Thursday, 8 February 2024

The Governance of Risk Management

Corporate Governance

  • Corporate Governance refers to the processes established to operate a business, including the roles and responsibilities of shareholders, senior managers, and the board of directors.
  • This discipline evolved from a vague principle to a series of well-defined best practices during the rise of corporate governance failures such as Enron in 2001 and WorldCom in 2002. 
  • SOX - Sarbanes-Oxley Act
    • These major frauds were discovered let to SOX - Sarbanes-Oxley Act in 2002, this led the regulators to strengthen internal controls and strict financial reporting and auditing parameters on public companies.
    • CFO and CEOs must personally verify and certify the accuracy of the financial statements of the firm.
    • CFO and CEOS must attest all the disclosures provided are accurate.
    • Any internal control deficiencies or failures must be reported accurately to investors and regulators.
    • The firm's reporting procedures and internal controls must be audited annually.
    • Audit committee member names must be disclosed publicly and must have :
      • audit experience professionals
      • able to understand accounting principles
      • able to comprehend financial statements
    • Less crimes would occur due to strict internal controls.
  • 2007-2009 Financial Crisis
    • Several risk management failures.
    • Too many securitised mortgage products were linked to subprime (high-risk and low-borrower-quality) loans.
    • Stakeholder priority
      • Diverse set of stakeholders makes risk management challenging.
    • Board composition
      • Showed no difference in outcome whether board directors were internal or external stakeholders.
    • Board risk oversight
      • Reactive to risk management rather proactive.
    • Risk appetite
      • Board did not clearly articulate and communicate the firm's risk appetite to stakeholders which should be translated into an enterprise risk system.
    • Compensation
      • Board did not exercise control over management compensation regimes to not incentivize underised risk-taking behaviour.
      • Ideally the compensation structures using deferred bonus payments and clawback provisions should be considered.
  • Dodd-Frank Act
    • Before the Dodd-Frank Act Before 1999 banks operated under the Glass-Steagall Act which prohibited commercial banks from operating investment banking divisions in the same firm, the core idea was to protect depositors from trading volatility.
    • The Graham-Leach-Bliley Act introduced in 1999 removed this barrier and permitted bank holding companies to reform as financial services holding companies(FSHCs).
    • After the 2007 financial crisis, the Dodd-Frank Act addressed several issues related to financial consumer protection and market stability.
    • Seven key elements:
      • Strengthen the FED - The Federal Reserve Bank
        • FED became more powerful
        • Need to oversight all the Systemically Important Financial Institutions - SIFIs with assets greater than $50 billion.
      • Ending too big to fail
        • Ended the too-big-to-fail theory and created orderly liquidation authority to deal with the failure of large financial institutions.
      • Resolution plan
        • All SIFIs need to provide a living will, stating the plan to survive during the event of distress.
      • Derivatives market
        • Created transparency in derivatives markets via clearing exchange and reducing counterparty risk.
      • The Volker Rule
        • Re-impose some of Glass-Steagall by prohibiting banks from engaging in proprietary trading where trading with the banks' money. Reassuring banks are not allowed to trade with consumers' money.
      • Consumer protection
        • Created the Consumer Financial Protection Bureau to regulate consumer-facing financial products.
      • Stress testing
        • Robust and dynamic stress testing must include a top-down approach incorporating macroeconomic shocks and their impact on several risk types.
        • This stress testing must be incorporated into the bank's liquidation planning process and the outcome must be evaluated at the bank and economic levels.
        • Two stresses performed by FED
          • Assets above $10 billion - Dodd-Frank Act Stress Test -DFAST
          • Assets above $50 billion - Comprehensive Capital Analysis and Review -CCAR
  • BCBS - Basel Committee on Banking Supervision
    • This organization is comprised of banking regulators from 27 jurisdictions.
    • Series of standards were devised, although they are not legally binding but do present sound risk management best practices for files willing to apply the guidance.
    • Basel I
      • In 1988 post-Latin American debt crisis created a uniform approach to bank capital adequacy standards.
      • Focused on managing credit risk by recommending minimum capital of 8% of a bank's risk-weighted assets.
    • Basel II
      • In 2006 replaced Basel I, here included both trading and lending activities in capital adequacy standards. 
      • Also imposed disclosure suggestions and standards for bank supervision by regulators.
    • Basel III
      • Post-financial crisis of 2007-2009, created system factors for handling both company-specific (idiosyncratic) risk and market-level (systematic) risk.
      • Limits Tier I capital which is the core measure of a bank's strength to include common equity and related earnings (reserves of the bank).
      • Imposes a LCR - Liquidity coverage ratio, where banks must hold enough highly liquid assets to fund 30-day's worth of cash needs.
      • A net stable funding ratio to encourage banks to have at least one year's worth of stable cash flow to fund required operations.
      • Macroprudential overlay (one bank failing other banks) to lessen systematic risk and procyclicality. This overlay consists of 5 elements:
        • A leverage ratio - Tier I capital/total consolidated assets cap of 3%.
        • CCCR - A countercyclical capital buffer/requirement.
        • Global systemically important banks (G-SIBs) have implementation of minimum total loss-absorbing capital (TLAC) standards.
          • TLAC standards are designed to ensure that G-SIBs have sufficient loss-absorbing capital to withstand financial stress and maintain their critical functions without requiring taxpayer bailouts or causing disruptions to the wider financial system. 
          • TLAC consists of a combination of equity, long-term debt, and other instruments that can be used to absorb losses in the event of a bank's failure.
        • Risk modelling and stress testing modified to better capture tail risks and minimize counterparty risk
    • Revised Guidelines in 2015 by BCBS to make better Basel III
      • The guidelines are for banking sector risk management making BOD responsible for risk management.
      1. Responsibility of the board of directors: 
        • Oversee senior management implementation of the firm's risk appetite strategic objectives and governance framework.
      2. Board composition
        • All board members should be qualified, topical knowledge and skillsets for their supervisory responsibility and to execute their duties.
      3. Policies of the board
        • The board should establish policies strategically for their own operations to reinforce their objectives.
      4. Senior management
        • Should conduct the day-to-day business operations and implement risk management as per the policy approved by the board.
      5. Governance for a conglomerate
        • Conglomerate is a combination of several businesses, often structured like a parent and several child firms.
        • The board of the parent firm needs to have ultimate oversight over the operations of all the members of the conglomerate.
      6. Risk management function
        • Should always be an independent risk management function that reports to the board under the daily supervision of a CRO.
      7. Risk identification, monitoring and control
        • Oversee risk mapping (identification)
        • Once identified need to direct if the risk needs to be retained, avoided, mitigated or transferred.
        • Incumbent is the process of monitoring dynamic risk on an ongoing basis.
      8. Risk communication
        • Effective communication about the firm's risk appetite to all levels of the firm.
      9. Compliance
        • Oversee compliance risk management.
      10. Internal audit
        • Perform periodic audits to inform the board of the firm's progress on risk management.
      11. Compensation
        • Board should organize and supervise the firm's compensation structure such that management is held financially accountable for risk decision-making.
      12. Disclosure
        • Firm's risk management process should be adequately disclosed to stakeholders.
    • Revised Guidelines in 2016 by BCBS to make better Basel III
      • Expanded to include the FRTB - Fundamentals Review of the Trading Book.
      • Intended to broaden the inclusion of market risk exposures.
      • Risk management through a bank's trading desks in banks engage in various activities involving derivatives, futures, currencies, indices, and other complex financial assets, which introduce several types of risks.


Risk Governance Implementation

Risk Advisory Director

  • In terms of risk governance, risk advisory directed is the specialized role of risk management and separate duties.
  • Recommended to have an independent risk advisory director(industry expert who understands risk factors very well) when the board of directors come from various backgrounds.
  • Risk Advisory Directors build the bridge between the board of directors and senior management.
  • Role involves educating members on the best practices in both corporate governance and risk management.
  • With or without the assistance of a risk advisory directory, the board's duties include the review and analysis of the following:
    • The firm's risk management process
    • The firm's periodic risk management reports
    • The firm's risk appetite and its impact on business strategy
    • The firm's internal controls
    • The firm's financial statements and disclosures
    • The firm's related parties and related party transactions
    • Any audit reports from internal or external audits
    • Corporate governance best practices for the industry
    • Risk management practices of competitors and the industry

Risk Management Committee

  • Risk management committee which is a subset of the full board of directors, and is responsible for setting the firm's risk appetite.
  • Independently monitor ongoing risk management.
  • Members will maintain contact with both internal and external auditors to ensure compliance with all relevant policies, (e.g., regulations and internal risk limits).
  • Approving credit facilities that are above certain limits or within limits but above a specific threshold.

Compensation Committee

  • Independent of management.
    • The Compensation Committee typically consists of independent directors who do not have any material relationship with the company or its executives. 
    • This independence ensures objectivity in decision-making and helps prevent conflicts of interest.
  • To ensure appropriate risk-taking concerning the Long-term risks assumed.
    • While short-term performance is important, remuneration structures should also consider long-term sustainable growth. 
    • Including a mix of short-term and long-term incentives, such as stock options or equity-based awards, can encourage a focus on both immediate results and the company's future prospects.
  • Discuss and approve the remuneration of key management personnel.
    • Incorporating performance-based incentives ensures that remuneration is tied to the achievement of specific goals and targets. 
    • This helps align the interests of key management personnel with those of shareholders and encourages a focus on value creation and operational excellence.
  • Clawback 
    • Remuneration decisions should be mindful of potential risks, such as excessive risk-taking or short-termism, that may arise from incentive structures. 
    • Implementing appropriate risk controls and clawback provisions can help mitigate these risks and promote responsible behaviour among key management personnel.
  • Bonus bonds
    • A bond that only pays a benefit if certain thresholds are met.
    • In simple terms, "bonus bonds" used as compensation might be subject to regulatory restrictions designed to ensure banks maintain certain levels of stability and financial health. 
    • If these regulations are breached, the distribution of such bonds might be restricted or halted. 
    • Let's unpack this with a straightforward example to illustrate how such a scenario might occur:  
      • Scenario: 
        • Bonus Bonds as Part of Compensation Packages Imagine a bank decides to offer special bonds, let's call them "bonus bonds," to its employees as part of their compensation package. 
        • These bonds might be an additional perk, providing employees with a potential return if the bank performs well.  
        • Regulatory Capital Ratios 
          • Banks are required to maintain certain levels of capital relative to their risk—their regulatory capital ratios. 
          • These ratios are critical safeguards implemented by financial regulators to ensure that banks have enough buffer to absorb losses and protect depositors' money. 
        • Breach of Regulatory Requirements 
          • Suppose the bank faces significant financial losses due to a downturn in the economy. 
          • As a result, the bank’s capital levels begin to fall close to or below the minimum requirement set by the regulators (known as the capital adequacy ratio).  
        • Supervisory Intervention 
          • In such a case, regulators would scrutinize the bank's practices, including compensation schemes involving "bonus bonds." 
          • If regulators determine that issuing these bonds could further jeopardize the bank's capital position (i.e., reduce the bank’s capital even more because these bonds might be counted as liabilities or require cash reserves), they may prohibit or limit the distribution of these bonds. 
          • The rationale is to conserve the bank's capital to ensure it remains stable and capable of covering its risks and obligations.  
      • Layman’s Term Example: Think of it like a family budget scenario:  
        • The family (bank) has a rule to always maintain a savings buffer of $1,000 for emergencies. 
        • They also have a practice of giving special gift coupons (bonus bonds) to family members as rewards. 
        • However, the family faces unexpected expenses (financial losses) and their savings are down to $1,100. 
        • The rule (regulatory requirement) says, if savings fall below $1,000, no more spending on extras until they replenish their buffer. 
        • Therefore, the family decides to stop issuing the coupons to ensure they don’t risk dipping below their necessary savings level. 
        • This simplified example mirrors how bonus bonds might be restricted to ensure the bank remains financially healthy and compliant with regulatory capital requirements.

Audit Committee

  • Audit committee a subcommittee of the full board, is responsible for the accuracy of financial statements and its regulatory reporting requirements.
  • Responsible for the firm's risk management process, ensuring the board-established policies are followed and that those policies are sufficient to adequately monitor and control risk exposures.
  • Oversee internal auditors, and they are responsible for the below:
    • monitoring risk management procedures
    • tracking the progress of existing systems
    • affirming the efficacy of the existing policies/systems
    • verify adherence to compliance standards
    • validate calculated risk metrics
    • validate any pricing models
    • offer opinion on the assumption used in internal risk estimation
  • Audit committee is largely meant to be independent of management, but it should work with management and communicate frequently to ensure that any issues arising are addressed and resolved.


Interdependence of Functional Units

  • For risk management and reporting various functional units are dependent on each other.
  • Risk committee
    • Oversees the firm's risk management process.
  • CRO
    • Monitors day-to-day limits.
    • It is the frontline managers and employees who implement the firm's risk policy.
    • Responsible for day-to-day risk supervision.
    • Approve temporary breaches of communicated risk limits as long as the enterprise-level risk limits are still within the board-established tolerance bands.
    • CRO liaison between the board and senior management. 
  • Senior management 
    • With supervision of the risk committee sets the firm's risk appetite. 
    • Design and oversee risk policy and evaluate performance relative to risk limits.
  • Business unit level
    • Risk policy is implemented
  • Finance and operations functions 
    • Physically execute the risk mitigation and transfer transaction.
    • Analyze current risk management tools to ensure the risk limits are maintained.
    • Help in the risk and business planning process.
  • Risk management
    • Led by CRO.
    • Monitors risk limits and controls.
    • Manage risk management process.
    • Regular communications with senior management and risk committee.


Corporate Governance vs. Risk Management

  • Corporate governance and risk management are interrelated concepts that are crucial for a well-functioning organization. Here's a breakdown of their distinctions and how they work together:
  • Corporate Governance:
    • Corporate governance establishes the principles and structures that guide how a company is directed and controlled. It defines the roles and responsibilities of the board of directors, management, and shareholders.
      • Promote transparency and accountability
      • Protect shareholder interests
      • Ensure compliance with laws and regulations
      • Foster ethical business practices
    • Key elements:
      • Board of directors: Provides strategic oversight, appoints management, and monitors risk management practices.
      • Management: Implements the company's strategy, manages day-to-day operations, and executes risk management plans.
      • Internal controls: A system of policies, procedures, and safeguards to ensure accurate financial reporting, operational efficiency, and regulation adherence.
      • Compliance: Adherence to relevant laws, regulations, and industry standards.
    • Best practices:
      • Board of directors should have sufficient knowledge of the firm's business and industry to make and approve management decisions independently.
      • Agency risk, in corporate governance arises from a fundamental conflict of interests between two key parties:
        • Principals: These are the owners of the company, typically represented by shareholders. Their primary interest lies in maximizing the value of their investment, which translates to increasing the company's profitability and stock price.
        • Agents: These are the managers or executives entrusted with running the company on behalf of the shareholders. While they should act in the best interests of the company and its shareholders, their motivations might not always perfectly align with those of the principals.
        • How Agency Risk Creates Problems:
          • Self-dealing: Managers might prioritize their own interests over the company's by taking actions that benefit them personally, such as excessive compensation packages or pursuing risky ventures that could jeopardize the company's financial health.
          • Shirking and moral hazard: Managers might not exert the necessary effort to manage the company effectively, or they might engage in risky behaviour knowing they are somewhat insulated from the consequences (moral hazard). This can lead to inefficiencies and decreased profitability.
          • Horizon problem: Managers might focus on short-term goals and financial performance to meet quarterly earnings expectations, even if it comes at the expense of long-term growth and shareholder value.
        • Consequences of Agency Risk:
          • Reduced profitability and shareholder value: If managers don't prioritize the company's best interests, it can lead to inefficiencies, missed opportunities, and ultimately, lower profits and reduced shareholder returns.
          • Loss of investor confidence: If shareholders perceive a high level of agency risk, they might be less willing to invest in the company, potentially hindering its ability to raise capital and grow.
          • Regulatory scrutiny and potential legal issues: Excessive agency risk can attract unwanted regulatory attention and potentially lead to legal repercussions for the company and its management.
        • Mitigating Agency Risk:
          • Corporate governance practices aim to establish a framework that aligns the interests of managers with those of shareholders and reduces agency risk. Here are some key mechanisms:
            • Strong Board of Directors: An independent and competent board can provide oversight of management and hold them accountable for their actions.
            • Clear Performance Measures: Establishing clear and measurable performance metrics that align with long-term shareholder value can help guide management decisions.
            • Compensation Plans: Structuring executive compensation packages to reward performance that benefits shareholders, such as stock options or performance-based bonuses, can incentivize managers to act in the best interests of the company.
        • Transparency and Disclosure: Regular and transparent communication with shareholders about the company's performance and strategy helps to build trust and reduce information asymmetry.
        • Shareholder activism: Shareholders can use their voting rights and engage with management to advocate for practices that promote long-term value creation.
      • Roles of the CEO and the chairperson of the board are two different people and should be separate and independent for stakeholder protection.
  • Risk Management:
    • Risk management is the process of identifying, assessing, and mitigating potential risks that could threaten the company's objectives. It involves developing strategies to minimize the impact of these risks.
      • Identify and analyze potential threats to the organization
      • Assess the likelihood and potential impact of these risks
      • Develop strategies to avoid, reduce, transfer, or accept risks
      • Implement controls and monitoring procedures to manage risks effectively
    • Key elements:
      • Risk identification: Proactive search for potential threats to the organization's financial performance, reputation, or operations.
      • Risk assessment: Evaluating the likelihood and severity of identified risks.
      • Risk mitigation: Developing strategies to address risks, such as implementing controls, acquiring insurance, or diversifying investments.
      • Risk monitoring: Continuously monitoring risks and updating risk management strategies as needed.
    • Best practices:
      • Communicate risk appetite enterprise level clearly.
      • Determine known risks needed to be retained, avoided, mitigated or transferred.
      • Establish and maintain a CRO role reporting to the CEO but retains full access to the board.
      • Establish a risk committee who are knowledgeable of the risks faced by the firm.
      • Connect the work of the compensation committee with the firm's risk appetite and the work of the risk committee.
      • Maintain an independent audit committee that can monitor relevant actions.
  • How They Work Together:
    • Corporate governance provides the framework for effective risk management. The board of directors sets the risk tolerance for the organization and ensures a robust risk management system is in place.
    • Risk management informs decision-making within corporate governance. By identifying and analyzing potential risks, risk management helps the board and management make informed decisions about the company's strategy, resource allocation, and overall direction.
    • Effective communication between these two functions is critical. The risk management team needs to communicate potential risks and mitigation strategies clearly to the board and management.
  • Here's an analogy:
    • Think of a company as a ship navigating a sea full of potential hazards (icebergs, storms, etc.). Corporate governance establishes the course, crew roles, and navigation tools (maps, compass). Risk management identifies potential hazards on the route, assesses their threat level, and recommends strategies to avoid or navigate them safely (detours, increased vigilance, lifeboats).
  • Corporate governance sets the stage for good decision-making, while risk management provides the vital information and tools to navigate potential threats and ensure the company's long-term success.


Risk Appetite vs. Business Strategy

  • There must be consistency between the firm's risk appetite and its business strategy.
    • If the firm's strategic goal is to make profitable loans, then the risk limits will impose credit risk parameters.
    • If the firm's strategic goal is smooth operations, needs to address operational risks or foreign currency risks.
  • Risk appetite and business strategy are two critical components of an organization's approach to risk management and decision-making, but they serve distinct purposes:
  • Risk Appetite
    • Definition: Risk appetite refers to the level of risk that an organization is willing to accept or tolerate in pursuit of its objectives. It represents the amount and type of risk that the organization considers acceptable in achieving its strategic goals.
    • Scope: Risk appetite applies across the entire organization and encompasses various types of risks, including strategic, financial, operational, compliance, and reputational risks.
    • Establishment: Risk appetite is typically defined and articulated by the organization's board of directors or senior management in consultation with key stakeholders. It reflects the organization's risk tolerance, risk appetite statement, risk appetite framework, and risk appetite metrics.
    • Alignment: Risk appetite should align with the organization's mission, vision, values, and overall risk culture. It provides guidance to decision-makers at all levels regarding the acceptable level of risk-taking in pursuit of organizational objectives.
    • Monitoring and Reporting: Risk appetite is monitored and reported on regularly to assess adherence to established risk thresholds, identify emerging risks, and inform strategic decision-making.
  • Business Strategy:
    • Definition: Business strategy outlines the organization's overall approach to achieving its objectives, including its goals, priorities, initiatives, and resource allocation decisions. It defines how the organization plans to create value, differentiate itself from competitors, and sustain long-term success.
    • Scope: Business strategy focuses on defining the direction and scope of the organization's activities, including market positioning, product development, geographic expansion, mergers and acquisitions, and other strategic initiatives.
    • Development: Business strategy is developed by senior management in collaboration with key stakeholders, taking into account internal capabilities, market dynamics, competitive landscape, customer needs, and other relevant factors.
    • Alignment: Business strategy should be aligned with the organization's mission, vision, values, and risk appetite. It considers risk factors and uncertainties inherent in the business environment and seeks to capitalize on opportunities while managing and mitigating potential risks.
    • Execution and Performance Measurement: Business strategy is executed through operational plans, projects, and initiatives, and performance is measured against predefined strategic objectives, key performance indicators (KPIs), and financial targets.
  • While risk appetite provides overarching guidance on the level of risk that an organization is willing to accept, business strategy defines the direction and priorities for achieving organizational objectives. Both risk appetite and business strategy are integral to effective risk management and decision-making, and they should be aligned to ensure that risk-taking activities support the organization's strategic goals and long-term success.


Credits and References

  • https://media.licdn.com/dms/image/D5612AQFm_1l6-JLwTg/article-cover_image-shrink_720_1280/0/1693782550842?e=2147483647&v=beta&t=4oMK7yPqbZfLSudw-_6sMH5HFkedpP3EyURSy-0rSgE
  • FRM 2023 Notes
  • Chapter 3
  • https://chatgpt.com/
  • https://gemini.google.com/

Thursday, 23 November 2023

Enterprise Risk Management and Future Trends.

ERM Introduction

  • Risk management is the process of identifying, assessing, and prioritising potential risks and taking actions to mitigate or avoid them. There are two ways to handle this situation:
  • Traditional
    • Silo Based: 
      • Risk assessment, management and mitigation will be performed separately for each division within the firm.
    • Advantages:
      • Adequate in a less volatile market environment.
    • Disadvantages:
      • Ignores the dynamic nature of risks and their interdependencies.
      • Costly overhedging of risks at the firm level.
      • Different risk measurement methodologies and formats across units may result in fragmented information for senior management and the board.
      • Risk management decisions are often made independently, without a comprehensive and strategic approach to enterprise-wide risk.
  • Modern
    • ERM
      • Risk assessment, management and mitigation will be performed in an integrated and centralized framework for the firm.
      • It's essential to keep in mind that risks are interconnected, and one type of risk can have a ripple effect on other areas of the company. However, when risks are evaluated from a company-wide perspective, they can sometimes offset each other. Therefore, it's crucial to consider risks holistically to create a robust risk management strategy.
    • Advantages:
      • Optimizing the total cost of risk expenses is better managed by avoiding overhedging and scaling various risks in a single umbrella (credit, regulatory, market, and so on).
      • Understand the correlation risks between specific risk types and the crossover risks where one risk creates additional risks.
      • Serves as a foundation for incorporating risk into business model selection and strategic decision-making, helping banks achieve their objectives while managing risks effectively.
      • Helps risk managers define risk appetite to the entire company and can put constraints on enterprise-level risk.
      • Managers and the board of directors can focus on the largest risk faced by the firm and not focus on day-to-day business divisions.
      • Identifies threats to the entire operation that arise from individual business lines.
      • Manage emerging risks such as cyber threats, reputation risks and anti-money laundering (AML) risks at the enterprise level.
      • Regulatory compliance.
      • Reassure stakeholders, stockholders and debtholders. 
      • Saving capital by incorporating stress testing into pricing and decision-making.
    • Disadvantages:
      • Limited foresight, might struggle to predict entirely new or unforeseen risks, especially those arising from rapid technological advancements or significant economic shifts.
      • The effectiveness of ERM can be challenging to measure quantitatively.
  • Silo-Based Risk Management VS ERM
    • Visualization
Credits: https://analystprep.com/study-notes/wp-content/uploads/2020/01/Enterprise_Risk_Management_ERM-1536x1273.jpg
    • Silo-Based
      1. Managing risks within the line of business
      2. Isolated risk managers
      3. Multiple risk metrics that cannot be compared
      4. Difficult to see enterprise-wide risk
      5. Hedging risk with specific risk transfer tools
      6. Risk management and risk transfer are not integrated with balance sheet management and financing strategies
    • ERM
      1. Risk managers review all business lines, functional areas, and risk types for diversification and concentration to avoid overhandling costs.
      2. Integrated risk managers and a chief risk officer.
      3. Integrated risk metrics can be compared.
      4. Aggregate risk across business lines and potentially across types of risk.
      5. Could lead to potential cost savings.
      6. Risk management is integrated with the bank's capital management strategy, balance sheet management strategy, and financing strategies.


Scenario Analysis and Stress Testing

  • Definitions
    • Sensitivity Analysis involves in changing one variable at a time to assess the impact on the model. The resulting impact is the net income for that variable.
    • Scenario Analysis examines multiple variables to understand their impact and the developing narrative to explain why they changed and their effects.
      • Advantages:
        • The frequency of a risk occurrence is not as important as its plausibility.
        • Scenarios can be intuitive and transparent.
        • Firms should anticipate the worst-case scenario and evaluate its potential consequences.
        • Helps firms focus on key risk types and their exposures.
        • Firms can see potential warning signals and develop contingency plans to manage risk events.
        • Scenarios can be created either by imagining hypothetical events or by using historical data.
        • Scenarios analysis is utilized to establish the firm's risk appetite, define risk limits, and inform capital adequacy planning.
      • Disadvantages
        • Probabilities of the adverse events are difficult to estimate.
        • Scenario analysis cannot quantify risk because it is qualitative.
        • It is possible to underestimate the occurrence of possible events and the potential impact they may have.
        • It is important to develop the right scenario, as only a limited number can be fully developed.
        • Most scenarios are based on past crises, not future possibilities.
        • The effectiveness of scenario analysis relies on its accuracy and comprehensiveness, which should encompass both past and future risks. 
        • Could be challenging to determine the credibility of a situation since the scenarios can vary in their complexity.
      • Scenarios may be intuitive and transparent which are advantage but are necessarily complex which is a disadvantage.
    • Stress testing is a crucial evaluation method to ensure a firm's sustainability. It assesses extreme scenarios that may occur rarely but can have a significant impact on losses. On the other hand, probabilistic risk metrics, such as VaR, ES, or Standard Deviation, are suitable when the frequency of losses is high, and the severity of losses is low.
    • Reverse stress tests, banks can identify worst-case outcomes on the key performance indicators and do the reverse engineering to see which scenarios could lead to these outcomes.
  • History
    • Before the 2007-2009 financial crisis, banks used to create historical scenarios based on actual past events. However, this approach failed to predict the crisis. 
    • Banks didn't understand the risk interaction and market behaviour changes during the crisis, as the correlation between assets and asset classes increased.
    • Bank stress test scenarios were mild, regulators demanded banks demonstrate the ability to withstand more realistic stress test scenarios. Hence multiple regulatory changes were announced, as noted below.
  • Regulatory Requirement
    • SCAP: Supervisory Capital Assessment Program
      • Stress testing is performed to review whether there is sufficient capital available or not.
    • DFAST: Dodd-Frank Act Stress Tests
      • A mid-year review will be conducted for all banks with assets of $10 Billion or more. 
      • Devised by supervisors.
      • The approach is more prescriptive, involves less reporting, and requires fewer assumptions about capital action.
    • CCAR: Comprehensive Capital Analysis and Review
      • A year-end review will be conducted for all banks with assets of $50 Billion or more.
      • Complex than SCAP.
      • Encompassed of 28 scenarios, considering all the factors that might affect their portfolio (allowing interlinking factors).
      • Mandated by regulators.
      • Requires projections over 9-quarters i.e. 2.25yrs.
      • Requires banks to dynamically forecast balance sheets and income sheets.
      • Forecast must include:
        • Actual loss
        • Revenues
        • Loan loss provisions
        • Credit losses related to defaulting loans and downgrades on debt scenarios
        • Rules for making new loans
        • Regulatory ratios
      • Capital plans based on each scenario/stress tests:
        • Forecast expected capital sources
        • Capital use over 9 quarter horizon
        • Describe methodologies that will be used to determine capital adequacy
        • Minimum capital standards required
        • How to raise capital if necessary
        • Plans for dividend payments, share repurchases and other factors that will affect the bank's capital
        • In the CCAR report about capital planning example:
          • CoCos - Contingent convertible bonds, in the event of trouble, bonds could be converted to equity and ease the bank's cash outflows in times of stress.
          • These bonds have the characteristic of being convertible into equity shares of the issuing company under certain conditions, typically triggered by predefined events related to the financial health of the issuer.
          • One of the key features of CoCos is that they come with contingent conversion triggers. These triggers are often tied to the issuer's capital levels or financial health.
          • The bonds act as insurance for banks thus a risk transfer from ERM perspective.
      • Tier 1
        • Tier 1 typically refers to the highest level of risk within an organization.
        • Organizations prioritize these risks due to their potential to cause substantial harm or disruption. 
        • Examples of Tier 1 risks may include major regulatory changes, economic downturns, catastrophic events, or severe cybersecurity breaches.
        • The capital ratio is like a measure of how safe a bank is. The higher the ratio, the safer the bank; the lower the ratio, the riskier it might be and may face regulatory scrutiny to improve its capital adequacy.
        • Stress test cannot dip below it:
          • Minimum common equity capital ratio is 4.5%.
          • Minimum capital requirement is 6%.
          • Total risk-based capital ratio is 8% and Tier 1 leverage ratio is 4%.
        • If banks fail to meet minimum capital standards under stress testing, the bank must lower its risk appetite.
      • CCAR requires banks to engage in exercises that require business line managers to come together and discuss risks, which is the key to the ERM process.
      • Different banks are testing the same scenarios, for regulators have a better sense of systematic risks and can compare bank risk exposures, which would be impossible if each bank had its own scenarios.
    • Federal Reserve Annual Stress Tests
      • Mandated by regulators.
      • Below are three macroeconomic scenarios that need to be considered:
        • Baseline: Normal
        • Adverse: Moderately declining economy
        • Severely Adverse: Global recession or depression with the corresponding decline in demand for fixed-income investments.
  • While all these are used for compliance issues, it is also used for below:
    • Develop warning signals
    • Specify risk appetites and risk limits
    • Check the reasonableness of capital plans
    • Put in contingency plans to manage different risks such as liquidity, and credit.
    • Stress tests focus on macroeconomics and can be used in day-to-day business planning.
    • Scenarios analysis can be in strategic decision-making.


Risk Culture

  • Risk culture
    • It is the heart of the ERM
    • It defines the behaviour and response towards risk.
    • It is the firm's goals, customs, values and beliefs both implicit and explicit that influence the behaviour of employees.
    • Corporate norms guide individuals in their understanding and responses to risk and were identified as primary contributors to bank failures in the 2007-2009 financial crisis.
    • Risk culture happens at the enterprise level, group level and individual level.
  • Measure risk culture
    • Measuring risk culture is a problem because it is multi-layered and complex. Individuals have their own risk attitudes because they come from different backgrounds and the risk behavior is as well influenced by peers and management.
    • Measures of risk culture help the firm to understand the changes in the risk culture but they do not quantify the losses associated with failures related to the firm's risk culture.
    • To measure progress in terms of risk culture there are different methods, one such method is to identify key risk culture indicators of the firm. The Financial Stability Board (FSB) has specified four risk indicators:
      • Tone of top management
        • Actions of management conflict with stated risk appetite or goals.
        • Board of directors communicate the fit between risk appetite and firm strategies and goals.
      • Effective communication and challenge
        • Firm is valuing whistleblower
        • Opposing views are valued
        • Right to disagree
      • Incentives
        • Compensation plans supportive of and in alignment with risk appetite and risk culture.
      • Accountability
        • Expectations are clear
        • Escalation process used
    • Survey and other data can be used to develop a risk culture score.
  • Factors that can be used to build a robust risk culture.
    • Knowledge of the firm's risk appetite and ability to answer questions about its application in day-to-day business operations.
    • Risk literacy through training programs and knowledge of the language used to describe risks and the consequences of risk-taking.
    • The flow of risk information, and the details about risk flow across the firm with clarity on the discussions of risk and decisions made.
    • Risk/reward decisions of managers.
    • Risk management stature typically refers to the level of maturity or sophistication of an organization's risk management practices. It reflects how effectively an organization identifies, assesses, mitigates, and monitors risks to achieve its objectives and protect its interests.
    • Whistleblowing and escalation, to report enterprise risks and methods in place to blow the whistle.
    • Priorities of the board.
    • Action against offenders.
    • Identification of risk culture concerns and incidents, that were taken in response to violations.
  • Factors that prevent firms from developing robust risk cultures that can withstand fluctuations and recover from setbacks relatively quickly.
    • Risk education
      • Throughout the organization risk education should be provided including the board of directors.
      • The board must be able to list key enterprise risks and relate key risks to the firm's risk appetite.
      • Having common risk language across the organization would be useful.
    • Risk indicators become risk levers
      • Firms identify risk indicators, but in many cases, it is easier to manage the risk indicator than to actually improve the firm's risk culture.
    • Curse of data
      • Growing amount of data available for analyzing risk.
    • Culture cycle
      • During a crisis behaviour towards risk will be very low due to the feelings and fear, but that fades away over time.
    • Risk across the organization and across time
      • Risks are generally established in business lines and often develop an internal risk culture rather than at the enterprise level.
      • By proactively identifying and managing risks that span multiple business lines, enterprises can strengthen their resilience and enhance their ability to achieve their strategic objectives despite potential challenges and uncertainties.
  • External factors also influence risk culture, a few factors are the economic cycle, industry and professional norms, changing industry practices, professional and regulatory standards, country risk and corruption indices.


ERM Best Practices

  • Corporate governance (CG) refers to the system of rules, practices, and processes by which a company is directed and controlled. 
  • It encompasses the relationships and responsibilities among a company's management, its board of directors, its shareholders, and other stakeholders.
  • Effective corporate governance is essential for the success of Enterprise Risk Management (ERM) initiatives
  • CG ensures senior management and the board have the requisite organizational practices and processes to adequately control risks.
  • CG practices have evolved considerably through recent regulatory initiatives including the Turnbull Report and the Sarbanes-Oxley Act.
  • A successful corporate governance framework requires the senior management and the board to adequately define the firm's risk appetite and risk and loss tolerance.
  • The firm should have the required management skills and organization structure to successfully implement the ERM program.
  • All key risks are successfully integrated into the ERM program.
  • Risk roles and responsibilities should be clearly defined including the role of the chief risk officer (CRO).
  • Audit and monitoring targets are crucial components of the ERM governance process.


ERM Program Dimensions

ERM programs typically encompass several dimensions that collectively contribute to effective risk management across an organization. The following are five important dimensions.
  • Targets
    • Set correct risk targets.
    • Targets should be in sync with strategic goals.
    • Targets includes:
      • Risk appetite operational mechanism and global risk limits are linked to the risk appetite of the firm.
      • Strategic goals are linked to the firm's risk appetite.
  • Structure
    • The roles along with a description of the firm's governance structure needs to be defined for chief risk officer, global risk committee and other risk committees.
    • Ensure enterprise wide risks are identified contributing to direct or indirect losses.
    • Establish reporting lines and frequency.
  • Identification and metrics
    • Identification of risks
      • impact on the firm
      • severity of the risks
      • frequency of the occurrence
      • concentration
    • Right metrics used to capture whole firm's risks
      • scenario analysis
      • stress testing
      • sensitivity analysis
      • standard deviation
      • value at risk (VaR)
      • total cost of risk approaches
      • enterprise-wide risk mapping
      • risk specific metrics
      • risk flagging tools
  • ERM Strategies
    • Communicate risk to the entire organization
    • Decisions must be made at the enterprise level regarding accept, avoid, mitigate or transfer.
  • Culture
    • Strong risk culture is the heart and soul of ERM
    • Top-down approach in instilling the importance of risk through goals, practices and behaviours.


Credits and References

  • https://st4.depositphotos.com/2547605/40711/v/450/depositphotos_407115488-stock-illustration-erm-enterprise-risk-management-business.jpg
  • FRM Book 1 - Chapter 8
  • https://gemini.google.com/
  • https://chatgpt.com/

Memcached - An Overview - InDraft

 

Cache and Session Store

A cache is a type of high-speed data storage layer in computing that temporarily stores a portion of data. This allows subsequent requests for that data to be delivered faster than if it had to be accessed from the data's primary storage location. Caching is a technique that helps you to use previously received or calculated data more effectively. The main objective of a cache is to enhance data retrieval performance by minimizing the need to contact the slower storage layer beneath. Cache data is usually stored in fast-access hardware such as RAM (Random-access memory) and may also be used with a software component.    

A session store is a server-side location where user session data is stored. In web applications, this is usually done through a cookie stored in the client's web browser. This allows your application to identify the user and keep them logged in, for example. Storing session data is crucial for the proper functioning of web applications. In-memory databases can ensure high-speed access, horizontal scalability, and high-fidelity data storage. These features improve the overall performance and user experience of web applications.

Memcached is a commonly used in-memory data store by application developers to manage session data for internet-scale applications. It is an excellent choice for implementing a high performance in-memory cache to reduce data access latency, improve throughput, and reduce the load on your back-end systems. Persistence is not critical when using Memcached.

Memcached

Memcached is an open-source distributed, high-performance in-memory system that caches memory objects in key-value storing short bits of random data (strings, objects) returned by databases queries, API requests or page rendering. It was initially designed to speed up dynamic web apps and reduce database load by Brad Fitzpatrick from Danga Interactive for LiveJournal in 2003. It was written is Perl, but is rewritten in C by Anatoly Vorobey. Memcached is now used by all the major websites having huge data, for example, YouTube, Wikipedia, Twitter etc.

Memcached enables to allocation of memory from the parts of the system where it’s surplus, and makes it accessible to the areas that need more memory. When you use memcached, all the servers in the cluster access the same virtual pool of memory. As a result, every item is stored and retrieved from the same location across the entire server cluster. Since Memcached is decentralized or distributed system, it can be easily scaled by adding more nodes. Additionally, Memcached’s multithreaded nature enables users to quickly increase computational capabilities by utilizing several cores in the given node.


Architecture of Memcache

Memcached is a type of in-memory key-value store that stores its data in RAM instead of on disks. This helps to eliminate delays caused by disk access and enables data to be accessed in microseconds. 

Memcached is a software that consists of three main components. 
  • The first component is the client software, which provides a list of available Memcached servers. 
  • The second component is a client-based hashing algorithm, which chooses a server to store based on the key - this helps to distribute the load.
  • The third component is the server software, which stores values and their keys into an internal hash table.  
The architecture of Memcached is straightforward. 
  • When a client requests a piece of data, Memcached checks to see if it is stored in the cache.
  • There are two possible outcomes. 
    • If the data is stored in the cache, Memcached returns the data without checking the database. 
    • However, if the data is not stored in the cache, Memcached queries the database, retrieves the data, and stores it in the cache. 
      • It is important to note that data is only sent to one server, and servers do not share data. 
      • Servers keep the values in RAM, and if RAM runs out, the oldest value is discarded. Memcached uses LRU caching algorithm(Least Recently Used (LRU) – discards the least recently used items first).
      • Whenever information is modified or the expiry value of an item has expired, Memcached updates its cache to ensure fresh content is delivered to the client.
  • Clients use a hashing algorithm to determine which memcached storage server to use, helping to distribute the load efficiently.
  • When the server receives a key, it computes a second hash to determine where to store the corresponding value in an internal hash table.
  • The name, expiration date, and raw data are included in every object. Whenever data is updated, or an object has an expiry value expired, it updates its cache to provide the client with fresh content.
A few important points about Memcached architecture include:  
    • Data is only sent to one server. 
    • Servers do not share data.
    • Servers store data in the Random Access Memory (RAM) of the system, it is not persistence. 


Benefits of Memcache

  • Response times in milliseconds
  • Server Client program can run in both TCP and UDP 
  • Open source
  • Data is saved in the server
  • Supports multiple OS
  • Provides APIs for major languages like Perl, Python, Java, Ruby, C, C++ and so on.
  • Scalability, easily by adding or removing nodes
  • Community support


Limitations of Memcached

  • Datastore is not persistent
  • As the data package is located in only one place, multiple users have limited access to it.
  • Also when the data is too rapidly changing, memcached is not preferred to use.


Credits and References

https://spin.atomicobject.com/wp-content/uploads/brain-forget.jpg
https://www.javatpoint.com/memcached-tutorial
https://www.keycdn.com/support/what-is-memcached

https://www.cs.cmu.edu/~dga/papers/memc3-nsdi2013.pdf
https://github.com/couchbase/Memcached/blob/master/docs/Architecture.md
https://acquia.my.site.com/s/article/360005256114-Memcached-in-detail
https://www.dragonflydb.io/guides/memcached
https://www.ijert.org/research/a-brief-introduction-to-memcached-with-its-limitation-IJERTV3IS21081.pdf
https://en.wikipedia.org/wiki/Memcached

Scarcity Brings Efficiency: Python RAM Optimization

  In today’s world, with the abundance of RAM available, we rarely think about optimizing our code. But sooner or later, we hit the limits a...