Top 10 operational risks for 2013
OpRisk looks again at the primary concerns for operational risk managers in the New Year
Please click here to read our latest Top 10 Operational Risks for 2014
The year to come will see, at best, sluggish economic growth worldwide. International Monetary Fund forecasts show a third year of lacklustre growth in the advanced economies (1.5%, after 1.6% in 2011 and 1.3% in 2012) with no hope of making up the shortfall created by the 2008 crisis (although the US, relatively unhampered by austerity policies or the European debt crisis, will grow considerably faster than the UK or the eurozone), and growth of just 5.6% in the emerging economies.
The stress this causes throughout the financial world will manifest itself in a number of ways: fraud, money laundering, regulatory change and uncertainty, mistrust of banks and the risk of control failure.
Some of the 10 operational risks on this list will be obvious – the challenge to business continuity from natural disasters, for example, was underlined by the impact of October’s hurricane on the north-east US, in particular its impact on the financial industry in southern Manhattan. Some, though, are less obvious – it’s a near-certainty that 2013 will see natural disasters somewhere in the world, but the odds of a worldwide disease outbreak are lower. Still, it deserves inclusion on the list as a risk against which many institutions may not be well prepared. Others again are closely linked – a failure in internal controls may be the result of problems with organisational culture, and may be the immediate cause of a breach in sanctions or money-laundering rules, and this in turn may attract political attention and cause reputational damage.
In no particular order, here are Operational Risk & Regulation’s Top 10 operational risks for 2013. Click on the links to read full analysis on each of the risk types.
Internet-based or cyber attacks have crossed the line from being a relatively minor institution-level threat to a significant danger to the stability of the financial system. A year which saw a growing chorus of warnings of the systemic dangers of cyber attack culminated in a speech by Atlanta Federal Reserve Bank president David Lockhart in late November. "In the last few months, the United States has experienced an escalating incidence of distributed denial of service attacks aimed at our largest banks," Lockhart said. Click to read full article
A good reputation has never been easier to lose - although this may not be a problem for much of the financial sector, as it doesn't have one. Once again in 2012, the annual Trust Barometer survey conducted by US PR firm Edelman found banks and financial services the least trusted sector of business - less trusted even than they were in 2011. Click to read full article
In 2011, UK banks ring-fenced a total of £5 billion for expected compensation payments to customers who had been mis-sold financial protection products - in particular, payment protection insurance (PPI). In 2012, it emerged that they had been too optimistic - the major banks have more than doubled their provisions for PPI payouts. Click to read full article
Internal fraud remains, as ever, a high priority for risk managers across the financial sector. Economic downturns are known to generate fraud: as employees come under real or anticipated financial pressure, they face the temptation to steal, or to concoct favourable-looking sales and profits in order to reap higher bonuses or simply to ensure they remain employed. Click to read full article
The past decade has seen two high-profile widespread outbreaks of respiratory disease: severe acute respiratory syndrome in 2003 and H1N1 influenza in 2009-10. The risk of a severe influenza pandemic - in which a sudden genetic shift creates a new strain of the influenza virus, which spreads to affect a significant proportion of the world - has been estimated at one in every 25-30 years. Click to read full article
The largest single economic uncertainty facing the world - and, not coincidentally, one of the largest potential sources of operational risk - remains, as it was a year ago, the eurozone debt crisis. The November agreement on aid to Greece and the €37 billion deal to restructure Spain's debt-laden banking sector are signs of hope, but the crisis is far from over and a break-up of the eurozone has still not been definitively averted. Click to read full article
2012 saw leading banks in the spotlight, accused of negligently or wilfully breaking anti-money laundering (AML) rules or international economic sanctions. Standard Chartered Bank, accused of breaches of US sanctions on Iran by the New York Department of Financial Services, was forced to pay a $340 million settlement. HSBC, accused of overlooking money laundering from Mexico into the US, predicted in November that the total fines could be more than $1.5 billion. Click to read full article
Emerging market operating risks
Regulators and financial institutions have long recognised that rapid economic growth in emerging markets will draw in not only investors but also the companies that serve them. Earlier this year, Vedat Akgiray, chairman of the Turkish Capital Markets Board and the emerging markets committee of the International Organisation of Securities Commissions (Iosco), called on his fellow regulators to follow the trend: "Proper securities regulation in today's emerging markets is tantamount to "proper" regulation of tomorrow's developed markets. Therefore, emerging markets within Iosco and the global financial system are much more important than they were in the past." Click to read full article
Business continuity and disaster recovery
Unusually low rates of disaster losses in the first half of the year were followed by the severe damage done by Hurricane Sandy to the Caribbean nations and the eastern US. The US suffered estimated direct damage of $20 billion, rising to $50 billion once interruptions to business are taken into account. Click to read full article
Failure to enforce internal controls
Under much recent legislation - the 2010 UK Bribery Act, for example - companies can use the existence of adequate controls as a defence, even when an offence has actually taken place. But the recent trial of UBS rogue trader Kweku Adoboli highlighted that adequate internal controls are useless if they are not maintained and monitored properly. Click to read full article
Operational risk best practice will be discussed at OpRisk Europe on June 11 - 14 in London. For more information and details about attending visit opriskeurope.com.
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@risk.net or view our subscription options here: http://subscriptions.risk.net/subscribe
You are currently unable to print this content. Please contact info@risk.net to find out more.
You are currently unable to copy this content. Please contact info@risk.net to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@risk.net
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@risk.net
More on Operational risk
Evalueserve tames GenAI to boost client’s cyber underwriting
Firm’s insurance client adopts machine learning to interrogate risk posed by hackers
Integrated GRC solutions 2024: market update and vendor landscape
In the face of persistent digitisation challenges and the attendant transformation in business practices, many firms have been struggling to maintain governance and business continuity
Vendor spotlight: Dixtior AML transaction monitoring solutions
This Chartis Research report considers how, by working together, financial institutions, vendors and regulators can create more effective AML systems
Financial crime and compliance50 2024
The detailed analysis for the Financial crime and compliance50 considers firms’ technological advances and strategic direction to provide a complete view of how market leaders are driving transformation in this sector
Automating regulatory compliance and reporting
Flaws in the regulation of the banking sector have been addressed initially by Basel III, implemented last year. Financial institutions can comply with capital and liquidity requirements in a natively integrated yet modular environment by utilising…
Investment banks: the future of risk control
This Risk.net survey report explores the current state of risk controls in investment banks, the challenges of effective engagement across the three lines of defence, and the opportunity to develop a more dynamic approach to first-line risk control
Op risk outlook 2022: the legal perspective
Christoph Kurth, partner of the global financial institutions leadership team at Baker McKenzie, discusses the key themes emerging from Risk.net’s Top 10 op risks 2022 survey and how financial firms can better manage and mitigate the impact of…
Emerging trends in op risk
Karen Man, partner and member of the global financial institutions leadership team at Baker McKenzie, discusses emerging op risks in the wake of the Covid‑19 pandemic, a rise in cyber attacks, concerns around conduct and culture, and the complexities of…