Risk MGMT
Risk MGMT
Risk MGMT
RISK ASSESSMENT
1
OVERVIEW
• Inherent Risk
• Risk Management
• Composite or
Net Residual Risk
• Trend
2
INHERENT RISK
Definition
Sources
Identification
Quantification
3
Definition
SOURCES OF RISK
People
Fraud
Breach of authorized limits
Human error
Processes
Execution failure
Product failure
Systems
Systems disruption or failure
Vendor/service provider failure
External events
Natural disaster
Political events
5
Risk Sources
UNDERSTANDING THE
OPERATIONAL AREA
People
Organization chart and reporting lines
What is department’s position within
organization? What is department’s
organization structure? Clear, direct, and
sufficiently high reporting lines?
Interfaces with other departments
What data, reports, or risk management
responsibilities flow across departmental
boundaries?
Role definitions or job descriptions
Are departmental activities—and
management’s roles—clearly defined?
Staff and management qualifications
What is the experience level and expertise 6
of management and key staff?
Risk Sources
UNDERSTANDING THE
OPERATIONAL AREA
Processes
Workflow diagrams
Work process documents from business line or
internal audit; Management interviews
Dependencies and interfaces
With other internal departments; With external
service providers.
Products
Transaction volumes and dollar amounts
Risk & control assessments
Procedures
Monitoring reports
Obtain a complete list of MIS; Identify distribution
and frequency. 7
Strategy and major projects
Risk Sources
UNDERSTANDING THE
OPERATIONAL AREA
Systems
Major systems and components
Architecture; Hardware and software
inventories
System interfaces
IT topologies; Data flow diagrams
Outsourcing vendors
Security
GLBA security report for board
Contingency plans
Corporate contingency plan; business 8
line and support area continuity plans
Risk Indicators
11
Risk Indicators
Inherent Residual
RISK IDENTIFICATION
-- INFORMATION SOURCES --
INFORMATION SOURCES
-- GENERAL --
18
Risk Quantity
INFORMATION SOURCES
-- SPECIALIZED --
Human Resources
Management succession plan
Training costs and penetration
Technology
Topology and data flow diagrams
Loan Operations
Payment processing exceptions
Document handling measurements
Overrides & limit exceptions
Suspense account resolution
Deposit Operations
Deposit processing exceptions
Encoding error rates
Research request response time
Statement mailing measurements 19
QUANTITY OF RISK
Volume
Measurement
Information sources
QUANTITY OF RISK
21
Risk Quantity
Systems:
The organization’s business operations utilize industry standard
networks.
Systems are flexible enough to upgrade performance levels
and increase capacity within reasonable time frames.
Existing / legacy systems relatively stable and supported
adequately by outside vendor or in-house staff, but significant
enhancements may be necessary to support all or parts of
critical business processes.
Restricted access granted to internal / external parties.
Manageable amount of systems development and acquisition
projects given the entity’s size and complexity.
The organization retains a reasonable level of technological
innovation, and selectively implements emerging technologies 28
that are consistent with its business plan.
Risk Quantity
QUALITY OF RISK
MANAGEMENT
35
Risk Management
POLICIES, PROCEDURES,
AND LIMITS
What to look for
Policies, procedures & limits for
major operational areas
Policy compliance testing and
enforcement
Information sources
Policy, procedures, & limits
documentation
Compliance mechanisms;
exception reports 37
Risk Management
MEASUREMENT, MONITORING,
AND MIS
What to look for
Comprehensive & appropriate
board, committee, and
management reporting
Reporting validation
Information sources
Board and committee packages;
management reports
Internal audit reports
38
Risk Management
RISK ASSESSMENT:
Determine Trend
RISK ASSESSMENT:
Develop Hypothesis
High Quantity High Exposure High Quantity
Weak RM Process Strong RM Process
Weak RM Strong RM
Process Process
47
Exam Strategy
RISK ASSESSMENT:
Examination Scope Based on Hypothesis
High Qty. - Weak Mgmt. High Qty. - Strong Mgmt.
Confirm risk assessment Confirm risk assessment
Low reliance internal Rely on internal measures
measures Modified on-site procedures
Full on-site procedures targeting specific areas
Low Qty. - Weak Mgmt. Low Qty. - Strong Mgmt.
Confirm risk assessment Confirm risk assessment
Low reliance internal Rely on internal measures
measures Minimal on-site procedures
Target “Management”
section of on-site 48
procedures
Risk Relationship
Operational Legal
Reputational
Credit Liquidity
49
OPERATIONAL RISK
RISK ASSESSMENT
50
RESOURCES
“Sound Practices for the Management and
Supervision of Operational Risk,” Basel
Committee on Banking Supervision, February
2003
“Operational Risk Data Collection Exercise -
2002,” Basel Committee on Banking
Supervision, June 2002
“Framework for Internal Control Systems in
Banking Organisations,” Basel Committee on
Banking Supervision, September 1998
“Internal Control – Integrated Framework,”
Committee of Sponsoring Organizations (COSO)
51