This paper examines the development of operational risk management (ORM) in a financial organization, focusing in particular on the role of IT in institutionalizing the new regime. Through an interpretive case study in a major US financial institution, the paper uses Giddens’ structuration theory to examine how it adjusts to the demands of protecting itself against new operational risks. The discussion and results of our study are expressed in three propositions: (1) the regulatory context and technological development affect the shape and the outcome of ORM; (2) implementing ORM is a process of reflexive monitoring and transforming organizational practices in a financial institution; (3) the role of IT in ORM is contingent on the extant organizational structure and on the choice of risk management approach.