Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y Risk Management - The Supervisor’s Perspective National Supervisors’ Forum November 2013 November 2013 David Matthews Risk Management - The Supervisor’s Perspective National Supervisors’ Forum November 2013 November 2013 David Matthews
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y Objective 1. To provide you with an overview of risk management: - Rationale, terminology, risk systems - Two aspects – Risk Management system / process Risk Management culture 2. To explain the Supervisor’s perspective on Risk Management – focus on culture!
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 3 Agenda 1.What is Risk Management – Why is it important? – Definitions & Terms 2.Risk Management System – Identify, analyse, action plan – System overview 3.The Supervisor’s perspective 4.Examples - Risk-Based Approach to Decision Making 5.Questions & Answers Identify Analyse & Measure Evaluate Internal Controls Residual Risk Action Plan Monitor & manage
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 4 Section 1: What is Risk Management?
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 5 Definitions Risk Management is a formal process that analyses prevailing risks facing the credit union and identifies appropriate responses for addressing them A risk is anything that could impact negatively on your credit union – transactional or organisational Impacts: Financial Loss, Disruption to Operations, Reputational Damage, Physical Responses: Accept – Mitigate – Transfer – Avoid
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 6 Why is it important? Republic of Ireland – now required by legislation System, process, culture, Risk Officer, risk register PRISM – focused on risk Northern Ireland – not required by legislation But, a risk management culture is a key requirement of a well-run business All Board and management decisions and activities should be framed within a risk management culture Lessons from recent years where risk was not considered
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 7 Risk Management Terms Risk Management Culture - a credit union’s collective system of values that shape its risk decisions Risk Capacity – how much risk can we afford to take? Determined by how much capital we have Risk Appetite – amount and type of risk that we are prepared to seek, accept or tolerate Zero, Low, Moderate, High Risk Tolerance – the actual level of risk that we will accept
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 8 Risk Management Terms Inherent Risk – the risk posed before systems and controls that relate to the risk are considered Residual Risk – the level of risk after considering the effectiveness of systems and controls put in place to manage the risk
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 9 Section 2: Risk Management System
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 10 Risk Management System Overview
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 11 Step 1: Identifying Risks Identify risks (current & future) that could impact upon the credit union Will be similar (but not identical) for all credit unions – Depends on structures, products, services, delivery channels, etc. Description of risk should describe impact, event, cause – To enable action to be taken
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 12 Step 2: Analysing Risks Impact & likelihood of occurrence – The impact of each risk is scored, e.g. 1 to 5 – The likelihood of occurrence is scored, e.g. 1 to 4. Scoring is a subjective exercise – Will vary between credit unions Scores are multiplied to get the risk ranking score Low scoring risks are excluded High scoring risks are taken to next stage for further analysis
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 13 Impact of Risk What is the impact?Score There is a negligible impact on the credit union1 There is a minor impact on the credit union2 There is a significant impact on the credit union3 There is a very serious impact on the credit union that would undermine the stability of the organisation 4 There is a disastrous impact on the credit union that could result in termination of business 5
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 14 Prevalence of Risk How likely?Score This risk is very unlikely to occur1 There is some possibility that this risk will occur2 It is likely that this risk will occur3 It is almost certain that this risk will occur4
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 15 Risk Ranking – Fraud RiskScore 1.2 An officer grants several large loans to family members outside the credit union’s loan policy requirements A member cashes a number of fraudulent cheques through the credit union resulting in a significant financial loss An officer of the credit union has been transferring funds from dormant member accounts An officer defrauds the credit union of significant sums of money by setting up false loans for fictitious members An officer of the credit union steals a series of small sums of cash from the cash drawer over a period of months. 4
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 16 Step 3: Determining Residual Risk This step will determine the threat posed by a risk once internal controls have been considered A control is any measure deliberately put in place to manage risks Determine effectiveness of these internal controls Risk ranking score is multiplied by the controls’ effectiveness scores to determine residual risk
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 17 Mapping Internal Controls
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 18 Example: Credit Risk
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 19 Internal Control Effectiveness
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 20 Calculating Residual Risk (Risk Ranking Score) x (Internal Control Score) = Residual Risk 12 x 0.2 = 2.4 (low residual risk) 8 x 0.6 = 4.8 (medium residual risk) 10 x 0.8 = 8.0 (high residual risk)
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 21 Step 4: Report & Action Plan Process has identified internal controls that must be improved Develop risk response plan Report findings to the Board for approval Delegate tasks to appropriate officers and set firm deadlines for delivery Review effectiveness of actions
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 22
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 23 Section 3: The Supervisor’s perspective
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 24 Supervisor’s perspective Board and management should be aware of risks as well as rewards – Doesn’t mean that all risk must be avoided, but that decisions consider pros as well as cons Assessment of risk should be part of the credit union’s decision-making process Board should promote a strong risk management culture – key issue for Supervisors
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 25 Supervisor’s perspective Supervisors should ask themselves: – What would I want to know if I was making this decision? – Does the Chair encourage debate and dissent? – Are dissident views given fair consideration? – Does everyone contribute to the debate? – Are directors asking the right questions? – Are they really considering both sides of the argument? Does the Board encourage a robust assessment of risk?
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 26 Section 4: Risk-based approach to decision making – some examples
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 27 Introducing a new service Positives More services for members Additional income Cross sale opportunities Negatives Compliance requirements Conduct risks Cost v benefit?
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 28 Staff Structure Manager and six tellers What if the manager is on leave or gets sick? Manager may spend too much time on admin work No promotional opportunities for staff But – lower cost, quick decisions and communication
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 29 Proposing a dividend What is the outlook for next few years? – Should we boost our capital / reserves instead? Attractive to savers – but do we need more savings? – Additional capital requirements – What about our borrowers (primary source of income)? Precedent – members will expect same again – Reputational Risk if we can’t pay it Surplus is sufficient to pay 4% ! Board keen to propose it, but what are the risks?
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 30 Loans to new members Potential for new borrowers identified in strategic planning process Member survey said that assessment criteria were too strict and intrusive Board is considering relaxing its requirements for small loans (to attract new borrowers) What factors should the Board consider? What are the risks that might result a) if the board proceeds? & b) if the board does not proceed?
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 31 Benefits of Risk Management More robust business decisions – Clear assessment of pros and cons – Fewer shocks and unwelcome surprises Continuous process improvement – Should lead to better internal controls – Should facilitate sharing of best practice Risk management culture – Structured approach to assessing opportunities – Enhanced member confidence
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 32 Key points Objective is to manage risks, not to eliminate them – Accept, mitigate, avoid Inherent Risk - identify, analyse, measure, rank Residual Risk – consider internal controls, rank, plan Process - identify, assess, manage and monitor risks Boards should consider risk as part of their decision making process Supervisor’s perspective – risk management culture should permeate the credit union
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y 33 Thank you for your attention! Any questions?