As new information technology comes on line, the Bank
must also ensure that the risks inherent in technology are well managed.
The Operational Risk Committee (ORC)
provides an executive-level forum for discussion and decisions on all
aspects of operational risk and its management. The Committee also
addresses critical back-up and contingency planning issues and provides
a focal point for responding to unforeseen circumstances that could
delay or interrupt service.
Sound business processes, internal controls, an
independent audit group and cross-functional committees are all integral
elements in managing operational risk. Our control environment is built
on the integrity, competence and supervision of our professionals, as
well as management's control philosophy and operating style. Primary
responsibility for managing operational risk rests with business
managers, who are responsible for establishing and maintaining internal
control procedures that are appropriate for their operating
environments. A comprehensive system of internal controls, comprising
business managers, the ORC and the Audit Committee, are designed to
ensure compliance with internal policies and regulatory procedures.