Taxonomy and three lines of defence
What a taxonomy is for
An operational risk taxonomy enables three things, and only three:
- Aggregating heterogeneous losses into a meaningful total;
- Comparing across business lines, entities, and against external data;
- Spotting concentrations: an event type recurring in five business lines reveals a systemic cause.
It is not there to describe an incident finely: that is the job of the event narrative, not its classification.
The seven Basel categories
| Category | Contents |
|---|---|
| Internal fraud | Acts by a member of staff |
| External fraud | Acts by a third party, including cyber fraud |
| Employment practices and workplace safety | Employment litigation, accidents, discrimination |
| Clients, products and business practices | Mis-selling, unsuitable product, conduct breach |
| Damage to physical assets | Natural disaster, vandalism, fire |
| Business disruption and system failures | IT unavailability, infrastructure failure |
| Execution, delivery and process management | Processing error, documentation failure, supplier dispute |
The seventh category alone concentrates the majority of events by count, and the smallest share by amount. Categories 1 and 4 concentrate the opposite: few events, extreme amounts.
The three lines of defence
First line — the front line. They take the risk and manage it. They perform first-level controls. The risk belongs to them.
Second line — control and compliance. It sets the framework, runs the method, challenges the first line's assessments and reports independently. It does not manage risk on the first line's behalf.
Third line — internal audit. It provides independent assurance on the effectiveness of the first two. It has no operational role.
The confusion to avoid
The three lines are three roles, not three hierarchical levels nor three departments.
The commonest drift: a second line that completes the risk self-assessments itself because the first line "has no time". The result is an assessment detached from operational reality, which nobody recognises as their own — and which will therefore produce no action.
The warning signal is simple: if you ask an operational manager for their three main risks and they must consult the register to answer, ownership has not happened.
Key takeaways
- A taxonomy exists to aggregate and compare, not to describe
- Three lines = three roles, never three hierarchical levels
- The second line challenges; it does not do the first line's work