Topic 8 Operational Risk and Cyber Risk
Topic 8: Operational Risk and Cyber Risk
Duration: 3 Hours
Learning Outcomes:
● Define operational risk and its categories.
● Identify common sources and triggers of operational risk.
● Develop strategies for measuring and managing operational risk.
● Understand the growing threat of cyber risk in financial services.
● Formulate a cyber risk management plan.
● Discuss regulatory expectations for operational and cyber risk management.
Module Content
1. Operational Risk Definition and Basel II/III Framework
Operational risk is a cornerstone of modern risk management frameworks, particularly in the financial
sector. The Basel Committee on Banking Supervision provides a widely accepted definition, which has
been instrumental in shaping how financial institutions manage this type of risk.
Definition: Basel II defines operational risk as "the risk of loss resulting from inadequate or failed internal
processes, people and systems or from external events." This definition is intentionally broad,
encompassing a wide array of potential issues that can lead to financial loss, reputational damage, or
even regulatory penalties. Unlike market risk (losses from price movements) or credit risk (losses from
borrower default), operational risk focuses on the internal workings of an organization and its interaction
with the external environment.
Basel II/III Framework:
The Basel framework has evolved significantly to address operational risk.
● Basel I: Did not explicitly include a capital charge for operational risk, focusing primarily on credit
risk.
● Basel II: Acknowledged the growing importance of operational risk and introduced a capital
charge for it. This was a significant step, recognizing that operational failures could lead to
substantial losses comparable to those from market or credit events. Basel II offered three
methods for calculating operational risk capital:
○ Basic Indicator Approach: A simple approach where capital is a fixed percentage of gross
income.
○ Standardized Approach: Divides a bank's activities into business lines, each with a
specific risk indicator and a fixed beta factor (multiplier) to determine capital.
○ Advanced Measurement Approaches: Allowed banks to use their internal models for
calculating operational risk capital, subject to supervisory approval. This required robust
internal data collection and risk measurement processes.
● Basel III (post-2008 financial crisis): While Basel III primarily focused on strengthening capital
and liquidity requirements, it continued to refine the operational risk framework. A key change
was the introduction of the Standardised Measurement Approach to replace BIA, SA, and AMA.
The SMA is a single, non-model-based method intended to be more robust, comparable, and
risk-sensitive. It combines a Business Indicator (based on income statement items) with an
Internal Loss Multiplier (based on a bank's historical operational losses). This move away from
AMA reflects concerns about the complexity and comparability of internal models.
2. Categories of Operational Risk: People, Process, Systems, External Events
To effectively manage operational risk, it's crucial to categorize its sources. The Basel framework typically
identifies four main categories:
● People: This category includes risks arising from human error, fraud (internal or external),
inadequate staffing, lack of necessary skills, poor training, employee misconduct, and insufficient
succession planning. Examples include a trader making an unauthorized transaction, an
employee inadvertently sending sensitive data to the wrong recipient, or a team lacking the
expertise to manage new technology.
● Process: Risks related to the design, execution, and control of internal business processes. This
can involve failures in transaction processing, reconciliation errors, inadequate approval
mechanisms, faulty product development, or non-compliance with internal policies and
procedures. An example would be incorrect data entry leading to erroneous customer billing or a
poorly designed loan origination process causing delays and losses.
● Systems: This category covers risks associated with failures or weaknesses in technology,
hardware, software, and IT infrastructure. It includes system outages, data corruption,
cybersecurity breaches, software bugs, insufficient data backup, and inadequate system capacity.
A core banking system crashing or a cyberattack compromising customer data are prime
examples.
● External Events: Risks originating from outside the organization's direct control. These include
natural disasters (e.g., floods, earthquakes), terrorism, geopolitical events, infrastructure failures
(e.g., power outages, telecommunications breakdown), supply chain disruptions, and major
changes in laws or regulations. An example is a regional power grid failure disrupting banking
operations or a new data privacy law requiring significant system changes.
3. Operational Risk Measurement Approaches: Loss Data Collection, Scenario Analysis, KRI
Measuring operational risk is challenging due to its diverse nature and the difficulty in predicting specific
events. However, several approaches are employed:
● Loss Data Collection: This involves systematically collecting and analyzing historical data on
operational losses within the organization. This internal loss data is categorized by event type,
business line, and gross loss amount. LDC is fundamental for understanding the frequency and
severity of past operational risk events, informing capital calculations, and identifying areas for
improvement. External loss data from industry consortia can also be used for benchmarking.
● Scenario Analysis: This involves identifying plausible future operational risk events, even those
without historical precedent, and assessing their potential impact. Expert judgment (from
business managers, risk managers, and external consultants) is used to estimate the frequency
and severity of these "what-if" scenarios. Scenario analysis is particularly useful for assessing
low-frequency, high-severity events that might not be captured by historical data alone.
● Key Risk Indicators: KRIs are metrics that provide early warnings of increasing operational risk
exposure. They are forward-looking indicators designed to monitor the current state of risk.
Examples include:
○ Number of failed transactions.
○ Employee turnover rates in critical functions.
○ Number of system outages.
○ Pending legal actions.
○ Cybersecurity vulnerability scan results.
Monitoring KRIs allows management to take proactive measures before a minor issue
escalates into a significant loss event.
4. Mitigation Strategies for Operational Risk: Internal Controls, Business Continuity Planning,
Insurance
Mitigating operational risk involves a combination of preventative measures, response planning, and risk
transfer.
● Internal Controls: These are policies, procedures, and systems designed to prevent errors, detect
fraud, and ensure compliance. Strong internal controls are the first line of defense against
operational risk. Examples include:
○ Segregation of Duties: Ensuring that different individuals are responsible for different
parts of a process to prevent fraud.
○ Authorization and Approval Limits: Requiring specific approvals for transactions above
certain thresholds.
○ Reconciliations: Regularly checking the consistency of data across different systems.
○ Policy and Procedure Documentation: Clear guidelines for all business activities.
○ Automated Controls: Embedded controls within IT systems.
● Business Continuity Planning: BCP involves creating systems and procedures to ensure that
critical business functions can continue during and after a disruptive event (e.g., natural disaster,
system failure). This includes:
○ Recovery Time Objective: The maximum tolerable duration of service interruption.
○ Recovery Point Objective: The maximum tolerable amount of data that can be lost.
○ Backup Sites: Alternate locations for operations if the primary site is unavailable.
○ Data Backup and Restoration: Regular backups of critical data and a tested plan for its
restoration.
○ Crisis Communication Plan: Strategies for communicating with employees, customers,
regulators, and the public during a crisis.
● Insurance: Risk transfer through insurance policies can protect against certain types of
operational losses. This includes:
○ Cyber Insurance: Covers costs associated with data breaches, cyberattacks, and other
cyber incidents.
○ Professional Indemnity Insurance: Protects against claims of negligence or error in
professional services.
○ Property Insurance: Covers physical damage to assets.
○ Business Interruption Insurance: Compensates for lost income and extra expenses
incurred due to a covered event.
5. Cyber Risk: Definition, Types of Cyber Threats, Impact on Financial Firms
Cyber risk is a rapidly evolving and critical component of operational risk, especially in the interconnected
financial services industry.
Definition: Cyber risk refers to the potential for loss or damage to an organization's information
technology systems, data, or reputation as a result of a cyberattack, system failure, or human error. It
encompasses both malicious acts and accidental events.
Types of Cyber Threats:
● Malware: Malicious software (e.g., viruses, worms, ransomware, spyware) designed to disrupt,
damage, or gain unauthorized access to computer systems.
● Phishing/Social Engineering: Deceptive techniques used to trick individuals into revealing
sensitive information (e.g., passwords, bank details) or executing malicious actions. This often
involves fake emails, websites, or phone calls.
● Denial-of-Service and Distributed Denial-of-Service Attacks: Attempts to make a computer or
network resource unavailable to its intended users by overwhelming it with traffic from multiple
sources.
● Data Breaches: Unauthorized access to or disclosure of sensitive, protected, or confidential data.
This can lead to financial loss, identity theft, and reputational damage.
● Insider Threats: Malicious or unintentional actions by current or former employees, contractors,
or business associates who have legitimate access to an organization's systems or data.
● Advanced Persistent Threats: Sophisticated, prolonged, and covert cyberattacks where an
intruder gains access to a network and remains undetected for an extended period, often to
steal data.
Impact on Financial Firms:
Financial firms are prime targets for cyberattacks due to the sensitive nature of the data they hold
(customer financial information, payment details) and the large sums of money they process. The impacts
can be severe:
● Financial Loss: Direct losses from fraud, theft, business interruption, and remediation costs.
● Reputational Damage: Loss of customer trust, negative media coverage, and reduced market
capitalization.
● Regulatory Fines and Penalties: Significant fines for non-compliance with data protection and
cybersecurity regulations.
● Legal Liabilities: Lawsuits from affected customers, partners, and shareholders.
● Systemic Risk: A major cyberattack on a critical financial institution could disrupt payment
systems and undermine confidence across the entire financial system.
6. Cyber Risk Management Frameworks: Identification, Protection, Detection, Response,
Recovery
Effective cyber risk management requires a structured approach. Frameworks like the National Institute
of Standards and Technology Cybersecurity Framework provide a common language and methodology.
Key functions include:
● Identification: Understanding the organization's assets, systems, data, and their vulnerabilities.
This involves:
○ Asset inventory (hardware, software, data).
○ Business environment analysis.
○ Risk assessments (identifying threats, vulnerabilities, and potential impacts).
○ Governance (policies, roles, responsibilities).
● Protection: Developing and implementing safeguards to limit the impact of a potential
cyberattack. This includes:
○ Access control (authentication, authorization).
○ Data security (encryption, data loss prevention).
○ Security awareness training for employees.
○ Network security (firewalls, intrusion prevention systems).
○ Maintenance (patch management, secure configurations).
● Detection: Implementing capabilities to identify the occurrence of a cybersecurity event. This
involves:
○ Continuous monitoring of networks and systems.
○ Intrusion detection systems.
○ Security information and event management systems.
○ Anomaly detection.
● Response: Developing and implementing activities to take action once a cybersecurity incident is
detected. This includes:
○ Incident response planning (containment, eradication, recovery).
○ Communication and coordination internally and externally.
○ Analysis of the incident.
○ Mitigation strategies.
● Recovery: Developing and implementing activities to restore any capabilities or services that
were impaired due to a cybersecurity incident. This involves:
○ Recovery planning and implementation.
○ Restoration of data and systems.
○ Post-incident reviews and lessons learned.
○ Improvements based on the incident.
7. Data Privacy and Regulatory Compliance (e.g., Philippine Data Privacy Act)
Data privacy is a critical aspect of operational and cyber risk, especially for financial institutions handling
vast amounts of sensitive personal and financial data. Regulatory compliance in this area is non-
negotiable.
Key Principles of Data Privacy:
● Consent: Obtaining explicit consent for collecting and processing personal data.
● Purpose Limitation: Collecting data only for specified, legitimate purposes.
● Data Minimization: Collecting only data that is necessary and relevant.
● Accuracy: Ensuring data is accurate and up-to-date.
● Storage Limitation: Retaining data only for as long as necessary.
● Integrity and Confidentiality: Protecting data from unauthorized access, processing, loss, or
destruction.
● Accountability: Organizations being responsible for complying with data protection principles.
Regulatory Compliance (e.g., Philippine Data Privacy Act of 2012 - RA 10173):
The Philippine Data Privacy Act regulates the collection, processing, and storage of personal information.
Key aspects include:
● Scope: Applies to all processing of personal information, whether automated or manual, by any
natural or juridical person in the Philippines.
● Data Subject Rights: Grants individuals rights such as the right to be informed, object, access,
rectification, erasure or blocking, damages, data portability, and to file a complaint.
● Obligations of Personal Information Controllers and Processors: Requires organizations to
implement reasonable and appropriate organizational, physical, and technical security measures
to protect personal data.
● Data Breach Notification: Mandates notification to the National Privacy Commission and
affected data subjects when a personal data breach occurs that likely poses a real risk to the
rights and freedoms of data subjects.
● Penalties: Imposes significant fines and imprisonment for violations, emphasizing the importance
of compliance.
Compliance with such acts is not just a legal requirement but a fundamental aspect of managing
reputational and operational risk. Financial institutions must implement robust data governance, privacy-
by-design principles, and regular audits to ensure adherence.
8. Resilience and Disaster Recovery Planning
Resilience and disaster recovery planning are integral to business continuity and operational risk
management, particularly in the face of increasingly frequent and severe disruptive events.
Resilience: The ability of an organization to absorb, adapt to, and recover from disruptive events while
continuing to deliver its core services. It moves beyond simply recovering from a disaster to building an
inherent capacity to withstand shocks and quickly return to normal (or even improved) operations. Key
aspects include:
● Operational Resilience: Focusing on the continuous delivery of critical services.
● Financial Resilience: Ability to absorb financial shocks.
● Organizational Resilience: The adaptability of its people, culture, and governance.
Disaster Recovery Planning: DR planning is a subset of BCP that specifically focuses on restoring IT
systems and infrastructure after a natural or human-induced disaster.
● Components of a DR Plan:
○ Data Backup and Restoration Strategy: Regular backups (full, incremental, differential)
stored off-site, with tested restoration procedures.
○ Alternative Site Strategy: Hot sites (fully equipped with hardware and software), warm
sites (basic infrastructure, requires some setup), or cold sites (basic space, requires
significant setup).
○ Network Recovery: Plans for restoring network connectivity and services.
○ Hardware and Software Procurement: Strategies for quickly replacing damaged
equipment and licenses.
○ Recovery Teams: Designated teams with clear roles and responsibilities for executing
the DR plan.
○ Testing and Maintenance: Regular testing of the DR plan (e.g., tabletop exercises, full
simulations) and periodic updates to ensure its effectiveness and relevance.
● Integration with BCP: DR is often integrated into the broader BCP, ensuring that the recovery of
IT infrastructure supports the resumption of critical business processes. This holistic approach is
crucial for achieving true organizational resilience.