0% found this document useful (0 votes)
11 views16 pages

Understanding Operational Risks in Banking

The document discusses operational risks in financial institutions, particularly in the context of the Basel II framework, which standardizes the definition, management, and quantification of such risks. It emphasizes the importance of identifying and managing operational risks to prevent systemic failures, as highlighted by past scandals like Société Générale and Barings. The document outlines various approaches for assessing regulatory capital requirements related to operational risks and provides principles for effective risk management practices within banks.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
11 views16 pages

Understanding Operational Risks in Banking

The document discusses operational risks in financial institutions, particularly in the context of the Basel II framework, which standardizes the definition, management, and quantification of such risks. It emphasizes the importance of identifying and managing operational risks to prevent systemic failures, as highlighted by past scandals like Société Générale and Barings. The document outlines various approaches for assessing regulatory capital requirements related to operational risks and provides principles for effective risk management practices within banks.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

CHAPTER I.

OPERATIONAL RISKS: NEW ISSUES AND


MEANS OF ACTIONS
The scandal of Société Générale revealed to the general public the consequences of
risks related to operational dysfunctions. With the Basel II reform, this
Risk categories must now be taken into account in the assessment of funds.
owned by financial institutions.

The operational framework for financial institutions (banking and insurance) is the
risk of direct or indirect losses due to inadequacy or failure of
establishment procedures (analysis or control absent or incomplete, procedure not
secured), its personnel (error, malice and fraud), internal systems
(computer failure ...) or to external risks (flood, fire ...). In the
In the context of the Basel II framework, the definition of operational risk, the procedures to implement
in place to limit it and the quantification methods have been standardized. The objective
The purpose of this device, implemented in European banks in 2008, is to prevent the
systemic risk.
Operational risks have taken on considerable importance in the context.
banking born from deregulation, from the increasing intertwining of the actors of the world
financier, of the increase in managed capital and the sophistication of products
as shown by the casesBaringsand Société Générale.
As part of the Basel II framework, good practices to be implemented have been defined.
by each financial institution. The national financial regulator is responsible for them
evaluate and control them. Financial institutions can choose to
risk assessment device more or less sophisticated. Since the Basel reform
II, operational risk is included in the calculation ofregulatory capital of
the banking institution with a proportional impact to the quality of its
procedures and its monitoring and evaluation device.

SECTION I. BETTER UNDERSTANDING OPERATIONAL RISK

1- Definition and Stakes of Operational Risks.

1.1- Definition of operational risk.

The device regulatorBasel IIdefines operational risk as the risk of losses


direct or indirect due to an inadequacy or failure of the procedures,
personnel and internal systems. This definition includes legal risk; however,
the risk of reputation (risk of loss resulting from damage to reputation

1 Bank Management Course – Professional License in Banking - Finance


the banking institution) and strategic risk (risk of loss resulting from poor
strategic decision) are not included.
This definition notably covers human errors, fraud, and malicious acts.
the failures of information systems, the problems related to personnel management,
commercial litigations, accidents, fires, floods.
TheBasel Committee has established a classification that introduces seven categories
events1related to this risk:

1. Fraudinternal: for example, inaccurate information about positions,


falsifications, crime committed by an employee and offense of initiation of an operating employee
for his own account.
2. External fraud: for example, robbery, forgery, and damages due to
computer hacking.
3. Practices regarding employment and workplace safety: for example,
claims for worker compensation, violation of health rules and
employee security, union activities, complaints of discrimination and
civil liability in general.
4. Clients, products, and business practices: for example, violation of
the fiduciary obligation, fraudulent use of confidential information about
the clientele, dishonest stock market operations on behalf of the bank,
money laundering and sale of unauthorized products.
5. Damage to bodily acts: for example, acts of terrorism, vandalism,
earthquakes, fires and floods.
6. Malfunction of activity and systems: for example, breakdowns of
computer hardware and software, telecommunications issues and
power outages.
7. Execution, delivery and management of processes: for example, error
data recording, failures in the management of securities, shortcomings
in legal documentation, error in accessing customer accounts and
supplier failures or conflicts with them.

1.2 - Stakes of Operational Risks

Since the middle of the last decade, knowledge in the field ofrisks of
creditand ofmarket riskshave sparked a wide debate and have been the subject of much
many research works. Normally, this work should have contributed to

2 Bank Management Course - Professional License in Banking - Finance


significant progress in the identification, measurement, and management of risks
his banking system. However, one cannot help but wonder about the impact
effect of these contributions, in light of recent events that have exerted a
determining influence on the2008 financial crisison one hand, the crisis
of thesubprimeson the other hand, the practices of the agencies ofnotetfinancial don't
The intervention is crucial in the process of managing credit risk.
That being said, during the same period, the evolution of the financial markets,
characterized notably by the globalization of banking activities and by their
deregulation has made these activities - and thus the corresponding risk profiles - of
increasingly complex. Financial regulators have also realized
that the risks were becoming increasingly difficult to identify because they were
present at all levels of an organization, increasingly difficult to measure
by the conjunction of direct losses and much more delicate indirect losses
to quantify, and increasingly difficult to manage due to the increasingly complex organization
crosses the meters of the bank and due to the difficulties in mastering them well
limits of their perimeters. It is partly for these reasons that both regulators
that banking institutions have put in place means to identify, measure
and control operational risks: events like those that occurred
products in New YorkSeptember 2001, or even the series of frauds that occurred
dans des insttutons bancaires (Société Générale, Barings, to name just a few
Media coverage shows that the management of banking risks goes far beyond
in the areas of credit risk or market risk, and requires the adoption
taking into account operational risks.

2-Context of the Regulation of Operational Risks specific to the device


of Basel II
For the determination of theregulatory capital, which constitutes one of the elements
As key elements of any banking regulation system, the Basel II framework establishes new
rules that take better account of economic reality, by refining the assessment of
risk profile of banking institutions and integrating systems into it
ofmetgatonof risks. This new regulation allows banks that meet
under certain conditions to reduce their regulatory capital requirements,
reserve the ability to demonstrate an efficient internal organization in management
of their risks.
To refine the management and control of risks, the McDonough report replaces the
previous Cooke ratio requires banks to allocate a portion of their own funds
to cover their credit risks, their market risks and - new feature of
McDonough rat - from their operational risks.
To assess a banking institution's exposure to operational risks, the
The Basel Committee proposes three approaches in increasing order of complexity and
sensitivity to risk

3 Bank Management Course - Professional License in Banking - Finance


A basic approach (Basic Indicator Approach BIA), consisting of a calculation
flat rate (α = 15%) of the regulatory capital requirements (KBIA), based on the
average net banking product (PNB) of the last three years: KBIA = α * PNB
A standardized approach (Standardized Approach STA), consisting of, for each
bank meter line, in a flat rate calculation (β = 12% to 18%, according to the eight
defined lines) of regulatory capital requirements (KSTA), based on GNP
average recorded on these meter lines over the past three financial years:
KSTA = Σ (β¹-⁸ * PNB¹-⁸)
An advanced approach (Advanced Measurement Approach AMA), consisting of
a calculation of regulatory capital requirements (KAMA) based on the
internal model(s) for measuring operational risks developed by the
bank and validated by the supervisory authority.
Even though the calculation of regulatory capital requirements is relatively simple
in the first two approaches (basic approach and standard approach), the
the weighting coefficient being fixed by the regulatory authority, the utilization of
the standard approach or by extension the advanced approach is subject to a
acceptance of the control authority, itself conditioned by compliance with certain
eligibility criteria: "...As with credit risk, the more management tools are
performant, so the more sophisticated the approach, the less great the requirement will be
equity. When the required conditions for the use of a method are met,
the bank is encouraged to use it. An active international bank, and the banks
having significant operational risks are supposed to use a more
more sophisticated than the basic approach. A combination of the three methods [approach of
basic, standard approach and advanced approach] is even possible depending on
activities, under certain conditions.2»
One of the innovations of the Basel II framework regarding operational risks is therefore
to encourage banking institutions to improve their management of operational risks,
the latter being framed by specific organizational requirements
each of the three approaches: the more complex the organization of the bank is and
sophisticated, through systems and practices more sensitive to risks, more
The approach proposed by the regulator allows for hope of a reduction in capital.
regulatory.

4 Bank Management Course - Professional License in Banking - Finance


SECTION II - BETTER ORGANIZE OPERATIONAL RISK MANAGEMENT

1- Good practices in operational risk management.

The entire Basel II framework was designed to encourage a gradual shift towards
the advanced method, which is in principle less capital-intensive
regulatory. This capital savings finds its counterpart in the implementation of
work of a specific organization aimed at better risk control
operational and, ultimately, to the reduction of losses. This is probably the reason
for which the regulator has itself defined a code of good practices to be used by
banks and their supervisors

1.1- The principles of good practices.

Starting from the principle set by the regulator that a risk is correctly
mastered if identified, measured, evaluated, and managed, the three approaches aim to
quantify operational risk with variable sensitivity and therefore, for the pair
supervisor / banker, to contribute to better prudential oversight of this
latest. Alongside these measurement tools, the regulator has developed ten principles of
good practices3necessary for the mastery of operational risks, thereby recalling
the importance of the involvement of the executive body in the implementation of such a
system, only for the identification of operational risks, notably through a
mapping of the latter.

Development of an appropriate environment for risk management


operational.

Principle 1: The board of directors [of the banking institution] should


consider the main aspects of operational risk of the bank as
a distinct category of risk to manage, and it should approve and review
periodically the risk management device. This device should provide
a definition of operational risk applicable to the entire bank and to pose the
principles used to identify, evaluate, monitor, and manage/mitigate this risk.
Principle 2: The board of directors should ensure that the management system
the operational risk of the bank is subject to an effective internal audit

5 Bank Management Course - Professional License in Banking - Finance


completed, carried out by functionally independent staff, equipped with a
appropriate and competent training. The internal audit function should not be
directly responsible for managing operational risk.
Principle 3: Management should aim to implement the
Operational risk management system approved by the board of directors.
This device should be applied consistently throughout
the banking organization, and the staff members, at all levels, should
understand their responsibilities in the management of operational risk. The
The general direction should also be responsible for developing policies, processes and
operational risk management procedures for all products, activities
important processes and systems.
Principle 4: Banks should identify and assess operational risk.
inherent in all products, activities, processes, and important systems. They
should also, before launching or exploiting products, activities, processes and
new systems, submit to an adequate risk assessment procedure
operational that is inherent to them.

Principle 5: - Banks should implement a monitoring process


regular operational risk profiles and significant exposures to
losses. The useful information for a dynamic management of operational risk
should be regularly communicated to the general management and the board
of administration.
Principle 6 – Banks should adopt policies, processes and
procedures to control and/or mitigate significant sources of risk
operational. They should periodically review their strategies
limitation and control of risk and adjust their operational risk profile in
consequence through the use of appropriate strategies, taking into account their appetite
for the risk and their overall risk profile.
Principle 7 – Banks should establish contingency plans and
continuity of operations to ensure uninterrupted functioning and
limit losses in the event of a serious disruption to operations.

6 Bank Management Course - Professional License in Banking - Finance


Role of supervisors

Principle 8 - Banking supervisory authorities should require all banks,


regardless of their size, have put in place an effective mechanism to identify,
evaluate, monitor and manage/mitigate significant operational risks, in the
framework of a comprehensive risk management approach.

Principle 9 – Supervisors should regularly conduct assessments, directly or


indirectly, to an independent evaluation of policies, procedures and practices of
banks in terms of operational risk. Supervisors should ensure that it
There are appropriate mechanisms that allow them to stay informed about the evolution.
in the banks.

Role of financial communication

Principle 10 - The financial communication of banks should be sufficient


elaborated to allow market participants to assess their methodology
management of operational risk.

1.2 - Organizational Challenges of Implementing Principles of


good practices.

The implementation of the basic method does not require any organizational requirements.
particular. If the structures of the other two approaches (standard and AMA) are quite
different, mainly due to the presence or absence of a dedicated entity
specifically concerning the management of operational risks, their implementation methods for
The works should theoretically be quite close in that, whatever the case may be,
the approach, these modalities are based on a processing model,
on the other hand on functionalities that are relatively standardized for the whole of
banks:

7 Bank Management Course - Professional License in Banking - Finance


1.2.1- Operational Risk Processing Model.
The operational risk processing model consists of four subprocesses.
necessary keys to develop an adequate management system:

risk identification;
risk assessment;
risk monitoring;
the control / attenuation of risk.
Identification
The identification of operational risks requires the bank to define what
are the factors inherent to operational risks and their multiple dimensions
(codification, internal/external aspect, frequency, belonging, severity, type of loss,
concerned activity(ies), concerned processes/functions, data and systems
involved, etc.). The implementation of this first sub-process of identification, in the
The framework of the Basel II device first encounters the problem of an internal definition.
operational risks that are consistent and compatible with those adopted by the
device itself, and then to that of their identification: indeed, if the losses
operational, which materialize the occurrence of operational risks, were
identified and controlled by the internal control departments or
of internal audit, they become in the new arrangement the responsibility of the
operational managers in all sectors of banking. The implementation of this
the first subprocess of identification may be influenced by the context in
which operates the bank ('principles based' versus 'rules based'), especially since
some go as far as to identify operational risk as any other financial risk
what credit risk or market risk. Second difficulty: a loss being
intrinsically measured by using accounting rules, due to its
impact on the bank's financial situation, the application of these accounting rules
can lead to divergent interpretations. Particularly difficult proves
the evaluation of certain impacts (loss of gross margin, loss of customers, by
example).
Evaluation
So far, to assess the amounts of risks, the experts in the field of
risk management have mainly developed their expertise in the field of
credit risks and market risks, with an emphasis on the application of
quantitative methods and statistical modeling and simulation. It was therefore
natural that these same experts, both within banks and with the authorities of
control, have tended to apply these proven techniques for evaluation of
operational risks. This could partly explain the presence in the approach
AMA criteria comparable to those of the IRB approach used for risks of

8 Bank Management Course - Professional License in Banking - Finance


credit. More fundamentally, the application of statistical modeling methods
the evaluation of operational risks has been the subject of severe criticism,
notably in the academic world. Thus it has been argued that certain
characteristics of operational loss data (atypical distributions of
amounts of extreme losses, irregular loss events, frequency and severity
non-stationary losses, existence or not of repetitive losses) were not
consistent with the modeling postulates. This first objection would be added to
that of a certain lack of data, and especially of consistent data. Finally
many are those who highlight the difficulties in modeling frequency events
low and high impact: three types of models are recommended within the framework of
the AMA approach (Internal Measurement Approach (IMA) method, Loss method
Distribution Approach (LDA), Scorecard method). Some consider that the IMA has been
designed as a simplified, practical and standardized version of an approach
actuarial of type LDA, more complete and more satisfactory, but more complicated to
implement4It would be under the pressure of certain banks, particularly Anglo-
Saxons, from the IIF5that the Scorecard method would have been integrated into the Basel II framework.
It is because of these criticisms that other methods have developed.
dynamics aimed at managing operational risks through more comprehensive control of
processes in which these risks are potentially present. This involves a
simulation of the functioning of the entire chain of processes, based both on
real scenarios and a virtual reality, theoretically allowing to anticipate all the
elements relating to a specific process, but also all the implications and
interrelations. This scenario method is increasingly used (¾ of banks)
surveyed in the PRMIA survey62006 against 50% in the same 2005 survey): it
assume that the operational risks associated with a process cannot be
evaluated separately from the organization in which this process operates; it is in
the interaction of a process with its environment where the key elements are located
d’appréciaton des risques opératonnels. Pour bien identfier les corrélatons entre les
processes and loss events, the difficulty is to properly isolate these processes.
of each other in order to properly assess their contribution to a loss in
particular. That being said, this method still has areas of uncertainty,
example the choice of the underlying assumptions for the major scenarios (assumptions of
place), the evaluation of certain extreme scenarios (avian influenza, for example), or
still the treatments regarding insurance.
Follow-up
Monitoring operational risks through appropriate indicators (indicators
alert, proven risk indicators and loss indicators) is the third process-
key of a management system for this category of risks. At this stage, the issue arises
problem of the consolidation of indicators, which can be addressed through two
approaches: bottom-up or top-down. In the bottom-up approach, the key indicators
Operational risks are defined and measured at lower levels, where
The individual assessment of managers will exert maximum leverage on monitoring.
operational risks, to be gradually consolidated to a level

9 Bank Management Course – Professional License in Banking - Finance


central. In the top-down approach, it is based on the overall strategic vision,
the overall profitability of operations that the allocation of regulatory capital to
Different activities will be decided by the executive bodies based on their risks.
operational. In this context, the decisions made at the higher levels of the
Hierarchy will be reflected and translated into action plans monitored and controlled by the
managers using appropriate indicators.
Mastery and attenuation
The mastery and attenuation of risk probably constitute the subprocess
more complex than this set, as it will depend on the bank's ability to
to equip with means of preventing risks by identifying the appropriate levers of action for
anticipate certain events or minimize their impact in case of occurrence. This sub-
the process is particularly complex to manage because it relies simultaneously on two
functions that interact with each other:

On one hand, the function that leads to setting the maximum risk level.
operational accepted. This implies setting limits, global limits or limits
by type of operational risk. But this mainly requires an evaluation
comparison of expected profitability in relation to the risks taken: this
Evaluation is often complex to implement when it comes to risks.
operational risks with high potential impact or difficult operational risks to
human risks7, for example) and to quantify because it will depend on choices
operated in the second function regarding the coverage of these risks
operational
On the other hand, the function that leads to making a choice between the different modes
of coverage (internal, external through insurance or outsourcing), and to translate it
in action plans specifying the chosen measures, the responsibilities in the implementation
in place and the deadlines for implementation. This is how the PCAs (continuity plans) are
activities) should logically be integrated into this subprocess; however, one
It is noted in practice that few banks have consolidated risk management.
operational and that of the PCA within the same entity; despite this, a
Coordination is beginning to be established between these two approaches.

1.2.2- Relatively standardized functionalities.


The two main application features to implement to master a
The operational risk management system is, on one hand, the determination of the profile.
operational risks of the bank, on the other hand the implementation of a device for
collected risk events.

10 Bank Management Course - Professional License in Banking - Finance


The determination of the operational risk profile of a bank corresponds
to the identification, at each level of its organization, of processes supporting
operational risks, to the formulation of these risks and their rating (probability
Occurrence and loss): it is the phase of mapping operational risks.
This phase is a key step as it will lead to determining, with more or less
of sensitivity, what is the nature of the incidents that will be collected and therefore monitored
subsequently. It is also the one that will allow to define a nomenclature of
operational risks valid for the entire organization, essential framework
to an effective and homogeneous collection of incidents. The risk mapping is
thus the formalization of the work of identifying operational risks. This
the exercise theoretically integrates the following phases: decomposition into activities
processes supporting operational risks; for each activity,
assessment of associated risks, for each risk, evaluation of losses and
probabilities of occurrence; constitution of a risk matrix on the axes
frequency and importance of losses; finally, selection, based on the matrix, of
significant risks (those that the bank decides to collect in the device of
collection).

To legitimize the use of standard or advanced methods, the bank must


concurrently having equipped itself in advance with a collection device of
incidents accessible by all its entities, and a dedicated database for
store incidents, with a view to having a loss history in accordance with
regulator requirements. Control and validation procedures for incidents
noted in the database generally rely on workflows, tools that
allowing managers to visualize the source of incidents, to control the
relevance of information reported by the database and to be alerted in real time
events that occurred in their service, to quickly implement
of theacton correcttvesFurthermore, analysis tools (of the datamining type) and

Restitutions can be implemented in order to complete the precise definition of


operational risk profile of the bank.
That being said, to ensure coverage of their operational risks, banks do
usually refers to allocation models, the two most commonly used approaches
being the bottom-up approach and the top-down approach, or even a combination of both
two. The principle of the bottom-up approach is to calculate the capital requirement
regulatory at the finest level, for example at the level of a category of operations,
and then consolidate these needs at increasingly centralized levels until
the entire meter line to which the corresponding equity will be allocated.

11 Bank Management Course - Professional License in Banking - Finance


On the contrary, the principle of the top-down approach consists of disaggregating information.
measured across all operational risks of the bank and then allocate them
equity at increasingly decentralized levels.

3-Complexity of implementation issues

Despite the simplicity of these two issues (processing model and functionalities)
of application), it turns out that, in practice, the implementation of the different
approaches has raised and still raises many disagreements whose complexity
it has gradually emerged on the occasion of numerous investigation missions conducted
both in France by the Banking Commission and abroad by the authorities or
competent organisms.

Complexity related to the very nature of operational risks: unlike


to other categories of risks (credit risks, market risks), the risks
operational concerns relate across all activities and all
banking sectors; while the available data for other categories
of risks are relatively standardized and commonly accepted, those that
operational risks depend on each bank taken
separately. It is likely for this reason that the mapping of
risks are very variable (number of risk events between 100 and more
de 20008), each bank having its own vision of the right balance between
granularity and relevance of the risk events considered. Finally, the substance
even operational risks are extremely volatile since, ideally, a
a large part of them could be reduced to nothing as soon as their
Identification should lead to eliminating the cause.
Complexity related to the governance of the system: if the involvement of the bodies
executives of banking groups in the implementation of the management system
operational risk within the sectors seems active, however, few are those
who have formal documentation outlining the principles and methods of
implementation of the policy regarding operational risks, as it has
was stopped by these executive bodies. However, these seem to have done well
understood the necessity of supporting the operational risk management function on
risk managers present within the different sectors
functions, that is to say those who are close to the risks on the ground and have a
in-depth knowledge of activities. This is how the majority of banks
those who responded to the PRMIA 2006 survey indicate that they have implemented a system of

12 Bank Management Course - Professional Bachelor's Degree in Banking - Finance


operational risk management, essentially covering databases
incidents, risk mapping, scenario implementation, and calculation
alert indicators.
Moreover, the allocation of equity other than solely for operational risks.
rare dwelling. Major banking groups having primarily opted for a
AMA approach considering a capitalization calculation for the entire group
bank and an allocation of the latter to the different entities according to a key
Allocation is a process like the one described below. Rare are the groups that
considering calculating requirements at the level of one or more of their subsidiaries,
although the principles laid down by the Basel Committee regarding recognition
Cross-border of an AMA approach imposes such a calculation for significant subsidiaries
of a group.

Complexity related to organizational choices. According to a survey conducted in


France8if all the banks surveyed, even medium-sized ones, have adopted
une foncton dédiée à la geston des risques opératonnels, il semble que deux types
of the organization currently prevalent: either – and this is by far the most common case
frequent – this function, most often organized in a hierarchical manner since
the meter lines or the geographical implantations up to a position
centralized, is integrated into a Risk Management Department, or it is coupled with another
function (management control, internal audit, for example). In either case,
We observe practical difficulties in delimiting the boundary between internal audit
of the quality of the operational risk management device and the functions of
management and control of these same risks.
Complexity related to data exploitation: if we take as a reference
the AMA approach that invites banks to use four types of data (data
internal loss data, external loss data, scenario analyses
of potential events and analyses of environmental and control factors
internally), it is observed that some banks have developed a model
essentially static calculation of regulatory own funds, in
based on data from internal and external losses, and using
Value at Risk (VaR) models, with a one-year horizon and interval of
99.9% confidence).
The use of internal historical data generally falls under a type of approach
top-down, where operational risks are first identified and measured on a basis
consolidated from their potential losses, and where the equity is then
allocated to the different meter lines. The growing awareness of this
The statistical modeling of operational risks faced challenges for a time.

13 Bank Management Course - Professional License in Banking - Finance


the insufficiency of internal data histories and practical issues, in
particulars related to the level at which all losses must be collected and how
This one must be captured in order to ensure a correct retrieval of data.
sought (automatic or declarative collection) and a credible distribution of
losses. However, significant progress has been made in this area,
notamment en raison de règles de collecte et de mesure qui s ’harmonisent
progressively between banks, and also due to the fact that the use of external data has
was facilitated by the maturity of the consortial bases (ORX9becoming the reference). Hence
a certain mistrust regarding the sole use of this historical data which
justify the use of external data.
The use of external data also raises questions about the
necessary correction of statistical bias and the adaptation of external data to the
internal situation of the bank (scaling issues).
Other banks build their measurement model by giving more priority to
prospective data, in the form of scenario analyses and/or risk indicators. In
In this case, the approach is intended to be bottom-up, with risks being mapped at the level of
each line of meter based on causes, then measured based on frequencies and
Estimated loss severities by experts of each meter and/or indicators of
performance, control, and risk. Although scenario analyses are
considered an important element in the dissemination of a risk culture
operational, due to the fact that they rely on the expertise of managers within the
meters, they generally require serious precautions before being fully
operational: indeed, these analyses must be sufficiently structured and
coherent so that the subjective quantifications of operational risks at the level
meters can properly feed the capital calculation model
consolidated level. Also, some banks reserve this type of analysis for only
low probability and high loss events.
Other banks use or are moving towards a scorecard method (indicators)
of risk or performance, based in part on the use of qualitative criteria
allowing in particular to carry out allocations of regulatory equity funds
between meter lines or between geographic implants depending on their
ability to manage operational risks. Besides its more synthetic aspect, this
method brings a double advantage: it first introduces a dimension
prospective that is part of an active risk prevention management
operational; it then facilitates reporting to the executive bodies by providing, to
means of local performance dashboards, a progress report compared to
the strategy defined by these bodies to ensure the management of operational risks.
In practice, the identification of risk indicators is carried out based on risks.
identified during the mapping and in relation to existing indicators (indicators
of quality, of performance...). Key risk indicators are then selected
(KRI10susceptible to facilitating decision-making. Among the difficulties encountered in
the implementation of this method notably includes the interpretation that should be
give to the indicators (for example those related to human resources), the definition of
14 Bank Management Course - Professional License in Banking - Finance
alert levels consistent with the general risk management policy
operational as well as the modalities for aggregating the indicators.
According to the regulator himself, banks [are willing] to adopt an approach
more pragmatic in terms of operational risk by reallocating the device towards the
risk management rather than just their measurement. The use of data
prospects assume taking into account the changes that have occurred or are to come in
the management of operational risks and/or in the activities of establishments and therefore
a strong involvement of risk managers at the level of the meters. But if
The use of qualitative factors in the form of scorecards benefits from a certain
experience, in particular for the allocation of equity among the different
The quantitative translation of these factors remains problematic.
and does not truly appear to be stabilized. This quantitative translation is all the more
more delicate when scenario analyses and expert assessments do not
do not fit into a well-structured and homogeneous approach within the group. It
It is therefore all the more necessary for institutions to develop questionnaires.
briefs addressed to experts in the fields as well as relevant risk indicators
observables on a regular basis, likely to limit the subjective nature even
sometimes politics of the quantification process11.
Finally, the implementation of an effective risk measurement and management device
operational, regardless of the methods of data analysis, requires
an adequate information system. This is probably one of the areas where the
banks still have significant progress to make, which is probably not
strange that the direction of information systems is not often
represented within banks in the operational risk management committees.
The adaptation of information systems to the specific requirements of processing
Operational risks have led banks to choose between the launch
of a completely new project or the realization of extensions intended to collect
the necessary data. In the first case, it was about implementing a
entirely new procedure for systematic collection of losses and, for this purpose,
conduct awareness missions at all levels of the bank. In the
In the second case, it was rather about taking back and reprocessing at the level of the meters of
existing loss histories.
In such a complex environment, it is clear that the definition of the true profile
of the risk of a large banking group and the establishment of an effective policy for
Reduction of operational losses in each entity is part of a global project.
requiring a large-scale deployment, and therefore, a real management of
change.
The challenges of managing change associated with Basel II mainly concern the
diffusion of a new culture of vigilance regarding operational risks, and the
perpetuation of this system.
The first challenge is to disseminate a culture of vigilance regarding these risks.
in each business unit of the bank. To this, we can speak of true

15 Bank Management Course - Professional Bachelor in Banking - Finance


the acculturation of employees is present in all modalities of implementation
(mapping of operational risks, incident collection device), the main
The attribute of this issue is the involvement of each bank employee.
The second challenge is to prevent the operational risk management system from
become fixed, and therefore to ensure that it can evolve under the effect of theacton
correcttvesof risks that disappear, and new risks that appear.
Overall, the issue of the regulatory processing of operational risks is not
to obtain a supervisor certification so that the bank can use such or
The approach proposed by the regulator is to promote a sustainable improvement.
the management of operational risks by the bank, by holding each of
stakeholders (regulator, supervisor, bank collaborator). This is precisely where
the device acquires an additional degree of complexity since in the end, the
The success of the implementation of the system depends not only on the good
practices of the bank but also the flexibility of the prudential supervision exercised
by the supervisor and the adaptability introduced into the system by the regulator.

16 Bank Management Course - Professional License in Banking - Finance

You might also like