Risk Management Headline Animator

Monday, September 14, 2009

Nature of 'Operational Risk'



Operational Risk as a process follows a cyclic fashion which revolves around risk identification, risk assessment, determining mitigating actions and setting controls to avoid or minimise the effect of the risk exposures arising out of the business operations. If we have to categorize risks in to two broad categories as ‘financial’ and ‘non-financial’, the loss can result due to human errors, external or internal events, the manner in which the systems or processes operate in a business. Operational risk covers all the above aspects of risk exposure. Does this mean that ‘Operational Risk Control’ is all that is required to save an organization or business from doom? The answer is ‘No’; it is certainly not the only process contributing towards risk management, as Market Risk & Credit Risk too has its due share. But the key differentiator between the other risk management process from that of Operational risk is the nature of its application in the business environment. To further simplify, there are pre-defined models to manage Credit / Market risks, whereas there is no specific model or application to bank on, as far as Operational risk is concerned. It is hence considered more dynamic in nature compared to other risk segments.



As represented in the pictographic representation of the Operational Risk Framework, the core of the Operations risk governance model of Assessing the risk exposures or incidents, placing controls, monitoring the performance of those controls and initiating necessary actions as required are carried out by scheduling appropriate set of processes, technology and of course the human resource. All the above comes together to ensure ‘Confidentiality’, ‘Integrity’ and ‘Availability’ of the assets of any organization.

Wednesday, September 2, 2009

Risk in Service Sector

Quality and timeliness with an optimum efficiency levels are the key factors affecting the delivery in service sectors. While this holds true even now, with the insertion of frequent market turmoil affecting the various line of services, many of which are linked to each other have turned the focus lights towards risk related considerations taken by the companies who strive to guard the interests of their existing customers, shareholders and employees on one end and to enhance their brand and goodwill to develop new clients.

The fashion in which Operations Management and Quality Management systems addresses the areas of improvement in the service delivery performance and customer delight, the processes and systems used to control and manage the various forms of risks like operational risks, credit risk, liquidity risk, market risk, IT risk etc., too have gained better momentum. Standards in the areas like information security, business continuity are changing the structure of operations models in the service sector.

Of all the service sectors, one industry which has been in the limelight for quite some time now and in fact, the industry which happens to respond most to this volatility in the market is the financial services industry. Based on the past experiences and future assumptions, it is expected that the financial markets will continue to experience some amount of volatility in the next few years. Even though various regulations like Basel II, Solvency II for insurers, UCITS 3 for Asset Managers and Sarbanes Oxley (SOX) for everything else are being prescribed, events wiping out major financial services giant like Lehman Brothers are promoting new sets of stringent regulations.


While it is very crucial from the risk management perspective to understand the appetite of the company to digest these new regulations and churn out positive outcomes for energising the overall financial system, it is more important to understand the gaps in the existing systems and regulations which resulted in such a large scale financial crises. Thus, finding realistic solutions which precisely lies in the basics of risk management needs to be looked afresh.

Sunday, August 30, 2009

Starting with Risk Management

The companies we work are huge, the processes we are involved are getting complex and demanding, not to mention the cut throat competition. One certainly gets the feeling if it is necessary to check/click on those checkboxes from the n number of checklists to ensure he / she has done their routine job? Of all the uncertainty prevailing around, is it necessary to add to ones paper work with those checklists popping in the table or screen?

The answers to all the questions above are ‘Yes’, it is absolutely necessary. It would be appropriate to say that a Risk would constitute of anything that can affect the performance of a product or service, all of which ultimately leads to financial or non-financial losses. If you dig deeper, all such effects roll’s up to the only constant factor in the world, viz., Uncertainty. This uncertainty is directly proportional to the risk exposures associated with a successful completion or achievement of any given task. What matters most is how prepared are we to face this uncertainty. Many might think that how can one possibly imagine the infinite probabilities in which a risk might arise. It is certainly not possible to track each such exposure, but being prepared to the best of our ability with the help of IT systems and of course logical thinking will certainly help us in withstanding the constant attack of risk on the process.

Even though several risk management standards have been developed, their definitions and goals differ widely based on the context and sector with which it is being associated. Members associated with project management, security, engineering, industrial processes, financial portfolios, actuarial assessments, or public health and safety use the risk management principles widely to prevent or minimise the impact of the losses resulting from risks. The various strategies to manage risk span from avoiding the risk, transferring the risk to another party, reducing the negative effect of the risk and also in some cases, accepting some or all of the consequences of a particular risk.

It is not a mathematical formula or a code of conduct which need to has a specific defined form. It is up to us to use all the available resources to manage risk in the most efficient manner. So lets get started…