Showing posts with label Operational Risk. Show all posts
Showing posts with label Operational Risk. Show all posts

Monday, 29 September 2014

CRO Forum's Principles on Operational Risk Measurement - "Quant touch this"...

Hammer Time?
Current efforts in Op Risk quantification
Despite practitioners efforts over the last few years, Operational Risk continues to live on starvation rations when it comes to considered quantification. Never treated as an alpha-topic by executives inside insurance institutions, it has been treated with similar indifference by legislators, culminating in the  "totally inadequate" take-a-percentage methodology for calculating Operational Risk capital in the Standard Formula.

Internal Modellers on the whole are not likely to be shaming that technique with their efforts either (basic summary of their problems here, while InsuranceERM cover struggles as a whole with a roundtable here). A paucity of operational risk event (and near miss) data within firms may be good news for ORIC as a vendor, but from a parameter and data uncertainty perspective, it leaves internal model operators and validators in an invidious position, particularly due to the quantum of insurers' capital likely to be involved (10%, give or take?).

It's not that the actuarial world hasn't taken a stab at it before (here), aren't fully aware of the data holes (here), or haven't used the word "Bayesian" in a sentence (here). However an activity which was "in its infancy" in the UK as far back as 2005, is surely now old enough to be working in the mines...

I was therefore happy to see the unprolific-yet-important CRO Forum bring a white paper to the table, Principles of Operational Risk Management and Measurement. It is an update to a 2009 version which takes into account Solvency II demands, as well as developing practice within insurers over the period, the suggestion being that 2009's efforts were a little too Banking Industry-influenced.

While this document might feel at outset like an idiot's guide to "quanting" operational risk (and bearing in mind the number of prospective standard formula applicants - 9 out of 10 in UK - one may be needed soon!), the document touches on a number of noteworthy technical matters, in particular;
  • The Definition section doesn't read well, but they have attempted to include outcomes other than monetary loss into the Op Risk definition, which from experience will improve discourse within firms. Are they attempting to squeeze strategic and reputational risks into this box though?
  • Nice coverage of Boundary Events, and encouraging firms to consider them in their management of Op Risk.
  • Very specific treatment of Risk Tolerance throughout, using it in preference to Risk Appetite. This is because it cannot be avoided, and so tolerance levels should be used to trigger "RAG"-type reporting up the chain. Nice work, and well justified, but I have certainly seen the expression "Zero Appetite" used for Op Risk, so no doubt this is not an industry standard perspective yet! (p5-6)
  • No problems with their coverage of tried and tested techniques - "Top Down", RCSA's & Loss Event analysis (p9-10)
  • Nice turn of phrase regarding emerging risks on p9 - "...assess the proximity of new risks to the organisation". It may need to include an attempt to quantify to be fully useful for ORSA purposes.
  • Concept of residual risk arrives quite late in the day, but isn't omitted. Important, given how much qualitative, or spuriously quantitative, material is being promoted as aiding this measurement work (p10)
  • Seem to accept at the bottom of p10 that Internal Modellers must do more than curve fit on internal Op Risk Event data - good news I guess.
  • Internal Model validation pressures on current Op Risk quantification practices flagged directly (p16 in particular)
  • Guidelines on embedding Op Risk monitoring processes highlight just how much work some practitioners are managing to cover (p11). Quite disheartening for those with smaller budgets.
Ther are a few points to make on section B around quantification:
  • Pretty scathing on Standard Formula relevance. (p14)
  • Scenario Analysis sold as something of a panacea to cure the ills of incomplete Op Risk Event data sets, but no mention of the biases which seem to permeate the creation of the scenarios, which is sadly a hostage to the invitee list. (p14)
  • Expand more on scenario analysis, bringing the "severe but plausible" terminology to the table (p15)
As well as the following generic comments;
  • Is risk measurement - "a tool for embedding risk culture in the organisation"? I would say so, particularly in the Op Risk arena, where decision makers will need to be involved at scenario-compilation time.
  • That said, they then go on to reference "senior management sign-off" of scenario work, which is somewhat contradictory!
  • Overweight in references to "culture" and "tone at the top", like most white papers these days (see the FRC's efforts from the other week). Playing with fire as a profession by shoehorning references to "culture" into everything.
  • A couple of horror-show schematics used on pages 7 and 8 - the Forum must know how much time risk professionals lose walking non-experts through things like this. They serve no purpose, and detract from surrounding text.
  • Attempt on p9 to solicit business for ORIC?
It was Professor Jagger who accurately prophesised "You can't always get what you Quant" - I'd say the Risk profession concurs, based on these very welcome principles.

Wednesday, 7 August 2013

Deloitte's 8th Global Risk Management Survey - cause for concern?

A survey from Deloitte has recently hit the news stands, namely the 8th edition of their Global Risk Management Survey - I thought I'd postpone my August holidays to pick through the bones of it (?).

The data was gleaned from an online survey they sent out to CRO/equivalents back in Sept-Dec 2012, so is a bit dusty, and there were 86 respondents, so a half-decent sample. It isn't dominated by a particular sector or continent (p7), but there are more conglomerate/bank-heavy respondents than pure insurers.

There is an infographic for those of a short attention span with a few headline numbers, but having sifted through the larger doc, I found the following elements worthy of note;

Boards, Committees and Risk Management
  • 80% of Boards are reviewing and approving Risk Management Policies/ERM Frameworks and Risk Appetite Statements. Bearing in mind the types of organisation in the sample, that is disappointingly low.
  • 25% don't review individual risk policies
  • 23% don't review strategy against risk profile
  • Almost half don't invite CRO to EXCOM meetings
  • Almost two-thirds delegate risk oversight to satellite committees (and two-thirds of those delegate to a Risk Committee)
  • Only half have their Risk Committee chaired by an INED.
  • Use of specific management risk committees for individual risk types tends to cluster around the 40-60% bracket (for example, 60% have an ERM committee, while 44% have an Op Risk Committee). Heavily weighted by organisation size i.e. larger ones tend to have them! 
  • Emerging risk reporting not supplied to 30% of Boards
  • Model validation results not supplied to 70% of Boards!
  • 66% (of insurance respondents) have their Boards responsible for reviewing economic capital results
CRO and Risk Management Function
  • 97% of large respondents have a CRO, 81% of smaller firms 
  • 88% using "3 Lines of Defence" (almost all of the larger respondents do)
  • 62% have an "ERM Programme"
  • 58% increasing risk management budgets (still!)
  • In the list of tasks currently performed by CROs, the fact that only 63% are involved in the approval of new business lines/products is pretty telling, and not in a good way.
Other control functions

  • Almost half of respondents said that Internal Audit and the ERM Framework do not use common risk categories and language.
  • 33% do not have a independent model validation 'function' (remember, the banks are in these stats as well!) - most of those who have made provision park it in the Risk Management function.

Risk management techniques

  • 90% using some form of stress testing in the business, with most saying the outputs are used in business planning, strategy setting and identifying risk tolerance. More than half however don't use the outputs in the allocation of capital to lines of business.
  • 74% have some type of Stress Testing policy
  • Over 20% either do not have a Risk Appetite Statement, or only have a quantitative one
  • Almost 70% still use regulatory capital as one of their quantitative measures in their Risk Appetite Statements
  • Risk limits tending to be set at enterprise level, as opposed to business or desk/subsidiary level - stats are a little murky due to the emphasis towards banking sector.
  • Model risk and Liquidity risk seem to be the risk types least factored in to companies ERM programmes
Management of Key Risks
  • Full list on p24, with the percentage shown representing the number of respondents who thought their management of each risk was "extremely" or "very" effective - stand outs were that perceptions of the effectiveness of the management of Operational, Model, Outsourcing and Data risks appear to be much lower than one would hope, with Lapse risk management ranked unusually high.
  • Op Risk KRIs and Loss data only collected in 60% of respondents
  • Just over half are modelling Op Risk in some way - varying degrees of complexity experienced
  • Most are using stress testing and/or reserving to assess Insurance risk - over 40% not currently using EC, and over 50% not using VaR.

Risk and Reward

  • Almost 60% of remuneration schemes have no clawback provisions
  • Almost 70% of schemes do not align incentive payouts with the term exposure of the underlying risks

Solvency II-specific
  • 92% (of relevant responders) will focus resource on ORSA in next 12 months
  • 77% will focus resource on Data Quality in next 12 months
  • 69% will focus resource on Documentation and Reporting in next 12 months
  • Less than 25% rate their processes and systems for Data Governance extremely/very effective.
  • Declining trend of insurers who will be modelling economic capital (p19)
  • Only 80% actually calculate Economic Capital
  • Some very grim stats on p21 covering which risk types are modelled for EC purposes (underwriting risks seemingly very low on the list)
There are a number of areas touched on here which fall short of pending (or indeed actual) national/international regulations and codes, never mind "best practice". Perhaps we can account for the innate conservatism of CROs in their responses, and assume things aren't quite as bad as they have self-assessed here?

Thursday, 28 March 2013

EIOPA Preparatory Guidelines - System of Governance

Consultation on System of Governance preparatory guidance (plus explanatory text)

For a topic which has felt like a given for a number of years (certainly in UK and Ireland where we already ask a lot in this area), the System of Governance preparatory guidance is still 40 pages, comprising of 57 guidelines, accompanied by 60 pages of explanatory text.

A couple of things immediately grabbed at me when going through the guidance (again anticipating a conservative approach of the supervisors rolling over and applying all content as is)
  • That the Risk Management Policy (regardless of how one structures the component elements) is expected to contain procedure-level information about the management of each major risk category - this sounds hopelessly disproportionate, and almost impossible for supervisors to reasonably get through;
  • That it is "expected" that large or complex firms separate their four key control functions, and that others at the small/medium end may ultimately find it easier to do so than consider the range of controls/maintenance of independence required to have combined functions;
  • That an expectation that insurers' systems of governance require regular independent review, with the AMSB only retaining the ability to choose the performer;
  • That insurers will be expected to formally identify/analyse/report on Operational Risk Events
  • That EIOPA bottled out of defining Risk Appetite and Risk Tolerance, leaving national supervisors and insurers to fight it out amongst themselves.
Ultimately, the document reads like a checklist which practitioners or full-timers can run through against the suite of documentation no doubt already in existence which, if based on CEIOPS/EIOPA final advice and/or the Commission's Draft Level 2 measures, won't be miles away as it stands. On that premise, I've only listed elements which jump out for me.


GENERAL GOVERNANCE REQUIREMENTS

Guideline 3
  • Evidence should be collected of the AMSB "proactively" seeking information from committees/key functions
Guideline 5
  • No more detail than an expectation that the AMSB "appropriately implements" their key functions - in the explanatory text, it goes on to say that larger companies will be "expected" to fully separate Risk/Actuarial/Compliance/IA, with a series of measures expected to preserve functional independence if smaller companies choose to combine some.
Guideline 7
  • Expectation that both AMSB decisions, and how information generated from the Risk Management System (RMS) influences them, is "appropriately documented" - compulsion for Board Decision Logs?
Guideline 8
  • Regular System of Governance reviews appear to be expected, which are documented and reported back to the AMSB - the AMSB retains the right to choose who performs it 
Guideline 9 - All policies must include:
  • Goal of policy
  • Tasks to be performed and by whom (person or role, unlike for validation, where person/s was specified)
  • Associated processes and reporting procedures
  • Obligations of affected operational teams to inform control functions of "relevant facts" at all times
Guideline 10
  • Contingency plans are expected for areas which are "especially vulnerable" - this pushes outside of what one would consider a conventional contingency plan for operational emergencies.

FIT AND PROPER

Guideline 11
  • Must have a Fit and Proper persons policy
  • It must be equally applicable to both hired staff and outsourced functions

RISK MANAGEMENT

Guideline 15 - AMSB is "ultimately responsible" for:
  • RMS effectiveness
  • Setting Risk Appetite and Risk Tolerance Limits
  • Approving Risk Management strategies and policies
Guideline 16 - Risk Management Policy must cover at least
  • Risk categories used and measurement methods
  • How each category/grouping of risks is managed
  • Risk tolerance limits for all categories in line with Risk Appetite
  • Linkage of both SCR and ORSA to risk tolerance limits
  • Frequency and content of regular stress tests, and circumstances for additional testing
In addition, the associated guidelines touch on the risk categories within one's Risk Management Policy. There is an expectation for pretty much every category that procedure-level information is included in the policy documents themselves, as well as hard limits, which is unlikely to be the case as it stands.

Guideline 18 - Insurance Risk Policy
  • Expected to cover types of acceptable insurance risks, how premiums will cover claims/expenses, as well as how product design accounts for investment restrictions and formal risk mitigation techniques
Guideline 19 - Op Risk Policy
  • Expectation that Operation Risk Events will be formally identified/analysed/reported in insurers, and that a system for collecting and monitoring them should be in place.
  • Operational Risk Scenarios should be developed and used, based on failures of key persons/processes/systems and external events
Guideline 23 - Investment Risk Policy
  • Buzzphrase introduced of managing the level of "security, quality, liquidity, profitability and availability" of one's asset portfolio

OWN FUND REQUIREMENTS AND THE SYSTEM OF GOVERNANCE

Guideline 32
  • Concept of a "medium term capital management plan" introduced which covers; planned capital issuances, maturities and distribution policies - not sure how that works for mutuals, but I can see what they're fishing for

INTERNAL CONTROLS

Guideline 33
  • "All personnel [should be] aware of their role in the Internal Control system
  • The Internal Control system should be "commensurate to the risks arising from the activities and processed to be controlled" - this line should hopefully avoid overkill

INTERNAL AUDIT FUNCTION

Guideline 36
  • The Internal Audit policy should include the procedure for informing supervisors [of whistleblowing-level wrongdoing I guess]

ACTUARIAL FUNCTION

Guideline 44
  • "Material"deviations of Best Estimate Liabilities should be back-tested for by the Actuarial function, reported on, and remedial changes proposed
Guideline 46
  • The Actuarial function is expected to "contribute to" specifying the risk coverage in the internal model, as well as the dependency structure - this feels like areas where, even in larger insurers, the function probably already leads, so will they be asked to take a step back?

Tuesday, 30 October 2012

Aon Benfield's CRO guide to Solvency II - in case you're not ready yet...

For all those CROs who are about to get left holding the Solvency II baby three years early by their over-enthusiastic executive colleagues, Aon Benfield pulled together a CRO guide to Solvency II which aims to take the journey "from complexity to best practice". 10 out of 10 for ambition...

It leans heavily towards General Insurers/Reinsurers (indeed it reads like a reinsurance sales brochure in many parts!), but nevertheless contains a suite of very useful content for anyone in the Risk space, as well as attempting to shatter a few myths. I took the following from it;
  • Steady early bits on capital planning and common questions a CRO should be posing in that space
  • On page 5, an excellent table comparing standard formula against internal modelling by risk driver, in particular emphasising why internal modelling may be more appropriate, rather than how much capital it could shave off. Being able to explain to the national regulator why one has neglected to apply the enhancements that internal modelling introduces to the accuracy of one's quantitative risk profile would be a smart thing for CROs to practice!
  • The undo some of that noble work by suggesting part of any IM feasibility study should include estimating the capital benefits!
  • Nice examples at the top of p6 of what mixes of business lend themselves to benefitting from an IM approach
  • Highlighting that domicile of firm continues to dictate feasibility of IMs for smaller firms (i.e some countries can't staff it!).
  • Recommend reviewing SF SCR factoring in the draft L2 asap. As was clear from the E&Y research I covered yesterday, many firms across the EU consider themselves to be advanced in the Pillar 1 space while disregarding draft L2. They highlight the Swiss experience as one where they struggled to authorise models for "Day 1" approval, and the Aon crowd propose some meaningful contingencies on p8
  • Useful analysis of capital drivers and optimisation strategies (p9-10)
  • Section on expert judgement validation (p15), touching on the Level 3 expectations, and in particular how a (non-Actuarial) CRO may struggle to adequately challenge certain judgement calls, such as selected data series or correlation matrices, without specialist advice. Very hard for smaller firms to obtain that, as most of their actuarial function will have probably contributed to the judgement!
  • Note that one of the key challenges for documenting the IM is getting the best-placed people (who are normally swimming in BAU) to pick up a pen and write!
  • Neat section on ORSA (p27-29), emphasising that SF firms with complex risk profiles may find they struggle to justify that approach when concluding the assessment. They go on to suggest that early experiences of ORSA Report/process documentation submissions have left CROs feeling that the regulatory approach is (Level 3?) tickbox as to content expectations.
  • Key challenges for CRO in briefing and educating senior colleagues for Solvency II-readiness are all fair, in particular the gap that could emerge if a CRO is not also an executive member.
  • The section on Risk Appetite is particularly useful for smaller non-IMAP firms, who may struggle to quantify their target measures - whether using Standard Deviations/volatility measures as suggested is a touch too simple depends on the business I guess.
  • The Pillar 3 section hits on the same issues I (and the FSA!)have picked up on earlier, such as end-user computing, inability to transition to BAU, data ownership issues etc.
I did take exception to a couple of bits in here, where the industry or indeed common sense appears to suggest otherwise;
  • The "fallacy" outlined on p5 that an IM enables a firm to hold less capital than an SF equivalent. The research I pointed to yesterday (p20) suggests across the EU that modellers are already "making it rain" with their capital savings
  • That the IM alternative for Op Risk is based on ORIC and individual loss event info. I'd certainly seen Milliman suggest that this approach is as flimsy as the SF approach, recommending options such as Bayesian networks to generate IM inputs.
  • Concerns that evidencing senior management model "use" could create a "value-destroying documentation burden". Is that what we call "minutes" these days!
  • Comments around the documentation delivery for the Internal Model Application Process becoming detached from the underlying processes referenced in those docs influencing BAU value-adding activity are perfectly valid, but no real solution is proposed.
  • The operation of the Model Change Policy features heavily (p19-21), as anyone in that space would expect. Again. little offered in the way of solutions, but I certainly would have expected more discussion on the "scope" of the model, which in my experience is a solid, liquid or gas depending on which control function you speak to, and I'm sure the FSA would agree!
PS All the best to you guys on the US East Coast, let's hope the worst has passed...

Tuesday, 21 August 2012

KMPG - Economic Capital Modelling in the Insurance Industry survey

Just when you think things will be quiet while the normal world goes to the beach for a month, KPMG chip in with a survey on EC modelling, polling 43 of the world's largest global insurers, with a nice spread of continents and insurer-types represented. Over 90% of respondents were Chief Actuary/CCO/CRO etc level.

With this subject being a hotter potato right now than a Jersey Royal locked in a sauna, in a tank top, in Bangkok, I've had a trawl through and found the following highlights:
  • Most reasonable business uses of EC metrics appear to be applied or planned by respondents (pricing/underwriting decisions being the straggler)
  • 40% of respondents said management understanding of EC is still limited - schematic on p9 showing the differences between 'sophisticated' Europe and 'savage' RoW hints at some kind of Solvency II dividend, though the results are not flattering across the board.
  • Interesting schematic on implementation difficulties (p12), broken down by continent - data quality seems to have topped the list of implementation problems, which is no surprise I guess, but they neatly connect it with potential for over-reliance on expert judgement, simplifications and approximations to fill the gaps (all of which are to the detriment of a pure EC approach, at least in theory).
  • Curve fitting is the majority-used approach (58%) to deliver model outputs quicker (i.e. 'lite' modelling), with replicating portfolios and LSMC less favoured
  • Understanding around fungibility and dependency higlighted as areas for improvement
  • Two-thirds still not allowing for sovereign debt risk in their EC calcs - I admire the persistency!
  • Very interesting bit towards the back on effectively projecting EC, the holy grail for anyone in the ORSA space right now. While they loosely refer to the business planning horizon as "typically 3 years" (I've seen longer than that before breakfast, lads!), the point made is perfectly valid, namely that methodologies for this kind of projection are in their infancy.
  • Finally, a nugget on Operational Risk Modelling (which I only touched on yesterday!), by some distance the least effective part of respondent's EC frameworks. They do note that 60% of EU respondents have moved to stochastic-based Op risk models with all bar one using expert judgement to calibrate them! They also bemoan the lack of credible data and subjectivity around cause/effect/latency of op risk events.
I guess the most surprising element of the document is how cagily it is written, as if EC modelling of risk profiles still has something to prove against, say, arbitrary and aimlessly prudent margins - the authors acknowledge that, if done badly, EC modelling is an accident waiting to happen, which supports the "rigour" being applied by the FSA when pre-assessing the UK insurance industry's model applications.

Also surprised that more reference to ratings agency demands wasn't made, particularly with that element seemingly influencing EC calibration points in the EU right now (hands up if you're at 1-in-2,000!)

Monday, 20 August 2012

Operational Risk - Scenario analysis and best practice

Short and sweet - couple of interesting papers in the Op Risk space which should help anyone working on operational risk scenarios or indeed brushing up on best practices.

Milliman start off with this scene setter on approaches being adopted in order to bypass the rather broad brush (and I suspect in some cases, financially onerous) standard formula approach to calculating the Op Risk SCR element. They of course touch on the old-but-legitimate complaint around imput data quality if one wants to model their capital requirement rather than sketch it on the back of EIOPA's fag packet.

While they take the opportunity to applaud the efforts of those creating a database of scenarios, or indeed using the ORIC database, they ultimately come down on the Bayesian side of the debate, which I suspect is a touch too rich for most people's blood, but those of us with deep pockets (and large Op Risk SCR totals!) may give that a stab.

The second piece came from Corven around best Op Risk practices from other industries, and how they could be adopted by the Financial Services industry. Not much of the research is actually published yet (and the main meat of their published findings is hidden behind FT's paywall), but I found it particularly interesting to see which industries were cited as areas where Financial Services could learn from.

Some good interim stats (full report to follow in October), including;
  • All respondents to date trying to tie in op risk performance with compensation
  • Regulatory hounding appears to have inspired 64% of respondents to inprove Op Risk management
  • Full root cause analysis only conducted by 38% of respondents upon a "major risk failure" - woolly words aside, that is not impressive at all.
  • Responses to major risk incidents overwhelmingly look to amend processes and systems, not the people and capabilities that inevitably led to them!
The example of air crews being compelled to point out senior staff members' inadequacies is a particularly powerful example of bottom-up op risk mitigation, though I struggle to see its application in financial services. However, it was also strange to see the Oil industry also cited as a best practitioner - the major risk events in that industry surely draw parallels with financial services at their most grasping over recent years.

Monday, 11 June 2012

Risk Appetite benchmarking study - Grant Thornton

Very neat release from Grant Thornton this week, trying to capture some of the juicy Risk Appetite space which corporate governance codes and indeed Solvency II is making particularly profitable.

The sample is reported on their website to be 43 CEO/Director-types from the London Market, hence the content isn't quite as picture perfect as a conventional life insurer may want, but the findings are very important for anyone who is in the thick of Risk Appetite Framework construction, refresh or replacement as we speak (which must be the majority of you, surely!).

Both ORSA and a general interest in understanding what one's neighbours were doing in the area of Risk Appetite Frameworks and Statements seems to have been the driver to participate, although strangely the corporate governance angle (whether it be UK code or indeed non-Solvency II EU activity) wasn't mentioned.

Elsewhere of note, I spotted;
  • Average 12-18 months to get a Risk Appetite Framework (RAF) signed off - from a standing start, that seems fair, bearing in mind the educational aspect is one which, from my experience, is massively constrained by pre-existing committee agendas which simply cannot (or perhaps will not) yield some additional time for coaching.
  • Wonderful split in perceptions between actuarial-led and risk-led RAFs. The actuaries are perceived to lend more weight to insurance and investment risk, use more quant in their synthesis, and as a result deploy the frameworks more effectively. The risk profession came off worse in this head-to-head, with a stringer focus on qualitative elements and operational risk. The actuarial approach was also observed to exert "more discipline, and in general demonstrated greater progress". Never mind, we'll win the war!
  • Instances where Risk Appetite Statements have been flexed in order to accomodate business cases which have been successfully presented to the Board. I seem to remember flexed limits (off the back of successful lobbying/inept challenging) causing Lehmans a problem or two a few years back...
  • Approaching the setting of limits in the Risk Appetite Statements from bottom up, using business plan content, appears to have been more successful than cascading down. Some debate about whether the tail should wag the dog here is also included.
  • Approach to Credit and Operational Risk was observed to be application of fixed limits for losses, as these are seen to be necessary evils in order to be in business.
  • Use of previous years results in setting some limits/tolerance levels seems to be common practice - not sure how that tallies with top-down/bottom-up approaches to rolling a framework out, but one might expect to see some element of projections in this activity.
  • Sadly, insurers were observed to be afraid to fall behind or indeed trailblaze on the matter due to fears of additional regulatory scrutiny. I truly hope that is a misplaced fear, and not a by-product of the zealousness of the pre-Solvency II regulatory interface.
Thanks GT, looking forward to the next one, but with a wider sample and a few more stats ideally.

Wednesday, 13 July 2011

FSA - Operational Risk Framework enhancement consultation for banks

Consultation alert! Anyone who likes their operational risk benchmarking and best practice will want to give this document released today their attention (divided though it may be by being Bank-oriented).

Whilst "the aim of this guidance is to assist supervisors in assessing and challenging firms' documentation and the way it is managed" as well as to "help Operational Risk functions at firms to meet the standardised approach requirements for operational risk", it actually reads like a best practice list which, in the shadow of Basel's efforts last week, is worthy of the attention of the insurance industry. My take was;
  • Heavy on document maintenance (definition/descriptions/formula consistency)
  • "Good practice" to map SYSC/BIPRU references to op risk documentation "on a periodic basis"
  • Firm wide terms of reference, naming conventions and mutual references in documents noted as "good practice"
  • Created 3 tiers of a "possible document hierarchy" which could be linked together in a firm-wide documentation map
  • "Good practice" to implement controls around documentation ownership, and a central register of all documentation "could be practicable"
  • Very unwieldy list of categories recommended for the document register
  • "Recommended" that firms identify all policies and documents that are critical to the operation of the firm
  • Practice of sticking revised documents on shared drives/intranet pages actively smacked down, advocating a proportional approach ranging from memos to formal training workshops
  • Advocates KRIs (or KCIs, which was a new one on me!) for documentation monitoring - I actually quite liked their suggestions
  • Recommends that firms meet a "use test" for documentation
Not seeing exactly how any of this might transfer over to the Insurance industry, but it doesn't augur well for anyone without SharePoint!

Friday, 1 July 2011

Basel Committee - Principles for sound management of Operational Risk refresh

The Basel Committee pushed out their new, improved version of the Operational Risk guidance for the Banking Industry - as I suspect the insurance industry will ferret through this for the good bits, I had a good look through myself.

The 11 principles they settle on are all logical - highlights next to each;

The board of directors should take the lead in establishing a strong risk management culture.

  • Recommends a code of conduct or "ethics policy"
  • Compensation should be aligned to the bank's risk appetite/tolerance statement
  • Training needs reflected by seniority, role and responsibilities of staffBanks should develop, implement and maintain a Framework that is fully integrated into the bank’s overall risk management processes.
    • Outputs of Op risk framework should be incorporated into the strategy development process (if used for capital allocation, this would be inevitable)
    • Framework should define Op Risk and Op Loss in a comprehensive board approved policy
    The board of directors should establish, approve and periodically review the Framework
    • Board should ensure that management avail themselves of best practice as it develops

    • Ticklists for what the board should be considering in context of this principle
    The board of directors should approve and review a risk appetite and tolerance statement for operational risk Senior management should develop for approval by the board of directors a clear, effective and robust governance structure
    • More ticklists for achievement
    • Provides for two-tier risk committee scrutiny based on "nature scale and complexity" (either an ERM committee considering reports from Market Credit and Op, or a flatter approach for smaller banks)

    • Standard list of identification/assessment tools, which are in use in most industries, so serve yourself if you are not familiar
    • Optional piece on "capture and [monitoring of] operational risk conttributions to credit and market risk related lossess in order to obtain a more complete view of operational risk exposure" - I like this piece on "border risks", and it is important from the Solvency II angle for correlation matrices
    • Differentiate KRIs and KPIs in a way I haven't seen previously
    Senior management should ensure that there is an approval process for all new products, activities, processes and systems that fully assesses operational risk. Senior management should implement a process to regularly monitor operational risk profiles and material exposures to losses.
    • "Reports should be manageable in scope and volume"! I suspect this will delight the Op Risk staff as well as the Board's, right up to the point at which something critical is left out on the principle of keeping the reporting 'manageable'.
    • Smal;l ticklist of content that "should" be included in Op Risk reports
    Banks should have a strong control environment that utilises policies, processes and systems; appropriate internal controls; and appropriate risk mitigation and/or transfer strategies.
    • Lots of ticklists on policy and process content that "should" be in place
    • Technology and Outsourcing risk given special treatment as far as internal controls go
    • Board of Directors expected to "determine the maximum loss exposure the bank is willing and has financial capacity to assume, and should perform an annual review of the bank's risk and insurance management programme".

    • Ticklists for continuity management processes and considerations
    Banks should have business resiliency and continuity plans in place A bank’s public disclosures should allow stakeholders to assess its approach to operational risk management.
    • No obligations for public disclosure of Op risk loss events
    • Disclosure focused mostly on detail of the Op Risk framework itself, ostensibly that it should be detailed enough to let the public make an informed judgement on its adequacy.

    • Ticklist for new product/activity/process/system consideration provided - noted as "should be considered"
    Senior management should ensure the identification and assessment of the operational risk inherent in all material products, activities, processes and systems
Strong culture unequivocally linked to "ethical business pactices"

Tuesday, 17 May 2011

Operational RIsk data - ORIC and the future

Spotted this ORIC slideshow from May's Solvency II presentation for the IRM. Not too much to glean from the light content other than the last slide, which gives a glimpse into the future of ORIC's work (develop consensus for industry use, improve data standards, develop best practices, increase usage levels).

All very noble aims, and can only aid the move towards stochastic modelling of Op Risk for the internal model users amongst us.