CAYMAN ISLANDS MONETARY AUTHORITY

Slides:



Advertisements
Similar presentations
Museum Presentation Intermuseum Conservation Association.
Advertisements

Disaster Planning: The Basics TEAJF Statewide Grantee Meeting Houston July 20, 2006.
Disaster Preparedness I Lessons Learned Don Hall Thomson Prometric 2006 Annual ConferenceAlexandria, Virginia Council on Licensure, Enforcement and Regulation.
Your Role in the New Normal Increased knowledge and active participation in disaster preparedness and recovery prepare you for the New Normal Baton Rouge,
Risk Management and Internal Controls ASSAL 20 November 2014 Annick Teubner Chair, IAIS Governance Working Group.
1 The critical challenge facing banks and regulators under Basel II: improving risk management through implementation of Pillar 2 Simon Topping Hong Kong.
Security Controls – What Works
1 Operational Risk Management Member Education Series Seminar Indian Institute of Banking & Finance Nagpur November 2005.
Internal Control and Internal Audit
EASTERN MICHIGAN UNIVERSITY Continuity of Operations Planning (COOP)
Hazard Mitigation Policy and Planning Process and Past and Current Initiatives DISASTER MITIGATION FACILITY FOR THE CARIBBEAN Strengthening Regional Capacity.
OECD Guidelines on Insurer Governance
Business Continuity Management May 20, 2010 Peter Zwingli ACME Business Consulting.
SMS Operation.  Internal safety (SMS) audits are used to ensure that the structure of an SMS is sound.  It is also a formal process to ensure continuous.
Consolidated Supervision: Managing the Risks in a Diversified Financial Services Industry Barbara Baldwin June 2001.
Financial Conglomerates, What are the Inherent Risks? 2006 CIAB Conference Port-of-Spain, Trinidad & Tobago November 16, 2006 Thordur Olafsson, CARTAC.
ISA 562 Internet Security Theory & Practice
From Findings over KRIs to Process Control
CDS Operational Risk Management - October 28, 2005 Existing Methodologies for Operational Risk Mitigation - CDS’s ERM Program ACSDA Seminar - October 26.
Conducting Compliance Assessments and Building Internal Controls In Pharmaceutical R&D Third Annual Medical Research Summit – Session 2.01 Michael Swiatocha.
Risk Management & Corporate Governance 1. What is Risk?  Risk arises from uncertainty; but all uncertainties do not carry risk.  Possibility of an unfavorable.
INFORMATION SECURITY MANAGEMENT L ECTURE 3: P LANNING FOR C ONTINGENCIES You got to be careful if you don’t know where you’re going, because you might.
Future of Credit Risk Management: Supervisory Approach to Basel II CIA Annual Meeting Session 4405 Ben Gully Director, Basel Implementation Division Office.
NFPA 1600 Disaster/Emergency Management and Business Continuity Programs.
Internal/External Audit and Internal Controls February 23, 2000 David Dudley Federal Reserve Bank of NY.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Auditing Internal Control over Financial Reporting Chapter Seven.
PD 8 OSFI Capital Update Stuart Wason Senior Director Actuarial Division OSFI CIA Appointed Actuary Seminar September 18, 2009.
The Importance of National Payments Systems in Reducing Market Risk S.W.I.F.T. Regional Conference in Central and Eastern Europe Prague, Czech Republic:
Revision N° 11ICAO Safety Management Systems (SMS) Course01/01/08 Module N° 9 – SMS operation.
Business Continuity Disaster Planning
CBIZ RISK & ADVISORY SERVICES BUSINESS CONTINUITY PLANNING Developing a Readiness Strategy that Mitigates Risk and is Actionable and Easy to Implement.
2007 Office of Risk Management Annual Conference 2007 David M. Shapiro Disaster Planning & Recovery Consultants
Business Continuity Planning 101
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
MANAGEMENT of INFORMATION SECURITY, Fifth Edition.
SUNY Maritime Internal Control Program. New York State Internal Control Act of 1987 Establish and maintain guidelines for a system of internal controls.
Pipeline Safety Management Systems
Information Systems Security
THINK DIFFERENT. THINK SUCCESS.
Principles for Recovery and Resolution of a Financial Market Infrastructure ACSDA Senior Leadership Summit – November 16 & 17, 2015.
Physical Security Governance Model
Chris Lintern Co-operative Financial Services
John Deere Supply Chain Risk Management
Disaster and Emergency Planning
Auditing & Investigations II
We will start momentarily…
PLANNING, MATERIALITY AND ASSESSING THE RISK OF MISSTATEMENT
Legislative Compliance Management Insurance Industry Workshop 1 – 2 November 2005 Bangkok, Thailand Kim Norris Managing Director International Advisory.
Disaster Recovery Policy & Procedures
Business Continuity Plan Training
9/16/2018 The ACT Government’s commitment to Performance and Accountability – the role of Evaluation Presentation to the Canberra Evaluation Forum Thursday,
Berry College Disaster Recovery Soft Exit
Continuity of Operations 101
HSE Case: Risk Based Approach.
Kuveyt Turk Participation Bank
Internal control - the IA perspective
Continuity Guidance Circular Webinar
Cybersecurity ATD technical
Risk management.
An Update of COSO’s Internal Control–Integrated Framework
Business Continuity Program Overview
Neopay Practical Guides #2 PSD2 (Should I be worried?)
Risk management.
Risks in Banking Operations
A Risk Management Approach to Business Continuity
MAZARS’ CONSULTING PRACTICE Helping your Business Venture Further
Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business.
Operational Risk Management
APRA PAIRS Model Ross Jones
Presentation transcript:

CAYMAN ISLANDS MONETARY AUTHORITY XXIII Annual Conference of the Caribbean Group of Banking Supervisors BVI May 19th – 21st 2005 02/12/2018

CAYMAN ISLANDS MONETARY AUTHORITY Disaster Recovery and Operational Risk – Are we truly prepared? Malcolm Eden, Deputy Head – Banking Supervision Cayman Islands Monetary Authority m.eden@cimoney.com.ky Ph: 345-949-7089 The topic of this paper is Disaster Recovery and Operational Risk – Are we truly prepared? and will focus on issues as they relate to Banking Regulators and Licensees. 02/12/2018

Disclaimer The views expressed in this paper are those of the writer and do not necessarily reflect those of the Cayman Islands Monetary Authority 02/12/2018

Presentation Summary/Overview Introduction Operational Risk Management Basel Principles on Operational Risk Management Licensees Operational Risk Concerns Business Continuity Management Disaster Recovery Plans Mitigation of Risk through Insurance Our Regulatory Responsibility Conclusion 02/12/2018

Introduction Caribbean dependence on tourism and international financial services Caribbean susceptible to natural disasters   5 02/12/2018

Introduction Disaster Recovery and Operational Risk gaining greater prominence Cayman and the Ivan experience Hurricane Ivan, September 11th – 13th 2004 Sixth most intense hurricane in Atlantic Basin Category 5 Hurricane, sustained wind speeds of 165 mph, minimum recorded central pressure of 910 millibars Total impact of Disaster CI$2.8 billion (183% of GDP) 90% of structures destroyed or damaged Approximately 10,000 cars estimated destroyed 02/12/2018

Introduction 02/12/2018

Introduction 02/12/2018

Introduction 02/12/2018

Introduction 02/12/2018

Introduction 02/12/2018

Introduction 02/12/2018

Introduction 02/12/2018

Introduction 02/12/2018

Introduction 02/12/2018

Introduction 02/12/2018

Introduction 02/12/2018

Introduction Number of factors not taken into account prior to Ivan Disaster Recovery Plans should be sufficiently robust Survey sent to CGBS members Goal is to review key elements of a sound disaster recovery plan for both Regulators and Licensees in the context of operational risk 02/12/2018

Operational Risk Management DRPs are a critical subset of an effective Operational Risk Management Strategy Basel Definition of Operational risk: “the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events” - Operational Risk includes internal fraud, external fraud, business disruption and systems failures, and damage to physical assets 02/12/2018

Operational Risk Management Increase in the awareness of Op Risk and management thereof by Regulators and Licensees over past five years Op Risk being viewed more as a stand alone risk category Banks expected to have an appropriate Op Risk management strategy 02/12/2018

Basel Principles on Op Risk Management Op Risk is distinct, and must be managed Op Risk should be subject to audit Senior management responsibility Identify and assess for all existing and new material products, activities, processes etc. Op Risk profiles and material exposures to losses to be monitored and reported continuously 02/12/2018

Basel Principles on Op Risk Management Continually updating of policies, processes, procedures etc. There should be contingency and business continuity plans Banking supervisors to require that banks have an effective Op Risk management framework Supervisors to conduct regular independent evaluation Banks to make public disclosure 02/12/2018

Key elements of a Sound Op Risk Management Strategy Stage 1. Stage 2. Stage 3. Stage 4. Stage 5. Op Risk identification Op Risk assessment Op Risk control procedure development and implementation Op Risk monitoring Op Risk control/mitigation. 02/12/2018

Licensees’ Op Risk Concerns Primary operational risks identified: IT, systems and process failures External and internal fraud Disasters Failure of utilities service Change in regulatory regime 02/12/2018

Business Continuity Management Definition BCM is “a holistic management process that identifies potential impacts that threaten an organization and provides a framework for building resilience with the capability for an effective response that safeguards the interests of its key stakeholders, reputation, brand and value creating activities” 02/12/2018

Business Continuity Management 02/12/2018

Business Continuity Management A disaster recovery plan is at the core of good BCM A sound disaster recovery plan involves five broad phases: Conceptualization and Risk Analysis Disaster Recovery Plan Creation Training Testing and Validation Audit and Maintenance 02/12/2018

Disaster Recovery Plans Creating a DRP requires a proactive organization-wide effort There should be a project timeline Each plan should account for emergency management, books and records backup and recovery, identification and backup of all mission critical systems, staff well being, regulatory reporting, communications with other regulators etc. 02/12/2018

Disaster Recovery Plans Be as comprehensive as possible in the development of the plan Risk management processes of banks were found to be relatively robust (based on survey) Key deficiencies identified in DRPs through CIMA’s survey include plans not being tested, limited end-user involvement, significant focus on IT, plans not frequently updated, plans being too generic and alternative facilities no being adequately equipped 02/12/2018

Mitigation of risk through insurance Common element in good BCM is the use of insurance Risks with insurance: Payment uncertainty Delayed payment Counterparty risk 02/12/2018

Our Regulatory Responsibility As per Basel Core Principle 13, banking supervisors must be satisfied that banks have in place a comprehensive risk management process The review of licensees disaster preparedness must form a part of our supervisory procedures Survey of CGBS members revealed that all members have in place some program for monitoring and assessing operational risk as it relates to their licensees 02/12/2018

Our Regulatory Responsibility Additional factors that regulators should consider include: Regulators have two different sets of “clients” or customers The assistance that regulators will be called upon to give may be well outside the realm of a regulator’s normal duties 02/12/2018

Conclusion Business continuity planning and disaster recovery should be made a priority The environment that we operate in makes us highly susceptible to countless events that could result in severe business interruption that could de-stabilize our financial systems 02/12/2018