Stress Testing Operational Risk
|
|
|
- Thomasine Lamb
- 10 years ago
- Views:
Transcription
1 Stress Testing Operational Risk Ali Samad-Khan OpRisk Advisory LLC Paper presented at the Expert Forum on Advanced Techniques on Stress Testing: Applications for Supervisors Hosted by the International Monetary Fund Washington, DC May 2-3, 2006 The views expressed in this paper are those of the author(s) only, and the presence of them, or of links to them, on the IMF website does not imply that the IMF, its Executive Board, or its management endorses or shares the views expressed in the paper.
2 Stress Testing Operational Risk Expert Forum on Advanced Techniques on Stress Testing: Applications for Supervisors Washington, D.C. May 3, 2006 Ali Samad-Khan OpRisk Advisory
3 OpRisk Advisory Company Profile Copyright , OpRisk Advisory LLC. All rights reserved. 2
4 Agenda I. Introduction II. What is Operational Risk? III. Defining & Classifying Operational Risks IV. Risk Assessment V. VaR Modeling in Operational Risk VI. Stress Testing in the Context of Operational Risk Management VII. Summary & Conclusions Copyright , OpRisk Advisory LLC. All rights reserved. 4
5 INTRODUCTION
6 Operational risk is one of the three major risks that banks face. Credit risk is generally thought to be a bank s biggest risk. Other Risks Market Risk Credit Risk Operational Risk Copyright , OpRisk Advisory LLC. All rights reserved. 6
7 But what s driving credit risk? More than 80% of our Credit Risk is really just Operational Risk. Senior Risk Officer, Large German Bank Copyright , OpRisk Advisory LLC. All rights reserved. 7
8 Large headline losses have caused banks and regulators to realize that operational risk is one of the most significant risks that banks face. FIRM NAME Nomura Securities International Incorporated ABN Amro Holding NV Merrill Lynch & Company BUSINESS LINE - LEVEL 1 LOSS AMOUNT ($M) Copyright , OpRisk Advisory LLC. All rights reserved. 8 DESCRIPTION Trading & Sales In July 1998, Nomura Securities International Inc, the US brokerage unit of Nomura Securities of Japan, reported that it had agreed to pay $47.9M in settlement of charges stemming from the Orange County's bankruptcy lawsuit. The suit was filed against the firm for investing municipal county funds in high risk derivatives and municipal bond trading that was illegal under California law. The Securities Exchange Commission reported that Nomura was one of the brokerage firms responsible for the county's bankruptcy. Orange County claimed to have lost $1.64 billion. The SEC stated that Nomura had lent the county huge sums of money, which it reinvested in search of high returns. Nomura also supplied the risky securities favoured by then county Treasurer and Tax Collector Robert L. Citron that plunged in value when interest rates rose sharply in The SEC also charged the firm for its role in underwriting key bonds for the county and accused Citron of illegally investing in volatile securities that were unsuitable for public funds. Agency Services In November 1998, ABN Amro Holding NV, a Netherlands full services bank and Europe's eighth largest banking firm, reported that it had realized a loss of 174M guilders ($141M) due to forgery, embezzlement and fraud perpetrated by four of its former employees. The four allegedly committed about 600 fraudulent transactions, making improper use of about 30 client accounts. The bank said that after uncovering the irregularities, it fired the employees and notified law enforcement officials in February, The transactions took place within the bank's trust department, whose functions included maintaining bank accounts for 600 to 800 clients living abroad. Its products included numbered bank accounts for clients whose identities were known only within the department. Employees also executed orders solely on the basis of telephone instructions. The bank said that, upon inspection, some packages in custody that supposedly contained diamonds turned out to contain false diamonds, and diamond shipment orders given by clients were sometimes accompanied by falsified invoices. Trading & Sales In December 1997, Merrill Lynch & Co, a US broker-dealer, reported that it had agreed to pay $100M in fines to settle charges of price fixing on the Nasdaq stock market. The Securities and Exchange Commission fined 30 Wall Street firms more than $910M in this regard. The lawsuit alleged that as many as a million investors lost billions of dollars because of collusion among the firms between 1989 and This collusion caused an artificial widening of spreads, the gap between the purchase and selling prices of stocks, thereby adding to dealer profits. The settlement also required the firms to improve trading policies and procedures. The case began in 1994, when the SEC and the Justice Department accused major Nasdaq dealers of conspiring to fix the bid-ask spreads on stock quotes resulting in extra costs to ordinary investors on their stock trades. Under the settlement, the brokerage firms with the most alleged violations agreed to pay higher fines. In making its original case, the SEC charged that major Nasdaq dealers harassed or refused to trade with others who tried to offer investors a better price for a stock. WGZ Bank Trading & Sales In October 1998, Westdeutsche Genossenschafts-Zentralbank AG (WGZ-Bank), a German commercial bank, reported that it had realised a loss of DM 377 ($200.4M) due to computer fraud perpetrated by two employees over the past sixteen months. The bank has initiated a case against the two employees, who used a loophole in the bank's computer system for currency derivatives. They entered unrealistic intermediary values, which the system failed to document and managed to realise the profits in their derivative securities. The fraud was only discovered after the installation of an updated system, required under a new law, which eliminates the opportunity for such manipulation. Korea First Bank Citibank Commercial Banking Commercial Banking In April 1998, Korea First Bank, a South Korean commercial bank with operations in the US, reported that it had agreed to pay $93M in settlement of a lawsuit that charged it with wrongfully dishonoring its irrevocable letter of credits. The New York Appellate Court ruled in favour of CalEnergy Company Inc, a global energy company that manages and owns an interest in over 5000 megawatts of power generation capability among various facilities in operation, construction and development worldwide. Casecnan Water and Energy Company Inc, a subsidiary of Calenergy was executing a power project in the Philippines. Hanbo Corporation had been acting as the turnkey contractor and guarantor for the Casecnan project.kfb's letter of credit was issued as financial security for the obligations of Hanbo. The contract with Hanbo Corp. was terminated by Casecnan due to Hanbo's insolvency and other misperformance in the project, at which time Casecnan made an initial draw on the KFB letter of credit securing Hanbo's performance under the contract. Furthermore, Casecnan had made three susbsequent draws on the letter of credit, all of which were opposed by Hanbo and draws under the letter of credit were dishonoured by Korea First Bank In September 1999, Citibank, a US commercial bank with global operations and unit of Citigroup, reported that it had realized a loss of $30M due to credit fraud. The firm's UK branch was one of 20 financial institutions operating in the Middle East which were the victims of fraud. Madhav Patel, an Indian businessman, allegedly deceived the bank by using forged documents to secure letters of credit guaranteeing payment for bogus transactions. The alleged fraud came to light earlier this year when Patel's British registered firm, Solo Industries, ran into financial difficulties in the Middle East. Patel, who ran several metal smelting businesses in Dubai, secured letters of credit from the firm as well as other banks to guarantee payments on shipments of metal to the United Arab Emirates. Police believe the shipments were bogus and the money was diverted elsewhere. Patel moved to London after his business collapsed in May. He has since disappeared. Source SAS OpRisk Global Data
9 Effectively managing operational risk requires a framework designed to turn raw operational risk data into information that supports managerial decision making. MANAGEMENT Economic Profit FOUNDATION Risk strategy, tolerance Roles and responsibilities Policies and procedures Risk definition and categorization DATA/METRICS Loss data indicator data Control assessment data Risk assessment and analysis data Issue log data Follow-up action reports data INFORMATION Expected Loss how much do I lose on average? Unexpected Loss how much I could reasonably expect to lose in a bad year? Control Scores how good are the controls I have in place? Awareness of real exposures Knowledge of controls quality Cost-benefit analysis Improved risk mitigation and transfer strategies Management & Control Quality Copyright , OpRisk Advisory LLC. All rights reserved. 9
10 Risk management means first of all managing the risk reward relationship. When entering a new business one must consider reward in the context of risk. RISK REWARD Copyright , OpRisk Advisory LLC. All rights reserved. 10
11 Once an organization has invested in a business, risk management involves managing the risk-control relationship in the context of cost benefit analysis. RISK CONTROL Copyright , OpRisk Advisory LLC. All rights reserved. 11
12 Operational risk management is the process of optimizing the risk control relationship in the context of cost-benefit analysis. RISK CONTROL What type of risks do I face? Which are the largest risks? How well are these risks being managed? Copyright , OpRisk Advisory LLC. All rights reserved. 12
13 To make clear what operational risk management is really all about, we need to express it in the context of a business problem. Consider two risks: Unauthorized Trading and Money Transfer Past Audits reveal that both risks are under-controlled To address Unauthorized Trading risk one must improve segregation of duties and audit frequency. (Solution: hire four new staff; cost = $400,000 per year) To address Money Transfer risk one must improve the system (Solution: buy a new system; cost = $5 million) You have $4 million in your budget. Where do you invest your money? Copyright , OpRisk Advisory LLC. All rights reserved. 13
14 WHAT IS OPERATIONAL RISK?
15 What is the textbook definition of risk? The best way to illustrate risk is through an example. Security A Guaranteed return of 10% Security B Security C 50% probability of a 0% gain 50% probability of a 20% gain 50% probability of a 10% loss 50% probability of a 30% gain Which investment has the highest expected return? Which investment has the most risk? How much risk is there in each investment? Which security is the best investment? Copyright , OpRisk Advisory LLC. All rights reserved. 15
16 What can we conclude about risk? Risk has to do with uncertainty (where there is certainty there is no risk Security A). Risk must be measured at a level of uncertainty (confidence level, e.g., 99%). However, it is often possible to ranks risks without specifying the confidence level. We know that Security A is less risky than Security B which is less risky than Security C, even without knowing how much risk each investment poses at the 99% level. Copyright , OpRisk Advisory LLC. All rights reserved. 16
17 What else do we know about risk? Risk is neither inherently good nor bad. A risk-neutral person will consider all three investments to be of equal value. A risk lover will choose Security C because it offers the higher possible return (30%) among choices with the same expected return (10%) and because risk increases his/her utility. Because most people are risk averse, they require more reward for assuming more risk, so will choose Security A. (Equal return with no risk). Copyright , OpRisk Advisory LLC. All rights reserved. 17
18 Operational risk is the risk of a loss at a specified confidence level. Probability Total Loss Distribution Expected Loss (cost) Unexpected Loss (VaR) Mean Annual Aggregate Loss ($) 99th percentile Copyright , OpRisk Advisory LLC. All rights reserved. 18
19 Since operational risk is measured in terms of the aggregate loss, there are two components to operational risk: Frequency and Severity. This is much more challenging than modeling market or credit risk. INDIVIDUAL LOSS EVENTS RISK MATRIX FOR LOSS DATA LOSS DISTRIBUTIONS VAR CALCULATION TOTAL LOSS DISTRIBUTION 74,712,345 74,603,709 74,457,745 74,345,957 74,344, , , , ,342 94,458 EMPLOYMENT CLIENTS, EXECUTION, BUSINESS PRACTICES & PRODUCTS & DAMAGE TO DELIVERY & DISRUPTION AND INTERN AL EXTERNAL W ORKPLACE BUSINESS PHYSICAL PROCESS SYSTEM FRAUD FRAUD SAFETY PRACTICES ASSETS MANAGEMENT FAILURES TOTAL Corporate Finance Number Mean 35,459 52,056 3,456 56,890 56,734 1,246 89,678 44,215 Standard Deviation 5,694 8,975 3,845 7,890 3, ,543 6,976 Trading & Sales Number Mean 53,189 78,084 5,184 85,335 85,101 1, ,517 66,322 Standard Deviation 8,541 13,463 5,768 11,835 5, ,315 10,464 Retail Banking Number Mean 47,870 70,276 4,666 76,802 76,591 1, ,065 59,690 Standard Deviation 7,687 12,116 5,191 10,652 4, ,783 9,417 Commercial Banking Number Mean 43,083 63,248 4,199 69,121 68,932 1, ,959 53,721 Standard Deviation 6,918 10,905 4,672 9,586 4, ,605 8,476 Payment & Settlements Number Mean 38,774 56,923 3,779 62,209 62,039 1,363 98,063 48,349 Standard Deviation 6,226 9,814 4,205 8,628 3, ,744 7,628 Agency Services Number Mean 46,529 68,308 4,535 74,651 74,446 1, ,675 58,018 Standard Deviation 7,472 11,777 5,045 10,353 4, ,893 9,154 Asset Management Number Mean 41,876 61,477 4,081 67,186 67,002 1, ,908 52,217 Standard Deviation 6,725 10,599 4,541 9,318 4, ,804 8,238 Retail Brokerage Number Mean 50,252 73,773 4,898 80,623 80,402 1, ,090 62,660 Standard Deviation Insurance Number Mean 45,226 66,395 4,408 72,561 72,362 1, ,381 56,394 Standard Deviation 7,262 11,447 4,904 10,063 4, ,028 8,897 Total Number , ,806 Mean 45,653 67,021 4,450 73,245 73,044 1, ,459 56,926 Standard Deviation 7,331 11,555 4,950 10,158 4, ,311 8,981 P P 0 Frequency of events Severity of loss 4 VaR Calculator e.g., Monte Carlo Simulation Engine Risk Mean 99th Percentile Annual Aggregate Loss ($) Copyright , OpRisk Advisory LLC. All rights reserved. 19
20 DEFINING & CLASSIFYING OPERATIONAL RISKS
21 REVIEW: Operational risk is one of the three major risks that banks face. Credit risk is generally thought to be a bank s biggest risk. Other Risks Market Risk Credit Risk Operational Risk Copyright , OpRisk Advisory LLC. All rights reserved. 21
22 What comprises operational risk? Transaction Execution Settlement Technological Inadequate Supervision Information Key Man Lack of Resources Reputation Relationship Theft Criminal Insufficient Training Compliance Poor Management Unauthorized Activities Legal Fixed Cost Structures Fraud Fiduciary Customer Business Interruption Rogue Trader Physical Assets Sales Practices People Copyright , OpRisk Advisory LLC. All rights reserved. 22
23 Effective ORM requires a structured way of thinking about risk a meaningful way of conceptualizing the issues and a common language. What are the standards for defining and categorizing operational risk? Management Information Statistical Consistency Logical Consistency Grouping of like items (homogenous risk types) to facilitate the management of similar risks which have similar controls Mutually exclusive (uncorrelated) and exhaustive (comprehensive) homogenous distributions Must be based on natural boundaries; examples must be consistent with definitions Copyright , OpRisk Advisory LLC. All rights reserved. 23
24 The universe of operational risk is best understood in terms of its three dimensions: causes, events and consequences. CAUSES EVENTS CONSEQUENCES Inadequate segregation of duties Insufficient training Internal Fraud Legal Liability Regulatory, Compliance & Taxation Penalties Lack of management supervision Inadequate auditing procedures External Fraud Execution, Delivery & Process Management Loss or Damage to Assets Restitution EFFECTS Monetary Losses Inadequate security measures Clients, Products & Business Practices Loss of Recourse Damage to Physical Assets Write-down Poor systems design Poor HR policies Business Disruption & System Failures Employment Practices & Workplace Safety Reputation Business Interruption OTHER IMPACTS Forgone Income Copyright , OpRisk Advisory LLC. All rights reserved. 24
25 Upon further analysis, it appears that causes consist of both contributory factors and events (contributory factors and events together cause losses). CAUSES EFFECTS CONTRIBUTORY FACTORS EVENTS CONSEQUENCES Inadequate segregation of duties Insufficient training Lack of management supervision Inadequate auditing procedures Inadequate security measures Poor systems design Poor HR policies Internal Fraud External Fraud Execution, Delivery & Process Management Clients, Products & Business Practices Accidents & Natural Disasters Systems Employment Practices & Workplace Safety Copyright , OpRisk Advisory LLC. All rights reserved. 25 Legal Liability Regulatory, Compliance & Taxation Penalties Loss or Damage to Assets Restitution Loss of Recourse Write-down Reputation Business Interruption Monetary Losses Non Monetary Losses (Forgone Income)
26 The starting point for diagnostic analysis is the business line event risk matrix. EVENT RISK MATRIX INTERNAL FRAUD EXTERNAL FRAUD EMPLOYMENT PRACTICES & WORKPLACE SAFETY CLIENTS, PRODUCTS & BUSINESS PRACTICES DAMAGE TO PHYSICAL ASSETS EXECUTION, DELIVERY & PROCESS MANAGEMENT BUSINESS DISRUPTION AND SYSTEM FAILURES TOTAL Corporate Finance Number Mean 35,459 52,056 3,456 56,890 56,734 1,246 89,678 44,215 Standard Deviation 5,694 8,975 3,845 7,890 3, ,543 6,976 Trading & Sales Number Mean 53,189 78,084 5,184 85,335 85,101 1, ,517 66,322 Standard Deviation 8,541 13,463 5,768 11,835 5, ,315 10,464 Retail Banking Number Mean 47,870 70,276 4,666 76,802 76,591 1, ,065 59,690 Standard Deviation 7,687 12,116 5,191 10,652 4, ,783 9,417 Commercial Banking Number Mean 43,083 63,248 4,199 69,121 68,932 1, ,959 53,721 Standard Deviation 6,918 10,905 4,672 9,586 4, ,605 8,476 Payment & Settlements Number Mean 38,774 56,923 3,779 62,209 62,039 1,363 98,063 48,349 Standard Deviation 6,226 9,814 4,205 8,628 3, ,744 7,628 Agency Services Number Mean 46,529 68,308 4,535 74,651 74,446 1, ,675 58,018 Standard Deviation 7,472 11,777 5,045 10,353 4, ,893 9,154 Asset Management Number Mean 41,876 61,477 4,081 67,186 67,002 1, ,908 52,217 Standard Deviation 6,725 10,599 4,541 9,318 4, ,804 8,238 Retail Brokerage Number Mean 50,252 73,773 4,898 80,623 80,402 1, ,090 62,660 Standard Deviation Insurance Number Mean 45,226 66,395 4,408 72,561 72,362 1, ,381 56,394 Standard Deviation 7,262 11,447 4,904 10,063 4, ,028 8,897 Total Number , ,484 Mean 45,653 67,021 4,450 73,245 73,044 1, ,459 56,926 Standard Deviation 7,331 11,555 4,950 10,158 4, ,311 8,981 Copyright , OpRisk Advisory LLC. All rights reserved. 26
27 Contributory factors are things that should have been done, but weren't done (nothing has necessarily happened). Events represent something that happened (e.g., a loss). CAUSES EFFECTS WHAT DIDN T HAPPEN Inadequate segregation of duties Insufficient training Lack of management supervision Inadequate auditing procedures Inadequate security measures Poor systems design Poor HR policies WHAT HAPPENED Internal Fraud External Fraud Execution, Delivery & Process Management Clients, Products & Business Practices Accidents & Natural Disasters Systems Employment Practices & Workplace Safety Copyright , OpRisk Advisory LLC. All rights reserved. 27 CONSEQUENCES Legal Liability Regulatory, Compliance & Taxation Penalties Loss or Damage to Assets Restitution Loss of Recourse Write-down Reputation Business Interruption Monetary Losses Non Monetary Losses (Forgone Income)
28 Contributory factors are really control issues. Events represent classes of inherent risk types. Contributory factors and consequences can be controlled. Events are not controllable directly. CAUSES EFFECTS CONTROL RISK CONSEQUENCE Inadequate segregation of duties Insufficient training Lack of management supervision Inadequate auditing procedures Inadequate security measures Poor systems design Poor HR policies Internal Fraud External Fraud Execution, Delivery & Process Management Clients, Products & Business Practices Accidents & Natural Disasters Systems Employment Practices & Workplace Safety Copyright , OpRisk Advisory LLC. All rights reserved. 28 Legal Liability Regulatory, Compliance & Taxation Penalties Loss or Damage to Assets Restitution Loss of Recourse Write-down Reputation Business Interruption Monetary Losses Non Monetary Losses (Forgone Income)
29 Operational risk management is the process of optimizing the risk control relationship in the context of cost-benefit analysis. RISK CONTROL What type of risks do I face? Which are the largest risks? How well are these risks being managed? Copyright , OpRisk Advisory LLC. All rights reserved. 29
30 RISK ASSESSEMENT
31 Risk can also be assessed using a likelihood-impact approach. This approach has been well documented by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Copyright , OpRisk Advisory LLC. All rights reserved. 31 Source: COSO
32 The COSO view of risk assessment is based on the likelihood and impact of a specific type of event; the output is probability-weighted impact. The high risk area is in the top right corner of the matrix. COSO High (3) LIKELIHOOD Med (2) Low (1) COSO Low (1) Med (2) High (3) IMPACT Likelihood x Impact = Risk Copyright , OpRisk Advisory LLC. All rights reserved. 32
33 Under the risk management industry approach, the high risk area is the bottom right cell in the matrix. BASEL II LIKELIHOOD High (3) Med (2) Low (1) n/a COSO n/a n/a Low (1) Med (2) High (3) IMPACT Copyright , OpRisk Advisory LLC. All rights reserved. 33
34 When compared, there are significant differences. BASEL II COSO High (3) n/a n/a High (3) Phantom Risks Likelihood Med (2) Low (1) COSO n/a Likelihood Med (2) Low (1) COSO Real Risks Low (1) Med (2) High (3) Impact Low (1) Med (2) High (3) Impact Copyright , OpRisk Advisory LLC. All rights reserved. 34
35 Using likelihood-impact analysis one can calculate risk results. Likelihood x Impact = Risk Risk 1 : 10% x $10,000 = $1,000 Copyright , OpRisk Advisory LLC. All rights reserved. 35
36 Using likelihood-impact analysis one can calculate more than one outcome. Likelihood x Impact = Risk Risk 1 : 10% x $10,000 = $1,000 Risk 2 : 1% x $50,000 = $ 500 Copyright , OpRisk Advisory LLC. All rights reserved. 36
37 Using likelihood-impact analysis one can calculate multiple outcomes. Likelihood x Impact = Risk Risk 1 : 10% x $10,000 = $1,000 Risk 2 : 1% x $50,000 = $ Risk 999 : 4% x $20,000 = $ 800 Risk 1000 : 20% x $ 6,000 = $1,200 Copyright , OpRisk Advisory LLC. All rights reserved. 37
38 The many probability and impact combinations represent a continuum. Probability (20%, $6,000) (10%, $10,000) (4%, $20,000) (1%, $50,000) Impact Copyright , OpRisk Advisory LLC. All rights reserved. 38
39 The severity distribution is a plot of all likelihood and impact combinations; loss severity is only one component of aggregate loss. INDIVIDUAL LOSS EVENTS RISK MATRIX FOR LOSS DATA LOSS DISTRIBUTIONS VAR CALCULATION TOTAL LOSS DISTRIBUTION 74,712,345 74,603,709 74,457,745 74,345,957 74,344, , , , ,342 94,458 EMPLOYMENT CLIENTS, EXECUTION, BUSINESS PRACTICES & PRODUCTS & DAMAGE TO DELIVERY & DISRUPTION AND INTERN AL EXTERNAL W ORKPLACE BUSINESS PHYSICAL PROCESS SYSTEM FRAUD FRAUD SAFETY PRACTICES ASSETS MANAGEMENT FAILURES TOTAL Corporate Finance Number Mean 35,459 52,056 3,456 56,890 56,734 1,246 89,678 44,215 Standard Deviation 5,694 8,975 3,845 7,890 3, ,543 6,976 Trading & Sales Number Mean 53,189 78,084 5,184 85,335 85,101 1, ,517 66,322 Standard Deviation 8,541 13,463 5,768 11,835 5, ,315 10,464 Retail Banking Number Mean 47,870 70,276 4,666 76,802 76,591 1, ,065 59,690 Standard Deviation 7,687 12,116 5,191 10,652 4, ,783 9,417 Commercial Banking Number Mean 43,083 63,248 4,199 69,121 68,932 1, ,959 53,721 Standard Deviation 6,918 10,905 4,672 9,586 4, ,605 8,476 Payment & Settlements Number Mean 38,774 56,923 3,779 62,209 62,039 1,363 98,063 48,349 Standard Deviation 6,226 9,814 4,205 8,628 3, ,744 7,628 Agency Services Number Mean 46,529 68,308 4,535 74,651 74,446 1, ,675 58,018 Standard Deviation 7,472 11,777 5,045 10,353 4, ,893 9,154 Asset Management Number Mean 41,876 61,477 4,081 67,186 67,002 1, ,908 52,217 Standard Deviation 6,725 10,599 4,541 9,318 4, ,804 8,238 Retail Brokerage Number Mean 50,252 73,773 4,898 80,623 80,402 1, ,090 62,660 Standard Deviation Insurance Number Mean 45,226 66,395 4,408 72,561 72,362 1, ,381 56,394 Standard Deviation 7,262 11,447 4,904 10,063 4, ,028 8,897 Total Number , ,806 Mean 45,653 67,021 4,450 73,245 73,044 1, ,459 56,926 Standard Deviation 7,331 11,555 4,950 10,158 4, ,311 8,981 P Frequency of events P Severity of loss 4 VaR Calculator e.g., Monte Carlo Simulation Engine Mean 99th Percentile Annual Aggregate Loss ($) Copyright , OpRisk Advisory LLC. All rights reserved. 39
40 What is the difference between the COSO and AS/NZS 4360? COSO AS/NZS 4360 High (3) Likelihood Med (2) Frequency Low (1) Low (1) Med (2) High (3) Impact Impact Copyright , OpRisk Advisory LLC. All rights reserved. 40
41 Additional comments about likelihood-impact analysis. What's the difference between a risk event and a loss event? There is no such thing as a risk event. An event is an incident that has happened; if it results in a loss then it becomes a loss event. Risk is the level of uncertainty surrounding an event or series of events. Likelihood-impact analysis allows you to measure the probability weighted damage from a specific event the cost not the risk surrounding the event and certainly not the aggregate risk from a class of events. Likelihood-impact analysis is more appropriate for crisis management than risk management. In crisis management one is trying to measure the magnitude of a potential loss from a specific, pre-defined event that is on the verge of taking place. Copyright , OpRisk Advisory LLC. All rights reserved. 41
42 A high likelihood high impact scenario: You are standing on the train tracks. 90% chance you will be hit by a train; impact $1,000,000. There can be a high likelihood-high impact scenario situations, but not a high likelihood-high severity class of events. Likelihood-impact analysis allows you to measure the probability weighted impact of a specific event in other words the cost or damage from the event ($900,000). The risk represents the uncertainty surrounding the $900,000 damage estimate. As likelihood approaches 1.0 (100%), the event becomes certain and the risk goes to zero. Likelihood and Frequency mean two very different things. Copyright , OpRisk Advisory LLC. All rights reserved. 42
43 The actuarial approach. INDIVIDUAL LOSS EVENTS RISK MATRIX FOR LOSS DATA LOSS DISTRIBUTIONS VAR CALCULATION TOTAL LOSS DISTRIBUTION 74,712,345 74,603,709 74,457,745 74,345,957 74,344, , , , ,342 94,458 EMPLOYMENT CLIENTS, EXECUTION, BUSINESS PRACTICES & PRODUCTS & DAMAGE TO DELIVERY & DISRUPTION AND INTERN AL EXTERNAL W ORKPLACE BUSINESS PHYSICAL PROCESS SYSTEM FRAUD FRAUD SAFETY PRACTICES ASSETS MANAGEMENT FAILURES TOTAL Corporate Finance Number Mean 35,459 52,056 3,456 56,890 56,734 1,246 89,678 44,215 Standard Deviation 5,694 8,975 3,845 7,890 3, ,543 6,976 Trading & Sales Number Mean 53,189 78,084 5,184 85,335 85,101 1, ,517 66,322 Standard Deviation 8,541 13,463 5,768 11,835 5, ,315 10,464 Retail Banking Number Mean 47,870 70,276 4,666 76,802 76,591 1, ,065 59,690 Standard Deviation 7,687 12,116 5,191 10,652 4, ,783 9,417 Commercial Banking Number Mean 43,083 63,248 4,199 69,121 68,932 1, ,959 53,721 Standard Deviation 6,918 10,905 4,672 9,586 4, ,605 8,476 Payment & Settlements Number Mean 38,774 56,923 3,779 62,209 62,039 1,363 98,063 48,349 Standard Deviation 6,226 9,814 4,205 8,628 3, ,744 7,628 Agency Services Number Mean 46,529 68,308 4,535 74,651 74,446 1, ,675 58,018 Standard Deviation 7,472 11,777 5,045 10,353 4, ,893 9,154 Asset Management Number Mean 41,876 61,477 4,081 67,186 67,002 1, ,908 52,217 Standard Deviation 6,725 10,599 4,541 9,318 4, ,804 8,238 Retail Brokerage Number Mean 50,252 73,773 4,898 80,623 80,402 1, ,090 62,660 Standard Deviation Insurance Number Mean 45,226 66,395 4,408 72,561 72,362 1, ,381 56,394 Standard Deviation 7,262 11,447 4,904 10,063 4, ,028 8,897 Total Number , ,806 Mean 45,653 67,021 4,450 73,245 73,044 1, ,459 56,926 Standard Deviation 7,331 11,555 4,950 10,158 4, ,311 8,981 P Frequency of events P Severity of loss 4 VaR Calculator e.g., Monte Carlo Simulation Engine Mean 99th Percentile Annual Aggregate Loss ($) Copyright , OpRisk Advisory LLC. All rights reserved. 43
44 Likelihood-impact analysis viewed in an actuarial context. INDIVIDUAL LOSS EVENTS RISK MATRIX FOR LOSS DATA LOSS DISTRIBUTIONS VAR CALCULATION TOTAL LOSS DISTRIBUTION 74,712,345 74,603,709 74,457,745 74,345,957 74,344, , , , ,342 94,458 EMPLOYMENT CLIENTS, EXECUTION, BUSINESS PRACTICES & PRODUCTS & DAMAGE TO DELIVERY & DISRUPTION AND INTERN AL EXTERNAL W ORKPLACE BUSINESS PHYSICAL PROCESS SYSTEM FRAUD FRAUD SAFETY PRACTICES ASSETS MANAGEMENT FAILURES TOTAL Corporate Finance Number Mean 35,459 52,056 3,456 56,890 56,734 1,246 89,678 44,215 Standard Deviation 5,694 8,975 3,845 7,890 3, ,543 6,976 Trading & Sales Number Mean 53,189 78,084 5,184 85,335 85,101 1, ,517 66,322 Standard Deviation 8,541 13,463 5,768 11,835 5, ,315 10,464 Retail Banking Number Mean 47,870 70,276 4,666 76,802 76,591 1, ,065 59,690 Standard Deviation 7,687 12,116 5,191 10,652 4, ,783 9,417 Commercial Banking Number Mean 43,083 63,248 4,199 69,121 68,932 1, ,959 53,721 Standard Deviation 6,918 10,905 4,672 9,586 4, ,605 8,476 Payment & Settlements Number Mean 38,774 56,923 3,779 62,209 62,039 1,363 98,063 48,349 Standard Deviation 6,226 9,814 4,205 8,628 3, ,744 7,628 Agency Services Number Mean 46,529 68,308 4,535 74,651 74,446 1, ,675 58,018 Standard Deviation 7,472 11,777 5,045 10,353 4, ,893 9,154 Asset Management Number Mean 41,876 61,477 4,081 67,186 67,002 1, ,908 52,217 Standard Deviation 6,725 10,599 4,541 9,318 4, ,804 8,238 Retail Brokerage Number Mean 50,252 73,773 4,898 80,623 80,402 1, ,090 62,660 Standard Deviation Insurance Number Mean 45,226 66,395 4,408 72,561 72,362 1, ,381 56,394 Standard Deviation 7,262 11,447 4,904 10,063 4, ,028 8,897 Total Number , ,806 Mean 45,653 67,021 4,450 73,245 73,044 1, ,459 56,926 Standard Deviation 7,331 11,555 4,950 10,158 4, ,311 8,981 P Frequency of events P Severity of loss 4 VaR Calculator e.g., Monte Carlo Simulation Engine Mean 99th Percentile Annual Aggregate Loss ($) Copyright , OpRisk Advisory LLC. All rights reserved. 44
45 VAR MODELING IN OPERATIONAL RISK
46 The two relevant outputs are the aggregate mean (EL) and the aggregate Value at Risk (VaR or UL). INDIVIDUAL LOSS EVENTS RISK MATRIX FOR LOSS DATA LOSS DISTRIBUTIONS VAR CALCULATION TOTAL LOSS DISTRIBUTION 74,712,345 74,603,709 74,457,745 74,345,957 74,344, , , , ,342 94,458 EMPLOYMENT CLIENTS, EXECUTION, BUSINESS PRACTICES & PRODUCTS & DAMAGE TO DELIVERY & DISRUPTION AND INTERN AL EXTERNAL W ORKPLACE BUSINESS PHYSICAL PROCESS SYSTEM FRAUD FRAUD SAFETY PRACTICES ASSETS MANAGEMENT FAILURES TOTAL Corporate Finance Number Mean 35,459 52,056 3,456 56,890 56,734 1,246 89,678 44,215 Standard Deviation 5,694 8,975 3,845 7,890 3, ,543 6,976 Trading & Sales Number Mean 53,189 78,084 5,184 85,335 85,101 1, ,517 66,322 Standard Deviation 8,541 13,463 5,768 11,835 5, ,315 10,464 Retail Banking Number Mean 47,870 70,276 4,666 76,802 76,591 1, ,065 59,690 Standard Deviation 7,687 12,116 5,191 10,652 4, ,783 9,417 Commercial Banking Number Mean 43,083 63,248 4,199 69,121 68,932 1, ,959 53,721 Standard Deviation 6,918 10,905 4,672 9,586 4, ,605 8,476 Payment & Settlements Number Mean 38,774 56,923 3,779 62,209 62,039 1,363 98,063 48,349 Standard Deviation 6,226 9,814 4,205 8,628 3, ,744 7,628 Agency Services Number Mean 46,529 68,308 4,535 74,651 74,446 1, ,675 58,018 Standard Deviation 7,472 11,777 5,045 10,353 4, ,893 9,154 Asset Management Number Mean 41,876 61,477 4,081 67,186 67,002 1, ,908 52,217 Standard Deviation 6,725 10,599 4,541 9,318 4, ,804 8,238 Retail Brokerage Number Mean 50,252 73,773 4,898 80,623 80,402 1, ,090 62,660 Standard Deviation Insurance Number Mean 45,226 66,395 4,408 72,561 72,362 1, ,381 56,394 Standard Deviation 7,262 11,447 4,904 10,063 4, ,028 8,897 Total Number , ,806 Mean 45,653 67,021 4,450 73,245 73,044 1, ,459 56,926 Standard Deviation 7,331 11,555 4,950 10,158 4, ,311 8,981 P P Frequency of events Severity of loss 4 VaR Calculator e.g., Monte Carlo Simulation Engine Risk Mean 99th Percentile Annual Aggregate Loss ($) Copyright , OpRisk Advisory LLC. All rights reserved. 46
47 Internal data generally does not contain a sufficient number of the tail events to accurately describe that part of the distribution, therefore one needs to supplement internal data with external data. Number of Events Internal data cannot describe this part of the distribution Size of Loss Copyright , OpRisk Advisory LLC. All rights reserved. 47
48 What issues are present in external loss data? Data Capture Size Control Geography Media Legal Environment In publicly reported data, the larger losses are more likely to be reported than smaller losses. Larger institutions (and businesses) are likely to experience more losses than smaller institutions. These institutions are also likely to suffer larger losses. Institutions with weak controls are more likely to be represented in the database because they experience more losses. These institutions are also likely to suffer more large losses than well-controlled institutions. Risk profiles vary from region to region. Some events will be less relevant than others outside their region. Large losses are more likely to be printed than small losses. The legal system in certain countries may lead to more frequent and/or larger losses. Copyright , OpRisk Advisory LLC. All rights reserved. 48
49 Loss data needs to be adjusted for inflation and scaled for size. Inflation Adjustment: $10 million loss in 1990 = $12.4 million loss in 2001 Scale Adjustment: $10 million loss when a $2 billion (revenue) bank = $13.2 million loss when a $6 billion bank 1 Scaled Loss = L DB R R int ext n LDB = R ext = = n = R int Actual Loss experienced by bank Revenue of external firm Revenue of firm Scaling co-efficient determined by regression analysis 1 Shih, J., A. Samad-Khan and P. Medapa, Is the Size of an Operational Loss Related to Firm Size? Operational Risk Magazine (January 2000) Copyright , OpRisk Advisory LLC. All rights reserved. 49
50 Loss data contains two integrally connected pieces of information; the loss magnitude and the relative probability of the loss in the context of the distribution from which it was drawn. Before Relevance Adjustment Probability Impact Copyright , OpRisk Advisory LLC. All rights reserved. 50
51 Selecting relevant loss data points in an unscientific manner causes any information contained in the data to be lost. Modeling is about applying relevant data sets not manipulating relevant data points. After Relevance Adjustment Probability Impact Copyright , OpRisk Advisory LLC. All rights reserved. 51
52 Copyright , OpRisk Advisory LLC. All rights reserved. 52 Source FRB Boston
53 Copyright , OpRisk Advisory LLC. All rights reserved. 53 Source FRB Boston
54 Copyright , OpRisk Advisory LLC. All rights reserved. 54 Source FRB Boston
55 Internal data generally does not contain a sufficient number of the tail events to accurately describe that part of the distribution, therefore one needs to supplement internal data with external data. Number of Events Internal data cannot describe this part of the distribution Size of Loss Copyright , OpRisk Advisory LLC. All rights reserved. 55
56 From internal data we seek pivot cells those cells that have enough information to reliably calculate severity parameters. INTERNAL EVENT RISK MATRIX INTERNAL FRAUD EXTERNAL FRAUD EMPLOYMENT PRACTICES & WORKPLACE SAFETY CLIENTS, PRODUCTS & BUSINESS PRACTICES DAMAGE TO PHYSICAL ASSETS EXECUTION, DELIVERY & PROCESS MANAGEMENT BUSINESS DISRUPTION AND SYSTEM FAILURES TOTAL Corporate Finance Number Mean 35,459 52,056 3,456 56,890 56, ,678 44,215 Standard Deviation 5,694 8,975 3,845 7,890 3, ,543 6,976 Trading & Sales Number Mean 53,189 78,084 5,184 85,335 85,101 1, ,517 66,322 Standard Deviation 8,541 13,463 5,768 11,835 5, ,315 10,464 Retail Banking Number Mean 47,870 70,276 4,666 76,802 76,591 1, ,065 59,690 Standard Deviation 7,687 12,116 5,191 10,652 4, ,783 9,417 Commercial Banking Number Mean 43,083 63,248 4,199 69,121 68,932 1, ,959 53,721 Standard Deviation 6,918 10,905 4,672 9,586 4, ,605 8,476 Payment & Settlements Number Mean 38,774 56,923 3,779 62,209 62,039 1,363 98,063 48,349 Standard Deviation 6,226 9,814 4,205 8,628 3, ,744 7,628 Agency Services Number Mean 46,529 68,308 4,535 74,651 74,446 1, ,675 58,018 Standard Deviation 7,472 11,777 5,045 10,353 4, ,893 9,154 Asset Management Number Mean 41,876 61,477 4,081 67,186 67,002 1, ,908 52,217 Standard Deviation 6,725 10,599 4,541 9,318 4, ,804 8,238 Retail Brokerage Number Mean 50,252 73,773 4,898 80,623 80,402 1, ,090 62,660 Standard Deviation Insurance Number Mean 45,226 66,395 4,408 72,561 72,362 1, ,381 56,394 Standard Deviation 7,262 11,447 4,904 10,063 4, ,028 8,897 Total Number , ,484 Mean 45,653 67,021 4,450 73,245 73,044 1, ,459 56,926 Standard Deviation 7,331 11,555 4,950 10,158 4, ,311 8,981 Copyright , OpRisk Advisory LLC. All rights reserved. 56
57 It is generally understood, for example, that trading and sales is inherently high-risk, whereby retail banking is inherently high-cost. Probability Total Loss Distribution for CPBP Total Loss Distribution for EDPM VaR VaR Mean Mean 99th percentile 99th percentile Annual Aggregate Loss ($) Copyright , OpRisk Advisory LLC. All rights reserved. 57
58 To capture these relationships we estimate severity parameters across all event risk classes. EXTERNAL EVENT RISK MATRIX SEVERITY PARAMETERS IN LOG TERMS INTERNAL FRAUD EXTERNAL FRAUD EXECUTION, DELIVERY & PROCESS MANAGEMENT Corporate Finance Number Mean Standard Deviation EXTERNAL EVENT RISK MATRIX SEVERITY PARAMETERS IN RELATIVE TERMS INTERNAL FRAUD EXTERNAL FRAUD EXECUTION, DELIVERY & PROCESS MANAGEMENT Corporate Finance Number Mean Standard Deviation Copyright , OpRisk Advisory LLC. All rights reserved. 58
59 From internal data we seek pivot cells those cells that have enough information to reliably calculate severity parameters. INTERNAL EVENT RISK MATRIX INTERNAL FRAUD EXTERNAL FRAUD EMPLOYMENT PRACTICES & WORKPLACE SAFETY CLIENTS, PRODUCTS & BUSINESS PRACTICES DAMAGE TO PHYSICAL ASSETS EXECUTION, DELIVERY & PROCESS MANAGEMENT BUSINESS DISRUPTION AND SYSTEM FAILURES TOTAL Corporate Finance Number Mean 35,459 52,056 3,456 56,890 56, ,678 44,215 Standard Deviation 5,694 8,975 3,845 7,890 3, ,543 6,976 Trading & Sales Number Mean 53,189 78,084 5,184 85,335 85,101 1, ,517 66,322 Standard Deviation 8,541 13,463 5,768 11,835 5, ,315 10,464 Retail Banking Number Mean 47,870 70,276 4,666 76,802 76,591 1, ,065 59,690 Standard Deviation 7,687 12,116 5,191 10,652 4, ,783 9,417 Commercial Banking Number Mean 43,083 63,248 4,199 69,121 68,932 1, ,959 53,721 Standard Deviation 6,918 10,905 4,672 9,586 4, ,605 8,476 Payment & Settlements Number Mean 38,774 56,923 3,779 62,209 62,039 1,363 98,063 48,349 Standard Deviation 6,226 9,814 4,205 8,628 3, ,744 7,628 Agency Services Number Mean 46,529 68,308 4,535 74,651 74,446 1, ,675 58,018 Standard Deviation 7,472 11,777 5,045 10,353 4, ,893 9,154 Asset Management Number Mean 41,876 61,477 4,081 67,186 67,002 1, ,908 52,217 Standard Deviation 6,725 10,599 4,541 9,318 4, ,804 8,238 Retail Brokerage Number Mean 50,252 73,773 4,898 80,623 80,402 1, ,090 62,660 Standard Deviation Insurance Number Mean 45,226 66,395 4,408 72,561 72,362 1, ,381 56,394 Standard Deviation 7,262 11,447 4,904 10,063 4, ,028 8,897 Total Number , ,484 Mean 45,653 67,021 4,450 73,245 73,044 1, ,459 56,926 Standard Deviation 7,331 11,555 4,950 10,158 4, ,311 8,981 Copyright , OpRisk Advisory LLC. All rights reserved. 59
60 Using the pivot cell and relative parameter ratios from external data we can estimate severity parameter for all cells in a business line. INITIAL INTERNAL EVENT RISK MATRIX INTERNAL FRAUD EXTERNAL FRAUD EMPLOYMENT PRACTICES & WORKPLACE SAFETY CLIENTS, PRODUCTS & BUSINESS PRACTICES DAMAGE TO PHYSICAL ASSETS EXECUTION, DELIVERY & PROCESS MANAGEMENT Corporate Finance Number 234 Mean 3 Standard Deviation 2 BUSINESS DISRUPTION AND SYSTEM FAILURES TOTAL PARAMETER RATIOS FROM EXTERNAL EVENT RISK MATRIX Corporate Finance Number INTERNAL FRAUD EXTERNAL FRAUD EMPLOYMENT PRACTICES & WORKPLACE SAFETY CLIENTS, PRODUCTS & BUSINESS PRACTICES DAMAGE TO PHYSICAL ASSETS EXECUTION, DELIVERY & PROCESS MANAGEMENT Mean Standard Deviation BUSINESS DISRUPTION AND SYSTEM FAILURES TOTAL FINAL INTERNAL EVENT RISK MATRIX INTERNAL FRAUD EXTERNAL FRAUD EMPLOYMENT PRACTICES & WORKPLACE SAFETY CLIENTS, PRODUCTS & BUSINESS PRACTICES DAMAGE TO PHYSICAL ASSETS EXECUTION, DELIVERY & PROCESS MANAGEMENT Corporate Finance Number 234 Mean Standard Deviation BUSINESS DISRUPTION AND SYSTEM FAILURES TOTAL Copyright , OpRisk Advisory LLC. All rights reserved. 60
61 STRESS TESTING OPERATIONAL RISK
62 What is stress testing in the context of operational risk management? Stress the assumptions of the model? Distribution Assumptions Data Transferability Data Sufficiency Sources of Data Selection of Data Points Weights Based on Expert Judgment Copyright , OpRisk Advisory LLC. All rights reserved. 62
63 SUMMARY & CONCLUSIONS
64 Stress testing is important, but there are many more serious issues we face in ORM today. Many people who work in operational risk management don t understand elementary risk management concepts. Following the advice of numerous experts most banks have developed ORM frameworks based on a convoluted blend of traditional and modern ORM. Traditional ORM and Modern ORM are based on entirely different definitions, approaches, processes and methodologies. These immature methodologies are highly subjective, resource intensive and generate a huge catalog of unmanageable risks. Any prioritization of controls based on this spurious and misleading information may lead managers to enhance controls in areas that are already over-controlled and at the same time ignore areas of major control weakness. Copyright , OpRisk Advisory LLC. All rights reserved. 64
65 Where do things stand today? Many banks know their ORM programs are producing no value. But their operational risk managers refuse to admit there is a better approach. Some auditors are validating these flawed methodologies. These approved methodologies are fast becoming the standard for industry best practices. Most banks have established ORM programs only to meet Basel II compliance; currently they see no need to make improvements. A paradigm shift is necessary for banks to evolve towards modern ORM, but the industry is not moving in this direction. This will only happen if the regulators lead the way. If the regulators don t take action soon, ORM under Basel II will fail. The window of opportunity is about to close for good! Many Asian banks are leap-frogging their Western counterparts by developing programs based on Modern ORM principles. Some Western banks may fail to comply with Basel II in Asia. Copyright , OpRisk Advisory LLC. All rights reserved. 65
66 Some recommendations Provide the industry with a clear definition of the term risk. Require that this definition be used in every aspect of the bank s ORM framework (not just the VaR models). Make clear that the product of likelihood and impact is not risk, nor even the expected loss. Educate the industry on the uses and misuses of historical loss data. Require that any use of external data be based on the objective application of data sets not the subjective manipulation of individual data points. As part of the Pillar III requirements, ask banks to disclose the confidence intervals around their model results, i.e., the range of expected loss and unexpected loss estimates that could be calculated by varying any weights and assumptions based on expert judgment. Copyright , OpRisk Advisory LLC. All rights reserved. 66
67 Biographical Information Ali Samad-Khan. Ali Samad-Khan is President of OpRisk Advisory LLC. He has over nine years experience in operational risk measurement and management and more than twenty years experience in financial services. His areas of expertise include: establishing an integrated operational risk measurement and management framework, developing policies and procedures, internal loss event database design and implementation; data quality assessment, data sufficiency analysis, risk indicator identification, risk and control self assessment, disciplined scenario analysis, causal/predictive modeling, advanced VaR measurement techniques and economic capital allocation. Ali has advised dozens of the world s leading banks on operational risk measurement and management issues. His significant practical experience in this field comes from managing the implementation of more than ten major operational risk consulting engagements at leading institutions in North America, Europe and Australia. Key elements of the ORA framework and methodology have been adopted by dozens of leading financial institutions worldwide and have also been incorporated into the Basel II regulations. Ali has frequently advised the major bank regulatory authorities, including the Risk Management Group of Basel Committee on Banking Supervision, the Board of Governors of the Federal Reserve System, the Federal Reserve Bank of New York, the Financial Services Authority (UK) and the Australian Prudential Regulation Authority. He also holds seminars and workshops in North America, Europe and Asia for the national and international regulators. Prior to founding OpRisk Advisory, Ali was founder and President of OpRisk Analytics LLC, which was acquired by SAS in (From June 2003 to September 2004 Ali provided transitional support for the acquisition of OpRisk Analytics, serving as SAS Head of Global Operational Risk Strategy.) He has also worked at PricewaterhouseCoopers (PwC) in New York, where from he headed the Operational Risk Group within the Financial Risk Management Practice, in the Operational Risk Management Department at Bankers Trust as well as the Federal Reserve Bank of New York and the World Bank. Ali holds a B.A. in Quantitative Economics from Stanford University and an M.B.A. in Finance from Yale University. Articles include: Fundamental Issue in OpRisk Management, with Armin Rheinbay and Stephane Le Blevec, OpRisk and Compliance Magazine, February 2006; Why COSO is Flawed, Operational Risk Magazine, January 2005; Is the Size of an Operational Loss Related to Firm Size, with Jimmy Shih and Pat Medapa, Operational Risk Magazine, January 2000; Measuring Operational Risk, with David Gittleson, Global Trading, Fourth Quarter, Working papers include: How to Categorize Operational Losses Applying Principals as Opposed to Rules March 2002 and Categorization Analysis January Copyright , OpRisk Advisory LLC. All rights reserved. 67
Why COSO is flawed. Operational risk is one of the most. COSO not only fails to help a firm assess its
Why COSO is flawed COSO not only fails to help a firm assess its risks, it actually obfuscates the risk assessment process. By Ali Samad-Khan Ali Samad-Khan Operational risk is one of the most significant
Modelling operational risk in Banking and Insurance using @RISK Palisade EMEA 2012 Risk Conference London
Modelling operational risk in Banking and Insurance using @RISK Palisade EMEA 2012 Risk Conference London Dr Madhu Acharyya Lecturer in Risk Management Bournemouth University [email protected]
MODERN OPERATIONAL RISK MANAGEMENT
MODERN OERATIONAL RISK MANAGEMENT A comprehensive two-day masterclass led by Ali Samad-Khan and Tigran Kalberer 14-15 October 2008 Widder Hotel, Zürich 2 I Towers errin Masterclass Objectives Immense competitive,
Modern Operational Risk Management
Modern Operational Risk Management A Comprehensive Two-Day Seminar Led by Ali Samad-Khan and Prakash Shimpi Hartford, June 25 26, 2008 2 Modern Operational Risk Management SEMINAR OBJECTIVES Alarmed by
QUANTIFYING OPERATIONAL RISK Charles Smithson
This article originally appeared in the March 2000 issue of RISK QUANTIFYING OPERATIONAL RISK Charles Smithson Financial institutions recognize the importance of quantifying (and managing) operational
REGULATION 9 ON OPERATIONAL RISK MANAGEMENT. Article 1 Purpose and Scope
Pursuant to Article 35, paragraph 1.1 of the Law No. 03/L-209 on Central Bank of the Republic of Kosovo (Official Gazette of the Republic of Kosovo, No.77 / 16 August 2010), Article 20 paragraph 1.3 and
Validating Third Party Software Erica M. Torres, CRCM
Validating Third Party Software Erica M. Torres, CRCM Michigan Bankers Association Risk Management & Compliance Institute September 29, 2014 MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT
INTERNATIONAL STANDARD ON AUDITING (UK AND IRELAND) 240 THE AUDITOR S RESPONSIBILITY TO CONSIDER FRAUD IN AN AUDIT OF FINANCIAL STATEMENTS CONTENTS
INTERNATIONAL STANDARD ON AUDITING (UK AND IRELAND) 240 THE AUDITOR S RESPONSIBILITY TO CONSIDER FRAUD IN AN AUDIT OF FINANCIAL STATEMENTS CONTENTS Paragraphs Introduction... 1-3 Characteristics of Fraud...
ANTI-FRAUD POLICY Adopted August 13, 2015
ANTI-FRAUD POLICY Adopted August 13, 2015 Introduction The Board of Commissioners of the Housing Authority of the City of Muskogee (MHA) has established an anti-fraud policy to enforce controls and to
Enterprise Risk Management
Enterprise Risk Management Enterprise Risk Management Understand and manage your enterprise risk to strike the optimal dynamic balance between minimizing exposures and maximizing opportunities. Today s
Guide to Internal Control Over Financial Reporting
Guide to Internal Control Over Financial Reporting The Center for Audit Quality prepared this Guide to provide an overview for the general public of internal control over financial reporting ( ICFR ).
Fraud Prevention, Detection and Response. Dean Bunch, Ernst & Young Fraud Investigation & Dispute Services
Fraud Prevention, Detection and Response. Dean Bunch, Ernst & Young Fraud Investigation & Dispute Services Agenda Fraud Overview Fraud Prevention Fraud Detection Fraud Response Questions Page 2 Fraud Overview
The Use of Spreadsheets: Considerations for Section 404 of the Sarbanes-Oxley Act*
The Use of Spreadsheets: Considerations for Section 404 of the Sarbanes-Oxley Act* July 2004 *connectedthinking The Use of Spreadsheets: Considerations for Section 404 of the Sarbanes-Oxley Act Introduction
An operational risk management framework for managing agencies
An operational risk management framework for managing agencies John Thirlwell Director, Operational Risk Research Forum Lloyd s Risk Forum, 28 May 2004 Operational risk and its evolution Regulators and
INTERACTIVE BROKERS LLC A Member of the Interactive Brokers Group
David M. Battan Executive Vice President and General Counsel INTERACTIVE BROKERS LLC A Member of the Interactive Brokers Group 1725 EYE STREET, N.W. SUITE 300 WASHINGTON, DC 20006 TEL (202) 530-3205 July
Insurance as Operational Risk Management Tool
DOI: 10.7763/IPEDR. 2012. V54. 7 Insurance as Operational Risk Management Tool Milan Rippel 1, Lucie Suchankova 2 1 Charles University in Prague, Czech Republic 2 Charles University in Prague, Czech Republic
APPLICATION FOR SECURITIES BROKER-DEALER S PROFESSIONAL LIABILITY GENERAL INFORMATION
APPLICATION FOR SECURITIES BROKER-DEALER S PROFESSIONAL LIABILITY Instructions for Completing This Application Please read carefully and fully answer all questions and submit all requested information
LAKE COUNTY BOARD OF DD/DEEPWOOD BOARD POLICY I. SUBJECT: FALSE CLAIMS PREVENTION AND WHISTLEBLOWER PROTECTION
File: E-11 LAKE COUNTY BOARD OF DD/DEEPWOOD BOARD POLICY Reviewed and Adopted by the Board: Date: February 28, 2011 Signature on file Elfriede Roman, Superintendent I. SUBJECT: FALSE CLAIMS PREVENTION
Fraud Prevention DEFINITIONS
AD 19 Fraud Prevention Classification: Responsible Authority: Director, Finance and Administrative Services Executive Sponsor: Approval Authority: President s Council Date First Approved: NEW Date Last
Implementing an AMA for Operational Risk
Implementing an AMA for Operational Risk Perspectives on the Use Test Joseph A. Sabatini May 20, 2005 Agenda Overview of JPMC s AMA Framework Description of JPMC s Capital Model Applying Use Test Criteria
Checklist for Market Risk Management
Checklist for Market Risk Management I. Development and Establishment of Market Risk Management System by Management Checkpoints - Market risk is the risk of loss resulting from changes in the value of
Effective Techniques for Stress Testing and Scenario Analysis
Effective Techniques for Stress Testing and Scenario Analysis Om P. Arya Federal Reserve Bank of New York November 4 th, 2008 Mumbai, India The views expressed here are not necessarily of the Federal Reserve
MANAGEMENT AND PROFESSIONAL LIABILITY INSURANCE
U.S. FINPRO MANAGEMENT AND PROFESSIONAL LIABILITY INSURANCE ALTERNATIVE INVESTMENT FUNDS/HEDGE FUNDS In turbulent economic times, the importance of a well designed management and professional liability
Introduction. Contact rate Promise rate Kept rate and payment size Regulatory compliance Sustained ability to collect - 2 -
Introduction The sub-prime mortgage crisis and the crash of the housing market have created declining economic conditions for consumers. Although debt is on the rise, debt collection is now more challenging
Basel Committee on Banking Supervision. Results from the 2008 Loss Data Collection Exercise for Operational Risk
Basel Committee on Banking Supervision Results from the 2008 Loss Data Collection Exercise for Operational Risk July 2009 Requests for copies of publications, or for additions/changes to the mailing list,
Operational Risk Modeling *
Theoretical and Applied Economics Volume XVIII (2011), No. 6(559), pp. 63-72 Operational Risk Modeling * Gabriela ANGHELACHE Bucharest Academy of Economic Studies [email protected] Ana Cornelia OLTEANU
INTERACTIVE BROKERS LLC (SEC I.D. No. 8-47257)
INTERACTIVE BROKERS LLC (SEC I.D. No. 8-47257) STATEMENT OF FINANCIAL CONDITION AS OF DECEMBER 31, 2003 AND INDEPENDENT AUDITORS REPORT AND SUPPLEMENTAL REPORT ON INTERNAL CONTROL ******* Filed pursuant
PFIN 12: Buying and Selling Investments 78
PFIN 12: Buying and Selling Investments 78 12-1 Researching Investments OBJECTIVES Describe the types of financial information found in magazines, newspapers, and newsletters. Describe the type of data
PROJECT RISK MANAGEMENT
PROJECT RISK MANAGEMENT DEFINITION OF A RISK OR RISK EVENT: A discrete occurrence that may affect the project for good or bad. DEFINITION OF A PROBLEM OR UNCERTAINTY: An uncommon state of nature, characterized
LDA at Work: Deutsche Bank s Approach to Quantifying Operational Risk
LDA at Work: Deutsche Bank s Approach to Quantifying Operational Risk Workshop on Financial Risk and Banking Regulation Office of the Comptroller of the Currency, Washington DC, 5 Feb 2009 Michael Kalkbrener
Fixed Income Liquidity in a Rising Rate Environment
Fixed Income Liquidity in a Rising Rate Environment 2 Executive Summary Ò Fixed income market liquidity has declined, causing greater concern about prospective liquidity in a potential broad market sell-off
Rockhaven Capital Management, LLC 132 Rock Haven Lane Pittsburgh, PA 15228 412-260- 7917 www.rockhavencapital.com 09/30/12
Item 1 Cover Page Rockhaven Capital Management, LLC 132 Rock Haven Lane Pittsburgh, PA 15228 412-260- 7917 www.rockhavencapital.com 09/30/12 This Brochure provides information about the qualifications
Operational Risk Management Policy
Operational Risk Management Policy Operational Risk Definition A bank, including a development bank, is influenced by the developments of the external environment in which it is called to operate, as well
Part 2A of Form ADV: Firm Brochure
Part 2A of Form ADV: Firm Brochure Item 1 Cover Page A. VL Capital Management LLC 55 West Church Street Orlando, FL 32801 Mailing Address: P.O. Box 1493 Orlando, FL 32802 Phone: (407) 412-6298 Effective
Board of Directors Meeting 12/04/2010. Operational Risk Management Charter
Board of Directors Meeting 12/04/2010 Document approved Operational Risk Management Charter Table of contents A. INTRODUCTION...3 I. Background...3 II. Purpose and Scope...3 III. Definitions...3 B. GOVERNANCE...4
Cyber Risk: Global Warning? by Cinzia Altomare, Gen Re
Cyber Risk: Global Warning? by Cinzia Altomare, Gen Re Global Warning It is a matter of time before there is a major cyber attackon the global financial system and the public needs to invest heavily in
Willis Group Holdings. February 2014 I Bank of America Merrill Lynch Insurance Conference
Willis Group Holdings February 2014 I Bank of America Merrill Lynch Insurance Conference Disclaimer Important disclosures regarding forward-looking statements These presentations contain certain forward-looking
Charles Schwab Bank. 2015 Annual Dodd-Frank Act Stress Test Disclosure
Charles Schwab Bank 2015 Annual Dodd-Frank Act Stress Test Disclosure June 2015 I. Dodd-Frank Act Stress Test Results A. About Charles Schwab Bank Charles Schwab Bank (the Bank) is a wholly-owned subsidiary
Glossary of Insurance Terms: (obtained from website: http://www.iii.org/individuals/glossary/alfa.l/)
Glossary of Insurance Terms: (obtained from website: http://www.iii.org/individuals/glossary/alfa.l/) ACTUAL CASH VALUE A form of insurance that pays damages equal to the replacement value of damaged property
Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement
Understanding the Entity and Its Environment 1667 AU Section 314 Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement (Supersedes SAS No. 55.) Source: SAS No. 109.
Regulatory and Economic Capital
Regulatory and Economic Capital Measurement and Management Swati Agiwal November 18, 2011 What is Economic Capital? Capital available to the bank to absorb losses to stay solvent Probability Unexpected
Understanding Today s Enterprise Risk Management Programs
Understanding Today s Enterprise Risk Management rograms Joel Tietz, TIAA-CREF Managing Director, Enterprise Risk Management March 23, 2015 TIAA-CREF - UBLIC USE Agenda 1) Enterprise Risk Management rograms
INVESTMENT ADVISORY AGREEMENT. Horizon Investments, LLC Lifetime Income Strategy
INVESTMENT ADVISORY AGREEMENT Horizon Investments, LLC Lifetime Income Strategy This agreement (the Agreement ) for investment management services is entered into by and between HORIZON INVESTMENTS, LLC
EXAMINATION PRIORITIES FOR 2015
EXAMINATION PRIORITIES FOR 2015 I. Introduction This document identifies selected 2015 examination priorities of the Office of Compliance Inspections and Examinations ( OCIE, we or our ) of the Securities
IQTick Advisors. Form ADV Part 2A Disclosure Brochure
Form ADV Part 2A Disclosure Brochure Effective: January 4, 2013 This Disclosure Brochure provides information about the qualifications and business practices of PredictWallStreet, Inc. d/b/a ( IQTick ).
Trends Impacting HR s Role in Enterprise Risk Management
Trends Impacting HR s Role in Enterprise Risk Management INTRODUCTION The management consulting firm, Deloitte, produced an astounding report titled, Human Capital Trends 2012: Leap Ahead. The report pointed
Basel II: Operational Risk Implementation based on Risk Framework
Systems Ltd General Kiselov 31 BG-9002 Varna Tel. +359 52 612 367 Fax +359 52 612 371 email [email protected] WEB: www.eurorisksystems.com Basel II: Operational Risk Implementation based on Risk
Capital Adequacy: Advanced Measurement Approaches to Operational Risk
Prudential Standard APS 115 Capital Adequacy: Advanced Measurement Approaches to Operational Risk Objective and key requirements of this Prudential Standard This Prudential Standard sets out the requirements
Stress Testing Trading Desks
Stress Testing Trading Desks Michael Sullivan Office of the Comptroller of the Currency Paper presented at the Expert Forum on Advanced Techniques on Stress Testing: Applications for Supervisors Hosted
The Libor Scandal and Its Effects Explained
The Libor Scandal and Its Effects Explained As if the credit crisis and rogue traders were not enough to undermine the reputation of the financial services industry, along comes an issue that may dwarf
THE NEW REALITY OF RISK CYBER RISK: TRENDS AND SOLUTIONS
THE NEW REALITY OF RISK CYBER RISK: TRENDS AND SOLUTIONS Read the Marsh Risk Management Research Briefing: Cyber Risks Extend Beyond Data and Privacy Exposures To access the report, visit www.marsh.com.
Credit Union Liability with Third-Party Processors
World Council of Credit Unions Annual Conference Credit Union Liability with Third-Party Processors Andrew (Andy) Poprawa CEO, Deposit Insurance Corporation of Ontario Canada 1 Credit Union Liability with
UNITED STATES DISTRICT COURT DISTRICT OF OREGON
ROBERT L. MITCHELL (Admitted in California) [email protected] LLOYD A. FARNHAM (Admitted in California) [email protected] HELANE L. MORRISON (Admitted in California) 44 Montgomery Street, Suite 2600 San
ACE elite fraudprotector
ACE elite fraudprotector Commercial Crime Insurance Policy ACE elite fraudprotector Insurance Policy (ed. AU 09/10) It wouldn t happen to us ACE elite fraudprotector Insurance Policy Fraud is a major threat
Rothschild Visa Card Terms and Conditions
Rothschild Visa Card Terms and Conditions These Rothschild Visa Card Terms and Conditions (June 2010 edition) are in addition to and supplemental to the Bank s standard Terms and Conditions (October 2007
Unison Advisors LLC. The date of this brochure is March 29, 2012.
Unison Advisors LLC 2032 Belmont Road NW, #619 Washington, DC 20009 T 646 290 7697 F 646 290 5477 www.unisonadvisors.com The date of this brochure is March 29, 2012. This brochure provides information
Fraud Control Theory
13 Fraud Control Theory Using a variation of a saying from the 1960s, fraud happens. Like all costs of doing business, fraud must be managed. Management must recognize that people commit fraudulent acts
PENNY STOCK UNSOLICITED TRANSACTION ACKNOWLEDGMENT
PENNY STOCK UNSOLICITED TRANSACTION ACKNOWLEDGMENT DATE CLIENT NAME: ADDRESS: Dear : You recently requested that we execute for your account a purchase or sale of (shares) that trades at less than $5.00
Performing Audit Procedures in Response to Assessed Risks and Evaluating the Audit Evidence Obtained
Performing Audit Procedures in Response to Assessed Risks 1781 AU Section 318 Performing Audit Procedures in Response to Assessed Risks and Evaluating the Audit Evidence Obtained (Supersedes SAS No. 55.)
APIP - Cyber Liability Insurance Coverages, Limits, and FAQ
APIP - Cyber Liability Insurance Coverages, Limits, and FAQ The state of Washington purchases property insurance from Alliant Insurance Services through the Alliant Property Insurance Program (APIP). APIP
Transactions in Financial Derivatives
127 Transactions in Financial Derivatives In This Section: Coverage and definitions Estimation methods overview Financial derivatives Coverage and definitions This account measures transactions arising
FINRA E-Learning Courses
FINRA E-Learning Courses The Definitive Source for Firm Element Training FINRA develops a wide range of e-learning courses for registered representatives, supervisors, operations staff, compliance personnel
FOCUSED ON YOUR INVESTMENTS YOUR FUTURE YOU
FOCUSED ON YOUR INVESTMENTS YOUR FUTURE YOU Table of Contents Harrington Capital Management, LLC is a branch office of and Securities offered through WFG Investments, Inc., member FINRA & SIPC. Investment
As of July 1, 2013. Risk Management and Administration
Risk Management Risk Control The ORIX Group allocates management resources by taking into account Group-wide risk preference based on management strategies and the strategy of individual business units.
Financial Planning Services Financial Goal Analysis
Financial Planning Services Financial Goal Analysis Prepared for: Tom and Christina Sample November 18, 2010 Prepared by : Erik Holton Corporate Stock Benefit Consultant The Callanan Group UBS Financial
Business Foreign Exchange Contracts
Business Foreign Exchange Contracts Product Disclosure Statement 1 August 2012 Copyright HSBC Bank Australia Limited ABN 48 006 434 162. 1 August 2012. ALL RIGHTS RESERVED. No part of this publication
OCC 98-3 OCC BULLETIN
To: Chief Executive Officers and Chief Information Officers of all National Banks, General Managers of Federal Branches and Agencies, Deputy Comptrollers, Department and Division Heads, and Examining Personnel
Credit Risk Management: Trends and Opportunities
Risk & Compliance the way we see it Credit Risk Management: Trends and Opportunities The Current State of Credit Risk Management 1 Overview The crisis exposed the shortcomings of existing risk management
A New Approach for Managing Operational Risk
A New Approach for Managing Operational Risk Addressing the Issues Underlying the 2008 Global Financial Crisis Sponsored by: Joint Risk Management Section Society of Actuaries Canadian Institute of Actuaries
Statement of Financial Condition unaudited
Statement of Financial Condition unaudited June 30, 2015 Vanguard Marketing Corporation (a wholly owned subsidiary of The Vanguard Group, Inc.) Vanguard Marketing Corporation (a wholly owned subsidiary
Dr Christine Brown University of Melbourne
Enhancing Risk Management and Governance in the Region s Banking System to Implement Basel II and to Meet Contemporary Risks and Challenges Arising from the Global Banking System Training Program ~ 8 12
ETHICS, FRAUD, AND INTERNAL CONTROL
CHAPTER ETHICS, FRAUD, AND INTERNAL CONTROL The three topics of this chapter are closely related. Ethics is a hallmark of the accounting profession. The principles which guide a manager s decision making
On the Setting of the Standards and Practice Standards for. Management Assessment and Audit concerning Internal
(Provisional translation) On the Setting of the Standards and Practice Standards for Management Assessment and Audit concerning Internal Control Over Financial Reporting (Council Opinions) Released on
FOURTH QUARTER NET INCOME INCREASES 12% TO A RECORD $5.32 BILLION FOURTH QUARTER EPS OF $1.02, UP 12% REVENUES INCREASE 9% TO $21.
FOURTH QUARTER NET INCOME INCREASES 12% TO A RECORD $5.32 BILLION FOURTH QUARTER EPS OF $1.02, UP 12% REVENUES INCREASE 9% TO $21.9 BILLION CITIGROUP 2004 NET INCOME OF $17.0 BILLION, EPS OF $3.26 REVENUES
A Risk-Based Audit Strategy November 2006 Internal Audit Department
Mental Health Mental Retardation Authority of Harris County ENTERPRISE RISK MANAGEMENT A Framework For Assessing, Evaluating And Measuring Our Agency s Risk A Risk-Based Audit Strategy November 2006 Internal
TITLE: Fraud Prevention and Detection Program IDENTIFIER: S-FW-LD-1008 APPROVED: Executive Cabinet (Pending)
PAGE 1 of 5 TITLE: Fraud Prevention and Detection Program IDENTIFIER: S-FW-LD-1008 APPROVED: Executive Cabinet (Pending) ORIGINAL: 11/03 REVISED: 10/07, 09/10, 04/13 REVIEWED: EFFECTIVE DATE Acute Care
IPS RIA, LLC CRD No. 172840
IPS RIA, LLC CRD No. 172840 ADVISORY CLIENT BROCHURE 10000 N. Central Expressway Suite 1100 Dallas, Texas 75231 O: 214.443.2400 F: 214-443.2424 FORM ADV PART 2A BROCHURE 1/26/2015 This brochure provides
REINSURANCE RISK MANAGEMENT GUIDELINE
REINSURANCE RISK MANAGEMENT GUIDELINE Initial publication: April 2010 Update: July 2013 Table of Contents Preamble... 2 Introduction... 3 Scope... 5 Coming into effect and updating... 6 1. Reinsurance
Prevention of Fraud, Waste and Abuse
Procedure 1910 Responsible Office: Yale Medical Group Effective Date: 01/01/2007 Responsible Department: Administration Last Revision Date: 09/20/2013 Prevention of Fraud, Waste and Abuse Policy Statement...
February 22, 2015 MEMORANDUM
February 22, 2015 MEMORANDUM Re: Due Diligence Information for Advisors, Brokers, Hedge Funds and Other Financial Institutions and Intermediaries Using or Considering Interactive Brokers LLC as Prime Broker/Custodian
Credit Risk Stress Testing
1 Credit Risk Stress Testing Stress Testing Features of Risk Evaluator 1. 1. Introduction Risk Evaluator is a financial tool intended for evaluating market and credit risk of single positions or of large
Using COBiT For Sarbanes Oxley. Japan November 18 th 2006 Gary A Bannister
Using COBiT For Sarbanes Oxley Japan November 18 th 2006 Gary A Bannister Who Am I? Who am I & What I Do? I am an accountant with 28 years experience working in various International Control & IT roles.
Pursuing Compliance with the FFIEC Guidance Risk Assessment 101 KPMG RISK ADVISORY SERVICES
Pursuing Compliance with the FFIEC Guidance Risk Assessment 101 KPMG RISK ADVISORY SERVICES Contents PART I An Increasing Threat: Identity Theft The FFIEC Response Risk Assessment Fundamentals The FFIEC
OBJECTIVES CHAPTER OVERVIEW CHAPTER OUTLINE SEMINAR 28 NOV 2013
OBJECTIVES To learn the fundamentals of foreign exchange To identify the major characteristics of the foreign-exchange market and how governments control the flow of currencies across national borders
Controls and accounting policies
Controls and accounting policies Controls and procedures Management s responsibility for financial information contained in this Annual Report is described on page 92. In addition, the Bank s Audit and
Answers to Concepts in Review
Answers to Concepts in Review 1. (a) In the money market, short-term securities such as CDs, T-bills, and banker s acceptances are traded. Long-term securities such as stocks and bonds are traded in the
TESTIMONY OF NEW YORK STATE ATTORNEY GENERAL ELIOT SPITZER
STATE OF NEW YORK OFFICE OF THE ATTORNEY GENERAL 120 BROADWAY NEW YORK, NY 10271 ELIOT SPITZER Attorney General (212) 416-8050 UNITED STATES SENATE COMMITTEE ON BANKING, HOUSING AND URBAN AFFAIRS HEARING
Sarbanes-Oxley Section 404: Compliance Challenges for Foreign Private Issuers
Sarbanes-Oxley Section 404: Compliance s for Foreign Private Issuers Table of Contents Requirements of the Act.............................................................. 1 Accelerated Filer s...........................................................
