0% found this document useful (0 votes)
70 views44 pages

Managing Operational Risk Workshop

The workshop covered operational risk management. Operational risk was defined as the risk of loss resulting from inadequate or failed internal processes, people and systems, or from external events. Key topics included Basel II requirements for operational risk, defining and understanding operational risk through frameworks and tools like the risk event database, risk and control self-assessments, key risk indicators, and governance structures for managing operational risk. Case studies on operational losses from various banks were also presented.

Uploaded by

harisaman
Copyright
© Attribution Non-Commercial (BY-NC)
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
70 views44 pages

Managing Operational Risk Workshop

The workshop covered operational risk management. Operational risk was defined as the risk of loss resulting from inadequate or failed internal processes, people and systems, or from external events. Key topics included Basel II requirements for operational risk, defining and understanding operational risk through frameworks and tools like the risk event database, risk and control self-assessments, key risk indicators, and governance structures for managing operational risk. Case studies on operational losses from various banks were also presented.

Uploaded by

harisaman
Copyright
© Attribution Non-Commercial (BY-NC)
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPT, PDF, TXT or read online on Scribd

WORKSHOP ON MANAGING OPERATIONAL RISK

Javed Ahmed Risk Manager Meezan Bank Ltd.

Operational Risk
Operational risk is the Risk of loss resulting from inadequate or failed internal processes, people and systems or from external events.
includes legal risk, but excludes strategic and reputational risk

Definition of Operational Risk


Potential or Forward looking Causal Categories: Employee Behaviour Corporate Behaviour Information Technology Force Majeure

The risk of loss

resulting from any inadequate or failed

internal processes or from external events

People and systems in the regulatory definition are captured in internal process

External Fraud, Fire, Flood, Legal action, Tax, Regulations, False money, Terrorism

Inadequate collateral management Failed matching of cash & securities Missed timelines Unenforceable documentation Internal fraud

Why Operational Risk Included

Why Operational Risk Included


Citigroup US$70M fine for failing to comply with federal lending regulations. First National Bank of Keystone US$691M embezzlement & loan fraud by senior managers Bank of America US$490M lawsuit settled for failure to adequately 3rd party relationships at the time of merger with Nations Bank Legal settlements by several firms for unfair business practices.

Providian US$300M, FirstUSA US$40M, Advanta US$7.2M, Sears US$36M.


CIBC paid US$25M penalty to SEC and USD100MM restitution to customers for rapid trading and market timing of hedge funds August 05 Arab Bank New York Branch USD24MM penalty for failing to properly implement anti-money laundering controls. August 05 CIBC - USD2.4B settlement with University of California for lost investments. Two CIBC executives have also paid personal fines for their role in the fraud. August 05 Merrill Lynch - $37MM settlement with stockbrokers not paid proper overtime.

SBP Penalty Fraud, Forgery and Dacoity Cases

No. of Cases: No. of Outstanding Cases: Amount involved in outstanding cases: Amount outstanding:

62 (2006-09) 23 Rs. 163 million Rs. 84 million

Nature of Cases

Issuance of cheque book on forged requisition slip Fraudulent withdrawal/ Forged cheque Mis-appropriation of security deposit Pocketing of deposits Opening of fake account and transfer of money Fraudulent withdrawals through internet banking/ ATM Fake property documents Issuance of Fake deposit slip Dacoity

Basel II Evolution of Ops Risk


Basel II
Three Pillars

Minimum Capital Requirements

Supervisory Review

Market Discipline

Providing a flexible, risk-sensitive capital management framework

Basel II Evolution of Ops Risk


Minimum Capital Requirement
Risk-weighted Exposures

Market Risk
Risk of losses in on and off balance sheet positions arising from movements in market prices

Credit Risk
Potential that a bank borrower or counterparty will fail to meet its obligations in accordance with agreed terms

Operational Risk
Risk of direct or indirect loss resulting from inadequate or failed internal processes, people and systems or external events

No Change

Major Changes

New element added

Defining & Understanding Operational Risk

Defining & Understanding Operational Risk

Defining & Understanding Operational Risk

Incident Definition
An actual event resulting from inadequate or failed internal processes or from external events which has, could, or could have, led to a loss, a gain, or an opportunity cost

Cause

Event

Effect

Risk Drivers and Indicators


Drivers Transaction Volume Staff Turnover Market Volatility Training hours vs. plan Product complexity Indicators Transaction errors Aged confirmations Reconciliation Audit points outstanding Settlement fails Operational loss

Operational Risk Loss Event Types


Risk categorization scheme divides operational risk into seven major risk types and twenty sub risk types.
Operational Risk

Internal Fraud

External Fraud

Employment Claims

Clients & Third Party Claims

Damage to Physical Assets

Business disruption and system failures

Transaction Processing Errors / Omissions

Unauthorized Activity

Theft and Fraud

Employee Relations

Suitability, Disclosure & Fiduciary

Disasters & Other Events

Systems

Transaction Capture, Execution & Maintenance

Theft and Fraud

System Security

Safe Environment

Improper Business or Market Practices

Monitoring & Reporting

Diversity & Discrimination

Product Flaws

Customer Intake & Documentation

Selection, Sponsorship & Exposure

Customer / Client Account Management

Advisory Activities

Trade Counterparties

Vendor & Suppliers

Basel II - Loss Event Types Definitions


Level 1 Categories Internal Fraud Definition Losses due to acts of a type intended to defraud, misappropriate property or circumvent regulations, the law or company policy, excluding diversity/ discrimination events, which involves at least one internal party

External fraud

Losses due to acts of a type intended to defraud, misappropriate property or circumvent the law, by a third party Employment Practices and Losses arising from acts inconsistent with employment, health or safety Workplace Safety laws or agreements, from payment of personal injury claims, or from diversity / discrimination events Clients, Products & Business Losses arising from an unintentional or negligent failure to meet a Practices professional obligation to specific clients (including fiduciary and suitability requirements), or from the nature or design of a product. Damage to Physical Assets Losses arising from loss or damage to physical assets from natural disaster or other events. Business disruption and Losses arising from disruption of business or system failures system failures Execution, Delivery & Process Losses from failed transaction processing or process management, from Management relations with trade counterparties and vendors

Incident Types

Incidents Causes Types


Individual Behaviour Organisational & Corporate Behaviour Information Technology External Banking Environment Non Banking External Environment

Loss Gain Opportunity Cost Near Miss (Undetermined)

Categories of Event Types


Internal fraud External Fraud Employment Practices & Workplace Safety Clients, Products & Business Practices Business Disruption & Systems Failures

Effects Types
Regulatory & Compliance Legal Liability Loss/Damage to Assets Restitution

Execution, Delivery & Process Management


Damage to Physical assets

Loss of Recourse
Write- Off

Managing Operational Risk


Risks can not be mitigated 100%, but they can be managed within appropriate tolerance levels Identification, measurement, monitoring and controlling

Operational Risk Management Principles


Disclosure
10 Public disclosure of risk exposure & quality of management 9 Regular evaluation of strategies policies, procedures & practices

Role of Supervisors
8

Ensure Banks have effective framework in place

Risk Management: Identification, measurement, monitoring and control

7 6 5 4

Contingency and Business Continuity Plans.

Policies, Processes and Procedures to mitigate Risks

Monitor Risk Profiles and Losses KRIs

Identify & Assess Risks in Products, activities, Processes systems by RCSA. and KRIs etc

Developing an Appropriate Risk Management Environment

Framework subject to effective and comprehensive internal audit. Board sets strategy and framework plus oversight

Senior Management responsible for implementing the Framework

Governance Structure
Governance models and reporting lines vary given below is the most common risk governance structure
BOD/ Board Risk Committee
Operational Risk Management Committee Head of Risk Management Risk Management Department
Depends on size of the organization (all risks vs. specific risks) Mandate defines membership / authorities / responsibilities

Market Risk

Operational Risk

Credit Risk

Risk Manager

Risk Manager

Unit Risk Managers

Ultimate responsibility for all risks lies with business units Risk managers provide tools and guidance in managing risks

Framework Overview
Credit Risk

Operational Risk

Market Risk

Governance Independent Assurance Business Strategy


Risk Mgmt. Committees Policy & Guidelines Risk Universe Categorisation Scheme

Tools
Risk & Control Self Assessments key Risk & Control Indicators

Internal Loss Data

External Loss Data / Scenario Analysis

Reporting
Modelling

Operational Risk Framework Components

Operational Risk

Operational Loss Data

Key Risk Indicators

Risk & Control SelfAssessments

Internal Fraud

External Fraud

Employee Claims

Client & Third Party Claims

Damage to Physical Assets

Business Disruption & System Failures

Transaction Processing Errors/ Omissions

Assessing Operational Risk Exposure


Process of Continuous Risk Assessment, Monitoring and Reporting
Reporting

Risk Identification

Mitigation Planning & Execution

Control Assessment

Measuring/ Monitoring

Likelihood and Severity

Operational Risk Management Tools


Control and Risk Self Assessment Key Risk Drivers and Indicators Loss Data Issue and Event Data Audit and Compliance Reports Scenario Analysis

Self Assessment Methodology


There are three main parts to risk & control self assessment (self assessment), namely

risk identification, risk assessment and control evaluation.

Risk & Control Self Assessment


Define Objectives Identification of risks that could inherently impact achievement of objectives, Impact (Low to Very High) Likelihood (Unlikely to Frequent)

Identification of Controls mitigating risks


Design Performance

Assess residual risk (Inherent Controls = Residual)


Develop action plans

Risk & Control Self Assessment


Objectives Level of granularity Generic or specific or a combination of both Risks Open discussion on risks Cultural issues Bosss view is the right view Controls Key Controls VS Controls Control weighting Design VS Performance Inherent Risk Difficult concept to digest but critical Impact / Likelihood estimation still subjective Developing Grids Granularity and Scale Residual Risk How much risk is mitigated by controls Impact / Likelihood estimation Developing Grids Granularity and Scale

Risk assessment
A typical risk profile

Key Risk Indicators (KRI) Definition


Early warning signals an increased risk of a future loss. These are meaningful drivers of risk that are translatable into quantitative measures.

Metrics that provide indication as to the current level of exposure which a firm faces, .. its performance over a recent timeframe or the effectiveness of its control environment. KRIs are often grouped into risk, performance and control effectiveness indicators and provide real-time measure as to the current status of the risk profile
Risk Business Risk Management Association

Parameters which can act as indicators and which can be seen to be predictive regarding of a business changes in risk profile
LLOYDS INSURANCE

Why KRIs Are Important?


Indicators are not easy to do however, running a business without indicators is the same as driving a motor vehicle on a long journey without a fuel gauge, a speedometer or engine/oil temperature gauges you simply would not contemplate in doing so.

KRIs identify areas of greater concern or exposure to the firm and are a means of provide management focus where it is needed most.

Why are they important?


Risk management the ability of KRIs to predict potential risk hotspots can help a franchisee avoid or minimise losses; KRIs help identify process and/or control weaknesses and thus enable action to be taken to strengthen controls and resolve issues; and

targets for KRIs can be set to drive behaviour and desired outcomes for the entity.
Regulatory compliance identification and management of KRIs is an area of regulatory focus; and

KRI Identification Sources & Methods


Historical Loss Events Risk and Control SelfAssessment Internal & External Audit Findings Regulatory Inspection Findings Business Intelligence

Losses

Near Misses
Claims

Process Mapping
Risk and Control Identification Control Effectiveness Testing

Audit Reports Outstanding Audit Issues

Market Driven Risks Short Approach Regulatory Requirements

KRI - Identification
You are the Pilot of your business unit you are monitoring all the indicators required to have a safe flight 1) List down top 5-10 risks your department manages on a daily/weekly/monthly basis

2) List down ALL reports produced as a summary of daily/ weekly/ monthly activity for the reviewer
3) List down ALL reports produced as a summary of activities for management reporting
Management Reporting

Maker

Checker

Reviewer

Sr. No.

DESCRIPTION OF KRI ALTERNATE DISTRIBUTION CHANNELS Physical damage to ATM per year Discontinuity of operation per day (ATM, Call Centre, Internet Banking) Number of f rauds on ADC per month Number of incomplete processing of transactions per day COMMERCIAL & SME Number of exceptions of SBP guidelines per month Number of non-compliance of internal guidelines Number of NPL accounts per year Number of policy / guidelines exception cases w hich subsequently lead to def ault Number of cases rejected : total cases approved Number of cases w here f inancials and/or risk rating is unavailable Number of overdue / classif ied accounts to Total accounts Number of new customers made in a month to total customers Number of approvals made beyond delegation matrix COMPLIANCE Number of circulars issued by SBP w hich w ere not circulated internally per month: - Deadline/Compliance based Circulars - Non-Deadline/Inf ormation based Circulars

MEASUREMENT

1 2 3 4

1 2 3 4 5 6 7 8 9

Number of circulars issued by SBP circulated to w rong departments per month: - Deadline/Compliance based Circlulars - Non-Deadline/Inf ormation based Circulars

3 4 5 6

Number of late / w rong/ incorrect submission of returns to SBP per month Number of suspicious/ AML transactions in the month Number of anti-money laundering transactions not monitored by Compliance but subsequently detected per quarter Number of polices not review ed/ revised during last three years

S. No.

Description of Risks OPERATIONS

Measurem ent

1 2 3 4 5 6 7 8 9 10 11 12

Excess cash maintained at branch Any basic document required by SOP/PR to open new account still pending Duly f illed KYC questionnaire is not available Account opening f orms are not properly maintained in chronological order Transactions are allow ed in the account prior to Letter of Thanks delivery verif ication Closed account opening f orm and specimen signature card do not contain Account Closed Stamp Closed accounts not yet marked as Closed in IB Closed accounts not yet entered in Account Opening Register Stop payment instructions either not entered in Stop Payment Register or duly signed request not available Any Inoperative account f alling w ithin the criteria of Dormant Account not yet marked as dormant at the month-end processes ATM - Cash could not be w ithdraw n by customer but account w as debited Head Of f ice/Branch reconciliation beyond 30 days TRADE FINANCE 1 Charges due but not obtained 2 Unauthorized transaction 3 Fake/f orged documents w ithout f ollow ing UCP 4 Loss of important / critical documents 5 SBP penalty imposed on account of Trade Finance matters 6 Unauthorized payments / remittances 7 Release of shipping documents prior to payment (Sight) or acceptance (Usance) 8 LC opened w ithout supporting documents While docs are lying under PAD against sight Letter of Credit goods are damaged/ 9 stolen/ perished at port In case of usance Letter of Credit documents w ere delivered w ithout obtaining draf t or 10 TR f orm Documents w ere not properly scrutinized if draw n under UCP currently in f orce, SBP 11 Manual and MBL Policies In case of Documents draw n under DP /CAD/ DA basis the bill of lading w as not in f avor 12 of MBL 13 Scrutiny sheet in respect of discrepancies is not available

Sr. No.

DESCRIPTION OF KRI CORPORATE FINANCE Number of cases w here annual review w as not performed Number of NPL accounts per year Number of exceptions of SBP regulations / guidelines Number of policy / guidelines exception cases w hich subsequently lead to default Number of cases rejected : total cases approved Number of cases renew ed after expiry per month Number of cases w here financials and/or risk rating is unavailable Number of overdue / classified accounts to Total accounts Number of total cases processed to cases received in a month Number of new customers made in a month to total customers Breaches in delegation of authority limits Customer calls due but not conducted in a month HUMAN RESOURCES

MEASUREMENT

1 2 3 4 5 6 7 8 9 10 11 12

1 2 3 4 5 6 7 8

No. of employees w ho did not avail mandatory leaves in a year Number of employee leaving w ithin 1 year service w it the Bank Number of employees terminated in a quarter Employee absenteeism rate in the month Number of employees w hose Job description w ere not available Number of cases w here antecedent of new joiners not obtained Number of vacant positions Percentage of staff appraisal below satisfactory

Loss Data

Pinpoints actual areas of control failures Highlights cost of operational risk Losses should be assigned to the business areas where they originated Data required for modelling Operational Risk Capital requirement. Both internal and external loss data can be utilised

Internal Loss Data


Apply

a minimum reporting threshold E.g. Losses > Rs. 5000 Make sure you record at least the 4 Ws (What, when, where, why) Allocate losses to correct business line and risk category. Ensure that you can revise the individual losses to record recoveries Include all losses !

Regulatory Framework
Regulatory Business Lines Operational Risk Categories IF EF EPWS CPBP DPA BDSF EDPM

Corporate Finance

Trading & Sales


Retail Banking Commercial Banking Retail Brokerage Asset Management Agency Services Payment & Settlement

Scenario Analysis
Apply

some formal real world what if analysis to your processes Highlight control weakness before it results in losses Stress test identified points of failure to test resilience Test again to ensure mitigation is working

Roles & responsibilities


Control owner roles and responsibilities ensuring effective and efficient control design to manage the impact and likelihood of the risk
effective performance of control activities as designed identifying and assessing the appropriateness and effectiveness of controls

sourcing and collating relevant data concerning the performance of controls

analysis of this data conversion into indicative information creating and implementing corrective action driven by the risk information

Roles & responsibilities


Risk owner roles and responsibilities
to identify, regularly maintain and communicate up to date risk information ongoing monitoring of risks for changes in their impact or likelihood reporting information to the appropriate individuals / forums / committees; ensuring effective implementation of risk management action plans. identifying and assessing the appropriateness and effectiveness of controls

creating and implementing appropriate action driven by the information;

sourcing, collating and analysing relevant data indicating movements in impact and likelihood of risk;

Governance - Risk Categorization


Basel II & Industry
Event Categories
Internal Fraud
People Risk External Fraud Employment Practices & Workplace Safety Clients, Products & Business Practices Damage to Physical Assets Technology Risk

Organization could develop its own or adopt what is available need to

Causal Categories

map
Challenges Neither categorization works ideally for all tools in operational risk framework Event categories good for loss data, scenarios & risk measurement - causal categories good for RCSA and KRIs Using different categories for different tools could make aggregation of results difficult
Benefits Provides a common risk language within the organization Facilitates participation in industry data consortiums Facilitates regulatory reporting Consistent use across risk tools will facilitate data aggregation

Process Risk

Business Disruption & System Failures


Execution, Delivery & Process Management External Events Risk

Problems and Practicalities


Risk

based culture and continued management support. Business Line Buy-in and Resources. Coordination with Existing Control Initiatives KRIs focussed on performance. Loss data collection. External loss data availability. Real world scenario analysis. Access to Appropriate Information and Reporting. System Support.

Thank You

Q &A

WORKSHOP 
                              ON 
    MANAGING OPERATIONAL RISK  
 
Javed Ahmed 
Risk Manager
Operational Risk   
 
 
 
Operational risk is the “Risk of loss 
resulting from inadequate or failed 
internal processes, p
Definition of Operational Risk 
 
 
  The   risk  of loss      resulting from any inadequate or failed 
 
   internal process
Why Operational Risk Included
Why Operational Risk Included 
Citigroup – US$70M fine for failing to comply with federal lending 
regulations.  
First Nat
SBP Penalty 
Fraud, Forgery and Dacoity Cases 

No. of Cases:   
 
 
62 (2006-09) 

No. of Outstanding Cases:  
 
23 

Amo
Supervisory 
Review 
Market 
Discipline 
Providing a flexible, risk-sensitive capital management 
framework 
Minimum 
Capital
Minimum 
Capital 
Requirement 
Risk-weighted 
Exposures 
Market Risk 
No Change  
Major 
Changes  
New element 
added 
Risk o
Defining & Understanding Operational 
Risk
Defining & Understanding Operational 
Risk

You might also like