operational risk & incident reporting

25
June 10, 2022 Kachhapi 1

Upload: shivaleela-choudary

Post on 20-Jun-2015

573 views

Category:

Automotive


8 download

DESCRIPTION

xcvcxv

TRANSCRIPT

Page 1: Operational risk &  incident reporting

April 13, 2023Kachhapi 1

Page 2: Operational risk &  incident reporting

April 13, 2023Kachhapi 2

OPERATIONAL RISK

Operational risk is the risk of direct or indirect loss resulting from inadequate or failed internal processes, people and system or from external events. Also includes, settlement or payment risk and business interruption, administrative and legal risks.

Page 3: Operational risk &  incident reporting

April 13, 2023Kachhapi 3

OPERATIONAL RISK IS

• EMBEDDED IN EACH ACTIVITY

• IMPLICIT IN ORDINARY COURSE OF CORPORATE ACTIVITY.

• NOT DIRECTLY A RISK Vs EXPECTED REWARD FUNCTION

• AN INDEPENDENT RISK MANAGEMENT FUNCTION, COMPARABLE TO MANAGEMENT OF CREDIT & MARKET

Page 4: Operational risk &  incident reporting

April 13, 2023Kachhapi 4

TYPES OF OPERATIONAL RISK EVENTS

EVENT EXAMPLE

Internal FraudInternal Fraud Intentional Mis-representationIntentional Mis-representationEmployee theftEmployee theftInsider Trading - EmployeesInsider Trading - Employees

External Fraud Robbery, Forgery, ChequekitingComputer Hacking Damage

Page 5: Operational risk &  incident reporting

April 13, 2023Kachhapi 5

Clients, Products, Business Practices

Fiduciary BreachesImproper TradingConfidential InformationMoney Laundering Claim

Employment Practices & Work Place Safety

Health & Safety RulesDiscrimination ClaimsGeneral Liability

EVENT EXAMPLE

Page 6: Operational risk &  incident reporting

April 13, 2023Kachhapi 6

EVENT EXAMPLE

Damage to Physical Damage to Physical AssetsAssets

Terrorism, VandalismTerrorism, VandalismEarth Quake, Fires & Earth Quake, Fires & FloodsFloods

Business Disruption & System Failures

Hardware & Software Failures, Telecom Failures, Utility Usage

Execution, Delivery & Process Management

Data Entry Errors, Incomplete Documentation, Vendor Disputes, Unauthorized Access to Client Accounts

Page 7: Operational risk &  incident reporting

April 13, 2023Kachhapi 7

MAJOR CASES OF LOSS MAJOR CASES OF LOSS EVENTS IN BANKINGEVENTS IN BANKING

Page 8: Operational risk &  incident reporting

April 13, 2023Kachhapi 8

LOSS EVENTS TYPE

BANK QUANTUM IN USD

Internal Fraud BaringsDaiwa Bank

$ 1.0 Billion$ 1.4 Billion

External Fraud Custodial Client of Republic of NY Corporation

$ 611 Mio

WORKPLACE SAFETY

Merrill Lynch Legal Settlement

$ 250 Mio

Page 9: Operational risk &  incident reporting

April 13, 2023Kachhapi 9

LOSS EVENTS TYPE

BANK QUANTUM IN USD

Client products & business practices

Improper SalesPractices Banks in US( Provision)

$ 405 Mio

Damage tophysical assets

Bank of NewYork 9/11

$ 140 Mio

Page 10: Operational risk &  incident reporting

April 13, 2023Kachhapi 10

LOSS EVENTS TYPE

BANK QUANTUM IN USD

Business disruption& system failure

Solomon Brothers( Due toUn-reconciledBalances withchange in I.TSystem )

$ 303 Mio

Execution, delivery& Processmanagement

BOA Wells Fargo BankFailed transactionProcessing &System IntegrationProcessing

$ 225 Mio$ 150 Mio

Page 11: Operational risk &  incident reporting

April 13, 2023Kachhapi 11

OPERATIONAL RISK –LOSS TYPES

• Processing risk.

• People risk.

• System risk.

• External events risk.

• Legal risk.

• Reputation risk.

Page 12: Operational risk &  incident reporting

April 13, 2023Kachhapi 12

PROCESSING RISK• Transactions put through without proper

authority/mandate.• Erroneous transaction execution.• Wrong reporting.• Erroneous cash movement.• Omission of task.• Inaccurate/incomplete documentation.• Frauds both internally/externally.• Money laundering.• Unauthorized persons access to bank’s records.

Page 13: Operational risk &  incident reporting

April 13, 2023Kachhapi 13

PEOPLE RISK• Inadequate staff.

• Hiring unsuitable staff.

• Loss of key personnel.

• Over reliance on few key staff.

• Insufficient succession & development planning.

• Insufficient training.

• Poor communication.

• Behaviour & attitude.

• Age profile.

Page 14: Operational risk &  incident reporting

April 13, 2023Kachhapi 14

SYSTEM RISKS• Programming error.• Irrelevant, inaccurate, incomplete MIS.• I T System failure.• Telecommunication failure.• Technology interference.• Failure of support functions.• Inadequacy of backup systems/procedures.• Working under different platforms/ software

environment.

Page 15: Operational risk &  incident reporting

April 13, 2023Kachhapi 15

LEGAL RISKS

• Breaching of regulatory requirements.

• Unenforceable contracts,lawsuits.

• Adverse judgments.

• Executing illegal transactions.

• Failure to fulfill fiduciary duties

Page 16: Operational risk &  incident reporting

April 13, 2023Kachhapi 16

External events risks.

• Natural disasters.Natural disasters.

• War/terrorism.War/terrorism.

• Sabotage.Sabotage.

• Crime.Crime.

Page 17: Operational risk &  incident reporting

April 13, 2023Kachhapi 17

REPUTATION RISKS.• Negative publicity leading to decline in

customer base, costly litigation, reduction in current & prospective earnings & capital.

• Effect of other risks.

Page 18: Operational risk &  incident reporting

April 13, 2023Kachhapi 18

Operational Risk – Framework & Management.

1. Organizational set up.

2. Operational Risk Management Policy.

3. Risk mapping.

4. Risk assessment.

5. Collection of Operational risk loss incident data.

6. Risk Quantification

Page 19: Operational risk &  incident reporting

April 13, 2023Kachhapi 19

Risk AssessmentCategorization of identified risks – Low,

Medium, High.

Grading of controls – Low, Medium, High.

Comparison between assessed risks & existing controls to identify :

1. High risk low control types 2. Low risk high control types 3. Less frequent high impact types 4. More frequent less impact types.

Page 20: Operational risk &  incident reporting

April 13, 2023Kachhapi 20

RISK QUANTIFICATION

OPERATIONAL OPERATIONAL RISKRISKCREDIT RISKCREDIT RISK MARKET RISKMARKET RISK

STANDARDIZEDSTANDARDIZED

APPROACHAPPROACH

FOUNDATION –FOUNDATION –

IRB APPROACHIRB APPROACH

ADVANCED – ADVANCED –

IRB APPROACHIRB APPROACH

STANDARDISEDSTANDARDISED

APPROACHAPPROACH

INTERNALINTERNAL

MEASUREMENTMEASUREMENT

APPROACHAPPROACH

BASIC BASIC INDICATOR INDICATOR APPROACHAPPROACH

STANDARDIZED STANDARDIZED APPROACHAPPROACH

ADVANCED ADVANCED MEASUREMENT MEASUREMENT APPROACHAPPROACH

Page 21: Operational risk &  incident reporting

April 13, 2023Kachhapi 21

Basic Indicator Approach

• Fixed percentage on Gross income shall be the Capital to be held by the Bank for Operational risk

Page 22: Operational risk &  incident reporting

April 13, 2023Kachhapi 22

Standardized Approach• Bank’s activities are divided into:

1) Corporate Finance.2) Trading & Sales.3) Retail Banking.4) Commercial Banking.5) Payment & Settlement.6) Agency Services & Custody.7) Retail Brokerage.8) Asset Management.

• Capital charge to be calculated for each business line by multiplying gross income by a factor percentage assigned to it.

Page 23: Operational risk &  incident reporting

April 13, 2023Kachhapi 23

Advanced Measurement Approach

• Gives discretion to the Bank to use their own internal loss data & assessment methods.

• Approach shall be used only after sufficient reliable data base of operational risk loss events is built up.

Page 24: Operational risk &  incident reporting

April 13, 2023Kachhapi 24

• We have to measure operational risk We have to measure operational risk by Basic Indicator Approach in terms by Basic Indicator Approach in terms of RBI guidelines.of RBI guidelines.

• What is beneficial to Banks is AMA. What is beneficial to Banks is AMA.

Page 25: Operational risk &  incident reporting

April 13, 2023Kachhapi 25

• THANK YOU

• T.V.RAO.FACULTY