How Basel II is Changing Attitudes to Operational Risk

Fuelled by a number of well-known examples of operational risk failures during the past two decades, and long before the series of accounting and management scandals within major companies that inspired the U.S. Congress to pass the Sarbanes-Oxley Act of 2002, Basel II made banks realize that their existing attitudes to operational risk would have […]

Author
Bert Geukens Date published
May 17, 2004 Categories

Fuelled by a number of well-known examples of operational risk failures during the past two decades, and long before the series of accounting and management scandals within major companies that inspired the U.S. Congress to pass the Sarbanes-Oxley Act of 2002, Basel II made banks realize that their existing attitudes to operational risk would have to change.

Under the heading of “operational risk” the Basel Committee on Banking Supervision has grouped “the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events”. This definition includes legal risk but excludes strategic, reputational and systemic risk. It is clear that operational risk differs from other banking risks in that it is typically not directly taken in return for an expected reward. Operational risk tends to reduce business value by limiting management’s ability to achieve its objectives. Management of operational risk is taken to mean the “identification, assessment, monitoring and control/mitigation” of operational risk.

Anything new?

At first glance, there is nothing new in Basel II focus on operational risk. It has always been important for the financial services industry to try to prevent fraud, maintain integrity of internal controls, reduce errors in transaction processing, and so on. The Basel Committee also recognizes that management of specific operational risks is not a new practice.

In the recent past, most banks relied almost exclusively upon internal control mechanisms within their businesses, supplemented by the audit function, to manage operational risk. Typically, banks were short of an explicit, shared and consensual vision on operational risk management across the whole banking organization. Often this was reflected in a fragmented, negative, reactive, ad-hoc, cost-based, narrowly focused approach to operational risk management. Banks’ reliance on the operational risk management capability model seemed to match only partially with the qualifications of a “monitored” or an “optimized” level. Occasionally, operational risk management practices are still performed very informally or even subconsciously.

Comprehensive management

Recently, there has been an increased industry focus on setting up specific, standardized structures and processes aimed at managing operational risk as a distinct class of risk (similar to the treatment of credit and market risk). The thinking, guidance and qualitative requirements of Basel II for operational risk management go along these lines.

What is new in Basel II, is the view of operational risk management as a comprehensive practice, and as an inclusive discipline, comparable to the management of credit and market risk in principle, if not always in form. This new perspective on operational risk management brings along an integrated, positive, proactive, continuous, value-based, broadly focused attitude to operational risks.

The Board – a prime change agent

Basel II helps banks to take operational risk out of the backrooms and into the Boardroom to ensure maximization of the benefits for the business. It is important that the tone is set at the top. In many instances senior management must move from thinking about operational risk management as chiefly a potential compliance cost to considering the benefits of operational risk management as a continuous change process.

By envisioning, developing, deploying and sustaining operational risk management, firms aim to bring their actual operational “risk profile” in line with both their desired operational “risk appetite” and their available operational “risk bearing capacity”. Clear strategies and oversight by the Board and Senior Management, a strong operational risk culture and internal control culture (including amongst other things, clear lines of responsibility and segregation of duties), effective internal reporting and contingency planning are all crucial elements of an effective Basel II compliant operational risk management framework.

Medicine or healthy practice?

The new Accord will give smarter institutions advantages in pricing, funding and capital flexibility. Still, some banks are grappling with how to ensure that the considerable investment made in Basel II preparations can be made to yield a positive return. The upfront cost of complying with the new Accord and the effort required to stay compliant are substantial for all institutions. Moreover, it is clear that a Basel II operational risk management program needs to compete for resources with other international initiatives (e.g. IFRS conversion, Sarbanes-Oxley). Banks need to ensure that an integrated approach is adapted for the implementation of all such initiatives.

Where CEOs are directly concerned, operational risk management is good medicine: it tends to increase their confidence in their business operations. Business managers believe Basel II operational risk requirements present an opportunity rather than a compliance requirement. They value operational risk management as a healthy business practice, a day-to-day responsibility for everyone to gain efficiency and operational effectiveness, and to avoid big surprises. The regulatory (operational risk) capital incentives around Basel II and the sense of urgency in the implementation time-line make banks even more receptive for this change ahead.

Effective management

Many banks identify significant gaps between their current capabilities and the Basel II operational risk qualitative and quantitative criteria. Firms are considering how they can be more effective in managing the operational risks they face, including the risks due to increased reliance on technology (cyber incidents) and (homeland) security, whilst they must of course still find the time and resources to run their business profitably.

Several elements are essential to create a successful attitude to operational risk management. One is clearly articulated operational risk management goals, which provide a foundation for the Basel II operational risk management program and for related training and communication. A second is a common operational risk language, which is critical because it enables individuals throughout the organization to conduct meaningful cross-functional discussions about operational risk. A third element essential to the implementation is that everyone clearly understands the roles and responsibilities in the operational risk assessment and risk management framework.

To-do list

Corporate Governance

Operational risk management is a means, not an end in itself. Instrumental to enterprise risk management, operational risk management is a very important building block in an integrated approach to building trust, managing risk and creating value in the financial services market. Each bank’s system of corporate governance is compelled to improve. Checks and balances are being reinforced. From this, boards are emerging as prime agents of good governance. The changing attitudes to operational risk are inspired by the developments in corporate governance, Basel II and Sarbanes-Oxley, more than by anything else.

Exit mobile version