Skip to main content
The state of ai impact assessment
Category: Enterprise Risk Management

Loss Event Data

Also known as: LED, Operational Loss Data, Operational Risk Event Data, Loss Data
Simply put

Loss Event Data is the information an organization, typically a financial institution, collects and records about operational risk events that have caused or could have caused a loss. Each record often captures details such as what happened, where it occurred, which functions were affected, and the actual or potential financial impact, including near misses. This data is used to help staff understand real-world operational risks and to support risk measurement and reporting.

Formal definition

Loss Event Data (LED) refers to the structured recording of operational risk loss events for use in operational risk management, measurement, and regulatory reporting. Individual records typically document attributes such as event description, date, region, functions or business lines impacted, regulatory classification, causal factors, and potential or actual loss amounts, as well as near misses. In the Basel framework's standardised approach for operational risk, loss event data feeds the calculation of average annual losses; the referenced Basel text sets a minimum threshold (stated as €20,000) for including a loss event in that data collection and calculation, though thresholds, scope, and applicability vary by jurisdiction, supervisor, and institution, for example, supervisory returns such as OSFI's L3 Operational Risk Event Data return consolidate this information for regulatory purposes. LED is generally considered a leading practice tool within operational risk programs and, where prescribed, an element of regulatory expectation; specific requirements and thresholds should be verified against the applicable primary source.

Why it matters

Loss Event Data provides organizations with an empirical, evidence-based view of the operational risks they actually face, drawn from events that have already occurred rather than from hypothetical scenarios alone. By recording what went wrong, where, and with what actual or potential financial impact, institutions can ground their risk management in real-world experience. This is particularly valuable in operational risk, where losses can arise from a wide range of causes such as process failures, human error, systems issues, or external events, and where forward-looking estimation is inherently uncertain.

Beyond internal learning, Loss Event Data often serves a measurement and reporting function. In the Basel framework's standardised approach for operational risk, loss event data feeds the calculation of average annual losses, with the referenced Basel text setting a minimum threshold (stated as €20,000) for including a loss event in that data collection and calculation. Because this data can influence regulatory outputs, its completeness and accuracy carry consequences that extend beyond a single risk register. Note, however, that thresholds, scope, and applicability vary by jurisdiction, supervisor, and institution, and specific requirements should be verified against the applicable primary source.

The practice also supports supervisory transparency. Supervisory returns such as OSFI's L3 Operational Risk Event Data return consolidate loss event information for regulatory purposes, illustrating how the same underlying data can support both internal management and external reporting obligations. Capturing near misses alongside realized losses further allows organizations to learn from events that could have caused a loss even where no loss ultimately materialized, though the treatment of near misses in any formal calculation depends on the applicable framework.

Who it's relevant to

Operational Risk Managers
Loss Event Data is a core input for identifying, measuring, and monitoring operational risk. Risk managers rely on structured records of past events, including near misses, to understand real-world exposures, spot concentrations across functions or business lines, and inform risk measurement and reporting.
Compliance and Regulatory Reporting Teams
Where loss event data feeds supervisory returns or capital-related calculations, compliance and reporting teams are responsible for ensuring that records meet applicable thresholds, classifications, and submission requirements. Examples include the Basel standardised approach inputs and supervisory returns such as OSFI's L3 Operational Risk Event Data return, though specific obligations vary by jurisdiction and should be verified against the primary source.
Internal Auditors
Internal auditors may assess the completeness, accuracy, and consistency of loss event data collection, including whether events are captured against the correct thresholds and classifications and whether near misses are recorded as intended. This supports assurance over both the internal risk view and any downstream regulatory reporting.
Staff Across Business Functions
Because loss events can originate anywhere in an organization, staff across business functions play a role in identifying and reporting events. Loss event data can also enhance staff awareness and understanding of operational risks by using real-world examples to highlight potential impacts.

Inside LED

Event Description
A narrative account of what occurred, typically capturing the nature of the operational risk event, the circumstances surrounding it, and the affected business process or unit.
Gross Loss Amount
The financial impact of the event before any recoveries or offsets, often recorded in a defined reporting currency. Some frameworks also capture near-miss or no-loss events for learning purposes.
Recoveries
Amounts recovered against the gross loss, such as insurance proceeds or reimbursements. Net loss is typically derived by subtracting recoveries, though the treatment of recoveries can vary by internal methodology.
Reference Dates
Key timestamps commonly associated with an event, which may include the date of occurrence, the date of discovery, and the accounting or settlement date. These often differ, and organizations typically define which date governs reporting.
Risk Categorization
Classification of the event against a risk taxonomy, such as event-type or cause categories used in many operational risk frameworks, to support aggregation and trend analysis.
Organizational Attribution
Identification of the business line, legal entity, geography, or function to which the loss is attributed, enabling reporting at different levels of the organization.
Status and Linkage
Indicators of whether the event is open, closed, or provisioned, along with links to related events, root-cause analysis, remediation actions, or associated control failures.

Common questions

Answers to the questions practitioners most commonly ask about LED.

Is loss event data the same as a record of financial losses only?
No. While financial impact is a common attribute captured in loss event data, the concept is broader. Loss event data typically records operational risk events that have materialized, which may include near-misses and events with non-financial consequences such as reputational, regulatory, or operational disruption effects. Limiting the data set to realized monetary losses can understate an organization's risk exposure and reduce the analytical value of the data. The precise scope of what is captured varies by organization and by the framework or convention adopted.
Does collecting loss event data mean an organization is measuring its future risk?
Not directly. Loss event data is fundamentally historical; it describes events that have already occurred. It can inform forward-looking risk assessment, for example, by supporting the estimation of event frequency and severity or by highlighting control weaknesses, but the data itself is not a measure of future risk. Treating historical loss data as a complete predictor of future exposure overlooks emerging risks, changes in the control environment, and events that are rare or unprecedented. Loss data is typically one input among several, often used alongside scenario analysis and forward-looking indicators.
What attributes are commonly captured for each loss event?
Practice varies, but organizations often record attributes such as the date of occurrence and date of discovery, a description of the event, the business unit or process affected, a risk category or event-type classification, gross and net financial impact where applicable, any recoveries, and the associated cause or control failure. Capturing a consistent set of attributes supports aggregation, trend analysis, and comparability over time. The specific fields should be aligned with the organization's risk taxonomy and reporting needs, and any regulatory expectations applicable to its sector and jurisdiction should be verified against the primary source.
How can an organization set a threshold for which loss events to collect?
Many organizations establish a data collection threshold, often a monetary floor, below which events are not individually recorded, to balance completeness against the cost of collection. Setting this threshold involves judgment about materiality, the analytical uses of the data, and any external reporting expectations. A threshold set too high may exclude patterns of frequent low-value events that are collectively significant, while a very low threshold can impose a heavy data-capture burden. The appropriate level is context-dependent and should be documented and periodically reviewed.
How should loss event data be governed to remain reliable?
Reliable loss event data typically depends on clear ownership, defined roles for reporting and validation, consistent classification against an agreed taxonomy, and controls over data quality such as completeness and accuracy checks. Timely capture near the point of discovery and periodic reconciliation against related records, such as financial ledgers or incident logs, are common governance practices. Because the effectiveness of these arrangements depends on organizational structure and culture, governance should be tailored rather than adopted wholesale, and independent review can help confirm that data is complete and consistently recorded.
How does loss event data relate to control assessment and remediation?
Loss event data can help identify where controls have failed or performed as intended, providing evidence to inform control assessments and prioritize remediation. Analyzing the causes recorded for events may reveal recurring weaknesses in specific processes or controls. However, the data reflects only events that occurred and were captured; the absence of recorded losses does not by itself confirm that controls are effective. Loss data is therefore best used alongside other assurance activities rather than as a sole basis for concluding on control effectiveness.

Common misconceptions

Loss event data is only relevant to regulated financial institutions with capital requirements.
While loss event data features prominently in banking operational risk frameworks, the underlying practice of recording and analyzing realized loss events supports risk management in many sectors. Its regulatory weight and specific requirements vary by jurisdiction, sector, and organization size, and applicability should be verified against the relevant primary sources.
A loss event and a risk are the same thing.
A risk is a potential future event and its effect on objectives, whereas a loss event is a realized occurrence that has already produced (or could have produced) an impact. Loss event data typically informs risk assessment, but recording an event is distinct from identifying or assessing a risk.
The gross loss amount fully captures the impact of an event.
Gross loss reflects a direct financial figure before recoveries, but events may carry indirect, reputational, or non-financial consequences that a single monetary field does not represent. Net loss, recoveries, and qualitative impacts are often tracked separately, and treatment conventions can differ across organizations.

Best practices

Establish clear, documented definitions for key data fields, such as gross loss, recoveries, and the governing reference date, so that events are captured consistently across business units.
Map events to a defined risk taxonomy at the point of capture to support reliable aggregation, trend analysis, and comparability over time.
Set and communicate a collection threshold and scope, including whether near-miss or no-loss events are recorded, and note that these choices should align with applicable framework or regulatory expectations where relevant.
Link each loss event to its root-cause analysis, associated control weaknesses, and remediation actions to connect the data to control improvement rather than treating it as a static record.
Validate and reconcile loss data against financial and accounting records to support completeness and accuracy, and document any adjustments.
Verify specific regulatory or capital-related requirements, effective dates, and thresholds against the applicable primary sources and jurisdiction, and seek professional advice where interpretation is contested.
Promotional banner for the Pentest Readiness checklist download