Operational and Credit Risk Management Guide
Operational and Credit Risk Management Guide
Risk
• Definitions of Operational Risk according to the Basel Committee on
Banking Supervision, Basel operational risk event types: Internal
Fraud, External Fraud, Employment Practices and Workplace Safety,
Clients, Products, & Business Practice, Damage to Physical Assets,
Business Disruption & Systems Failures, Execution, Delivery &
Process Management, Operational Risk Policy, Operational Risk
Framework: identification, measurement, management and control,
management information, monitoring, escalation, remediation.
Operational Risk Identification, Operational Risk Assessment and
Measurement, Managing Operational Risk.
• Credit Risk: Identification of Credit Risk: understand the key
components of credit risk and how they arise: counterparty risk,
issuer risk, and concentration risk. Credit Risk Measurement:
techniques for measuring credit risk, credit exposure, credit risk
premium, credit ratings. Credit Risk Management: sound practice
features of an effective credit risk management function, reporting
and escalation tools of credit risk management, Basel key stages of
credit risk policy development.
Definition of Operational Risk
• The Bank for International Standards (BIS) defines operational risk as
‘The risk of loss resulting from inadequate or failed internal
processes, people and systems or from external events’.
• This definition covers legal risk (including fines, penalties and
punitive(disciplinary) damage resulting from regulatory actions, as
well as private settlements), but excludes reputation risk.
Basel Operational Risk Event Types
• To know the Basel operational risk event types and what forms they
take:
1. Internal Fraud;
2. External Fraud;
3. Employment Practices and Workplace Safety;
4. Clients, Products, & Business Practice;
5. Damage to Physical Assets;
6. Business Disruption & Systems Failures;
7. Execution, Delivery & Process Management.
• BIS believes that for banks of all sizes, the following are crucial
elements of an effective operational risk management framework:
1. clear risk oversight by the board and senior management
2. a strong operational risk culture
3. a strong internal control culture
4. effective internal reporting
5. contingency planning.
Basel provides the following seven operational risk event
types, with examples of where and how they might arise.
Financial Crime Legislation: (To understand the
implications of financial crime legislation in terms
of appropriate implementation and risk
management, both internally and externally)
• The global financial services industry provides an essential role in the
facilitation of international commerce.
• Unfortunately, it also has the potential to enable the financial
proceeds of crime to be moved around the world quickly and easily.
• The nature of the industry means that there are sometimes
opportunities for unscrupulous practitioners to make money through
dishonest means, at the expense of clients or other market
participants.
• Therefore, in most jurisdictions there are strict rules in place,
enforceable through national and international legal systems, to:
1. Prohibit certain undesirable practitioner behaviours, collectively
known as market abuse; these fall into two overlapping categories
– insider information and market manipulation.
2. Oblige financial services firms to monitor financial transactions and
report any that appear suspicious, to reduce the likelihood of
criminal proceeds being moved around the system; these also fall
into two related categories – money laundering and terrorist
financing.
• Examples of insider information market abuse include:
1. Insider dealing – when an insider (eg, a member of staff) deals on
the basis of information which is not known to the market.
2. Improper disclosure – where an insider improperly discloses inside
information to another person.
3. Improper dissemination – giving out information that conveys a
false or misleading impression about an investment or the issuer of
an investment where the person doing this knows the information
to be false or misleading.
• Money laundering is the process of turning ‘dirty’ money (money
derived from criminal activities) into money which appears to be from
legitimate origins. Dirty money is difficult to invest or spend, and
carries the risk of being used as evidence of the initial crime.
Laundered money can be invested and spent with less risk of
incrimination.
• There are three stages to a successful money laundering operation:
1. Placement – this is the introduction of dirty money into the
financial system. Typically, this involves placing the criminally-
derived cash into a bank or building society account.
2. Layering –
• this involves moving the placed money around the system in order to make it
difficult for the authorities to link the placed funds with the ultimate
beneficiary of the money.
• This might involve buying and selling foreign currencies, shares or bonds in
rapid succession, investing in collective investment schemes, insurance-based
investment products or moving the money from one country to another.
3. Integration –
• At this final stage, the layering has been successful and the ultimate
beneficiary appears to be holding legitimate funds (ie, clean rather than dirty
money).
• The money is regarded as ‘integrated’ into the legitimate financial system.
The international anti-money laundering provisions are aimed at
requiring firms to:
1. Identify customers and report suspicious transactions at the
placement and layering stages.
2. Keep adequate records which should prevent the integration stage
being reached.
3. Report suspicious activity or behaviour to the relevant regulatory or
legislative authority.
• Many of the requirements of national and international anti-terrorism
legislation on financial services firms are similar to the anti-money
laundering provisions described above, and involve:
• customer identification
• record keeping
• reporting suspicious activity.
• The areas of financial crime considered above (market abuse, money
laundering and financing of terrorism) require an appropriate set of
risk management responses by firms, such as:
• 1. Educating staff on the risks to:
• society, if financial crimes are committed
• the firm, if placed under regulatory censure(Criticism)
• the individual, of a custodial sentence or heavy fine.
2. Putting systems and controls in place to mitigate the risk of
occurrence.
3. Monitoring staff compliance with the internal rules and the external
legal and regulatory stipulations.
4. Escalating behavioural exceptions to a specific individual or
committee for investigation.
5. Penalising contravention (breach) with the rules and if necessary
informing the relevant authorities.
Operational Risk and its
Consequential Effects
• When an operational risk materialises, it often causes other risk issues
too. These typically include:
1. Reputational risks – if clients or the media become aware of the issue and it
tarnishes the firm’s reputation.
2. Compliance (or regulatory) risks – certain process failures will result, for
example, in customers not being treated fairly. This in turn is a regulatory
breach and could result in fines or other sanctions being applied by the
regulator.
3. Credit risks – areas in the credit function where
operational risk issues can lead to losses are:
• data errors causing inadvertent credit limit breaches
• lack of adequate monitoring and/or analysis or
misinterpretation of a counterparty’s financial
statements due to a lack of training or incompetence
• legal risk, including the inability to enforce contracts
in credit-related areas such as the posting of collateral
• failing to carry out suitable credit checks on
counterparties, or wrongly assuming that credit rating
agencies always get ratings right.
4. Market risks – an undetected error in the portfolio management
system might lead to a breach of a market risk limit.
5. Liquidity risks – a process breakdown in the finance department
could lead to the firm having insufficient liquidity to pay staff
salaries.
6. Investment risks – carelessness on the part of a fund manager,
coupled with a process that contains no subsequent checking, could
cause a mandate limit breach.
Operational Risk Policy
• A firm needs to have a written operational risk policy that defines a
coherent, consistent approach to the firm’s operational risk
management.
• It provides a ‘roadmap’ to move the organisation from what might be
a fragmented, non-strategic approach to operational risk
management, to a comprehensive, firmwide methodology that uses a
common risk language throughout the organisation.
• The policy defines the operational risk methodology, or framework,
within which the firm will operate.
Building this framework will involve,
for example:
A. Defining the firm’s operational risk appetite.
B. Defining the methodology used to identify and categorize the operational
risks that exist in the organisation.
C. Defining the methodology used to measure and assess the significance of the
identified risks
D. Assigning responsibility to line managers for owning the mitigating actions
required to reduce risk exposures to within the risk appetite.
E. Assigning responsibility for monitoring the effects of the mitigating actions.
F. Establishing the reporting and escalating mechanisms for risk issues to all
levels of the organization in order to ensure transparency, and aid the
decision-making process.
• The process of developing an operational risk policy is cyclical and
continuous, maturing in line with the firm’s growing understanding of
its operational risk profile.
Areas Addressed by An
Operational Risk Policy
The operational risk policy, then, is a document which outlines a firm’s
strategy and objectives for operational risk management. It is also
where the boundary between other risk areas, such as market and
credit risk, is clarified. To meet the prime objectives of operational risk
management the risk policy and its associated standards should
address the following areas:
1. Identification of key officers - CROs
2. Roles and responsibilities
3. Segregation of duties
4. Cross-functional involvement and agreement.
Identification of Key Officers
It is important for firms to identify and empower those individuals who are given
key responsibilities in the management of operational risk. Key officers will include
the following:
1. Line managers within the independent operational risk management function,
responsible for monitoring and reporting to the board.
2. Senior business managers, responsible for operational risks within their areas of
the business.
3. The group risk management function, responsible for the firm’s overall financial
risk.
4. Certain members of staff, sometimes called risk representatives or risk
champions, may also be designated from within the business itself to monitor a
department’s operational risks on behalf of the owning manager.
Roles and Responsibilities
• The policy should provide clear responsibility and accountability for risk
management at all levels.
• Staff throughout the organization need to know precisely what is expected of
them, and why.
• If they are accountable for managing risk, they also require the necessary
control and authority to be able to take action and implement risk reduction
plans.
• The risk policy should include clear lines of authority, identify key risk officers
to carry out prescribed actions, and define their roles and responsibilities.
• The risk policy should also make clear the consequences of non-compliance
for staff not observing the policy.
Segregation of Duties
• To effectively manage and control its processes, the firm will need to
ensure effective segregation of duties between the trading and
support functions, such as front-office, operations, accounting and
risk monitoring.
• Barings Bank was ruined as a business because the head of its
Singapore front-office was also head of the Singapore back-office and
was able to cover up trading errors until they grew to a level that
brought down the bank.
• This case study consists of the “Report of the Board of Banking Supervision
Inquiry into the Circumstances of the Collapse of Barings, 18 July 1995.”
• Events
• Massive Losses incurred by Nick Leeson, the General Manager and Head
Trader of Barings Financial Services (BFS) by reason of unauthorised and
concealed trading activities within BFS.
• The true position was not noticed earlier by reason of a serious failure of
controls and managerial confusion within Barings.
• The external auditors, supervisors or regulators of Barings had not detected
the true position prior to the collapse.
• Risks Incurred
• Operational Risk – A lack of segregation between front and back
office. Leeson was permitted throughout to remain in charge of both
front office and back office at BFS.
• [Link]
feb/24/nick-leeson-barings-bank-1995-20-archive
• Operational Risk – The lack of understanding of BFS’s trading
activities, the lack of reconciliation to client records of the funding
provided by Barings in London to BFS and the lack of verification of
the (false) information provided by BFS, the deficiencies and
inaccuracies in large exposure reporting to the Bank of England.
• Operational Risk – The system of checks and balances necessary for
the proper management and control of a financial institution failed in
the case of Barings with regard to BFS in a most serious way, at a
number of levels and in more than one location.
Potential Mitigation
• Management teams have a duty to understand fully the businesses they
manage.
• Responsibility for each business activity has to be clearly established and
communicated.
• Clear segregation of duties is fundamental to any effective control system.
• Relevant internal controls, including independent risk management, have
to be established for all business activities.
• Top management and the Audit Committee have to ensure that
significant weaknesses, identified to them by internal audit or otherwise,
are resolved quickly.
Cross-Functional Involvement
and Agreement
• The policy should promote collaboration between functions,
departments and divisions, because
• many operational risks occur as a result of ownerless or unnoticed
boundary errors. Where possible, cross-functional teamwork should
be encouraged (notwithstanding the need for segregation of duties)
through incentives, education and a supportive organisational
structure.
Operational Risk Management
• Many operational risks are best managed within the departments in
which they arise. So, for example,
• IT staff are best qualified to address systems-related risks, and
• back-office staff are best suited to address settlement issues.
• However, overall planning, challenge and monitoring should be
provided by a centralised operational risk management department
which is independent from the business areas it serves.
• The role of the operational risk management function is to:
• Work with managers and other risk owners to assess and quantify
risks
• Benchmark good industry practice
• Provide risk oversight and monitoring
• Ensure issues are properly escalated, and track the actions arising
from operational risk incidents
• Conduct qualitative operational risk analysis using, for example:
• HR reports from exit interviews
• internal audit reports, and the rate at which audit points are closed by the
business
Identification and Assessment
of Risks
• A significant amount of time is required from managers and staff to ensure the
compilation of a good quality, comprehensive operational risk register for each
area of the business.
• There are a variety of methods used for the practical capture and identification of
operational risk; the more common ones include:
• Self-assessment
• KRIs
• risk and control assessment workshops
• loss data causal trend analysis
• external loss data (where available)
• audit reviews.
Management of Risk and Reduction of
Potential Impact and Likelihood of Occurrence
• Once risks have been identified and measured, the risk owner is in a
position to take effective action, to address them where they fall
outside of the firm’s risk tolerance or appetite.
• Managing the risk involves taking steps to reduce both its likelihood
and its impact, should it occur.
• The key to reducing the likelihood of a risk occurring is to:
• clearly identify the risk before it occurs
• establish clear ownership for the risk, and ensure that the owner is
able to put proper controls in place
• set up and monitor appropriate risk indicators, and act before they
ever reach their predefined danger limits.
• If the risk does occur, its impact can be reduced by ensuring:
• speedy escalation to senior management, if their help is necessary
for resolution
• if necessary, that appropriate insurance policies are in place.
Stages of Operational Risk
Management
Identification, measurement, management and control, management
information, monitoring, escalation and remediation
1. Risk Identification – clearly identify the firm’s risks.
2. Risk measurement and assessment – score the impact and the
likelihood of the risk against pre-defined criteria.
3. Management and control – ensure that appropriate controls are in
place to mitigate the risk. Put actions in place for under-controlled
risks. Ensure that ‘real-time’ escalation mechanisms are set up, with
pre-defined thresholds that define how high up the chain of
command the limit breaches or loss incidents should be escalated.
Ensure that remediation work is owned and tracked to completion.
4. Risk monitoring – Monitor the risk and control indicators and other
risk management information (MI), and act before they ever reach
their predefined danger limits.
5. Risk reporting – reporting of risk MI should include indicators, the
risks and controls to which they relate, and incidents – ideally both
losses and near misses. Pre-defined danger limits should be defined
by setting triggers and limits on the data.
6. Operational Risk Policy – lessons learned during the operation of
the risk framework are used to update the policy.
Operational Risk Identification
Operational Risk Identification
and Categorisation
• Categorizing the risks will enable:
• A better understanding of where in particular the firm’s operational
weakness lie:
• processes
• systems
• people, or
• vulnerability to external events
• a sound basis for operational risk capital allocation across the
different categories
Self-Assessment Risk
Identification
• This typically involves a checklist of the risks that a particular area of
the firm faces.
• Managers and staff in a department are required to score each risk,
perhaps as part of a survey or questionnaire.
• The risks are usually scored by probability and impact.
Risk Assessment and
Measurement
Operational Risk Assessment
and Measurement
• Risk assessment and risk measurement are both concerned with
understanding the likelihood of risks occurring and their potential
impact on the business.
• Once an understanding of the size of a problem has been gained,
appropriate action can be taken to address it.
• The reasons for measuring and assessing operational risk are to:
1. Establish a quantitative baseline for improving the control
environment – knowing how much the firm might save by avoiding
the risk is a useful input to the business case for upgrading
processes and controls
2. Provide an incentive for risk management and the development of a
strong risk culture
3. Improve management decision-making; by knowing the size of their
risks, managers are in a better position to decide how much risk
they wish to take.
4. Satisfy regulators and shareholders that a firm is adopting a
proactive and transparent approach to risk management, and
5. Make an assessment of the financial risk exposure that can be used
for capital allocation purposes.
• The main difficulty in measuring and assessing operational risk is the
lack of relevant and objective data.
• Many firms do not have enough historic loss data of their own to
predict objectively the likelihood and impact of new risks that have
been identified.
Methods of Assessment
1. Impact and Likelihood Assessment
2. Scenario Analysis
3. Bottom-Up Analysis
Impact and Likelihood
Assessment
• One of the simplest methods of assessing risk is the creation of an
impact and likelihood assessment.
• This enables risks to be ranked in order of their severity. The
assessment may be subjective (using the experience of the
professionals involved) or objective (being supported by historical
data) – or both. In either event, the severity ranking decision depends
on two criteria: the likelihood of the risk being realized and the
magnitude of the impact.
• Likelihood Probability Ratings
• The likelihood of the risk can be represented as a range of
probabilities that correspond to a rating. For example, depending on
the business area being measured, the following ratings might be
used:
Impact Loss Ratings
• The impact of the risk is the potential loss if the risk occurs. This can
be represented as a monetary range, and also assigned a rating. For
example:
• Customer identification
• Record-keeping, and
• Reporting suspicious activity.
Operational Resilience
• [Link]
zarm/[Link]
• A business continuity plan (BCP) which deals with the premises and
people aspects – where will staff work if their main site is out of
action?
• Disaster recovery (DR) procedures which deal with the IT and other
infrastructure required to keep the business running.
Operational Resilience
• [Link]
zarm/[Link]
• A business continuity plan (BCP) which deals with the premises and
people aspects – where will staff work if their main site is out of
action?
• Disaster recovery (DR) procedures which deal with the IT and other
infrastructure required to keep the business running.
In order to construct a robust BCP and DR solution, a thorough analysis
of the causes of potential disruption is required, ranging from minor
mishaps to major catastrophes. Typical risks whose materialization
could require staff to use temporary alternative working
accommodation are:
• fire
• power failure
• civil unrest and strikes
• terrorism.
Outsourcing
• A firm may choose to outsource some aspects of its business to a
third party with specific expertise in managing certain risks.
Insurance
• Another common method of transferring risk is to purchase insurance
cover.
• Insurance policies can be constructed to cover losses due to fire, theft
and losses caused by human error.
Information and Cyber Security
• Information and cyber security are both associated with IT risks, but
information can of course also be held on paper.
• A firm should categorise the types of information which it receives
and processes so that appropriate steps can be taken to protect it
regardless of the medium.
• For example, personal staff or customer information needs greater
care than a report downloaded from the internet which is already in
the public domain.
‘10 Steps To Cyber Security’.
• Information Risk Management Regime – assess the risks to your
organisation’s information assets with the same vigour as you would
for any other risk.
• Secure IT systems – remove or disable unnecessary functionality from
IT systems, and keep them patched against known vulnerabilities.
Patching refers to the periodic updates which software vendors
release to close any security weaknesses that have been discovered in
their systems.
• Network security – connecting to untrusted networks (such as the
internet) can expose your organisation to cyber attacks. Filter all
traffic at the network perimeter so that only traffic required to
support your business is allowed, and monitor traffic for unusual or
malicious incoming and outgoing activity that could indicate an attack
(or attempted attack). Assess the effectiveness of the perimeter filters
by conducting regular penetration tests.
• Managing user privileges – users of your IT systems should only be
provided with the user privileges that they need to do their job.
Control the number of privileged accounts for roles such as system or
database administrators, and ensure this type of account is not used
for high risk or day-to-day user activities.
• User education and awareness – produce user security policies that
describe acceptable and secure use of your organization's IT systems.
These should be formally acknowledged in employment terms and
conditions. All users should receive regular training on the cyber risks
they face as employees and individuals. Security related roles (such as
system administrators, incident management team members and
forensic investigators) will require specialist training.
• Incident management – establish an incident response and disaster
recovery capability that addresses the full range of incidents that can
occur. All incident management plans (including disaster recovery and
business continuity) should be regularly tested. Report online crimes
to the relevant law enforcement agency to help build a clear view of
the national threat and deliver an appropriate response.
• Malware prevention – viruses and other malicious software are
known as malware. Produce policies that directly address the
business processes (such as email, web browsing, removable media
and personally owned devices) that are vulnerable to malware. Scan
for malware across your organization and protect all host and client
machines with antivirus solutions that will actively scan for malware.
All information supplied to or from your organisation should be
scanned for malicious content.
• Monitoring – continuously monitor inbound and outbound network
traffic to identify unusual activity or trends that could indicate attacks
and the compromise of data.
• Removable media controls – where the use of removable media is
unavoidable (for example USB keys or external hard drives), limit the
types of media that can be used together with the users, systems, and
types of information that can be transferred. Scan all media for
malware using a standalone media scanner before any data is
imported into your organisation’s system.
• Home and mobile working – assess the risks to all types of mobile
working where the device connects to the corporate network
infrastructure. Train mobile users on the secure use of their mobile
devices for locations they will be working from. Protect data using
encryption if the device supports it.
Physical Security
• vetting all staff and contractors for previous criminal records
• visible ID cards for all staff
• sign-in for all visitors to the building, and
• remaining vigilant and preparing for external threats such as protests
or marches, especially those aimed at financial services firms.
Financial Reserves