Skip to content
       

Blog

Operations Is a Boardroom Risk, Not a Back-Office Function

Operations Is a Boardroom Risk, Not a Back-Office Function

 Every board has a hierarchy of risks that determines where its attention goes. Financial risk is on it. So is compliance risk, and increasingly cyber risk, which fought its way onto the agenda over the past decade. These are the categories that get a standing item, a committee, a place in the risk appetite statement, and a portion of the board's scarce time. They are treated as enterprise risks, the kind that can materially damage the company, and so the board governs them directly.

Operations rarely appears on that map. It is filed somewhere below the line of things a board concerns itself with, in the category of execution, the daily running of the business, the domain of management. When operations comes up at all, it tends to arrive dressed as a financial result rather than as a risk in its own right. The board sees the margin, not the fragility that produced it. And so one of the largest sources of enterprise risk in an operations-intensive business sits almost entirely outside the board's formal risk governance, not because anyone decided it should, but because it was quietly categorized as a back-office function a long time ago and never reclassified.

 This piece argues that the categorization is wrong, and the consequences are costly. Operational failure is not a back-office inconvenience. It is enterprise risk, it meets the formal definition of enterprise risk, and it belongs on the board's risk agenda alongside the categories that already command its attention. The case for this is not novel in principle. It is exactly the case that put cyber risk on the board agenda, applied to a risk that has not yet made the same journey.

What Operational Risk Actually Is

The reason operations belongs in the risk conversation becomes clear the moment you look at how risk professionals actually define operational risk, rather than how boards informally think about it.

The reference definition comes from the Basel Committee on Banking Supervision, which describes operational risk as the risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events. Although the definition was developed for financial institutions, the framework travels remarkably well to any operations-intensive business, and to property in particular. Read slowly, it says something broader and sharper than the casual sense of the word. Operational risk is not merely the chance that something goes wrong on a given day. It is the standing exposure a business carries because of how its processes, its people, and its systems are built, and how they hold up when tested. It is a structural property of the organization, not a series of isolated incidents.

That definition also supplies a ready-made taxonomy, and it is a useful one for any board that wants to think clearly about operational exposure. Every major operational failure can usually be traced to one of four places. It lives in people, in the reality that critical capability often resides in specific individuals whose departure quietly removes it. It lives in process, in workflows that are poorly designed, undocumented, or dependent on manual workarounds that fail under stress. It lives in systems, in the tools and data that may be fragmented, unreliable, or unable to produce a trustworthy answer when one is needed. And it lives in external events, in the disruptions from outside that a fragile operation absorbs badly and a resilient one weathers. A board that has never examined its business through those four lenses has never actually assessed one of its largest risk categories, however rigorously it governs the others.

The Cyber Precedent: How a Back-Office Concern Became a Boardroom Risk

The most instructive thing a board can do with operational risk is to remember how recently cyber risk occupied exactly the same position, and how it got out of it.

Not long ago, cybersecurity was regarded as a technical matter for the IT department, several levels below the boardroom. It was a back-office function, competently handled by specialists, and boards saw no reason to spend their limited attention on it. That view collapsed, and it collapsed for a specific reason: a series of failures made it undeniable that a cyber event was not a technical inconvenience but an enterprise-level threat capable of destroying financial value, customer trust, and reputation in a matter of days. Once cyber risk was understood as operational resilience and business exposure rather than as a systems issue, its place on the board agenda became obvious. Boards built committees, demanded reporting, wrote it into their risk appetite, and in some jurisdictions accepted personal accountability for overseeing it.

The lesson in that transition is not really about cybersecurity. It is about the difference between where a risk feels like it belongs and where it actually belongs. Cyber risk always had enterprise consequences; what changed was the board's willingness to reclassify it from a technical function to a governance responsibility.  Operational risk faces a challenge similar to the one cyber risk faced: translating operational exposure into a governance priority before a major failure forces the issue. It carries the same kind of enterprise consequences, it is still widely mistaken for a back-office function, and it is waiting for the same reclassification. The boards that make that shift deliberately, rather than after a failure forces it, will be the ones that were not surprised.

Why Operational Risk Stays Invisible Until It Is Not

If operational risk is this significant, a fair question is why boards have been able to ignore it for so long without obvious consequence. The answer explains both the neglect and its danger.

Operational risk is unusually good at staying quiet. Unlike a financial covenant breach or a cyber breach, which announce themselves sharply, operational risk usually accumulates slowly and invisibly, as small degradations that individually look manageable. A process grows a little more dependent on one person. A workaround becomes a little more load-bearing. The systems fall a little further behind what the business needs. None of these register as a risk event, and none of them produce a headline. The exposure builds under the surface while every visible indicator stays reassuring, which is precisely what makes it dangerous. A risk that grows silently is a risk that boards, which govern largely through what is reported to them, are structurally inclined to miss.

Then the accumulated exposure surfaces, and when it does, it rarely surfaces as an operational problem. It arrives as a financial shortfall, a compliance failure, a service collapse, a reputational event, or the sudden discovery during a transaction that the business cannot substantiate its own numbers. The board experiences the consequence in a category it does recognize and never traces it back to the operational fragility that produced it. This is the quiet tragedy of operational risk governance: the failure shows up wearing the costume of a different risk, so the board treats the symptom and never diagnoses the cause, leaving the underlying exposure fully intact to surface again.

What Operational Risk Looks Like in Property

The four categories become far more useful when they are made concrete, because operational risk in a property business is not abstract. It has specific, recognizable forms, and a board that wants to govern it should be able to point to each one on its own risk register.

  • People risk is the exposure that lives in individuals. It is the site or regional manager whose departure would remove relationships and judgment that were never written down, the concentration of critical knowledge in a few long-tenured staff, and the turnover in key operational roles that quietly resets institutional memory. In a dispersed portfolio, people risk is easy to underestimate, because the dependence is invisible until the person is gone.

  • Process risk is the exposure that lives in how work is done. It is the renewal workflow that only works because someone manually chases it, the maintenance escalation path that breaks down under volume, the inconsistent handling of compliance procedures across a portfolio, and the reliance on undocumented workarounds that function until the conditions change. Process risk is where operational fragility most often hides in plain sight, because the process appears to work right up until it does not.

  • Systems risk is the exposure that lives in tools and data. It is fragmented operational data spread across incompatible systems, reporting whose integrity cannot be fully trusted, and dependence on a vendor ecosystem whose failure or lock-in the business does not control. Systems risk is what turns a simple board question into a multi-week manual exercise, and the difficulty of answering is itself the symptom.

  • External-event risk is the exposure that lives outside the business. It is regulatory change that alters how the portfolio must operate, rising insurance cost and shrinking availability, climate-driven events that damage physical assets or disrupt service, and utility or supply disruptions that a fragile operation absorbs badly. External events cannot be prevented, which is exactly why the board's concern is whether the operation is resilient enough to withstand them.

A property board that walks its business through these four categories, deliberately and periodically, is doing something most boards never do: assessing its largest risk surface with the same structure it already brings to financial and cyber risk.

Operational Resilience Is the New Governance Language

There is a reason the word resilience now appears in almost every serious governance discussion, and it is directly relevant here. Operational resilience is simply operational risk viewed through the lens of continuity. Where operational risk management asks how to prevent failures, operational resilience asks whether the business can keep its critical operations running when a failure happens anyway. Regulators have increasingly linked the two, treating the ability to withstand and recover from disruption as a governance responsibility in its own right rather than an operational detail.

For a board, resilience is the more useful framing of the two, because it forces the right question. The issue is not only whether the operation runs well on a good day, but whether it keeps functioning when a key person leaves, a core system fails, or an external shock lands. A resilient operation absorbs those shocks. A fragile one transmits them straight to the financial results, the compliance position, and the reputation. Governing for operational resilience is how a board converts an abstract risk category into a concrete standard: not perfection, but the capacity to continue when conditions deteriorate.

Why This Is Sharper in Property Than Almost Anywhere

Operational risk is a serious matter in any business, but in a property business it is arguably the dominant risk category, for reasons rooted in how the sector actually creates and loses value.

In property, the operation is not a support layer beneath the real business. It is close to the whole business. Returns are produced or destroyed through the daily execution of leasing, renewals, maintenance, cost control, and resident relationships across the portfolio, which means operational fragility translates almost directly into financial loss. A property business with weak operations is not merely inefficient; it is carrying a large, live, and largely ungoverned risk to its core returns. Yet property boards, like most boards, often govern their financial and capital risk far more rigorously than the operational risk that actually drives those financials.

The structure of property operations makes the risk harder to see and more costly when it lands. Because the work is dispersed across many buildings, markets, vendors, and teams, operational deterioration in one part of the portfolio can grow well beyond the point of easy correction before it aggregates into anything visible at the center. And because a small per-unit weakness multiplies across a large portfolio, the eventual financial impact of unmanaged operational risk is magnified by the very scale that makes the business attractive. The dispersion that defines property operations is exactly what allows operational risk to compound quietly and surface expensively.

What It Means to Govern Operations as a Risk

Treating operations as a boardroom risk does not mean directors descending into the running of the business, and it does not mean adding operational trivia to an already crowded agenda. It means applying to operational risk the same governance disciplines the board already applies to the risk categories it takes seriously. A few shifts define the change.

The board should name operational risk explicitly in its risk framework. Risks that are not explicitly identified tend to receive less structured oversight, less reporting, and less board attention, which is precisely what has happened to operational risk for decades. Giving it a defined place in the risk register and the risk appetite statement, with the same standing as financial, compliance, and cyber risk, is the single act that moves it from back-office assumption to governed exposure. Naming it forces the questions that follow.

The board should ask management to make the invisible exposure visible. Because operational risk accumulates silently, the board's job is to insist it be surfaced before it converts into a different kind of loss. That means asking where the business depends on specific people rather than systems, where processes rely on undocumented workarounds, whether the operational systems and data are reliable enough to trust under pressure, and how the operation would absorb an external shock. These are risk questions, pitched at the level of exposure rather than daily detail.

The board should treat operational resilience as a governance objective in its own right. The relevant question is not only whether the operation is efficient today but whether it is robust enough to keep functioning when a key person leaves, a system fails, or an external event hits. Resilience is what separates an operation that absorbs a shock from one that transmits it straight to the financial results, and it is a legitimate object of board oversight precisely because its absence is an enterprise risk.

And the board should insist on the instrumentation to see operational risk coming. If management cannot produce reliable operational information, or can produce it only slowly and by hand, that is not a minor gap. It means the organization cannot observe its own operational exposure early enough to manage it, which means the board cannot govern it. The inability to see operational risk is itself one of the most important operational risks a board can uncover.

The Reclassification

The distance between a back-office function and a boardroom risk is not a distance of importance. Operations was always important. It is a distance of governance, of whether the board treats operational exposure as something it oversees directly or something it assumes management is quietly handling. For most boards, and for most of the history of most companies, operations has sat on the wrong side of that line, governed by assumption rather than by design.

The argument for moving it is the same argument that moved cyber risk, and it is worth stating plainly. A risk capable of materially damaging the enterprise belongs under the board's risk oversight, regardless of how operational or technical or routine it once appeared. Operational failure is capable of exactly that kind of damage, especially in a business where the operation is the engine of returns. Continuing to treat it as a back-office function is not a neutral choice. It is a decision to leave one of the enterprise's largest risks outside the room where enterprise risk is governed, and to keep being surprised, in the language of financial results, by a risk the board could have named and overseen all along. The reclassification costs a board very little. Refusing it has been costing companies a great deal, quietly, for a long time.

Frequently Asked Questions

Q1. Why is operations a boardroom risk rather than a back-office function?
Because operational failure can materially damage the enterprise, which is the test of what belongs under board risk oversight. Operational risk meets the formal definition of enterprise risk, and in operations-intensive businesses it is one of the largest exposures. Treating it as routine execution leaves a major risk ungoverned.

Q2. What is operational risk?
The Basel Committee defines operational risk as the risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events. It is not a series of isolated incidents but a standing, structural exposure created by how a business is built and how well it holds up under stress.

Q3. What are the main categories of operational risk?
Four, following the Basel definition: people, where critical capability sits with specific individuals; process, where workflows are poorly designed or dependent on manual workarounds; systems, where tools and data are fragmented or unreliable; and external events, disruptions from outside that a fragile operation absorbs badly.

Q4. What does operational risk look like in a property business?
It takes concrete forms: people risk (key-person dependency, site-manager turnover), process risk (fragile renewal and maintenance workflows, inconsistent compliance), systems risk (fragmented data, unreliable reporting, vendor dependency), and external-event risk (regulatory change, insurance pressure, climate events, utility disruption). Each belongs on the risk register.

Q5. How is this different from cyber risk oversight?
It is the same journey at an earlier stage. Cyber risk was once treated as a back-office IT matter and became a board-level enterprise risk once its business consequences were undeniable. Operational risk carries comparable consequences but has not yet been reclassified in most non-financial businesses. The cyber precedent shows the path.

Q6. Why does operational risk stay invisible until it causes damage?
Because it accumulates slowly as small, individually manageable degradations rather than announcing itself like a breach or default. It then surfaces disguised as a financial, compliance, or reputational problem, so boards treat the symptom and never trace it to the operational fragility that caused it, leaving the exposure intact.

Q7. How should a board govern operations as a risk?
By naming operational risk explicitly in the risk register and risk appetite statement; asking management to surface hidden exposures in people, process, systems, and resilience; treating operational resilience as a governance objective; and insisting on reliable operational information, since the inability to see operational risk is itself a serious operational risk.

Q8. What is the difference between operational risk and operational resilience?
They are related but distinct. Operational risk management focuses on preventing failures in people, process, and systems. Operational resilience focuses on continuing critical operations when a failure happens anyway. Resilience is operational risk viewed through the lens of continuity, and regulators increasingly treat both as board-level governance concerns.