Oprisk Flashcards
Risk Capacity
level risk firm’s resources can tolerate / ability withstand worst case outcome of risk taking
Risk Appetite
expression of risk boundaries / desired level risk taking
Risk Appetite -
- eg of quantification
- escalation,
- link to loss expectation
eg. no appetite indiv losses above $x within 12mo.
Losses above $y reported to risk committee
Loss expectation is effectively its appetite -sb included in budget. Most fin institutions expect loss of 2% revenue annually to OpRisk
Risk Appetite zero eg
If appetite says zero appetite phone outages and had 30min outage lost $5k, and backup sys costs $60K, willing to invest?
Risk Culture
policing of risk appetite / incentives
Threshold for investigation
What op risk threshold triggers investigation (what mean, AUO?)
$10k? EB okay with this? Give them analysis
Requirements in Policy
-start with what are obligations? What do on top of that?
Communication tip
Policy approved -email to all staff -1 thing want you to remember we’ve changed threshold op risk events from 8K to 10K
Mtgs op risk
not say monthly discuss all incidents over 10K. What is obligation -put in policy and ensure it done e.g meet quarterly incidents >50K or 100K
Exceptions approved?
Yes no
Stress tests
must perform monthly, qtly, yrly
Process flows every area -ask 3 qs:
- Controls effective? 2. Proper reporting? 3. Risk part everything do
Incident reporting
if 29 events in year, 14 full op losses, ensure reports for each
3 lines alternatives:
- Initial control, 2. Challenge, 3. Assurance
Diagram op loss by category -% of total loss
- damage physical assets
- business disruption, sys fail
- internal fraud
- empl practices-workplace safety
- clients, products and bus practices
- external fraud
- exec delivery process mgmt