Governance Frameworks
Navigating the Web of Interconnected Risks
By Thomas DiGiovanni, Partner and Founder
April 2, 20256 min read
Operational, technology, third-party, and conduct risks no longer move independently. The institutions managing them well are the ones that connect their governance frameworks rather than running them in parallel silos.
Risk taxonomies were designed when each risk type had relatively independent root causes and mitigations. That world is gone. A vendor outage is operational risk, technology risk, and third-party risk simultaneously. A model failure is technology risk, model risk, and potentially conduct risk. The taxonomy is still useful. Treating it as a set of silos is not.
What interconnection actually means
Two practical implications. First, risk identification needs to ask whose other taxonomies are touched. Second, mitigation needs to be tested across boundaries: a control that mitigates operational risk can fail in a way that creates conduct risk.
Governance designs that hold up
The institutions doing this well share three patterns. They have a single risk register that supports multiple lenses rather than separate registers per risk type. They have explicit cross-taxonomy escalation paths. And their second line challenges across boundaries, not just within them.
The exam dimension
Examiners are starting to probe these connections. They will ask how a third-party finding flows into operational risk metrics, or how a model risk issue shows up in conduct risk reporting. Institutions that can answer have done the integration work upstream.
Questions this raises
What does a single risk register supporting multiple lenses mean in practice?
One register of record, with views onto it, rather than a separate register maintained per risk type. When operational risk, technology risk, and third-party risk each keep their own list, the same vendor outage is entered three times, ages differently in each, and reconciles nowhere. A single register lets one entry carry several classifications at once. The second requirement is explicit cross-taxonomy escalation paths, so an issue raised under one lens has a defined route to the others.
What will an examiner ask about interconnected risk?
They tend to test the seams rather than the categories. How does a third-party finding flow into operational risk metrics. How does a model risk issue show up in conduct risk reporting. The questions are answerable only if the integration work happened upstream, because they cannot be reconstructed during an examination. Institutions that run their taxonomies as parallel silos can describe each one competently and still fail to trace a single issue across them.
Back to all insights