What's Hot

Nassim Nicholas Taleb's blog, an inspiring read | Incerto


Wednesday, September 26, 2012

How many controls are too many?

In a recent discussion on the G31000 Linkedin forum, a member put forward an interesting question. 

How many controls are too many?

Can an organisation literally have too many controls?

Tuesday, September 25, 2012

Cluster Events

The world of risk management is continually evolving but where is the next developmental phase for the practice of risk theory?

In my opinion, one area which offers great opportunity is the relatively undiscovered work around event predictability. Let's be real of course, there is no way to predict the future but it might be nice to understand the shape of that future.

In this blog, we review the use of the Extensible Markov Model for shaping event clusters.

Wednesday, September 19, 2012

PV01 vs Historical VaR

The world of fixed income is very much impacted by PV01, yet Market Risk analysts hang onto historical Value at Risk as if it is the be all for measuring potential downside. In my opinion this is a bit busted and I will explain why in this short blog post.

Thursday, September 6, 2012

Understanding risk appetite

Over the last week, there have been a lot of discussions on risk appetite in the G31000 forum and while ISO 31000 refers to risk appetite as risk attitude, broadly the concept is not fully appreciated by many risk analysts in the market place.

In this blog we look at risk appetite; what it is, where it has been used and why it is important.

Saturday, August 18, 2012

Risk Charting and Bubble Charts

Perhaps ten years ago; reporting risk profiles or organisational threats was a challenging thing to do for many risk analysts on the job and while the majority of risk reports were fundamentally ordinary, it became apparent quite quickly that a simple list of hazards was never going to cut it.

In this blog we look at an emerging era of risk reporting.

Monday, August 13, 2012

ROC Control Optimization

In the world of risk, analysts and managers alike try to reduce the likelihood of an event occurring by inserting controls between the event's driving factors and its outcome. Additionally, these analysts often regularly monitor specific indicators they believe will give them insight into something unwanted happening.

While the logic around this is sound, not all controls are equal and more often than not, some key risk indicators emit erroneous measures which mislead entire risk teams.

In this short post, we look at a method for weeding out erroneous control signals.

Monday, August 6, 2012

ISO 31010 and Loss Modeling

One of the most concerning trends that continually persists in operational risk management, is the lack of interest analysts have for attempting to quantify this risk exposure coherently.

In this blog we look at operational risk from the perspective of the normal and the extreme.

Thursday, July 26, 2012

ISO 31000 for Property Development

It states in the ISO 31000 standards guide, that organisations of all types and sizes face internal and external factors as well as influences that make it uncertain whether and when they will achieve their objectives.

If we were to look at property development or the construction industry for example, we know that these types of issues are also likely to be evident. So, would ISO 31000 be of benefit to the construction sector?

In this short journal post, we share a presentation that reviews some of the problems of risk management in property development, how risk management currently functions in this industry sector and why it would be advantageous to adopt ISO 31000 in property development.

Friday, July 13, 2012

Retrofitting ISO 31000

There have been some interesting discussions on the G31000 forum over the last week which allude to a future of potential conflict for ISO 31000.

In this short post, we look at some of the headwinds that ISO 31000 is going meet, as the adoption of the standard ramps-up across multiple industries.
  

Tuesday, July 3, 2012

Cause and Effect Analysis

There are several ways of looking at operational risk specifically but perhaps one of the most exciting and intuitive methods in use today is Cause~Effect Analysis.

In this short post, we look at how Cause-Effect Analysis works and we extend a bow tie diagram further to show how it can be applied to a Cause~Effect risk space.
  

Thursday, June 28, 2012

ISO 31004 Wishlist

The International Organisation for Standardization [ ISO ] is about to enter into a trial review for its ISO 31004 guide.

Being an active risk manager, I believe it is important to highlight potential key topical points for inclusion in the ISO 31004 program. This is all in the hope that the final ISO 31004 document will address some of the open ended elements that ISO 31000 seems to omit. The risk community at large seems to struggle with some of the items listed in the attachment that is linked to this post and more information, example case studies and critique on these areas of risk measurement specifically, would be welcome from the ISO body.

This blog lists 50 key aspects of commercial enterprise risk management which are not only common practice in some cases, but are also important for evolving the enterprise risk management field today.

Friday, June 22, 2012

The Model Dilemma

Over the last few months, risk models have come under the spotlight as a potential reason why risk management as an entire institutional function is failing. In the recent JP Morgan CDX tranche 9 blow up, Value at Risk was held accountable in much of the part. The JP Morgan disaster initially put the bank into a negative trajectory of at least USD 2bn and is very much a tail event that might just fall outside a traditional risk modelling technique.

But this is not an isolated case. There have been other claims from many corners of society that risk models are as dangerous as the risk they are attempting to quantify.
  
In this blog we look at the argument to rebuke the model.

Monday, June 18, 2012

Why Banks Fail Stress Tests

Perhaps one of the most important risk activities a bank should initiate or enhance over the coming years ahead is stress testing. The stress testing framework, not that risk analysts currently see it as that, is probably going to be the next best thing and the only viable commercially alternative for reducing financial sector fragility other than crippling regulation or bailouts.
  
In this blog we look at why banks have been failing their stress tests. 

Saturday, June 9, 2012

Time in risk

A recent debate on the G31000 Linked in forum about time and risk poses the following question "Is delaying a risk considered a separate treatment method or is it just a sub-type of changing the likelihood?"
  
This is a very interesting statement and it leads this blog posting into looking at some of the aspects of risk through time. 
  
Time or the lack of it would intuitively have anyone believe that impact is likely to increase overtime just like a pressure cooker building up. I suppose that is one manner in which to conceptualize these time effects more practically. Alternatively, the "spreading out" of risk events makes for easier management, rather than having a lot of events occurring in a short period of time, it can go both ways. Perhaps then, time features more in risk management than we would like to first acknowledge?

In this blog posting we take a look at eight situations where time intertwines with risk. There are many more examples of risk in time or time in risk as it is, but we have chosen to talk about eight unique relationships of risk and time.

Saturday, June 2, 2012

Perception in Objectives

Over the last two years alone, we have seen some incredible risk events across the planet. 

These disasters have not only been extremely high profile but also massively impacting and questions are now emanating from all quarters, that risk management as a commercial discipline of planning control is missing the mark.
  
What is wrong with risk management?

Monday, May 28, 2012

Concentration Risk

The quantification of Credit Risk has both normal and stressed modes of measurement, just as all measures of risk do. However, when an analyst attempts to quantify stress in credit portfolios, they should attempt to dimension the concentration risk aspects of their portfolio in line with the stress test they have in mind.
  
In this blog post we look at the stress testing aspects around concentration risk and a presentation has also been attached to the end of this journal which can be downloaded. This presentation investigates standard and accepted practices for measuring concentration risk in credit portfolios.


Thursday, May 24, 2012

Modelling Loss Data

In our previous post on Loss Event Data, we discussed the types of fields and specific risk framework elements that need to be in place for a best practice Loss Data Repository and you can follow this [Link] for a recap. In this third series on the Loss Data Monte Carlo debate (this is turning into a bit of a tome on data modelling), we take look at the types of techniques that can be used for understanding Operational Risk Loss Data better.
  
There are 14 key models that have been listed in this post and brief summaries, as well as the purpose for each model has been supplied within.

Friday, May 18, 2012

The Loss Data Process

In our last blog posting on Monte Carlo and Loss Data we described the importance of the Loss Data exercise. A few people have personally emailed me asking for more information on this aspect of risk management, so I have decided to write a blog post on it.
  
I will be posting two articles on the risk function around loss data specifically. In this post we look at what comprises a Loss Database and the event management process for administering Loss Data itself.  In a second posting, I will describe the types of statistical models we can use to carry out analysis of the data we capture in our Loss Data repository.

Thursday, May 17, 2012

ISO 31000 for banks

ISO 31000 is a risk management standard that provides generic guidelines for the design and operation of an enterprise risk management framework. Released in 2009 by the ISO standards board, the standard itself has been crafted in such a manner that it makes ISO applicable for any organisation type. Theoretically banks to manufacturing firms can benefit from implementing ISO 31000.

What we are exploring in brief today is: Should the banking sector entertain ISO 31000 when it already has an established global risk standard of its own?

The presentation for this posting can be found by following this [link]

Friday, May 11, 2012

Monte Carlo and Loss Data

Recently I had a discussion on modelling risk with a fantastic and successful business person who said to me : "I have read about Monte Carlo, you even make mention to it on your blog but it doesn't make great sense to me. The maths in Monte Carlo is even worse because it seems to confuse the concept by taking it into an academic place that most people aren't from.

Is it possible to explain Monte Carlo by using a tool we all understand such as Microsoft Excel?"

So be it, this blog posting is an Excel example of Monte Carlo and Loss Data. Due to the size of the post, it will be separated into two, possibly three updates.