Key Operational Risk Processes to Focus On
Operational risk, alongside credit risk and market risk, remains one of the three key pillars of enterprise risk management yet most organisations still don’t focus sufficient resource on addressing the potential pitfalls that operational risk management is meant to control. French economy minister, Christine Lagarde, recently urged banks to re-evaluate their operational risk management strategies when she said: “There is a risk, which is operational risk, as opposed to market risk, which must be taken more seriously into consideration.”
Although of increasing importance to financial institutions, operational risk remains the poor relation to its better-known counterparts. While the market has demonstrated that it remains essential to effectively manage all three pillars of enterprise risk management in order to best protect performance of financial services institutions, it has also been widely shown that lapses in any will negatively impact an organisation’s revenue, cost, profitability and reputation. However, aside from any compliance or regulatory mandate, the effective management of operational risk with a properly controlled approach is necessary in its own right simply for the performance of the organisation and must be baked into the very fabric of day-to-day operation and long-term planning.
Operational risk is largely linked to internal policies and procedures of a bank. It is built on transparency and communication. Indeed any organisation that still silos information cannot be said to have effective operation risk procedures. Operational risk management supports the organisation’s profit and loss (P&L) objectives but it also drives the concurrent requirement of regulatory compliance.
The performance of financial institutions has clearly been seen to have wider ripple effects in the overall market, e.g. sub-prime, mortgages, regulatory bodies have a vested interest in ensuring the stability of the financial sector. Indeed many of the most recent regulatory mandates followed well-publicised bankruptcies or internal control breakdowns and have been driven by a need to restore investor and client confidence. For example, Basel II includes the computation of operational risk which was not required under Basel I. Therefore the twin benefit angle emerges in that while operational risk management is key to market performance in its own right it also simultaneously will support an array of compliance mandates such as Sarbanes-Oxley (SOX), Basel II, Markets in Financial Instruments Directive (MiFID) and Solvency II.
As already mentioned, operational risk should be part of the fabric of a company’s day-to-day operations and long-term planning. There exists in an any organisation a cornerstone set of operational processes which are both essential to the financial health of the business and, because of their operational ubiquity, also traverse multiple compliance mandates simultaneously. These processes and systems can become cornerstones upon which both operational and compliance improvements can be built. These allow sponsors and managers to build wider return on investment (ROI) and business case support.
One such cornerstone process is reconciliation and exception management, which embeds controls that are critical foundation elements of any organisation’s operational risk management and financial control strategy. The pervasive nature of these requirements is evident when you consider their role in the various lines of business units as well as accounting and finance groups. For example, automation of reconciliation and exception management systems is often done to increase efficiency, focus on exceptions more quickly and minimise the cost of operations typically associated with the middle and back office. It also facilitates transparency, one of our operational risk goals, as it provides a more accurate view of information and value at risk across the enterprise in different locations.
Such a cornerstone process also provides compliance transparency. If you factor in the control activities, e.g. authorisations, verification, reconciliation totals and transactions and segregation of duties, it becomes clear that reconciliation and exception management processes extend across several compliance initiatives including SOX, Basel II and MiFID.
The figure below illustrates the far-reaching impact of reconciliation and exception management across various elements of enterprise risk management. Despite the clear overlap in compliance initiatives that map back to reconciliation processes and systems, traditionally, organisations engage in the fragmented approach of reviewing each initiative separately.
| Control Activities | Global System Under Review | SOX | Basel II | MiFID | COSO | COBIT |
|---|---|---|---|---|---|---|
| R001- Timely Review and reconciliation of Key Accounts and Transactions |
-Reconciliation and Exceptions Management -Account Certification |
?
|
?
|
?
|
?
|
|
| S001- Segregation of Duties Across Key Functions |
-Reconciliation and Exceptions Management -Workflow -Account Certification -AR/AP Systems |
?
|
?
|
?
|
?
|
|
| A001-Access Control to Key Systems Based on Job Function |
-Reconciliation and Exceptions Management -Workflow -Account Certification -AR/AP Systems |
?
|
?
|
?
|
Source:
CheckFree
Focusing on cornerstone processes can provide twin benefits in operational efficiency and improved internal controls but also yield the third benefit of risk mitigation. This three-pronged benefit is driven by the fact that cornerstone systems, such as reconciliation and exception management, will include the primary building blocks of any comprehensive risk and compliance management programme including:

Operational risk needs to be treated as integral part of the overall enterprise risk management strategy. Those that champion it and want to shepherd in change will often face a hard sell, even though the toughest critic must admit that the current labour intensive, fragmented approach isn’t sustainable in the long run.
The most effective way to create the catalyst for change is by implementing a phased approach that delivers verifiable outcomes based on a strategic focus. In other words taking small, directed steps that lead to obvious quick wins can smooth the path towards widespread adoption of converging risk management and compliance initiatives.
Process automation allows an organisation to apply and enforce standard procedures across various business functions. As a result, workflow tools play a key role in demonstrating control over critical activities and serve as the foundation for operational risk management strategies. According to Gartner: “The financial governance market will include applications that help the finance functions improve the timeliness and quality of financial management processes and reporting; facilitate audits; extend ERP transactional controls and improve financial risk management.”
When reviewing process automation systems, opportunities exist to identify and collectively evaluate business processes that are relevant across multiple governance, risk and compliance initiatives. Targeted process flows typically include exceptions handling, journal entries, revenue recognition, transaction auditing, applied segregation of duties and account certification approvals associated with the financial close process. By abandoning the myopic approach to business process review across all of these workflows, potential problems and improvements can be identified and simultaneously applied.
Fully documenting business processes was once a task left for outside consultants when a special business process engineering project was commissioned. Generally these types of projects were only executed when competitive pressures or cost cutting measures forced the hand of a given operational area. Forward thinking organisations are taking the opportunity to rise above the bare minimum approach and beginning to analyse information in order to uncover process improvements as well as opportunities for greater levels of automation.
There is significant pressure for financial institutions to focus on operational risk and enhance the effectiveness of their operational risk management strategies. This comes at a time when most organisations have already spent large sums on regulatory compliance initiatives with little return and are being battered by the turmoil in the global economic markets. There is a silver lining in the cloud that represents operational risk management and that benefit is associated with the fact that a properly implemented control framework in the middle and back offices will not only improve operational risk handling but deliver quantifiable ROI through the adoption of best practice execution and process automation. The road to achieving a holistic approach to operational risk management may be long but there are low risk, high value foundational components that all financial institutions should review now, as they consider and mature their overall enterprise risk management strategy.