5 Mart 2011 Cumartesi

The alternative approaches

There seem to be three schools of thought in relation to the alternative approaches
to defining operational risk. The first takes a very broadbrush approach and assumes
that operational risk is everything except for market and credit risk. I will call this
the ‘wide definition’. The problem with this approach is that it becomes increasingly
difficult to manage and measure all the risks identified. However, the big advantage
is that it captures everything that is left. The second school of thought argues that
operational risk is only the risk associated with the operations department of the
financial institution. I will call this the ‘narrow definition’. There is a third school of
thought the approach of which differentiates those events over which we have control
from those which we do not due to the influence of external entities such as regulators
or competitors. An institution’s exposure to controllable events is operational risk
whereas the ‘beyond our control’ events are part of what some institutions are calling
‘strategic’ and or ‘business’ risk.
There is also a fourth approach to defining operational risk steeped in political
compromise. This takes the existing departments of the bank and splits the various
subcategories of operational risks in accordance with that organization. If any
department objects to being considered as a subcategory of the operational risk
framework they are excluded.
The problem that a lot of today’s operational risk managers are finding is that if
they adopt the wide definition they step on many toes throughout the organization.
That is why a number of banks are now adopting the third school of thought as it
allows for some political expediency by providing a convenient place to put those
risks which are deemed wholly contentious for the operational risk manager to be
involved with. Some good examples are the risks of:
Ω being taken over
Ω poor product packaging
Ω bad marketing
Ω poor public relations/reputation
Ω being uncompetitive due to pricing, customer service or poor relationship
management
Ω change in the tax laws, regulations or a change in a regulator’s interpretation of
existing rules.
IBM (UK) Ltd established the first Operational Risk Forum, an industry thought
leadership forum on 21 May 1998. At the first meeting an interesting and pragmatic
view was presented to a group of leading banks. The approach outlined was to satisfy
the following objectives:
Ω economic capital to reflect operational risk
Ω transparent calculation
Ω enable management to influence the amount of capital required through their
activities.

A number of activities had to be performed:
Ω develop methodology for Operational Event Risk measurements
Ω develop reporting infrastructure and exposure/risk calculations
Ω integrate Operational Event Risk in Economic Capital Reporting
The approach was to fit the definition of operational risk to what was achievable in
the timescales allowed by management. This approach is likely to produce early
deliverables but may not address all aspects of operational risk. The resulting
definition presented at the Operational Risk Forum was as follows:
Operational Risk is any risk or exposure associated with: customers, inadequately defined
controls, control/system failure, and unmanageable events.
It is interesting to note that ‘unmanageable events’, effectively those which are not
controllable, have been included from the perspective of managing the security of
the event. It could be argued that a firm needs to go further and address the risk of
inadequately designed controls.
The participants at the Operational Risk Forum agreed that the definition of
operational risk was the first step in addressing issues such as setting up dedicated
operational risk management groups, identifying risk types and exposures, financial
modeling, data collection, assessing regulatory requirements and addressing
resource, planning and reporting needs.
Before we attempt to offer a definition of operational risk it is worth reviewing
some of the sources of sound practice. The British Bankers’ Association/Coopers &
Lybrand survey on operational risk (March 1997) concentrated on a lack of adequate
internal controls. The more common examples of operational risk used by banks in
the survey included: system failure/error; transaction processing/control error;
business interruption; internal/external criminal act including breach of security;
and personnel risks. The Basel definition referred to by many of the Operational Risk
Forum’s participants also concentrates on losses caused by omissions of controls,
inadequacies in systems and lack of management information. The Forum agreed
that these definitions were very useful as they recognized the importance of banks’
internal control frameworks, systems and reporting mechanisms in mitigating operational
risk. However, as highlighted by many participants in the Operational Risk
Forum, the Basel definition is meant to address the minimum standard across all
banks rather than define best practice. Therefore to satisfy the more complex issues
faced by banks, who on average may have a wider business mix, products geographies
as well as a larger size it was recognized that a wider definition could be made.

Hiç yorum yok:

Yorum Gönder