BIS国际清算银行-Operational-and-cyber-risks-in-the-financial-sector_39页_562kb
报告摘要
Summary of "Operational and Cyber Risks in the Financial Sector"
Core Content
This working paper by the Bank for International Settlements (BIS) explores the evolution and characteristics of operational and cyber risks in the financial sector, using a unique cross-country dataset of operational loss events. The study highlights the importance of understanding these risks for both banks and regulators, especially in light of the growing digital transformation and increased regulatory focus.
Main Views and Key Information
Operational Risk Trends
- Post-GFC Increase and Post-2015 Decline: After a spike following the Great Financial Crisis (GFC), operational risk losses in banks have been declining since 2015.
- Event Type Responsibility: The spike in losses was largely due to "Clients, Products & Business Practices" events, which include improper business practices such as fiduciary breaches, aggressive sales, and privacy violations.
- Time to Discovery and Recognition: On average, it takes 251 days from the occurrence to discovery of an operational loss event, and 184 days from discovery to recognition, resulting in an average time of 435 days from occurrence to recognition.
- Heterogeneity Across Regions and Event Types: There is significant variation in the time to discovery and recognition, with internal fraud and business practices events taking longer. North American banks are the fastest to discover losses, while banks in Eastern Europe are the slowest.
- Macro and Regulatory Impact: Operational losses are not independent of macroeconomic conditions and regulatory frameworks. Credit booms and periods of excessively accommodative monetary policy are followed by larger operational losses. Better regulation and supervision are associated with lower operational losses.
Value-at-Risk (VaR) Estimates
- Variability in VaR Estimates: Operational VaR estimates vary widely, ranging from 6% to 12% of total gross income, depending on the methodology used.
- AMA vs. SMA: The use of the Advanced Measurement Approach (AMA) results in lower VaR estimates compared to the Basic Indicator Approach (BIA), which uses a 15% benchmark. This supports the move towards the Standardised Measurement Approach (SMA) for regulatory purposes.
Cyber Risk
- Cyber Losses as Subset of Operational Risk: Cyber losses are a subset of operational losses and represent a relatively small fraction of total operational losses.
- Growing Attention: Despite their small share, cyber losses have seen a spike in recent years, reflecting increased regulatory and public concern.
- Cyber VaR: Cyber VaR can account for up to a third of total operational VaR, indicating its importance in risk management.
Data and Methodology
Data Sources
- ORX Database: The study uses a database of operational losses from ORX, a consortium of financial institutions that collects and shares anonymised data.
- Time Period: The data spans from 2002 to end-2017, with over 700,000 loss events reported by 74 large banks across different regions.
- Event Types and Business Lines: The dataset includes seven level 1 event types and nine business lines, with detailed categorisation of events. Level 2 event types are used for more granular analysis, particularly for identifying cyber-related events.
Additional Data
- Credit-to-GDP Gap: Used to proxy for the build-up of financial imbalances.
- Boone Indicator: Measures bank competition using the elasticity of profits to marginal costs.
- Taylor Rule Deviations: Used to assess the stance of monetary policy.
- Regulation Index: A composite index measuring the quality of regulation and supervision, based on seven dimensions including capital adequacy, independence of supervisory agencies, and coverage of financial institutions.
Stylised Facts
- Loss Frequency and Value: The frequency of operational loss events has shown a rising trend up to 2014, followed by a decline, suggesting the trend is not solely due to the growth of the consortium.
- Regional Distribution: North America and Western Europe account for the majority of operational losses, likely due to the presence of large global banks.
- Bank Size and Losses: Larger banks experience more variability in gross losses, while the frequency of events is relatively stable across bank sizes.
- Legal and Supervisory Delays: Legal proceedings and delayed recognition are key factors in the time lag between occurrence and recognition of losses, particularly in business practices and internal fraud events.
Conclusion
- Policy Implications: The findings on the duration of loss events can inform discussions on executive compensation and regulatory frameworks.
- Regulatory Focus: The paper supports the adoption of the Standardised Measurement Approach (SMA) for operational risk, as it reduces model heterogeneity and simplifies regulation.
- Emerging Risks: Cyber risks are an important emerging class of operational risk, with potential to significantly impact VaR estimates, especially in a digital financial environment.
Structure of the Paper
- Section I: Introduction and background on operational risk.
- Section II: Review of related literature.
- Section III: Description of the data used, including operational loss data and additional macroeconomic and regulatory data.
- Section IV: Analysis of operational VaR using different methodologies.
- Section V: Examination of the time lag between occurrence, discovery, and recognition of operational loss events.
- Section VI: Link between operational losses and macroeconomic conditions.
- Section VII: Estimation and analysis of cyber risk using the ORX dataset.
- Section VIII: Summary of main findings and policy implications.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载