Operational Risk: A Multi-Layered Problem Presented to the London Chapter of The Professional Risk Managers’ International Association and International.

Slides:



Advertisements
Similar presentations
Policies and Processes for Limiting Conflict of Interest Patrick N. Breysse, PhD, CIH Johns Hopkins University Bloomberg School of Public Health Vice-Chair,
Advertisements

Rizwan Chughtai. Risk exposure arising from business activities Need to effectively manage because of Potential business losses Ensure business continuity.
1 Practical and Business Implications of Basel 2 for UK Mortgage Lenders. Bruce T Porteous 29 April 2004.
Corporate Governance Chapter 2.
Monitoring Compliance with the Basel II Accord Charles H. Le Grand Reliability of Global Financial Infrastructures, Information, and Reporting Accountability.
1 The critical challenge facing banks and regulators under Basel II: improving risk management through implementation of Pillar 2 Simon Topping Hong Kong.
1 Lecture 6b: An Introduction The Basel I & Basel II.
“High Performing Financial Institutions and the Keys to Success in an Uncertain Environment”
Presented by Muhamad Abrar Bahaman W. Fatimatul Akmar Md. Hassan
Introduction to Enterprise Risk Management (ERM)
Risk Management Assessment: The Canadian Banking System Nawal K Roy Vice President Risk Management Specialist Nawal K Roy Vice President Risk Management.
The World Bank Superintendencia Bancaria Banco de la Republica Colombia Asobancaria Building a Technology Framework to Meet the Basel II Requirements Risk.
Service Design – Section 4.5 Service Continuity Management.
Operational risk management Margaret Guerquin, FSA, FCIA Canadian Institute of Actuaries 2006 General Meeting Chicago Confidential © 2006 Swiss Re All.
Risk Management at ANZ Banking Group Jun 18, 2008 Patrick Zhu Head of Retail Risk China Partnerships.
IS Audit Function Knowledge
Elements of Planning and Decision-Making
Expanded Version of COSO a presentation by Steve Wadleigh Expanded Version of COSO a presentation by Steve Wadleigh Standards for Internal Control in the.
Training.
B RITISH B ANKERS' A SSOCIATION Operational Risk & the Regulatory Environment Simon Hills Director - Prudential Capital team.
1 Operational Risk Management Member Education Series Seminar Indian Institute of Banking & Finance Nagpur November 2005.
Auditing II Unit 1 : Audit Procedures Unit 2: Audit of Limited Companies Unit 3: Audit of Government Companies.
Systemise your compliance management Peter Scott Consulting
Click to add text © 2010 IBM Corporation OpenPages Solution Overview Mark Dinning Principal Solutions Consultant.
Leveraging XBRL for Basel II Daniel D’Amico, IBM Business Consulting Services, UK.
Oracle’s BASEL II Solution Bucuresti 24 th February 2004 Pal Ribarics Oracle Financial Services Consulting, EU Enlargement Countries Solution Team.
Control environment and control activities. Day II Session III and IV.
Internal Auditing and Outsourcing
Practical Implications of Regulatory Convergence – Lessons from Basel II Mary Frances Monroe Division of Banking Supervision and Regulation Board of Governors.
Fiduciary Key Risk Indicators
Governance of the Treasury Function CIPFA Scottish Treasury Management Forum Alan George, Regional Director 23rd February 2012.
8 – 12 December 2008 Bruce Le Bransky MAFC / APEC / AFDC Shanghai Conference: Session 7.2: Challenges to Governance Structures.
1 Basel II – The Implementation Phase Simon Topping Hong Kong Monetary Authority / City University of Hong Kong 9 March 2005 Banking & Finance Technology.
Risk Management Office ECO-IDB Workshop on Risk Management 4 March 2012.
Corporate Governance: Basel II and Beyond Corporate Governance Program for Bank Directors of Indian Banks Mumbai December 14, 2005.
1 The Asian Banker Summit 2004 Capital Management After Basel II Simon Topping Executive Director (Banking Policy) Hong Kong Monetary Authority 5 May 2004.
Overview of Credit Risk Management practices in banksMarketing Report 1 st Half 2009 Overview of Credit Risk Management practices – The banking perspective.
Enterprise Risk Management (ERM) ABN AMRO Business Unit North America (BU NA) Overview for ERM Committee April 11, 2007.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 3-1 Chapter Three Risk Assessment and Materiality Chapter Three.
From Findings over KRIs to Process Control
CDS Operational Risk Management - October 28, 2005 Existing Methodologies for Operational Risk Mitigation - CDS’s ERM Program ACSDA Seminar - October 26.
Managing Risk Through Performance Measurement FIRMA Risk Management Training Conference Lori Loken-King - SVP Union Bank, N.A., Operational Risk Management.
Regulatory Convergence under Post Basel II: some comments Giovanni Majnoni Contractual Saving Conference Washington, DC, May 1, 2002.
Mrs.Shefa El Sagga F&BMP110/2/ Problems with the VaR Approach   Bankers The first problem with VaR is that it does not give the precise.
1 Meycor Solution for Basel II Operational Risk Management.
B RITISH B ANKERS' A SSOCIATION Implementing Basel II a trade association view Simon Hills Director Prudential Capital & Risk.
OPERATIONAL RISK Issues & Challenges March 9, 2007 Partners in Risk & Compliance.
1 BASEL II: ONE CREDIT ANALYST’S PERSPECTIVE Presented November 9, 2004 in Quito, Ecuador, on the occasion of the 10th anniversary celebration of ECUABILITY.
Basel-II Implementation & Implication BASEL II ACCORD Implications & Implementation by M. Saeed Sajid Institute of Chartered Accountant of India Riyadh.
Deutsche Bank Corporate Security & Business Continuity Business Continuity Metrics March 19 th 2008.
2006 General Meeting Assemblée générale 2006 Chicago, Illinois 2006 General Meeting Assemblée générale 2006 Chicago, Illinois Canadian Institute of Actuaries.
Copyright 2012 Delmar, a part of Cengage Learning. All Rights Reserved. Chapter 9 Improving Quality in Health Care Organizations.
Future of Credit Risk Management: Supervisory Approach to Basel II CIA Annual Meeting Session 4405 Ben Gully Director, Basel Implementation Division Office.
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
The World Bank The World Bank Risk Architecture in a Basel-II World Presented to the World Bank Risk Management Seminar Washington, D.C. May 18, 2004 Presented.
Credit risk vs. Market risk Credit risk is the risk that a borrower or counterparty may fail to fulfill an obligation whereas market risk is the risk to.
Credit risk in banks - importance of appraisal and monitoring PRESENTED BY : KRATI VERMA (09bshyd0390)
1  The objective of operational risk management is the same as for credit, market and liquidity risks that is to find out the extent of the financial.
Basel Committee Norms. Basel Framework Basel Committee set up in 1974 Objectives –Supervision must be adequate –No foreign bank should escape supervision.
1 Banking Risks Management Chapter 8 Issues in Bank Management.
The Future of Banking Regulation 7-8 April 2005, LSE Oliver Page OBE Director Major Retail Groups Division.
ERM and Information Risks July 2013 Advisory. 1 © KPMG, a partnership established under Ghanaian law and a member firm of the KPMG network of independent.
Strategic and Financial Logistics
Capital Regulations and Management Chapter 6
Measurement of Operational Risk
Energy Risk Management Credit Rating Perspective
Take Risks but Calculated!!!
Christopher Irwin Taipei October 17, 2001
An overview of Internal Controls Structure & Mechanism
Backtesting.
Presentation transcript:

Operational Risk: A Multi-Layered Problem Presented to the London Chapter of The Professional Risk Managers’ International Association and International Swaps and Derivatives Association London, England March 7, 2005 Presented by David M. Rowe, Ph.D. Executive Vice President for Risk Management SunGard

Basel Capital Accord – Brief History U.S. Bank Capital Ratios – Depression thru WWII Post-War Recovery thru early 1960s Mid-60s thru Mid-70’s Mid-70s thru Late-80’s

Basel Capital Accord – Brief History Basel 1 Proposed: 1986 Effective: 1988 Credit Risk

Overview of risk weights The Basel I Approach Claim Sovereigns Assessment Corporates Comm. Banks OECDNon-OECD 0%100% 20% 100% OECDNon-OECDAll 50% Multi-National Development Banks All Secured Residential Mortgages Required data could largely be from financial reporting systems.

Basel Capital Accord – Brief History Bank Capital Ratios – Depression thru WWII Post-War Recovery thru early 1960s Mid-60s thru Mid-70’s Mid-70s thru Late-80’s

Basel Capital Accord – Brief History Bank Capital Ratios – Depression thru WWII Post-War Recovery thru early 1960s Mid-60s thru Mid-70’s Mid-70s thru Late-80’s Late-80s forward

Basel Capital Accord – Brief History Basel 1.5 Proposed: 1993 Effective: 1998 Credit Risk + Market Risk Basel 1 Proposed: 1986 Effective: 1988 Credit Risk

Basel Capital Accord – Brief History April, 1993 –Initial “prescriptive” proposal. April, 1995 –Proposed allowing use of internal market risk models for calculation of regulatory capital (subject to supervisory review and approval.) Jan 1, Market risk amendment took effect with internal VaR models as a major source of risk estimates. Basel I Market Risk Amendment

Basel Capital Accord – Brief History Basel 1.5 Proposed: 1993 Effective: 1998 Credit Risk + Market Risk Basel 1 Proposed: 1986 Effective: 1988 Credit Risk Basel 2 Proposed: 1999 Effective: 2007 Credit Risk (Enhanced) + Market Risk (No change) + Op Risk (New) Key sources of required work for affected banks. Op Risk (New)

Men of Influence Jack Welch Long-time CEO of GE W. Edwards Deming

Operational Processes 1. Control & Risk Self-Assessment 2. Key Risk Indicators 3. Loss Data Collection 4. Analytics 5. The Operational Risk Pyramid

Operational Processes 1. Control & Risk Self-Assessment 2. Key Risk Indicators 3. Loss Data Collection 4. Analytics 5. Operational Processes Money Transfer, ATMs, Deposit Processing Statement Preparation Trade Processing Market VaR Calculation Credit Decisions P&L Calculation Front ePI Collateral Manager Adaptiv Reech

Operational Processes 1. Control & Risk Self-Assessment 2. Key Risk Indicators 3. Loss Data Collection 4. Analytics 5. Control & Risk Self-Assessment

The Deming Perspective Special Causes - these are often easily assignable: changes of operator, shift, or procedure, for example. They can often be identified, and sometimes solved by local operators. Common Causes - remain after special causes have been eliminated. They are due to the design, or the operation of the process or system. They may be identified by the operators, but only management authority can eliminate them.

Self-Assessment – One Model Define Process Quality Objectives ( Elective or Mandated) Define Threats to Achievement Document Control Portfolio Evaluate Risk Transfer/Insurance Estimate Residual Risk of Loss Acceptable? Optimal? Yes No Re-examine objectives and/or control design & risk transfer: develop action plan Yes Monitor and Review Periodically No Based on the CARDdecisions, Inc. Model

Operational Processes 1. Control & Risk Self-Assessment 2. Key Risk Indicators 3. Loss Data Collection 4. Analytics 5. Key Risk Indicators

Commensurable - capable of being measured by a common standard. Appropriate - suitable for a particular condition, occasion or place. An important challenge of risk management is balancing the conflicting needs for both commensurable and appropriate risk measures. Commensurable Versus Appropriate Measures

The trade-off between commensurable and appropriate risk measures is quite severe. Unexpected Loss

Operational Processes 1. Control & Risk Self-Assessment 2. Key Risk Indicators 3. Loss Data Collection 4. Analytics 5. Key Risk Indicators (Appropriate Metrics) Staff Turnover Settlement Failures ¥  ? € Computer Breakdowns Customer Complaints Electronic Security Breaches Internal Limit Violations

Time Performance Process is Under Control 68.2% 27.2% 4.3% 0.3%

Time Performance Any One Point in the Red Zone 68.2% 27.2% 4.3% 0.3%

Time Performance Two Out of Three Points in the Orange Zone 68.2% 27.2% 4.3% 0.3%

Time Performance Four Out of Five Points Beyond the Green Zone 68.2% 27.2% 4.3% 0.3%

Time Performance Eight or More Points on One Side of Zero 68.2% 27.2% 4.3% 0.3%

Time Performance Six or More Points With a Common Trend 68.2% 27.2% 4.3% 0.3%

Time Performance 14 or More Points That Oscillate Up and Down 68.2% 27.2% 4.3% 0.3%

Time Performance Eight or More Points Outside the Green Zone 68.2% 27.2% 4.3% 0.3%

Time Performance 15 or More Points Inside the Green Zone 68.2% 27.2% 4.3% 0.3%

Key Risk Indicators (Appropriate Metrics) Define relevant Key Risk Indicators (Risk Management Association) Map these to broad OpRisk causes Compare performance across similar operations Monitor KRIs over time using Statictical Process Control techniques as an early warning system.

Operational Processes 1. Control & Risk Self-Assessment 2. Key Risk Indicators 3. Loss Data Collection 4. Analytics 5. Loss Data Collection

Loss data are not the only, or even the most important, source of early warning signals. Such data are necessary for evaluating the aggregate potential losses from operational failures. They need to be collected using a carefully controlled process to: – Assure reconciliation to financial statements. – Enrich the loss amounts with control failure details.

Loss Database - Workflow Process 1 Line employee (problem owner) accesses via Intranet 1 2 Loss Events are written to the DB. 2 3 Immediate notice to dept. management; triggers action 3 4 Reconciliation with Accounting (Compliance Officer) 4 5 Op Risk Manager does analysis, categorization and events control 5 6 Op Risk Reports are periodically distributed to management 6 Dept. Management

Operational Processes 1. Control & Risk Self-Assessment 2. Key Risk Indicators Analytics 5. Analytics Loss Data Collection

Operational Processes 1. Control & Risk Self-Assessment 2. Key Risk Indicators 3. Loss Data Collection 4. Analytics 5. Analytics Expected loss Unexpected loss Stress loss Loss Distribution Approach EXTERNAL LOSSES

Operational Processes 1. Control & Risk Self-Assessment 2. Key Risk Indicators 3. Loss Data Collection 4. Analytics 5. The Operational Risk Pyramid

Principle 10 - Banks should make… … sufficient public disclosure to allow market participants to assess... (the banks’) operational risk exposure and the quality of … (the banks’) operational risk management... Basel Committee - Sound Practices Principle 3 - Information flows... reporting flows should enable senior management to monitor the effectiveness of the risk management system for operational risk … Principle 6 - Banks should implement… … a system to monitor, on an on-going basis, operational risk exposures and loss events by major business lines … Level 2 - Control and Risk Self-Assessment Level 3 - Key Risk Indicators Level 4 - Loss Data Collection

Three Approaches  One Aggregate Indicator (Aggr. Gross Revenue) Basic Indicator Approach RC Op  12%  Multiple Indicators (Gross Revenue by Bus. Unit) Standardised Approach RC Op < 12% RC Op << 12%  Banks‘ Internal Data and Models Advanced Measurement Approaches Operational Risk Capital Requirement

Advanced Measurement Approaches  Internal Measurement Approach  Scorecard Approach All AMA‘s include: Controlled collection of loss data Meeting of qualitative regulatory requirements Regulatory review and approval of the capital model Quantitative requirements: multi-year loss data series. Qualitative requirements: periodic review of data quality and a disciplined approach to process quality control. Expected loss Unexpected loss Stress loss  Loss Distribution Approach 

 Comply and minimize the regulatory burden/cost: –Minimize and justify minimum economic/regulatory capital –Don’t want to stand out vs. what everybody else is doing –Avoiding regulatory criticism / regulatory pressure is key  These banks tend to use: –LDA (single most important number in terms of bank cost) –Internal LDB (you need to know where you’ve been) –Scenarios (in order to complement analysis where the LDA stops) What Motivation Is Driving ORM Development?

 Genuine commitment to change the op risk profile of the organization: –avoid “Wall Street Journal events” –belief that ORM will lead to substantial performance improvement –strong internal conviction how things should be done –Desire and will to make a fundamental cultural change  These banks tend to use: –C&RSA (beginning of a cultural change) –Scorecard Appr. (incentives drive desired behaviour) –KRI / KPI

 We are where we are - but what measures can warn of potential future events?  These banks tend to use: –KRI (as an early warning system) –Formal statistical process control methods –Scenario analysis –Stress-testing –Attempt to correlate losses with early warning indicators. What Motivation Is Driving ORM Development?

Scorecard Approach LDAScenario Analysis LDC Ext. losses Control & Risk SA KRI & Loss Correlation Influence Behaviour  Assess Future Potential Risk  Comply & Minimize Cost  Motivation Data, systems, organizational requirements Business Continuity / DR Motivations and Strategies Functional Layers Identification Assessment Reports Evolution of Approaches Execution Recovery Senior Mgt. Engagement ORM Heatmap

Conclusions The operational risk capital charge began as a means of preventing lower aggregate capital requirements despite lower credit risk capital. Regulators quickly came to see it as a means of forcing improved process control on banks (most of which badly need it.) The OpRisk capital charge is likely to look rather like Pillar II with the teeth of Pillar I. That is, the actual charge is likely to reflect substantial supervisory discretion based on demonstrable improvements in process controls and disciplined execution.