
Operational risk management is taking hold
Corporate Statement
Financial institutions globally are evolving a more common view of the purpose, function and value contribution of operational risk management (ORM), as evidenced by the third annual global op risk survey conducted by Operational Risk magazine and Protiviti. Since this survey’s initiation in 2003, ORM programmes have continued to mature, with focus on the identification, measurement and communication of operational risk exposures becoming the widely held standards.
The new Basel Accord and related domestic regulations continue to be the most significant stimulus for the development of operational risk programmes globally, with 90% of respondents citing Basel II as a significant factor, and more than half the respondents naming it as the primary factor affecting the development of their programmes. Even in the US, where only the largest banking organisations are required to comply with the Accord, 85% of banks with less than $10 billion in assets identified the Accord as the most influential factor. This also suggests operational risk management will become pervasive across institutions of all sizes.
In light of the recent delay by US regulators in announcing proposed rules, some may be concerned that support for ORM programmes may weaken. However, performance-based motivations have gained in significance since the first survey in 2003. More than 60% of the respondents to this year’s survey identified internal best practices benchmarking exercises, concern over levels of operating losses, and industry initiatives addressing operational risk as critical factors in the formation and growth of their ORM programmes.
While regulation might have been the impetus behind creating initial demand and awareness, value creation and improved results appear to be the drivers of the next wave of evolution and adoption. A majority of respondents cite improved business and performance management and reductions in operating losses as key programme benefits (see figure 1). Interestingly, more than one in four respondents acknowledged "optimised allocation of economic capital" and "reduction of regulatory capital" as having little or no impact on the success of their ORM programmes.
A converging view of the ORM framework
In 2005, more than 92% of respondents have a formal ORM programme in place, up from 81% in 2003. Nearly 60% of ORM programmes have a distributed ORM framework, led by a chief operational risk officer or central governance structure supplemented by dedicated (35% of respondents) or part-time (24%) risk professionals at the business unit level. And the scope of ORM is branching out. While early ORM initiatives were often handled by audit and/or compliance departments, we now see indications that ORM departments at larger financial firms (more than $100 billion in assets) are picking up selected compliance responsibilities, such as Sarbanes-Oxley compliance.
A common set of responsibilities has also emerged, with 70% of respondents identifying three primary functions within the ORM programme:
• Creation and management of operational risk policies and procedures.
• Administration of operational loss database.
• Administration of the risk control self-assessment programme.
Functional responsibilities such as oversight of business continuity (41%), internal fraud (31%) and information security (22%) were also identified within the mandate of some ORM programmes, but did not represent a systematic trend among respondents (see figure 2).
The average size of dedicated ORM teams is also expanding. Nearly 30% of respondents report team sizes of 11 or more members versus 18% last year, with expectations for continued hiring by more than half of all respondents in the next 12 months. The most common backgrounds of ORM team members include audit and general banking, cited by more than 50% of respondents, with other source groups being operations (37%) and finance/controllers (27%).
As in past surveys, a majority of respondents believe these expanding programmes can be funded with less than $1 million expenditure. However, more than 60% of the respondents projected that costs related to ORM will rise over the next 12 months, with less than 7% anticipating any decrease in funding. Top categories for future expenditure are support for increased reporting (60%), increased staff (52%) and training expenditures (50%).
Further opportunity
The impact of ORM programmes is being realised in many ways. More than 90% noted that ORM information is widely used to support risk assessment, while more than half of all respondents used such information in the approval of new products and initiatives. ORM programmes are promoting the development of an ORM culture through increased reporting to senior management (75%), the board of directors (69%) and business units (55%) - all at levels higher than in past surveys. And the use of ORM tools is steadily increasing over prior years, as more than 70% of respondents identified current or planned implementation of self-assessment tools, internal loss databases, external operational loss databases, statistical modelling for economic capital measurement and internal reporting tools. Key risk indicators were most commonly identified as part of future tool development.
Despite these trends, it is disconcerting to see that organisations are not yet linking the value of ORM programmes more closely to critical performance indicators. Less than 20% cited the use of ORM information in annual budgeting or product profitability, indicating that the information has yet to make its way into the risk/reward analysis of many financial firms. Likewise, such programmes as linking compensation to ORM performance, and the use of the code of conduct to recognise employee responsibility for ORM exposures were identified by less than 20% of the respondents as critical to promoting cultural awareness. Not surprisingly, the key obstacle to successful implementation of ORM most commonly cited was a lack of overall awareness and knowledge of operational risk issues among general staff. For the first time, this obstacle outweighed concerns raised in past surveys for measurement and data issues.
ORM and Basel II implementation
The recent delay by US regulators in issuing proposed Basel II rules has many speculating as to the eventual timing of implementation. With parallel testing quickly approaching for many jurisdictions, it is interesting to note that 27% of respondents are only in the initial stages of implementation, while 19% have not started implementation. Only 19% stated that Basel implementation was at or near completion. Fewer respondents appear to be using the advanced measurement approach to calculate economic capital (40% versus 44% in 2004), while a greater number of respondents are selecting the standardised approaches (45% versus 33% in 2004). And more than half of those respondents adopting Basel have not started implementing the disclosure requirements specified under Pillar 3.
In conclusion
Based on these most recent survey results, ORM is clearly taking hold as a standard risk practice of financial firms. Additional progress is needed, however, in linking ORM performance to the performance of the firm, before the full value of these programmes can be fully realised. l
Protiviti co-sponsored the third global operational risk study with Operational Risk magazine to survey risk professionals and interested parties worldwide. Respondents represent financial services organisations of all sizes and regions globally, predominantly from individuals based in the European Union, North America and Asia.
For survey results, please send an e-mail to angela.isaac@protiviti.com.
Protiviti (www.Protiviti.com) is a leading provider of independent business and technology risk consulting and internal audit services. Protiviti helps clients identify, assess and manage operational and technology-related risks encountered in their industries, and assists in the implementation and the processes and controls to enable their continued monitoring. The firm also offers a full spectrum of internal audit services focused on bringing the deep skills and technological expertise to enable business risk management and the continual transformation of internal audit functions.
Protiviti, which has more than 40 offices in North America, Europe, Asia and Australia, is a wholly owned subsidiary of Robert Half International Inc. (NYSE symbol: RHI). Founded in 1948, Robert Half International is a member of the S&P 500 index.
Contact
Angela Isaac, director and practice leader, Basel II services
Protiviti, Inc
Tel: 1 312 476 6489
Email: angela.isaac@protiviti.com
Please click here to view PDF versionOnly users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@risk.net or view our subscription options here: http://subscriptions.risk.net/subscribe
You are currently unable to print this content. Please contact info@risk.net to find out more.
You are currently unable to copy this content. Please contact info@risk.net to find out more.
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. Printing this content is for the sole use of the Authorised User (named subscriber), as outlined in our terms and conditions - https://www.infopro-insight.com/terms-conditions/insight-subscriptions/
If you would like to purchase additional rights please email info@risk.net
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. Copying this content is for the sole use of the Authorised User (named subscriber), as outlined in our terms and conditions - https://www.infopro-insight.com/terms-conditions/insight-subscriptions/
If you would like to purchase additional rights please email info@risk.net
More on Risk management
Core-Payments for business leaders: why real-time access to payment data is key to long‑term business success
Business leaders require easy access to timely, reliable and complete information across post-trade processes. Aside from the usual requirements of senior managers to optimise for risk, revenues and costs, they increasingly need to demonstrate to their…
UN climate risk chief calls for shorter-term stress tests
But banks say heavy modelling demands will take time to respond to adequately
Don’t count on repo to monetise liquidity books, say experts
QT could force banks to sell bonds during stress, underlining need for fair value accounting
US Basel endgame hits clearing with op risk capital charges
Dealers also fret about unlevel playing field compared with requirements in the EU
Calibrating interest rate curves for a new era
Dmitry Pugachevsky, director of research at Quantifi, explores why building an accurate and robust interest rate curve has considerable implications for a broad range of financial operations – from setting benchmark rates to managing risk – and hinges on…
Bankers – shape up or ship out, says UBS compliance head
Tough approach comes as ECB prepares new guidance on conduct risk for 2024 release
Op risk data: WhatsApp fines keep on coming
Also: ‘Five families’ stock-lending cartel pays up; double hit for Wells Fargo. Data by ORX News
The impact of emerging risk on credit portfolio management
Bank credit portfolio managers are increasingly finding that non-financial risks, such as cyber risk and climate risk, are falling under the remit of credit portfolio management (CPM). This will also be impacted by the upcoming Basel III Final Reforms,…