0% found this document useful (0 votes)
6 views20 pages

Understanding Operational Risk Management

Operation Risk

Uploaded by

deloarjkkniuhrm
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOC, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views20 pages

Understanding Operational Risk Management

Operation Risk

Uploaded by

deloarjkkniuhrm
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOC, PDF, TXT or read online on Scribd

CHAPTER ‐ 5

OPERATIONAL RISK MANAGEMENT


5.1 Operational Risk

Operational Risk is the risk of financial losses related to breakdown in internal control and
corporate governance. Such breakdown can be the result of human error, inadequate or
failed internal processes and technical systems, fraud, or from any other adverse external
events.

Of all the risks that an FI can face, operational risk may be the most devastating and at the
same time, the most difficult to anticipate. Its appearance can result in sudden and dramatic
reductions in the value of an FI. Operational risk differs from other risks since it is typically
not taken in return for an expected reward rather exists in the natural course of corporate
activity. At the same time, failure to manage operational risk properly can misinterpret
the risk profile of FI and expose it to significant losses.

5.2 Importance of Operational Risk Management


An FI can obtain the following values through operational risk management:

a. Validate and improve the reliability and effectiveness of business operations and
the operation of the risk management framework;

b. Enhance the risk‐based decision‐making process and improve the risk


management capability of its employees;
c. Enhance confidence in planning process and prevents delay and cost overruns in
the execution process;
d. Develop organizational capability in ensuring safety of employees;
e. Increase accuracy and visibility of risk information;
f. Quickly identify the institution’s operational deficiencies;
g. Increase management foresight;
h. Optimize business performance; and
i. Reduce the cost and complexity of operational risk process.
5.3 Components of Operational Risk

Operational risk can be subdivided into two components:

a. Operational strategic risk, and


b. Operational failure risk

a. Operational Strategic Risk


Operational strategic risk arises from the environmental factors that are usually beyond
the control of an FI. It may also arise from a new strategic initiative, such as getting into a
new line of business or redoing how current business is to be done in the future. It is also
defined as external operational risk. The operational strategic risk factors may be political,
government policies, regulatory issues, societal, ethnic values, competition etc.

b. Operational Failure Risk

An FI uses people, process, and technology to achieve business plans. Operational failure
risk arises if any of these factors fail to perform properly. A certain level of the failures
may be anticipated and should be built into the business plan. These failures can be
expected to occur periodically, although both their impact and their frequency may be
uncertain.

5.4 Categorization of Operational Risk

Operational risk of an FI may arise from different events. The risk event can be of the
following types‐

a. Internal Fraud
b. External Fraud
c. Employment Practices and Workplace Safety
d. Clients, Products and Business Practices
e. Damage to Physical Assets
f. Business Disruption and System Failure
g. Execution, Delivery, and Process Management
FIs face above risk events most frequently for the following circumstances‐

- Embezzlement
- Unauthorized trading
- Misappropriation of assets
- Fraudulent transfer of funds
- Theft of customer funds
- Fraudulent payment
- Misuse of confidential information
- Cybercrime
- Robbery
- Environmental issues
- Wrongful termination of employees
- Discrimination at workplace
- Natural disaster/ Accidental issues
- Regulatory breach
- Pandemic
- Fiduciary breach
- Compromised customer information
- Terrorist attack etc.
FIs are required to adopt and utilize standard categorization of operational risk. They
should consider their products in this categorization mechanism. For each combination of
products and event types there may be one or more circumstances. FIs should carefully
observe the related circumstances for each combination to deal with the operational risk
effectively.

5.5 Operational Risk Management Principles

All financial institutions, regardless of their size or complexity, should address following
fundamental principles in their approach to operational risk management‐

a. Level of risk appetite that the financial institution is willing to accept, together with
the basis for managing those risks are to be fixed by the board.

b. Effective and integrated operational risk management framework of an FI is to be


ensured.

c. Risk management framework should incorporate a clearly defined organizational


structure, with defined roles and responsibilities for all aspects of operational risk
management/monitoring and appropriate tools that support the identification,
assessment, control and reporting of key risk indicators.

d. All categories of operational risk applicable to the FI should be recognized,


understood and properly defined. Furthermore, it is to be ensured that the
operational risk management framework adequately covers all the categories of
operational risk.

e. Operational risk policies and procedures should be clearly defined, documented


and communicated.

f. All business and support functions should be an integral part of the overall
operational risk management framework in order to manage the key operational
risks effectively.

g. Identification, assessment, mitigation, monitoring and reporting of operational


risks are to be done primarily by the line management.

h. Proper training is to be organized for establishing the risk management culture


within the financial institution.
5.6 Operational Risk Management Process

FIs need to manage operational risk after categorization. The process of operational risk
management will be as follows:

Identification of operational
risk

Collection of data for


assessment

Assessment of risk

Framing of risk policies and


actions

Culture and awareness of risk

Risk monitoring and reporting

Evaluation of actions for


mitigation of risk

5.7 Operational Risk Management Framework

Operational risk management framework should clearly address all the components
associated with operational risks. The framework should cover‐

a. institution’s tolerance limit of the risk defined by the board;

b. prioritization of operational risk management activities including the extent of, and
manner in which, operational risk is to be managed and mitigated;
c. include the policies outlining the institution’s approach to identify, assess, monitor
and control/mitigate the operational risk; and
d. responsibilities and reporting between operational risk control functions, business
lines and support functions should be clearly separated in order to avoid conflict of
interest.

5.8 Key Risk Indicators

In the operational risk management framework there must be some key risk indicators
that shall provide the management an early‐warning, specifying the areas where pre ‐
defined thresholds exist and thus shall highlight the potential danger spots in a timely
fashion.

Based on the nature of activities, financial institutions should identify appropriate


indicators that provide early warning of an increased risk of future losses. Such indicators
should be forward‐looking and could reflect potential sources of operational risk such as
rapid growth, the introduction of new products, employee turnover, transaction breaks,
system failure, and so on. When thresholds are directly linked to these indicators an
effective monitoring process can help identifying key material risks in a transparent
manner and enable the financial institution to act upon these risks appropriately. Regular
reviews should be carried out by internal audit, to analyze the control environment and
test the effectiveness of implemented controls, thereby ensuring business operations are
conducted in a controlled manner.

5.9 Operational Risk Management Responsibilities

Operational risk management is an overall process. Both the Board and the senior
management of an FI should be responsible for the operational risk management principles.

5.9.1 Board’s Responsibilities

The fundamental premise of sound operational risk management in an FI primarily


depends on the Board’s leadership and directives. Keeping that in mind, the Board of
Directors of an FI should take the lead in establishing a strong operational risk
management culture in the company that to be guided by strong risk management
policies and procedures.
Operational risk management will be most effective where organizational culture
emphasizes high standards of ethical behavior at all levels. So, the Board of an FI should
encourage such culture in the organization, which establishes through both actions and
words, the expectations of integrity for all employees in conducting the business of the FI.
The Board is responsible for creating an organizational culture that places high priority on
effective operational risk management and adherence to sound operating controls.
Generally, the Board’s responsibilities shall include the following:

a. To lead the institution through establishing a strong operational risk management


culture within the company;

[Link] establish management structure capable of implementing the FI’s operational risk
management framework specifying clear lines of management responsibility,
accountability and reporting;

c. To approve the policies for operational risk management of the institution to be


prepared under the guidelines of the principles;

[Link] set the strategic direction in relation to operational risk based on the
requirements and obligation to the stakeholders of the FI;

e. To set tolerance level of the risk management;

f. To establish code of conduct and ethical practices within the company through
human resources setting clear expectations for integrity and ethical values of the
highest standard;

g. To monitor institution’s safety and soundness on account of operational risk;

[Link] provide clear guidance and direction to the senior management regarding the
principles underlying the operational risk management framework; and

i. To monitor and review the operational risk management policies and procedures
along with the framework regularly to ensure that the institution is managing the
operational risks. This review process should also aim to assess industry best practice
in operational risk management appropriate for the institution’s activities, systems
and processes.
5.9.2 Senior Management’s Responsibilities

Strong and consistent support and ethical behavior of senior management for managing
risk convincingly reinforces codes of conduct and ethics within the institution. Clear
expectations and accountabilities ensure that institution’s employees understand their roles
and responsibilities for operational risks, as well as their authority to act. So, it is the
senior management’s responsibility to translate the principles in the policies through
identifying the acceptable business practices prohibiting conflicts among the employees.
Generally, the senior management’s responsibilities shall include the following:

a. To translate the operational risk management framework into specific policies and
procedures that can be implemented and verified within the business;
b. To implement the policies and procedures within the organization as approved by
the Board;
c. To clearly assign authority, responsibility and reporting relationships within the
employees to encourage and maintain the accountability and ensure that the
necessary resources are available to manage operational risk effectively;
d. To ensure that the financial institution's operational risk management policies and
procedures has been clearly communicated to all employees;
e. To assess the appropriateness of the risk management process in light of the risks
inherent in the institution’s business policy;
f. To ensure that institution possesses qualified employees with the necessary
experience, technical capabilities and access to resources, and that employee
responsible for monitoring and enforcing compliance with the FI’s risk policy have
authority and are independent from the units they oversee; and
g. To ensure that the financial institution’s remuneration policies are consistent with its
appetite for risk.

5.10 Policies and Procedures

The fundamental premise of sound operational risk management is to understand the


nature and complexity of the risks inherent in the institution’s business, products, services
and activities. A vital means of understanding the nature and complexity of operational
risk is to have the components of the risk framework fully integrated into the overall risk
management processes of the institution. The framework should be appropriately
integrated into the risk management processes across all levels of the institution.
FIs should develop, implement and maintain the policies and procedures of the
operational risk management that is fully integrated with the institution’s overall risk
management processes. The policies and procedures for operational risk management will
depend on a range of factors, including its nature, size, complexity and risk profile.

The operational risk management policies should include the following:

a. The strategy given by the Board;


b. The systems and procedures to introduce effective operational risk management
framework; and
c. The structure of operational risk management function and the roles and
responsibilities of individuals involved.

The policy should establish a process to ensure that any new or changed activity, such as
new products or systems conversions, will be evaluated for operational risk prior to
coming into effect. It should be approved by the board and documented. The policy
should be regularly reviewed and updated, to ensure that it continues to reflect the
environment within which the institution operates.

5.11 Identification and Assessment

Risk identification and assessment are fundamental characteristics of an effective


operational risk management system. Effective risk identification considers both internal
and external factors. Sound risk assessment allows the institution to better understand its
risk profile and allocate risk management resources and strategies most efficiently.

FIs should identify and assess the operational risk inherent in all existing products,
activities, processes and systems and its vulnerability to the risk. FIs should also ensure
the inherent operational risk while introducing or undertaking new products, activities,
processes and systems. FIs should consider the following tools to identify and assess the
operational risk:

a. Self risk assessment: An FI assesses its operations and activities against a menu of
potential operational risk vulnerabilities. This process is internally driven and often
incorporates checklists and/or workshops to identify the strengths and weaknesses
of the operational risk environment.

b. Risk mapping: Risk mapping identify the key steps in business processes, activities
and organizational functions. It also identifies the key risk points in the overall
business process. Risk mapping can reveal individual risks, risk interdependencies,
and areas of control or risk management weakness. They also can help prioritize
subsequent management action.

c. Risk indicators: Risk indicators are statistics and/or metrics, often financial, which
can provide insight into a financial institution's risk position. These indicators are to
be reviewed on a periodic basis (such as monthly or quarterly) to alert financial
institutions to changes that may be indicative of risk concerns. Such indicators may
include the number of failed trades, staff turnover rates and the frequency and/or
severity of errors and omissions. Threshold/limits could be tied to these indicators
such that when exceeded, could alert management on areas of potential problems.

d. Historical data analyses: The use of data on an FI’s historical loss experience could
provide meaningful information for assessing its exposure to operational risk and
developing a policy to mitigate the risk. An effective way of making good use of this
information is to establish a framework for systematically tracking and recording
the frequency, severity and other relevant information on individual loss events.

5.12 Mitigation of Operational Risks

Some significant operational risks have low probabilities but potentially very large
financial impact. Moreover, not all risk events can be controlled, e.g. natural disasters.
Risk mitigation tools or programs can be used to reduce the exposure to, or frequency
and/or severity of such events. For example, insurance policies can be used to externalize
the risk of "low frequency, high severity" losses which may occur as a result of events such
as third‐ party claims resulting from errors and omissions, physical loss of securities,
employee or third‐party fraud, and natural disasters.

However, FIs should view risk mitigation tools as complementary to, rather than a
replacement for, thorough internal operational risk control. Having mechanisms in place
to quickly recognize and rectify legitimate operational risk errors can greatly reduce exposures.
Careful consideration also needs to be given to the extent to which risk mitigation tools
such as insurance truly reduce risk, or transfer the risk to another business sector or area,
or even create a new risk e.g. legal or counterparty risk.
Investments in appropriate processing technology and information technology security
are also important for risk mitigation. However, FIs should be aware that increased
automation could transform high‐frequency, low‐severity losses into low ‐frequency, high ‐
severity losses. The latter may be associated with loss or extended disruption of services
caused by internal factors or by factors beyond the institution's immediate control e.g.
external events. Such problems may cause serious difficulties for FIs and could jeopardize
an FI’s ability to conduct key business activities. FIs should therefore establish disaster
recovery and business continuity plans that address this risk.

5.13 Monitoring

FIs should implement a process to regularly monitor operational risk profiles and material
exposures to losses. There should be regular reporting of pertinent information to senior
management and the board of directors that supports the proactive management of
operational risk.

An effective monitoring process is essential for adequately managing operational risk.


Regular monitoring activities can offer the advantage of quickly detecting and correcting
deficiencies in the policies, processes and procedures for managing operational risk.
Promptly detecting and addressing these deficiencies can substantially reduce the
potential frequency and/or severity of a loss event. Senior management should establish a
program to:

a. monitor assessment of the exposure to all types of operational risk faced by the
financial institution;
b. assess the quality and appropriateness of mitigating actions, including the extent
to which identifiable risks can be transferred outside the financial institution; and
c. ensure that adequate controls and systems are in place to identify and address
problems before they become major concerns.

It is essential that:

- responsibility for the monitoring and controlling of operational risk should follow
the same type of organizational structure that has been adopted for other risks,
including market and credit risk;
- senior management ensure that an agreed definition of operational risk together
with a mechanism for monitoring, assessing and reporting is designed and
implemented; and
- this mechanism should be appropriate to the scale of risk and activity undertaken.

In addition to monitoring operational loss events, financial institutions should identify


appropriate indicators that provide early warning of an increased risk of future losses.
Such indicators (often referred to as key risk indicators or early warning indicators or
operational risk matrix) should be forward‐looking and could reflect potential sources of
operational risk such as rapid growth, the introduction of new products, employee
turnover, transaction breaks, system downtime, and so on. When thresholds are directly
linked to these indicators an effective monitoring process can help identify key material
risks in a transparent manner and enable the financial institution to act upon these risks
appropriately. Regular reviews should be carried out by internal audit, or other qualified
parties, to analyze the control environment and test the effectiveness of implemented
controls, thereby ensuring business operations are conducted in a controlled manner.

The results of monitoring activities should be included in regular management and board
reports, as should compliance reviews performed by the internal audit and risk
management functions.

5.14 Reporting

Appropriate reporting mechanisms should be in place at required levels that support


proactive management of operational risk. FIs should ensure that its reports are
comprehensive, accurate, consistent and actionable across business lines and products.
Reports should be manageable in scope and volume since effective decision ‐making is
impeded by both excessive amounts and paucity of data.

FIs should produce reports both in normal and stressed market conditions. The frequency
of reporting should reflect the risks involved and the pace and nature of changes in the
operating environment. For regular reporting senior management should establish a
program to:
a. monitor all types of assessed operational risk faced by the institution;
b. assess the quality and appropriateness of mitigating actions, including the
extent to which identifiable risks can be removed; and
c. ensure that adequate controls and systems are in place to identify and address
problems before they become major concerns.
Senior management should ensure that information is available to the Audit Committee of
Directors on a timely basis, in a form and format that will aid in monitoring and control of
the business. The reporting process should include information such as:

- the critical operational risks facing or potentially facing, by the financial


institution;
- risk events and issues together with intended remedial actions;
- the effectiveness of actions taken;
- details of plans formulated to address any exposures where appropriate;
- areas of stress where crystallization of operational risks is imminent; and
- the status of steps taken to address operational risk.
In general, the Board of Directors should receive the most critical and important information
from the Audit Committee of the Directors to enable them to understand the institution’s
overall operational risk profile and focus on the material and strategic implications for the
business.

Operational risk reports may contain internal financial, operational, and compliance
indicators, as well as external market or environmental information about events and
conditions that are relevant to decision making.

Operational risk reports should include:

- breaches of the institution’s risk appetite and tolerance levels, as well as thresholds
or limits;
- details of recent significant internal operational risk events and losses; and
- relevant external events and any other potential impact on the FI.

Data capture and risk reporting processes should be analyzed periodically with a view to
continuously enhancing risk management performance as well as advancing risk
management policies, procedures and practices.
5.15 Establishing Control Mechanism

Control activities are designed to address the operational risks that an FI has identified.
For all material operational risks that have been identified, the institution should decide
whether to use appropriate procedures to control and/or mitigate the risks, or bear the
risks. For those risks that cannot be controlled, the FI should decide whether to accept
these risks, reduce the level of business activity involved, or withdraw from this activity
completely. To be effective, control activities should be an integral part of the regular
activities of an FI. A framework of formal, written policies and procedures is necessary; it
needs to be reinforced through a strong control culture that promotes sound risk
management practices.

5.16 Resiliency, Continuity and Contingency Planning

FIs should have business resiliency, continuity and contingency plans in place to ensure an
ability to operate on an ongoing basis and limit losses in the event of severe business
disruption.

Resiliency, continuity and contingency plans should incorporate business impact analysis,
recovery strategies, testing, training and awareness programs, and communication and
crisis management programs. An FI should identify critical business operations, key
internal and external dependencies, and appropriate resilience levels. Plausible disruptive
scenarios should be assessed for their financial, operational and reputational impact, and the
resulting risk assessment should be the foundation for recovery priorities and objectives.
These plans should establish contingency strategies, recovery and resumption procedures,
and communication plans for informing management, employees, regulatory authorities,
customer, suppliers, and civil authorities (if applicable).

FIs should periodically review these plans to ensure contingency strategies remain
consistent with current operations, risks and threats, resiliency requirements, and
recovery priorities.
5.17 Internal Controls
Internal control systems should be established to ensure adequacy of the risk
management framework and compliance with a documented set of internal policies
concerning the risk management system. Principal elements of this could include‐
a. top‐level reviews of the FI’s progress towards the stated objectives;
b. policies, processes and procedures concerning the review, treatment and
resolution of non‐compliance issues; and
c. a system of documented approvals and authorizations to ensure accountability
to the appropriate level of management.
Although a framework of formal, written policies and procedures is critical, it needs to be
reinforced through a strong control culture that promotes sound risk management
practices. Board and senior management are responsible for establishing a strong internal
control culture in which control activities are an integral part of the regular activities of an
FI.

Operational risk can be more pronounced where FIs engage in new activities or develop new
products (particularly where these activities or products are not consistent with the FI’s core
business strategies), enter unfamiliar markets, and/or engage in businesses that are
geographically distant from the head office. It is therefore important for FIs to ensure that
special attention is paid to internal control activities including review of policies and
procedures to incorporate such conditions.

FIs should have in place adequate internal audit coverage to verify that operating policies
and procedures have been implemented effectively. The board (either directly or
indirectly through its audit committee) should ensure that the scope and frequency of the
audit program is appropriate to the risk exposures. Audit should periodically validate that
the FI's operational risk management framework is being implemented effectively across
the institution.

To the extent that the audit function is involved in oversight of the operational risk
management framework, the board should ensure that the independence of the audit
function is maintained. This independence may be compromised if the audit function is
directly involved in the operational risk management process. The audit function may
provide valuable input to those responsible for operational risk management, but should
not itself have direct operational risk management responsibilities.

An effective internal control system also requires existence of appropriate segregation of


duties and that personnel are not assigned responsibilities which may create a conflict of
interest. Assigning such conflicting duties to individuals, or a team, may enable them to
Risk Management Guidelines for FIs conceal losses, errors or inappropriate actions.
Therefore, areas of potential conflict of interest should be identified, minimized, and
subjected to careful independent monitoring and review.

In addition to segregation of duties, FIs should ensure that other internal practices are in
place as appropriate to control operational risk which include‐

a. close monitoring of adherence to assigned risk limits or thresholds;


b. maintaining safeguards for access to, and use of, FI's assets and records;
c. ensuring that staffs have appropriate expertise and training;
d. identifying business lines or products where returns appear to be out of
line with reasonable expectations e.g. where a supposedly low risk, low
margin trading activity generates high returns that could call into question
whether such returns have been achieved as a result of an internal control
breach; and
e. regular verification and reconciliation of transactions and accounts.

You might also like