0% found this document useful (0 votes)
72 views37 pages

Morgan Stanley Operational Risk Framework

a view on ops risk

Uploaded by

suwandi.tjia
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
72 views37 pages

Morgan Stanley Operational Risk Framework

a view on ops risk

Uploaded by

suwandi.tjia
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Morgan Stanley

Operational Risk Programme


January 2004
Table of Contents

What the Programme has to achieve

What is an Operational Risk Framework?


Current State

What Needs Doing?


Timeline
Project Phases
Potential E&Y Support
Conclusion?

Appendix
E&Y Team – CV’s
What is an Operational Risk Framework?
What
What the
the Programme
Programme has
has to
to Achieve
Achieve

• Build a first class operational risk framework which consolidates the work done to
date at firm management level and within Divisions / Functions
• Meet CP142 and provide the basis for Basel II Operational Risk
• Extend the work of the Sarbanes Oxley programme
• Gel with any global operational risk initiatives
• Build consensus within the bank by demonstrating at an early stage how this can
help to manage the business more effectively

1
What is an Operational Risk Management Framework? - Summary

Operational Risk Environment


Vision, Guiding Principles, Risk Strategy, Risk Appetite, Organisation Structure, Risk Glossary

Risk Identification & Assessment Risk Monitoring Risk Measurement

Strategic Key:
Risk
Assessment CP 142

SOX
Ongoing Risk Key Risk
and Control Self Indicators
Assessments (KRIs) Loss Data
Basel
(RCSA)
Business
Business Value
Initiatives /
Risk
Assessment

Model

Risk Reporting
Operational risk management continuum

N2 Additional CP 142 Additional Basel


Baseline Sarbanes-Oxley Future
By 31/12/04 By 31/12/06
1/12/01 15/6/04
• Approved person • Focus on operational risks • All categories of Operational Risk • Builds on CP142 Operational Risk •Standardization and increase
regime - formal and controls over financial • Focus on managing the cause of Framework adding: of sophistication of operational
allocation of reporting risk occurring – more focus on • Loss events - collection, analysis risk quantification and capital
roles and preventative / predictive controls • Measurement, Quantification, of Op modelling
responsibilities • Focus on managing
consequence of risk, ie, • Operational Risk Framework, i.e: Risk •Integration with market and
• High level - Strategy, policy, governance,
systems and impact on financial • Capital Modelling and allocation credit risk
statements – somewhat appetite
controls - Risk and control identification, •Link qualitative and
biased to detective controls
• Interim assessment and monitoring • Consideration of the Risk Based quantitative
Prudential • Documentation of • High Level – provides guidance Capital Directive (as implemented
•Risk transfer/insurance linked
sourcebook processes and controls over on the types of operational risks by FSA) and selection of approach -
either:
with risk analysis and capital
• Conduct of financial reporting that firms are expected to
Business manage (interpretation of existing - PRU 6.3 - Basic indicator •Fully linked set of tools
Sourcebook • Risk and control Rules) - PRU 6.4 - Standardised
- PRU 6.5 - Advanced •Correlation between indicators,
assessment process • PRU 6.1 – provides guidance on measurement RCSA, losses and
the design and documentation of quantification
• Management and auditor risk management systems for
attestation of the operational risk (interpretation of •Ops risk linked to RAPM at all
effectiveness of internal forthcoming Rules) levels, comp., plan and
financial controls in the budgeting
annual report.
What is an Operational Risk Management Framework? - Detail

Risk Identification, Assessment, and Mitigation Risk Monitoring Risk Measurement

Operational Risk Framework


Vision, Guiding Principles, Organization Structure, Strategy, Risk Taxonomy

Business Process Strategic /


Strategic Business Validation/ Risk
and Full Business
Strategy Risk Profile/ Risk Quality Transaction
Assurance Taxonomy Risk
Risk Score Prioritization Indicators
Performance
Measurement
Management Strategic Action Plans,
– Static and
and Strategy and Risk and Issues Escalation, Dynamic Intranet Ops Credit Risk Risk Based
Business Risk Infrastructure
Control Management
RCSA Scores
Threshold Capital
Action Plans Generator Risk Event
Unit Risk Assessment Templates and Tracking Capture Generator
Assessment MIS
Risk Profile/Score for
Business Risk Validation/
Market and Business Unit XPerformance Distribution Market Risk
Risk Measurement Taxonomy Quality and
Competitive Self Assurance G/L
Prioritization People Behavioral Strategic
Data Assessments X
Integrated Planning /
Effectiveness Analysis
X Strategic Capture New Business
Business Reporting Initiatives
Key Risk Structural
Internal Audit On-going Risk Planning Indicators to Key Risk Electronic
Interest Rate
Dashboard Risk Transfer
Validation/
Risk and Control Track Indicators Intranet Pricing Risk
Assessments Distribution
Quality Self Trend (KRI) Manual Operational Risk
Assurance
Assessments Analysis/ Early Database Capture
(RCSA) Intervention Data Capture Hierarchical
Exception
Capital Allocation
IA Regulatory (Data Polling
New
Initiatives Action Plans, and External Via Email) (Message
Audit Findings Operational Probabilistic
Issues Via Email)
New Business Escalation, Operational Risk VAR Estimates of
Risk Taxonomy Near Miss Generator Loss
Management Initiatives/
Management (KRIs, Loss Events, RCSA / KRI / Capture Risk Event
and Tracking Interfaces Loss Event
Reporting
and
Risk Key Risk etc…)
to Core Exception
Database
Business Indicators Systems / MIS Reporting
Unit Risk Assessment (KRIs) Input Info Regulatory
Scenario
Assessment Risk Profile/ Capital
Audit Risk Generator
Score Assessment Generator
Operational and Audit Scaling Data
Risk and Risk Events, Audit /
Fieldwork / Data
Control
Distributions,
Base Regulator / Validation/
and Root BCP Scores Quality Regulatory
Templates Cause Analysis
Assurance Validation /
Risk and Quality Capital
Key Risk Root Cause
Control Assurance Reporting
Indicators Risk Analysis
Templates Transfer
To Track Loss Events
Activities
Indicators
Risk
Categorized
Loss Events
External Loss
Events Data
Operational Risk: Ernst & Young Experience

Why Select Ernst & Young?


Choosing the right partner for your Operational Risk Programme implementation is an important decision for Morgan
[Link] the following five reasons we believe that Ernst & Young should be your partner of choice for this assignment :
• We are staffed by senior industry practitioners with operational risk expertise. These individuals will be involved in
this assignment as core members of the Project Team.
• We have carefully monitored the developments and requirements of the Basel Accord, the Prudential Sourcebook
and other related regulatory requirements and are in regular dialogue with global regulators regarding implications
and implementation.
• We have developed an effective methodology for operational risk and have implemented operational risk
frameworks across a wide spectrum of financial services institutions for a large proportion of the big Insurance
firms, several Investment Management clients, and a significant number of UK and Global banks
• We are committed to operating with you in a partnership approach whereby we would work with your own internal
resources as one team to ensure a successful delivery of the project and a transfer of knowledge across the
team.
• We are helping you in implementing SOX404, which provides the basis for the systems and controls workstream
as well as the entity level controls that are an essential part of the governance framework.
Current State

• Much work has been done to date which can be utilised, and many of the building blocks are in place.

Governance framework in place at firm SOX Risk and Controls


management level through EORC and in work can be extended to
some cases in divisions (eg FORC) cover remaining
categories of operational
Risk and control
Framework assessments risk

Risk Strategy
Risk Policy
Org structure
Governance
Future State Risk
Model

Performance
Capital management Measurement & Risk
Reporting
Probability of Loss

Economic Capital
• Confidence level
• Bank Risk
Metrics exist at an operational
level which could be utilised in
• Target Debt Rating

Expected Loss (EL)


UL
µ xσ 2
yσ2

creating a performance
Total Loss Severity Per Period

Loss events
database measurement framework
Capital allocation is probably the least developed
area – in terms of how this will be built into
operational risk management processes – from
the firm and the regulators perspectives

Loss event data exists although this is


not comprehensive and needs
standardisation
What Needs Doing?

• Refine what exists to create a consolidated policy,


Methodology Design, Strategy,
strategy, and governance structure
Policy & Governance
• Mould to fit the existing organisation and governance
process

• Extend SOX work to address all categories of


Risks and Controls operational risk
• We will provide a methodology and route map to reuse
the SOX work for the Risk and Controls Assessments

Performance Measurement / • Build risk metrics per business from population


Risk reporting identified in SOX work, define and build reporting (eg
functional, legal entity, etc)

• Define loss event data requirements (data sources,


Loss events data structure, quality), assess current state and develop gap
solutions
• We will tailor and develop existing MI and loss event
collection, rather than starting from scratch

Capital Modelling • Define capital modelling requirements and gap solutions


Potential Timescales

Workstream Feb Mar /April May / June July / Aug Sept / Oct Deliverables
Phase I Future State Design:
• Programme Planning
• Definition of
• Strategy / Policy / Operational risk
Governance
• Definition of scope
• Methodology Design
• RCSA • Risk Strategy
• KI • Risk Policy
• Loss Events • Risk Appetite
Phase II - Pilot
• Governance structure
• Pilot selection &
design Plan
• Pilot Implementation • For pilot
• Assess & refine • For extension of SOX
methodology design Risk & Control Work
& tool • For rollout
Phase III
• Extend SOX Risks &
Controls Work
• Publish Manual
• Rollout performance
metrics / reporting /
loss event data
Phase IV
• Capital Modelling
Workstream: Methodology Design, Strategy, Policy & Governance

Phase I Deliverables Issues / Considerations Work Required


• Definition of operational risk and sub- • Operational risk definitions, policies and • Identify forum for approving framework
categories of risk which it will address strategies exist within Divisions / Businesses – (EORC for Europe?)
• Definition of scope: we need to review these and arrive at one • Create working group with cross divisional
• Organisational consolidated version which can have global representation / authority to commit
applicability • Operational risk definition & scope
• Geographic
• Scope issues: for CP142 overseas desks • Create definition
• Boundaries with other risk functions booking business in London will need to be
• Risk Strategy included • Gain endorsement
• Relationship to business strategy • Risk policies will need to be addressed on a • Publication
• High level risk assessment by business business and legal entity basis • Communications with credit and market
unit, prioritisation and action plans • European framework has to be aligned to any risk
• Risk Policy global framework created for the bank • Risk Strategy / Policy /Appetite
• Principles for identifying, assessing, • Review existing strategies / policies
monitoring and controlling risk • Understand existing risk appetite
• Risk Appetite • Develop with businesses
• Setting of risk appetites by category at • Gain endorsement
entity level and for each business • Rollout / publication

E&Y Support • CP142 and Basel 2 guidance and interpretation of regulatory


• E&Y Risk Framework pronouncements
• Strategic assessment tool • Training materials
• Templates and generic content material for definition, policy, appetite • Knowledge of commercial software and implementation experience
(eg, Horizon, Risk Navigator, Sword, Amelia)
Workstream: Methodology Design, Strategy, Policy & Governance

Phase I Deliverables Issues / Considerations Work Required


• Governance Structure including: • Much work has been done in the past • Confirm overall governance structure
• Roles and responsibilities re governance – in functional and • Review and enhance generic
• Reporting lines and information legal entity terms definition of roles and responsibilities
flows • CP142, with its emphasis on risk for all levels of management / TOR
• Ownership of operational risk monitoring by legal entity, may for committees
from Board down require some enhancement – • Agree risk objectives with business
particularly re reporting to and heads
training of approved persons • Define how risk objectives will be
• We need to define the various risk built into performance
universes and how these interrelate – • Document specific roles and
eg global, European, Divisional responsibilities
• How organisationally will the • Clarify lines of reporting and how
responsibilities of the risk information will flow
management function be discharged?

E&Y Support
• Generic industry based templates & content / examples from other large FS organisations
• Knowledge of Morgan Stanley
Workstream: Risk and Control Assessment

Phase I Deliverables
• Purpose: Issues / Considerations Work Required
• Approach and plan for • SOX 404 work provides: • Extend existing SOX
documentation of all • Methodology planning to incorporate
operational risks and controls • Process library (for ISG) additional risk categories
by business (including Pilot) • Identify generic risks per
• Definition of process ownership at a business level
• Methodology for self business / product / process
assessment to co-ordinate with • By April 2004 documentation of process risks and controls will be complete
for ISG. Other Divisions are progressing - perception is they are further • Review templates and
SOX approach determine changes (if any)
behind
• Team currently in place in ISG experienced in process of managing • Decide approach to
businesses through the documentation process, handoffs, etc documentation
• Identification of risk categories not covered by SOX (eg people, reputational, • Develop risk scoring
legal..) approach (probability / scale
of potential loss). Map in
• Decide approach to extending work. eg: SOX ‘key control’ concept.
• ‘assessment’ versus ‘self assessment,’
• do we adopt the ‘process library’ approach for risks?
• level and nature of support offered centrally?)
• Look at how we extend scheduled work. In particular front office reviews
(March / April) could currently be extended to cover wider risks
• Need to review new product policies to ensure appropriate operational risk
review and approval

E&Y Support
• SOX Team and knowledge
• Understanding of what is needed to convert SOX to Operational Risk – and methodology
• Process and technology for conducting risk and control assessments
Extending SOX to operational risk

SOX Deliverables Risk Categories?

• Processes 9
• Business overview
• Systems 9
• IT Security 9
• Documentation Partial
• Map of end to end business processes • BCM Partial
• Outsourcing Partial
• People x
• Employee Responsibilities x
• Risks and controls assessment • Geographic x
• Insurance x
• External Events x

Moving from SOX to Operational Risk Methodology Tool?

• Need to map SOX risks to overall risk universe • Risk navigator being used for SOX
• SOX focus narrower and deeper than required for CP142 • Has capability to cover operational risk
• SOX focuses mainly on Risk Consequences, Op Risk • Need to tailor - for instance, scoring methodology
will have increased focus more on Risk Cause.
• SOX focuses mainly on detective measures, Op Risk
will have increased focus on preventative measures
Workstream: Risk Reporting

Phase I Deliverables Issues / Considerations Work Required


• Plan for Pilot and Rollout: • SOX risk / control assessments already • Produce draft set of entity level metrics
• Development of methodology, which will identify what metrics exist for controls • For pilot area, test against current state and
include: defined. This work needs to be expanded assess scale of work required to create future
• Definition of: upon – eg definition of metric, target, format, state reporting
frequency, etc • Plan pilot
•metrics and cascade from
entity level • These metrics will primarily be operational –
need to address other categories
•standard reporting formats,
target definition, frequency, • Measures are likely to be backward looking
etc since many are linked to preventative controls
– need to identify forward looking metrics
•reporting hierarchy required
• Analysis of current metrics produced • We need to
and identification of gaps
•define a set of entity level measures
• Draft process for production of metrics and cascade to businesses
and functional responsibilities (including
interpretation / analysis) • map gaps between cascaded measures
and current state at business level
• Mapping of production responsibilities
per business •define all reporting required to all
roles with operational risk management
responsibilities, including board and
senior management

E&Y Support
• Example metrics and KRI dashboards
• Generic risk reporting and metrics definition templates
• Experience of performance measurement design and technology support required
Workstream: Loss Data

Phase I Deliverables Issues / Considerations Issues / Considerations


• High level requirements including data types • Various loss event databases exist in Morgan • Map current databases, and idnetify gaps in
required Stanley. It is unclear if they hold the same coverage of loss event data (risk type,
• High level architecture data, degree of similarities of data structures, businesses, products), and extent of historic
• Plan for Pilot quality and comprehensiveness of data held. data
• A decision will be required as to approach – ie • Perform high level assessment to identify
consolidate to create one loss event database, degree of similarity between databases
align data structures • Identify external sources currently used /
• Requirements will be influenced by whether available (eg: SAS, OpVantage, OpData)
the bank plans to go for standardised or • Develop high level requirements, logical
advanced status for Basel II architecture and plan
• The loss event database will need to contain an
analysis and description of the loss event,
along with its:
-consequence – financial/non-financial
impact
-cause – underlying reasons for the loss

E&Y Support
• Proforma data requirements
Workstream: Capital Modelling

Phase I Deliverables Issues / Considerations Work Required


• Methodology to incorporate operational risk • We want to have the building blocks in place • Development of plan to develop building
into capital modelling to have the flexibility as the industry blocks to accommodate different approaches.
determines approach for different business • Independent review of quantitative
units assumptions
• Issues for consideration: • Selection of Tools
• Methodology (Actuarial/Stochastic, • Implementation of Tools
Scorecard)
• Expected Loss
• Unexpected Loss
• Stress and Scenario Testing
• Incorporation of Qualitative
Adjustments
• Loss Types: High Frequency – Low
Severity, Low Frequency – High
Severity
• Mitigation / Insurance

E&Y Support
• Modelling methodologies – both for data rich and data-poor environments
• Access to quantitative capability and experience of all significant modelling approaches (eg monte carlo, stochastic, etc)
Workstream: Pilot

Deliverables Issues / Considerations Work Required


• Plan for pilot • Pilot selection (potentially take a key business • Pilot selection
• Consolidated methodology product area, eg, equity derivatives, and a key • Securing buy in
• Pilot results - business support process, eg, BCM) • Mobilisation, training, communication
• Risk and Control Assessment • Use of Risk Navigator as is • Management of pilot
• Reporting • Showcase for operational risk? • Evaluation
• Speed to get pilot up and running:
• Loss events data • resources • Publication of results
• Pilot Evaluation, including amendments to: • governance
• tool • Extent to which it will represent microcosm of
• methodology wider rollout (particularly in surfacing issues)
• rollout plan • Degree to which we can reuse work already
completed

E&Y Support
• Experience in implementing operational risk management
• Experience in implementing Risk Navigator
Potential E&Y Team

•Integrated team Management Team

•E&Y resources which could be made Relationship Partner Project Directors Advisory Partner
available are shown opposite Ian Baggs Stuart Thomson, Partner Tim Pagett
Chris Bowles, Director

•Our involvement depends on bank


resources available
•Redeploy SOX team Strategy, Pilot & SOX Team
Governance & Policy Methodology
•Selection of illustrative CVs included
in Appendix I ¾Peter McCormack,
Senior Manager
¾John Walsh
Director
¾Chris Richardson
Manager
¾Richard Kent, Senior ¾Jonathan Mogg, ¾Andrew Parkin,
Manager Senior Manager Manager
Fees

Our fee rates incorporating standard discount for Morgan Stanley are:

Partner 3,440
Director 3,440
Senior Manager 2,640
Manager 1,720
Executive 1,320

Costs will vary depending on the exact scope of the engagement, the individuals you wish to include in your team, and the extent of their
involvement.
Phase I Typical Staffing and Fees

Activity Resource Days Fees


£

Planning / Methodology / MS Project Manager 30


Prepare Pilot S Thomson 3 10,320
C Bowles 10 34,400
2 Executives 60 79,200

Future State Framework MS Manager 30


P McCormack 20 52,800

QA & Review T Pagett 1 3,440


I Baggs 1 3,440
Appendices

APPENDIX I – CV’s
Appendix I – CV’s

Team member Relevant experience

Ian Baggs Ian is a partner in Ernst & Young’s Financial Services practice, based in our London Office, and is National Industry Leader for the Wholesale
Banking & Capital Markets sector. He has over 16 years experience of working with financial services clients in both an audit and advisory
Partner, Financial Services capacity. He works with a wide range of banks, broker / dealers and other market participants. Ian is the Client Service Partner for Morgan
Banking & Capital Stanley in the UK and Europe, coordinating all Ernst & Young services to Morgan Stanley, and works closely with our other Morgan Stanley
Markets,Sector London, teams around the world.
United Kingdom
He has been involved in a number of significant projects in recent years including:
Direct line +44 20 7951 2391 • A review of the OPALS business,
Direct fax +44 20 7951 1693 • Project GRIP (firmwide corporate governance review) and assisting the Compliance Department with their reviews of front office trading
E-mail cbowles@[Link] desks.

Currently he is overseeing the advisory role that Ernst & Young is undertaking for Morgan Stanley on the Sarbanes-Oxley 404 project.

Current clients include ABN AMRO, Credit Suisse First Boston, Goldman Sachs, Morgan Stanley and Nomura. Previous audit and advisory
clients have included Bank of America, Bankers Trust, Barclays, CitiGroup, Deutsche Bank, ING Barings, NatWest, PaineWebber, Sumitomo
and UBS.
Appendix I – CV’s (cont’d)

Team member Relevant experience

Tim is the Partner leading our UK Financial Services Risk Management Practice, and has over sixteen years experience within the Financial Services
Tim Pagett industry. Through this and his previous role as Head of Financial Risk Management in the Banking and Financial Services Group of Ernst & Young,
Australia, Tim has been fundamental in the development of Ernst & Young’s Global Risk Management leading practices approaches, tools and
Partner, FS Risk Management methodologies, including Operational Risk Measurement tools and the Ernst & Young Basel II & PSB Diagnostic Framework.
London, United Kingdom
Tim is a highly experienced and successful project manager and team leader, and has led a wide range of projects, including the design,
implementation and audit of Risk Management frameworks across the Financial Services industry in Europe, the US and Asia.
Direct line +44 20 7951 2834
Direct fax +44 20 7951 0202 Some of his relevant assignments include:
E-mail tpagett@[Link] ƒ The design and implementation of Prudential Sourcebook compliance programmes for 7 major insurance companies
ƒ The design and implementation of a risk management framework for a global re-insurer
ƒ The design and programme support for Basel II programmes for 4 major financial conglomerates
ƒ The assessment and subsequent design and implementation of a risk management framework for the UK operations of a major global life insurer
ƒ The assessment, critique and challenge of the governance framework of the UK operations of a leading Money, Foreign Exchange and Equities
broker and the UK operations of a major re-insurer incorporating the requirements of the FSA Prudential Source Book requirements, the Turnbull
guidance and other UK listing requirements
ƒ Design and implementation of the global corporate governance process for a major UK retail bank
ƒ The design and implementation of a business risk management process for a UK life insurer
ƒ The assessment of Credit Risk measurement and monitoring processes of a significant UK based Export Credit Agency
ƒ The design and implementation of an operational risk measurement process for a major UK retail bank.
ƒ Audit and best practice review of the Treasury operations for a major UK-based retail bank and a major international central bank
ƒ The design and development of an Enterprise Risk Management framework for a global investment bank
ƒ The design and development of an operations and processing Risk Management framework for a UK-based unit trust manager
ƒ The re-engineering of the audit function for a major Singapore-based retail bank
ƒ Implementation support for a Control Self Assessment for a major international investment bank
ƒ Design and implementation of an operational Risk Management framework for a UK investment bank
Tim’s clients include HBoS, Swiss RE, Prudential, Winterthur Life (UK), Legal & General, AXA, Barclays, Zurich Financial Services, Tullett & Tokyo
Liberty plc, Investec, ECGD, Jupiter Unit Trust Management, Merrill Lynch, Old Mutual, Morgan Stanley, Commonwealth Bank of Australia, AMP, JP
Morgan, Goldman Sachs, Bradford & Bingley, Co-Operative Bank plc, Britannia Building Society, XL Winterthur.
Appendix I – CV’s

Team member Relevant experience

Stuart Thomson Stuart is a partner in Ernst & Young’s financial services risk practice focusing on operational and regulatory risk within banking and asset management.
He is a qualified chartered accountant with 15 years client experience, mostly in banking and fund management groups. He is a regular speaker at risk
Partner, FS Risk Management
and industry conferences. He was also a key member of the team who developed E&Y’s business process based methodology which forms the basis of
London, United Kingdom
our Operational risk and governance solutions. He is leader of our Corporate Governance proposition to financial services organisations. Some of his
relevant assignments include:
Direct line +44 20 7951 8260
Direct fax +44 20 7951 0202 ƒ Development of Operational risk frameworks and implementation of operational risk technology (Horizon by JP Morgan and Amelia ORCAS) at
E-mail sthomson@[Link] three major financial services groups (Investment Bank, Private Bank, Fund Manager)
ƒ Comprehensive risk review together with development of an operational and regulatory risk framework within a major banking and private client
group
ƒ Development of a risk framework and detailed risk assessment for the wholesale division of a global bank with particular focus on the FX,
Stocklending and Repo businesses
ƒ Implemented an operational risk Framework within a mid sized international bank
ƒ Development of a derivatives risk management framework within a major asset manager
ƒ Led the design and implementation of a compliance framework for an Investment bank to comply with relevant US Federal Reserve requirements
ƒ Investigation into the root cause of dealing errors and implementation of remedial action within several major UK fund managers
ƒ Review and development of Risk reporting framework (key risk indicators, exception reporting and management reporting) within a major securities
business
ƒ Led a reconciliation remediation and reconstruction project within the securities area of a major bank
ƒ Program review and healthcheck on a major core system design and implementation for a banking / asset management organisation,
Stuart’s clients include, Barclays (BarCap, Barclays Private Clients), Schroders, Lloyds TSB/Scottish Widows, Morley Fund Management, Gartmore,
Henderson Global Investors, Deutsche Asset Management, UBS
Appendix I – CV’s (cont’d)

Team member Relevant experience

Chris Bowles Chris is a director Ernst & Young’s Financial Services practice, based in our London Office. He has over twenty years of professional
services experience, primarily in management consulting, working with multi-national blue chip financial services organisations, including
Director, Financial Services – Citigroup, UBS, Deutsche Bank, ING Barings and NatWest Group. His experience spans wholesale banking, capital markets, private
Wholesale Banking & Capital banking / wealth management, and retail banking.
Markets Sector
London, United Kingdom He has led a number of strategic client programmes, often with complex change implications, focusing on pan-European or global
Operations, Finance and IT transformation.
Some of his relevant assignments include:
• Mobilizing and managing a major transformation programme for a leading UK Banking Group, creating the blueprint for systems,
process and information quality improvements needed to meet changing regulatory (Basel 2, IPSB), and group decision making
demands.
• Led 40-man project which re-engineered European Securities Processing and Exceptions Clearance for a UK Global Bank.
• Led the Operations design for a new pan-European & Asian wealth management business for a Global Investment Bank.
• Director of a global programme to develop a business and IT Finance Systems Strategy based on a regional shared services model,
replacing disparate legacy processes and systems in 50 countries, for a Global Investment Bank (business case $70m)
• Developed a strategy to combine and rationalise the existing operations of the retail, private and investment banking divisions of a
Global Bank, and build a securities processing utility, leading to major cost and service improvements;
• Planned the pan-European re-engineering of Securities, Cash and Trade Finance to centralise operations processing for a Global
Transaction Bank. This was subsequently implemented achieving a 40% cost reduction over 5 years
• Secondment to a UK Banking Group to improve the effectiveness of the Internal Consultancy. Part of the management team which
merged three existing internal units to create a new 180 strong consultancy (£13m revenues), raised the performance of the consultancy
so it competed effectively with external firms, and built a consulting brand which was recognised for its quality internally and externally.
• Project managed a range of information systems projects in retail and wholesale banking, including development of group strategies for
Executive Information Systems and for HR information systems, systems selection, business requirements analysis, and evaluation of
systems under development
Appendix I – CV’s (cont’d)

Team member Relevant experience

John Walsh John is a Director in the Global Financial Services Risk Management (GFSRM) practice of Ernst & Young LLP in London and works with
financial services clients to evaluate, design, and implement effective processes and systems to manage risk. John has provided
assurance and advisory services to a broad range of financial institutions, particularly derivative dealers and global banks for over eleven
Director, FS Risk years. John was based in New York for ten years Some of John’s relevant assignments include:
Management, London ƒ Managed projects in valuation and infrastructure for derivatives trading and the infrastructure to support lending activities at
Direct line: +44 20 7951 7341 global banks and investment banks. John recently managed a team developing and implementing operational solutions at a
high growth capital markets company
Email:jwalsh@[Link]
ƒ Managed a team in providing assistance to a global investment bank on the development of a consistent global framework for
the measurement and management of counterparty exposure data and processes. His team developed a framework and the
data requirements for a global counterparty exposure data warehouse
ƒ Managed a wide range of projects from the identification of issues through the implementation of solutions. These have also
included leading large advisory teams in preparing global international banks to develop the risk management infrastructure to
comply with a regulatory review, and in developing the support and analyses to support a business interruption insurance
claim.
ƒ Managed a team performing an independent review of the market risk measurement and management processes and tools at
a U.S. Bank. The procedures included reviewing the stress testing and back testing procedures and results
John’s clients have included ABN Amro, American Express Bank, Bank of America, Lehman Brothers, Morgan Stanley, PNC, State Street
Bank and Trust, UBS, and Zurich Financial Services.
Appendix I – CV’s (cont’d)

Team member Relevant experience

Peter McCormack Peter joined Ernst & Young in September 2003 and has been assisting clients with risk management, PSB planning and implementation,
ARROW assessments, and general advice on the evolving regulatory framework.
Prior to joining Ernst & Young Peter spent three years at the Financial Services Authority (FSA) where he was a policy advisor on
Senior Manager, FS Risk operational risk and latterly member of the operational and insurance risk team in the FSA Risk Review Department. During his time at the
Management, London FSA he has carried out numerous risk review visits on firms’ approach to risk management, high level systems and controls, corporate
Direct line: +44 20 7951 2446 governance, compliance and outsourcing. Peter was a contributor to CP 142 and the July 2003 paper ‘Building a framework for operational
risk management: the FSA’s observations’. Peter was also the ARROW ‘superuser’ for the Prudential Standards Division at the FSA, and
Email:pmccormack@[Link] the FSA member on the Basel Committee’s sub-committee on electronic-banking.
Prior to joining the FSA Peter worked in retail banking with Standard Bank and Barclays Bank, investment management with the Kleinwort
Benson Group (eurobond operations, banking operations, institutional fund management operations, and management accounting), law
with Norton Rose and Simmons & Simmons (the former of which included a secondment to the Financial Services Directorate at the
European Commission).
Peter has worked in financial services since 1981 and in addition to risk and regulatory knowledge has an excellent knowledge of all
aspects of the financial services industry. Peter holds the following academic, regulatory, and professional qualifications BSc(Hons),
BCL(Hons), DipLP, LLM, MBA, ACIB CeFA, Solicitor
Appendix I – CV’s (cont’d)

Team member Relevant experience

Richard Kent Richard is a Senior Manager in Financial Services Risk Management with an invaluable breadth of financial services advisory experience
gained from 7 years in Financial Services Group at PwC, 2 years at the FSA, and 4 years holding senior positions within the fund
Senior Manager, FS Risk management industry.
Management
London, United Kingdom
A Qualified Chartered Accountant, he has considerable experience within leading fund management firms of delivering solutions to complex
problems. Prior to joining Ernst & young, Richard was Head of Risk, Institutional Business, Schroders, before that Head of Business Risk,
Direct line +44 20 7951 0811
Morley Fund Management where he was responsible for delivering:
Direct fax +44 20 7951 0202
E-mail rkent@[Link] • The design and implementation of a new Operational Risk Management framework, meeting the requirements of both Turnbull and the
FSA;
• Assessment of business needs and the design of KPIs to monitor, control and drive Risk Management initiatives in relation to these;
• Design and implementation of new procedures and controls for OTC and ET derivatives transactions, and
• Played pivotal role in re-shaping corporate structure and governance for senior management
Most recently, Richard has led a number of quality assurance reviews at large financial institutions, advising on the design, content,
application and implementation of the critical success factors of an operational risk management frameworks.
Richard’s clients have included: Hendersons, Jupiter, Swiss Re, Legal & General, Aviva Group, Threadneedle
Appendix I – CV’s (cont’d)

Team member Relevant experience

Jonathan Mogg Jonathan is a Senior Manager in our UK Financial Services Risk Management Practice, with over 10 years of Financial Services experience
across a range of front, middle and back office functions in the banking and capital markets. Prior to joining Ernst & Young, Jonathan worked
Senior Manager, FS Risk in the front office of a leading investment bank. Since joining Ernst & Young Jonathan's experience includes:
Management
London, United Kingdom ƒ Significant involvement / project lead in the transformation of Risk Management Functions including Business Process Analysis, Change
Management, Risk Identification and Assessment, Corporate Governance review, Impact Analysis and Issue Identification for a wide
range of Financial Services clients
Direct line +44 20 7951 1257 ƒ Leading a complex international process development project for a newly created Foreign Exchange settlement bank, covering all
Direct fax +44 20 7951 0202 processes
E-mail jmogg@[Link]
ƒ Jonathan also managed the production of a Risk Management Policy manual and a review of the various committee terms of reference.
The role included advisory work around major management decisions and several other software development projects
ƒ Undertook a risk assessment and controls review of the trading function of several leading Investment Management house / investment
banks
ƒ Reviewed the controls around the payment area of a major US bank
ƒ Assisted in the formation and documentation of the procedures surrounding credit decisions, setting up of new accounts and business
support processes for a major bank launching a new credit card
ƒ Recently undertaken an operational risk framework implementation with a leading retail organisation in preparation for the forthcoming
Basel II regulation
Clients have included Morgan Stanley, UBS, Tullet & Tokyo, Gartmore, MBNA, CLS, Investec, AXA UK, NUIM, FSA, Swiss Re, Co-operative
Bank, Chelsea Building Society, Barclays Bank, Prudential
Appendix I – CV’s (cont’d)

Team member Relevant experience

Andrew Parkin Andrew is a Manager in our UK Financial Services Risk Management Practice, with 9 years of Financial Services experience. Andrew is
ACA qualified and is now focused on operational risk and related projects. Andrew has previously worked in the Investment Banking and
Manager, Investment Management Industries and has a variety of relevant experience. Some of Andrew’s projects include;
Financial, Services Risk Management • Sarbanes Oxley 404 – project manager for Institutional Securities Division of a major US Investment Bank.
London, United Kingdom
• Review of implementation and operation of an operational risk framework for a Global Investment Management firm.
• Process review of the design and implementation of market risk valuation models for the structured products business of an
Direct line +44 20 7951 7030 Investment Bank.
Direct fax +44 20 7951 0202
E-mail aparkin@[Link] • Part of the Project team tasked with the closedown of a Japanese Securities Broking business.
• Reviewed the implementation of an order management system for a Global Investment Management firm.
• Managed the Internal Audit team responsible for the monitoring of the Institutional Investment Management business of a Global
Investment Management firm.
• Conducted numerous internal audit reviews within a Global Investment Bank covering all aspects of the business, from front to back
both domestically and internationally.
Clients have included Morgan Stanley, Schroders
Appendix I – CV’s (cont’d)

Team member Relevant experience

Chris Richardson Chris is a Manager in our UK Financial Services Risk Management Practice, with 5 years of Financial Services experience. Chris is CIMA
qualified and now is focused on operational risk where he leads our approach to operational risk technology. He combines this role with
Manager, managing our teams to deliver Sarbanes Oxley projects and also assists in designing and implementing operational risk frameworks for
Financial, Services Risk Management the Firm’s clients. Some of Chris’s projects include;
London, United Kingdom • Sarbanes Oxley 404 – project manager for Institutional Securities Division of a major US Investment Bank.
• Advising a Global investment Bank on Sarbanes Oxley/operational risk technology selection and implications for satisfying UK
Direct line +44 20 7951 1012 regulation.
Direct fax +44 20 7951 0202 • Advising and assisting the global roll out of a RCSA software tool for a global investment bank, including formulating policies and
E-mail crichardson4@[Link] processes.
• Advising a large UK Retail Bank on their operational risk framework and risk and control assessment processes
• Sarbanes Oxley 404 – project manager for Global Property & Casualty Insurer. Coordinated the work in 17 areas (approx 150
processes/activities) supported by a central project management office.
• Leading a large UK Insurer through a current state analysis of their operational risk framework, planning the future state and project
managing the actions to achieve the desired operational risk framework.
• Leading several UK insurers through software selection for operational risk assessment in response to new PSB regulations.
• Project managing the UK workstream for the re-engineering of a global insurer’s economic capital calculation processes
• Turnbull readiness project for a global Investment Bank

Clients have included Morgan Stanley, CSFB, Merrill Lynch, Investec, XL Capital, Bradford & Bingley, AMP, CLS, Cornhill Insurance,
Swiss Re, Lloyds Insurance Market
Appendices

APPENDIX II – Credentials
Appendix II – Credentials

As our team’s credentials demonstrate, the global Financial Services Risk Canadian Bank– Framework and RCSA (3 months)
Management Practice includes staff who have extensive knowledge and Ernst & Young worked with this Canadian Bank to develop an operational risk
understanding of risk management frameworks gained through industry experience. management framework that was consistent with their internal culture and
Our credentials include: organisation structure, yet met Canadian and Basel regulatory requirements. Based
Global European-Based Financial Institution on the framework that was developed, The Bank has begun development of internal
We have been engaged to assist the Corporate Centre in the development of an loss tracking, and has successfully integrated this with other operational risk
integrated operational risk management and Sarbanes Oxley risk assessment management techniques. Also it selected JP Morgan’s Risk and Control Self
process. This has involved the design and development of the methodology, Assessment (“RCSA”) tool – “HORIZON” as the foundation of their Operational Risk
assistance in the selection of appropriate technology, oversight and assistance in Management approach. We are currently engaged with deploying this tool on a pilot
the development of the pilot process and documentation of various policies and basis within the Bank.
procedures.

G7 Central Bank– Framework and RCSA (ongoing) UK Building Society – Basel II Operational Risk Approach and Framework
(ongoing)
We worked with a Central Bank to develop an operational risk management Ernst & Young were retained as Basel II Advisors during this engagement. An initial
approach for their Markets Group, which was risk sensitive and would be consistent two-day strategic planning workshop to develop the Basel II Programme leveraging
with the leading practices used by their member banks. Based on the framework, the business’s knowledge of the gaps in current risk management capability. A series
this Central Bank selected Ernst & Young’s Risk and Control Self Assessment tool of targeted workshops were held to provide specialist advice and support relating to
– “HORIZON” as the foundation of their operational risk management approach. the implementation of the programme. These workshops addressed senior
management roles and responsibilities, the risk management framework, operational
risk modelling and how to move from the standardised approach to the advanced
UK Retail Bank – Basel II Operational Risk Gap Analysis (6 months) approach. This left the business with a clear vision of what is needed and a plan to
Ernst & Young helped the client understand the detailed requirements of Basel II, help them achieve this. The client has realised that to adopt the advanced
and identified the strengths and weaknesses in the current operational risk measurement approach and realise a further reduction in operational risk capital is not
management framework. We developed detailed action plans to address the gaps a significant step once the standardised approach has been achieved.
and addressing the weaknesses in such a way that was consistent with the
strategic running of the business. Ongoing support is provided for the Basel II
Programme including quality assurance over action plans.
Appendix II – Credentials (cont’d)
French Investment Bank –RCSA and KRIs (4 months) Large Reinsurance Company – Framework and RCSA (12 months)
We were engaged to assist in the enhancement of the client’s risk management We worked with this organisation to improve and embed a worldwide comprehensive
and operational risk environment with the implementation of HORIZON RCSA. We risk management and control framework. This included ensuring risk management
focused on methodology & “HORIZON” training, system implementation, process practices and protocols were embedded within the operating units, further enhancing
decomposition, risk assessment, action plan identification, and “HORIZON” risk management awareness and ownership, and using the HORIZON self
population. We were also engaged by this bank to focus on the identification of assessment tool to ensure clear and consistent mechanisms exist to identify, assess,
critical leading, multi-dimensional KRIs, process to identify key risks, risk drivers, manage and report risks Swiss Investment Bank – Quantification (3 months)
and potential metrics. We created a knowledge transfer environment to enable the
Bank’s Operations Risk Group to independently educate and train business units on For a large global European bank Ernst & Young headed the operational risk
quantification efforts, developing and implementing the methodology currently used by
KRI methodology.
the bank to measure operational risk. At this same bank, Ernst & Young managed the
US Investment Bank – KRIs (2 months) Risk Technology group that supported the systems demands of the operational risk
The Bank engaged Ernst & Young to assist with the identification of key risk area.
indicators (“KRIs”) and to help design a KRI Dashboard. Ernst & Young trained the UK Retail Bank – Quantification (4 months)
operational risk management personnel and business unit personnel on our KRI
identification methodology through pilot projects on selected business lines in the Ernst & Young developed a risk measurement approach with this UK retail bank for
bank. We then assisted the Bank by drafting the business requirements and the quantification of operational risk across the Bank. The objective of this project was
functional specifications for the “KRI Dashboard”, enabling the Bank to gain a one- to enable the building of capital model for each of the significant operational risks of
the Bank, at different confidence levels. Confidence levels would stretch from 99.5 %
page overview of critical management information.
to the 99.99% identified as a parameter by the Regulator.
US Investment Bank – KRIs (2 months)
To build the model, each risk was broken down into its components (causes) and
Ernst & Young worked with this organisation to reduce the amount of metrics controls identified for each. The risk was dimensioned in terms of gross impact and
tracked by the Finance department, and focus on the critical few, leading indicators probability, and controls were dimensioned in terms of design and performance.
that the business unit could focus on to measure its risk profile. This project
significantly reduced the amount of metrics tracked by each unit, and allowed for These forced values were run through the Ernst & Young ScoreCard, with the output
being a loss distribution for the risk event. The residual loss without control was used
enhanced, exception based reporting to senior management.
as the figure required to allocate capital against it. The great advantage of the
. scorecard approach is that it uses a Company ’s own assessment of its risks and
controls, rather than its previous losses, as the input data for modeling and measuring
the operational risk capital it requires. So, although the assessment of those risks and
controls is a matter of judgment, it is based on what the company thinks might happen
in future rather than what has happened in the past – where most companies have
already tightened the controls.
Appendix II – Credentials (cont’d)

A Large Latin American Bank – Quantification (3 months) Step 2: This step consisted of the ORM Executives, along with E&Y, selecting
For one of the largest Latin American banks Ernst & Young managed the the ORM methodologies and the automated operational risk tools the GSE
client’s risk management personnel in developing the bank’s operational risk wished to implement, along with a time line for implementation of these
measurement methodology. approaches. The ORM approaches that were selected included:

• Risk and Control Self Assessment (RCSA),


Government Sponsored Entity (GSE) – Framework and Policy
• Process Sustainability / Strategic Assessments,
Development
• Key Risk Indicators (KRIs),
• Loss Event Tracking,
E&Y assisted this GSE with a four-step project designed to assist with the
• Near Miss Analysis, and
design and development of its operational risk management approach. These
• Targeted Process Reviews.
four steps were completed over a three month time frame, and were designed
to educate the ORM Group as to operational risk’s regulatory and industry
trends, select an operating risk management approaches, develop a detail
Step 3: Once the Operational Risk Management methodologies and
implementation plan, and educate the Business Unit personnel and the ORM
automated tools were selected, project and implementation plans were
Team.
developed, and the ORM personnel were trained on the methodologies the
tools.
This project was executed according to the following sequence:
Upon completion of this project, the ORM group began to implement and deploy
the methodologies and tools according to the project plan, with E&Y providing
Step 1: This step consisted of several workshops with the company’s Senior
limited deployment assistance where needed.
Executives, focused on developing the mandate of the ORM group within the
organization, reviewing the banking industry’s operational risk trends and
Step 4: E&Y developed and delivered ORM training to the Management within
techniques, reviewing the current regulatory perspective on operational risk,
the Business Units on the firm’s ORM approach, as well as on the specific tools
and educating these executives as to the elements of a well designed and
and methodologies to be used. This training was provided to several divisions
controlled process.
within the GSE, including the Technology and Operations Division, and included
a comparison of the GSE’s to ORM approach and risk catalog to that of COBIT
(US IT Security Standard).

You might also like