0% found this document useful (0 votes)
110 views200 pages

Unit 10 - Operational Risk Ed14

Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
110 views200 pages

Unit 10 - Operational Risk Ed14

Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Operational Risk

The Official Learning and Reference Manual

14th Edition, September 2010


This Workbook relates to syllabus version 10.0 and will cover examinations from
21 January 2011 to 31 December 2011

PROFESSIONALISM INTEGRITY EXCELLENCE


OPERATIONAL RISK
Welcome to the Chartered Institute for Securities & Investment’s Operational Risk study material.

This workbook has been written to prepare you for the Chartered Institute for Securities &
Investment’s Operational Risk examination.

PUBLISHED BY:
Chartered Institute for Securities & Investment
© Chartered Institute for Securities & Investment 2010
8 Eastcheap
London
EC3M 1AE
Tel: +44 (0) 20 7645 0600
Fax: + 44 (0) 20 7645 0601

WRITTEN BY:
Stephen Robinson

TECHNICAL REVIEW BY:


Brendan Leddy

SENIOR REVIEW BY:


Markus Krebsz

This is an educational manual only and Chartered Institute for Securities & Investment accepts no
responsibility for persons undertaking trading or investments in whatever form.

While every effort has been made to ensure its accuracy, no responsibility for loss occasioned to any
person acting or refraining from action as a result of any material in this publication can be accepted by
the publisher or authors.

All rights reserved. No part of this publication may be reproduced, stored in a retrieval system,
or transmitted, in any form or by any means, electronic, mechanical, photocopying, recording or
otherwise without the prior permission of the copyright owner.

Warning: any unauthorised act in relation to all or any part of the material in this publication may result
in both a civil claim for damages and criminal prosecution.

A Learning Map, which contains the full syllabus, appears at the end of this workbook. The syllabus
can also be viewed on the Institute’s website at [Link] and is also available by contacting
Client Services on +44 (0) 20 7645 0680. Please note that the examination is based upon the
syllabus. Candidates are reminded to check the Candidate Common Room area of the Institute’s
website ([Link]/candidatecommonroom) on a regular basis for updates that could affect their
examination as a result of industry change.

The questions contained in this manual are designed as an aid to revision of different areas of the
syllabus and to help you consolidate your learning chapter by chapter.

Workbook version: 14.1 (September 2010)


FOREWORD
Learning and Professional Development with the CISI
Formerly the Securities & Investment Institute (SII), and originally founded by members of
the London Stock Exchange in 1992, the Institute is the leading examining, membership
and awarding body for the securities and investment industry. We were awarded a royal
charter in October 2009, becoming the Chartered Institute for Securities & Investment.
We currently have around 40,000 members who benefit from a programme of professional
and social events, with continuing professional development (CPD) and the promotion of
integrity, very much at the heart of everything we do.

This learning manual (or ‘workbook’ as it is often known in the industry) provides not only
a thorough preparation for the appropriate CISI examination, but is a valuable desktop
reference for practitioners. It can also be used as a learning tool for readers interested in
knowing more, but not necessarily entering an examination.

The CISI official learning manuals ensure that candidates gain a comprehensive
understanding of examination content. Our material is written and updated by industry
specialists and reviewed by experienced, senior figures in the financial services industry.
Exam and manual quality is assured through a rigorous editorial system of practitioner panels
and boards. CISI examinations are used extensively by firms to meet the requirements of
government regulators. The CISI works closely with a number of international regulators
which recognise our examinations and the manuals supporting them, as well as the UK
regulator, the Financial Services Authority (FSA).

CISI learning manuals are normally revised annually. It is important that candidates check
they purchase the correct version for the period when they wish to take their examination.
Between versions, candidates should keep abreast of the latest industry developments
through the Candidate Commonroom area of the CISI website. (The CISI also endorses the
workbooks of 7City Learning and BPP.)

The CISI produces a range of elearning revision tools such as Revision Express Interactive,
Revision Express Online and Professional Refresher that can be used in conjunction with our
learning and reference manuals. For further details, please visit [Link].

As a Professional Body, around 40,000 CISI members subscribe to the CISI Code of Conduct
and the CISI has a significant voice in the industry, standing for professionalism, excellence
and the promotion of trust and integrity. Continuing professional development is at the
heart of the Institute’s values. Our CPD scheme is available free of charge to members,
and this includes an online record keeping system as well as regular seminars, conferences
and professional networks in specialist subjects areas, all of which cover a range of current
industry topics. Reading this manual and taking a CISI examination is credited as professional
development with the CISICPD scheme. To learn more about CISI membership visit our
website at [Link].

We hope that you will find this manual useful and interesting. Once you have completed it
you will find helpful suggestions on qualifications and membership progression with the CISI
at the end of this book.

With best wishes for your studies.

Ruth Martin
Managing Director
CONTENTS

Chapter 1: Risk Basics 1

Chapter 2: Other Major Risks 13

Chapter 3: The Nature of Operational Risk 47

Chapter 4: The Causes, Events and Impact of Operational Risk 89

Chapter 5: Operational Risks Arising In The Trade Cycle 107

Chapter 6: The Support and Control Functions 117

Chapter 7: Enterprise Risk Management (ERM) 127

Chapter 8: Achieving Common Standards and Protection 133

Glossary 141

Multiple Choice Questions 155

Syllabus Learning Map 169

It is estimated that this workbook will require approximately 70 hours of study time.
CHAPTER ONE

RISK BASICS

1. INTRODUCTION 3
2. WHAT IS RISK? 3

This syllabus area will provide approximately 1 of the 50 examination questions

Operational Risk 1
Risk Basics Chapter One

2 Operational Risk
Risk Basics Chapter One

1. INTRODUCTION
This workbook describes what risk is and what it means to the financial services industry. It describes
the three common categories of financial risk – Credit and Market (Chapter 2) and Operational
(Chapter 3) – providing a brief contextual overview of the first two and focusing particularly on the
latter. Operational risk and some of the more important aspects of its management are described in
detail in Chapters 3, 4 and 5.

This opening chapter introduces the basics. It explains why risk in general is a subject of concern in all
industries and all walks of life. It then focuses on what financial risk means and where the category of
operational risk fits into the overall picture. Finally, it describes some of the high profile events that have
served to highlight the critical need to understand and manage operational risk effectively.

2. WHAT IS RISK?

2.1 OPENING COMMENTS


Operational risk has existed since man first started ‘producing things’ (manufacture) and ‘determining
the best way to make things’ (design). From that moment there was always the possibility, or chance,
that an unexpected result would ensue.

This consequence of ‘something going wrong’ can be critical. Manufacturers know this fact and,
consequently, have always placed a high priority on product safety and systems reliability. The
aerospace, civil engineering and chemical processing industries are prime examples.

The need to understand why something might go wrong and then to try to prevent the possibility
of occurrence is, therefore, a fundamental requirement for any industry. For instance, for an
airline operator, an aircraft crash in service will have some profound consequences. The five major
consequences are:

• loss of passenger/aircrew lives;


• financial loss arising from destruction of the aircraft;
• consequential financial loss arising from litigation;
• loss of passenger confidence and reduction in future airline travel leading to a fall in revenues;
• damage to reputation.

For these reasons, all airline operators expend a great deal of time, effort and money on ensuring
adequate safety standards by maintaining rigorous air frame and engine maintenance, adequate aircrew
training, established safety procedures and general compliance with all relevant industry standards. As
you will realise, the same approach has been adopted by many other industries and activities. Think of
the importance in the modern world of health and safety regulations, inspection and enforcement.

Operational Risk 3
Risk Basics Chapter One

These steps represent some of the mitigating activities necessary to reduce operating risks experienced
in the airline business. Even so, things can go wrong, as the case study below illustrates.

CASE STUDY – HEATHROW JUMBO – SO NEAR DISASTER


Extract from the Evening Standard, dated 12 June 2001

“A British Airways jumbo jet came within 200 feet of landing on a British Midland Airbus at Heathrow
in one of the most serious near misses in British aviation history.

Hundreds of passengers came close to disaster because of ‘inappropriate’ actions by the air traffic
controller overseeing the operation on 28 April last year, an official report revealed today. The report
will make alarming reading for the hundreds of thousands of people using the airport as the summer
holiday season gets under way.

The BA jet was just 118 feet above ground level when it pulled out of the landing manoeuvre –
probably travelling at around 150mph – to avoid the Airbus as it prepared to take off from the same
runway.

The Airbus crew was ‘startled to see an aircraft flying directly above them, along the runway centre
line and approximately 200 feet above them’.

A 28-year-old trainee air traffic controller, a third of the way through her course, was controlling the
operation, the Air Accident Investigation Branch special report revealed. However, it was a series of
mistakes by her supervisor that were instrumental in the ‘very dangerous’ incident.”

There are direct parallels with the approach to operational risk in the financial services industry. Here,
loss generally occurs in the form of money or reputation and, to prevent this, firms put
risk control procedures in place. Financial services regulators, like airline regulators, set minimum
standards and then police them to ensure that firms are doing enough to protect their clients’ interests.

Historically, financial institutions have concentrated on market and credit risk as a means of
understanding their exposure to loss. However, following a number of high profile losses due to
operational failures, the industry has been increasingly focused on the measurement and management
of operational risk as well.

An appropriate starting point for understanding the subject is to review the commonly used risk terms
and definitions employed by the financial services industry.

4 Operational Risk
Risk Basics Chapter One

2.2 GENERAL RISK DEFINITION


LEARNING OBJECTIVES
1.1.1 Know the following major risk categories: credit risk; market risk;
operational risk; liquidity risk

The Concise Oxford Dictionary defines risk as:

“The chance or possibility of damages, loss, injury or other adverse consequences.”

The essential points to note when applying this definition to risk management are:

• Chance - this is the ‘chance’ or ‘probability’ of an event happening in the future. The event has not
yet happened – it exists as one of a number of possible outcomes that may occur in the future. This
is important because it suggests that people can take action today that may reduce the chance of
the event occurring in the future.
• Adverse consequences - the potential outcome is regarded as negative. It is a potential
occurrence that people are trying to avoid. This is also called the downside of risk.

It is generally accepted that there are three main categories of risk in the financial services industry.

Credit risk relates to lending or agreeing to trade with another counterparty. Will the other
counterparty pay or deliver the asset they have undertaken to deliver on the due date? Traditionally,
the primary risk for financial institutions has been credit risk or the potential for loss that results from
lending. Institutions accept credit risk in order to earn revenue. They lend to firms with a higher risk
because of the potential for higher returns.

Market risk is manifested by exposure to the uncertain market value of a portfolio. For example, a
trader may hold a portfolio of securities or other commodities. They know what their market value is
today, but are uncertain as to what their market value will be a week from today. Therefore the trader
faces market risk. Market risk represents the potential risk of loss of earnings or capital arising from a
reduction in the value of financial instruments. In simple terms, an investor is exposed to market risk as
soon as a financial product is purchased. This is intrinsic in all markets and across all products.

Although there are other descriptions, the definition of operational risk, which is widely accepted
today is: ‘The risk of loss resulting from inadequate or failed internal processes, people and systems or from
external events’. This is the formal definition which has been drawn up by the Basel Committee on
Banking Supervision.

In practical terms, operational risk addresses the risk of things going wrong with the day-to-day
operating activities of the firm, which then results in financial loss.

Liquidity risk is the risk that a bank or other financial institution may not be able to close out a position
because the market is illiquid in some way. For example, there may not be enough buyers of stock
when an institution is wishing to sell some stock.

Operational Risk 5
Risk Basics Chapter One

2.3 RISK MANAGEMENT


LEARNING OBJECTIVES
1.1.2 Understand simple examples of risk in the financial services industry

The financial services industry has become increasingly aware of the importance of managing risk. For
financial services institutions, this may involve credit risk, market risk or operational risk. For financial
services regulators, it has come to mean adopting risk-based supervision. For banks in particular, the
measurement and control of capital risk has become a key issue.

Traditionally, credit risk from lending was the primary risk of banks. As financial institutions
entered new markets and traded new products, other risks such as market risk began to occupy
management’s attention. In the last few decades financial institutions have developed some elegant and
complex tools and methodologies to manage market risk, driven by the huge rewards involved in its
upside. The methods have been modified to allow the modelling of credit risk.

More recently, the importance of operational risk has been acknowledged and it now takes its place as
one of the three fundamental categories of risk that require effective management.

There is, as yet, no single agreed industry standard definition for operational risk. Some common
variations on the Basel Committee definition (given earlier in this section) are:

• The risk that deficiencies in information systems or internal controls will result in unexpected loss.
The risk is associated with human error, system failures and inadequate procedures and controls.
• The risk of loss arising from various types of human or technical error.
• The risk inherent in internal processes.
• The risk to earnings or capital arising from problems with service or product delivery.
• All risks that are not categorised as either credit or market risk.

The common theme to these definitions is that risk exists because of the potential for things to go
wrong. Activities such as the following exist in any financial institution, along with their associated
processes:

• trading and dealing;


• marketing and selling;
• operations;
• legal;
• credit;
• payments and treasury;
• accounting;
• technology, IT and project functions;
• human resources; and
• compliance.

6 Operational Risk
Risk Basics Chapter One

They can affect one or many areas of the firm and can cross departmental boundaries. The main
sources from which deficiencies can originate are:

• information systems;
• internal controls;
• human errors;
• system failures;
• inadequate procedures; and
• external events.

Operational risk management is concerned principally with identifying, measuring and mitigating
deficiencies inherent in the operational workings of a financial institution.

Risk management tries to ensure that the likelihood of risks being realised and the potential impact is
reduced to acceptable levels.

The four important aspects of this description are:

• Implementation - risk management is concerned with taking action to reduce risk levels. It
requires a proactive, or preventive, approach. There is little benefit in the foreknowledge that a
loss-making event may occur if no action is taken to prevent it, or mitigate its consequences.
• A structured process - this means using the result of a planned, ongoing, decision process and
related action programme. This involves identifying, assessing, controlling, monitoring and mitigating
risks where possible. Once implemented, there will be a need for feedback and review of the
process to aid and inform future decision-making.
• Reduces the likelihood - risks can only be reduced – they cannot be eliminated completely
(unless the activity is not undertaken at all). This is linked to the idea of probability. If the future
were certain, there would be no probabilities, only certain outcomes. The best that can be done is
to try to make the future a little more certain and to reduce the chance of negative outcomes.
• Acceptable levels - given that risk cannot be entirely eliminated, effective risk management is
concerned with reducing the chances of misfortune to an acceptable level. This is an extremely
subjective measure. What is meant by ‘acceptable’? Something that is acceptable to one person
or institution may not be acceptable to another. Assessing acceptability means understanding and
balancing the downside of risk with the potential benefits of the upside. Finding agreement at a
firm-wide or industry-wide level and obtaining regulatory consent on the level of acceptability of
risk is a major area of contention when designing risk management strategies.

Operational Risk 7
Risk Basics Chapter One

2.4 MAJOR OPERATIONAL RISK INCIDENTS


LEARNING OBJECTIVES
1.1.3 Understand the operational risk issues associated with major risk
related incidents in the financial services industry, such as: Barings Bank
(1995); Enron (2001); Allied Irish Bank/First Maryland Bank (2002);
National Australia Bank (2004); Nationwide (2007); Société Générale
(2008); Standard Life (2009); UBS (2009)

Historically, financial institutions have concentrated on market and credit risk as a means of managing
their exposure to loss. However, following a number of high-profile losses due to operational failures,
the industry has increasingly been focusing on managing and measuring the risks inherent in their
internal processes. This section summarises well-known operational failures which have highlighted the
need for better understanding and control of operational risk.

• Barings - this was the most high-profile case of the 1990s. Nick Leeson, a trader for Barings Bank,
a long-established, prestigious small British investment bank, generated unnoticed trading losses of
US$1.3 billion on futures markets in Singapore and Osaka. This forced the bankruptcy of Barings
Bank in February 1995. He did this by failing to follow agreed trading strategies and by obscuring
losses from his head office by setting up an unauthorised hidden trading account. Furthermore,
he was allowed the responsibility for trading positions as well as settling his own trades. The
operational risk issues were that:
• Leeson was in charge of both the front office and related support areas of the office;
• major differences in culture existed between the bank’s management and some of its traders;
• the senior management of Barings failed to understand the risks involved in the trading
operation and failed to have the appropriate reporting measures in place in order to measure
their exposure accurately.

• Allied Irish Bank - in February 2002, Allied Irish Bank (AIB) – Ireland’s second-biggest bank –
revealed that it was investigating an apparent currency fraud at its Baltimore-based subsidiary,
Allfirst. It soon became clear that the scale and nature of the losses would make the AIB/Allfirst
story one of the biggest ‘rogue trader’ scandals since Nick Leeson brought down Barings Bank
in 1995. The losses were calculated at US$691million. The operational risk issues were:
• there were serious errors in the bank’s controls environment;
• the trader was able to falsify entries into the bank’s value-at-risk (VaR) control system as
independent checking of his entries into the model was not carried out;
• the internal audit department was under-resourced and inexperienced in foreign exchange
dealing. It did not demonstrate a clear understanding of the risks associated with the business
strategies. Key controls were not tested and other tests were not effective;
• the bank’s head of treasury ignored numerous warning signs of the trader’s activities by not
reviewing sufficiently closely the daily profit and loss (P&L) figures and by not questioning
excessive daily volume figures. He also failed to act upon warnings given by operations and
actually prevented risk specialists from having access to information necessary to fulfil their
work; and
• the risk, operations and internal audit culture was too deferential to the business lines.

8 Operational Risk
Risk Basics Chapter One

• Enron - the collapse of energy giant Enron is the largest bankruptcy in US corporate history.
In a little over 15 years Enron grew into one of the US’s largest companies. It embraced new
technologies, established new methods of trading in energy and was seen as a major corporate
success in the US. However, the apparent success of the company was based on artificially inflated
profits, dubious accounting practices and fraud. The company filed for bankruptcy in December
2001 but, in the three months prior to it, had claimed that its assets were worth almost £62 billion.
The operational risk issues were:
• the mismanagement and mistreatment of shareholders;
• many allegations of fraud by the company’s staff and, in particular, their most senior staff;
• the company’s auditors admitted that they had instructed their employees to shred many Enron
documents, meaning that a lot of evidence was destroyed; and
• Enron’s growth and that of its share price was increasingly dependent on dubious accounting
practices, such as the company making investments and then shifting debt off its books to
theoretically independent partnerships, in return for potential income that provided a buffer
against future losses. Revenue figures were thus greatly over-exaggerated.

• National Australia Bank - in January 2004 the Bank announced substantial losses arising
from currency options trading. The final figure was A$360 million, twice as much as had initially
been reported earlier the same month. It emerged from the official investigation that between
September 2001 and the date of the revelations the value of the currency options portfolio, already
overstated by approximately A$4 million, grew to become hundreds of millions. A group of traders
was responsible. They concealed their losses by booking false transactions and by under- and
over-reporting profits. They exceeded risk limits and falsified positions against a weakening
Australian dollar, which significantly increased the risk exposure of the currency options desk to the
US dollar in late 2003. The traders’ market dealing activities were contrary to the Bank’s strategy.
The operational risk issues were:
• Integrity of people:
– dishonesty of the individuals in the trading group.
• Risk and control framework:
– lack of adequate supervision;
– failure of risk management;
– absence of financial controls;
– gaps in back-office procedures.
• Governance and culture:
– poor quality of risk information available to senior management;
– failures of Audit and Risk committees to investigate and act;
– lack of escalation to senior management;
– the Bank’s culture focused on process rather than understanding issues, taking
responsibility and resolving them.

• Nationwide - the Nationwide Building Society was fined £980,000 in 2007 by the UK Financial
Services Authority (FSA) over security breaches. The fine followed the theft of a laptop from a
Nationwide employee’s home which contained confidential customer data. The FSA found security
was not up to scratch after the man had put details of nearly 11 million customers on his computer.
The FSA also found that the Nationwide did not start an investigation until three weeks after the
theft occurred.

Operational Risk 9
Risk Basics Chapter One

The Nationwide claimed that the information on it could not have been used for identity fraud
as there were no PIN numbers, passwords or account balance information on it. However, it
appeared the laptop may have contained names, addresses and account numbers. As a result, the
building society’s customers had been exposed to the risk of financial crime.
The FSA’s investigation showed that the building society had not known that the laptop contained
any confidential customer information at all. The laptop was stolen from the home of a
long-standing and trusted employee of the Nationwide who needed access to the data. However,
despite reporting the theft of the laptop promptly, he did not tell his employer what was on it.

• Société Générale - on 24 January 2008, the bank announced that a single futures trader at the
bank had fraudulently lost the bank €4.9 billion, the largest such loss in history. The bank did not
name the trader, but other sources identified him as Jérôme Kervial, a relatively junior futures
trader, who allegedly entered into a series of bogus transactions that spiralled out of control amid
volatile markets in 2007 and early 2008. Partly due to the loss, that same day, two credit rating
agencies reduced the bank’s long-term debt ratings.
Executives at the bank said that the trader had acted alone and that he may not have benefited
directly from the fraudulent deals. The bank immediately announced that it would be seeking to
raise €5.5 billion in additional financing. Police raided the bank’s offices and also the apartment of
the trader. The Paris prosecutor’s office confirmed two days later that the trader was not ‘on the
run’ and that he would be questioned at the appropriate time, once a full investigation had taken
place.
There were found to be a number of operational risk issues in this instance, including:
• The fact that the trader had an in-depth knowledge of the control procedures resulting from
his former employment in the middle office (which also included the bank’s compliance
department).
• The trader was therefore able to conceal his dealing positions through a scheme of elaborate
and fictitious transactions.
• The trader used his knowledge of the bank’s control procedures to gain access into its
computers and erase all traces of the alleged fraud.

• Standard Life - standard Life spent £100 million compensating customers in 2009 who had
invested in a supposedly safe cash fund that instead lost money on more exotic products. The
life assurer paid the compensation to customers who saw the value of their pensions drop by an
average of £1,000 in a single day because of the deterioration in value of asset-backed securities in
which one of the company’s funds was heavily invested.
Standard Life had to compensate all 97,000 investors in its Pension Sterling Fund, which dropped
in value by 4.8% in a day, when Standard Life revalued the asset-backed securities that constituted
almost half its holdings.
Standard Life accepted it had not made it sufficiently clear that the fund’s holdings were potentially
subject to this degree of volatility. Standard Life confirmed the Pension Sterling Fund would
continue to operate as it had in the past, though it had made changes to the way the fund is
marketed.

• UBS - the Financial Services Authority (FSA) fined Swiss bank UBS £8 million in 2009 for failing to
stop its employees making unauthorised transactions. The FSA said four UBS employees had carried
out the transactions using customer money on at least 39 accounts. The FSA also said the trades
involved foreign exchange and precious metals.

10 Operational Risk
Risk Basics Chapter One

According to the FSA, an internal UBS investigation found that as many as 50 unauthorised
transactions a day were taking place at the operation’s peak. It criticised the bank not only for
systems failures that led to the trades, but also for not responding to ‘several warning signs’ that the
systems were not working.
The FSA confirmed that these employees were able to take advantage of UBS’ inadequate systems
and controls, giving them free rein to make unauthorised trades with customer money that they
were then able to conceal.

2.5 OPERATIONAL RISK ASPECTS OF THE BANKING


CRISIS OF 2007/09
LEARNING OBJECTIVES
1.1.4 Understand the operational risk aspects of the banking crisis (2007/09)

The US mortgage market default that triggered the global financial crisis around the world in 2007 has
changed the financial landscape drastically. Since that time policy makers have been trying to formulate
solutions to the problems that the financial industry and the global economy is facing.

The sub-prime lending crisis evolved into a full market meltdown. A large number of worldwide major
investment firms and institutions had either collapsed or suffered huge losses. The organisations faced
huge collateral calls based on the decline of the mortgage securities underlying their various credit
default swap protection products for collateralised debt obligations. A number of governments pledged
very large sums of money to support the institutions based in their own countries.

Organisations questioned why audit risk assessments, conventional financial controls and corporate
compliance activities did not reveal the extent of the potential collapse. There was a fundamental failure
to embrace appropriate enterprise risk management behaviours and attributes. Alongside this there
was a failure to develop and reward internal risk competencies. A large number of firms have been
criticised for taking a relatively short-term view to the profits that were being made.

There was an over reliance on the use of financial models and the mistaken assumption that these
models were both reliable and sufficient tools to justify decisions to take risk in the pursuit of profit.

The Financial Services Authority (FSA) is working with firms to promote a more risk-aware enterprise
risk management culture, demonstrate appropriate risk management behaviours, develop internal risk
management competencies and use enterprise risk to influence management decision-making in both
taking and trying to avoid risks.

Markets will need to enter a period of restructuring to take into account the realities of the impact of
the crisis. Bank liquidity is now recognised as being much more important in the banking industry than
in the past, when banks paid insufficient attention to the need to diversify funding sources. The market
participants must become aware of the changing dynamic in the financial industry and adapt their
strategy and approach accordingly.

The G20 summit in London in April 2009 confirmed that governments around the globe would tackle
the problem and take measures to prevent a crisis like this happening again.

Operational Risk 11
Risk Basics Chapter One

END OF CHAPTER QUESTIONS


Think of an answer for each question and refer to the appropriate section for confirmation.

Question Answer Reference

1. What are the four related aspects of risk management? Section 2.3

2. Name two of the high-profile losses that have occurred. Section 2.4

3. What were the operational risk issues involved in the Allied Irish Bank case? Section 2.4

4. What were the operational risk issues involved in the National Australia Bank case? Section 2.4

12 Operational Risk
CHAPTER TWO

OTHER MAJOR RISKS

1. CREDIT RISK 15
2. MEASURING CREDIT RISK 17
3. CREDIT RISK MANAGEMENT AND REPORTING 22
4. THE CREDIT RISK MANAGEMENT FUNCTION 29
5. MARKET RISK 30
6. MEASURING MARKET RISK 32
7. VALUE-AT-RISK (VAR) 33
8. MARKET RISK MANAGEMENT AND REPORTING 36
9. THE MARKET RISK MANAGEMENT FUNCTION 37
10. MARKET RISK REGULATORY REQUIREMENTS 38
11. LIQUIDITY RISK 39
12. MEASURING LIQUIDITY RISK 42
13. LIQUIDITY RISK MANAGEMENT AND REPORTING 43

This syllabus area will provide approximately 6 of the 50 examination questions

Operational Risk 13
Other Major Risks Chapter Two

14 Operational Risk
Other Major Risks Chapter Two

1. CREDIT RISK
LEARNING OBJECTIVES
2.1.1 Know the basic terms used in the subject of credit risk: counterparty
risk; issuer risk

1.1 INTRODUCTION
Traditionally, the primary risk for financial institutions has been credit risk or the potential for loss that
results from lending. Institutions accept credit risk in order to earn revenue. They will also lend to firms
with a higher risk because of the potential for higher returns.

Over the last few decades, companies have expanded rapidly both nationally and globally, markets have
developed, new and complex products have been created and the client base of firms has increased.
This has led to greater opportunities for revenue growth as well as new and increased market and
credit risks that need to be identified, assessed and controlled. As a result, new ways are continually
being developed to offset these risks. Products such as interest rate and currency derivatives have been
created for the purpose of risk management by enabling hedging strategies to be adopted but a side
effect of these products is the creation of yet more risk inherent in using such products themselves.

Understanding credit risk has become a complex subject and its mitigation to acceptable levels is a
major concern for all financial institutions. This chapter introduces the basic methods of measurement
and some common mitigation techniques.

Before considering how credit risk can be managed, the basic question needs asking, ‘What is it?’

1.2 DEFINITION
Credit risk, also sometimes known as default risk, is defined as:

‘The risk of loss caused by the failure of a counterparty to meet its obligations.’

Credit risk affects any firm to which money is owed by way of loan debt or obligation to pay, such
as fees. The firm that has the financial obligation is called an obligor. Credit risk exists in any contract
where one party has an obligation to another, and is present in the trading of all financial instruments.

A counterparty is one of the parties to a transaction – either the buyer or the seller.

Operational Risk 15
Other Major Risks Chapter Two

1.3 TYPES OF CREDIT RISK


LEARNING OBJECTIVES
2.1.2 Be able to apply the concept of credit risk to simple, practical
situations

Credit risk is associated with either on-balance sheet transactions or off-balance sheet
transactions.

On-balance sheet transactions include instruments such as loans and the buying and selling of securities.

Loans carry ‘direct risk’, which is the simple risk of loan default when money is lent to a customer.
Securities carry ‘issuer risk’, which is the risk of default by the issuer on redemption or interest servicing
when one institution or investor holds debt securities (eg, bonds) issued by the issuing institution. Bonds
are long-term forms of debt and thus there is a risk that the issuer will default on its obligations to pay
coupons and repay the principal with regard to the bond. Hence gilts (UK government securities) are
deemed to be less risky than corporate bonds. When considering issuer risk an investor must assess the
likelihood of a default taking place, the severity of such a default and when a default might occur. The
Russian government famously defaulted on payment of interest and bond redemptions in September
1998.

Off-balance sheet transactions involve financial instruments such as securitisation products, forwards
and over-the-counter (OTC) derivatives. One of the main advantages of using off-balance sheet
products is that they are treated differently from a capital adequacy perspective and allow a firm to
reduce its balance sheet liabilities.

Both on- and off-balance sheet transactions can carry pre-settlement risk and settlement risk.

• Pre-settlement risk (PSR) is the risk that an institution defaults prior to the settlement of the
transaction when the traded instrument has a positive economic value to the other party.
• Settlement risk (SR) occurs when there is a non-simultaneous exchange of value (eg, cash for
securities) and one party defaults during the exchange.

16 Operational Risk
Other Major Risks Chapter Two

EXAMPLES OF CREDIT RISK


• A firm makes a loan to a corporate client. Because it is possible that the client will fail to make
timely principal or interest payments, the firm faces direct credit risk.

• Bond investors who lose their investment if the bond issuer fails face issuer credit risk.

• Firm A and Firm B trade an interest swap. If interest rates move in firm A’s favour, firm B will owe
a net obligation. Because firm B could fail to perform on such an obligation, the corporation faces
pre-settlement credit risk.

• An investment company has a forward contract to exchange euros for US dollars with a foreign
firm. On the contract’s maturity date, the investment company makes its euro payment but,
because of time differences, there is a delay in the foreign firm making its corresponding dollar
payment. Given it is possible that the firm will fail to make its payment, the corporation faces
settlement credit risk.

2. MEASURING CREDIT RISK


LEARNING OBJECTIVES
2.2.1 Know the basic techniques for measuring credit risk: credit
exposure management; credit risk premium; credit ratings; modern
measurement techniques

Measuring credit risk involves the use of tools or models to estimate the credit exposure of the lender.
These range from basic crude techniques, such as simply taking the credit exposure as being equal
to the notional values of all transactions, and managing this exposure, to more modern approaches
that measure more precisely the risks inherent in a portfolio. This section explains the following basic
techniques:

• credit exposure;
• credit risk premium;
• credit ratings; and
• modern measurement techniques.

Operational Risk 17
Other Major Risks Chapter Two

2.1 CREDIT EXPOSURE


LEARNING OBJECTIVES
2.1.2 Be able to apply the concept of credit risk to simple, practical
situations
2.2.2 Understand credit exposure

Credit exposure is the amount that can potentially be lost if a debtor defaults on their obligations. It is
used to quantitatively assess the severity of credit risk from:

• counterparties; and
• portfolios.

Credit exposure consists of two parts: current exposure and potential future exposure.

Current exposure is the current obligation outstanding.

Potential future exposure is a calculation of the likely maximum loss in the future. The potential
exposure calculation is usually performed using statistical techniques and forms part of value-at-risk
(VaR) calculations (this is explained in more detail in Chapter 7).

2.2 CREDIT RISK PREMIUM


LEARNING OBJECTIVES
2.2.3 Understand credit risk premium

A credit risk premium is the difference between the interest rate a firm pays when it borrows
and the interest rate on a default-free security, such as a government bond. The premium is the
extra compensation the market or financial institution requires for lending to a firm that has a risk of
defaulting.

As a firm’s credit risk increases, lenders demand a higher credit risk premium through an increase in the
amount of interest paid. This increase is necessary to offset the increased probability that the loan will
not be repaid in accordance with its terms.

There is a strong relationship between credit risk premium and credit rating (see next section). The
higher the rating, the more creditworthy the firm, so the lower the premium. This means that the cost of
borrowing will be lower for a higher-rated firm as a reflection of its lower likelihood to default. As a result,
a downgrade in a company’s credit rating can significantly increase its borrowing costs.

18 Operational Risk
Other Major Risks Chapter Two

2.3 CREDIT RATINGS


LEARNING OBJECTIVES
2.2.4 Understand external credit ratings as a means to measure the
credit-worthiness of a company
2.2.5 Understand the limitations in credit rating agencies’ assessment of a
company

A broad measure of a firm’s credit risk is its external credit rating which is an assessment of its credit
worthiness and financial health. It is used by investors in public issues of debt as a guide to managing
their credit exposure. An independent rating agency will assign a credit rating based on analysis of the
company’s financial statements. This is usually done with a short- and long-term outlook. The services
provided by the credit rating agencies enable investors to rely upon impartial and regularly updated
research which takes into account all the various factors which are necessary in respect of credit risk
assessment.

Different agencies assign different terminologies to their ratings.

For example, Moody’s uses ratings for long-term credit that range from Aaa, representing the highest
quality investments, to C for firms more likely to default.

The leading agencies supplying ratings are:

• Moody’s;
• Standard & Poor’s; and
• Fitch Ratings.

Operational Risk 19
Other Major Risks Chapter Two

Figure 2.1 – Examples of Long-Term Credit Ratings


Moody’s S&P Fitch Ratings Meaning

Aaa AAA AAA • Best quality investment


• Very well protected
Aa AA AA

A A A

Baa BBB BBB • Medium grade


• Not highly protected
Ba BB BB

B B B

Caa CCC CCC • Bonds of poor standing


• Some threat to security
• Often in default
Ca CC CC

C C DDD • Lowest grade


• Poor prospects
DD

Any instrument appearing in the first four rows (ie, including Baa or BBB) are deemed to be investment
grade, the remainder below this level being referred to as non-investment grade. Investment grade
bonds are those that have been judged likely enough to meet their payment obligations.

The credit rating agencies have been subject to some criticisms which have potentially undermined
market confidence in them, including:

• On occasions they have not downgraded companies promptly enough. For example, Enron’s rating
remained at investment grade four days before the company went bankrupt, despite the fact that
the credit rating agencies had been aware of the company’s problems for months (see Chapter 1
for more details on the collapse of Enron).
• Some of the rating agencies have been criticised for having too familiar a relationship with company
management, possibly opening themselves to undue influence or the vulnerability of being misled.
This is implicit in the relationships when the companies being rated are the ones paying fees to the
rating agencies.
• Some credit rating agencies have made errors of judgement in rating some structured products,
particularly in assigning AAA ratings to structured debt, which in a large number of cases has
subsequently been downgraded or defaulted. As part of the Sarbanes-Oxley Act of 2002, the US
Securities Exchange Commission (SEC) was required to produce a report detailing how credit
ratings are used in US regulation and the policy issues this use raises.

Please see Chapter 8 for more details regarding the Sarbanes-Oxley Act of 2002.

20 Operational Risk
Other Major Risks Chapter Two

2.4 MODERN MEASUREMENT TOOLS


LEARNING OBJECTIVES
2.2.6 Understand the basic concepts used by modern credit risk
measurement tools

Modern tools concentrate on measuring the credit risk of a portfolio through the use of mathematical
modelling techniques. These use statistical computer programs that attempt to simulate the complexity
of the real world to measure the probability of default (PD) and calculate the loss, given default
(LGD) from a range of complex potential scenarios. From these calculations, a value-at-risk (VaR)
estimate can be made which makes an estimate of the maximum loss that can occur in a given period of
time. (VaR is explained in more detail in Chapter 7.)

These tools are commercially available to help companies gain an overall view of credit risk across
their entire organisation and product spectrum and have become powerful aids in measuring the credit
exposure of portfolios.

Although they represent significant advances in aiding credit risk management at the portfolio level,
their accuracy generally depends on good quality historical data. If the quality of this data is poor then
confidence in the model’s output is degraded. The quality of data is affected by issues such as:

• The simple lack of availability of data, for instance, for emerging markets.
• Significant economic or political changes in a country, making historical data irrelevant or misleading.
For example, a change in political ideology or the discovery of large reserves of natural resources.
• Major market movements making historical data irrelevant or misleading. For example, the
liberalisation of financial markets in the early 1980s ‘changed the rules’ for the future and disrupted
the established trends.

2.5 LIMITATIONS OF CREDIT RISK MEASUREMENT


LEARNING OBJECTIVES
2.2.7 Understand the main limitations of credit risk measurement tools

Although the science of measuring credit risk using modern measurement techniques and tools has
been developing rapidly in recent years, there are some common assumptions used by both firms
and regulators that can introduce inaccuracies into the risk models and produce inaccurate credit risk
calculations.

Some of the main issues are:

• Using simplified calculations of potential exposure. Generally, the potential exposure of a portfolio
is greater than the current exposure. Institutions may apply charges to account for potential
exposure based on broad categories that oversimplify the different levels of risk. These charges
are stated as percentages of notional amounts but notionals are not always true measures of the
underlying credit risks.

Operational Risk 21
Other Major Risks Chapter Two

• Assuming that some exposures have equal credit risk when the reality is that they do not. For
instance, due to the simple rules applied in the Basel Committee’s original guidelines on capital
adequacy, the risks associated with Korean and German banks were treated as equivalent. The
latest capital adequacy proposal from the Basel Committee relates a firm’s capital more closely to
its true risk.
Note: The Basel Committee is a committee of the Bank for International Settlements, which was
established at the end of 1974, comprising members from Belgium, Canada, France, Germany, Italy,
Japan, Luxembourg, the Netherlands, Spain, Sweden, Switzerland, the United Kingdom and the
United States. Countries are represented by their central bank and also by the authority with formal
responsibility for the prudential supervision of banking business where this is not the central bank.
• The Committee formulates broad supervisory standards and guidelines and recommends
statements of best practice in the expectation that individual authorities will take steps to
implement them through detailed arrangements – statutory or otherwise – which are best suited to
their own national systems.
• A lack of recognition of the time period of credit risk. Default risk increases as the time of exposure
increases. This is sometimes not accounted for.
• A lack of recognition of portfolio diversification. Overall credit risk is significantly reduced by
diversification but measurement calculations may not take this into account.

3. CREDIT RISK MANAGEMENT AND REPORTING


LEARNING OBJECTIVES
2.3.1 Understand the role of the credit risk management function
2.3.2 Understand the following examples of credit risk mitigation: asset
securitisation; central counterparties; clearing houses; collateral;
credit derivatives; credit limits; diversification; loan sales; netting;
underwriting standards

The Credit Risk Management Function


The key objective of the credit risk management function is to maximise an institutions risk adjusted
rate of return by maintaining credit risk exposure within acceptable limits. This is an essential part of
the overall long term success of the organistaion. Institutions should identify, measure, monitor and
control credit risk to ensure that they hold adequate levels of capital to cover these risks and that they
are adequately compensated should these risks occur.

The board of directors should have ultimate responsibility for approving and, at least annually,
reviewing the credit risk strategy and major credit risk policies of the institution. It should then be the
responsibility of the senior management to implement this credit risk strategy.

Mitigating credit risk involves the use of a range of techniques that aim to maintain a firm’s credit
exposure within acceptable parameters. These techniques operate at both the individual level and
portfolio level.

22 Operational Risk
Other Major Risks Chapter Two

3.1 INDIVIDUAL LEVEL


Techniques at the individual level aim to mitigate the credit risk of specific borrowers. These
might involve simple decision-making based upon information derived from risk measurement
(for instance, a decision to charge a higher credit risk premium to a firm with a low credit rating). They
can also be more complex. The common risk mitigation techniques employed by financial institutions
are:

• underwriting standards;
• credit limits;
• netting;
• collateral.

3.1.1 Underwriting Standards


Underwriting standards are the standards that financial institutions apply to borrowers in order to
evaluate their credit-worthiness and, therefore, mitigate the risk of default. Evaluation requires specific
knowledge of their business and includes:

• a review of the borrower’s cash flow and financial statements;


• the consideration of earnings, profit margin and outstanding debt;
• analysis of industry variables such as competitive pressures, product cycles and future growth
potential;
• controlling the terms of the loan, eg, limiting loan size, establishing a repayment schedule and
requiring additional collateral for higher risk loans.

3.1.2 Credit Limits


Credit limits are maximum limits for all aspects of credit exposure, including lending set by financial
institutions to prevent too much borrowing by a particular firm. All financial institutions will set limits of
some description for all borrowers.

Operational Risk 23
Other Major Risks Chapter Two

3.1.3 Netting
LEARNING OBJECTIVES
2.3.4 Be able to calculate a simple example of a cash netting agreement

Netting is the practice whereby two parties that exchange multiple cash flows during a given day agree
bilaterally to net those cash flows to one payment per currency, thereby reducing settlement risk. It
also reduces transaction costs and communication expenses.

Figure 2.2 shows an example of cash netting.

Figure 2.2 – An Example of Cash Netting

Party A

£2m £3m
£4m £1m

£3m
Party C Party B
£6m

The diagram above shows the end-of-day commitments between parties A, B and C.
No netting agreement is in place. If, for instance, party C defaulted on its commitments,
the replacement costs would be £4 million for party A and £6 million for party B.

Party A

£2m £2m

£3m
Party C Party B

The diagram above shows the same commitments but this time a netting agreement
exists between each party. The cash flows shown above reflect the net obligation
between each party. Now if party C defaults, the replacements costs would be only £2
million for party A and £3 million for party B.

24 Operational Risk
Other Major Risks Chapter Two

3.1.4 Collateral
Collateral is an asset held by a lender on behalf of an obligor, under certain agreed conditions,
as security for a loan. It generally takes the form of cash or securities and is used by the lender as
insurance against default. In the event that the obligor defaults, the lender may seize the collateral.
Collateralisation is, therefore, used as a means of reducing credit exposure to a counterparty.

Collateral is used to mitigate credit risk for a variety of transactions such as foreign exchange forwards,
securities lending and derivatives.

A collateral arrangement can be unilateral, bilateral or netted:

• A unilateral arrangement means that one party gives collateral to the other.
• A bilateral arrangement allows for two-sided obligations, such as a swap or foreign exchange
forward. In this situation, both parties may post collateral for the value of their total obligation
to the other.
• A netted arrangement means that the net obligation may be collateralised so that, at any point
in time, the party who is the net obligor posts collateral for just the value of the net obligation.

In a typical arrangement, the collateral is periodically marked-to-market (ie, its present value
is calculated using current market prices/rates), and the amount adjusted to reflect changes in
value. The obligor has to supply additional collateral when the market value has risen, or removes
collateral when it has fallen. An example of this is the use of variation margin in exchange-traded
derivatives markets, when collateral (or margin) calls (demands) are made by the exchange, clearing
house or clearing broker on a daily basis to reflect changes in the market value of the trades.

3.2 PORTFOLIO LEVEL


A portfolio is a collection of investments owned by the same individual or organisation. An efficient or
optimal portfolio either:

• provides the greatest expected return for a given level of risk; or


• provides the lowest risk for a given expected return.

Portfolio management is concerned with optimising market and credit risk inherent in the portfolio
components to maximise returns. Some of the common techniques for mitigating credit risk within a
portfolio are:

• diversification;
• asset securitisation;
• loan sales;
• credit derivatives.

3.2.1 Diversification
Diversification is a means of offsetting risk in a portfolio by spreading it across borrowers in different,
negative correlating industry sectors (ie, industry sectors that have an inverse or opposite relationship to
each other). By doing this, institutions avoid unacceptable concentrations of credit risk.

Operational Risk 25
Other Major Risks Chapter Two

Hence, the earnings of some loans in a portfolio will offset the losses of others, making it less likely that
the institution will lose money overall. By this principle of combining individual loans into a portfolio, it
is possible to reduce overall credit risk.

AN EXAMPLE OF DIVERSIFICATION
An investor is seeking to invest in a British sun cream retail outlet. However, they are concerned
about the seasonal nature of the business and the unpredictability of the weather. In order to reduce
the dependence on one company, they decide to diversify their portfolio and achieve this by investing
in a shop specialising in umbrellas.

The sun cream shop does well on sunny days, while the umbrella shop does well on rainy days.
Although the earnings of each individual business can be volatile, the combined earnings will be less so
because of the inverse relationship, or negative correlation between their earnings.

3.2.2 Asset Securitisation


Asset securitisation is the practice of pooling bonds or loans with credit risk and selling them as a
package to outside investors. This is attractive for the seller because it removes their credit exposure.
It is also attractive for investors because the diversification they can achieve across many loans reduces
their overall credit risk.

3.2.3 Loan Sales


Loan sales is the practice of a firm making a loan to a company and then selling the loan to other
institutions or investors. This strategy is attractive to firms because they earn a fee from the original
loan but the new investor assumes the credit risk. This can be very important if large amounts are
concerned for such purposes as financing takeovers.

3.2.4 Credit Derivatives


Credit Derivatives are a type of specialised over-the-counter (OTC) product that allows credit risk to
be managed by the transfer of credit exposure between parties. They enable credit risk to be managed.
Institutions can use credit derivatives to increase or decrease their credit exposure to a particular
counterparty, for a particular period of time. They are attractive because they allow financial institutions
to:

• mitigate their credit risk more effectively and improve their portfolio diversification by reducing
undesirable credit risk concentrations;
• customise their credit exposure to another party without having a direct relationship with them;
• transfer credit risk without adversely affecting the customer relationship.

Over the last decade these instruments have probably been the most important innovation in the
mitigation of credit risk. However, they can also expose the user to other types of financial risks and
regulatory costs.

Like other OTC products, they are privately negotiated financial contracts. These contracts expose
the user to operational risk, counterparty risk, liquidity risk and legal risk. Controlling these risks is an
essential factor in the future development of this market.

26 Operational Risk
Other Major Risks Chapter Two

Popular examples of credit derivatives include:

• credit default swaps;


• total return swaps; and
• credit linked notes.

Examples of how a credit default swap works are shown below.

Figure 2.3 – Example of a Credit Default Swap (CDS)

A credit default swap (CDS) is a bilateral financial contract in which one counterparty (the
protection buyer) pays a periodic or one-off fee (typically expressed in basis points on
the notional amount) in return for a contingent payment by the other counterparty (the
protection seller) following a credit event of a reference entity. A credit event is commonly
defined as ‘bankruptcy, insolvency, receivership, material adverse restructuring of debt or
failure to meet payment obligations when due’.

Regular or
one-off fee Bonds
Institution Customer
Institution
B C
A
Default Loan
amount

In the diagram above, institution B purchases bonds (the reference asset) from customer C
(the reference entity). B then enters into a credit default swap with institution A, whereby B
pays A a fixed periodic coupon or one-off fee for the life of the swap. In return, if customer
C defaults due to a credit event, A pays B the default amount and the swap then terminates.
This provides B with protection against the possibility of C defaulting on its payments, as A
assumes the credit risk.

EXAMPLE OF A CREDIT DEFAULT SWAP (CDS)


Bank A holds an asset in the form of a loan made to a corporate client. Bank A is concerned that the
corporate client might default on their obligations to service and/or repay the debt, so Bank A enters
into a CDS with another bank, Bank B. In return for a regular payment based on a percentage of the
face value of the loans, Bank B agrees to pay out in the event of the corporate client defaulting.

Bank A is using the CDS to hedge. By buying a CDS, Bank A can manage its credit exposure and
maintain its relationship with the client. Any payout from Bank B will be triggered by prespecified
credit events and will typically be based on the fall in the value of the loan as a result of the event, for
example, the actual default or a credit-rating downgrade by an external credit rating agency.

Operational Risk 27
Other Major Risks Chapter Two

EXTRACT
A letter to CEOs of Regulated Firms from the FSA in February 2005

‘Outstanding Confirmations

Various studies on credit derivatives have clearly illustrated the benefits of credit derivatives and
commented on emerging good practice in individual firms and cross-industry initiatives. However, we
believe that more can be done to reduce operational and settlement risks. The difficulties of back-
office functions keeping pace with the rapidly developing front office trading activity were highlighted
during the Joint Forum’s investigation and the FSA’s soundings of firms confirmed this.

Specifically we are concerned about the level of unsigned confirmations with some transactions
remaining unconfirmed for months. Although we recognise that work undertaken in 2004 is helping
reduce the backlog, levels of unsigned confirmations and master agreements remain relatively high
and raise serious issues for market efficiency and market confidence.

We ask you to consider your firm’s operational processes and risk management frameworks – and the
resourcing of these in relation to credit derivatives – to assess their robustness in this rapidly evolving
market. Confirmations and other documentation should be issued and affirmed promptly after the
transaction has been agreed.’

3.3 CENTRAL COUNTERPARTIES (CCPs) AND CLEARING


HOUSES
The use of a central counterparty (CCP) is a means practised on a great number of exchanges to
reduce credit risk. Futures and options exchanges all over the world have always adopted a central
clearing house system, which is often referred to as a central counterparty these days as the same
approach has been applied to cash equity exchanges and to other markets including energy contracts,
cash bonds and OTC derivatives. The clearing house serving an exchange acts as a central counterparty,
or guarantor of contracts for the market and products concerned. By this means, the clearing house
assumes the credit risk, thereby limiting the exposure of its clearing members by protecting them from
the impact of the default of others. The central counterparty in the UK is [Link] Ltd.

For example, rather than two members of an exchange being involved in a direct
counterparty-to-counterparty contract (and so assuming each other’s credit risk), the clearing house
acts as the central counterparty to each. If one clearing member defaults, the clearing house will
guarantee the performance of the contract to the other member.

In order for clearing houses to be credible in their ability to reduce credit risk, they need to have
significant resources to cope with potential major market default events and scenarios. They obtain
these resources in a variety of ways, such as capital supplied by:

• their members;
• the exchange; or
• other parties that do not have a direct relationship with the economics of their market.

28 Operational Risk
Other Major Risks Chapter Two

For instance, [Link] Ltd (LCH) has a series of sources providing financial backing. The major
tranche of this support, which is next in line after clearing member initial margin cover held, is the
Member Default Fund to which every clearing member contributes in cash (interest bearing) according
to the volume of its clearing activities. This is reviewed and adjusted every three months. In March 2005
this fund stood at £582 million. The fund is fully fungible across the business streams of [Link].
Hence, for example, a member default occurring in swaps clearing is supported by funds provided by
those firms involved in futures or equity clearing.

The next level of support is provided by an insurance policy from a triple A rated American insurer.
[Link] is contemplating the removal of this category at the time of writing but has encountered
a great deal of resistance to this proposal from its member firms.

Because the clearing house takes on the credit risk of all trades, it must manage the risk effectively. This
is done through stringent membership requirements, continuously reviewing existing members and
employing position monitoring and margining.

• Position monitoring is the analysis of an individual member’s exposure risk in relation to their ability
to cover their margin liabilities and delivery obligations. This is performed on an intra-day basis.
• Margining refers to the practice of evaluating the risk to the clearing house of a member’s position
and making collateral calls to insure against the risk of the member’s default (explained previously
in Section 3.1.4). Two types of margin are taken into account by the clearing house when calling for
margin at the start of the day’s trading:
• Initial margin, which reflects the worst-case scenario of a one-day price move on all registered
open positions.
• Variation margin, based upon a mark-to-market calculation at the previous day’s closing prices,
which reflects the profit or loss on all registered open positions.

4. THE CREDIT RISK MANAGEMENT FUNCTION


LEARNING OBJECTIVES
2.3.3 Be able to apply risk mitigation techniques to simple practical situations
2.3.5 Understand the mechanics of a credit default swap in simple practical
situations
2.3.6 Understand the role of reporting and escalation tools of credit risk
management

The credit risk management function is responsible for ensuring that the firm’s credit risk is
satisfactorily managed. This means implementing a sound risk management policy to manage credit risk
in a firm-wide context. This includes:

• performing adequate credit analysis by counterparty, country and sector (this includes the
performance of regulatory know your customer checks as well as assessing creditworthiness);
• ensuring decisions on granting credit are made independent of the trading areas; and
• integrating the credit risk policy with the firm’s general business strategy.

Operational Risk 29
Other Major Risks Chapter Two

Although the information provided by external rating agencies can be useful, it is of limited value to the
needs of a sophisticated credit risk management function. This is because it is often too historic, not
detailed enough to meet the firm’s requirements fully and is not as sensitive to changes as the firm’s
own analysis. As well as performing detailed credit analysis, the responsibilities of this function will
include:

• ensuring the credit policy is adhered to;


• making credit decisions on methods of trading to reduce credit risk (eg, the use of netting);
• setting, monitoring and reviewing credit limits;
• measuring and monitoring daily credit exposure. This will also involve providing information for the
assessment of capital adequacy;
• assessing potential credit risk events;
• reporting and escalating risk issues to senior management, to make them aware and be able to
react to such issues, in order to minimise potential loss to the firm.

5. MARKET RISK
LEARNING OBJECTIVES
2.4.1 Know the basic features of market risk: price level risk; volatility risk;
liquidity risk; basis risk
2.4.2 Be able to apply the basic features of market risk to simple, practical
situations

5.1 INTRODUCTION
One of the major aims of many financial institutions is to make profit by investing in the global financial
markets. This business, by its nature, is based on price uncertainty – the uncertainty of knowing
whether market prices will move in a favourable or adverse direction. Price uncertainty is the
mechanism that allows profit or losses to be made and the risk of loss associated with it is known as
market risk. This risk reflects the uncertainty of an asset’s future price. The factors affecting market risk
are complex. For instance, when investing in a company’s shares there are direct and indirect market
risk factors to consider:

• Direct factors are those that directly reflect the performance of a company, such as the health of
its balance sheet, its vision, the energy and strength of its management team and its policy.
• Indirect factors are those that indirectly affect the performance of a company, such as interest
rate levels, economic events, political and environmental effects. The financial services industry
takes advantage of the existence of market risk to make profit. The aim of managing this risk is
not to eradicate it but to understand it and quantify it. If this is done accurately, then an informed
decision can be made on how acceptable the risk is compared to the firm’s strategic risk
appetite, and whether this investment is worthwhile. The crucial aspect, as with all forms of risk
management, is the confidence in the accuracy of the estimate of the size of risk. As there are vast
profits to be made in getting this right, financial institutions have invested heavily in research, tools
and expertise to try to predict the future performance of their investments.

30 Operational Risk
Other Major Risks Chapter Two

The need to understand this market risk is also important in the pricing of some financial products,
such as futures and options. For these reasons, the methods and tools employed for measuring market
risk have become very advanced, involving cutting-edge mathematical theory and computer processing
technology. This chapter provides a basic understanding of these methods and tools and explains how
they fit into an overall risk management strategy.

5.2 DEFINITION
Market risk can be defined as: ‘The risk of loss of earnings or capital arising from changes in the value of
financial instruments.’ In simple terms, an investor is exposed to market risk as soon as they purchase a
financial product and the value of that product goes down. It is intrinsic in all markets and all products,
such as:

• money market products;


• equities and gilts;
• bonds;
• commodities and energy products;
• interest rate and exchange rate products;
• futures and options; and
• other derivatives.

Different types of market risk will relate to each product.

5.3 TYPES OF MARKET RISK


Market risk can be sub-divided into the following types:

• Price level risk - this is due to the potential for adverse changes in the price of a financial
instrument and includes:
• FX rate or currency risk - this exists due to adverse movements in exchange rates. It affects
any portfolio with cash flows denominated in a currency other than the base currency of the
business.
• Interest rate risk - this exists due to adverse movements in interest rates and will affect fixed
income securities, futures, options and forwards.
• Equity price risk - this exists due to adverse movements in share prices affecting a portfolio.
• Commodity price risk - this is the risk of an adverse price movement in the value of a
commodity.
• Volatility risk - this is the risk of price movements that are more uncertain than usual affecting the
pricing of products. All priced instruments suffer from this form of volatility. This particularly affects
options pricing because if the market is volatile then the pricing of an option is more difficult and
options will become more expensive.
• Liquidity risk - this is the risk of loss through not being able to trade in a market or obtain a price
on a desired product when required. This can occur in a market due to either a lack of supply or
demand or a shortage of market makers. Liquidity risk can also refer to the liquidity of a specific
firm, meaning the risk that it may not be able to meet its obligations when they are due. Loss in this
case can be incurred due to the cost of borrowing or facing contractual penalties and may ultimately
result in insolvency.

Operational Risk 31
Other Major Risks Chapter Two

• Basis risk - this occurs when one kind of risk exposure is offset with another exposure in
an instrument that behaves in a similar, but not identical, manner (ie, hedged). It reflects the
uncertainty of the difference in the impact of the market factors on the prices of the two
instruments. An example of basis risk is the risk when the price of a futures contract varies from
the price of the underlying cash instrument as the expiry date approaches. Measurement of market
risk involves advanced statistical and probability theory and analysis techniques. However, most
conventional methods rely on basic principles, such as distribution analysis.

6. MEASURING MARKET RISK


LEARNING OBJECTIVES
2.5.1 Understand the measures of central values and dispersion: mean;
median; mode; standard deviation; distribution analysis

6.1 DISTRIBUTION ANALYSIS


Distribution analysis is a statistical means of using historical data to predict future events and relies
on an understanding of probability distributions. These are mathematical functions that describe the
probability of possible outcomes. They are depicted as graphs with the ‘probability of occurrence’ on
the vertical axis and the ‘possible outcome’ on the horizontal axis. Many types of distribution are used
for analysis but for the purposes of this workbook, only an understanding of the most common form is
needed, which is called a normal distribution or bell curve, as shown:

Figure 3.1 – Example of a Normal Distribution Curve

Number
of events

1 SD

2 SDs

Mean
1.20 1.50 1.70 1.90 Height
2.10

The curve shows how people’s height varies in a particular population. The mean, or
average, height is assumed to be 1.7 metres, so most people in the population will fall in a
band around this value. A few people are very tall and a few very short. Using this curve
we can make a prediction on how high the next person to be measured will be or what
percentage of people are above or below a certain height. Many other natural events, such
as people’s intelligence (IQ), or a country’s temperature, can be described by this type of
distribution.

32 Operational Risk
Other Major Risks Chapter Two

A normal distribution curve has the following attributes:

• It is continuous. This means that each point on the curve has a real value.
• It is symmetric about its mean (a measure of central value).
• It is defined by its mean and its standard deviation (a measure of dispersion):
• The mean is a measure of the average value of some data, calculated by dividing the sum of all
the values (eg, heights of people) by the total population (eg, total number of people). Other
measures of central value are the median and the mode. The median is the value such that
exactly half of a population is of a greater quantity. If the population has an odd number of
entries, the median is the middle entry after sorting in increasing order. If the list has an even
number of entries, the median is equal to the sum of the two middle numbers after sorting,
divided by two. The mode is the value that has the greatest frequency of occurrence. For
example, from the following list of numbers: 1, 1, 2, 3, 3, 3, 4, 5, 5, 6 the mean is 3.3; the
median is 3 and the mode is 3.
• The standard deviation (SD) is a means of measuring variability, uncertainty or volatility. It
measures the dispersion from the average or mean value. If, for instance, an equity is highly
volatile, it will have a high standard deviation. In finance, investment returns from primary
instruments (but not derivatives), based on market factors, are often assumed to be normally
distributed. By making this assumption, it is possible to create a model that will predict the
future performance of the instrument to a given probability. This probability is also known as
the confidence level. For example, if the mean, historical price of an instrument was £1, we
would be 50% confident that tomorrow’s price would be more than £1. By using a knowledge
of standard deviation we could also calculate what the price would be that would ensure we
had a 95% confidence level that tomorrow’s price would be higher. This means if we bought an
equity, say, at that price, we would be 95% certain that we wouldn’t lose money. This sort of
calculation is useful as a basis for establishing the risk appetite of the firm and limiting loss.

7. VALUE-AT-RISK (VaR)
LEARNING OBJECTIVES
2.6.1 Understand the meaning of VaR and its constituents
2.6.2 Be able to apply VaR to the mitigation of market risk
2.6.3 Understand the meaning of back testing
2.6.4 Understand the meaning of stress testing
2.6.5 Know the limitations of using VaR for market risk management

7.1 DEFINITION OF VaR


The most significant recent development in the measurement of market risk has been the invention of
the value-at-risk (VaR) measure. This is a statistical measure that uses distribution analysis and sensitivity
analysis to determine how much value of a portfolio may be lost given certain market conditions.

Operational Risk 33
Other Major Risks Chapter Two

Value-at-risk can be formally defined as: ‘The maximum loss that can occur with a specified confidence
over a specified period.’ For example, if a portfolio’s one-week VaR is stated as £1 million in 99 weeks
out of 100, then the portfolio is predicted to lose less than £1 million over 99 weeks out of 100. This
estimate would be based upon the portfolio’s current composition and recent market conditions, so it
would not account for potential future changes.

Value-at-risk is a category of risk metrics that describes, in terms of probability, the market risk of a
trading portfolio. VaR is widely used by banks, securities firms, commodity and energy traders and
other trading organisations. Such firms could track their portfolios’ market risk by using historical
volatility as a risk metric. They might do so by calculating the historical volatility of their portfolios’
market value over a rolling look-back period of a given number of trading days. The problem with
doing this is that it would provide a retrospective indication of risk. The historical volatility would
illustrate how risky the portfolio had been over the previous period. It would say nothing about how
much market risk the portfolio was presenting today. For institutions to manage risk, they must know
about risks while they are being taken. If a trader fails to hedge a portfolio correctly, his supervisor
and firm needs to find out before a loss is incurred. VaR gives institutions the ability to do this. Unlike
retrospective risk metrics, such as historical volatility, VaR is prospective. It quantifies market risk while
it is being taken. VaR attempts to measure market risk in an integrated manner, theoretically taking into
account all sources of market risk in a portfolio. It can, however, be difficult to calculate in practice.

7.2 METHODS OF CALCULATING VAR


VaR can be calculated in the following ways:

• Historical simulation - this is the simplest method which uses actual historic returns in the risk
factors to estimate risk exposure in the future. Its advantage is that it is the least controversial,
because it is based on actual data.
• Correlation simulation - this is also known as the variance/co-variance simulation. It calculates the
volatility of each risk factor from historical data and estimates their effect on the portfolio to give an
overall estimate of risk that accounts for all risk factors.

7.3 MODEL RISK


The powerful mathematical models described have been developed as a means of predicting, or
anticipating, future events. This is not a perfect process and the models can break down if the
assumptions that they are based upon are violated. The risk of this happening is called model risk. An
important aspect in the application of these models is to understand the assumptions and test their
accuracy as far as possible. This is achieved by performing back testing and stress testing.

7.4 BACK TESTING


Back testing is the practice of comparing the actual daily trading exposure to the predicted VaR figure.
It is a test of reliability of the VaR methodology and ensures that the approach is of sufficient quality. It
is usually performed on a daily basis by the financial reporting function and if unsatisfactory differences
between reality and estimation are found, the VaR model must be revised.

34 Operational Risk
Other Major Risks Chapter Two

7.5 STRESS TESTING


Stress testing means testing the model against ‘extreme’ market event scenarios. It can be thought
of as emphasising particular risks that may, or may not, have been captured by the VaR calculation.
Stress tests are not designed to generate worst-case results. Stress testing is normally performed by
the financial reporting function and serves to improve the appreciation of market risk. The results can
also be fed back into the VaR model to improve it. There is no standard way of stress testing but the
Bank for International Settlements (BIS) does carry out surveys of common practice in the marketplace.
There is a wide range of stress test practices at banks and securities firms.

The use of stress tests continues to broaden from the exploration of exceptional, but plausible, events
– the traditional focus of stress testing – to cover a much wider range of applications. These include the
exploration of the risk profile of a firm, the allocation of economic capital, the verification of existing
limits, and the evaluation of business risks. The expanded usage of stress testing derives from its wider
acceptance within firms. Aside from its inherent flexibility, it benefits from explicitly linking potential
impacts to specific events. Nonetheless, stress tests continue to focus primarily on traded market
portfolios. These portfolios are well suited to stress testing as they can be marked-to-market on a
regular basis. Stress tests on loan books are conducted less frequently and, quite often, by separate
business units of the firm. Stress testing works as a complement, rather than a supplement, to major
risk management tools such as value-at-risk. It is, therefore, becoming an integral part of the risk
management framework of banks and securities firms.

7.6 LIMITATIONS
Value-at-risk is now recognised as one of the most effective concepts in risk management. However, it
must be closely integrated with the day-to-day market risk management process. Its advantages are:

• it provides a statistical probability of potential loss;


• it can make an assessment of the correlation between different assets;
• it translates all risks in a portfolio into a common standard – that of potential loss, allowing the
quantification of firm-wide, cross-product exposures. Its disadvantages are:
• it does not account for liquidity risk;
• it is dependent on good historical data. For this reason, it is most useful for financial instruments
that have easily available records of market values such as:
• derivative instruments;
• bonds;
• currency instruments.

For areas such as loans and deposits, it is less useful due to the long-term maturities involved. There
are a number of techniques for managing market risk that operate both on the portfolio (micro) and
organisational (macro) levels. To be successful, an integrated approach to market risk must be followed
and an overall risk framework and structure set up. This section describes some of the more common
mitigation techniques and introduces some good practice requirements for an effective framework. The
following mitigation techniques will be explained:

• hedging;
• risk limits;
• diversification.

Operational Risk 35
Other Major Risks Chapter Two

8. MARKET RISK MANAGEMENT AND REPORTING


LEARNING OBJECTIVES
2.7.1 Understand the following techniques for mitigating market risk:
hedging; market risk limits; diversification

8.1 HEDGING
Hedging is a means of reducing the risk of adverse price movements by taking an offsetting position
in a related product. It is a means of insuring against market risk in the same way that a car is insured
against damage and loss. The main financial instruments used in hedging are derivatives, in particular
futures and options. For instance, an investor may buy an equity and is at risk of losing money if the
market declines. This could be hedged by buying a put option. This option gives the buyer the right
to sell the stock at a set price (the strike price) within a particular time in the future. The investor is
now protected against adverse market movements. The decision to hedge is a trade-off between the
risk of adverse movement and the cost of the hedge – in this case the purchase price of the option. It
is, however, difficult to achieve perfect offsetting of the risk because the use of hedging introduces, or
exacerbates, other risks such as basis risk, credit risk and operational risk.

8.2 DIVERSIFICATION
Diversifying a portfolio is a technique for mitigating market risk that uses the same principles as for
credit risk mitigation described in the previous chapter.

8.3 RISK LIMITS


Market risk limits are used as a tool for managing market risk in the same way that credit limits are
applied to protect firms from credit risk. The existence of market risk limits does not assume the
existence of credit limits. These will be established separately, and vice versa. When an organisation
takes a risk, it will often specify the maximum loss that it is prepared to make on a portfolio or
transaction. This is called the market risk limit or stop-loss limit, and may be expressed in terms of
VaR. The effectiveness of risk limits to manage market risk is dependent upon the accuracy of the risk
measurement used to set the limits. The potential problems of using over-simplified risk measurement
are:

• Risk limits usually have to be inflated in order to accommodate the errors and uncertainty in the
measurement. This adversely affects the potential profit of the firm.
• Traders or other investment professionals may exploit the inaccuracy of risk measurement and take
risks that they know the measurement does not account for. Providing that high-quality risk data
is used, risk limits can be very effective. While investment professionals sometimes see them as
restrictive they can also be viewed as empowering because they set the risk appetite of the firm and
represent explicit authority to take specified levels of risk.

36 Operational Risk
Other Major Risks Chapter Two

9. THE MARKET RISK MANAGEMENT FUNCTION


LEARNING OBJECTIVES
2.7.2 Understand the role of the market risk management function
2.7.3 Know good practice for an effective market risk management function:
VaR limit setting, monitoring and reporting; scenario analysis and stress
tests for large market movements; position limit setting, monitoring
and reporting; pre-transaction analysis and approval

Market risk relates to the loss of earnings or capital arising from changes in the value of financial
instruments and is covered more fully in this chapter.

In the same way that institutions employ a credit risk management function to manage credit risk, it is
also essential that they develop and implement an independent market risk management framework
to manage market risk in a firm-wide context and then to make sure that there is adequate reporting.
This also includes implementing a firm-wide policy with clear roles and responsibilities. A good practice
framework for market risk will include:

• a clearly defined market risk management policy;


• proactive management involvement in market risk issues;
• defined escalation procedures to deal with rising levels of trading loss, which include market risk
limits;
• VaR as a common measure of market risk exposure and for it to be adequately reported;
• an independent daily monitoring and reporting function of risk utilisation through the daily
production of P&L accounts and review of front office closing prices (independent means a
separately accountable function reporting directly to senior management);
• independent validation of market pricing and adequacy of VaR models.
• analysing a range of different scenarios for large or extreme market movements and see what effect
they have, the results can be fed back into the VaR model;
• considering implementing position limits to reduce market risk.

Operational Risk 37
Other Major Risks Chapter Two

10. MARKET RISK REGULATORY REQUIREMENTS


LEARNING OBJECTIVES
2.8.1 Understand the capital adequacy requirements in relation to market
risk: confidence levels; 10 day holding period; not less than 250 days
historic data

10.1 REGULATORY REQUIREMENTS


As with credit risk, the Basel Capital Accord has heavily influenced market risk management practices.
For market risk in the trading portfolio, financial institutions must reserve capital in the balance sheet as
laid down in the Capital Adequacy Directive (in the EU) according to a capital requirement calculation
based on their open position exposure. The Directive allows banks to use their own VaR models for
calculating the market risk exposure, providing they pass a review process and are officially recognised.
The objective of the review process is to ensure integrity and consistency in the market risk calculation.
The basic standards demanded by the Directive are:

• The VaR estimate must be to a 99% confidence.


• Losses must be calculated on the basis of a 10-day holding period.
• Historic data must cover a minimum period of 250 days.

Firms that do not pass the review process are liable to increased capital requirements. In order to
introduce these measures, the Basel Accord of 1988 was amended in 1996 to respond to the industry’s
request to allow banks to use proprietary in-house models for measuring market risks as an alternative
to a standardised measurement framework, as had been originally put forward in April 1993. In order
to ensure a minimum degree of prudence, transparency and consistency of capital requirements across
banks, the Basel Committee proposed a number of quantitative and qualitative criteria for those banks
which wish to use proprietary models. The committee made decisions following comments received
on their proposals and defined the quantitative criteria that would then govern the use of proprietary
models for determining capital charges. These required that VaR be computed daily, using a 99th
percentile, single confidence interval; that a minimum price shock equivalent to 10 trading days (holding
period) be used; and that the model should incorporate a minimum historical observation period of 250
days. The capital charge for a bank that used a proprietary model would be the higher of:

• the previous day’s VaR;


• three times the average of the daily VaR of the preceding 60 business days.

There is an updated set of regulatory requirements for insurance firms that operate in the EU, called
Solvency II. These rules are very similar to the Basel II rules that apply to banks.

38 Operational Risk
Other Major Risks Chapter Two

11. LIQUIDITY RISK


LEARNING OBJECTIVES
2.9.1 Know the basic terms used in the subject of liquidity risk: asset and
liability management; maturity ladders; actual and contractual cash
receipts; asset liquidity risk; funding liquidity risk

11.1 INTRODUCTION
Liquidity risk is the risk that an institution will not be able to meet its liabilities as they become due
because of an inability to liquidate assets or obtain enough funding or that it cannot easily unwind or
offset specific exposures without significantly lowering market prices because of inadequate market
depth or market disruptions.

A method of helping improve liquidity for an organisation is to invest in a range of securities that have
varying maturity dates, also referred to as a maturity ladder. This ensures regular cash flows in terms
of both income and capital maturing. These cash flows can be matched against the liabilities of the firm,
ensuring that the cash to be received is greater than the liabilities due.

Some cash receipts from investments will be contractual ie a pre-determined fixed amount of income
will be received on a set date. Other cash receipts may be actual ie will be linked to the performance
level of a suitable index. Firms will need to balance the types of cash being received in order to meet
future liabilities as they fall due.

Asset liquidity risk is when an asset cannot be sold due to lack of liquidity in the market – essentially a
sub-set of market risk. This can be accounted for by:

• widening bid/offer spread;


• making explicit liquidity reserves;
• lengthening holding period for VaR calculations.

Funding liquidity risk is when liabilities cannot be met when they fall due or can only be met at an
uneconomic price or can be name-specific or systemic.

Operational Risk 39
Other Major Risks Chapter Two

11.2 THE APPLICATION OF LIQUIDITY RISK


LEARNING OBJECTIVES
2.9.2 Be able to apply the concept of liquidity risk to simple, practical
situations

In September 2007, Northern Rock suffered from the crystallisation of liquidity risk due to the sub-
prime crisis. The bank was over-exposed to the sub-prime mortgage sector and suffered from short-
term liquidity issues despite being solvent at the time. The UK government gave huge amounts of
financial assistance to provide sufficient levels of liquidity to Northern Rock. The bank in this case was
unable to meet its various liabilities with the assets that it had available. In response the FSA now places
greater supervisory focus on liquidity risk especially with regard to high-impact retail firms.

11.3 IMPLICATIONS OF BORROWING AND LENDING


LEARNING OBJECTIVES
2.9.3 Understand the implications of lending long and borrowing short

Some institutions may wish to borrow funds on a long-term basis, therefore committing themselves
to a regular repayment of capital and interest on the borrowing. This regular payment may fluctuate
if the interest rate being charged is variable or it may be fixed at the outset. The institution may also
wish to lend out monies to clients on a short-term basis. Hopefully, the interest payments received
on the short-term loans will be greater than those paid out on the long-term borrowing, therefore
representing profit to the organisation. However, if some of the clients borrowing on a short-term
basis default on their repayments, the institution may not have the available cash to meet the regular
repayments on its long-term borrowing. This causes liquidity issues for the organisation.

The main risk associated with stock lending and borrowing relates to when a party to the transaction
defaults on their obligations. For example the collateral given in return for the stock may not be of
sufficient value to cover the lending or may not actually be handed over at all. This means that the stock
lending institution is exposed to the full amount of the stock lent.

40 Operational Risk
Other Major Risks Chapter Two

11.4 BANKS’ USE OF FUNDING INSTRUMENTS TO


PROVIDE LIQUIDITY
LEARNING OBJECTIVES
2.9.4 Understand why banks use basic funding instruments to provide
liquidity

Banks will use a range of funding instruments to ensure that they do not have liquidity issues. Banks
will typically invest in securities that have a range of maturities; short, medium and long and also yields
or returns. They will balance their ongoing liabilities with the maturity profiles of their investments to
ensure liquidity. For example, banks will be large investors in government bonds and corporate bonds
that provide a suitable range of maturities and a certain level of income.

11.5 THE INTERBANK LENDING PROCESS


LEARNING OBJECTIVES
2.9.5 Understand the interbank lending process and the concept and
mechanism for using the lender of last resort (central banks)

In order to help meet liquidity funding levels, banks will borrow and lend unsecured funds from other
banks in the wholesale money markets. In the UK the interbank interest rates for borrowing are linked
to the London Interbank Offered Rate (LIBOR). This rate fluctuates daily and is calculated by Thomson
Reuters. Money market instruments include Treasury Bills and Certificates of Deposit (CDs). CDs are
issued with maturities typically between one day and one year. A bank will borrow funds on a
short-term basis from another bank using CDs and after a pre-agreed period of time will repay the
capital borrowed together with a pre-agreed amount of interest.

If a bank is experiencing financial difficulties or has taken on too much risk and is near to collapse it may
approach a reserve financial institution that secures banks or eligible institutions, as a last resort. This
will usually be the central bank of a country, known as the lender of last resort, for example, the Bank
of England in the UK.

Operational Risk 41
Other Major Risks Chapter Two

12. MEASURING LIQUIDITY RISK


LEARNING OBJECTIVES
2.10.1 Know the key measures of asset liquidity risk: bid-offer spread; market
depth; immediacy; resilience
2.10.2 Know the key measures for funding liquidity risk: yield curve ratios;
interest rate swaps

12.1 HOW INSTITUTIONS MEASURE ASSET LIQUIDITY


RISK
12.1.1 Bid-Offer Spread
The bid-offer spread is used by market participants as an asset liquidity measure. The bid price is the
price at which the institution will buy an asset and the offer price is the price at which the institution
will sell an asset. To compare different products the ratio of the spread to the product’s mid price can
be used. The smaller the ratio, the more liquid the asset is. This spread comprises operational costs,
administrative and processing costs, as well as the compensation required for the possibility of trading
with a more informed trader.

12.1.2 Market Depth


This is the amount of an asset that can be bought and sold at various bid-ask spreads. Slippage is related
to the concept of market depth. An institution needs to consider the effect of executing a large order
on the market and to adjust the bid-ask spread accordingly. The institution will need to calculate the
liquidity cost as the difference between the execution price and the initial execution price.

12.1.3 Immediacy
This refers to the time needed to successfully trade a certain amount of an asset at a prescribed cost.

12.1.4 Resilience
This is the speed with which prices return to former levels after a large transaction. Unlike the other
measures, resilience can only be determined over a period of time.

12.2 FUNDING LIQUIDITY RISK


Funding liquidity risk is the risk that a firm will not be able to meet its current and future cash flow
and collateral needs, both expected and unexpected, without materially affecting its daily operations
or overall financial condition. Financial firms are especially sensitive to funding liquidity risk since debt
maturity transformation (for example, funding longer-term loans or asset purchases with shorter-term
deposits or debt obligations) is one of their key business areas. Firms may achieve this by using key
measures such as yield curve ratio analysis and interest rate swaps.

42 Operational Risk
Other Major Risks Chapter Two

Financial firms can meet their liquidity needs through several sources, ranging from existing assets to
debt obligations and equity. The most readily available is operating cash flows arising from interest and
principal payments from existing assets, service fees, and the receipt of funds from various transactions.
For example, active management of the timing and maturity of firms’ asset and liability cash flows
can enhance liquidity. In addition, firms may sell assets that are near-term cash equivalents, such as
government securities. This is typically done on a contingency basis to meet unexpected cash needs,
and such liquidity reserves must be actively managed, since the assets must be unencumbered (that
is, not pledged as collateral for any other transaction) and easy to liquidate under potentially adverse
market conditions.

13. LIQUIDITY RISK MANAGEMENT AND


REPORTING
LEARNING OBJECTIVES
2.11.1 Understand the following techniques of liquidity risk management:
asset and liability management; liquidity limits; scenario analysis and
stress testing; liquidity at risk; diversification; behavioural analysis
2.11.2 Understand the role of the liquidity risk management function

13.1 HOW INSTITUTIONS MANAGE ASSET LIQUIDITY


RISK
13.1.1 Asset and Liability Management
The types of assets that an institution holds will have to be sufficiently liquid in order to meet its various
liabilities, as we have seen earlier. The type, value and maturity of these assets will have to be closely
managed to ensure sufficient levels of liquidity are maintained. The firm must have robust internal
controls in place to monitor this.

13.1.2 Liquidity Limits


Liquidity risk tolerances or limits should be appropriate for the complexity and liquidity risk profile of
the institution and should employ both quantitative targets and qualitative guidelines.

13.1.3 Scenario Analysis-Based and Stress Testing-Based Contingency


Plans
Contingency funding plans should include events that could rapidly affect an institution’s liquidity,
including a sudden inability to securitise assets, tightening of collateral requirements or other restrictive
terms associated with secured borrowings, or the loss of a large depositor or counterparty. The
liquidity at risk concept is an example of scenario analysis-based and stress testing-based liquidity risk
management.

Operational Risk 43
Other Major Risks Chapter Two

13.1.4 Liquidity at Risk


The liquidity at risk position takes into account a range of possible outcomes for relevant financial
variables (exchange rates, commodity prices, credit spreads, etc). It might be possible to express a
standard in terms of the probabilities of different outcomes. For example, an acceptable debt structure
could have an average maturity, averaged over estimated distributions for relevant financial variables, in
excess of a certain limit.

13.1.5 Diversification of Liquidity Providers


If several liquidity providers are on call then, if any of those providers increases its costs of supplying
liquidity, the impact of this is reduced. If a company appears to be in a sound financial position, it may
wish to establish durable, always available liquidity lines of credit. The credit issuer should have an
appropriately high credit rating to increase the chances that the resources will be there when needed.

13.1.6 Behavioural Analysis


Institutions will have to come to their own conclusion based on their appetite for risk and, in particular,
the balance they wish to strike between cost and certainty, in deciding how and in what form they keep
its assets to meet their various liabilities.

13.2 THE LIQUIDITY RISK MANAGEMENT FUNCTION


Managing liquidity is a fundamental component in the safe and sound management of all financial
institutions. Sound liquidity management involves prudently managing assets and liabilities both as
to cash flow and concentration, to ensure that cash inflows have an appropriate relationship to cash
outflows. The liquidity risk management function will carry out and monitor all aspects of the liquidity
profile of the institution to ensure an appropriate level of liquidity is maintained.

44 Operational Risk
Other Major Risks Chapter Two

END OF CHAPTER QUESTIONS


Think of an answer for each question and refer to the appropriate section for confirmation.

Question Answer Reference

1. What is the definition of credit risk? Section 1.2

2. What is the difference between pre-settlement and settlement risk? Section 1.3

3. What is the difference between credit exposure and credit risk premium? Sections 2.1
& 2.2

4. Name three credit rating agencies. Section 2.3

5. What does LGD stand for? Section 2.4

6. What is the definition of potential exposure? Section 2.5

7. What are four assumptions that can produce inaccurate credit risk calculations? Section 2.5

8. What are the five techniques used for mitigating individual credit risk? Section 3.1

9. The following end-of-day commitments exist between four counterparties:

A owes B £2m
B owes C £7m
C owes D £3m
D owes A £1m
B owes D £2m
A owes D £4m
D owes C £2m
C owes B £4m
B owes A £5m
D owes B £2m
What is the credit risk exposure for B:
• Without netting? (£8m)
• With netting? (£0m) Section 3.1.3

10. How can a collateral agreement be arranged? Section 3.1.4

11. What are the common techniques for managing credit risk within a
portfolio? Section 3.2

12. What three reasons make credit derivatives attractive as a means of


managing credit risk? Section 3.2.4

13. Name three types of credit derivative. Section 3.2.4

Operational Risk 45
Other Major Risks Chapter Two

14. What is the main reason for the existence of a central counterparty (CCP)? Section 3.3

15. What is the definition of market risk? Section 5.2

16. What are the four main types of market risk? Section 5.3

17. What are the attributes of a normal distribution (bell) curve? Section 6.1

18. What is the difference between mean, median and mode? Section 6.1

19. What is the definition of value-at-risk (VaR)? Section 7.1

20. What are the two methods of calculating VaR? Section 7.2

21. Why is it important to stress test VaR models? Section 7.5

22. What are the advantages and disadvantages of using VaR models to
assess market risk? Section 7.6

23. What is hedging? Section 8.1

24. Give three examples of good practice for a market risk management
function. Section 9.1

25. What are the EU standards demanded of a VaR model in order for it to
pass the regulatory review process? Section 10.1

26. What is liquidity risk? Section 11.1

27. Name four ways that asset liquidity risk can be measured. Section 12.1

46 Operational Risk
CHAPTER THREE

THE NATURE OF OPERATIONAL


RISK
1. INTRODUCTION 49
2. CORPORATE CULTURE 50
3. OPERATIONAL RISK POLICY 54
4. THE OPERATIONAL RISK MANAGEMENT PROCESS 57
5. RISK IDENTIFICATION 59
6. RISK ASSESSMENT AND MEASUREMENT 63
7. RISK MONITORING AND REPORTING 73
8. RISK MITIGATION 74
9. PRACTICAL CONSTRAINTS OF IMPLEMENTING AN 79
OPERATIONAL RISK MANAGEMENT FRAMEWORK
10. REGULATORY CAPITAL REQUIREMENTS 80

This syllabus area will provide approximately 18 of the 50 examination questions

Operational Risk 47
The Nature of Operational Risk Chapter Three

48 Operational Risk
The Nature of Operational Risk Chapter Three

1. INTRODUCTION
Over the last decade or so the full impact of the effects of operational risk has begun to be appreciated
in the financial services industry. This is mainly due to the increase in recent years of major loss events
that have seriously affected corporate profitability and reputation (see Chapter 1). As a result, the
effective management of these risks has become a major priority for senior management, regulators
and customers. This change in thinking in the industry has led to the need for a rigorous and structured
approach to understanding, identifying, measuring, mitigating and monitoring operational risk.

This chapter first looks at how the concept of operational risk has been developed and driven by the
international regulators. It then introduces cultural and leadership issues to highlight the importance of
developing a favourable environment for risk management.

Next, a generic, practical framework for managing operational risk is explained. Finally, the ‘chain of
events’ is introduced. This describes the root causes of risk and their knock-on events that lead to the
ultimate effect of financial loss to the firm. This chain of events is shown in Figure 3.1.

Figure 3.1 – The Chain of Events of Operational Risk

Root Cause Events Effects

1.1 DEFINITION
LEARNING OBJECTIVES
3.1.1 Know the basic Bank for International Settlements’ definition of
operational risk

The Bank for International Settlements (BIS) defines operational risk as:

“The risk of loss resulting from inadequate or failed internal processes, people and systems or from external
events.”

In practical terms this may involve the risk of things going wrong with the day-to-day processing
activities of the firm, which then result in loss.

The Bank for International Settlements is referred to further in Chapter 8 of this workbook.

Operational Risk 49
The Nature of Operational Risk Chapter Three

1.2 BASEL II – OPERATIONAL RISK CATEGORIES


LEARNING OBJECTIVES
3.1.2 Know the Basel II operational risk categories

Basel II incorporated, for the first time, a detailed categorisation of operational risk, including credit and
market risk and, in particular, it provided a breakdown of the specific risk categories that give rise to
operational risk exposure. These categories are as follows:

• Internal fraud – examples include employee theft or insider trading on an employee’s own
account.
• External fraud – examples include robbery, forgery, computer hacking and denial of service
attacks.
• Employment practices and workplace safety – examples include violation of employee health
and safety rules and discrimination claims.
• Clients, products and business practices – examples include misuse of confidential information
and money laundering.
• Damage to physical assets – examples include loss or damage to physical assets from natural
disasters or man-made events such as terrorism, war, arson or vandalism.
• Business disruption and system failures – examples include hardware, software and
telecommunications outages, utility failure and problems with real estate facilities.
• Execution, delivery and process management – examples include unapproved access to client
accounts and outsourcing vendor disruptions or failures.

Please note that these risk categories are banking focused and, as such, other types of financial
institutions may find it difficult to solely use this list to provide them with meaningful risk analysis.

2. CORPORATE CULTURE

2.1 WHAT IS A CORPORATE CULTURE?


Culture is to a firm what personality is to an individual. An organisation’s culture is its identity. It is the
collective norms and values of its employees.

Culture can be loosely defined as ‘the way we do things around here’. While it reflects the collective
beliefs and traditions of the workforce, it is strongly influenced by a firm’s leadership. This is because
people naturally take their lead from their superiors. For instance, if senior managers are seen to have
an appetite to take risks, then they will most likely attract individuals who like to take risks, so that the
culture will also be one of risk-taking.

Firms will also aim to have high levels of governance in place in order to operate efficiently and
effectively. All relevant staff need to be aware of the firm’s attitude to governance and must be fully
trained in how this governance is being implemented by their firm.

50 Operational Risk
The Nature of Operational Risk Chapter Three

2.2 RELEVANCE TO OPERATIONAL RISK


A risk culture means that the firm’s employees possess a common understanding and awareness of
what risk is, where it occurs and how it can be managed. A certain amount of risk in different forms
may be tolerated by the firm as part of its day-to-day operational activities. They will also understand
the nature or extent of risk which the firm will and will not tolerate. This awareness must form part
of the firm’s beliefs and values. Developing and maintaining the right culture and attitude towards risk
is a hugely influential factor in the risk management process and the effectiveness of risk management
policies and actions. Without a favourable culture, a firm can never be fully confident that it is managing
its risk properly.

If risk consciousness is not part of the culture then the culture needs to be changed. This can be difficult
because it is a reflection of the people that make it up. People tend not to be entirely rational in their
thought processes and actions, as the less tangible effects of emotion, habits, principles, ethos and ego
all play a part in their decision-making. As a result, there can be a resistance to change.

Operational risk due to cultural issues has a large intangible element to it. The cause-effect relationship
is often not obvious, which makes managing it more of a perceptual issue than a logical one. Some of
the main issues that impact the risk culture are:

• quality and integrity of staff;


• extent of change the organisation is going through;
• effectiveness of the control environment;
• reward practices.

2.3 LEADERSHIP
One of the key roles of senior management is to position a firm’s culture so that it best supports the
business objectives. This can also be seen as adapting the strategy and objectives of the organisation
to best fit the prevailing culture. Either view requires senior managers to be effective leaders and to
understand how leadership can affect a firm’s operational risk and prevailing culture.

Leadership is viewed as one of the most significant drivers of culture. How organisational leaders
behave and interact with employees is critical in the fostering of a favourable risk culture. Research has
shown that leadership is as much a skill as it is a personality trait and, as such, styles can be adapted to
meet the demands of a particular situation. Effective leaders will deliberately alter their style depending
on the situation. This requires both a sensitivity to the requirements of the business (and its culture)
and an understanding of their own leadership abilities.

If the risk environment is relatively stable and predictable, and there is a well-established,
risk-aware culture, then one style of leadership is appropriate. If, however, there is a high pace of
change, and an immature risk environment, another style is appropriate.

Leaders, therefore, need to be aware of their organisation’s position and what strategies they must
adopt to create the most effective environment.

Operational Risk 51
The Nature of Operational Risk Chapter Three

2.4 THE ROLE OF SENIOR MANAGEMENT


Financial regulators including the FSA state that the Board of Directors will be accountable for the
effectiveness of the risk management processes. Their responsibilities regarding operational risk
management will be to:

• be aware of major operational risks;


• approve and review the operational risk framework;
• ensure the operational risk framework is audited by independent, trained and competent staff; and
• ensure a segregation of duties between internal audit and operational risk management.

Senior management will have the responsibility for:

• implementing the operational risk framework;


• developing effective policies, processes and procedures;
• ensuring consistency across the organisation; and
• ensuring all staff understand their responsibilities.

2.5 CREATING A ROBUST RISK AND CONTROL CULTURE


LEARNING OBJECTIVES
3.2.1 Understand the importance of effective leadership in sustaining a
robust risk and control culture
3.2.2 Understand the role of senior management in promoting an effective
risk and control culture
3.2.3 Understand the importance of appropriate personnel management,
incentivisation and compensation schemes in the context of the
operational risk environment
3.2.4 Know the main factors determining a firm’s risk and control culture:
governance; risk appetite/risk tolerance; transparency; education;
communication
3.2.5 Know the actions required and structures necessary to ensure a
continuing robust risk and control culture
3.2.6 Understand the contribution of the risk officers in continuing a robust
risk and control culture

Good risk processes and planning are worth nothing without the commitment and energy of a
motivated, effective workforce. Equally, weaknesses in risk processes and systems can be offset by
vigilant, expert staff. So the need for a robust culture in the effective management of operational risk
cannot be overstated. Creating, instilling and communicating this culture is, as has been explained,
largely the role of senior management and the leadership levels of a firm. The firms risk officers play
a significant part in continuing a robust risk and control culture. As well as appropriate and adaptive
leadership a robust risk culture will depend on the ability of the organisation to develop positive
attributes in the following areas:

52 Operational Risk
The Nature of Operational Risk Chapter Three

2.5.1 Personal Responsibility


A high degree of personal responsibility and empowerment gives individuals the freedom to take
appropriate risks within the control and accepted risk appetite of the firm. Encouraging risk-taking by
the right people at the right time is essential to a firm’s success. The key is to know when and how
much risk should be taken.

2.5.2 Motivation
Motivation is a psychological phenomenon that relates to the amount of effort, care and commitment
that people put into a task. People’s levels of motivation are recognised as being a key factor in
improving their performance. Examples of factors that motivate people are the interest, challenge
and rewards of their job. Also incentive schemes and compensation initiatives help to keep staff
motivated. Motivation also depends on limiting the negative effect of ‘hygiene factors’ such as poor pay,
working conditions and management style. If jobs and careers can be designed to unlock an individual’s
motivation, a more positive risk culture will result and organisational performance will be enhanced.

2.5.3 Morale
Excellent morale is related to how positively staff view their organisation, working conditions, outlook
and leaders. It is linked closely to motivation and commitment.

2.5.4 Integrity
Firms need staff with high integrity who have pride in their performance, are professional in their
approach and demonstrate high levels of honesty. A lack of integrity (perceived or otherwise) can cause
significant damage to a firm’s reputation. The quality of integrity is instilled into the culture through the
words and actions of its leaders and senior managers.

2.5.5 Appropriate Environment


An appropriate environment for managing operational risk encourages staff to challenge the status quo
and question why things are done. This includes healthy levels of positive conflict and competition and
means the absence of a blame culture so that people do not feel intimidated or persecuted if they make
mistakes or challenge accepted norms or report problems and losses.

2.5.6 Continuous Improvement


Continuous improvement is an attitude of mind where people constantly look for ways of doing things
better, challenge the status quo and take personal responsibility for being more effective and efficient.
It also involves the continuous measurement of performance against targets. A deep commitment to
continuous improvement supports the process of good risk management where measurement is key.

2.5.7 Collective Awareness


A collective ‘conscience’ about risk is the idea of a ‘risk-aware’ organisation where staff are comfortable
with the language and ideas behind risk management. Everyone becomes their own mini risk manager
and the organisation promotes a good risk attitude through training, reward and recognition.

Operational Risk 53
The Nature of Operational Risk Chapter Three

2.5.8 Managing Change


An ability to absorb and adapt to change at all levels of the organisation is essential. Managing change is
one of the most difficult aspects of maintaining a controlled environment. Introducing new processes,
procedures and technology to cope with changing business conditions creates uncertainty which can
have a major adverse impact on organisational culture and the control environment.

2.5.9 Expertise
The technical ability and experience of staff is a major factor in perceiving and anticipating risks. High
quality staff with high levels of expertise provide confidence that business is being conducted to high
standards.

3. OPERATIONAL RISK POLICY


LEARNING OBJECTIVES
3.4.1 Understand the following areas addressed by an operational risk
policy: need for sponsorship; need for identification of key officers;
need for cross-divisional involvement and agreement; need to define
clear roles and responsibilities; need to define and communicate the
risk management framework; need for segregation of duties; need
for consistency of approach firm-wide; need for co-ordination; need
to establish acceptable risk levels; need to define and communicate
control standards framework

The operational risk policy is the document which outlines a firm’s strategy, methodology and
objectives for operational risk management. It is also where the boundary between other risk areas,
such as market and credit risk, is clarified. In order to meet the prime objectives of operational risk
management the risk policy should address the following areas:

• sponsorship;
• identification of key officers;
• roles and responsibilities;
• definition and communication of the risk management framework and explicitly the firm’s risk
methodology;
• cross-divisional involvement and agreement;
• consistency of approach firm-wide;
• co-ordination;
• segregation of duties.

3.1 SPONSORSHIP
The policy and approach should be agreed and sponsored at board level. As it is firm-wide and often
requires significant cultural change, it must have the full and continued support of senior management if
it is to succeed.

54 Operational Risk
The Nature of Operational Risk Chapter Three

3.2 IDENTIFYING KEY OFFICERS


It is important for firms to identify and empower those individuals who are given the key responsibilities
of managing the operational risk function. Key risk officers are the people in the organisation that
manage operational risk. Line managers within the independent operational risk management function
will be key officers, responsible for monitoring and reporting to the board, senior business managers,
audit committee, the group risk management function (responsible for the firm’s overall financial risk)
and, via senior management, to regulators.

Key risk officers may also be designated from within the business itself. If ownership of operational
risk issues is assigned to the department or business process where they originate, then the relevant
line manager will often be made responsible for risk management. For this reason, managers may
have direct reporting lines through their own business lines and dotted lines into the risk management
function.

3.3 ROLES AND RESPONSIBILITIES


The policy should provide clear responsibility and accountability for risk management at all levels. Staff
throughout the organisation need to know precisely what is expected of them and why. If they are
accountable for managing risk then they also require the necessary control and authority to be able to
take action and implement risk reduction plans. The risk policy should include clear lines of authority,
identify key risk officers to carry out prescribed actions, and define specific roles and responsibilities.
The risk policy should also make clear the consequences of non-compliance for staff not observing the
policy.

3.4 CROSS-DIVISIONAL INVOLVEMENT AND


AGREEMENT
The plan should promote collaboration between functions, departments and divisions as it is becoming
increasingly recognised that many of the key operational risks occur at the interface between these
boundaries. The cultural tendency of departmentalisation should be addressed and cross-functional
teamwork encouraged through incentives, education and a supportive organisational structure.

Collaboration with other risk management disciplines is becoming ever more important as
understanding of the inter relationship of financial risk increases.

3.5 DEFINE AND COMMUNICATE THE RISK


MANAGEMENT FRAMEWORK
The risk management framework itself is the responsibility of the board of directors to agree and
define. It is then the responsibility of senior management to implement, monitor and report on the
risk management policy and how successfully the firm is adhering to the policy. Regular reviews of the
policy are needed to ensure that the success criteria remain valid and relevant. The policy must be
communicated to all relevant staff and they should be made aware of the implications of not following
the firm’s risk management policy.

Operational Risk 55
The Nature of Operational Risk Chapter Three

3.6 CONSISTENCY OF FIRM-WIDE APPROACH


A coherent, consistent and comprehensive approach should be defined that will provide a ‘road map’
to move the organisation from what might be a fragmented, non-strategic attitude to operational
risk management to a more comprehensive, global and firm-wide methodology, and a common risk
language throughout the firm. The approach lays out the framework or rules of engagement under
which the firm will operate. This must be in unison with and support the overall business strategy. This
means (see Figure 3.2):

• employing a methodology that identifies and categorises all the operational risks that exist in the
organisation;
• employing a methodology for measuring and assessing the significance of all the identified risks;
• working with line managers to agree the mitigating action required to reduce the risk exposure to
acceptable levels;
• monitoring the effects of the mitigating action to ensure its success;
• reporting and escalating risk issues to all appropriate levels of the organisation. This ensures that
there is transparency and aids the decision-making process.

In practice, the framework described is rarely fixed and standardised immediately. It is more
evolutionary to begin with, and its maturity will reflect the maturity of the organisation with respect to
operational risk management.

The process of developing the approach is therefore cyclical and continuous and can result in
refinements to the risk policy.

Some common factors in developing the approach are:

• the need for centralised control;


• regional differences;
• divisional differences and autonomy; and
• the level of ownership of risk within the business.

The strategy should be consistent throughout the firm. A common operational policy and terminology,
which exists globally and across all functions, allows:

• a meaningful overall capital adequacy assessment to be performed across the organisation;


• objectivity when risk prioritisation needs to be performed; and
• a sense of fairness when rewarding or penalising risk performance.

3.7 CO-ORDINATION
Again, because the risk policy takes a firm-wide approach and cuts across departmental boundaries,
there should be a central, independent risk management role responsible for the co-ordination and
implementation of risk policies and procedures. Depending on the size and type of organisation, this
role may be set up as an independent department. Most large organisations have now developed an
independent operational risk management function that reports into an overall group risk officer.

56 Operational Risk
The Nature of Operational Risk Chapter Three

3.8 SEGREGATION OF DUTIES


In order to effectively control and manage procedures, the firm will need to ensure effective
segregation of duties between the trading and support functions, such as front office, operations,
accounting and risk monitoring.

3.9 ESTABLISH ACCEPTABLE RISK LEVELS


The firm needs to establish acceptable risk levels for all relevant aspects of its business. These individual
risks need to be identified, monitored and reported effectively to ensure the firm does not face
unnecessary levels of risk. Setting a benchmark level of risk also provides a foundation for measuring a
company’s current residual risk exposure.

3.10 DEFINE AND COMMUNICATE A CONTROL


STANDARDS FRAMEWORK
The firm needs to properly define and then communicate an effective control standards framework in
which it will operate in and then monitor this on an ongoing basis.

4. THE OPERATIONAL RISK MANAGEMENT


PROCESS
LEARNING OBJECTIVES
3.3.1 Know the basic terms used in the process of operational risk
management; inherent risk; residual risk
3.3.2 Understand the role of the operational risk management function
3.3.3 Understand the key aims of operational risk management:
identification and assessment of risks; mitigation of risk; reduction of
potential impact and likelihood of occurrence
3.3.4 Know the six stages of the risk management process: policy;
identification; measurement and assessment; mitigation; monitoring;
reporting

Risk management as described in Chapter 1: Risk management tries to ensure that the likelihood of
risks being realised and the potential impact is reduced to acceptable levels.

This means exploiting the business opportunities that risk-taking provides (or the upside) whenever
possible, while at the same time managing the potential loss (or the downside).

Operational Risk 57
The Nature of Operational Risk Chapter Three

The main focus within the financial services industry is managing the downside, or the potential loss,
due to operational risk. Practically, the operational risk management function has two key aims:

1. assisting with the effective identification, measurement, assessment and management of operational
risk; and
2. assisting with the reduction or mitigation of the potential impact should the risk occur.

Once the high level risk policy has been agreed, a risk management process must be implemented to
enable the risk management function to achieve its aims. Figure 3.2 describes a typical process, which
includes the following stages:

• policy and appetite;


• identification of risks;
• measurement and assessment of risks;
• mitigation (the reduction of potential risk impact, and the likelihood of any occurrences in the first
place);
• monitoring of risks;
• reporting of risks; and
• planning and change.

The following sections explain each stage and how they interrelate.

Figure 3.2 – The Risk Management Process

Risk Risk
Identification Measurement
and Assessment

Operational
Risk Policy and
Appetite Risk Mitigation
RISK
MANAGEMENT

Risk
Monitoring
Risk
Reporting

58 Operational Risk
The Nature of Operational Risk Chapter Three

Inherent risks are those risks that are impossible to manage or transfer away and relate to the
probability of loss arising out of circumstances or existing in an environment. Residual risk relates to the
exposure to loss remaining after other known risks have been countered, factored in and eliminated.
Residual risk is a product of inherent risk and control risk (ie, the risk that all the controls that the firm
has in place, will not prevent, detect or correct errors) and represents the risks that will always be
present.

5. RISK IDENTIFICATION
LEARNING OBJECTIVES
3.5.1 Understand the purpose of identifying risks

5.1 WHY IDENTIFY RISKS?


The purpose of identifying operational risks is to understand, record and categorise a firm’s operational
risks. By doing this the firm can create a basis for establishing its risk profile and an understanding of the
types of risk it faces and its level of exposure. There is a need to do this in order to:

• provide information to management on which to make decisions and take action to ensure a
controlled environment;
• establish the chain of events relationship of operational risk described in Section 1 (Introduction)
and understand where they occur throughout the firm;
• provide a basis for risk measurement and assessment which may, for example, be used for capital
allocation purposes;
• set boundaries to differentiate between operational risk and other risk types (such as market and
credit) and assign ownership for their mitigation;
• develop a common language for discussing, assessing and managing risk that allows clear and
transparent communication and decision-making.

When identifying risks, a firm needs to consider not only its own processes and systems, but also its
relationships with its clients, the nature of its products and the wider business environment.

Risk identification is the fundamental first step in understanding how operational risk affects the firm,
raising awareness of risk issues and assessing the culture of the organisation.

It can be a difficult exercise due to the diverse nature of risk causes and the difficulty in distinguishing
cause from effect.

Operational Risk 59
The Nature of Operational Risk Chapter Three

5.2 METHODS OF IDENTIFICATION


LEARNING OBJECTIVES
3.5.2 Be able to apply risk categorisation to simple, practical examples:
process; people; technology; environment
3.5.3 Understand the following methods for identifying operational risk: risk
and control self-assessment; reviews and audits; focus workshops; risk
event analysis; management information

Classifying operational risk using common categories is the first step in developing a common risk
language. It also helps to distinguish causes from effects and can be used as a basis for the development
of a risk capture, identification and measurement system.

Different organisations will put a different emphasis on risks and will, therefore, categorise risks in
different ways. It is not important what categories are chosen, providing that they are:

• logical and understood;


• relevant; and
• consistent across the organisation.

For example, a common method is to categorise by the root causes of process, people, technology and
the environment. This method is summarised in Figure 3.3.

60 Operational Risk
The Nature of Operational Risk Chapter Three

Figure 3.3 – Risk Categorisation

Process People Technology Environment


Procedures Role and responsibilities Availability External Companies
Technology

Capacity Authority to act Design Volumes


Volume sensitivity Supervision Security Integration
Controls Escalation procedures System integrity Pace of change
Documentation Accountability System controls Vendors
Delivery mechanisms Human error Testing Catastrophe
Integrity/honesty Denial of Fraud
service attacks
Customer focus Identity theft Competition
Training Viruses Political climate
Communication Capacity
management

Expertise concentration
Culture

Uncertainty
Labour
There are a variety of methods used for the practical capture and identification of risk. Some of the
more common ones are:

• risk and control self-assessment;


• reviews/audits;
• focus workshops;
• historical loss data; and
• management information statistics and key risk indicators (KRIs).

In order to capture the complete risk profile, all of these methods require the involvement and
partnership of risk owners and risk experts. Risk owners include senior management, process and
product heads and the line staff who deal with the risks on a daily basis.

They can be used either individually or in combination and are explained in more detail below.

Operational Risk 61
The Nature of Operational Risk Chapter Three

5.2.1 Risk and Control Self-Assessment


This involves using the expertise of managers and staff to produce a checklist of the risks that the firm
faces and their causes. It usually includes a regular re-assessment of potential risk exposure as part
of the measurement process. This will also take into account the probability and impact of the risk
identified.

Risk and control self-assessments can be based on a silo within a team or department, or can
encompass an entire end-to-end process spanning multiple teams.

5.2.2 Reviews/Risk Audits


This involves a review of an aspect of the organisation from a risk perspective by a risk expert. Risk
experts are analysts trained in operational risk management with the responsibility for monitoring the
risk environment. The risk expert will work together with management and staff in order to produce
a risk profile that can be used in the risk measurement or assessment phase. Reviews can also be
performed on the external risk environment to identify and compare the risks faced by competitors and
other market participants.

A review will typically consider the following:

• clarity of risk ownership;


• adequacy of the existing controls;
• potential impact of losses or control breakdown to the firm; and
• existence of a suitable mechanism for monitoring the risk.

5.2.3 Focus Workshops


Organisations use focus workshops to identify risks and their causes. They are most effective when
organised by process rather than function. By involving all of the functional activities in a process, the
workshops have the ability to:

• engage all of the relevant risk owners at the same time;


• analyse the end-to-end chain of events;
• investigate cross-functional dependencies; and
• raise risk awareness.

5.2.4 Risk Event Analysis


After a particular risk event has occurred within a firm, it can be analysed by key staff to help identify
the reasons for the occurrence and ways in which any further occurrences may be avoided. The firm
may learn more about the way they operate and question their own practices to help them develop
their risk policy further.

5.2.5 Management Information and Key Risk Indicators (KRIs)


This involves identifying a number of process- and non-process-related indicators. These indicators or
statistics can be used by the business to act as early warning signals or forward-looking measures to
alert management to problem areas. See Section 6.2.6 for more details on KRIs.

62 Operational Risk
The Nature of Operational Risk Chapter Three

5.3 THE PRACTICAL PROBLEMS OF RISK


IDENTIFICATION
LEARNING OBJECTIVES
3.5.4 Understand the practical problems of risk identification: changes to
business operating models; changes to business environment; firm
wide engagement

The biggest practical problems with the risk identification phase are:

• the amount of time required to be invested by managers and staff to ensure the compilation of a
good quality, comprehensive risk profile;
• the type of business carried on by the firm, changes to the business operating model and the
particular environment in which it operates;
• any changes associated with the firm wide engagement arising from new markets, products,
systems and regulation that may hinder the identification of risk;
• although it is perhaps more of a measurement factor (and is addressed again later in this chapter),
the lack of good quality, consistent historical data on operational risk available to a firm both
internally and externally does present a practical limitation;
• the lack of robust policies;
• the methods of collecting and compiling a risk profile;
• difficulties in consistently categorising risk data, and issues relating to consistency generally.

6. RISK ASSESSMENT AND MEASUREMENT

6.1 WHY MEASURE RISK?


LEARNING OBJECTIVES
3.6.1 Know the basic terms used in the assessment and measurement of
operational risk
3.6.2 Understand the main reasons for measuring and assessing operational
risk
3.8.1 Understand the main activities that comprise the risk monitoring of the
risk management process: measurement; assessment

Risk assessment and risk measurement are concerned with understanding the likelihood of risks
occurring and their impact on the business in terms of direct or indirect loss. Once an understanding of
the size of a problem has been gained, appropriate action can be taken to address it. The reasons for
measuring and assessing operational risk are to:

• establish a quantitative base line for improving the control environment;


• ensure there is appropriate accountability and responsibility for risk management. By understanding
where risk occurs and measuring how big it is, accountability and responsibility can be assigned to
the people that are in a position to manage it;

Operational Risk 63
The Nature of Operational Risk Chapter Three

• provide an incentive for risk management and the development of a risk-aware culture. The
development of the right environment and culture cannot be over-emphasised as a key aspect of
managing operational risk. Measuring risk can powerfully demonstrate the impact of operational risk
issues and help to gain the commitment that is essential for driving cultural change;
• improve management decision-making. By knowing the size of risks they face, managers are in a
position to decide how much risk they wish to take;
• satisfy regulators and shareholders that a firm is adopting a proactive and transparent approach to
risk management; and
• make an assessment of the financial risk exposure that can be used for capital allocation purposes.

Risk assessment is closely linked to risk measurement. It delivers an assessment of risk at a point in time
with appropriate controls in place. Measurement is associated with the use of quantitative techniques to
understand the size of risk such as measuring losses, measuring the frequency and impact of risk events
and making statistical predictions. Assessment has more to do with evaluating measurement data and
estimating the impact on the business. It is especially useful for considering those risks which cannot
be actuarially or statistically measured, given the lack of appropriate data. For instance, a firm’s risk
measurement system might record that the front office trading system is 98.5% reliable. Assessment
would make the judgement as to whether this is acceptable for normal business performance. Put
another way, measurement is objective and assessment is subjective. These terms are closely linked
and are often used interchangeably – both address the question: how big is the problem?

6.2 METHODS OF MEASUREMENT


LEARNING OBJECTIVES
3.6.3 Understand the difficulties involved in measuring operational risk
3.6.11 Be able to apply the following methods of risk assessment and risk
measurement to simple, practical examples: rating and ranking; risk
and control self-assessment; scenario analysis; bottom-up analysis;
benchmarking; key risk indicators; risk event analysis

Quantifying risk in terms of the precise financial impact it has on the business would be the ideal basis
for decision-making. However, the problem with using financial measures and models is supporting
them with accurate, comprehensive data. The acquisition of this data is the most difficult aspect of
measurement due to operational risk’s complex nature and the fact that much of the data is difficult
to derive automatically from the firm’s systems. Objective measurement is difficult because of the
same practical problems explained in the previous section on risk identification. Objectivity is further
complicated by the multi-dependencies between functional areas and processing activities.

For these reasons it is hard to measure and assess operational risk precisely with confidence, so both
qualitative and quantitative methods are commonly used such as:

• rating, ranking and assessing;


• risk and control self-assessment;
• scenario analysis;
• bottom-up approaches;
• benchmarking;
• using risk indicators; and
• risk event data analysis.

64 Operational Risk
The Nature of Operational Risk Chapter Three

6.2.1 Rating, Ranking and Assessing


LEARNING OBJECTIVES
3.6.4 Understand the ranking method of assessing operational risk

From the control perspective, one of the simplest methods of assessing risk is the creation and
application of a rating or ranking hierarchy. This is a method of rating or ranking risks in order of their
importance.

For instance, a firm might decide that the process risk of volume sensitivity is higher than the system
risk of inadequate security, or that a lack of training is worse than the pace of change.

The assessment may be subjective – depending on the experience of the professionals involved, or
objective – being supported by historical data, or both. In either event, the ranking decision depends on
two criteria – the likelihood of the risk being realised and the magnitude of the impact.

• The likelihood of the risk being realised can be represented as a range of probabilities which
correspond to a rating, for example:
Rating

Very Low = less than 1% 1

Low = 1% to 5% 2

Medium = 5% to 10% 3

High = 10% to 20% 4

Very High = Greater than 20% 5

• The magnitude of the impact is the potential loss if the risk is realised. This can be represented as a
monetary range, and also assigned a rating, for example:
Rating

Very Low = £1m to £5m 1

Low = £5m to £20m 2

Medium = £20m to £50m 3

High = £50m to £100m 4

Very High = Greater then £100m 5

Note: The monetary ranges will change depending on the business area being measured and scale of
the firm’s activities.

Operational Risk 65
The Nature of Operational Risk Chapter Three

An overall risk assessment can be made by multiplying together the likelihood or probability and
magnitude of impact ratings to give a crude score which is effective in prioritising risks:

Risk = Likelihood × Magnitude of Impact

If there is good quality historical data available, actual percentages of monetary figures can be used.

Each risk can be plotted on a ranking chart to produce a risk profile as shown in Figure 3.4.

Firms will often perform this process for both inherent and residual risks. Inherent risk assessment
considers likelihood without controls in place while residual risk assessment includes consideration
of the control environment. This procedure allows the effectiveness of controls to be evaluated and
provides an analysis of risk based on:

• existing controls working (residual); and


• existing controls failing (inherent).

Figure 3.4 – A Risk Ranking Chart

Magnitude (£)

Medium Risk High Risk


4

2
Low Risk Medium Risk
1

1 2 3 4 5 Likelihood (%)

A firm which falls into the top right hand box of ‘High Risk’ will, in theory, fail and would, in practice,
not exist for long.

The advantages of rating or ranking are that it:

• provides a simple, powerful method for viewing the range of risks the business faces;
• provides an evaluation of the effectiveness of the control environment;
• focuses management attention on the most important risks;

66 Operational Risk
The Nature of Operational Risk Chapter Three

• can be used with minimal hard data so if historical data is not available, useful subjective
measurement can still be performed;
• can capture a wide range of risk possibilities – from large, strategic risks to everyday, more detailed
issues. For this reason it can be effective at all levels of an organisation;
• can be used to anticipate loss by ranking the potential risks of new situations. This means it is
forward looking as well as backward looking. It is, therefore, a useful method if fundamental
industry changes need to be understood, such as the impact on the control environment of new
ways of working, for example, e-commerce or teleworking;
• encourages a risk-aware culture and a more transparent risk environment. In order to maintain
the risk profiles, a culture of continuous assessment is needed. This encourages line staff and risk
managers to work closely and allows good practice to be adopted more easily
• enables a firm to assess its risk exposure against its defined risk appetite.

Its main disadvantages are that it is subjective, and may present an oversimplified view. All subjective
assessments should be validated by:

• real loss data; and


• an independent party, such as internal audit, a central risk function or peer review.

6.2.2 Risk and Control Self-Assessment


LEARNING OBJECTIVES
3.6.5 Understand the risk and control self-assessment (self-certification)
method of assessing operational risk

Risk and control self-assessment (self-certification) can be used for measurement as an extension
of the risk identification and control process. It generally utilises the ranking approach mentioned
previously. Once a list of risks have been compiled, managers make their own assessment of their
exposure to each risk on a regular basis. Self-assessment as a single method of measurement has
limitations because:

• it can be subjective and possibly open to abuse and manipulation by managers. For this reason, it
should be independently validated; and
• it can be difficult to apply consistently across the various business units and multiple locations that
exist within a global financial institution.

It is more effective when used in conjunction with other methods.

Operational Risk 67
The Nature of Operational Risk Chapter Three

6.2.3 Scenario Analysis


LEARNING OBJECTIVES
3.6.6 Understand the scenario analysis method of assessing operational risk

Scenario analysis is a subjective method of highlighting potential risk issues in order to allow
preventive action to be taken. It uses the experience of business professionals to capture possible
scenarios that have occurred in the past, or may result in loss in the future. By investigating these
scenarios, preventive measures can be taken to reduce their risk of occurrence. It is broadly concerned
with looking at worst case scenarios.

Its advantages are the same as for ranking, while its main disadvantage is that it depends on the
expertise of the professionals involved. If there are gaps in knowledge or experience, then the scenarios
may lack rigour.

6.2.4 Bottom-Up
LEARNING OBJECTIVES
3.6.7 Understand the bottom-up analysis method of assessing operational
risk

The bottom-up measurement approach seeks to analyse the individual risks and adequacy of
controls across the entire business. It is called ‘bottom-up’ because it builds up a detailed profile
of the risks that occur in each area, aggregating them to provide overall measures of exposure for
departments, divisions or the firm as a whole.

It uses the experience of line managers and staff, coupled with loss data as its source of information (see
Section 6.2.7), so the resultant measures contain both qualitative and quantitative elements.

Compiling bottom-up profiles usually involves a combination of the above three methods to produce a
consolidated understanding of the risk exposure. Much of the data will often be collected during a risk
review.

Its advantages are:

• it addresses risk and control issues at the process level, thus complementing the role of line
managers;
• accountability and responsibility for risk management can be clearly defined. The owner or manager
of a process is usually made accountable for managing the risks it contains;
• it encourages a risk-aware culture and a more transparent environment;
• it encourages a continuous improvement approach to risk management. As risks are identified and
assessed, mitigation action can be taken immediately if necessary. This means that improvements to
the control environment can be made quickly in the short-term;
• it improves the quality of management information;
• it allows a cross-section of staff to give a balanced view.

68 Operational Risk
The Nature of Operational Risk Chapter Three

Its disadvantages are:

• it takes time to implement. The assessment of all operational risks requires a detailed understanding
of how a firm’s processes work and what its weaknesses are. Documenting this can be a lengthy
exercise;
• the continuing maintenance of firm risk profiles is often a major undertaking. This is exacerbated in
a high-change environment where profiles may change continuously;
• it can be influenced by senior managers if not properly managed.

6.2.5 Benchmarking
LEARNING OBJECTIVES
3.6.8 Understand the benchmarking method of measuring operational risk

Benchmarking involves comparing loss data and measures of operational risk with competitors and
other firms in the industry. This allows the firm to establish how effectively they manage risk compared
with their peer group.

The advantages of benchmarking are that it:

• allows the firm to make a judgement on what good is. It sets a standard for the industry based on
the best firm;
• makes operational risk more transparent within the industry.
• its disadvantages are that it:
• is difficult to find suitable data sources that compare like with like;
• may be difficult to verify open and honest reporting of risk measures;
• may create a false sense of security for market leaders. Just because a firm ranks highly in their
industry, does not imply that it manages risk effectively – it merely outperforms its competitors in
the risk areas.

6.2.6 Key Risk Indicators (KRIs)


LEARNING OBJECTIVES
3.6.9 Understand the key risk indicators (KRIs) method of measuring
operational risk

By identifying and assessing the severity of risks and properly understanding the cause of the chain of
events, objective measurement criteria can be chosen to measure ongoing risk status. These measures
are called risk indicators. They are a ‘health check’ on the performance of the business and are used
by all functions to ensure that risk is satisfactorily controlled. They usually measure the effects (rather
than the cause) of risk at set control points in the business and act as early warning signals or
forward-looking measures to alert management to problem areas.

Risk indicators can be thought of in terms of process-related indicators (which tend to relate directly
to performance) and non-process indicators (which incorporate other important measures of control,
especially relating to people).

Operational Risk 69
The Nature of Operational Risk Chapter Three

Levels of acceptable risk can be established by attaching limits, or thresholds of acceptability, to the
indicators. These allow the firm to set its risk appetite and give managers the autonomy to make
business decisions within specified boundaries.

Examples of process-related indicators are:

• number of settlement failures occurring over a given time period;


• number of times a trader exceeds agreed credit limits;
• average length of time a confirmation remains unsigned;
• mark-to-market value of transactions with confirmations unsigned;
• number of times funding deadlines are missed in a given time period;
• number and value of cash (nostro) or position (depot) reconciliation breaks over a given time
period;
• number of reconciliation breaks between front office and back office systems over a given time
period;
• value of interest claims incurred over a given time period; and
• volume/number of transactions per head.

Examples of non-process-related indicators are:

• staff turnover;
• percentage of temporary staff to permanent staff;
• amount of overtime;
• percentage of staff with an agreed training plan;
• period of time to review departmental plans;
• response and resolution times to line problems and audit queries; and
• absenteeism.

In summary, the advantages of using indicators are:

• they allow trends to be monitored and can therefore be used to anticipate problems;
• they allow limits of acceptability to be established;
• they provide a basis for objective performance measurement. Performance measurement can
be used to encourage staff to become more risk-aware, especially when performance targets,
expressed in terms of key indicators, are linked to compensation;
• they act as early warning signals to alert management to problem areas.

Their disadvantages are:

• they can be misleading if used in isolation;


• they are generally difficult to obtain automatically.

70 Operational Risk
The Nature of Operational Risk Chapter Three

Case Study – Using Risk Indicators to Measure Operational Risk – Setting Risk
Bands for Cash (Nostro) Breaks

The table below shows how risk bands might be set in practice to assess the risk of
unresolved cash (nostro) breaks. So, for instance:
• risk is considered to be medium if the total number of unresolved breaks is between
5% and 7% of total volumes;
• risk is considered to be medium if the number of breaks that have remained unresolved
for between 8 and 14 days is between 1% and 1.5% of total volumes;
• risk is considered to be medium if the value of unresolved breaks is between £800
million and £2,000 million.

Assessment Risk Bands


Criteria (Approximate percentage of total volumes)

LOW MEDIUM HIGH


Number of breaks 3% 5% 7%
Ageing 0-7 days 2% 4% 6%
Ageing 8-14 days 0.75% 1% 1.5%
Ageing 15-29 days 0.25% 0.5% 1%
Ageing 30-59 days 0.10% 0.25% 0.5%
Ageing 60+ days 0.05% 0.10% 0.25%
Value £200m £800m £2,000m

6.2.7 Risk Event Data Analysis


LEARNING OBJECTIVES
3.6.10 Understand how risk event data can be used in measuring operational
risk

Risk event data evaluation is important in mapping the actual risk events and losses experienced by the
firm back to a sensible categorisation system. Once the data has been collected (from either internal
or external sources) it can then be used in the measurement process, often using benchmarking or
statistical methods.

For instance, a ‘loss distribution’ curve may be created that records the value of all material (direct)
losses in a particular risk category over a time period of, say, three years. By analysing this curve using
similar VaR techniques to those introduced in Chapter 2 on ‘Market Risk’, some prediction of future
losses can be made within specified confidence limits.

Operational Risk 71
The Nature of Operational Risk Chapter Three

A typical loss distribution curve might look like Figure 3.5 below:

Figure 3.5

No. of incidents

Expected Losses
Unexpected Losses

Value of Loss (£)

Expected losses are those that occur with reasonable frequency. They represent known weaknesses,
or sit within the risk appetite of the firm. They must be managed by good process controls and an
effective, continuous risk management process.

The unexpected losses are those low-frequency, high-impact events that can create serious problems.
They are much more difficult to manage on a day-to-day level because they don’t occur often enough
to test the control environment. They are best managed using contingency planning.

The advantage of this measurement method is that it allows the firm to understand the size of losses, in
monetary terms, which can be attributed to particular risks.

Its main disadvantage is that it does not predict unexpected losses very well, due to the lack of data.
Some firms also don’t make allowance for ‘near misses’, ie, potential events that might have caused
serious harm but were detected in time – by luck or judgement. As a result, reporting the results of
historical loss analysis in a way that makes decision-making easier can be difficult. It is also worth noting
that often firms do not always include indirect or ‘soft’ costs, as these are not easily identifiable from
the accounting system or general ledger.

72 Operational Risk
The Nature of Operational Risk Chapter Three

7. RISK MONITORING AND REPORTING

7.1 MONITORING
LEARNING OBJECTIVES
3.8.2 Understand the importance of risk monitoring in the risk management
process

The monitoring and reporting cycle allows the risk management process to be continuous. The
monitoring stage comprises the following activities:

• the establishment and firm-wide adoption of appropriate risk parameters such as risk indicators
(explained in Section 6.2.6 of this chapter) to measure the level of risk;
• an ongoing, continuous process of objective measurement against a pre-agreed risk appetite;
• an independent policing of risk parameters by the firm’s risk managers.

If, as a result of monitoring, risks are found to be unchanged or increasing, then:

• a re-assessment of risk appetite may be required; or


• further mitigating action may be required; or
• the risk policy needs to be reviewed and amended to improve risk management at the strategic
level.

Monitoring is, therefore, an important feedback step that ensures that the risk management process is
effective. Effectiveness is dependent on the ability of the firm to retrieve, collate and, when necessary,
accrue the required information in real time.

7.2 REPORTING
LEARNING OBJECTIVES
3.8.3 Understand the main functions of operational risk reporting to
regulators, clients and internal stakeholders

The Need for Reporting


Risk reporting is the mechanism of communicating the losses, exposure and risks to the right level of
management in the firm. Its functions are to:

• provide transparency of risk status and issues;


• aid communication;
• reduce uncertainty;
• escalate issues and recommendations; and
• allow early, decisive action to address the risk.

Operational Risk 73
The Nature of Operational Risk Chapter Three

It is necessary to report risk internally (across and up the organisation to internal stakeholders) and
externally (to clients, regulators, auditors and analysts). A firm’s risk policy should also include controls
to ensure that the right reports are received by the right people at the right time.

The Audit and Accounting Faculty of the accounting body ICAEW issued guidance to directors
and reporting accountants of service organisations. This guidance is contained in AAF01/06 and
recommends that an internal control report contains a report by the directors and the reporting
accountants of the firm.

SAS70 is the name of a report on the processing of transactions by service firms, where the professional
standards are set up for a service auditor that audits and assesses the internal controls of the service
firm. The initials SAS stand for Statement on Auditing Standard.

8. RISK MITIGATION
LEARNING OBJECTIVES
3.7.1 Understand the use of operational controls in reducing the impact or
likelihood of operational risk
3.7.3 Know the common methods for operational risk mitigation: risk
control or reduction; business continuity and contingency planning;
outsourcing; information and physical security; risk awareness training;
insurance

Once risks have been identified and measured, the firm is in a position to take effective action to
address them. Mitigation means to make less intense or severe and there are four potential mitigation
methods:

• reduce the likelihood of the risk occurring;


• reduce the impact of the risk, should it occur;
• transfer the risk; and
• retain and accept the risk.

74 Operational Risk
The Nature of Operational Risk Chapter Three

8.1 REDUCING THE LIKELIHOOD


LEARNING OBJECTIVES
3.7.1 Understand the use of operational controls in reducing the impact or
likelihood of operational risk
3.7.2 Be able to apply the following methods for reducing operational risk
exposure: reducing the likelihood and the impact; risk avoidance; risk
transfer

The likelihood of operational risk exposure can be reduced through the use of operational risk
controls and therefore the impact of the risks on the firm, should they occur, can hopefully be
minimised. Operational risk controls are activities that are inserted into a process to protect it against
specific operational risks. Controls do not generally add value to processing in direct terms (ie, by
moving the process forward from one state to another), but they can add value in indirect terms by
protecting against error and consequential loss. Risk awareness training for all relevant staff should be
given by the firm to help staff understand the principle of reducing the likelihood of risk occurring and
details of such training being given and attendance should be recorded.

For instance, a procedural control might be set up to protect against the risk of a member of staff
diverting funds to a personal bank account when making a payment (ie, committing fraud). This
procedure might ensure that one person prepares the documentation to send a payment and another
person physically sends it. This action doesn’t directly make the process any quicker or cheaper (in
fact in might make it slower and more costly) but it is necessary to protect the firm against fraudulent
activity, in order to save money in the longer term. There should be an independent control function
and/or internal system audit trail in place to deter this from happening in practice.

Potential risks should be anticipated and evaluated when the process is first designed and the necessary
controls embedded within it. There are two main types of control – preventive and detective control.

Preventive controls are those that prevent errors occurring in the first place. They attempt to tackle
the root causes of risk and are most effective when incorporated within processes at the outset by
anticipating a risky outcome. Technology solutions are often used as a key means of implementing
preventive controls.

A key preventive control is the segregation of duties. This means the separation of trading, operation
and control, financial reporting and risk management functions. The aim of segregating these functions
is to prevent too much responsibility and authority being concentrated in the hands of specific
individuals. In turn, this prevents the possibility of the internal control structure being compromised and
the risk of fraud arising. The lack of appropriate segregation of duties is one of the major process causes
of operational risk (this was discussed in Sections 2.4 and 3.8).

Operational Risk 75
The Nature of Operational Risk Chapter Three

From the transaction processing perspective, another important area is the maintenance of data
integrity in systems. For instance, the incorrect capture of a transaction’s details in a firm’s systems
due to errors created through manual input. If the process was designed so that the transaction was
captured once at the point of execution and checked and this data then flowed automatically into the
downstream systems, the risk of manual errors would disappear (being replaced by system risks, which
are generally considered to be smaller). This illustrates the benefit of a straight-through processing
(STP) environment.

Other examples of preventive controls are:

• the setting up and ongoing maintenance of good procedures to prevent unauthorised actions and
errors;
• the use of training to reduce the likelihood of human error arising from a lack of expertise;
• the use of well-designed systems to automate processes and controls to eliminate risk due to
human error.

Detective controls detect errors once they have occurred. They can be further split into two sub
categories – internal and external detection:

• Internal detection controls detect errors after they have occurred but before a potential loss is
realised in the outside world, ie, they detect the risk event in order to prevent the effect. Checking
and inspection-type activities fall under this category. For instance, checking the legal terms of a
contract before it is signed is a control that may detect errors in the terms and conditions of the
contract. These errors would then be rectified and the contract sent out at no loss to the firm. If
the control did not exist, the potential for legal risk to be realised would increase.
• External detection controls are those that detect errors and losses once they have been realised,
ie, they detect the effects. Post-settlement checks such as statement-to-ledger reconciliations, fall
under this category. If a problem is found, for instance, if a counterparty has not been paid on time,
loss due to a compensation claim for lost interest will occur. If the detective control is effective,
the problem will be resolved quickly and the loss effect limited. External detective controls are
important because they can limit the direct and indirect losses to the firm. External detective
controls are really concerned with reducing the impact of loss, rather than reducing the likelihood
of loss (because the loss has already occurred). This is discussed in the next section.

8.2 REDUCING THE IMPACT


LEARNING OBJECTIVES
3.7.2 Be able to apply the following methods for reducing operational risk
exposure: reducing the likelihood and the impact; risk avoidance; risk
transfer

If a risk does crystallise, there are a number of ways that the resulting loss to the firm can be reduced.
As stated in the previous section, using detective controls is one method. Other strategies are:

• Diversification strategies - an over-reliance on a particular customer, product or market may


expose the firm to heavier losses than if it operated a more diverse business.

76 Operational Risk
The Nature of Operational Risk Chapter Three

• Risk sharing. By collaborating with other firms, or pursuing joint ventures, it is possible to share
any potential operational losses. Risk sharing differs from risk transfer, an explanation of which
appears below.
• Continuity planning, contingency planning and financial mitigators - in the same way that
financial provisioning provides financial continuity, the ability to anticipate and plan for potential
operational crises reduces the harm of unexpected losses. Continuity or contingency planning
may take the form of disaster recovery, succession planning or the production of other fall-back
procedures to deal with potential crises or threats to the continuity operation of the business. Both
business continuity and business availability are important for management to address. Analysis of
any potential disruption is required, ranging from minor mishaps to major catastrophes. Typical
risks that lend themselves to continuity planning are:
• fire;
• system failure;
• power failure;
• earthquake;
• explosion;
• civil unrest;
• strikes;
• adverse weather conditions.
• Good communication and reporting - having high quality, integrated management information
systems allows information to be shared globally and efficiently. This means that if a risk is realised,
the firm is able to react quickly to reduce its impact.
• Limit setting - market and credit risk limits are also relevant management strategies for
operational risk as exceeding limits can be the first sign of operational errors. Limits can be used
in other ways to reduce the impact of risk, such as setting capital limits on major technology
development or using them as ‘early warning’ signals in process controls (eg, risk indicators).
• Business continuity and contingency planning - this includes emergency response, crisis
management and business resumption planning, covering a whole range of scenarios as identified
by the business. Businesses need to understand the underlying risks and the potential impact of
each type of disaster. A contingency plan needs to be drawn up, maintained, tested and checked
regularly. It is also important to consider the magnitude of the risks which could result in these
impacts. This will help determine which scenarios are most likely to occur, and to which ones
resources should be given at the planning stage.

8.3 RISK AVOIDANCE


LEARNING OBJECTIVES
3.7.2 Be able to apply the following methods for reducing operational risk
exposure: reducing the likelihood and the impact; risk avoidance; risk
transfer

Avoiding risk means either withdrawing from a business because of an unacceptable level of risk, or
deciding not to take on new business, mergers or growth for the same reasons.

Operational Risk 77
The Nature of Operational Risk Chapter Three

8.4 RISK TRANSFER


LEARNING OBJECTIVES
3.7.2 Be able to apply the following methods for reducing operational risk
exposure: reducing the likelihood and the impact; risk avoidance; risk
transfer

Transferring risk can be achieved in a number of ways:

• Outsourcing - if a firm understands the amount of operational risk it carries, it may choose to
outsource aspects of its business to a third party with specific expertise in managing certain risk
and who will carry the risk exposure for a fee. This option of risk management is gaining popularity
with financial institutions; however, it is important to remember that a firm only transforms the risk
from, say, direct process risk to managing the quality of the outsourced process. A risk still exists.
On the other hand, some firms also actively take on risk from others, as seen in insourcing business.
• Insurance - for instance:
• covers the event of loss due to fire, theft, risk of non-payment of monies owed, losses when
they occur, loss of profits;
• provides potential balance sheet protection; and
• smoothes income flows for the business.

A firm needs to know, when taking out insurance, what the insurance will pay out for and when it will
pay out.

• Information and physical security - the operational risks associated with information and
physical security can be reduced by firms making adequate and suitable arrangements for
safeguarding them. The level to which this can be done depends on the amount, type and value of
the things that need to be safeguarded.
• Financial reserves - these need to be kept in a form that ensures that they are sufficiently liquid,
so that they can be accessed at short notice and without delay, in any crisis situation.

While risk transfer can be attractive to businesses seeking to reduce their direct financial losses and
capital adequacy costs, it does not address the reputational impact. The indirect costs of operational
losses incurred by an insurer or third party will most likely still have to be borne by the firm. Similarly, a
firm cannot outsource its regulatory responsibilities.

8.5 RETAIN AND ACCEPT THE RISK


If a firm is satisfied that its identification and measurement systems are rigorous and effective, and that
it has a good understanding of its risks, it may decide to retain a certain level of risk. In other words, a
degree of risk exposure is acceptable in return for higher profit.

78 Operational Risk
The Nature of Operational Risk Chapter Three

9. PRACTICAL CONSTRAINTS OF IMPLEMENTING


AN OPERATIONAL RISK MANAGEMENT
FRAMEWORK
LEARNING OBJECTIVES
3.6.12 Understand the practical constraints of implementing an operational
risk management framework

Understanding the constituents of a risk management framework is one thing – implementing it


successfully is another. Picking up on some of the themes that have been discussed so far in this chapter
as a summary, some of the practical constraints of implementation are:

• Data collection and management constraints - in practice, it is very difficult to build a truly
comprehensive data set – apart from the general lack of data, system constraints and a lack
of standardisation mean that the required data feeds from disparate sources cannot be easily
developed. There is also relatively little availability of industry-wide data, as this depends on firms
‘self reporting’ and, by definition, it is not straightforward to gain an understanding of high-impact,
low-frequency events. Firms may also not be allowed to report for legal disclosure reasons.
• Cultural constraints - operational risk managers used to find that building momentum and
demand for operational risk practices across the business was a constant struggle, but this is no
longer the case as firms are capturing data more frequently. Business heads need to be convinced
of the value that operational risk management (ORM) will bring. If not implemented in a well
structured manner it is often seen as a cost to the business, and even a nuisance, rather than a
real asset. Consequently, many firms have rolled out risk management frameworks little by little –
attempting to gain the confidence and support of one area before moving on to another.
• Resource and cost constraints - firms continually underestimate the amount of time and
resources required to implement identification and measurement systems. In an era of tight cost
controls, resource constraints put a limit on how quickly or comprehensively implementation is
carried out.
• Indicator constraints - it can be difficult to design risk indicators that monitor the full range
of risks. There is a natural tendency to use indicators that are already available (such as existing
management information) but these are often designed to monitor performance rather than risk.
The extra cost and time required to design and maintain a truly comprehensive set of risk indicators
is often prohibitive.

Operational Risk 79
The Nature of Operational Risk Chapter Three

10. REGULATORY CAPITAL REQUIREMENTS

10.1 THE NEW ACCORD – BASEL II


LEARNING OBJECTIVES
3.9.2 Understand the main operational risk features of the Basel II Accord

This Accord has evolved to satisfy the changing risk landscape and to safeguard institutions’ solvency.
It is primarily aimed at making the capital charge for credit more risk-sensitive, and it also includes a
framework for calculating a capital charge for operational risk. It recognises that the way banks assess
and manage their risk is now far more sophisticated. As a result, financial risk exposure (market, credit
and operational) can be assessed and provisioned for far more accurately. It, therefore, allows:

• a greater emphasis on firms’ internal processes for managing and controlling risk, supervisory
reviews and market discipline;
• a greater flexibility towards risk measurement by presenting a menu of approaches (rather than the
single ‘one size fits all’ measure of the 1988 Accord). This flexibility is reflected in the provision of
incentives for better risk management;
• a greater risk-sensitivity so that capital requirements are more closely aligned to a firm’s risks.

A significant innovation of the revised framework is the greater use of assessments of risk provided by
the banks’ internal systems as inputs to capital calculations.

The New Accord is known as Basel II.

The new Accord forms the basis for the new EU Capital Requirement Directive (CRD) which provides
the basis for new national ‘rulebooks’ for all firms in the EU. Hence in the UK the FSA implemented
the Basel II Accord via the CRD. Finalised handbook changes appeared towards the end of 2006 with
full implementation (other than for the advanced approaches) from 1 January 2007. The advanced
approaches were implemented from 1 January 2008.

The global implementation of the Basel II Accord began at the end of December 2006 (country
timetables varied), with full international implementation probably continuing well beyond. The new
capital rules will apply to all financial institutions, not just banks.

The process to reach the agreed framework in June 2004 took many turns among the world’s leading
banks and their regulators. Its form has been amended since its early stages. The revised Basel Capital
Framework aims to make the requirements which apply to internationally active banks (wholesale and
retail) more risk-sensitive and representative of modern risk management practices.

80 Operational Risk
The Nature of Operational Risk Chapter Three

10.2 THE THREE PILLARS


LEARNING OBJECTIVES
3.9.3 Understand the Pillar 1 requirements under Basel II
3.9.4 Understand the Pillar 2 requirements under Basel II
3.9.5 Understand the Pillar 3 requirements under Basel II

The New Accord is structured on three pillars. These are:

• Pillar 1 - a minimum capital requirement. Capital adequacy is measured as:


Capital Ratio = Capital Requirement
(Credit risk exposure + Market risk exposure + OR exposure)
The minimum overall capital ratio remains eight per cent but the methods of measuring market,
credit and operational risk exposure are now more elaborate (these are described in more detail in
the following section).
• Pillar 2 - The supervisory review process (not a measurement). This pillar requires supervisors to
ensure that each bank has sound internal processes to assess capital adequacy based on a thorough
evaluation of its risks. The importance of institutions developing their own processes is stressed,
together with the need for appropriate targets for capital that are in line with the firm’s risk profile
and control environment. It is worth noting that an unsatisfactory review can result in an immediate
additional capital charge, and/or force changes in senior management responsibilities. For the first
time the Accord provides guidance for the independent review of a firm’s operational risk and its
management. Recommendations include reviewing:
• its framework and processes for determining its operational risk capital charge;
• the effectiveness of its risk management process;
• the effectiveness of its monitoring and reporting systems;
• its procedures to ensure the timely resolution of risk events; and
• the effectiveness of its ‘action’ strategies for managing risk.
• Pillar 3 - Market discipline (not a measurement). This pillar aims to tighten market discipline by
requiring greater public disclosure to allow more transparency of banks’ risk profiles and the capital
adequacy of their positions.

Operational Risk 81
The Nature of Operational Risk Chapter Three

10.3 PILLAR 1 EXPLAINED


LEARNING OBJECTIVES
3.9.6 Understand the three measurement approaches for operational risk
under Basel II: Basic Indicator Approach; Standardised Approach;
Advanced Measurement Approach (AMA)
3.9.7 Be able to apply the Basic Indicator and Standardised approaches to
simple, practical examples

Pillar 1 breaks up regulatory capital into three parts, to match credit risk, market risk and operational
risk. The market risk element, dealing with trading losses, is unchanged from Basel 1, which was
amended for this purpose in 1997. The operational risk part is new – it says that banks’ capital
should reflect the risk of mistakes and wrongdoing. An example might be a fine levied on a bank for
overcharging its credit card customers.

From the operational risk perspective, Pillar 1 requires a more detailed explanation. It lays down a new
means of measurement acceptable to international regulators. In seeking to provide common standards,
it outlines three different measurement approaches for calculating risk exposure. These are as follows:

1. The basic indicator approach.


2. The standardised approach.
3. The advanced measurement approaches (AMA).

The complexity of approach increases from the basic indicator approach through to the advanced
measurement approaches.

10.3.1 The Basic Indicator Approach


As the name implies, this is the most basic approach and requires a bank to hold a fixed percentage
(denoted ‘alpha’) of its gross income as operational risk capital. This fixed percentage is set by the Basel
Committee at a level of 15%.

It is anticipated that smaller, domestic institutions that do not possess sophisticated risk management
tools and techniques will use the basic indicator approach.

10.3.2 The Standardised Approach


This approach is more refined than the basic indicator approach because it divides a firm’s activities into
a number of standardised business lines, allowing different risk profiles to be allocated to each. This is
intended to provide a more representative reflection of an organisation’s overall operational risk profile.

Like the basic indicator approach, it uses gross income as a broad indicator that reflects the scale of
business operations within each business line and, therefore, the likely scale of operational risk.

82 Operational Risk
The Nature of Operational Risk Chapter Three

It splits a firm’s gross income between eight defined business lines and then multiplies this by a factor
(denoted ‘beta’) specific to each business line to produce the amount required to be held as operational
risk capital for that particular business. The overall amount of operational risk capital is then the sum of
all these calculations. The relationship between business unit and indicator is shown in Figure 3.6.

Figure 3.6 – The Standard Approach

Business Unit Business Line Indicator Factor

Investment Banking Corporate Finance Gross Income beta 1 = 18%

Trading and Sales Gross Income beta 2 = 18%

Banking Retail Banking Gross Income beta 3 = 12%

Commercial Banking Gross Income beta 4 = 15%

Payment & Settlement Gross Income beta 5 = 18%

Agency Services Gross Income beta 6 = 15%

Others Retail Brokerage Gross Income beta 7 = 12%

Asset Management Gross Income beta 8 = 12%

So, for example, for the corporate finance (CF) business line:

Required capital for CF = Gross income for CF x beta factor

The different factors reflect the assumed riskiness of each business and range from 12% to 18%.

The standardised approach relies on indicators and factors set by the regulators and recognises that
many institutions do not yet have sufficient loss data and analytical risk processes to calculate their
own capital charge. It provides a basis for moving towards a more sophisticated methodology and
encourages better operational risk management.

In order to qualify to use this approach, a firm must meet the following criteria:

• Its board of directors and senior management must be actively involved in the oversight of the
operational risk management framework.
• It must have an operational risk management system that is conceptually sound and implemented
with integrity.
• It must have sufficient resources to staff its approach within its business lines, control and audit
areas.
• Internationally active banks must have clear responsibilities assigned to an operational risk
management (ORM) function. This function should be responsible for managing the process.
• It must perform systematic tracking of operational risk data, including losses by business line.
• It must use an effective risk reporting system.
• It must have an independent, well-documented risk management and control process (see the next
section for a description of the operational risk function).

Operational Risk 83
The Nature of Operational Risk Chapter Three

• It must conduct regular internal audits of the operational risk process.


• It must develop criteria for mapping current business lines to the standardised framework.

Note that the EU Capital Requirements Directive is less prescriptive than Basel.

10.3.3 The Advanced Measurement Approaches (AMA)


Advanced measurement approaches (AMA) are the most risk-sensitive of the three approaches. They
allow banks to use their own internal measurement system and loss data as a basis for calculating the
capital charge. The primary motive for a firm to move from the standardised approach to the AMA is to
reduce its capital allocation requirement which rewards more sophisticated risk management.

The AMA can cover a range of measurement techniques, usually VaR-based, providing that the
regulators approve them. Approval will mean the inclusion of quantitative and qualitative measures. If
qualitative measures are used, they must have an ability to be objectively validated.

10.3.4 Qualifying Criteria for the Advanced Measurement Approaches


(AMA)
In order to qualify to use an advanced measurement approach, regulators require banks to comply with
more stringent criteria than the standardised approach. They list generic, qualitative and quantitative
criteria aimed at ensuring that the bank has satisfactory risk management processes, risk measurement
systems and risk infrastructure in place to be able to use the AMA. In addition to the qualifying criteria
required under the standardised approach, some key quantitative requirements specific to the AMA are
as follows:

• The bank must establish rigorous procedures for the development and validation of risk models.
• The risk measure must incorporate the impact of infrequent, high-impact losses.
• The bank must be able to demonstrate that the risk measure reflects the equivalent of a holding
period of one year and a confidence level of 99.9%. Note that while this confidence limit is
stipulated by the Basel Committee, there are exceptions to its application.
• The bank must develop specific criteria for assigning loss data to specific risk types within business
lines. Examples of these risk types are:
• fraud (internal and external);
• employment practices and workplace safety;
• client negligence;
• damage due to physical assets;
• business disruption and failure; and
• transaction processing.
• The risk process must include external, as well as internal, loss data.
• Measures must be based on a minimum five year observation period of loss data (with a minimum
three years required when a bank first moves to AMA).
• The risk mitigation impact of insurance can be recognised up to a limit of 20% of the total
operational risk capital.

84 Operational Risk
The Nature of Operational Risk Chapter Three

10.4 THE CAPITAL REQUIREMENTS DIRECTIVE (CRD)


LEARNING OBJECTIVES
3.9.1 Know the basic requirements of: Basel II; the Capital Requirements
Directive

The objective of the CRD was to have in place a comprehensive and risk-sensitive framework and to
encourage and enhance risk management among financial institutions. The Directive aimed to maximise
the effectiveness of the capital rules in ensuring continuing financial stability, maintaining confidence in
financial institutions and protecting consumers. The Directive came into force in June 2006.

10.5 RISK-BASED FSA REVIEWS AND ARROW VISITS


LEARNING OBJECTIVES
3.9.8 Understand the principles of the lead UK regulator, the FSA: FSA
reviews; ARROW visits;

The FSA is the UK regulator for financial services and is a risk-based regulator. ARROW is the
framework they use to make risk-based regulation operational. ARROW stands for Advanced,
Risk-Responsive Operating framework and covers all types of risks.

ARROW has helped the FSA greatly with the implementation of the FSA’s principles-based approach to
regulation, which means that in practice for firms that present less risk to the FSA’s statutory objectives,
there will be a somewhat lighter regulatory burden imposed on them. This ensures that the FSA can
deliver regulation in an efficient and economic way.

The FSA’s five statutory objectives are to:

• maintain confidence in the financial system;


• promote public awareness of the financial system;
• secure the appropriate degree of protection for consumers;
• reduce the level of financial crime; and
• contribute to the protection and enhancement of the UK financial system.

• The ARROW Project was set up by the FSA in 2004 and this has been overhauled by the
implementation of ARROW II. The FSA, through ARROW II, seeks to provide greater clarity
about the outcomes which the FSA considers to be important to it. ARROW II enables the FSA
to accurately capture its assessment of how a firm is applying the FSA principles to protect its
customers.

By using a more risk-based approach to the FSA’s assessment of whether firms are operating in line
with the FSA principles, the FSA can create incentives for firms to do the right thing in return for less
supervisory intervention. Under ARROW II, firms will receive more detail than ever before on the
FSA’s assessment of them.

Operational Risk 85
The Nature of Operational Risk Chapter Three

The FSA will carry out ARROW visits to all firms and assess them in terms of the level of risk they pose
to the FSA’s statutory objectives. For example, all firms will be assessed in the following core areas:

• management, governance and culture;


• control functions; and
• capital and liquidity.

10.6 INTERNAL CAPITAL ADEQUACY ASSESSMENT


PROCESS (ICAAP)
LEARNING OBJECTIVES
3.9.8 Understand the principles of the lead UK regulator, the FSA:
International Capital Adequacy Assessment Process (ICAAP)

Firms that are within the scope of the Capital Requirements Directive (CRD), have to calculate their
capital adequacy in a different way. In addition to the accounts-based capital adequacy calculations,
the FSA requires firms (from January 2008) to use its Internal Capital Adequacy Assessment Process
(ICAAP).

The ICAAP has four key steps:

• a Risk Survey to identify the risks a firm faces;


• a Risk Assessment to establish the likelihood of those risks materialising and their potential impact
on the firm;
• stress testing to model how well the firm as a whole would survive this impact; and
• a capital calculation to work out the amount of additional risk capital a firm will need to hold.

The FSA requires the whole process to be fully documented in an ICAAP report which firms must
review regularly and keep up to date.

86 Operational Risk
The Nature of Operational Risk Chapter Three

END OF CHAPTER QUESTIONS


Think of an answer for each question and refer to the appropriate section for confirmation.

Question Answer Reference

1. What are the three stages of the operational risk chain of events? Section 1

2. Which seven areas should an operational risk policy address? Section 3

3. Why does an operational risk policy require board level


sponsorship? Section 3

4. What are the key objectives of operational risk management? Section 4

5. Name the seven stages of the risk management process. Section 4

6. Why do operational risks need to be understood, recorded and


categorised? Section 5

7. List the five common methods of risk identification. Section 5.2

8. How do risk measurement and risk assessment differ? Section 6

9. Give three reasons why it is important to measure operational risk. Section 6.1

10. Why is it difficult to measure operational risk quantitatively? Section 6.2

11. List six common methods of risk measurement and assessment. Section 6.2

12. List three advantages of ranking as a form of risk assessment. Section 6.2.1

13. Why is bottom-up measurement so called? Section 6.2.4

14. Give three advantages of bottom-up measurement. Section 6.2.4

15. Give three disadvantages of bottom-up measurement. Section 6.2.4

16. What does benchmarking involve? Section 6.2.5

17. What do the initials KRI stand for? Section 6.2.6

18. What are the advantages of using risk indicators? Section 6.2.6

19. List the attributes of a good risk report. Sion 7.2

20. What are the five risk mitigation strategies? Section 8

21. Continuity planning is an example of which risk mitigation strategy? Section 8.2

Operational Risk 87
The Nature of Operational Risk Chapter Three

22. Name two ways of transferring risk. Section 8.4

23. Why might a firm decide to retain a certain level of risk? Section 8.5

24. What are the advantages of the new Accord proposals to risk managers
and regulators? Section 10.1

25. What does the second pillar of the new Accord require? Section 10.2

26. What are the three approaches for measuring capital adequacy
requirements in the new Accord? Section 10.3

27. Explain the standardised approach for calculating operational risk capital
adequacy. Section 10.3.2

28. List four criteria with which a firm must comply if it is to qualify for
assessment using the standardised approach. Section 10.3.2

29. What is the main advantage for a firm to use the advanced
measurement approach? Section 10.3.3

30. What are the FSA’s five statutory objectives? Section 10.5

88 Operational Risk
CHAPTER FOUR

THE CAUSES, EVENTS AND


IMPACT OF OPERATIONAL RISK
1. THE CAUSES OF OPERATIONAL RISK 91
2. THE EVENTS OF OPERATIONAL RISK 96
3. THE IMPACT OF OPERATIONAL RISK 99

This syllabus area will provide approximately 10 of the 50 examination questions

Operational Risk 89
The Causes, Events and Impact of Operational Risk Chapter Four

90 Operational Risk
The Causes, Events and Impact of Operational Risk Chapter Four

1. THE CAUSES OF OPERATIONAL RISK


LEARNING OBJECTIVES
4.1.1 Know the root causes of operational risk
4.1.2 Understand how the root causes of operational risk interrelate with
each other

All types of operational risk can be traced back to four root causes. Failure of:

• the processes they are involved in to execute the business;


• the people or staff employed by the institution;
• the technology that is developed to support the processes and the people; or
• the environment within which the people, processes and technology operate. The environment has
both internal influences – influenced by internal business strategy such as the choice of technology
and mergers and acquisitions – and external influences such as economic conditions, competition,
law, tax policy, the labour market, the pace of change, war and natural disasters.

The relationship of these causes is represented in Figure 4.1. The diagram shows that each cause of risk
cannot be considered in isolation. Each one affects the other and they are mutually interdependent. This
means that an ineffective approach to the management of one area will have knock-on effects on the
others.

How well an organisation influences and adapts to its environment and harmonises its people, processes
and technology dictates how successful it will be in managing its risk.

For instance, if staff are using old, manually intensive and incompatible systems, the reliance on their
integrity and expertise to deal with system-related problems is greater and the complexity of the
process design to ensure control is increased. This will impact the firm’s ability to adapt to its changing
environment and its effectiveness in controlling its risk environment.

Conversely, adopting an efficient straight-through processing (STP) system will greatly reduce people
risk, but will increase technology risk, due to the increased reliance on IT.

Operational Risk 91
The Causes, Events and Impact of Operational Risk Chapter Four

Figure 4.1 – The Causes of Operational Risk

Internal Environment External Environment

People

Process Technology

1.1 PROCESS CAUSES


LEARNING OBJECTIVES
4.1.3 Be able to apply an understanding of process as a root cause of
operational risk to simple, practical situations

A process is a set of activities that allow the firm to deliver its product to the customer. A process
takes a collection of inputs and turns them into desired outputs by adding value to them. For instance,
a reconciliation process is a collection of activities concerned with moving unreconciled data from a
stage of unknown agreement to a stage of known agreement, thereby reducing the risk of errors and so
adding value to the business.

Inefficiencies create operational risk that, in turn, reduces the added value of the process. Some
common examples are:

• A lack of effective procedures and/or procedural documentation - this is especially important


when there is a high pace of change or when the firm is introducing increasingly complex products.
For instance, if a firm is expanding rapidly, the quality of procedures and documentation often
suffers as they are seen to be less important than the primary business. This leads to confusion
and a lack of a standardised approach that then creates errors and conflicting interpretations of
the process. The importance of this issue is highlighted by regulators and auditors who carefully
examine procedural documentation for evidence of effectiveness.
• A lack of capacity -this is the basic inability of a firm to cope with business demand. For instance,
when Tesco became the first supermarket to offer savings facilities, the demand was eight times
greater than expected. This created difficulties in processing the new business and keeping up with
demand.

92 Operational Risk
The Causes, Events and Impact of Operational Risk Chapter Four

• Volume sensitivity - this issue concerns the volume of work per head. If the workload increases in
proportion to increasing volumes, there will either be a point of overload, or ever greater numbers
of staff will have to be recruited to deal with the growing business. In either case, the process will
become inefficient. For instance, in investment banking, equity-trading volumes have multiplied
over recent years, putting pressure on old processes and systems that were not designed to cope
with the increase in throughput. Similarly, there are also occasional instances of high volumes or
‘spikes’ in the process, such as on the last business day of each quarter. This again puts pressure on
the process and its people. The challenge for the industry is to design new processes that are not
sensitive to volumes so that they are able to cope with the projected increases in business.
• A lack of effective controls and/or control documentation - all processes have controls and
check points designed into them to detect errors and prevent fraud and theft. For instance, firms
have controls to ensure segregation of duties so that no single person has the end-to-end authority
to process transactions (ie, one person may be able to book a payment into a system but another has
to check it). This prevents fraudulent activities, such as assigning cash movements to personal bank
accounts. In the case of Barings Bank, Nick Leeson was responsible for both front and back office
functions. The lack of segregation gave him the opportunity to commit fraud.
• A failure to review controls when the process changes - processes continuously change and
(hopefully) improve. If the control structure is not reviewed and assessed as part of this change it is
possible that some potential new risks are introduced that are not covered by adequate controls.
The identification of these control gaps is a key objective of the operational risk management
function.

1.2 PEOPLE CAUSES


LEARNING OBJECTIVES
4.1.4 Be able to apply an understanding of people as a root cause of
operational risk to simple, practical situations

People are an organisation’s greatest asset – this is reflected in the high proportion of a firm’s costs
being attributed to staff compensation. However, the operational risks due to people-related issues
are difficult to assess. This is partly due to the difficulty in measuring their effects. As the understanding
of the ‘human factor’ has improved, it has become even more apparent how damaging losses due to
people issues can be. People causes can take the following forms:

• a lack or loss of people of the right number and quality;


• human error;
• staff acting in an unauthorised manner;
• a lack of integrity and honesty;
• a lack of care when dealing with customers;
• a lack of skills and/or insufficient training;
• poor communication;
• concentration of expertise;
• a lack of appropriate supervision; and
• a lack of accountability for operational risk management.

Operational Risk 93
The Causes, Events and Impact of Operational Risk Chapter Four

All of the issues above result in a greater likelihood that the risk of loss will be realised and, as a result,
companies have to focus time and resources on ways to reduce their effects. It is a key responsibility of
senior management to ensure that sufficient personnel are attracted and retained who have:

• the requisite technical knowledge and experience; and


• the ability to react flexibly and quickly to client needs.

It is also important that robust succession planning is in place to avoid an increase in people risk
exposure in key roles.

These cultural qualities are as important as the technical qualities and should exist in the organisation, its
management and its recruits.

1.3 TECHNOLOGY CAUSES


LEARNING OBJECTIVES
4.1.5 Be able to apply an understanding of technology as a root cause of
operational risk to simple, practical situations

Firms employ technology to improve the effectiveness and efficiency of their processes. Its use is
generally accepted to improve controls and reduce cost and, in the age of e-commerce, its importance
to business success is greater than ever before. However, it is also a cause of operational risk. Some
technology causes are:

• A lack of system availability due to operational failure, caused by:


• poor design;
• inadequate security, leaving the systems vulnerable to hacking, unauthorised access, sabotage and
attack by computer viruses;
• power failures;
• vulnerability of systems to the forces of nature, such as earthquakes, lightning strikes, fire and
floods.
• A lack of system integrity. If systems do not automatically pass information between themselves,
there is a need for:
• manual rekeying between systems;
• reconciliations between systems.
• Inadequate control functionality. This is a growing concern as the pace of change and pressure
for operational areas to become revenue generators increases. This may lead to a greater
requirement for technology to deliver cost reductions rather than ensure control integrity.
• Inadequate capacity or scalability to cater for production volumes and increasing system demands
brought about by trading levels, for example. Similarly, management failure to plan its systems
requirement and capacity in good time.
• Inadequate testing of systems in their development stage, leading to later production problems.
• Errors made in software changeover procedures by moving new systems from ‘test’ to ‘live’ mode
without proper testing and controls, reflecting poor technical management and resulting in a project
risk.

94 Operational Risk
The Causes, Events and Impact of Operational Risk Chapter Four

• The lack of a strategic approach to system design. Symptoms of this lack of strategy might be
a preponderance of ‘tactical’ system solutions, the uncontrolled use of business-critical spreadsheets
or a lack of integration of systems across functional areas.
• High system complexity, meaning that there can be a lack of understanding of functionality and
it can be difficult to predict the knock-on effects of any major changes.

Due to the increasing reliance on technology, there is a growing effort to measure its impact on
operational risk.

1.4 ENVIRONMENTAL CAUSES


LEARNING OBJECTIVES
4.1.6 Be able to apply an understanding of environment as a root cause of
operational risk to simple, practical situation

The three causes of process, people and technology are inherent in the internal structure of an
organisation. The environmental causes have an impact by exacerbating the risks that already exist in
these areas. Environmental causes can be categorised into the internal environment and the external
environment. Some examples are as follows:

1.4.1 Internal Environment


• The use of new technology such as new delivery mechanisms and straight-through processing (STP)
systems (ie, systems that deal with the automatic end-to-end processing of transactions). The result
of ever-increasing levels of automation and system complexity is to create an organisational reliance
on systems and, therefore, to increase technology risk. This is made worse by the accompanying
reduction in administrative staff and the loss of their expertise.
• The accelerating increase in volumes as a result of increased market activity, and internet trading.
This results in greater pressure on staff, their processes and technology and may lead to delays and
more errors in transaction confirmation, matching, settlement etc.
• Continuing industry rationalisation resulting in the need to integrate the process, working practices,
systems and the corporate culture of separate organisations not originally intended to operate
together.

1.4.2 External Environment


• War, terrorism and natural disasters. The events of 11 September 2001 demonstrated clearly the
potential effects of terrorism. This group of causes tend to be relatively unlikely but have a very high
impact, and firms must have good contingency planning arrangements to mitigate their effects.
• Change in regulatory and tax requirements for firms. These changes can create huge difficulties in
modifying processes and reporting requirements within fixed and often tight timescales set by the
regulators.
• The growth and competitiveness of the labour market, resulting in higher salaries and a lack of
available experienced staff. This results in a greater reliance on temporary staff who may not have
adequate knowledge of company processes and procedures to control risk adequately.

Operational Risk 95
The Causes, Events and Impact of Operational Risk Chapter Four

1.4.3 The Management of Change


The management of change is a major cause that is becoming a more important issue for financial
institutions as the environment in which they operate becomes more and more complex. New markets
and products continue to emerge; competition becomes fiercer; and the technological boundaries
continue to be extended. It therefore becomes more and more important for firms to be able to
anticipate and adapt to change – to take advantage of being first to market and gaining the competitive
advantage of using new and more efficient processes. The amount of change happening at the same
time may reach a critical point of capacity beyond which the firm ceases to cope. This is a particularly
dangerous cause because it affects every other area of a firm’s operation.

The other causes of operational risk cannot be adequately understood without taking these
environmental issues into account.

2. THE EVENTS OF OPERATIONAL RISK


LEARNING OBJECTIVES
4.2.1 Know the events arising from operational risk

If a lack of effective people, processes and technology coupled with an inability to adequately manage
the environment are the root causes of risk, and financial loss is the ultimate effect, what is the trail of
errors or events that lead from the cause to the effect?

Because of the breadth of operational risk, the potential events that link root causes to effects cover a
wide range of activities that can eventually result in loss.

These root causes of risk can lead to a wide variety of events. Some of the important root causes are:

• incorrect data;
• delayed processing and documentary omissions;
• regulatory non-compliance;
• project mismanagement;
• fraud and theft; and
• unforeseen litigation.

The events are described in the rest of Section 2 and their consequent effects in Section 3.

96 Operational Risk
The Causes, Events and Impact of Operational Risk Chapter Four

2.1 INCORRECT DATA


LEARNING OBJECTIVES
4.1.7 Understand the key causes of incorrect data

Institutions today hold and process vast quantities of data often in different forms and in more than one
place. Data can be wrong for two reasons:

• it has been captured incorrectly or incompletely;


• it has not been updated to reflect changes in its source.

This lack of integrity can originate from any or all of the causes described at the start of this chapter.

For example, data may need to be manually keyed into a system because two systems are incompatible
with each other (technology cause), leading to mis-keying because of human error (people cause).
The error may then not be detected due to the lack of an effective control procedure (process cause),
which may then result in incorrect documentation being sent to a client. The chance of this problem
occurring might be increased due to the pressure of increasing volumes (environmental cause).

2.2 DELAYED PROCESSING AND DOCUMENTARY


OMISSIONS
LEARNING OBJECTIVES
4.1.8 Understand the key causes of delayed processing and documentary
omissions

Delays and documentary omissions are often caused by the inability of a process to cope under stressful
conditions, such as abnormally high volumes or too much change affecting the business. These are often
‘early warning signs’ of process weakness.

They may also be caused by a lack of awareness of the operational risk issues leading to a lack of timely
action due to the pressure of mistakes and errors.

2.3 REGULATORY NON-COMPLIANCE


LEARNING OBJECTIVES
4.1.9 Understand the key causes of regulatory non-compliance

Institutions operate within a set of industry rules and regulations defined by law, or industry guidelines
enforced by their regulators. Firms aim to operate within these rules. However, they may inadvertently
transgress due to lack of adequate people, processes or technology. For instance, reporting deadlines
may be missed, reports may be incorrect or limits may be exceeded.

Operational Risk 97
The Causes, Events and Impact of Operational Risk Chapter Four

2.4 PROJECT MISMANAGEMENT


LEARNING OBJECTIVES
4.1.10 Understand the key causes of project mismanagement

The way firms bring about change is through the implementation of projects. Projects are packages of
work that deliver a ‘piece of change’. They usually form part of an integrated programme that helps
the firm to manage its changing environment. They can be large and strategic or small and tactical but
the sum total of all the project work occurring in an organisation has an effect on its ‘business-as-usual’
business. Examples of projects are:

• The design and implementation of a new process capable of processing ten times the volume of
business with lower risk and for the same cost. This would be a large, strategic project and would
involve people, processes and technological aspects.
• The design and implementation of a client query system that helps to improve the quality of client
service. This may vary in size from a small project in one particular area of operation to a more
strategic project involving a number of departments.
• The design and implementation of a management training programme to support a cultural change
to a more consensual style of management.
• The design and implementation of a new organisational structure for a firm to provide greater
autonomy and decision-making for middle managers.

Project risk is the risk that the failure, or partial failure, of a project to meet its objectives leads to
financial loss.

2.5 FRAUD AND THEFT


LEARNING OBJECTIVES
4.1.11 Understand the key causes of fraud and theft

Fraud and theft can be committed from within the organisation (internal fraud) or by persons
outside the organisation (external fraud). They can occur due to a combination of causes, such as the
dishonesty of the fraudster (people cause) or the weakness in process or system design that gives
him the opportunity to commit the crime (process cause). For fraud and theft to occur there must be
opportunity and this opportunity is usually the result of an operational issue.

98 Operational Risk
The Causes, Events and Impact of Operational Risk Chapter Four

2.6 UNFORESEEN LITIGATION


LEARNING OBJECTIVES
4.1.12 Understand the key causes of unforeseen litigation

Unforeseen litigation is an aspect of legal risk which includes instances when the firm is sued, for
example, due to:

• contractual differences or ambiguities relating to a transaction or client;


• any litigation brought by a competitor due to issues such as intellectual property; or
• employee litigation resulting from grievances involving equal opportunities, health and safety,
compensation or employee contracts.

2.7 TECHNOLOGY FAILURES


LEARNING OBJECTIVES
4.1.13 Understand the key causes of technology failures

The final event category is technology failure. The ultimate effect or impact of operational risk being
realised is direct or indirect financial loss. Technology failures can occur for many different reasons,
some of which are in the control of the firm, some of which are not. Examples include:

• power failure;
• back-up power systems not working;
• viruses and bugs affecting the operation of systems; and
• overusage or overloading of systems.

3. THE IMPACT OF OPERATIONAL RISK


LEARNING OBJECTIVES
4.2.1 Know the events arising from operational risk
4.3.1 Understand direct and indirect financial loss

As with market and credit risk, the ultimate effect or impact of operational risk being realised is financial
loss. This loss can be either direct (quantifiable) or indirect (non-quantifiable).

Operational Risk 99
The Causes, Events and Impact of Operational Risk Chapter Four

3.1 DIRECT (QUANTIFIABLE) FINANCIAL LOSS


Direct or quantifiable financial loss is the direct financial penalty that a firm incurs as a result of a risk
being realised. It can be due to:

• claims for damages or compensation as a result of failure to meet contractual obligations;


• penalties and fines arising from regulatory censure or revocation of licences;
• loss of income from transaction fees, direct fees and commissions;
• loss of assets or cash through unenforceable contracts;
• corrections to P&L due to mistakes in booking; and
• the associated direct costs of rectifying the operational weakness that led to the loss (when
this leads to an additional debit on the profit and loss account). This could also include any fines
imposed.

3.2 INDIRECT (NON-QUANTIFIABLE) FINANCIAL LOSS


Indirect or non-quantifiable financial loss is associated with the opportunity costs that arise due to:

• a lack of operational capability, meaning that the firm is unable to trade in the way it wishes;
• the damage to the firm’s reputation in the market or with a specific client (or both). The potential
for financial loss due to a damaged reputation is known as reputational risk. Reputation and the
integrity of a financial institution are major factors in its competitiveness and success.

They can be damaged by:

• adverse publicity due to a lack of client suitability, ie, being associated with criminals, notoriety or
scandal;
• perceived malpractice, such as inflating commissions, misselling, concealing losses and the
identification of accounting irregularities;
• public disputes with customers, which could possibly lead to litigation;
• client dissatisfaction resulting in loss of future business opportunities;
• the associated costs of rectifying the operational weakness that led to the loss, such as through
re-allocating staff from profitable activities to help correct the problem (where this does not lead to
an additional debit on the profit and loss account).

100 Operational Risk


The Causes, Events and Impact of Operational Risk Chapter Four

3.3 THE EFFECTS OF OPERATIONAL RISK EVENTS


LEARNING OBJECTIVES
4.2.2 Know the main consequences of the following operational risk events:
incorrect data; delayed processing and documentary omissions;
regulatory non-compliance; project mismanagement; fraud and theft;
unforeseen litigation; technology failures

The following table gives some examples of the main impacts of the risk events described earlier.

Risk Event Risk Effect


Incorrect data Examples of the potential effects of incorrect data are:
• direct loss due to failed transactions;
• direct loss if the error is not spotted early enough, eg, a
transaction being incorrectly priced with the market moving
against the trader; and
• indirect loss due to a damaged reputation resulting from
incorrect documentation.
Delayed processing and Delays in the processing of a transaction or omissions in documents
documentary omissions can result in the following effects:
• direct loss due to a payment or funding deadline being missed,
resulting in interest claims or financial penalties; and
• indirect loss due to a damaged reputation resulting from
incorrect documentation.
Regulatory non-compliance Examples of the potential effects of regulatory non-compliance are:
• direct loss through fines or penalties; and
• indirect loss through regulatory censure resulting in damaged
reputation or inability to trade.

Operational Risk 101


The Causes, Events and Impact of Operational Risk Chapter Four

Risk Event Risk Effect


Project mismanagement The potential effects of project mismanagement are:
• a direct loss to the firm because of:
• the need to use more resources to bring a delayed project
back on course;
• project delays creating higher costs of run-the-bank
business;
• cancelling a project midway through its life;
• having to set up further projects to take remedial action
due to the initial project delivering an inadequate solution.
• an indirect loss due to:
• the opportunity of using the resources employed on
the unsuccessful (or semi-successful) project in a more
effective manner;
• the project de-stabilising the day-to-day operation. For
instance, the involvement of line staff in the project may
put extra pressure on the business. This has knock-on
events such as incorrect data, delayed processing and
documentary omissions or deterioration in client service
that then leads to financial loss;
• the project being part of a change programme that is
unco-ordinated or inadequately controlled. The sum total
of all projects may be beyond the capacity of the business.
Fraud and theft The potential effects of fraud and theft are:
• direct losses as a result of the crime; and
• adverse publicity on the firm’s reputation.
Unforeseen litigation The potential effects of unforeseen litigation are:
• the potentially large compensation and legal bills resulting from
losing a lawsuit; and
• the effects of adverse publicity on the firm’s reputation.
Technology failures The potential effects of technology failures are:
• direct loss through fines or penalties;
• the amount of time spent by staff that are unable to proceed
with their responsibilities; and
• adverse publicity on the firm’s reputation.

102 Operational Risk


The Causes, Events and Impact of Operational Risk Chapter Four

3.4 EXAMPLES OF THE CHAIN OF EVENTS OF


OPERATIONAL RISK
LEARNING OBJECTIVES
4.3.2 Understand how different events impact on the business: costs;
reputation; fees and fines; staff demotivation; client dissatisfaction; cost
of rectification; litigation; closure/prohibition; censure

There are many instances of operational risk within a business and these could result in any or all of the
following:

• increased operating costs;


• damage to reputation;
• imposition of fees and fines;
• staff becoming demotivated;
• client dissatisfaction;
• missed payments;
• the cost of rectification;
• closure/prohibition; and
• censure.

Operational Risk 103


The Causes, Events and Impact of Operational Risk Chapter Four

Here are some examples of these operational risks. In each example there are details of the root cause,
the event and the effect of the operational risks.

EXAMPLES OF THE CHAIN OF EVENTS OF OPERATIONAL RISK


1. In the front office of an investment bank, traders not being adequately trained in the use of their
systems may input incorrect trade details into their systems, leading to financial loss. The chain of
events is:
• Root cause = Technology (over-complex systems) and/or Human (lack of training).
• Event = Incorrect booking.
• Effects = Financial loss due to a failed trade (eg, interest claims) plus possible knock-on effects
if the trade is part of a structured product or hedge as well as reputational loss.

2. In the legal department, an ambiguous clause may be inserted into a contract, leading to financial
loss.
• Root cause = People (lack of training or carelessness), compounded by Process (the
complexity of the job).
• Event = Incorrect documentation.
• Effects = Financial loss arising from contention of contract by client or a third party (eg, cost of
litigation, inability to claim profits etc) as well as reputational loss.

3. In the credit department, an error in a credit model could result in a client being able to exceed
its credit limit. This may lead to regulatory censure and unexpected financial loss if the client
defaulted.
• Root cause = Either Technology (a poor design of the model) or Process (the mis-translation
of the business requirements when developing the model).
• Event = Regulatory non-compliance or breach.
• Effects = Potentially larger-than-expected loss, if the client defaults, and financial penalties from
regulators (with consequential reputational damage).

4. In the operations department, the expiry date of an option may not be monitored effectively,
leading to an in-the-money option not being exercised.
• Root cause = Weak process and controls in identifying and monitoring option events.
• Event = A missed event (eg, the expiry date of an in-the-money option).
• Effects = Financial loss due to not calling an in-the-money option.

5. In the treasury department, an inadequate collateral management process may lead to


opportunity costs by not maximising the use of collateral.
• Root cause = poor processing capabilities.
• Event = Missing potential avenues to generate revenue (such as using approved collateral to
cover margin calls rather than borrowing ‘off the street’).
• Effects = Financial loss due to paying a higher cost of borrowing.

There are countless other instances of operational risk that can occur anywhere in the transaction life
cycle.

104 Operational Risk


The Causes, Events and Impact of Operational Risk Chapter Four

END OF CHAPTER QUESTIONS


Think of an answer for each question and refer to the appropriate section for confirmation.

Question Answer Reference

1. What are the four root causes of operational risk? Section 1

2. Give two examples of process causes. Section 1.1

3. Give four examples of people causes. Section 1.2

4. Give three examples of technology causes. Section 1.3

5. Why is the pace of change a major environmental cause? Section 1.4.3

6. Name six events of operational risk? Section 2

7. What is project risk? Section 2.4

8. What is project risk? What are the potential effects of delayed


processing and documentary omissions Section 3.3

Operational Risk 105


The Causes, Events and Impact of Operational Risk Chapter Four

106 Operational Risk


CHAPTER FIVE

OPERATIONAL RISKS ARISING


IN THE TRADE
1. THE PRIMARY BUSINESS ENVIRONMENT 109

This syllabus area will provide approximately 7 of the 50 examination questions

Operational Risk 107


Operational Risks Arising in the Trade Chapter Five

108 Operational Risk


Operational Risks Arising in the Trade Chapter Five

1. THE PRIMARY BUSINESS ENVIRONMENT


The primary business environment comprises the areas most closely associated with revenue generation
and processing activities. It consists of various functions: the front office and related support functions.
These are explained in more detail below.

1.1 THE FRONT OFFICE


LEARNING OBJECTIVES
5.2.1 Understand the role of the front office
5.2.2 Understand the nature of key controls and KRIs in the front office;
transaction capture; exchange of settlement instructions; trade
reporting; regulatory transaction reporting; monitoring position and
credit limits; capital reporting/usage
5.2.3 Understand the key controls and KRIs associated with the execution
phase

The front office of a financial institution is where trading takes place. It is populated by the firm’s
revenue earners. These are the traders, fund managers, salesmen and market risk managers. Only
authorised employees in the front office can commit the firm to a contract and a clear distinction must
be drawn between staff having the status of traders or dealers (these provide the actual execution of
the trades or deals) and trade support staff that assist in order handling and the provision of quotations/
prices to the client.

The revenue earners are interested primarily in making a profit for the firm and generally have most
involvement in the transaction life cycle up to the point of transaction execution (ie, the commitment
of funds). After this point, the administration of the transaction is conducted by the support functions.
Revenue earners will monitor transactions throughout their life in order to manage market risk (implicit
in the daily profit & loss (P&L) calculation) and may also be involved in specific issues or problems, such
as dealing with sensitive clients or making decisions on options.

1.1.1 Risk and Control


Some of the most serious operational risk issues occur in the front office such as fraud, exceeding
credit limits, and point-of-trade errors. They must, therefore, have effective control and management
procedures in place. Also they will have a number of key risk indicators (KRIs), as defined in Chapter 3.

Some typical controls will cover the following aspects:

• Ensuring that effective segregation of duties are in place between trading and support functions,
such as the front office, operations, accounting and risk monitoring.
• Having clear escalation procedures in place covering all key risks, such as exceeding agreed limits.
• Ensuring adequate research has been carried out before dealing in a new product, portfolio or
counterparty. This may include, for instance, the production and authorisation of a detailed business
plan.
• Controlling new market and credit limit requests and ensuring they are adhered to.

Operational Risk 109


Operational Risks Arising in the Trade Chapter Five

• Effective capital requirement reporting and details relating to the usage of capital.
• Conducting continuous limit reviews in order to maintain the firm’s risk appetite. For instance,
counterparty credit limits may be reviewed annually or whenever there is an adverse material
change in either their financial status or market.
• Ensuring effective control over front office systems; including reference data, computer models,
spreadsheets and algorithms. This is particularly important when complex mathematical models are
used involving ‘chaining’ of calculations, so that the output from one calculation is used as the input
for another, or when there are no easily devised plausibility checks possible on the results of the
model.
• Ensuring after-hours trading is properly defined and controlled.
• Tightly controlling dealing tickets and ensuring they are processed quickly and efficiently, eg,
numbering them consecutively, using time-stamps and transmitting them immediately to the
settlement department after they have been produced in the dealing room.
• Continuously updating positions. Dealers should always know the value of their long, short and net
positions, as well as the value of any hedge relating to a position.
• Maintaining high ethical standards by having effective procedures in place to ensure that:
• there is no trading at off-market rates or at rates which deviate from prevailing market levels;
• dealing only occurs within the dealing room, unless specifically authorised otherwise;
• there is client confidentiality in accordance with data protection principles; and
• compliance rules are followed, particularly with respect to the rules of conduct and
entertainment, and ensuring that token gifts are not excessive and are only accepted in
accordance with rules.

When setting up operational risk management processes in the front office, appropriate risk indicators
are chosen to monitor the effectiveness of these controls such as the number of limits breaches, system
availability and dealing ticket processing times.

1.1.2 Accepting New Customers


LEARNING OBJECTIVES
5.1.1 Understand what tasks must be completed during set-up: marketing
and sales; Know Your Customer; account set-up; static information;
credit assessment; standard settlement instructions; legal contract
negotiation; client and counterparty agreements
5.1.2 Understand the key controls and KRIs associated with a set-up phase

• Marketing and sales - the Financial Services Authority has very specific rules regarding how
investments should be marketed, particularly to private customers. Some of these rules cover the
following: adverts to be clear, fair and not misleading; certain minimum information to appear in the
advert; contact details of the advertising firm; rules relating to cold calling and record keeping.
• Know your customer - KYC is central to the firm’s ability to give proper advice. Without
up-to-date knowledge of the customer it becomes difficult to make sure that recommendations are
suitable. Consequently, the rules require that the firm takes ‘reasonable steps’ to gather information
about the private customer. This is commonly done using a KYC fact-finding questionnaire. The
penalties for non-compliance can be severe. The FSA has issued requirements in its Rulebook for
firms to abide by.

110 Operational Risk


Operational Risks Arising in the Trade Chapter Five

• Account set-up - certain details relating to the customer will need to be recorded by the firm and
the correct customer classification must be applied on the firm’s internal records.
• Static information - this is also called ‘current standing data’ and includes details to be recorded
by the firm, eg, customer’s name, address, contact details, investment objectives etc. These details
need to be rechecked by the firm on a regular basis, so as to ensure they are still correct.
• Credit assessment - the firm may also need to carry out a credit reference search for a potential
customer to assess their financial standing.
• Standard settlement instructions - including details of how customers will pay for their
investment purchases and how they wish to receive their settlement monies when selling
investments.
• Legal contract negotiation - including agreeing terms and conditions by the legal department
within the business that may be used in client agreements and terms of business.
• Client and counterparty agreements - these may need to be sent out to customers (depending
on the type of investment) and their written confirmation may be required before the firm can start
carrying out the activities that the customer has requested.

If a firm is advising a private customer, or acting as an investment manager for a private customer, or
arranging a pension opt-out or transfer for a private customer, it must take reasonable steps to ensure
that it is in possession of sufficient personal and financial information relevant for the services that the
firm has agreed to provide. This could include information about income, other assets, outgoings, age,
investment objectives and attitude to risk. Potential customers may also be credit-checked to confirm
that they may be accepted as customers. They may also be sent a ‘terms of business’ letter or may
need to complete and return a client agreement letter.

1.2 THE FRONT OFFICE SUPPORT FUNCTIONS, PRE-


SETTLEMENT PHASE
LEARNING OBJECTIVES
5.3.1 Understand the components of the pre-settlement phase: trade
affirmation; trade confirmation; asset and cash positioning
5.3.2 Understand the key controls and KRIs associated with the
pre-settlement phase

The front office support functions mainly ensure that front office trade information passes smoothly and
accurately into the front office support settlement systems. In some organisations this function forms
part of the operations department.

It generally involves the capture of transactions in the front office functions systems and trade
confirmation processes.

1.2.1 Transaction Capture


Operational risk can arise from errors or delays in capture and processing, resulting in incorrect
hedging, funding and settlement.

Operational Risk 111


Operational Risks Arising in the Trade Chapter Five

Key risk indicators might be:

• trends in the volume of transactions when compared with the percentage handled manually;
• the number of errors detected by reconciliations;
• the time taken to detect and resolve the errors;
• the number of transactions not captured within a specific time from trade execution.

Key controls might be:

• implementing STP (a preventive control);


• daily sign-off of front-to-back positions (an internal detective control);
• funding position reconciliations (an internal detective control).

1.2.2 Trade Confirmation


Transactions are confirmed with clients prior to settlement and as close to the trade day as possible.
The prime aim of this activity is to ensure that the counterparty recognises the transaction and that
there is agreement with the key legal, economic and settlement terms. It should occur as soon as
possible after transaction execution so that discrepancies are quickly identified and resolved.

Confirmations can be made by telephone and in writing and their format is usually agreed through a
legal agreement signed by the two parties involved as part of the set-up activity. For some products,
such as listed derivatives that use a central counterparty, confirmation can involve a high degree of
automation by being performed electronically with the exchange. For other products, such as OTC
derivatives, confirmations are performed as part of a bilateral agreement using hard copy documents
that become largely standardised. This standardisation helps reduce the risk of error and legal ambiguity
and allows firms to design processes assuming consistent inputs.

Operational risk exists due to the possibility of disputes of transaction details, confirmation errors or
delays when confirming trades, all of which could result in the counterparty defaulting without the firm
having legal recourse.

Key controls might be:

• ensuring that a legal agreement covering confirmation protocol is in place prior to trading (a
preventive control);
• a confirmation checking function performed by a different person to the creator (an internal
detective control);
• front office sign-off of the economic terms of the confirmation (an internal detective control);
• follow-up actions to counterparties which have not returned written confirmations.

Key risk indicators might be:

• length of time taken to formalise a legal agreement;


• number and type of confirmation errors found in the checking process;
• number of confirmations not yet agreed with the counterparty;
• time taken for counterparties to return confirmations.

112 Operational Risk


Operational Risks Arising in the Trade Chapter Five

1.3 THE FRONT OFFICE SUPPORT FUNCTIONS –


SETTLEMENT AND POST-SETTLEMENT PHASES
LEARNING OBJECTIVES
5.4.1 Understand the components of the settlement phase: payment
instructions; payments receipts; financial and regulatory reporting;
securities transfers and custody
5.4.2 Understand the key controls and KRIs associated with the settlement
phase
5.5.1 Understand the components of the post-settlement phase:
reconciliation; inventory management
5.5.2 Understand the key controls and KRIs associated with the
post-settlement phase

Traditionally, operations departments exist to process and settle transactions. Their objectives are:

• to monitor the life of a transaction through to settlement, ensuring that key events are flagged and
acted upon when necessary;
• to provide the transaction, position and cash movement information that are used as a basis for the
accounting function.

Typical activities within this function are:

• transaction instruction;
• positioning;
• settlement; and
• reconciliation.

These activities will now be explained in more detail below.

1.3.1 Transaction Instruction


Transaction instruction is the process of agreeing delivery instructions with a third party. For
exchange-traded products, a clearing house will fulfil this function on behalf of the market participants
using a clearing system. For OTC transactions, the process will involve a bilateral written or verbal
agreement between the transacting parties.

In order to perform the transaction instruction activity effectively, firms will hold ‘Standard Settlement
Instruction’ (SSI) data for most of their counterparties. This allows the automation of the instruction
process, as SSI details are received when the counterparty is first set up in operational systems. In some
cases, and for some products, SSI details are not available when the settlement date approaches and a
separate transaction-specific instruction must be used. This introduces additional risk.

Automated trade confirmation and matching systems, linking trading organisations with custodians and
other counterparties, are commonly provided by third party systems vendors. A good example is the
OMGEO service provided by DTCC/Thomson.

Operational Risk 113


Operational Risks Arising in the Trade Chapter Five

In order to reduce the chances of error and improve process efficiency, this stage can sometimes be
combined with the confirmation stage, with a single combined transaction confirmation and instruction
being sent.

Risks and controls are similar to the confirmation process described above.

1.3.2 Positioning
Positioning is the process of ensuring that there is sufficient cash or stock available to fulfil the contract.
Operational risk exists because positioning is part of an overall inventory management process in which
firms strive to make the most efficient use of their resources. This means that cash and stock are being
continually recycled and used in a way that will generate the maximum return for the firm. Because of
this dynamic process, there may be insufficient assets available when they are required. This leads to
two potential consequences:

• settlement being delayed, exposing the firm to interest claims, potential fines and reputational
damage; and
• higher borrowing costs – in order to ensure settlement, a firm may have to borrow cash or
securities at a higher cost than would otherwise be necessary.

Risk indicators might be:

• number of transactions missing the internal funding deadlines;


• number of late-settled transactions due to a lack of funds;
• extra cost of borrowing to ensure settlement.

Key controls might be:

• the use of internal funding deadlines by which time confirmation and transaction instructions must
be completed. These deadlines would allow enough time for the funding and settlement activities to
be completed (a preventive control);
• system limits to warn users that there are insufficient assets available to cover an upcoming
settlement (a detective control).

1.3.3 Settlement
Settlement is the physical delivery of an asset in exchange for an equivalent amount in cash or payment
receipt. The main operational risk is that the preceding steps in the process break down, resulting in
settlement failure. This is exacerbated in markets that do not employ true delivery versus payment
(DVP) systems.

A risk indicator that measures the quality of the overall process is the number of times a firm settles
late but this could also be affected by market influences.

114 Operational Risk


Operational Risks Arising in the Trade Chapter Five

1.3.4 Reconciliation and Inventory Management


Reconciliation is an accounting function that ensures the firm’s record of cash and stock movements
(the ‘internal world’) agrees with its statement of balance and holdings (the ‘external world’). It is a
key detective control that ensures that the differences between internal world and external world
are identified and resolved in a timely manner. Reconciliation controls are typically applied to provide
checks against a wide range of records – cash, stock or depot accounts, collateral, margin, dealing
positions, client money, custody accounts etc.

The volume of unreconciled events (or ‘breaks’) is commonly used as a risk indicator to assess the
quality of the transaction capture and processing activity.

Inventory management involves how a firm keeps records of its customers’ cash and stock movements.
For example, if it uses an electronic system to record these details, then the firm must ensure that the
system is sufficient for this purpose.

Operational Risk 115


Operational Risks Arising in the Trade Chapter Five

END OF CHAPTER QUESTIONS


Think of an answer for each question and refer to the appropriate section for confirmation.

Question Answer Reference

1. What is a firm’s front office? Section 1.1

2. Give six examples of controls that may be used in a front office to


reduce risks. Section 1.1.1

3. Give three examples of key risk indicators that may be used by the
front office support functions when capturing transactions. Section 1.2.1

4. What are the two objectives of a typical operations department? Section 1.3

5. What are transactions instructions? Section 1.3.1

6. What is positioning? Section 1.3.2

116 Operational Risk


CHAPTER SIX

THE SUPPORT AND CONTROL


FUNCTIONS
1. THE SUPPORT AND CONTROL FUNCTIONS 119

This syllabus area will provide approximately 4 of the 50 examination questions

Operational Risk 117


The Support and Control Functions Chapter Six

118 Operational Risk


The Support and Control Functions Chapter Six

1. THE SUPPORT AND CONTROL FUNCTIONS

1.1 THE COMPLIANCE FUNCTION


LEARNING OBJECTIVES
6.1.1 Understand the role and responsibilities of the compliance function in
managing operational risk
6.1.2 Understand the consequences of compliance risk
6.4.2 Know the requirements of the MiFID level 2 Directive in respect of the
internal audit function

Compliance with regulatory requirements and ethical conduct standards is a major concern to boards
of directors and senior executives because they are held accountable and personally liable for violations.
In a complex and decentralised business environment, corporations must institute consistent, firm-wide
compliance policies and procedures to prevent litigation and reputational damage and meet shareholder
accountability demands.

Under the Markets in Financial Instruments Directive (MiFID), which was adopted in the UK with
effect from 1 November 2007, it is a requirement for each firm to have an independent and permanent
compliance function, if it is sufficiently large enough. This independent section must have sufficient
authority and be structured, resourced and operated effectively.

1.1.1 Compliance Risk


Compliance risk (or regulatory risk) is the risk to earnings or capital arising from violations, or
non-conformance with laws, rules, regulations, prescribed practices or ethical standards. It exposes
the firm to fines, payment of damages, the voiding of contracts and damaged reputation (with its
accompanying indirect costs). This is intimately tied up with operational risk because it is often the
breakdown in processes, procedures and the control culture that allows compliance risk to be realised.
Compliance risk may, for instance, arise if:

• product-related legal regulations are not complied with;


• due diligence is not observed;
• clients’ interests are not protected.

The compliance function in a firm exists to combat this risk. Its objectives are to ensure:

• good corporate governance by defining the way the board of directors and senior executives
execute and govern the company’s overall compliance strategy and ethical mission;
• organisational integrity through the development of ethics and integrity programmes. These define
the training and communication programmes and related accountability processes (such as a
self-assessment process) that attempt to motivate, measure and monitor the organisation’s ethical
performance;
• regulatory compliance by defining the programmes and processes that measure and monitor the
extent to which the organisation adheres to existing laws, regulations, industry guidelines and
general business norms or conventions.

Operational Risk 119


The Support and Control Functions Chapter Six

In many firms the compliance function is also one of the top-level internal procedure-makers for risk
control across all functions and covers the key areas of market, credit and operational risk. When
operating successfully, the compliance role balances the limiting effects of necessary controls with the
empowerment of the workforce to operate within clear boundaries (that may be enforced by other
functions).

The policies and procedures that the compliance function generates are designed to meet these
objectives and to provide direction and clarity to the firm’s employees. Its responsibilities are
wide, covering all aspects of the business and interacting with all of the firm’s functions. These
responsibilities may typically include:

• Good practice - the compliance function keeps abreast of good practices in the industry and
the recommendations of the regulators. It ensures that the following practices are incorporated into
the firm’s policies:
• advice for business units on regulatory issues;
• compliance monitoring;
• communication with the regulatory authorities and reviewing regulatory policy initiatives;
• routine compliance duties such as staff registration and staff dealing approval.
• Regulatory reporting requirements - regulatory reporting covers the reporting of required
information to the relevant regulators. Compliance will ensure the firm sets policies for
requirements such as:
• monthly financial accounts;
• lists of authorised traders, counterparties and products;
• bank account and custodian details.
• Employee conduct - the compliance function will ensure that employees are provided with clear
guidelines and training reflecting law, industry regulations and the firm’s expectations.
The following issues would be addressed:
• insider trading;
• acceptance of gifts;
• client entertainment;
• whistleblower protection;
• stock ownership in companies that the firm has involvement with;
• relationship with competitors;
• relationship with the media;
• confidentiality;
• money laundering.

1.1.2 Consequences of Compliance Risk


Some typical examples of compliance risk being realised are fines or regulatory censure due to:

• fraud;
• insider trading;
• money laundering;
• exposure violations;
• non-compliance with regulatory requirements, eg, misleading selling;
• non-co-operation with regulatory investigations;
• unauthorised trading;
• concealing losses.

120 Operational Risk


The Support and Control Functions Chapter Six

The firm may also have to pay damages, contracts may also be void and reputational damage may
occur, all of which could materially impact the firm.

1.2 THE FINANCIAL REPORTING FUNCTION


LEARNING OBJECTIVES
6.2.1 Understand the role of the financial reporting function in the context
of the operational risk environment

The financial reporting function exists to ensure that the assets and liabilities of the firm are accurately
compiled and reported. A prime financial report is the balance sheet which shows a running total of a
firm’s assets, liabilities, profit and loss.

Accounting risk is the risk of inaccurate financial reporting. Its effects are poor management
decision-making (based on incorrect information) and regulatory non-compliance. These effects can
lead to the consequences of direct and indirect loss such as fines and penalties. Accounting errors can
also conceal already realised losses. These can often go undetected for a long period as they become
lost among other problems and causes.

The financial reporting function performs both internal reporting and external reporting:

• Internal reporting is performed to assist management decision-making and is concerned with


assessing the daily profitability of the firm (the profit and loss or P&L).
• External reporting is performed to satisfy legal and regulatory requirements to report financial
accounts.

Operational risk is inherent in the policies, processes or procedures that ensure accurate financial
reporting. If these break down, accounting risk can be realised. For instance:

• Traders misreporting a transaction’s details in the trading book to make it appear more profitable.
The key control is to validate front office positions on a daily basis as part of the daily reporting
function. This is done by reconciling front office positions (the trader’s view of the world) with the
back office positions (which, when the transactions have settled, should represent the external view
of the world). Some firms call this activity the product control function.
• Misreporting accounts because of complex aggregation rules. Financial institutions usually report
internally by trading book because information is collected at the trader’s book level in order to
assess trader performance. However, they are required to report externally at a legal entity level.
For this reason, the financial reporting systems need to aggregate information to the entity and
group level. While this might seem a simple process in theory, in practice it can prove very difficult
due to poor system integration and the lack of an overall view of the business (both of which are
operational risks).
• A trader is focused on the future – ie, trying to predict what a market will do, while the accounting
function focuses on the past, ie, ensuring that what has been traded is accurately reported. This can
occasionally create a tension between the front office and the accounting function. The intention
must be to develop a good relationship, to foster open communication and avoid operational
difficulties.

Operational Risk 121


The Support and Control Functions Chapter Six

• Changing accounting standards in the industry can lead to confusion in the interpretation of
regulations and reporting requirements.
• Mergers and takeovers can exacerbate accounting risk by adding to the fragmentation of the
business view. It takes time for a company to understand the full financial details of the merged
company and to incorporate these efficiently into the financial reporting of the new firm.

1.3 THE HUMAN RESOURCES (HR) FUNCTION


LEARNING OBJECTIVES
6.3.1 Understand the role of the HR function in the context of the
operational risk environment

Human Resources (HR) - operational risk exists throughout the process. The HR function is
responsible for many things, including:

• recruiting new employees;


• writing job descriptions;
• tracking attendance;
• instituting and monitoring policies and current HR regulations;
• establishing and maintaining a formal policies and procedures manual, incorporating benefits for
employees; and
• maintaining employee records.

If a firm wished to gain access to a new market, it would look to risk management to provide an
assessment of the likelihood of success of the venture. HR might identify a constricted labour market
along with alternatives for addressing the problem. Risk management has the responsibility of
co-ordinating the risk assessments of all of the operational disciplines, along with options to address
the identified issues. Using the above example, the solutions could range from transferring existing
employees, to paying a premium for local talent, to the acquisition of a local company that already has
the required talent. With these options identified, business managers can make educated decisions on
the course of action that is best aligned with their goals.

1.4 THE INTERNAL AUDIT FUNCTION


LEARNING OBJECTIVES
6.4.1 Understand the role of the internal audit function in relation to
operational risk
6.4.2 Know the requirements of the MiFID level 2 Directive in respect of
the internal audit function

Internal audit plays an important role in the risk control framework. It provides an independent, internal
assessment of the effectiveness of the firm’s controls and procedures. It also independently assesses the
effectiveness of the risk management process.

122 Operational Risk


The Support and Control Functions Chapter Six

Also under MiFID, it is a requirement for each firm to have an independent internal audit function, if it
is appropriate and proportionate. This independent section must again have sufficient authority and be
structured, resourced and operated effectively.

The independent periodic review of all transaction life cycle activities is an indispensable safeguard
for senior management in ensuring the integrity of the internal control structure. It also ensures that
management information systems (MIS) are operating effectively.

By performing reviews, internal audit assesses control strength, questioning whether an institution’s
processes and procedures are:

• adequately controlled;
• up-to-date;
• practised in accordance with manuals and documentation.

It also acts as a ‘dry run’ for external audits and regulatory examiners.

Internal audit must have an unrestricted mandate to review all aspects of the transaction life cycle and
be totally independent of senior managers and their departments who are subject to the review.

There is a crossover with the operational risk management process in that both involve the
identification of risk issues. However, auditing is aimed more at checking the control environment on a
‘snapshot’ basis (eg, once every six months), highlighting issues (audit points) but leaving
‘cause-effect’ analysis and solution implementation to the business. Operational risk management
on the other hand, monitors risk on a continuous, day-to-day basis as part of the process allowing
more dynamic and strategic management. Audit information should, therefore, be used as an input to
operational risk management. Audit points can also be used as risk indicators.

Both internal and external audits can be a powerful enabler of change. As part of the cultural change to
a more risk aware outlook, the company’s desire to clear audit issues can significantly raise the profile
of the need for effective risk management.

1.5 THE IT FUNCTION


LEARNING OBJECTIVES
6.5.1 Understand the role of the IT function in the context of the
operational risk environment

Operational risk exists throughout the IT process, from strategic decisions about IT, managing projects,
to design, implementation and maintenance. The IT function is responsible for:

• maintaining an adequate day-to-day systems environment; and


• delivering strategic change solutions that meet the business needs. The technology causes of
operational risk have already been explained in Chapter 4 and the risk management responsibility
for these causes sit within the IT function. In summary, its broad responsibilities include:
• highlighting and managing deficiencies in the design or operation of all systems that support the
firm’s activities;

Operational Risk 123


The Support and Control Functions Chapter Six

• protecting the organisation from system security issues such as viruses and hacking;
• ensuring system development keeps pace with rapidly evolving user requirements; and
• ensuring that systems integrate effectively, thereby minimising manual intervention and data
integrity issues.

1.6 THE LEGAL FUNCTION


LEARNING OBJECTIVES
6.6.1 Understand the role of the legal function in the context of the
operational risk environment
6.6.2 Know the common legal areas where operational risk issues arise

Legal risk is the risk of loss due to legal issues brought about by an inability to enforce legal contracts or
documents.

The legal function’s role is to manage risk by ensuring that:

• contracts accurately represent the firm’s intentions;


• contracts are enforceable.

It does this by implementing effective policies and procedures. Their effectiveness depends on how well
the operational risk issues are managed.

The legal role is critical at the set-up stage when legal agreements are negotiated prior to trading.
Agreements can be at the entity, product or transaction level. They are designed to cover any legal
eventuality that may reasonably occur, as agreed by the business line, during the course of the contract.

1.6.1 Operational Risk Impact


Some common legal areas where operational risk issues exist are:

• Contract formation - ensuring the appropriate legal documentation is in place and is satisfactory
prior to trading. Getting the contract details right at the outset is one of the main responsibilities of
the legal function. The best way to avoid legal risk is to produce contracts that are taut and clear.
This would be done in conjunction with advice from the relevant business area.
• Legal names - confirming the counterparty’s legal name helps to establish the legal, contractual
rights of each party.
• Jurisdiction - law in one jurisdiction may not apply, or apply differently, in another.
• Netting arrangements - netting is used as a means of reducing credit risk. The terms or rules for
netting must be contractually agreed and care taken to ensure enforceability.
• Collateral arrangements - ensuring that all collateral arrangements are legally enforceable and
cover the assets intended.
• Power to transact - ensuring the counterparty has the legal power to transact, ie, checking that it
is not ultra vires.
• Employee authority - ensuring that the counterparty’s employees have the appropriate authority
to transact.

124 Operational Risk


The Support and Control Functions Chapter Six

• Fiduciary responsibilities - ensuring the fiduciary responsibilities of a firm are understood, ie,
having a duty of care. A fiduciary is an individual, corporation or association holding assets for
another party, often with the legal authority and duty to make decisions regarding financial matters
on behalf of the other party.
• Client Relationship - ensuring the maintenance of an arm’s length relationship with the client (via
the legal agreement) and disclosure of the relevant risks. There must be clarity between an arm’s
length relationship and an advisory relationship.

1.7 THE MARKETING FUNCTION


LEARNING OBJECTIVES
6.7.1 Understand the role of the marketing function in the context of the
operational risk environment

The marketing function plays a critical role in linking sales, development, customers and potential
customers of a business. Typical responsibilities of the marketing function include:

• identifying customer needs and wants;


• planning and creating ideas, goods or services to satisfy needs and wants;
• establishing pricing that results in profitable transactions;
• promoting ideas, goods or services to an identified target market;
• ensuring all promotional material is appropriate and compliant;
• managing distribution and logistics strategies; and
• understanding competitors and the market fully.

The marketing function will also have a responsibility to ensure that the business does not grow too
rapidly, resulting in the problems of not having enough resources to cope with the increase in demand
for its services, for example, staff, IT systems and related infrastructure. This also needs to be balanced
with having an optimum level of business to ensure survival.

1.8 THE PROJECT MANAGEMENT AND CHANGE


MANAGEMENT FUNCTION
LEARNING OBJECTIVES
6.8.1 Understand the role of the project management and change
management function in the context of the operational risk
environment

The project management team aims to bring about the successful completion of specific project goals
and objectives. It is often referred to as program management. The change management team ensures
that any required system changes are implemented in a controlled manner by following a predefined
framework or model. The various operational risks faced by both of these functions will need to be
identified and managed throughout the process.

Operational Risk 125


The Support and Control Functions Chapter Six

END OF CHAPTER QUESTIONS


Think of an answer for each question and refer to the appropriate section for confirmation.

Question Answer Reference

1. Which aspects of the life cycle are covered by the compliance function? Section 1.1.1

2. What is compliance risk? Section 1.1.1

3. Describe three objectives of the compliance function. Section 1.1.1

4. What three questions does the internal audit function seek to answer
when performing reviews? Section 1.4

5. What is the difference between the role of the internal audit function
and the role of the risk management function? Section 1.4

126 Operational Risk


CHAPTER SEVEN

ENTERPRISE RISK
MANAGEMENT (ERM)
1. THE OBJECTIVES OF ERM 129
2. THE CHALLENGES OF IMPLEMENTING ERM 130

This syllabus area will provide approximately 1 of the 50 examination questions

Operational Risk 127


Enterprise Risk Management (ERM) Chapter Seven

128 Operational Risk


Enterprise Risk Management (ERM) Chapter Seven

1. THE OBJECTIVES OF ERM


LEARNING OBJECTIVES
7.1.1 Understand the objectives of ERM

Enterprise risk management (ERM) is also known as integrated risk management or firm-wide risk
management. It is a concept that provides a firm with the ability to understand, address and manage
their interrelated financial risks in the most effective way. It is commonly referred to as integrated
risk management or firm-wide risk management because it is a structured, consistent and continuous
process across the whole organisation (which could extend outside the UK) for identifying, assessing,
deciding on responses to, and reporting on, opportunities and threats that affect the achievement of its
objectives.

One of its main aims is to protect shareholder value by integrating the management of all the disparate
risks of a portfolio of businesses. This allows a firm to appreciate its overall risk profile and to identify
and explain financial risk in a transparent, structured and comprehensive way.

In terms of measuring risk, a recent development is the attempt to measure total risk using an
integrated Value-at-Risk (VaR) model. Such a model would calculate a total capital-at-risk figure which
would allow appropriate financial provisioning and help strategic decision-making.

In order to protect shareholder value, ERM has four practical objectives that make financial risk
management more effective. These are to:

• optimise the overall risk process;


• provide an understanding of total risk exposure, for example collating and reporting to the board all
the information from many different parts of the firm;
• manage the consequences of risk in an integrated manner; and
• ensure the firm has a common understanding of risk and risk language.

These objectives are common to any risk management process. The difference with ERM is that it
integrates the management of ALL risks. This means generating a common framework and using a
common approach and common systems for the management of:

• market risk;
• credit risk;
• operational risk;
• strategic risk; and
• business risk.

Much of the effort involved in ERM at present is in understanding the interrelationship between the
different risk types that face a business and improving the way the various risk specialists work with
each other in forming the overall risk picture.

As a result, ERM is the next major strategic step forward for financial institutions to help them manage
their risk.

Operational Risk 129


Enterprise Risk Management (ERM) Chapter Seven

2. THE CHALLENGES OF IMPLEMENTING ERM


LEARNING OBJECTIVES
7.1.2 Understand the challenges of implementing ERM

There are a number of areas to be considered when implementing an effective ERM policy. These
include:

• Has the firm adopted a common process for risk management and is there a common
understanding of risk and risk management within the firm?
• How are risk management tools being applied to decision-making within the firm and are they being
used effectively and consistently?
• Do all the firm’s business and operational plans consider risks and incorporate measures to mitigate
those risks and/or to maximise opportunities?
• Is there a full understanding of how each risk area impacts others within the risk teams, to allow
them to provide adequate challenge to business decisions?

130 Operational Risk


Enterprise Risk Management (ERM) Chapter Seven

END OF CHAPTER QUESTIONS


Think of an answer for each question and refer to the appropriate section for confirmation.

Question Answer Reference

1. What is the main aim of ERM? Section 1

2. What is enterprise risk management (ERM)? Section 1

3. What is ERM also known as? Section 1

4. What are the four objectives of ERM? Section 1

Operational Risk 131


Enterprise Risk Management (ERM) Chapter Seven

132 Operational Risk


CHAPTER EIGHT

ACHIEVING COMMON
STANDARDS AND PROTECTION
1. INTRODUCTION 135
2. MARKET DEVELOPMENTS 135
3. MARKETS IN FINANCIAL INSTRUMENTS DIRECTIVE (MiFID) 138

This syllabus area will provide approximately 3 of the 50 examination questions

Operational Risk 133


Enterprise Risk Management (ERM) Chapter Eight

134 Operational Risk


Enterprise Risk Management (ERM) Chapter Eight

1. INTRODUCTION
This chapter describes the main events that have occurred so far in the development of standard
practice, culminating in the publication of the proposal for a new Capital Accord. This includes an
explicit treatment of operational risk for the first time and represents a watershed in the drive for
common standards and protection.

The operational risk area is relatively immature in financial services and there remain practical difficulties
in identifying and accurately assessing exposures. For this reason, standard methodologies have not yet
found widespread agreement. There are, however, guidelines for good practice which are available for
firms to use.

These guidelines have evolved over the past 10 to 15 years as a result of global research, surveys and
investigation into the disparate methods of understanding, assessing and managing operational risk.
These investigations have attempted to highlight the most promising and effective practices in the
industry and have gradually developed a body of knowledge that can be called good practice.

2. MARKET DEVELOPMENTS
LEARNING OBJECTIVES
8.1.1 Understand the drivers of the development of operational risk
standards: Basel Accord; Sound Practices for the Management and
Supervision of Operational Risk; European Commission;
Sarbanes-Oxley; UCITS IV; Solvency II; RDR; AIFMD
8.1.3 Understand how these developments affect financial institutions
8.1.4 Understand how these developments impact the operational risk
management environment

As the importance of operational risk has grown, there has been a gathering momentum from
international regulators to ensure that it is managed in an objective and consistent manner. There is
now an accepted belief that it should be assessed separately from credit risk and market risk and that
regulatory capital should be provided for separately.

The concepts for risk management have been developed by the industry to the point where a number
of reasonably sophisticated techniques are now being employed. There is, however, no commonly
accepted approach, nor is there a convincing argument that there should be one. Operational risk,
unlike credit risk and market risk, involves the assessment and management of risks whose cause can lie
outside a firm’s control and whose effects are not capable of being limited or capped. In addition, each
firm has a unique environment and a unique risk appetite, so it is becoming accepted that operational
risk will be managed differently as a result. This is understood by the regulators and is being reflected in
their new rules.

Operational Risk 135


Enterprise Risk Management (ERM) Chapter Eight

A committee was formed under the auspices of the Bank for International Settlements (BIS). Known
as the Basel Committee on Banking Supervision, it comprises representatives from central banks
and regulatory authorities. Over time, the focus of the committee has evolved, embracing initiatives
designed to address the regulatory supervision of banks and to promote uniform capital requirements
so banks from different countries may compete openly with one another.

The Basel Committee, which has, since 1988, set capital adequacy standards for banks in respect
of credit risk, began addressing the need for setting aside additional capital for both market risk
and operational risk during the 1990s in response to market events including the Barings crisis and
other high profile cases. The original requirement for banks to hold as capital 8% of their risk assets
is gradually being extended. Market risk as a result of VaR measurement was added to the capital
requirement formula in 1996.

In January 1999, the Basel Committee proposed a New Capital Accord. In 2001 and 2003 the Basel
Committee introduced some consultation papers. The New Capital Accord was published in June 2004
and became known as the New Basel Accord or Basel II. For the first time, the requirement for specific
capital to cover operational risk was introduced. Greater detail on the Basel II Accord is included in
Chapter Three, Section 10.1. Please note that Basel II has a global significance to financial institutions
and is not limited in scope to the EU.

There was a desire to harmonise capital requirements for banks and securities dealing firms across
the EU. The solution implemented with the 1993 Capital Adequacy Directive (CAD) was to regulate
functions instead of institutions.

CAD established uniform capital requirements applicable to both universal banks’ securities operations
and non-bank securities firms. A universal bank would identify a portion of its balance sheet as
comprising a ‘trading book’. Capital for the trading book would be held in accordance with CAD while
capital for the remainder of the bank’s balance sheet would be held in accordance with the 1988 Basel
Accord.

Europe developed CAD at the same time that the Basel Committee was developing an amendment
covering market risk for its 1988 Capital Accord. The two initiatives influenced each other. Essentially,
Europe was pursuing locally what Basel was pursuing globally. European regulators had hoped that both
initiatives could be completed simultaneously, but this did not occur. The EU had set a deadline of 1992
for reaching agreement on all significant single-market legislation.

2.1 THE RISK MANAGEMENT GROUP OF THE BASEL


COMMITTEE
The Risk Management Group of the Basel Committee on Banking Supervision has set out some
principles that provide a framework for the effective management and supervision of operational risk,
for use by banks and supervisory authorities when evaluating operational risk management policies and
practices. The Committee realised that the exact approach for operational risk management chosen
by an individual bank will depend on a range of factors, for example, its size and sophistication and the
nature and complexity of its business activities.

136 Operational Risk


Enterprise Risk Management (ERM) Chapter Eight

However, despite these differences, clear strategies and oversight by the board of directors and
senior management, a strong operational risk culture and internal control culture (including, among
other things, clear lines of responsibility and segregation of duties), effective internal reporting and
contingency planning are all vital elements of an effective operational risk management framework for
banks of any size and scope.

In 1993, CAD and proposals for the Basel amendment were very similar. Both calculated capital
requirements for a trading book based upon a building-block VaR measure.

The EU and Basel processes have now converged. CAD was superseded by the Capital Requirements
Directive (CRD) in June 2006, which represents the EU’s interpretation of Basel II. The EU capital
requirements for implementation by national regulators across member states are
to be based upon the Basel II approach.

Following the stock market falls in 2001, particularly the collapse of technology, media and telecom
stocks which resulted in significant investor losses, the New York Attorney General conducted an
investigation into the quality and impartiality of advice given by research analysts.

Serious conflicts of interest in the production of investment research were uncovered and US
regulatory action followed with the enactment of the Sarbanes-Oxley Act 2002. The Act brought
in new rules relating to public company accounting, auditor independence, corporate responsibility
and analysts’ conflicts of interest. It gave the US Securities Exchange Commission (SEC) the power
to regulate, or to require securities associations and national securities exchanges to create rules to
protect investors and the public interest. Subsequently, many more rules have been introduced, for
example, the requirement that analysts now certify the truthfulness of their views and to disclose if they
have received payment for them.

An EU directive called UCITS IV (Undertakings for Collective Investments in Transferable Securities)


was approved by the European Parliament in January 2009 and is to be implemented in 2011. The
changes from UCITS III include notification procedure, key investor information, adapted framework
for mergers, master feeder structures, co-operation between member state supervisory authorities and
management company passport.

UCITS directives allow collective investment schemes to operate freely throughout the EU on the basis
of a single authorisation from one member state. Agreeing on a common set of rules for all member
states has proved to be very difficult, often slowed down by a range of political and industry-related
disagreements.

Solvency II is the updated set of regulatory requirements for insurance firms that operate in the EU. It
aims to develop a single market in insurance services in Europe, while trying to maintain an adequate
level of consumer protection. A number of member states have realised that the current EU minimum
requirements are not sufficient and have implemented their own amendments. This has the effect of
slowing down the high level reforms that are proposed.

Solvency II is a risk-based system as risk will be measured on consistent principles and capital
requirements for assets and liabilities will depend directly on this. It aims to reduce the risk that an
insurance company would be unable to meet its claims and to reduce losses suffered by policyholders
should a firm be unable to meet its claims in full.

Operational Risk 137


Enterprise Risk Management (ERM) Chapter Eight

The FSA announced the Retail Distribution Review (RDR) in 2009, which will affect the way in which
retail clients receive advice regarding financial products and services. The outcomes which the FSA aim
to achieve are:

• to provide greater consumer clarity on products and services;


• to ensure that more consumers have their needs and wants addressed;
• to have in place standards of professionalism that inspire confidence;
• to make sure that remuneration of advisers works in favour of the consumers;
• to ensure that the financial services industry remains viable over the long-term;
• to ensure that the financial regulatory framework does not stifle innovation within the industry.

The FSA aims to raise the minimum levels of competence, skills and knowledge for advisers that give
financial advice to retail clients. The minimum level of benchmark qualifications for such advisers will be
raised accordingly.

The Alternative Investment Fund Managers Directive (AIFM Directive) was proposed by the European
Union (EU) in 2009. It aims to regulate fund managers of alternative investments, rather than the funds.
Under the proposal, only AIFM’s established in the EU will be able to provide their services and sell
their funds to investors in the wider European Economic Area (EEA).

In order to get permission to market their funds in the EEA, the AIFM’s must be authorised by the
regulator of the EU country in which they are established. Managers based outside the EU will be
prohibited from marketing their funds in the EEA unless they meet various fiscal and regulatory
requirements. Managers based in the EU, who operate funds established outside the EU, are also
subject to additional restrictions.

3. MARKETS IN FINANCIAL INSTRUMENTS


DIRECTIVE (MIFID)

3.1 MIFID – RISK MANAGEMENT POLICIES AND


PROCEDURES FOR FIRMS
LEARNING OBJECTIVES
8.1.2 Understand how MiFID has changed the operational risk management
approach

MiFID – The EU Markets in Financial Instruments Directive – came into force on 1 November 2007.
Its implementation significantly altered financial services regulation in the UK, how firms operate their
businesses and the way they interact with their customers.

The aim of MiFID is to promote fair, efficient and integrated markets while facilitating competition
between different trade execution methods.

138 Operational Risk


Enterprise Risk Management (ERM) Chapter Eight

Most firms that fall within the scope of MiFID will also have to comply with the Capital Requirements
Directive which sets requirements for the regulatory capital that a firm must hold.

MiFID requires financial services firms to have an effective risk management policy in place together
with internal control mechanisms that are appropriate to each individual firm. Firms are asked to
identify the risks relating to their activities, processes and systems and to set the level of risk tolerated
by them.

There were many changes for financial firms including client classification, best execution, information
that is provided to clients, execution-only business, suitability and conflicts of interest.

The MiFID requirements for compliance and internal risk functions are broadly the same as the
UK Financial Services Authority (FSA) rules that are already in place, including the following:

• Firms must establish and maintain policies and procedures aimed at ensuring effective compliance.
• Firms must establish procedures that identify the risks associated with a failure by the firm to
comply with its obligations.
• Firms must establish a monitoring programme to regularly assess and address any inadequacies or
deficiencies arising in the firm’s compliance and address any issues arising.
• Firms must have an independent compliance function (unless inappropriate or impractical to
do so) which has the necessary authority and is structured, resourced and operated effectively.
• Firms must appoint a compliance officer who has the necessary authority and also has the
responsibility for the compliance oversight function.
• If appropriate and proportionate, firms must establish and maintain an internal audit function which
is separate and independent from its other functions and activities.
• Firms must establish, implement and maintain adequate risk management policies and procedures
which identify and set the tolerable level of risk relating to a firm’s activities including employees’
compliance with them.
• Firms must have a separate risk control function, if this is proportionate, depending on the nature,
scale and complexity of its business. The risk function must document the organisation and
responsibilities of the risk assessment function.

The Financial Services Authority believes that the operational risk posed by outsourcing arrangements
presents a large threat to its statutory objectives of providing the appropriate level
of protection for consumers, maintaining confidence in the financial system, promoting awareness for
consumers and reducing financial crime. This is because outsourcing arrangements have the potential
to transfer risk, management and compliance to third parties who may not be regulated and also may
operate offshore. Firms must, therefore, have robust governance arrangements and adequate internal
control mechanisms that cover all outsourcing arrangements.

Operational Risk 139


Enterprise Risk Management (ERM) Chapter Eight

END OF CHAPTER QUESTIONS


Think of an answer for each question and refer to the appropriate section for confirmation.

Question Answer Reference

1. What do the initials ‘BIS’ stand for? Section 2

2. Which regulatory guideline was issued in 1988 and what were its
objectives? Section 2

3. What are the main aims of MiFID? Section 3.1

4. What must firms ensure when creating a compliance function under


the MiFID rules? Section 3.1

140 Operational Risk


Glosssary

GLOSSARY
Accounting Risk
The risk of inaccurate financial reporting.

Asset Securitisation
The practice of pooling bonds or loans with credit risk and selling them as a package to outside
investors.

Advanced Measurement Approaches (AMA)


A group of risk sensitive methods used to calculate the capital charge for operational risk.

Advanced, Risk-Responsive Operating frameWork (ARROW)


The framework the FSA uses to make risk-based regulation operational.

Back Testing
The practice of comparing actual data with predicted data in order to ensure the veracity of a predictive
model.

Basis Risk
The risk of a difference in the impact of market factors on the price of two similar instruments.

Bell Curve
See Normal Distribution Curve.

Benchmarking
In the operational risk context, this means comparison of a firm’s loss data and measures of operational
risk with competitors and other firms in the industry.

Bilateral Arrangement (of Collateral)


Both parties post collateral for the value of their total obligation to the other.

Bottom-Up Measurement
A method of measuring operational risk that builds up a detailed profile of risks occurring in each
process, aggregating these risks to provide overall measures of exposure for the department or the firm
as a whole.

Business Risk
The risk of loss due to an adverse external environment, such as high inflation affecting labour costs; an
over-competitive market reducing margins or legal, tax or regulatory changes in the markets.

Operational Risk 141


Glossary

Central Counterparty (CCP)


The guarantor of contracts normally, but not necessarily, for exchange-traded products, usually the
clearing house of an exchange.

Collateral (Margin)
An asset held by a lender on behalf of an obligor, under certain agreed conditions, as security for a loan
or borrowed assets. An acceptable asset used to cover a margin requirement.

Commodity Price Risk


This is the risk of an adverse movement in the price of a commodity.

Compliance Risk
The risk to earnings or capital arising from violations, or non-conformance with laws, rules, regulations,
prescribed practices or ethical standards. See also Regulatory Risk.

Confidence Level
An assessment of the probability that an event will occur, usually expressed as a percentage.

Confirmation Process
The process of agreeing the details of a transaction with a counterparty.

Convexity
A second order measure of the exposure of fixed income products to interest rate risk by calculating
how much duration changes with respect to interest rates.

Correlation Simulation
A VaR measure that calculates the volatility of each risk factor from historical data and estimates its
effect on the portfolio to give an overall composite VaR that includes all risk factors.

Credit Default Swap


A bilateral financial contract in which one counterparty (the protection buyer) pays a periodic, or one-
off, fee (typically expressed in basis points on the notional amount), in return for a contingent payment
by the other counterparty (the protection seller) following a credit event of a reference entity.

Credit Derivatives
Specialised over-the-counter (OTC) products that allow the transfer of credit exposure between
parties.

Credit Event
An adverse change such as bankruptcy, insolvency, receivership, material adverse restructuring of debt,
or failure to meet payment obligations when due.

142 Operational Risk


Glosssary

Credit Exposure
The amount that can potentially be lost if a debtor defaults on their obligations.

Credit Limits
The maximum limits for lending set by financial institutions to prevent too much exposure to a
particular firm or counterparty.

Credit Rating
An assessment of the credit worthiness of a firm that is used by lenders to manage their credit
exposure.

Credit Risk
The potential loss of earnings or capital due to an obligor’s failure to meet the terms of a contract or
otherwise failing to perform as agreed.

Credit Risk Premium


The difference between the interest rate a firm pays when it borrows and the interest rate on a default-
free security, such as a government bond.

Current Exposure
The current obligation outstanding.

Delta
A first order measure of the exposure of derivatives to a risk factor such as the change in value of the
underlying instrument.

Detective Controls
Operational controls that detect errors once they have occurred and prevent further losses.

Direct Credit Risk


The simple risk of loan default where money is lent to a customer.

Direct Loss
The direct financial penalty that a firm incurs as a result of a risk being realised.

Direct Market Risk Factors


The factors that have a direct bearing on an instrument’s price, such as the financial performance of a
company and the health of its balance sheet.

Operational Risk 143


Glossary

Distribution Analysis
A statistical means of using historical data to predict future events.

Diversification
A means of offsetting risk by spreading it across borrowers in different, negative correlating industry
sectors.

Downside
The negative aspect of incurring risk.

Duration
A first order measure of the exposure of fixed income products to changes in the risk factor of interest
rates.

Enterprise Risk Management (ERM)


A philosophy that provides a firm with the ability to understand and address any risk in any area in the
most effective way.

Equity Price Risk


The risk of adverse movements in share prices affecting a portfolio.

External Detective Controls


Controls that detect errors and losses once they have been realised, ie, they detect the consequence.

External Environmental Causes


Environmental causes of operational risk arising from external influences such as economics, law, tax
policies and natural events (eg, fire and flood).

Fiduciary Responsibility
The duty of care and trust an individual, corporation or association has when holding assets for another
party.

Financial Risk
The quantifiable likelihood of loss or less-than-expected returns.

First Order
A general sensitivity measure of how much the value instrument or portfolio is affected by (ie, is
sensitive to) changes in a risk factor.

144 Operational Risk


Glosssary

Fitch Ratings
A credit rating agency.

FX Rate Risk
The risk of adverse movements in exchange rates.

Gamma
A second order measure of the exposure of derivatives to a risk factor such as the change in value of
the underlying instrument. The rate of change of delta.

Hedge
A means of reducing the risk of adverse price movements by taking an offsetting position in a related
product.

Historical Loss Analysis


The process of identifying previous loss events and attributing them to operational risk event types or
causes.

Historical Simulation
The simplest method of VaR calculation that uses actual historic data to estimate risk exposure in the
future.

Indirect Loss
The loss associated with the opportunity costs or losses of a risk being realised.

Indirect Market Risk Factors


The factors that have an indirect bearing on an instrument’s price, such as interest rate levels, economic
events, political and environmental effects.

Initial Margin
The amount a futures market participant must deposit with the broker or clearing house at the time he
takes a position in a contract.

Interest Rate Risk


The risk of adverse movements in interest rates.

Internal Detective Controls


Controls that detect errors after they have occurred but before a potential loss is realised in the outside
world, ie, they detect the internal effect in order to prevent the consequence.

Operational Risk 145


Glossary

Internal Environmental Causes


Environmental causes of operational risk arising from a firm’s business strategy.

Issuer Risk
The risk of default, with respect to redemption or interest servicing, when one institution holds debt
securities issued by another institution.

Key Risk Indicators (KRIs)


Objective measurement criteria that measure a firm’s ongoing risk status.

Legal Risk
The risk of loss due to the unenforceability of contracts or documents.

Liquidity Risk
The risk that an institution will not be able to meet its liabilities as they become due because of an
inability to liquidate assets or obtain enough funding or that it cannot easily unwind or offset specific
exposures without significantly lowering market prices because of inadequate market depth or market
disruptions.

Loan Sales
The practice of a firm making a loan to a company and then selling the loan to other institutions or
investors.

Loss, Given Default (LGD)


The estimated loss that a firm would incur at a specific time if a counterparty defaulted.

Margin
See Collateral. Money or collateral deposited that serves as a performance guarantee.

Market Liquidity Risk


The risk of loss through not being able to trade in a market or obtain a price on a desired product when
required.

Mark-to-Market
The present value of an instrument.

Market Risk
The potential loss of earnings or capital arising from changes in the value of portfolios of financial
instruments.

146 Operational Risk


Glosssary

Market Risk Limit


See Stop-Loss Limit.

Mean
The average of a group of numbers, calculated by dividing the sum of all the numbers by however many
numbers are in the group.

Moody’s
A credit rating agency.

Negative Correlation
An inverse, or opposite relationship between two factors.

Netting
The practice whereby two parties who exchange multiple cash flows during a given day agree bilaterally
to net those cash flows to one payment per currency, thereby reducing settlement risk. Multi-lateral
netting between a group of counterparties is performed by a clearing house.

Normal Distribution Curve


A common form of probability distribution which is continuous, symmetrical about its mean and is
defined by its mean and standard deviation.

Obligor
A party that has a financial obligation to another party.

Off-Balance-Sheet Transaction
A transaction that is not required to be reported in a firm’s financial accounts.

On-Balance-Sheet Transaction
A transaction that is required to be reported in a firm’s financial accounts.

Operational Controls
Activities that are inserted into a process to protect it against specific operational risks.

Operational Risk Policy


A framework for operational risk management.

Outsourcing
The transfer of an aspect of a firm’s business to a third party who will carry the risk exposure for a fee.

Operational Risk 147


Glossary

Over-The-Counter (OTC) Product


A product that is traded via a bilateral agreement between two counterparties off-exchange.

Pillar 1
The rules in the New Basel Capital Accord that define the minimum ratio of capital to risk weighted
assets.

Pillar 2
The supervisory review pillar of the New Basel Capital Accord, which requires supervisors to
undertake a qualitative review of a bank’s capital allocation techniques and compliance with relevant
standards.

Pillar 3
The disclosure requirements of the New Basel Capital Accord, which facilitate market discipline.

Portfolio
A collection of investments owned by the same individual or organisation.

Position Reconciliation Process


The process of ensuring that all managed positions are the same as those being settled.

Positioning Process
The process of ensuring that there is sufficient cash or stock available to fulfil the contract.

Post-Settlement Stage
The third stage of a transaction’s lifecycle involving the movement of, and control over, cash and
physical assets.

Potential Exposure
The likely maximum loss (for a specified confidence level) in the event of default at a particular point in
time.

Pre-Settlement Risk
The risk that an institution defaults prior to settlement when the instrument has a positive economic
value to the other party.

Pre-Settlement Stage
The second stage of a transaction’s lifecycle involving the capture and agreement of transaction-specific
data.

148 Operational Risk


Glosssary

Preventive Controls
Operational controls that prevent errors occurring.

Price Level Risk


The risk of potential adverse changes in the price of a financial instrument.

Price Uncertainty
The uncertainty of knowing whether market prices will move in a favourable or adverse direction.

Probability Distributions
Mathematical functions that describe the probabilities of possible outcomes occurring. They are
depicted as graphs with the ‘probability of occurrence’ on the vertical axis and the ‘possible outcome’
on the horizontal axis.

Probability of Default (PD)


The estimated likelihood that a counterparty will default on an obligation.

Process
A set of activities that allows the firm to deliver its product to the customer. A process takes a
collection of inputs and turns them into desired outputs by adding value to them.

Project Risk
The risk that the failure or partial failure of a project to meet its objectives leads to financial loss.

Ranking
A method of assessing risk by estimating the likelihood of it being realised and the magnitude of its
impact. This information is usually depicted graphically.

Reconciliation
An accounting function that ensures the firm’s record of cash and stock movements agrees with its
statement of balance and holdings.

Regulatory Risk
The risk to earnings or capital arising from violations or non-conformance with laws, rules, regulations,
prescribed practices or ethical standards. See also Compliance Risk.

Risk
The hazard or chance of bad consequences or loss occurring.

Operational Risk 149


Glossary

Risk Factor
An environmental effect that influences the price of a financial instrument or value of a portfolio.

Risk Management
The implementation of a strategic process that reduces the likelihood of risks being realised to
acceptable levels.

Risk Measurement
Risk measurement is concerned with understanding the size of a risk by trying to predict a future event
using past knowledge.

Risk Profile
The types of operational risks that are faced by a firm and its exposure to those risks.

Scenario Analysis
A subjective method of highlighting potential risk issues in order to allow preventative action to be
taken.

Second Order
A sensitivity measure that accounts for a changing relationship between the value of the portfolio/
instrument and the associated risk factor (or a curved line if expressed as a graph).

Securitisation
See Asset Securitisation.

Sensitivity Analysis
A means of understanding how the price of a financial instrument or value of a portfolio changes in
response to influencing effects.

Settlement
The fulfilment of contractual commitments such as payment of cash for securities. The conclusion of a
securities transaction by delivery against payment.

Settlement Risk
The risk that occurs when there is a non-simultaneous exchange of value and one party defaults.

Set-Up Stage
The first stage of a transaction’s lifecycle involving all pre-transaction activities.

150 Operational Risk


Glosssary

Solvency II
Aims to provide a single European marketplace for insurance services.

Standard Deviation (SD)


A means of measuring variability, uncertainty or volatility of return. It measures how far a variable
moves over time away from its average (mean).

Standard & Poor’s


A credit rating agency.

Stop-Loss Limit
The specified maximum loss that a firm is prepared to make.

Strategic Risk
The risk of loss due to a sub-optimal strategy being employed and associated with the way the
institution is managed. For instance, a competitor or product strategy may be employed that fails to
maximise the return on the investment made.

Stress Testing
A means of testing the accuracy of VaR models against ‘extreme’ market event scenarios.

Trade Instruction Process


The process of agreeing delivery instructions with a third party.

Transaction Capture
The activity of capturing trades in back office systems.

UCITS IV
Undertakings for Collective Investments in Transferable Securities – aims to provide a single European
marketplace for collective investments.

Underwriting Standards
The standards that financial institutions apply to borrowers in order to evaluate their creditworthiness
and therefore limit the risk of default.

Unilateral Arrangement (of Collateral)


One party gives collateral to the other.

Upside
The positive aspects of incurring risk.

Operational Risk 151


Glossary

Value-at-Risk (VaR)
The maximum loss that can occur with a specified confidence over a specified period of days.

Value Chain
A number of processes that must occur to achieve a desired outcome.

Variance/Co-Variance Simulation
See Correlation Simulation.

Variation Margin
A demand for extra cash cover for margin made by broker and clearing houses on a daily basis to reflect
changes in the market value of the trades.

Volatility
The relative rate that a financial instrument’s price moves up and down.

Volatility Risk
The risk of price movements that are more uncertain than usual affecting the pricing of products.

Volume Sensitivity
A process cause of operational risk where the workload increases in proportion to increasing volumes.

152 Operational Risk


Glosssary

ABBREVIATIONS
AMA Advanced Measurement Approach

ARROW Advanced, Risk-Responsive Operating Framework

BBA British Bankers’ Association

BIS Bank for International Settlements

CAD Capital Adequacy Directive

CCP Central Counterparty

CDS Credit Default Swap

COB Conduct of Business Rules

CRD Capital Requirements Directive

DVP Delivery Versus Payment

EC European Commission

ERM Enterprise Risk Management

EU European Union

FSA Financial Services Authority

HR Human Resources

IRM Integrated Risk Management

IT Information Technology

KPI Key Performance Indicator

KRI Key Risk Indicator

LCH London Clearing House ([Link] Group)

LDA Loss Distribution Approach

LGD Loss, Given Default

LGE Loss, Given Event

LSE London Stock Exchange

MI Management Information

MiFID Markets in Financial Instruments Directive

MIS Management Information Systems

OR Operational Risk

Operational Risk 153


Glossary

ORM Operational Risk Management

OTC Over-The-Counter

P&L Profit and Loss

PD Probability of Default

PE Probability of Event

PSR Pre-Settlement Risk

SD Standard Deviation

SR Settlement Risk

SSI Standard Settlement Instruction

VaR Value-at-Risk

154 Operational Risk


Multiple Choice Questions

MULTIPLE CHOICE QUESTIONS


The following additional questions have been compiled to reflect as closely as possible the examination
standard you will experience in your examination. Please note, however, they are not the CISI
examination questions themselves.
Think of an answer for each question and refer to to the end for the answers.

1. One of the key operational issues which lead to the huge losses incurred by the National Australia
Bank in 2004 was the:
A. Integrity of people
B. Implementation of new systems
C. Lack of capacity
D. Mistreatment of shareholders

2. Which of the following statements is an advantage of credit derivatives?


A. They help to reduce concentrations of credit risk
B. They reduce market volatility
C. They replace the need for diversification
D. They allow credit risk to be monitored

3. Which of the following is an attribute of a normal distribution curve?


A. It is symmetrical about its standard deviation
B. It is plotted about its median
C. Its average value is always greater than its standard deviation
D. It is defined by its standard deviation and its mean

4. A ‘lack of capacity’ is an example of which cause of risk?


A. People
B. Process
C. Technology
D. Environment

5. The key role of the compliance function is to ensure that the firm:
A. Defines programmes to enhance individual accountability
B. Issues guidelines on collateral and margin usage
C. Operates according to corporate governance parameters
D. Accurately compiles reports of its assets and liabilities

6. A clash of cultures is a likely effect of which of the following?


A. Poor leadership
B. Interdepartmental conflict
C. Mergers
D. The introduction of a new risk policy

Operational Risk 155


Multiple Choice Questions

7. The risk of a difference in the impact of market factors on the price of two similar investments, is
normally known as:
A. Volatility risk
B. Basis risk
C. Settlement risk
D. Liquidity risk

8. Which of the following is a means of mitigating credit risk within a portfolio?


A. Hedging
B. Top slicing
C. Diversification
D. Equalisation

9. Where Value-at-Risk back testing shows unsatisfactory differences between the estimates and
reality, what action is normally taken?
A. Additional capital is sought
B. The methodology model is reviewed
C. A report is immediately issued to the FSA
D. Extra hedging is arranged

10. Which of the following is an environmental cause of risk?


A. An increase in staff resignations
B. The introduction of new delivery mechanisms
C. The lack of a strategic approach to risk management
D. Inadequate control procedures

11. The primary purpose of positioning is to ensure that:


A. Delivery occurs on time
B. Funding deadlines are met
C. There are sufficient assets available to fulfil a contract
D. The bank’s stock and cash holdings are liquid

12. Pillar 3 of the New Capital Accord is primarily concerned with:


A. The regulatory review process
B. Calculating capital adequacy
C. Operational risk measurement
D. Public disclosure

13. Which ONE of the following statements BEST describes settlement risk?
A. The risk of losses caused by the failure of a firm to pay its creditors
B. The risk of loan default where money is lent to a customer
C. The risk that occurs when there is a non-simultaneous exchange of value and one party defaults
D. The risk that an institution defaults prior to settlement when the instrument has a positive
economic value to the other party

156 Operational Risk


Multiple Choice Questions

14. The operational risk policy of a bank should normally be:


A. Provided in writing to all customers
B. Sponsored at board level
C. Registered with the Bank of England
D. Compiled by the Compliance Officer

15. What stage normally follows immediately after the Risk Measurement and Assessment stage in a
typical risk management process?
A. Risk identification
B. Risk reporting
C. Risk mitigation
D. Risk monitoring

16. What is the minimum level of capital required to be held by financial institutions as protection
against the realisation of financial risk?
A. 6%
B. 8%
C. 10%
D. 12%

17. Where a firm’s various risks are plotted on a standard risk ranking chart, the highest risks will
normally appear in the:
A. Top right hand quadrant
B. Top left hand quadrant
C. Bottom right hand quadrant
D. Bottom left hand quadrant

18. Which type of measure of operational risk is a means of peer group comparison within the industry?
A. Scenario analysis
B. Cost-based provisioning
C. Benchmarking
D. Ranking

19. The self-assessment approach to risk identification normally utilises which other method of
assessing operational risk?
A. Ranking
B. Scenario analysis
C. KRIs
D. Benchmarking

20. When establishing Key Risk Indicators, which one of the following would be an example of a
non-process related indicator?
A. Volume of transactions per head
B. Number of times a trader exceeds agreed credit limits
C. Annual level of staff turnover
D. Average duration of unsigned confirmations

Operational Risk 157


Multiple Choice Questions

21. Which one of the following is an example of the risk transfer method of mitigating risk?
A. Introducing internal detection controls
B. Designing a contingency planning policy
C. Taking out a fire and theft insurance policy
D. Setting market and credit risk limits

22. One of the primary changes brought about by the Basel 2 Accord was to:
A. Impose quarterly internal reviews of the risk measurement process
B. Introduce incentives for better risk management
C. Exempt MiFID-compliant firms from extra risk requirements
D. Incorporate the requirements of the Sarbanes-Oxley regulations

23. Focus workshops are used to identify risks and their causes because they have the ability to:
A. Ensure risk reporting is being performed
B. Show clearly the adequacy of controls
C. Satisfy regulators that an adequate control environment exists
D. Investigate cross-functional dependencies

24. Contingency planning is an example of which operational risk mitigation strategy?


A. Reducing the likelihood
B. Reducing the impact
C. Transferring the risk
D. Retaining the risk

25. Under the Standardised Approach adopted for Pillar 1 of Basel 2, the beta factor used to calculate
the required capital varies according to:
A. The relative risk level as measured by ranking
B. The relative risk level as measured by benchmarking
C. The firm’s business lines
D. The firm’s age

26. Which ONE of the following methods of measurement has the advantage that accountability for risk
management can be clearly defined?
A. Ranking
B. Scenario analysis
C. Bottom-up
D. Benchmarking

27. Which ONE of the following methods of credit risk mitigation BEST reduces settlement risk?
A. Diversification
B. Delivery versus payment
C. Credit derivatives
D. Credit limits

28. Which Basel II operational risk category does money laundering fall into?
A. Internal fraud
B. External fraud
C. Employment practices and workplace safety
D. Clients, products and business practice

158 Operational Risk


Multiple Choice Questions

29. A bank has been advised that it is to receive an ‘ARROW’ visit in order to review various aspects of
its risk management process. Representatives from which body will conduct this visit?
A. Bank of England
B. HM Treasury
C. Financial Services Authority
D. Office of Fair Trading

30. Which ONE of the following is the BEST reason for using external detective controls?
A. To reduce the likelihood of risk occurring
B. To prevent a risk occurring
C. To reduce the impact of a risk occurring
D. To provide feedback in the risk reporting process

31. When adopting the ‘outsourcing’ method of risk transfer, it is important to appreciate that:
A. The nature of the risk will change rather than be wholly eliminated
B. The transferred risk will be at its greatest towards the middle of the outsourced period
C. The outsourcing cost is likely to outweigh the internal cost savings
D. The regulatory responsibility will fully pass to the outsourced firms

32. One of the key characteristics of technology failure is that:


A. It is impossible to reduce the likelihood of occurrence
B. It is something outside the control of the firm
C. It only impacts on short-term issues
D. It only impacts on long-term issues

33. One of the key reasons why firms have controls in place to ensure segregation of duties between
front office and back office functions, is to:
A. Reduce settlement risk
B. Speed up the processing time
C. Achieve best execution
D. Minimise fraudulent opportunities

34. Where a series of documentary omissions has occurred in a firm, this is often an early indication of:
A. Data capture errors
B. Cultural difficulties
C. Process weaknesses
D. Capital adequacy problems

35. A life office recently breached compliance rules by both missing a reporting deadline and exceeding
an investment limit. In which case, if either, could the cause result from technology issues?
A. In neither case
B. Only in the case of the missed deadline
C. Only in the case of the exceeded limit
D. In both cases

Operational Risk 159


Multiple Choice Questions

36. The primary difference between enterprise risk management (ERM) and market risk management is
that ERM:
A. Focuses primarily on long-term issues
B. Aims to integrate the management of all risks
C. Covers non-financial risks only
D. Operates on a bottom-up approach basis

37. One of the key impacts of the Sarbanes-Oxley Act 2002 was to increase the level of corporate
responsibility in the specific area of:
A. Company accounting
B. Competitor activities
C. Product range
D. Remuneration terms

38. Where a firm’s compliance risk is realised, which one of the following results is MOST likely to
consequently occur?
A. A cross-compensating reduction in the firm’s market risk level
B. Damage to the firm’s credit risk
C. A fall in the firm’s costs
D. Damage to the firm’s reputation

39. Where data has been wrongly captured by a firm, which of the four main root causes will be to
blame?
A. Technology in all cases
B. Environment in all cases
C. It will be people or processes
D. It could be any of the four

40. The primary role of the ‘front office’ of a financial institution is to:
A. Oversee strategy
B. Earn revenue
C. Settle transactions
D. Monitor risk

41. Which specific rule is normally addressed by the employee of a financial institution completing a fact
find?
A. Status disclosure
B. Money laundering
C. Best execution
D. Know your customer

42. Which one of the following is a characteristic of trade confirmations?


A. They are all performed electronically
B. They must be made in writing
C. They are usually based on pre-established legal agreements
D. They usually take place two days after the trade day

160 Operational Risk


Multiple Choice Questions

43. Which one of the following is MOST likely to be a key risk indicator for the positioning stage of the
settlement process?
A. Time taken to formulate a legal agreement
B. Time taken for counterparties to return confirmations
C. Number of late-settled transactions due to lack of funds
D. Number of transactions not captured within a specified time frame

44. The number of ‘breaks’ is often used as a risk indicator in connection with which stage of the front
office support function activities?
A. Transaction instruction
B. Positioning
C. Settlement
D. Reconciliation

45. Where ‘Standard Settlement Instruction’ data is not used for a particular transaction instruction, this
will often result in:
A. Faster processing
B. Additional risk
C. The involvement of an extra third party
D. Problems occurring at the positioning stage

46. Where an independent internal audit section is required under MiFID, this team must:
A. Have sufficient authority
B. Report directly to the Compliance Officer
C. Include a qualified accountant or solicitor
D. Be separately funded from the firm’s reserves

47. The main difference between direct and indirect financial loss, which can result from a risk being
realised, mainly relates to whether the loss:
A. Is borne by a third party
B. Is long lasting
C. Can be quantified
D. Can seriously impact profitability

48. Where a firm carries out an ‘ultra vires’ check, this is done in an attempt to mitigate which
particular risk?
A. Volatility risk
B. Liquidity risk
C. Basis risk
D. Legal risk

49. Contractual ambiguity is a common aspect of which one of the following types of risk?
A. Regulatory risk
B. Basis risk
C. Legal risk
D. Pre-settlement risk

Operational Risk 161


Multiple Choice Questions

50. Which one of the four main root causes of operational risk has a recognised separate internal and
external dimension?
A. People
B. Technology
C. Process
D. Environment

162 Operational Risk


Multiple Choice Questions

ANSWERS TO MULTIPLE CHOICE QUESTIONS


Q1. Answer: A Ref: Chapter 1, Section 2.4
A group of traders concealed losses by falsifying transactions and reporting incorrect profits.

Q2. Answer: A Ref: Chapter 2, Section 3.2.4


Credit derivatives enable credit exposure to be transferred between parties.

Q3. Answer: D Ref: Chapter 2, Section 6.1


It is a bell curve with the mean at the centre and the slopes are dependent on the standard deviation.

Q4. Answer: B Ref: Chapter 2, Section 1.1


A lack of capacity can lead to firms being unable to process business demand.

Q5. Answer: A Ref: Chapter 6, Section 1.1.1


The compliance function defines the programmes and processes and its related accountability.

Q6. Answer: C Ref: Chapter 3, Section 2.1


Culture is strongly influenced by leadership and if two sets of leaders combine, it can create conflict.

Q7. Answer: B Ref: Chapter 2, Section 5.3


Basis risk occurs when one kind of risk exposure is designed to offset another.

Q8. Answer: C Ref: Chapter 2, Section 3.2.1


Diversification is a method of offsetting credit risk in a portfolio by spreading it across borrowers in
different industry sectors.

Q9. Answer: B Ref: Chapter 2, Section 7.4


The model should be revised in order to improve the accuracy of future estimates.

Q10. Answer: B Ref: Chapter 4, Section 1.4


An increase in automation or system complexity can increase technology risk.

Q11. Answer: C Ref: Chapter 5, Section 1.3


The process of positioning ensures that sufficient cash or stock is available to fulfil a contract.

Q12. Answer: D Ref: Chapter 3, Section 10.2


Pillar 3 requires greater public disclosure to allow improved transparency of banks’ risk profiles and
capital adequacy.

Operational Risk 163


Multiple Choice Questions

Q13. Answer: C Ref: Chapter 2, Section 1.3


Settlement risk relates to when one party defaults at the point of exchange.

Q14. Answer: B Ref: Chapter 3, Section 3


In order to be effective the policy should be agreed and explained at board level.

Q15. Answer: C Ref: Chapter 3, Section 4


After a risk has been identified and quantified, steps should be taken to try and mitigate it.

Q16. Answer: B Ref: Chapter 3, Section 10.2


The minimum overall capital ratio under the New Accord is 8%.

Q17. Answer: A Ref: Chapter 3, Section 6.2.1


Those with the relatively largest magnitude and likelihood ratings will appear in the top right section.

Q18. Answer: C Ref: Chapter 3, Section 6.2.5


Benchmarking compares loss data and measures of operational risk with competitors and other firms in
the industry.

Q19. Answer: A Ref: Chapter 3, Section 6.2.2


This method often involves compiling a list of risks which managers then assess and measure.

Q20. Answer: C Ref: Chapter 3, Section 6.2.6


Non-process related indicators primarily cover measures relating to people.

Q21. Answer: C Ref: Chapter 3, Section 8.4


Insurance effectively transfers risk from the policyholder to the insurance company.

Q22. Answer: B Ref: Chapter 3, Section 10.1


Basel 2 introduced a menu of approaches which effectively reward those that operate better risk
management.

Q23. Answer: D Ref: Chapter 3, Section 5.2


By involving all of the functional activities in a process, inter-related dependencies can be identified.

Q24. Answer: B Ref: Chapter 3, Section 8


The ability to anticipate and plan for operational crises is likely to reduce the harm of unexpected
losses.

164 Operational Risk


Multiple Choice Questions

Q25. Answer: C Ref: Chapter 3, Section 10.3.2


The beta factor used is specific to each business line.

Q26. Answer: C Ref: Chapter 3, Section 6.2.4


The owner or manager of a process is identified and usually made accountable for managing the
relevant risks.

Q27. Answer: B Ref: Chapter 5, Section 1.3.3


DVP reduces the risk of settlement failure.

Q28. Answer: D Ref: Chapter 3, Section 10.5


Clients, products and business practice includes misused confidential information and money laundering.

Q29. Answer: C Ref: Chapter 3, Section 10.6


The FSA set up the ARROW project to monitor how firms protect their customers.

Q30. Answer: C Ref: Chapter 3, Section 8.1


External detection controls operate after an error or loss has been realised, in order to limit the effect
of the loss.

Q31. Answer: A Ref: Chapter 3, Section 8.4


The process transforms the risk rather than completely removing it.

Q32. Answer: B Ref: Chapter 4, Section 2.7


Power failure, for example, is often outside the firm’s control.

Q33. Answer: D Ref: Chapter 4, Section 1.1


If a single individual has end-to-end authority, the opportunity for fraud is greatly increased.

Q34. Answer: C Ref: Chapter 4, Section 2.2


The incidence of documentary omissions is likely to be an early warning sign of weaknesses in the
process.

Q35. Answer: D Ref: Chapter 4, Section 2.7


The transgressions could be inadvertently caused by people, process or technology problems.

Q36. Answer: B Ref: Chapter 7, Section 1


ERM attempts to manage a firm’s inter-related risks in the most effective way.

Operational Risk 165


Multiple Choice Questions

Q37. Answer: A Ref: Chapter 8, Section 2.1


Sarbanes-Oxley introduced new rules relating to the sign-off of company accounts.

Q38. Answer: D Ref: Chapter 6, Section 1.1.2


A compliance breach could result in a fine and/or censure, which could affect reputation.

Q39. Answer: D Ref: Chapter 4, Section 1


The problem could originate from any or all of the four main root causes.

Q40. Answer: B Ref: Chapter 5, Section 1.1


The front office is where trading takes place.

Q41. Answer: D Ref: Chapter 5, Section 1.1.2


The fact find is used to gather the required information about the customer.

Q42. Answer: C Ref: Chapter 5, Section 1.2.2


All confirmations are based on a legal agreement set up at outset.

Q43. Answer: C Ref: Chapter 5, Section 1.3.2


Monitoring is carried out to achieve the most efficient use of a firm’s resources.

Q44. Answer: D Ref: Chapter 5, Section 1.3.4


‘Breaks’ measure the volume of unreconciled events.

Q45. Answer: B Ref: Chapter 5, Section 1.3.1


The absence of an automated instruction process means that a separate transaction specific instruction
must be used which increases the risk.

Q46. Answer: A Ref: Chapter 6, Section 1.2


MiFID requires this independent section to have sufficient authority.

Q47. Answer: C Ref: Chapter 4, Section 3.2


Direct financial loss is quantifiable but indirect financial loss is non-quantifiable.

Q48. Answer: D Ref: Chapter 6, Section 1.3.1


Ultra vires means acting beyond one’s authority which could give rise to legal implications.

Q49. Answer: C Ref: Chapter 4, Section 2.6


Contracted ambiguities can lead to unforeseen litigation.

166 Operational Risk


Multiple Choice Questions

Q50. Answer: D Ref: Chapter 4, Section 1


The environment has internal and external influences which separately affect operational risk.

Operational Risk 167


Multiple Choice Questions

168 Operational Risk


Syllabus Learning Map

Syllabus Unit/ Chapter/


Element Section
ELEMENT 1 RISK BASICS CHAPTER 1
1.1 Risk in the Financial Services Industry
On completion, the candidate should:
1.1.1 know the following major risk categories: Section 2.2
• credit risk
• market risk
• operational risk
• liquidity risk
1.1.2 understand simple examples of risk in the financial services industry Section 2.3
1.1.3 understand the operational risk issues associated with major risk Section 2.4
related incidents in the financial services industry, such as:
• Barings Bank (1995)
• Enron (2001)
• Allied Irish Bank / First Maryland Bank (2002)
• National Australia Bank (2004)
• Nationwide (2007)
• Société Générale (2008)
• Standard Life (2009)
• UBS (2009)
1.1.4 understand the operational risk aspects of the banking crisis (2007/9) Section 2.5
ELEMENT 2 OTHER MAJOR RISKS CHAPTER 2
2.1 The Nature of Credit Risk
On completion, the candidate should:
2.1.1 know the basic terms used in the subject of credit risk: Section 1
• counterparty risk
• issuer risk
2.1.2 be able to apply the concept of credit risk to simple, practical Sections
situations 1.3,2.1
2.2 Measuring Credit Risk
On completion, the candidate should:
2.2.1 know the basic techniques for measuring credit risk: Section 2
• credit exposure management
• credit risk premium
• credit ratings
• modern measurement techniques
2.2.2 understand credit exposure Section 2.1
2.2.3 understand credit risk premium Section 2.2
2.2.4 understand external credit ratings as a means to measure the credit- Section 2.3
worthiness of a company
2.2.5 understand the limitations in credit rating agencies’ assessment of a Section 2.3
company

Operational Risk 169


Syllabus Learning Map

Syllabus Unit/ Chapter/


Element Section
2.2.6 understand the basic concepts used by modern credit risk Section 2.4
measurement tools
2.2.7 understand the main limitations of credit risk measurement tools Section 2.5
2.3 Credit Risk Management and Reporting
On completion, the candidate should:
2.3.1 understand the role of the credit risk management function Section 3
2.3.2 understand the following examples of credit risk mitigation: Section 3
• asset securitisation
• central counterparties
• clearing houses
• collateral
• credit derivatives
• credit limits
• diversification
• loan sales
• netting
• underwriting standards
2.3.3 be able to apply risk mitigation techniques to simple practical Section 4
situations
2.3.4 be able to calculate a simple example of a cash netting agreement Section 3
2.3.5 understand the mechanics of a credit default swap in simple practical Section 4
situations
2.3.6 understand the role of reporting and escalation tools of credit risk Section 4
management
2.4 The Nature of Market Risk
On completion, the candidate should:
2.4.1 know the basic features of market risk: Section 5
• price level risk
• volatility risk
• liquidity risk
• basis risk
2.4.2 be able to apply the basic features of market risk to simple, practical Section 5
situations
2.5 Measuring Market Risk
On completion, the candidate should:
2.5.1 understand the measures of central values and dispersion: Section 6
• mean
• median
• mode
• standard deviation
• distribution analysis

170 Operational
Operational Risk
Risk
Syllabus Learning Map

Syllabus Unit/ Chapter/


Element Section
2.6 Value-at-Risk (VaR)
On completion, the candidate should:
2.6.1 understand the meaning of VaR and its constituents Section 7
2.6.2 be able to apply VaR to the mitigation of market risk Section 7
2.6.3 understand the meaning of back testing Section 7
2.6.4 understand the meaning of stress testing Section 7
2.6.5 know the limitations of using VaR for market risk management Section 7
2.7 Market Risk Management and Reporting
On completion, the candidate should:
2.7.1 understand the following techniques for mitigating market risk: Section 8
• hedging
• market risk limits
• diversification
2.7.2 understand the role of the market risk management function Section 9
2.7.3 know good practice for effective market risk management: Section 9
• VaR limit setting, monitoring and reporting
• scenario analysis and stress tests for large market movements
• position limit setting, monitoring and reporting
• pre-transaction analysis and approval
2.8 Market Risk Regulatory Requirements
On completion, the candidate should:
2.8.1 understand the capital adequacy requirements in relation to market Section 10
risk:
• confidence levels
• 10 day holding period
• not less than 250 days historic data
2.9 The Nature of Liquidity Risk
On completion, the candidate should:
2.9.1 know the basic terms used in the subject of liquidity risk: Section 11
• asset and liability management
• maturity ladders
• actual and contractual cash receipts
• asset liquidity risk
• funding liquidity risk
2.9.2 be able to apply the concept of liquidity risk to simple, practical Section 11.2
situations
2.9.3 understand the implications of lending long and borrowing short Section 11.3
2.9.4 understand why banks use basic funding instruments to provide Section 11.4
liquidity
2.9.5 understand the interbank lending process and the concept and Section 11.5
mechanism for using the lender of last resort (central banks)

Operational
Operational Risk
Risk 171
171
Syllabus Learning Map

Syllabus Unit/ Chapter/


Element Section
2.10 Measuring Liquidity Risk
On completion, the candidate should:
2.10.1 know the key measures of asset liquidity risk: Section 12
• bid-offer spread
• market depth
• immediacy
• resilience
2.10.2 know the key measures for funding liquidity risk: Section 12
• yield curve ratios
• interest rate swaps
2.11 LIQUIDITY RISK MANAGEMENT AND REPORTING
On completion, the candidate should:
2.11.1 understand the following techniques of liquidity risk management: Section 13
• asset and liability management
• liquidity limits
• scenario analysis and stress testing
• liquidity at risk
• diversification
• behavioural analysis
2.11.2 understand the role of the liquidity risk management function Section 13
ELEMENT 3 THE NATURE OF OPERATIONAL RISK CHAPTER 3
3.1 Definition of Operational Risk and Operational Risk
Categories
On completion, the candidate should:
3.1.1 know the basic Bank for International Settlements’ definition of Section 1.1
operational risk
3.1.2 know the Basel II operational risk categories Section 1.2,
3.2 Culture
On completion, the candidate should:
3.2.1 understand the importance of effective leadership in sustaining a Section 2.5
robust risk and control culture
3.2.2 understand the role of senior management in promoting an effective Section 2.5
risk and control culture
3.2.3 understand the importance of appropriate personnel management, Section 2.5
incentivisation and compensation schemes in the context of the
operational risk environment
3.2.4 know the main factors determining a firm’s risk and control culture: Section 2.5
• governance
• risk appetite/risk tolerance
• transparency
• education
• communication

172 Operational Risk


Syllabus Learning Map

Syllabus Unit/ Chapter/


Element Section
3.2.5 know the actions required and structures necessary to ensure a Section 2.5
continuing robust risk and control culture
3.2.6 understand the contribution of the risk officers in continuing a Section 2.5
robust risk and control culture
3.3 The Risk Management Process
On completion, the candidate should:
3.3.1 know the basic terms used in the process of operational risk Section 4
management:
• inherent risk
• residual risk
3.3.2 understand the role of the operational risk management function Section 4
3.3.3 understand the key aims of operational risk management: Section 4
identification and assessment of risks
mitigation of risk
reduction of potential impact and likelihood of occurrence
3.3.4 know the six stages of the risk management process: Section 4
• policy
• identification
• measurement and assessment
• mitigation
• monitoring
• reporting
3.4 The Policy for Managing Operational Risk
On completion, the candidate should:
3.4.1 understand the following areas addressed by an operational risk Section 3
policy:
• need for sponsorship
• need for identification of key officers
• need for cross divisional involvement and agreement
• need to define clear roles and responsibilities
• need to define and communicate the risk management
framework
• need for segregation of duties
• need for consistency of approach firm wide
• need for co-ordination
• need to establish acceptable risk levels
• need to define and communicate control standards framework
3.5 Risk Identification
On completion, the candidate should:
3.5.1 understand the purpose of identifying risks Section 5
3.5.2 be able to apply risk categorisation to simple, practical examples: Section 5.2
• process

Operational
Operational Risk
Risk 173
173
Syllabus Learning Map

Syllabus Unit/ Chapter/


Element Section
• people
• technology
• environment
3.5.3 understand the following methods for identifying operational risk: Section 5.2
• risk and control self-assessment
• reviews and audits
• focus workshops
• risk event analysis
• management information
3.5.4 understand the practical problems of risk identification: Section 5.3
• changes to business operating models
• changes to business environment
• firm wide engagement
3.6 Risk Assessment and Measurement
On completion, the candidate should:
3.6.1 know the basic terms used in the assessment and measurement of Section 6
operational risk
3.6.2 understand the main reasons for measuring and assessing Section 6.1
operational risk
3.6.3 understand the difficulties involved in measuring operational risk Section 6.2
3.6.4 understand the ranking method of assessing operational risk Section 6.2.1
3.6.5 understand the risk and control self-assessment (self-certification) Section 6.2.2
method of assessing operational risk
3.6.6 understand the scenario analysis method of assessing operational Section 6.2.3
risk
3.6.7 understand the bottom-up analysis method of assessing operational Section 6.2.4
risk
3.6.8 understand the benchmarking method of measuring operational risk Section 6.2.5
3.6.9 understand the Key Risk Indicators (KRIs) method of measuring Section 6.2.6
operational risk
3.6.10 understand how risk event data can be used in measuring Section 6.2.7
operational risk
3.6.11 be able to apply the following methods of risk assessment and risk Section 6.2
measurement to simple, practical examples:
• rating and ranking
• risk and control self-assessment
• scenario analysis
• bottom-up analysis
• benchmarking
• key risk indicators
• risk event analysis

174 Operational Risk


Syllabus Learning Map

Syllabus Unit/ Chapter/


Element Section
3.6.12 understand the practical constraints of implementing an operational Section 9
risk management framework
3.7 Risk Mitigation
On completion, the candidate should:
3.7.1 understand the use of operational controls in reducing the impact or Section 8
likelihood of operational risk
3.7.2 be able to apply the following methods for reducing operational risk Section 8
exposure:
• reducing the likelihood and the impact
• risk avoidance
• risk transfer
3.7.3 know the common methods for operational risk mitigation: Section 8
• risk control or reduction
• business continuity and contingency planning
• outsourcing
• information and physical security
• risk awareness training
• insurance
3.8 Risk Monitoring, Reporting and Governance
On completion, the candidate should:
3.8.1 understand the main activities that comprise the risk monitoring of Section 6.1
the risk management process:
• measurement
• assessment
3.8.2 understand the importance of risk monitoring in the risk Section 7
management process
3.8.3 understand the main functions of operational risk reporting to Section 7.2
regulators, clients and internal stakeholders
3.9 Regulatory Capital Requirements
On completion, the candidate should:
3.9.1 know the basic requirements of: Section 10.4
• Basel II
• the Capital Requirements Directive
3.9.2 understand the main operational risk features of the Basel II Accord Section 10
3.9.3 understand the Pillar 1 requirements under Basel II Section 10.2
3.9.4 understand the Pillar 2 requirements under Basel II Section 10.2
3.9.5 understand the Pillar 3 requirements under Basel II Section 10.2
3.9.6 understand the three measurement approaches for operational risk Section 10.3
under Basel II:
• Basic Indicator Approach Section 10.3
• Standardised Approach
• Advanced Measurement Approach (AMA)

Operational Risk 175


Syllabus Learning Map

Syllabus Unit/ Chapter/


Element Section
3.9.7 be able to apply the Basic Indicator and Standardised Approaches to Section 10.3
simple, practical examples
3.9.8 understand the principles of the lead UK regulator, the FSA: Section 10.5
• FSA reviews
• ARROW visits
• Internal Capital Adequacy Assessment Process (ICAAP)
ELEMENT 4 THE CAUSES, EVENTS AND IMPACT OF OPERATIONAL CHAPTER 4
RISK
4.1 Operational Risk – The Causes
On completion, the candidate should:
4.1.1 know the root causes of operational risk Section 1
4.1.2 understand how the root causes of operational risk interrelate with Section 1
each other
4.1.3 be able to apply an understanding of process as a root cause of Section 1.1
operational risk to simple, practical situations
4.1.4 be able to apply an understanding of people as a root cause of Section 1.2
operational risk to simple, practical situations
4.1.5 be able to apply an understanding of technology as a root cause of Section 1.3
operational risk to simple, practical situations
4.1.6 be able to apply an understanding of environment as a root cause of Section 1.4
operational risk to simple, practical situations
4.1.7 understand the key causes of incorrect data Section 2.1
4.1.8 understand the key causes of delayed processing and documentary Section 2.2
omissions
4.1.9 understand the key causes of regulatory non-compliance Section 2.3
4.1.10 understand the key causes of project mismanagement Section 2.4
4.1.11 understand the key causes of fraud and theft Section 2.5
4.1.12 understand the key causes of unforeseen litigation Section 2.6
4.1.13 understand the key causes of technology failures Section 2.7
4.2 Operational Risk – The Events
On completion, the candidate should:
4.2.1 know the events arising from operational risk Sections 2, 3
4.2.2 know the main consequences of the following operational risk Section 3.3
events:
• incorrect data
• delayed processing and documentary omissions
• regulatory non-compliance
• project mismanagement
• fraud and theft
• unforeseen litigation
• technology failures

176 Operational Risk


Syllabus Learning Map

Syllabus Unit/ Chapter/


Element Section
4.3 Operational Risk – The Impact
On completion, the candidate should:
4.3.1 understand direct and indirect financial loss Section 3
4.3.2 understand how different events impact on the business: Section 3.4
• costs
• reputation
• fees and fines
• staff demotivation
• client dissatisfaction
• cost of rectification
• litigation
• closure/prohibition
• censure
4.3.3 • be able to apply to simple, practical examples the impact of Section 3.4
different events
ELEMENT 5 OPERATIONAL RISKS ARISING IN THE TRADE CYCLE CHAPTER 5
5.1 Set-up
On completion, the candidate should:
5.1.1 understand what tasks must be completed during set-up: Section 1.1.2
• marketing and sales
• Know Your Customer
• account set-up
• static information
• credit assessment
• standard settlement instructions
• legal contract negotiation
• client and counterparty agreements
5.1.2 understand the key controls and KRIs associated with a set-up phase Section 1.1.2
5.2 Execution
On completion, the candidate should:
5.2.1 understand the role of the Front Office Section 1.1
5.2.2 understand the nature of key controls and KRIs in the Front Office Section 1.1
• transaction capture
• exchange of settlement instructions
• trade reporting
• regulatory transaction reporting
• monitoring position and credit limits
• capital reporting/usage
5.2.3 understand the key controls and KRIs associated with the execution Section 1.1
phase
5.3 Pre-settlement phase

Operational Risk 177


Syllabus Learning Map

Syllabus Unit/ Chapter/


Element Section
On completion, the candidate should:
5.3.1 understand the components of the pre-settlement phase: Section 1.2
• trade affirmation
• trade confirmation
• asset and cash positioning
5.3.2 understand the key controls and KRIs associated with the pre- Section 1.2
settlement phase
5.4 Settlement phase
On completion, the candidate should:
5.4.1 understand the components of the settlement phase: Section 1.3
• payment instructions
• payment receipts
• financial and regulatory reporting
• securities transfers and custody
5.4.2 understand the key controls and KRIs associated with the settlement Section 1.3
phase
5.5 Post-settlement phase
On completion, the candidate should:
5.5.1 understand the components of the post-settlement phase: Section 1.3
• reconciliation
• inventory management
5.5.2 understand the key controls and KRIs associated with the post- Section 1.3
settlement phase
ELEMENT 6 THE SUPPORT AND CONTROL FUNCTIONS CHAPTER 6
6.1 The Compliance Function
On completion, the candidate should:
6.1.1 understand the role and responsibilities of the compliance function Section 1
in managing operational risk
6.1.2 understand the consequences of compliance risk Section 1
6.2 The Financial Reporting Function
On completion, the candidate should:
6.2.1 understand the role of the financial reporting function in the context Section 1.2
of the operational risk environment
6.3 The HR Function
On completion, the candidate should:
6.3.1 understand the role of the HR function in the context of the Section 1.3
operational risk environment
6.4 The Internal Audit Function
On completion, the candidate should:
6.4.1 understand the role of the internal audit function in relation to Section 1.4
operational risk

178 Operational Risk


Syllabus Learning Map

Syllabus Unit/ Chapter/


Element Section
6.4.2 know the requirements of the MiFID level 2 Directive in respect of Section 1.4
the internal audit function
6.5 The IT Function
On completion, the candidate should:
6.5.1 understand the role of the IT function in the context of the Section 1.5
operational risk environment
6.6 The Legal Function
On completion, the candidate should:
6.6.1 understand the role of the legal function in the context of the Section 1.6
operational risk environment
6.6.2 know the common legal areas where operational risk issues arise Section 1.6
6.7 The Marketing Function
On completion, the candidate should:
6.7.1 understand the role of the marketing function in the context of the Section 1.7
operational risk environment
6.8 The Project Management and Change Management Function
On completion, the candidate should:
6.8.1 understand the role of the project management and change Section 1.8
management function in the context of the operational risk
environment
ELEMENT 7 ENTERPRISE RISK MANAGEMENT (ERM) CHAPTER 7
7.1 The Nature of Enterprise Risk Management (ERM)
On completion, the candidate should:
7.1.1 understand the objectives of ERM Section 1
7.1.2 understand the challenges of implementing ERM Section 2
ELEMENT 8 ACHIEVING COMMON STANDARDS AND PROTECTION CHAPTER 8
8.1 The Development of Good Practice in Achieving Common
Standards and Protection
On completion, the candidate should:
8.1.1 understand the drivers of the development of operational risk Section 2
standards:
• Basel Accord
• Sound Practices for the Management and Supervision of
Operational Risk
• European Commission
• Sarbanes-Oxley
• UCITS IV
• Solvency II
• RDR
• AIFMD
8.1.2 understand how MiFID has changed the operational risk Section 3.1
management approach

Operational Risk 179


Syllabus Learning Map

Syllabus Unit/ Chapter/


Element Section
8.1.3 understand how these developments affect financial institutions Section 2
8.1.4 understand how these developments impact the operational risk Section 2
management environment

EXAMINATION SPECIFICATION
Each examination paper is constructed from a specification that determines the weightings that will be
given to each element. The specification is given below.

It is important to note that the numbers quoted may vary slightly from examination to examination as
there is some flexibility to ensure that each examination has a consistent level of difficulty. However, the
number of questions tested in each element should not change by more than plus or minus 2.

Questions
Element 1 Risk Basics 1
Element 2 Other Major Risks 6
Element 3 The Nature of Operational Risk 18
Element 4 The Causes, Events and Impact of Operational Risk 10
Element 5 Operational Risks Arising in the Trade Cycle 7
Element 6 The Support and Control Functions 4
Element 7 Enterprise Risk Management (ERM) 1
Element 8 Achieving Common Standards and Protection 3
Total 50

180 Operational Risk


CISI Membership

Studying for a CISI qualification is hard work and


we’re sure you’re putting in plenty of hours, but
don’t lose sight of your goal! This is just the first
step in your career, there is much more to
achieve!

The securities and investments industry attracts


ambitious and driven individuals. You’re probably
one yourself and that’s great, but on the other
hand you’re almost certainly surrounded by lots
of other people with similar ambitions. So how
can you stay one step ahead during these
uncertain times?

Entry Criteria: Pass in either:


• Investment Operations Certificate (IOC, also known as IAQ), IFQ, ICFA,
CISI Certificates in, eg, Securities, Derivatives or Investment
Management, Advanced Certificates
• one or two CISI Diploma/Masters papers

Joining Fee: £25 or free if applying via prefilled application form


Annual Subscription (pro rata): £115
International Annual Subscription: £86.25

Using your new CISI qualification* to become an Associate (ACSI) member of the Chartered Institute for
Securities & Investment could well be the next important career move you make this year, and help you
maintain your competence.

Join our global network of over 40,000 financial services professionals and start enjoying both the
professional and personal benefits that CISI membership offers. Once you become a member you can use
the prestigious ACSI designation after your name and even work towards becoming personally chartered.

* ie, Investment Operations Certificate (IOC, also known as IAQ), IFQ, CISI Certificate Programme

Turn over to find out more about CISI membership



“ ... competence is not just about examinations. It is about skills, knowledge, expertise,
ethical behaviour and the application and maintenance of all these
April 2008
FSA, Retail Distribution Review Interim Report

Becoming an Associate member of CISI offers you…


ü Use of the CISI CPD Scheme
ü Unlimited free CPD seminars
ü Highly recognised designatory letters
ü Free access to online training tools including Professional Refresher and Infolink
ü Free webcasts and podcasts
ü Unlimited free attendance at CISI Professional Interest Forums
ü CISI publications including S&I Review and Regulatory Update
ü 20% discount on all CISI conferences and training courses
ü Invitation to CISI Annual Lecture
ü Select Benefits – our exclusive personal benefits portfolio

Plus many other networking opportunities which could be invaluable for your career.

To upgrade your student membership to Associate,

get in touch…

+44 (0)20 7645 0650


memberservices@[Link]
[Link]/membership
CISI Elearning Products

You’ve bought the workbook.....


...now test your knowledge before your examination
CISI elearning products are high quality, interactive and engaging learning tools and revision aids
which can be used in conjunction with CISI workbooks, or to help you remain up to date with regula-
tory developments in order to meet compliance requirements.

Features of CISI elearning products include:

• Questions throughout to reaffirm understanding of the subject


• All modules now contain questions that reflect as closely as possible the standard you
will experience in your examination*
• Interactive exercises and tutorials
* (please note, however, they are not the CISI examination questions themselves)

Price per elearning module: £35


Price when purchased with the CISI workbook: £100 (normal price: £110)

For more information on our elearning products call:


+44(0)20 7645 0756
Or visit our web site at:
[Link]/elearning
To order call CISI elearning products call Client Services on:
+44(0)20 7645 0680
Feedback to CISI
Have you found this workbook to be a valuable aid to your studies? We would like your views,
so please email us (learningresources@[Link]) with any thoughts, ideas or comments.

Accredited Training Providers


Support for examination students studying for the Chartered Institute for Securities & Investment
(CISI) Qualifications is provided by several Accredited Training Providers (ATPs), including 7City
Learning and BPP. The CISI's ATPs offer a range of face-to-face training courses, distance
learning programmes, their own learning resources and study packs which have been accredited
by the CISI. The CISI works in close collaboration with its accredited training providers to ensure
they are kept informed of changes to CISI examinations so they can build them into their own
courses and study packs.

CISI Workbook Specialists Wanted


Workbook Authors
Experienced freelance authors with finance experience, and who have published work in their
area of specialism, are sought. Responsibilities include:
Updating workbooks in line with new syllabuses and any industry developments
* Ensuring that the syllabus is fully covered
*
Workbook Reviewers
Individuals with a high-level knowledge of the subject area are sought. Responsibilities include:
Highlighting any inconsistencies against the syllabus
* Assessing the author’s interpretation of the workbook
*
Workbook Technical Reviewers
Technical reviewers provide a detailed review of the workbook and bring the review comments to
the panel. Responsibilities include:
Cross-checking the workbook against the syllabus
* Ensuring sufficient coverage of each learning objective
*
Workbook Proofreaders
Proofreaders are needed to proof workbooks both grammatically and also in terms of the format
and layout. Responsibilities include:
Checking for spelling and grammar mistakes
* Checking for formatting inconsistencies
*
Notes
Notes
Notes
Notes
Notes
Notes
Notes
Notes

14th Edition, September 2010
This Workbook relates to syllabus version 10.0 and will cover examinations from 
21 January 2011
O P E R A T I O N A L  R I S K
Welcome to the Chartered Institute for Securities & Investment’s Operational Risk study materi
F O R E W O R D
Learning and Professional Development with the CISI
Formerly the Securities & Investment Institute (SII), and
Chapter 1: 
Risk Basics 
1
Chapter 2: 
Other Major Risks 
13
Chapter 3: 
The Nature of Operational Risk 
47
Chapter 4: 
The C
Operational Risk 
1
RISK BASICS
1. 
INTRODUCTION  
3
2. 
WHAT IS RISK?  
3
 CHAPTER ONE
 This syllabus area will provide ap
Risk Basics 
Chapter  One
2  
Operational Risk
Risk Basics 
Chapter  One
 
Operational Risk 
3
1. 
INTRODUCTION
This workbook describes what risk is and what it means to th
Risk Basics 
Chapter  One
4  
Operational Risk
These steps represent some of the mitigating activities necessary to reduce op

You might also like