Featured Product

    BIS Paper Analyzes Operational and Cyber Risks in Financial Sector

    February 11, 2020

    BIS published a working paper that uses a unique cross-country dataset at the loss event level to document the evolution and characteristics of the operational risk of banks. The paper highlights that better supervision is associated with lower operational losses. It also provides an estimate of losses due to cyber events, which constitute a subset of operational loss events. Cyber losses are a small fraction of total operational losses, but can account for a significant share of total operational value-at-risk.

    Representing a significant portion of total bank risks, operational risks are second only to credit risks as a source of losses. Thus, measuring and understanding operational risks, including cyber risks, is critical for both banks and public authorities. The paper uses a unique cross-country dataset from ORX, which is a consortium of financial institutions. The sample contains over 700,000 operational loss events from 2002 until the end of 2017 for a group of 74 large banks with headquarters worldwide. The granularity of the dataset allowed the authors to study the evolution of operational risks through time, compute an operational and cyber value-at-risk for financial intermediaries, document the time lag between occurrence, discovery and recognition of losses, and investigate the link between operational losses, macroeconomic conditions, and regulatory characteristics.

    The results of the study show that, after a spike following the Great Financial Crisis, operational losses have fallen in recent years. The spike was largely due to losses arising from improper business practices in large banks that were incurred in the run-up to the crisis but recognized only later. Operational value-at-risk can vary substantially across banks—from 6% to 12% of total gross income—depending on the method used. These numbers are consistent with the actual capital requirements, but notably smaller than the basic indicator approach. The results provide some support for the shift to the standardized approach in Basel III.

    The analysis shows that it takes, on average, more than a year for operational losses to be discovered and recognized in the books. However, there is significant variation across regions and event types. For instance, improper business practices and internal fraud events take longer to be discovered. Operational losses are not independent of macroeconomic conditions and regulatory characteristics. The paper shows that credit booms and periods of excessively accommodative monetary policy are followed by larger operational losses. Furthermore, it is to be noted that a higher quality of financial regulation and supervision is also associated with lower cyber losses. Despite representing a relatively minor share of operational losses, cyber losses can account for up to a third of total operational value-at-risk.

     

    Related Links

    Keywords: International, Banking, Operational Risk, Value-at-Risk, Cyber Risk, Standardized Approach, Research, BIS

    Featured Experts
    Related Articles
    News

    APRA Penalizes Heritage Bank for Incorrect Reporting of Capital

    The Australian Prudential Regulation Authority (APRA) found that Heritage Bank Limited had incorrectly reported capital because of weaknesses in operational risk and compliance frameworks, although the bank did not breach minimum prudential capital ratios at any point and remains well-capitalized.

    November 29, 2021 WebPage Regulatory News
    News

    OSFI Releases Annual Report 2021-2022

    The Office of the Superintendent of Financial Institutions (OSFI) released the annual report for 2020-2021.

    November 29, 2021 WebPage Regulatory News
    News

    APRA Finalizes Capital Adequacy Standards for Banks

    The Australian Prudential Regulation Authority (APRA) published, along with a summary of its response to the consultation feedback, an information paper that summarizes the finalized capital framework that is in line with the internationally agreed Basel III requirements for banks.

    November 29, 2021 WebPage Regulatory News
    News

    CPMI-IOSCO Seek Comments on Access to Central Clearing and Portability

    The Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) issued a consultative report focusing on access to central counterparty (CCP) clearing and client-position portability.

    November 29, 2021 WebPage Regulatory News
    News

    APRA Finalizes Guidance on Management of Climate Change Risks

    The Australian Prudential Regulation Authority (APRA) released the final Prudential Practice Guide on management of climate change financial risks (CPG 229) for banks, insurers, and superannuation trustees.

    November 26, 2021 WebPage Regulatory News
    News

    EBA Publishes Single Rulebook Q&A Updates in November 2021

    The European Banking Authority (EBA) Single Rulebook Question and Answer (Q&A) tool updates for this month include answers to 10 questions.

    November 26, 2021 WebPage Regulatory News
    News

    EC Finalizes Rules on Internal Approaches Benchmarking Exercise

    The European Commission, or EC, finalized the Implementing Regulation 2021/2017 with respect to the benchmark portfolios, reporting templates, and reporting instructions for the supervisory benchmarking of internal approaches for calculating own funds requirements.

    November 26, 2021 WebPage Regulatory News
    News

    EC Proposes New Measures Under Capital Markets Union Package

    The European Commission (EC) has adopted a package of measures related to the Capital Markets Union.

    November 25, 2021 WebPage Regulatory News
    News

    European Council Adopts Position on Digital Finance Package Proposals

    The European Council adopted its position on two proposals that are part of the digital finance package adopted by the European Commission in September 2020, with one of the proposals involving the regulation on markets in crypto-assets (MiCA) and the other involving the Digital Operational Resilience Act (DORA).

    November 25, 2021 WebPage Regulatory News
    News

    PRA Proposes Rulebook Changes; BoE Extends BEEDS Testing Window

    The Prudential Regulation Authority (PRA) is proposing, via the consultation paper CP21/21, to apply group provisions in the Operational Resilience Part of the PRA Rulebook (relevant for the Capital Requirements Regulation or CRR firms) to holding companies.

    November 25, 2021 WebPage Regulatory News
    RESULTS 1 - 10 OF 7740