BIS published a working paper that uses a unique cross-country dataset at the loss event level to document the evolution and characteristics of the operational risk of banks. The paper highlights that better supervision is associated with lower operational losses. It also provides an estimate of losses due to cyber events, which constitute a subset of operational loss events. Cyber losses are a small fraction of total operational losses, but can account for a significant share of total operational value-at-risk.
Representing a significant portion of total bank risks, operational risks are second only to credit risks as a source of losses. Thus, measuring and understanding operational risks, including cyber risks, is critical for both banks and public authorities. The paper uses a unique cross-country dataset from ORX, which is a consortium of financial institutions. The sample contains over 700,000 operational loss events from 2002 until the end of 2017 for a group of 74 large banks with headquarters worldwide. The granularity of the dataset allowed the authors to study the evolution of operational risks through time, compute an operational and cyber value-at-risk for financial intermediaries, document the time lag between occurrence, discovery and recognition of losses, and investigate the link between operational losses, macroeconomic conditions, and regulatory characteristics.
The results of the study show that, after a spike following the Great Financial Crisis, operational losses have fallen in recent years. The spike was largely due to losses arising from improper business practices in large banks that were incurred in the run-up to the crisis but recognized only later. Operational value-at-risk can vary substantially across banks—from 6% to 12% of total gross income—depending on the method used. These numbers are consistent with the actual capital requirements, but notably smaller than the basic indicator approach. The results provide some support for the shift to the standardized approach in Basel III.
The analysis shows that it takes, on average, more than a year for operational losses to be discovered and recognized in the books. However, there is significant variation across regions and event types. For instance, improper business practices and internal fraud events take longer to be discovered. Operational losses are not independent of macroeconomic conditions and regulatory characteristics. The paper shows that credit booms and periods of excessively accommodative monetary policy are followed by larger operational losses. Furthermore, it is to be noted that a higher quality of financial regulation and supervision is also associated with lower cyber losses. Despite representing a relatively minor share of operational losses, cyber losses can account for up to a third of total operational value-at-risk.
Keywords: International, Banking, Operational Risk, Value-at-Risk, Cyber Risk, Standardized Approach, Research, BIS
Previous ArticleISDA Updates List of Derivative Instruments Subject to Margin Rules
The European Commission (EC) published a report summarizing responses to the targeted consultation on the supervisory convergence and the single rulebook in the European Union (EU).
The Office of the Superintendent of Financial Institutions (OSFI) published an update on the discussion paper that intended to engage federally regulated financial institutions and other interested stakeholders in a dialog with OSFI, to proactively enhance and align assurance expectations over key regulatory returns.
The European Central Bank (ECB) published its opinion on a proposal for a regulation on European green bonds, following a request from the European Parliament.
The Advisory Scientific Committee (ASC) of the European Systemic Risk Board (ESRB) published a report that explores the expected impact of digitalization on provision of financial and banking services, and proposes policy measures to address the risks stemming from digitalization.
The European Banking Authority (EBA) announced that the guidelines on the reporting and disclosure of exposures subject to measures COVID-relief measures shall continue to apply until further notice.
The Swedish Financial Supervisory Authority (FI) announced that the capital adequacy reporting as at December 31, 2021 must be done by February 11, 2022.
The Central Bank of the Philippines (BSP) issued communications covering developments related to online lending platforms, open finance framework and roadmap, and on the expected regulations in the area sustainable finance.
The Board of Governors of the Federal Reserve System (FED) published the final rule that amends Regulation I to reduce the quarterly reporting burden for member banks by automating the application process for adjusting their subscriptions to the Federal Reserve Bank capital stock, except in the context of mergers.
The European Banking Authority (EBA) published its assessment of risks through the quarterly Risk Dashboard and the results of the Autumn edition of the Risk Assessment Questionnaire (RAQ).
The Malta Financial Services Authority (MFSA) updated the guidelines on supervisory reporting requirements under the reporting framework 3.0.