due in 3 hours ..500 words business risk management .the attachment is the PowerPoint for the operationall risk management
1
Business Risk Management
Week 7: Operational Risk
MULT90014 Semester 1, 2015.
2
Learning Objectives:
By the end of this session students should be able to:
Define the nature and scope of operational risk
Compare and contrast the roles and responsibilities in the three lines of defence model.
Develop a business environment scorecard and appropriately define several key operational risks for the business.
Identify key risk indicators given a well-defined operational risk.
Distinguish between detective and preventative controls.
Operational Risk
The risk of loss resulting from inadequate or failed internal
processes, people and systems or external events.
It is often viewed as the “other” category of risk.
– i.e., if you can’t classify a risk elsewhere in the taxonomy it’s operational
risk
Less formally it is the risk of running a business.
It can permeate all aspects and every level of the business.
From the definition there appears to be no “upside”
– But: a firm may take on operational risk to achieve greater returns.
o E.g., introducing a new product, not well supported by current processes and
systems.
Because it is so pervasive it is often difficult to measure.
3
4
A Taxonomy of Operational Risks
Losses arising from acts
inconsistent with
employment, health or
safety laws or agreements,
from payment of personal
injury claims, or from
diversity / discrimination
events
Losses arising from a failure
to adequately monitor, or
provide adequate
management information on,
the transactions that the
business undertakes
Losses due to acts of a type intended to
defraud, misappropriate property or
circumvent regulations, the law or
company policy
Losses due to acts of a type
intended to defraud,
misappropriate property or
circumvent the law, by a third
party
Losses from failed transaction processing
or process management, from relations
with trade counterparties and vendors
Losses arising from an
unintentional or negligent
failure to meet a professional
obligation to specific clients
(including fiduciary and
suitability requirements), or
from the nature or design of
a product
Losses from failure to follow laws
and regulations e.g. new process
breaches a law
Risk of damage (whether real or perceived)
to the brand e.g. having a 3rd Party
sell our products Losses arising from
disruption of business or
system failures
Operational
Risk
External
Fraud/Criminal
Activities Payments & Process
Management
Customers,
Products & Sales
Practices
Internal
Fraud/Criminal
Activities
Monitoring,
Reporting
&
Oversight
Workplace Practices &
Environment
Third Party
Providers Regulatory
Environment
& Market
Practices
Systems &
Infrastructure
Some Impacts of Operational Risk
Financial - losses to the P&L, potential damage to the balance sheet
Regulatory - increased regulatory focus, resultant demands on
management time, potential enforcement and fines
Reputational - negative media coverage, industry and ratings agency
comment
Customer - customer experience damaged, loss of existing
customers, inability to attract new customers
Management Remediation - significant proportion of management
time taken up with rework and remediation of problems: ‘firefighting’
rather than getting on with managing the business for profit.
5
6
Managing Risk: Three Lines of Defence
7
7
Three Lines of Defence:
An Example Implementation in Op. Risk @ NAB
Role Accountabilities
1st
line
Business Units Accountable for identifying & managing the business
and its risks
Embedded Risk
Managers
Accountable for implementing and using the
Operational Risk processes
2nd
line
Regional Operational
Risk teams
Accountable for ensuring that Operational Risk
processes are used effectively
Group Operational
Risk Managers
Accountable for providing oversight of Regional
Operational Risk functions and ensuring that
Operational Risk Framework is working effectively
3rd
line
Internal Audit Accountable for providing independent assurance of
the NAB’s Operational Risk processes
External Audit Accountable for providing independent assurance
of the NAB’s Operational Risk processes
Source: Rob Anderson, General Manager – Operational Risk & Security, NAB
Note: The three lines of defence model applies to risk management in general, not
just operational risk. It is however especially critical in operational risk because
Operational Risk is so broad and difficult to manage by its very nature.
Managing Operational Risk The ISO31000 framework revisited
Establish the context
– The Business Environment Scorecard
Risk Assessment
– Risk identification
o Defining Risks
– Analysis & Evaluation o Impact Assessment
Risk Treatment
– Controls
o Preventative versus Detective
Monitoring and Review
– Key Risk Indicators
– Tracking Operational Risk Events
8
We’ll revisit this in
Week 8 when we
look at risk
measurement
Issues.
Business Environment Scorecard
A snapshot of the business
Covers both the external and internal environment.
Captures information about what a Business Unit does and informs
the risk profile (assessment and treatment).
Order of dimensions is important – to build up ‘picture’ of the
business.
Scorecard Dimensions:
9
1. External Social & economic environment, including dealing with external suppliers as well as competitors
2. Regulatory Regulatory/Legal environment in countries of operation.
3. Customers Type/Segment targetted by the business
4. People No. & type of employees (full/part-time, contractor, skills, salaries and incentives etc.)
5. Process Procedures & transactions carried out to deliver products & services
6. Systems Key IT systems and infrastructure
7. Change Number, size & impact of projects & change initiatives
8. Products/Services Nature of products & services (e.g., volume, quality etc.)
Risk Identification: Defining a Risk
To clearly articulate a risk, you need to:
– Understand what could possibly go wrong, identify “all the ways” it
could go wrong, identify the impact if the risk occur.
How do you know when you have got it right?
– Any person should be able to read your risk description, and
understand the risk and impact and the Controls and Key Risk
Indicators should be easy to identify.
Example Definitions:
Poor Example: Loss of key personnel
Good Example: Risk of failure to retain key personnel responsible for critical business processes, due to highly competitive
employment market in major operational centres
resulting in poor service to customers, lost
opportunities, reputational damage, and regulatory
censure 10
11
Analysis & Evaluation:
An Example Impact Assessment Template F
in a n
c ia
l
Expected Estimated aggregated operational risk loss that a BU can reasonably anticipate & estimate annually
Exceptional Estimated aggregated operational risk loss that a BU can anticipate and estimate might occur in an exceptional year, i.e. one that occurs approximately once in every 5 years.
Extreme Is it plausible that this risk could result in a potentially extreme financial impact? An extreme event is a rare single event, which is referred to as low-frequency, high-impact.
N o
n -F
in a n
c ia
l
Reputational Estimate the potential impact of the risk on the Group’s or BU’s reputation.
Regulatory Estimate the potential impact of the risk in relation to Regulatory
intervention, breach of requirements and resulting sanctions.
Customer Estimate the potential impact of the risk on customer inconvenience/ loss.
Management
Remediation
Estimate the potential impact of the risk on management time in terms of
remediation activities required to address any exposures.
Risk Treatment: Controls Controls can prevent a risk from occurring or reduce the impact
if it does occur.
Detective Controls: alert you to the fact that the risk has
occurred (ex post). E.g:
– Analysis of talent pool and potential successors for moves,
transfers and attrition
– Exit interview
– Regular performance appraisals*
Preventative Controls: help reduce the likelihood of the risk
occurring and/or the impact should it occur.
– All new staff must complete an induction program within 2 weeks,
be assigned a “buddy” from day one and complete an evaluation
questionnaire about the induction process after three months.
– Regular performance appraisals*
*(Depends on how regular and how you use them) 12
Ex Ante: Monitoring Risks - KRI
Key Risk Indicators (KRIs) provide early warnings of risks to allow
proactive risk management. They maybe either:
Leading indicators: Identify where there is a potential change in the likelihood or impact of a future or emerging risk event, given the
effectiveness of controls.
Lagging indicators: Measure retrospective data to identify the change in likelihood or impact over a given period & the current state of the control
environment.
KRIs should have tolerance thresholds set against them that align to
the business’ risk appetite.
13
Example Risk Example KRIs
Failure to manage HR availability and
capability in a call centre may lead to
general dilution of staff experience,
increased errors and a higher rate of
complaints.
Monitoring staff turnover, absence rates,
training completion and setting acceptable
thresholds for these can allow you to take
corrective action to avoid the
consequences.
Ex Post Monitoring:
Operational Risk Loss Events Databases
What: – Record operational risk events AND near misses
o Describe events/near misses, their causes and the remedial actions taken.
– Record losses involved o Include remediation costs
o Above loss thresholds (appetite issues)
– Classify events/near misses (taxonomy issues)
– Facilitate sharing of summary data with peers
Why: – Minimise future risk events
– Because regulations require it (e.g. banking/finance capital requirements,
Health and Safety requirements)
– To identify o Trends
o Systemic failures in risk management practice/culture
14
Example Summary Op. Risk Event Data
15
Source: 2014 ORX Report on Operational Risk Loss Data
16
Source: 2014 ORX Report on Operational Risk Loss Data
Example Summary Op. Risk Event Data
17
S o
u rc
e : 2
0 1
4 O
R X
R e
p o
rt o
n O
p e
ra ti o
n a l R
is k L
o s s D
a ta
18
In-Class Exercise Develop a partial Operational Risk Profile for the CEO of Tigerair
Australia focusing on:
– Business Environment
o Business objectives
o Business environment scorecard
– Risk Identification
o Define (carefully) Three Key Operational Risks.
o Identify appropriate Three Risk Indicators.
– Risk Analysis & Evaluation (for class purposes skip this and assume all risks are beyond appetite and require treatment)
o Likelihood & Consequence relative to appetite (to inform treatment)
– Risk Treatment
o For each risk identify at least one preventative control and one
detective control.
o Qualitatively describe the costs/benefits (including likely
effectiveness).