0% found this document useful (0 votes)
21 views135 pages

Operational and Credit Risk Management Guide

The document outlines the definitions and frameworks for Operational Risk and Credit Risk as per the Basel Committee, detailing various event types and management strategies. It emphasizes the importance of a coherent operational risk policy, risk identification, and the roles of key officers in managing risks effectively. Additionally, it discusses the implications of financial crime legislation and the necessity for firms to implement robust risk management practices to mitigate potential operational failures and their consequential effects.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
21 views135 pages

Operational and Credit Risk Management Guide

The document outlines the definitions and frameworks for Operational Risk and Credit Risk as per the Basel Committee, detailing various event types and management strategies. It emphasizes the importance of a coherent operational risk policy, risk identification, and the roles of key officers in managing risks effectively. Additionally, it discusses the implications of financial crime legislation and the necessity for firms to implement robust risk management practices to mitigate potential operational failures and their consequential effects.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Operational Risk and Credit

Risk
• Definitions of Operational Risk according to the Basel Committee on
Banking Supervision, Basel operational risk event types: Internal
Fraud, External Fraud, Employment Practices and Workplace Safety,
Clients, Products, & Business Practice, Damage to Physical Assets,
Business Disruption & Systems Failures, Execution, Delivery &
Process Management, Operational Risk Policy, Operational Risk
Framework: identification, measurement, management and control,
management information, monitoring, escalation, remediation.
Operational Risk Identification, Operational Risk Assessment and
Measurement, Managing Operational Risk.
• Credit Risk: Identification of Credit Risk: understand the key
components of credit risk and how they arise: counterparty risk,
issuer risk, and concentration risk. Credit Risk Measurement:
techniques for measuring credit risk, credit exposure, credit risk
premium, credit ratings. Credit Risk Management: sound practice
features of an effective credit risk management function, reporting
and escalation tools of credit risk management, Basel key stages of
credit risk policy development.
Definition of Operational Risk
• The Bank for International Standards (BIS) defines operational risk as
‘The risk of loss resulting from inadequate or failed internal
processes, people and systems or from external events’.
• This definition covers legal risk (including fines, penalties and
punitive(disciplinary) damage resulting from regulatory actions, as
well as private settlements), but excludes reputation risk.
Basel Operational Risk Event Types
• To know the Basel operational risk event types and what forms they
take:
1. Internal Fraud;
2. External Fraud;
3. Employment Practices and Workplace Safety;
4. Clients, Products, & Business Practice;
5. Damage to Physical Assets;
6. Business Disruption & Systems Failures;
7. Execution, Delivery & Process Management.
• BIS believes that for banks of all sizes, the following are crucial
elements of an effective operational risk management framework:
1. clear risk oversight by the board and senior management
2. a strong operational risk culture
3. a strong internal control culture
4. effective internal reporting
5. contingency planning.
Basel provides the following seven operational risk event
types, with examples of where and how they might arise.
Financial Crime Legislation: (To understand the
implications of financial crime legislation in terms
of appropriate implementation and risk
management, both internally and externally)
• The global financial services industry provides an essential role in the
facilitation of international commerce.
• Unfortunately, it also has the potential to enable the financial
proceeds of crime to be moved around the world quickly and easily.
• The nature of the industry means that there are sometimes
opportunities for unscrupulous practitioners to make money through
dishonest means, at the expense of clients or other market
participants.
• Therefore, in most jurisdictions there are strict rules in place,
enforceable through national and international legal systems, to:
1. Prohibit certain undesirable practitioner behaviours, collectively
known as market abuse; these fall into two overlapping categories
– insider information and market manipulation.
2. Oblige financial services firms to monitor financial transactions and
report any that appear suspicious, to reduce the likelihood of
criminal proceeds being moved around the system; these also fall
into two related categories – money laundering and terrorist
financing.
• Examples of insider information market abuse include:
1. Insider dealing – when an insider (eg, a member of staff) deals on
the basis of information which is not known to the market.
2. Improper disclosure – where an insider improperly discloses inside
information to another person.
3. Improper dissemination – giving out information that conveys a
false or misleading impression about an investment or the issuer of
an investment where the person doing this knows the information
to be false or misleading.
• Money laundering is the process of turning ‘dirty’ money (money
derived from criminal activities) into money which appears to be from
legitimate origins. Dirty money is difficult to invest or spend, and
carries the risk of being used as evidence of the initial crime.
Laundered money can be invested and spent with less risk of
incrimination.
• There are three stages to a successful money laundering operation:
1. Placement – this is the introduction of dirty money into the
financial system. Typically, this involves placing the criminally-
derived cash into a bank or building society account.
2. Layering –
• this involves moving the placed money around the system in order to make it
difficult for the authorities to link the placed funds with the ultimate
beneficiary of the money.
• This might involve buying and selling foreign currencies, shares or bonds in
rapid succession, investing in collective investment schemes, insurance-based
investment products or moving the money from one country to another.
3. Integration –
• At this final stage, the layering has been successful and the ultimate
beneficiary appears to be holding legitimate funds (ie, clean rather than dirty
money).
• The money is regarded as ‘integrated’ into the legitimate financial system.
The international anti-money laundering provisions are aimed at
requiring firms to:
1. Identify customers and report suspicious transactions at the
placement and layering stages.
2. Keep adequate records which should prevent the integration stage
being reached.
3. Report suspicious activity or behaviour to the relevant regulatory or
legislative authority.
• Many of the requirements of national and international anti-terrorism
legislation on financial services firms are similar to the anti-money
laundering provisions described above, and involve:
• customer identification
• record keeping
• reporting suspicious activity.
• The areas of financial crime considered above (market abuse, money
laundering and financing of terrorism) require an appropriate set of
risk management responses by firms, such as:
• 1. Educating staff on the risks to:
• society, if financial crimes are committed
• the firm, if placed under regulatory censure(Criticism)
• the individual, of a custodial sentence or heavy fine.
2. Putting systems and controls in place to mitigate the risk of
occurrence.
3. Monitoring staff compliance with the internal rules and the external
legal and regulatory stipulations.
4. Escalating behavioural exceptions to a specific individual or
committee for investigation.
5. Penalising contravention (breach) with the rules and if necessary
informing the relevant authorities.
Operational Risk and its
Consequential Effects
• When an operational risk materialises, it often causes other risk issues
too. These typically include:
1. Reputational risks – if clients or the media become aware of the issue and it
tarnishes the firm’s reputation.
2. Compliance (or regulatory) risks – certain process failures will result, for
example, in customers not being treated fairly. This in turn is a regulatory
breach and could result in fines or other sanctions being applied by the
regulator.
3. Credit risks – areas in the credit function where
operational risk issues can lead to losses are:
• data errors causing inadvertent credit limit breaches
• lack of adequate monitoring and/or analysis or
misinterpretation of a counterparty’s financial
statements due to a lack of training or incompetence
• legal risk, including the inability to enforce contracts
in credit-related areas such as the posting of collateral
• failing to carry out suitable credit checks on
counterparties, or wrongly assuming that credit rating
agencies always get ratings right.
4. Market risks – an undetected error in the portfolio management
system might lead to a breach of a market risk limit.
5. Liquidity risks – a process breakdown in the finance department
could lead to the firm having insufficient liquidity to pay staff
salaries.
6. Investment risks – carelessness on the part of a fund manager,
coupled with a process that contains no subsequent checking, could
cause a mandate limit breach.
Operational Risk Policy
• A firm needs to have a written operational risk policy that defines a
coherent, consistent approach to the firm’s operational risk
management.
• It provides a ‘roadmap’ to move the organisation from what might be
a fragmented, non-strategic approach to operational risk
management, to a comprehensive, firmwide methodology that uses a
common risk language throughout the organisation.
• The policy defines the operational risk methodology, or framework,
within which the firm will operate.
Building this framework will involve,
for example:
A. Defining the firm’s operational risk appetite.
B. Defining the methodology used to identify and categorize the operational
risks that exist in the organisation.
C. Defining the methodology used to measure and assess the significance of the
identified risks
D. Assigning responsibility to line managers for owning the mitigating actions
required to reduce risk exposures to within the risk appetite.
E. Assigning responsibility for monitoring the effects of the mitigating actions.
F. Establishing the reporting and escalating mechanisms for risk issues to all
levels of the organization in order to ensure transparency, and aid the
decision-making process.
• The process of developing an operational risk policy is cyclical and
continuous, maturing in line with the firm’s growing understanding of
its operational risk profile.
Areas Addressed by An
Operational Risk Policy
The operational risk policy, then, is a document which outlines a firm’s
strategy and objectives for operational risk management. It is also
where the boundary between other risk areas, such as market and
credit risk, is clarified. To meet the prime objectives of operational risk
management the risk policy and its associated standards should
address the following areas:
1. Identification of key officers - CROs
2. Roles and responsibilities
3. Segregation of duties
4. Cross-functional involvement and agreement.
Identification of Key Officers
It is important for firms to identify and empower those individuals who are given
key responsibilities in the management of operational risk. Key officers will include
the following:
1. Line managers within the independent operational risk management function,
responsible for monitoring and reporting to the board.
2. Senior business managers, responsible for operational risks within their areas of
the business.
3. The group risk management function, responsible for the firm’s overall financial
risk.
4. Certain members of staff, sometimes called risk representatives or risk
champions, may also be designated from within the business itself to monitor a
department’s operational risks on behalf of the owning manager.
Roles and Responsibilities
• The policy should provide clear responsibility and accountability for risk
management at all levels.
• Staff throughout the organization need to know precisely what is expected of
them, and why.
• If they are accountable for managing risk, they also require the necessary
control and authority to be able to take action and implement risk reduction
plans.
• The risk policy should include clear lines of authority, identify key risk officers
to carry out prescribed actions, and define their roles and responsibilities.
• The risk policy should also make clear the consequences of non-compliance
for staff not observing the policy.
Segregation of Duties
• To effectively manage and control its processes, the firm will need to
ensure effective segregation of duties between the trading and
support functions, such as front-office, operations, accounting and
risk monitoring.
• Barings Bank was ruined as a business because the head of its
Singapore front-office was also head of the Singapore back-office and
was able to cover up trading errors until they grew to a level that
brought down the bank.
• This case study consists of the “Report of the Board of Banking Supervision
Inquiry into the Circumstances of the Collapse of Barings, 18 July 1995.”
• Events
• Massive Losses incurred by Nick Leeson, the General Manager and Head
Trader of Barings Financial Services (BFS) by reason of unauthorised and
concealed trading activities within BFS.
• The true position was not noticed earlier by reason of a serious failure of
controls and managerial confusion within Barings.
• The external auditors, supervisors or regulators of Barings had not detected
the true position prior to the collapse.
• Risks Incurred
• Operational Risk – A lack of segregation between front and back
office. Leeson was permitted throughout to remain in charge of both
front office and back office at BFS.
• [Link]
feb/24/nick-leeson-barings-bank-1995-20-archive
• Operational Risk – The lack of understanding of BFS’s trading
activities, the lack of reconciliation to client records of the funding
provided by Barings in London to BFS and the lack of verification of
the (false) information provided by BFS, the deficiencies and
inaccuracies in large exposure reporting to the Bank of England.
• Operational Risk – The system of checks and balances necessary for
the proper management and control of a financial institution failed in
the case of Barings with regard to BFS in a most serious way, at a
number of levels and in more than one location.
Potential Mitigation
• Management teams have a duty to understand fully the businesses they
manage.
• Responsibility for each business activity has to be clearly established and
communicated.
• Clear segregation of duties is fundamental to any effective control system.
• Relevant internal controls, including independent risk management, have
to be established for all business activities.
• Top management and the Audit Committee have to ensure that
significant weaknesses, identified to them by internal audit or otherwise,
are resolved quickly.
Cross-Functional Involvement
and Agreement
• The policy should promote collaboration between functions,
departments and divisions, because
• many operational risks occur as a result of ownerless or unnoticed
boundary errors. Where possible, cross-functional teamwork should
be encouraged (notwithstanding the need for segregation of duties)
through incentives, education and a supportive organisational
structure.
Operational Risk Management
• Many operational risks are best managed within the departments in
which they arise. So, for example,
• IT staff are best qualified to address systems-related risks, and
• back-office staff are best suited to address settlement issues.
• However, overall planning, challenge and monitoring should be
provided by a centralised operational risk management department
which is independent from the business areas it serves.
• The role of the operational risk management function is to:
• Work with managers and other risk owners to assess and quantify
risks
• Benchmark good industry practice
• Provide risk oversight and monitoring
• Ensure issues are properly escalated, and track the actions arising
from operational risk incidents
• Conduct qualitative operational risk analysis using, for example:
• HR reports from exit interviews
• internal audit reports, and the rate at which audit points are closed by the
business
Identification and Assessment
of Risks
• A significant amount of time is required from managers and staff to ensure the
compilation of a good quality, comprehensive operational risk register for each
area of the business.
• There are a variety of methods used for the practical capture and identification of
operational risk; the more common ones include:
• Self-assessment
• KRIs
• risk and control assessment workshops
• loss data causal trend analysis
• external loss data (where available)
• audit reviews.
Management of Risk and Reduction of
Potential Impact and Likelihood of Occurrence

• Once risks have been identified and measured, the risk owner is in a
position to take effective action, to address them where they fall
outside of the firm’s risk tolerance or appetite.
• Managing the risk involves taking steps to reduce both its likelihood
and its impact, should it occur.
• The key to reducing the likelihood of a risk occurring is to:
• clearly identify the risk before it occurs
• establish clear ownership for the risk, and ensure that the owner is
able to put proper controls in place
• set up and monitor appropriate risk indicators, and act before they
ever reach their predefined danger limits.
• If the risk does occur, its impact can be reduced by ensuring:
• speedy escalation to senior management, if their help is necessary
for resolution
• if necessary, that appropriate insurance policies are in place.
Stages of Operational Risk
Management
Identification, measurement, management and control, management
information, monitoring, escalation and remediation
1. Risk Identification – clearly identify the firm’s risks.
2. Risk measurement and assessment – score the impact and the
likelihood of the risk against pre-defined criteria.
3. Management and control – ensure that appropriate controls are in
place to mitigate the risk. Put actions in place for under-controlled
risks. Ensure that ‘real-time’ escalation mechanisms are set up, with
pre-defined thresholds that define how high up the chain of
command the limit breaches or loss incidents should be escalated.
Ensure that remediation work is owned and tracked to completion.
4. Risk monitoring – Monitor the risk and control indicators and other
risk management information (MI), and act before they ever reach
their predefined danger limits.
5. Risk reporting – reporting of risk MI should include indicators, the
risks and controls to which they relate, and incidents – ideally both
losses and near misses. Pre-defined danger limits should be defined
by setting triggers and limits on the data.
6. Operational Risk Policy – lessons learned during the operation of
the risk framework are used to update the policy.
Operational Risk Identification
Operational Risk Identification
and Categorisation
• Categorizing the risks will enable:
• A better understanding of where in particular the firm’s operational
weakness lie:
• processes
• systems
• people, or
• vulnerability to external events
• a sound basis for operational risk capital allocation across the
different categories
Self-Assessment Risk
Identification
• This typically involves a checklist of the risks that a particular area of
the firm faces.
• Managers and staff in a department are required to score each risk,
perhaps as part of a survey or questionnaire.
• The risks are usually scored by probability and impact.
Risk Assessment and
Measurement
Operational Risk Assessment
and Measurement
• Risk assessment and risk measurement are both concerned with
understanding the likelihood of risks occurring and their potential
impact on the business.
• Once an understanding of the size of a problem has been gained,
appropriate action can be taken to address it.
• The reasons for measuring and assessing operational risk are to:
1. Establish a quantitative baseline for improving the control
environment – knowing how much the firm might save by avoiding
the risk is a useful input to the business case for upgrading
processes and controls
2. Provide an incentive for risk management and the development of a
strong risk culture
3. Improve management decision-making; by knowing the size of their
risks, managers are in a better position to decide how much risk
they wish to take.
4. Satisfy regulators and shareholders that a firm is adopting a
proactive and transparent approach to risk management, and
5. Make an assessment of the financial risk exposure that can be used
for capital allocation purposes.
• The main difficulty in measuring and assessing operational risk is the
lack of relevant and objective data.
• Many firms do not have enough historic loss data of their own to
predict objectively the likelihood and impact of new risks that have
been identified.
Methods of Assessment
1. Impact and Likelihood Assessment
2. Scenario Analysis
3. Bottom-Up Analysis
Impact and Likelihood
Assessment
• One of the simplest methods of assessing risk is the creation of an
impact and likelihood assessment.
• This enables risks to be ranked in order of their severity. The
assessment may be subjective (using the experience of the
professionals involved) or objective (being supported by historical
data) – or both. In either event, the severity ranking decision depends
on two criteria: the likelihood of the risk being realized and the
magnitude of the impact.
• Likelihood Probability Ratings
• The likelihood of the risk can be represented as a range of
probabilities that correspond to a rating. For example, depending on
the business area being measured, the following ratings might be
used:
Impact Loss Ratings
• The impact of the risk is the potential loss if the risk occurs. This can
be represented as a monetary range, and also assigned a rating. For
example:

Risk score = likelihood score X impact score


Heat Map
The advantages of an impact and
likelihood assessment are the
following:
• It provides a simple method for viewing the range of risks the
business faces.
• It provides an evaluation of the effectiveness of the control
environment if gross and net risk scores are plotted separately.
• It focuses management attention on the most important risks.
Scenario Analysis
• Scenario analysis is a ‘top-down’ method of highlighting potential risk
combinations in order to allow preventative action to be taken.
• It uses the experience of business professionals to capture possible
scenarios that have occurred in the past, or may result in loss in the
future.
• By investigating these scenarios, perhaps through stressing (ie,
exaggerating) a particular aspect of each scenario, preventative
measures can be taken to reduce their risk of occurrence.
Bottom-Up Analysis
• The bottom-up measurement approach seeks to analyse the
individual risks and adequacy of controls across business processes.
• It is called ‘bottom-up’ because it builds up a detailed profile of the
risks that occur in each area, aggregating them to provide overall
measures of exposure for departments, divisions or the firm as a
whole.
• It uses the experience of line managers and staff, coupled with loss
data as its source of information, so the resultant measures contain
both qualitative and quantitative elements.
Key Risk Indicators (KRIs)
• Having produced a list of risks, and having then ranked them in order
of severity, the firm can designate the top ‘x’ risks as its key risks.
• It is then possible to obtain data that describes the current status of
those key risks, and to define upper and lower acceptable limits on
the behaviour of this data.
• This approach provides indicators on the firm’s key risks, or, in other
words, it produces a series of KRIs.
The advantages of using KRIs are the following:
• They allow trends to be monitored and can therefore be used to
anticipate problems.
• They allow limits of acceptability to be established.
• They can provide a basis for objective risk measurement.
Practical Constraints
To know the practical constraints of implementing an operational risk
management framework:
• Data collection constraints – in practice, it is very difficult to build a
truly comprehensive data set. Apart from the general lack of data,
system constraints and a lack of standardization mean that the required
data feeds from disparate sources cannot be easily developed.
• Cultural constraints – business heads need to be convinced of the value
that operational risk management (ORM) will bring. If not implemented
in a well-structured manner, it is often seen as a cost to the business,
and even a nuisance, rather than a real asset.
• Resource and cost constraints – firms continually underestimate the
amount of time and resources required to implement identification
and measurement systems. In an era of tight cost control, resource
constraints put a limit on how quickly or comprehensively
implementation is carried out.
Managing Operational Risk
Operational Risk Register
• Risk Register and its Core Features: Having identified and then
assessed the various operational risks facing the firm, and having then
ranked the risks to decide the priority order for mitigation, the next
stage in the process would be the construction of a risk register, also
known as a risk log.
• There is no widely accepted definition of what a risk register should
look like, The actual content and format of a risk register will depend
on the level within the organization for which it is being constructed,
and the risk types to which it refers.
• A risk register could consist of a list of identified risks, linked to the
business objectives, processes or products whose success would be
threatened if the risk materialized. The overall risk score is used to
sort the risks so that the list runs from the most significant to the least
significant.
• Each risk would be assigned to an owner or lead person – ideally a
member of staff or perhaps a department – and then the mitigating
actions would be listed, along with their deadlines for completion.
• Finally, the sources of assurance and oversight would be given in
order to allow periodic reassessment of the risk, and the status of the
mitigating controls which the actions will have implemented.
• Both ‘assurance’, and ‘oversight’, refer to the mechanisms used by the
firm to provide an objective view about the quality of each risk’s
management.
• Mitigating controls are ways in which the likelihood and impact of a
risk are reduced. They could include, for example, managerial sign-off
of work before it leaves the department, or perhaps an IT system that
requires a second member of staff to verify inputs for accuracy.
In summary then, the risk register’s column headings would be:
• objectives, processes or products affected by this risk
• description of risk
• risk ranking
• lead person or department
• action plan
• target and completion dates
• sources of assurance and oversight (which may or may not be the
lead person or department)
• mitigating controls, their effectiveness and owner(s), and
• gross, net and residual risks.
Common Methods of Operational Risk
Mitigation
• Controls
• Financial Crime Compliance
• Operational Resilience
• Outsourcing
• Insurance
• Information, Cyber Security, Data Protection and Privacy
• Physical Security
• Financial Reserves
• Risk Awareness Training
Controls
• Preventative controls are those that prevent errors occurring in the
first place.
• They attempt to tackle the root causes of risk and are most effective
when incorporated within processes at the outset by anticipating a
risky outcome.
• Technology solutions are often used as a key means of implementing
preventative controls.
• For example, a key preventative control is the provision of individual
IT passwords and system access control for all staff.
• Without it, firms would lose the ability to audit which system actions
had been performed by which members of staff.
• System data security would also be compromised if there was no way
of stopping people logging on to whichever systems they were
interested in.
• Detective controls detect errors once they have occurred, and quality
assurance checks fall under this category.
• It is important to remember that processes frequently change.
• If the control structure is not reviewed and assessed as part of this
change, it is possible that potential risks are introduced that are not
covered by adequate controls.
Financial Crime Compliance

• Customer identification
• Record-keeping, and
• Reporting suspicious activity.
Operational Resilience
• [Link]
zarm/[Link]
• A business continuity plan (BCP) which deals with the premises and
people aspects – where will staff work if their main site is out of
action?
• Disaster recovery (DR) procedures which deal with the IT and other
infrastructure required to keep the business running.
Operational Resilience
• [Link]
zarm/[Link]
• A business continuity plan (BCP) which deals with the premises and
people aspects – where will staff work if their main site is out of
action?
• Disaster recovery (DR) procedures which deal with the IT and other
infrastructure required to keep the business running.
In order to construct a robust BCP and DR solution, a thorough analysis
of the causes of potential disruption is required, ranging from minor
mishaps to major catastrophes. Typical risks whose materialization
could require staff to use temporary alternative working
accommodation are:
• fire
• power failure
• civil unrest and strikes
• terrorism.
Outsourcing
• A firm may choose to outsource some aspects of its business to a
third party with specific expertise in managing certain risks.
Insurance
• Another common method of transferring risk is to purchase insurance
cover.
• Insurance policies can be constructed to cover losses due to fire, theft
and losses caused by human error.
Information and Cyber Security
• Information and cyber security are both associated with IT risks, but
information can of course also be held on paper.
• A firm should categorise the types of information which it receives
and processes so that appropriate steps can be taken to protect it
regardless of the medium.
• For example, personal staff or customer information needs greater
care than a report downloaded from the internet which is already in
the public domain.
‘10 Steps To Cyber Security’.
• Information Risk Management Regime – assess the risks to your
organisation’s information assets with the same vigour as you would
for any other risk.
• Secure IT systems – remove or disable unnecessary functionality from
IT systems, and keep them patched against known vulnerabilities.
Patching refers to the periodic updates which software vendors
release to close any security weaknesses that have been discovered in
their systems.
• Network security – connecting to untrusted networks (such as the
internet) can expose your organisation to cyber attacks. Filter all
traffic at the network perimeter so that only traffic required to
support your business is allowed, and monitor traffic for unusual or
malicious incoming and outgoing activity that could indicate an attack
(or attempted attack). Assess the effectiveness of the perimeter filters
by conducting regular penetration tests.
• Managing user privileges – users of your IT systems should only be
provided with the user privileges that they need to do their job.
Control the number of privileged accounts for roles such as system or
database administrators, and ensure this type of account is not used
for high risk or day-to-day user activities.
• User education and awareness – produce user security policies that
describe acceptable and secure use of your organization's IT systems.
These should be formally acknowledged in employment terms and
conditions. All users should receive regular training on the cyber risks
they face as employees and individuals. Security related roles (such as
system administrators, incident management team members and
forensic investigators) will require specialist training.
• Incident management – establish an incident response and disaster
recovery capability that addresses the full range of incidents that can
occur. All incident management plans (including disaster recovery and
business continuity) should be regularly tested. Report online crimes
to the relevant law enforcement agency to help build a clear view of
the national threat and deliver an appropriate response.
• Malware prevention – viruses and other malicious software are
known as malware. Produce policies that directly address the
business processes (such as email, web browsing, removable media
and personally owned devices) that are vulnerable to malware. Scan
for malware across your organization and protect all host and client
machines with antivirus solutions that will actively scan for malware.
All information supplied to or from your organisation should be
scanned for malicious content.
• Monitoring – continuously monitor inbound and outbound network
traffic to identify unusual activity or trends that could indicate attacks
and the compromise of data.
• Removable media controls – where the use of removable media is
unavoidable (for example USB keys or external hard drives), limit the
types of media that can be used together with the users, systems, and
types of information that can be transferred. Scan all media for
malware using a standalone media scanner before any data is
imported into your organisation’s system.
• Home and mobile working – assess the risks to all types of mobile
working where the device connects to the corporate network
infrastructure. Train mobile users on the secure use of their mobile
devices for locations they will be working from. Protect data using
encryption if the device supports it.
Physical Security
• vetting all staff and contractors for previous criminal records
• visible ID cards for all staff
• sign-in for all visitors to the building, and
• remaining vigilant and preparing for external threats such as protests
or marches, especially those aimed at financial services firms.
Financial Reserves

Regulatory capital and liquidity requirements for firms


Risk Awareness Training
Risk awareness training for all relevant staff should be given by the firm
to help staff understand the principle of reducing the likelihood of risk
occurring, and the key role which they play in achieving this.
Details of the training being given, and attendance, should be recorded
and tracked by the operational risk function.
Credit Risk
• Identification of Credit Risk: Counterparty risk, Issuer risk and
Concentration risk.
• Credit risk is the risk of loss caused by the failure of a counterparty or
issuer to meet its obligations.
• The party that has the financial obligation is called the obligor.
• The goal of credit risk management is to maximize a firm’s risk-
adjusted rates of return by maintaining credit risk exposure within
acceptable parameters.
• Credit risk exists in two broad forms: counterparty risk and issuer
risk.
• Counterparty risk is the risk that a counterparty fails to fulfil its
contractual obligations. A counterparty is one of the parties to a
transaction – either the buyer or the seller.
• Examples of counterparty credit risk from a bank’s perspective would
include:
1. the risk that a customer fails to pay back a loan
2. the risk that a company with whom the bank does business declares
bankruptcy before having paid for goods or services supplied by the
bank
3. the risk that a broker from whom the bank has purchased a bond
fails to deliver – or delivers late.
• Concentration risk arises through an uneven distribution of exposures
to individual issuers or counterparties (single-name concentration) or
within industry sectors and geographical regions (sectorial
concentration).
• For example, if a bank is overly-dependent on a small number of
counterparties – single-name concentration risk – then, if any of those
counterparties default, the bank’s revenues could drop by a significant
amount.
Counterparty and Issuer Risk
Exposures
• It can be seen then that credit risk consists of counterparty and issuer
risk, and that the following differences exist between them.
1. A broker could fail to deliver a bond issued by a good quality
company that is currently paying its coupons and redeeming its
bonds. This is counterparty risk.
2. The same broker could deliver the bond exactly as required, but the
issuing company, previously assessed as being of high quality, runs
into trouble. It declares bankruptcy and stops paying its interest on
bonds. This is issuer risk.
• For most banks, loans are the largest and most obvious source of
credit risk; however, other sources of credit risk exist throughout the
activities of a bank, including in the banking book and in the trading
book. These sources include:
• the extension of commitments and guarantees
• interbank transactions
• financial instruments such as futures, options, swaps and bonds
• the settlement of these and other transactions.
Systemic Risk
• Systemic risk refers to a possible breakdown of the entire financial
system rather than simply the failure of an individual firm.
• Systemic risk exists because of the close interlinkages between the
different parts of the financial system. These interlinkages create
feedback loops that can turn relatively minor events into major crises.
• For example, the credit crisis that started in the US housing market
caused banks around the world to withdraw from the interbank
lending markets as trust in the resilience of other banks evaporated.
• Northern Rock, a UK bank, had built its business model on borrowing
cheaply on the short-term interbank markets, and turning those loans
into long term mortgages.
• A slowdown in the US and global financial system directly impacted
the UK when Northern Rock failed in 2007-08 – the first banking
failure in the UK for 140 years.
• On the other hand, when Barings Bank failed in 1995 as a result of
losses caused by a rogue trader, the bank went into bankruptcy, but
this did not lead to a wider crisis.
Credit Risk Boundary Issues – To Understand
credit risk boundary issues as identified within Basel

• Basel describes the following key operational (‘boundary’) risks to be


considered when banks are developing their credit administration
areas.
1. Internal processes – the efficiency and effectiveness of the credit
administration operations, including:
• prescribed management policies and procedures monitoring documentation;
• adequacy of controls over all back-office procedures
• contractual requirements
• legal covenants
• collateral management.
2. Systems – the accuracy and timeliness of credit risk information
provided to management information systems.
3. People – adequate segregation of duties.
Credit Risk Measurement
Basic techniques for measuring credit risk:
1. credit exposure
2. credit risk premium
3. credit ratings.
Credit Exposure
• Credit exposure is the amount that can potentially be lost if a debtor
defaults on its obligations. It is used to quantitatively assess the
severity of credit risk from:
• counterparties, and
• portfolios.
• Credit exposure consists of two parts:
1. Current exposure - The current exposure is the current obligation
outstanding which is normally fairly straightforward to calculate.
2. potential future exposure - The potential future exposure calculation is
usually performed using statistical techniques, such as Value-at-Risk (VaR)
modelling.
Credit Risk Premium
• A credit risk premium is the difference between the interest rate a
firm pays when it borrows and the interest rate on a default-free
security, such as a government bond.
• The premium is the extra compensation the market or financial
institution requires for lending to a firm that has a risk of defaulting.
Credit Ratings
• There is a strong relationship between credit risk premium and credit
rating (see next section). In theory, the higher the rating is, the more
creditworthy the obligor is and the lower the obligor’s risk premium.
• This means that the cost of borrowing will be less for a higher rated
firm as a reflection of its lower likelihood to default. Conversely,
downgrades in a company’s credit rating can (and, typically, do)
significantly increase its borrowing costs.
Role and Influence of Credit
Rating Agencies
• There are more than 75 ratings agencies around the world, many of
whom specialize in certain geographic regions or areas of credit
finance.
• The Basel Accord introduced a ratings-based method to the
calculation of credit risk for the standardized approach, and the Basel
Committee defined a set of guidelines that national regulators could
use for recommending permissible rating agencies.
• In the UK, the regulators nominated:
• Fitch Ratings
• Moody’s
• Standard & Poor’s (S&P).
• Elsewhere in Europe, the Bundesbank in Germany nominated the same
three plus another two, Dominion Bond Rating Service (DBRS) and Japan
Credit Rating Agency (JCRA).
• Moody’s, S&P and Fitch all use similar, but not identical, terminologies for
their bond ratings. They are based on letters of the alphabet, with, for
example, ‘AAA’ being the highest S&P rating. The terms ‘investment grade’
and ‘speculative grade’ have emerged to describe the categories ‘AAA’ to
‘BBB’ (investment grade) and ‘BB’ to ‘D’ (speculative grade), but these terms
are simply market conventions, and do not imply any recommendation or
endorsement of a specific security for investment purposes.
Merits and Limitations of Credit
Ratings
• Credit ratings are a useful method for lenders to assess the
creditworthiness of a borrower.
• Sovereign credit ratings take into account the overall economic
conditions of a country, including the volume of foreign, public and
private investment, capital market transparency and foreign currency
reserves.
• Sovereign ratings also assess political conditions, such as overall
political stability and the level of economic stability a country will
maintain during times of political transition.
• In theory, the ratings agencies play a useful part in helping firms
assess the credit risks of worldwide companies. However, in the run-
up to the recent credit crunch, many investors had started to rely
more on the ratings supplied by the credit rating agencies than on
their own credit risk analysis.
Specific criticisms of the rating
agencies include the following:
• Companies have not been downgraded fast enough. For example, the
major US firm Enron’s rating remained at investment grade up until
four days before the company went bankrupt, despite the fact that
the credit rating agencies had been aware of the company’s problems
for some months. This is a balancing act though, and the agencies’
ratings would lose their stability if they moved up and down in line
with every market movement.
• Rating agencies have been criticized for having too familiar a
relationship with company management, possibly opening
themselves to undue influence or the vulnerability of being misled.
• In addition, any business model that allows the receiver of a rating to
pay for it, and not the user, may encourage conflicts of interest on the
part of the rating agency.
• During the liquidity and credit crisis of 2008–2009, rating agencies
came under immense public scrutiny and, as a result of this pressure,
revised their rating criteria. This particularly affected the whole array
of structured finance products. This led to investment grade ratings
being downgraded straight to speculative grades on a scale that had
never before been seen.
• [Link]
841235575386
Counterparty Credit Risk and
Applications in Practice
• For credit risks associated with loan defaults, we can say that:
• When a counterparty defaults on payment, the loss to the bank is not
necessarily the total of what the counterparty owes. For example, if Newbank
lent ABC Co. £ 500 million, and ABC then defaulted, how much would
Newbank lose?
• Newbank may have a guarantee in place with ABC and may be able to reclaim
some of that amount through the legal process. In addition, ABC may have
placed collateral with Newbank which would offset some of loss to the bank.
• If the actual loss is £ 300 million then the loss given default (LGD) would be
60% (LGD is expressed as a percentage). Newbank might then use 60% as a
factor to apply to its other outstanding loans in recognition of the fact that its
loss in this particular case was 60% of what it could have been.
• The probability of default (PD) of a borrower or group of borrowers is
a measure of the likelihood of their failing to pay what they owe. The
bank will estimate the probability of default using historical
experience and empirical evidence. The higher the default probability
estimate, the higher the interest rate the lender will charge the
borrower to compensate for the higher default risk.
• The exposure at default (EAD) is the amount which a bank will be
exposed to in the future at the point of a potential default. This
amount may not be the amount they are exposed to ‘now’. In many
cases it will be the same, but for certain facilities (eg, those with
undrawn commitments), the EAD will include an estimate of future
lending before default.
Credit Risk Management
Examples of Credit Risk Protection and Mitigation
• Underwriting Standards
• Underwriting standards are the standards that financial institutions apply to
borrowers in order to evaluate their creditworthiness and, therefore, manage
the risk of default.
• Evaluation requires specific knowledge of their business and includes:
• a review of the borrower’s cash flow and financial statements
• the consideration of earnings, profit margin and outstanding debt
• analysis of industry variables such as competitive pressures, product
cycles and future growth potential
• controlling the terms of the loan, eg, limiting loan size, establishing a
repayment schedule and requiring additional collateral for higher risk
loans.
• Guarantees
To make their bond issues more attractive to investors, many issuers
arrange for another organization, generally one with very strong
finances, to guarantee the debt. This means that if the issuer cannot
pay the interest or capital from its own resources, the guarantor will
make the repayments.
• Netting Agreements
A netting agreement allows two parties that exchange multiple cash flows
during a given day to agree bilaterally to net those cash flows to one payment
per currency.
• Collateral
Collateral is an asset held by a lender on behalf of an obligor, under certain
agreed conditions, as security for a loan. It can be a physical asset (such as a
house that secures a mortgage loan), or can be in the form of cash or securities,
and is used by the lender as a form of insurance to reduce credit exposure to a
counterparty. In the event that the obligor defaults, the lender may retain the
collateral.
• Diversification
Diversification can be used as a means of reducing portfolio credit risk by
ensuring that the portfolio is spread across borrowers in different, negatively
correlating industry sectors that have an inverse economic relationship to each
other.
• Insurance and Credit Derivatives
In addition to loan-based instruments such as bonds, a range of
‘secondary’ instruments exist which derive their value from an
underlying loan or series of loans. These are called credit
derivatives, and the two most common types are the credit default
swap (CDS) and the collateralised debt obligation (CDO).
• Central Counterparties (CCPs)
The use of a CCP, or clearing house, is a method used by many
exchanges to reduce credit risk. The clearing house acts as the
guarantor of all transactions, limiting the exposure of its clearing
members by protecting them from defaults.
Credit Risk Management
Implementing a sound credit risk management policy to manage credit risk
in a company-wide context and includes:
• owning the credit policy and ensuring that it is adhered to
• setting, monitoring and reviewing credit limits
• assessing potential credit risk events
• ensuring decisions on granting credit are made independently of the
trading areas
• measuring and monitoring daily credit exposure. This will also involve
providing information for the assessment of capital adequacy, and
• performing credit analysis by counterparty, country, sector and
instrument or financial product.
Reporting and Escalation Tools
• Firms need to develop and implement comprehensive procedures and
information systems to monitor the condition of individual and grouped
counterparties across the bank’s various portfolios.
• These procedures need to define criteria for identifying and escalating
potential counterparty credit issues to senior management, to enable
them to resolve issues, to minimize loss to the firm.
• Problem areas will need more frequent monitoring, as well as possible
corrective action, classification and/or provisioning.
Basel Key Stages
• Board of directors should have responsibility for approving and
periodically reviewing (at least annually) the firm’s credit risk strategy and
significant credit risk policies.
• Senior management should have responsibility for implementing the
credit risk strategy approved by the board of directors and for developing
policies and procedures for identifying, measuring, monitoring and
controlling credit risk.
• Credit policies must be communicated throughout the organization,
implemented through appropriate procedures, monitored and
periodically revised to take into account changing internal and external
circumstances.
Managing and Measuring Credit
Risk
• Credit Scoring Systems
For retail customers, credit scoring systems include using
questionnaires and standard credit request application forms which
are subsequently scored. The questions are chosen to enable
standardized credit profiles to be applied to new applicants, and
would include:
• age
• credit history
• occupation
• years in current job
• home owner or renting.
• Factor Inputs
• In applying credit scores to firms, banks will use financial, non-financial and other
inputs:
• financial inputs will include an assessment of each firm’s earnings, cash flow,
asset values, liquidity, leverage, financial size and debt capacity
• non-financial inputs will include a view of each firm’s:
o management quality
o governance structure
o industry characteristics
o country risk
o credit rating
• extraordinary inputs might include:
o court actions
o other factors that emerge from time to time and which could impact the
firm’s ability to honour its commitments.
• Stress Testing
• Stress testing involves identifying possible events or future changes in
economic conditions that could have unfavourable effects on a bank’s
credit exposures, and assessing the bank’s ability to withstand such
changes.
• Areas for stress testing which the BIS recommends that banks could
‘usefully examine’ are:
• economic or industry downturns
• interest rate and other market movements
• market-risk events, and
• liquidity conditions.
• Internal Credit Rating
• One of the aims of the Basel Accord is to incentivize banks to improve their
risk management, and as part of this improvement, banks are encouraged to
develop their own internal credit rating systems.
• A well-structured internal risk rating system is a good means of differentiating
the degree of credit risk in the different credit exposures of a bank.
• This allows more accurate determination of the overall characteristics of the
credit portfolio, concentrations, problem credits and the adequacy of loan
loss reserves.
• Segmentation
• Under Basel, retail banking attracts less capital compared to commercial
banking, and banks have to provide regulators with PD, LGD, and EAD
statistics for clearly differentiated segments of their portfolios.
• Segmentation should be based (i) on credit scores (or some equivalent
measure), and (ii) on the time that the transaction has been on the bank’s
books.
• Impairment
Evidence of impairment includes:
• information about significant financial difficulties of the borrower (eg, as
indicated by liquidity or cash flow projections)
• an actual breach of contract (eg, delay in the borrower making principal or
interest payments)
• a high probability of bankruptcy or other financial reorganisation of the
borrower (eg, as indicated by a downgrading of credit status by a credit rating
agency), and
• the granting by the lender to the borrower, for economic or legal reasons
relating to the borrower’s financial difficulties, of a concession that the lender
would not otherwise consider. .
• Credit limits
• Limits need to be set for all counterparties whether single or part of a group.

You might also like