Tools For Risk
Management
Week 11
Lecturer: Barney Baldwin
Announcements
• Individual project due today by 11:59 PM
• Office hours Wednesday April 16 11-1
• Group project mandatory status update for each group 11-1
• SELECT A TIME
• Final Exam is May 1 (room TBD)
2
Quiz 4
Individual Project
Presentations
Group Project
Steps for Planning an ERM tool implementation
• Identify the Business Problem Accounting for:
• People
• Process
• Define High-level Requirements • Technology
• Data
• Select Target Platform(s) • Change Capability
• Define / Refine the plan Data
• Identify Opportunities, Risks, Pros, Cons* Data
Data
People/
Data
Refine requirements
Organization
People/
• Data Organization
People/
Organization
People/
• Define delivery approach / steps Organization
People/
Organization Process/
Technology
Refine High-level plan
Functions
•
Process/
Technology
Functions
Process/
Technology
Functions
Process/
Present the Proposal
Technology
Process/Functions
• Functions
Technology
* A.k.a. Strengths, Weaknesses, Opportunities, Threats (SWOT)
6
Project Deliverables
• Agile Scrum Template
• High-level Business Requirements
• Tasks and Plan Presentation
7
High Level Requirements
• Demonstrate understanding of the problem
• Focus is Issue Management
• What is the business process for managing enterprise issues?
• Do some research online
• Summarize the requirements for a centralized issue
management platform
• Should meet Hypobank’s stated objectives
8
Tasks and Plan
• Identify all the tasks that are necessary to implement
Hypobank’s target state
• People
• Establish governance over the project
• Establish governance over the platform
• Who will prioritize changes
• Target business process
• Establish Data governance
• Canonical Model
• Ensure that teams are appropriately staffed
• Ensure vendor engagement
• Training for technology and users
9
Tasks and Plan (2)
• Technology
• What vendor platforms
• Dev/Test/Production environments
• Automation
• Migrations from Dev to Test to Prod
• Data Tools
• Data Migration tools (scripts) to move from the legacy environments
• Testing Tools
• Technology Change management
• Architecture approval
• Security
• Roles, add/remove staff
• Penetration testing
10
Tasks and Plan ()
• Technology Continued
• Performance testing
• Availability Testing
• Agile process for supporting teams? Or waterfall?
• Manage Vendor releases
• Test
• Production Rollout
• Upstream and Downstream systems
• Data feeds scripted, in and out
• Report production
• System maintenance and monitoring
11
Tasks and Plan (3)
• Risk Business Processes
• Define and evolve Target business process
• Issue management
• Other Op Risk processes (new business, tech risk, BCP, etc.)
• What is the order of migration to new platform?
• Timing for US/EU issue management?
• Other business processes?
12
Tasks and Plan (4)
• Data
• For each business migration:
• Data cleansing in legacy stores
• Data mapping to target state
• Implement data migration scripts
• Migrate test data
• Migrate production data
• Ensure that historical data is migrated
13
Tasks and Plan - Gantt Chart Example
14
Tasks and Plan
• Your Gantt chart will have
• Activities that extend for the duration of the project
• For example, data management
• Activities required to set up the project
• Vendor contracts
• Detailed requirements
• Environment setup
• Etc.
• Activities that are specific to the migration of each legacy environment
• Data cleansing in legacy environment
• Development
• Data migration
• Testing, production cutover, etc.
15
Final Presentation
• Powerpoint (8-20 slides)
• State the problem
• Summarize the approach to solving
• Summarize the delivery plan
• Identify Strengths and Opportunities
• Identify Risks and Weaknesses
• DO NOT INCLUDE SCREENSHOTS OF THE DETAILED MATERIAL
• We will be doing the presentations in office hours Thursday
November 21
• 15 minutes per group
• All students should speak
16
Data Context (review)
Data Protection
• Ensure data is available to those who need it:
• Backups – storage outage
• System availability – local systems outage
• Disaster Recovery – sitewide issues
• Ensure data is not accessible to those who shouldn't have it:
• Access controls for applications
• Role-based in most risk tools
• Server and Storage access controls
• Data Encryption
18
Key Concepts in Data Management (1)
• Data Model
• A physical or logical model of the data used by business processes
• Involves on one or more ”taxonomies” – data classifications
• Often represented in an Entity-Relationship diagram (ERD)
• “Entities” are the things themselves
• Relationships define how they are connected
• E.g. one-to-one, one to many, etc.
• Risk tools have in-built data models
• Mature organizations usually have teams that manage an Enterprise Data Model
• “Canonical Form”
• Chief Data Office (CDO) governs the models
• Data architects and data modelers do the hands-on documentation
19
Key Concepts in Data Management (2)
• Data Mapping
• The “translation” from one data model to another
• Required to get data from one system into another
• Data mapping is a major effort in most risk projects
• Business Analysts work with technology and business functions (e.g. Risk
Managers) to define data maps between process
• Key issues in Data Mapping
• Data privacy and accountability (Regulatory, client, and business confidentiality)
• Often data is hidden (“dark data”) used by local business processes
• Data maps can grow unmanageably complex
• Automation can help produce some of the documentation in structured databases
20
Key Concepts in Data Management (3)
• Data Migration
• Movement of data between system and processes
• Between System A and System B
• Complex data maps between systems
• Mapping from one system to the canonical form
• Between environments (dev/test/production)
• May require “masking” for sensitive data migrating from production to “lower”
environment
• Easier with a clean and complete data map
• Full automation is desirable
• Some aspects may require manual effort (re-keying)
21
BCBS 239 Principles - Introduction
22
Conceptual Structure of a Risk Data Platform
• Source systems capture data
Trading and
• For example, a trading system will capture all trades Risk Reports
• A security system will record unauthorized access attempts Systems and
• In some cases, data is already aggregated at a lower level Dashboard
(desk)
• Additional Data is imported to support analysis
• Data is normalized, standardized, and Analytics
Data
gathered into an analytics data repository Normalization (Risk)
Repository
• Real-time or end-of-day
• Typically, a data warehouse or data lake Other
• Calculations may run directly on warehouse data Sources
• Processes run on the data repository to Risk
Calculation
produce analyses of the data – views or
reports
23
Data Cubes
Conceptually, the underlying data in almost any
report can be represented in a multi-dimensional
cube (hypercube)
• Slicing, dicing, and drilldown
This model (or generally a more complex version)
underlies almost all enterprise risk reporting.
24
Next Week…
Next Module (Week 12)
• Current events and industry developments
• Read:
• Jean-Jules, J., & Vicente, R. (2020). Rethinking the implementation of enterprise risk
management (ERM) as a socio-technical challenge. [link]
26