Operational Risk Scenario Analysis. 17/03/2010 Michał Sapiński michal.sapinski@statconsulting.com.pl



Similar documents
Operational Risk An Enterprise Risk Management Presentation

Modelling operational risk in Banking and Insurance Palisade EMEA 2012 Risk Conference London

Agenda. Introduction. Well known cases. Regulatory Framework. Operational Risk Management Process

LDA at Work: Deutsche Bank s Approach to Quantifying Operational Risk

Operational Risk Management Policy

Understanding Today s Enterprise Risk Management Programs

Basel II: Operational Risk Implementation based on Risk Framework

Solvency II New Framework for Risk Management Organisation. Dr. Maciej Sterzynski (Triglav Insurance, Ltd.) Matija Bitenc (Triglav Insurance, Ltd.

DEVELOPING A KRI PROGRAM: GUIDANCE FOR THE OPERATIONAL RISK MANAGER SEPTEMBER Mayowa BabatolaMayowa BabatolaBITS 2004 September 2

Insurance as Operational Risk Management Tool

Implementing an AMA for Operational Risk

RESERVE BANK OF VANUATU OPERATIONAL RISK MANAGEMENT

Regulatory and Economic Capital

Operational Risk Modeling *

Risk Management Toolkit

ORSA and Economic Modeling Choices. Bert Kramer, André van Vliet, Wendy Montulet

Actuarial Risk Management

An operational risk management framework for managing agencies

Own Risk and Solvency Assessment

Solvency II Standard Model for Health Insurance Business

Capital requirements for health insurance under Solvency II

Modelling operational risk in the insurance industry

An update on QIS5. Agenda 4/27/2010. Context, scope and timelines The draft Technical Specification Getting into gear Questions

REGULATION 9 ON OPERATIONAL RISK MANAGEMENT. Article 1 Purpose and Scope

GUIDELINES FOR THE MANAGEMENT OF OPERATIONAL RISK

How To Manage Operational Risk

Operational Risk Management in Insurance Companies

International Financial Reporting for Insurers: IFRS and U.S. GAAP September 2009 Session 25: Solvency II vs. IFRS

Operational risk in Basel II and Solvency II

Introduction to Operational Risk Modelling. 21 September 2015

Underwriting put to the test: Process risks for life insurers in the context of qualitative Solvency II requirements

ERM Practice and Challenge in China Insurance Company. Zhang Chensong, FSA,CERA,FIA,FCAA Head of Risk Management Taikang Life Insurance

Operational Risk Management in a Property/Casualty Insurance Company

BEL best estimate liability, deduced from the mean loss as a present value of mean loss,

Preparing for ORSA - Some practical issues Speaker:

Be Afraid, Be Very Afraid!!! Hacking Out the Pros and Cons of Captive Cyber Liability Insurance

Subject ST9 Enterprise Risk Management Syllabus

Operational Risk. Operational Risk in Life Insurers. Operational Risk similarities with General Insurance? unique features

Prudential Practice Guide

ERM Exam Core Readings Fall Table of Contents

INVESTMENT FUNDS: Funds investments. KPMG Business DialogueS November 4 th 2011

ERM from a Small Insurance Company Perspective

Insurance Groups under Solvency II

Cyber- Attacks: The New Frontier for Fraudsters. Daniel Wanjohi, Technology Security Specialist

Operational Risk. Operational Risk Policy

Operational Risk Management Concept Paper

Solvency ii: an overview. Lloyd s July 2010

An Internal Model for Operational Risk Computation

CEIOPS-DOC-45/09. (former CP 53) October 2009

Operational Risk Management Table of Contents

Application Security in the Software Development Lifecycle

SCOR inform - April Life (re)insurance under Solvency II

Fifth Quantitative Impact Study of Solvency II (QIS5)

Practical methods of modelling operational risk

Practical Calculation of Expected and Unexpected Losses in Operational Risk by Simulation Methods

SOLVENCY II ARE YOU READY AND COMPLIANT?

The Investment Implications of Solvency II

Chapter 7. Statistical Models of Operational Loss

Solvency II for Beginners

CEIOPS Advice for Level 2 Implementing Measures on Solvency II: Articles 120 to 126. Tests and Standards for Internal Model Approval

Advisory Guidelines of the Financial Supervisory Authority. Requirements regarding the arrangement of operational risk management

ORSA Implementation Challenges

Evaluating Insurers Enterprise Risk Management Practice

Brief. The BakerHostetler Data Security Incident Response Report 2015


ACCELUS RISK MANAGEMENT SOLUTIONS THOMSON REUTERS ACCELUS ACCELUS RISK MANAGEMENT SOLUTIONS

Fourth study of the Solvency II standard approach

How to Model Operational Risk, if You Must

Managing Capital Adequacy with the Internal Capital Adequacy Assessment Process (ICAAP) - Challenges and Best Practices

Supervisory Guidance on Operational Risk Advanced Measurement Approaches for Regulatory Capital

OnSite: Support and Software Maintenance

Solvency Assessment and Management. Summary of Roadmap Responses

Internal Loss Data A Regulator s Perspective

ICAAP Report Q2 2015

MSA400 - Reading project Solvency II

Solvency II Eligibility of Contingent Capital

OVERVIEW. In all, this report makes recommendations in 14 areas, such as. Page iii

Sound Practices for the Management of Operational Risk

Modelling Uncertainty in Claims Experience to Price General Insurance Contracts

ORSA - The heart of Solvency II

Information Technology

Quantitative Impact Study 1 (QIS1) Summary Report for Belgium. 21 March 2006

Risk Management Systems of the Resona Group

Operational risk management in the energy industry

Excellent Courses, Exceptional Venues

OPERATIONAL RISK EFFECT ON INSURANCE MARKET S ACTIVITY Darja Stepchenko, Irina Voronova, Gaida Pettere Riga Technical University, Latvia

Introduction to Solvency II

Standard & Poor s ERM Benchmark Review

Operational Risk Management Program Version 1.0 October 2013

Basel Committee on Banking Supervision. Results from the 2008 Loss Data Collection Exercise for Operational Risk

Solvency II overview

Transcription:

Operational Risk Scenario Analysis 17/03/2010 Michał Sapiński michal.sapinski@statconsulting.com.pl www.statconsulting.com.pl Copyright by StatConsulting Sp. z o.o. 2010

Operational Risk Tail Events Copyright by StatConsulting Sp. z o.o. 2010 2

Agenda Operational Risk - Scenario Analysis Operational Risk - Definition Solvency II Role of Scenarios in Risk Management Role of Scenarios in Risk Quantification (VaR) Summary Copyright by StatConsulting Sp. z o.o. 2010 3

Operational Risk Operational risk means the risk of loss arising from inadequate or failed internal processes, personnel or systems, or from external events Operational risk shall include legal risks and exclude risks arising from strategic decisions, as well as reputation risks The capital requirement for operational risk shall reflect operational risks to the extent they are not already reflected in the risk modules. SOLVENCY II DIRECTIVE, 25 November 2009 Copyright by StatConsulting Sp. z o.o. 2010 4

Operational Risk Solvency II/Basel II Solvency II Basel II Operational risk is the risk of loss arising from inadequate or failed internal processes, people, systems or external events. Operational risk also includes legal risks. Reputation risks and risks arising from strategic decisions do not count as operational risks. Operational risk is defined as the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events. This definition includes legal risk, but excludes strategic and reputation risk. Copyright by StatConsulting Sp. z o.o. 2010 5

Operational Risk Types Internal Fraud Unauthorized activity, theft and fraud External Fraud - theft of information, hacking damage, third-party theft and forgery Employment Practices and Workplace Safety - discrimination, workers compensation, employee health and safety Clients, Products, & Business Practice - market manipulation, antitrust, improper trade, product defects, fiduciary breaches, account churning Damage to Physical Assets - natural disasters, terrorism, vandalism Business Disruption & Systems Failures - utility disruptions, software failures, hardware failures Execution, Delivery, & Process Management - data entry errors, accounting errors, failed mandatory reporting, negligent loss of client assets Copyright by StatConsulting Sp. z o.o. 2010 6

Operational Scenarios, Events, Losses Scenario Class of Operational Events Event - An operational risk event is an incident leading to the actual outcome(s) of a business process to differ from the expected outcome(s), due to inadequate or failed processes, people and systems, or due to external facts or circumstances (ORX). Loss - An operational risk loss is a negative impact on the earnings or equity value of the firm due to an operational risk event (ORX). Scenario Event Events Losses Loss Losses Copyright by StatConsulting Sp. z o.o. 2010 7

Operational Risk Risk of loss arising from inadequate or failed internal processes, personnel or systems, or from external events Risks Processes, People, Systems, External Events Events Losses { Frequency, Severity } Copyright by StatConsulting Sp. z o.o. 2010 8

Solvency II Three Pillars Solvency II Pillar I Technical Provisions MCR (Minimal Capital Requirement) SCR (Solvency Capital Requirement) Pillar II Corporate Governance Principles for internal control and risk management ORSA (Own Risk and Solvency Assessment) Pillar III Reporting Market Discipline Copyright by StatConsulting Sp. z o.o. 2010 9

SCR (Solvency Capital Requirement): Standard Formula QIS4 -Technical Specifications Copyright by StatConsulting Sp. z o.o. 2010 10

QIS4 Operational Risk Standard Method SCR Źródło: QIS4 Copyright by StatConsulting Sp. z o.o. 2010 11

Operational Risk Management Loss Database KRI Scenario Analysis History Now Future Precise qualitative and quantitative operational risk assessment Copyright by StatConsulting Sp. z o.o. 2010 12

Analysis KRI selection Operational Risk Management Risk types KRI Business Lines KRI identification and definition Processes Scenarios Units Products Systems Scenario definition based on occurring losses or loss possibility Losses Copyright by StatConsulting Sp. z o.o. 2010 13

Scenario Analysis Once an year, owners of the processes are collecting operational scenarios Every scenario describes the possibility of occurrence of operational loss. Scenarios besides description have the following properties Risk type, line of business, process, business unit Risk control level, possible enhancements in risk control level Business continuity plans Quantitative information Frequency Severity Copyright by StatConsulting Sp. z o.o. 2010 14

Scenarios - Sources of Information Internal Loss Data Scenario 1 Scenario 2 External Loss Data Imaginative Thinking Copyright by StatConsulting Sp. z o.o. 2010 15

Business Lines x Processes Homogeneous organization parts Risks Insurance Company Homogeneous Independent Clear Risk Types Scenario: Server crash Frequency: 1-2 times per 5 years. Expected loss: 5-10k Unexpected loss: 50-60k Copyright by StatConsulting Sp. z o.o. 2010 16

Scenario Analysis - Scenario Example Field Line of business: Process: Business unit: Value Ubezpieczenia majątkowe Zarządzanie sprzedażą online Risk type: Oszustwa zewnętrzne Product: - System: E-Sales Scenario: Włamanie do systemu i kradzież danych Risk control level: Nieakceptowalny Enhancements in risk control: Wprowadzenie dodatkowych zabezpieczeń i procedur Connected KRIs: Rotacja pracowników w dziale IT,... Quantitative information: Occurrence frequency: 1-2 / 5 lat Severity (median): 30 000-40 000 Stress severity: 100 000 300 000 (Maximum severity): Events/Losses list: Copyright by StatConsulting Sp. z o.o. 2010 17

Scenario Analysis VaR modeling Severity Frequency Frequency, Severity distributions Comparison with collected loss data Aggregation, diversification Result: Aggregated operational risk loss distribution with decomposition Lognormal Gumbel Negative binomial Poisson Weibull Copyright by StatConsulting Sp. z o.o. 2010 18

Value at Risk Expected Loss Unexpected Loss Extra capital for unexpected loss Solvency II- 99,5 Copyright by StatConsulting Sp. z o.o. 2010 19

Scenario Analysis VaR aggregation Process Process Process Line of business Whole company Copyright by StatConsulting Sp. z o.o. 2010 20

Loss frequency Scenario Analysis Risk Maps Fixing processes Critical situation management Recurring losses Critical situation Low High Minor risk Essential risk (unexpected losses) Continuation plans, insurance Small amounts Loss severity Big amounts Copyright by StatConsulting Sp. z o.o. 2010 21

Operational Risk Scenario Analysis Summary Scenario Analysis Advantages Forward looking Collected loss data can be used as a valuable support Allows you to implement risk controls prior to the loss occurrence Allows risk quantification - VaR method Allows risk sources identification (for example VaR drill-down) Allows to present risk on risk maps Disadvantages Labor-intensity smaller in subsequent rounds big proportion of the scenarios remains unchanged Copyright by StatConsulting Sp. z o.o. 2010 22

Contact: StatConsulting Sp. z o.o. Wołodyjowskiego 38a, 02-724 Warsaw, Poland phone: +48 22 847 97 17 fax: +48 22 499 45 31 e-mail: info@statconsulting.com.pl www.statconsulting.com.pl Copyright by StatConsulting Sp. z o.o. 2010