Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Risk, Treasury & Financial Control
1Risk Foundations
Risk Appetite, Tolerance, Capacity…The Risk Taxonomy and UniverseRisk Register vs Risk MatrixStress TestingScenario Analysis vs Stress TestingImpact and LikelihoodLikelihoodThe Risk EventRisk Assessment
2Enterprise Risk Management
Enterprise Risk ManagementThe Four Risk TreatmentsRisk CultureRisk MaturityRisk Monitoring
3Risk Governance
Risk GovernanceHow to set a…The Risk PolicyThe Risk OwnerThe Risk Committee and Its CharterThe Risk Limit FrameworkRisk EscalationHow to set a…
4Credit and Counterparty Risk
Collateral AgreementsCollateral vs NettingProbability of DefaultExposureCounterparty ExposureConcentration Risk vs Wrong Way RiskCounterparty Risk vs Credit RiskHow to assess Counterparty ExposureHow to assess Concentration Risk
5Market Risk
Market RiskSensitivity MeasuresThe Hedging PolicyInterest Rate Risk in the Banking BookIRRBB vs Market RiskExpected ShortfallEconomic Value of EquityVaR BacktestingOpen PositionValue at RiskValue at Risk and Expected ShortfallEconomic Value SensitivityFX ExposureValue at Risk vs Expected ShortfallEarnings at Risk vs…FX Transaction Risk vs…How to measure Interest…How to measure Foreign…
6Liquidity Risk
Liquidity Stress TestingLiquidity Gap vs Liquidity BufferMaturity MismatchThe Debt Maturity ProfileFunding ConcentrationSurvival HorizonThe Contingency Funding PlanNet Stable Funding RatioLiquidity Risk vs Funding RiskLiquidity Coverage RatioLiquidity Gap and BufferHow to run a Liquidity Gap Analysis
7Operational Risk
Operational LossThe Loss EventRisk and Control Self AssessmentException ManagementInformation Security as a…Segregation of DutiesIssue ManagementThe Near MissRoot Cause Analysis in RiskThe Fraud TriangleCyber Risk vs Third Party RiskHow to run a…How to assess Third…
8Risk Reporting, Data and Model Risk
Model RiskModel Validation vs BacktestingHow to run Model ValidationData Governance in RiskModel Risk vs Data RiskKey Risk IndicatorsManagement InformationRisk ReportingRisk ScoreEarnings at RiskRisk Adjusted ReturnEarly Warning IndicatorsHow to build a KRI Dashboard
9Treasury
Corporate TreasuryAsset Liability ManagementIntragroup FundingThe Treasury PolicyThe Treasury Management SystemThe Cash ForecastCash Pooling and ConcentrationHow to build a Cash Forecast
10Financial Controls and Assurance
Control AssuranceThe Control LifecycleThe Assurance MapThe Audit FindingIssue RemediationInternal Financial ControlsControl Design vs Control EffectivenessHow to map Internal Financial ControlsHow to test Control…Control DeficiencyMaterial Weakness
11Operational Resilience
Operational ResilienceBusiness Continuity and Disaster RecoveryBusiness Continuity vs Operational…Crisis ManagementDisaster RecoveryIncident Management

The Loss Event: Recording What Actually Went Wrong

A loss event is one failure recorded as one entry, carrying what happened, the process it came out of, its category, its three money columns and its dates. A loss event has more than one date. The date it began, the date it was discovered and the date it was recorded are different dates, and a loss year built on one is a different year from a loss year built on the other.

What is a loss event, and when does something become one?

A household shows the shape of the problem. A tap has been dripping behind a wall for two years. Nobody notices until a patch of damp appears on the ceiling below, a mason is called, and Rs 40,000/- is spent on the repair. When did that loss happen? The money left the house this month. The failure started two years ago. Asked when the damage occurred, the household gives one answer; asked when they paid for it, another; asked when they first knew, a third. Nobody is lying. There are three honest dates attached to one event, and the household never had to choose between them because nobody was keeping a book.

An institution keeps a book, so an institution does have to choose. A loss eventOne operational failure recorded as one entry in the loss record, with its own dates, category, process and money columns. is one operational failure written down as one row in that record. A loss event is not a category, not a trend and not a theme. The entry records a single failure, described well enough that somebody who was not there can tell what happened, with money attached to it and, crucially, with dates attached to it. The moment a failure becomes an entry, somebody has decided which of its dates the row belongs to, and every figure computed from that record afterwards inherits the decision.

Vindhya Commercial Bank Limited, invented for this material, records thirteen operational risk incidents over twelve numbered months, with month 12 as the reporting date. Incident I13 is the entry to open. A trade finance officer and an external party issued 9 letters of credit against forged shipping documents. The scheme ran for fourteen months, ending in month 8, and was discovered when a beneficiary bank claimed. Gross loss Rs 22.4 crore, recovery Rs 7.0 crore, net loss Rs 15.4 crore. The letter of credit itself is named here; what it is and how it pays belongs to a different subject area.

Consider what a row is not. A row is not the sum of several failures that merely felt related. If the same forged document pattern had been presented on other occasions and refused, nothing was lost on those refusals, so they are not part of this row. A row is not a period either. An outage that lasted 4 hours and 20 minutes is one row, and an outage that recurs every month for a year is twelve rows or one row depending on a decision somebody has to make and write down. One failure, one row, and the rule stating what counts as one failure is part of the record rather than a footnote below it.

Derivatives Foundation Bootcamp — Fin Maverick

What has to be on the entry before it is worth keeping?

A loss record with only two columns, a description and an amount, is a list of expensive surprises. Such a list can be totalled and it can be depressing, and it supports very little else. The fields that make it useful are the ones that allow it to be sorted, grouped, and pointed at a year later.

Here is the entry for incident I13 as this invented bank holds it. Read the label column first, then read what sits against it.

ONE LOSS EVENT, ONE ENTRY Incident I13, in the record of an invented bank FIELD WHAT THIS ENTRY CARRIES Reference I13 What happened An officer and an external party issued 9 letters of credit against forged shipping documents Process it came out of PR5 trade finance Category 1, internal fraud, a Basel Committee label Date it began Month minus 5 Date of discovery Month 8, when a beneficiary bank claimed Date of recording Month 8, when the entry was written THREE DATE FIELDS, NOT ONE Gross loss Rs 22.4 crore Recovery Rs 7.0 crore Net loss Rs 15.4 crore Named risk owner Purnima Ganeshan, head of operational risk
Eleven fields carry one entry, and the three separate date fields are the ones a short failure would have collapsed into a single month without anybody noticing.

Every one of those fields does work. The description lets a reader who was not there tell what happened. The process field is what turns a list into a map. The category is a label from the seven the Basel Committee at the Bank for International Settlements publishes, used here as a labelling scheme and taught separately. The three money columns keep gross, recovery and net apart so nobody has to guess which one a headline figure is on. The risk ownerThe named person accountable for the risk the event came out of, recorded on the entry so the record points at somebody. field means the entry points at a person rather than at the building. And the three date fields matter most. A careless record collapses all three of them into one.

Try it out

Why is the field connecting an event to a process the one that makes the record usable later?

How many dates does one loss event have?

Three, and only one of them is usually written on the report. The date it began is when the failure actually started, and for a long-running event the start is a period rather than a day. The date of discoveryWhen the institution first knew the failure had occurred, which can be years after it began. is when the institution first knew. The date of recordingWhen the entry was written into the loss record, which is the date most loss years are actually built on. is when somebody wrote the entry into the book.

For most failures these three sit close enough together that nobody thinks about them. Incident I3 at this invented bank was a core banking outage of 4 hours and 20 minutes on a working day in month 3. The outage began in month 3, was discovered while it was happening in month 3, and was recorded in month 3. Incident I9 was a vendor-hosted payment gateway down for 9 hours in month 9, and 48,000 transactions failed. Same story. Incident I6 ran for eleven days inside month 6, when the rate applied to 6,200 term deposits was 25 basis points above the approved card. Eleven of the thirteen incidents behave like this. A short failure puts all three date fields in the same month and hides them there. A record built only on short failures never discovers that it has a dating problem.

A SHORT FAILURE: INCIDENT I3, CORE BANKING UNAVAILABLE 4 HOURS 20 MINUTES BEGAN, month 3 DISCOVERED, month 3 RECORDED, month 3 ALL THREE IN ONE MONTH A LONG FAILURE: INCIDENT I13, FORGED DOCUMENTS OVER FOURTEEN MONTHS FOURTEEN MONTHS RUNNING BEGAN, month minus 5 DISCOVERED, month 8 RECORDED, month 8 THIRTEEN MONTHS APART
One short failure puts all three of its dates in a single month while one long failure spreads them thirteen months apart on the same record.

Two of the thirteen are not like that at all. Incident I13, category 1, ran fourteen months ending in month 8. Incident I5, also category 1, was a branch officer creating 14 fictitious accounts through which Rs 3.6 crore moved, and it ran twenty two months ending in month 5. Gross Rs 3.6 crore, recovery Rs 0.9 crore, net Rs 2.7 crore. For both of these the three dates are far apart, and the moment they are far apart, the choice of which date the row belongs to stops being a formality.

Try it out

How many dates does one loss event have, and which of them is a loss year usually built on?

Debt Capital Markets Bootcamp — Fin Maverick

Where do the two long-running events in this record actually sit?

The record runs over twelve numbered months and month 12 is the reporting date. No calendar year is stated and no month is named anywhere in it, so the count runs backwards. Incident I13 ran fourteen months ending in month 8. Fourteen months inclusive back from month 8 lands on months minus 5 through 8. Months minus 5, minus 4, minus 3, minus 2, minus 1 and 0 fall before the window opens. Six of the fourteen months, being 42.9 per cent, sit outside it. Eight fall inside.

Incident I5 is worse. Twenty two months ending in month 5 runs from month minus 16 through month 5. Seventeen of those twenty two months, being 77.3 per cent, sit before month 1. Five sit inside. Between them the two frauds ran for thirty six months, of which twenty three fall outside the reporting window entirely, and both of them land inside it at their full value because both are dated by discovery.

THE TWELVE MONTH WINDOW, MONTHS 1 TO 12 INCIDENT I5 17 of 22 months outside 5 inside INCIDENT I13 6 of 14 months outside 8 inside month minus 16 month minus 5 month 1 month 5 month 8 month 12 Pale bar, the months that ran before the window opened. Solid bar, the months inside it. Both entries are dated by discovery. So both land inside the window at their full net value: incident I5 at Rs 2.7 crore and incident I13 at Rs 15.4 crore.
Twenty three of the thirty six months these two frauds ran fall outside the reporting window, yet both entries land inside it whole.
Try it out

Incident I13 ran fourteen months ending in month 8, in a case that runs over twelve numbered months. In which month did it begin, and how many of its months fall inside the window?

What does the same year cost on each basis?

One step of the arithmetic that follows is an assumption rather than something the record supplies. The record says how long each fraud ran and what it cost in total. The record does not say how the loss accrued month by month. Spreading it evenly is a straight line the reader draws, and it stands as an assumption rather than as a measurement.

Incident I13 cost Rs 15.4 crore net over fourteen months, and straight-lined that is Rs 1.10 crore a month exactly. Six of its months sit before the window, so Rs 6.60 crore of it belongs outside. Incident I5 cost Rs 2.7 crore net over twenty two months, or Rs 0.1227 crore a month. Seventeen of its months sit outside the window, so Rs 2.09 crore of it belongs outside. Together that is Rs 8.69 crore.

Basis the year is built onNet operational lossUtilisation of limit L11
Date of recording, the basis this bank reportsRs 43.8 crore73.0 per cent
Date of the event, straight lined across the months each failure ranRs 35.1 crore58.5 per cent
The differenceRs 8.7 crore14.5 points

Limit L11 is this invented bank's own cap of Rs 60.0 crore on net operational loss over a rolling twelve months, sitting under its own appetite clause A7. The cap is a decision by this bank's own board and not a requirement from any authority.

The same thirteen events, the same rupees and the same failures produce two honest loss years Rs 8.7 crore apart, being 19.8 per cent of the reported year and 14.5 percentage points of limit utilisation. Nothing about what went wrong differs between them. Only the question differs.

46.0 42.0 38.0 34.0 30.0 Rs 43.8 crore less Rs 6.60 crore less Rs 2.09 crore Rs 35.1 crore THE YEAR ON THE DATE OF RECORDING incident I13, six months before the window incident I5, seventeen months before it THE YEAR ON THE DATE OF THE EVENT, STRAIGHT LINED 73.0 per cent of limit L11 58.5 per cent of limit L11 Scale starts at Rs 30.0 crore and not at nil, so bar heights show the movement and never the proportion. Straight line accrual across the months each failure ran is the reader's assumption and not a measurement.
The same thirteen events produce two honest loss years Rs 8.7 crore apart, and nothing about the underlying failures differs between them.
Try it out

Two of the thirteen incidents ran for years before they were found. Before the control below is moved: how much of the year's Rs 43.8 crore belongs to months before the window opened?

Play with it

Move the record from one date basis to the other

One control: a, the share of a long-running loss attributed to the months it actually ran rather than to the month it was recorded, from nil to 100 per cent. Two consequences shown together: this invented bank's net operational loss for the year in Rs crore, and what that is as a percentage of limit L11, its own cap of Rs 60.0 crore over a rolling twelve months. Only incidents I13 and I5 move. The other eleven have all three of their dates inside one month. Incident I13 straight lines at Rs 1.10 crore a month with six months outside the window, being Rs 6.60 crore, and incident I5 at Rs 0.1227 crore a month with seventeen outside, being Rs 2.09 crore, so the whole lever is worth Rs 8.686 crore. The solved points are these. At a nil the year is Rs 43.8 crore and 73.0 per cent, exactly what this bank reports. At a 25 per cent, Rs 41.6 crore and 69.4 per cent. At a 50 per cent, Rs 39.5 crore and 65.8 per cent. At a 75 per cent, Rs 37.3 crore and 62.1 per cent. At a 100 per cent, Rs 35.1 crore and 58.5 per cent. The whole range is Rs 8.7 crore and 14.5 percentage points, and no point anywhere on it reaches limit L11: the highest reading on the entire range is the Rs 43.8 crore the bank already reports. The control starts at nil, reproducing this bank's record exactly.

ALL ON THE RECORDING DATEa = 0.0 PER CENTALL ON THE EVENT DATE
Net loss for the year
Rs 43.8 cr
Utilisation of limit L11
73.0%
Moved off the window
Rs 0.00 cr
60.0 50.0 40.0 30.0 LIMIT L11, Rs 60.0 CRORE, THIS BANK'S OWN CAP. THE LINE BELOW NEVER REACHES IT. Rs 43.8 cr, 73.0% Rs 35.1 cr, 58.5% a = 0 25 50 75 100 Share of a long running loss attributed to the months it ran, per cent. Vertical scale starts at Rs 30.0 crore.

Attributing 0.0 per cent of a long-running loss to the months it ran, this bank's year reads Rs 43.8 crore and 73.0 per cent of its own limit L11.

Educational illustration. Spreading a multi-month loss evenly is the reader's own straight line, and the record does not say how either loss accrued. On incident I13 an equally defensible alternative is Rs 15.4 crore over 9 letters of credit, being Rs 1.71 crore each. The alternative puts the loss where the instruments were issued rather than evenly across the months. The eleven other incidents do not move at all. Their three dates fall in one month. The limit of Rs 60.0 crore is this invented bank's own and is not a requirement from anybody.

Is either basis wrong?

No, and this is the part people get impatient with. A colleague who says the date of the event is the correct basis and the date of recording is a fudge has not thought it through. Ask that colleague what this bank's operational loss was for the year on the event basis. Nobody can know yet. There may be a fraud running right now that will be found in month 26 and will belong, on that basis, to months 3 through 20. The event basis can only ever be completed backwards, and it is never complete.

The recording basis has the opposite property. The recording basis can be closed at month end. Everything known by the reporting date is in, everything not yet known is out, and next month's figure does not reach back and change last month's. A basis that can be closed is usable for a limit measured over a rolling twelve monthsA measurement window that moves forward each month rather than resetting at a year end., and limit L11 is exactly that kind of limit. A limit computable only in hindsight is not a limit anybody can run a business against.

The recording basis answers what this institution found out this year, the event basis answers what this year actually produced, and the fault is never the choice between them but a report that makes the choice silently. The basis belongs beside the number, every time. Stating the basis is the whole discipline, and it costs one line.

Try it out

A colleague says the date of the event is the right basis and the date of recording is a fudge. What is wrong with that?

What breaks when nobody states the basis?

Read the twelve month window at this invented bank as a stranger would. The window contains two internal frauds, incident I5 at Rs 2.7 crore net and incident I13 at Rs 15.4 crore net, together Rs 18.1 crore and 41.3 per cent of the year. The obvious reading is that this was a bad year for internal fraud. But both entries are dated by discovery, and between them the two frauds ran for thirty six months of which twenty three fall outside the window entirely, so a year that looks like a year of internal fraud is partly a year of internal fraud discovery, and those are two different claims.

The consequence is not cosmetic. Any measure computed over a rolling twelve months, including limit L11, moves when a long-running event is found, and it moves by the whole amount at once rather than by the part that belongs inside the window. A bank that finds two old frauds in one year reports a bad year. The same bank finding the same two frauds a year apart reports two ordinary ones. Nothing about the underlying failures changed between those two worlds. Only the discovery timing did, and discovery timing is partly a function of how hard the institution was looking. The measure therefore moves in the wrong direction when detection improves.

Turn that around and it gets worse. A very quiet year on a discovery-dated record is consistent with two entirely different situations: nothing much went wrong, or something has been running for eighteen months and nobody has found it. The record cannot tell those apart, and it is the one question a reader most wants answered.

WHAT ACTUALLY HAPPENED WHAT THE RECORD SHOWS 23 months outside the window 13 inside Rs 18.1 crore, category 1 the other Rs 25.7 crore THIRTY SIX MONTHS OF FRAUD RAN, TWENTY THREE OF THEM OUTSIDE ALL OF IT LANDS INSIDE THE WINDOW, BEING 41.3 PER CENT OF THE YEAR A year that looks like a year of internal fraud is partly a year of internal fraud discovery, and those are two different claims. Incident I5 net Rs 2.7 crore and incident I13 net Rs 15.4 crore, against the year of Rs 43.8 crore net. Both are dated by discovery.
Twenty three of the thirty six months these frauds ran fall outside the window, yet the whole Rs 18.1 crore lands inside it.
Try it out

Vindhya Commercial Bank Limited found two old internal frauds in one twelve month window. What does that do to a rolling twelve month measure such as limit L11?

Investment Banking Analyst Bootcamp — Fin Maverick

What does the record show before the recoveries arrive?

The dates are not the only field with a timing problem. The money columns have one too, and it is easier to see.

Incident I2 happened in month 2. A settlement instruction was sent twice and Rs 42 crore left this invented bank twice. The duplicated payment is the largest gross loss of the year by a distance, ahead of incident I13 at Rs 22.4 crore. Then Rs 41.4 crore came back, and the entry settled at a net loss of Rs 0.6 crore. On the net basis that is joint smallest of the year, tied with incident I8 at Rs 0.6 crore. Notice that both of those sentences named the basis before the position. On gross this entry is the biggest event of the year, and on net it sits at the bottom of the list. A reader given the rank without the basis has been told something close to the opposite of the truth.

Between the money leaving and the money returning there is a gap, and the record does not date the return. The gap is the recovery lagThe gap between the money going out and any of it coming back, during which the same event reads as a much larger loss.. While the lag is running the entry is completely honest and reads Rs 42.0 crore. The same entry read at two different moments gives two different numbers, so a loss report has an as-at date as well as a period, and a report that states only the period has left out half of what a reader needs.

INCIDENT I2: ONE SETTLEMENT INSTRUCTION SENT TWICE IN MONTH 2 GROSS Rs 42.0 crore READ BEFORE THE RECOVERY LANDED: LARGEST LOSS OF THE YEAR, ON GROSS RECOVERY Rs 41.4 crore Rs 41.4 crore came back, and this invented case does not date the return. NET Rs 0.6 crore READ AFTER IT LANDED: JOINT SMALLEST OF THE YEAR ON NET, TIED WITH INCIDENT I8 AT Rs 0.6 CRORE All three bars on one scale: the full width is Rs 42.0 crore.
One entry read before and after the recovery lands reports the largest loss of the year on gross and the joint smallest on net.
Try it out

Incident I2 shows gross Rs 42.0 crore and net Rs 0.6 crore. What would the same entry have shown before the recovery arrived, and what does that reveal about a loss report?

Rebalancing: When, Why and What It Costs — free micro-course from Fin Maverick

What does a recording threshold hide?

A small shop shows the same thing. The owner writes down every loss above Rs 500/-: the stolen crate, the water damage, the delivery that never arrived. Below Rs 500/- nothing gets written. A book full of Rs 40/- entries is a book nobody reads. The cut-off is sensible. The cut-off is also invisible in the totals, and asked how many things went wrong last year, the honest answer is not a number of events but a number of events above Rs 500/-.

Institutions do exactly the same thing. A recording thresholdA cut-off below which small losses are not entered individually, which keeps a record readable and removes the smallest events from every count taken on it. keeps a loss record readable and quietly removes the smallest events from every count taken on it. The record does not state a threshold at all, and the absence is worth saying out loud rather than assuming. Every incident count in this guide is a count of thirteen recorded events and not a claim that thirteen things went wrong in the year.

Try two cut-offs on this record to feel the size of it. Neither cut-off is this bank's. The record states none. A cut-off at Rs 1.0 crore would drop incidents I2 and I8, both at Rs 0.6 crore net, removing 2 of 13 entries, being 15.4 per cent of the count and Rs 1.2 crore, being 2.7 per cent of the value. A cut-off at Rs 2.0 crore would drop six entries, incidents I2, I8, I11, I10, I7 and I12, removing 46.2 per cent of the count and Rs 6.9 crore, being 15.8 per cent of the value. Almost half the events, a sixth of the money, and the year still reports as a year.

THE THIRTEEN NET LOSSES OF THE YEAR, IN Rs CRORE, AND TWO CUT-OFFS TRIED ON A cut-off at Rs 1.0 crore removes 2 of 13 entries, being 2.7 per cent of the value B cut-off at Rs 2.0 crore removes 6 of 13 entries, being 15.8 per cent of the value A B I2 I7 I3 I13 Rs 15.4 crore I8 I12 I9 I11 I6 I1 I10 I5 I4 0 2 4 6 8 10 12 14 16 Cut-offs A and B are tried on by the reader. This invented bank states no recording threshold at all, so every count here is a count of thirteen recorded events rather than of everything that went wrong.
A cut-off at Rs 2.0 crore would remove almost half the entries and only a sixth of the money from this same record.
Try it out

What recording threshold does this invented bank apply, and what follows from the answer?

Value at Risk and What It Hides teaches you to compute value at risk three ways, interpret the figure, and say precisely what it refuses to describe.

What makes the record usable a year later?

One field on the entry card above deserves a second look. The process linkThe field connecting an event to the business process it came out of, without which a record of losses cannot become a record of weaknesses. is what stops the record being thirteen unrelated stories. Vindhya Commercial Bank Limited runs nine processes numbered PR1 to PR9, and every entry points at one of them. Incident I13 points at PR5 trade finance. Incident I10, where the collateral valuation feed was stale for 11 working days and 340 loans were wrongly marked, points at PR3 collateral management and valuation.

One entry against PR3 is bad luck. Two entries against PR3 in eighteen months is a sentence about the bank rather than about an incident, and that sentence cannot be written unless somebody filled in the field. Without the process link a loss record is a list of expensive surprises, and with it the same list becomes a description of where this institution is weak. The same is true of the category and the risk owner. Category gives the kind of failure it was on a shared vocabulary. The risk owner gives the person who has to answer for it. The process gives the place to go and look.

Who receives this record, and what can they actually do with it?

Follow one entry after it is written. Purnima Ganeshan, head of operational risk at this invented bank, receives it first, and what she can do with it is limited and specific: check that the fields are complete, check that the process and category are right, and put it into the count that runs against limit L11 for the rolling twelve months. She cannot make the loss smaller. Sunanda Ravikumar, the chief risk officer, sees the total and the movement, and asks whether the year is drifting toward the Rs 60.0 crore cap. Committee G2 sees the utilisation figure and decides whether anything follows.

Now notice what none of them can do without the fields. Nobody can ask whether trade finance is the weak process unless the process link is filled in. Nobody can ask whether this year's total is comparable with last year's unless the date basis is the same on both. The comparison is a question about a field rather than about a total. And nobody outside the institution can read the loss year at all without being told the basis it sits on. The person who receives the record can only ask the questions the fields allow, so the fields are not clerical detail, they are the whole of what the record will ever be able to say.

For a reader outside a risk function the transferable habit is small and blunt. Any operational loss figure deserves two questions before any reaction to the size of it: over what period, and as at what date. The first settles which twelve months. The second settles how many of the recoveries had landed when somebody totalled it. A figure without both is not yet a figure.

Where the rule actually comes from

Naming the bodies, and confirming at source

The mechanism set out here is jurisdiction free. One failure, one entry, a set of fields, three dates and three money columns is how a loss record works anywhere. The obligation sitting above the mechanism is not jurisdiction free. The Basel Committee on Banking Supervision, at the Bank for International Settlements at bis.org, publishes the operational risk framework within which loss data collection sits, and the seven event categories used here as labels are theirs. The Basel framework is the origin and, on its own, it obliges no bank anywhere. The Reserve Bank of India at rbi.org.in sets what an Indian bank must actually collect, keep and report about operational risk events. Any minimum observation period, recording threshold, capital charge, ratio or effective date must be taken from the issuing body. Naming only the global standard and stopping there is the confident and common error.

The subjects that sit outside this guide. The whole-year total, the split across the seven categories and the findings that record is built to carry are handled separately. The near miss, an event that produced no loss and therefore no money columns at all, is handled separately. Root cause analysis asks why the event happened rather than what it cost and when, and it is handled separately too. The self assessment, the control, the exception and the issue each get their own treatment. Control testing, the assurance map, the finding, the deficiency rating and remediation sit in a later sequence that checks what this one designs. Incident response, meaning what somebody actually does while the failure is still running, and escalation and crisis declaration, sit elsewhere again. The letter of credit forged in incident I13 is explained under trade finance.

Risk Management Program Bootcamp — Fin Maverick

Sources

SourceDocumentSite
Bank for International SettlementsThe Basel Committee on Banking Supervision publications setting out the operational risk framework and the seven event categories within which loss data collection sitsbis.org
Reserve Bank of IndiaWhat an Indian bank must actually collect, keep and report about operational risk events, and its requirements on outsourcing and information securityrbi.org.in

Vindhya Commercial Bank Limited, Purnima Ganeshan and Sunanda Ravikumar are invented.
Educational material. Not advice on any investment, tax, budget or market position.

← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.