加中金融协会(CCFA)
风险管理概述
(Overview of Risk Management)
声 明
All the views expressed in this presentation are those of my own and do not necessarily represent the views of RBC Financial Group.
提 纲
加拿大银行简介
风险管理过程
风险管理框架
信用风险
市场风险
操作风险
利率风险
流通风险
在资产负债管理讲座中详细阐述!
详细内容可参见“现代西方商业银行核心业务管理”, 第二版,陈林龙,王勇/著
加拿大银行业
银行状况
六大银行拥有92%的银行资产
大约有六十家银行,而美国有上千家
八个一级(Schedule I )
四十六个二级(Schedule II )
混业经验,管理严谨
业绩衡量(股权回报,资产回报)
功能
主要金融媒介
提供存款服务
提供贷款服务
“期限转换”
加拿大银行业绩
资产以及核心资本回报率
收入构成
加拿大皇家银行金融集团
加拿大最大的银行
北美第十大,全球第二十七大 (以二00二年十月一日市值计算)
总资产$3780亿(加园,1加园=美元)
壹佰二十万客户
在全球三十国家大约有六万雇员
加拿大主要银行资本金回报率
全球大银行资产回报率
风险管理的职权划分
银行业务有以下几类风险
信用风险
市场风险
操作风险
法律风险
流通风险
利率风险
风险管理部门
资产负债管理部门
加拿大皇家银行金融集团 - 结构
RBC
银行业
集团
管理委员会
RBC
保险
系统技术部
RBC
资本市场
RBC
投资
财务/
库务部
RBC
交易处理
风险控制部
人事部
皇家银行金融集团风险委员会
审计委员会(董事会)
管理审查和风险政策委员会(董事会)
集团风险委员会
Chair – CEO
资产负债管理委员会
Chair – CFO
道德和职守理委员会
Chair – CRO
风险管理委员会
Chair – CRO
利率风险管理委员会
Chair – CFO
外汇和流动资金管理委员会
Chair – SVP & VP
风险政策审查委员会
Chair – CRO
交易风险管理委员会
Chair – SVP
国家风险和行业风险
Chair – SVP
皇家银行金融集团风险金字塔
缺少控制能力
更多控制能力
信誉
策略
竞争
监督机制
和法律
金融
系统性
信贷
市场
流动
资产
保险
保险承销
保险统计
运作
技术应用
人员
运作程序
RBC 风险金字塔:组织结构透视
监督
所有权
监视
升级
商业平台
个人/商业银行
保险
投资
资本市场
全球整体业务
风险总监
集团风险管理委员会
风险管理委员会
董事会
管理审查和
风险政策委员会
集团风险管理委员会
文化
体制
委派
责任
风险管理的发展过程
市场以及经济萧条引发系统管理风险的概念
管理条例的放松
市场监管人员对衍生产品的担忧
巴塞耳资本金管理条例的引入
新技术,新理论的影响
Markowitz证券组合理论
Black-Scholes期权定价理论
VaR
风险管理以及利润寻求
资产平衡表
现金 存款
贷款 短期债券
固定资产 长期债券
投资人权益
非资产平衡表
衍生产品 衍生产品
风险管理以及利润寻求
利息收入
- 操作费用
= 税前收入
- 折价,税收
- 准备金
= 净收入
风险与收益
因业务需要,银行必需承担风险. 一般是 险越大,预期收益越大. 风险与收益有非对称关系.
消除风险=消除收益
风险本身并不是坏东西,我们的主要责任是管理风险。最糟糕的是对风险没有正确认识和错误管理风险。
信用风险
债务人或客户不能按合同的要求归还其债务的可能性
破产可能性
市场价钱变化
信用风险管理理论是世界主要银行所关心的热点
信用分析
目的:分析信贷人信用分析
信用分析系统
定量标准
定性标准
信用评审公司的做法
业务(Business Risk)风险:工业特征,竞争能力,技术,管理特征
金融风险(Financial Risk):容资结构, Financial Policy, Cash Flow Protection, Financial Flexibility etc.
内部做法
信贷人信用分析
贷款评级
信用审批过程
贷款动机
风险回报率是否可接受?
偿还能力
企业发展计划, 管理能力
资产负债平衡表审查
资金流检验
管理能力审查
竞争力审查
定价分析
定量分析准则
信用评级
法律审评
等等
审批通过
支撑资金
贷款组合
初期审察
定量检验
贷款定价
审批通过
后期管理
传统信用管理的弊病
受主观的影响
费用昂贵
难以定量化
难以识别资产集中风险
信用解析过程
敞口计算
信誉评估
信誉变化
破产概率
破产损失
相关性
其它因素
= f
预期损失,非预期损失,灾难性损失
For which reserves
should be held
2
损失密度函数
无损失
预期损失
灾难性损失
%的置信区间
非预期损失
For which economic capital
should be held
protecting against unexpected
credit losses
Potential “Unexpected” Loss
against which it will be too
expensive to hold equity
市场风险
指由于市场价格变动使资产值发生变化可能性。
特点
利率风险,汇率,股票价格等等
绝对型,相对型
市场风险管理较为发达
市场风险管理主要包括
风险识别
风险测算
风险政策和过程
风险分析和检测
风险报告
风险确认和审计
物理学家/数学家
风险价值度
风险价值度(Value at Risk)主要用来测试在给定的时间内,在某一置信度下,在正常的市场条件下,银行一个投资组合可能产生的最大的损失。VAR有三个因素需要考虑:
(1)时间长度:如天数或周数;
(2)置信度(把握程度);
(3)损益的分布。
为什么用VAR来管理风险?
VAR可以回答这样的问题:在某一段时间内,在X%(如99%)的把握下,银行至多会损失多少。如管理层在每个营业日的开始,可能会给风险管理部门提出这样的问题:在99%的把握内,一天内整个银行的损失至多有多大?
VAR将风险转化成一个货币数量
VAR可以用来计算复杂投资组合的风险
操作风险
是指所有潜在的、由非市场因素和信用因素引起的风险,也就是除了信用风险和市场风险以外的一切风险。
系统风险:主要指计算机故障给银行业务操作带来的风险。
技术风险:由于技术的落后,可能给银行带来的风险。
模型风险:在模型构造过程中,没有对市场状况和风险识别有一个全面的认识,导致模型的低效和无能 。
会计风险:指由于会计制度和政策不能正确反映企业经营状况
操作风险
难以定量化,操作风险往往是突发性事件。
小概率,大损失。
可以有效的进行控制。
操作风险损失
Source: E
交易风险 操作控制风险 系统风险
指令错误 超出风险控制量 系统失效
记帐错误 违法交易 模型风险
清算错误 作弊 市场定价错误
实物传达 洗劫现金 错误信息
文件错误 保安风险 编成错误
主要工作人员风险 通讯错误
过程风险 后备计划失效
Source: GRAP
操作风险
操作风险管理实例
前台
People Risk High
Process Risk Low
Model Risk High
Booking Risk Low
System Risk Low
Strategic Risk Low
Total Medium
后台
People Risk Low
Process Risk High
Model Risk Low
Booking Risk High
System Risk Low
Strategic Risk Low
Total Medium-
操作风险的正确管理态度
每一业务平台拥有操作风险。
操作风险种类多种多样。
操作风险管理犹如人类的身体保健活动。
操作风险管理也要确保风险与回报的关系。
操作风险管理
风险部的责任
业务部门的责任
内部审计部也要负责
BU
RM
Group
Management
Implementation
操作风险管理的实施过程
准备
分析模型
具体分析
行动
操作风险管理实例
Activity 1
1. Process – Documentation/Contract
2. Process – Transaction Process Failures
3. Management Information/Data Integrity(NA)
Activity 2
4. Technology – Business Continuity
5. People – Capability and Learning
6. People – Work-Life Balance
7. People – Inadequate or Loss of People Resources
8. Process- Valuation/Model
9. Process- Transaction Processing
10. Reputation
Activity 3
11. Process – Valuation/Model
流动性风险
流通风险可分为两类
灾难性的:这类流通风险是由于其它风险引发。当其它风险造成损失很大时,可引发顾客对银行产生怀疑。从而造成银行资金短缺。
容资困难(正常性的):因为容资困难而产生的损失的可能。
流动性风险管理
懂得流通风险的监测
设立流通风险安全区域
理解流通风险对权益人影响
概念的统一
业务部门与风险管理部门的矛盾
风险管理方法
数据
人才
技术
风险管理所面临的挑战
企业上下风险管理统一化
文化的统一
方法的统一
更加依赖技术
网络的影响
风险管理发展方向
As of July 2002 there were 14 domestic banks, 33 foreign bank subsidiaries and 20 foreign bank branches operating in Canada. In total, these institutions had over $ trillion in assets, which accounted for over 70 per cent of the total assets within the Canadian financial services sector. The six largest domestic banks accounted for the bulk of the activity, holding over 90 per cent of banking are among Canada’s leading employers. In 2000 the industry employed over 235,000 Canadians and had a Canadian payroll of approximately $ billion. In addition, in 2001 the six major domestic banks paid $ billion in taxes to all levels of ’s banks operate through an extensive network that includes over 8,000 branches and close to 18,000 automated banking machines (ABMs) across the country. Canada has the highest number of ABMs per capita in the world and benefits from the highest penetration levels of electronic channels such as debit cards, Internet banking and telephone banking. In 2001 Canadians conducted billion debit card transactions from over 328,000 merchants, ranking Canada first in the world in ABM use. Between 1997 and 2000 the number of Internet banking customers registered with the six major banks increased by 262 per cent, to over million customers. Telephone banking, which permits customers to make account inquiries, transfers and bill payments over the telephone 24 hours a day, is also an increasingly popular delivery channel for Canada’s six major banks, with over million customers using the service in 2000.
\
\
QUOTE
RMA defines operational risk as anything that adds to the volatility of earnings that is not credit and market risk.
One of the reasons it is getting more attention is that, as our analytics refine our measurement of credit and market risks, we find that much of our unexpected losses are caused by operational breakdowns.
China, Refco, Student Loans ……...
If you accept the alternative definition that operational losses arise from internal or external events due to inadequate or failed strategies, processes, human performance or systems, I could argue that restructuring charges and other one- time writeoffs fall into that category.
How do we work on that basis?
The first step is to meet with the head of the ORE, the Sponsor, to discuss a number of topics, such as ..what is the RCSA process, what else has been done in ORM, the unit’s key business objectives, key processes to meet the objective and key threats or risks that get in the way of achieving the objectives.
After your initial meeting with the ORE head, you’ll scope out the key processes using high level process maps and then meet again with the ORE head to confirm the scope of the assessment, discuss key stakeholders and potential RCSA participants
In the first box, you will do a fair amount of work, reviewing reports/reviews and conducting interviews. The next step, should be to generate detailed process maps for the key processes if that has not been done already. You could gather the process level information at the same time as you conduct interviews to learn more about the risks. There are many ways to gather information including conducting a series of “Focus groups” in order to solicit feedback on processes, risks etc.
Often all workshop participants are interviewed in advance of the workshop. The reason that you invite them to the workshop is because they are a key player or possess knowledge.
With the information from your interviews you can prepare a Risk Profile. The Risk Profile is circulated to workshop participants in advance of the assessment workshop and forms the basis of the workshop discussions and rating. You’ll see how we use it here.
The first step in a risk assessment is to ensure that all the participants fully understand what Operational Risk is, its importance, and what we are doing in an RCSA. This session can be done as part of the Assessment session or in advance of the session, with perhaps someone who has been through this process before providing testimonial.
In a risk assessment session we would start with an introduction to this specific session reviewing the mission, scope, milestones, deliverables, ground rules as well as terminology. Then we would briefly present the key ORE business objectives and business processes to the participants. Taking each risk, one by one we would discuss risk experience and existing controls and then rate the impact and likelihood of the specific risk. Once all the risks have been evaluated, Action Plans will be developed with initial responsibility assigned. Note that Action Plans can include the escalation of an issue to the ORE head if necessary. The workshop should be closed with further information regarding timing and next steps, and a brief participant feedback survey should be completed.
Shortly after the workshop is complete, the Action Items should be reviewed by those who accepted initial responsibility and finalized with due dates assigned.
First step after the Action plans have been slightly fleshed out, would be to share a draft copy of the assessment results with the participants.
The assessment should be reviewed with the ORE head with special attention being paid to the Ratings and the Action Plans. It would also be appropriate at this time to talk about Key Risk Indicators, and attempt to set them for the ORE. The ORE head may disagree with the impact and likelihood ratings and want to change them. Any changes that the executive would like to make are not to be taken lightly. If management continues to believe that they disagree with the ratings, any changes that are made can be recorded in a field in the software..
Results of the RCSA incorporating any changes or responses of management are to be shared with all participants.
Action plans are to be tracked and reported. It is very important that the ORE head be involved on a regular basis, enquiring and requesting feedback concerning the timely completion of the action plans. There should also be ongoing communication concerning the progress of the action plans to the RCSA participants as well as executives and other members of the ORE, all the way up to the top of the platform and onwards
RCSA is not a one off project or event. RCSAs should be done on a regular basis, especially when change occurs.
The last step of the process is to begin preparation for the next RCSA