Thursday, July 30, 2009

“Risk Governance: let us start with the Board of Directors”

In recent weeks, several banks have revamped their Boards. Some new Directors even have the word “risk” feature in parts of their Resumes. That’s very nice. Now what?

The current crisis has revealed that many banks’ boards (and executive management) failed in their risk oversight responsibilities. Not only do many lack board-level risk committees, but those that have risk committees do not meet regularly nor do they have the functional feedback necessary for meaningful governance.

It is time Boards of Directors become pro-actively committed to risk management. It is time Regulators focus keenly on risk governance in their analysis of the health of banks. And it is time investors and shareholders and customers differentiate banks on this basis.

So, with so many stakeholders looking over its shoulders, what’s a Board to do?

• Start with a holistic approach. Align practice with strategic objectives by issuing a well developed top down statement of risk appetite. It is high time we moved away from cliché in this regard. Risk appetite need not be all quantitative. And it is unlikely to be static. And it is always relative. Boards must not only understand current business risks but assess the changing marketplace, identify new risks, monitor the business and be prepared to respond rapidly.

Transparency is crucial. Set the trend by actively disclosing risk appetite and tolerance to all stakeholders for critique and comment.

• Mandatorily disclose the available risk architecture that reconciles bottom-up business and risk management practices and output, with target appetite, tolerance, and results.

• ‘Stakeholders’ necessarily includes the internal organization. Are all employees aware of the statement of risk appetite, can they find it, have they read it? Does the statement of risk appetite describe what is expected insofar as the unusual, the unintended, and the unacceptable? Does the firm have a meaningful way to aggregate, understand, and respond to risk? Are all staff able to articulate the parameters of their own risk responsibilities?

• Define a meaningful relationship between the risk function and the Board. Equip and empower the CRO and the risk management organization, with clarity in culture, role, and accountabilities.

More on this soon

Read more >>
Posted by Jaidev Iyer, MD, GARP 0 comments

Monday, July 27, 2009

Compensation

Compensation has been brought to task as a major contributor to the global financial crisis. Chasing short-term positive results, failing to implement a robust internal control environment, not fully understanding the risks of financial instruments being sold, or, in many cases not caring, simply to pad personal compensation resulted in a major disconnect between company and shareholder interests and the interests of the individual whose contracts provided for incentives tied to profit making. Government initiated “thinking” such as that set out by the Sir Warren in his recent report issued in the United Kingdom , many in the United States Congress and various other country legislative bodies suggests compensation should be more highly controlled, directly or indirectly by the government.


The problem with dealing with compensation and incentives is obvious, it goes against most all notions of capitalism and free markets, and having the government involved in setting compensation policy is generally not considered a positive move in the right direction.
But the way forward is not at all clear. If compensation controls are implemented, or “suggestions” made by regulators that cannot go ignored, e.g., governments providing disincentives through taxation policies mitigating against personal wealth creation, one result is that individuals will simply forum shop, moving to another location to practice their craft. Of even greater concern is that a wrong policy or incentive structure will stifle innovation and initiative will diminish - not a good thing. Regulators have a tendency to overreact in times of stress, and may not necessarily look at an issue as volatile and complex as compensation in a forward thinking and objective manner.

An approach to this issue would be for companies to proactively establish compensation policies tied to long-term incentives and other risk-based compensation methodologies. The financial industry taking a proactive approach would keep governments out of the highly personal compensation issue.

Questions:

  1. Is there really a compensation solution that is politically viable and commercially acceptable?
  2. How can compensation policies be linked to the risks a person takes?
  3. Is this really much to do about nothing in that the problems we’re now dealing with were really only marginally linked to banking compensation and because it is perceived to be generous it has become an easy target?

Read more >>
Posted by Rich Apostolik 6 comments

Wednesday, July 22, 2009

Some thoughts on the Walker Review (continued)

The independence of the chief risk officer (CRO)

It is imperative that a CRO be insulated from business line, or other, pressures that would cause him or her to give biased, incorrect, or incomplete information to the board. While various methods can be proposed for accomplishing this, the review suggests that the CRO should report directly to the risk committee (with an internal reporting line to the CEO), and be completely independent of the business lines. Additionally, removal of the CRO and the CRO’s compensation would be subject to approval by the board. This arrangement will provide a degree of independence for the CRO, although dual reporting responsibilities will make it difficult to prevent the CRO from being completely insulated from pressure by the CEO.

Additionally, the review was largely silent on the issue of the process for hiring the CRO. If the hiring is done by the CEO, either from internal or external candidates, some degree of the wanted independence may be lost. However, if the board is in charge of the hiring (or has approval power over the hire), current boards may not feel up to the task of rigorously evaluating the credentials of a CRO candidate and may rely heavily on senior management’s recommendations - again possibly losing a degree of the sought-after independence. Hopefully, over time, as board’s skills and confidence in risk management improve, this may become less of an issue.

Read more >>
Posted by Anonymous 2 comments

Tuesday, July 21, 2009

Some thoughts on the Walker Review (continued)

The role of the risk committee

While the specifics of committee structure should remain the responsibility of individual boards, the review’s recommendations concerning the need for a separate risk committee warrants serious consideration. Risk should be a consideration in board’s forward-looking considerations; not as a backward-looking measure - a tendency which may exist when handled under another committee, such as audit. Separating risk from other committee structures should help foster the development of a risk management-prism through which many business decisions – acquisitions, new product and market development, remuneration, etc. – can be viewed.
Having a competent risk committee, however, will require boards to critically evaluate their skill and experience needs and to consider any shortcomings when they develop recruitment and training plans. An empowered risk committee may also encounter resistance at the board level as it involves itself with issues that are typically the purview of other committees (such as compensation). The board chair will be important in this period of transition as he or she will need to lead the board forward in the process of giving the risk committee sufficient breadth of responsibility to not only advise on the development of the bank’s risk appetite but to play an active role in the creation of policies that seek to align employee behavior with it.

Read more >>
Posted by Anonymous 0 comments

Monday, July 20, 2009

Some thoughts on the Walker Review

On Thursday, Sir David Walker, a former chairman of Morgan Stanley International issued a report (at the behest of the UK Prime Minister) entitled “A review of corporate governance in UK banks and other financial industry entities”. This review covers a wide range of issues and offers thirty-nine recommendations in total. While many of the issues addressed in the report warrant comment, over the next few days, I will focus on three:

  1. The “specialness” of banks and the primary responsibility of bank boards to shareholders
  2. The role of the risk committee, and
  3. The independence of the chief risk officer (CRO).

Bank “Specialness”

The special role of banks in the economic and social order introduces unique challenges for a board. As deposit holding, loan granting institutions that retain only a small fraction of the deposits entrusted to them, modern banks are inherently highly leveraged institutions for which the management of financial risk is a fundamental - as opposed to an ancillary or derivative - aspect of their business model. Through their role in trade finance and business and personal credit creation, banks are connected and interconnected in ways that other, non-bank, institutions are not. The failure, or partial failure, of a bank can have a significantly greater impact on the society and economic system in which it exists than, say, the demise of an industrial firm. The possibility of these negative public interest externalities puts significantly greater pressure on bank boards to properly steward their operations.

Despite the important role of banks, the growing pressure from some corners to charge bank boards with statutory responsibilities beyond those owed to shareholders – to include employees, depositors, and/or taxpayers - is rejected in the review. While I do understand the idea that protecting the interests of depositors, taxpayers, and other non-shareholders is an important issue, I agree with Walker that this protection must be attended to via other means and that in order to function effectively a bank board must be explicitly charged with only one master – the shareholder. How then to attend to the proper protection of depositors – and by extension in many cases – to taxpayers?

Improved risk management practices certainly can be expected to afford depositors added protection. If the actions of the board are driven by a desire to benefit shareholders, however, the achieved level of protection may be less than that desired by a depositor. In many modern economies this issue is largely handled through deposit insurance - which has the effect of shifting the ultimate risk in many cases to the taxpayers and renders the depositor as somewhat indifferent to the risk management activities of a given bank. As the discussions of how to improve the risk management of banks, both individually and systematically, advance, it may be beneficial to include in these an evaluation of deposit insurance – the rationale for it, the moral hazards and behavioral effects it introduces, and its proper pricing. Perhaps an improved risk pricing mechanism associated with either public or private deposit insurance could serve a useful purpose in aligning board actions with depositor and taxpayer objectives.

Read more >>
Posted by Anonymous 0 comments

Here are my recommendations for key elements to the solutions.

  1. Everything is standard; the burden of proof is on the institution to prove otherwise. - I have to presume that markets are in fact in favor of central counter-parties, to help mitigate credit risk and operational risk (the system does take new concentration risk). Meanwhile, ensuring that “non-standard” contracts are at least as stringently regulated as standard ones should mitigate incentive to innovate around the regulations.
  2. Institutions must be asked to decompose their “products” into underlying “factors of risk exposure”.
    All exposures, however complex, can be broken down into underlying Market Factors, Terms & Conditions determining payoffs, and Time (this is Derivatives 101).This way, we will get out of the confusing product jargon. A uniform market model for breaking down risk into components means that it can be communicated and aggregated easily across institutions, and across the market as a whole.
  3. A College of Regulators -While the Federal Reserve seems ready to take on the driving regulatory role, there are alternatives with unique merits. A college of regulators could have the mandate to collect and examine inventories and exposures in the market at factor, instrument, product, and player levels, and set alerts to determine how much gross and net exposure warrants attention. This would be a “heat map” of risk levels fed by regular scenario analysis and stress-testing against liquidity, correlations, market risk factor, and macro-economic considerations.
  4. But empower one regulatory voice for the global dialogue -Our financial solutions seek to address issues nationally but the markets and risk are global. The US must appoint one regulator, to be its voice at the international table of regulators. A new systemic regulator is a redundancy. Having said that, the Fed (if it is the chosen one) needs some cultural transformation from the micro to the macro, and in resolving the conflict between monetary policy and supervision, and between regulation of a firm versus the market.
  5. Create additional sharp focus on Liquidity - Liquidity risk remains very little understood and the least developed of all Risk-types. At the height of a crisis, Liquidity risk creates binary outcomes…here today, gone tomorrow. The Regulatory College must develop good perspective for liquidity in markets as a whole.
  6. But above all, smart principle-based Regulation, please - Do recognize there are no guarantees. Smart regulation will not allow players to abdicate risk responsibility to the regulator and the politician. It will instead put the onus firmly on institutions to establish complete and transparent principles, practices, and policies. It is high time that Boards and CEOs, with their CROs, define and articulate their risk appetite (it doesn’t have to be all quantitative); and then prove they have the architecture to implement, support and manage actual risk exposure against appetite & tolerance.


Bottom-line, Regulators must

  • Provide principles and incentives that each firm clearly articulates risk appetite and tolerance
  • Demand disclosure across all stakeholders, including shareholder, investor, and regulator
  • Create aggregate simple metrics for risk at the level of the system
  • Require standards as to what firms do warehouse and trade outside of the standard systems
  • Require strong independent internal risk management structures for reliable measurement, monitoring, reporting and management
  • Provide disincentives to arbitrage out of standardization without curtailing ability to innovate and customize client solutions

It is not going to be easy. There is much rock and many hard places.
Read more >>
Posted by Jaidev Iyer, MD, GARP 0 comments

Thursday, July 16, 2009

Here are my thoughts on the 4 big challenges to derivatives regulation:

1. Markets are always smarter than regulators.

Too much regulation spurs bad innovation. If regulation is onerous, costs of adherence are high, and firms perceive a shift in competitiveness, then expect markets (the good guys and the bad guys) to find ways to circumvent it. Also, much of the day-to-day function at Regulators is focused on magnifying-glass level examination of details; whereas the need here is to have a broader macro-perspective of how “it” all fits together, where “it” is much more than any regulatory form, any individual bank and even the banking system.



2. Are the right products regulated? In the right way?

What is a ‘standard’ derivative, in the context of the move to exchanges and clearing-houses? Standard derivatives didn’t cause the crisis at any individual institution. At a systemic level arguably they did, in the volume and liquidity sense. Complex and exotic products, not regulated because nobody has figured out how, are often the serious offenders.


3. There is as yet no way to measure the overall health, and level of systemic risk, in the market.

Ex-ante, who knows what systemic risk is. Regulators are currently unable to even pull together a comprehensive view of the market. And if we do get a market-level aggregate report, when is the light going to turn from orange to red. Some absolute level decided by the Fed? At the level of each instrument? At the change of the light, will the Fed via individual regulators go back to firms and demand action. What action? And so, are we about to see a hitherto undefined conflict between regulation of an institution versus regulation of the market as a whole?

4. National regulators do not talk to each other, not enough, not effectively

One key lesson from the recent crisis seems to be that risk and flows and financial markets are global, whereas most regulation is national and often nationalistic. This brings another central point to the discussion, a single regulator versus a committee of them.


Read more >>
Posted by Jaidev Iyer, MD, GARP 2 comments

Tuesday, July 14, 2009

Derivative regulation: want a rock or a hard place?

A New Regulatory Regime, and no perfect solution for a problem that is not well defined

Do not envy Tim Geithner. There is simply no chance to get it all right all at once – in form, content, and effectiveness. And the critics have it too easy. Some will call new regulations as not far reaching enough and unable to guarantee against future financial meltdowns. Others will want to preserve complete freedom of the derivatives markets and howl about the baby versus the bathwater. And all will wring hands about market constraints and cost.

Do remember that derivatives before they went toxic, were good creative ways to hedge exposures, to isolate asset allocation decisions from risk decisions, to synthetically overcome barriers to market access. Till parts of the market went rogue, and we had too much of a good thing. And, we also found out that self regulation is a myth in competitive markets in the face of “let’s make revenues Monday, manage costs on Tuesday, and oh let’s do get a Risk report on Wednesday; everybody else is doing it”.


Most will agree ‘some’ incremental regulation is needed. What it will look like, how much of it, and how effective it will be has yet to be defined. The challenge is of course in the balance – we want just the right amount to curb bad innovation, to stifle system-wide blowups, and with incentives for organizations to institutionalize solid risk management principles.



Read more >>
Posted by Jaidev Iyer, MD, GARP 11 comments