The problem of defining operational risk is perplexing financial institutions. Many
banks have adopted the approach of listing categories of risk, analyzing what they
are and deciding whether they should be reporting and controlling them as a separate
risk ‘silo’ within their risk management framework as many of them have done for
market and credit risk. It is also important to note that operational risk is not
confined to financial institutions and useful examples of approaches to defining and
measuring operational risk can be gained from the nuclear, oil, gas, construction
and other industries.
Not surprisingly, operational risk is already being managed locally within each
business area with the support of functions such as legal, compliance and internal
audit. It is at the group level where the confusion is taking place on defining
operational risk. Therefore a good place to start is to internally survey ‘local’ practice
within each business unit. Such surveys will invariably result in a risk subcategorisation
of operational risk as follows:
Ω Control risk
Ω Process risk
Ω Reputational risk
Ω Human resources risk
Ω Legal risk
Ω Takeover risk
Ω Marketing risk
Ω Systems outages
Ω Aging technology
Ω Tax changes
Ω Regulatory changes
Ω Business capacity
Ω Legal risk
Ω Project risk
Ω Security
Ω Supplier management
Hiç yorum yok:
Yorum Gönder