July 30, 2014Kachhapi 1
July 30, 2014Kachhapi 2
OPERATIONAL RISK
Operational risk is the risk of direct
or indirect loss resulting from
inadequate or failed internal
processes, people and system or
from external events. Also
includes, settlement or payment
risk and business interruption,
administrative and legal risks.
July 30, 2014Kachhapi 3
OPERATIONAL RISK IS
• EMBEDDED IN EACH ACTIVITY
• IMPLICIT IN ORDINARY COURSE OF
CORPORATE ACTIVITY.
• NOT DIRECTLY A RISK Vs EXPECTED
REWARD FUNCTION
• AN INDEPENDENT RISK MANAGEMENT
FUNCTION, COMPARABLE TO
MANAGEMENT OF CREDIT & MARKET
July 30, 2014Kachhapi 4
TYPES OF OPERATIONAL RISK EVENTS
EVENT EXAMPLE
Internal FraudInternal Fraud Intentional Mis-representationIntentional Mis-representation
Employee theftEmployee theft
Insider Trading - EmployeesInsider Trading - Employees
External Fraud Robbery, Forgery, Cheque
kiting
Computer Hacking Damage
July 30, 2014Kachhapi 5
Clients, Products,
Business
Practices
Fiduciary Breaches
Improper Trading
Confidential Information
Money Laundering Claim
Employment
Practices & Work
Place Safety
Health & Safety Rules
Discrimination Claims
General Liability
EVENT EXAMPLE
July 30, 2014Kachhapi 6
EVENT EXAMPLE
Damage to PhysicalDamage to Physical
AssetsAssets
Terrorism, VandalismTerrorism, Vandalism
Earth Quake, Fires &Earth Quake, Fires &
FloodsFloods
Business Disruption &
System Failures
Hardware & Software
Failures, Telecom
Failures, Utility Usage
Execution, Delivery &
Process Management
Data Entry Errors,
Incomplete
Documentation, Vendor
Disputes, Unauthorized
Access to Client
Accounts
July 30, 2014Kachhapi 7
MAJOR CASES OF LOSSMAJOR CASES OF LOSS
EVENTS IN BANKINGEVENTS IN BANKING
July 30, 2014Kachhapi 8
LOSS EVENTS
TYPE
BANK QUANTUM IN
USD
Internal Fraud Barings
Daiwa Bank
$ 1.0 Billion
$ 1.4 Billion
External Fraud Custodial Client
of Republic of
NY Corporation
$ 611 Mio
WORKPLACE
SAFETY
Merrill Lynch
Legal Settlement
$ 250 Mio
July 30, 2014Kachhapi 9
LOSS EVENTS
TYPE
BANK QUANTUM IN
USD
Client products
& business
practices
Improper Sales
Practices
Banks in US
( Provision)
$ 405 Mio
Damage to
physical assets
Bank of New
York 9/11
$ 140 Mio
July 30, 2014Kachhapi 10
LOSS EVENTS
TYPE
BANK QUANTUM IN
USD
Business disruption
& system failure
Solomon Brothers
( Due to
Un-reconciled
Balances with
change in I.T
System )
$ 303 Mio
Execution, delivery
& Process
management
BOA
Wells Fargo Bank
Failed transaction
Processing &
System Integration
Processing
$ 225 Mio
$ 150 Mio
July 30, 2014Kachhapi 11
OPERATIONAL RISK –
LOSS TYPES
• Processing risk.
• People risk.
• System risk.
• External events risk.
• Legal risk.
• Reputation risk.
July 30, 2014Kachhapi 12
PROCESSING RISK
• Transactions put through without proper
authority/mandate.
• Erroneous transaction execution.
• Wrong reporting.
• Erroneous cash movement.
• Omission of task.
• Inaccurate/incomplete documentation.
• Frauds both internally/externally.
• Money laundering.
• Unauthorized persons access to bank’s records.
July 30, 2014Kachhapi 13
PEOPLE RISK
• Inadequate staff.
• Hiring unsuitable staff.
• Loss of key personnel.
• Over reliance on few key staff.
• Insufficient succession & development
planning.
• Insufficient training.
• Poor communication.
• Behaviour & attitude.
• Age profile.
July 30, 2014Kachhapi 14
SYSTEM RISKS
• Programming error.
• Irrelevant, inaccurate, incomplete MIS.
• I T System failure.
• Telecommunication failure.
• Technology interference.
• Failure of support functions.
• Inadequacy of backup systems/procedures.
• Working under different platforms/ software
environment.
July 30, 2014Kachhapi 15
LEGAL RISKS
• Breaching of regulatory requirements.
• Unenforceable contracts,lawsuits.
• Adverse judgments.
• Executing illegal transactions.
• Failure to fulfill fiduciary duties
July 30, 2014Kachhapi 16
External events risks.
• Natural disasters.Natural disasters.
• War/terrorism.War/terrorism.
• Sabotage.Sabotage.
• Crime.Crime.
July 30, 2014Kachhapi 17
REPUTATION RISKS.
• Negative publicity leading to decline in
customer base, costly litigation,
reduction in current & prospective
earnings & capital.
• Effect of other risks.
July 30, 2014Kachhapi 18
Operational Risk – Framework &
Management.
1. Organizational set up.
2. Operational Risk Management Policy.
3. Risk mapping.
4. Risk assessment.
5. Collection of Operational risk loss incident
data.
6. Risk Quantification
July 30, 2014Kachhapi 19
Risk Assessment
Categorization of identified risks – Low,
Medium, High.
Grading of controls – Low, Medium, High.
Comparison between assessed risks &
existing controls to identify :
1. High risk low control types
2. Low risk high control types
3. Less frequent high impact types
4. More frequent less impact types.
July 30, 2014Kachhapi 20
RISK QUANTIFICATION
OPERATIONALOPERATIONAL
RISKRISK
CREDIT RISKCREDIT RISK MARKET RISKMARKET RISK
STANDARDIZEDSTANDARDIZED
APPROACHAPPROACH
FOUNDATION –FOUNDATION –
IRB APPROACHIRB APPROACH
ADVANCED –ADVANCED –
IRB APPROACHIRB APPROACH
STANDARDISEDSTANDARDISED
APPROACHAPPROACH
INTERNALINTERNAL
MEASUREMENTMEASUREMENT
APPROACHAPPROACH
BASICBASIC
INDICATORINDICATOR
APPROACHAPPROACH
STANDARDIZEDSTANDARDIZED
APPROACHAPPROACH
ADVANCEDADVANCED
MEASUREMENTMEASUREMENT
APPROACHAPPROACH
July 30, 2014Kachhapi 21
Basic Indicator Approach
• Fixed percentage on Gross income
shall be the Capital to be held by the
Bank for Operational risk
July 30, 2014Kachhapi 22
Standardized Approach
• Bank’s activities are divided into:
1) Corporate Finance.
2) Trading & Sales.
3) Retail Banking.
4) Commercial Banking.
5) Payment & Settlement.
6) Agency Services & Custody.
7) Retail Brokerage.
8) Asset Management.
• Capital charge to be calculated for each business line
by multiplying gross income by a factor percentage
assigned to it.
July 30, 2014Kachhapi 23
Advanced Measurement Approach
• Gives discretion to the Bank to use
their own internal loss data &
assessment methods.
• Approach shall be used only after
sufficient reliable data base of
operational risk loss events is built up.
July 30, 2014Kachhapi 24
• We have to measure operational riskWe have to measure operational risk
by Basic Indicator Approach in termsby Basic Indicator Approach in terms
of RBI guidelines.of RBI guidelines.
• What is beneficial to Banks is AMA.What is beneficial to Banks is AMA.
July 30, 2014Kachhapi 25
• THANK YOU
• T.V.RAO.FACULTY

Operational risk & incident reporting

  • 1.
  • 2.
    July 30, 2014Kachhapi2 OPERATIONAL RISK Operational risk is the risk of direct or indirect loss resulting from inadequate or failed internal processes, people and system or from external events. Also includes, settlement or payment risk and business interruption, administrative and legal risks.
  • 3.
    July 30, 2014Kachhapi3 OPERATIONAL RISK IS • EMBEDDED IN EACH ACTIVITY • IMPLICIT IN ORDINARY COURSE OF CORPORATE ACTIVITY. • NOT DIRECTLY A RISK Vs EXPECTED REWARD FUNCTION • AN INDEPENDENT RISK MANAGEMENT FUNCTION, COMPARABLE TO MANAGEMENT OF CREDIT & MARKET
  • 4.
    July 30, 2014Kachhapi4 TYPES OF OPERATIONAL RISK EVENTS EVENT EXAMPLE Internal FraudInternal Fraud Intentional Mis-representationIntentional Mis-representation Employee theftEmployee theft Insider Trading - EmployeesInsider Trading - Employees External Fraud Robbery, Forgery, Cheque kiting Computer Hacking Damage
  • 5.
    July 30, 2014Kachhapi5 Clients, Products, Business Practices Fiduciary Breaches Improper Trading Confidential Information Money Laundering Claim Employment Practices & Work Place Safety Health & Safety Rules Discrimination Claims General Liability EVENT EXAMPLE
  • 6.
    July 30, 2014Kachhapi6 EVENT EXAMPLE Damage to PhysicalDamage to Physical AssetsAssets Terrorism, VandalismTerrorism, Vandalism Earth Quake, Fires &Earth Quake, Fires & FloodsFloods Business Disruption & System Failures Hardware & Software Failures, Telecom Failures, Utility Usage Execution, Delivery & Process Management Data Entry Errors, Incomplete Documentation, Vendor Disputes, Unauthorized Access to Client Accounts
  • 7.
    July 30, 2014Kachhapi7 MAJOR CASES OF LOSSMAJOR CASES OF LOSS EVENTS IN BANKINGEVENTS IN BANKING
  • 8.
    July 30, 2014Kachhapi8 LOSS EVENTS TYPE BANK QUANTUM IN USD Internal Fraud Barings Daiwa Bank $ 1.0 Billion $ 1.4 Billion External Fraud Custodial Client of Republic of NY Corporation $ 611 Mio WORKPLACE SAFETY Merrill Lynch Legal Settlement $ 250 Mio
  • 9.
    July 30, 2014Kachhapi9 LOSS EVENTS TYPE BANK QUANTUM IN USD Client products & business practices Improper Sales Practices Banks in US ( Provision) $ 405 Mio Damage to physical assets Bank of New York 9/11 $ 140 Mio
  • 10.
    July 30, 2014Kachhapi10 LOSS EVENTS TYPE BANK QUANTUM IN USD Business disruption & system failure Solomon Brothers ( Due to Un-reconciled Balances with change in I.T System ) $ 303 Mio Execution, delivery & Process management BOA Wells Fargo Bank Failed transaction Processing & System Integration Processing $ 225 Mio $ 150 Mio
  • 11.
    July 30, 2014Kachhapi11 OPERATIONAL RISK – LOSS TYPES • Processing risk. • People risk. • System risk. • External events risk. • Legal risk. • Reputation risk.
  • 12.
    July 30, 2014Kachhapi12 PROCESSING RISK • Transactions put through without proper authority/mandate. • Erroneous transaction execution. • Wrong reporting. • Erroneous cash movement. • Omission of task. • Inaccurate/incomplete documentation. • Frauds both internally/externally. • Money laundering. • Unauthorized persons access to bank’s records.
  • 13.
    July 30, 2014Kachhapi13 PEOPLE RISK • Inadequate staff. • Hiring unsuitable staff. • Loss of key personnel. • Over reliance on few key staff. • Insufficient succession & development planning. • Insufficient training. • Poor communication. • Behaviour & attitude. • Age profile.
  • 14.
    July 30, 2014Kachhapi14 SYSTEM RISKS • Programming error. • Irrelevant, inaccurate, incomplete MIS. • I T System failure. • Telecommunication failure. • Technology interference. • Failure of support functions. • Inadequacy of backup systems/procedures. • Working under different platforms/ software environment.
  • 15.
    July 30, 2014Kachhapi15 LEGAL RISKS • Breaching of regulatory requirements. • Unenforceable contracts,lawsuits. • Adverse judgments. • Executing illegal transactions. • Failure to fulfill fiduciary duties
  • 16.
    July 30, 2014Kachhapi16 External events risks. • Natural disasters.Natural disasters. • War/terrorism.War/terrorism. • Sabotage.Sabotage. • Crime.Crime.
  • 17.
    July 30, 2014Kachhapi17 REPUTATION RISKS. • Negative publicity leading to decline in customer base, costly litigation, reduction in current & prospective earnings & capital. • Effect of other risks.
  • 18.
    July 30, 2014Kachhapi18 Operational Risk – Framework & Management. 1. Organizational set up. 2. Operational Risk Management Policy. 3. Risk mapping. 4. Risk assessment. 5. Collection of Operational risk loss incident data. 6. Risk Quantification
  • 19.
    July 30, 2014Kachhapi19 Risk Assessment Categorization of identified risks – Low, Medium, High. Grading of controls – Low, Medium, High. Comparison between assessed risks & existing controls to identify : 1. High risk low control types 2. Low risk high control types 3. Less frequent high impact types 4. More frequent less impact types.
  • 20.
    July 30, 2014Kachhapi20 RISK QUANTIFICATION OPERATIONALOPERATIONAL RISKRISK CREDIT RISKCREDIT RISK MARKET RISKMARKET RISK STANDARDIZEDSTANDARDIZED APPROACHAPPROACH FOUNDATION –FOUNDATION – IRB APPROACHIRB APPROACH ADVANCED –ADVANCED – IRB APPROACHIRB APPROACH STANDARDISEDSTANDARDISED APPROACHAPPROACH INTERNALINTERNAL MEASUREMENTMEASUREMENT APPROACHAPPROACH BASICBASIC INDICATORINDICATOR APPROACHAPPROACH STANDARDIZEDSTANDARDIZED APPROACHAPPROACH ADVANCEDADVANCED MEASUREMENTMEASUREMENT APPROACHAPPROACH
  • 21.
    July 30, 2014Kachhapi21 Basic Indicator Approach • Fixed percentage on Gross income shall be the Capital to be held by the Bank for Operational risk
  • 22.
    July 30, 2014Kachhapi22 Standardized Approach • Bank’s activities are divided into: 1) Corporate Finance. 2) Trading & Sales. 3) Retail Banking. 4) Commercial Banking. 5) Payment & Settlement. 6) Agency Services & Custody. 7) Retail Brokerage. 8) Asset Management. • Capital charge to be calculated for each business line by multiplying gross income by a factor percentage assigned to it.
  • 23.
    July 30, 2014Kachhapi23 Advanced Measurement Approach • Gives discretion to the Bank to use their own internal loss data & assessment methods. • Approach shall be used only after sufficient reliable data base of operational risk loss events is built up.
  • 24.
    July 30, 2014Kachhapi24 • We have to measure operational riskWe have to measure operational risk by Basic Indicator Approach in termsby Basic Indicator Approach in terms of RBI guidelines.of RBI guidelines. • What is beneficial to Banks is AMA.What is beneficial to Banks is AMA.
  • 25.
    July 30, 2014Kachhapi25 • THANK YOU • T.V.RAO.FACULTY