Operational Risk Flashcards

(50 cards)

1
Q

Types of Risk in Regulatory Def

A

Internal fraud, external fraud, employment practices and workplace safety, business practices (client facing), damage to physical assets, business disruption and system failures, process management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Unofficial definition

A

Operation risk is everything that is not credit and market risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Risk management framework

A

A representation of actions, techniques or tools deployed to manage the risk of an entity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Four main activities of risk management

A

Risk identification, risk assessment, risk mitigation and risk monitoring.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Corollary definition of risk

A

Risk of impact due to event, caused by cause.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Exposure

A

The surface at risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Environment

A

This refers both to external and internal environments, which are controllable only to a certain extent.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Internal business environment

A

The organizational features of the firm, such as effective straight-through processing, competent staff and inspiring leaders.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Strategy

A

The most controllable part of risk causes. A major driver of exposure to operational risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Events

A

Risks turn into ‘events’ or ‘incidents’ when they become a reality rather than a possibility. An event is the materialization of a risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Preventative controls

A

Besides process design and sensible organization of tasks, internal controls are the main methods for risk reduction.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Corrective controls

A

Reaction once an incident occurs, early intervention and contingency planning.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Risk identification

A

Exposures and vulnerabilities, risk wheel, root causes of impact, past losses and near misses, process mapping interviews.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Risk assessment

A

Expected losses, RCSA, scenarios.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Risk mitigation

A

Internal controls & testing/bowtie analysis + preventative action plans.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Risk monitoring

A

KPI, KRI, risk reporting.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Examples of top down

A

Risks to strategy, emerging risks, global trends, major threats.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Examples of bottom up

A

Operational efficiency, organized processes, efficient systems, competent staff.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Types of Exposures

A

Key distribution channels, main clients, main suppliers and third parties, critical systems, regulatory exposure, main drivers of revenues, brand value.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Types of Vulnerabilities

A

Weakest links, fragile systems, revenue channels at risk, systems or processes not integrated, parts of the business resistant to risk management, unmonitored operations or people, unmaintained systems, BCP due for testing or updates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

The Risk Wheel

A

Governance, strategic objectives, reward & value, political & social, reputation & ethics, technology, project & change, regulation, legal liability, natural events, information, business continuity.

22
Q

Scenario analysis

A

The assessment and management of the exposure to high severity, low frequency events on the firm.

23
Q

Scenario analysis steps

A

Preparation and governance, generation and selection, assessment, validation, incorporation into management, scenario aggregation, incorporation into capital.

24
Q

Preparation documents

A

External loss data, internal loss data, RCSA results, key risk indicator scores, audit issues and other issue logs, concentrated exposures, relevant documents for risk and exposure assessment.

25
Internal fraud
Losses due to acts of a type intended to defraud, misappropriate property or circumvent regulations, the law or company policy, excluding diversity/discrimination events, which involve at least one internal party.
26
External fraud
Losses due to acts of a type intended to defraud, misappropriate property or circumvent the law, by a third party.
27
Employee practices and workplace safety
Losses arising from acts inconsistent with employment, health, or safety laws or agreements, from payment of personal injury claims or from diversity/discrimination events.
28
Clients' products & business practices
Losses arising from an unintentional or negligent failure to meet a professional obligation to specific clients (including fiduciary and suitability requirements) or from the nature or design of a product.
29
Damage to physical assets
Losses arising from loss or damage to physical assets from natural disaster or other events.
30
Execution, delivery, and process management
Losses from failed transaction processing or process management, from relations with trade counter-parties and vendors.
31
Basel definition of operational risk
The risk of loss resulting from inadequate or failed internal processes, people and systems or from external events.
32
Preventive
The aim is to reduce the likelihood of risks materializing by mitigating their possible causes.
33
Detective
This takes place during the event or soon after, with early detection helping to reduce impact. There is a preventive element if detection also identifies the cause of an incident.
34
Corrective
This reduces impacts caused by incidents. Damage is repaired or loss is compensated for by using backup and redundancies.
35
Directive
This comprises guidelines and procedures that structure the mode of operations to reduce risks.
36
Risk appetite
Qualitative statements, implicit risk/reward tradeoff, or pure risk avoidance at a cost, per risk category.
37
Risk tolerance
Metrics translating appetite, value at risk, indicators, budget.
38
Key controls
Internal controls and processes ensuring the respect of risk limits.
39
Risk limits
Key indicators and thresholds, allow monitoring, loss budget or incident tolerance.
40
Governance
What to do if limits are breached, risk owners and accountabilities.
41
KRI
Key Risk Indicator.
42
Top four KRIs
Aggressive profit growth targets, under-investment in infrastructure and people, regulatory negligence, top-level wishful risk appetite statements that are not consistently tied to actual controls and limits.
43
RCSA
Risk and Control Self-Assessment.
44
RAU
Risk Assessment Unit.
45
Assessment dimensions
Probability of occurrence, impact if occurring, velocity.
46
RSA
Residual risk self-assessment.
47
Key risks exposures
A view of the magnitude of impacts if key controls are missing or failing.
48
Four types of impact
Financial, regulatory, customer, reputation.
49
SMA
Standardized Management Approach.
50
IMA
Internal Modeling Approach.