Banks use operational risk indicators to log every early signal, a key risk indicator breach, an audit finding, an RCSA finding, or a near miss, into one issue register the moment it appears, then assign an owner, a due date, and a linked control before the signal can compound into a realized loss.
This article covers what counts as a signal, where signals originate, how a signal becomes a tracked issue, what closes it, and how a system of record connects the four sources to one register.

What Counts as a Signal Before a Loss Event
A loss event is a realized operational failure that has already cost the institution money, reputational standing, or regulatory standing. A signal is anything that indicates a control gap or emerging risk before it produces that loss, and operational risk indicators are the metrics an institution watches specifically to catch a signal.
The two call for different responses:
- A loss event triggers accounting, disclosure, remediation, and often a report to the board on how the gap went undetected.
- A signal caught early triggers only an issue record and a due date
Where Issue Signals Come From
Four sources produce most operational issue signals:
- A key risk indicator crossing its threshold
- A risk and control self-assessment finding
- An audit finding
- A near miss or self-reported issue from staff
Each source produces a different kind of first evidence:
- A KRI breach is a number crossing a line, timestamped and unambiguous
- An audit finding shows up as a documented control gap with a severity opinion
- RCSA findings tend to be a self-identified weakness that needs further digging
- A near miss is a narrative account with no data attached
All four feed the same downstream issue register once triaged, and treating them as separate tracks is the most common reason an institution loses visibility into its own risk posture.
How a Signal Becomes a Tracked Issue
Each signal source routes to a different first reviewer, but every signal that clears triage becomes the same kind of record.
| Signal Source | Trigger | Who Owns Triage |
|---|---|---|
| KRI threshold breach | Metric crosses its defined limit | Risk management |
| RCSA finding | Self-assessment identifies a control gap | Business line owner |
| Audit finding | Internal or external audit documents a gap | Internal audit |
| Near miss | Staff reports an event that almost caused loss | Frontline manager |
A tracked issue record needs five fields regardless of source:
- Severity
- Owner
- Due date
- The control it links to
- Root cause once identified
A record missing any of these is still a flagged signal waiting on triage, and it should not appear in board reporting as though it were already being managed.
What Closes an Issue and What Evidence It Leaves
A corrective action plan is the artifact that documents root cause and the specific remediation steps taken, separate from the original issue record that flagged the problem.
An examiner reviewing the register looks for the severity rationale behind each rating, how long each issue has been open against its due date, the control each issue links to, and the evidence that closure actually happened rather than being marked complete without support.
Why Tracking Matters: The Cost of Catching Issues Late
An issue caught at the signal stage costs a triage review and a corrective action plan. The same gap caught after it produces a loss event costs the loss itself, plus the same remediation work carried out under closer scrutiny and a shorter timeline.
Two figures reach the board from a well-kept issue register:
- The count of open issues past their due date
- The aging distribution of the open population
Both numbers describe how close the institution’s operational risk program is running to the line between a tracked signal and a realized loss, and a rising trend in either one is itself an operational risk indicator worth escalating on its own.
How Predict360 Connects Signals to a Single Issue Register
Predict360‘s Risk Insights module tracks KRIs against defined thresholds and triggers a real-time alert when a metric moves outside tolerance.
Its Issues Management module then records the resulting issue with an owner, a due date, and a linked control, on the same platform used for audit findings and RCSA findings.
Frequently Asked Questions
What is the difference between a key risk indicator and an issue?
A key risk indicator is a metric that signals emerging risk when it crosses a defined threshold. An issue is the tracked record created once that signal, or any other source such as an audit finding, has been triaged and assigned an owner, a due date, and a linked control.
What evidence do examiners want for issue tracking?
Examiners look for a documented severity rationale, the issue’s age against its due date, the control it links to, and evidence that closure happened, such as a completed corrective action plan.
How does a corrective action plan differ from an issue record?
The issue record documents that a signal was caught, its severity, and who owns it. The corrective action plan documents the root cause identified during investigation and the specific remediation steps taken to close the issue, and stays linked to the original record.
What is a loss event in operational risk management?
A loss event is a realized operational failure that has already cost the institution money, reputational standing, or regulatory standing, as distinct from a signal caught and closed before that cost occurred.
Institutions that review their open-issue aging report monthly catch the gap between a tracked signal and a realized loss before the distance between the two closes.
The Predict360 Enterprise Risk Management Software ensures managers have complete visibility of enterprise risk on a single dashboard.
Request Demo- Cloud-Based
- Risk Repository
- Assess Risks
- Real-time Monitoring