Risk Knows No Boundaries [RMA Journal, The]
| By Holmquist, Eric | |
| Proquest LLC |
ANYONE WHO HAS worked in banking for any length of time is all too aware of the acute challenges in breaking down the operational silos that inhibit communication, collaboration, and-ultimately-effective risk management. This is one reason why risk management evolved as a discipline in the first place: to develop frameworks for awareness, accountability, and actionability for various types of risks.
But as the discipline has evolved into systems for managing discrete types of risk (principally credit, market, and operational risks), we have ended up with the greatest of ironies. In the process of creating systems to break down silos, we created whole new silos.
The tragicomedy aspect aside, the fact is that a number of fairly material risks dangle awkwardly between the worlds of credit risk and operational risk, often leading to ambiguity about who should own the risk and how it should be classified, monitored, and managed. This ambiguity has been further complicated by the language of
For the benefit of context, it is worth at least considering several types of risk and how they could, or should, be classified. If we have to start somewhere, it would be fair to say that things like credit policy, borrower performance, and certain market conditions fit fairly neatly within true credit risk. These affect both the framework in which lending is allowed to take place and the external factors that impact the credit environment. On the other hand, areas such as loan boarding and servicing systems and process represent specific operational risks.
But what are we to do with things like policy exceptions? Faulty underwriting models? Misinterpreted analytics? Are these representative of credit risk or operational risk? The reality is that they are both. While it would be fair to say that, for the most part, credit risk involves the who, what, when, where, and why of lending, and operational risk is mostly about the how, in reality it is never that neat. It's not so much that you can't draw a line; it's just that there's really not much point in doing it.
Simply put, we need dynamic systems that ensure risks are identified, assessed, and actively managed by risk managers from within both disciplines. These risks are inextricably linked, and even the process of classifying them can create its own set of risks (not the least of which is, "But I thought they owned that risk"). Ultimately, it's a business risk-so manage it. In fact, a bank's ability to successfully manage the boundary between credit risk and operational risk is directly correlated to its ability to get past its operational silos.
When it comes to boundary issues, there are some fairly common trouble spots, including the following:
* Models.
* Policies.
* Roles and responsibilities.
* Siloed operations.
* Automated systems.
* Change management.
* Analytics and reporting.
The remainder of this article addresses these and other areas and outlines some proactive strategies for more actively managing boundary issues and creating a more balanced, holistic approach to managing credit and operational risks.
Awareness
Let's start by considering opportunities for increasing awareness, the first principle of risk management. Going back to my #1 rule of operational risk-people can only manage the risks that they understand-one of the best ways to improve awareness is by improving documentation.
One incredibly effective tool for identifying boundary issues is end-to-end process maps. Face it, these are difficult to produce, require massive collaboration, have little perceived value, and are outdated 24 hours after they are produced. But they are, in fact, pure gold when it comes to identifying not only subtle process steps, but some of the underlying assumptions built into those processes. As an example, a good end-to-end process map would have gone a long way toward identifying some of the vendor management issues associated with the recent loan foreclosure documentation failures.
To continue, no automated system should ever be allowed to go into production without complete documentation, including use, logic, assumptions, error states, owners, and so on. An undocumented system, no matter how simple, can only create risk-and sometimes a substantial amount of it. The documentation should be reviewed and approved by both credit and operational stakeholders.
Finally, under documentation, ensure that roles and responsibilities are exceedingly well defined. This may seem incredibly obvious, but it's amazing how many operations have key processes that involve people whose roles are assumed or undocumented. The bottom line for documentation in all of the above areas: If it isn't written down, you don't get credit. Period.
The next area within better awareness is to increase operational transparency. This means cross-functional risk assessments and scenario analysis. In other words, when analyzing and assessing the embedded risk within a given process, both the credit and operational professionals can weigh in. No analysis is ever complete without input from both sides of the house.
That said, one point to remember is that credit risk and operational risk differ in many ways, but one key way is in the number and types of stakeholders. Credit risk tends to be largely influenced by a very small number of subject-matter experts, notably the chief credit officer. Almost everyone else can violate credit policy, but they don't have the ability to set policy (in other words, set risk tolerance). Operational risk, on the other hand, is influenced by many stakeholders throughout the organization, each with subject-matter expertise within his or her own operating unit. This difference is significant, and it can have a profound influence in decisions on who needs to be in the conversation when assessing risk.
And finally, the last area around operational transparency involves the transfer of risk. Say, for example, a system has shortcomings that allow customer service agents to place account codes outside of their authority, creating repeated credit policy violations. Implementing a system change to restrict codes to a user's profile does not eliminate the risk; it only transfers it to a pure operational risk. Are the profiles maintained accurately and is the system functioning correctly? The managers of both credit risk and operational risk need to be aware of this transfer of risk and ensure that it is owned and managed.
When it comes to operational transparency, the simple saying goes, "Leave your ego at the door." These are everybody's risks. The goal is to build collaboration, communication, and a mutual appreciation for corporate risk, regardless of how it is classified. Awareness breeds appreciation, and appreciation breeds cooperation.
Accountability
Risk management is, at its core, about accountability, and nowhere is this truer than when considering boundary risks.
The fabric of accountability is woven from the tone at the top. Simply put, if the executives talk in silos, the staff will work in silos. It's always been this way and always will be. But it's a fact that the chief credit officer has a responsibility to own and understand operational risk, and process and division heads have a responsibility to own and understand credit risk. These responsibilities cannot and should not be separated. Similarly, it is imperative that risk ownership, in either world, not be assigned to committees. Committees aren't accountable; only people are. Sadly, too many people hide behind committees.
At the end of the day, it is critical that people remember that everyone is striving for the same goal: profits. Any conversation that devolves down to "my risk" or "his risk" can only pull an organization further away from that goal.
The next area of accountability is in quality control process. Simply put, quality control functions must be seen as a secondary, not a primary, control. The phrase, "It's okay, they'll catch it in QC," should never be heard. So who in the organization is testing for compliance with credit policy? Who owns metrics on operational performance (on originations, servicing, etc.)? Who is viewing failure rates? Internal risk ratings? These are operational risks, but with credit implications. Therefore, they have, by default, multiple stakeholders.
Next under accountability is what I call locker inspection. Pencils down, step back. The area where this is most needed is with automated models, whether they are spreadsheets or database applications. Model risk remains one of most underexamined areas of operational risk in banking. When it comes to automated tools that are used to make business decisions, the following rule must apply: All models must be documented and then tested at least annually. No exceptions.
The litmus testing is this: Do you have a current inventory of all models currently supporting business decisions? Is each one documented in terms of what it is used for? Who uses it? What are the assumptions built into it? What data goes in (and is it any good)? What data comes out? What formulas are used? And, finally, how often are those models tested? The answers I hear all too often are "Sort of," "No," and "Um, no." That's the moment when everyone looks around the room awkwardly. It's not good risk management.
The final area under the area of accountability involves change management. Remember, the seeds of risk are sown in change and then watered by how we execute. When it comes to managing change, this is where cross-functional input is simply critical. It means input and involvement from both credit and operational staff when considering a range of changes, including those to policy, systems, vendors, acquisitions, and product offerings. Each area brings a unique perspective and needs to have input into those changes.
The organization also needs to understand that all risk assessments are built as of a certain point in time and are based on a set of assumptions. The minute something changes (sometimes even the smallest change), those assumptions may no longer hold true and a new risk assessment is in order. But it takes the input and experience of both disciplines to analyze and assess the impact of change. The first question that every technical support representative is trained to ask when something goes wrong is, "What changed?"
Actionability
The last area after awareness and accountability in managing boundary issues is the ability to take action when things go wrong-and they always do. In this case, culture is the key. Does the organization allow people to discuss failure openly, with an emphasis on what happened, what they need to do about it, and (most importantly) what they learned from it? If the focus remains on who did it, people will not be cooperative in the response process. This problem is exacerbated if there are clear lines between risk types, and instead of focusing on process improvement, you end up in a blame game. This is not good risk management.
In many organizations, actionability is a difficult area because too many old-school managers in the senior ranks still feel that the correct response is to find someone to figuratively execute. This is a very bad idea. Fear will never, ever promote transparency and the ability for quick response. Sometimes risk management is not about risk avoidance but damage mitigation, and that works only if you're all playing on the same team.
To summarize, everything starts with culture and tone. Any hints of an "us against them" attitude need to be addressed proactively. Learn from each other. Gain an appreciation of each other's pain points. The more I understand and appreciate your risks, the more I can own them as well. (And, honestly, this happens more at a ballgame than in a boardroom.)
It's worth repeating: Awareness breeds appreciation, and appreciation breeds accountability. Document everything and test, test, test. Transparency is a very, very good thing. Remember, a rope of three braids is so much stronger than three separate ropes. It's a risk-so manage it.
It is critical that people remember that everyone is striving for the same goal: profits. Any conversation that devolves down to "my risk" or "his risk" can only pull an organization further away from that goal.
The minute something changes (sometimes even the smallest change), those assumptions may no longer hold true and a new risk assessment is in order.
It's a risk-so manage it.
| Copyright: | (c) 2011 Robert Morris Associates |
| Wordcount: | 2097 |


Advisor News
- Americans aren’t turning retirement plans into action, LIMRA finds
- Ashley Hinson ‘death tax’ story collides with truth
- How advisors can prepare clients for an uncertain retirement landscape
- Investors aren’t waiting out uncertainty
- Transamerica and Advo(k)ate Advisors launch pooled employer plan
More Advisor NewsAnnuity News
- Investigation finds deceptive sales, churning of annuities targeting postal workers
- Corebridge annuity sales slip ahead of Equitable marriage
- California teachers settle class-action lawsuit over in-plan annuity fees
- Jackson Financial CEO caps 40-year career with blockbuster Q2
- Lumos Insurance introduces the Immediate Care Plan to help families fund long-term care
More Annuity NewsHealth/Employee Benefits News
- Commissioner rejects proposed rate increase from Fallon Community Health Plan, re-negotiated seven proposals to save $72 million for 670,000 residents
- Medicaid insurers' contracts on line in tight Iowa governor's race
- Ashley Hinson unveils insurance transparency bill amid scrutiny of record
- California nearly achieved universal healthcare. Now, millions are losing coverage
- Oregon poised to adopt double-digit health insurance premium hikes in 2027
More Health/Employee Benefits NewsLife Insurance News
- Indiana eyes more oversight of insurance companies' exposure to private credit
- HEALEY-DRISCOLL ADMINISTRATION RETURNS $14.5 MILLION TO HEALTH AND DENTAL INSURANCE CONSUMERS AND BUSINESSES
- ‘Uniquely positioned’: Equitable outlines future post-Corebridge merger
- Don't keep checks with clerical errors
- The insurance distributor that builds its own software will win the next decade
More Life Insurance News