Banks face risky business of Basle

Operational risk is not new – it’s a concept that banks have been struggling with for years with varying degrees of success. But setting aside capital against the risk of loss from human error, systems failure, or fraud is new, and of growing concern to the industry. With the Basle Accord’s capital requirements coming into effect in January 2005, banks and other financial institutions are having to face operational risk issues with a new sense of urgency. In the following roundtable discussion, euromoney.com brought together a number of professionals with different operational risk challenges to discuss the questions they face and the business implications of the Basle Accord. IBM’s Keith Saxton moderated

       
Keith Saxton

Keith Saxton: We know operational risks are growing rapidly – those related to human mistakes, fraud, and legal and regulatory issues being the most common – and I think September 11 has heightened the real focus on this issue. However, designing and implementing an effective enterprise-wide risk management and control system is one of the most difficult issues facing markets and banks today. What does it mean for the balance sheets of both small and large banks and how can they manage the effects of the Basle Accord?

Jeremy Quick: We are concerned. That’s not to say we are against operational risk at all – we know that’s the way firms earn money – we are anxious to ensure that firms know what sort of operational risk they are taking on. We also want to ensure they are comfortable that the level of operational risk that they take on can be handled both in terms of systems controls and also in terms of solvency.

Operational risk is an extremely difficult subject. How do you weld together operational risk teams, how do you identify operational risk, how do you mitigate it? What is the function of the internal audit in this, what is the function of the traditional process controls that have been around for a long time and are they the right ones? Are key risk indicators, which are a traditional internal audit tool, helpful or do they mislead you? How do you control information security issues, how do you inform boards, which frankly don’t know much about it?

How do firms have an overall view of the outsourcing issues, how do they buy insurance that is effective against their particular operational risks? Do they hold very intensive discussions with the business lines and how do they keep that up for a long time? What is operational risk when you compare it with credit and market risk?

There are also huge doubts over whether you can quantify operational risk. There’s this whole issue of operational risk capital. We believe in it because of solvency reasons, we believe in it because of incentive reasons. So I see this as an area where there are a huge amount of questions. I am certain we are not going to solve them as regulators, it’s not our job and we don’t have the resources. I’m absolutely certain we won’t solve them all by the end of Basle II. There is a huge problem with how we incentivize firms as regulators without being prescriptive or overbearing.

Keith Saxton: David, how would you view this from Barclays’ point of view?

David Curd: I spend a lot of my time trying to encourage the bank to manage its operational risk. At the moment I find, particularly post September 11, that some of our best people are distracted. I applaud the intent – we need to incentivize, encourage the development of how we manage it and move it forward – but it has to be practical and at the moment I find a lot of the distractions unhelpful.

       
David Curd

Secondly, yes, we have always managed operational risk. We have learnt that the interactions of operational risk, credit risk and market risk add a new dimension. Globalization and technology are driving that and therefore we need to raise our game.

So, in that respect Basle and what the regulators are trying to do is very helpful. Lots of questions are fine, but I need some answers. I hope that in the next six months or so we can crystallize through consultation and bring this down to practical things that I can deploy in our processes.

That said, for the first time in my career, operational risk has a profile, a priority and maybe will even get some investment that we have traditionally not seen.

Keith Saxton: Margaret, how would you view it from Abbey National’s view? How are you measuring operational risk?

Margaret Schwarz: Measuring operational risk is probably one of the biggest difficulties we face. You can actually measure costs when they have occurred, when you have had a loss, you can see how much it’s cost you, but how do monitor and measure it? You can’t – it’s very anecdotal.

       
Margaret Schwarz

Before I came tonight I was just reading over the operational risk report that we produce every six months – and it’s words. How do you capture words in a database and how do you then share the data? How do you model these things?

If we think we are going to approach operational risk the way we can approach financial risks, we’re wrong. We need to think in different terms. We need to think perhaps in process terms. The focus on operational risk increases costs. By having to add a layer of management you suddenly just increase your fixed costs, you’ve made it more expensive to be in the market.

Operational risk has gone up because our operations have got a lot more complex. Not long ago 24-by-seven would have been completely unheard of in banking and now it is a real issue. How do you justify standby for your e-commerce? How do you play in a playing field that is all of a sudden more expensive?

There is a danger that the well-run banks will be the expensive banks, the well-run financial institutions will be the ones that price themselves out of the market by people who come in and undermine it. That is the danger and that is a warning to the regulators.

       
Pierre Pourquery

Keith Saxton: How can technology help us get over the complexity of what these institutions are trying to achieve?

Pierre Pourquery: I think it is very important to understand that measuring risk and partial risk is not the end point. What is much more important is to understand your operational resilience, whatever it is, and this could help us to define operational risk. There are a lot of new technologies that could be applied.

What we found out from the events of September 11 was that a lot of banks have a solid and robust infrastructure framework but this was not properly aligned with their business and their operations so the foundation was not consistent. So I think technology will help solve a lot of problems but the business side will have to be pretty sophisticated.

David Curd: Barclays has some operations a block away from the World Trade Centre which we had to evacuate and move to our disaster sites. It was not about Barclays but about keeping the system going. I don’t think at an operational risk level that this is competitive. There is incentive in order to reduce regulatory capital and therefore costs, but that is not a competitive advantage.

What was very interesting about events in New York was how competitors worked together to ensure the integrity and the viability of the system. That was not a competitive issue, that was an industry working together because those operational risks, if not contained, were going to spill over into the market.

Mark Kalderon: Operational risk is a requirement that applies to banks and not to insurance companies or pure investment firms. That doesn’t seem a fair situation in terms of competition.

David Curd: There needs to be a level playing field, particularly outside the EC. If firms can’t comply they shouldn’t be in the business because if you cannot invest enough to ensure the integrity of your operations I don’t think you should be in the game. In that respect the regulators have got it right.

       
Reto Tuffli

Keith Saxton: This could be a very expensive process and therefore the best banks are going to be the most expensive. But are the firms who do this first in an advantageous position?

Reto Tuffli: Our company is coming out with a new offering and is introducing an enterprise system approach for capital markets. This is not a new concept, it exists in the manufacturing world, but it’s not something that you see in the capital markets. We see a lot of tie-ins to operational risk simply because operational risk is a catalyst for focusing on the processes and process management. People who focus on it strategically will look at it far beyond just a regulatory requirement.

Keith Saxton: What implications does all this have for bank credit ratings?

Walter Pompliano: Operational risk isn’t a new risk, it’s a heightened risk and is definitely on our agenda. We have historically been very qualitative in our approach in looking at how overall risk management is conducted by a financial institution. Operational risk can be heightened in any given situation at any given point.

       
Walter Pompliano

A firm may experience a great increase in volumes as a result of consolidation, it may be seeing a significant turnover as a result of integration. We are concerned with integration risk, which is an operational risk issue. Risk management isn’t very different from our capital analysis which, from a credit perspective, is very keen on protecting creditors. We have concerns in terms of this competitive landscape, particularly in Europe where we have several fragmented supervisors, different laws and jurisdictions.

We view operational risk more broadly than it is currently being defined. But however you define it, capital is the buffer for all risk.

We are pleased that the Basle Accord is providing interest in financial institution wide risk management systems, putting operational risk on the agenda of so many large institutions where it should be. There are some positive things that are coming out of Basle but there are also some concerns.

Keith Saxton: Mark, how much leeway do you think the banks have in terms of a legal interpretation of all this?

Mark Kalderon: One of the areas people talk about a lot is insurance, insuring the credit risk. That does now seem to be recognized in the latest paper on operational risk at least to an extent.

       
Mark Kalderon

Outsourcing is another interesting area – the extent to which outsourcing and various business lines and capabilities is recognized as reducing the operational risk charge for firms.

The paper talks a bit about the need for the firm which takes on the outsourcing to take on the legal responsibility for the outsourcing, but there is always a lot of negotiation and a limit to the willingness of the outsourcing firm to take on that liability.

Margaret Schwarz: Arguably, when you do outsource, you actually compound your operational risk because if you are outsourcing a key part of your business, then if something goes wrong, whether you get directly compensated for that direct loss, your customers and your reputation suffers. You must be as concerned with their operational risk as you are with your own.

Jeremy Quick: In terms of a level playing field, as a regulator there is very little we can do at the end of the day. We cannot, in the US, force the SEC to apply the capital ratios that Brussels dictates.

We are trying, however, to calibrate the charge so it is worth doing on a cost benefit basis. All we’ve done with Basle is produce very broad, high-level stuff. We’ve got to talk about all the data issues in a serious way.

Keith Saxton: What are the issues of complexity? Could you end up with a whole bunch of rules that people are striving to meet and they don’t ever know if they have met them or not?

Margaret Schwarz: The whole idea of quantifying, measuring and explicitly setting capital against operational risk is relatively new so it has taken us a long time to get where we are with financial risks. You don’t have that many observations and that’s where the industry data will come in handy.

Reto Tuffli: The operational risk challenge is large, for the simple reason that you are not just focused on one particular data type, ie risk. You are talking about resource data, process data, systems metrics, financial metrics. It touches on every single piece of data type in the enterprise if you want to do it in a comprehensive way.

Pierre Pourquery: In the last century we were using normal distribution as a rule for quantifying anything and I think the new century is more focused on extreme events.

Lack of data is one big issue because we don’t have enough data to back-test our model but which model are we going to apply? I think it will take years before we agree on which model is appropriate for quantifying operational risk.

You can use one distribution for market risk and to some extent for credit risk but for operational risk each event type will have its own distribution and this, from a mathematical point of view, is the dirty aspect of risk.

       
Jeremy Quick

Keith Saxton: What sort of time scale do we have to do this? Is there a danger of setting standards that are so far out that people again delay because there’s a cost implication?

Jeremy Quick: The Basle timetable is January 2005 implementation. I think firms generally recognize that time is running out on operational risk because of the data issue. You need three years of data as a minimum and firms are waking up to this very quickly.

Operational risk can be divided into four stages: identification, measurement, modelling, mitigation. If you compartmentalize them, life becomes easier.

David Curd: This isn’t all about regulation when, if your ATM network is down or your online bank isn’t available, you are on the nine o’clock news. There is a big consumerism driver here that has brought operational risk to the forefront.

A lot of what we are doing in operational risk is not driven by Basle, it’s driven by some bad experiences in the press and – misreported as they were – they have taught us a hard lesson.

Jeremy Quick: The lower your historical losses with the models and the lower your charge, then the better your processes and the more effective you are.

David Curd: But I am looking forward, that’s the difference.

Jeremy Quick: That’s assuming models can then become predictive and that is the nirvana.

David Curd: What I am saying is I don’t think you can model that at a firm level, I think you may do it at a process level.

Margaret Schwarz: Technology is a tool, it is not the end in itself. You need to spend an awful lot of time thinking about what exactly your business processes are before you even start thinking what the solution is.

Operational risk is about very good management. Some of the tools that we are talking about developing for operational risk are to enhance the management that we need to put into place so we talk about process re-engineering. There is an awful lot of non-technology thinking that has to go on.

Jeremy Quick: There were some very public mishaps around security in the scramble to market that we saw 18 months ago in internet banking. They may not actually have been threatening the solvency of the institutions but they sure as hell made an impact on the reputation of those providers. I suspect that in certain institutions the commercial pressures were overpowering.

Margaret Schwarz: That’s exactly the tension that you face and probably until you can quantify and measure, it always will be. I think it keeps coming back to that being the issue because you need to look at these investments. It is going to cost me a pound, am I going to get at least a pound’s worth of value out of this? What’s the risk if I don’t do it?

Pierre Pourquery: Commercial pressures will always win. With operational risk you can measure the impact of bad decisions – or at least you can evaluate it.

Margaret Schwarz: After the fact.