WORKSHOP ON MANAGING OPERATIONAL RISK
Javed Ahmed Risk Manager Meezan Bank Ltd.
Operational Risk
Operational risk is the Risk of loss resulting from inadequate or failed internal processes, people and systems or from external events.
includes legal risk, but excludes strategic and reputational risk
Definition of Operational Risk
Potential or Forward looking Causal Categories: Employee Behaviour Corporate Behaviour Information Technology Force Majeure
The risk of loss
resulting from any inadequate or failed
internal processes or from external events
People and systems in the regulatory definition are captured in internal process
External Fraud, Fire, Flood, Legal action, Tax, Regulations, False money, Terrorism
Inadequate collateral management Failed matching of cash & securities Missed timelines Unenforceable documentation Internal fraud
Why Operational Risk Included
Why Operational Risk Included
Citigroup US$70M fine for failing to comply with federal lending regulations. First National Bank of Keystone US$691M embezzlement & loan fraud by senior managers Bank of America US$490M lawsuit settled for failure to adequately 3rd party relationships at the time of merger with Nations Bank Legal settlements by several firms for unfair business practices.
Providian US$300M, FirstUSA US$40M, Advanta US$7.2M, Sears US$36M.
CIBC paid US$25M penalty to SEC and USD100MM restitution to customers for rapid trading and market timing of hedge funds August 05 Arab Bank New York Branch USD24MM penalty for failing to properly implement anti-money laundering controls. August 05 CIBC - USD2.4B settlement with University of California for lost investments. Two CIBC executives have also paid personal fines for their role in the fraud. August 05 Merrill Lynch - $37MM settlement with stockbrokers not paid proper overtime.
SBP Penalty Fraud, Forgery and Dacoity Cases
No. of Cases: No. of Outstanding Cases: Amount involved in outstanding cases: Amount outstanding:
62 (2006-09) 23 Rs. 163 million Rs. 84 million
Nature of Cases
Issuance of cheque book on forged requisition slip Fraudulent withdrawal/ Forged cheque Mis-appropriation of security deposit Pocketing of deposits Opening of fake account and transfer of money Fraudulent withdrawals through internet banking/ ATM Fake property documents Issuance of Fake deposit slip Dacoity
Basel II Evolution of Ops Risk
Basel II
Three Pillars
Minimum Capital Requirements
Supervisory Review
Market Discipline
Providing a flexible, risk-sensitive capital management framework
Basel II Evolution of Ops Risk
Minimum Capital Requirement
Risk-weighted Exposures
Market Risk
Risk of losses in on and off balance sheet positions arising from movements in market prices
Credit Risk
Potential that a bank borrower or counterparty will fail to meet its obligations in accordance with agreed terms
Operational Risk
Risk of direct or indirect loss resulting from inadequate or failed internal processes, people and systems or external events
No Change
Major Changes
New element added
Defining & Understanding Operational Risk
Defining & Understanding Operational Risk
Defining & Understanding Operational Risk
Incident Definition
An actual event resulting from inadequate or failed internal processes or from external events which has, could, or could have, led to a loss, a gain, or an opportunity cost
Cause
Event
Effect
Risk Drivers and Indicators
Drivers Transaction Volume Staff Turnover Market Volatility Training hours vs. plan Product complexity Indicators Transaction errors Aged confirmations Reconciliation Audit points outstanding Settlement fails Operational loss
Operational Risk Loss Event Types
Risk categorization scheme divides operational risk into seven major risk types and twenty sub risk types.
Operational Risk
Internal Fraud
External Fraud
Employment Claims
Clients & Third Party Claims
Damage to Physical Assets
Business disruption and system failures
Transaction Processing Errors / Omissions
Unauthorized Activity
Theft and Fraud
Employee Relations
Suitability, Disclosure & Fiduciary
Disasters & Other Events
Systems
Transaction Capture, Execution & Maintenance
Theft and Fraud
System Security
Safe Environment
Improper Business or Market Practices
Monitoring & Reporting
Diversity & Discrimination
Product Flaws
Customer Intake & Documentation
Selection, Sponsorship & Exposure
Customer / Client Account Management
Advisory Activities
Trade Counterparties
Vendor & Suppliers
Basel II - Loss Event Types Definitions
Level 1 Categories Internal Fraud Definition Losses due to acts of a type intended to defraud, misappropriate property or circumvent regulations, the law or company policy, excluding diversity/ discrimination events, which involves at least one internal party
External fraud
Losses due to acts of a type intended to defraud, misappropriate property or circumvent the law, by a third party Employment Practices and Losses arising from acts inconsistent with employment, health or safety Workplace Safety laws or agreements, from payment of personal injury claims, or from diversity / discrimination events Clients, Products & Business Losses arising from an unintentional or negligent failure to meet a Practices professional obligation to specific clients (including fiduciary and suitability requirements), or from the nature or design of a product. Damage to Physical Assets Losses arising from loss or damage to physical assets from natural disaster or other events. Business disruption and Losses arising from disruption of business or system failures system failures Execution, Delivery & Process Losses from failed transaction processing or process management, from Management relations with trade counterparties and vendors
Incident Types
Incidents Causes Types
Individual Behaviour Organisational & Corporate Behaviour Information Technology External Banking Environment Non Banking External Environment
Loss Gain Opportunity Cost Near Miss (Undetermined)
Categories of Event Types
Internal fraud External Fraud Employment Practices & Workplace Safety Clients, Products & Business Practices Business Disruption & Systems Failures
Effects Types
Regulatory & Compliance Legal Liability Loss/Damage to Assets Restitution
Execution, Delivery & Process Management
Damage to Physical assets
Loss of Recourse
Write- Off
Managing Operational Risk
Risks can not be mitigated 100%, but they can be managed within appropriate tolerance levels Identification, measurement, monitoring and controlling
Operational Risk Management Principles
Disclosure
10 Public disclosure of risk exposure & quality of management 9 Regular evaluation of strategies policies, procedures & practices
Role of Supervisors
8
Ensure Banks have effective framework in place
Risk Management: Identification, measurement, monitoring and control
7 6 5 4
Contingency and Business Continuity Plans.
Policies, Processes and Procedures to mitigate Risks
Monitor Risk Profiles and Losses KRIs
Identify & Assess Risks in Products, activities, Processes systems by RCSA. and KRIs etc
Developing an Appropriate Risk Management Environment
Framework subject to effective and comprehensive internal audit. Board sets strategy and framework plus oversight
Senior Management responsible for implementing the Framework
Governance Structure
Governance models and reporting lines vary given below is the most common risk governance structure
BOD/ Board Risk Committee
Operational Risk Management Committee Head of Risk Management Risk Management Department
Depends on size of the organization (all risks vs. specific risks) Mandate defines membership / authorities / responsibilities
Market Risk
Operational Risk
Credit Risk
Risk Manager
Risk Manager
Unit Risk Managers
Ultimate responsibility for all risks lies with business units Risk managers provide tools and guidance in managing risks
Framework Overview
Credit Risk
Operational Risk
Market Risk
Governance Independent Assurance Business Strategy
Risk Mgmt. Committees Policy & Guidelines Risk Universe Categorisation Scheme
Tools
Risk & Control Self Assessments key Risk & Control Indicators
Internal Loss Data
External Loss Data / Scenario Analysis
Reporting
Modelling
Operational Risk Framework Components
Operational Risk
Operational Loss Data
Key Risk Indicators
Risk & Control SelfAssessments
Internal Fraud
External Fraud
Employee Claims
Client & Third Party Claims
Damage to Physical Assets
Business Disruption & System Failures
Transaction Processing Errors/ Omissions
Assessing Operational Risk Exposure
Process of Continuous Risk Assessment, Monitoring and Reporting
Reporting
Risk Identification
Mitigation Planning & Execution
Control Assessment
Measuring/ Monitoring
Likelihood and Severity
Operational Risk Management Tools
Control and Risk Self Assessment Key Risk Drivers and Indicators Loss Data Issue and Event Data Audit and Compliance Reports Scenario Analysis
Self Assessment Methodology
There are three main parts to risk & control self assessment (self assessment), namely
risk identification, risk assessment and control evaluation.
Risk & Control Self Assessment
Define Objectives Identification of risks that could inherently impact achievement of objectives, Impact (Low to Very High) Likelihood (Unlikely to Frequent)
Identification of Controls mitigating risks
Design Performance
Assess residual risk (Inherent Controls = Residual)
Develop action plans
Risk & Control Self Assessment
Objectives Level of granularity Generic or specific or a combination of both Risks Open discussion on risks Cultural issues Bosss view is the right view Controls Key Controls VS Controls Control weighting Design VS Performance Inherent Risk Difficult concept to digest but critical Impact / Likelihood estimation still subjective Developing Grids Granularity and Scale Residual Risk How much risk is mitigated by controls Impact / Likelihood estimation Developing Grids Granularity and Scale
Risk assessment
A typical risk profile
Key Risk Indicators (KRI) Definition
Early warning signals an increased risk of a future loss. These are meaningful drivers of risk that are translatable into quantitative measures.
Metrics that provide indication as to the current level of exposure which a firm faces, .. its performance over a recent timeframe or the effectiveness of its control environment. KRIs are often grouped into risk, performance and control effectiveness indicators and provide real-time measure as to the current status of the risk profile
Risk Business Risk Management Association
Parameters which can act as indicators and which can be seen to be predictive regarding of a business changes in risk profile
LLOYDS INSURANCE
Why KRIs Are Important?
Indicators are not easy to do however, running a business without indicators is the same as driving a motor vehicle on a long journey without a fuel gauge, a speedometer or engine/oil temperature gauges you simply would not contemplate in doing so.
KRIs identify areas of greater concern or exposure to the firm and are a means of provide management focus where it is needed most.
Why are they important?
Risk management the ability of KRIs to predict potential risk hotspots can help a franchisee avoid or minimise losses; KRIs help identify process and/or control weaknesses and thus enable action to be taken to strengthen controls and resolve issues; and
targets for KRIs can be set to drive behaviour and desired outcomes for the entity.
Regulatory compliance identification and management of KRIs is an area of regulatory focus; and
KRI Identification Sources & Methods
Historical Loss Events Risk and Control SelfAssessment Internal & External Audit Findings Regulatory Inspection Findings Business Intelligence
Losses
Near Misses
Claims
Process Mapping
Risk and Control Identification Control Effectiveness Testing
Audit Reports Outstanding Audit Issues
Market Driven Risks Short Approach Regulatory Requirements
KRI - Identification
You are the Pilot of your business unit you are monitoring all the indicators required to have a safe flight 1) List down top 5-10 risks your department manages on a daily/weekly/monthly basis
2) List down ALL reports produced as a summary of daily/ weekly/ monthly activity for the reviewer
3) List down ALL reports produced as a summary of activities for management reporting
Management Reporting
Maker
Checker
Reviewer
Sr. No.
DESCRIPTION OF KRI ALTERNATE DISTRIBUTION CHANNELS Physical damage to ATM per year Discontinuity of operation per day (ATM, Call Centre, Internet Banking) Number of f rauds on ADC per month Number of incomplete processing of transactions per day COMMERCIAL & SME Number of exceptions of SBP guidelines per month Number of non-compliance of internal guidelines Number of NPL accounts per year Number of policy / guidelines exception cases w hich subsequently lead to def ault Number of cases rejected : total cases approved Number of cases w here f inancials and/or risk rating is unavailable Number of overdue / classif ied accounts to Total accounts Number of new customers made in a month to total customers Number of approvals made beyond delegation matrix COMPLIANCE Number of circulars issued by SBP w hich w ere not circulated internally per month: - Deadline/Compliance based Circulars - Non-Deadline/Inf ormation based Circulars
MEASUREMENT
1 2 3 4
1 2 3 4 5 6 7 8 9
Number of circulars issued by SBP circulated to w rong departments per month: - Deadline/Compliance based Circlulars - Non-Deadline/Inf ormation based Circulars
3 4 5 6
Number of late / w rong/ incorrect submission of returns to SBP per month Number of suspicious/ AML transactions in the month Number of anti-money laundering transactions not monitored by Compliance but subsequently detected per quarter Number of polices not review ed/ revised during last three years
S. No.
Description of Risks OPERATIONS
Measurem ent
1 2 3 4 5 6 7 8 9 10 11 12
Excess cash maintained at branch Any basic document required by SOP/PR to open new account still pending Duly f illed KYC questionnaire is not available Account opening f orms are not properly maintained in chronological order Transactions are allow ed in the account prior to Letter of Thanks delivery verif ication Closed account opening f orm and specimen signature card do not contain Account Closed Stamp Closed accounts not yet marked as Closed in IB Closed accounts not yet entered in Account Opening Register Stop payment instructions either not entered in Stop Payment Register or duly signed request not available Any Inoperative account f alling w ithin the criteria of Dormant Account not yet marked as dormant at the month-end processes ATM - Cash could not be w ithdraw n by customer but account w as debited Head Of f ice/Branch reconciliation beyond 30 days TRADE FINANCE 1 Charges due but not obtained 2 Unauthorized transaction 3 Fake/f orged documents w ithout f ollow ing UCP 4 Loss of important / critical documents 5 SBP penalty imposed on account of Trade Finance matters 6 Unauthorized payments / remittances 7 Release of shipping documents prior to payment (Sight) or acceptance (Usance) 8 LC opened w ithout supporting documents While docs are lying under PAD against sight Letter of Credit goods are damaged/ 9 stolen/ perished at port In case of usance Letter of Credit documents w ere delivered w ithout obtaining draf t or 10 TR f orm Documents w ere not properly scrutinized if draw n under UCP currently in f orce, SBP 11 Manual and MBL Policies In case of Documents draw n under DP /CAD/ DA basis the bill of lading w as not in f avor 12 of MBL 13 Scrutiny sheet in respect of discrepancies is not available
Sr. No.
DESCRIPTION OF KRI CORPORATE FINANCE Number of cases w here annual review w as not performed Number of NPL accounts per year Number of exceptions of SBP regulations / guidelines Number of policy / guidelines exception cases w hich subsequently lead to default Number of cases rejected : total cases approved Number of cases renew ed after expiry per month Number of cases w here financials and/or risk rating is unavailable Number of overdue / classified accounts to Total accounts Number of total cases processed to cases received in a month Number of new customers made in a month to total customers Breaches in delegation of authority limits Customer calls due but not conducted in a month HUMAN RESOURCES
MEASUREMENT
1 2 3 4 5 6 7 8 9 10 11 12
1 2 3 4 5 6 7 8
No. of employees w ho did not avail mandatory leaves in a year Number of employee leaving w ithin 1 year service w it the Bank Number of employees terminated in a quarter Employee absenteeism rate in the month Number of employees w hose Job description w ere not available Number of cases w here antecedent of new joiners not obtained Number of vacant positions Percentage of staff appraisal below satisfactory
Loss Data
Pinpoints actual areas of control failures Highlights cost of operational risk Losses should be assigned to the business areas where they originated Data required for modelling Operational Risk Capital requirement. Both internal and external loss data can be utilised
Internal Loss Data
Apply
a minimum reporting threshold E.g. Losses > Rs. 5000 Make sure you record at least the 4 Ws (What, when, where, why) Allocate losses to correct business line and risk category. Ensure that you can revise the individual losses to record recoveries Include all losses !
Regulatory Framework
Regulatory Business Lines Operational Risk Categories IF EF EPWS CPBP DPA BDSF EDPM
Corporate Finance
Trading & Sales
Retail Banking Commercial Banking Retail Brokerage Asset Management Agency Services Payment & Settlement
Scenario Analysis
Apply
some formal real world what if analysis to your processes Highlight control weakness before it results in losses Stress test identified points of failure to test resilience Test again to ensure mitigation is working
Roles & responsibilities
Control owner roles and responsibilities ensuring effective and efficient control design to manage the impact and likelihood of the risk
effective performance of control activities as designed identifying and assessing the appropriateness and effectiveness of controls
sourcing and collating relevant data concerning the performance of controls
analysis of this data conversion into indicative information creating and implementing corrective action driven by the risk information
Roles & responsibilities
Risk owner roles and responsibilities
to identify, regularly maintain and communicate up to date risk information ongoing monitoring of risks for changes in their impact or likelihood reporting information to the appropriate individuals / forums / committees; ensuring effective implementation of risk management action plans. identifying and assessing the appropriateness and effectiveness of controls
creating and implementing appropriate action driven by the information;
sourcing, collating and analysing relevant data indicating movements in impact and likelihood of risk;
Governance - Risk Categorization
Basel II & Industry
Event Categories
Internal Fraud
People Risk External Fraud Employment Practices & Workplace Safety Clients, Products & Business Practices Damage to Physical Assets Technology Risk
Organization could develop its own or adopt what is available need to
Causal Categories
map
Challenges Neither categorization works ideally for all tools in operational risk framework Event categories good for loss data, scenarios & risk measurement - causal categories good for RCSA and KRIs Using different categories for different tools could make aggregation of results difficult
Benefits Provides a common risk language within the organization Facilitates participation in industry data consortiums Facilitates regulatory reporting Consistent use across risk tools will facilitate data aggregation
Process Risk
Business Disruption & System Failures
Execution, Delivery & Process Management External Events Risk
Problems and Practicalities
Risk
based culture and continued management support. Business Line Buy-in and Resources. Coordination with Existing Control Initiatives KRIs focussed on performance. Loss data collection. External loss data availability. Real world scenario analysis. Access to Appropriate Information and Reporting. System Support.
Thank You
Q &A