Home › Academy › Library › Revisions to the principles for the sound…
Synthesis note · Standard

Revisions to the principles for the sound management of operational risk

Basel Committee on Banking Supervision · 2021 · Standard · 23 pages · Intermediate

The document outlines the revisions made to the Principles for the Sound Management of Operational Risk, initially introduced by the Basel Committee in 2003 and revised in 2011. It highlights implementation gaps identified during a 2014 review and offers guidance to improve risk management, particularly in risk identification, change management, and governance. Additionally, it introduces a specific principle on…

General Information

This document, published in March 2021 by the Basel Committee on Banking Supervision, presents the revisions of the Principles for sound operational risk management. It is a 23-page international standard aimed at banks, covering governance, risk management environment, information technology, business continuity, disclosure, and the role of supervisors. These principles apply to all banks, with adaptation according to the nature, size, complexity, and risk profile of activities. The document incorporates lessons from the 2007-2009 financial crisis, Basel III regulatory developments, and new challenges related to operational resilience, notably against pandemics, cyberattacks, and natural disasters (p. 1-6).

Executive Summary

The document addresses the update of the Principles for sound operational risk management in banks, to improve the management of risks related to internal processes, people, systems, and external events. This revision responds to gaps identified in 2014, notably in risk identification and assessment, change management, implementation of the three lines of defense, board supervision, and risk communication. It introduces a specific principle for managing risks related to information and communication technologies (ICT), recognizing their growing importance. The document highlights the interconnection between operational risk management and operational resilience, aiming to reduce the frequency and impact of incidents. The main findings emphasize the need for strong governance, a clear risk culture driven by the board and management, and an integrated and documented operational risk management framework. Recommendations include adopting a proportionate approach according to bank size and complexity, formalizing responsibilities within the three lines of defense, implementing robust tools for risk identification, assessment, and monitoring, as well as developing business continuity plans and ICT risk management programs. The role of supervisors is strengthened to ensure banks’ compliance with these principles (p. 5-23).

Context and Objectives

The document updates the original Principles published in 2003 and revised in 2011, to incorporate lessons from the 2007-2009 financial crisis and the 2014 review which revealed deficiencies in implementation. The objective is to improve the effectiveness of operational risk management in banks, addressing gaps identified notably in risk identification and assessment tools, change management, governance, and risk communication. The scope covers operational risks as defined by the Basel framework, including legal risk but excluding strategic and reputational risks. The document also aims to strengthen consideration of information technology risks and operational resilience, in a context marked by increasing threats such as cyberattacks and pandemics. Limitations concern the adaptation of principles according to bank size, complexity, and risk profile (p. 5-6).

Summary of Key Points by Theme

Governance:

- The board of directors must establish a strong risk management culture, approve and periodically review the operational risk management framework (ORMF) and the risk appetite and tolerance statement. It must ensure dynamic oversight of processes and integration of operational risk into overall risk management. An ethics and conduct policy must be implemented and overseen by a dedicated committee (p. 9-13).

- Senior management is responsible for effective policy implementation, clear definition of responsibilities, coordination among the lines of defense, and adequate resourcing. It must ensure the CORF (operational risk management function) is sufficiently independent and has status equivalent to other risk functions (p. 13-14).

Three lines of defense:

- First line: management of operational units, responsible for identifying, assessing, and managing inherent risks, as well as monitoring residual risks.

- Second line: independent CORF, responsible for challenging the first line, developing policies, and ensuring training and risk culture.

- Third line: internal or external audit, providing independent review of framework effectiveness and controls (p. 7-9).

Risk identification and assessment:

- Various tools: event management, internal and external data collection, self-assessments, control monitoring, key risk indicators, scenario analyses, benchmarking.

- Importance of strong data governance, tool validation, and integration of results into strategy and pricing (p. 14-16).

Change management:

- Formalized processes to identify, manage, approve, and monitor changes, involving the three lines of defense.

- Assessment of inherent risks, controls, impacts on risk profile, and required resources before implementation (p. 16-17).

Monitoring and reporting:

- Regular, accurate, consistent, and actionable reports at all levels, including deviations from risk appetite and tolerance, emerging risks, significant events, and regulatory changes.

- Frequency adapted to context and ability to produce reports under normal and stress conditions (p. 17-18).

Controls and mitigation:

- Robust control environment including policies, processes, internal controls, mitigation strategies, and risk transfer (e.g., insurance).

- Importance of segregation of duties, conflict of interest monitoring, and appropriate use of technology.

- Management of outsourcing risks with due diligence procedures, clear contracts, monitoring, and contingency plans (p. 18-20).

ICT risk management:

- ICT risk management program aligned with the ORMF, including identification, mitigation, monitoring, and regular testing.

- Continuous monitoring, alignment of business, risk, and ICT strategies, and preparation for stress scenarios (p. 20-21).

Business continuity:

- Continuity plans linked to the ORMF, approved by the board, involving management and operational units.

- Forward-looking scenarios with impact analyses, activation thresholds, recovery objectives, and communication.

- Regular testing, training, and participation in tests with critical suppliers (p. 21-22).

Disclosure:

- Formal policy for disclosure of operational risk management and exposure information, adapted to bank size and complexity.

- Transparency on significant operational losses without compromising security or confidentiality (p. 22).

Role of supervisors:

- Regular evaluation of banks’ ORMFs, including all described components.

- Coordination among supervisors, possible use of external auditors.

- Follow-up on deficiencies and encouragement of continuous improvements (p. 22-23).

Main Findings and Lessons Learned

Findings:

- Several operational risk management principles were insufficiently implemented in 2014, notably risk identification, change management, responsibilities within the three lines of defense, board supervision, and risk communication (p. 5).

- ICT risk is a major source of operational risk previously insufficiently considered, justifying a dedicated principle (p. 5).

- Operational risk management is inseparable from operational resilience, aiming to reduce the frequency and impact of incidents (p. 6).

- The three lines of defense model is common practice but sometimes suffers from role confusion (p. 7).

Assumptions and interpretations:

- Full integration of the ORMF into overall risk management is essential for effective management (p. 10).

- A strong culture driven by the board and management reduces the likelihood and impact of operational events (p. 9).

- Combined use of various identification and assessment tools enables better understanding and management of risks (p. 14).

Uncertainties:

- Adaptation of principles according to bank size, complexity, and profile leaves room for interpretation on the required level of formalization (p. 6).

- The inherent subjectivity of some methods such as scenario analysis requires rigorous governance to ensure quality of results (p. 15).

- Rapid evolution of ICT risks and cyber threats requires regular updating of practices (p. 20).

Conclusions and Recommendations

The Committee recommends that banks:

- Establish and maintain a strong risk management culture, driven by the board of directors and senior management, with clear ethics policies and appropriate training (p. 9-10).

- Develop an integrated operational risk management framework, documented and adapted to their profile, including clear risk definitions, responsibilities, tools, thresholds, and review processes (p. 10-12).

- Implement the three lines of defense model with clearly defined roles, adequate resources, and effective independence of the CORF (p. 7-9).

- Use a comprehensive range of risk identification and assessment tools, including event management, self-assessments, indicators, scenario analyses, and benchmarking, with rigorous data governance (p. 14-16).

- Ensure formalized and monitored management of changes impacting operational risks (p. 16-17).

- Establish regular, accurate, and actionable monitoring and reporting processes, adapted to context and including alerts on threshold breaches (p. 17-18).

- Maintain a robust control environment, including segregation of duties, conflict of interest management, appropriate use of technologies, and rigorous management of outsourcing risks (p. 18-20).

- Develop a specific ICT risk management program aligned with the ORMF, including regular testing and stress scenario preparation (p. 20-21).

- Develop and test forward-looking business continuity plans, approved by the board and integrating critical dependencies (p. 21-22).

- Publicly disclose relevant information on their operational risk management and exposure, respecting confidentiality (p. 22).

- Cooperate with supervisors who must regularly assess their ORMF and ensure correction of identified deficiencies (p. 22-23).

Key takeaways

References

Year
2021
Type
Standard
Level
Intermediate
Licence
Attribution required
Original document
https://www.bis.org/bcbs/publ/d515.htm
Read the original document ← Back to the library

Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.