This chapter focuses on the challenges facing a risk manager overseeing an energy
portfolio. It sets out a general overview of the markets as they relate to risk management
and the risk quantification and control issues implicit in an energy portfolio.
The energy markets are extremely intricate, rich in multiple markets, liquidity
problems, extreme volatility issues, non-normal distributions, ‘real’ option pricing
problems, mark-to-model problems, operational difficulties and data management
nightmares. The market, to use the academic understatement, is complex and
challenging but most of all it is extremely interesting. In particular, this chapter will
focus on the challenges in the electricity market, which is by far the largest market
within energy1 and exhibits most of the problems faced by energy risk managers,
whether in power or not.
24 Haziran 2011 Cuma
21 Haziran 2011 Salı
Special issues
There should be frequent interaction between the risk managers and the and
compliance unit. Risk managers can alert compliance to risk concentrations as well
as large risk changes. Conversely, compliance violations may serve as an early
warning for the risk managers that analysis or operations controls may be
insufficient.
Both internal and external auditors provide a fresh perspective on compliance
and documentation controls. Regulators frequently refer to external auditors’ work
papers. Since work papers may be accessed by the regulators, it is important to
review problem areas or challenges cited in these reports. On a cautionary note,
one should not always rely on the conclusions of external auditors. Often they are
not tough enough, especially if they have been reviewing the same firm for many
years. They may become complacent. Alternatively, in a merger situation, there is
the moral hazard risk that the auditors may be less confrontational if they fear
losing the company’s business. Audits typically occur on an annual basis but rarely
more frequently. One should ensure that the day-to-day gets done properly and a
year between recommendations of changes and the next audit may be too long a
time.
The required implementation of FAS 133, delayed until after June 2000, will
necessitate extensive new documentation requirements for individual companies.
The exact contours of these requirements are still being worked out by a FAS working
group and interested parties. Each derivatives hedge will need to be classified, e.g.
as a fair value or cash flow hedge and each hedge will need to be tested periodically
for effectiveness. The economic performance of the hedge will be divided into ineffective
and effective components, assuming it is not a perfect offset. New subledger
accounts need to be created to record these entries and income and/or equity
volatility is likely occur due to these changes. High-volume users will need to integrate
FAS 133 classification directly into the reporting systems. An ironic result of FAS
133 is that the accounting hurdles to qualify for hedge accounting may well be more
stringent that legal requirements authorizing the use of derivatives for some endusers.
Since the new changes are so fundamental, it is likely that a new accounting
policy manual will need to be written to incorporate all the contemplated changes.
Ensuring consistent usage and treatments across portfolios will create new compliance
hurdles.
Y2K preparations have received endless attention in the popular media and industry
meetings. Business resumption plans and back-up systems are an integral part
of theses efforts. Special issues to be addressed include the need to maintain ready
(manual) access to trade confirmations, ISDA master agreements, cash forecast
reports, credit line availability, etc. The prompt receipt of and sending of trade
confirmations is a crucial control to establishing contractual rights.
Summary
Compliance and documentation controls are rarely popular topics. In the area of
derivatives, controls are complicated by overlapping or inconsistent regulatory oversight.
One senior attorney termed the complicated US regulatory system as a ‘bifurcated
mess’ (Russo, 1994). Compliance extends beyond addressing regulators’
guidance or adherence to internal polices; other agencies can exercise oversight.
Witness First Union Corp.’s problems for violating US Treasury auction rules. These
violations were against restrictions prohibiting the prior resale of Treasuries bought
via no-competitive bids at government auction. Although the US Treasury did not
have regulatory oversight and was not on the ‘radar screen’, it still was able to enforce
sanctions against First Union (Vames, 1999).
Compliance serves an especially valuable role in safeguarding the reputation of a
firm and ensuring that there are no nasty surprises. There is a variety of compliance
infrastructures and the most workable ones have the flexibility to respond to market
and regulatory changes. Large compliance problems do not typically result as the
result of a single transaction but of a pattern of action that develops over time. Onsite
monitoring helps discourage these patterns of behavior. The support of business
lines should be sought and they should be involved in the writing of the compliance
policies. Compliance controls should be on-site, comprehensive, linked to the business,
and coordinated by a central compliance unit. Effective controls can help
reduce capital needed for the business.
Compliance must examine the microlevel transactions as well as the macrolevel
(e.g. credit concentrations.) Partnerships, joint ventures, and third-party sales forces
are especially troublesome since a firm’s money and reputation are on the line and
the firm may have limited oversight of compliance controls.
Compliance management can be costly and may absorb valuable resources, and
regulators are cognizant of this. In the future, regulators will likely rely more on
internal business reports and function more as supervisors than regulators. This
oversight should allow examination to be more streamlined and to focus on existing
and emerging problem areas (Wixted, 1987). Regulators will ask for special exposure
reports as new crises emerge and a firm’s data systems must be able to run these
special queries.
The goal of compliance is not to achieve a minimum passing grade. Rather it is to
ensure that regulations are being followed, internal policies and procedures are being
adhered to, effective controls are in place, and that timely and accurate information
is being provided to senior management and ultimately to the board. If a company
performs its compliance duties well, the controls will be professional and unobtrusive,
and enable senior management to focus on other business concerns. The best
compliance efforts are those that will keep pace with the ever-expanding derivatives
markets.
Notes
1 OCC, release 96.2, occ.treas.gov
2 Enterprise Risk Management, Glyn Holton, p. 7, contingencyanalysis.com
3 Several large US life insurers have implemented enhanced compliance policies due to the
sales practices scandal of the early 1990s. (Salesforces often view them as quite burdensome
since every new sale is checked as opposed to a spot-checking process.) Several companies
received large fines from state regulators due to the manner in which policies were sold to
the public. Although derivatives were not involved, the lack of disclosure is analogous to
derivative sales problems.
4 Charges were based on the ‘books and records’ provision of the Securities Exchange Act of
1934.
5 ISDA stands for International Swaps and Derivatives Association, Inc. and IFEMA for International
Foreign Exchange Master Agreement. Standard contract forms created by these
industry groups are used as the basis for documenting the rights and duties of parties to
over-the-counter derivatives contracts.
6ABN’s New York office discovered the misvaluations of foreign currency call options held by
a FX options trader. In the news stories published, it was indicated that the implied volatilities
of options held were overstated in order to hide losses.
7 There is a wealth of guidance in the area of derivative risk control. Several regulatory
organizations as well as private industry groups have produced excellent suggestions and
guidelines for writing risk policies. Most prominent are Group of 30, the Federal Reserve,
the OCC, and others as well as the Risk Standards Working Group (focusing on money
managers).
8 By David E. Aron, an associate in the futures and derivatives practice at Dechert Price &
Rhoads in Washington, DC, and Jeremy Bassil, an associate in the Financial Services
Department at Titmuss Sainer Dechert in London.
Appendix: US and UK regulatory schemes
Table A1 Major US regulatory oversight
Commercial bank (depending on charter)
Federal Reserve Board and local Fed OCC (depending on charter)
State Banking Department (depending on charter)
FDIC
Insurance company (pension fund monies trigger ERISA laws)
State Insurance Department
NAIC
SEC
NASD
Investment bank
SEC
State securities (blue sky) laws
NASD
Exchanges and their clearing corporations (e.g. NYSE)
Banking Regulator (if bank sub)
CFTC and commodities exchanges
Table A2 Current major UK regulatory oversight8
Commercial or investment banka
Bank of England (BoE)b
Financial Services Authority (FSA)c
Insurance companyd
Her Majesty’s Treasury (HMT)e
Pesonal investment authority (PIA)f
Retail brokerage
SFAg
PIA
aInsofar as commercial or investment banks (or other entities in this table)
conduct certain activities, they may also be regulated by the Investment
Management Regulatory Organization (investment management) or
Securities and Futures Authority (SFA) (e.g. corporate finance).
bHas only general market protection authority – regulates the banking
system, the money supply and payment systems.
cRegulates authorization and supervision.
dLloyd’s and other commercial insurers are generally unregulated.
eResponsible fo prudential and related regulation.
fRegulates intermediaries marking investment products to retail customers
and regulates the product providers themselves.
gRegulates broker-dealers.
Table A3 UK regulatory oversight upon enactment of the Financial
services and Markets Billa,8
Commercial or investment bank
BoE
FSA
Insurance company
FSAb
Retail brokerage
FSAc
aThe Financial Services and Markets Bill is expected to be enacted by
early 2000.
bWill assume current authority of HMT and PIA; regulation of Lloyd’s and
other commercial insurers is being considered.
c Will assume current authority of SFA and PIA.
References
Basel Committee on Banking Supervision (1998) Framework for the evaluation of
internal control systems, Basel, January, p. 15.
Erikson, J. O. (1996) ‘Lessons for policymakers and private practitioners in risk
management’, Derivatives and Public Policy Conference, frbchi.org, p. 54.
Ewing, T. and Bailey, J. (1999) ‘Dashed futures: how a trading firm’s founders were
blindsided by a bombshell’, Wall Street Journal, 18 February, C1.
McDermott, D. and Webb, S. (1999) ‘How Merrill wished upon a star banker and
wound up in a Singapore sling’, Wall Street Journal, 21 May, C1.
OCC Comptroller’s Handbook (1997) ‘Risk management of financial derivatives’,
Washington, DC, January. occ.treas.gov, p. 64.
Peteren, M. (1999) ‘Merrill charged with 2d firms in copper case’, New York Times,
21 May, d7.
Risk Standards Working Group (1996) Risk Standards for Institutional Investment
Managers and Institutional Investors, p. 19, cmra.com.
Russo, T. A. (1996) Address to Futures Industry Association, 4 March.
Singer, J. (1999) ‘Credit Suisse apologizes for blocking Japan probe’, Bloomberg
News Service, 21 May.
Vames, S. (1999) ‘Some public penance is payment in full for breaking rules’, Wall
Street Journal, 20 May, C20.
Wixted, J. J., Jr (1987) ‘The future of bank regulation’, Federal Reserve Bank of
Chicago, 18 July, address to the Iowa Independent Bankers Annual Meeting and
Convention, frbchi.org, p. 8. 524
compliance unit. Risk managers can alert compliance to risk concentrations as well
as large risk changes. Conversely, compliance violations may serve as an early
warning for the risk managers that analysis or operations controls may be
insufficient.
Both internal and external auditors provide a fresh perspective on compliance
and documentation controls. Regulators frequently refer to external auditors’ work
papers. Since work papers may be accessed by the regulators, it is important to
review problem areas or challenges cited in these reports. On a cautionary note,
one should not always rely on the conclusions of external auditors. Often they are
not tough enough, especially if they have been reviewing the same firm for many
years. They may become complacent. Alternatively, in a merger situation, there is
the moral hazard risk that the auditors may be less confrontational if they fear
losing the company’s business. Audits typically occur on an annual basis but rarely
more frequently. One should ensure that the day-to-day gets done properly and a
year between recommendations of changes and the next audit may be too long a
time.
The required implementation of FAS 133, delayed until after June 2000, will
necessitate extensive new documentation requirements for individual companies.
The exact contours of these requirements are still being worked out by a FAS working
group and interested parties. Each derivatives hedge will need to be classified, e.g.
as a fair value or cash flow hedge and each hedge will need to be tested periodically
for effectiveness. The economic performance of the hedge will be divided into ineffective
and effective components, assuming it is not a perfect offset. New subledger
accounts need to be created to record these entries and income and/or equity
volatility is likely occur due to these changes. High-volume users will need to integrate
FAS 133 classification directly into the reporting systems. An ironic result of FAS
133 is that the accounting hurdles to qualify for hedge accounting may well be more
stringent that legal requirements authorizing the use of derivatives for some endusers.
Since the new changes are so fundamental, it is likely that a new accounting
policy manual will need to be written to incorporate all the contemplated changes.
Ensuring consistent usage and treatments across portfolios will create new compliance
hurdles.
Y2K preparations have received endless attention in the popular media and industry
meetings. Business resumption plans and back-up systems are an integral part
of theses efforts. Special issues to be addressed include the need to maintain ready
(manual) access to trade confirmations, ISDA master agreements, cash forecast
reports, credit line availability, etc. The prompt receipt of and sending of trade
confirmations is a crucial control to establishing contractual rights.
Summary
Compliance and documentation controls are rarely popular topics. In the area of
derivatives, controls are complicated by overlapping or inconsistent regulatory oversight.
One senior attorney termed the complicated US regulatory system as a ‘bifurcated
mess’ (Russo, 1994). Compliance extends beyond addressing regulators’
guidance or adherence to internal polices; other agencies can exercise oversight.
Witness First Union Corp.’s problems for violating US Treasury auction rules. These
violations were against restrictions prohibiting the prior resale of Treasuries bought
via no-competitive bids at government auction. Although the US Treasury did not
have regulatory oversight and was not on the ‘radar screen’, it still was able to enforce
sanctions against First Union (Vames, 1999).
Compliance serves an especially valuable role in safeguarding the reputation of a
firm and ensuring that there are no nasty surprises. There is a variety of compliance
infrastructures and the most workable ones have the flexibility to respond to market
and regulatory changes. Large compliance problems do not typically result as the
result of a single transaction but of a pattern of action that develops over time. Onsite
monitoring helps discourage these patterns of behavior. The support of business
lines should be sought and they should be involved in the writing of the compliance
policies. Compliance controls should be on-site, comprehensive, linked to the business,
and coordinated by a central compliance unit. Effective controls can help
reduce capital needed for the business.
Compliance must examine the microlevel transactions as well as the macrolevel
(e.g. credit concentrations.) Partnerships, joint ventures, and third-party sales forces
are especially troublesome since a firm’s money and reputation are on the line and
the firm may have limited oversight of compliance controls.
Compliance management can be costly and may absorb valuable resources, and
regulators are cognizant of this. In the future, regulators will likely rely more on
internal business reports and function more as supervisors than regulators. This
oversight should allow examination to be more streamlined and to focus on existing
and emerging problem areas (Wixted, 1987). Regulators will ask for special exposure
reports as new crises emerge and a firm’s data systems must be able to run these
special queries.
The goal of compliance is not to achieve a minimum passing grade. Rather it is to
ensure that regulations are being followed, internal policies and procedures are being
adhered to, effective controls are in place, and that timely and accurate information
is being provided to senior management and ultimately to the board. If a company
performs its compliance duties well, the controls will be professional and unobtrusive,
and enable senior management to focus on other business concerns. The best
compliance efforts are those that will keep pace with the ever-expanding derivatives
markets.
Notes
1 OCC, release 96.2, occ.treas.gov
2 Enterprise Risk Management, Glyn Holton, p. 7, contingencyanalysis.com
3 Several large US life insurers have implemented enhanced compliance policies due to the
sales practices scandal of the early 1990s. (Salesforces often view them as quite burdensome
since every new sale is checked as opposed to a spot-checking process.) Several companies
received large fines from state regulators due to the manner in which policies were sold to
the public. Although derivatives were not involved, the lack of disclosure is analogous to
derivative sales problems.
4 Charges were based on the ‘books and records’ provision of the Securities Exchange Act of
1934.
5 ISDA stands for International Swaps and Derivatives Association, Inc. and IFEMA for International
Foreign Exchange Master Agreement. Standard contract forms created by these
industry groups are used as the basis for documenting the rights and duties of parties to
over-the-counter derivatives contracts.
6ABN’s New York office discovered the misvaluations of foreign currency call options held by
a FX options trader. In the news stories published, it was indicated that the implied volatilities
of options held were overstated in order to hide losses.
7 There is a wealth of guidance in the area of derivative risk control. Several regulatory
organizations as well as private industry groups have produced excellent suggestions and
guidelines for writing risk policies. Most prominent are Group of 30, the Federal Reserve,
the OCC, and others as well as the Risk Standards Working Group (focusing on money
managers).
8 By David E. Aron, an associate in the futures and derivatives practice at Dechert Price &
Rhoads in Washington, DC, and Jeremy Bassil, an associate in the Financial Services
Department at Titmuss Sainer Dechert in London.
Appendix: US and UK regulatory schemes
Table A1 Major US regulatory oversight
Commercial bank (depending on charter)
Federal Reserve Board and local Fed OCC (depending on charter)
State Banking Department (depending on charter)
FDIC
Insurance company (pension fund monies trigger ERISA laws)
State Insurance Department
NAIC
SEC
NASD
Investment bank
SEC
State securities (blue sky) laws
NASD
Exchanges and their clearing corporations (e.g. NYSE)
Banking Regulator (if bank sub)
CFTC and commodities exchanges
Table A2 Current major UK regulatory oversight8
Commercial or investment banka
Bank of England (BoE)b
Financial Services Authority (FSA)c
Insurance companyd
Her Majesty’s Treasury (HMT)e
Pesonal investment authority (PIA)f
Retail brokerage
SFAg
PIA
aInsofar as commercial or investment banks (or other entities in this table)
conduct certain activities, they may also be regulated by the Investment
Management Regulatory Organization (investment management) or
Securities and Futures Authority (SFA) (e.g. corporate finance).
bHas only general market protection authority – regulates the banking
system, the money supply and payment systems.
cRegulates authorization and supervision.
dLloyd’s and other commercial insurers are generally unregulated.
eResponsible fo prudential and related regulation.
fRegulates intermediaries marking investment products to retail customers
and regulates the product providers themselves.
gRegulates broker-dealers.
Table A3 UK regulatory oversight upon enactment of the Financial
services and Markets Billa,8
Commercial or investment bank
BoE
FSA
Insurance company
FSAb
Retail brokerage
FSAc
aThe Financial Services and Markets Bill is expected to be enacted by
early 2000.
bWill assume current authority of HMT and PIA; regulation of Lloyd’s and
other commercial insurers is being considered.
c Will assume current authority of SFA and PIA.
References
Basel Committee on Banking Supervision (1998) Framework for the evaluation of
internal control systems, Basel, January, p. 15.
Erikson, J. O. (1996) ‘Lessons for policymakers and private practitioners in risk
management’, Derivatives and Public Policy Conference, frbchi.org, p. 54.
Ewing, T. and Bailey, J. (1999) ‘Dashed futures: how a trading firm’s founders were
blindsided by a bombshell’, Wall Street Journal, 18 February, C1.
McDermott, D. and Webb, S. (1999) ‘How Merrill wished upon a star banker and
wound up in a Singapore sling’, Wall Street Journal, 21 May, C1.
OCC Comptroller’s Handbook (1997) ‘Risk management of financial derivatives’,
Washington, DC, January. occ.treas.gov, p. 64.
Peteren, M. (1999) ‘Merrill charged with 2d firms in copper case’, New York Times,
21 May, d7.
Risk Standards Working Group (1996) Risk Standards for Institutional Investment
Managers and Institutional Investors, p. 19, cmra.com.
Russo, T. A. (1996) Address to Futures Industry Association, 4 March.
Singer, J. (1999) ‘Credit Suisse apologizes for blocking Japan probe’, Bloomberg
News Service, 21 May.
Vames, S. (1999) ‘Some public penance is payment in full for breaking rules’, Wall
Street Journal, 20 May, C20.
Wixted, J. J., Jr (1987) ‘The future of bank regulation’, Federal Reserve Bank of
Chicago, 18 July, address to the Iowa Independent Bankers Annual Meeting and
Convention, frbchi.org, p. 8. 524
Automating processes
Automating processes for the benefit of compliance is a difficult sell in most organizations.
It costs money and compliance is not a revenue area. Compliance often finds
itself looking to risk management reports generated for different purposes in order
to track activities and transactions. Information may indeed be available but the
focus of the data architects was on different goals. A common hurdle is that
reconciliation are done manually to end reports and not to source input. This causes
the similar reconciliation to be preformed periodically and sometimes previous
corrections are omitted in later reports and have to be redone.
Risk management reports may utilize different standards of accuracy since those
reports are focused more on economic exposure as opposed to legal risks and
documentation risks. The reports will likely focus on end-of-day or reporting period
rather than providing equal focus with intraday trades and closed-out positions.
Obviously any computer report will not provide the reader with the context for the
decision nor whether sufficient disclosure occurred nor what suitability checks were
performed.
Given the variety of systems and derivative instruments available, there may not
be a ready ability to perform an electronic file transfer. The alternative is to work
with existing reports and often a rekeying the data into a spreadsheet format. If the
number of transactions are too cumbersome then a possible approach is to sample
typical transactions and test the thoroughness and timeliness of the supporting
documentation.
With the proliferation of databases, these are useful tools to help standardize
documentation and disclosure. A database can provide a sample of standardized
disclosures and consistent templates for term sheets. One should require that all
term sheets sent out be copied and retained by a compliance unit.
When compliance standards and controls are set too high, it can engender resistance,
avoidance, or a hesitation to do something profitable and in the best interests
of the shareholders. The following are several examples of processes or procedures
that were counterproductive.
An end-user established an elaborate approval process for the approval of foreign
exchange forwards. Only a couple of senior managers could authorize transactions.
Given the difficulty of getting a time slot to see the senior people and the elaborate
form, the employee simply waited until the forward exposure became a spot transaction.
He then executed in the market and avoided the approval process. The trader
was not held accountable for gains or losses on unhedged positions and so expediency
ruled.
In another case, a company allowed only its CEO to authorize the use of the
company’s guarantee. Given the inability to schedule time with the CEO and the
smaller relative size of the transaction that need a guarantee, the profitable opportunity
was allowed to be passed by.
In another situation, the SVP level in a company could approve expenditures up
to a limited dollar amount on IT systems, otherwise it went to the board for approval.
A derivatives monitoring system was needed. So the need was split into different
budget cycles. The result was two systems that did not provide a consistent valuation
and monitoring capabilities to the derivatives holdings.
In another case, an end-user in a highly regulated industry wanted to buy receiver
swaptions in order to hedge MBS prepayment risk in the event of lower rates. There
was no specific authorization or prohibition in the law as to the use of swaptions.
The in-house legal department refrained from going for regulatory approval since
derivatives were considered to have too high a profile and the company wanted to
avoid additional oversight requirements. So no hedges were ever done.
The highest comfort level possible is obtained by performing a compliance audit.
Although onerous and time-consuming, it’s the best approach. If practical, randomly
select several days a month where you review each transaction that occurred and
‘track through’ the process to ensure that all procedures were adequately followed.
Look more closely than simply verifying that all documents were signed. How
many revisions occurred (were they material), was there a delay in the sign-off
confirmations? Were intraday or overnight position limits breached? Did the market
trigger the violation or was it an active breach? How long did the breach languish?
Was the breach properly escalated? Did management reports contain all the required
information? Were exceptions properly noted? Is there a compliance calendar? Were
regulatory reports filed on time?
Each salesperson should be able to provide a listing of active clients and deactivate
old customers. Old authorizations or documentation that becomes stale should be
reviewed automatically. On an annual basis, a compliance staffer should review the
documentation file to ensure that it remains adequate and there are no omissions.
Companies are rarely blindsided by regulatory change, rather it is the failure to
adequately prepare to accommodate the change that is the problem.
Consistency in approach and effort is a critical standard for effective compliance
oversight. It is inconsistent controls that create the opportunity for problems to
occur, fester, and multiply. Critical to success is a good personal and working
relationship between the business side and compliance ‘crew’. If personality conflicts
occur or egos clash, then the each side may work at cross-purposes or simply revert
to a ‘help only if asked’ approach. Effectiveness only occurs with consistent teamwork
and trust.
It costs money and compliance is not a revenue area. Compliance often finds
itself looking to risk management reports generated for different purposes in order
to track activities and transactions. Information may indeed be available but the
focus of the data architects was on different goals. A common hurdle is that
reconciliation are done manually to end reports and not to source input. This causes
the similar reconciliation to be preformed periodically and sometimes previous
corrections are omitted in later reports and have to be redone.
Risk management reports may utilize different standards of accuracy since those
reports are focused more on economic exposure as opposed to legal risks and
documentation risks. The reports will likely focus on end-of-day or reporting period
rather than providing equal focus with intraday trades and closed-out positions.
Obviously any computer report will not provide the reader with the context for the
decision nor whether sufficient disclosure occurred nor what suitability checks were
performed.
Given the variety of systems and derivative instruments available, there may not
be a ready ability to perform an electronic file transfer. The alternative is to work
with existing reports and often a rekeying the data into a spreadsheet format. If the
number of transactions are too cumbersome then a possible approach is to sample
typical transactions and test the thoroughness and timeliness of the supporting
documentation.
With the proliferation of databases, these are useful tools to help standardize
documentation and disclosure. A database can provide a sample of standardized
disclosures and consistent templates for term sheets. One should require that all
term sheets sent out be copied and retained by a compliance unit.
When compliance standards and controls are set too high, it can engender resistance,
avoidance, or a hesitation to do something profitable and in the best interests
of the shareholders. The following are several examples of processes or procedures
that were counterproductive.
An end-user established an elaborate approval process for the approval of foreign
exchange forwards. Only a couple of senior managers could authorize transactions.
Given the difficulty of getting a time slot to see the senior people and the elaborate
form, the employee simply waited until the forward exposure became a spot transaction.
He then executed in the market and avoided the approval process. The trader
was not held accountable for gains or losses on unhedged positions and so expediency
ruled.
In another case, a company allowed only its CEO to authorize the use of the
company’s guarantee. Given the inability to schedule time with the CEO and the
smaller relative size of the transaction that need a guarantee, the profitable opportunity
was allowed to be passed by.
In another situation, the SVP level in a company could approve expenditures up
to a limited dollar amount on IT systems, otherwise it went to the board for approval.
A derivatives monitoring system was needed. So the need was split into different
budget cycles. The result was two systems that did not provide a consistent valuation
and monitoring capabilities to the derivatives holdings.
In another case, an end-user in a highly regulated industry wanted to buy receiver
swaptions in order to hedge MBS prepayment risk in the event of lower rates. There
was no specific authorization or prohibition in the law as to the use of swaptions.
The in-house legal department refrained from going for regulatory approval since
derivatives were considered to have too high a profile and the company wanted to
avoid additional oversight requirements. So no hedges were ever done.
The highest comfort level possible is obtained by performing a compliance audit.
Although onerous and time-consuming, it’s the best approach. If practical, randomly
select several days a month where you review each transaction that occurred and
‘track through’ the process to ensure that all procedures were adequately followed.
Look more closely than simply verifying that all documents were signed. How
many revisions occurred (were they material), was there a delay in the sign-off
confirmations? Were intraday or overnight position limits breached? Did the market
trigger the violation or was it an active breach? How long did the breach languish?
Was the breach properly escalated? Did management reports contain all the required
information? Were exceptions properly noted? Is there a compliance calendar? Were
regulatory reports filed on time?
Each salesperson should be able to provide a listing of active clients and deactivate
old customers. Old authorizations or documentation that becomes stale should be
reviewed automatically. On an annual basis, a compliance staffer should review the
documentation file to ensure that it remains adequate and there are no omissions.
Companies are rarely blindsided by regulatory change, rather it is the failure to
adequately prepare to accommodate the change that is the problem.
Consistency in approach and effort is a critical standard for effective compliance
oversight. It is inconsistent controls that create the opportunity for problems to
occur, fester, and multiply. Critical to success is a good personal and working
relationship between the business side and compliance ‘crew’. If personality conflicts
occur or egos clash, then the each side may work at cross-purposes or simply revert
to a ‘help only if asked’ approach. Effectiveness only occurs with consistent teamwork
and trust.
Centralized data gathering
Compliance casts a wide net but there are events and occurrences that can slip
through the interstices. A major pitfall of centralized data gathering is the wide
variety of derivatives products offered and the need to standardize the data. This
aggregation process can come at a cost of accuracy in the details of individual
transactions. The derivatives business has evolved dramatically and controls and
compliance efforts may fail to keep pace.
Business and technical support often falls into strict control units or divisions and
there is little overlap with other units. The systems requirements are often developed
devoid of ensuring compatibility within the entire organization. Since the same
salesperson can often sell products on behalf of a number of legal entities, effective
control becomes more problematic. Data fields, reports, etc. can mean different
things or be used for different purposes within different parts of an organization.
Information is often aggregated for risk management or accounting purposes and it
becomes difficult to isolate all the details of individual transactions. A related problem
occurs when holding are managed by an outside manager and the numbers need to
be manually ‘rolled into’ total holdings reports.
With specially tailored transactions, there may be special provisions or options
that cannot be recorded in the existing systems. As a result they may not appear on
a regular report. For simplicity, information may be ordered by stated maturity date
and not include other pertinent data. A major challenge is that report cutoff times
are often different and a good deal of time is spent on needless reconciliation. There
may be classification overlaps as well. Trusts, partnerships and affiliates and custody
agents may all figure in the equation and one may not readily obtain a complete
listing of all positions held.
To ensure that all data is being collected, one should obtain process flow diagrams
covering all product and customer flows. Lists of reports and samples of each reports
should be obtained to ensure completeness. Special attention should be paid to
reports whose formats or scope change over time since this may trigger unintended
omissions or other unhappy consequences.
Typical problem signs occur when you sometimes have the original trade documents
and sometimes copies. This indicates a lack of consistency or control. All
transactions should be serial numbered or time stamped in order to enable crosschecking
with market levels and credit limits. Files that contain only part of
the required documents or inconsistency in contents and storage locations of the
files should also cause concern. One should be especially alert for backdated
approvals.
One should also obtain a document-aging list. A signed document gives protection
against breaches since it provides the written terms of the deal and often the four
corners of the document may be the exclusive basis for determining the terms
and condition of the contract. If unsigned documents are outstanding longer than
60 days, you may want to reconsider doing another deal with the same counterparty.
through the interstices. A major pitfall of centralized data gathering is the wide
variety of derivatives products offered and the need to standardize the data. This
aggregation process can come at a cost of accuracy in the details of individual
transactions. The derivatives business has evolved dramatically and controls and
compliance efforts may fail to keep pace.
Business and technical support often falls into strict control units or divisions and
there is little overlap with other units. The systems requirements are often developed
devoid of ensuring compatibility within the entire organization. Since the same
salesperson can often sell products on behalf of a number of legal entities, effective
control becomes more problematic. Data fields, reports, etc. can mean different
things or be used for different purposes within different parts of an organization.
Information is often aggregated for risk management or accounting purposes and it
becomes difficult to isolate all the details of individual transactions. A related problem
occurs when holding are managed by an outside manager and the numbers need to
be manually ‘rolled into’ total holdings reports.
With specially tailored transactions, there may be special provisions or options
that cannot be recorded in the existing systems. As a result they may not appear on
a regular report. For simplicity, information may be ordered by stated maturity date
and not include other pertinent data. A major challenge is that report cutoff times
are often different and a good deal of time is spent on needless reconciliation. There
may be classification overlaps as well. Trusts, partnerships and affiliates and custody
agents may all figure in the equation and one may not readily obtain a complete
listing of all positions held.
To ensure that all data is being collected, one should obtain process flow diagrams
covering all product and customer flows. Lists of reports and samples of each reports
should be obtained to ensure completeness. Special attention should be paid to
reports whose formats or scope change over time since this may trigger unintended
omissions or other unhappy consequences.
Typical problem signs occur when you sometimes have the original trade documents
and sometimes copies. This indicates a lack of consistency or control. All
transactions should be serial numbered or time stamped in order to enable crosschecking
with market levels and credit limits. Files that contain only part of
the required documents or inconsistency in contents and storage locations of the
files should also cause concern. One should be especially alert for backdated
approvals.
One should also obtain a document-aging list. A signed document gives protection
against breaches since it provides the written terms of the deal and often the four
corners of the document may be the exclusive basis for determining the terms
and condition of the contract. If unsigned documents are outstanding longer than
60 days, you may want to reconsider doing another deal with the same counterparty.
Build on existing reports
A major challenge is simply to track changes and rejig reports and information to
accommodate changing regulatory needs and senior management requests. Given
the likelihood of unanticipated situations in the future, reports must be built to be
flexible with a variety of key fields or sorting methodologies. Query tools should
make reporting quite flexible. The range of reports frequently requested are market
or credit exposure by instrument, by counterparty, by industry, by country, by
maturity, etc. Depending on where the latest ‘crisis’ occurs, requests will change
accordingly.
In most companies there are official board reports that are prepared for use by the
board of directors. Generally the law department will review them to certify that all
transactions were done in compliance with applicable law and in compliance with
internal policies and authorizations. When a compliance problem occurs, the board
needs to know the nature and scope of the problem. A major pitfall is that board
meetings tend to be heavily scripted and have full agendas and focus on compliance,
other than audit reviews, may not be given high priority.
In order to ensure compliance success, the staff needs to inventory those items
and processes to be monitored. The need here is to cast as wide a net as is
appropriate. To monitor properly, one needs to know who the players are, what
instruments do they use, and how the work is organized. The following is a sample
listing of the types of reports that would be needed:
1 Aggregate volume and profitability numbers
2 Itemized information on all trades
3 VaR and scenarios results
4 Limits violation reports
5 New customer listing
6 Turnover in staff (front and back office)
7 Systems failure reports
8 UOR unusual occurrence reports (catchall)
9 Trend analysis
10 Sample term sheets used
Other relevant reports are error logs, limit violations and revenue reports. Unsigned
document aging reports are also important. These monitoring reports should be
viewed in the context of how they enable the proper timing of regulatory review and
reporting. Given the ease of renaming products for regulatory purposes, compliance
staff are well advised to request risk reports as well. Measurement of economic
exposure in the risk reports might shed more light on the true nature of some
derivative instruments.
accommodate changing regulatory needs and senior management requests. Given
the likelihood of unanticipated situations in the future, reports must be built to be
flexible with a variety of key fields or sorting methodologies. Query tools should
make reporting quite flexible. The range of reports frequently requested are market
or credit exposure by instrument, by counterparty, by industry, by country, by
maturity, etc. Depending on where the latest ‘crisis’ occurs, requests will change
accordingly.
In most companies there are official board reports that are prepared for use by the
board of directors. Generally the law department will review them to certify that all
transactions were done in compliance with applicable law and in compliance with
internal policies and authorizations. When a compliance problem occurs, the board
needs to know the nature and scope of the problem. A major pitfall is that board
meetings tend to be heavily scripted and have full agendas and focus on compliance,
other than audit reviews, may not be given high priority.
In order to ensure compliance success, the staff needs to inventory those items
and processes to be monitored. The need here is to cast as wide a net as is
appropriate. To monitor properly, one needs to know who the players are, what
instruments do they use, and how the work is organized. The following is a sample
listing of the types of reports that would be needed:
1 Aggregate volume and profitability numbers
2 Itemized information on all trades
3 VaR and scenarios results
4 Limits violation reports
5 New customer listing
6 Turnover in staff (front and back office)
7 Systems failure reports
8 UOR unusual occurrence reports (catchall)
9 Trend analysis
10 Sample term sheets used
Other relevant reports are error logs, limit violations and revenue reports. Unsigned
document aging reports are also important. These monitoring reports should be
viewed in the context of how they enable the proper timing of regulatory review and
reporting. Given the ease of renaming products for regulatory purposes, compliance
staff are well advised to request risk reports as well. Measurement of economic
exposure in the risk reports might shed more light on the true nature of some
derivative instruments.
Purpose and range of reports
Reports serve as the lifeblood of any organization. Their purpose is to inform
management and staff as to past activity, current positions and profitability and to
measure performance versus budget. In addition, the reports provide a basis for
guidance and planning future activity. Market and credit risk are likely two of the
largest risks that an institution faces and these risks are often analyzed from a
patchwork of reports. Reports are focused primarily on providing an accurate reflection
of current positions and providing mark-to-market valuations and exposures.
The reports often provide static, snapshots of positions as of a cut-off time. Those
focusing specifically on compliance needs are generally less available.
Reports should provide aggregate numbers certainly, but they should be accompanied
with supporting trend analysis. There should be sufficient detail to enable
management to determine if the composition of the business is changing. This can
have a significant impact on future business plans as well as alerting compliance to
refocus some of its resources. It is axiomatic that the reports generated for management
originate from departments independent of the trading activity.
Regulators have an evolving focus today. Since management has specific informational
needs, the reporting is primarily geared to business requirements. There is a
realization among regulators now that there is a benefit to be achieved by focusing
more on management’s own reports rather than creating entirely new reports for the
regulatory agencies.
In addition, regulators are more open to the concept of sharing information among
themselves (to the extent legally possible) and in some cases even relying on the
expertise and analysis of another regulator, especially a foreign one. Although the
regulators are cognizant of the cost of providing special reports to regulators, they
have little choice in times of financial crisis but to request ad-hoc reports. This
occurred with the hedge funds being scrutinized closely during the Long Term
Capital Management crisis in 1998. Regulators asked for special reports keyed to
counterparty concentrations as well as exposures to specific markets from hedge
funds and counterparty banks.
To this end, an essential listing of documents and reports needed by divisional
compliance would be as follows:
Ω Organizational chart of business unit and divisional groups
Ω Work processes mapped out
Ω Current compliance manuals
Ω Compliance databases
Ω Copies of applicable regulations
Ω Copies of corporate authorizations
Ω List of authorized traders
Ω List of permitted products
Ω Approved counterparty list
Ω List of signed ISDA/IFEMA agreements
Ω Listing of available reports (e.g. credit line usage, exception reports)
Ω List of brokers used
Ω List of bank accounts
Ω List of custodians
Ω List of safety deposit boxes
Ω List of repo agreements signed
Ω Document aging list
The central compliance unit is typically focused on more firmwide issues. The
unit would likely work closely with the law department on setting policies for
implementation by the divisional compliance units. Central compliance typically
focuses on the following:
Ω Outside money managers
Ω List of approved signatories (internal)
Ω Certificates of incumbency
Ω Filings required for regulatory agencies
Ω Disaster recovery plans/business resumption plans
Ω Coordination of internal audit recommendations
The law department’s focus would include some of the following issues:
Ω Software contracts
Ω Data vendor contracts
Ω Insurance coverage
Ω Bonding
The lists of documents and reports represent the initial step of the compliance
review. Using an ISDA master agreement as an example, the law department should
create a template as to the preferred language and range of alternative language
permitted. It is advisable that there be a large degree of standardization as to the
ISDA contracts that are signed. Whenever there are omissions or variations in
language, they may expose the company to additional legal risk. Legal planning
becomes more difficult since outcomes may be less certain if contracts need to be
enforced and there is no uniformity of terms among the agreements that one
institution has negotiated. As the credit derivatives market experienced in 1998, lack
of uniformity of interpretation by signatories to a contract is another impediment to
limiting risk. Whether certain sovereigns experienced a default remains a matter in
dispute.
The legal agreement is not the end point. The organization must have a strong
operations team to monitor the implementation of the terms of the contract. Let’s
use, as an example, an agreement to post collateral. Some derivatives contracts have
springing collateral language. Operations has to verify receipt of collateral, often by
trustee if it is a tripartite agreement. They must determine that it is acceptable
collateral, value it, and they may need to perfect an interest in the collateral as well.
The analysis should not end with the question, has collateral been posted?
With posting of collateral or mark-to-market triggers, it may be preferable not to
key them to counterparty credit grades. If a major dealer were to get downgraded
then everyone’s collateral or termination trigger might be invoked at the same time.
It may be more prudent to require language that calls for an automatic posting of
collateral if exposure rises above a preset limit. If it is simply a right to be exercised,
a ‘tickler system’ might not catch the change. With a mandatory posting of collateral,
your firm is less susceptible to the moral suasion of a senior officer of the other
company calling and requesting that the demand to post collateral be waived. You
can always decline to exercise your right but you should avoid having the situation
of needing to assert a right that is not clear-cut or that could forseeably force the
counterparty into bankruptcy.
Tracking the aging and disposition of unsigned documents is an important
preventative control. Deals may be fully negotiated but the contract memorializing
the terms may remain unsigned. Alternatively, ISDAs could be signed but a term
might be unilaterally initialed and so not fully agreed upon. Some firms require the
counterparty to sign a one-page acknowledgement agreeing to all terms of the
confirmation. This approach precludes a counterparty from initialing a change on
page 2 or 3 in the confirmation and faxing it back and the change being overlooked.
Months or years later, the initialed contract term might become a source of contention
and no final agreement would be documented for that contract term. A fully signed
contract should provide each party with a clearer legal position in the event of a
breach.
Another problem area exists when there is no signed ISDA in place between
counterparties or where the terms of the swap confirmation are made to supercede
the terms of the ISDA master agreement. It may be appropriate but you want to
ensure that the desired results occur. The law department should review the master
agreement and the swap supplement language. If an unsigned deal confirmation
remains outstanding for a long period of time, an overly efficient officer may just sign
them to reduce the backlog. Some end-users simply sign off on master agreements
without examining or understanding all the ramifications of various terms agreed.
They may even agree to netting across entities in same corporate family without
evaluating the appropriateness of such action.
management and staff as to past activity, current positions and profitability and to
measure performance versus budget. In addition, the reports provide a basis for
guidance and planning future activity. Market and credit risk are likely two of the
largest risks that an institution faces and these risks are often analyzed from a
patchwork of reports. Reports are focused primarily on providing an accurate reflection
of current positions and providing mark-to-market valuations and exposures.
The reports often provide static, snapshots of positions as of a cut-off time. Those
focusing specifically on compliance needs are generally less available.
Reports should provide aggregate numbers certainly, but they should be accompanied
with supporting trend analysis. There should be sufficient detail to enable
management to determine if the composition of the business is changing. This can
have a significant impact on future business plans as well as alerting compliance to
refocus some of its resources. It is axiomatic that the reports generated for management
originate from departments independent of the trading activity.
Regulators have an evolving focus today. Since management has specific informational
needs, the reporting is primarily geared to business requirements. There is a
realization among regulators now that there is a benefit to be achieved by focusing
more on management’s own reports rather than creating entirely new reports for the
regulatory agencies.
In addition, regulators are more open to the concept of sharing information among
themselves (to the extent legally possible) and in some cases even relying on the
expertise and analysis of another regulator, especially a foreign one. Although the
regulators are cognizant of the cost of providing special reports to regulators, they
have little choice in times of financial crisis but to request ad-hoc reports. This
occurred with the hedge funds being scrutinized closely during the Long Term
Capital Management crisis in 1998. Regulators asked for special reports keyed to
counterparty concentrations as well as exposures to specific markets from hedge
funds and counterparty banks.
To this end, an essential listing of documents and reports needed by divisional
compliance would be as follows:
Ω Organizational chart of business unit and divisional groups
Ω Work processes mapped out
Ω Current compliance manuals
Ω Compliance databases
Ω Copies of applicable regulations
Ω Copies of corporate authorizations
Ω List of authorized traders
Ω List of permitted products
Ω Approved counterparty list
Ω List of signed ISDA/IFEMA agreements
Ω Listing of available reports (e.g. credit line usage, exception reports)
Ω List of brokers used
Ω List of bank accounts
Ω List of custodians
Ω List of safety deposit boxes
Ω List of repo agreements signed
Ω Document aging list
The central compliance unit is typically focused on more firmwide issues. The
unit would likely work closely with the law department on setting policies for
implementation by the divisional compliance units. Central compliance typically
focuses on the following:
Ω Outside money managers
Ω List of approved signatories (internal)
Ω Certificates of incumbency
Ω Filings required for regulatory agencies
Ω Disaster recovery plans/business resumption plans
Ω Coordination of internal audit recommendations
The law department’s focus would include some of the following issues:
Ω Software contracts
Ω Data vendor contracts
Ω Insurance coverage
Ω Bonding
The lists of documents and reports represent the initial step of the compliance
review. Using an ISDA master agreement as an example, the law department should
create a template as to the preferred language and range of alternative language
permitted. It is advisable that there be a large degree of standardization as to the
ISDA contracts that are signed. Whenever there are omissions or variations in
language, they may expose the company to additional legal risk. Legal planning
becomes more difficult since outcomes may be less certain if contracts need to be
enforced and there is no uniformity of terms among the agreements that one
institution has negotiated. As the credit derivatives market experienced in 1998, lack
of uniformity of interpretation by signatories to a contract is another impediment to
limiting risk. Whether certain sovereigns experienced a default remains a matter in
dispute.
The legal agreement is not the end point. The organization must have a strong
operations team to monitor the implementation of the terms of the contract. Let’s
use, as an example, an agreement to post collateral. Some derivatives contracts have
springing collateral language. Operations has to verify receipt of collateral, often by
trustee if it is a tripartite agreement. They must determine that it is acceptable
collateral, value it, and they may need to perfect an interest in the collateral as well.
The analysis should not end with the question, has collateral been posted?
With posting of collateral or mark-to-market triggers, it may be preferable not to
key them to counterparty credit grades. If a major dealer were to get downgraded
then everyone’s collateral or termination trigger might be invoked at the same time.
It may be more prudent to require language that calls for an automatic posting of
collateral if exposure rises above a preset limit. If it is simply a right to be exercised,
a ‘tickler system’ might not catch the change. With a mandatory posting of collateral,
your firm is less susceptible to the moral suasion of a senior officer of the other
company calling and requesting that the demand to post collateral be waived. You
can always decline to exercise your right but you should avoid having the situation
of needing to assert a right that is not clear-cut or that could forseeably force the
counterparty into bankruptcy.
Tracking the aging and disposition of unsigned documents is an important
preventative control. Deals may be fully negotiated but the contract memorializing
the terms may remain unsigned. Alternatively, ISDAs could be signed but a term
might be unilaterally initialed and so not fully agreed upon. Some firms require the
counterparty to sign a one-page acknowledgement agreeing to all terms of the
confirmation. This approach precludes a counterparty from initialing a change on
page 2 or 3 in the confirmation and faxing it back and the change being overlooked.
Months or years later, the initialed contract term might become a source of contention
and no final agreement would be documented for that contract term. A fully signed
contract should provide each party with a clearer legal position in the event of a
breach.
Another problem area exists when there is no signed ISDA in place between
counterparties or where the terms of the swap confirmation are made to supercede
the terms of the ISDA master agreement. It may be appropriate but you want to
ensure that the desired results occur. The law department should review the master
agreement and the swap supplement language. If an unsigned deal confirmation
remains outstanding for a long period of time, an overly efficient officer may just sign
them to reduce the backlog. Some end-users simply sign off on master agreements
without examining or understanding all the ramifications of various terms agreed.
They may even agree to netting across entities in same corporate family without
evaluating the appropriateness of such action.
Reporting and documentation controls
This section outlines a full range of compliance and document reports that are
typically needed. It focuses on building from existing information sources and how
to automate some of the processes. The section ends with a review of how to perform
periodic evaluations as to effectiveness.
typically needed. It focuses on building from existing information sources and how
to automate some of the processes. The section ends with a review of how to perform
periodic evaluations as to effectiveness.
Kaydol:
Kayıtlar (Atom)