Operational Risk Scenario Analysis

Transcription

Operational RiskScenario Analysis17/03/2010Michał statconsulting.com.plCopyright by StatConsulting Sp. z o.o. 2010

Operational Risk – ‘Tail Events’Copyright by StatConsulting Sp. z o.o. 20102

AgendaOperational Risk - Scenario Analysis Operational Risk - DefinitionSolvency IIRole of Scenarios in Risk ManagementRole of Scenarios in Risk Quantification (VaR)SummaryCopyright by StatConsulting Sp. z o.o. 20103

Operational Risk Operational risk means the risk of loss arising frominadequate or failed internal processes, personnel orsystems, or from external events Operational risk shall include legal risks and exclude risksarising from strategic decisions, as well as reputationrisks The capital requirement for operational risk shall reflectoperational risks to the extent they are not alreadyreflected in the risk modules.SOLVENCY II DIRECTIVE, 25 November 2009Copyright by StatConsulting Sp. z o.o. 20104

Operational RiskSolvency II/Basel IISolvency IIOperational risk is the riskof loss arisingfrom inadequate or failedinternal processes,people, systemsor external events.Operational risk alsoincludes legal risks.Reputation risks and risksarising from strategicdecisions do not count asoperational risks.Basel IIOperational risk is definedas the risk of loss resultingfrom inadequate or failedinternal processes,people and systemsor from external events.This definitionincludes legal risk,but excludes strategic andreputation risk.Copyright by StatConsulting Sp. z o.o. 20105

Operational Risk Types Internal Fraud – Unauthorized activity, theft and fraud External Fraud - theft of information, hacking damage, third-party theftand forgery Employment Practices and Workplace Safety - discrimination, workerscompensation, employee health and safety Clients, Products, & Business Practice - market manipulation, antitrust,improper trade, product defects, fiduciary breaches, account churning Damage to Physical Assets - natural disasters, terrorism, vandalism Business Disruption & Systems Failures - utility disruptions, softwarefailures, hardware failures Execution, Delivery, & Process Management - data entry errors,accounting errors, failed mandatory reporting, negligent loss of clientassetsCopyright by StatConsulting Sp. z o.o. 20106

Operational Scenarios, Events, Losses Scenario –Class of OperationalEventsScenario Event - An operational risk event isan incident leading to the actualoutcome(s) of a business process todiffer from the expected outcome(s),due to inadequate or failed processes,people and systems, or due to externalfacts or circumstances (ORX). Loss -An operational risk loss is anegative impact on the earnings orequity value of the firm due to anoperational risk event (ORX).EventEventsLossLossesLossesCopyright by StatConsulting Sp. z o.o. 20107

Operational RiskRisk of loss arising from inadequate or failed internal processes, personnel or systems,or from external eventsRisksProcesses, People, Systems, External EventsEventsLosses{ Frequency, Severity }Copyright by StatConsulting Sp. z o.o. 20108

Solvency II – Three PillarsSolvency IIPillar IPillar IIPillar IIITechnical ProvisionsCorporate GovernanceReportingMCR(Minimal CapitalRequirement)Principles for internalcontrol and riskmanagementMarket DisciplineSCR(Solvency CapitalRequirement)ORSA(Own Risk and SolvencyAssessment)Copyright by StatConsulting Sp. z o.o. 20109

SCR (Solvency Capital Requirement):Standard FormulaQIS4 -TechnicalSpecificationsCopyright by StatConsulting Sp. z o.o. 201010

QIS4 – Operational RiskStandard Method SCRŹródło: QIS4Copyright by StatConsulting Sp. z o.o. 201011

Operational Risk sFuturePrecise qualitative and quantitativeoperational risk assessmentCopyright by StatConsulting Sp. z o.o. 201012

Operational Risk ManagementRisk typesKRI identificationand RI selectionBusinessLinesKRIScenario definition –based on occurringlosses or losspossibilityLossesSystemsCopyright by StatConsulting Sp. z o.o. 201013

Scenario Analysis Once an year, owners of the processes are collectingoperational scenarios Every scenario describes the possibility of occurrence ofoperational loss. Scenarios besides description have the following properties Risk type, line of business, process, business unit Risk control level, possible enhancements in risk control level Business continuity plans Quantitative information Frequency SeverityCopyright by StatConsulting Sp. z o.o. 201014

Scenarios - Sources of InformationInternal Loss DataScenario1Scenario2External Loss DataImaginative ThinkingCopyright by StatConsulting Sp. z o.o. 201015

Homogeneous organization partsBusiness Lines x ProcessesRisksInsurance CompanyRisk TypesHomogeneousIndependentClearScenario:Server crashFrequency: 1-2 times per 5 years.Expected loss: 5-10kUnexpected loss: 50-60kCopyright by StatConsulting Sp. z o.o. 201016

Scenario Analysis - Scenario ExampleFieldValueLine of business:Ubezpieczenia majątkoweProcess:Zarządzanie sprzedażą onlineBusiness unit:Risk type:Oszustwa ie do systemu i kradzież danychRisk control level:NieakceptowalnyEnhancements in risk control:Wprowadzenie dodatkowych zabezpieczeń i procedurConnected KRIs:Rotacja pracowników w dziale IT, .Quantitative information:Occurrence frequency:1-2 / 5 latSeverity (median):30 000 - 40 000Stress severity:100 000 – 300 000(Maximum severity):Events/Losses list: Copyright by StatConsulting Sp. z o.o. 201017

Scenario Analysis – VaR modelingSeverity Frequency,Severity distributions Comparisonwith collected loss n Aggregation, diversification Result: Aggregatedoperational risk loss distributionwith decompositionWeibullCopyright by StatConsulting Sp. z o.o. 201018

Value at RiskExpected LossUnexpected LossExtra capital forunexpected lossSolvency II- 99,5Copyright by StatConsulting Sp. z o.o. 201019

Scenario Analysis – VaR aggregationProcessProcessProcessLine of businessWhole companyCopyright by StatConsulting Sp. z o.o. 201020

Scenario Analysis – Risk MapsCriticalsituationmanagementHighLowLoss frequencyFixingprocessesRecurring lossesCritical situationMinor riskEssential risk(unexpected losses)Small amountsBig amountsContinuationplans,insuranceLoss severityCopyright by StatConsulting Sp. z o.o. 201021

Operational Risk – Scenario AnalysisSummaryScenario Analysis Advantages Forward looking Collected loss data can be used as a valuable support Allows you to implement risk controls prior to the loss occurrence Allows risk quantification - VaR method Allows risk sources identification (for example VaR drill-down) Allows to present risk on risk maps Disadvantages Labor-intensity – smaller in subsequent rounds – big proportion of the scenariosremains unchangedCopyright by StatConsulting Sp. z o.o. 201022

Contact:StatConsulting Sp. z o.o.Wołodyjowskiego 38a,02-724 Warsaw, Polandphone: 48 22 847 97 17fax: 48 22 499 45 31e-mail: lCopyright by StatConsulting Sp. z o.o. 2010

Operational Risk -Scenario Analysis Summary Scenario Analysis Advantages Forward looking Collected loss data can be used as a valuable support Allows you to implement risk controls prior to the loss occurrence Allows risk quantification - VaR method Allows risk sources identification (for example VaR drill-down)