10th September 2013
CEI Compliance: The FCA Are Focusing On Risk: Are You?
In the FCA Risk Outlook Document, there are numerous risks that the FCA will be concentrating on and expecting firms to take steps to address.
The FCARO states “Firms need to ensure they are putting the consumer and the integrity of markets at the heart of their business models and strategies. This includes making strategic cultural changes which promote good conduct, establishing oversight around the design and innovation of products and services; and ensuring they are transparent in their dealings with consumers.
Firms should look at their business model, strategy and structure to critically assess whether any of the drivers and forward looking risks apply to their own business and how they may play a role in dealing with these in a way that is fair to consumers, promotes effective competition and market integrity.”
At the heart of this “business model, strategy and structure” assessment is ensuring that the risks are identified, managed and monitored appropriately. This means having a robust Operational Risk Management System.
What is the scope of operational risk management (ORM)?
Operational risk is recognised as being distinct from market risk and credit or trade risk (although an operational failure may result in a loss of control and an increase in exposure). However, as the definition suggests, operational risk confines itself to managing those elements that fall within the business operational remit. They include:
- Process and procedural robustness and integrity
- People, skills and training
- Insurance and self-insurance
- The supply chain, outsourcing and inherited risk
- Infrastructure, systems and telecommunications
- Physical and information/data security.
What is the value of operational risk management?
Undoubtedly, you already manage your exposure to operational risk in a number of ways; you lock doors and windows at night, you encourage staff to access the firm's data securely, you run anti-virus software and so on. But most companies buy CCTV only after a break-in. They test their backups only after a system failed. They buy disaster recovery provision for computers only after being persuaded by a disaster recovery IT salesman, usually when it has happened to a peer organisation.
The result is usually a patchwork of overlapping and gap-ridden investments reflecting the legacy of past decisions. Rarely are the provisions matched to the organisation's actual needs and often it is left unwittingly exposed but feeling 'safe'.
There are many other good reasons for embarking on an ORM programme; some of the main drivers are as follows:
- The changing environment invites new risks and dilutes old ones
- Prospective customers expect risk management to be in place
- Business acquisition specialists require ORM results and history or will devalue accordingly
- The cost of even a brief period of downtime is now unacceptable
- Corporate governance is already under the audit spotlight by the regulators in most countries
ORM is a logical response to these requirements; it is:
- Systematic, ensuring all risks are identified and treated appropriately
- Repeatable, as part of a process that accommodates change
- Auditable, evidencing governance decisions
- Entirely at the discretion of the business; you choose to accept or mitigate a risk based entirely on the evidence placed before you.
How can we manage operational risk?
The key to ORM lies in the understanding and management of two important concepts - loss and probability.
Loss (or Severity or Impact)is defined in this context as:
"...any financial or otherwise unwelcome effect that impinges on a business stakeholder as a result of operational failure"
- Loss can include a wide range of both tangible and intangible components such as:
- Lost sales and missed trade opportunities
- Loss of market share and long-term revenue
- Fines, penalties, lawsuits and interest payments
- Eroded reputation, share price, brand value and image
- Loss of employment or directorship
- Reduced pay, compensation or benefits
- Excessive overtime
- Physical trauma, hospitalisation or death.
Probability (or Likelihood) is defined in this context as:
"...the qualitative or quantitative likelihood of a particular operational failure occurring"
This reflects the fact that most operational failures are rare and a precise statistical value cannot be readily obtained. This is therefore an area of subjectivity where we manage improvement rather than absolute value. For example:
- Earthquake damage to buildings occurs once in 100 years in the UK
- Theft of PCs occurs in one-in-ten businesses each year in the UK
- Computer viruses affect 60 percent of computer users each year globally.
Of course, neither loss nor probability exists in isolation and each is associated instead with specific failure events, for example:
"Server A” has a mean time between failures of 20,000 hours and a mean time to repair of 18 hours. If it fails we expect to suffer losses of £80,000 due to missed sales opportunities and increased staff costs." This measures our exposure to risk of “Server A” failing in this particular way. However, we must add the exposures due to other events such as:
- Theft
- Sabotage
- User error
- Power loss
and so on.
These are called 'threats', and are defined in this context as:
"...Unpredictable events arising from beyond present operational controls giving rise to failure mode(s) in process (es), person(s) or system(s)"
Different threats can give rise to a single failure mode e.g. a fire, an earthquake or an air accident may equally cause a building to be destroyed. Conversely, a single threat can generate failure modes in many assets e.g. a power surge may cause equipment to fail.
We can repeat this form of evaluation for any or all of the internal processes, people and systems that form the business and obtain an overall appraisal of exposure.
At this point, the potential enormity of the task should become apparent and you are, no doubt, asking some probing questions:
- We have how many assets...?
- There are how many threats to each and every one...?
- They overlap by how much...?
- How can we even begin to...?
DON'T WORRY!
We recognise the problem and provide rationalisation, appropriate actions and segregation or relevant apportionment; nonetheless, it is important that you understand risk before you begin to manage it.
Help Is Available
If you want to demonstrate your risk management system for reputation, insurance and regulatory needs, quickly manage all your operational risks, then CEI Compliance will help you install and run a system specifically designed for your business.
YOU DON’T NECESSARILY NEED TO PURCHASE EXPENSIVE SOFTWARE
We even provide and explain the suite of risk templates designed to help you provide a complete package of demonstrable results of risk assessments, then
Implementing our system will provide
- Support for strategic and business planning from top down and bottom up;
- reassurance for all stakeholders;
- helping focus the annual compliance monitoring programme;
- increase operational stability and potentially reduce your insurance premium and
- maintain your organisation's reputation and image!
Call us on 0800 689 9689 and quote PAN75
Not yet registered?
Please complete this form to join our community