Week 5 Flashcards
What is Incident Data Collection
gathering information about
incidents and events that may pose risks to the organization
Purpose of Incident Data Collection
create a comprehensive database that aids in risk assessment and management.
Importance of Incident Data Collection
identifying patterns, understanding root causes, improves risk management
Supports compliance with regulatory requirements
4 Incident Data Collection Methods
Automated Systems
Manual Reporting
Audits
Existing Sources
What existing sources can provide incident data
general ledger,
customer complaints,
IT logs,
legal provisions
4 Benefits of Comprehensive Data Collection
Trend Analysis
Risk Assessment
Compliance
Improvement
What is the Importance of Loss Reporting
Incident data collection
Data beyond regulation
Regulatory capital
Pillar 2 Compliance
BCBS Data Quality Requirements
What are BCBS Data Quality Requirements
Must maintain a 10-year history, a €20,000
threshold
What is a major driver of capital requirements under Basel regulations
Loss Data
what are Near Misses
Avoided losses by luck or accident outside of normal controls
Indirect vs. Direct Losses
Direct: Immediate financial consequences
Indirect: Resulting impacts - loss customers, reputational, compliance costs, lower morale.
What is Non-Financial Impacts Fallacy
That “non-financial impacts have real financial consequences
What is used to ensure consistency in
reporting the incident data
drop down menus
How to to avoid over-reporting incident data
Stick to essential core data fields
What does net loss reported show
net includes reimbursements
what does gross loss reported show
Total impact
What do loss reporting thresholds vary between
0-20k, must be justified
What Key Dates should be recorded to avoid discrepancies
discovery, occurrence, reporting, and accounting dates
Within what timeframe should material incidents be reported
2-5 days
Minor incidents reporting timeline
summarized periodically
How should severity be judged
Use potential impact, not just actual losses, Near misses and unintentional gains should be treated like actual losses
How is severity rated for ease
severity bands (e.g., >10k, >100k)
Steps of the incident data collection process
Reporting
Recording
Reviewing
Analyzing
Send reports
Who do incident data collection reports go to
management and regulatory bodies