As new information technology comes on line, the Bank must also ensure that the risks inherent in technology are well managed. The Operational Risk Committee (ORC) provides an executive-level forum for discussion and decisions on all aspects of operational risk and its management. The Committee also addresses critical back-up and contingency planning issues and provides a focal point for responding to unforeseen circumstances that could delay or interrupt service.
Sound business processes, internal controls, an independent audit group and cross-functional committees are all integral elements in managing operational risk. Our control environment is built on the integrity, competence and supervision of our professionals, as well as management's control philosophy and operating style. Primary responsibility for managing operational risk rests with business managers, who are responsible for establishing and maintaining internal control procedures that are appropriate for their operating environments. A comprehensive system of internal controls, comprising business managers, the ORC and the Audit Committee, are designed to ensure compliance with internal policies and regulatory procedures.