Managing Operational Risk With Six Sigma
There is an opinion that operational risk as a standalone subject is not progressing and, to keep the stakeholders interested, risk practitioners are riding piggyback on programs such as Six Sigma. I don’t think anything could be further from the truth. Though operational risk management (ORM) is a challenge, it is an exciting subject area with depths that remain unexplored. It is also an evolving subject and, like any subjects in their infancy, it borrows heavily from other related disciplines. There is a growing conviction that Six Sigma can be successfully applied in the banking industry to manage operational risk, thereby reducing the cost and harnessing the synergies of an existing Six Sigma implementation. Going by the number of banks that are already using Six Sigma, a practical implementation approach to integrate ORM and Six Sigma will not only benefit the risk management practice but the banking industry as a whole.
Six Sigma is a rigorous and disciplined methodology that uses data and statistical analysis to measure and improve a company’s operational performance by identifying and eliminating ‘defects’ in processes. To achieve Six Sigma, a process must not produce more than 3.4 defects per million opportunities (DPMO). A defect in this context is defined as anything outside set specifications. In other words, they are the process variation that is calculated by sigma level. The objective of Six Sigma implementation is to reduce variation and drives towards six standard deviation between mean and the nearest specification limit (upper/lower specification) in any process. A Six Sigma opportunity is the total number of chances for a defect.

As the process sigma value increases to six, the process variation around the mean decreases. The target is to decrease process variation (variation is the square of process standard deviation) to increase sigma level. Process variation is reduced by implementation of various six sigma projects and improvement initiatives. This results in the process approaching zero defects and thus increasing quality, customer satisfaction, cost reduction and increased profit.
Operational risk as a concept is also centred on variation. It arises when there is variation from the expected state (value, mean, process – USL/LSL, error, defect, loss, etc.). Thus the standard deviation measures this risk as it captures the variation around the expected value. The higher the sigma level, the lesser the variation and risk. Therefore, increasing the sigma level of an organisation reduces operational risk.
However, implementation of Six Sigma and arriving at zero defect state does not eliminate operational risk completely as operational risk is a function of four risk categories: people risk, process risk, system risk, external risk.
Six Sigma can help to reduce and manage process and system risk whereas the other risk categories will still exist. Nevertheless, application of Six Sigma together
with its methodology and its tool set will help considerably to identify and manage risk .

Risk identification is one of the basic requirements of risk management. Though it is supposedly a basic and easy function, a complete identification of risk or the key risk is not an easy task. The identification process requires analysing the banking process in molecular details that require resource, time and expertise. Risk points and corresponding controls have to be identified to determine the risk being carried by the bank. The Six Sigma technique of process mapping (flow charts) can be used to analyse the processes in granular detail and identify gaps in the processes and the associated risks. The frequency of different types of losses and errors at different stages of the process can also be used to identify the risks.
Similarly, flowcharts and process diagram analysis can be used to identify the controls in various processes and systems across the bank. The defined phase of Six Sigma methodology can be used for risk identification.
Theoretically, operational risks arise when there is a variance from the expected state. Thus, variation is the proxy for operational risk. Operational risk (like other risk forms) is the standard deviation of the present state from the expected state. This state can be errors, losses, process gaps, etc. Therefore the higher the sigma level, the lower the variance. Implementing Six Sigma and increasing the sigma level will be a proxy to lower operational risk, which can also provide a measure of process related risk. The sigma level based on cycle time, transaction error, process defects and process breach can be a measure of operational risk existing in a bank.
The Six Sigma level of a bank, the business lines and the processes, can be a good proxy measure of risk. It cannot be a complete measure as it does not quantify risk. However, it can be a proxy for measuring the process and system risks of an organisation. When Six Sigma is implemented in an organisation with twin objectives or improved processes and also improved controls and reduced errors, the level of Six Sigma will indicate the robustness of the process or the weakness of the processes. A higher sigma level can be taken to indicate less risk and vice versa.
The proxy measure of risk can also be a good risk indicator for a bank, business line or process. The Six Sigma level of the unit can be used as a key risk indicator, which will effectively indicate the level of risk being carried by the unit.
The measurement and analysis phase of Six Sigma will help not only in measuring the risk in a process but also in prioritising the risks and the process for improvement.
The big benefit of Six Sigma is found in risk mitigation and management. The improvement and control phases of a Six Sigma implementation can effectively help manage risk. In this phase, the target process is improved by designing creative solutions to fix and prevent problems. Solutions are created using technology and discipline. The implementation plan is then developed and deployed.
For example, the improvement stage will involve development and implementation of internal controls within the process. Once the process is re-engineered to include the control aspects, the process is defined, measured, analysed and documented and it is then implemented and tested to check the effectiveness of the control measures.
Various Six Sigma techniques can be used during this exercise. These include brainstorming, mistake proofing, failures mode and effect analysis (FMEA), affinity diagram and root cause analysis, etc.
The control phase of implementation helps to control the improvements and to keep the process on the new course, without reverting back to the ‘old way’. This requires the development, documentation and implementation of an ongoing monitoring plan and to institutionalise the improvements through the modification of systems and structures (staffing, training and incentives).

Historically, risk management as a discipline was looked upon to highlight problem areas and control them rather than a way to improve process and products and bring tangible business benefits to banks. However, by applying Six Sigma in risk management there is a strong business case of not only reducing operational risk but also improving process and customer experiences. Six Sigma is a proven methodology for reducing errors and cycle time and improving quality that has tangible business value. Banks will benefit as a result of improvement in processes that increase savings and drives revenues. Banks will also be able to improve risk perception and, as a result, reduce capital requirement towards operational risk.
Though Six Sigma is a proven process improvement methodology, few banks have currently integrated their Six Sigma framework with their operational risk framework. The reason is that, even now, ORM is looked at more as risk identification, measurement (quantification) and provision of capital rather than a risk management, control and improvement process. The reason for such an approach is to do partly with the way ORM is organised, with operational risk managers being primarily responsible for awareness trainings, collecting and compiling information, and creating MIS reports rather than improving business processes where risks exist.
Another reason is the background of most risk managers, who come from either credit risk, market risk or audit. As a result, for most risk managers, loss reduction and thereby their contribution to ORM is limited to managing the relatively immaterial expected losses. This can lead to them missing larger unexpected losses that arise from defective processes.
The second challenge is that most banks are not implementing ORM at the molecular level. However, this should not be a challenge for banks that are already implementing Six Sigma. In such an organisation, the objective of projects have to be realigned to management of risk apart from improvement of process and quality.
The third challenge is that the current technologies and systems are not flexible enough to incorporate Six Sigma framework and metrices into their risk management programmes.
Despite the challenges, there is a strong case for using Six Sigma for managing operational risk in process and there could be a significant buy in from banks as the ORM matures.