Skip to content
About

Why oprisk.ai

The thesis

Operational risk is being rewritten by AI. Not in the distant, speculative sense that dominates most conference panels, but in the concrete, working sense that shows up in how scenarios get designed, how controls get tested, how regulators frame their expectations, and how risk teams allocate their next hour of attention.

I write about that rewrite. And I build against it.

The premise is simple and, I think, under-appreciated: the operational risk discipline was built for a slower world. Loss Distribution Approaches were calibrated on pre-2008 data. Scenario libraries were assembled in a pre-multipolar era. Key Risk Indicators were designed when a geopolitical shock took weeks to cascade, not hours. The tools worked, but they are no longer fast enough for the environment risk teams are actually operating in.

While the discipline slowed, the expectations accelerated. The UK regime (PRA SS1/21 and its FCA counterpart) made impact tolerances for important business services a board-level obligation, with the transition period closed since March 2025. DORA, Regulation (EU) 2022/2554, has applied to EU financial entities since January 2025. OSFI’s Guideline E-21 now frames the discipline as operational risk and resilience, with full adherence expected by September 2026 and scenario testing of critical operations by 2027. Read those texts side by side and the pattern is unmistakable: regulators are no longer asking banks to register their risks. They are asking banks to demonstrate, with mapping, testing, and evidence, that critical services can survive severe but plausible disruption. Most banks are answering that demand with GRC platforms that are, functionally, glorified registers, dependency maps in spreadsheets, and board reporting assembled by hand.

AI changes the tempo. A bank that can generate Basel-mapped stress scenarios against live geopolitical signals has an entirely different relationship to emerging risk than one still running annual scenario workshops. A resilience program that can simulate third-party concentration shocks overnight is playing a different game than one assembling tabletop exercises twice a year.

This is what I believe, and what oprisk.ai is a working argument for.

The career arc

The path to this thesis wasn’t theoretical. It ran through eighteen years of North American banking risk, three regulators, and the unglamorous work of actually building things that supervisors would accept and models that would hold up under stress.

It started at IIT Delhi, where I read engineering and learned, though I couldn’t have named it at the time, how to decompose complicated systems into their governing mechanics. Then IIM Calcutta, where I learned that the hard part of finance was rarely the math. It was the institutional context around the math: who had to agree with the answer, who had to defend it, and who had to be protected from it.

In 2008 I joined ICICI Bank Canada, arriving into the Canadian banking system in the middle of the financial crisis. In retrospect, that was an exceptional time to learn what operational risk actually means. The theoretical frameworks mattered less than the texture of how a bank responds when the world tilts.

Four years later I moved to TD Bank, where I have spent the last fourteen years across stress testing, operational resilience, and risk analytics, most recently as Vice President. I have engaged with the FRB, OCC, OSFI, FDIC, and CDIC across CCAR submissions, resilience assessments, and model validation exercises. The resilience mandate included direct second line oversight and challenge of the UK entity’s FCA and PRA operational resilience submissions: important business services, impact tolerances, and submission readiness. What I am most proud of is driving successful transformations, again and again: programs delivered on time, models that held up under supervisory scrutiny, and resilience frameworks that banks actually adopted.

That discipline, building things supervisors can live with and businesses can operate, is what oprisk.ai translates into writing, and now into working tools.

Why the builder matters

I hold the AI thesis with some discipline, because our industry has a long record of overpromising technology into risk management. Large language models are genuinely good at the substance of operational risk work: reading regulatory text and mapping it to obligations, drafting and challenging scenario narratives, classifying events against taxonomies, finding the inconsistencies across three hundred assessments, turning a quarter’s data into prose a board can act on. But the model is not the tool. Generic AI applied to risk management produces plausible-sounding artifacts that collapse under examination. What makes a tool is the scaffolding around the model: the workflow that enforces challenge, the audit trail that makes every output reconstructable, the judgment about what an examiner will actually probe. That scaffolding can only be designed by someone who has operated inside it. The difference is not the model. It is the builder.

What this site is

oprisk.ai is an independent publication and a prototyping lab.

The publication documents the rewrite: essays and analysis written from inside the discipline, in the register of a risk committee memo rather than a vendor brochure. The OpRisk Signal, the bi-weekly newsletter, curates what actually matters and adds one practitioner essay per issue.

The Lab is where the thesis gets tested in code. I maintain AEGIS, a twelve-module suite: the tools I believe every mid-tier bank’s operational risk function will need and largely cannot buy today. Two builds are live as working prototypes: DELPHI, which rebuilds scenario analysis as a continuous, challenged, auditable process; and ORBIT, an operational resilience workbench spanning important business services, impact tolerances, dependency mapping, and scenario testing.

I focus on mid-tier banks deliberately. The largest institutions build in-house. The smallest buy whatever their core provider bundles. The banks in between carry nearly the full weight of the regulatory expectations described above, with a fraction of the build capacity; they are the underserved segment, and the one where better blueprints change outcomes fastest.

What this site is not: a vendor. Nothing here is for sale: no pricing, no implementation services, no sales calls. The tools are prototypes, research builds, and blueprints, published so they can be examined, challenged, and cited. It is a personal project, run in a personal capacity, and is not affiliated with any employer.

Credentials

Passed CFA Level III, charter application in progress  ·  MBA, IIM Calcutta  ·  B.Tech., IIT Delhi  ·  18 years across three regulators

Expertise

Six areas of practice. Each has shaped what I write and what I build.

Enterprise Risk Governance. Board reporting, risk appetite frameworks, three-lines-of-defense architecture, and the structural questions of how risk functions relate to the businesses they oversee.

Stress Testing & CCAR. Scenario design, qualitative and quantitative narrative construction, supervisory engagement through the submission cycle, and the craft of writing stress tests that regulators find credible.

Operational Resilience. Important Business Services mapping, impact tolerance design, third-party and concentration risk analysis, and BOE/FRB/OSFI resilience frameworks as implemented inside a large bank.

Quantitative Modeling. Monte Carlo simulation, Loss Distribution Approach, scenario analysis, and the working relationship between modeling choices and the regulatory scrutiny those choices invite.

Regulatory Engagement. Direct engagement across FRB, OCC, OSFI, FDIC, CDIC on CCAR, DFAST, operational resilience reviews, model risk, and resolution planning. Consolidated parent-bank ICAAP submissions to RBI, built from inception. Direct second line oversight and challenge of UK FCA and PRA operational resilience submissions.

AI in Risk. The newest layer, and the one this platform is organized around: where large language models, agentic systems, and live search fit into the identify-measure-test-respond-govern lifecycle of operational risk management.

Beyond the work

I live in Mullica Hill, New Jersey, in the Philadelphia area, with my wife and two children. I watch a great deal of cricket, read more geopolitics than is strictly necessary, and maintain a working affection for the two institutions, IIT Delhi and IIM Calcutta, that shaped how I think more than I usually admit.

The shortest version of what keeps me at this: the belief that operational risk is one of the most intellectually demanding disciplines in finance, and the most under-served by quality writing and tooling. I am trying to contribute to both.

Connect

I read everything sent to chitresh@oprisk.ai.

For newsletter subscriptions, The OpRisk Signal goes out bi-weekly: one core idea, a framework from practice, a geopolitical lens, and two or three things I am reading. Subscribe at the bottom of any page.

For speaking opportunities or constructive conversations, please reach me at chitresh@oprisk.ai or via LinkedIn. I am selective about engagements and responsive about replies.

For everything else (pieces you’d like me to read, frameworks you’d like me to critique, disagreements with anything I have written), the email address is the same.

Chitresh Sainia