Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Risk, Treasury & Financial Control
1Risk Foundations
Risk Appetite, Tolerance, Capacity…The Risk Taxonomy and UniverseRisk Register vs Risk MatrixStress TestingScenario Analysis vs Stress TestingImpact and LikelihoodLikelihoodThe Risk EventRisk Assessment
2Enterprise Risk Management
Enterprise Risk ManagementThe Four Risk TreatmentsRisk CultureRisk MaturityRisk Monitoring
3Risk Governance
Risk GovernanceHow to set a…The Risk PolicyThe Risk OwnerThe Risk Committee and Its CharterThe Risk Limit FrameworkRisk EscalationHow to set a…
4Credit and Counterparty Risk
Collateral AgreementsCollateral vs NettingProbability of DefaultExposureCounterparty ExposureConcentration Risk vs Wrong Way RiskCounterparty Risk vs Credit RiskHow to assess Counterparty ExposureHow to assess Concentration Risk
5Market Risk
Market RiskSensitivity MeasuresThe Hedging PolicyInterest Rate Risk in the Banking BookIRRBB vs Market RiskExpected ShortfallEconomic Value of EquityVaR BacktestingOpen PositionValue at RiskValue at Risk and Expected ShortfallEconomic Value SensitivityFX ExposureValue at Risk vs Expected ShortfallEarnings at Risk vs…FX Transaction Risk vs…How to measure Interest…How to measure Foreign…
6Liquidity Risk
Liquidity Stress TestingLiquidity Gap vs Liquidity BufferMaturity MismatchThe Debt Maturity ProfileFunding ConcentrationSurvival HorizonThe Contingency Funding PlanNet Stable Funding RatioLiquidity Risk vs Funding RiskLiquidity Coverage RatioLiquidity Gap and BufferHow to run a Liquidity Gap Analysis
7Operational Risk
Operational LossThe Loss EventRisk and Control Self AssessmentException ManagementInformation Security as a…Segregation of DutiesIssue ManagementThe Near MissRoot Cause Analysis in RiskThe Fraud TriangleCyber Risk vs Third Party RiskHow to run a…How to assess Third…
8Risk Reporting, Data and Model Risk
Model RiskModel Validation vs BacktestingHow to run Model ValidationData Governance in RiskModel Risk vs Data RiskKey Risk IndicatorsManagement InformationRisk ReportingRisk ScoreEarnings at RiskRisk Adjusted ReturnEarly Warning IndicatorsHow to build a KRI Dashboard
9Treasury
Corporate TreasuryAsset Liability ManagementIntragroup FundingThe Treasury PolicyThe Treasury Management SystemThe Cash ForecastCash Pooling and ConcentrationHow to build a Cash Forecast
10Financial Controls and Assurance
Control AssuranceThe Control LifecycleThe Assurance MapThe Audit FindingIssue RemediationInternal Financial ControlsControl Design vs Control EffectivenessHow to map Internal Financial ControlsHow to test Control…Control DeficiencyMaterial Weakness
11Operational Resilience
Operational ResilienceBusiness Continuity and Disaster RecoveryBusiness Continuity vs Operational…Crisis ManagementDisaster RecoveryIncident Management

The Risk Event: What Counts, and When It Is Recorded

A risk event is something that has actually happened. A risk is something that might. An event counts whether or not it cost money: a failure caught before it caused a loss carries the same information as one that was not. And every event has two dates, the date it occurred and the date it was recorded. The two dates are frequently different and never interchangeable.

Everything else in this part of the subject deals in things that might happen. Sizes are estimated, chances are argued over, and a careful reader learns to hold every number loosely. A record of events deals in things that did happen, and the discipline is completely different. An event record estimates nothing and defines everything. Three choices define it: what counts, when it is written down, and what is left out on purpose. Each choice quietly decides what the institution will later be able to learn from its own history.

The worked case throughout is Vindhya Commercial Bank Limited, an invented mid-sized Indian commercial bank with a balance sheet of Rs 96,000 crore. Over twelve numbered months it collected eighteen events: thirteen incidents numbered I1 to I13 with a loss attached, and five near misses numbered N1 to N5 with none. Every figure below is that invented bank's own. Eighteen rows in one file carry the whole argument, and what any single row is for is worth settling.

What is a risk event, and what makes something one?

The smallest possible distinction comes first. Nothing else in the subject is this simple. A risk eventSomething that has actually happened, as against a risk, which is something that might. is a risk in the past tense. The tense is the whole of it. A risk is something that might happen and therefore carries an estimate: an estimate of how big it would be and an estimate of how likely it is. An event is something that did happen and therefore carries no estimate at all. An event carries a date, an owner, an amount and a consequence. The line between a risk and an event is about tense and nothing else, and it is the only distinction in this part of the subject that is.

Here is the everyday version. A person who cycles to work every day has a risk: they might come off the bicycle. The risk has a size, roughly, and a chance, roughly, and reasonable people can disagree about both. On a wet Tuesday in June they come off the bicycle and break a wrist. The broken wrist is an event. There is nothing left to estimate. There is a date, a cost, a cause and a consequence, and no amount of arguing about how likely it was changes any of them. The risk and the event are the same subject, and they live in two different records because two different questions are being asked of them.

The same is true at Rs 96,000 crore. Inside this bank the collateral valuation control appears in two places at once. On the risk register it is a red entry: a control that might fail, sized and rated by people who are guessing. In the loss record it is incident I10, month 10, a valuation feed that was stale for 11 working days, 340 loans wrongly marked, and a net loss of Rs 1.4 crore. Same subject, same institution, same week. One row is a forecast about the future and the other is a report about the past, and a reader who does not know which one they are holding will misread both.

THE SAME SUBJECT, TWO TENSES, TWO RECORDS Every field below is either an estimate about the future or a fact about the past, and no field is both. A RISK: SOMETHING THAT MIGHT HAPPEN carries an estimate of how big it would be carries an estimate of how likely it is has no date, because it has not happened can be argued about, and often is sits on the register IN THIS BANK the collateral valuation control, rated red AN EVENT: SOMETHING THAT DID HAPPEN carries an amount, not an estimate carries two dates, and they differ has an owner and a consequence cannot be argued about, only found late sits in the loss record IN THIS BANK the same control, month 10, incident I10 ONE SUBJECT CAN SIT IN BOTH RECORDS ON THE SAME DAY A feed that might go stale is a risk. A feed that was stale for 11 working days is an event, and it cost Rs 1.4 crore net.
A risk carries two estimates and no date while an event carries an amount and two dates, and the invented bank's collateral valuation control sits in both records at once as a red rating and as incident I10.

Why labour a distinction this small? Because institutions get it wrong in one specific direction, and the wrongness is expensive. Institutions treat the event record as a scorecard for the register. Somebody notices that a risk rated as unlikely has now happened twice, and concludes that the rating was bad. Sometimes it was. But an unlikely thing happening is exactly what unlikely means, and a register that never rates anything unlikely is not a better register, it is a more frightened one. The event record is not a mark scheme for the register. The record is a separate body of evidence the register may draw on, and the drawing takes judgement.

Try it out

What separates a risk from a risk event?

Does an event have to cost money to count?

No, and this is where most event records go wrong before they have collected anything. Cost is the field that is easiest to fill in and the only field anybody asks about at the year end, so the instinct is to define an event by its cost. Follow that instinct and the record becomes a list of the failures that happened to be expensive. A list of expensive failures is a different and much less useful object.

Four different kinds of thing belong in the file, and only one of them is defined by money. First, a failure that cost money, the thing everybody already means by a loss eventA risk event that cost the institution money, gross before recoveries and net after them.. Second, a failure that cost nothing because something caught it in time. Third, a failure that cost money without any customer being worse off. The harmlessness is itself the signal: a control failed in a way nobody outside was positioned to complain about, and that is often the clearest signal of all. Fourth, a failure that cost very little and broke a promise the institution had made, where the money is trivial and the promise is not. Four kinds of thing count as an event and only one of them is a loss, so an institution that collects losses is collecting a quarter of the record.

FOUR KINDS OF THING THAT COUNT, AND ONE INVENTED EXAMPLE OF EACH Only the first tile is defined by the money. The other three are defined by what failed. KIND 1: IT COST MONEY incident I1, month 1 card-not-present fraud on the debit card book gross Rs 6.4 crore, recovered Rs 1.6 crore NET Rs 4.8 CRORE KIND 2: SOMETHING CAUGHT IT near miss N1, month 2 a duplicate settlement instruction for Rs 68 crore stopped by the four eyes check before release NET NOTHING AT ALL KIND 3: NO CUSTOMER WAS WORSE OFF incident I10, month 10 a valuation feed stale for 11 working days 340 loans wrongly marked, nobody outside lost NET Rs 1.4 CRORE KIND 4: CHEAP, AND A PROMISE BROKEN incident I12, month 12 2,260 complaints closed with no reply sent compensation followed, per customer it is small NET Rs 1.6 CRORE THE FIVE EVENTS OF KIND 2 ARE 5 OF THE 18 COLLECTED, BEING 27.8 PER CENT They are 27.8 per cent of the record and 0 per cent of the rupees, which is why a file sorted by amount never shows them.
Four kinds of thing count as an event and only the first is defined by its cost, so the five near misses are 27.8 per cent of the eighteen events collected and none of the money.

Notice what tile three does to the instinct. Incident I10 wrongly marked 340 loans and no customer lost a rupee, so there was nobody outside the institution with a reason to complain. On a record built around customer harm it would barely register. Incident I10 is in fact the failure sitting behind this bank's single most serious control finding of the year, and the reason is not the Rs 1.4 crore. The reason is that the same feed sets the value of collateral across a secured book, and a control that can be wrong for 11 working days without anybody noticing is a control that can be wrong for longer.

Try it out

An institution's event file contains only the failures that cost money. What is it missing?

Risk Management Program Bootcamp — Fin Maverick

What is a near miss, and why is it worth collecting?

A near missA failure that occurred and did not produce a loss, usually because something caught it. is the same failure with a different ending. Not a smaller failure, not a lucky escape, not a hypothetical. The control broke in exactly the way it would have broken on the expensive day, and then something downstream caught it. Everything the expensive version could have taught is available in the cheap version, and the cheap version costs nothing to collect because somebody has already done the work of noticing.

Take the household version first. A person leaves the gas ring on and walks out of the kitchen. On Monday they come back in two minutes and turn it off. On Friday they come back in forty minutes and there is a fire. Monday and Friday are the same failure. Monday is free. Any household that treats Monday as nothing has decided to buy its information on Fridays.

Vindhya Commercial Bank ran exactly that pair on its collateral valuation feed. Near miss N3 is month 6: the feed was stale for 2 working days and a data quality check caught it. Nobody raised it as an issue. In month 10 the same feed was stale for 11 working days, 5.5 times as long, 340 loans were wrongly marked and it cost Rs 1.4 crore net. N3 and I10 are one control failure with two endings, and the institution had the whole of the second one in its hands four months early, at no cost, and did nothing with it.

ONE CONTROL: THE COLLATERAL VALUATION FEED NEAR MISS N3, MONTH 6 the feed was stale for 2 working days a data quality check caught it no loan was wrongly marked nobody raised it as an issue COST: NOTHING INCIDENT I10, MONTH 10 the feed was stale for 11 working days nothing caught it in time 340 loans were wrongly marked no customer lost money by it COST: Rs 1.4 CRORE NET SAME CAUSE, SAME CONTROL, TWO ENDINGS, FOUR MONTHS APART 11 working days is 5.5 times 2 working days. The institution learned the same amount from both and acted on neither. Both rows are the invented bank's own. Neither is a statement about any real institution or person.
Near miss N3 and incident I10 are the same valuation feed failing twice with two different endings, and the free version arrived four months before the Rs 1.4 crore one.

There is a second reason a near miss earns its row, and it is subtler. The near miss is the only place where a control that worked is recorded at all. Every other row in the file is a control that did not work. If only the failures are ever written down, no evidence ever accumulates about which checks are actually catching things, and decisions about which controls to keep get made with no data on any of them. Near miss N1 records that the four eyes check on settlement instructions stopped a Rs 68 crore duplicate. Nothing else in this bank's file records that.

Why is a near miss worthless unless it is linked?

Now the uncomfortable part, and it is the part that separates institutions that collect near misses from institutions that use them. Vindhya Commercial Bank collected all five. Two of the five, being 40.0 per cent, were the same failure as an incident that followed, and neither was connected to anything.

LinkingConnecting an event to an earlier one with the same cause, which is the only thing that makes a near miss record valuable. means going back through the record already held and asking whether this failure has a relative. Linking is not a field on a form. Somebody has to perform the act, on a schedule, over a window of time that somebody has to choose. N3 sat in month 6 and its incident arrived in month 10, a gap of four months. Near miss N4 sat in month 7, a trade finance document set carrying a particular forgery pattern that a checker refused and recorded as a routine refusal, and one month later that same pattern surfaced as incident I13, the largest net loss of the year at Rs 15.4 crore. A lookback of a single month would have reached the second link and a lookback of four months would have reached both, and this bank ran neither.

EIGHTEEN EVENTS ON ONE TIMELINE, AND THE THREE PAIRS THAT SHARE A CAUSE Incidents are placed at the month each was recorded. The line joins events that were the same failure. NEAR MISSES INCIDENTS 10 DAYS, AND THE OTHER WAY ROUND GAP: 4 MONTHS GAP: 1 MONTH N1 N2 N3 N4 N5 I1 I2 I3 I4 I5 I6 I7 I8 I13 I9 I10 I11 I12 MONTH 1 2 3 4 5 6 7 8 9 10 11 12 ALL EIGHTEEN WERE COLLECTED. NOT ONE OF THE THREE PAIRS WAS EVER JOINED UP.
Three pairs of events in this invented bank share a cause, and the gap a lookback would have had to reach is four months for one pair and a single month for another.

The third line on that timeline points the other way, and it is worth a sentence of its own. Near miss N1 in month 2 was a second duplicate settlement instruction, this one for Rs 68 crore, stopped by the four eyes check before release. Its relative, incident I2, had already gone out ten days earlier and was not stopped. So the pair exists, but the free version came second. The direction matters for how the count is made: counting only near misses that predict, this bank has two. Counting events that share a cause with another event, it has three. How many links a record contains depends on which direction the search is willing to run in, and most institutions only look one way.

There is one thing the linking does not buy, and the discipline of not claiming it matters. Linking N4 to I13 would not have stopped I13. The forgery had been running for fourteen months by month 7 and the loss was already largely incurred. The Rs 16.8 crore of net loss carried by I10 and I13 together, being 38.4 per cent of the year's Rs 43.8 crore, is loss the learning would have been looking at. The Rs 16.8 crore is not loss avoided, and anybody who presents it as loss avoided is selling something.

Try it out

Vindhya Commercial Bank collected both of the near misses that preceded an incident and used neither. What was missing?

Derivatives Foundation Bootcamp — Fin Maverick

When is an event recorded: when it happened, or when it was found?

One question separates a tidy event record from a usable one, and almost nobody asks it until a number comes out wrong. Every row carries a date of occurrenceWhen the thing actually happened, which for a long running failure is a period rather than a day. and a date of recordingWhen the institution wrote it down, which is usually when it was discovered., and they are different dates answering different questions. The first says when the institution was harmed. The second says when the institution found out. The gap between the two dates measures how good the detection is. Neither date alone gives that.

For a short failure the gap is small and the question feels academic. Incident I3, the core banking system unavailable for 4 hours and 20 minutes, happened and was known about within the same afternoon. Incident I6, a rate applied 25 basis points above the approved card on 6,200 term deposits for eleven days, occurred over eleven days and was found shortly after. Neither of those puts pressure on the definition. Two events in this record do, and they do it hard.

SEVEN FIELDS ON ONE EVENT ROW, FILLED IN FOR INCIDENT I13 Two of the seven are dates, and only one of them is the date most templates keep. 1. WHAT HAPPENED 9 letters of credit issued against forged shipping documents 2. DATE OF OCCURRENCE fourteen months, from month minus 5 to month 8 3. DATE OF RECORDING month 8, when a beneficiary bank claimed 4. GROSS LOSS Rs 22.4 crore 5. RECOVERED Rs 7.0 crore, being 31.25 per cent of the gross 6. NET LOSS Rs 15.4 crore, the largest net loss of the year 7. CAUSE an officer inside and a party outside, working together DELETE FIELD 2 AND THE INSTITUTION HAS CHOSEN A LOSS YEAR NOBODY DISCUSSED A template with a single date column always keeps field 3, because field 3 is the one somebody can fill in on the day.
An event row has seven fields and two of them are dates, so a template with one date column has silently chosen a loss year for the whole institution.
Try it out

One incident ran for fourteen months and was discovered in month 8. Which year does its loss belong to?

How a NAV Is Struck and Which Day You Get — free micro-course from Fin Maverick

How does one event become one row when it ran for months?

Two of the thirteen incidents did not happen on a day. Incident I13, the letters of credit, ran for fourteen months ending in month 8, so it began in month minus 5. Only eight of its fourteen months fall inside the twelve month window this record covers, and six of them, being 42.9 per cent of its run, are before the window opens. Incident I5, a branch officer who created 14 fictitious accounts and moved Rs 3.6 crore through them, ran for twenty two months ending in month 5, so it began in month minus 16. Five of its twenty two months fall inside and seventeen, being 77.3 per cent, fall before.

Both long running rows still get one date of recording each, and they sit in this year's file at their full net loss. The recorded loss yearThe set of events attributed to a period, which depends entirely on which of the two dates the attribution uses. is Rs 43.8 crore, and that is this bank's own figure and stays its own figure. Now build the year the other way, on the date each loss occurred, spreading each long running loss evenly across its run. The even spread is an assumption and not the bank's figure: the case says nothing about when within its run either loss actually accrued, and a fraud that accelerates in its final months would move the answer again.

On that assumption I13 puts 15.4 times 6 over 14, being Rs 6.6 crore, outside the window, and I5 puts 2.7 times 17 over 22, being Rs 2.09 crore, outside. Together that is Rs 8.69 crore. The event-dated year is 43.8 less 8.69, being Rs 35.11 crore, or 80.2 per cent of the recorded one. Against this bank's own internal cap on rolling twelve month net operational loss of Rs 60.0 crore, the recorded year runs at 73.0 per cent of the cap and the event-dated year runs at 58.5 per cent. The gap is 14.5 percentage points on one year, produced entirely by which date somebody chose in a template.

ONE TWELVE MONTH RECORD, TWO LOSS YEARS, ONE CHOICE OF COLUMN Both bars are measured against the same internal cap of Rs 60.0 crore, which is this invented bank's own. DATED BY DISCOVERY the bank's own figure Rs 43.8 crore, 73.0 per cent DATED BY OCCURRENCE spread evenly, this guide's own Rs 35.11 crore, 58.5 per cent Rs 8.69 crore THE INTERNAL CAP, Rs 60.0 CRORE THE TWO PALE SLICES ARE THE TWO LONG RUNNING FAILURES, MOVED OUT OF THE YEAR I13 places Rs 6.6 crore before the window opens and I5 places Rs 2.09 crore, on an even spread across each run. The even spread is this guide's assumption. The case does not say when within its run either loss accrued.
The same twelve months produce Rs 43.8 crore dated by discovery and Rs 35.11 crore dated by occurrence, a difference of 14.5 percentage points against the same internal cap.

Neither number is wrong. Dating by discovery gives what the institution had to deal with this year. A treasurer or an auditor usually wants exactly that. Dating by occurrence gives what the institution's controls actually let through this year. Somebody studying the controls wants that instead. The error is never picking one; the error is picking one silently and then presenting the answer as a fact about the year. Rs 43.8 crore is a figure, and a figure is not a fact about twelve months.

How a NAV Is Struck and Which Day You Get teaches you to know which day's price applies to any transaction, and why.

What does a recording cut-off drop, and is the record still complete?

Most institutions do not record everything. A recording cut-offThe size below which an institution does not record an event at all. is the size below which an event never enters the file, and it exists for an entirely reasonable reason: somebody has to write the row, somebody has to review it, and there is no point spending an hour of two people's time on a failure that cost a few thousand rupees. Vindhya Commercial Bank recorded all thirteen and states no cut-off, so the cut-off below is a dial the reader turns rather than a policy the bank has.

Turn the dial and two things move at once, and they move at completely different speeds. Suppose the cut-off is Rs 2.0 crore of net loss. Seven of the thirteen incidents survive and six drop out, so 46.2 per cent of the record has gone. The value that goes with them is Rs 6.9 crore of Rs 43.8 crore, being 15.8 per cent of the money, so the file still holds 84.2 per cent of what the year cost. A cut-off drops events far faster than it drops money, so a record can be nearly complete in rupees and badly incomplete as a record, and those are different claims about the same file.

THE COUNT FALLS OFF A CLIFF. THE MONEY BARELY MOVES. Thirteen incidents, net Rs 43.8 crore in total, all figures the invented bank's own. 100 75 50 25 0 PER CENT RETAINED AT THE GREEN LINE, A CUT-OFF OF Rs 2.0 CRORE 84.2 per cent of the money, 53.8 per cent of the events I2 DROPS OUT JUST ABOVE HERE share of the year's net loss still held share of the thirteen events still recorded RECORDING CUT-OFF, Rs crore of net loss 0 2 4 6 8 10 12 14 16
The share of events retained falls far faster than the share of money retained, so at a cut-off of Rs 2.0 crore the file keeps 84.2 per cent of the loss and only 53.8 per cent of the failures.

The reason the two lines separate is arithmetic rather than accident, and it is worth seeing directly. Value concentrates and counts do not. Sort the thirteen net losses and the median is Rs 2.4 crore while the mean is Rs 3.37 crore, so the mean is 1.40 times the median. The largest single net loss, incident I13 at Rs 15.4 crore, is 4.57 times the mean and 6.42 times the median. Take I13 out and the mean of the remaining twelve is Rs 2.37 crore, almost exactly the median of the whole set. One event is doing all the work in the average, and that is what people mean when they say a loss record has a tail.

THIRTEEN NET LOSSES, SORTED, AND ONE OF THEM IS THE YEAR Every bar is on the same scale. The longest bar is Rs 15.4 crore, being 35.2 per cent of the year's Rs 43.8 crore. I8 Rs 0.6 crore I2 Rs 0.6 crore I11 Rs 1.2 crore I10 Rs 1.4 crore I7 Rs 1.5 crore I12 Rs 1.6 crore I6 Rs 2.4 crore I5 Rs 2.7 crore I9 Rs 3.2 crore I3 Rs 3.2 crore I1 Rs 4.8 crore I4 Rs 5.2 crore I13 Rs 15.4 crore MEDIAN Rs 2.4 crore MEAN Rs 3.37 crore Take I13 out and the mean of the other twelve is Rs 2.37 crore, which is almost the median of the whole set.
Twelve of the thirteen net losses sit between Rs 0.6 crore and Rs 5.2 crore while one sits at Rs 15.4 crore, which is why the mean is 1.40 times the median.
Try it out

A cut-off drops events faster than it drops money. Why?

The table below is the one to put in front of anybody proposing a cut-off. The same arithmetic runs at seven settings, and the two right hand columns are the argument.

Cut-off on net lossEvents recordedShare by countNet loss heldShare by value
No cut-off13 of 13100.0 per centRs 43.8 crore100.0 per cent
Rs 1.0 crore11 of 1384.6 per centRs 42.6 crore97.3 per cent
Rs 1.5 crore9 of 1369.2 per centRs 40.0 crore91.3 per cent
Rs 2.0 crore7 of 1353.8 per centRs 36.9 crore84.2 per cent
Rs 3.0 crore5 of 1338.5 per centRs 31.8 crore72.6 per cent
Rs 5.0 crore2 of 1315.4 per centRs 20.6 crore47.0 per cent
Rs 6.0 crore1 of 137.7 per centRs 15.4 crore35.2 per cent

Read the bottom row slowly. At a cut-off of Rs 6.0 crore this bank's entire operational event record for the year is one row, and that one row still carries 35.2 per cent of the money. Anybody defending the cut-off on value has a true statement available at every setting on that table. The record is a wreck at most of them.

Try it out

A cut-off of Rs 2.0 crore drops six of the thirteen events. What share of the year's money does it drop?

Play with it

Move the cut-off and watch the two lines separate

One control: the recording cut-off, in Rs crore of net loss, from nothing to Rs 16.0 crore. An incident is recorded when its net loss is at or above the cut-off. The default is Rs 2.0 crore, at which 7 of the 13 events survive, being 53.8 per cent by count, and Rs 36.9 crore of Rs 43.8 crore survives, being 84.2 per cent by value. Watch the chip for incident I2: the largest gross loss of the year at Rs 42.0 crore, and a net loss of Rs 0.6 crore.

NO CUT-OFFCUT-OFF Rs 2.0 CRORERs 16.0 CRORE
THIRTEEN INCIDENTS. GREY MEANS THE CUT-OFF HAS TAKEN IT OUT OF THE RECORD. I1 Rs 4.8 crore IN I2 Rs 0.6 crore OUT I3 Rs 3.2 crore IN I4 Rs 5.2 crore IN I5 Rs 2.7 crore IN I6 Rs 2.4 crore IN I7 Rs 1.5 crore OUT I8 Rs 0.6 crore OUT I9 Rs 3.2 crore IN I10 Rs 1.4 crore OUT I11 Rs 1.2 crore OUT I12 Rs 1.6 crore OUT I13 Rs 15.4 crore IN EVENTS STILL RECORDED 53.8 per cent NET LOSS STILL HELD 84.2 per cent INCIDENT I2, THE LARGEST GROSS LOSS OF THE YEAR AT Rs 42.0 CRORE: GONE FROM THE RECORD The two bars answer different questions and neither of them on its own is the completeness of the record. The cut-off is the reader's dial. This invented bank recorded all thirteen and states no cut-off of any kind.
Cut-off
Rs 2.0 crore
Events recorded
7 of 13
Net loss held
Rs 36.9 crore

At a cut-off of Rs 2.0 crore, this record holds 7 of 13 events and Rs 36.9 crore of the year's Rs 43.8 crore, being 53.8 per cent by count and 84.2 per cent by value.

Educational illustration. The cut-off is the reader's dial and is not a case figure: this bank recorded all thirteen incidents and no cut-off appears anywhere in its own record. The two bars answer different questions, so neither is the completeness of the record on its own.

Why is a cut-off on the net figure not a cut-off on the gross?

The gross and net question arrives again here, and this time it does something worse than confuse a ranking. Gross loss is what left the institution. Net loss is what stayed gone after recoveries. For most rows the two are close, so the distinction feels like bookkeeping. For one row in this record they are not close at all, and that row is the one everything turns on.

The cut-off that deleted the largest control failure of the year

Suppose this bank recorded an event only when the net loss reached Rs 2.0 crore. Run it against the thirteen incidents and seven survive, six drop out, and 84.2 per cent of the money is still in the file. Defensible, and the defence is true.

Now the sting. The cut-off is on net loss. Incident I2 is the largest gross loss of the year: a settlement instruction sent twice, and Rs 42.0 crore left the bank twice. Rs 41.4 crore came back, being a recovery rate of 98.6 per cent, so its net loss is Rs 0.6 crore. A net cut-off of Rs 2.0 crore deletes the biggest control failure of the year from the record entirely, and the year's largest event never appears in the file at all.

And it is not a knife-edge case that a slightly lower cut-off would have caught. I2 drops out at any cut-off above Rs 0.6 crore, almost the first movement of the control. The failure is not that somebody chose the wrong number. The failure is that recoveries and severity are unrelated quantities, so filtering on one of them sorts by the other purely at random. Push the cut-off further and it gets starker: at Rs 5.0 crore only two events remain, being 15.4 per cent by count, and they still carry 47.0 per cent of the money.

The ranking makes the point without any cut-off at all. Rank the thirteen on gross loss and rank them again on net loss, and the two lists disagree at the top. I2 is first on gross and joint twelfth of thirteen on net, tied with I8 at Rs 0.6 crore, a move of eleven places on a list of thirteen. I13's recovery rate was 31.25 per cent against I2's 98.6, so I13 is second on gross and first on net. Across the year the bank recovered Rs 53.9 crore of Rs 97.7 crore gross, being 55.2 per cent. The top two on gross are 65.9 per cent of the gross and the top two on net are 47.0 per cent of the net, and they are not the same two incidents.

THE SAME THIRTEEN INCIDENTS, RANKED TWICE, AND THE TOP OF THE LIST SWAPS Gross totals Rs 97.7 crore and net totals Rs 43.8 crore. Both columns hold the same thirteen rows. RANKED ON GROSS LOSS RANKED ON NET LOSS 1I2Rs 42.0 crore 2I13Rs 22.4 crore 3I1Rs 6.4 crore 4I4Rs 5.2 crore 5I9Rs 4.4 crore 6I5Rs 3.6 crore 7I3Rs 3.2 crore 8I6Rs 2.4 crore 9I8Rs 2.1 crore 10I7Rs 1.8 crore 11I12Rs 1.6 crore 12I10Rs 1.4 crore 13I11Rs 1.2 crore 1I13Rs 15.4 crore 2I4Rs 5.2 crore 3I1Rs 4.8 crore 4I3Rs 3.2 crore 5I9Rs 3.2 crore 6I5Rs 2.7 crore 7I6Rs 2.4 crore 8I12Rs 1.6 crore 9I7Rs 1.5 crore 10I10Rs 1.4 crore 11I11Rs 1.2 crore 12I2Rs 0.6 crore 12I8Rs 0.6 crore I2 MOVES ELEVEN PLACES ON A LIST OF THIRTEEN, ON A RECOVERY RATE OF 98.6 PER CENT I2 and I8 tie at Rs 0.6 crore, so both are joint twelfth on net. I13 recovered 31.25 per cent and moves the other way.
Ranked on gross loss incident I2 is first and ranked on net loss it is joint twelfth of thirteen, a move of eleven places driven entirely by a 98.6 per cent recovery.
Try it out

Why does a net loss cut-off delete the year's largest gross failure?

Debt Capital Markets Bootcamp — Fin Maverick

What is an event record actually for?

Everything above has been about what goes into the record. Whether any of the definitional work was worth doing depends on what comes out. The honest answer is that the record is not primarily for adding up. An event record exists to make the same failure findable twice, so the cause field, the two dates and the link to any earlier event with the same cause matter more than the amount column ever will.

A total answers exactly one question: what did the year cost. The cost of the year is a real question and somebody has to answer it. But a total cannot answer much beyond it. A total cannot show that a valuation feed failed in month 6 and again in month 10. A total cannot show that a forgery pattern was refused by a checker in month 7 and surfaced as the largest loss of the year in month 8. Three incidents in the year were process failures in execution and delivery, carrying 23.1 per cent of the count and 10.0 per cent of the value. Two were internal fraud, carrying 15.4 per cent of the count and 41.3 per cent of the value. A total shows neither split. Every one of those statements needs a record with rows in it, and none of them survives being summed.

Which is why the definitional choices made earlier are not pedantry. If the four kinds collapse to one, the near misses never enter and the two links can never be found. If the cut-off sits at Rs 2.0 crore on net, incident I2 is not in the file, so nobody can ever notice that near miss N1 in month 2 was its relative. If the template carries one date column, the year is dated by discovery and nobody knows that Rs 8.69 crore of it belongs to months before the record opens. Each of the three choices removes not a number but a question that can no longer be asked.

Try it out

What is an event record actually for?

Breaking Into Quants Bootcamp — Fin Maverick

Who actually picks up an event record, and what do they do with it?

Four different readers open this file for four different reasons, and watching them read it is the fastest way to see which fields carry weight.

The head of operational risk, Purnima Ganeshan in this invented bank, reads it for repetition. She is not looking at the total at all. A cause that recurs is a control that is still broken, and a cause that appears once may be nothing, so she is looking for two rows with the same cause and asking how long the gap was. On this file she would find three pairs, and the gaps are four months, one month and ten days.

The internal auditor reads it for the fields that are empty. A row with a cause of "human error" and no link is a row somebody closed rather than investigated, and in a file of thirteen incidents an auditor can read every cause field in twenty minutes. Reading every cause field is the cheapest test of an event record there is, and it needs no arithmetic at all.

A credit analyst at another institution, looking at Vindhya Commercial Bank Limited as a counterparty rather than as an employer, reads the disclosed operational loss figure and asks one question before anything else: which date is it on. A bank that dates by discovery and has just found a fourteen month fraud reports a bad year that was partly somebody else's. A bank that dates by occurrence reports a smoother series that hides how late its detection is. Comparing a discovery-dated year to an occurrence-dated year across two institutions is comparing nothing to nothing. Neither series is misleading, and the analyst has to know which one is in front of them.

The mechanism is the same at every scale, so a household reader opens the same kind of file. A person who keeps every repair bill for a scooter has a total. A person who writes one line beside each bill saying what actually broke has a record, and after three years the second person knows the chain keeps going and the first person only knows that scooters are expensive. The line beside the bill is the cause field, and it is the only part of either file that ever changes a decision.

India

What is named here, and where the binding version lives

Every incident, near miss, date, amount, recovery and internal cap belongs to Vindhya Commercial Bank Limited and binds nobody. The recording cut-off is the reader's dial rather than any institution's policy.

The seven category structure that this bank sorts its operational events into originates with the Basel Committee on Banking Supervision, whose standards are published by the Bank for International Settlements at bis.org. The Reserve Bank of India at rbi.org.in sets what an Indian bank must actually record, to whom it must report an event, in what form and inside what period. Where a duty to keep and retain records sits in Indian company law, the Ministry of Corporate Affairs at mca.gov.in is the source.

An event record identifies a cause and a control rather than a person, so the officer behind an internal fraud incident is never the field that decides anything.

How an operational loss is defined into event categories, provided for or capitalised, root cause analysis, and the near miss register run as a discipline with its own procedure are all covered separately under operational risk. The four stage response to a live incident, being detect, contain, recover and learn, is covered separately under operational resilience. Who must report an event to whom, through which committee and inside what period is a governance and a jurisdiction question and is settled elsewhere. Impact and likelihood as a pair are covered separately. The individual risk types are covered in their own right.

Sources

SourceDocumentSite
Reserve Bank of IndiaWhat actually binds a bank in India on operational risk arrangements, incident reporting and the maintenance of recordsrbi.org.in
Bank for International SettlementsThe Basel Committee standards behind operational risk, including the seven event categories this invented loss record is sorted intobis.org
Ministry of Corporate AffairsWhere the duty to keep and retain company records sits in Indian company lawmca.gov.in

Vindhya Commercial Bank Limited and Purnima Ganeshan are invented.
Educational material. Not advice on any investment, tax, budget or market position.

← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.