Technology

December 7, 2010

Why does operational risk matter? (2)

By Peter Hill

Information in those dashboards and reports can be shared with business heads and line managers across the organisation. The information contained in those reports can be filtered using the facilities in our system so that branch mangers for example may see data that is specific to them and their branch, and not the equivalent data that is ‘owned’ by other branches.

It is possible to collect fraud data with out revealing how the fraud was constructed; that information should be considered by only those people who need to know in order that controls can be strengthened appropriately.

Causal analysis is a good way of learning from the experience of a loss event occurring. Linking the loss to the risk ensures the risk has already been identified, and linking the loss event to the failed control encourages action to re_assess the control for its design and effectiveness in preventing future loss events. The advantage of a web_based system is that all this can take place dynamically, across the organisation. People can update the system through a standard web browser.

Progress with action plans can be monitored through this system. It is always far easier to talk about the need to do something, to make some change in the organisation, but always far harder to take that action through to a proper conclusion.

And a powerful workflow engine brings alerts and approvals to the attention of various managers around the business, keeping them properly informed at all times of KRIs that have breached a threshold, a regulation that has changed that they should be aware of, a risk or control assessment that needs approval, or an action plan that is nearing its target completion date.

One system can bring all this knowledge in one place. It can tell you whether every part of the organisation has a Business Continuity Plan, and when it what last tested, or what it is doing about Information Security. It can tell you how many action plans were created in the last six months and how many are still outstanding. It can tell you the most significant causes of losses and what is being done to prevent their re_occurrence.

Is this an important investment for the future? Will it give the board of directors the confidence, and the evidence, that the bank is well-managed, at every level of the business and better positioned to tackle any risk scenario because these will have been examined in findings of a workshop already recorded in the system. Will it make meetings with the Central Bank a little easier because the Board can point out where every regulation is being applied, and who in the bank has attested it is being applied correctly?

And more importantly, will this mean your Bank can tangibly demonstrate it operates good practices and gain the confidence of its customers. Will this lead to a reduction in the cost of funds as well as a reduction in the number of losses?

Anecdotal evidence tells us that a good operational risk strategy does lead to a reduction in losses as banks learn lessons and take steps to improve controls. Increasing the number of controls may not reduce the risk, but just make processes more complex. Improving the quality of controls and making investments in staff training may be much better for the business in the long term.

Even in medium sized business, there can be a lot of data to collect, and manage. It is not difficult to collect data with spreadsheets but to manage this data? To compare risk assessments from one date with another date to see whether the organisation is really improving? To create reports showing bar charts with history to show trends is obviously possible, but with how much time and effort.

Operational risk data is much more valuable and important, even critical to a business, that it demands a web_based system so that everybody in the business can easily and quickly contribute and access this single repository of knowledge.  And as the old saying goes, ‘knowledge is power’.

lCONCLUDED.
Peter Hill is the Vice-President, Operational Risk and GRC at Oracle.