due in 3 hours ..500 words business risk management .the attachment is the PowerPoint for the operationall risk management

profileyueryongyuan
07_oprisk.pdf

1

Business Risk Management

Week 7: Operational Risk

MULT90014 Semester 1, 2015.

2

Learning Objectives:

By the end of this session students should be able to:

 Define the nature and scope of operational risk

 Compare and contrast the roles and responsibilities in the three lines of defence model.

 Develop a business environment scorecard and appropriately define several key operational risks for the business.

 Identify key risk indicators given a well-defined operational risk.

 Distinguish between detective and preventative controls.

Operational Risk

The risk of loss resulting from inadequate or failed internal

processes, people and systems or external events.

 It is often viewed as the “other” category of risk.

– i.e., if you can’t classify a risk elsewhere in the taxonomy it’s operational

risk

 Less formally it is the risk of running a business.

 It can permeate all aspects and every level of the business.

 From the definition there appears to be no “upside”

– But: a firm may take on operational risk to achieve greater returns.

o E.g., introducing a new product, not well supported by current processes and

systems.

 Because it is so pervasive it is often difficult to measure.

3

4

A Taxonomy of Operational Risks

Losses arising from acts

inconsistent with

employment, health or

safety laws or agreements,

from payment of personal

injury claims, or from

diversity / discrimination

events

Losses arising from a failure

to adequately monitor, or

provide adequate

management information on,

the transactions that the

business undertakes

Losses due to acts of a type intended to

defraud, misappropriate property or

circumvent regulations, the law or

company policy

Losses due to acts of a type

intended to defraud,

misappropriate property or

circumvent the law, by a third

party

Losses from failed transaction processing

or process management, from relations

with trade counterparties and vendors

Losses arising from an

unintentional or negligent

failure to meet a professional

obligation to specific clients

(including fiduciary and

suitability requirements), or

from the nature or design of

a product

Losses from failure to follow laws

and regulations e.g. new process

breaches a law

Risk of damage (whether real or perceived)

to the brand e.g. having a 3rd Party

sell our products Losses arising from

disruption of business or

system failures

Operational

Risk

External

Fraud/Criminal

Activities Payments & Process

Management

Customers,

Products & Sales

Practices

Internal

Fraud/Criminal

Activities

Monitoring,

Reporting

&

Oversight

Workplace Practices &

Environment

Third Party

Providers Regulatory

Environment

& Market

Practices

Systems &

Infrastructure

Some Impacts of Operational Risk

 Financial - losses to the P&L, potential damage to the balance sheet

 Regulatory - increased regulatory focus, resultant demands on

management time, potential enforcement and fines

 Reputational - negative media coverage, industry and ratings agency

comment

 Customer - customer experience damaged, loss of existing

customers, inability to attract new customers

 Management Remediation - significant proportion of management

time taken up with rework and remediation of problems: ‘firefighting’

rather than getting on with managing the business for profit.

5

6

Managing Risk: Three Lines of Defence

7

7

Three Lines of Defence:

An Example Implementation in Op. Risk @ NAB

Role Accountabilities

1st

line

Business Units Accountable for identifying & managing the business

and its risks

Embedded Risk

Managers

Accountable for implementing and using the

Operational Risk processes

2nd

line

Regional Operational

Risk teams

Accountable for ensuring that Operational Risk

processes are used effectively

Group Operational

Risk Managers

Accountable for providing oversight of Regional

Operational Risk functions and ensuring that

Operational Risk Framework is working effectively

3rd

line

Internal Audit Accountable for providing independent assurance of

the NAB’s Operational Risk processes

External Audit Accountable for providing independent assurance

of the NAB’s Operational Risk processes

Source: Rob Anderson, General Manager – Operational Risk & Security, NAB

Note: The three lines of defence model applies to risk management in general, not

just operational risk. It is however especially critical in operational risk because

Operational Risk is so broad and difficult to manage by its very nature.

Managing Operational Risk The ISO31000 framework revisited

 Establish the context

– The Business Environment Scorecard

 Risk Assessment

– Risk identification

o Defining Risks

– Analysis & Evaluation o Impact Assessment

 Risk Treatment

– Controls

o Preventative versus Detective

 Monitoring and Review

– Key Risk Indicators

– Tracking Operational Risk Events

8

We’ll revisit this in

Week 8 when we

look at risk

measurement

Issues.

Business Environment Scorecard

 A snapshot of the business

 Covers both the external and internal environment.

 Captures information about what a Business Unit does and informs

the risk profile (assessment and treatment).

 Order of dimensions is important – to build up ‘picture’ of the

business.

Scorecard Dimensions:

9

1. External Social & economic environment, including dealing with external suppliers as well as competitors

2. Regulatory Regulatory/Legal environment in countries of operation.

3. Customers Type/Segment targetted by the business

4. People No. & type of employees (full/part-time, contractor, skills, salaries and incentives etc.)

5. Process Procedures & transactions carried out to deliver products & services

6. Systems Key IT systems and infrastructure

7. Change Number, size & impact of projects & change initiatives

8. Products/Services Nature of products & services (e.g., volume, quality etc.)

Risk Identification: Defining a Risk

 To clearly articulate a risk, you need to:

– Understand what could possibly go wrong, identify “all the ways” it

could go wrong, identify the impact if the risk occur.

 How do you know when you have got it right?

– Any person should be able to read your risk description, and

understand the risk and impact and the Controls and Key Risk

Indicators should be easy to identify.

 Example Definitions:

Poor Example: Loss of key personnel

Good Example: Risk of failure to retain key personnel responsible for critical business processes, due to highly competitive

employment market in major operational centres

resulting in poor service to customers, lost

opportunities, reputational damage, and regulatory

censure 10

11

Analysis & Evaluation:

An Example Impact Assessment Template F

in a n

c ia

l

Expected Estimated aggregated operational risk loss that a BU can reasonably anticipate & estimate annually

Exceptional Estimated aggregated operational risk loss that a BU can anticipate and estimate might occur in an exceptional year, i.e. one that occurs approximately once in every 5 years.

Extreme Is it plausible that this risk could result in a potentially extreme financial impact? An extreme event is a rare single event, which is referred to as low-frequency, high-impact.

N o

n -F

in a n

c ia

l

Reputational Estimate the potential impact of the risk on the Group’s or BU’s reputation.

Regulatory Estimate the potential impact of the risk in relation to Regulatory

intervention, breach of requirements and resulting sanctions.

Customer Estimate the potential impact of the risk on customer inconvenience/ loss.

Management

Remediation

Estimate the potential impact of the risk on management time in terms of

remediation activities required to address any exposures.

Risk Treatment: Controls  Controls can prevent a risk from occurring or reduce the impact

if it does occur.

 Detective Controls: alert you to the fact that the risk has

occurred (ex post). E.g:

– Analysis of talent pool and potential successors for moves,

transfers and attrition

– Exit interview

– Regular performance appraisals*

 Preventative Controls: help reduce the likelihood of the risk

occurring and/or the impact should it occur.

– All new staff must complete an induction program within 2 weeks,

be assigned a “buddy” from day one and complete an evaluation

questionnaire about the induction process after three months.

– Regular performance appraisals*

*(Depends on how regular and how you use them) 12

Ex Ante: Monitoring Risks - KRI

 Key Risk Indicators (KRIs) provide early warnings of risks to allow

proactive risk management. They maybe either:

Leading indicators: Identify where there is a potential change in the likelihood or impact of a future or emerging risk event, given the

effectiveness of controls.

Lagging indicators: Measure retrospective data to identify the change in likelihood or impact over a given period & the current state of the control

environment.

 KRIs should have tolerance thresholds set against them that align to

the business’ risk appetite.

13

Example Risk Example KRIs

Failure to manage HR availability and

capability in a call centre may lead to

general dilution of staff experience,

increased errors and a higher rate of

complaints.

Monitoring staff turnover, absence rates,

training completion and setting acceptable

thresholds for these can allow you to take

corrective action to avoid the

consequences.

Ex Post Monitoring:

Operational Risk Loss Events Databases

 What: – Record operational risk events AND near misses

o Describe events/near misses, their causes and the remedial actions taken.

– Record losses involved o Include remediation costs

o Above loss thresholds (appetite issues)

– Classify events/near misses (taxonomy issues)

– Facilitate sharing of summary data with peers

 Why: – Minimise future risk events

– Because regulations require it (e.g. banking/finance capital requirements,

Health and Safety requirements)

– To identify o Trends

o Systemic failures in risk management practice/culture

14

Example Summary Op. Risk Event Data

15

Source: 2014 ORX Report on Operational Risk Loss Data

16

Source: 2014 ORX Report on Operational Risk Loss Data

Example Summary Op. Risk Event Data

17

S o

u rc

e : 2

0 1

4 O

R X

R e

p o

rt o

n O

p e

ra ti o

n a l R

is k L

o s s D

a ta

18

In-Class Exercise  Develop a partial Operational Risk Profile for the CEO of Tigerair

Australia focusing on:

– Business Environment

o Business objectives

o Business environment scorecard

– Risk Identification

o Define (carefully) Three Key Operational Risks.

o Identify appropriate Three Risk Indicators.

– Risk Analysis & Evaluation (for class purposes skip this and assume all risks are beyond appetite and require treatment)

o Likelihood & Consequence relative to appetite (to inform treatment)

– Risk Treatment

o For each risk identify at least one preventative control and one

detective control.

o Qualitatively describe the costs/benefits (including likely

effectiveness).