Operational Loss: Measuring the Cost of a Failure
An operational loss is the money consequence of a failure of process, people or systems, or of an external event. Gross loss is what went out. Recovery is what came back. Net loss is the cost. At Vindhya Commercial Bank Limited, an invented lender, thirteen incidents produced Rs 97.7 crore gross, Rs 53.9 crore of recoveries and Rs 43.8 crore net. The Rs 43.8 crore runs at 73.0 per cent of the bank's own internal limit.
Before any figure in this guide means anything, one separation has to be made, and it is the separation almost every published loss number quietly skips. An operational loss has three columns and not one. Because it is the biggest, the column that reaches a headline is nearly always the first. The column that records what the year actually cost is the third. And the two columns rank the same thirteen events in a different order, so the choice of column is not a presentation decision. The choice of column decides which question the report answers.
What makes a loss an operational one rather than any other kind?
Start with a food stall outside an office building. The stall loses money in three completely different ways, and only one of the three is operational. If the office moves and the lunchtime crowd disappears, that is the business the stall chose and the market turning against it. If a regular customer runs a tab and never pays, that is somebody failing to pay what was owed. But if the gas cylinder runs out at noon on a Tuesday and the stall serves nobody for two hours, nothing about the market changed and nobody defaulted. A process the stall depends on simply did not work. The empty cylinder is the operational loss, and the test that separates it from the other two is not how much it cost but what broke.
An operational lossThe money consequence of a failure of process, people or systems, or of an external event. is the money consequence of a failure of process, people or systems, or of an external event. Read that definition slowly. The definition is a list of causes and not a list of outcomes. A payment sent twice, a system that stops, a rate applied that nobody approved, a document accepted that was forged, water in a branch: these have almost nothing in common in what they look like. All five have one thing in common in where they came from. Something the institution runs, or something the world did to it, failed to work the way it was designed to.
The definition also settles what an operational loss is not, and that matters more than it sounds. A borrower who cannot repay is not an operational loss. Nothing inside the institution failed, and the lending decision may even have been a reasonable one that simply landed badly. A bond that falls in price is not an operational loss either. A price moving is what a price does. Operational risk is the exposure left over once everything the institution was knowingly taking a position on has been taken out. Operational risk is therefore the only exposure an institution earns nothing for carrying. There is a return for taking credit risk and a return for taking market risk. There is no return at all for having a control that does not work.
Every failure here is a design failure, and that changes what is worth looking for. When a settlement instruction leaves twice, the interesting question is not who released it, it is why the arrangement allowed one instruction to be released twice at all. When forged documents pass, the question is why one pair of eyes was enough to let an instrument go out. Naming an individual explains a single event and prevents nothing. Naming the design explains the event and prevents the next one.
Why does one loss need three columns instead of one?
Go back to the food stall. The cylinder ran out, two hours of lunch trade went, say Rs 4,000/-. Then the supplier, who was meant to deliver that morning and did not, knocks Rs 1,500/- off next month's bill. So what did the incident cost? Rs 4,000/- is true and Rs 2,500/- is true, and they answer two different questions. The first answers how big the failure was. The second answers how much the stall is out of pocket. Neither figure is wrong and neither figure is sufficient on its own. A loss record therefore carries three columns and never one.
The three columns are these. Gross lossWhat actually went out of the institution before anything came back. is what actually left, measured before anything came back. RecoveryWhat came back afterwards, from insurance, from a counterparty, from a vendor, or from the person responsible. is what came back afterwards: from insurance, from a counterparty who was overpaid, from a vendor under a contract, or from the person responsible. Net lossGross loss less recovery, being what the event actually cost. is gross less recovery, and it is the only one of the three that answers what the event cost.
A record carrying only gross states the size of the failure and not the bill. A record carrying only net states the bill and hides the size, and the size is what the control was meant to stop. Rs 42.0 crore leaving the bank twice is a failure of a certain magnitude whether or not the money comes back, and a report showing only the Rs 0.6 crore that stuck has quietly reclassified a very large failure as a very small one. The reclassification is not a hypothetical worry. Incident I2 at this invented bank, Rs 42.0 crore gross and Rs 0.6 crore net, does exactly that to anybody who reads one column.
What are the seven event categories, and who publishes them?
Thirteen incidents that share nothing but a cause type are hard to think about until they are sorted, and the sorting scheme used almost everywhere in banking is a set of seven labels. Each one is an event categoryOne of seven labels the Basel Committee publishes for sorting operational risk events by what kind of failure produced them., and the seven are published by the Basel Committee on Banking Supervision at the Bank for International Settlements, at bis.org. The seven labels are for sorting rather than for deciding.
The categories are: 1 internal fraud, 2 external fraud, 3 employment practices and workplace safety, 4 clients products and business practices, 5 damage to physical assets, 6 business disruption and system failures, and 7 execution delivery and process management. Read that list once and notice the shape of it. Categories 1 and 2 split fraud by whether the person was inside or outside. Categories 5 and 6 split things that stopped working by whether the thing was physical or a system. Category 7 is where everything that was simply done wrong ends up: a payment sent twice, a rate applied that nobody approved, a feed that went stale. The seven labels sort events by what kind of failure produced them and by nothing else, so two events with the same rupee figure and the same customer impact can and do sit in different categories.
Now the part that gets skipped, and skipping it is the most confident and common error in this whole subject. The Basel Committee is a standard setting body. The Committee publishes the categories and the wider operational risk framework, and on their own the categories oblige an Indian bank to do nothing whatsoever. The Reserve Bank of India, at rbi.org.in, sets what an Indian bank must actually do about operational risk, about outsourcing and about information security. The label scheme is useful and it is not the rule. Naming only the global standard sounds authoritative and is incomplete.
Who publishes the seven operational risk event categories, and what do they oblige an Indian bank to do?
Thirteen incidents, and one of them cost Rs 15.4 crore net out of a year of Rs 43.8 crore. Before the record is opened: what share of the year is that one incident?
What does a whole year of operational loss actually look like?
Here is the record. Vindhya Commercial Bank Limited, invented, recorded thirteen operational risk incidents across twelve numbered months, and every figure in the table below is the bank's own and invented. A loss recordThe set of every operational loss event over a stated period, with its dates, its category and its three money columns. is nothing more exotic than this. One row per event carries the month it happened in, the category it fell in, what happened, and the three money columns. The shape of a year is not visible from any single row, so all thirteen rows have to be read before anything is read about them.
| Id | Month | Cat | What happened | Gross | Recovery | Net |
|---|---|---|---|---|---|---|
| I1 | 1 | 2 | Card-not-present fraud on the debit card portfolio | 6.4 | 1.6 | 4.8 |
| I2 | 2 | 7 | A settlement instruction was sent twice and Rs 42 crore left the bank twice | 42.0 | 41.4 | 0.6 |
| I3 | 3 | 6 | The core banking system was unavailable for 4 hours and 20 minutes on a working day | 3.2 | nil | 3.2 |
| I4 | 4 | 4 | A third party insurance product sold to 1,840 customers without the disclosure the bank's own procedure required, and premiums refunded | 5.2 | nil | 5.2 |
| I5 | 5 | 1 | A branch officer created 14 fictitious accounts over twenty two months ending in month 5 and moved Rs 3.6 crore through them | 3.6 | 0.9 | 2.7 |
| I6 | 6 | 7 | The rate applied to 6,200 term deposits was 25 basis points above the approved card for eleven days | 2.4 | nil | 2.4 |
| I7 | 7 | 2 | A phishing campaign against internet banking customers reached 312 customers, who were reimbursed | 1.8 | 0.3 | 1.5 |
| I8 | 8 | 5 | Flooding at a currency chest branch | 2.1 | 1.5 | 0.6 |
| I9 | 9 | 6 | A vendor-hosted payment gateway failed for 9 hours and 48,000 transactions failed | 4.4 | 1.2 | 3.2 |
| I10 | 10 | 7 | The collateral valuation feed was stale for 11 working days and 340 loans were wrongly marked. No customer lost money | 1.4 | nil | 1.4 |
| I11 | 11 | 3 | An employment tribunal settlement | 1.2 | nil | 1.2 |
| I12 | 12 | 4 | 2,260 customer complaints were closed without a response being sent, and compensation followed | 1.6 | nil | 1.6 |
| I13 | 8 | 1 | A trade finance officer and an external party issued 9 letters of credit against forged shipping documents over fourteen months ending in month 8, found when a beneficiary bank claimed | 22.4 | 7.0 | 15.4 |
| Total | 13 | Rs crore, and every column ties | 97.7 | 53.9 | 43.8 |
All figures in Rs crore and all of them invented. The two shaded rows are the largest gross loss of the year, incident I2, and the largest net loss of the year, incident I13. Gross 97.7 less recoveries 53.9 gives net 43.8, and the thirteen net figures add to 43.8 independently.
Two things about that table are worth pausing on before any analysis. The first is that month 8 carries two incidents, I8 and I13, and they have nothing to do with each other. The second is that incident I13 ran for fourteen months ending in month 8, and incident I5 ran for twenty two months ending in month 5, so two of the thirteen rows describe things that were happening long before the year opened and were only found inside it. A loss record dated by month records when the bank learned. When the bank learned is not always when the money went. Which date an entry should carry is a real question with a real answer, and it is covered separately, under the loss event record and its dating.
Does one incident in thirteen really carry a third of the money?
Look at that drawing again and then count the bars. There are thirteen of them, and by count each incident is one thirteenth of the year, being 7.7 per cent. By value they are nothing of the sort. Incident I13 alone is Rs 15.4 crore of the year's Rs 43.8 crore of net loss, being 35.2 per cent. One event in thirteen, being 7.7 per cent of the count, carries more than a third of the money, and no measure that counts events can see that at all.
The concentration is worth being concrete about. Concentration is the single most important shape in an operational loss record, and it is genuinely counter-intuitive the first time. Told that this bank had thirteen incidents, a reader pictures thirteen roughly comparable problems. Told that it lost Rs 43.8 crore, the same reader divides and pictures thirteen events of about Rs 3.4 crore each. Both pictures are wrong in the same direction. The truth is one event at Rs 15.4 crore and twelve events sharing Rs 28.4 crore between them, and the average of Rs 3.4 crore describes exactly none of the thirteen.
The household version of this is a year with twelve small annoyances and one hospital admission. Counted, the admission is one line in thirteen. Weighed, it is most of what the year cost, and a household budget built by counting problems rather than weighing them will be wrong every time. The reason to insist on this in a bank is that a great deal of operational risk work is naturally organised by count: how many incidents this month, how many issues open, how many findings raised. A count of incidents is useful, and a count is not the cost.
Do gross and net rank the same thirteen events in the same order?
Gross and net produce two different orders, and the difference between the two orders decides what a loss report is worth. Take the thirteen incidents and sort them on gross loss, largest first. The list opens incident I2 at Rs 42.0 crore, incident I13 at Rs 22.4 crore and incident I1 at Rs 6.4 crore. Now sort exactly the same thirteen on net loss. The list opens incident I13 at Rs 15.4 crore, incident I4 at Rs 5.2 crore and incident I1 at Rs 4.8 crore, with incidents I3 and I9 joint fourth at Rs 3.2 crore each. Incident I2 is first on one list and joint twelfth on the other, and nothing about the event changed between the two readings.
One incident followed through both lists shows it. Incident I3, the four hour and twenty minute core banking outage, is seventh by gross at Rs 3.2 crore and joint fourth by net, tied with incident I9, at the same Rs 3.2 crore. Nothing was recovered on incident I3, so its rupee figure did not move at all. Its position moved three places because the events around it moved. A rank is a statement about a population and not about an event, so a position with no basis attached is not a usable fact.
Now think about what this does inside a real meeting. A committee is handed a paper opening with the largest incident of the year, Rs 42.0 crore, incident I2, a settlement instruction sent twice. Rs 42.0 crore is a genuinely alarming number, so the discussion will go there, and it should. A control that let Rs 42.0 crore out twice needs fixing whatever came back. But if that is the only list in the pack, the meeting can end without ever reaching incident I13, the trade finance fraud that cost Rs 15.4 crore and did not come back. The gross list is not wrong; it is answering a question about control failure while the reader thinks it is answering a question about cost.
A committee paper ranks the year's incidents and puts incident I2 at the top with Rs 42.0 crore. Which fact has the paper left out?
Does the category with the most incidents cost the most?
The same trap has a second form, and this one hides inside the category column. Sort the thirteen incidents by category and count them, then sort them by category and add up the money. The two orderings disagree, and they disagree in the direction that flatters the busiest category.
Category 7, execution delivery and process management, carries 3 of the 13 incidents, being 23.1 per cent of the count, and it is the busiest category of the year. Its whole net loss for the year is Rs 4.4 crore, being 10.0 per cent of the value: incident I2 at Rs 0.6 crore plus incident I6 at Rs 2.4 crore plus incident I10 at Rs 1.4 crore. Category 1, internal fraud, carries 2 incidents, being 15.4 per cent of the count, and Rs 18.1 crore, being 41.3 per cent of the value. The category producing the most events produced a tenth of the cost, and the category producing the most cost is not in the top three by count.
Be careful with one figure in that paragraph. Two different objects in this record wear it. Rs 4.4 crore is category 7's entire net loss for the year across three incidents. Rs 4.4 crore is also the gross loss of incident I9, a single event, before its Rs 1.2 crore recovery. The two figures are not related, they never combine, and the only protection against confusing them is to name the object every time rather than quoting the number on its own.
| Category | Incidents | Count | Net loss | Share of value |
|---|---|---|---|---|
| 1 internal fraud | I5, I13 | 2 | 18.1 | 41.3 |
| 2 external fraud | I1, I7 | 2 | 6.3 | 14.4 |
| 3 employment practices and workplace safety | I11 | 1 | 1.2 | 2.7 |
| 4 clients products and business practices | I4, I12 | 2 | 6.8 | 15.5 |
| 5 damage to physical assets | I8 | 1 | 0.6 | 1.4 |
| 6 business disruption and system failures | I3, I9 | 2 | 6.4 | 14.6 |
| 7 execution delivery and process management | I2, I6, I10 | 3 | 4.4 | 10.0 |
| Total | all thirteen | 13 | 43.8 | 99.9 |
Net loss in Rs crore, share of value in per cent, all figures the invented bank's own. The rupee column ties exactly to Rs 43.8 crore and the count column ties exactly to 13. The seven shares are 100.0 per cent of one total, and the seven printed figures add to 99.9 because each was rounded to one decimal place on its own. The residual is one tenth of a point and not an error, and no figure has been adjusted to force the column to add up.
The rounding note deserves a moment. The situation arises constantly, and the wrong instinct is very tempting. When a share column does not add to 100.0, the fastest fix is to nudge one figure. Nudging a figure is the wrong fix. The rupee figures are the measurement and the shares are derived from them, so moving a share to tidy a total makes the printed table disagree with the record it came from. The honest course is to state what happened: seven figures each rounded separately, and a residual of a tenth of a point. A note that explains a rounding residual costs one line and keeps every printed figure true; a silent adjustment saves the line and puts a false number in front of the reader.
Category 7 produced three of the thirteen incidents and category 1 produced two. Which category cost more?
Where do recoveries come from, and how much of a year do they move?
Recoveries are the least examined column in most loss reports and the one that changes the answer the most. Recoveries arrive from four places in this record. Insurance paid on incident I8, the flooded currency chest branch, giving Rs 1.5 crore back on Rs 2.1 crore of gross. A settlement that goes out twice goes to somebody who was not owed it, so a counterparty returned money on incident I2, giving Rs 41.4 crore back on Rs 42.0 crore. A vendor paid under a contract on incident I9, giving Rs 1.2 crore back on Rs 4.4 crore of gross. And money was recovered from the people responsible on incidents I5 and I13, giving Rs 0.9 crore and Rs 7.0 crore back. Everything else came back through the ordinary route of chasing card and payment fraud, on incidents I1 and I7.
Now the arithmetic that matters. The whole-year recovery rateRecovery divided by gross loss, which can be quoted for one event or for a whole population and means different things in each. is Rs 53.9 crore over Rs 97.7 crore, being 55.2 per cent. The 55.2 per cent is a clean, quotable, board-friendly figure, and it describes not one of the thirteen incidents in the record. Six of the thirteen incidents, being I3, I4, I6, I10, I11 and I12, recovered nothing at all. Six in thirteen is 46.2 per cent of the record, and the closest any single incident comes to the average is incident I8 at 71.4 per cent.
The reason is concentration, and it is stark. Incident I2 alone supplied Rs 41.4 crore of the Rs 53.9 crore recovered in the year, being 76.8 per cent of every rupee that came back. One event, out of thirteen, produced three quarters of the year's recoveries. Wherever an average is computed across a population, the question to ask is not whether the arithmetic is right, it is whether the population is concentrated enough that the average has stopped describing any member of it. Here it has, comprehensively.
The year's recovery rate is 55.2 per cent. How many of the thirteen incidents recovered anything close to that?
The failure: a loss report that carries one column
A loss report goes wrong in practice without anybody making a mistake. Somebody builds a loss report for the operational risk management committee. The report ranks the year's incidents by size, largest first. Ranking by size is what a report does. Inside the team that built the report everybody knows the basis, so nobody states it. The paper is one of forty in the committee pack, the committee reads the top three rows, and the discussion is about a settlement instruction that was sent twice.
Every step of that is reasonable and the outcome is still wrong. A reasonable process with a wrong outcome is the definition of a design failure. The committee has spent its time on incident I2, whose net cost was Rs 0.6 crore, and has not reached incident I13, whose net cost was Rs 15.4 crore and which ran for fourteen months before anybody found it. The report did not lie; it answered a different question from the one the reader thought it was answering, and no individual in the chain did anything careless.
The recovery column makes it worse rather than better. An average conceals the concentration underneath it. Quote a 55.2 per cent recovery rate and a reader will assume that roughly half of any future loss comes back. Test that assumption by removing one incident. Take incident I2 out of the population and the remaining twelve show gross Rs 55.7 crore, recoveries Rs 12.5 crore and a recovery rate of 22.4 per cent. The year's net loss falls only from Rs 43.8 crore to Rs 43.2 crore. One incident carries more than three quarters of the year's recoveries and almost none of its net loss, so an average recovery rate quoted without that sentence is a number describing nothing.
The fix is not clever. The fix is three columns, printed together, with the basis named above any ranking and the population named beside any rate. The whole remedy costs nothing but the discipline of writing the label.
Remove incident I2 from the population. How far does the recovery rate move, and how far does the net loss move?
Thirteen incidents produced Rs 97.7 crore of gross loss and the bank's own limit on net operational loss is Rs 60.0 crore. Before the control below is moved: how much of that gross would have to come back before the year sits inside the limit?
Move the recovery rate and watch the year cross its own limit
One control: r, a single recovery rate applied uniformly to the whole Rs 97.7 crore of gross loss, from nil to 100 per cent. Two consequences shown together: the year's net loss in Rs crore, and what that is as a percentage of limit L11, the invented bank's own cap of Rs 60.0 crore on net operational loss over a rolling twelve months. The relationship is a straight line and every percentage point of recovery removes Rs 0.977 crore of net loss. The solved points are these. At r nil the year costs Rs 97.7 crore, being 162.8 per cent of the limit. At r 20.0 per cent, Rs 78.2 crore and 130.3 per cent. The crossing sits at r 38.6 per cent, Rs 60.0 crore and 100.0 per cent. At r 40.0 per cent, Rs 58.6 crore and 97.7 per cent. At r 55.2 per cent the year costs Rs 43.8 crore and fills 73.0 per cent of the limit, and r 55.2 per cent is the rate this bank recorded. At r 60.0 per cent, Rs 39.1 crore and 65.1 per cent. At r 80.0 per cent, Rs 19.5 crore and 32.6 per cent. At r 100 per cent, nothing. The control starts at 55.2 per cent, reproducing the case exactly.
How does a year of loss get measured against a limit?
A loss figure sitting on its own is a fact without a verdict. The verdict comes from putting it against something the institution decided in advance, and at this invented bank there are two such things stacked one above the other. Appetite clause A7, set by the board, says that net operational loss over a rolling twelve months stays below Rs 60 crore. Limit L11, set by the board risk management committee underneath it, is the working cap of Rs 60.0 crore that somebody measures against every month. The year's Rs 43.8 crore runs at 73.0 per cent utilisationWhat is running against a limit, expressed as a percentage of the limit, where above 100 per cent is a live breach. of limit L11, and it is within.
Three details in that sentence do real work. The first is the word net. The net column runs against the limit, not the gross one. The choice of column is therefore a governance decision and not a formatting one. Had the gross figure of Rs 97.7 crore been the measure, this bank would be reporting 162.8 per cent of its own cap. The second is rolling twelve monthsA measurement window that moves forward each month rather than resetting at a year end.. The window moves forward every month rather than resetting at a year end, so a large loss stays in the reading for twelve months and then drops out, and utilisation can fall with nothing at all improving. A limit measured on a rolling window falls by the passage of time as readily as by any control being fixed, and reading a fall as an improvement without checking which one it was is the standard mistake.
The third is whose figure Rs 60.0 crore is. The Rs 60.0 crore is this invented bank's own, and not a regulatory number, an industry norm or a benchmark. A limit like this is a decision somebody made about how much of this kind of failure the institution is prepared to absorb before the arrangement has to change, and a different board would reasonably set a different number.
Which limit does the Rs 43.8 crore run against, and whose figure is that limit?
What does a loss figure not measure?
A rupee figure is one measurement of an event, and it is easy to slide from that into treating it as the measurement. It is not. Incident I3, the core banking outage, makes the point. Its net loss was Rs 3.2 crore, being 7.3 per cent of the year, and that figure answers exactly one question: what it cost. The rupee figure says nothing about the 4 hours and 20 minutes the system was unavailable on a working day, and nothing about how many people could not do what they came to do in that time. Hours of downtime and customers turned away are real measurements of the same event, kept in a different record, and both belong to the resilience subject area.
The same is true in the other direction. Incident I10, the stale collateral valuation feed, cost Rs 1.4 crore and is the smallest net loss but one in the record, and no customer lost money at all. Read on cost alone it is a footnote. Read on what it says about a control, 340 loans wrongly marked for 11 working days because a feed nobody was watching went stale, it is something else entirely. A loss record measures consequence and never significance, and the two come apart most sharply on the cheapest incidents.
There is an arithmetic hazard here as well, and this record is full of them. Incident I3 booked Rs 3.2 crore net and so did incident I9, and they are unrelated events in different months. Incident I2 booked Rs 0.6 crore net and so did incident I8. Two identical numbers in a loss record are almost always two different objects, so the incident has to be named every single time and the bare figure never quoted.
Incident I3 booked a net loss of Rs 3.2 crore, being 7.3 per cent of the year. Is that the whole measurement of what incident I3 did?
Who actually reads a loss record, and what do they do with it?
Three people read this record, and each of the three reads it for something different. Watching all three is the fastest way to see what a loss record is actually for.
The head of operational risk reads it for the tail and the gaps. She is not surprised by thirteen incidents; a bank of this size will produce a stream of small execution problems every year and category 7 duly supplied three of them. She is looking for anything in the record large enough to change a decision, and this year exactly one entry qualifies: incident I13 at Rs 15.4 crore net, run over fourteen months by an arrangement where one person could both check a document set and release the instrument. Her question of the record is not what it cost but what the record now obliges the bank to change, and only the largest few entries ever answer that.
A credit analyst at another institution, looking at this bank from outside as a counterparty rather than from inside it, reads the same record for its shape. Rs 43.8 crore of net operational loss against a Rs 96,000 crore balance sheet is a small number, and the analyst is not going to lose sleep over the total. The composition is worth a question on the call: 41.3 per cent of the year in internal fraud, one event running fourteen months before discovery, and a category 7 population of three that suggests execution problems are routine rather than rare. The profile differs from Rs 43.8 crore spread evenly across thirteen ordinary processing errors, and a different profile points at different questions.
The mechanism is identical at every scale, so the household version works the same way. Anybody running a small shop keeps some version of this record in their head: the month the fridge failed, the delivery that was paid twice, the takings that went missing. The discipline that turns that into something usable is exactly the discipline set out here. The money that went out is written down. The money that came back, and where it came from, is written down separately. The one is subtracted from the other. Then, at the end of the year, the list is sorted twice, once by what went out and once by what it cost, and the two lists turn out not to be the same list. Sorting the list twice is the entire method, and the method works on thirteen incidents at a bank and on five at a shop.
Where the obligations on operational risk actually come from
The mechanism set out here is jurisdiction free. A failure of process, people or systems, three money columns, a category label and a rolling measurement window work the same way anywhere. Countries differ in what an institution is required to do about any of it, and the sources are named below.
The seven event categories used throughout, and the wider operational risk framework they belong to, are published by the Basel Committee on Banking Supervision at the Bank for International Settlements, bis.org. The Basel Committee is a standard setting body and not an Indian supervisor. Naming only the global standard is the confident and common error in this subject, and it settles nothing about what binds. The Reserve Bank of India, at rbi.org.in, sets what an Indian bank must actually do about operational risk, about outsourcing arrangements and about information security.
Where a loss event carries a conduct dimension, as incidents I4 and I12 do, the duties on customer disclosure and complaint handling also come from the Reserve Bank of India. Where a control failure has to be reported on in the accounts, the duty on internal financial controls sits in the Companies Act, whose text, applicability and exemptions come from the Ministry of Corporate Affairs at mca.gov.in, with the assurance standard from the Institute of Chartered Accountants of India at icai.org. Every capital charge, ratio, minimum, threshold, section number and effective date lives in the issuer's own text, and each issuer changes its own without asking anybody else.
Sources
| Source | Document | Site |
|---|---|---|
| Bank for International Settlements | The Basel Committee on Banking Supervision publications setting out the seven operational risk event categories and the operational risk framework | bis.org |
| Reserve Bank of India | What an Indian bank must actually do about operational risk, outsourcing arrangements, information security, customer disclosure and complaint handling | rbi.org.in |
| Ministry of Corporate Affairs | The Companies Act duty on internal financial controls, its applicability and the form of the report | mca.gov.in |
| Institute of Chartered Accountants of India | The assurance standard and guidance note behind reporting on internal financial controls | icai.org |
Vindhya Commercial Bank Limited and every counterparty, customer and person in it are invented.
Educational material. Not advice on any investment, tax, budget or market position.
