Operational Risk Flashcards

1
Q

Types of Risk in Regulatory Def

A

Internal fraud, external fraud, employment practices and workplace safety, business practices (client facing), damage to physical assets, business disruption and system failures, process management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Unofficial definition

A

Operation risk is everything that is not credit and market risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Risk management framework

A

A representation of actions, techniques or tools deployed to manage the risk of an entity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Four main activities of risk management

A

Risk identification, risk assessment, risk mitigation and risk monitoring.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Corollary definition of risk

A

Risk of impact due to event, caused by cause.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Exposure

A

The surface at risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Environment

A

This refers both to external and internal environments, which are controllable only to a certain extent.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Internal business environment

A

The organizational features of the firm, such as effective straight-through processing, competent staff and inspiring leaders.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Strategy

A

The most controllable part of risk causes. A major driver of exposure to operational risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Events

A

Risks turn into ‘events’ or ‘incidents’ when they become a reality rather than a possibility. An event is the materialization of a risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Preventative controls

A

Besides process design and sensible organization of tasks, internal controls are the main methods for risk reduction.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Corrective controls

A

Reaction once an incident occurs, early intervention and contingency planning.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Risk identification

A

Exposures and vulnerabilities, risk wheel, root causes of impact, past losses and near misses, process mapping interviews.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Risk assessment

A

Expected losses, RCSA, scenarios.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Risk mitigation

A

Internal controls & testing/bowtie analysis + preventative action plans.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Risk monitoring

A

KPI, KRI, risk reporting.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Examples of top down

A

Risks to strategy, emerging risks, global trends, major threats.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Examples of bottom up

A

Operational efficiency, organized processes, efficient systems, competent staff.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Types of Exposures

A

Key distribution channels, main clients, main suppliers and third parties, critical systems, regulatory exposure, main drivers of revenues, brand value.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Types of Vulnerabilities

A

Weakest links, fragile systems, revenue channels at risk, systems or processes not integrated, parts of the business resistant to risk management, unmonitored operations or people, unmaintained systems, BCP due for testing or updates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

The Risk Wheel

A

Governance, strategic objectives, reward & value, political & social, reputation & ethics, technology, project & change, regulation, legal liability, natural events, information, business continuity.

22
Q

Scenario analysis

A

The assessment and management of the exposure to high severity, low frequency events on the firm.

23
Q

Scenario analysis steps

A

Preparation and governance, generation and selection, assessment, validation, incorporation into management, scenario aggregation, incorporation into capital.

24
Q

Preparation documents

A

External loss data, internal loss data, RCSA results, key risk indicator scores, audit issues and other issue logs, concentrated exposures, relevant documents for risk and exposure assessment.

25
Q

Internal fraud

A

Losses due to acts of a type intended to defraud, misappropriate property or circumvent regulations, the law or company policy, excluding diversity/discrimination events, which involve at least one internal party.

26
Q

External fraud

A

Losses due to acts of a type intended to defraud, misappropriate property or circumvent the law, by a third party.

27
Q

Employee practices and workplace safety

A

Losses arising from acts inconsistent with employment, health, or safety laws or agreements, from payment of personal injury claims or from diversity/discrimination events.

28
Q

Clients’ products & business practices

A

Losses arising from an unintentional or negligent failure to meet a professional obligation to specific clients (including fiduciary and suitability requirements) or from the nature or design of a product.

29
Q

Damage to physical assets

A

Losses arising from loss or damage to physical assets from natural disaster or other events.

30
Q

Execution, delivery, and process management

A

Losses from failed transaction processing or process management, from relations with trade counter-parties and vendors.

31
Q

Basel definition of operational risk

A

The risk of loss resulting from inadequate or failed internal processes, people and systems or from external events.

32
Q

Preventive

A

The aim is to reduce the likelihood of risks materializing by mitigating their possible causes.

33
Q

Detective

A

This takes place during the event or soon after, with early detection helping to reduce impact. There is a preventive element if detection also identifies the cause of an incident.

34
Q

Corrective

A

This reduces impacts caused by incidents. Damage is repaired or loss is compensated for by using backup and redundancies.

35
Q

Directive

A

This comprises guidelines and procedures that structure the mode of operations to reduce risks.

36
Q

Risk appetite

A

Qualitative statements, implicit risk/reward tradeoff, or pure risk avoidance at a cost, per risk category.

37
Q

Risk tolerance

A

Metrics translating appetite, value at risk, indicators, budget.

38
Q

Key controls

A

Internal controls and processes ensuring the respect of risk limits.

39
Q

Risk limits

A

Key indicators and thresholds, allow monitoring, loss budget or incident tolerance.

40
Q

Governance

A

What to do if limits are breached, risk owners and accountabilities.

41
Q

KRI

A

Key Risk Indicator.

42
Q

Top four KRIs

A

Aggressive profit growth targets, under-investment in infrastructure and people, regulatory negligence, top-level wishful risk appetite statements that are not consistently tied to actual controls and limits.

43
Q

RCSA

A

Risk and Control Self-Assessment.

44
Q

RAU

A

Risk Assessment Unit.

45
Q

Assessment dimensions

A

Probability of occurrence, impact if occurring, velocity.

46
Q

RSA

A

Residual risk self-assessment.

47
Q

Key risks exposures

A

A view of the magnitude of impacts if key controls are missing or failing.

48
Q

Four types of impact

A

Financial, regulatory, customer, reputation.

49
Q

SMA

A

Standardized Management Approach.

50
Q

IMA

A

Internal Modeling Approach.