Issued 15 December 2008
Last updated 12 June 2024

The policy covers operational risk management and internal control for all processes within the responsibility of the NBIM CEO, including projects and outsourced services.


Operational risks shall systematically be identified, assessed, mitigated, monitored, and reported to provide reasonable assurance that objectives will be achieved in accordance with the Executive Board’s operational risk tolerance. Business continuity and crisis management shall ensure priorities according to the Executive Board principles for emergency preparedness and crisis management.

NBIM shall have a second-line operational risk function to advise and assist the organisation in the management of operational risk. The second-line risk function shall maintain an NBIM wide operational risk picture.


Risk tolerance

Risk identification and assessment

 Risk response

Risk review and control assurance

Incident management

Reporting and escalation