction matters. Looking at each function independently may show reasonable processes, appropriate controls and legitimate requirements. Looking across them may reveal an operating model that has become increasingly difficult for the business to navigate.

​

Complexity Is Not the Same as Ineffectiveness

​

A complex organisation will often require a more sophisticated risk operating model. Multiple jurisdictions, regulated activities, products, technologies and third-party dependencies cannot always be governed through simple structures.

The objective should therefore not be to eliminate complexity for its own sake.

​

The more useful question is whether the complexity remains necessary, proportionate and connected to an identifiable risk management or decision-making outcome.

​

This shifts the operating-model discussion away from simply asking whether Risk and Compliance have enough resources.

​

It raises a different question:

How much activity is the organisation generating through the way risk is managed, governed, evidenced and assured?

​

That is the question behind Risk Demand.

​

4. Risk Demand: Looking Beyond Risk Function Headcount

​

When organisations review their risk management operating model, the discussion often starts with resources and structure. How large should the Risk function be? Where should particular responsibilities sit? Is there duplication between the First and Second Lines? Could technology reduce the workload?

​

These are important questions, but they primarily examine the supply of risk management capacity.

They do not necessarily explain what is generating the work in the first place.

​

What Is Risk Demand?

​

Risk Demand is the total organisational activity required to manage risk, together with the additional activity generated by how that risk is governed, evidenced and assured.

​

This extends the operating-model discussion beyond the size of formal Risk, Compliance or assurance functions. Risk management activity is distributed across the organisation.

​

Business teams perform controls, complete assessments, maintain evidence, investigate exceptions and respond to challenge. Specialist functions establish requirements and conduct monitoring. Management reviews information and attends governance forums. Internal Audit provides independent assurance. Issues generate remediation activity that can involve multiple teams over extended periods.

​

The true organisational footprint of risk management can therefore be significantly larger than the number of people whose job titles contain the word risk.

​

From Risk Supply to Risk Demand

​

Traditional operating-model reviews often begin with supply:

  • How many people are in Risk?

  • How large should Compliance be?

  • What should sit in the First or Second Line?

  • Where should a 1.5 Line sit?

  • What activities could technology automate?

 

A supply perspective is necessary. Organisations need the right structures, capabilities and resources.

​

But changing supply does not necessarily change the underlying workload.

​

Moving an activity from the Second Line into a 1.5 Line, for example, may change who performs it without reducing the activity itself. Automating a report may reduce the effort required to produce it without answering whether the report is still needed. Adding resources can relieve immediate capacity pressure while leaving the causes of that pressure unchanged.

​

Risk Demand asks the complementary question: What is generating the work in the first place?

​

That changes the focus of an operating-model review. Instead of looking only at where activities sit, it examines why those activities exist, how they interact and whether the cumulative demand remains proportionate to the risks and decisions they are intended to support.

​

Where Does Risk Demand Come From?

​

Risk Demand can emerge through three forms of layering: horizontal, vertical and temporal. These layers help explain why risk-related workload can grow even when individual requirements appear reasonable.

​

Horizontal Layering: Multiple Risk Disciplines Converge on the Same Activity

​

Horizontal layering occurs when multiple specialist risk disciplines apply requirements to the same business activity.

A significant business change, for example, might require input from Operational Risk, Compliance, Financial Crime, Cyber Security, Data Privacy, Third-Party Risk, Operational Resilience and, increasingly, AI or Model Risk.

​

Each discipline may have a legitimate reason for being involved. But if each operates through separate assessments, evidence requests, approvals, reporting and governance, the business experiences the combined demand, not each requirement in isolation.

​

The operating-model question is therefore not simply whether every specialist function has an appropriate process. It is whether those processes are sufficiently coordinated when they converge on the same activity.

​

Vertical Layering: One Requirement Creates Multiple Layers of Activity

​

Vertical layering occurs when managing a risk generates successive layers of governance, evidence and assurance around the underlying activity.

​

A regulatory or internal requirement may initially result in the introduction of a control. Operating that control creates a need to demonstrate that it has been performed, which generates evidence. That evidence may then be subject to monitoring and challenge, with the results incorporated into management reporting and governance.

​

Further layers can develop through control testing and independent assurance. Where weaknesses are identified, issues and remediation actions may be created, bringing their own requirements for ownership, tracking, reporting, evidence of completion and closure validation.

​

In this way, a single requirement can generate a much wider chain of organisational activity than the control itself. None of those activities is necessarily unnecessary. Evidence, challenge, governance and assurance can all play important roles in effective risk management.

​

The operating-model question is whether the cumulative activity remains proportionate to the risk being managed, and whether each layer continues to provide information, challenge or assurance that supports a clear purpose.

​

Temporal Layering: New Requirements Accumulate Without Older Ones Disappearing

​

Temporal layering occurs when new risk requirements, controls and governance arrangements are added while earlier ones remain in place.

​

This frequently happens because organisations evolve incrementally. Regulatory change creates a new process. An incident produces additional controls. A remediation programme introduces enhanced reporting. A new risk taxonomy creates further assessments. Technology enables additional monitoring.

​

The immediate requirement may eventually change or disappear, but the processes created in response can remain.

Over time, the organisation can accumulate controls, reports, committees, assessments and evidence requirements that were each introduced for a reason but have rarely been reconsidered as a complete system.

​

This is one reason risk management workload can increase without any single decision appearing responsible for the increase.

​

Why Risk Demand Matters to Operating Model Design

​

Understanding these three sources of Risk Demand changes what an operating-model review is trying to solve.

​

If the problem is viewed primarily as a capacity issue, the likely responses are structural: increase resources, redistribute responsibilities, create an embedded team, change reporting lines or automate existing processes.

​

Those interventions may be appropriate. But they can also redistribute or accelerate Risk Demand without reducing it.

 

A stronger operating-model review therefore considers both sides of the equation:

  1. Risk supply: Do we have the right people, capabilities, structures and technology?

  2. Risk demand: Are we generating the right activities, at the right level, for the risks and decisions that matter?

 

The objective is not simply to reduce activity. Some organisations may discover that particular risks require more oversight, stronger controls or additional capability. The purpose is to understand the demand being generated and determine whether it is necessary, proportionate and connected to a clear risk management or decision-making outcome.

​

That distinction becomes particularly important when organisations consider redesigning the Three Lines, introducing 1.5 Line functions, centralising or decentralising risk capabilities, or using AI and technology to increase efficiency.

​

Explore Risk Demand in More Detail

​

Risk Demand can grow both through the volume of risk activity an organisation generates and through the administrative activity required to govern, evidence and assure it.

​

Sources of Risk Demand infographic showing how business requirements, regulatory requirements, risk framework requirements, and assurance and oversight generate overlapping risk management activity across an organisation.

5. How Does the Three Lines Model Fit Within a Risk Operating Model?

​

The Three Lines Model provides a structure for accountability, oversight and assurance, but it is only one component of the wider risk management operating model.

​

It helps organisations distinguish between ownership of business activity and risk, oversight and challenge, and independent assurance. But an effective operating model must go further. It also needs to determine where specialist capabilities sit, how functions interact, how information flows and how risk activity supports decision-making.

​

What Are the Roles of the Three Lines?

​

First Line

The First Line owns business decisions, the risks arising from those decisions and the controls required to manage them. Risk management should therefore be part of how the business operates rather than an activity performed on its behalf by the Risk function.

 

Embedded / 1.5 Line

Some organisations establish embedded or 1.5 Line risk teams to provide specialist capability closer to business activity. These arrangements can strengthen risk capability and coordination, but their role needs to be clearly defined so that support does not inadvertently transfer ownership away from the business or duplicate Second Line activity.

 

Second Line

The Second Line provides risk frameworks, specialist expertise, oversight and independent challenge. Its role is not simply to produce policies or monitor compliance with processes, but to help ensure that material risks are understood, managed and appropriately escalated.

 

Third Line

The Third Line provides independent assurance over the effectiveness of governance, risk management and control. Its independence from management responsibilities is fundamental to the assurance it provides.

 

Where Do Specialist Risk Functions Fit?

​

The Three Lines can become less straightforward when organisations develop specialist functions for areas such as Compliance, Financial Crime, Cyber Security, Data Privacy, Operational Resilience and Model or AI Risk.

​

Depending on the organisation, these capabilities may sit within the First or Second Line, operate through embedded teams, or involve responsibilities spanning several parts of the operating model.

​

The objective should not be to force every capability into a theoretical organisational structure. It should be to establish clear ownership, appropriate independence and effective interaction between the different capabilities involved in managing risk.

​

The More Important Operating-Model Question

​

Debates about risk operating models can quickly become debates about where activities should sit: First Line or Second Line? Centralised or embedded? Risk or Compliance? Business or specialist function?

​

Those questions matter, but they can start too late in the analysis.

​

The question is not simply which Line should perform an activity. It is why the activity exists, what outcome it supports, and where it can most effectively be performed without compromising accountability or independent challenge.

​

This is particularly important when reviewing 1.5 Line arrangements or attempting to reduce duplication. Moving an existing activity from one Line to another may change organisational responsibility without changing the underlying Risk Demand.

​

A more effective review therefore starts with the purpose of the activity and the outcome it is intended to achieve. Only then should the organisation determine where that activity is best performed and what level of oversight or assurance it requires.

​

This shifts the Three Lines discussion from organisational placement to operating-model effectiveness.

​

Related insights:

​

6. How to Design a Risk Operating Model Around Business Activity

​

Risk management operating models are often designed around specialist functions. Operational Risk, Compliance, Financial Crime, Cyber Security, Data Privacy, Operational Resilience, Third-Party Risk, Model Risk and Internal Audit each have distinct responsibilities, expertise and requirements.

​

That vertical structure can provide important clarity and specialist capability.

​

The business, however, does not experience risk management vertically.

​

Business activity cuts across those organisational boundaries. A new product, outsourcing arrangement, technology transformation or customer journey may involve several risk and control functions at the same time. From the perspective of the business, those separate requirements become part of a single decision or activity.

​

This creates an important operating-model challenge: how to preserve specialist expertise and appropriate independence while making the combined risk management experience coherent and proportionate.

​

When Multiple Risk Functions Converge on One Decision

​

Consider the launch of a new product. Depending on its nature, the initiative might require interaction with:

  • Compliance;

  • Financial Crime;

  • Data Privacy;

  • Cyber Security;

  • Third-Party Risk;

  • Operational Risk;

  • Operational Resilience; and

  • Model or AI Risk.

 

Each function may be addressing a legitimate and materially different risk.

​

Compliance may consider regulatory obligations and customer outcomes. Financial Crime may assess exposure to fraud, money laundering or sanctions. Data Privacy may examine how personal information will be collected and processed. Cyber Security may assess vulnerabilities and security requirements. Third-Party Risk may review external providers. Operational Resilience may consider dependencies and disruption scenarios. Model or AI Risk may introduce further requirements where automated decision-making or artificial intelligence is involved.

​

The problem is not necessarily the involvement of multiple functions. It is how their requirements interact.

​

If every function independently requests information, performs assessments, establishes approvals, requires evidence and reports through separate governance channels, a single business initiative can generate substantial cumulative Risk Demand.

​

From within each specialist function, the process may appear reasonable. From the perspective of the product team, it can feel like navigating multiple risk management systems simultaneously.

​

Design for the Point Where Risk Functions Meet

​

An effective risk operating model therefore needs to work from the perspective of business activity as well as individual risk disciplines.

​

That does not mean combining specialist functions or removing their independence. Nor does it mean that every risk should be assessed through a single generic process. Different risks require different expertise and, in some cases, distinct regulatory treatment.

​

The opportunity is to examine where those requirements converge.

​

For example, organisations can consider whether common information can be collected once rather than repeatedly, whether assessments can be coordinated around the same decision, whether approval and escalation routes are clear, and whether governance receives an integrated view of the material risks rather than a series of disconnected functional perspectives.

​

This changes the design question from:

“How should each risk function operate?”

to:

“How should risk management operate when multiple functions interact with the same business activity?”

 

That distinction is important because operating-model effectiveness is experienced at the points of interaction between functions, not simply within them.

​

A well-designed model should therefore preserve the depth of specialist risk expertise while reducing unnecessary friction at those points of convergence. The objective is not fewer risk disciplines. It is better coordination of their combined contribution to business decisions.

​

Risk functions converging around business activity, showing a product launch passing through Compliance, Financial Crime, Data Privacy, Cyber Security, Third-Party Risk, Operational Risk, Operational Resilience and Model/AI Risk requirements.

7. The Hidden Administrative Footprint of Risk Management

​

Not all risk management activity is directly concerned with managing the underlying risk.

​

As risk frameworks mature, organisations also create activity to demonstrate, govern and assure that risks are being managed appropriately. This activity is often necessary, but it can create a substantial administrative footprint that is easy to underestimate when reviewing a risk management operating model.

​

Managing Risk vs Administering Risk Management

​

There is an important distinction between managing the underlying risk and administering the mechanisms used to demonstrate, govern and assure that the risk is being managed.

​

Managing the underlying risk includes activities that directly influence the exposure or outcome: designing an effective process, preventing fraud, protecting systems, managing a supplier dependency, responding to an incident or maintaining the resilience of a critical service.

​

Administering risk management includes the surrounding activity required to establish responsibilities, document controls, maintain evidence, monitor performance, report through governance, respond to challenge, track remediation and demonstrate that the required processes have been followed.

​

The two are closely connected. Effective risk management requires appropriate governance, evidence and assurance. The distinction matters because the administrative activity surrounding a risk can expand independently of the underlying risk itself.

​

How the Administrative Footprint Grows

​

A single risk management requirement can generate activity throughout its lifecycle.

​

It begins with the need to define and allocate responsibilities, requirements and controls. The organisation may then need to evidence and demonstrate that those controls are operating. That evidence can create further activity to monitor and challenge performance, followed by requirements to report and govern the results.

​

Where weaknesses are identified, organisations need to remediate and close issues and actions, often with further evidence and validation. Meanwhile, policies, assessments, controls, systems, committee materials and reporting arrangements need to be maintained and coordinated as the organisation and its risks change.

​

The administrative footprint therefore extends across six connected areas:

Define & allocate → Evidence & demonstrate → Monitor & challenge → Report & govern → Remediate & close → Maintain & coordinate

​

Each stage can generate work across the business, Risk, Compliance and assurance functions. When multiplied across risk types, regulations, controls, legal entities and governance structures, relatively small administrative requirements can become a significant source of Risk Demand.

​

Administration Is Not the Problem

​

The objective is not to remove risk administration.

​

Evidence can demonstrate that controls are working. Reporting can support effective oversight. Challenge can identify weaknesses. Assurance can provide confidence to Boards, management and regulators. Remediation processes help ensure that identified problems are addressed.

​

The issue is proportionality.

​

Over time, organisations can retain reports after their original purpose has changed, collect similar evidence for different functions, maintain overlapping control sets or subject the same activity to several layers of monitoring, testing and assurance. Individually, each requirement may still appear reasonable. Collectively, they can consume significant organisational capacity without providing an equivalent increase in risk insight or control effectiveness.

​

This creates a different question for operating-model design:

Is the total administrative footprint proportionate to the risk management, governance or assurance outcome it supports?

​

Answering that question requires looking beyond the efficiency of individual processes. A report can be efficiently produced and still be unnecessary. A control can be efficiently evidenced while the same evidence is requested elsewhere. Technology can make an assessment faster to complete without addressing whether multiple assessments are needed in the first place.

​

The aim is therefore not simply to make risk administration faster. It is to understand where it creates value, where requirements overlap and where activity has accumulated without sufficient consideration of its continuing purpose.

That is an important part of reducing Risk Demand without weakening risk management.

​

Explore the Hidden Administrative Burden of Risk Management

​

Explore how evidence, reporting, governance, assurance and remediation can create a growing organisational workload around the management of risk, and why improving efficiency requires looking beyond the formal size of the Risk function.

​

​​

Iceberg infographic showing the visible work of fixing a risk issue above the waterline and the larger administrative workload below it, including classification, remediation actions, ownership, reporting, evidence, challenge, extensions, closure and validation.

8. What Does an Effective Risk Management Operating Model Look Like?

​

An effective risk management operating model is not defined by the number of frameworks, committees, controls or specialist functions an organisation has. It is defined by whether those components work together to support the organisation in managing risk effectively.

​

As organisations grow, some additional complexity is inevitable. New risks emerge, regulatory expectations change, specialist expertise becomes necessary and governance evolves. The objective is therefore not structural simplicity for its own sake. It is an operating model in which complexity remains purposeful and manageable.

​

Six characteristics provide a useful test.

​

1. Clear

Accountability, responsibilities and decision rights are understood.

People should know which risks and decisions they own, what is expected of them and when specialist input, challenge or escalation is required. This includes clarity between business ownership, embedded or 1.5 Line capabilities, Second Line oversight and Third Line assurance.

Clarity reduces both gaps and duplication. Where responsibilities are ambiguous, activities can be repeated because several functions believe they need to perform them, or omitted because each assumes someone else is responsible.

​

2. Proportionate

Governance, control, challenge and assurance reflect the risk and outcome involved.

Not every risk, decision or business activity requires the same level of assessment, documentation, approval or assurance. Materiality, complexity, regulatory requirements and potential impact should influence the response.

Proportionality also applies over time. Enhanced monitoring or governance may be appropriate following an incident or during a significant change without needing to become the permanent operating standard.

​

3. Integrated

Risk management connects with business processes rather than operating as a parallel administrative system.

Risk considerations should be embedded where products are developed, suppliers selected, technology changed, customers served and strategic decisions made. Wherever possible, the information generated through those activities should also support risk management rather than requiring a separate version of the business to be recreated for the risk framework.

Integration keeps attention on the underlying activity and outcome rather than on completing a parallel risk process.

 

4. Coordinated

Different risk and assurance functions retain appropriate independence without unnecessarily reproducing work.

Operational Risk, Compliance, Financial Crime, Cybersecurity, Data Privacy and other specialists may need different perspectives on the same activity. Internal Audit must retain the independence required to provide objective assurance.

Coordination does not mean collapsing those responsibilities. It means understanding where their requirements intersect, using existing information where appropriate and ensuring that independence of judgement does not automatically translate into duplication of activity.

 

5. Decision-focused

Risk information and activity exist for identifiable governance, monitoring, accountability or decision purposes.

A risk assessment may inform a decision. A KRI may indicate when intervention is required. A control record may establish accountability. Reporting may support oversight. Evidence may demonstrate that an obligation has been met.

The form can differ, but the purpose should be identifiable. When an organisation can no longer explain who uses an activity or information requirement, what it enables or why it remains necessary, its continued value becomes difficult to establish.

6. Adaptable

Controls, governance, reporting and assurance can be changed, consolidated or retired as circumstances evolve.

Risk operating models accumulate. New requirements are introduced following regulatory change, incidents, audit findings, organisational growth and emerging risks. Without an equivalent mechanism for reviewing what already exists, yesterday's responses can become tomorrow's permanent infrastructure.

​

An adaptable operating model treats its own design as something that requires continuing attention. Requirements can be strengthened when exposure increases, simplified when circumstances change and retired when their original purpose no longer exists.

​

Taken together, these characteristics shift the emphasis away from the quantity of risk management activity and towards the quality of the operating model supporting it.

​

An effective risk management operating model creates enough structure to provide control, challenge and assurance, while remaining sufficiently connected to the business to support timely decisions and effective management of risk.

​

Infographic showing six characteristics of an effective risk operating model: clear, proportionate, integrated, coordinated, decision-focused and adaptable, working together to support better decisions, efficient use of resources and stronger risk management outcomes.

9. How AI and Technology Are Changing Risk Operating Models

​

Technology can make risk management faster and more scalable. Workflows can be automated, controls monitored continuously, evidence collected directly from systems, reporting generated more efficiently and large volumes of information analysed more quickly.

​

These capabilities can remove significant manual effort. They can also improve the timeliness and accessibility of risk information. But their impact depends heavily on the operating model into which they are introduced.

​

Automating an assessment does not determine whether the assessment is still necessary. Connecting systems does not resolve overlapping governance requirements. Generating management information faster does not establish whether that information is useful. Technology can improve individual activities while leaving the wider architecture of risk management largely unchanged.

​

Generative AI takes this further because it materially changes the economics of producing risk-management content.

Policies, risk assessments, control documentation, committee papers, regulatory analysis, management information, monitoring outputs and assurance documentation can increasingly be produced or analysed with substantially less manual effort.

​

Evidence from other forms of knowledge work indicates how significant this productivity effect could become. Research involving 758 consultants found that participants using GPT-4 completed 12.2% more tasks and worked 25.1% faster on tasks within the technology's capability frontier. A 2026 study of software development found that generative AI increased code output by more than 50%, while completed tasks increased by 22%. These studies do not examine risk management, but they demonstrate the potential for generative AI to increase the volume of knowledge-work outputs while reducing the effort required to produce them.

​

The AI Risk Administration Rebound Effect

​

That productivity creates a different operating-model challenge.

​

Risk administration has historically been constrained partly by the effort required to produce it. Assessments take time. Committee papers need to be written. Regulatory requirements need to be analysed. Evidence needs to be examined. Expanding any of these activities has traditionally required additional people or capacity.

​

AI weakens that constraint.

​

A risk function may be able to undertake more frequent assessments without additional headcount. Governance forums can receive more tailored analysis. Monitoring can examine more data and identify more exceptions. Regulatory developments can be mapped against more policies, controls and obligations. Assurance teams can analyse larger populations of evidence.

​

Each development may appear beneficial in isolation. Collectively, however, they could increase the amount of risk-management activity that the organisation then has to absorb.

​

If the cost of producing administration falls, organisations may produce more administration.

​

This resembles the economic concept of a rebound effect, where efficiency improvements reduce the cost of an activity but increased consumption offsets some of the resulting benefit. Its application to risk management remains a hypothesis rather than an empirically established effect, but it raises an important question for the design of AI-enabled risk operating models.

​

The constraint may increasingly sit with the people expected to make sense of what technology produces.

More analysis requires attention. More monitoring can generate more exceptions requiring investigation. More detailed assessments create more findings to consider. More regulatory mappings may identify additional gaps or dependencies. AI-generated recommendations still need contextual judgement, challenge and accountable decisions.

​

The consequence is not necessarily less work. It may be a different distribution of work.

​

Research involving 7,137 knowledge workers across 66 firms offers an early indication of this broader dynamic. Frequent users of an AI tool spent around 3.6 fewer hours each week on email and completed documents faster, while meeting time did not significantly decline. Technology made particular activities more efficient without automatically removing the organisational processes surrounding them.

​

For risk operating models, productivity therefore needs to be considered beyond the activity being automated. Hours saved in producing an assessment matter, but so does any additional activity created because assessments have become easier to produce. Faster monitoring is valuable, but its benefit depends partly on what happens to the additional signals it generates.

​

This makes total Risk Demand a useful test of technology investment. The opportunity is not simply to perform the existing risk operating model faster. Technology can also help organisations reuse information, identify overlapping requirements, draw directly on existing evidence and remove administrative activity that no longer contributes sufficiently to governance or risk outcomes.

​

The greater opportunity from AI is not faster risk administration. It is a better risk operating model.

​

10. When Should an Organisation Review Its Risk Operating Model?

​

Risk operating models should evolve as the organisation around them changes. Growth, new regulation, technology, acquisitions and changes to the business model can all alter the risks an organisation faces and the capabilities required to manage them.

​

The need for review, however, is not limited to major organisational events. It can also become visible through persistent friction in day-to-day risk management.

​

Typical triggers include:

  • Organisational growth or restructuring, particularly where responsibilities, governance arrangements or reporting lines have not evolved at the same pace.

  • Persistent pressure on Risk and Compliance resources, despite additional investment, recruitment or technology.

  • Unclear First and Second Line responsibilities, including recurring uncertainty over ownership, challenge, oversight or escalation.

  • Establishment or review of a 1.5 Line, where the organisation needs to determine which activities should remain embedded within the business and which benefit from specialist capability.

  • Duplicated assessments, controls or assurance, particularly where different functions repeatedly interact with the same business activities.

  • Recurring control weaknesses, where remediation addresses individual findings but similar problems continue to emerge.

  • Regulatory change, especially where new requirements have been added to existing frameworks without considering their cumulative effect.

  • Major transformation programmes, which can expose gaps between established risk arrangements and new ways of operating.

  • Fragmented risk reporting, where significant information exists but management struggles to develop a coherent view across risks, dependencies and business activities.

  • Technology or AI adoption, particularly where automation changes how controls operate, how evidence is generated or how risk information is produced and consumed.

  • Mergers and acquisitions, where different frameworks, systems, controls and governance arrangements need to coexist or be integrated.

  • Significant changes to the business model, including new products, markets, delivery channels, outsourcing arrangements or strategic priorities.

 

These conditions can indicate that the existing model no longer fits the organisation as well as it once did. But they do not automatically mean the organisational structure needs redesigning.

​

Persistent resource pressure, for example, could reflect insufficient staffing, but it could also result from duplicated processes or unnecessary Risk Demand. Unclear accountability may arise from reporting lines or from poorly defined responsibilities and decision rights. Fragmented reporting might originate in technology, information flows or governance rather than organisational structure.

​

An effective review therefore needs to diagnose the source of the problem before proposing a solution. Depending on the circumstances, that may involve structure, processes, governance, capability, technology, information or the amount of Risk Demand being generated across the organisation. More than one may be contributing at the same time.

​

In some organisations, structural change will be appropriate. Others may need clearer responsibilities, better coordination between risk disciplines, stronger capabilities, improved information flows or changes to requirements that have accumulated over time.

​

This avoids turning every operating-model problem into a reorganisation. The purpose of the review is not necessarily to design a new structure. It is to determine what is preventing the risk operating model from working as effectively as it should.

11. How to Review and Redesign a Risk Management Operating Model

​

Reviewing a risk operating model should begin with how risk management actually works across the organisation, rather than with a proposed structure.

​

Organisation charts, role profiles and governance frameworks provide part of that picture. They do not necessarily show where risk activity takes place in practice, how different functions interact with the business, where administrative demand accumulates or how effectively information reaches decision-makers.

​

A five-stage review can provide a more complete view.

​

1. Understand the Current Model

​

Start by establishing how risk management operates today.

Map where significant risk and control activities take place across the First, Second and Third Lines, including any embedded or 1.5 Line capabilities. Understand the governance forums involved, how information moves between them, where specialist functions interact with the business and how significant decisions are escalated.

The objective is to capture the operating reality, including activities that may not be visible from formal structures.

 

2. Diagnose Risk Demand

​

Once the current model is understood, examine what is generating the workload within it.

This includes regulatory requirements and legitimate business needs, but also the cumulative effect of assessments, controls, evidence, reporting, governance, testing, assurance and remediation. Particular attention should be paid to duplication, repeated hand-offs, overlapping requirements and activities that have persisted after their original purpose has changed.

This helps distinguish genuine capacity requirements from demand created by the way risk management itself has been designed.

 

3. Test Roles and Capabilities

​

The next stage is to determine whether responsibilities and capabilities support the risks the organisation needs to manage.

Accountability should be clear across the Three Lines, including who owns risk and decisions, where specialist support belongs, what independent challenge is expected and when escalation is required.

Capability should be considered alongside responsibility. Assigning ownership achieves little if the relevant function lacks the expertise, authority, information, technology or capacity required to exercise it effectively.

 

4. Design the Target Operating Model

​

Only after the existing model and its underlying problems are understood should the target model be designed.

The design should align structure, processes, governance, capabilities, information and technology with the organisation's strategy, business model and risk profile. It should also consider how the different components operate together rather than optimising each one independently.

The target model does not necessarily need more structure. In some areas it may require additional capability or oversight. In others, clearer accountability, consolidation of requirements or removal of unnecessary activity may provide the greater improvement.

 

5. Implement and Adapt

​

Implementation should test whether the redesigned model changes how risk management actually operates, rather than simply whether the new structure has been introduced.

Responsibilities need to be embedded, governance transitioned, processes and systems changed where necessary, and people given the capabilities required to operate the model.

​

The model should then continue to evolve. Reporting that no longer serves its original purpose can be retired. Overlapping processes can be consolidated. Controls and assurance can change as risks develop. New technology can alter where work is performed and what information is available.

​

A risk operating model is therefore not finished when the target structure goes live. Its effectiveness depends on whether it continues to support the organisation's strategy, decisions and risk profile without allowing unnecessary Risk Demand to accumulate around it.

​

From Diagnosis to Implementation

​

The depth of review required will depend on the organisation. Some may need a focused assessment of responsibilities, governance or a particular source of Risk Demand. Others may require a broader redesign spanning the risk framework, Three Lines model, capabilities, information flows and supporting technology.

​

Aevitium's Integrated Risk Management Framework™ supports organisations through this process, from assessing the current model and identifying priority improvements through to redesign and implementation. The emphasis is on strengthening how risk management works as a connected organisational capability, rather than assuming that every review requires structural change.

​

Explore Aevitium's Integrated Risk Management & Governance services →​​​​​​​​​​

Integrated Risk Management visual illustrating the connection between strategy, governance, accountability and decision-making through Aevitium’s integrated risk framework.

12. Case Study: Reviewing Risk Activity Beyond the Formal Operating Model

​

The Challenge

​

An organisation reviewing the appropriate scope of its 1.5 Line initially framed the question around structure and responsibilities: which activities should sit within the 1.5 Line, which should remain with the business, and how responsibilities should interact with the Second Line.

​

Looking beyond the formal operating model revealed a broader issue. Significant risk and control activity was taking place throughout the organisation, including activity performed by teams and individuals without formally designated risk roles.

​

The question therefore became wider than where the 1.5 Line should sit or what it should own. It required understanding where risk-related work was actually being performed and what was generating that activity.

​

The Approach

​

The review looked beyond organisation charts and formal role descriptions to examine the operating model as it worked in practice.

​

This included mapping where risk and control activity occurred across the organisation, identifying what generated that activity, and examining how responsibilities interacted across business, embedded and specialist risk functions.

​

The analysis also considered areas of duplicated or overlapping activity, the administrative demand created by governance and risk processes, the capabilities required to perform different activities effectively, and how governance, challenge and assurance operated across the model.

​

This provided a broader view of the organisation's Risk Demand, rather than treating formally designated risk resources as the full extent of its risk management activity.

​

Key Outcomes

​

The review highlighted an important distinction between changing organisational structure and changing the amount of risk activity the organisation generates.

​

Changing where activity sits does not necessarily change how much activity the organisation generates.

Moving an assessment, control, monitoring activity or governance responsibility from one team to another may clarify accountability or place capability closer to the business. But if the underlying requirement remains unchanged, the work has been reallocated rather than removed.

​

This means a structural redesign can move Risk Demand between the First Line, 1.5 Line and Second Line without reducing the organisation's overall risk management workload.

​

The analysis therefore provided a stronger basis for considering the future operating model: not simply where should this activity sit?, but why does it exist, what outcome does it support, what capability does it require, and where can it most effectively be performed?

​

That distinction helps prevent operating-model transformation from becoming an exercise in redrawing organisational boundaries while leaving the underlying drivers of complexity and workload untouched.

13. Transforming the Risk Operating Model

​

Transforming a risk operating model should start with understanding how risk management actually operates today, not simply redrawing organisational charts.

​

Reporting lines and organisational structures are important, but they show only part of the operating model. Effective transformation requires understanding where risk activity occurs, what generates it, how responsibilities interact and whether the overall model supports the decisions and outcomes the organisation needs.

​

Aevitium's approach examines the operating model as a connected system, including:

  • Organisational structure — where risk and control capabilities sit across the organisation.

  • Responsibilities and accountability — who owns risk, makes decisions, provides challenge and delivers assurance.

  • Risk Demand — what generates risk-related activity and where unnecessary duplication, layering or administrative demand may have accumulated.

  • Governance — how decisions, escalation, oversight and accountability operate.

  • Processes and interactions — how business, Risk, Compliance and other specialist functions work together in practice.

  • Capabilities — whether the organisation has the skills, capacity, authority and specialist expertise required.

  • Information — whether risk information reaches the right people at the right time and supports effective decisions.

  • Technology — how systems, automation, data and AI enable the model, and where they may simply accelerate existing complexity.

  • Assurance — how monitoring, testing and independent assurance combine to provide confidence without unnecessary overlap.

 

Designing the Target Risk Operating Model

​

The objective is not to impose a standard operating model or automatically centralise, decentralise or restructure risk functions.

​

The target risk management operating model should reflect the organisation's strategy, regulatory obligations, risk profile and required capabilities. It should also be proportionate to the complexity of the organisation and practical for the people expected to operate within it.

​

Depending on the issues identified, transformation may involve changes to structure and reporting lines. But it may equally require clearer accountability, simplified processes, better coordination between specialist functions, changes to governance or assurance, stronger capabilities, improved information flows or more effective use of technology.

​

The aim is a risk operating model that is clearer, more connected and proportionate, while preserving the specialist expertise, challenge and assurance the organisation needs.

Frequently Asked Questions

​

What is a risk management operating model?

A risk management operating model defines how risk management works across an organisation in practice. It translates risk strategy and the risk management framework into the roles, structures, capabilities, processes, interactions, information and technology through which risks are managed, challenged and assured.

Its purpose is not simply to define where the Risk function sits. It establishes how different parts of the organisation work together to support effective risk management and decision-making.

 

What does a risk management operating model include?

A risk management operating model typically covers governance and accountability, roles and responsibilities, organisation and structure, processes and interactions, people and capability, and data and technology.

It should also consider how these components work together. A change to organisational structure, for example, may affect accountability, information flows, capability requirements, governance and assurance. Operating-model design therefore needs to consider the system as a whole rather than individual functions in isolation.

 

What is the difference between a risk management framework and a risk operating model?

A risk management framework defines the principles, governance, methodologies and processes through which an organisation manages risk. A risk management operating model determines how the organisation is structured and equipped to make that framework work in practice.

Put simply, the framework establishes how risk should be managed, while the operating model establishes how the organisation makes that happen through its people, structures, capabilities, interactions, information and technology.

 

How does the Three Lines Model fit within a risk management operating model?

The Three Lines Model provides a structure for distinguishing business ownership of risk, oversight and challenge, and independent assurance. It is therefore an important part of many risk management operating models, but it is not the operating model itself.

A wider operating model also needs to address specialist risk capabilities, embedded teams, governance, information flows, technology and how different functions interact around business activity. The objective is not simply to allocate activities to a Line, but to determine where they can be performed most effectively while maintaining clear accountability and appropriate independence.

 

What is a 1.5 Line risk function?

A 1.5 Line risk function generally describes a risk or control capability embedded within, or operating close to, the First Line while providing more specialised risk support than the underlying business teams.

There is no single universal 1.5 Line model. Its responsibilities depend on the organisation and may include risk coordination, control support, monitoring, reporting or specialist expertise. The important operating-model question is whether its purpose and responsibilities are sufficiently clear to avoid transferring ownership away from the First Line or duplicating Second Line activity.

 

What is Risk Demand?

Risk Demand is the total organisational activity required to manage risk, together with the additional activity generated by how that risk is governed, evidenced and assured.

It looks beyond formal Risk and Compliance headcount to consider the workload generated across the organisation. Risk Demand can increase as multiple specialist functions interact with the same business activity, as governance and assurance create additional layers of work, and as new requirements accumulate without earlier activities being removed.

Understanding Risk Demand helps distinguish between a genuine resource shortage and an operating model that is generating unnecessary or disproportionate activity.

 

How can organisations reduce duplication across Risk, Compliance and Internal Audit?

Reducing duplication should start by identifying where different functions interact with the same risks, controls, evidence and business activities, rather than simply attempting to reduce the number of functions involved.

Organisations can then examine whether information can be collected once and reused, whether assessments or monitoring can be coordinated, whether assurance activities overlap, and whether different governance requirements serve distinct purposes.

The objective should not be to remove necessary independent challenge or assurance. It is to reduce duplication while preserving the different responsibilities and levels of independence those functions provide.

 

When should an organisation review its risk management operating model?

A review may be appropriate when the organisation experiences significant growth, restructuring, regulatory change, acquisitions, changes in business model or major technology transformation.

Operational symptoms can also indicate a need for review, including persistent capacity pressure in Risk or Compliance, unclear First and Second Line responsibilities, duplicated controls or assessments, fragmented reporting, recurring control weaknesses, overlapping assurance or increasing difficulty navigating risk processes.

These symptoms do not automatically mean that organisational restructuring is required. The underlying issue may instead relate to governance, processes, capability, information, technology or excessive Risk Demand.

 

How can AI improve a risk management operating model?

AI can support a risk management operating model by reducing manual activity in areas such as information analysis, monitoring, evidence review, reporting and the preparation of risk management documentation.

Its greater value, however, may come from redesigning how work is performed rather than simply automating existing processes. Organisations can use AI as an opportunity to reconsider what information is required, where human judgement and challenge add value, and which administrative activities can be simplified or removed.

Technology should therefore be considered alongside operating-model design rather than treated purely as an efficiency layer applied to existing processes.

 

Can AI increase the administrative burden of risk management?

Yes. AI can reduce the cost of producing risk administration while simultaneously increasing the amount of administration an organisation creates.

If policies, assessments, control documentation, regulatory analysis, management information and assurance materials become easier to generate, organisations may produce more of them. The constraint can then move from producing information to reviewing, interpreting, challenging and acting on it.

This creates an AI Risk Administration Rebound Effect: greater production efficiency does not necessarily reduce overall Risk Demand.

The more important operating-model question is therefore whether AI is being used to reduce unnecessary activity and improve decisions, or simply to make the existing administrative footprint faster and cheaper to reproduce.

bottom of page