This chapter describes the criteria that banks must meet to be able to calculate operational risk capital requirements based on internal risk measurement systems.
Under the Advanced Measurement Approaches (AMA), the regulatory capital requirement will equal the risk measure generated by the bank’s internal operational risk measurement system using the quantitative and qualitative criteria for the AMA discussed below. Use of the AMA is subject to supervisory approval.
A bank adopting the AMA may, with the approval of its host supervisors and the support of its home supervisor, use an allocation mechanism for the purpose of determining the regulatory capital requirement for internationally active banking subsidiaries that are not deemed to be significant relative to the overall banking group but are themselves subject to this Framework in accordance with SCO10. Supervisory approval would be conditional on the bank demonstrating to the satisfaction of the relevant supervisors that the allocation mechanism for these subsidiaries is appropriate and can be supported empirically. The board of directors and senior management of each subsidiary are responsible for conducting their own assessment of the subsidiary’s operational risks and controls and ensuring the subsidiary is adequately capitalised in respect of those risks.
Subject to supervisory approval as discussed in [[OPE30.11]](4), the incorporation of a well-reasoned estimate of diversification benefits may be factored in at the group-wide level or at the banking subsidiary level. However, any banking subsidiaries whose host supervisors determine that they must calculate stand-alone capital requirements (see SCO10) may not incorporate group-wide diversification benefits in their AMA calculations (eg where an internationally active banking subsidiary is deemed to be significant, the banking subsidiary may incorporate the diversification benefits of its own operations — those arising at the sub-consolidated level — but may not incorporate the diversification benefits of the parent).
The appropriateness of the allocation methodology will be reviewed with consideration given to the stage of development of risk-sensitive allocation techniques and the extent to which it reflects the level of operational risk in the legal entities and across the banking group. Supervisors expect that AMA banking groups will continue efforts to develop increasingly risk-sensitive operational risk allocation techniques, notwithstanding initial approval of techniques based on gross income or other proxies for operational risk.
Banks adopting the AMA will be required to calculate their capital requirement using this approach as well as the 1988 Accord as outlined in RBC20.14.
In order to qualify for use of the AMA a bank must satisfy its supervisor that, at a minimum:
A bank’s AMA will be subject to a period of initial monitoring by its supervisor before it can be used for regulatory purposes. This period will allow the supervisor to determine whether the approach is credible and appropriate. As discussed below, a bank’s internal measurement system must reasonably estimate unexpected losses based on the combined use of internal and relevant external loss data, scenario analysis and bank-specific business environment and internal control factors. The bank’s measurement system must also be capable of supporting an allocation of economic capital for operational risk across business lines in a manner that creates incentives to improve business line operational risk management.
A bank must meet the following qualitative standards before it is permitted to use an AMA for operational risk capital:
Given the continuing evolution of analytical approaches for operational risk, the Committee is not specifying the approach or distributional assumptions used to generate the operational risk measure for regulatory capital purposes. However, a bank must be able to demonstrate that its approach captures potentially severe “tail” loss events. Whatever approach is used, a bank must demonstrate that its operational risk measure meets a soundness standard comparable to that of the internal ratings-based approach for credit risk (ie comparable to a one year holding period and a 99.9th percentile confidence interval).
In the development of operational risk measurement and management systems, banks must have and maintain rigorous procedures for operational risk model development and independent model validation.
The following quantitative standards apply to internally generated operational risk measures for purposes of calculating the regulatory minimum capital requirements.
| Detailed loss event type classification | Table 1 | |||
| Event-type category (Level 1) | Definition | Categories (Level 2) | Activity examples (Level 3) | |
| Internal fraud | Losses due to acts of a type intended to defraud, misappropriate property or circumvent regulations, the law or company policy, excluding diversity/ discrimination events, which involves at least one internal party | Unauthorised activity | Transactions not reported (intentional) Transaction type unauthorised (with monetary loss) Mismarking of position (intentional) | |
| Theft and fraud | Fraud / credit fraud / worthless deposits Theft / extortion / embezzlement / robbery Misappropriation of assets Malicious destruction of assets Forgery Check kiting Smuggling Account takeover / impersonation etc Tax non-compliance / evasion (wilful) Bribes / kickbacks Insider trading (not on firm’s account) | |||
| External fraud | Losses due to acts of a type intended to defraud, misappropriate property or circumvent the law, by a third party | Theft and fraud | Theft / robbery Forgery Check kiting | |
| Systems security | Hacking damage Theft of information (with monetary loss) | |||
| Employment practices and workplace safety | Losses arising from acts inconsistent with employment, health or safety laws or agreements, from payment of personal injury claims, or from diversity / discrimination events | Employee relations | Compensation, benefit, termination issues Organised labour activity | |
| Safe environment | General liability (slip and fall etc) Employee health and safety rules events Workers compensation | |||
| Diversity and discrimination | All discrimination types | |||
| Clients, products and business practices | Losses arising from an unintentional or negligent failure to meet a professional obligation to specific clients (including fiduciary and suitability requirements), or from the nature or design of a product. | Suitability, disclosure and fiduciary | Fiduciary breaches / guideline violations Suitability / disclosure issues (know-your-customer etc) Retail customer disclosure violations Breach of privacy Aggressive sales Account churning Misuse of confidential information Lender liability | |
| Improper business or market practices | Antitrust Improper trade / market practices Market manipulation Insider trading (on firm’s account) Unlicensed activity Money laundering | |||
| Product flaws | Product defects (unauthorised etc) Model errors | |||
| Selection, sponsorship and exposure | Failure to investigate client per guidelines Exceeding client exposure limits | |||
| Advisory activities | Disputes over performance of advisory activities | |||
| Damage to physical assets | Losses arising from loss or damage to physical assets from natural disaster or other events | Disasters and other events | Natural disaster losses Human losses from external sources (terrorism, vandalism) | |
| Business disruption and system failures | Losses arising from disruption of business or system failures | Systems | Hardware Software Telecommunications Utility outage / disruptions | |
| Execution, delivery and process management | Losses from failed transaction processing or process management, from relations with trade counterparties and vendors | Transaction capture, execution and maintenance | Miscommunication Data entry, maintenance or loading error Missed deadline or responsibility Model / system misoperation Accounting error / entity attribution error Other task misperformance Delivery failure Collateral management failure Reference data maintenance | |
| Monitoring and reporting | Failed mandatory reporting obligation Inaccurate external report (loss incurred) | |||
| Customer intake and documentation | Client permissions / disclaimers missing Legal documents missing / incomplete | |||
| Customer / client account management | Unapproved access given to accounts Incorrect client records (loss incurred) Negligent loss or damage of client assets | |||
| Trade counterparties | Non-client counterparty misperformance Miscellaneous non-client counterparty disputes | |||
| Vendors and suppliers | Outsourcing Vendor disputes | |||
Banks must track internal loss data according to the criteria set out in [[OPE30.12]] to [[OPE30.15]]. The tracking of internal loss event data is an essential prerequisite to the development and functioning of a credible operational risk measurement system. Internal loss data is crucial for tying a bank’s risk estimates to its actual loss experience. This can be achieved in a number of ways, including using internal loss data as the foundation of empirical risk estimates, as a means of validating the inputs and outputs of the bank’s risk measurement system, or as the link between loss experience and risk management and control decisions.
Internal loss data is most relevant when it is clearly linked to a bank’s current business activities, technological processes and risk management procedures. Therefore, a bank must have documented procedures for assessing the on-going relevance of historical loss data, including those situations in which judgement overrides, scaling, or other adjustments may be used, to what extent they may be used and who is authorised to make such decisions.
Internally generated operational risk measures used for regulatory capital purposes must be based on a minimum five-year observation period of internal loss data, whether the internal loss data is used directly to build the loss measure or to validate it. When the bank first moves to the AMA, a three-year historical data window is acceptable (this includes the parallel calculations in RBC20.14).
To qualify for regulatory capital purposes, a bank’s internal loss collection processes must meet the following standards:
| 1 | This applies to all banks, including those that may only now be designing their credit risk and operational risk databases. |
A bank’s operational risk measurement system must use relevant external data (either public data and/or pooled industry data), especially when there is reason to believe that the bank is exposed to infrequent, yet potentially severe, losses. These external data should include data on actual loss amounts, information on the scale of business operations where the event occurred, information on the causes and circumstances of the loss events, or other information that would help in assessing the relevance of the loss event for other banks. A bank must have a systematic process for determining the situations for which external data must be used and the methodologies used to incorporate the data (eg scaling, qualitative adjustments, or informing the development of improved scenario analysis). The conditions and practices for external data use must be regularly reviewed, documented, and subject to periodic independent review.
A bank must use scenario analysis of expert opinion in conjunction with external data to evaluate its exposure to high-severity events. This approach draws on the knowledge of experienced business managers and risk management experts to derive reasoned assessments of plausible severe losses. For instance, these expert assessments could be expressed as parameters of an assumed statistical loss distribution. In addition, scenario analysis should be used to assess the impact of deviations from the correlation assumptions embedded in the bank’s operational risk measurement framework, in particular, to evaluate potential losses arising from multiple simultaneous operational risk loss events. Over time, such assessments need to be validated and re-assessed through comparison to actual loss experience to ensure their reasonableness.
In addition to using loss data, whether actual or scenario-based, a bank’s firm-wide risk assessment methodology must capture key business environment and internal control factors that can change its operational risk profile. These factors will make a bank’s risk assessments more forward-looking, more directly reflect the quality of the bank’s control and operating environments, help align capital assessments with risk management objectives, and recognise both improvements and deterioration in operational risk profiles in a more immediate fashion. To qualify for regulatory capital purposes, the use of these factors in a bank’s risk measurement framework must meet the following standards:
Under the AMA, a bank will be allowed to recognise the risk mitigating impact of insurance in the measures of operational risk used for regulatory minimum capital requirements. The recognition of insurance mitigation will be limited to 20% of the total operational risk capital requirements calculated under the AMA.
A bank’s ability to take advantage of such risk mitigation will depend on compliance with the following criteria:
A bank’s methodology for recognising insurance under the AMA also needs to capture the following elements through appropriate discounts or haircuts in the amount of insurance recognition:
The risk-weighted assets for operational risk under the AMA are determined by multiplying the capital requirements calculated as set out in this chapter by 12.5.
This standard describes the scope of application of the Basel Framework.
This standard describes the criteria that bank capital instruments must meet to be eligible to satisfy the Basel capital requirements, as well as necessary regulatory adjustments and transitional arrangements.
This standard describes the framework for risk-based capital requirements.
This standard describes how to calculate capital requirements for credit risk.
This standard describes how to calculate capital requirements for market risk and credit valuation adjustment risk.
This standard describes how to calculate capital requirements for operational risk.
This standard describes the simple, transparent, non-risk-based leverage ratio. This measure intends to restrict the build-up of leverage in the banking sector and reinforce the risk-based requirements with a simple, non-risk-based "backstop" measure.
This standard describes the Liquidity Coverage Ratio, a measure which promotes the short-term resilience of a bank's liquidity risk profile.
The net stable funding ratio requires banks to maintain a stable funding profile in relation to the composition of their assets and off-balance-sheet activities.
Large exposures regulation limits the maximum loss that a bank could face in the event of a sudden counterparty failure to a level that does not endanger the bank's solvency. This standard requires banks to measure their exposures to a single counterparty or a group of connected counterparties and limit the size of large exposures in relation to their capital.
This standard establishes minimum standards for margin requirements for non-centrally cleared derivatives. Such requirements reduce systemic risk with respect to non-standardised derivatives by reducing contagion and spillover risks and promoting central clearing.
The Pillar 2 supervisory review process ensures that banks have adequate capital and liquidity to support all the risks in their business, especially with respect to risks not fully captured by the Pillar 1 process, and encourages good risk management.
This standard sets out disclosure requirements, which aim to encourage market discipline.
The Basel Core Principles provide a comprehensive standard for establishing a sound foundation for the regulation, supervision, governance and risk management of the banking sector.