Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Risk Management Program · CoreTrack
1Risk, Treasury & Financial Control
iRisk Foundations
Risk Appetite, Tolerance, Capacity…The Risk Taxonomy and UniverseRisk Register vs Risk MatrixStress TestingScenario Analysis vs Stress TestingImpact and LikelihoodLikelihoodThe Risk EventRisk Assessment
iiEnterprise Risk Management
Enterprise Risk ManagementThe Four Risk TreatmentsRisk CultureRisk MaturityRisk Monitoring
iiiRisk Governance
Risk GovernanceHow to set a…The Risk PolicyThe Risk OwnerThe Risk Committee and Its CharterThe Risk Limit FrameworkRisk EscalationHow to set a…
ivCredit and Counterparty Risk
Collateral AgreementsCollateral vs NettingProbability of DefaultExposureCounterparty ExposureConcentration Risk vs Wrong Way RiskCounterparty Risk vs Credit RiskHow to assess Counterparty ExposureHow to assess Concentration Risk
vMarket Risk
Market RiskSensitivity MeasuresThe Hedging PolicyInterest Rate Risk in the Banking BookIRRBB vs Market RiskExpected ShortfallEconomic Value of EquityVaR BacktestingOpen PositionValue at RiskValue at Risk and Expected ShortfallEconomic Value SensitivityFX ExposureValue at Risk vs Expected ShortfallEarnings at Risk vs…FX Transaction Risk vs…How to measure Interest…How to measure Foreign…
viLiquidity Risk
Liquidity Stress TestingLiquidity Gap vs Liquidity BufferMaturity MismatchThe Debt Maturity ProfileFunding ConcentrationSurvival HorizonThe Contingency Funding PlanNet Stable Funding RatioLiquidity Risk vs Funding RiskLiquidity Coverage RatioLiquidity Gap and BufferHow to run a Liquidity Gap Analysis
viiOperational Risk
Operational LossThe Loss EventRisk and Control Self AssessmentException ManagementInformation Security as a…Segregation of DutiesIssue ManagementThe Near MissRoot Cause Analysis in RiskThe Fraud TriangleCyber Risk vs Third Party RiskHow to run a…How to assess Third…
viiiRisk Reporting, Data and Model Risk
Model RiskModel Validation vs BacktestingHow to run Model ValidationData Governance in RiskModel Risk vs Data RiskKey Risk IndicatorsManagement InformationRisk ReportingRisk ScoreEarnings at RiskRisk Adjusted ReturnEarly Warning IndicatorsHow to build a KRI Dashboard
ixTreasury
Corporate TreasuryAsset Liability ManagementIntragroup FundingThe Treasury PolicyThe Treasury Management SystemThe Cash ForecastCash Pooling and ConcentrationHow to build a Cash Forecast
xFinancial Controls and Assurance
Control AssuranceThe Control LifecycleThe Assurance MapThe Audit FindingIssue RemediationInternal Financial ControlsControl Design vs Control EffectivenessHow to map Internal Financial ControlsHow to test Control…Control DeficiencyMaterial Weakness
xiOperational Resilience
Operational ResilienceBusiness Continuity and Disaster RecoveryBusiness Continuity vs Operational…Crisis ManagementDisaster RecoveryIncident Management

Operational Loss: Measuring the Cost of a Failure

An operational loss is the money consequence of a failure of process, people or systems, or of an external event. Gross loss is what went out. Recovery is what came back. Net loss is the cost. At Vindhya Commercial Bank Limited, an invented lender, thirteen incidents produced Rs 97.7 crore gross, Rs 53.9 crore of recoveries and Rs 43.8 crore net. The Rs 43.8 crore runs at 73.0 per cent of the bank's own internal limit.

Before any figure in this guide means anything, one separation has to be made, and it is the separation almost every published loss number quietly skips. An operational loss has three columns and not one. Because it is the biggest, the column that reaches a headline is nearly always the first. The column that records what the year actually cost is the third. And the two columns rank the same thirteen events in a different order, so the choice of column is not a presentation decision. The choice of column decides which question the report answers.

What makes a loss an operational one rather than any other kind?

Start with a food stall outside an office building. The stall loses money in three completely different ways, and only one of the three is operational. If the office moves and the lunchtime crowd disappears, that is the business the stall chose and the market turning against it. If a regular customer runs a tab and never pays, that is somebody failing to pay what was owed. But if the gas cylinder runs out at noon on a Tuesday and the stall serves nobody for two hours, nothing about the market changed and nobody defaulted. A process the stall depends on simply did not work. The empty cylinder is the operational loss, and the test that separates it from the other two is not how much it cost but what broke.

An operational lossThe money consequence of a failure of process, people or systems, or of an external event. is the money consequence of a failure of process, people or systems, or of an external event. Read that definition slowly. The definition is a list of causes and not a list of outcomes. A payment sent twice, a system that stops, a rate applied that nobody approved, a document accepted that was forged, water in a branch: these have almost nothing in common in what they look like. All five have one thing in common in where they came from. Something the institution runs, or something the world did to it, failed to work the way it was designed to.

The definition also settles what an operational loss is not, and that matters more than it sounds. A borrower who cannot repay is not an operational loss. Nothing inside the institution failed, and the lending decision may even have been a reasonable one that simply landed badly. A bond that falls in price is not an operational loss either. A price moving is what a price does. Operational risk is the exposure left over once everything the institution was knowingly taking a position on has been taken out. Operational risk is therefore the only exposure an institution earns nothing for carrying. There is a return for taking credit risk and a return for taking market risk. There is no return at all for having a control that does not work.

Every failure here is a design failure, and that changes what is worth looking for. When a settlement instruction leaves twice, the interesting question is not who released it, it is why the arrangement allowed one instruction to be released twice at all. When forged documents pass, the question is why one pair of eyes was enough to let an instrument go out. Naming an individual explains a single event and prevents nothing. Naming the design explains the event and prevents the next one.

Derivatives Foundation Bootcamp — Fin Maverick

Why does one loss need three columns instead of one?

Go back to the food stall. The cylinder ran out, two hours of lunch trade went, say Rs 4,000/-. Then the supplier, who was meant to deliver that morning and did not, knocks Rs 1,500/- off next month's bill. So what did the incident cost? Rs 4,000/- is true and Rs 2,500/- is true, and they answer two different questions. The first answers how big the failure was. The second answers how much the stall is out of pocket. Neither figure is wrong and neither figure is sufficient on its own. A loss record therefore carries three columns and never one.

The three columns are these. Gross lossWhat actually went out of the institution before anything came back. is what actually left, measured before anything came back. RecoveryWhat came back afterwards, from insurance, from a counterparty, from a vendor, or from the person responsible. is what came back afterwards: from insurance, from a counterparty who was overpaid, from a vendor under a contract, or from the person responsible. Net lossGross loss less recovery, being what the event actually cost. is gross less recovery, and it is the only one of the three that answers what the event cost.

A record carrying only gross states the size of the failure and not the bill. A record carrying only net states the bill and hides the size, and the size is what the control was meant to stop. Rs 42.0 crore leaving the bank twice is a failure of a certain magnitude whether or not the money comes back, and a report showing only the Rs 0.6 crore that stuck has quietly reclassified a very large failure as a very small one. The reclassification is not a hypothetical worry. Incident I2 at this invented bank, Rs 42.0 crore gross and Rs 0.6 crore net, does exactly that to anybody who reads one column.

THREE COLUMNS, NOT ONE: THE YEAR AT VINDHYA COMMERCIAL BANK LIMITED, INVENTED All three bars are drawn on one rupee scale. Only the third one answers what the year cost. Rs 97.7 crore GROSS LOSS what left the bank less Rs 53.9 crore RECOVERIES what came back Rs 43.8 crore NET LOSS what the year cost 97.7 less 53.9 = 43.8, and the same subtraction is done once for every incident before it is done for the year. THE SAME THREE COLUMNS FOR ONE EVENT: INCIDENT I2, A SETTLEMENT INSTRUCTION SENT TWICE GROSS LOSS OF INCIDENT I2 Rs 42.0 crore RECOVERY ON INCIDENT I2 Rs 41.4 crore NET LOSS OF INCIDENT I2 Rs 0.6 crore The largest gross loss of the year and one of the two smallest net ones are the same event. One column would have shown either, and never both.
The year at this invented bank builds from Rs 97.7 crore of gross loss less Rs 53.9 crore of recoveries to Rs 43.8 crore net, and the strip beneath shows the identical subtraction on one event, incident I2, where Rs 42.0 crore gross became Rs 0.6 crore of cost.
Risk Management Program Bootcamp — Fin Maverick

What are the seven event categories, and who publishes them?

Thirteen incidents that share nothing but a cause type are hard to think about until they are sorted, and the sorting scheme used almost everywhere in banking is a set of seven labels. Each one is an event categoryOne of seven labels the Basel Committee publishes for sorting operational risk events by what kind of failure produced them., and the seven are published by the Basel Committee on Banking Supervision at the Bank for International Settlements, at bis.org. The seven labels are for sorting rather than for deciding.

The categories are: 1 internal fraud, 2 external fraud, 3 employment practices and workplace safety, 4 clients products and business practices, 5 damage to physical assets, 6 business disruption and system failures, and 7 execution delivery and process management. Read that list once and notice the shape of it. Categories 1 and 2 split fraud by whether the person was inside or outside. Categories 5 and 6 split things that stopped working by whether the thing was physical or a system. Category 7 is where everything that was simply done wrong ends up: a payment sent twice, a rate applied that nobody approved, a feed that went stale. The seven labels sort events by what kind of failure produced them and by nothing else, so two events with the same rupee figure and the same customer impact can and do sit in different categories.

Now the part that gets skipped, and skipping it is the most confident and common error in this whole subject. The Basel Committee is a standard setting body. The Committee publishes the categories and the wider operational risk framework, and on their own the categories oblige an Indian bank to do nothing whatsoever. The Reserve Bank of India, at rbi.org.in, sets what an Indian bank must actually do about operational risk, about outsourcing and about information security. The label scheme is useful and it is not the rule. Naming only the global standard sounds authoritative and is incomplete.

SEVEN LABELS, AND WHERE THIS INVENTED BANK PUT ITS THIRTEEN INCIDENTS The labels sort by what kind of failure produced the event. They are not a ranking and they carry no obligation. CATEGORY 1 internal fraud incidents I5 and I13 CATEGORY 2 external fraud incidents I1 and I7 CATEGORY 3 employment practices and workplace safety incident I11 CATEGORY 4 clients products and business practices incidents I4 and I12 CATEGORY 5 damage to physical assets incident I8 CATEGORY 6 business disruption and system failures incidents I3 and I9 CATEGORY 7 execution delivery and process management incidents I2, I6 and I10 Every one of the thirteen sits in exactly one category, and the counts 2 + 2 + 1 + 2 + 1 + 2 + 3 add to 13, tying to the record. Category 7 carries the most. WHO PUBLISHES THE LABELS The Basel Committee on Banking Supervision at the Bank for International Settlements, bis.org. A standard setter, and on its own it obliges this bank to nothing. WHO SETS WHAT AN INDIAN BANK MUST DO The Reserve Bank of India, rbi.org.in, for operational risk, outsourcing and information security. No ratio, threshold or date from either body is stated here.
The seven event categories published by the Basel Committee sort the invented bank's thirteen incidents into groups of 2, 2, 1, 2, 1, 2 and 3, and the two panels beneath separate who publishes the labels from who sets what an Indian bank must actually do.
Try it out

Who publishes the seven operational risk event categories, and what do they oblige an Indian bank to do?

Try it out

Thirteen incidents, and one of them cost Rs 15.4 crore net out of a year of Rs 43.8 crore. Before the record is opened: what share of the year is that one incident?

What does a whole year of operational loss actually look like?

Here is the record. Vindhya Commercial Bank Limited, invented, recorded thirteen operational risk incidents across twelve numbered months, and every figure in the table below is the bank's own and invented. A loss recordThe set of every operational loss event over a stated period, with its dates, its category and its three money columns. is nothing more exotic than this. One row per event carries the month it happened in, the category it fell in, what happened, and the three money columns. The shape of a year is not visible from any single row, so all thirteen rows have to be read before anything is read about them.

IdMonthCatWhat happenedGrossRecoveryNet
I112Card-not-present fraud on the debit card portfolio6.41.64.8
I227A settlement instruction was sent twice and Rs 42 crore left the bank twice42.041.40.6
I336The core banking system was unavailable for 4 hours and 20 minutes on a working day3.2nil3.2
I444A third party insurance product sold to 1,840 customers without the disclosure the bank's own procedure required, and premiums refunded5.2nil5.2
I551A branch officer created 14 fictitious accounts over twenty two months ending in month 5 and moved Rs 3.6 crore through them3.60.92.7
I667The rate applied to 6,200 term deposits was 25 basis points above the approved card for eleven days2.4nil2.4
I772A phishing campaign against internet banking customers reached 312 customers, who were reimbursed1.80.31.5
I885Flooding at a currency chest branch2.11.50.6
I996A vendor-hosted payment gateway failed for 9 hours and 48,000 transactions failed4.41.23.2
I10107The collateral valuation feed was stale for 11 working days and 340 loans were wrongly marked. No customer lost money1.4nil1.4
I11113An employment tribunal settlement1.2nil1.2
I121242,260 customer complaints were closed without a response being sent, and compensation followed1.6nil1.6
I1381A trade finance officer and an external party issued 9 letters of credit against forged shipping documents over fourteen months ending in month 8, found when a beneficiary bank claimed22.47.015.4
Total13Rs crore, and every column ties97.753.943.8

All figures in Rs crore and all of them invented. The two shaded rows are the largest gross loss of the year, incident I2, and the largest net loss of the year, incident I13. Gross 97.7 less recoveries 53.9 gives net 43.8, and the thirteen net figures add to 43.8 independently.

Two things about that table are worth pausing on before any analysis. The first is that month 8 carries two incidents, I8 and I13, and they have nothing to do with each other. The second is that incident I13 ran for fourteen months ending in month 8, and incident I5 ran for twenty two months ending in month 5, so two of the thirteen rows describe things that were happening long before the year opened and were only found inside it. A loss record dated by month records when the bank learned. When the bank learned is not always when the money went. Which date an entry should carry is a real question with a real answer, and it is covered separately, under the loss event record and its dating.

ONE YEAR OF NET OPERATIONAL LOSS, BAR HEIGHT IS Rs CRORE OF NET LOSS Every bar on this drawing is a net figure. No gross figure appears anywhere on it. incident I13 ran for fourteen months ending in month 8, so it began before month 1 I1 I2 I3 I4 I5 I6 I7 I8 I13 I9 I10 I11 I12 1 2 3 4 5 6 7 8 9 10 11 12 THE TWELVE NUMBERED MONTHS, AND MONTH 12 IS THE REPORTING DATE Month 8 carries two unrelated incidents, I8 at Rs 0.6 crore net and I13 at Rs 15.4 crore net, drawn side by side.
Drawn on net loss, the invented bank's year is one very tall bar and twelve short ones, with incident I13 at Rs 15.4 crore standing more than twice as high as the next largest, incident I4 at Rs 5.2 crore.

Does one incident in thirteen really carry a third of the money?

Look at that drawing again and then count the bars. There are thirteen of them, and by count each incident is one thirteenth of the year, being 7.7 per cent. By value they are nothing of the sort. Incident I13 alone is Rs 15.4 crore of the year's Rs 43.8 crore of net loss, being 35.2 per cent. One event in thirteen, being 7.7 per cent of the count, carries more than a third of the money, and no measure that counts events can see that at all.

The concentration is worth being concrete about. Concentration is the single most important shape in an operational loss record, and it is genuinely counter-intuitive the first time. Told that this bank had thirteen incidents, a reader pictures thirteen roughly comparable problems. Told that it lost Rs 43.8 crore, the same reader divides and pictures thirteen events of about Rs 3.4 crore each. Both pictures are wrong in the same direction. The truth is one event at Rs 15.4 crore and twelve events sharing Rs 28.4 crore between them, and the average of Rs 3.4 crore describes exactly none of the thirteen.

The household version of this is a year with twelve small annoyances and one hospital admission. Counted, the admission is one line in thirteen. Weighed, it is most of what the year cost, and a household budget built by counting problems rather than weighing them will be wrong every time. The reason to insist on this in a bank is that a great deal of operational risk work is naturally organised by count: how many incidents this month, how many issues open, how many findings raised. A count of incidents is useful, and a count is not the cost.

THE SAME INCIDENT, COUNTED AND THEN WEIGHED Both bars are the same total width. Only what fills them changes. BY COUNT: THIRTEEN INCIDENTS, EACH ONE CELL I1 I2 I3 I4 I5 I6 I7 I8 I9 I10 I11 I12 I13 Incident I13 is 1 cell of 13, being 7.7 per cent of the count. BY VALUE: THE YEAR'S Rs 43.8 CRORE OF NET LOSS incident I13 Rs 15.4 crore, 35.2 per cent the other twelve incidents together Rs 28.4 crore, 64.8 per cent The same incident is 35.2 per cent of the value, which is more than four and a half times its share of the count. 15.4 + 28.4 = 43.8, and 35.2 + 64.8 = 100.0. Both bars describe the same thirteen events at the same invented bank.
Incident I13 takes one cell of thirteen when the year is counted, being 7.7 per cent, and 35.2 per cent of the width when the year is weighed, so the two readings of the same record differ by more than four times.

Do gross and net rank the same thirteen events in the same order?

Gross and net produce two different orders, and the difference between the two orders decides what a loss report is worth. Take the thirteen incidents and sort them on gross loss, largest first. The list opens incident I2 at Rs 42.0 crore, incident I13 at Rs 22.4 crore and incident I1 at Rs 6.4 crore. Now sort exactly the same thirteen on net loss. The list opens incident I13 at Rs 15.4 crore, incident I4 at Rs 5.2 crore and incident I1 at Rs 4.8 crore, with incidents I3 and I9 joint fourth at Rs 3.2 crore each. Incident I2 is first on one list and joint twelfth on the other, and nothing about the event changed between the two readings.

One incident followed through both lists shows it. Incident I3, the four hour and twenty minute core banking outage, is seventh by gross at Rs 3.2 crore and joint fourth by net, tied with incident I9, at the same Rs 3.2 crore. Nothing was recovered on incident I3, so its rupee figure did not move at all. Its position moved three places because the events around it moved. A rank is a statement about a population and not about an event, so a position with no basis attached is not a usable fact.

Now think about what this does inside a real meeting. A committee is handed a paper opening with the largest incident of the year, Rs 42.0 crore, incident I2, a settlement instruction sent twice. Rs 42.0 crore is a genuinely alarming number, so the discussion will go there, and it should. A control that let Rs 42.0 crore out twice needs fixing whatever came back. But if that is the only list in the pack, the meeting can end without ever reaching incident I13, the trade finance fraud that cost Rs 15.4 crore and did not come back. The gross list is not wrong; it is answering a question about control failure while the reader thinks it is answering a question about cost.

TWO RANKINGS OF ONE RECORD, DRAWN AS TWO SEPARATE PANELS ON PURPOSE RANKED ON GROSS LOSS scale runs 0 to Rs 42.0 crore RANKED ON NET LOSS scale runs 0 to Rs 15.4 crore 1 I2 42.0 2 I13 22.4 3 I1 6.4 4 I4 5.2 5 I9 4.4 6 I5 3.6 7 I3 3.2 8 I6 2.4 9 I8 2.1 10 I7 1.8 11 I12 1.6 12 I10 1.4 13 I11 1.2 1 I13 15.4 2 I4 5.2 3 I1 4.8 4= I3 3.2 4= I9 3.2 6 I5 2.7 7 I6 2.4 8 I12 1.6 9 I7 1.5 10 I10 1.4 11 I11 1.2 12= I2 0.6 12= I8 0.6 TWO DIFFERENT MEASUREMENTS ON TWO DIFFERENT SCALES. A BAR ON THE LEFT IS NOT COMPARABLE WITH A BAR ON THE RIGHT. Incident I2 in red is first on gross and joint twelfth on net. Incident I3 in green is seventh on gross and joint fourth on net, tied with incident I9.
Ranked on gross the list opens with incident I2 at Rs 42.0 crore, ranked on net it opens with incident I13 at Rs 15.4 crore, and incident I2 falls from first to joint twelfth without a single figure about the event changing.
Try it out

A committee paper ranks the year's incidents and puts incident I2 at the top with Rs 42.0 crore. Which fact has the paper left out?

Common Size and Trend Analysis — free micro-course from Fin Maverick

Does the category with the most incidents cost the most?

The same trap has a second form, and this one hides inside the category column. Sort the thirteen incidents by category and count them, then sort them by category and add up the money. The two orderings disagree, and they disagree in the direction that flatters the busiest category.

Category 7, execution delivery and process management, carries 3 of the 13 incidents, being 23.1 per cent of the count, and it is the busiest category of the year. Its whole net loss for the year is Rs 4.4 crore, being 10.0 per cent of the value: incident I2 at Rs 0.6 crore plus incident I6 at Rs 2.4 crore plus incident I10 at Rs 1.4 crore. Category 1, internal fraud, carries 2 incidents, being 15.4 per cent of the count, and Rs 18.1 crore, being 41.3 per cent of the value. The category producing the most events produced a tenth of the cost, and the category producing the most cost is not in the top three by count.

Be careful with one figure in that paragraph. Two different objects in this record wear it. Rs 4.4 crore is category 7's entire net loss for the year across three incidents. Rs 4.4 crore is also the gross loss of incident I9, a single event, before its Rs 1.2 crore recovery. The two figures are not related, they never combine, and the only protection against confusing them is to name the object every time rather than quoting the number on its own.

CategoryIncidentsCountNet lossShare of value
1 internal fraudI5, I13218.141.3
2 external fraudI1, I726.314.4
3 employment practices and workplace safetyI1111.22.7
4 clients products and business practicesI4, I1226.815.5
5 damage to physical assetsI810.61.4
6 business disruption and system failuresI3, I926.414.6
7 execution delivery and process managementI2, I6, I1034.410.0
Totalall thirteen1343.899.9

Net loss in Rs crore, share of value in per cent, all figures the invented bank's own. The rupee column ties exactly to Rs 43.8 crore and the count column ties exactly to 13. The seven shares are 100.0 per cent of one total, and the seven printed figures add to 99.9 because each was rounded to one decimal place on its own. The residual is one tenth of a point and not an error, and no figure has been adjusted to force the column to add up.

The rounding note deserves a moment. The situation arises constantly, and the wrong instinct is very tempting. When a share column does not add to 100.0, the fastest fix is to nudge one figure. Nudging a figure is the wrong fix. The rupee figures are the measurement and the shares are derived from them, so moving a share to tidy a total makes the printed table disagree with the record it came from. The honest course is to state what happened: seven figures each rounded separately, and a residual of a tenth of a point. A note that explains a rounding residual costs one line and keeps every printed figure true; a silent adjustment saves the line and puts a false number in front of the reader.

COUNT AND VALUE, THE SAME SEVEN CATEGORIES, TWO SEPARATE PANELS The panels measure different things on different scales. Read them one under the other, never bar against bar. PANEL A. HOW MANY INCIDENTS FELL IN EACH CATEGORY, COUNT 2 2 1 2 1 2 3 CAT 1 CAT 2 CAT 3 CAT 4 CAT 5 CAT 6 CAT 7 PANEL B. WHAT EACH CATEGORY COST, NET LOSS IN Rs CRORE 18.1 6.3 1.2 6.8 0.6 6.4 4.4 CAT 1 internal fraud CAT 2 external fraud CAT 3 employment CAT 4 clients and products CAT 5 physical assets CAT 6 disruption CAT 7 execution Category 7 is tallest in panel A at 3 incidents, being 23.1 per cent of the count, and fifth in panel B at Rs 4.4 crore, being 10.0 per cent of the value. Category 1 is joint second in panel A at 2 incidents, being 15.4 per cent of the count, and tallest in panel B at Rs 18.1 crore, being 41.3 per cent of the value.
Category 7 is the tallest bar when the year is counted and the fifth tallest when it is weighed, while category 1 is the reverse, so the busiest category of the year cost a tenth of it and the most expensive one produced two events.
Try it out

Category 7 produced three of the thirteen incidents and category 1 produced two. Which category cost more?

Common Size and Trend Analysis teaches you to make three years of statements comparable and see what moved.

Where do recoveries come from, and how much of a year do they move?

Recoveries are the least examined column in most loss reports and the one that changes the answer the most. Recoveries arrive from four places in this record. Insurance paid on incident I8, the flooded currency chest branch, giving Rs 1.5 crore back on Rs 2.1 crore of gross. A settlement that goes out twice goes to somebody who was not owed it, so a counterparty returned money on incident I2, giving Rs 41.4 crore back on Rs 42.0 crore. A vendor paid under a contract on incident I9, giving Rs 1.2 crore back on Rs 4.4 crore of gross. And money was recovered from the people responsible on incidents I5 and I13, giving Rs 0.9 crore and Rs 7.0 crore back. Everything else came back through the ordinary route of chasing card and payment fraud, on incidents I1 and I7.

Now the arithmetic that matters. The whole-year recovery rateRecovery divided by gross loss, which can be quoted for one event or for a whole population and means different things in each. is Rs 53.9 crore over Rs 97.7 crore, being 55.2 per cent. The 55.2 per cent is a clean, quotable, board-friendly figure, and it describes not one of the thirteen incidents in the record. Six of the thirteen incidents, being I3, I4, I6, I10, I11 and I12, recovered nothing at all. Six in thirteen is 46.2 per cent of the record, and the closest any single incident comes to the average is incident I8 at 71.4 per cent.

The reason is concentration, and it is stark. Incident I2 alone supplied Rs 41.4 crore of the Rs 53.9 crore recovered in the year, being 76.8 per cent of every rupee that came back. One event, out of thirteen, produced three quarters of the year's recoveries. Wherever an average is computed across a population, the question to ask is not whether the arithmetic is right, it is whether the population is concentrated enough that the average has stopped describing any member of it. Here it has, comprehensively.

EVERY INCIDENT'S OWN RECOVERY RATE, AGAINST THE WHOLE-YEAR AVERAGE Each dot is that one incident's recovery divided by its own gross loss. I1 card-not-present fraud 25.0 per cent I2 settlement sent twice 98.6 per cent I3 core banking outage nothing recovered I4 disclosure not given nothing recovered I5 fictitious accounts 25.0 per cent I6 wrong deposit rate nothing recovered I7 phishing campaign 16.7 per cent I8 flooding at a branch 71.4 per cent I9 payment gateway down 27.3 per cent I10 stale valuation feed nothing recovered I11 tribunal settlement nothing recovered I12 complaints not answered nothing recovered I13 forged document sets 31.3 per cent nil 25 50 75 100 THE WHOLE-YEAR RATE IS 55.2 PER CENT AND NO INCIDENT SITS ON IT Recovery rate, per cent of that incident's own gross loss. Six hollow rings mean nothing at all came back.
Six of the thirteen incidents recovered nothing, incident I2 recovered 98.6 per cent of its own gross loss, and the whole-year rate of 55.2 per cent falls in an empty stretch of the scale where no individual incident sits.
Try it out

The year's recovery rate is 55.2 per cent. How many of the thirteen incidents recovered anything close to that?

The failure: a loss report that carries one column

A loss report goes wrong in practice without anybody making a mistake. Somebody builds a loss report for the operational risk management committee. The report ranks the year's incidents by size, largest first. Ranking by size is what a report does. Inside the team that built the report everybody knows the basis, so nobody states it. The paper is one of forty in the committee pack, the committee reads the top three rows, and the discussion is about a settlement instruction that was sent twice.

Every step of that is reasonable and the outcome is still wrong. A reasonable process with a wrong outcome is the definition of a design failure. The committee has spent its time on incident I2, whose net cost was Rs 0.6 crore, and has not reached incident I13, whose net cost was Rs 15.4 crore and which ran for fourteen months before anybody found it. The report did not lie; it answered a different question from the one the reader thought it was answering, and no individual in the chain did anything careless.

The recovery column makes it worse rather than better. An average conceals the concentration underneath it. Quote a 55.2 per cent recovery rate and a reader will assume that roughly half of any future loss comes back. Test that assumption by removing one incident. Take incident I2 out of the population and the remaining twelve show gross Rs 55.7 crore, recoveries Rs 12.5 crore and a recovery rate of 22.4 per cent. The year's net loss falls only from Rs 43.8 crore to Rs 43.2 crore. One incident carries more than three quarters of the year's recoveries and almost none of its net loss, so an average recovery rate quoted without that sentence is a number describing nothing.

The fix is not clever. The fix is three columns, printed together, with the basis named above any ranking and the population named beside any rate. The whole remedy costs nothing but the discipline of writing the label.

TAKE ONE INCIDENT OUT AND WATCH WHICH NUMBER MOVES The upper pair is a rate. The lower pair is money. Removing incident I2 does something very different to each. RECOVERY RATE, PER CENT OF THAT POPULATION'S OWN GROSS LOSS all thirteen 55.2 the other twelve 22.4 NET LOSS, Rs CRORE, BOTH BARS ON ONE SCALE RUNNING TO 50 all thirteen 43.8 the other twelve 43.2 0 25 50 The rate falls by more than thirty percentage points. The money falls by Rs 0.6 crore. The lower two bars are meant to look alike. That is the finding, not a drawing error.
Removing incident I2 collapses the recovery rate from 55.2 per cent to 22.4 per cent while the net loss moves only from Rs 43.8 crore to Rs 43.2 crore, which is what a single concentrated recovery does to an average.
Try it out

Remove incident I2 from the population. How far does the recovery rate move, and how far does the net loss move?

Try it out

Thirteen incidents produced Rs 97.7 crore of gross loss and the bank's own limit on net operational loss is Rs 60.0 crore. Before the control below is moved: how much of that gross would have to come back before the year sits inside the limit?

Play with it

Move the recovery rate and watch the year cross its own limit

One control: r, a single recovery rate applied uniformly to the whole Rs 97.7 crore of gross loss, from nil to 100 per cent. Two consequences shown together: the year's net loss in Rs crore, and what that is as a percentage of limit L11, the invented bank's own cap of Rs 60.0 crore on net operational loss over a rolling twelve months. The relationship is a straight line and every percentage point of recovery removes Rs 0.977 crore of net loss. The solved points are these. At r nil the year costs Rs 97.7 crore, being 162.8 per cent of the limit. At r 20.0 per cent, Rs 78.2 crore and 130.3 per cent. The crossing sits at r 38.6 per cent, Rs 60.0 crore and 100.0 per cent. At r 40.0 per cent, Rs 58.6 crore and 97.7 per cent. At r 55.2 per cent the year costs Rs 43.8 crore and fills 73.0 per cent of the limit, and r 55.2 per cent is the rate this bank recorded. At r 60.0 per cent, Rs 39.1 crore and 65.1 per cent. At r 80.0 per cent, Rs 19.5 crore and 32.6 per cent. At r 100 per cent, nothing. The control starts at 55.2 per cent, reproducing the case exactly.

NOTHING RECOVEREDr = 55.2 PER CENTEVERYTHING RECOVERED
THE CROSSING: r = 38.6 PER CENT below this the year breaches limit L11 WHAT THIS BANK ACTUALLY RECORDED r = 55.2 per cent, Rs 43.8 crore, 73.0 per cent of limit L11 0 20 40 60 80 100 RECOVERY RATE APPLIED UNIFORMLY TO THE WHOLE Rs 97.7 CRORE OF GROSS LOSS, PER CENT 0 25 50 75 100 NET LOSS, Rs CRORE 0 50 100 150 PER CENT OF LIMIT L11 limit L11, Rs 60.0 crore, the bank's own cap the crossing at r = 38.6 per cent what this bank recorded the current reading THE SAME READING DRAWN AS A BAR AGAINST LIMIT L11 Rs 43.8 crore net, 73.0 per cent of limit L11 LIMIT L11, Rs 60.0 CRORE
recovery rate r
55.2%
net loss for the year
Rs 43.8 cr
utilisation of limit L11
73.0%
At a uniform recovery rate of 55.2 per cent the thirteen incidents cost Rs 43.8 crore for the year, which is 73.0 per cent of limit L11 and inside it.
Educational illustration. A uniform recovery rate is a teaching device and not a scenario in this invented case. Six of the thirteen incidents recovered nothing and incident I2 alone supplied 76.8 per cent of every rupee that came back, so recovery in this record is nowhere near uniform and no single rate describes it. The limit of Rs 60.0 crore is Vindhya Commercial Bank Limited's own decision and is not a requirement from any authority.
Debt Capital Markets Bootcamp — Fin Maverick

How does a year of loss get measured against a limit?

A loss figure sitting on its own is a fact without a verdict. The verdict comes from putting it against something the institution decided in advance, and at this invented bank there are two such things stacked one above the other. Appetite clause A7, set by the board, says that net operational loss over a rolling twelve months stays below Rs 60 crore. Limit L11, set by the board risk management committee underneath it, is the working cap of Rs 60.0 crore that somebody measures against every month. The year's Rs 43.8 crore runs at 73.0 per cent utilisationWhat is running against a limit, expressed as a percentage of the limit, where above 100 per cent is a live breach. of limit L11, and it is within.

Three details in that sentence do real work. The first is the word net. The net column runs against the limit, not the gross one. The choice of column is therefore a governance decision and not a formatting one. Had the gross figure of Rs 97.7 crore been the measure, this bank would be reporting 162.8 per cent of its own cap. The second is rolling twelve monthsA measurement window that moves forward each month rather than resetting at a year end.. The window moves forward every month rather than resetting at a year end, so a large loss stays in the reading for twelve months and then drops out, and utilisation can fall with nothing at all improving. A limit measured on a rolling window falls by the passage of time as readily as by any control being fixed, and reading a fall as an improvement without checking which one it was is the standard mistake.

The third is whose figure Rs 60.0 crore is. The Rs 60.0 crore is this invented bank's own, and not a regulatory number, an industry norm or a benchmark. A limit like this is a decision somebody made about how much of this kind of failure the institution is prepared to absorb before the arrangement has to change, and a different board would reasonably set a different number.

WHAT THE YEAR RUNS AGAINST, AND WHOSE DECISION IT IS Both the clause and the limit belong to the invented bank. Neither is a requirement from any authority. APPETITE CLAUSE A7, SET BY THE BOARD Net operational loss over a rolling twelve months stays below Rs 60 crore. cascades into one working limit that somebody measures against every month LIMIT L11, OPERATIONAL LOSS, ROLLING TWELVE MONTHS, Rs 60.0 CRORE Rs 43.8 crore of net loss 73.0 per cent of limit L11, and within it Rs 16.2 crore of headroom left 0 15 30 45 60 Rs CRORE OF NET OPERATIONAL LOSS OVER THE ROLLING TWELVE MONTHS It is the NET column that runs against the limit. The gross figure of Rs 97.7 crore sits off this scale entirely, at 162.8 per cent of the same cap.
The year's Rs 43.8 crore of net loss fills 73.0 per cent of the invented bank's own limit L11 of Rs 60.0 crore under appetite clause A7, leaving Rs 16.2 crore of headroom, while the gross figure would sit off the scale at 162.8 per cent.
Try it out

Which limit does the Rs 43.8 crore run against, and whose figure is that limit?

What does a loss figure not measure?

A rupee figure is one measurement of an event, and it is easy to slide from that into treating it as the measurement. It is not. Incident I3, the core banking outage, makes the point. Its net loss was Rs 3.2 crore, being 7.3 per cent of the year, and that figure answers exactly one question: what it cost. The rupee figure says nothing about the 4 hours and 20 minutes the system was unavailable on a working day, and nothing about how many people could not do what they came to do in that time. Hours of downtime and customers turned away are real measurements of the same event, kept in a different record, and both belong to the resilience subject area.

The same is true in the other direction. Incident I10, the stale collateral valuation feed, cost Rs 1.4 crore and is the smallest net loss but one in the record, and no customer lost money at all. Read on cost alone it is a footnote. Read on what it says about a control, 340 loans wrongly marked for 11 working days because a feed nobody was watching went stale, it is something else entirely. A loss record measures consequence and never significance, and the two come apart most sharply on the cheapest incidents.

There is an arithmetic hazard here as well, and this record is full of them. Incident I3 booked Rs 3.2 crore net and so did incident I9, and they are unrelated events in different months. Incident I2 booked Rs 0.6 crore net and so did incident I8. Two identical numbers in a loss record are almost always two different objects, so the incident has to be named every single time and the bare figure never quoted.

Try it out

Incident I3 booked a net loss of Rs 3.2 crore, being 7.3 per cent of the year. Is that the whole measurement of what incident I3 did?

Who actually reads a loss record, and what do they do with it?

Three people read this record, and each of the three reads it for something different. Watching all three is the fastest way to see what a loss record is actually for.

The head of operational risk reads it for the tail and the gaps. She is not surprised by thirteen incidents; a bank of this size will produce a stream of small execution problems every year and category 7 duly supplied three of them. She is looking for anything in the record large enough to change a decision, and this year exactly one entry qualifies: incident I13 at Rs 15.4 crore net, run over fourteen months by an arrangement where one person could both check a document set and release the instrument. Her question of the record is not what it cost but what the record now obliges the bank to change, and only the largest few entries ever answer that.

A credit analyst at another institution, looking at this bank from outside as a counterparty rather than from inside it, reads the same record for its shape. Rs 43.8 crore of net operational loss against a Rs 96,000 crore balance sheet is a small number, and the analyst is not going to lose sleep over the total. The composition is worth a question on the call: 41.3 per cent of the year in internal fraud, one event running fourteen months before discovery, and a category 7 population of three that suggests execution problems are routine rather than rare. The profile differs from Rs 43.8 crore spread evenly across thirteen ordinary processing errors, and a different profile points at different questions.

The mechanism is identical at every scale, so the household version works the same way. Anybody running a small shop keeps some version of this record in their head: the month the fridge failed, the delivery that was paid twice, the takings that went missing. The discipline that turns that into something usable is exactly the discipline set out here. The money that went out is written down. The money that came back, and where it came from, is written down separately. The one is subtracted from the other. Then, at the end of the year, the list is sorted twice, once by what went out and once by what it cost, and the two lists turn out not to be the same list. Sorting the list twice is the entire method, and the method works on thirteen incidents at a bank and on five at a shop.

India

Where the obligations on operational risk actually come from

The mechanism set out here is jurisdiction free. A failure of process, people or systems, three money columns, a category label and a rolling measurement window work the same way anywhere. Countries differ in what an institution is required to do about any of it, and the sources are named below.

The seven event categories used throughout, and the wider operational risk framework they belong to, are published by the Basel Committee on Banking Supervision at the Bank for International Settlements, bis.org. The Basel Committee is a standard setting body and not an Indian supervisor. Naming only the global standard is the confident and common error in this subject, and it settles nothing about what binds. The Reserve Bank of India, at rbi.org.in, sets what an Indian bank must actually do about operational risk, about outsourcing arrangements and about information security.

Where a loss event carries a conduct dimension, as incidents I4 and I12 do, the duties on customer disclosure and complaint handling also come from the Reserve Bank of India. Where a control failure has to be reported on in the accounts, the duty on internal financial controls sits in the Companies Act, whose text, applicability and exemptions come from the Ministry of Corporate Affairs at mca.gov.in, with the assurance standard from the Institute of Chartered Accountants of India at icai.org. Every capital charge, ratio, minimum, threshold, section number and effective date lives in the issuer's own text, and each issuer changes its own without asking anybody else.

The contents of a single loss event record, and which date it is dated on, meaning the difference between the date the event happened and the date it was recorded, are settled under the loss event record and its dating. The near miss is a separate subject, and so is root cause analysis, the self assessment, the control and the issue. Control testing, the assurance map, the audit finding, the deficiency rating and remediation belong to the financial controls and assurance subject area, the subject that checks what operational risk designs. Business continuity, crisis management, incident response and impact tolerance belong to the resilience subject area, the subject that uses this same loss record and holds those measures. Limit L11, appetite clause A7 and the committee that receives the loss report are governance objects, and governance settles how each of them is set. The letters of credit in incident I13 matter only as the instruments that were forged.

Sources

SourceDocumentSite
Bank for International SettlementsThe Basel Committee on Banking Supervision publications setting out the seven operational risk event categories and the operational risk frameworkbis.org
Reserve Bank of IndiaWhat an Indian bank must actually do about operational risk, outsourcing arrangements, information security, customer disclosure and complaint handlingrbi.org.in
Ministry of Corporate AffairsThe Companies Act duty on internal financial controls, its applicability and the form of the reportmca.gov.in
Institute of Chartered Accountants of IndiaThe assurance standard and guidance note behind reporting on internal financial controlsicai.org

Vindhya Commercial Bank Limited and every counterparty, customer and person in it are invented.
Educational material. Not advice on any investment, tax, budget or market position.

← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.