Unit 10 - Operational Risk Ed14
Unit 10 - Operational Risk Ed14
This workbook has been written to prepare you for the Chartered Institute for Securities &
Investment’s Operational Risk examination.
PUBLISHED BY:
Chartered Institute for Securities & Investment
© Chartered Institute for Securities & Investment 2010
8 Eastcheap
London
EC3M 1AE
Tel: +44 (0) 20 7645 0600
Fax: + 44 (0) 20 7645 0601
WRITTEN BY:
Stephen Robinson
This is an educational manual only and Chartered Institute for Securities & Investment accepts no
responsibility for persons undertaking trading or investments in whatever form.
While every effort has been made to ensure its accuracy, no responsibility for loss occasioned to any
person acting or refraining from action as a result of any material in this publication can be accepted by
the publisher or authors.
All rights reserved. No part of this publication may be reproduced, stored in a retrieval system,
or transmitted, in any form or by any means, electronic, mechanical, photocopying, recording or
otherwise without the prior permission of the copyright owner.
Warning: any unauthorised act in relation to all or any part of the material in this publication may result
in both a civil claim for damages and criminal prosecution.
A Learning Map, which contains the full syllabus, appears at the end of this workbook. The syllabus
can also be viewed on the Institute’s website at [Link] and is also available by contacting
Client Services on +44 (0) 20 7645 0680. Please note that the examination is based upon the
syllabus. Candidates are reminded to check the Candidate Common Room area of the Institute’s
website ([Link]/candidatecommonroom) on a regular basis for updates that could affect their
examination as a result of industry change.
The questions contained in this manual are designed as an aid to revision of different areas of the
syllabus and to help you consolidate your learning chapter by chapter.
This learning manual (or ‘workbook’ as it is often known in the industry) provides not only
a thorough preparation for the appropriate CISI examination, but is a valuable desktop
reference for practitioners. It can also be used as a learning tool for readers interested in
knowing more, but not necessarily entering an examination.
The CISI official learning manuals ensure that candidates gain a comprehensive
understanding of examination content. Our material is written and updated by industry
specialists and reviewed by experienced, senior figures in the financial services industry.
Exam and manual quality is assured through a rigorous editorial system of practitioner panels
and boards. CISI examinations are used extensively by firms to meet the requirements of
government regulators. The CISI works closely with a number of international regulators
which recognise our examinations and the manuals supporting them, as well as the UK
regulator, the Financial Services Authority (FSA).
CISI learning manuals are normally revised annually. It is important that candidates check
they purchase the correct version for the period when they wish to take their examination.
Between versions, candidates should keep abreast of the latest industry developments
through the Candidate Commonroom area of the CISI website. (The CISI also endorses the
workbooks of 7City Learning and BPP.)
The CISI produces a range of elearning revision tools such as Revision Express Interactive,
Revision Express Online and Professional Refresher that can be used in conjunction with our
learning and reference manuals. For further details, please visit [Link].
As a Professional Body, around 40,000 CISI members subscribe to the CISI Code of Conduct
and the CISI has a significant voice in the industry, standing for professionalism, excellence
and the promotion of trust and integrity. Continuing professional development is at the
heart of the Institute’s values. Our CPD scheme is available free of charge to members,
and this includes an online record keeping system as well as regular seminars, conferences
and professional networks in specialist subjects areas, all of which cover a range of current
industry topics. Reading this manual and taking a CISI examination is credited as professional
development with the CISICPD scheme. To learn more about CISI membership visit our
website at [Link].
We hope that you will find this manual useful and interesting. Once you have completed it
you will find helpful suggestions on qualifications and membership progression with the CISI
at the end of this book.
Ruth Martin
Managing Director
CONTENTS
Glossary 141
It is estimated that this workbook will require approximately 70 hours of study time.
CHAPTER ONE
RISK BASICS
1. INTRODUCTION 3
2. WHAT IS RISK? 3
Operational Risk 1
Risk Basics Chapter One
2 Operational Risk
Risk Basics Chapter One
1. INTRODUCTION
This workbook describes what risk is and what it means to the financial services industry. It describes
the three common categories of financial risk – Credit and Market (Chapter 2) and Operational
(Chapter 3) – providing a brief contextual overview of the first two and focusing particularly on the
latter. Operational risk and some of the more important aspects of its management are described in
detail in Chapters 3, 4 and 5.
This opening chapter introduces the basics. It explains why risk in general is a subject of concern in all
industries and all walks of life. It then focuses on what financial risk means and where the category of
operational risk fits into the overall picture. Finally, it describes some of the high profile events that have
served to highlight the critical need to understand and manage operational risk effectively.
2. WHAT IS RISK?
This consequence of ‘something going wrong’ can be critical. Manufacturers know this fact and,
consequently, have always placed a high priority on product safety and systems reliability. The
aerospace, civil engineering and chemical processing industries are prime examples.
The need to understand why something might go wrong and then to try to prevent the possibility
of occurrence is, therefore, a fundamental requirement for any industry. For instance, for an
airline operator, an aircraft crash in service will have some profound consequences. The five major
consequences are:
For these reasons, all airline operators expend a great deal of time, effort and money on ensuring
adequate safety standards by maintaining rigorous air frame and engine maintenance, adequate aircrew
training, established safety procedures and general compliance with all relevant industry standards. As
you will realise, the same approach has been adopted by many other industries and activities. Think of
the importance in the modern world of health and safety regulations, inspection and enforcement.
Operational Risk 3
Risk Basics Chapter One
These steps represent some of the mitigating activities necessary to reduce operating risks experienced
in the airline business. Even so, things can go wrong, as the case study below illustrates.
“A British Airways jumbo jet came within 200 feet of landing on a British Midland Airbus at Heathrow
in one of the most serious near misses in British aviation history.
Hundreds of passengers came close to disaster because of ‘inappropriate’ actions by the air traffic
controller overseeing the operation on 28 April last year, an official report revealed today. The report
will make alarming reading for the hundreds of thousands of people using the airport as the summer
holiday season gets under way.
The BA jet was just 118 feet above ground level when it pulled out of the landing manoeuvre –
probably travelling at around 150mph – to avoid the Airbus as it prepared to take off from the same
runway.
The Airbus crew was ‘startled to see an aircraft flying directly above them, along the runway centre
line and approximately 200 feet above them’.
A 28-year-old trainee air traffic controller, a third of the way through her course, was controlling the
operation, the Air Accident Investigation Branch special report revealed. However, it was a series of
mistakes by her supervisor that were instrumental in the ‘very dangerous’ incident.”
There are direct parallels with the approach to operational risk in the financial services industry. Here,
loss generally occurs in the form of money or reputation and, to prevent this, firms put
risk control procedures in place. Financial services regulators, like airline regulators, set minimum
standards and then police them to ensure that firms are doing enough to protect their clients’ interests.
Historically, financial institutions have concentrated on market and credit risk as a means of
understanding their exposure to loss. However, following a number of high profile losses due to
operational failures, the industry has been increasingly focused on the measurement and management
of operational risk as well.
An appropriate starting point for understanding the subject is to review the commonly used risk terms
and definitions employed by the financial services industry.
4 Operational Risk
Risk Basics Chapter One
The essential points to note when applying this definition to risk management are:
• Chance - this is the ‘chance’ or ‘probability’ of an event happening in the future. The event has not
yet happened – it exists as one of a number of possible outcomes that may occur in the future. This
is important because it suggests that people can take action today that may reduce the chance of
the event occurring in the future.
• Adverse consequences - the potential outcome is regarded as negative. It is a potential
occurrence that people are trying to avoid. This is also called the downside of risk.
It is generally accepted that there are three main categories of risk in the financial services industry.
Credit risk relates to lending or agreeing to trade with another counterparty. Will the other
counterparty pay or deliver the asset they have undertaken to deliver on the due date? Traditionally,
the primary risk for financial institutions has been credit risk or the potential for loss that results from
lending. Institutions accept credit risk in order to earn revenue. They lend to firms with a higher risk
because of the potential for higher returns.
Market risk is manifested by exposure to the uncertain market value of a portfolio. For example, a
trader may hold a portfolio of securities or other commodities. They know what their market value is
today, but are uncertain as to what their market value will be a week from today. Therefore the trader
faces market risk. Market risk represents the potential risk of loss of earnings or capital arising from a
reduction in the value of financial instruments. In simple terms, an investor is exposed to market risk as
soon as a financial product is purchased. This is intrinsic in all markets and across all products.
Although there are other descriptions, the definition of operational risk, which is widely accepted
today is: ‘The risk of loss resulting from inadequate or failed internal processes, people and systems or from
external events’. This is the formal definition which has been drawn up by the Basel Committee on
Banking Supervision.
In practical terms, operational risk addresses the risk of things going wrong with the day-to-day
operating activities of the firm, which then results in financial loss.
Liquidity risk is the risk that a bank or other financial institution may not be able to close out a position
because the market is illiquid in some way. For example, there may not be enough buyers of stock
when an institution is wishing to sell some stock.
Operational Risk 5
Risk Basics Chapter One
The financial services industry has become increasingly aware of the importance of managing risk. For
financial services institutions, this may involve credit risk, market risk or operational risk. For financial
services regulators, it has come to mean adopting risk-based supervision. For banks in particular, the
measurement and control of capital risk has become a key issue.
Traditionally, credit risk from lending was the primary risk of banks. As financial institutions
entered new markets and traded new products, other risks such as market risk began to occupy
management’s attention. In the last few decades financial institutions have developed some elegant and
complex tools and methodologies to manage market risk, driven by the huge rewards involved in its
upside. The methods have been modified to allow the modelling of credit risk.
More recently, the importance of operational risk has been acknowledged and it now takes its place as
one of the three fundamental categories of risk that require effective management.
There is, as yet, no single agreed industry standard definition for operational risk. Some common
variations on the Basel Committee definition (given earlier in this section) are:
• The risk that deficiencies in information systems or internal controls will result in unexpected loss.
The risk is associated with human error, system failures and inadequate procedures and controls.
• The risk of loss arising from various types of human or technical error.
• The risk inherent in internal processes.
• The risk to earnings or capital arising from problems with service or product delivery.
• All risks that are not categorised as either credit or market risk.
The common theme to these definitions is that risk exists because of the potential for things to go
wrong. Activities such as the following exist in any financial institution, along with their associated
processes:
6 Operational Risk
Risk Basics Chapter One
They can affect one or many areas of the firm and can cross departmental boundaries. The main
sources from which deficiencies can originate are:
• information systems;
• internal controls;
• human errors;
• system failures;
• inadequate procedures; and
• external events.
Operational risk management is concerned principally with identifying, measuring and mitigating
deficiencies inherent in the operational workings of a financial institution.
Risk management tries to ensure that the likelihood of risks being realised and the potential impact is
reduced to acceptable levels.
• Implementation - risk management is concerned with taking action to reduce risk levels. It
requires a proactive, or preventive, approach. There is little benefit in the foreknowledge that a
loss-making event may occur if no action is taken to prevent it, or mitigate its consequences.
• A structured process - this means using the result of a planned, ongoing, decision process and
related action programme. This involves identifying, assessing, controlling, monitoring and mitigating
risks where possible. Once implemented, there will be a need for feedback and review of the
process to aid and inform future decision-making.
• Reduces the likelihood - risks can only be reduced – they cannot be eliminated completely
(unless the activity is not undertaken at all). This is linked to the idea of probability. If the future
were certain, there would be no probabilities, only certain outcomes. The best that can be done is
to try to make the future a little more certain and to reduce the chance of negative outcomes.
• Acceptable levels - given that risk cannot be entirely eliminated, effective risk management is
concerned with reducing the chances of misfortune to an acceptable level. This is an extremely
subjective measure. What is meant by ‘acceptable’? Something that is acceptable to one person
or institution may not be acceptable to another. Assessing acceptability means understanding and
balancing the downside of risk with the potential benefits of the upside. Finding agreement at a
firm-wide or industry-wide level and obtaining regulatory consent on the level of acceptability of
risk is a major area of contention when designing risk management strategies.
Operational Risk 7
Risk Basics Chapter One
Historically, financial institutions have concentrated on market and credit risk as a means of managing
their exposure to loss. However, following a number of high-profile losses due to operational failures,
the industry has increasingly been focusing on managing and measuring the risks inherent in their
internal processes. This section summarises well-known operational failures which have highlighted the
need for better understanding and control of operational risk.
• Barings - this was the most high-profile case of the 1990s. Nick Leeson, a trader for Barings Bank,
a long-established, prestigious small British investment bank, generated unnoticed trading losses of
US$1.3 billion on futures markets in Singapore and Osaka. This forced the bankruptcy of Barings
Bank in February 1995. He did this by failing to follow agreed trading strategies and by obscuring
losses from his head office by setting up an unauthorised hidden trading account. Furthermore,
he was allowed the responsibility for trading positions as well as settling his own trades. The
operational risk issues were that:
• Leeson was in charge of both the front office and related support areas of the office;
• major differences in culture existed between the bank’s management and some of its traders;
• the senior management of Barings failed to understand the risks involved in the trading
operation and failed to have the appropriate reporting measures in place in order to measure
their exposure accurately.
• Allied Irish Bank - in February 2002, Allied Irish Bank (AIB) – Ireland’s second-biggest bank –
revealed that it was investigating an apparent currency fraud at its Baltimore-based subsidiary,
Allfirst. It soon became clear that the scale and nature of the losses would make the AIB/Allfirst
story one of the biggest ‘rogue trader’ scandals since Nick Leeson brought down Barings Bank
in 1995. The losses were calculated at US$691million. The operational risk issues were:
• there were serious errors in the bank’s controls environment;
• the trader was able to falsify entries into the bank’s value-at-risk (VaR) control system as
independent checking of his entries into the model was not carried out;
• the internal audit department was under-resourced and inexperienced in foreign exchange
dealing. It did not demonstrate a clear understanding of the risks associated with the business
strategies. Key controls were not tested and other tests were not effective;
• the bank’s head of treasury ignored numerous warning signs of the trader’s activities by not
reviewing sufficiently closely the daily profit and loss (P&L) figures and by not questioning
excessive daily volume figures. He also failed to act upon warnings given by operations and
actually prevented risk specialists from having access to information necessary to fulfil their
work; and
• the risk, operations and internal audit culture was too deferential to the business lines.
8 Operational Risk
Risk Basics Chapter One
• Enron - the collapse of energy giant Enron is the largest bankruptcy in US corporate history.
In a little over 15 years Enron grew into one of the US’s largest companies. It embraced new
technologies, established new methods of trading in energy and was seen as a major corporate
success in the US. However, the apparent success of the company was based on artificially inflated
profits, dubious accounting practices and fraud. The company filed for bankruptcy in December
2001 but, in the three months prior to it, had claimed that its assets were worth almost £62 billion.
The operational risk issues were:
• the mismanagement and mistreatment of shareholders;
• many allegations of fraud by the company’s staff and, in particular, their most senior staff;
• the company’s auditors admitted that they had instructed their employees to shred many Enron
documents, meaning that a lot of evidence was destroyed; and
• Enron’s growth and that of its share price was increasingly dependent on dubious accounting
practices, such as the company making investments and then shifting debt off its books to
theoretically independent partnerships, in return for potential income that provided a buffer
against future losses. Revenue figures were thus greatly over-exaggerated.
• National Australia Bank - in January 2004 the Bank announced substantial losses arising
from currency options trading. The final figure was A$360 million, twice as much as had initially
been reported earlier the same month. It emerged from the official investigation that between
September 2001 and the date of the revelations the value of the currency options portfolio, already
overstated by approximately A$4 million, grew to become hundreds of millions. A group of traders
was responsible. They concealed their losses by booking false transactions and by under- and
over-reporting profits. They exceeded risk limits and falsified positions against a weakening
Australian dollar, which significantly increased the risk exposure of the currency options desk to the
US dollar in late 2003. The traders’ market dealing activities were contrary to the Bank’s strategy.
The operational risk issues were:
• Integrity of people:
– dishonesty of the individuals in the trading group.
• Risk and control framework:
– lack of adequate supervision;
– failure of risk management;
– absence of financial controls;
– gaps in back-office procedures.
• Governance and culture:
– poor quality of risk information available to senior management;
– failures of Audit and Risk committees to investigate and act;
– lack of escalation to senior management;
– the Bank’s culture focused on process rather than understanding issues, taking
responsibility and resolving them.
• Nationwide - the Nationwide Building Society was fined £980,000 in 2007 by the UK Financial
Services Authority (FSA) over security breaches. The fine followed the theft of a laptop from a
Nationwide employee’s home which contained confidential customer data. The FSA found security
was not up to scratch after the man had put details of nearly 11 million customers on his computer.
The FSA also found that the Nationwide did not start an investigation until three weeks after the
theft occurred.
Operational Risk 9
Risk Basics Chapter One
The Nationwide claimed that the information on it could not have been used for identity fraud
as there were no PIN numbers, passwords or account balance information on it. However, it
appeared the laptop may have contained names, addresses and account numbers. As a result, the
building society’s customers had been exposed to the risk of financial crime.
The FSA’s investigation showed that the building society had not known that the laptop contained
any confidential customer information at all. The laptop was stolen from the home of a
long-standing and trusted employee of the Nationwide who needed access to the data. However,
despite reporting the theft of the laptop promptly, he did not tell his employer what was on it.
• Société Générale - on 24 January 2008, the bank announced that a single futures trader at the
bank had fraudulently lost the bank €4.9 billion, the largest such loss in history. The bank did not
name the trader, but other sources identified him as Jérôme Kervial, a relatively junior futures
trader, who allegedly entered into a series of bogus transactions that spiralled out of control amid
volatile markets in 2007 and early 2008. Partly due to the loss, that same day, two credit rating
agencies reduced the bank’s long-term debt ratings.
Executives at the bank said that the trader had acted alone and that he may not have benefited
directly from the fraudulent deals. The bank immediately announced that it would be seeking to
raise €5.5 billion in additional financing. Police raided the bank’s offices and also the apartment of
the trader. The Paris prosecutor’s office confirmed two days later that the trader was not ‘on the
run’ and that he would be questioned at the appropriate time, once a full investigation had taken
place.
There were found to be a number of operational risk issues in this instance, including:
• The fact that the trader had an in-depth knowledge of the control procedures resulting from
his former employment in the middle office (which also included the bank’s compliance
department).
• The trader was therefore able to conceal his dealing positions through a scheme of elaborate
and fictitious transactions.
• The trader used his knowledge of the bank’s control procedures to gain access into its
computers and erase all traces of the alleged fraud.
• Standard Life - standard Life spent £100 million compensating customers in 2009 who had
invested in a supposedly safe cash fund that instead lost money on more exotic products. The
life assurer paid the compensation to customers who saw the value of their pensions drop by an
average of £1,000 in a single day because of the deterioration in value of asset-backed securities in
which one of the company’s funds was heavily invested.
Standard Life had to compensate all 97,000 investors in its Pension Sterling Fund, which dropped
in value by 4.8% in a day, when Standard Life revalued the asset-backed securities that constituted
almost half its holdings.
Standard Life accepted it had not made it sufficiently clear that the fund’s holdings were potentially
subject to this degree of volatility. Standard Life confirmed the Pension Sterling Fund would
continue to operate as it had in the past, though it had made changes to the way the fund is
marketed.
• UBS - the Financial Services Authority (FSA) fined Swiss bank UBS £8 million in 2009 for failing to
stop its employees making unauthorised transactions. The FSA said four UBS employees had carried
out the transactions using customer money on at least 39 accounts. The FSA also said the trades
involved foreign exchange and precious metals.
10 Operational Risk
Risk Basics Chapter One
According to the FSA, an internal UBS investigation found that as many as 50 unauthorised
transactions a day were taking place at the operation’s peak. It criticised the bank not only for
systems failures that led to the trades, but also for not responding to ‘several warning signs’ that the
systems were not working.
The FSA confirmed that these employees were able to take advantage of UBS’ inadequate systems
and controls, giving them free rein to make unauthorised trades with customer money that they
were then able to conceal.
The US mortgage market default that triggered the global financial crisis around the world in 2007 has
changed the financial landscape drastically. Since that time policy makers have been trying to formulate
solutions to the problems that the financial industry and the global economy is facing.
The sub-prime lending crisis evolved into a full market meltdown. A large number of worldwide major
investment firms and institutions had either collapsed or suffered huge losses. The organisations faced
huge collateral calls based on the decline of the mortgage securities underlying their various credit
default swap protection products for collateralised debt obligations. A number of governments pledged
very large sums of money to support the institutions based in their own countries.
Organisations questioned why audit risk assessments, conventional financial controls and corporate
compliance activities did not reveal the extent of the potential collapse. There was a fundamental failure
to embrace appropriate enterprise risk management behaviours and attributes. Alongside this there
was a failure to develop and reward internal risk competencies. A large number of firms have been
criticised for taking a relatively short-term view to the profits that were being made.
There was an over reliance on the use of financial models and the mistaken assumption that these
models were both reliable and sufficient tools to justify decisions to take risk in the pursuit of profit.
The Financial Services Authority (FSA) is working with firms to promote a more risk-aware enterprise
risk management culture, demonstrate appropriate risk management behaviours, develop internal risk
management competencies and use enterprise risk to influence management decision-making in both
taking and trying to avoid risks.
Markets will need to enter a period of restructuring to take into account the realities of the impact of
the crisis. Bank liquidity is now recognised as being much more important in the banking industry than
in the past, when banks paid insufficient attention to the need to diversify funding sources. The market
participants must become aware of the changing dynamic in the financial industry and adapt their
strategy and approach accordingly.
The G20 summit in London in April 2009 confirmed that governments around the globe would tackle
the problem and take measures to prevent a crisis like this happening again.
Operational Risk 11
Risk Basics Chapter One
1. What are the four related aspects of risk management? Section 2.3
2. Name two of the high-profile losses that have occurred. Section 2.4
3. What were the operational risk issues involved in the Allied Irish Bank case? Section 2.4
4. What were the operational risk issues involved in the National Australia Bank case? Section 2.4
12 Operational Risk
CHAPTER TWO
1. CREDIT RISK 15
2. MEASURING CREDIT RISK 17
3. CREDIT RISK MANAGEMENT AND REPORTING 22
4. THE CREDIT RISK MANAGEMENT FUNCTION 29
5. MARKET RISK 30
6. MEASURING MARKET RISK 32
7. VALUE-AT-RISK (VAR) 33
8. MARKET RISK MANAGEMENT AND REPORTING 36
9. THE MARKET RISK MANAGEMENT FUNCTION 37
10. MARKET RISK REGULATORY REQUIREMENTS 38
11. LIQUIDITY RISK 39
12. MEASURING LIQUIDITY RISK 42
13. LIQUIDITY RISK MANAGEMENT AND REPORTING 43
Operational Risk 13
Other Major Risks Chapter Two
14 Operational Risk
Other Major Risks Chapter Two
1. CREDIT RISK
LEARNING OBJECTIVES
2.1.1 Know the basic terms used in the subject of credit risk: counterparty
risk; issuer risk
1.1 INTRODUCTION
Traditionally, the primary risk for financial institutions has been credit risk or the potential for loss that
results from lending. Institutions accept credit risk in order to earn revenue. They will also lend to firms
with a higher risk because of the potential for higher returns.
Over the last few decades, companies have expanded rapidly both nationally and globally, markets have
developed, new and complex products have been created and the client base of firms has increased.
This has led to greater opportunities for revenue growth as well as new and increased market and
credit risks that need to be identified, assessed and controlled. As a result, new ways are continually
being developed to offset these risks. Products such as interest rate and currency derivatives have been
created for the purpose of risk management by enabling hedging strategies to be adopted but a side
effect of these products is the creation of yet more risk inherent in using such products themselves.
Understanding credit risk has become a complex subject and its mitigation to acceptable levels is a
major concern for all financial institutions. This chapter introduces the basic methods of measurement
and some common mitigation techniques.
Before considering how credit risk can be managed, the basic question needs asking, ‘What is it?’
1.2 DEFINITION
Credit risk, also sometimes known as default risk, is defined as:
‘The risk of loss caused by the failure of a counterparty to meet its obligations.’
Credit risk affects any firm to which money is owed by way of loan debt or obligation to pay, such
as fees. The firm that has the financial obligation is called an obligor. Credit risk exists in any contract
where one party has an obligation to another, and is present in the trading of all financial instruments.
A counterparty is one of the parties to a transaction – either the buyer or the seller.
Operational Risk 15
Other Major Risks Chapter Two
Credit risk is associated with either on-balance sheet transactions or off-balance sheet
transactions.
On-balance sheet transactions include instruments such as loans and the buying and selling of securities.
Loans carry ‘direct risk’, which is the simple risk of loan default when money is lent to a customer.
Securities carry ‘issuer risk’, which is the risk of default by the issuer on redemption or interest servicing
when one institution or investor holds debt securities (eg, bonds) issued by the issuing institution. Bonds
are long-term forms of debt and thus there is a risk that the issuer will default on its obligations to pay
coupons and repay the principal with regard to the bond. Hence gilts (UK government securities) are
deemed to be less risky than corporate bonds. When considering issuer risk an investor must assess the
likelihood of a default taking place, the severity of such a default and when a default might occur. The
Russian government famously defaulted on payment of interest and bond redemptions in September
1998.
Off-balance sheet transactions involve financial instruments such as securitisation products, forwards
and over-the-counter (OTC) derivatives. One of the main advantages of using off-balance sheet
products is that they are treated differently from a capital adequacy perspective and allow a firm to
reduce its balance sheet liabilities.
Both on- and off-balance sheet transactions can carry pre-settlement risk and settlement risk.
• Pre-settlement risk (PSR) is the risk that an institution defaults prior to the settlement of the
transaction when the traded instrument has a positive economic value to the other party.
• Settlement risk (SR) occurs when there is a non-simultaneous exchange of value (eg, cash for
securities) and one party defaults during the exchange.
16 Operational Risk
Other Major Risks Chapter Two
• Bond investors who lose their investment if the bond issuer fails face issuer credit risk.
• Firm A and Firm B trade an interest swap. If interest rates move in firm A’s favour, firm B will owe
a net obligation. Because firm B could fail to perform on such an obligation, the corporation faces
pre-settlement credit risk.
• An investment company has a forward contract to exchange euros for US dollars with a foreign
firm. On the contract’s maturity date, the investment company makes its euro payment but,
because of time differences, there is a delay in the foreign firm making its corresponding dollar
payment. Given it is possible that the firm will fail to make its payment, the corporation faces
settlement credit risk.
Measuring credit risk involves the use of tools or models to estimate the credit exposure of the lender.
These range from basic crude techniques, such as simply taking the credit exposure as being equal
to the notional values of all transactions, and managing this exposure, to more modern approaches
that measure more precisely the risks inherent in a portfolio. This section explains the following basic
techniques:
• credit exposure;
• credit risk premium;
• credit ratings; and
• modern measurement techniques.
Operational Risk 17
Other Major Risks Chapter Two
Credit exposure is the amount that can potentially be lost if a debtor defaults on their obligations. It is
used to quantitatively assess the severity of credit risk from:
• counterparties; and
• portfolios.
Credit exposure consists of two parts: current exposure and potential future exposure.
Potential future exposure is a calculation of the likely maximum loss in the future. The potential
exposure calculation is usually performed using statistical techniques and forms part of value-at-risk
(VaR) calculations (this is explained in more detail in Chapter 7).
A credit risk premium is the difference between the interest rate a firm pays when it borrows
and the interest rate on a default-free security, such as a government bond. The premium is the
extra compensation the market or financial institution requires for lending to a firm that has a risk of
defaulting.
As a firm’s credit risk increases, lenders demand a higher credit risk premium through an increase in the
amount of interest paid. This increase is necessary to offset the increased probability that the loan will
not be repaid in accordance with its terms.
There is a strong relationship between credit risk premium and credit rating (see next section). The
higher the rating, the more creditworthy the firm, so the lower the premium. This means that the cost of
borrowing will be lower for a higher-rated firm as a reflection of its lower likelihood to default. As a result,
a downgrade in a company’s credit rating can significantly increase its borrowing costs.
18 Operational Risk
Other Major Risks Chapter Two
A broad measure of a firm’s credit risk is its external credit rating which is an assessment of its credit
worthiness and financial health. It is used by investors in public issues of debt as a guide to managing
their credit exposure. An independent rating agency will assign a credit rating based on analysis of the
company’s financial statements. This is usually done with a short- and long-term outlook. The services
provided by the credit rating agencies enable investors to rely upon impartial and regularly updated
research which takes into account all the various factors which are necessary in respect of credit risk
assessment.
For example, Moody’s uses ratings for long-term credit that range from Aaa, representing the highest
quality investments, to C for firms more likely to default.
• Moody’s;
• Standard & Poor’s; and
• Fitch Ratings.
Operational Risk 19
Other Major Risks Chapter Two
A A A
B B B
Any instrument appearing in the first four rows (ie, including Baa or BBB) are deemed to be investment
grade, the remainder below this level being referred to as non-investment grade. Investment grade
bonds are those that have been judged likely enough to meet their payment obligations.
The credit rating agencies have been subject to some criticisms which have potentially undermined
market confidence in them, including:
• On occasions they have not downgraded companies promptly enough. For example, Enron’s rating
remained at investment grade four days before the company went bankrupt, despite the fact that
the credit rating agencies had been aware of the company’s problems for months (see Chapter 1
for more details on the collapse of Enron).
• Some of the rating agencies have been criticised for having too familiar a relationship with company
management, possibly opening themselves to undue influence or the vulnerability of being misled.
This is implicit in the relationships when the companies being rated are the ones paying fees to the
rating agencies.
• Some credit rating agencies have made errors of judgement in rating some structured products,
particularly in assigning AAA ratings to structured debt, which in a large number of cases has
subsequently been downgraded or defaulted. As part of the Sarbanes-Oxley Act of 2002, the US
Securities Exchange Commission (SEC) was required to produce a report detailing how credit
ratings are used in US regulation and the policy issues this use raises.
Please see Chapter 8 for more details regarding the Sarbanes-Oxley Act of 2002.
20 Operational Risk
Other Major Risks Chapter Two
Modern tools concentrate on measuring the credit risk of a portfolio through the use of mathematical
modelling techniques. These use statistical computer programs that attempt to simulate the complexity
of the real world to measure the probability of default (PD) and calculate the loss, given default
(LGD) from a range of complex potential scenarios. From these calculations, a value-at-risk (VaR)
estimate can be made which makes an estimate of the maximum loss that can occur in a given period of
time. (VaR is explained in more detail in Chapter 7.)
These tools are commercially available to help companies gain an overall view of credit risk across
their entire organisation and product spectrum and have become powerful aids in measuring the credit
exposure of portfolios.
Although they represent significant advances in aiding credit risk management at the portfolio level,
their accuracy generally depends on good quality historical data. If the quality of this data is poor then
confidence in the model’s output is degraded. The quality of data is affected by issues such as:
• The simple lack of availability of data, for instance, for emerging markets.
• Significant economic or political changes in a country, making historical data irrelevant or misleading.
For example, a change in political ideology or the discovery of large reserves of natural resources.
• Major market movements making historical data irrelevant or misleading. For example, the
liberalisation of financial markets in the early 1980s ‘changed the rules’ for the future and disrupted
the established trends.
Although the science of measuring credit risk using modern measurement techniques and tools has
been developing rapidly in recent years, there are some common assumptions used by both firms
and regulators that can introduce inaccuracies into the risk models and produce inaccurate credit risk
calculations.
• Using simplified calculations of potential exposure. Generally, the potential exposure of a portfolio
is greater than the current exposure. Institutions may apply charges to account for potential
exposure based on broad categories that oversimplify the different levels of risk. These charges
are stated as percentages of notional amounts but notionals are not always true measures of the
underlying credit risks.
Operational Risk 21
Other Major Risks Chapter Two
• Assuming that some exposures have equal credit risk when the reality is that they do not. For
instance, due to the simple rules applied in the Basel Committee’s original guidelines on capital
adequacy, the risks associated with Korean and German banks were treated as equivalent. The
latest capital adequacy proposal from the Basel Committee relates a firm’s capital more closely to
its true risk.
Note: The Basel Committee is a committee of the Bank for International Settlements, which was
established at the end of 1974, comprising members from Belgium, Canada, France, Germany, Italy,
Japan, Luxembourg, the Netherlands, Spain, Sweden, Switzerland, the United Kingdom and the
United States. Countries are represented by their central bank and also by the authority with formal
responsibility for the prudential supervision of banking business where this is not the central bank.
• The Committee formulates broad supervisory standards and guidelines and recommends
statements of best practice in the expectation that individual authorities will take steps to
implement them through detailed arrangements – statutory or otherwise – which are best suited to
their own national systems.
• A lack of recognition of the time period of credit risk. Default risk increases as the time of exposure
increases. This is sometimes not accounted for.
• A lack of recognition of portfolio diversification. Overall credit risk is significantly reduced by
diversification but measurement calculations may not take this into account.
The board of directors should have ultimate responsibility for approving and, at least annually,
reviewing the credit risk strategy and major credit risk policies of the institution. It should then be the
responsibility of the senior management to implement this credit risk strategy.
Mitigating credit risk involves the use of a range of techniques that aim to maintain a firm’s credit
exposure within acceptable parameters. These techniques operate at both the individual level and
portfolio level.
22 Operational Risk
Other Major Risks Chapter Two
• underwriting standards;
• credit limits;
• netting;
• collateral.
Operational Risk 23
Other Major Risks Chapter Two
3.1.3 Netting
LEARNING OBJECTIVES
2.3.4 Be able to calculate a simple example of a cash netting agreement
Netting is the practice whereby two parties that exchange multiple cash flows during a given day agree
bilaterally to net those cash flows to one payment per currency, thereby reducing settlement risk. It
also reduces transaction costs and communication expenses.
Party A
£2m £3m
£4m £1m
£3m
Party C Party B
£6m
The diagram above shows the end-of-day commitments between parties A, B and C.
No netting agreement is in place. If, for instance, party C defaulted on its commitments,
the replacement costs would be £4 million for party A and £6 million for party B.
Party A
£2m £2m
£3m
Party C Party B
The diagram above shows the same commitments but this time a netting agreement
exists between each party. The cash flows shown above reflect the net obligation
between each party. Now if party C defaults, the replacements costs would be only £2
million for party A and £3 million for party B.
24 Operational Risk
Other Major Risks Chapter Two
3.1.4 Collateral
Collateral is an asset held by a lender on behalf of an obligor, under certain agreed conditions,
as security for a loan. It generally takes the form of cash or securities and is used by the lender as
insurance against default. In the event that the obligor defaults, the lender may seize the collateral.
Collateralisation is, therefore, used as a means of reducing credit exposure to a counterparty.
Collateral is used to mitigate credit risk for a variety of transactions such as foreign exchange forwards,
securities lending and derivatives.
• A unilateral arrangement means that one party gives collateral to the other.
• A bilateral arrangement allows for two-sided obligations, such as a swap or foreign exchange
forward. In this situation, both parties may post collateral for the value of their total obligation
to the other.
• A netted arrangement means that the net obligation may be collateralised so that, at any point
in time, the party who is the net obligor posts collateral for just the value of the net obligation.
In a typical arrangement, the collateral is periodically marked-to-market (ie, its present value
is calculated using current market prices/rates), and the amount adjusted to reflect changes in
value. The obligor has to supply additional collateral when the market value has risen, or removes
collateral when it has fallen. An example of this is the use of variation margin in exchange-traded
derivatives markets, when collateral (or margin) calls (demands) are made by the exchange, clearing
house or clearing broker on a daily basis to reflect changes in the market value of the trades.
Portfolio management is concerned with optimising market and credit risk inherent in the portfolio
components to maximise returns. Some of the common techniques for mitigating credit risk within a
portfolio are:
• diversification;
• asset securitisation;
• loan sales;
• credit derivatives.
3.2.1 Diversification
Diversification is a means of offsetting risk in a portfolio by spreading it across borrowers in different,
negative correlating industry sectors (ie, industry sectors that have an inverse or opposite relationship to
each other). By doing this, institutions avoid unacceptable concentrations of credit risk.
Operational Risk 25
Other Major Risks Chapter Two
Hence, the earnings of some loans in a portfolio will offset the losses of others, making it less likely that
the institution will lose money overall. By this principle of combining individual loans into a portfolio, it
is possible to reduce overall credit risk.
AN EXAMPLE OF DIVERSIFICATION
An investor is seeking to invest in a British sun cream retail outlet. However, they are concerned
about the seasonal nature of the business and the unpredictability of the weather. In order to reduce
the dependence on one company, they decide to diversify their portfolio and achieve this by investing
in a shop specialising in umbrellas.
The sun cream shop does well on sunny days, while the umbrella shop does well on rainy days.
Although the earnings of each individual business can be volatile, the combined earnings will be less so
because of the inverse relationship, or negative correlation between their earnings.
• mitigate their credit risk more effectively and improve their portfolio diversification by reducing
undesirable credit risk concentrations;
• customise their credit exposure to another party without having a direct relationship with them;
• transfer credit risk without adversely affecting the customer relationship.
Over the last decade these instruments have probably been the most important innovation in the
mitigation of credit risk. However, they can also expose the user to other types of financial risks and
regulatory costs.
Like other OTC products, they are privately negotiated financial contracts. These contracts expose
the user to operational risk, counterparty risk, liquidity risk and legal risk. Controlling these risks is an
essential factor in the future development of this market.
26 Operational Risk
Other Major Risks Chapter Two
A credit default swap (CDS) is a bilateral financial contract in which one counterparty (the
protection buyer) pays a periodic or one-off fee (typically expressed in basis points on
the notional amount) in return for a contingent payment by the other counterparty (the
protection seller) following a credit event of a reference entity. A credit event is commonly
defined as ‘bankruptcy, insolvency, receivership, material adverse restructuring of debt or
failure to meet payment obligations when due’.
Regular or
one-off fee Bonds
Institution Customer
Institution
B C
A
Default Loan
amount
In the diagram above, institution B purchases bonds (the reference asset) from customer C
(the reference entity). B then enters into a credit default swap with institution A, whereby B
pays A a fixed periodic coupon or one-off fee for the life of the swap. In return, if customer
C defaults due to a credit event, A pays B the default amount and the swap then terminates.
This provides B with protection against the possibility of C defaulting on its payments, as A
assumes the credit risk.
Bank A is using the CDS to hedge. By buying a CDS, Bank A can manage its credit exposure and
maintain its relationship with the client. Any payout from Bank B will be triggered by prespecified
credit events and will typically be based on the fall in the value of the loan as a result of the event, for
example, the actual default or a credit-rating downgrade by an external credit rating agency.
Operational Risk 27
Other Major Risks Chapter Two
EXTRACT
A letter to CEOs of Regulated Firms from the FSA in February 2005
‘Outstanding Confirmations
Various studies on credit derivatives have clearly illustrated the benefits of credit derivatives and
commented on emerging good practice in individual firms and cross-industry initiatives. However, we
believe that more can be done to reduce operational and settlement risks. The difficulties of back-
office functions keeping pace with the rapidly developing front office trading activity were highlighted
during the Joint Forum’s investigation and the FSA’s soundings of firms confirmed this.
Specifically we are concerned about the level of unsigned confirmations with some transactions
remaining unconfirmed for months. Although we recognise that work undertaken in 2004 is helping
reduce the backlog, levels of unsigned confirmations and master agreements remain relatively high
and raise serious issues for market efficiency and market confidence.
We ask you to consider your firm’s operational processes and risk management frameworks – and the
resourcing of these in relation to credit derivatives – to assess their robustness in this rapidly evolving
market. Confirmations and other documentation should be issued and affirmed promptly after the
transaction has been agreed.’
For example, rather than two members of an exchange being involved in a direct
counterparty-to-counterparty contract (and so assuming each other’s credit risk), the clearing house
acts as the central counterparty to each. If one clearing member defaults, the clearing house will
guarantee the performance of the contract to the other member.
In order for clearing houses to be credible in their ability to reduce credit risk, they need to have
significant resources to cope with potential major market default events and scenarios. They obtain
these resources in a variety of ways, such as capital supplied by:
• their members;
• the exchange; or
• other parties that do not have a direct relationship with the economics of their market.
28 Operational Risk
Other Major Risks Chapter Two
For instance, [Link] Ltd (LCH) has a series of sources providing financial backing. The major
tranche of this support, which is next in line after clearing member initial margin cover held, is the
Member Default Fund to which every clearing member contributes in cash (interest bearing) according
to the volume of its clearing activities. This is reviewed and adjusted every three months. In March 2005
this fund stood at £582 million. The fund is fully fungible across the business streams of [Link].
Hence, for example, a member default occurring in swaps clearing is supported by funds provided by
those firms involved in futures or equity clearing.
The next level of support is provided by an insurance policy from a triple A rated American insurer.
[Link] is contemplating the removal of this category at the time of writing but has encountered
a great deal of resistance to this proposal from its member firms.
Because the clearing house takes on the credit risk of all trades, it must manage the risk effectively. This
is done through stringent membership requirements, continuously reviewing existing members and
employing position monitoring and margining.
• Position monitoring is the analysis of an individual member’s exposure risk in relation to their ability
to cover their margin liabilities and delivery obligations. This is performed on an intra-day basis.
• Margining refers to the practice of evaluating the risk to the clearing house of a member’s position
and making collateral calls to insure against the risk of the member’s default (explained previously
in Section 3.1.4). Two types of margin are taken into account by the clearing house when calling for
margin at the start of the day’s trading:
• Initial margin, which reflects the worst-case scenario of a one-day price move on all registered
open positions.
• Variation margin, based upon a mark-to-market calculation at the previous day’s closing prices,
which reflects the profit or loss on all registered open positions.
The credit risk management function is responsible for ensuring that the firm’s credit risk is
satisfactorily managed. This means implementing a sound risk management policy to manage credit risk
in a firm-wide context. This includes:
• performing adequate credit analysis by counterparty, country and sector (this includes the
performance of regulatory know your customer checks as well as assessing creditworthiness);
• ensuring decisions on granting credit are made independent of the trading areas; and
• integrating the credit risk policy with the firm’s general business strategy.
Operational Risk 29
Other Major Risks Chapter Two
Although the information provided by external rating agencies can be useful, it is of limited value to the
needs of a sophisticated credit risk management function. This is because it is often too historic, not
detailed enough to meet the firm’s requirements fully and is not as sensitive to changes as the firm’s
own analysis. As well as performing detailed credit analysis, the responsibilities of this function will
include:
5. MARKET RISK
LEARNING OBJECTIVES
2.4.1 Know the basic features of market risk: price level risk; volatility risk;
liquidity risk; basis risk
2.4.2 Be able to apply the basic features of market risk to simple, practical
situations
5.1 INTRODUCTION
One of the major aims of many financial institutions is to make profit by investing in the global financial
markets. This business, by its nature, is based on price uncertainty – the uncertainty of knowing
whether market prices will move in a favourable or adverse direction. Price uncertainty is the
mechanism that allows profit or losses to be made and the risk of loss associated with it is known as
market risk. This risk reflects the uncertainty of an asset’s future price. The factors affecting market risk
are complex. For instance, when investing in a company’s shares there are direct and indirect market
risk factors to consider:
• Direct factors are those that directly reflect the performance of a company, such as the health of
its balance sheet, its vision, the energy and strength of its management team and its policy.
• Indirect factors are those that indirectly affect the performance of a company, such as interest
rate levels, economic events, political and environmental effects. The financial services industry
takes advantage of the existence of market risk to make profit. The aim of managing this risk is
not to eradicate it but to understand it and quantify it. If this is done accurately, then an informed
decision can be made on how acceptable the risk is compared to the firm’s strategic risk
appetite, and whether this investment is worthwhile. The crucial aspect, as with all forms of risk
management, is the confidence in the accuracy of the estimate of the size of risk. As there are vast
profits to be made in getting this right, financial institutions have invested heavily in research, tools
and expertise to try to predict the future performance of their investments.
30 Operational Risk
Other Major Risks Chapter Two
The need to understand this market risk is also important in the pricing of some financial products,
such as futures and options. For these reasons, the methods and tools employed for measuring market
risk have become very advanced, involving cutting-edge mathematical theory and computer processing
technology. This chapter provides a basic understanding of these methods and tools and explains how
they fit into an overall risk management strategy.
5.2 DEFINITION
Market risk can be defined as: ‘The risk of loss of earnings or capital arising from changes in the value of
financial instruments.’ In simple terms, an investor is exposed to market risk as soon as they purchase a
financial product and the value of that product goes down. It is intrinsic in all markets and all products,
such as:
• Price level risk - this is due to the potential for adverse changes in the price of a financial
instrument and includes:
• FX rate or currency risk - this exists due to adverse movements in exchange rates. It affects
any portfolio with cash flows denominated in a currency other than the base currency of the
business.
• Interest rate risk - this exists due to adverse movements in interest rates and will affect fixed
income securities, futures, options and forwards.
• Equity price risk - this exists due to adverse movements in share prices affecting a portfolio.
• Commodity price risk - this is the risk of an adverse price movement in the value of a
commodity.
• Volatility risk - this is the risk of price movements that are more uncertain than usual affecting the
pricing of products. All priced instruments suffer from this form of volatility. This particularly affects
options pricing because if the market is volatile then the pricing of an option is more difficult and
options will become more expensive.
• Liquidity risk - this is the risk of loss through not being able to trade in a market or obtain a price
on a desired product when required. This can occur in a market due to either a lack of supply or
demand or a shortage of market makers. Liquidity risk can also refer to the liquidity of a specific
firm, meaning the risk that it may not be able to meet its obligations when they are due. Loss in this
case can be incurred due to the cost of borrowing or facing contractual penalties and may ultimately
result in insolvency.
Operational Risk 31
Other Major Risks Chapter Two
• Basis risk - this occurs when one kind of risk exposure is offset with another exposure in
an instrument that behaves in a similar, but not identical, manner (ie, hedged). It reflects the
uncertainty of the difference in the impact of the market factors on the prices of the two
instruments. An example of basis risk is the risk when the price of a futures contract varies from
the price of the underlying cash instrument as the expiry date approaches. Measurement of market
risk involves advanced statistical and probability theory and analysis techniques. However, most
conventional methods rely on basic principles, such as distribution analysis.
Number
of events
1 SD
2 SDs
Mean
1.20 1.50 1.70 1.90 Height
2.10
The curve shows how people’s height varies in a particular population. The mean, or
average, height is assumed to be 1.7 metres, so most people in the population will fall in a
band around this value. A few people are very tall and a few very short. Using this curve
we can make a prediction on how high the next person to be measured will be or what
percentage of people are above or below a certain height. Many other natural events, such
as people’s intelligence (IQ), or a country’s temperature, can be described by this type of
distribution.
32 Operational Risk
Other Major Risks Chapter Two
• It is continuous. This means that each point on the curve has a real value.
• It is symmetric about its mean (a measure of central value).
• It is defined by its mean and its standard deviation (a measure of dispersion):
• The mean is a measure of the average value of some data, calculated by dividing the sum of all
the values (eg, heights of people) by the total population (eg, total number of people). Other
measures of central value are the median and the mode. The median is the value such that
exactly half of a population is of a greater quantity. If the population has an odd number of
entries, the median is the middle entry after sorting in increasing order. If the list has an even
number of entries, the median is equal to the sum of the two middle numbers after sorting,
divided by two. The mode is the value that has the greatest frequency of occurrence. For
example, from the following list of numbers: 1, 1, 2, 3, 3, 3, 4, 5, 5, 6 the mean is 3.3; the
median is 3 and the mode is 3.
• The standard deviation (SD) is a means of measuring variability, uncertainty or volatility. It
measures the dispersion from the average or mean value. If, for instance, an equity is highly
volatile, it will have a high standard deviation. In finance, investment returns from primary
instruments (but not derivatives), based on market factors, are often assumed to be normally
distributed. By making this assumption, it is possible to create a model that will predict the
future performance of the instrument to a given probability. This probability is also known as
the confidence level. For example, if the mean, historical price of an instrument was £1, we
would be 50% confident that tomorrow’s price would be more than £1. By using a knowledge
of standard deviation we could also calculate what the price would be that would ensure we
had a 95% confidence level that tomorrow’s price would be higher. This means if we bought an
equity, say, at that price, we would be 95% certain that we wouldn’t lose money. This sort of
calculation is useful as a basis for establishing the risk appetite of the firm and limiting loss.
7. VALUE-AT-RISK (VaR)
LEARNING OBJECTIVES
2.6.1 Understand the meaning of VaR and its constituents
2.6.2 Be able to apply VaR to the mitigation of market risk
2.6.3 Understand the meaning of back testing
2.6.4 Understand the meaning of stress testing
2.6.5 Know the limitations of using VaR for market risk management
Operational Risk 33
Other Major Risks Chapter Two
Value-at-risk can be formally defined as: ‘The maximum loss that can occur with a specified confidence
over a specified period.’ For example, if a portfolio’s one-week VaR is stated as £1 million in 99 weeks
out of 100, then the portfolio is predicted to lose less than £1 million over 99 weeks out of 100. This
estimate would be based upon the portfolio’s current composition and recent market conditions, so it
would not account for potential future changes.
Value-at-risk is a category of risk metrics that describes, in terms of probability, the market risk of a
trading portfolio. VaR is widely used by banks, securities firms, commodity and energy traders and
other trading organisations. Such firms could track their portfolios’ market risk by using historical
volatility as a risk metric. They might do so by calculating the historical volatility of their portfolios’
market value over a rolling look-back period of a given number of trading days. The problem with
doing this is that it would provide a retrospective indication of risk. The historical volatility would
illustrate how risky the portfolio had been over the previous period. It would say nothing about how
much market risk the portfolio was presenting today. For institutions to manage risk, they must know
about risks while they are being taken. If a trader fails to hedge a portfolio correctly, his supervisor
and firm needs to find out before a loss is incurred. VaR gives institutions the ability to do this. Unlike
retrospective risk metrics, such as historical volatility, VaR is prospective. It quantifies market risk while
it is being taken. VaR attempts to measure market risk in an integrated manner, theoretically taking into
account all sources of market risk in a portfolio. It can, however, be difficult to calculate in practice.
• Historical simulation - this is the simplest method which uses actual historic returns in the risk
factors to estimate risk exposure in the future. Its advantage is that it is the least controversial,
because it is based on actual data.
• Correlation simulation - this is also known as the variance/co-variance simulation. It calculates the
volatility of each risk factor from historical data and estimates their effect on the portfolio to give an
overall estimate of risk that accounts for all risk factors.
34 Operational Risk
Other Major Risks Chapter Two
The use of stress tests continues to broaden from the exploration of exceptional, but plausible, events
– the traditional focus of stress testing – to cover a much wider range of applications. These include the
exploration of the risk profile of a firm, the allocation of economic capital, the verification of existing
limits, and the evaluation of business risks. The expanded usage of stress testing derives from its wider
acceptance within firms. Aside from its inherent flexibility, it benefits from explicitly linking potential
impacts to specific events. Nonetheless, stress tests continue to focus primarily on traded market
portfolios. These portfolios are well suited to stress testing as they can be marked-to-market on a
regular basis. Stress tests on loan books are conducted less frequently and, quite often, by separate
business units of the firm. Stress testing works as a complement, rather than a supplement, to major
risk management tools such as value-at-risk. It is, therefore, becoming an integral part of the risk
management framework of banks and securities firms.
7.6 LIMITATIONS
Value-at-risk is now recognised as one of the most effective concepts in risk management. However, it
must be closely integrated with the day-to-day market risk management process. Its advantages are:
For areas such as loans and deposits, it is less useful due to the long-term maturities involved. There
are a number of techniques for managing market risk that operate both on the portfolio (micro) and
organisational (macro) levels. To be successful, an integrated approach to market risk must be followed
and an overall risk framework and structure set up. This section describes some of the more common
mitigation techniques and introduces some good practice requirements for an effective framework. The
following mitigation techniques will be explained:
• hedging;
• risk limits;
• diversification.
Operational Risk 35
Other Major Risks Chapter Two
8.1 HEDGING
Hedging is a means of reducing the risk of adverse price movements by taking an offsetting position
in a related product. It is a means of insuring against market risk in the same way that a car is insured
against damage and loss. The main financial instruments used in hedging are derivatives, in particular
futures and options. For instance, an investor may buy an equity and is at risk of losing money if the
market declines. This could be hedged by buying a put option. This option gives the buyer the right
to sell the stock at a set price (the strike price) within a particular time in the future. The investor is
now protected against adverse market movements. The decision to hedge is a trade-off between the
risk of adverse movement and the cost of the hedge – in this case the purchase price of the option. It
is, however, difficult to achieve perfect offsetting of the risk because the use of hedging introduces, or
exacerbates, other risks such as basis risk, credit risk and operational risk.
8.2 DIVERSIFICATION
Diversifying a portfolio is a technique for mitigating market risk that uses the same principles as for
credit risk mitigation described in the previous chapter.
• Risk limits usually have to be inflated in order to accommodate the errors and uncertainty in the
measurement. This adversely affects the potential profit of the firm.
• Traders or other investment professionals may exploit the inaccuracy of risk measurement and take
risks that they know the measurement does not account for. Providing that high-quality risk data
is used, risk limits can be very effective. While investment professionals sometimes see them as
restrictive they can also be viewed as empowering because they set the risk appetite of the firm and
represent explicit authority to take specified levels of risk.
36 Operational Risk
Other Major Risks Chapter Two
Market risk relates to the loss of earnings or capital arising from changes in the value of financial
instruments and is covered more fully in this chapter.
In the same way that institutions employ a credit risk management function to manage credit risk, it is
also essential that they develop and implement an independent market risk management framework
to manage market risk in a firm-wide context and then to make sure that there is adequate reporting.
This also includes implementing a firm-wide policy with clear roles and responsibilities. A good practice
framework for market risk will include:
Operational Risk 37
Other Major Risks Chapter Two
Firms that do not pass the review process are liable to increased capital requirements. In order to
introduce these measures, the Basel Accord of 1988 was amended in 1996 to respond to the industry’s
request to allow banks to use proprietary in-house models for measuring market risks as an alternative
to a standardised measurement framework, as had been originally put forward in April 1993. In order
to ensure a minimum degree of prudence, transparency and consistency of capital requirements across
banks, the Basel Committee proposed a number of quantitative and qualitative criteria for those banks
which wish to use proprietary models. The committee made decisions following comments received
on their proposals and defined the quantitative criteria that would then govern the use of proprietary
models for determining capital charges. These required that VaR be computed daily, using a 99th
percentile, single confidence interval; that a minimum price shock equivalent to 10 trading days (holding
period) be used; and that the model should incorporate a minimum historical observation period of 250
days. The capital charge for a bank that used a proprietary model would be the higher of:
There is an updated set of regulatory requirements for insurance firms that operate in the EU, called
Solvency II. These rules are very similar to the Basel II rules that apply to banks.
38 Operational Risk
Other Major Risks Chapter Two
11.1 INTRODUCTION
Liquidity risk is the risk that an institution will not be able to meet its liabilities as they become due
because of an inability to liquidate assets or obtain enough funding or that it cannot easily unwind or
offset specific exposures without significantly lowering market prices because of inadequate market
depth or market disruptions.
A method of helping improve liquidity for an organisation is to invest in a range of securities that have
varying maturity dates, also referred to as a maturity ladder. This ensures regular cash flows in terms
of both income and capital maturing. These cash flows can be matched against the liabilities of the firm,
ensuring that the cash to be received is greater than the liabilities due.
Some cash receipts from investments will be contractual ie a pre-determined fixed amount of income
will be received on a set date. Other cash receipts may be actual ie will be linked to the performance
level of a suitable index. Firms will need to balance the types of cash being received in order to meet
future liabilities as they fall due.
Asset liquidity risk is when an asset cannot be sold due to lack of liquidity in the market – essentially a
sub-set of market risk. This can be accounted for by:
Funding liquidity risk is when liabilities cannot be met when they fall due or can only be met at an
uneconomic price or can be name-specific or systemic.
Operational Risk 39
Other Major Risks Chapter Two
In September 2007, Northern Rock suffered from the crystallisation of liquidity risk due to the sub-
prime crisis. The bank was over-exposed to the sub-prime mortgage sector and suffered from short-
term liquidity issues despite being solvent at the time. The UK government gave huge amounts of
financial assistance to provide sufficient levels of liquidity to Northern Rock. The bank in this case was
unable to meet its various liabilities with the assets that it had available. In response the FSA now places
greater supervisory focus on liquidity risk especially with regard to high-impact retail firms.
Some institutions may wish to borrow funds on a long-term basis, therefore committing themselves
to a regular repayment of capital and interest on the borrowing. This regular payment may fluctuate
if the interest rate being charged is variable or it may be fixed at the outset. The institution may also
wish to lend out monies to clients on a short-term basis. Hopefully, the interest payments received
on the short-term loans will be greater than those paid out on the long-term borrowing, therefore
representing profit to the organisation. However, if some of the clients borrowing on a short-term
basis default on their repayments, the institution may not have the available cash to meet the regular
repayments on its long-term borrowing. This causes liquidity issues for the organisation.
The main risk associated with stock lending and borrowing relates to when a party to the transaction
defaults on their obligations. For example the collateral given in return for the stock may not be of
sufficient value to cover the lending or may not actually be handed over at all. This means that the stock
lending institution is exposed to the full amount of the stock lent.
40 Operational Risk
Other Major Risks Chapter Two
Banks will use a range of funding instruments to ensure that they do not have liquidity issues. Banks
will typically invest in securities that have a range of maturities; short, medium and long and also yields
or returns. They will balance their ongoing liabilities with the maturity profiles of their investments to
ensure liquidity. For example, banks will be large investors in government bonds and corporate bonds
that provide a suitable range of maturities and a certain level of income.
In order to help meet liquidity funding levels, banks will borrow and lend unsecured funds from other
banks in the wholesale money markets. In the UK the interbank interest rates for borrowing are linked
to the London Interbank Offered Rate (LIBOR). This rate fluctuates daily and is calculated by Thomson
Reuters. Money market instruments include Treasury Bills and Certificates of Deposit (CDs). CDs are
issued with maturities typically between one day and one year. A bank will borrow funds on a
short-term basis from another bank using CDs and after a pre-agreed period of time will repay the
capital borrowed together with a pre-agreed amount of interest.
If a bank is experiencing financial difficulties or has taken on too much risk and is near to collapse it may
approach a reserve financial institution that secures banks or eligible institutions, as a last resort. This
will usually be the central bank of a country, known as the lender of last resort, for example, the Bank
of England in the UK.
Operational Risk 41
Other Major Risks Chapter Two
12.1.3 Immediacy
This refers to the time needed to successfully trade a certain amount of an asset at a prescribed cost.
12.1.4 Resilience
This is the speed with which prices return to former levels after a large transaction. Unlike the other
measures, resilience can only be determined over a period of time.
42 Operational Risk
Other Major Risks Chapter Two
Financial firms can meet their liquidity needs through several sources, ranging from existing assets to
debt obligations and equity. The most readily available is operating cash flows arising from interest and
principal payments from existing assets, service fees, and the receipt of funds from various transactions.
For example, active management of the timing and maturity of firms’ asset and liability cash flows
can enhance liquidity. In addition, firms may sell assets that are near-term cash equivalents, such as
government securities. This is typically done on a contingency basis to meet unexpected cash needs,
and such liquidity reserves must be actively managed, since the assets must be unencumbered (that
is, not pledged as collateral for any other transaction) and easy to liquidate under potentially adverse
market conditions.
Operational Risk 43
Other Major Risks Chapter Two
44 Operational Risk
Other Major Risks Chapter Two
2. What is the difference between pre-settlement and settlement risk? Section 1.3
3. What is the difference between credit exposure and credit risk premium? Sections 2.1
& 2.2
7. What are four assumptions that can produce inaccurate credit risk calculations? Section 2.5
8. What are the five techniques used for mitigating individual credit risk? Section 3.1
A owes B £2m
B owes C £7m
C owes D £3m
D owes A £1m
B owes D £2m
A owes D £4m
D owes C £2m
C owes B £4m
B owes A £5m
D owes B £2m
What is the credit risk exposure for B:
• Without netting? (£8m)
• With netting? (£0m) Section 3.1.3
11. What are the common techniques for managing credit risk within a
portfolio? Section 3.2
Operational Risk 45
Other Major Risks Chapter Two
14. What is the main reason for the existence of a central counterparty (CCP)? Section 3.3
16. What are the four main types of market risk? Section 5.3
17. What are the attributes of a normal distribution (bell) curve? Section 6.1
18. What is the difference between mean, median and mode? Section 6.1
20. What are the two methods of calculating VaR? Section 7.2
22. What are the advantages and disadvantages of using VaR models to
assess market risk? Section 7.6
24. Give three examples of good practice for a market risk management
function. Section 9.1
25. What are the EU standards demanded of a VaR model in order for it to
pass the regulatory review process? Section 10.1
27. Name four ways that asset liquidity risk can be measured. Section 12.1
46 Operational Risk
CHAPTER THREE
Operational Risk 47
The Nature of Operational Risk Chapter Three
48 Operational Risk
The Nature of Operational Risk Chapter Three
1. INTRODUCTION
Over the last decade or so the full impact of the effects of operational risk has begun to be appreciated
in the financial services industry. This is mainly due to the increase in recent years of major loss events
that have seriously affected corporate profitability and reputation (see Chapter 1). As a result, the
effective management of these risks has become a major priority for senior management, regulators
and customers. This change in thinking in the industry has led to the need for a rigorous and structured
approach to understanding, identifying, measuring, mitigating and monitoring operational risk.
This chapter first looks at how the concept of operational risk has been developed and driven by the
international regulators. It then introduces cultural and leadership issues to highlight the importance of
developing a favourable environment for risk management.
Next, a generic, practical framework for managing operational risk is explained. Finally, the ‘chain of
events’ is introduced. This describes the root causes of risk and their knock-on events that lead to the
ultimate effect of financial loss to the firm. This chain of events is shown in Figure 3.1.
1.1 DEFINITION
LEARNING OBJECTIVES
3.1.1 Know the basic Bank for International Settlements’ definition of
operational risk
The Bank for International Settlements (BIS) defines operational risk as:
“The risk of loss resulting from inadequate or failed internal processes, people and systems or from external
events.”
In practical terms this may involve the risk of things going wrong with the day-to-day processing
activities of the firm, which then result in loss.
The Bank for International Settlements is referred to further in Chapter 8 of this workbook.
Operational Risk 49
The Nature of Operational Risk Chapter Three
Basel II incorporated, for the first time, a detailed categorisation of operational risk, including credit and
market risk and, in particular, it provided a breakdown of the specific risk categories that give rise to
operational risk exposure. These categories are as follows:
• Internal fraud – examples include employee theft or insider trading on an employee’s own
account.
• External fraud – examples include robbery, forgery, computer hacking and denial of service
attacks.
• Employment practices and workplace safety – examples include violation of employee health
and safety rules and discrimination claims.
• Clients, products and business practices – examples include misuse of confidential information
and money laundering.
• Damage to physical assets – examples include loss or damage to physical assets from natural
disasters or man-made events such as terrorism, war, arson or vandalism.
• Business disruption and system failures – examples include hardware, software and
telecommunications outages, utility failure and problems with real estate facilities.
• Execution, delivery and process management – examples include unapproved access to client
accounts and outsourcing vendor disruptions or failures.
Please note that these risk categories are banking focused and, as such, other types of financial
institutions may find it difficult to solely use this list to provide them with meaningful risk analysis.
2. CORPORATE CULTURE
Culture can be loosely defined as ‘the way we do things around here’. While it reflects the collective
beliefs and traditions of the workforce, it is strongly influenced by a firm’s leadership. This is because
people naturally take their lead from their superiors. For instance, if senior managers are seen to have
an appetite to take risks, then they will most likely attract individuals who like to take risks, so that the
culture will also be one of risk-taking.
Firms will also aim to have high levels of governance in place in order to operate efficiently and
effectively. All relevant staff need to be aware of the firm’s attitude to governance and must be fully
trained in how this governance is being implemented by their firm.
50 Operational Risk
The Nature of Operational Risk Chapter Three
If risk consciousness is not part of the culture then the culture needs to be changed. This can be difficult
because it is a reflection of the people that make it up. People tend not to be entirely rational in their
thought processes and actions, as the less tangible effects of emotion, habits, principles, ethos and ego
all play a part in their decision-making. As a result, there can be a resistance to change.
Operational risk due to cultural issues has a large intangible element to it. The cause-effect relationship
is often not obvious, which makes managing it more of a perceptual issue than a logical one. Some of
the main issues that impact the risk culture are:
2.3 LEADERSHIP
One of the key roles of senior management is to position a firm’s culture so that it best supports the
business objectives. This can also be seen as adapting the strategy and objectives of the organisation
to best fit the prevailing culture. Either view requires senior managers to be effective leaders and to
understand how leadership can affect a firm’s operational risk and prevailing culture.
Leadership is viewed as one of the most significant drivers of culture. How organisational leaders
behave and interact with employees is critical in the fostering of a favourable risk culture. Research has
shown that leadership is as much a skill as it is a personality trait and, as such, styles can be adapted to
meet the demands of a particular situation. Effective leaders will deliberately alter their style depending
on the situation. This requires both a sensitivity to the requirements of the business (and its culture)
and an understanding of their own leadership abilities.
If the risk environment is relatively stable and predictable, and there is a well-established,
risk-aware culture, then one style of leadership is appropriate. If, however, there is a high pace of
change, and an immature risk environment, another style is appropriate.
Leaders, therefore, need to be aware of their organisation’s position and what strategies they must
adopt to create the most effective environment.
Operational Risk 51
The Nature of Operational Risk Chapter Three
Good risk processes and planning are worth nothing without the commitment and energy of a
motivated, effective workforce. Equally, weaknesses in risk processes and systems can be offset by
vigilant, expert staff. So the need for a robust culture in the effective management of operational risk
cannot be overstated. Creating, instilling and communicating this culture is, as has been explained,
largely the role of senior management and the leadership levels of a firm. The firms risk officers play
a significant part in continuing a robust risk and control culture. As well as appropriate and adaptive
leadership a robust risk culture will depend on the ability of the organisation to develop positive
attributes in the following areas:
52 Operational Risk
The Nature of Operational Risk Chapter Three
2.5.2 Motivation
Motivation is a psychological phenomenon that relates to the amount of effort, care and commitment
that people put into a task. People’s levels of motivation are recognised as being a key factor in
improving their performance. Examples of factors that motivate people are the interest, challenge
and rewards of their job. Also incentive schemes and compensation initiatives help to keep staff
motivated. Motivation also depends on limiting the negative effect of ‘hygiene factors’ such as poor pay,
working conditions and management style. If jobs and careers can be designed to unlock an individual’s
motivation, a more positive risk culture will result and organisational performance will be enhanced.
2.5.3 Morale
Excellent morale is related to how positively staff view their organisation, working conditions, outlook
and leaders. It is linked closely to motivation and commitment.
2.5.4 Integrity
Firms need staff with high integrity who have pride in their performance, are professional in their
approach and demonstrate high levels of honesty. A lack of integrity (perceived or otherwise) can cause
significant damage to a firm’s reputation. The quality of integrity is instilled into the culture through the
words and actions of its leaders and senior managers.
Operational Risk 53
The Nature of Operational Risk Chapter Three
2.5.9 Expertise
The technical ability and experience of staff is a major factor in perceiving and anticipating risks. High
quality staff with high levels of expertise provide confidence that business is being conducted to high
standards.
The operational risk policy is the document which outlines a firm’s strategy, methodology and
objectives for operational risk management. It is also where the boundary between other risk areas,
such as market and credit risk, is clarified. In order to meet the prime objectives of operational risk
management the risk policy should address the following areas:
• sponsorship;
• identification of key officers;
• roles and responsibilities;
• definition and communication of the risk management framework and explicitly the firm’s risk
methodology;
• cross-divisional involvement and agreement;
• consistency of approach firm-wide;
• co-ordination;
• segregation of duties.
3.1 SPONSORSHIP
The policy and approach should be agreed and sponsored at board level. As it is firm-wide and often
requires significant cultural change, it must have the full and continued support of senior management if
it is to succeed.
54 Operational Risk
The Nature of Operational Risk Chapter Three
Key risk officers may also be designated from within the business itself. If ownership of operational
risk issues is assigned to the department or business process where they originate, then the relevant
line manager will often be made responsible for risk management. For this reason, managers may
have direct reporting lines through their own business lines and dotted lines into the risk management
function.
Collaboration with other risk management disciplines is becoming ever more important as
understanding of the inter relationship of financial risk increases.
Operational Risk 55
The Nature of Operational Risk Chapter Three
• employing a methodology that identifies and categorises all the operational risks that exist in the
organisation;
• employing a methodology for measuring and assessing the significance of all the identified risks;
• working with line managers to agree the mitigating action required to reduce the risk exposure to
acceptable levels;
• monitoring the effects of the mitigating action to ensure its success;
• reporting and escalating risk issues to all appropriate levels of the organisation. This ensures that
there is transparency and aids the decision-making process.
In practice, the framework described is rarely fixed and standardised immediately. It is more
evolutionary to begin with, and its maturity will reflect the maturity of the organisation with respect to
operational risk management.
The process of developing the approach is therefore cyclical and continuous and can result in
refinements to the risk policy.
The strategy should be consistent throughout the firm. A common operational policy and terminology,
which exists globally and across all functions, allows:
3.7 CO-ORDINATION
Again, because the risk policy takes a firm-wide approach and cuts across departmental boundaries,
there should be a central, independent risk management role responsible for the co-ordination and
implementation of risk policies and procedures. Depending on the size and type of organisation, this
role may be set up as an independent department. Most large organisations have now developed an
independent operational risk management function that reports into an overall group risk officer.
56 Operational Risk
The Nature of Operational Risk Chapter Three
Risk management as described in Chapter 1: Risk management tries to ensure that the likelihood of
risks being realised and the potential impact is reduced to acceptable levels.
This means exploiting the business opportunities that risk-taking provides (or the upside) whenever
possible, while at the same time managing the potential loss (or the downside).
Operational Risk 57
The Nature of Operational Risk Chapter Three
The main focus within the financial services industry is managing the downside, or the potential loss,
due to operational risk. Practically, the operational risk management function has two key aims:
1. assisting with the effective identification, measurement, assessment and management of operational
risk; and
2. assisting with the reduction or mitigation of the potential impact should the risk occur.
Once the high level risk policy has been agreed, a risk management process must be implemented to
enable the risk management function to achieve its aims. Figure 3.2 describes a typical process, which
includes the following stages:
The following sections explain each stage and how they interrelate.
Risk Risk
Identification Measurement
and Assessment
Operational
Risk Policy and
Appetite Risk Mitigation
RISK
MANAGEMENT
Risk
Monitoring
Risk
Reporting
58 Operational Risk
The Nature of Operational Risk Chapter Three
Inherent risks are those risks that are impossible to manage or transfer away and relate to the
probability of loss arising out of circumstances or existing in an environment. Residual risk relates to the
exposure to loss remaining after other known risks have been countered, factored in and eliminated.
Residual risk is a product of inherent risk and control risk (ie, the risk that all the controls that the firm
has in place, will not prevent, detect or correct errors) and represents the risks that will always be
present.
5. RISK IDENTIFICATION
LEARNING OBJECTIVES
3.5.1 Understand the purpose of identifying risks
• provide information to management on which to make decisions and take action to ensure a
controlled environment;
• establish the chain of events relationship of operational risk described in Section 1 (Introduction)
and understand where they occur throughout the firm;
• provide a basis for risk measurement and assessment which may, for example, be used for capital
allocation purposes;
• set boundaries to differentiate between operational risk and other risk types (such as market and
credit) and assign ownership for their mitigation;
• develop a common language for discussing, assessing and managing risk that allows clear and
transparent communication and decision-making.
When identifying risks, a firm needs to consider not only its own processes and systems, but also its
relationships with its clients, the nature of its products and the wider business environment.
Risk identification is the fundamental first step in understanding how operational risk affects the firm,
raising awareness of risk issues and assessing the culture of the organisation.
It can be a difficult exercise due to the diverse nature of risk causes and the difficulty in distinguishing
cause from effect.
Operational Risk 59
The Nature of Operational Risk Chapter Three
Classifying operational risk using common categories is the first step in developing a common risk
language. It also helps to distinguish causes from effects and can be used as a basis for the development
of a risk capture, identification and measurement system.
Different organisations will put a different emphasis on risks and will, therefore, categorise risks in
different ways. It is not important what categories are chosen, providing that they are:
For example, a common method is to categorise by the root causes of process, people, technology and
the environment. This method is summarised in Figure 3.3.
60 Operational Risk
The Nature of Operational Risk Chapter Three
Expertise concentration
Culture
Uncertainty
Labour
There are a variety of methods used for the practical capture and identification of risk. Some of the
more common ones are:
In order to capture the complete risk profile, all of these methods require the involvement and
partnership of risk owners and risk experts. Risk owners include senior management, process and
product heads and the line staff who deal with the risks on a daily basis.
They can be used either individually or in combination and are explained in more detail below.
Operational Risk 61
The Nature of Operational Risk Chapter Three
Risk and control self-assessments can be based on a silo within a team or department, or can
encompass an entire end-to-end process spanning multiple teams.
62 Operational Risk
The Nature of Operational Risk Chapter Three
The biggest practical problems with the risk identification phase are:
• the amount of time required to be invested by managers and staff to ensure the compilation of a
good quality, comprehensive risk profile;
• the type of business carried on by the firm, changes to the business operating model and the
particular environment in which it operates;
• any changes associated with the firm wide engagement arising from new markets, products,
systems and regulation that may hinder the identification of risk;
• although it is perhaps more of a measurement factor (and is addressed again later in this chapter),
the lack of good quality, consistent historical data on operational risk available to a firm both
internally and externally does present a practical limitation;
• the lack of robust policies;
• the methods of collecting and compiling a risk profile;
• difficulties in consistently categorising risk data, and issues relating to consistency generally.
Risk assessment and risk measurement are concerned with understanding the likelihood of risks
occurring and their impact on the business in terms of direct or indirect loss. Once an understanding of
the size of a problem has been gained, appropriate action can be taken to address it. The reasons for
measuring and assessing operational risk are to:
Operational Risk 63
The Nature of Operational Risk Chapter Three
• provide an incentive for risk management and the development of a risk-aware culture. The
development of the right environment and culture cannot be over-emphasised as a key aspect of
managing operational risk. Measuring risk can powerfully demonstrate the impact of operational risk
issues and help to gain the commitment that is essential for driving cultural change;
• improve management decision-making. By knowing the size of risks they face, managers are in a
position to decide how much risk they wish to take;
• satisfy regulators and shareholders that a firm is adopting a proactive and transparent approach to
risk management; and
• make an assessment of the financial risk exposure that can be used for capital allocation purposes.
Risk assessment is closely linked to risk measurement. It delivers an assessment of risk at a point in time
with appropriate controls in place. Measurement is associated with the use of quantitative techniques to
understand the size of risk such as measuring losses, measuring the frequency and impact of risk events
and making statistical predictions. Assessment has more to do with evaluating measurement data and
estimating the impact on the business. It is especially useful for considering those risks which cannot
be actuarially or statistically measured, given the lack of appropriate data. For instance, a firm’s risk
measurement system might record that the front office trading system is 98.5% reliable. Assessment
would make the judgement as to whether this is acceptable for normal business performance. Put
another way, measurement is objective and assessment is subjective. These terms are closely linked
and are often used interchangeably – both address the question: how big is the problem?
Quantifying risk in terms of the precise financial impact it has on the business would be the ideal basis
for decision-making. However, the problem with using financial measures and models is supporting
them with accurate, comprehensive data. The acquisition of this data is the most difficult aspect of
measurement due to operational risk’s complex nature and the fact that much of the data is difficult
to derive automatically from the firm’s systems. Objective measurement is difficult because of the
same practical problems explained in the previous section on risk identification. Objectivity is further
complicated by the multi-dependencies between functional areas and processing activities.
For these reasons it is hard to measure and assess operational risk precisely with confidence, so both
qualitative and quantitative methods are commonly used such as:
64 Operational Risk
The Nature of Operational Risk Chapter Three
From the control perspective, one of the simplest methods of assessing risk is the creation and
application of a rating or ranking hierarchy. This is a method of rating or ranking risks in order of their
importance.
For instance, a firm might decide that the process risk of volume sensitivity is higher than the system
risk of inadequate security, or that a lack of training is worse than the pace of change.
The assessment may be subjective – depending on the experience of the professionals involved, or
objective – being supported by historical data, or both. In either event, the ranking decision depends on
two criteria – the likelihood of the risk being realised and the magnitude of the impact.
• The likelihood of the risk being realised can be represented as a range of probabilities which
correspond to a rating, for example:
Rating
Low = 1% to 5% 2
Medium = 5% to 10% 3
• The magnitude of the impact is the potential loss if the risk is realised. This can be represented as a
monetary range, and also assigned a rating, for example:
Rating
Note: The monetary ranges will change depending on the business area being measured and scale of
the firm’s activities.
Operational Risk 65
The Nature of Operational Risk Chapter Three
An overall risk assessment can be made by multiplying together the likelihood or probability and
magnitude of impact ratings to give a crude score which is effective in prioritising risks:
If there is good quality historical data available, actual percentages of monetary figures can be used.
Each risk can be plotted on a ranking chart to produce a risk profile as shown in Figure 3.4.
Firms will often perform this process for both inherent and residual risks. Inherent risk assessment
considers likelihood without controls in place while residual risk assessment includes consideration
of the control environment. This procedure allows the effectiveness of controls to be evaluated and
provides an analysis of risk based on:
Magnitude (£)
2
Low Risk Medium Risk
1
1 2 3 4 5 Likelihood (%)
A firm which falls into the top right hand box of ‘High Risk’ will, in theory, fail and would, in practice,
not exist for long.
• provides a simple, powerful method for viewing the range of risks the business faces;
• provides an evaluation of the effectiveness of the control environment;
• focuses management attention on the most important risks;
66 Operational Risk
The Nature of Operational Risk Chapter Three
• can be used with minimal hard data so if historical data is not available, useful subjective
measurement can still be performed;
• can capture a wide range of risk possibilities – from large, strategic risks to everyday, more detailed
issues. For this reason it can be effective at all levels of an organisation;
• can be used to anticipate loss by ranking the potential risks of new situations. This means it is
forward looking as well as backward looking. It is, therefore, a useful method if fundamental
industry changes need to be understood, such as the impact on the control environment of new
ways of working, for example, e-commerce or teleworking;
• encourages a risk-aware culture and a more transparent risk environment. In order to maintain
the risk profiles, a culture of continuous assessment is needed. This encourages line staff and risk
managers to work closely and allows good practice to be adopted more easily
• enables a firm to assess its risk exposure against its defined risk appetite.
Its main disadvantages are that it is subjective, and may present an oversimplified view. All subjective
assessments should be validated by:
Risk and control self-assessment (self-certification) can be used for measurement as an extension
of the risk identification and control process. It generally utilises the ranking approach mentioned
previously. Once a list of risks have been compiled, managers make their own assessment of their
exposure to each risk on a regular basis. Self-assessment as a single method of measurement has
limitations because:
• it can be subjective and possibly open to abuse and manipulation by managers. For this reason, it
should be independently validated; and
• it can be difficult to apply consistently across the various business units and multiple locations that
exist within a global financial institution.
Operational Risk 67
The Nature of Operational Risk Chapter Three
Scenario analysis is a subjective method of highlighting potential risk issues in order to allow
preventive action to be taken. It uses the experience of business professionals to capture possible
scenarios that have occurred in the past, or may result in loss in the future. By investigating these
scenarios, preventive measures can be taken to reduce their risk of occurrence. It is broadly concerned
with looking at worst case scenarios.
Its advantages are the same as for ranking, while its main disadvantage is that it depends on the
expertise of the professionals involved. If there are gaps in knowledge or experience, then the scenarios
may lack rigour.
6.2.4 Bottom-Up
LEARNING OBJECTIVES
3.6.7 Understand the bottom-up analysis method of assessing operational
risk
The bottom-up measurement approach seeks to analyse the individual risks and adequacy of
controls across the entire business. It is called ‘bottom-up’ because it builds up a detailed profile
of the risks that occur in each area, aggregating them to provide overall measures of exposure for
departments, divisions or the firm as a whole.
It uses the experience of line managers and staff, coupled with loss data as its source of information (see
Section 6.2.7), so the resultant measures contain both qualitative and quantitative elements.
Compiling bottom-up profiles usually involves a combination of the above three methods to produce a
consolidated understanding of the risk exposure. Much of the data will often be collected during a risk
review.
• it addresses risk and control issues at the process level, thus complementing the role of line
managers;
• accountability and responsibility for risk management can be clearly defined. The owner or manager
of a process is usually made accountable for managing the risks it contains;
• it encourages a risk-aware culture and a more transparent environment;
• it encourages a continuous improvement approach to risk management. As risks are identified and
assessed, mitigation action can be taken immediately if necessary. This means that improvements to
the control environment can be made quickly in the short-term;
• it improves the quality of management information;
• it allows a cross-section of staff to give a balanced view.
68 Operational Risk
The Nature of Operational Risk Chapter Three
• it takes time to implement. The assessment of all operational risks requires a detailed understanding
of how a firm’s processes work and what its weaknesses are. Documenting this can be a lengthy
exercise;
• the continuing maintenance of firm risk profiles is often a major undertaking. This is exacerbated in
a high-change environment where profiles may change continuously;
• it can be influenced by senior managers if not properly managed.
6.2.5 Benchmarking
LEARNING OBJECTIVES
3.6.8 Understand the benchmarking method of measuring operational risk
Benchmarking involves comparing loss data and measures of operational risk with competitors and
other firms in the industry. This allows the firm to establish how effectively they manage risk compared
with their peer group.
• allows the firm to make a judgement on what good is. It sets a standard for the industry based on
the best firm;
• makes operational risk more transparent within the industry.
• its disadvantages are that it:
• is difficult to find suitable data sources that compare like with like;
• may be difficult to verify open and honest reporting of risk measures;
• may create a false sense of security for market leaders. Just because a firm ranks highly in their
industry, does not imply that it manages risk effectively – it merely outperforms its competitors in
the risk areas.
By identifying and assessing the severity of risks and properly understanding the cause of the chain of
events, objective measurement criteria can be chosen to measure ongoing risk status. These measures
are called risk indicators. They are a ‘health check’ on the performance of the business and are used
by all functions to ensure that risk is satisfactorily controlled. They usually measure the effects (rather
than the cause) of risk at set control points in the business and act as early warning signals or
forward-looking measures to alert management to problem areas.
Risk indicators can be thought of in terms of process-related indicators (which tend to relate directly
to performance) and non-process indicators (which incorporate other important measures of control,
especially relating to people).
Operational Risk 69
The Nature of Operational Risk Chapter Three
Levels of acceptable risk can be established by attaching limits, or thresholds of acceptability, to the
indicators. These allow the firm to set its risk appetite and give managers the autonomy to make
business decisions within specified boundaries.
• staff turnover;
• percentage of temporary staff to permanent staff;
• amount of overtime;
• percentage of staff with an agreed training plan;
• period of time to review departmental plans;
• response and resolution times to line problems and audit queries; and
• absenteeism.
• they allow trends to be monitored and can therefore be used to anticipate problems;
• they allow limits of acceptability to be established;
• they provide a basis for objective performance measurement. Performance measurement can
be used to encourage staff to become more risk-aware, especially when performance targets,
expressed in terms of key indicators, are linked to compensation;
• they act as early warning signals to alert management to problem areas.
70 Operational Risk
The Nature of Operational Risk Chapter Three
Case Study – Using Risk Indicators to Measure Operational Risk – Setting Risk
Bands for Cash (Nostro) Breaks
The table below shows how risk bands might be set in practice to assess the risk of
unresolved cash (nostro) breaks. So, for instance:
• risk is considered to be medium if the total number of unresolved breaks is between
5% and 7% of total volumes;
• risk is considered to be medium if the number of breaks that have remained unresolved
for between 8 and 14 days is between 1% and 1.5% of total volumes;
• risk is considered to be medium if the value of unresolved breaks is between £800
million and £2,000 million.
Risk event data evaluation is important in mapping the actual risk events and losses experienced by the
firm back to a sensible categorisation system. Once the data has been collected (from either internal
or external sources) it can then be used in the measurement process, often using benchmarking or
statistical methods.
For instance, a ‘loss distribution’ curve may be created that records the value of all material (direct)
losses in a particular risk category over a time period of, say, three years. By analysing this curve using
similar VaR techniques to those introduced in Chapter 2 on ‘Market Risk’, some prediction of future
losses can be made within specified confidence limits.
Operational Risk 71
The Nature of Operational Risk Chapter Three
A typical loss distribution curve might look like Figure 3.5 below:
Figure 3.5
No. of incidents
Expected Losses
Unexpected Losses
Expected losses are those that occur with reasonable frequency. They represent known weaknesses,
or sit within the risk appetite of the firm. They must be managed by good process controls and an
effective, continuous risk management process.
The unexpected losses are those low-frequency, high-impact events that can create serious problems.
They are much more difficult to manage on a day-to-day level because they don’t occur often enough
to test the control environment. They are best managed using contingency planning.
The advantage of this measurement method is that it allows the firm to understand the size of losses, in
monetary terms, which can be attributed to particular risks.
Its main disadvantage is that it does not predict unexpected losses very well, due to the lack of data.
Some firms also don’t make allowance for ‘near misses’, ie, potential events that might have caused
serious harm but were detected in time – by luck or judgement. As a result, reporting the results of
historical loss analysis in a way that makes decision-making easier can be difficult. It is also worth noting
that often firms do not always include indirect or ‘soft’ costs, as these are not easily identifiable from
the accounting system or general ledger.
72 Operational Risk
The Nature of Operational Risk Chapter Three
7.1 MONITORING
LEARNING OBJECTIVES
3.8.2 Understand the importance of risk monitoring in the risk management
process
The monitoring and reporting cycle allows the risk management process to be continuous. The
monitoring stage comprises the following activities:
• the establishment and firm-wide adoption of appropriate risk parameters such as risk indicators
(explained in Section 6.2.6 of this chapter) to measure the level of risk;
• an ongoing, continuous process of objective measurement against a pre-agreed risk appetite;
• an independent policing of risk parameters by the firm’s risk managers.
Monitoring is, therefore, an important feedback step that ensures that the risk management process is
effective. Effectiveness is dependent on the ability of the firm to retrieve, collate and, when necessary,
accrue the required information in real time.
7.2 REPORTING
LEARNING OBJECTIVES
3.8.3 Understand the main functions of operational risk reporting to
regulators, clients and internal stakeholders
Operational Risk 73
The Nature of Operational Risk Chapter Three
It is necessary to report risk internally (across and up the organisation to internal stakeholders) and
externally (to clients, regulators, auditors and analysts). A firm’s risk policy should also include controls
to ensure that the right reports are received by the right people at the right time.
The Audit and Accounting Faculty of the accounting body ICAEW issued guidance to directors
and reporting accountants of service organisations. This guidance is contained in AAF01/06 and
recommends that an internal control report contains a report by the directors and the reporting
accountants of the firm.
SAS70 is the name of a report on the processing of transactions by service firms, where the professional
standards are set up for a service auditor that audits and assesses the internal controls of the service
firm. The initials SAS stand for Statement on Auditing Standard.
8. RISK MITIGATION
LEARNING OBJECTIVES
3.7.1 Understand the use of operational controls in reducing the impact or
likelihood of operational risk
3.7.3 Know the common methods for operational risk mitigation: risk
control or reduction; business continuity and contingency planning;
outsourcing; information and physical security; risk awareness training;
insurance
Once risks have been identified and measured, the firm is in a position to take effective action to
address them. Mitigation means to make less intense or severe and there are four potential mitigation
methods:
74 Operational Risk
The Nature of Operational Risk Chapter Three
The likelihood of operational risk exposure can be reduced through the use of operational risk
controls and therefore the impact of the risks on the firm, should they occur, can hopefully be
minimised. Operational risk controls are activities that are inserted into a process to protect it against
specific operational risks. Controls do not generally add value to processing in direct terms (ie, by
moving the process forward from one state to another), but they can add value in indirect terms by
protecting against error and consequential loss. Risk awareness training for all relevant staff should be
given by the firm to help staff understand the principle of reducing the likelihood of risk occurring and
details of such training being given and attendance should be recorded.
For instance, a procedural control might be set up to protect against the risk of a member of staff
diverting funds to a personal bank account when making a payment (ie, committing fraud). This
procedure might ensure that one person prepares the documentation to send a payment and another
person physically sends it. This action doesn’t directly make the process any quicker or cheaper (in
fact in might make it slower and more costly) but it is necessary to protect the firm against fraudulent
activity, in order to save money in the longer term. There should be an independent control function
and/or internal system audit trail in place to deter this from happening in practice.
Potential risks should be anticipated and evaluated when the process is first designed and the necessary
controls embedded within it. There are two main types of control – preventive and detective control.
Preventive controls are those that prevent errors occurring in the first place. They attempt to tackle
the root causes of risk and are most effective when incorporated within processes at the outset by
anticipating a risky outcome. Technology solutions are often used as a key means of implementing
preventive controls.
A key preventive control is the segregation of duties. This means the separation of trading, operation
and control, financial reporting and risk management functions. The aim of segregating these functions
is to prevent too much responsibility and authority being concentrated in the hands of specific
individuals. In turn, this prevents the possibility of the internal control structure being compromised and
the risk of fraud arising. The lack of appropriate segregation of duties is one of the major process causes
of operational risk (this was discussed in Sections 2.4 and 3.8).
Operational Risk 75
The Nature of Operational Risk Chapter Three
From the transaction processing perspective, another important area is the maintenance of data
integrity in systems. For instance, the incorrect capture of a transaction’s details in a firm’s systems
due to errors created through manual input. If the process was designed so that the transaction was
captured once at the point of execution and checked and this data then flowed automatically into the
downstream systems, the risk of manual errors would disappear (being replaced by system risks, which
are generally considered to be smaller). This illustrates the benefit of a straight-through processing
(STP) environment.
• the setting up and ongoing maintenance of good procedures to prevent unauthorised actions and
errors;
• the use of training to reduce the likelihood of human error arising from a lack of expertise;
• the use of well-designed systems to automate processes and controls to eliminate risk due to
human error.
Detective controls detect errors once they have occurred. They can be further split into two sub
categories – internal and external detection:
• Internal detection controls detect errors after they have occurred but before a potential loss is
realised in the outside world, ie, they detect the risk event in order to prevent the effect. Checking
and inspection-type activities fall under this category. For instance, checking the legal terms of a
contract before it is signed is a control that may detect errors in the terms and conditions of the
contract. These errors would then be rectified and the contract sent out at no loss to the firm. If
the control did not exist, the potential for legal risk to be realised would increase.
• External detection controls are those that detect errors and losses once they have been realised,
ie, they detect the effects. Post-settlement checks such as statement-to-ledger reconciliations, fall
under this category. If a problem is found, for instance, if a counterparty has not been paid on time,
loss due to a compensation claim for lost interest will occur. If the detective control is effective,
the problem will be resolved quickly and the loss effect limited. External detective controls are
important because they can limit the direct and indirect losses to the firm. External detective
controls are really concerned with reducing the impact of loss, rather than reducing the likelihood
of loss (because the loss has already occurred). This is discussed in the next section.
If a risk does crystallise, there are a number of ways that the resulting loss to the firm can be reduced.
As stated in the previous section, using detective controls is one method. Other strategies are:
76 Operational Risk
The Nature of Operational Risk Chapter Three
• Risk sharing. By collaborating with other firms, or pursuing joint ventures, it is possible to share
any potential operational losses. Risk sharing differs from risk transfer, an explanation of which
appears below.
• Continuity planning, contingency planning and financial mitigators - in the same way that
financial provisioning provides financial continuity, the ability to anticipate and plan for potential
operational crises reduces the harm of unexpected losses. Continuity or contingency planning
may take the form of disaster recovery, succession planning or the production of other fall-back
procedures to deal with potential crises or threats to the continuity operation of the business. Both
business continuity and business availability are important for management to address. Analysis of
any potential disruption is required, ranging from minor mishaps to major catastrophes. Typical
risks that lend themselves to continuity planning are:
• fire;
• system failure;
• power failure;
• earthquake;
• explosion;
• civil unrest;
• strikes;
• adverse weather conditions.
• Good communication and reporting - having high quality, integrated management information
systems allows information to be shared globally and efficiently. This means that if a risk is realised,
the firm is able to react quickly to reduce its impact.
• Limit setting - market and credit risk limits are also relevant management strategies for
operational risk as exceeding limits can be the first sign of operational errors. Limits can be used
in other ways to reduce the impact of risk, such as setting capital limits on major technology
development or using them as ‘early warning’ signals in process controls (eg, risk indicators).
• Business continuity and contingency planning - this includes emergency response, crisis
management and business resumption planning, covering a whole range of scenarios as identified
by the business. Businesses need to understand the underlying risks and the potential impact of
each type of disaster. A contingency plan needs to be drawn up, maintained, tested and checked
regularly. It is also important to consider the magnitude of the risks which could result in these
impacts. This will help determine which scenarios are most likely to occur, and to which ones
resources should be given at the planning stage.
Avoiding risk means either withdrawing from a business because of an unacceptable level of risk, or
deciding not to take on new business, mergers or growth for the same reasons.
Operational Risk 77
The Nature of Operational Risk Chapter Three
• Outsourcing - if a firm understands the amount of operational risk it carries, it may choose to
outsource aspects of its business to a third party with specific expertise in managing certain risk
and who will carry the risk exposure for a fee. This option of risk management is gaining popularity
with financial institutions; however, it is important to remember that a firm only transforms the risk
from, say, direct process risk to managing the quality of the outsourced process. A risk still exists.
On the other hand, some firms also actively take on risk from others, as seen in insourcing business.
• Insurance - for instance:
• covers the event of loss due to fire, theft, risk of non-payment of monies owed, losses when
they occur, loss of profits;
• provides potential balance sheet protection; and
• smoothes income flows for the business.
A firm needs to know, when taking out insurance, what the insurance will pay out for and when it will
pay out.
• Information and physical security - the operational risks associated with information and
physical security can be reduced by firms making adequate and suitable arrangements for
safeguarding them. The level to which this can be done depends on the amount, type and value of
the things that need to be safeguarded.
• Financial reserves - these need to be kept in a form that ensures that they are sufficiently liquid,
so that they can be accessed at short notice and without delay, in any crisis situation.
While risk transfer can be attractive to businesses seeking to reduce their direct financial losses and
capital adequacy costs, it does not address the reputational impact. The indirect costs of operational
losses incurred by an insurer or third party will most likely still have to be borne by the firm. Similarly, a
firm cannot outsource its regulatory responsibilities.
78 Operational Risk
The Nature of Operational Risk Chapter Three
• Data collection and management constraints - in practice, it is very difficult to build a truly
comprehensive data set – apart from the general lack of data, system constraints and a lack
of standardisation mean that the required data feeds from disparate sources cannot be easily
developed. There is also relatively little availability of industry-wide data, as this depends on firms
‘self reporting’ and, by definition, it is not straightforward to gain an understanding of high-impact,
low-frequency events. Firms may also not be allowed to report for legal disclosure reasons.
• Cultural constraints - operational risk managers used to find that building momentum and
demand for operational risk practices across the business was a constant struggle, but this is no
longer the case as firms are capturing data more frequently. Business heads need to be convinced
of the value that operational risk management (ORM) will bring. If not implemented in a well
structured manner it is often seen as a cost to the business, and even a nuisance, rather than a
real asset. Consequently, many firms have rolled out risk management frameworks little by little –
attempting to gain the confidence and support of one area before moving on to another.
• Resource and cost constraints - firms continually underestimate the amount of time and
resources required to implement identification and measurement systems. In an era of tight cost
controls, resource constraints put a limit on how quickly or comprehensively implementation is
carried out.
• Indicator constraints - it can be difficult to design risk indicators that monitor the full range
of risks. There is a natural tendency to use indicators that are already available (such as existing
management information) but these are often designed to monitor performance rather than risk.
The extra cost and time required to design and maintain a truly comprehensive set of risk indicators
is often prohibitive.
Operational Risk 79
The Nature of Operational Risk Chapter Three
This Accord has evolved to satisfy the changing risk landscape and to safeguard institutions’ solvency.
It is primarily aimed at making the capital charge for credit more risk-sensitive, and it also includes a
framework for calculating a capital charge for operational risk. It recognises that the way banks assess
and manage their risk is now far more sophisticated. As a result, financial risk exposure (market, credit
and operational) can be assessed and provisioned for far more accurately. It, therefore, allows:
• a greater emphasis on firms’ internal processes for managing and controlling risk, supervisory
reviews and market discipline;
• a greater flexibility towards risk measurement by presenting a menu of approaches (rather than the
single ‘one size fits all’ measure of the 1988 Accord). This flexibility is reflected in the provision of
incentives for better risk management;
• a greater risk-sensitivity so that capital requirements are more closely aligned to a firm’s risks.
A significant innovation of the revised framework is the greater use of assessments of risk provided by
the banks’ internal systems as inputs to capital calculations.
The new Accord forms the basis for the new EU Capital Requirement Directive (CRD) which provides
the basis for new national ‘rulebooks’ for all firms in the EU. Hence in the UK the FSA implemented
the Basel II Accord via the CRD. Finalised handbook changes appeared towards the end of 2006 with
full implementation (other than for the advanced approaches) from 1 January 2007. The advanced
approaches were implemented from 1 January 2008.
The global implementation of the Basel II Accord began at the end of December 2006 (country
timetables varied), with full international implementation probably continuing well beyond. The new
capital rules will apply to all financial institutions, not just banks.
The process to reach the agreed framework in June 2004 took many turns among the world’s leading
banks and their regulators. Its form has been amended since its early stages. The revised Basel Capital
Framework aims to make the requirements which apply to internationally active banks (wholesale and
retail) more risk-sensitive and representative of modern risk management practices.
80 Operational Risk
The Nature of Operational Risk Chapter Three
Operational Risk 81
The Nature of Operational Risk Chapter Three
Pillar 1 breaks up regulatory capital into three parts, to match credit risk, market risk and operational
risk. The market risk element, dealing with trading losses, is unchanged from Basel 1, which was
amended for this purpose in 1997. The operational risk part is new – it says that banks’ capital
should reflect the risk of mistakes and wrongdoing. An example might be a fine levied on a bank for
overcharging its credit card customers.
From the operational risk perspective, Pillar 1 requires a more detailed explanation. It lays down a new
means of measurement acceptable to international regulators. In seeking to provide common standards,
it outlines three different measurement approaches for calculating risk exposure. These are as follows:
The complexity of approach increases from the basic indicator approach through to the advanced
measurement approaches.
It is anticipated that smaller, domestic institutions that do not possess sophisticated risk management
tools and techniques will use the basic indicator approach.
Like the basic indicator approach, it uses gross income as a broad indicator that reflects the scale of
business operations within each business line and, therefore, the likely scale of operational risk.
82 Operational Risk
The Nature of Operational Risk Chapter Three
It splits a firm’s gross income between eight defined business lines and then multiplies this by a factor
(denoted ‘beta’) specific to each business line to produce the amount required to be held as operational
risk capital for that particular business. The overall amount of operational risk capital is then the sum of
all these calculations. The relationship between business unit and indicator is shown in Figure 3.6.
So, for example, for the corporate finance (CF) business line:
The different factors reflect the assumed riskiness of each business and range from 12% to 18%.
The standardised approach relies on indicators and factors set by the regulators and recognises that
many institutions do not yet have sufficient loss data and analytical risk processes to calculate their
own capital charge. It provides a basis for moving towards a more sophisticated methodology and
encourages better operational risk management.
In order to qualify to use this approach, a firm must meet the following criteria:
• Its board of directors and senior management must be actively involved in the oversight of the
operational risk management framework.
• It must have an operational risk management system that is conceptually sound and implemented
with integrity.
• It must have sufficient resources to staff its approach within its business lines, control and audit
areas.
• Internationally active banks must have clear responsibilities assigned to an operational risk
management (ORM) function. This function should be responsible for managing the process.
• It must perform systematic tracking of operational risk data, including losses by business line.
• It must use an effective risk reporting system.
• It must have an independent, well-documented risk management and control process (see the next
section for a description of the operational risk function).
Operational Risk 83
The Nature of Operational Risk Chapter Three
Note that the EU Capital Requirements Directive is less prescriptive than Basel.
The AMA can cover a range of measurement techniques, usually VaR-based, providing that the
regulators approve them. Approval will mean the inclusion of quantitative and qualitative measures. If
qualitative measures are used, they must have an ability to be objectively validated.
• The bank must establish rigorous procedures for the development and validation of risk models.
• The risk measure must incorporate the impact of infrequent, high-impact losses.
• The bank must be able to demonstrate that the risk measure reflects the equivalent of a holding
period of one year and a confidence level of 99.9%. Note that while this confidence limit is
stipulated by the Basel Committee, there are exceptions to its application.
• The bank must develop specific criteria for assigning loss data to specific risk types within business
lines. Examples of these risk types are:
• fraud (internal and external);
• employment practices and workplace safety;
• client negligence;
• damage due to physical assets;
• business disruption and failure; and
• transaction processing.
• The risk process must include external, as well as internal, loss data.
• Measures must be based on a minimum five year observation period of loss data (with a minimum
three years required when a bank first moves to AMA).
• The risk mitigation impact of insurance can be recognised up to a limit of 20% of the total
operational risk capital.
84 Operational Risk
The Nature of Operational Risk Chapter Three
The objective of the CRD was to have in place a comprehensive and risk-sensitive framework and to
encourage and enhance risk management among financial institutions. The Directive aimed to maximise
the effectiveness of the capital rules in ensuring continuing financial stability, maintaining confidence in
financial institutions and protecting consumers. The Directive came into force in June 2006.
The FSA is the UK regulator for financial services and is a risk-based regulator. ARROW is the
framework they use to make risk-based regulation operational. ARROW stands for Advanced,
Risk-Responsive Operating framework and covers all types of risks.
ARROW has helped the FSA greatly with the implementation of the FSA’s principles-based approach to
regulation, which means that in practice for firms that present less risk to the FSA’s statutory objectives,
there will be a somewhat lighter regulatory burden imposed on them. This ensures that the FSA can
deliver regulation in an efficient and economic way.
• The ARROW Project was set up by the FSA in 2004 and this has been overhauled by the
implementation of ARROW II. The FSA, through ARROW II, seeks to provide greater clarity
about the outcomes which the FSA considers to be important to it. ARROW II enables the FSA
to accurately capture its assessment of how a firm is applying the FSA principles to protect its
customers.
By using a more risk-based approach to the FSA’s assessment of whether firms are operating in line
with the FSA principles, the FSA can create incentives for firms to do the right thing in return for less
supervisory intervention. Under ARROW II, firms will receive more detail than ever before on the
FSA’s assessment of them.
Operational Risk 85
The Nature of Operational Risk Chapter Three
The FSA will carry out ARROW visits to all firms and assess them in terms of the level of risk they pose
to the FSA’s statutory objectives. For example, all firms will be assessed in the following core areas:
Firms that are within the scope of the Capital Requirements Directive (CRD), have to calculate their
capital adequacy in a different way. In addition to the accounts-based capital adequacy calculations,
the FSA requires firms (from January 2008) to use its Internal Capital Adequacy Assessment Process
(ICAAP).
The FSA requires the whole process to be fully documented in an ICAAP report which firms must
review regularly and keep up to date.
86 Operational Risk
The Nature of Operational Risk Chapter Three
1. What are the three stages of the operational risk chain of events? Section 1
9. Give three reasons why it is important to measure operational risk. Section 6.1
11. List six common methods of risk measurement and assessment. Section 6.2
12. List three advantages of ranking as a form of risk assessment. Section 6.2.1
18. What are the advantages of using risk indicators? Section 6.2.6
21. Continuity planning is an example of which risk mitigation strategy? Section 8.2
Operational Risk 87
The Nature of Operational Risk Chapter Three
23. Why might a firm decide to retain a certain level of risk? Section 8.5
24. What are the advantages of the new Accord proposals to risk managers
and regulators? Section 10.1
25. What does the second pillar of the new Accord require? Section 10.2
26. What are the three approaches for measuring capital adequacy
requirements in the new Accord? Section 10.3
27. Explain the standardised approach for calculating operational risk capital
adequacy. Section 10.3.2
28. List four criteria with which a firm must comply if it is to qualify for
assessment using the standardised approach. Section 10.3.2
29. What is the main advantage for a firm to use the advanced
measurement approach? Section 10.3.3
30. What are the FSA’s five statutory objectives? Section 10.5
88 Operational Risk
CHAPTER FOUR
Operational Risk 89
The Causes, Events and Impact of Operational Risk Chapter Four
90 Operational Risk
The Causes, Events and Impact of Operational Risk Chapter Four
All types of operational risk can be traced back to four root causes. Failure of:
The relationship of these causes is represented in Figure 4.1. The diagram shows that each cause of risk
cannot be considered in isolation. Each one affects the other and they are mutually interdependent. This
means that an ineffective approach to the management of one area will have knock-on effects on the
others.
How well an organisation influences and adapts to its environment and harmonises its people, processes
and technology dictates how successful it will be in managing its risk.
For instance, if staff are using old, manually intensive and incompatible systems, the reliance on their
integrity and expertise to deal with system-related problems is greater and the complexity of the
process design to ensure control is increased. This will impact the firm’s ability to adapt to its changing
environment and its effectiveness in controlling its risk environment.
Conversely, adopting an efficient straight-through processing (STP) system will greatly reduce people
risk, but will increase technology risk, due to the increased reliance on IT.
Operational Risk 91
The Causes, Events and Impact of Operational Risk Chapter Four
People
Process Technology
A process is a set of activities that allow the firm to deliver its product to the customer. A process
takes a collection of inputs and turns them into desired outputs by adding value to them. For instance,
a reconciliation process is a collection of activities concerned with moving unreconciled data from a
stage of unknown agreement to a stage of known agreement, thereby reducing the risk of errors and so
adding value to the business.
Inefficiencies create operational risk that, in turn, reduces the added value of the process. Some
common examples are:
92 Operational Risk
The Causes, Events and Impact of Operational Risk Chapter Four
• Volume sensitivity - this issue concerns the volume of work per head. If the workload increases in
proportion to increasing volumes, there will either be a point of overload, or ever greater numbers
of staff will have to be recruited to deal with the growing business. In either case, the process will
become inefficient. For instance, in investment banking, equity-trading volumes have multiplied
over recent years, putting pressure on old processes and systems that were not designed to cope
with the increase in throughput. Similarly, there are also occasional instances of high volumes or
‘spikes’ in the process, such as on the last business day of each quarter. This again puts pressure on
the process and its people. The challenge for the industry is to design new processes that are not
sensitive to volumes so that they are able to cope with the projected increases in business.
• A lack of effective controls and/or control documentation - all processes have controls and
check points designed into them to detect errors and prevent fraud and theft. For instance, firms
have controls to ensure segregation of duties so that no single person has the end-to-end authority
to process transactions (ie, one person may be able to book a payment into a system but another has
to check it). This prevents fraudulent activities, such as assigning cash movements to personal bank
accounts. In the case of Barings Bank, Nick Leeson was responsible for both front and back office
functions. The lack of segregation gave him the opportunity to commit fraud.
• A failure to review controls when the process changes - processes continuously change and
(hopefully) improve. If the control structure is not reviewed and assessed as part of this change it is
possible that some potential new risks are introduced that are not covered by adequate controls.
The identification of these control gaps is a key objective of the operational risk management
function.
People are an organisation’s greatest asset – this is reflected in the high proportion of a firm’s costs
being attributed to staff compensation. However, the operational risks due to people-related issues
are difficult to assess. This is partly due to the difficulty in measuring their effects. As the understanding
of the ‘human factor’ has improved, it has become even more apparent how damaging losses due to
people issues can be. People causes can take the following forms:
Operational Risk 93
The Causes, Events and Impact of Operational Risk Chapter Four
All of the issues above result in a greater likelihood that the risk of loss will be realised and, as a result,
companies have to focus time and resources on ways to reduce their effects. It is a key responsibility of
senior management to ensure that sufficient personnel are attracted and retained who have:
It is also important that robust succession planning is in place to avoid an increase in people risk
exposure in key roles.
These cultural qualities are as important as the technical qualities and should exist in the organisation, its
management and its recruits.
Firms employ technology to improve the effectiveness and efficiency of their processes. Its use is
generally accepted to improve controls and reduce cost and, in the age of e-commerce, its importance
to business success is greater than ever before. However, it is also a cause of operational risk. Some
technology causes are:
94 Operational Risk
The Causes, Events and Impact of Operational Risk Chapter Four
• The lack of a strategic approach to system design. Symptoms of this lack of strategy might be
a preponderance of ‘tactical’ system solutions, the uncontrolled use of business-critical spreadsheets
or a lack of integration of systems across functional areas.
• High system complexity, meaning that there can be a lack of understanding of functionality and
it can be difficult to predict the knock-on effects of any major changes.
Due to the increasing reliance on technology, there is a growing effort to measure its impact on
operational risk.
The three causes of process, people and technology are inherent in the internal structure of an
organisation. The environmental causes have an impact by exacerbating the risks that already exist in
these areas. Environmental causes can be categorised into the internal environment and the external
environment. Some examples are as follows:
Operational Risk 95
The Causes, Events and Impact of Operational Risk Chapter Four
The other causes of operational risk cannot be adequately understood without taking these
environmental issues into account.
If a lack of effective people, processes and technology coupled with an inability to adequately manage
the environment are the root causes of risk, and financial loss is the ultimate effect, what is the trail of
errors or events that lead from the cause to the effect?
Because of the breadth of operational risk, the potential events that link root causes to effects cover a
wide range of activities that can eventually result in loss.
These root causes of risk can lead to a wide variety of events. Some of the important root causes are:
• incorrect data;
• delayed processing and documentary omissions;
• regulatory non-compliance;
• project mismanagement;
• fraud and theft; and
• unforeseen litigation.
The events are described in the rest of Section 2 and their consequent effects in Section 3.
96 Operational Risk
The Causes, Events and Impact of Operational Risk Chapter Four
Institutions today hold and process vast quantities of data often in different forms and in more than one
place. Data can be wrong for two reasons:
This lack of integrity can originate from any or all of the causes described at the start of this chapter.
For example, data may need to be manually keyed into a system because two systems are incompatible
with each other (technology cause), leading to mis-keying because of human error (people cause).
The error may then not be detected due to the lack of an effective control procedure (process cause),
which may then result in incorrect documentation being sent to a client. The chance of this problem
occurring might be increased due to the pressure of increasing volumes (environmental cause).
Delays and documentary omissions are often caused by the inability of a process to cope under stressful
conditions, such as abnormally high volumes or too much change affecting the business. These are often
‘early warning signs’ of process weakness.
They may also be caused by a lack of awareness of the operational risk issues leading to a lack of timely
action due to the pressure of mistakes and errors.
Institutions operate within a set of industry rules and regulations defined by law, or industry guidelines
enforced by their regulators. Firms aim to operate within these rules. However, they may inadvertently
transgress due to lack of adequate people, processes or technology. For instance, reporting deadlines
may be missed, reports may be incorrect or limits may be exceeded.
Operational Risk 97
The Causes, Events and Impact of Operational Risk Chapter Four
The way firms bring about change is through the implementation of projects. Projects are packages of
work that deliver a ‘piece of change’. They usually form part of an integrated programme that helps
the firm to manage its changing environment. They can be large and strategic or small and tactical but
the sum total of all the project work occurring in an organisation has an effect on its ‘business-as-usual’
business. Examples of projects are:
• The design and implementation of a new process capable of processing ten times the volume of
business with lower risk and for the same cost. This would be a large, strategic project and would
involve people, processes and technological aspects.
• The design and implementation of a client query system that helps to improve the quality of client
service. This may vary in size from a small project in one particular area of operation to a more
strategic project involving a number of departments.
• The design and implementation of a management training programme to support a cultural change
to a more consensual style of management.
• The design and implementation of a new organisational structure for a firm to provide greater
autonomy and decision-making for middle managers.
Project risk is the risk that the failure, or partial failure, of a project to meet its objectives leads to
financial loss.
Fraud and theft can be committed from within the organisation (internal fraud) or by persons
outside the organisation (external fraud). They can occur due to a combination of causes, such as the
dishonesty of the fraudster (people cause) or the weakness in process or system design that gives
him the opportunity to commit the crime (process cause). For fraud and theft to occur there must be
opportunity and this opportunity is usually the result of an operational issue.
98 Operational Risk
The Causes, Events and Impact of Operational Risk Chapter Four
Unforeseen litigation is an aspect of legal risk which includes instances when the firm is sued, for
example, due to:
The final event category is technology failure. The ultimate effect or impact of operational risk being
realised is direct or indirect financial loss. Technology failures can occur for many different reasons,
some of which are in the control of the firm, some of which are not. Examples include:
• power failure;
• back-up power systems not working;
• viruses and bugs affecting the operation of systems; and
• overusage or overloading of systems.
As with market and credit risk, the ultimate effect or impact of operational risk being realised is financial
loss. This loss can be either direct (quantifiable) or indirect (non-quantifiable).
Operational Risk 99
The Causes, Events and Impact of Operational Risk Chapter Four
• a lack of operational capability, meaning that the firm is unable to trade in the way it wishes;
• the damage to the firm’s reputation in the market or with a specific client (or both). The potential
for financial loss due to a damaged reputation is known as reputational risk. Reputation and the
integrity of a financial institution are major factors in its competitiveness and success.
• adverse publicity due to a lack of client suitability, ie, being associated with criminals, notoriety or
scandal;
• perceived malpractice, such as inflating commissions, misselling, concealing losses and the
identification of accounting irregularities;
• public disputes with customers, which could possibly lead to litigation;
• client dissatisfaction resulting in loss of future business opportunities;
• the associated costs of rectifying the operational weakness that led to the loss, such as through
re-allocating staff from profitable activities to help correct the problem (where this does not lead to
an additional debit on the profit and loss account).
The following table gives some examples of the main impacts of the risk events described earlier.
There are many instances of operational risk within a business and these could result in any or all of the
following:
Here are some examples of these operational risks. In each example there are details of the root cause,
the event and the effect of the operational risks.
2. In the legal department, an ambiguous clause may be inserted into a contract, leading to financial
loss.
• Root cause = People (lack of training or carelessness), compounded by Process (the
complexity of the job).
• Event = Incorrect documentation.
• Effects = Financial loss arising from contention of contract by client or a third party (eg, cost of
litigation, inability to claim profits etc) as well as reputational loss.
3. In the credit department, an error in a credit model could result in a client being able to exceed
its credit limit. This may lead to regulatory censure and unexpected financial loss if the client
defaulted.
• Root cause = Either Technology (a poor design of the model) or Process (the mis-translation
of the business requirements when developing the model).
• Event = Regulatory non-compliance or breach.
• Effects = Potentially larger-than-expected loss, if the client defaults, and financial penalties from
regulators (with consequential reputational damage).
4. In the operations department, the expiry date of an option may not be monitored effectively,
leading to an in-the-money option not being exercised.
• Root cause = Weak process and controls in identifying and monitoring option events.
• Event = A missed event (eg, the expiry date of an in-the-money option).
• Effects = Financial loss due to not calling an in-the-money option.
There are countless other instances of operational risk that can occur anywhere in the transaction life
cycle.
The front office of a financial institution is where trading takes place. It is populated by the firm’s
revenue earners. These are the traders, fund managers, salesmen and market risk managers. Only
authorised employees in the front office can commit the firm to a contract and a clear distinction must
be drawn between staff having the status of traders or dealers (these provide the actual execution of
the trades or deals) and trade support staff that assist in order handling and the provision of quotations/
prices to the client.
The revenue earners are interested primarily in making a profit for the firm and generally have most
involvement in the transaction life cycle up to the point of transaction execution (ie, the commitment
of funds). After this point, the administration of the transaction is conducted by the support functions.
Revenue earners will monitor transactions throughout their life in order to manage market risk (implicit
in the daily profit & loss (P&L) calculation) and may also be involved in specific issues or problems, such
as dealing with sensitive clients or making decisions on options.
• Ensuring that effective segregation of duties are in place between trading and support functions,
such as the front office, operations, accounting and risk monitoring.
• Having clear escalation procedures in place covering all key risks, such as exceeding agreed limits.
• Ensuring adequate research has been carried out before dealing in a new product, portfolio or
counterparty. This may include, for instance, the production and authorisation of a detailed business
plan.
• Controlling new market and credit limit requests and ensuring they are adhered to.
• Effective capital requirement reporting and details relating to the usage of capital.
• Conducting continuous limit reviews in order to maintain the firm’s risk appetite. For instance,
counterparty credit limits may be reviewed annually or whenever there is an adverse material
change in either their financial status or market.
• Ensuring effective control over front office systems; including reference data, computer models,
spreadsheets and algorithms. This is particularly important when complex mathematical models are
used involving ‘chaining’ of calculations, so that the output from one calculation is used as the input
for another, or when there are no easily devised plausibility checks possible on the results of the
model.
• Ensuring after-hours trading is properly defined and controlled.
• Tightly controlling dealing tickets and ensuring they are processed quickly and efficiently, eg,
numbering them consecutively, using time-stamps and transmitting them immediately to the
settlement department after they have been produced in the dealing room.
• Continuously updating positions. Dealers should always know the value of their long, short and net
positions, as well as the value of any hedge relating to a position.
• Maintaining high ethical standards by having effective procedures in place to ensure that:
• there is no trading at off-market rates or at rates which deviate from prevailing market levels;
• dealing only occurs within the dealing room, unless specifically authorised otherwise;
• there is client confidentiality in accordance with data protection principles; and
• compliance rules are followed, particularly with respect to the rules of conduct and
entertainment, and ensuring that token gifts are not excessive and are only accepted in
accordance with rules.
When setting up operational risk management processes in the front office, appropriate risk indicators
are chosen to monitor the effectiveness of these controls such as the number of limits breaches, system
availability and dealing ticket processing times.
• Marketing and sales - the Financial Services Authority has very specific rules regarding how
investments should be marketed, particularly to private customers. Some of these rules cover the
following: adverts to be clear, fair and not misleading; certain minimum information to appear in the
advert; contact details of the advertising firm; rules relating to cold calling and record keeping.
• Know your customer - KYC is central to the firm’s ability to give proper advice. Without
up-to-date knowledge of the customer it becomes difficult to make sure that recommendations are
suitable. Consequently, the rules require that the firm takes ‘reasonable steps’ to gather information
about the private customer. This is commonly done using a KYC fact-finding questionnaire. The
penalties for non-compliance can be severe. The FSA has issued requirements in its Rulebook for
firms to abide by.
• Account set-up - certain details relating to the customer will need to be recorded by the firm and
the correct customer classification must be applied on the firm’s internal records.
• Static information - this is also called ‘current standing data’ and includes details to be recorded
by the firm, eg, customer’s name, address, contact details, investment objectives etc. These details
need to be rechecked by the firm on a regular basis, so as to ensure they are still correct.
• Credit assessment - the firm may also need to carry out a credit reference search for a potential
customer to assess their financial standing.
• Standard settlement instructions - including details of how customers will pay for their
investment purchases and how they wish to receive their settlement monies when selling
investments.
• Legal contract negotiation - including agreeing terms and conditions by the legal department
within the business that may be used in client agreements and terms of business.
• Client and counterparty agreements - these may need to be sent out to customers (depending
on the type of investment) and their written confirmation may be required before the firm can start
carrying out the activities that the customer has requested.
If a firm is advising a private customer, or acting as an investment manager for a private customer, or
arranging a pension opt-out or transfer for a private customer, it must take reasonable steps to ensure
that it is in possession of sufficient personal and financial information relevant for the services that the
firm has agreed to provide. This could include information about income, other assets, outgoings, age,
investment objectives and attitude to risk. Potential customers may also be credit-checked to confirm
that they may be accepted as customers. They may also be sent a ‘terms of business’ letter or may
need to complete and return a client agreement letter.
The front office support functions mainly ensure that front office trade information passes smoothly and
accurately into the front office support settlement systems. In some organisations this function forms
part of the operations department.
It generally involves the capture of transactions in the front office functions systems and trade
confirmation processes.
• trends in the volume of transactions when compared with the percentage handled manually;
• the number of errors detected by reconciliations;
• the time taken to detect and resolve the errors;
• the number of transactions not captured within a specific time from trade execution.
Confirmations can be made by telephone and in writing and their format is usually agreed through a
legal agreement signed by the two parties involved as part of the set-up activity. For some products,
such as listed derivatives that use a central counterparty, confirmation can involve a high degree of
automation by being performed electronically with the exchange. For other products, such as OTC
derivatives, confirmations are performed as part of a bilateral agreement using hard copy documents
that become largely standardised. This standardisation helps reduce the risk of error and legal ambiguity
and allows firms to design processes assuming consistent inputs.
Operational risk exists due to the possibility of disputes of transaction details, confirmation errors or
delays when confirming trades, all of which could result in the counterparty defaulting without the firm
having legal recourse.
• ensuring that a legal agreement covering confirmation protocol is in place prior to trading (a
preventive control);
• a confirmation checking function performed by a different person to the creator (an internal
detective control);
• front office sign-off of the economic terms of the confirmation (an internal detective control);
• follow-up actions to counterparties which have not returned written confirmations.
Traditionally, operations departments exist to process and settle transactions. Their objectives are:
• to monitor the life of a transaction through to settlement, ensuring that key events are flagged and
acted upon when necessary;
• to provide the transaction, position and cash movement information that are used as a basis for the
accounting function.
• transaction instruction;
• positioning;
• settlement; and
• reconciliation.
In order to perform the transaction instruction activity effectively, firms will hold ‘Standard Settlement
Instruction’ (SSI) data for most of their counterparties. This allows the automation of the instruction
process, as SSI details are received when the counterparty is first set up in operational systems. In some
cases, and for some products, SSI details are not available when the settlement date approaches and a
separate transaction-specific instruction must be used. This introduces additional risk.
Automated trade confirmation and matching systems, linking trading organisations with custodians and
other counterparties, are commonly provided by third party systems vendors. A good example is the
OMGEO service provided by DTCC/Thomson.
In order to reduce the chances of error and improve process efficiency, this stage can sometimes be
combined with the confirmation stage, with a single combined transaction confirmation and instruction
being sent.
Risks and controls are similar to the confirmation process described above.
1.3.2 Positioning
Positioning is the process of ensuring that there is sufficient cash or stock available to fulfil the contract.
Operational risk exists because positioning is part of an overall inventory management process in which
firms strive to make the most efficient use of their resources. This means that cash and stock are being
continually recycled and used in a way that will generate the maximum return for the firm. Because of
this dynamic process, there may be insufficient assets available when they are required. This leads to
two potential consequences:
• settlement being delayed, exposing the firm to interest claims, potential fines and reputational
damage; and
• higher borrowing costs – in order to ensure settlement, a firm may have to borrow cash or
securities at a higher cost than would otherwise be necessary.
• the use of internal funding deadlines by which time confirmation and transaction instructions must
be completed. These deadlines would allow enough time for the funding and settlement activities to
be completed (a preventive control);
• system limits to warn users that there are insufficient assets available to cover an upcoming
settlement (a detective control).
1.3.3 Settlement
Settlement is the physical delivery of an asset in exchange for an equivalent amount in cash or payment
receipt. The main operational risk is that the preceding steps in the process break down, resulting in
settlement failure. This is exacerbated in markets that do not employ true delivery versus payment
(DVP) systems.
A risk indicator that measures the quality of the overall process is the number of times a firm settles
late but this could also be affected by market influences.
The volume of unreconciled events (or ‘breaks’) is commonly used as a risk indicator to assess the
quality of the transaction capture and processing activity.
Inventory management involves how a firm keeps records of its customers’ cash and stock movements.
For example, if it uses an electronic system to record these details, then the firm must ensure that the
system is sufficient for this purpose.
3. Give three examples of key risk indicators that may be used by the
front office support functions when capturing transactions. Section 1.2.1
4. What are the two objectives of a typical operations department? Section 1.3
Compliance with regulatory requirements and ethical conduct standards is a major concern to boards
of directors and senior executives because they are held accountable and personally liable for violations.
In a complex and decentralised business environment, corporations must institute consistent, firm-wide
compliance policies and procedures to prevent litigation and reputational damage and meet shareholder
accountability demands.
Under the Markets in Financial Instruments Directive (MiFID), which was adopted in the UK with
effect from 1 November 2007, it is a requirement for each firm to have an independent and permanent
compliance function, if it is sufficiently large enough. This independent section must have sufficient
authority and be structured, resourced and operated effectively.
The compliance function in a firm exists to combat this risk. Its objectives are to ensure:
• good corporate governance by defining the way the board of directors and senior executives
execute and govern the company’s overall compliance strategy and ethical mission;
• organisational integrity through the development of ethics and integrity programmes. These define
the training and communication programmes and related accountability processes (such as a
self-assessment process) that attempt to motivate, measure and monitor the organisation’s ethical
performance;
• regulatory compliance by defining the programmes and processes that measure and monitor the
extent to which the organisation adheres to existing laws, regulations, industry guidelines and
general business norms or conventions.
In many firms the compliance function is also one of the top-level internal procedure-makers for risk
control across all functions and covers the key areas of market, credit and operational risk. When
operating successfully, the compliance role balances the limiting effects of necessary controls with the
empowerment of the workforce to operate within clear boundaries (that may be enforced by other
functions).
The policies and procedures that the compliance function generates are designed to meet these
objectives and to provide direction and clarity to the firm’s employees. Its responsibilities are
wide, covering all aspects of the business and interacting with all of the firm’s functions. These
responsibilities may typically include:
• Good practice - the compliance function keeps abreast of good practices in the industry and
the recommendations of the regulators. It ensures that the following practices are incorporated into
the firm’s policies:
• advice for business units on regulatory issues;
• compliance monitoring;
• communication with the regulatory authorities and reviewing regulatory policy initiatives;
• routine compliance duties such as staff registration and staff dealing approval.
• Regulatory reporting requirements - regulatory reporting covers the reporting of required
information to the relevant regulators. Compliance will ensure the firm sets policies for
requirements such as:
• monthly financial accounts;
• lists of authorised traders, counterparties and products;
• bank account and custodian details.
• Employee conduct - the compliance function will ensure that employees are provided with clear
guidelines and training reflecting law, industry regulations and the firm’s expectations.
The following issues would be addressed:
• insider trading;
• acceptance of gifts;
• client entertainment;
• whistleblower protection;
• stock ownership in companies that the firm has involvement with;
• relationship with competitors;
• relationship with the media;
• confidentiality;
• money laundering.
• fraud;
• insider trading;
• money laundering;
• exposure violations;
• non-compliance with regulatory requirements, eg, misleading selling;
• non-co-operation with regulatory investigations;
• unauthorised trading;
• concealing losses.
The firm may also have to pay damages, contracts may also be void and reputational damage may
occur, all of which could materially impact the firm.
The financial reporting function exists to ensure that the assets and liabilities of the firm are accurately
compiled and reported. A prime financial report is the balance sheet which shows a running total of a
firm’s assets, liabilities, profit and loss.
Accounting risk is the risk of inaccurate financial reporting. Its effects are poor management
decision-making (based on incorrect information) and regulatory non-compliance. These effects can
lead to the consequences of direct and indirect loss such as fines and penalties. Accounting errors can
also conceal already realised losses. These can often go undetected for a long period as they become
lost among other problems and causes.
The financial reporting function performs both internal reporting and external reporting:
Operational risk is inherent in the policies, processes or procedures that ensure accurate financial
reporting. If these break down, accounting risk can be realised. For instance:
• Traders misreporting a transaction’s details in the trading book to make it appear more profitable.
The key control is to validate front office positions on a daily basis as part of the daily reporting
function. This is done by reconciling front office positions (the trader’s view of the world) with the
back office positions (which, when the transactions have settled, should represent the external view
of the world). Some firms call this activity the product control function.
• Misreporting accounts because of complex aggregation rules. Financial institutions usually report
internally by trading book because information is collected at the trader’s book level in order to
assess trader performance. However, they are required to report externally at a legal entity level.
For this reason, the financial reporting systems need to aggregate information to the entity and
group level. While this might seem a simple process in theory, in practice it can prove very difficult
due to poor system integration and the lack of an overall view of the business (both of which are
operational risks).
• A trader is focused on the future – ie, trying to predict what a market will do, while the accounting
function focuses on the past, ie, ensuring that what has been traded is accurately reported. This can
occasionally create a tension between the front office and the accounting function. The intention
must be to develop a good relationship, to foster open communication and avoid operational
difficulties.
• Changing accounting standards in the industry can lead to confusion in the interpretation of
regulations and reporting requirements.
• Mergers and takeovers can exacerbate accounting risk by adding to the fragmentation of the
business view. It takes time for a company to understand the full financial details of the merged
company and to incorporate these efficiently into the financial reporting of the new firm.
Human Resources (HR) - operational risk exists throughout the process. The HR function is
responsible for many things, including:
If a firm wished to gain access to a new market, it would look to risk management to provide an
assessment of the likelihood of success of the venture. HR might identify a constricted labour market
along with alternatives for addressing the problem. Risk management has the responsibility of
co-ordinating the risk assessments of all of the operational disciplines, along with options to address
the identified issues. Using the above example, the solutions could range from transferring existing
employees, to paying a premium for local talent, to the acquisition of a local company that already has
the required talent. With these options identified, business managers can make educated decisions on
the course of action that is best aligned with their goals.
Internal audit plays an important role in the risk control framework. It provides an independent, internal
assessment of the effectiveness of the firm’s controls and procedures. It also independently assesses the
effectiveness of the risk management process.
Also under MiFID, it is a requirement for each firm to have an independent internal audit function, if it
is appropriate and proportionate. This independent section must again have sufficient authority and be
structured, resourced and operated effectively.
The independent periodic review of all transaction life cycle activities is an indispensable safeguard
for senior management in ensuring the integrity of the internal control structure. It also ensures that
management information systems (MIS) are operating effectively.
By performing reviews, internal audit assesses control strength, questioning whether an institution’s
processes and procedures are:
• adequately controlled;
• up-to-date;
• practised in accordance with manuals and documentation.
It also acts as a ‘dry run’ for external audits and regulatory examiners.
Internal audit must have an unrestricted mandate to review all aspects of the transaction life cycle and
be totally independent of senior managers and their departments who are subject to the review.
There is a crossover with the operational risk management process in that both involve the
identification of risk issues. However, auditing is aimed more at checking the control environment on a
‘snapshot’ basis (eg, once every six months), highlighting issues (audit points) but leaving
‘cause-effect’ analysis and solution implementation to the business. Operational risk management
on the other hand, monitors risk on a continuous, day-to-day basis as part of the process allowing
more dynamic and strategic management. Audit information should, therefore, be used as an input to
operational risk management. Audit points can also be used as risk indicators.
Both internal and external audits can be a powerful enabler of change. As part of the cultural change to
a more risk aware outlook, the company’s desire to clear audit issues can significantly raise the profile
of the need for effective risk management.
Operational risk exists throughout the IT process, from strategic decisions about IT, managing projects,
to design, implementation and maintenance. The IT function is responsible for:
• protecting the organisation from system security issues such as viruses and hacking;
• ensuring system development keeps pace with rapidly evolving user requirements; and
• ensuring that systems integrate effectively, thereby minimising manual intervention and data
integrity issues.
Legal risk is the risk of loss due to legal issues brought about by an inability to enforce legal contracts or
documents.
It does this by implementing effective policies and procedures. Their effectiveness depends on how well
the operational risk issues are managed.
The legal role is critical at the set-up stage when legal agreements are negotiated prior to trading.
Agreements can be at the entity, product or transaction level. They are designed to cover any legal
eventuality that may reasonably occur, as agreed by the business line, during the course of the contract.
• Contract formation - ensuring the appropriate legal documentation is in place and is satisfactory
prior to trading. Getting the contract details right at the outset is one of the main responsibilities of
the legal function. The best way to avoid legal risk is to produce contracts that are taut and clear.
This would be done in conjunction with advice from the relevant business area.
• Legal names - confirming the counterparty’s legal name helps to establish the legal, contractual
rights of each party.
• Jurisdiction - law in one jurisdiction may not apply, or apply differently, in another.
• Netting arrangements - netting is used as a means of reducing credit risk. The terms or rules for
netting must be contractually agreed and care taken to ensure enforceability.
• Collateral arrangements - ensuring that all collateral arrangements are legally enforceable and
cover the assets intended.
• Power to transact - ensuring the counterparty has the legal power to transact, ie, checking that it
is not ultra vires.
• Employee authority - ensuring that the counterparty’s employees have the appropriate authority
to transact.
• Fiduciary responsibilities - ensuring the fiduciary responsibilities of a firm are understood, ie,
having a duty of care. A fiduciary is an individual, corporation or association holding assets for
another party, often with the legal authority and duty to make decisions regarding financial matters
on behalf of the other party.
• Client Relationship - ensuring the maintenance of an arm’s length relationship with the client (via
the legal agreement) and disclosure of the relevant risks. There must be clarity between an arm’s
length relationship and an advisory relationship.
The marketing function plays a critical role in linking sales, development, customers and potential
customers of a business. Typical responsibilities of the marketing function include:
The marketing function will also have a responsibility to ensure that the business does not grow too
rapidly, resulting in the problems of not having enough resources to cope with the increase in demand
for its services, for example, staff, IT systems and related infrastructure. This also needs to be balanced
with having an optimum level of business to ensure survival.
The project management team aims to bring about the successful completion of specific project goals
and objectives. It is often referred to as program management. The change management team ensures
that any required system changes are implemented in a controlled manner by following a predefined
framework or model. The various operational risks faced by both of these functions will need to be
identified and managed throughout the process.
1. Which aspects of the life cycle are covered by the compliance function? Section 1.1.1
4. What three questions does the internal audit function seek to answer
when performing reviews? Section 1.4
5. What is the difference between the role of the internal audit function
and the role of the risk management function? Section 1.4
ENTERPRISE RISK
MANAGEMENT (ERM)
1. THE OBJECTIVES OF ERM 129
2. THE CHALLENGES OF IMPLEMENTING ERM 130
Enterprise risk management (ERM) is also known as integrated risk management or firm-wide risk
management. It is a concept that provides a firm with the ability to understand, address and manage
their interrelated financial risks in the most effective way. It is commonly referred to as integrated
risk management or firm-wide risk management because it is a structured, consistent and continuous
process across the whole organisation (which could extend outside the UK) for identifying, assessing,
deciding on responses to, and reporting on, opportunities and threats that affect the achievement of its
objectives.
One of its main aims is to protect shareholder value by integrating the management of all the disparate
risks of a portfolio of businesses. This allows a firm to appreciate its overall risk profile and to identify
and explain financial risk in a transparent, structured and comprehensive way.
In terms of measuring risk, a recent development is the attempt to measure total risk using an
integrated Value-at-Risk (VaR) model. Such a model would calculate a total capital-at-risk figure which
would allow appropriate financial provisioning and help strategic decision-making.
In order to protect shareholder value, ERM has four practical objectives that make financial risk
management more effective. These are to:
These objectives are common to any risk management process. The difference with ERM is that it
integrates the management of ALL risks. This means generating a common framework and using a
common approach and common systems for the management of:
• market risk;
• credit risk;
• operational risk;
• strategic risk; and
• business risk.
Much of the effort involved in ERM at present is in understanding the interrelationship between the
different risk types that face a business and improving the way the various risk specialists work with
each other in forming the overall risk picture.
As a result, ERM is the next major strategic step forward for financial institutions to help them manage
their risk.
There are a number of areas to be considered when implementing an effective ERM policy. These
include:
• Has the firm adopted a common process for risk management and is there a common
understanding of risk and risk management within the firm?
• How are risk management tools being applied to decision-making within the firm and are they being
used effectively and consistently?
• Do all the firm’s business and operational plans consider risks and incorporate measures to mitigate
those risks and/or to maximise opportunities?
• Is there a full understanding of how each risk area impacts others within the risk teams, to allow
them to provide adequate challenge to business decisions?
ACHIEVING COMMON
STANDARDS AND PROTECTION
1. INTRODUCTION 135
2. MARKET DEVELOPMENTS 135
3. MARKETS IN FINANCIAL INSTRUMENTS DIRECTIVE (MiFID) 138
1. INTRODUCTION
This chapter describes the main events that have occurred so far in the development of standard
practice, culminating in the publication of the proposal for a new Capital Accord. This includes an
explicit treatment of operational risk for the first time and represents a watershed in the drive for
common standards and protection.
The operational risk area is relatively immature in financial services and there remain practical difficulties
in identifying and accurately assessing exposures. For this reason, standard methodologies have not yet
found widespread agreement. There are, however, guidelines for good practice which are available for
firms to use.
These guidelines have evolved over the past 10 to 15 years as a result of global research, surveys and
investigation into the disparate methods of understanding, assessing and managing operational risk.
These investigations have attempted to highlight the most promising and effective practices in the
industry and have gradually developed a body of knowledge that can be called good practice.
2. MARKET DEVELOPMENTS
LEARNING OBJECTIVES
8.1.1 Understand the drivers of the development of operational risk
standards: Basel Accord; Sound Practices for the Management and
Supervision of Operational Risk; European Commission;
Sarbanes-Oxley; UCITS IV; Solvency II; RDR; AIFMD
8.1.3 Understand how these developments affect financial institutions
8.1.4 Understand how these developments impact the operational risk
management environment
As the importance of operational risk has grown, there has been a gathering momentum from
international regulators to ensure that it is managed in an objective and consistent manner. There is
now an accepted belief that it should be assessed separately from credit risk and market risk and that
regulatory capital should be provided for separately.
The concepts for risk management have been developed by the industry to the point where a number
of reasonably sophisticated techniques are now being employed. There is, however, no commonly
accepted approach, nor is there a convincing argument that there should be one. Operational risk,
unlike credit risk and market risk, involves the assessment and management of risks whose cause can lie
outside a firm’s control and whose effects are not capable of being limited or capped. In addition, each
firm has a unique environment and a unique risk appetite, so it is becoming accepted that operational
risk will be managed differently as a result. This is understood by the regulators and is being reflected in
their new rules.
A committee was formed under the auspices of the Bank for International Settlements (BIS). Known
as the Basel Committee on Banking Supervision, it comprises representatives from central banks
and regulatory authorities. Over time, the focus of the committee has evolved, embracing initiatives
designed to address the regulatory supervision of banks and to promote uniform capital requirements
so banks from different countries may compete openly with one another.
The Basel Committee, which has, since 1988, set capital adequacy standards for banks in respect
of credit risk, began addressing the need for setting aside additional capital for both market risk
and operational risk during the 1990s in response to market events including the Barings crisis and
other high profile cases. The original requirement for banks to hold as capital 8% of their risk assets
is gradually being extended. Market risk as a result of VaR measurement was added to the capital
requirement formula in 1996.
In January 1999, the Basel Committee proposed a New Capital Accord. In 2001 and 2003 the Basel
Committee introduced some consultation papers. The New Capital Accord was published in June 2004
and became known as the New Basel Accord or Basel II. For the first time, the requirement for specific
capital to cover operational risk was introduced. Greater detail on the Basel II Accord is included in
Chapter Three, Section 10.1. Please note that Basel II has a global significance to financial institutions
and is not limited in scope to the EU.
There was a desire to harmonise capital requirements for banks and securities dealing firms across
the EU. The solution implemented with the 1993 Capital Adequacy Directive (CAD) was to regulate
functions instead of institutions.
CAD established uniform capital requirements applicable to both universal banks’ securities operations
and non-bank securities firms. A universal bank would identify a portion of its balance sheet as
comprising a ‘trading book’. Capital for the trading book would be held in accordance with CAD while
capital for the remainder of the bank’s balance sheet would be held in accordance with the 1988 Basel
Accord.
Europe developed CAD at the same time that the Basel Committee was developing an amendment
covering market risk for its 1988 Capital Accord. The two initiatives influenced each other. Essentially,
Europe was pursuing locally what Basel was pursuing globally. European regulators had hoped that both
initiatives could be completed simultaneously, but this did not occur. The EU had set a deadline of 1992
for reaching agreement on all significant single-market legislation.
However, despite these differences, clear strategies and oversight by the board of directors and
senior management, a strong operational risk culture and internal control culture (including, among
other things, clear lines of responsibility and segregation of duties), effective internal reporting and
contingency planning are all vital elements of an effective operational risk management framework for
banks of any size and scope.
In 1993, CAD and proposals for the Basel amendment were very similar. Both calculated capital
requirements for a trading book based upon a building-block VaR measure.
The EU and Basel processes have now converged. CAD was superseded by the Capital Requirements
Directive (CRD) in June 2006, which represents the EU’s interpretation of Basel II. The EU capital
requirements for implementation by national regulators across member states are
to be based upon the Basel II approach.
Following the stock market falls in 2001, particularly the collapse of technology, media and telecom
stocks which resulted in significant investor losses, the New York Attorney General conducted an
investigation into the quality and impartiality of advice given by research analysts.
Serious conflicts of interest in the production of investment research were uncovered and US
regulatory action followed with the enactment of the Sarbanes-Oxley Act 2002. The Act brought
in new rules relating to public company accounting, auditor independence, corporate responsibility
and analysts’ conflicts of interest. It gave the US Securities Exchange Commission (SEC) the power
to regulate, or to require securities associations and national securities exchanges to create rules to
protect investors and the public interest. Subsequently, many more rules have been introduced, for
example, the requirement that analysts now certify the truthfulness of their views and to disclose if they
have received payment for them.
UCITS directives allow collective investment schemes to operate freely throughout the EU on the basis
of a single authorisation from one member state. Agreeing on a common set of rules for all member
states has proved to be very difficult, often slowed down by a range of political and industry-related
disagreements.
Solvency II is the updated set of regulatory requirements for insurance firms that operate in the EU. It
aims to develop a single market in insurance services in Europe, while trying to maintain an adequate
level of consumer protection. A number of member states have realised that the current EU minimum
requirements are not sufficient and have implemented their own amendments. This has the effect of
slowing down the high level reforms that are proposed.
Solvency II is a risk-based system as risk will be measured on consistent principles and capital
requirements for assets and liabilities will depend directly on this. It aims to reduce the risk that an
insurance company would be unable to meet its claims and to reduce losses suffered by policyholders
should a firm be unable to meet its claims in full.
The FSA announced the Retail Distribution Review (RDR) in 2009, which will affect the way in which
retail clients receive advice regarding financial products and services. The outcomes which the FSA aim
to achieve are:
The FSA aims to raise the minimum levels of competence, skills and knowledge for advisers that give
financial advice to retail clients. The minimum level of benchmark qualifications for such advisers will be
raised accordingly.
The Alternative Investment Fund Managers Directive (AIFM Directive) was proposed by the European
Union (EU) in 2009. It aims to regulate fund managers of alternative investments, rather than the funds.
Under the proposal, only AIFM’s established in the EU will be able to provide their services and sell
their funds to investors in the wider European Economic Area (EEA).
In order to get permission to market their funds in the EEA, the AIFM’s must be authorised by the
regulator of the EU country in which they are established. Managers based outside the EU will be
prohibited from marketing their funds in the EEA unless they meet various fiscal and regulatory
requirements. Managers based in the EU, who operate funds established outside the EU, are also
subject to additional restrictions.
MiFID – The EU Markets in Financial Instruments Directive – came into force on 1 November 2007.
Its implementation significantly altered financial services regulation in the UK, how firms operate their
businesses and the way they interact with their customers.
The aim of MiFID is to promote fair, efficient and integrated markets while facilitating competition
between different trade execution methods.
Most firms that fall within the scope of MiFID will also have to comply with the Capital Requirements
Directive which sets requirements for the regulatory capital that a firm must hold.
MiFID requires financial services firms to have an effective risk management policy in place together
with internal control mechanisms that are appropriate to each individual firm. Firms are asked to
identify the risks relating to their activities, processes and systems and to set the level of risk tolerated
by them.
There were many changes for financial firms including client classification, best execution, information
that is provided to clients, execution-only business, suitability and conflicts of interest.
The MiFID requirements for compliance and internal risk functions are broadly the same as the
UK Financial Services Authority (FSA) rules that are already in place, including the following:
• Firms must establish and maintain policies and procedures aimed at ensuring effective compliance.
• Firms must establish procedures that identify the risks associated with a failure by the firm to
comply with its obligations.
• Firms must establish a monitoring programme to regularly assess and address any inadequacies or
deficiencies arising in the firm’s compliance and address any issues arising.
• Firms must have an independent compliance function (unless inappropriate or impractical to
do so) which has the necessary authority and is structured, resourced and operated effectively.
• Firms must appoint a compliance officer who has the necessary authority and also has the
responsibility for the compliance oversight function.
• If appropriate and proportionate, firms must establish and maintain an internal audit function which
is separate and independent from its other functions and activities.
• Firms must establish, implement and maintain adequate risk management policies and procedures
which identify and set the tolerable level of risk relating to a firm’s activities including employees’
compliance with them.
• Firms must have a separate risk control function, if this is proportionate, depending on the nature,
scale and complexity of its business. The risk function must document the organisation and
responsibilities of the risk assessment function.
The Financial Services Authority believes that the operational risk posed by outsourcing arrangements
presents a large threat to its statutory objectives of providing the appropriate level
of protection for consumers, maintaining confidence in the financial system, promoting awareness for
consumers and reducing financial crime. This is because outsourcing arrangements have the potential
to transfer risk, management and compliance to third parties who may not be regulated and also may
operate offshore. Firms must, therefore, have robust governance arrangements and adequate internal
control mechanisms that cover all outsourcing arrangements.
2. Which regulatory guideline was issued in 1988 and what were its
objectives? Section 2
GLOSSARY
Accounting Risk
The risk of inaccurate financial reporting.
Asset Securitisation
The practice of pooling bonds or loans with credit risk and selling them as a package to outside
investors.
Back Testing
The practice of comparing actual data with predicted data in order to ensure the veracity of a predictive
model.
Basis Risk
The risk of a difference in the impact of market factors on the price of two similar instruments.
Bell Curve
See Normal Distribution Curve.
Benchmarking
In the operational risk context, this means comparison of a firm’s loss data and measures of operational
risk with competitors and other firms in the industry.
Bottom-Up Measurement
A method of measuring operational risk that builds up a detailed profile of risks occurring in each
process, aggregating these risks to provide overall measures of exposure for the department or the firm
as a whole.
Business Risk
The risk of loss due to an adverse external environment, such as high inflation affecting labour costs; an
over-competitive market reducing margins or legal, tax or regulatory changes in the markets.
Collateral (Margin)
An asset held by a lender on behalf of an obligor, under certain agreed conditions, as security for a loan
or borrowed assets. An acceptable asset used to cover a margin requirement.
Compliance Risk
The risk to earnings or capital arising from violations, or non-conformance with laws, rules, regulations,
prescribed practices or ethical standards. See also Regulatory Risk.
Confidence Level
An assessment of the probability that an event will occur, usually expressed as a percentage.
Confirmation Process
The process of agreeing the details of a transaction with a counterparty.
Convexity
A second order measure of the exposure of fixed income products to interest rate risk by calculating
how much duration changes with respect to interest rates.
Correlation Simulation
A VaR measure that calculates the volatility of each risk factor from historical data and estimates its
effect on the portfolio to give an overall composite VaR that includes all risk factors.
Credit Derivatives
Specialised over-the-counter (OTC) products that allow the transfer of credit exposure between
parties.
Credit Event
An adverse change such as bankruptcy, insolvency, receivership, material adverse restructuring of debt,
or failure to meet payment obligations when due.
Credit Exposure
The amount that can potentially be lost if a debtor defaults on their obligations.
Credit Limits
The maximum limits for lending set by financial institutions to prevent too much exposure to a
particular firm or counterparty.
Credit Rating
An assessment of the credit worthiness of a firm that is used by lenders to manage their credit
exposure.
Credit Risk
The potential loss of earnings or capital due to an obligor’s failure to meet the terms of a contract or
otherwise failing to perform as agreed.
Current Exposure
The current obligation outstanding.
Delta
A first order measure of the exposure of derivatives to a risk factor such as the change in value of the
underlying instrument.
Detective Controls
Operational controls that detect errors once they have occurred and prevent further losses.
Direct Loss
The direct financial penalty that a firm incurs as a result of a risk being realised.
Distribution Analysis
A statistical means of using historical data to predict future events.
Diversification
A means of offsetting risk by spreading it across borrowers in different, negative correlating industry
sectors.
Downside
The negative aspect of incurring risk.
Duration
A first order measure of the exposure of fixed income products to changes in the risk factor of interest
rates.
Fiduciary Responsibility
The duty of care and trust an individual, corporation or association has when holding assets for another
party.
Financial Risk
The quantifiable likelihood of loss or less-than-expected returns.
First Order
A general sensitivity measure of how much the value instrument or portfolio is affected by (ie, is
sensitive to) changes in a risk factor.
Fitch Ratings
A credit rating agency.
FX Rate Risk
The risk of adverse movements in exchange rates.
Gamma
A second order measure of the exposure of derivatives to a risk factor such as the change in value of
the underlying instrument. The rate of change of delta.
Hedge
A means of reducing the risk of adverse price movements by taking an offsetting position in a related
product.
Historical Simulation
The simplest method of VaR calculation that uses actual historic data to estimate risk exposure in the
future.
Indirect Loss
The loss associated with the opportunity costs or losses of a risk being realised.
Initial Margin
The amount a futures market participant must deposit with the broker or clearing house at the time he
takes a position in a contract.
Issuer Risk
The risk of default, with respect to redemption or interest servicing, when one institution holds debt
securities issued by another institution.
Legal Risk
The risk of loss due to the unenforceability of contracts or documents.
Liquidity Risk
The risk that an institution will not be able to meet its liabilities as they become due because of an
inability to liquidate assets or obtain enough funding or that it cannot easily unwind or offset specific
exposures without significantly lowering market prices because of inadequate market depth or market
disruptions.
Loan Sales
The practice of a firm making a loan to a company and then selling the loan to other institutions or
investors.
Margin
See Collateral. Money or collateral deposited that serves as a performance guarantee.
Mark-to-Market
The present value of an instrument.
Market Risk
The potential loss of earnings or capital arising from changes in the value of portfolios of financial
instruments.
Mean
The average of a group of numbers, calculated by dividing the sum of all the numbers by however many
numbers are in the group.
Moody’s
A credit rating agency.
Negative Correlation
An inverse, or opposite relationship between two factors.
Netting
The practice whereby two parties who exchange multiple cash flows during a given day agree bilaterally
to net those cash flows to one payment per currency, thereby reducing settlement risk. Multi-lateral
netting between a group of counterparties is performed by a clearing house.
Obligor
A party that has a financial obligation to another party.
Off-Balance-Sheet Transaction
A transaction that is not required to be reported in a firm’s financial accounts.
On-Balance-Sheet Transaction
A transaction that is required to be reported in a firm’s financial accounts.
Operational Controls
Activities that are inserted into a process to protect it against specific operational risks.
Outsourcing
The transfer of an aspect of a firm’s business to a third party who will carry the risk exposure for a fee.
Pillar 1
The rules in the New Basel Capital Accord that define the minimum ratio of capital to risk weighted
assets.
Pillar 2
The supervisory review pillar of the New Basel Capital Accord, which requires supervisors to
undertake a qualitative review of a bank’s capital allocation techniques and compliance with relevant
standards.
Pillar 3
The disclosure requirements of the New Basel Capital Accord, which facilitate market discipline.
Portfolio
A collection of investments owned by the same individual or organisation.
Positioning Process
The process of ensuring that there is sufficient cash or stock available to fulfil the contract.
Post-Settlement Stage
The third stage of a transaction’s lifecycle involving the movement of, and control over, cash and
physical assets.
Potential Exposure
The likely maximum loss (for a specified confidence level) in the event of default at a particular point in
time.
Pre-Settlement Risk
The risk that an institution defaults prior to settlement when the instrument has a positive economic
value to the other party.
Pre-Settlement Stage
The second stage of a transaction’s lifecycle involving the capture and agreement of transaction-specific
data.
Preventive Controls
Operational controls that prevent errors occurring.
Price Uncertainty
The uncertainty of knowing whether market prices will move in a favourable or adverse direction.
Probability Distributions
Mathematical functions that describe the probabilities of possible outcomes occurring. They are
depicted as graphs with the ‘probability of occurrence’ on the vertical axis and the ‘possible outcome’
on the horizontal axis.
Process
A set of activities that allows the firm to deliver its product to the customer. A process takes a
collection of inputs and turns them into desired outputs by adding value to them.
Project Risk
The risk that the failure or partial failure of a project to meet its objectives leads to financial loss.
Ranking
A method of assessing risk by estimating the likelihood of it being realised and the magnitude of its
impact. This information is usually depicted graphically.
Reconciliation
An accounting function that ensures the firm’s record of cash and stock movements agrees with its
statement of balance and holdings.
Regulatory Risk
The risk to earnings or capital arising from violations or non-conformance with laws, rules, regulations,
prescribed practices or ethical standards. See also Compliance Risk.
Risk
The hazard or chance of bad consequences or loss occurring.
Risk Factor
An environmental effect that influences the price of a financial instrument or value of a portfolio.
Risk Management
The implementation of a strategic process that reduces the likelihood of risks being realised to
acceptable levels.
Risk Measurement
Risk measurement is concerned with understanding the size of a risk by trying to predict a future event
using past knowledge.
Risk Profile
The types of operational risks that are faced by a firm and its exposure to those risks.
Scenario Analysis
A subjective method of highlighting potential risk issues in order to allow preventative action to be
taken.
Second Order
A sensitivity measure that accounts for a changing relationship between the value of the portfolio/
instrument and the associated risk factor (or a curved line if expressed as a graph).
Securitisation
See Asset Securitisation.
Sensitivity Analysis
A means of understanding how the price of a financial instrument or value of a portfolio changes in
response to influencing effects.
Settlement
The fulfilment of contractual commitments such as payment of cash for securities. The conclusion of a
securities transaction by delivery against payment.
Settlement Risk
The risk that occurs when there is a non-simultaneous exchange of value and one party defaults.
Set-Up Stage
The first stage of a transaction’s lifecycle involving all pre-transaction activities.
Solvency II
Aims to provide a single European marketplace for insurance services.
Stop-Loss Limit
The specified maximum loss that a firm is prepared to make.
Strategic Risk
The risk of loss due to a sub-optimal strategy being employed and associated with the way the
institution is managed. For instance, a competitor or product strategy may be employed that fails to
maximise the return on the investment made.
Stress Testing
A means of testing the accuracy of VaR models against ‘extreme’ market event scenarios.
Transaction Capture
The activity of capturing trades in back office systems.
UCITS IV
Undertakings for Collective Investments in Transferable Securities – aims to provide a single European
marketplace for collective investments.
Underwriting Standards
The standards that financial institutions apply to borrowers in order to evaluate their creditworthiness
and therefore limit the risk of default.
Upside
The positive aspects of incurring risk.
Value-at-Risk (VaR)
The maximum loss that can occur with a specified confidence over a specified period of days.
Value Chain
A number of processes that must occur to achieve a desired outcome.
Variance/Co-Variance Simulation
See Correlation Simulation.
Variation Margin
A demand for extra cash cover for margin made by broker and clearing houses on a daily basis to reflect
changes in the market value of the trades.
Volatility
The relative rate that a financial instrument’s price moves up and down.
Volatility Risk
The risk of price movements that are more uncertain than usual affecting the pricing of products.
Volume Sensitivity
A process cause of operational risk where the workload increases in proportion to increasing volumes.
ABBREVIATIONS
AMA Advanced Measurement Approach
EC European Commission
EU European Union
HR Human Resources
IT Information Technology
MI Management Information
OR Operational Risk
OTC Over-The-Counter
PD Probability of Default
PE Probability of Event
SD Standard Deviation
SR Settlement Risk
VaR Value-at-Risk
1. One of the key operational issues which lead to the huge losses incurred by the National Australia
Bank in 2004 was the:
A. Integrity of people
B. Implementation of new systems
C. Lack of capacity
D. Mistreatment of shareholders
5. The key role of the compliance function is to ensure that the firm:
A. Defines programmes to enhance individual accountability
B. Issues guidelines on collateral and margin usage
C. Operates according to corporate governance parameters
D. Accurately compiles reports of its assets and liabilities
7. The risk of a difference in the impact of market factors on the price of two similar investments, is
normally known as:
A. Volatility risk
B. Basis risk
C. Settlement risk
D. Liquidity risk
9. Where Value-at-Risk back testing shows unsatisfactory differences between the estimates and
reality, what action is normally taken?
A. Additional capital is sought
B. The methodology model is reviewed
C. A report is immediately issued to the FSA
D. Extra hedging is arranged
13. Which ONE of the following statements BEST describes settlement risk?
A. The risk of losses caused by the failure of a firm to pay its creditors
B. The risk of loan default where money is lent to a customer
C. The risk that occurs when there is a non-simultaneous exchange of value and one party defaults
D. The risk that an institution defaults prior to settlement when the instrument has a positive
economic value to the other party
15. What stage normally follows immediately after the Risk Measurement and Assessment stage in a
typical risk management process?
A. Risk identification
B. Risk reporting
C. Risk mitigation
D. Risk monitoring
16. What is the minimum level of capital required to be held by financial institutions as protection
against the realisation of financial risk?
A. 6%
B. 8%
C. 10%
D. 12%
17. Where a firm’s various risks are plotted on a standard risk ranking chart, the highest risks will
normally appear in the:
A. Top right hand quadrant
B. Top left hand quadrant
C. Bottom right hand quadrant
D. Bottom left hand quadrant
18. Which type of measure of operational risk is a means of peer group comparison within the industry?
A. Scenario analysis
B. Cost-based provisioning
C. Benchmarking
D. Ranking
19. The self-assessment approach to risk identification normally utilises which other method of
assessing operational risk?
A. Ranking
B. Scenario analysis
C. KRIs
D. Benchmarking
20. When establishing Key Risk Indicators, which one of the following would be an example of a
non-process related indicator?
A. Volume of transactions per head
B. Number of times a trader exceeds agreed credit limits
C. Annual level of staff turnover
D. Average duration of unsigned confirmations
21. Which one of the following is an example of the risk transfer method of mitigating risk?
A. Introducing internal detection controls
B. Designing a contingency planning policy
C. Taking out a fire and theft insurance policy
D. Setting market and credit risk limits
22. One of the primary changes brought about by the Basel 2 Accord was to:
A. Impose quarterly internal reviews of the risk measurement process
B. Introduce incentives for better risk management
C. Exempt MiFID-compliant firms from extra risk requirements
D. Incorporate the requirements of the Sarbanes-Oxley regulations
23. Focus workshops are used to identify risks and their causes because they have the ability to:
A. Ensure risk reporting is being performed
B. Show clearly the adequacy of controls
C. Satisfy regulators that an adequate control environment exists
D. Investigate cross-functional dependencies
25. Under the Standardised Approach adopted for Pillar 1 of Basel 2, the beta factor used to calculate
the required capital varies according to:
A. The relative risk level as measured by ranking
B. The relative risk level as measured by benchmarking
C. The firm’s business lines
D. The firm’s age
26. Which ONE of the following methods of measurement has the advantage that accountability for risk
management can be clearly defined?
A. Ranking
B. Scenario analysis
C. Bottom-up
D. Benchmarking
27. Which ONE of the following methods of credit risk mitigation BEST reduces settlement risk?
A. Diversification
B. Delivery versus payment
C. Credit derivatives
D. Credit limits
28. Which Basel II operational risk category does money laundering fall into?
A. Internal fraud
B. External fraud
C. Employment practices and workplace safety
D. Clients, products and business practice
29. A bank has been advised that it is to receive an ‘ARROW’ visit in order to review various aspects of
its risk management process. Representatives from which body will conduct this visit?
A. Bank of England
B. HM Treasury
C. Financial Services Authority
D. Office of Fair Trading
30. Which ONE of the following is the BEST reason for using external detective controls?
A. To reduce the likelihood of risk occurring
B. To prevent a risk occurring
C. To reduce the impact of a risk occurring
D. To provide feedback in the risk reporting process
31. When adopting the ‘outsourcing’ method of risk transfer, it is important to appreciate that:
A. The nature of the risk will change rather than be wholly eliminated
B. The transferred risk will be at its greatest towards the middle of the outsourced period
C. The outsourcing cost is likely to outweigh the internal cost savings
D. The regulatory responsibility will fully pass to the outsourced firms
33. One of the key reasons why firms have controls in place to ensure segregation of duties between
front office and back office functions, is to:
A. Reduce settlement risk
B. Speed up the processing time
C. Achieve best execution
D. Minimise fraudulent opportunities
34. Where a series of documentary omissions has occurred in a firm, this is often an early indication of:
A. Data capture errors
B. Cultural difficulties
C. Process weaknesses
D. Capital adequacy problems
35. A life office recently breached compliance rules by both missing a reporting deadline and exceeding
an investment limit. In which case, if either, could the cause result from technology issues?
A. In neither case
B. Only in the case of the missed deadline
C. Only in the case of the exceeded limit
D. In both cases
36. The primary difference between enterprise risk management (ERM) and market risk management is
that ERM:
A. Focuses primarily on long-term issues
B. Aims to integrate the management of all risks
C. Covers non-financial risks only
D. Operates on a bottom-up approach basis
37. One of the key impacts of the Sarbanes-Oxley Act 2002 was to increase the level of corporate
responsibility in the specific area of:
A. Company accounting
B. Competitor activities
C. Product range
D. Remuneration terms
38. Where a firm’s compliance risk is realised, which one of the following results is MOST likely to
consequently occur?
A. A cross-compensating reduction in the firm’s market risk level
B. Damage to the firm’s credit risk
C. A fall in the firm’s costs
D. Damage to the firm’s reputation
39. Where data has been wrongly captured by a firm, which of the four main root causes will be to
blame?
A. Technology in all cases
B. Environment in all cases
C. It will be people or processes
D. It could be any of the four
40. The primary role of the ‘front office’ of a financial institution is to:
A. Oversee strategy
B. Earn revenue
C. Settle transactions
D. Monitor risk
41. Which specific rule is normally addressed by the employee of a financial institution completing a fact
find?
A. Status disclosure
B. Money laundering
C. Best execution
D. Know your customer
43. Which one of the following is MOST likely to be a key risk indicator for the positioning stage of the
settlement process?
A. Time taken to formulate a legal agreement
B. Time taken for counterparties to return confirmations
C. Number of late-settled transactions due to lack of funds
D. Number of transactions not captured within a specified time frame
44. The number of ‘breaks’ is often used as a risk indicator in connection with which stage of the front
office support function activities?
A. Transaction instruction
B. Positioning
C. Settlement
D. Reconciliation
45. Where ‘Standard Settlement Instruction’ data is not used for a particular transaction instruction, this
will often result in:
A. Faster processing
B. Additional risk
C. The involvement of an extra third party
D. Problems occurring at the positioning stage
46. Where an independent internal audit section is required under MiFID, this team must:
A. Have sufficient authority
B. Report directly to the Compliance Officer
C. Include a qualified accountant or solicitor
D. Be separately funded from the firm’s reserves
47. The main difference between direct and indirect financial loss, which can result from a risk being
realised, mainly relates to whether the loss:
A. Is borne by a third party
B. Is long lasting
C. Can be quantified
D. Can seriously impact profitability
48. Where a firm carries out an ‘ultra vires’ check, this is done in an attempt to mitigate which
particular risk?
A. Volatility risk
B. Liquidity risk
C. Basis risk
D. Legal risk
49. Contractual ambiguity is a common aspect of which one of the following types of risk?
A. Regulatory risk
B. Basis risk
C. Legal risk
D. Pre-settlement risk
50. Which one of the four main root causes of operational risk has a recognised separate internal and
external dimension?
A. People
B. Technology
C. Process
D. Environment
170 Operational
Operational Risk
Risk
Syllabus Learning Map
Operational
Operational Risk
Risk 171
171
Syllabus Learning Map
Operational
Operational Risk
Risk 173
173
Syllabus Learning Map
EXAMINATION SPECIFICATION
Each examination paper is constructed from a specification that determines the weightings that will be
given to each element. The specification is given below.
It is important to note that the numbers quoted may vary slightly from examination to examination as
there is some flexibility to ensure that each examination has a consistent level of difficulty. However, the
number of questions tested in each element should not change by more than plus or minus 2.
Questions
Element 1 Risk Basics 1
Element 2 Other Major Risks 6
Element 3 The Nature of Operational Risk 18
Element 4 The Causes, Events and Impact of Operational Risk 10
Element 5 Operational Risks Arising in the Trade Cycle 7
Element 6 The Support and Control Functions 4
Element 7 Enterprise Risk Management (ERM) 1
Element 8 Achieving Common Standards and Protection 3
Total 50
Using your new CISI qualification* to become an Associate (ACSI) member of the Chartered Institute for
Securities & Investment could well be the next important career move you make this year, and help you
maintain your competence.
Join our global network of over 40,000 financial services professionals and start enjoying both the
professional and personal benefits that CISI membership offers. Once you become a member you can use
the prestigious ACSI designation after your name and even work towards becoming personally chartered.
* ie, Investment Operations Certificate (IOC, also known as IAQ), IFQ, CISI Certificate Programme
Plus many other networking opportunities which could be invaluable for your career.
get in touch…









