operational risk & business continuity management

21
Operational Risk & Business Continuity Management - An Effective And Integrated Approach Chris Lintern Co-operative Financial Services Leading the risk profession

Upload: ujjwal-shanu

Post on 04-Nov-2014

661 views

Category:

Business


5 download

DESCRIPTION

 

TRANSCRIPT

Page 1: Operational risk & business continuity management

Operational Risk & Business ContinuityManagement - An Effective And Integrated Approach

Chris LinternCo-operative Financial Services

Leading the risk profession

Page 2: Operational risk & business continuity management

Introduction & Approach

Chris Lintern• Background in all aspects of Business Continuity Management

within Financial Services• Part of central Operational Risk Management TeamCo-operative Financial Services• Includes Co-operative Bank, Co-operative Insurance, Co-

operative Investments• Merged last year with Britannia Building Society • Our vision is to be the UK’s most admired financial services

businessApproach to this session• Active participation• All views welcome and appreciated

Page 3: Operational risk & business continuity management

Purpose

• To share thoughts on the benefits of integrating Operational Risk & Business Continuity

• Consider some of the key stakeholders, and the aims, and components for Operational Risk and Business Continuity frameworks

• Conclusions

Page 4: Operational risk & business continuity management

What is Operational Risk Management?Managing the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events (Basel Committee of the Bank of International Settlements)

What is Business Continuity?A holistic management process that identifies potential threats to an organisation and the impacts to business operations that those threats, if realised, might cause and which provides a framework for building organisational resilience with the capability for an effective response that safeguards the interests of its key stakeholders reputation, brand and value creating activities (BS25999 – British Standard for BCM)

Page 5: Operational risk & business continuity management

Back to Basics

Preventing nasty surprises wherever practical, and having the confidence that your organisation can respond to and mitigate them - if and when they occur

Health &

Safety

Key Suppliers

/ Outsourc

e Partners

System failures

Property &

Facilities

Key person dependencies

External threats

Page 6: Operational risk & business continuity management

Historic Positioning of Op Risk & BCM

• Focus on “traditional” business continuity – denial of access to premises, or loss of systems• BCM and Operational Risk seen as separate entities

BCMOperation

al Risk

Page 7: Operational risk & business continuity management

Synergies between the twoStakeholders Framework

ComponentsIntended Outcome

Board Policy & Procedures

Understanding of appetite

Executive & Senior Management

Supporting documents

Proactive assessment

Operational Management

Plans & Training Understanding of impact

Other Considerations

Impact on Capital Impact on Change Insurance

Page 8: Operational risk & business continuity management

Operational Risk – Integrated Approach

Operational Risk

Business Continuity

InsuranceOperational Risk Capital

Control Self-Assessment

Page 9: Operational risk & business continuity management

Operational Risk – Integrated Approach

Operational Risk

Business Continuity

InsuranceOperational Risk Capital

Proactive identification of risks• Assessment and evaluation • Scenario analysis

Control Self-Assessment

Page 10: Operational risk & business continuity management

Operational Risk – Integrated Approach

Operational Risk

Business Continuity

InsuranceOperational Risk Capital

Control Self-Assessment

Assess controls• CSA process• Review control weaknesses• Track actions• Link control evidence to risks• Review incidents as evidence of control failures

Page 11: Operational risk & business continuity management

Operational Risk – Integrated Approach

Operational Risk

Business Continuity

InsuranceOperational Risk Capital

Control Self-Assessment

Mitigation of operational risks• Crisis Management Team & Plan• Incident Management Teams• Crisis Management Centre• Work-Area Recovery• Disaster Recovery strategy

Page 12: Operational risk & business continuity management

Operational Risk – Integrated Approach

Operational Risk

Business Continuity

InsuranceOperational Risk Capital

Control Self-Assessment

Risk transfer• Placement• Claims Handling• Specific perils e.g. Buildings/Contents, Business Interruption Insurance

• Advice & Guidance

Page 13: Operational risk & business continuity management

Operational Risk – Integrated Approach

Operational Risk

Business Continuity

InsuranceOperational Risk Capital

Control Self-Assessment

Capital against unexpected losses• Calculation• Planning

Page 14: Operational risk & business continuity management

Operational Risk Components

Purpose

Vision

3 Year Strategic Plan

Strategy

Core Processes

Critical Systems

Colleagues

External Eventse.g. Weather,

Terrorism

Change agenda

Bottom-up Operational Risk

Profile

Scenarios

Top-down Operational Risk

Profile

Facilities

Operational Risk Capital

Operational Risk Appetite

Business Continuity

Incident & Near-Miss Reporting

Resilience

Work-Area Recovery

Disaster Recovery

Incident & Crisis

Management

Insurance Programme

Operational Risk strategy and plan

ReportingSuppliers & Outsource Partners

Operational Risk

End-to-end Process view

Key Controls

Control Self-Assessment

Policies

Claims

Page 15: Operational risk & business continuity management

Operational Risk Components

Purpose

Vision

3 Year Strategic Plan

Strategy

Core Processes

Critical Systems

Colleagues

External Eventse.g. Weather,

Terrorism

Change agenda

Bottom-up Operational Risk

Profile

Scenarios

Top-down Operational Risk

Profile

Facilities

Operational Risk Capital

Operational Risk Appetite

Business Continuity

Incident & Near-Miss Reporting

Resilience

Work-Area Recovery

Disaster Recovery

Incident & Crisis

Management

Insurance Programme

Operational Risk strategy and plan

ReportingSuppliers & Outsource Partners

Operational Risk

End-to-end Process view

Key Controls

Control Self-Assessment

Policies

Claims

Page 16: Operational risk & business continuity management

Embedding the Culture

• Business buy-in of paramount importance• Incident Management framework known and utilised –

importance of exercising• Risk Division seen as involved – not sat in Ivory Towers• Part of the solution, not part of the problem - BC & Op

Risk representatives heavily involved in Incident Management

• Keep things simple – common language• Linked to the CFS customer promise

Page 17: Operational risk & business continuity management

Incident Framework

Crisis

Management

Team

Incident Management Teams

IS Service Continuity

Business units / areas

BC plan owners and Plan co-ordinators

Escalate up

Cascade down

Operational Risk (incl. BCM)

Page 18: Operational risk & business continuity management

Incident Management Team - Structure

People Co-ordinator

IS Co-ordinator

Information Co-ordinator

CommsCo-ordinator

Business Operations

Co-ordinator

Incident ManagementTeam Leader

Site Facilities & Security

Page 19: Operational risk & business continuity management

Integrated Approach

Operational Risk

BCM

Key risks mitigated

Tangible exercising

Incident Management

CapabilityRisk

Assessments

Stress scenarios

Issues raised as risks

Page 20: Operational risk & business continuity management

Conclusions

• An effective, and consistent framework• Can be used to define overall risk appetite at Board

level• Practical considerations – both areas need policies &

procedures• Simple for the business• Aligned to business processes• Crucial that it’s accepted from a cultural perspective

within the newly merged organisation • Potential to drive efficiencies and cost-savings

Page 21: Operational risk & business continuity management

Thank You

Any Further Questions – [email protected]