Transcription of Operational Risk Management: An Evolving Discipline
1 Operational Risk Management: An Evolving Discipline 4 Supervisory InsightsSummer 2006 Operational risk is not a new concept inthe banking industry. risks associatedwith Operational failures stemming fromevents such as processing errors, internaland external fraud, legal claims, andbusiness disruptions have existed atfinancial institutions since the inceptionof banking. As this article will discuss,one of the great challenges in systemati-cally managing these types of risks isthat Operational losses can be quitediverse in their nature and highly unpre-dictable in their overall financial impact. Banks have traditionally relied onappropriate internal processes, auditprograms, insurance protection, andother risk management tools to counter-act various aspects of Operational tools remain of paramount impor-tance; however, growing complexity inthe banking industry, several large andwidely publicized Operational losses inrecent years, and a changing regulatorycapital regime have prompted bothbanks and banking supervisors toincreasingly view Operational riskmanagement (ORM) as an Evolving disci-pline.
2 Of particular note is the applica-tion of quantitative concepts, similar tothose used to measure credit and marketrisks, to the measurement of operationalrisk. This article provides an introduction tooperational risk, outlines the currentstate of ORM, and describes differentquantification approaches in this evolv-ing Risk DefinedThe definition of Operational riskcontinues to evolve, in part owing to itsscope. Before attempting to define theterm, it is essential to understand thatoperational risk is present in all activitiesof an organization. As a result, some ofthe earliest practitioners defined opera-tional risk as every risk source that liesoutside the areas covered by market riskand credit risk. But this definition ofoperational risk includes several otherrisks (such as interest rate, liquidity, andstrategic risk) that banks manage anddoes not lend itself to the managementof Operational risk per se. As part of therevised Basel framework,1the BaselCommittee on Banking Supervision setforth the following definition: Operational riskis defined as therisk of loss resulting from inadequateor failed internal processes, people,and systems or from external definition includes legal risk, butexcludes strategic and the Basel Committee s definitionincludes what the Committee considersto be crucial elements, each bank s defi-nition for internal management purposesshould recognize its unique risk charac-teristics, including its size and sophistica-tion, as well as the nature andcomplexity of its products and cooperation with industry partici-pants, the Basel Committee has identi-fied the seven Operational risk eventtypes, shown in Table Evolving BankingLandscapeThe Operational environment for manybanks has evolved dramatically in recentyears.
3 Deregulation and globalization of1 Basel Committee on Banking Supervision (Basel Committee), International Convergence of Capital Measure-ment and Capital Standards(the revised Basel II framework), November 2005, Paragraph 644. Available The event types and abbreviated examples presented in the table appear in the Basel Committee s Sound Practicesfor the management and Supervision of Operational Risk, Paragraph 5. Available at financial services, the proliferation of newand highly complex products, large-scaleacquisitions and mergers, and greater useof outsourcing arrangements have led toincreased Operational risk profiles formany institutions. Technologicaladvances, including growth in e-bankingtransactions, automation, and otherrelated business applications also presentnew and potentially heightened expo-sures from an Operational risk standpoint. Available data support the idea thatbanks Operational environments aregetting riskier. Chart 1 depicts datagleaned from the 2004 Loss Data Collec-tion Exercise (LDCE)3conducted inpreparation for the implementationof the Basel II capital framework.
4 Despitecertain inherent limitations in the data,such as differences in data availabilityamong the reporting banks and improve-ments in data capture methods over thecollection period, it appears that in aggre-gate loss amounts have increased sincecollection efforts began. For example, 20participating banks reported operationallosses of $15 billion in 2004, surpassingthe previous high of $5 billion in lossesreported by 17 institutions in 2002. Losses associated with Operational riskevents can be large. Some well-knownexamples are the collapse of BaringsBank due to fraudulent trading and thesubstantial legal settlements entered intoby Citigroup and JPMorgan Chase withregard to the Enron and WorldCommatters. The business disruptions andfinancial impacts resulting from Hurri-cane Katrina and the September 11terrorist attacks also exemplify howmajor, unforeseen events can materiallyaffect a bank s operations. 5 Supervisory InsightsSummer 2006 Table 1 Event TypeExamplesLoss Event Types and Examples External fraudRobbery, forgery, and check kitingEmployment practicesand workplace safetyWorkers compensation and discrimination claims, violation ofemployee health and safety rules, and general liabilityClients, products, andbusiness practicesFiduciary breaches, misuse of confidential customer information,money laundering, and sale of unauthorized productsDamage to physicalassetsTerrorism, vandalism, earthquakes, fires, and floodsBusiness disruptionand system failuresHardware and software failures, telecommunication problems, and utility outagesExecution, delivery, andprocess managementData entry errors, collateral management failures, incomplete legaldocumentation, and vendor disputesInternal fraudEmployee theft, intentional misreporting of positions.
5 And insider trading on an employee s own account3 The 2004 LDCE was a voluntary survey that asked respondents to provide data on individual Operational lossesthrough June or September 2004 to enable the banking agencies to assess the potential impact of Basel II on capitalfor banking organizations. The results of the survey can be found at Additional information regarding the LDCEis at 6 Controlling Operational Risk Traditional ORM practices, which mostbanks employ today , rely on internalprocesses, audit programs, and insur-ance protection to counterbalance opera-tional risk. They are based largely on theassumption that intelligent, educatedpeople can, through their intuition, iden-tify their organization s significant risks ,corresponding controls, and such environments, businesslines manage their Operational risks asthey see fit (using a silo approach )with little or no formality or processtransparency. Some larger banks have gone beyondthe silo approach by establishing central-ized departments or groups responsiblefor focusing on particular segments ofoperational risk, such as operatingprocesses, compliance, fraud, businesscontinuity, or vendor management /outsourcing.
6 While this evolution hasimproved overall risk awareness, it tendsto promote a natural segmentation ofrisk awareness, because risks are catego-rized along functional lines. Thisapproach can create significant opera-tional risks if management fails toconsider end-to-end More recent ORM practices arefounded on the view that intuition aloneis not sufficient to drive the ORMprocess. In this view, ORM practicesmust extend to quantitative measure-ment, including historical loss data,formal risk assessments, statistical analy-sis, and independent common framework at the banks combines the traditional siloapproach with an enterprise-wide over-sight function. The enterprise-wide (orcorporate) function designs and imple-ments the bank s ORM framework,which serves as the structure to identify,measure, monitor, and control or miti-gate Operational risk. The framework isdefined by the risk tolerance determinedby the board of directors, as well as theOperational Riskcontinued from pg. 5 Supervisory InsightsSummer 2006 Available Data Suggest Riskier Operational Environment [ Operational Losses Frequency and Severity]05,00010,00015,00020,000 Pre-1999 1999 2000 2001 2002 2003 200406121824 Total # of Losses (Left hand scale)Total Loss Amount ($M, left hand scale)# of Firms Reporting (Right hand scale)Source: 2004 Loss Data Collection Exercise3 Chart 14 Ali Samad-Khan, Fundamental Issues in OpRisk management , OpRisk & Compliance, February 2006.
7 5 Eric Holmquist, Scaling Op Risk management for SMIs: How to Avoid Boundary Disputes, OpRisk & Compliance, January Ali Samad-Khan, Fundamental Issues in OpRisk management . 7formal Operational risk policies outliningroles and responsibilities, data standards,risk assessment processes, reportingstandards, and a quantification line managers continueto own the risk, but risks are identifiedthrough formal self-assessments. The riskassessments are designed to capture end-to-end processes as well as generate anunderstanding of the risks in individualprocesses and products. Table 2compares the two approaches to primary value of such ORM tech-niques, as demonstrated by a growingnumber of institutions using them, istheir application to decision making andrisk management . Specifically, the use ofa well-integrated ORM framework can dothe following: Increase risk awareness and mitiga-tion opportunities, which may mini-mize potential exposure Assist in evaluating the adequacy ofcapital in relation to the bank s overallrisk profile Enhance risk management efforts byproviding a common framework formanaging the riskQuantifying Operational Risk:Roots in Economic CapitalAs ORM continues to evolve into adistinct Discipline , efforts to quantifyoperational risk have gained number of large financial institutionshave been working to quantify opera-tional risk for several years as part oftheir economic capital frameworks.
8 Theyhave developed and implementedeconomic capital models to allocate capi-tal to different business segments basedon a variety of risk factors ( , credit,market, interest rate, Operational ).However, within these internal capitalmeasurement and managementSupervisory InsightsSummer 2006 Table 2 Traditional PracticeEmerging PracticeComparison of Traditional and Modern Operational Risk Management8 Silo-ed business unit Integrated corporate risk management (CRM)risk managementBusiness line managers CRM supplements and reinforces business line risk ownership own the risk Ad-hoc or no risk Uniform risk assessments across business units facilitated by CRMself-assessmentVoluminous performance Core set of key risk and performance metrics/escalation triggersindicatorsToo much or too little Concise, uniform reporting to senior management and the board of information; inconsistent directorsbusiness unit reportingReliance on qualitative Use of quantitative information (potential Operational risk processes to improve exposure) and risk assessments to improve risk managementrisk management7 The Basel Committee, International Convergence of Capital Measurement and Capital Standards, Paragraph663(b).
9 8 Table adapted from Operational Risk: Regulation, Analysis, and Managementby Carol Alexander (2003), p. Times Prentice Hall. , there is great variation inmethods used and levels of sophistica-tion, ranging from largely qualitative orjudgmental approaches to complex statis-tical modeling. With respect to opera-tional risk, in particular, many of themeasurement techniques have tradition-ally focused on proxies such as grossincome to estimate capital few institutions have incorpo-rated Operational risk quantificationsystems into their economic capitalmodels, ongoing work in this area isbecoming increasingly important giventhe anticipated implementation of a newregulatory capital framework known asBasel II. This new framework, which hasbeen under development since the late1990s and is approaching internationaladoption, is intended to align capitallevels more closely with underlying general intention is consistent withthe broad goal of most economic capitalframeworks. Operational Risk BecomesPart of Regulatory CapitalUnder the Basel II framework, institu-tions (both mandatory and opt-in)9willbe required to determine an appropriateoperational risk charge, along with creditand market risk charges, as part of theirrisk-weighted assets (RWA) institution s estimate of its opera-tional risk exposure will, subject tosupervisory approval, directly affect itsrisk-based capital (RBC) ratio.
10 Under the existing regulatory capitalregime (Basel I), which was adopted in1988, there is no explicit charge for oper-ational risk. In determining RBC ratios,financial institutions calculate RWA onthe basis of prescribed percentage alloca-tions for on- and off-balance sheet creditexposures and for certain market risks . Itcould be argued that Operational risk andother risks were implicitly accounted forin the calibration of the minimum ratiothresholds for the various PromptCorrection Action categories10( , 4percent Tier 1 capital to average adjustedbalance sheet assets for the AdequatelyCapitalized designation), but they arenot considered in determining a bank scapital ratios. Quantifying Operational RiskThe Basel II framework outlines threequantitative approaches (shown in Table 3)for determining an Operational risk capi-tal charge: the basic indicator approach,the standardized approach, and theadvanced measurement approach. The first two approaches are simple andgenerate results on the basis of predeter-mined multipliers (percentages of grossincome11for an entire entity or for indi-vidual business lines).