Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Risk, Treasury & Financial Control
1Risk Foundations
Risk Appetite, Tolerance, Capacity…The Risk Taxonomy and UniverseRisk Register vs Risk MatrixStress TestingScenario Analysis vs Stress TestingImpact and LikelihoodLikelihoodThe Risk EventRisk Assessment
2Enterprise Risk Management
Enterprise Risk ManagementThe Four Risk TreatmentsRisk CultureRisk MaturityRisk Monitoring
3Risk Governance
Risk GovernanceHow to set a…The Risk PolicyThe Risk OwnerThe Risk Committee and Its CharterThe Risk Limit FrameworkRisk EscalationHow to set a…
4Credit and Counterparty Risk
Collateral AgreementsCollateral vs NettingProbability of DefaultExposureCounterparty ExposureConcentration Risk vs Wrong Way RiskCounterparty Risk vs Credit RiskHow to assess Counterparty ExposureHow to assess Concentration Risk
5Market Risk
Market RiskSensitivity MeasuresThe Hedging PolicyInterest Rate Risk in the Banking BookIRRBB vs Market RiskExpected ShortfallEconomic Value of EquityVaR BacktestingOpen PositionValue at RiskValue at Risk and Expected ShortfallEconomic Value SensitivityFX ExposureValue at Risk vs Expected ShortfallEarnings at Risk vs…FX Transaction Risk vs…How to measure Interest…How to measure Foreign…
6Liquidity Risk
Liquidity Stress TestingLiquidity Gap vs Liquidity BufferMaturity MismatchThe Debt Maturity ProfileFunding ConcentrationSurvival HorizonThe Contingency Funding PlanNet Stable Funding RatioLiquidity Risk vs Funding RiskLiquidity Coverage RatioLiquidity Gap and BufferHow to run a Liquidity Gap Analysis
7Operational Risk
Operational LossThe Loss EventRisk and Control Self AssessmentException ManagementInformation Security as a…Segregation of DutiesIssue ManagementThe Near MissRoot Cause Analysis in RiskThe Fraud TriangleCyber Risk vs Third Party RiskHow to run a…How to assess Third…
8Risk Reporting, Data and Model Risk
Model RiskModel Validation vs BacktestingHow to run Model ValidationData Governance in RiskModel Risk vs Data RiskKey Risk IndicatorsManagement InformationRisk ReportingRisk ScoreEarnings at RiskRisk Adjusted ReturnEarly Warning IndicatorsHow to build a KRI Dashboard
9Treasury
Corporate TreasuryAsset Liability ManagementIntragroup FundingThe Treasury PolicyThe Treasury Management SystemThe Cash ForecastCash Pooling and ConcentrationHow to build a Cash Forecast
10Financial Controls and Assurance
Control AssuranceThe Control LifecycleThe Assurance MapThe Audit FindingIssue RemediationInternal Financial ControlsControl Design vs Control EffectivenessHow to map Internal Financial ControlsHow to test Control…Control DeficiencyMaterial Weakness
11Operational Resilience
Operational ResilienceBusiness Continuity and Disaster RecoveryBusiness Continuity vs Operational…Crisis ManagementDisaster RecoveryIncident Management

How to assess Third Party Risk, From Onboarding to Exit

Assess it in eight steps and in this order: build the inventory, classify by criticality, assess before contracting, contract for the four terms that carry the risk, onboard and connect, monitor in life against what the arrangement actually does, test the exit, then report. Step one is the one most institutions have not done, and nothing after it works without it.

Start with the ordinary version. The bank version is the same shape at a larger scale. A shop that takes card payments does not run the card machine. Somebody else runs it, somebody the shopkeeper has never met maintains the line it sits on, and on the afternoon it stops working the shop cannot sell anything. Nobody in that shop was careless. The shopkeeper simply bought a service instead of building one. Everybody does that, and in buying it the shopkeeper took on a failure they cannot fix and did not price.

Vindhya Commercial Bank Limited, invented, is that shop at a balance sheet of Rs 96,000 crore. In month 9 a payment gateway hosted by an outside provider stopped working for 9 hours and 48,000 transactions failed. The provider is not named, and the record does not say what caused the failure. The record does state the cost: Rs 4.4 crore gross, Rs 1.2 crore recovered from the provider under the contract, and Rs 3.2 crore net, booked as incident I9. Everything an assessment method is for either happened before that one afternoon or did not happen at all.

In what order should a third party arrangement be assessed?

A third partySomebody the institution contracted with to perform an activity it would otherwise do itself. is anybody the institution contracted with to do something it would otherwise have done itself. The wide definition is deliberate. Every narrow version fails in the same way: an institution that defines third parties as the ones with a technology contract will not have the printer that produces its statements on the list, and an institution that defines them by department will have a different list in every department.

Everything in this method rests on one fact about timing, and holding it makes the order obvious. An arrangement is assessed at two moments, and the second one is far harder than the first. Before contracting there is leverage and no information: nothing has run yet, nobody can say how the service behaves under load, and the institution can still walk away without cost. Afterwards there is information and no leverage: the service is live, customers are on it, the alternative is expensive and slow, and every question has stopped being a condition of the deal and become a request. The eight steps are arranged the way they are so that as much of the assessment as possible happens on the side of the line where the institution can still say no.

THE EIGHT STEPS, AND THE ONE LINE THAT SPLITS THEM The numbering TP1 to TP8 is this material's own. No authority prescribes eight steps or this order. TP1 build the inventory the list of every arrangement, and it comes first STILL FREE TO WALK AWAY TP2 classify by criticality judged against what depends on it, never against its price STILL FREE TO WALK AWAY TP3 assess before contracting while there is still leverage and no live service to protect STILL FREE TO WALK AWAY TP4 contract for the four terms that carry the risk the right to examine, data, sub-contracting, and how it ends STILL FREE TO WALK AWAY THE MOMENT OF CONTRACTING: LEVERAGE IS NOW BEHIND AND INFORMATION IS AHEAD TP5 onboard and connect access, connections, and a named owner on both sides EVERY QUESTION IS NOW A REQUEST TP6 monitor in life against what the arrangement produces, not what it says EVERY QUESTION IS NOW A REQUEST TP7 test the exit exercise it once, or it stays an assumption EVERY QUESTION IS NOW A REQUEST TP8 report what goes up, to whom, and how often EVERY QUESTION IS NOW A REQUEST Steps one to four happen while the institution can still decline the arrangement altogether. Steps five to eight happen when the service is live and the cheapest option is to leave it alone.
The eight steps split at the moment of contracting: above the heavy band the institution can still decline the arrangement altogether, and below it every unanswered question has become a request to a provider that already holds a live service.

What has to exist before any single arrangement can be assessed at all?

Step TP1 is the inventoryThe list of every such arrangement, which has to exist before any of them can be classified or assessed., and it is skipped more often than any other step in this method. The inventory is a list of every arrangement, with the activity it performs, the part of the institution that bought it, and one named person accountable for it. Nothing more elaborate than that, and it is still the step most institutions have not finished.

Here is why it has to come first, and the reason is mechanical rather than tidy-minded. Every step after it operates on a list. Classification operates on a list. Assessment before contracting operates on the classification. Monitoring operates on what classification said mattered. So an institution without an inventory does not skip one step. Such an institution performs all seven of the others on whatever subset it happens to remember. The finance system makes large invoices visible, so the remembered subset is the arrangements with large invoices.

There is a second thing only an inventory can do, and no single contract negotiation can ever reach it. Two separate parts of the institution can buy from the same provider without either knowing, and three separate providers can turn out to sit on the same underlying service. Both of those are concentration in a supplierThe exposure created when many arrangements or many institutions depend on the same provider, which no single contract can reduce and which only the list can reveal.. Each arrangement on its own looks fine, so no individual assessment can see the concentration. The household version is a street of ten shops in one market, all of whom think they have their own electrician, and all of whom have the same one. Concentration is a property of the list and not of any arrangement on it, so an institution with no list cannot see it at all, however carefully it assesses each contract.

Try it out

Why does nothing in this method work until the inventory exists?

How is criticality decided, and against what?

Step TP2 is classification, and criticalityHow much depends on the arrangement, judged against the services the institution has decided matter, and never against the size of the contract. is how much depends on the arrangement. Criticality is judged against the services the institution has already decided matter, a list settled under important business services: how much stops when this arrangement stops, for whom it stops, and how quickly the stopping starts to hurt. None of the three questions has anything to do with money changing hands under the contract.

The commonest error in the whole method lives here, and it is not stupidity, it is availability. The institution grades what it can see, and what it can see is spending. So the arrangement with the biggest invoice gets the deepest assessment, the annual review, the senior sponsor and the escalation route, and the arrangement with the small invoice gets a form. Run that against this bank's own record and the order comes out backwards. 48,000 failed transactions over 9 hours is 5,333 an hour, so the gateway that failed in month 9 was carrying 5,333 transactions an hour. Nothing about that rate is visible in a purchase order.

TWO ARRANGEMENTS, TWO RANKINGS, AND THEY DISAGREE Only the gateway carries figures from the invented bank's record. The other arrangement is illustrative and carries no figure at all. RANKED BY WHAT THE CONTRACT COSTS RANKED BY WHAT DEPENDS ON IT FIRST a large facilities contract the biggest invoice in the file, so it gets the deepest assessment and the senior sponsor FIRST the vendor-hosted payment gateway 5,333 transactions an hour, and Rs 0.4889 crore of gross loss an hour when it stops SECOND the vendor-hosted payment gateway a modest contract, so it gets a form and an annual set of questions SECOND a large facilities contract nothing customers can see stops for an afternoon if it fails, so the hurt starts slowly THE ORDER REVERSES, AND ONLY THE RIGHT-HAND ORDER PREDICTS WHERE THE LOSS CAME FROM Vindhya Commercial Bank Limited is invented and the provider behind the gateway is unnamed and invented.
Ranking the same two arrangements by contract value and by dependence puts them in opposite orders, and the gateway that sat second on price is the one that produced 5,333 failed transactions an hour when it stopped.
Try it out

Two arrangements: one costs ten times as much as the other. Which is more critical?

What can be assessed before contracting, and what only afterwards?

Step TP3 is the pre-contract assessment, and the useful way to think about it is as a race against the loss of leverage drawn in the first figure. Before signing, the answer to a refusal is that the deal does not happen, so the institution can ask for anything. The institution can ask who else the provider serves, whether it depends on anybody the institution also depends on, how it is financed, what its own failure record looks like, where the work is physically done, and who would actually be doing it.

No pre-contract assessment can see the service run. The institution's volumes have never been on the service, so nobody can say how the arrangement behaves on its worst day. So a pre-contract assessment is always an assessment of the provider and never of the service, and the honest way to hold that is to write down what the assessment could not see. The whole point of the contract step that follows is to buy the right to find out later the things that could not be found out now.

Which contract terms are the ones that actually carry the risk?

A contract for a bought service has a great many terms and most of them are about money, timing and blame. Four of them are about risk, and they are the four that decide whether anything in steps five to eight is possible at all.

THE FOUR TERMS THAT CARRY THE RISK Written as ideas, not as clause wording. No clause template, requirement or effective date is stated anywhere here. the right to examine the institution may look at how the other side actually operates WITHOUT IT: ASSERTIONS ONLY data where it sits, who may see it, and what happens to it when this ends WITHOUT IT: NO WAY BACK sub-contracting whether the work may be passed on, to whom, and whether the institution is told WITHOUT IT: UNKNOWN DOER exit how it ends, on whose notice, in what time, and with what help WITHOUT IT: NO ROUTE OUT ALL FOUR ARE NEGOTIABLE BEFORE SIGNING AND ALMOST IMPOSSIBLE TO OBTAIN AFTERWARDS
Four contract terms decide whether later steps are possible at all: examine, data, sub-contracting and exit, each cheap to ask for before signing and each nearly unobtainable once the service is live.

Take them one at a time. The right to examineA contract term letting the institution look at how the other side actually operates, without which monitoring is a set of assertions. is the term that converts monitoring from a conversation into evidence, and it is worth noticing that it is the only one of the four whose value shows up in a different step entirely. An institution that cannot get its data back has no exit whatever the exit clause says, so the data term settles where the data sits, who may see it, and above all what happens to it at the end. The sub-contractingThe term governing whether and to whom the other side may pass the work on, without which the institution does not know who is actually doing it. term matters because an arrangement the institution assessed and an arrangement somebody else is now performing are not the same arrangement, and without this term nobody is told. And the exit arrangementThe agreed route for taking the activity back or moving it, whose only real test is having exercised it. is how this ends, on whose notice, in what time, and with what help from the side that is losing the revenue.

Try it out

Which four contract terms carry the risk?

The fifth term, and it is the one everybody argues about

There is a fifth term that takes up more negotiating time than the other four together, and it is the recovery basisWhether the other side bears a share of a loss or a fixed maximum, which are different contracts that look identical on a small loss.: what the provider pays when its failure costs the institution money. Two shapes are common. One is a share of the loss. The other is a fixed maximum, whatever the loss turns out to be. The two are different contracts, and on a small loss they are impossible to tell apart.

Watch it happen on this bank's own numbers. Incident I9 cost Rs 4.4 crore gross and Rs 1.2 crore came back from the provider. Rs 1.2 crore is 27.3 per cent of Rs 4.4 crore. The recovery is exactly what a 27.3 per cent share would have paid, and exactly what a fixed maximum of Rs 1.2 crore would have paid. The record does not say which contract this was, and on this loss nothing distinguishes them. Now make the failure bigger. At the length that takes this bank's year to its own loss limit, worked out below, the gross loss is about Rs 26.7 crore. A share leaves Rs 19.4 crore of net loss with the bank. A fixed maximum leaves Rs 25.5 crore. A term that makes no difference at all on the loss that happened makes a difference of Rs 6.1 crore on the loss that could.

A SHARE AND A FIXED MAXIMUM, ON TWO SIZES OF THE SAME FAILURE Bars are net loss left with the bank after recovery. Both contracts are the reader's own comparison; the record does not say which one this was. THE LOSS THAT HAPPENED: GROSS Rs 4.4 CRORE A 54.6 HOUR FAILURE: GROSS ABOUT Rs 26.7 CRORE a 27.3 per cent share of the loss Rs 3.2 crore net a fixed maximum of Rs 1.2 crore Rs 3.2 crore net a 27.3 per cent share of the loss Rs 19.4 crore net a fixed maximum of Rs 1.2 crore Rs 25.5 crore net DIFFERENCE: NOTHING AT ALL DIFFERENCE: Rs 6.1 CRORE The bars on the left are drawn to the same length because the two contracts pay the same Rs 1.2 crore on this loss. Every figure belongs to the invented Vindhya Commercial Bank Limited. The provider is unnamed and invented. Rs 26.7 crore is the reader's own extension of the observed rate and is not a loss this bank suffered.
On the loss that actually happened a share and a fixed maximum pay identically, and on a failure five times longer the same two terms differ by Rs 6.1 crore of net loss.
Try it out

The contract recovered Rs 1.2 crore of a Rs 4.4 crore loss. Is that a share of the loss or a fixed maximum, and does it matter here?

Derivatives Foundation Bootcamp — Fin Maverick

What changes at the moment the arrangement goes live?

Step TP5 is onboarding, and it is short because most of what it does is plumbing. Access is granted. Connections are opened. People on both sides are named. The reason it earns a step of its own is that this is the moment the assessment stops being about a company and starts being about a running service, and the institution's own record is about to start producing evidence it will either read or ignore.

Two things belong here and are forgotten with great regularity. The first is that whoever is named as accountable inside the institution has to be a person and not a department, for the same reason a risk owner is a person everywhere else in this subject area. The second is that access granted at onboarding has to be recorded somewhere that a later review will actually look at. An arrangement that goes live without a named accountable person on the institution's side has no reader for any of the evidence steps six to eight will produce.

What makes monitoring real rather than an annual questionnaire?

Monitoring in lifeWatching what the arrangement actually does using data it produces anyway, as distinct from asking the other side questions once a year. is step TP6, and it is where most institutions substitute an activity that looks like monitoring for monitoring. The substitute is the annual questionnaire: a set of questions sent to the provider, answered by the provider, filed by the institution, and read by nobody until something goes wrong. The questionnaire is not worthless. A completed questionnaire is evidence of what the other side says, and that is worth having. No questionnaire is evidence of what the arrangement does.

The alternative is not more questions. Monitoring runs instead on the operational data the arrangement produces anyway: how many transactions it handled, how many failed, how long it took, how often it stopped, how quickly it came back, and how many complaints followed. The operational record exists every day whether anybody reads it or not. The household version is the difference between asking the landlord whether the roof leaks and looking at the ceiling after it rains. Only the second kind of monitoring can contradict the first, and a monitoring arrangement that cannot contradict the provider is not monitoring anything.

TWO THINGS BOTH CALLED MONITORING The right-hand column only exists as evidence because somebody negotiated the right to examine before signing. THE ANNUAL QUESTIONNAIRE WHAT THE ARRANGEMENT PRODUCES WHAT IT IS a set of questions and a set of answers WHAT IT IS volumes, failures, durations, complaints WHO WROTE IT the side being assessed WHO WROTE IT the running service, without being asked HOW OFTEN IT ARRIVES once a year HOW OFTEN IT ARRIVES every day, read or unread ONLY THE RIGHT-HAND COLUMN CAN CONTRADICT THE LEFT, AND THAT IS THE WHOLE DIFFERENCE Neither column is worthless. One is evidence of what is said and the other is evidence of what happened.
A questionnaire is evidence of what the provider says and the operational record is evidence of what the service did, and only the second can ever contradict the first.
Try it out

The institution sends an annual questionnaire and gets it back completed. What does it now know?

Breaking Into Quants Bootcamp — Fin Maverick

Why does the exit have to be tested, and what does an untested exit cost?

Step TP7 is the one institutions defer, and they defer it for a completely rational reason: testing an exit is disruptive, costs real money, annoys the provider, and produces nothing anybody can put in a report except a list of what went wrong. So the exit stays on paper, and everybody involved believes it works.

An untested exit holds an assumption with three parts, and none of them has been checked. How long would the move take. Who exactly would do it, on both sides, with the ordinary work still running. What else depends on this arrangement that nobody has thought of. Every one of the three is a belief until somebody exercises it. The first exercise of an untested exit happens on the day the arrangement has already failed, and that is the worst possible day to discover that the answer to the second question is a person who left last year. Testing an exit does not make the exit work; it converts a belief about the exit into a measurement of it, and that conversion is the only thing that turns a document into a capability.

WHAT IS HELD BEFORE AND AFTER ONE EXERCISE The same clause, the same provider, the same route out. The only difference is whether anybody has ever run it. a documented exit how long it would take: a belief who would do it: a belief what else depends on it: a belief EVIDENCE HELD: NONE to one exercise is the only thing that moves it an exercised exit how long it took: a measurement who did it: a name on both sides what else depends on it: a list EVIDENCE HELD: ONE RUN, AND WHAT BROKE IN IT AN UNTESTED EXIT IS FIRST TESTED ON THE DAY THE ARRANGEMENT HAS ALREADY FAILED Continuity, recovery objectives and crisis declaration are separate subjects and are named here rather than taught.
The same exit clause holds three beliefs before it is exercised and three measurements afterwards, and only one exercise anywhere separates the two positions.
Try it out

The exit route is documented and has never been used. What is actually held?

What goes up, to whom, and what does this record not say?

Step TP8 is reporting, and its content follows from the seven steps above: the number of arrangements, the number graded critical, any of the four contract terms missing on any of them, what the operational record showed, the exits exercised and when, and any incident that happened at a provider. The list is short, and it fits on a single sheet.

The record runs out at exactly this step, and the silence is itself part of the answer. Vindhya Commercial Bank Limited has a policy numbered PL8 for outsourcing and third parties. The record names no committee as its recipient. The record also gives no count of third parties, no criticality grading of any of them, and no cause for the failure in month 9. Four silences. The correct response to a record that does not say who receives the reporting is to report that as a gap, not to assume a committee that the record does not name.

WHAT THIS RECORD SAYS, AND WHAT IT DOES NOT The right-hand column is what the record does not state. STATED IN THE RECORD NOT STATED, AND NOT INVENTED HERE policy PL8 exists for outsourcing and third parties which committee receives it one vendor-hosted gateway failed in month 9 how many third parties there are at all it ran 9 hours and 48,000 transactions failed what caused the failure Rs 4.4 crore gross, Rs 1.2 crore back, Rs 3.2 crore net which service it touched, so nothing is measured against a tolerance FOUR SILENCES, NAMED RATHER THAN FILLED IN, AND NAMING THEM IS PART OF THE METHOD
Four things the record states sit beside four matching things it does not, and every one of the four gaps stays a gap rather than an assumption.
Try it out

Which committee at this bank receives third party and outsourcing reporting?

Risk Management Program Bootcamp — Fin Maverick Bond Pricing and Yield Mechanics — free micro-course from Fin Maverick

What does a failure at a third party actually cost, hour by hour?

Everything above is method. The arithmetic below is what makes the method worth doing, and it is built entirely from figures the record already carries. Incident I9, month 9, of the seven event categories the Basel Committee publishes it sits in the sixth, business disruption and system failures. A payment gateway hosted by an unnamed outside provider failed for 9 hours, 48,000 transactions failed, the gross loss was Rs 4.4 crore, Rs 1.2 crore was recovered from the provider and Rs 3.2 crore was the net loss.

One event is an anecdote. Four divisions turn it into rates, and rates are the only thing anybody can reason with about a failure that has not happened yet. 48,000 over 9 gives 5,333 transactions an hour. Rs 4.4 crore over 9 gives Rs 0.4889 crore of gross loss an hour. Rs 4.4 crore over 48,000 gives Rs 917 per failed transaction. And at the recovery actually achieved, Rs 3.2 crore over 9 gives Rs 0.3556 crore of net loss an hour. Every one of those four is a division on two figures already sitting in the record, and none of them is a new fact about anything.

ONE EVENT, FOUR DIVISIONS, FOUR RATES Nothing below is a new fact. Each tile divides two figures the invented bank's loss record already carries. INCIDENT I9, MONTH 9, CATEGORY 6 9 hours, 48,000 failed transactions, Rs 4.4 crore gross, Rs 1.2 crore recovered, Rs 3.2 crore net TRANSACTIONS AN HOUR 48,000 over 9 hours 5,333 invisible in any purchase order ever written GROSS LOSS AN HOUR Rs 4.4 crore over 9 hours Rs 0.4889 cr before anything comes back from the provider PER FAILED TRANSACTION Rs 4.4 crore over 48,000 Rs 917 the unit the customer side of this is measured in NET LOSS AN HOUR Rs 3.2 crore over 9 hours Rs 0.3556 cr at the recovery this contract actually achieved A RATE IS WHAT LETS ANYBODY REASON ABOUT A FAILURE THAT HAS NOT HAPPENED YET Rs 4.4 crore here is incident I9's gross loss. The same figure is category 7's whole net loss for the year, which is a different object. A real outage does not lose at a constant rate: a queue clears and a backlog compounds. The straight line is the reader's own.
Four divisions on figures the record already carries turn one nine hour event into rates of 5,333 transactions and Rs 0.4889 crore of gross loss an hour.

Now run the length out and watch where it goes. At 1 hour the failure costs 5,333 transactions and Rs 0.49 crore gross. At 2 hours, 10,667 and Rs 0.98 crore. At 9 hours, 48,000 and Rs 4.4 crore, the outage that actually happened. At 12 hours, 64,000 and Rs 5.87 crore. At 24 hours, 1,28,000 and Rs 11.73 crore. Two lengths further out are worth marking. At about 45.8 hours the gross loss reaches Rs 22.4 crore. Rs 22.4 crore is the gross loss of incident I13, the letter of credit fraud and the largest single loss of this bank's year: a provider outage has to run nearly two days to match a fourteen month fraud on a gross basis.

The second crossing is the one that changes how an arrangement is graded. The bank's year of operational loss was Rs 43.8 crore net across thirteen incidents, and its own limit L11 caps that at Rs 60.0 crore over a rolling twelve months. Take incident I9 out and the rest of the year is Rs 40.6 crore. Reaching the limit therefore needs Rs 19.4 crore more of net loss, and at Rs 0.3556 crore an hour that is about 54.6 hours. One arrangement, run by somebody else, failing for about two and a quarter days, takes this bank's entire annual operational loss to its own limit. The 54.6 hour figure is what step TP2 exists to produce and step TP7 exists to make survivable, and neither step is about the contract at all.

RUNNING THE SAME FAILURE OUT PAST THE LENGTH THAT HAPPENED Both lines are the observed rate extended in a straight line. The other twelve incidents are held still at Rs 40.6 crore. GROSS LOSS OF THE OUTAGE, Rs CRORE 0 10 20 30 Rs 22.4 CRORE, THE GROSS LOSS OF INCIDENT I13 9 HOURS, Rs 4.4 CRORE, WHAT HAPPENED 45.8 HOURS 0 12 24 36 48 60 THE YEAR'S NET OPERATIONAL LOSS, Rs CRORE, ALL THIRTEEN INCIDENTS 40 45 50 55 60 LIMIT L11, Rs 60.0 CRORE, THE BANK'S OWN CAP 9 HOURS, Rs 43.8 CRORE, 73.0 PER CENT OF THE LIMIT 54.6 HOURS, ABOUT TWO AND A QUARTER DAYS 0 12 24 36 48 60 OUTAGE LENGTH IN HOURS Limit L11 is the invented bank's own cap and is not any regulatory figure. The provider is unnamed and invented.
Extended at the observed rate, the failure matches the year's largest fraud on gross at about 45.8 hours and takes the whole year's net loss to the bank's own Rs 60.0 crore cap at about 54.6 hours.
Try it out

Did this nine hour outage breach any of the institution's service tolerances?

Try it out

This outage ran 9 hours and cost Rs 3.2 crore net. Before the control below is moved: how long would it have to run to take the bank's whole year to its own Rs 60.0 crore limit?

Play with it

Run the outage longer and watch the year walk up to the limit

One control: the length of the failure in hours, from 0 to 60. Three things move together: how many transactions fail, what the outage costs gross, and where the bank's whole year of operational loss ends up with the other twelve incidents held still at Rs 40.6 crore. The default is 9 hours, the outage that actually happened: 48,000 failed transactions, Rs 4.4 crore gross, Rs 1.2 crore recovered from the unnamed provider and Rs 3.2 crore net, inside a year of Rs 43.8 crore at 73.0 per cent of limit L11.

0 HOURS9.0 HOURS60 HOURS
ONE FAILURE, THREE CONSEQUENCES, DRAWN AT THE OBSERVED RATE FAILED TRANSACTIONS 48,000 GROSS LOSS OF THE OUTAGE Rs 22.4 CRORE, INCIDENT I13 GROSS Rs 4.4 crore THE YEAR'S NET OPERATIONAL LOSS, SCALE Rs 40 TO Rs 62.5 CRORE LIMIT L11, Rs 60.0 CRORE Rs 43.8 crore THE OUTAGE LENGTH ON A 0 TO 60 HOUR SCALE 9.0 HOURS 9 h, what happened 45.8 h, matches incident I13 on gross 54.6 h, the year reaches limit L11 The loss is assumed to run at the rate the observed nine hours produced. That straight line is the reader's own and not a measurement. Recovery is held at the observed 27.3 per cent share. The record does not say whether the contract was a share or a fixed maximum. No service tolerance is computed anywhere, because the record does not say which service the outage touched.
Failed transactions
48,000
Gross loss
Rs 4.4 cr
The year's net loss
Rs 43.8 cr
Utilisation of limit L11
73.0 per cent

An outage of 9.0 hours fails 48,000 transactions and costs Rs 4.4 crore gross, taking this bank's year to Rs 43.8 crore, being 73.0 per cent of its own limit L11.

Educational illustration. Invented figures throughout. Limit L11 is the bank's own cap rather than any regulatory figure, and the other twelve incidents are held still at Rs 40.6 crore. A queue clears and a backlog compounds, so a real outage does not lose at a constant rate: the straight line sits above the real loss early and below it once a backlog builds.

Four failures, and the first one causes the other three

The first failure is that step TP1 never finished, and everything downstream inherits it. An institution that cannot list its arrangements cannot classify them, so it classifies the ones it happens to know about, and those are the ones with large invoices.

The second follows immediately and is the commonest of the four: criticality graded by contract value rather than by what depends on the arrangement. A gateway can be a modest contract carrying 5,333 transactions an hour, and a large contract can carry nothing that matters for an afternoon, so grading by invoice size sorts the list in almost exactly the wrong order.

The third is monitoring as a questionnaire. An annual set of questions answered by the other side tells the institution what the other side says. Two things would tell it what is actually happening. The right to examine is settled at step TP4 and cannot be obtained later. The operational data the arrangement itself produces arrives every day and is usually unread.

The fourth is the untested exit, and it is the expensive one. An exit that has never been exercised is an assumption about how long something would take and who would do it, and it is discovered to be wrong at exactly the moment it is needed. None of the four is carelessness. Each one is a reasonable local decision, and each looks wrong only from the list, so the list has to exist first.

An outage at a third party costs by the hour. See how much.

Who actually uses this method, and what do they do with it?

Three different readers pick this up for three different things. The head of operational risk inside the institution, Purnima Ganeshan in this invented case, uses it as a queue: the inventory tells her how many arrangements there are, criticality tells her which ten to look at this quarter, and the exit test schedule tells her which of those ten she still cannot say anything honest about. She is not trying to assess everything. She is trying to make sure the order of assessment is not set by invoice size.

A credit analyst at another institution, looking at Vindhya Commercial Bank Limited as a counterparty rather than as an employer, uses it differently. The analyst cannot see the inventory and would not be given it. The analyst can ask one question with a very informative answer: has any exit ever been exercised, and what did it take. An institution that has exercised one can state a duration. An institution that has not will talk about its policy. The gap between those two answers is the whole of what this method delivers, and it is audible in one question.

Take the household version. The mechanism does not change with scale. A person whose salary, savings and borrowing all sit at one place has one arrangement carrying everything, and the size of the fees tells them nothing about that. A caterer whose only refrigeration is a rented unit has one supplier who can end a wedding. In both cases the useful question is not whether the provider is reputable. The useful question is what stops, how fast it starts to hurt, and whether anybody has ever tried the alternative even once.

India

What is named here, and where the binding version lives

No authority prescribes eight steps, or this order, or these four contract terms as a set, and the labels TP1 to TP8 are a numbering convention rather than anything a regulator publishes. Every figure, incident, policy and limit belongs to Vindhya Commercial Bank Limited and to nothing else.

One international standard sits behind the classification used above: the operational risk framework published by the Basel Committee on Banking Supervision at the Bank for International Settlements, bis.org. The seven event categories that place the month 9 failure in business disruption and system failures come from that framework. The Basel framework is the origin of the classification and not what binds anybody.

The rules that actually bind an Indian bank on outsourcing, on arrangements with third parties and on technology service providers come from the Reserve Bank of India at rbi.org.in. Where the institution is a market intermediary rather than a bank, the equivalent expectations come from the Securities and Exchange Board of India at sebi.gov.in.

The wording of these requirements moves, and only the text the regulator itself has published binds anybody.

The separation of cyber risk from third party risk is covered separately and used here as understood, as is information security. The impact tolerance, the recovery time objective, the recovery point objective, the important business services, business continuity, disaster recovery and crisis declaration all belong to the resilience material: they are the objects criticality is judged against at steps TP2 and TP7. The record does not say which service the month 9 failure touched, so no tolerance breach can be computed for it. Control testing, the audit finding, the deficiency rating and remediation are covered separately. The outsourcing policy itself, its owner and its approver, and the committee structure, belong to the governance material.

Sources

SourceDocumentSite
Reserve Bank of IndiaWhat actually binds a bank in India on outsourcing, arrangements with third parties and technology service providersrbi.org.in
Bank for International SettlementsThe Basel Committee operational risk framework and the seven event categories used to classify a lossbis.org
Securities and Exchange Board of IndiaThe equivalent expectations where the regulated institution is a market intermediary rather than a banksebi.gov.in

Vindhya Commercial Bank Limited, Purnima Ganeshan and the unnamed provider behind the failed payment gateway are invented, along with every incident, policy, limit and figure attributed to them.
Educational material. Not advice on any investment, tax, budget or market position.

Framework

Other frameworks in Operational Risk

Framework

How to run a Risk and Control Self Assessment

← Previous
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.