How to Use Artificial Intelligence to Calculate Operational Capital at Risk

Risk measurement techniques have been widely used by banking institution to determine the capital adequacy requirements in the Basel II accord. Under this accord, capital adequacy is calculated based on credit, market and operational risks. While the first two have been traditionally calculated using statistical techniques, there are several problems in applying these to operational risk, such as lack of adequate and accurate historical data and a moving target to calculate the various parameters required for operational risk.

Traditionally, several artificial intelligence (AI) techniques have found applications in the field of financial services. One of the areas where AI techniques can be applied is operational risk measurement. Neural networks and fuzzy modeling are two system paradigms that lie at extreme poles of artificial intelligence system modeling. Neural networks can be viewed as ‘black boxes’ in which the process is unknown but there are many examples or observations. Fuzzy models, on the other hand can be viewed as ‘white boxes’ in which structured human knowledge is used to model the system and no data is required.

Most of the real world problems, however, typically present a ‘grey box’ situation, where there are some observations and some structured human knowledge. A new technique called neuro-fuzzy modeling, which incorporates neural network learning concepts into fuzzy inference systems, forms a pivotal technique in what is today known as soft computing. A notable contribution was the development of the adaptive neuro fuzzy inference system (ANFIS) and its generalized version, CANFIS exploiting the equivalence of radial basis function networks (RBFNs) from neural network theory and various fuzzy inference system (FIS) models, to provide a performance superior to that of conventional neural networks and Fuzzy Inference systems.

The ANFIS model was chosen because compliance with some of the most stringent regulations under both AML and Basel II will have a large impact on systems infrastructure in almost all cases. It will require a bank to amass and process a considerable amount of historical data. Databases will have to be built and integrated with the bank’s processes, as data must be available to banks and their subsidiaries across all geographical locations. In most cases, such a large amount of data is unavailable and there is continuous pressure on banks to maintain the data integrity to ensure the capital adequacy. The ANFIS model will help in forecasting the capital adequacy in situations with a fluctuating KRI (key risk indicator), with the least data.

Need for Risk Analysis

The development of risk analysis and modeling has evolved rapidly over recent years
and there are two reasons for this. One is external, i.e. banking regulatory compliance, such as Basel II accord, and the other is internal, i.e. most banks are realizing that good risk management is a sound business practice. Risks in a banking operation can be categorized as credit risk, market risk and operational risk. Unlike Basel I, Basel II hinges on three Pillars – credit, market and operational which are mutually reinforcing. Basel II
provides three approaches: the basic indicator approach, the standardized approach, and the advanced measurement approach for calculating operational capital at risk in a continuum of increasing sophistication and risk sensitivity.

Unlike market and credit risk, which tend to be isolated in specific areas of the business, operational risks are inherent in all business processes. The concept is broader than operations or back office risk. Of all the different types of risks that can affect firms, operational risk can be among the most devastating and the most difficult to anticipate.

Risk Framework

In general, the risk framework consists of the following elements:

  • Risk identification and assessment: This is usually done through a risk and control self assessment (RCSA) program. Line of business (LOB) managers identify key processes, risks and controls in these processes, gaps and action plans to close the gaps.
  • Risk quantification and measurement: A quantitative framework is suggested, so operational risk can be measured accurately. Typically, exposure indicators, e.g. gross income, past losses, key risk drivers / indicators constitute the internal database. Availability and integrity of internal data as well as relevance and scalability of external data are important issues.
  • Risk analysis, monitor and reporting: Analysis contributes to the integration of risk and business performance, making risks transparent and identifying gaps.
  • Risk capital calculation: Operational capital at risk (CaR) – both regulatory and economic capital is calculated for every LOB to protect against unexpected losses at a
    certain time horizon and percentile.
  • Risk management and mitigation: This consists of sophisticated alternative risk financing and transfer arrangements.

Approaches for Operational Risk Measurement

While the simple basic indicator and standardized approach calculate the required capital based on certain percentages of annual income, the advanced measurement approach is based on a risk measure generated by a bank’s own internal operational risk measurement systems. It uses qualitative and quantitative criteria, to ensure that the internal risk management processes and regulatory requirement are addressed together i.e. economic and regulatory capital are allocated in tandem.

Techniques for Risk Measurement

According to Basel, “A capital charge for operational risk should cover unexpected
losses. Provision should cover expected losses”. The measurement of operational
risks along the different lines of business will enable the allocation of risk capital to be determined from historical loss information and/or scenario analysis.

Traditionally, several statistical techniques have been used for evaluating credit and market risk for Basel I compliance. The computations use maximum likelihood estimators to various types of distributions. The distributions are based on descriptive statistics and empirical evidence on observations of public and non- public loss events. Families of distributions often suggested are:

  • Frequency distributions – poisson, binomial and negative binomial.
  • Severity distributions – lognormal, Weibull, Gumbel, Pareto, etc.

Having selected the distribution, the available sets of data are used to estimate the model parameters on the basis of the opinion, by visual inspection or by applying ‘goodness of fit’ tests to existing data like Chisquare, Kolomogorov-Sirov tests. Once the distributions have been established, a capital at risk (CAR) model can be applied and results can be obtained. Currently, most groups use either real loss data, or scenario analysis for computation of operational risk. The model derives frequency and severity distributions, which drive the cumulative loss distribution (losses due to different risk types) for each line of business. Monte Carlo simulation is used to calculate the expected losses and the operational variable percentiles. A typical time horizon is one year. Other approaches to operational risk measurement include Bayesian modeling, extreme value theory and causal modeling.

The most obvious issue is that both credit risk and market risk exhibit similar properties. They are both characterized by the concept of risk exposure and both are subject to industry-wide standards for assessing and rating the probability of a loss event.

Operational risk does not exhibit these properties, largely because there is no systematic, consistent and industry- standard method for collecting and collating the data. Also the available data is sparse and is largely randomly subjective. In the case of market risk and credit risk, all the data is available in electronic form. Whereas in operational risk, each loss event could be the result of complex interaction between many causal factors, and a significant loss event can usually be analyzed in the alignment of many factors where the collection, collation and analysis of this data is almost impossible to fully automate. Also even if the data is available, identifying and calculating correlation between apparently independent factors is also a difficult issue. Also part of the problem is the context dependency of operational risk. Size of the loss and probability of the event differ considerably according to the circumstance of the event.

In addition, the business context, the nature of operational infrastructure and the threat scenarios change over time, in some cases quite quickly, and so historical data collected in one context may not be applicable in the current context. This brings to question the relevance of historical loss data i.e. context of the losses can change dramatically, which means that the size of potential losses and probability of them occurring is a continuously moving target. Therefore, an assumed loss distribution is not very useful in this context.

To ensure that the assessment of operational risk provides accurate models of both the size and probability of loss events and is relevant to business operations, it must be based on an up to date and accurate model of business processes than on abstract taxonomy of risk types.

The focus on business process analysis is more likely to provide insights into the complex interdependence of minor factors and may be a profitable method than the statistical models based on loss distributions.

In an operational environment, a financial institution supports business transactions and the operational risks are associated with failure of those transactions, either individually or in bulk. The ‘Value at Risk’ is related to volume of transactions being processed and the probability of transaction failure is related to number of standardized risk factors that characterize the transaction type.

The probability of failure for each line of business could be predicted by using a suitable AI model with various KRIs as the inputs and probability of failure as output. The ANFIS model offers a distinct advantage here because it is known to perform well in situations where there is limited data – one of the limitations which conventional statistical operational risk modeling techniques are faced with.

Various type of KRIs (like volume indicator, causal indicator and control effectiveness indicator) can be used as a model to the input. The model recommended is a ‘first order Sugeno model’. The ANFIS system has self-tuning capabilities for checking the optimal parameters of the model. The model can tune the system adequately (faster) and within a lesser degree of error (when applied to real world data) compared to traditional regression methods and isable to predict the probability of failure and hence value at risk. The error when compared against the actual data for probability of failure was 0.019 as against linear regression techniques, which is as high as 0.3 and also the tuning of the parameters were done with minimum number of epochs compared to regression techniques.

Conclusion

Considering the success that this model provides for operational risk, the same can also be extended for the calculation/simulation of systemic risk in pan-geographic payment system integration and for enterprise wide payment risk calculation.

Whitepapers & Resources

2021 Transaction Banking Services Survey
Banking

2021 Transaction Banking Services Survey

5y
CGI Transaction Banking Survey 2020

CGI Transaction Banking Survey 2020

6y
TIS Sanction Screening Survey Report
Payments

TIS Sanction Screening Survey Report

7y
Enhancing your strategic position: Digitalization in Treasury
Payments

Enhancing your strategic position: Digitalization in Treasury

7y
Netting: An Immersive Guide to Global Reconciliation

Netting: An Immersive Guide to Global Reconciliation

7y