OCC published the Semiannual Risk Perspective for Fall 2019. The report covers risks facing national banks and federal savings associations based on data as of June 30, 2019. In this issue, operational, credit, and interest rate risks are among the key themes for the federal banking system. The report also highlights cyber-security and technology management as a special topic in emerging risks.
The report focuses on issues that pose threats to the financial institutions regulated by OCC. It report covers information on operating environment of banks, bank performance, special topics in emerging risks, trends in key risks, and supervisory actions to address issues. According to the report, financial performance of banks is sound, partly because of a favorable credit environment and the longest economic expansion in U.S. history. Asset quality is strong and stable while leverage and risk-based capital ratios are at record levels, providing strong loss-absorption capacity. The following are the key highlights from the report:
- Operational risk is elevated, as banks adapt to a changing and increasingly complex operating environment. Key drivers elevating operational risk include the need to adapt and evolve current technology systems for ongoing cyber-security threats.
- Credit risk accumulated in many portfolios. Banks should prepare for a cyclical change while credit performance remains strong. Preparation includes maintaining robust credit control functions, particularly credit review, problem-loan identification, and workout, collections and collateral management.
- Recent volatility in market rates led to increasing levels of interest rate risk. The complexity of asset-liability management is exacerbated by the recent yield curve inversions.
- The London Interbank Offered Rate (LIBOR) will likely cease to be an active index by the end of 2021. Accordingly, OCC is increasing regulatory oversight of this area to evaluate bank awareness and preparedness.
- Banks face strategic risks from non-depository financial institutions, use of innovative and evolving technology, and progressive data analysis capabilities.
The report highlights that cyber-security continues to be a key concern as breaches and operational outages occur across all industries, including the financial sector. Banks generally have appropriate controls for operational stability and protection of bank and customer data. Banks strengthened risk management processes and controls to address concerns. As a result, cyber-security-related issues have decreased and have remained relatively stable over recent quarters, reflecting increasing maturity of banks’ cyber-security programs. However, cyber-security remains a significant risk area for banks, with opportunities for further improvement.
In the special feature on cyber-security, OCC emphasizes that the cyber-security program of a bank should be part of an overall operational resilience framework. In addition to a well-documented and comprehensive incident response program, banks should consider partnering with the Financial Services Information Sharing and Analysis Center to share threat information and self-reporting incidents through the Federal Bureau of Investigation’s Internet Crime Complaint Center. Also, banks may be required to file Suspicious Activity Reports (SAR) with the Financial Crimes Enforcement Network for certain cyber events resulting in fraud. As institutions increasingly rely on third parties to help reduce costs and enhance technological capabilities, they should have processes to ensure that cyber-security controls are appropriate for the outsourced operations.
Keywords: Americas, US, Banking, Operational Risk, Credit Risk, Interest Rate Risk, LIBOR, Semiannual Risk Perspective, Cyber Risk, OCC
Previous ArticleFED Publishes Financial Stability Report in November 2019
The Australian Prudential Regulation Authority (APRA) released the final Prudential Practice Guide on management of climate change financial risks (CPG 229) for banks, insurers, and superannuation trustees.
The European Council adopted its position on two proposals that are part of the digital finance package adopted by the European Commission in September 2020, with one of the proposals involving the regulation on markets in crypto-assets (MiCA) and the other involving the Digital Operational Resilience Act (DORA).
The Prudential Regulation Authority (PRA) is proposing, via the consultation paper CP21/21, to apply group provisions in the Operational Resilience Part of the PRA Rulebook (relevant for the Capital Requirements Regulation or CRR firms) to holding companies.
The European Commission (EC) has adopted a package of measures related to the Capital Markets Union.
The European Banking Authority (EBA) published the final report on draft regulatory technical standards for the calculation of risk-weighted exposure amounts of collective investment undertakings or CIUs, in line with the Capital Requirements Regulation (CRR).
The Board of Governors of the Federal Reserve System (FED) published a report that summarizes banking conditions in the United States, along with the supervisory and regulatory activities of FED.
The Australian Prudential Regulation Authority (APRA) recently completed two pilot initiatives in its 2020-2024 Cyber Security Strategy, which was published in November 2020.
The Basel Committee on Banking Supervision (BCBS) published further information related to its 2021 assessment of global systemically important banks (G-SIBs), with additional details to help understand the scoring methodology.
The Financial Accounting Standards Board (FASB) is consulting on an Accounting Standards Update and the associated taxonomy improvements for requirements on troubled debt restructurings and vintage disclosures under the credit losses standard (for financial instruments) topic 326.
US Agencies issued a statement that summarizes the work undertaken during the interagency policy sprints focused on crypto-assets and provides a roadmap of future work related to crypto-assets.