- Published on
Investment - Operational Risk
Operational risk is the risk of losses from inadequate or failed personnel, systems, and internal rules and procedures as well as from external events that are outside the control of the organization but that affect its operations.
Managing People
Human failures range from unintentional errors to fraudulent behaviors. Many firms are subject to occupational fraud (also termed internal fraud or employee fraud), which is when an employee abuses their position for personal benefit by misappropriating the company’s assets or resources. In a poll carried out by the Association for Certified Fraud Examiners (ACFE), anti-fraud professionals calculated that globally organizations lose, on average, 5% of their yearly revenues to fraud.
One example of operational risk that includes a human component and is more frequent in the financial services business than in any other industry is rogue trading.
Rogue trading refers to circumstances in which traders bypass management controls and place unauthorized deals, at times creating huge losses for the companies they work for. Rogue trading may involve fraudulent trading done for personal enrichment or to make up losses.
Example: Libor Manipulation Scandal
One of the most comprehensive criminal investigations and prosecutions that arose in the wake of the 2008 financial crisis was a premeditated attempt by numerous banks and certain employees to manipulate the London Interbank Offered Rate known as Libor. At that time, Libor was the worldwide accepted benchmark rate used by banks to establish interest rates on a myriad of loans (consumer and financial) and depended on self-reported estimates of borrowing costs from banks.
Prosecutors in many jurisdictions determined that banks had collaborated by pushing their estimations higher or lower in a bid to profit from connected assets tied to the rate. In the end, many banks across the world would plead guilty and were fined billions, while scores of individuals were pursued and charged with criminal activity.
Mitigating Risk
Banks, like other corporations, have tried to learn from past disasters and plug the holes in its systems and controls to prevent similar catastrophes from recurring. The bankruptcy of Barings Bank in 1995 exposed the consequences of not segregating front- and back-office activities appropriately.
In the modest bank branch of Barings in Singapore, the same staff managed both types of business. An initial trading loss (a front-office activity) due of a human error was hidden in the accounting system (a back-office activity), and subsequent losses mounted until they surpassed the bank’s equity capital. Following Barings’ failure, banks were compelled to establish a clear division between their front and back offices.
Companies can decrease operational risks through education by clearly conveying rules and processes and by establishing efficient and effective internal controls. Good human resource management techniques are also crucial; employing the right people and motivating them with the right incentives are well-known factors for success.
To reduce the risk of recruiting the incorrect personnel, companies often take numerous safeguards, such as the following:
Conducting background checks, such as verifying criminal records and disciplinary records with regulators for new employment
Verifying qualifications and past work experience
Performing personality assessment tests
Getting character references to establish suitability
Although these safeguards may appear to be conventional, research have revealed that inconsistencies between presented and actual qualifications are prevalent. Cases in which background checks of senior executives were not correctly done are often reported. Because of a loss of trust, some of these executives had to resign when the truth was known, even if they had performed satisfactorily in their jobs.
Risk taking should also be addressed in the structure of compensation, for example when setting bonus payments for employees. It is particularly critical for employees who expose the organization to large risks, such as traders and investment professionals. A fair compensation system should take into account the level of risk incurred for a given level of return and should reward those who accomplish returns without incurring excessive risks.
An example of an incentive that could lead to deviant behaviour is rewarding traders for earnings regardless of the risks they take. This technique would provide them all the upside for trading gains, but less downside for taking on risks and for trading losses. In actuality, traders creating big losses frequently lose their jobs and reputations, although they usually do not have to pay back much compared with the income they previously earned.
Some authorities are already implementing new compensation systems that incorporate deferred remuneration to take into consideration long-term performance as well as claw-back provisions, wherein employees may have to refund their bonuses if claimed profitable transactions result in losses later.
Managing Systems
Companies rely substantially on information technology (IT) systems. Consequently, technology has become an increasingly major source of operational risk. Automated processes can lessen the incidence and severity of operational failures, but they are not flawless. Failures of IT and communication systems can paralyse business activities or severely diminish their efficiency, affecting the company’s profitability via reduced revenues, higher costs, or a combination of both.
IT networks are inherently vulnerable to disturbances and outside intervention owing to technical limits and human factors. One source of danger is the attitude of employees who do not follow corporate policies and, for instance, download illegal software for personal or professional use.
The disadvantages of this technique include harmful viruses and unauthorized, and perhaps incompatible, software infiltrating enterprise systems. In addition, IT departments are in a constant war with hackers who exploit holes to enter systems.
Key controls to secure systems and corporate information include the following:
Establishing and disseminating internal policies for users and IT technical staff Creating acceptable security standards and configurations for systems
Allocating appropriate manpower and technical resources to ensure a well-controlled IT environment
The security of secret information is also vital in the investment industry. Data privacy has lately gained in popularity due to a series of situations in which companies and government agencies allowed people’s private information to enter the public domain, exposing them to the danger of fraud.
A corporation should understand how data are produced and flow internally, classify the information by sensitivity, estimate the risks of data loss, and adopt suitable preventative measures. Many countries have strict laws and regulations for securing customer data, coupled with significant consequences for breaking these laws and regulations.
Complying with Internal Policies and Procedures
The structure of a company varies with size and the business activities it is engaged in, but there are aspects common to all firms. For example, power and authority are delegated and duties assigned within most corporations. In smaller entrepreneurial organizations, such assignments may be communicated informally, with individuals recognizing their respective positions and degrees of authority.
In larger and more complicated firms, the responsibilities and degrees of authority will be explicitly defined and the business processes written out in more detail, frequently contained in corporate management systems. Policies and procedures should expressly set out the delegation of authority and identify clear roles and accountability. These definitions constitute the basis for the monitoring of and control of business operations and provide feedback mechanisms.
The division of duties is a fundamental notion that international firms and regulators, along with other authorities in many nations, need and urge. As discussed before, a clear distinction needs to exist between front and back offices. In accounting departments, there should also be a clear separation between those who enter items into the accounts and those who reconcile the bank statements with the cash balances in the accounting system.
This separation of roles decreases the chance that personnel who possess cash may commit fraud or pilfer funds. Compliance and internal audit responsibilities are crucial to verifying that staff are truly following internal policies and procedures.
Managing the Business Environment
The sort of environment in which a company operates might add levels of uncertainty that need to be addressed.
Political risk is the risk that a change in the dominant political party of a country would lead to changes in policies that can affect anything from monetary policy (money supply, interest rates, and credit) and fiscal policy (taxation) to investment incentives, public projects, and procurement.
Some industries are significantly controlled by governments that, for example, regulate natural resources or set pricing of raw material inputs or outputs. In some circumstances, a change in administration or policy can impact the value of an investment. Political risk is inherent in all countries and should always be considered, even if it is deemed to be relatively remote.
Legal risk is the chance that an external party would sue the company for breach of contract or other infractions. A corporation should assess how it identifies and conforms to the legal responsibilities it has undertaken
The function of an in-house legal professional is vital to controlling legal risk. Most sections of a corporation have relations with external parties, such as deal counterparties, business partners, suppliers, and service providers. An key control in managing the legal risk of these external ties is to have legal professionals analyze every contract.
Companies should explicitly allocate authority and indicate who should evaluate and approve certain type of contracts. The most major deals normally require clearance at the level of the board of directors. Another solution is to use template agreements and standard contract terms and conditions that have been examined and approved by the legal staff.
The preservation of records, documents, and other forms of communication must also be in conformity with legal standards for all relevant jurisdictions.
Settlement risk (or counterparty risk) is the danger that while closing a transaction, a corporation fulfills one side of the contract, such as sending a security or money, but the counterparty does not complete its side of the deal as agreed, frequently because it has declared bankruptcy. This risk is sometimes also called Herstatt risk because of an incident in 1974 when the German Herstatt Bank ceased operations after counterparties had honoured their obligation to transfer Deutsche Marks to Herstatt, but before Herstatt honoured its obligation to transfer the equivalent amount in US dollars back to these counterparties.
Although there are usually legal procedures to compel a counterparty to meet its obligations, such actions are costly and time consuming. A counterparty is more likely to find it difficult to fulfil its obligations during adverse economic times or when bankruptcy is imminent than during successful periods. In the case of bankruptcy, it may take months or years to receive assets through a bankruptcy resolution procedure and the proceeds may only be a fraction of the original nominal amount of debt.
It is vital to identify the risks inherent in bilateral arrangements from those in transactions contracted through central counterparties, such as clearing institutions. Clearing houses may step in to accept the risk of a counterparty failing to meet its contractual obligations. Other measures to mitigate this risk are margin requirements or standardised agreements.
Operational risk is the risk of losses from inadequate or failed personnel, systems, and internal rules and procedures as well as from external events that are outside the control of the organization but that affect its operations.
Managing People
Human failures range from unintentional errors to fraudulent behaviors. Many firms are subject to occupational fraud (also termed internal fraud or employee fraud), which is when an employee abuses their position for personal benefit by misappropriating the company’s assets or resources. In a poll carried out by the Association for Certified Fraud Examiners (ACFE), anti-fraud professionals calculated that globally organizations lose, on average, 5% of their yearly revenues to fraud.
One example of operational risk that includes a human component and is more frequent in the financial services business than in any other industry is rogue trading.
Rogue trading refers to circumstances in which traders bypass management controls and place unauthorized deals, at times creating huge losses for the companies they work for. Rogue trading may involve fraudulent trading done for personal enrichment or to make up losses.
Example: Libor Manipulation Scandal
One of the most comprehensive criminal investigations and prosecutions that arose in the wake of the 2008 financial crisis was a premeditated attempt by numerous banks and certain employees to manipulate the London Interbank Offered Rate known as Libor. At that time, Libor was the worldwide accepted benchmark rate used by banks to establish interest rates on a myriad of loans (consumer and financial) and depended on self-reported estimates of borrowing costs from banks.
Prosecutors in many jurisdictions determined that banks had collaborated by pushing their estimations higher or lower in a bid to profit from connected assets tied to the rate. In the end, many banks across the world would plead guilty and were fined billions, while scores of individuals were pursued and charged with criminal activity.
Mitigating Risk
Banks, like other corporations, have tried to learn from past disasters and plug the holes in its systems and controls to prevent similar catastrophes from recurring. The bankruptcy of Barings Bank in 1995 exposed the consequences of not segregating front- and back-office activities appropriately.
In the modest bank branch of Barings in Singapore, the same staff managed both types of business. An initial trading loss (a front-office activity) due of a human error was hidden in the accounting system (a back-office activity), and subsequent losses mounted until they surpassed the bank’s equity capital. Following Barings’ failure, banks were compelled to establish a clear division between their front and back offices.
Companies can decrease operational risks through education by clearly conveying rules and processes and by establishing efficient and effective internal controls. Good human resource management techniques are also crucial; employing the right people and motivating them with the right incentives are well-known factors for success.
To reduce the risk of recruiting the incorrect personnel, companies often take numerous safeguards, such as the following:
Conducting background checks, such as verifying criminal records and disciplinary records with regulators for new employment
Verifying qualifications and past work experience
Performing personality assessment tests
Getting character references to establish suitability
Although these safeguards may appear to be conventional, research have revealed that inconsistencies between presented and actual qualifications are prevalent. Cases in which background checks of senior executives were not correctly done are often reported. Because of a loss of trust, some of these executives had to resign when the truth was known, even if they had performed satisfactorily in their jobs.
Risk taking should also be addressed in the structure of compensation, for example when setting bonus payments for employees. It is particularly critical for employees who expose the organization to large risks, such as traders and investment professionals. A fair compensation system should take into account the level of risk incurred for a given level of return and should reward those who accomplish returns without incurring excessive risks.
An example of an incentive that could lead to deviant behaviour is rewarding traders for earnings regardless of the risks they take. This technique would provide them all the upside for trading gains, but less downside for taking on risks and for trading losses. In actuality, traders creating big losses frequently lose their jobs and reputations, although they usually do not have to pay back much compared with the income they previously earned.
Some authorities are already implementing new compensation systems that incorporate deferred remuneration to take into consideration long-term performance as well as claw-back provisions, wherein employees may have to refund their bonuses if claimed profitable transactions result in losses later.
Managing Systems
Companies rely substantially on information technology (IT) systems. Consequently, technology has become an increasingly major source of operational risk. Automated processes can lessen the incidence and severity of operational failures, but they are not flawless. Failures of IT and communication systems can paralyse business activities or severely diminish their efficiency, affecting the company’s profitability via reduced revenues, higher costs, or a combination of both.
IT networks are inherently vulnerable to disturbances and outside intervention owing to technical limits and human factors. One source of danger is the attitude of employees who do not follow corporate policies and, for instance, download illegal software for personal or professional use.
The disadvantages of this technique include harmful viruses and unauthorized, and perhaps incompatible, software infiltrating enterprise systems. In addition, IT departments are in a constant war with hackers who exploit holes to enter systems.
Key controls to secure systems and corporate information include the following:
Establishing and disseminating internal policies for users and IT technical staff Creating acceptable security standards and configurations for systems
Allocating appropriate manpower and technical resources to ensure a well-controlled IT environment
The security of secret information is also vital in the investment industry. Data privacy has lately gained in popularity due to a series of situations in which companies and government agencies allowed people’s private information to enter the public domain, exposing them to the danger of fraud.
A corporation should understand how data are produced and flow internally, classify the information by sensitivity, estimate the risks of data loss, and adopt suitable preventative measures. Many countries have strict laws and regulations for securing customer data, coupled with significant consequences for breaking these laws and regulations.
Complying with Internal Policies and Procedures
The structure of a company varies with size and the business activities it is engaged in, but there are aspects common to all firms. For example, power and authority are delegated and duties assigned within most corporations. In smaller entrepreneurial organizations, such assignments may be communicated informally, with individuals recognizing their respective positions and degrees of authority.
In larger and more complicated firms, the responsibilities and degrees of authority will be explicitly defined and the business processes written out in more detail, frequently contained in corporate management systems. Policies and procedures should expressly set out the delegation of authority and identify clear roles and accountability. These definitions constitute the basis for the monitoring of and control of business operations and provide feedback mechanisms.
The division of duties is a fundamental notion that international firms and regulators, along with other authorities in many nations, need and urge. As discussed before, a clear distinction needs to exist between front and back offices. In accounting departments, there should also be a clear separation between those who enter items into the accounts and those who reconcile the bank statements with the cash balances in the accounting system.
This separation of roles decreases the chance that personnel who possess cash may commit fraud or pilfer funds. Compliance and internal audit responsibilities are crucial to verifying that staff are truly following internal policies and procedures.
Managing the Business Environment
The sort of environment in which a company operates might add levels of uncertainty that need to be addressed.
Political risk is the risk that a change in the dominant political party of a country would lead to changes in policies that can affect anything from monetary policy (money supply, interest rates, and credit) and fiscal policy (taxation) to investment incentives, public projects, and procurement.
Some industries are significantly controlled by governments that, for example, regulate natural resources or set pricing of raw material inputs or outputs. In some circumstances, a change in administration or policy can impact the value of an investment. Political risk is inherent in all countries and should always be considered, even if it is deemed to be relatively remote.
Legal risk is the chance that an external party would sue the company for breach of contract or other infractions. A corporation should assess how it identifies and conforms to the legal responsibilities it has undertaken
The function of an in-house legal professional is vital to controlling legal risk. Most sections of a corporation have relations with external parties, such as deal counterparties, business partners, suppliers, and service providers. An key control in managing the legal risk of these external ties is to have legal professionals analyze every contract.
Companies should explicitly allocate authority and indicate who should evaluate and approve certain type of contracts. The most major deals normally require clearance at the level of the board of directors. Another solution is to use template agreements and standard contract terms and conditions that have been examined and approved by the legal staff.
The preservation of records, documents, and other forms of communication must also be in conformity with legal standards for all relevant jurisdictions.
Settlement risk (or counterparty risk) is the danger that while closing a transaction, a corporation fulfills one side of the contract, such as sending a security or money, but the counterparty does not complete its side of the deal as agreed, frequently because it has declared bankruptcy. This risk is sometimes also called Herstatt risk because of an incident in 1974 when the German Herstatt Bank ceased operations after counterparties had honoured their obligation to transfer Deutsche Marks to Herstatt, but before Herstatt honoured its obligation to transfer the equivalent amount in US dollars back to these counterparties.
Although there are usually legal procedures to compel a counterparty to meet its obligations, such actions are costly and time consuming. A counterparty is more likely to find it difficult to fulfil its obligations during adverse economic times or when bankruptcy is imminent than during successful periods. In the case of bankruptcy, it may take months or years to receive assets through a bankruptcy resolution procedure and the proceeds may only be a fraction of the original nominal amount of debt.
It is vital to identify the risks inherent in bilateral arrangements from those in transactions contracted through central counterparties, such as clearing institutions. Clearing houses may step in to accept the risk of a counterparty failing to meet its contractual obligations. Other measures to mitigate this risk are margin requirements or standardised agreements.
0 Comments