When the three astronauts of Apollo 13 put their lives in the hands of the advanced technology of the NASA moon landing missions and things went wrong, a large dose of human intervention and ingenuity came to their rescue.
It just goes to show that while technology, and computing power in particular, has enabled mankind to achieve great things, there are limitations. Human skill and judgement cannot be eradicated from the mix.
The world’s financial community is still facing up to not heeding this lesson. All the processes were followed, the complex financial models on which the businesses relied to assess their risks may have been technically excellent, but two things went wrong:
- The assumptions underlying the models were wrong.
- The model outputs were believed with insufficient challenge.
Amid the fallout of his stewardship of the Royal Bank of Scotland (RBS), Sir Fred Goodwin observed: “At the heart of this I think there was an issue not about risk recognition but about how the risk was calibrated. They (traders) were holding positions in what we perceived to be triple-A securities and they turned out to be worth five or 10 cents in the dollar. The risk was recognised but, in the risk systems it was quantified as being very small: it turned out to be very large and it was wrong.”
Avoiding the Crutch of Technology
There have been many failures of technology over the years. But in many cases, this can be put down to unrealistic expectations and a failure to recognise the limits of technology – or indeed the additional risks it may pose.
All too often, people have a rather naïve faith in the power of technology. Take the case of the ‘unsinkable’ Titanic, which led to the risk of icebergs not being sufficiently recognised. And then fast-forward to the highly sophisticated risk models in today’s financial markets that made it both difficult and politically incorrect to challenge the outputs.
There are few things that are certain when it comes to risk, but one is that any attempt to quantify it will be wrong. It may be close enough to reality to provide a sound basis for decision-making or it may be a different ballpark altogether. But how do you tell? Risk management is a qualitative exercise that, if supported appropriately by the right data and information, can add real value to businesses and other organisations by improving decision-making. But it’s true that ‘what you can’t measure, you can’t manage’. For this reason, it makes absolute sense to put in place the best risk management technology you can, but it makes equal sense to recognise its limitations.
So, how can technology help risk management in business? There are four main areas where it has a role to play:
- Data collection and storage.
- Risk analysis and modelling.
- Risk monitoring and control.
- Risk information and communication.
The starting point is good data, and lots of it – enough to provide a sound statistical basis for effective decision-making. Collecting data requires good front-end systems, an effective systems and data architecture with limited human intervention, and good database and business intelligence technology.
But, it also needs people – the right type of people with the right culture, attitude and processes to capture and log the data accurately, and also to analyse the data effectively.
Business processes have to balance the ability to capture data effectively with what it is used for. Many companies operating call centres, for example, miss the opportunity to capture useful business intelligence by the pressure they place on operators to handle a certain volume of calls.
Data analysis can take many forms but actuarial techniques of stochastic modelling recognise that there is no single quantifiable answer to any risk. It is a combination of the probability of a risk occurring; the potential impact or impacts; and the mitigating effects of controls. At the extremes, any one risk or combination of risks, however seemingly unlikely, can bring a company down. Increases in computer power have meant that this type of modelling – often including hundreds of thousands of scenarios – is much more effective and efficient than it used to be and can be brought to bear more readily to assist business decision making.
Technology, and the access to information it affords, has also made it far easier to monitor an organisation’s continuing risks. It would be almost inconceivable for risk management to work effectively without the storage and processing capabilities of modern computers and the almost instant ability to communicate data-rich material around the globe. And computerised controls play an ever-increasing part in reducing risk.
Let’s be clear then. It’s no time to throw the baby out with the bath water. The banking industry’s risk models may not have predicted the near-global financial meltdown, but technology is an essential part of modern financial services risk management.
Regulatory Recognition
Nevertheless, the banking crisis had led some people to ask if the banking regulation (Basel II) and enterprise risk management (ERM) were misconceived: is it a failure of concept or of implementation? And was the failure one of technology or people?
Interestingly, the insurance industry’s version of Basel II – Solvency II – which is currently being debated by the European Parliament, attempts to reconcile and address some of these questions head-on. One of its provisions encourages the use of an ‘internal model’ to assess risk and to set solvency capital on the basis of that assessment. This is similar to an advanced approach for Basel II. However, there are two points to consider:
- The ‘internal model’ is much more than a calculation engine. It is the full system of assessing and quantifying risk, including governance, oversight and challenge to the financial model.
- The regulators will insist that, if the internal model is used to set the amount of solvency capital, the model should also be used heavily within the business for strategic decision-making. This is known as the ‘use test’. However, at the same time, they are insistent that there must not be over-reliance on the model and that there should be effective challenge to it.
Behavioural Impact
What we have to recognise, as the insurance industry appears to be doing, are the limitations of technology and its impact on human behaviour.
We can all already see this in how automated risk management touches upon our personal lives through technology such as CCTV cameras, speed cameras and speed limiters. Often this means there is less focus on human, ‘intelligent’ risk management. But to what extent does our reliance on technology drive behaviour?
The reality is that we often learn to understand how technology works and how to manipulate or avoid disadvantageous outcomes – for instance, slowing down for a speed camera. Therefore, the technology itself can change behaviours and potentially lead to riskier, unexpected outcomes. That certainly seems partially at the root of the current financial crisis. How much did the existence of complex financial models allow bank staff to absolve themselves of risk management responsibilities?
The author, Douglas Adams, had some thoughts on technology and behaviour when he said: “A common mistake that people make when trying to design something completely foolproof is to underestimate the ingenuity of complete fools.”
Not quite how we’d put it to a client, but a telling insight nonetheless. Technology can be very effective in managing risk – as long as it is treated as a tool rather than the panacea.