Current rules permit directors and officers to avoid personal liability for gross negligence. That is a wise rule for most business decisions: courts are generally not skilled at assessing business judgment. But risk is different. Why should a bank manager who is grossly negligent in supervising risk avoid liability?Mr. Portnoy is correct to promote the notion of greater accountability for monitoring risk. However, attaching personal liability to executives may not necessarily be the best method. It would be very difficult to define what is an adequate level of risk monitoring since it really differs for every institution. That is why the industry is so heavily regulated. However, Mr. Portnoy is certainly on point in the fact that stronger risk monitoring is needed to rebuild trust in banks.
Shareholders might never be able to understand the risks of modern banks, and current regulatory approaches will not give them much confidence. But if they knew that senior managers had agreed to be personally liable for gross negligence in monitoring risk, they might trust the banks more. Without trust, it is hard to see how banks can recover.
Friday, September 23, 2011
Rebuilding Trust Through Better Risk Monitoring
Saturday, July 2, 2011
Now Is Not The Time to Reduce Investment in Risk Management
According to the Financial Times, US regulators are keenly aware of what may be on the minds of bank executives and are issuing warnings to avoid cutting risk management budgets. According to Michael Alix, a senior vice-president at the Federal Reserve Bank of New York who heads the risk-management function within the regulator’s financial-institutions supervision group, the regulators are paying close attention to any plans to lower investment in risk management programs. “We haven’t seen it yet, but we’re vigilant,” says Alix.
Sacrificing the progress made in strengthening risk management programs at this precarious stage of recovery is certainly short-sighted and could lead to even greater problems for companies looking to weather the next storm.
Thursday, May 5, 2011
FDIC Calls for Risk Management Improvements
The reviews uncovered many common issues among the mortgage servicers. The FDIC noted the following, “concerns included lax foreclosure documentation, ineffective controls over foreclosure procedures, and deficient loss mitigation procedures and controls. Many institutions failed to commit resources sufficient to manage responsibly the rapidly growing volume of mortgage loans in default or at risk of default. Weak governance and controls increased legal, reputational, operational, and financial risks while creating unnecessary confusion for borrowers.”
While the report focuses specifically on the foreclosure shortcomings, it can also serve as a reminder of the value of strong internal controls and risk management practices. As our business processes grow to be more complex and interconnected, the risks inherent in the processes grow exponentially. Unchecked, these risks can quickly propel a business into a full-blown crisis.
Tuesday, March 15, 2011
Viewing Risk in a Different Way
David Spiegelhalter, leading risk expert and professor at Cambridge University, supports this view in a recent video (see below) that is both enlightening and humorous. Through his real-life examples, Professor Spiegelhalter provides a unique view of how we as humans typically view risk. His lessons are particularly relevant as we continue our struggle to emerge from the financial crisis of 2008. As he concludes, "One of the biggest risks is being too cautious."
Thursday, January 27, 2011
CNBC Profiles Internal Audit & Risk Management Practices
Tuesday, January 4, 2011
Wheelhouse Advisors Joins the Business Finance Expert Network
Monday, December 6, 2010
The Human Element of Risk Management
As business has grown more complex, we have developed elaborate protocols, systems, frameworks, and approaches to manage risk. A consequence of putting science at the forefront of these risk management systems has been a stripping of human behavior out of the risk model.
The future of risk management lies in an ability to incorporate and inspire more of the behaviors we want, finding new models to map, monitor, intervene, support, and react to the behaviors of individuals and groups—both the behaviors we want to encourage and those we'd like to avoid. Critically, this taking account of behavior means we need a much sharper comprehensive strategy for corporate culture, so that our models are founded on the way "things really happen around this place."
Examining the human element of risk management is a key part of Wheelhouse Advisors' upcoming workshop, Navigating Risk: From Crisis to Innovation. To learn more about the workshop and enroll for this groundbreaking event, please visit www.oldedwardsinn.com/navigatingrisk.
Monday, July 12, 2010
More Change is on the Way
The Securities and Exchange Commission will act quickly to revise corporate risk disclosure requirements and also consider more sweeping recommendations on executive compensation disclosures and easy-to-read corporate filings, SEC Chairman Mary Schapiro said Friday. The SEC also is looking at trading activities such as hedging, shorting, arbitrage and certain types of market orders, to ensure that all investors have access to a highly complex and technologically sophisticated trading market, Ms. Schapiro said in the text of prepared remarks.
SEC staffers now are re-evaluating all corporate filing forms and disclosure requirements, asking whether the information that is being sought is "still relevant," Ms. Schapiro said. "After this review, I expect the staff will present individual recommendations that we can act on quickly, such as revising the risk disclosure requirements," Ms. Schapiro said in the text of her speech to the Society of Corporate Secretaries and Governance Professionals.
Companies should be prepared to provide more substantive information regarding their risk programs. Wheelhouse Advisors can help your company with a complimentary risk program diagnostic review. For more information, email us at NavigateSuccessfully@WheelhouseAdvisors.com.
Tuesday, June 22, 2010
Federal Reserve Issues Final Guidance on Risks & Incentive Pay
"Many large banking organizations have already implemented some changes in their incentive compensation policies, but more work clearly needs to be done," Federal Reserve Governor Daniel K. Tarullo said. "The Federal Reserve expects firms to make material progress this year on the matters identified as we work toward the ultimate goal of ensuring that incentive compensation programs are risk appropriate and are supported by strong corporate governance."
During the next stage, the banking agencies will be conducting additional cross-firm, horizontal reviews of incentive compensation practices at the large, complex banking organizations for employees in certain business lines, such as mortgage originators. The agencies will also be following up on specific areas that were found to be deficient at many firms, such as:
- Many firms need better ways to identify which employees, either individually or as a group, can expose banking organizations to material risk;
- While many firms are using or are considering various methods to make incentive compensation more risk sensitive, many are not fully capturing the risks involved and are not applying such methods to enough employees;
- Many firms are using deferral arrangements to adjust for risk, but they are taking a "one-size-fits-all" approach and are not tailoring these deferral arrangements according to the type or duration of risk; and
- Many firms do not have adequate mechanisms to evaluate whether established practices are successful in balancing risk.
In addition to the work with the large, complex banking organizations, the agencies are also working to incorporate oversight of incentive compensation arrangements into the regular examination process for smaller firms. These reviews are being tailored to take account of the size, complexity, and other characteristics of these banking organizations.
Having a solid understanding of your risk profile and the resulting impact of incentive programs is now critical for financial institutions as well as companies in other industries. Wheelhouse Advisors can help you develop stronger incentive programs with a thorough analysis of your risks. To learn more, visit www.WheelhouseAdvisors.com.
Thursday, June 17, 2010
Risk Blindness at BP
In 2007, when Mr. Hayward first took over as chief executive, BP settled a series of criminal charges, including some related to the explosion of BP's Texas City, Tex., refinery, and agreed to pay $370 million in fines. Admitting that the company's operations had failed to meet its own safety standards and requirements of the law, Mr. Hayward pledged to improve BP's risk management. Following the Deepwater Horizon explosion, Mr. Hayward conceded that the company had problems when he took over in 2007. But he said he had instituted broad changes to improve safety, including setting up a common management system with precise safety rules and training for all facilities.
Some analysts say the safety problems indicate that BP has not yet reined in the culture of risk that prevailed under Mr. Hayward's predecessor, who transformed BP from a sleepy British oil producer into one of the world's top explorers through the acquisitions of Amoco and Atlantic Richfield.
A strong culture dedicated to risk management is essential for companies who are looking to succeed in the long run. BP's current crisis is a prime example of the perils of ignoring the importance of strong risk management practices.
Tuesday, June 15, 2010
Growing Web of Risks in Today's Business World
AS the oil spill in the Gulf of Mexico follows on the heels of the financial crisis, we can discern a toxic recipe for catastrophe. The ingredients include risks that are erroneously thought to be vanishingly small, complex technology that isn’t fully grasped by either top management or regulators, and tricky relationships among companies that are not sure how much they can count on their partners.
For the financial crisis, it has become clear that many chief executives and corporate directors were not aware of the risks taken by their trading desks and partners. Recent accusations against Goldman Sachs suggest the potential for conflicts of interest among banks, investors, hedge funds and rating agencies. And it is clear that regulators like the Securities and Exchange Commission, an agency staffed primarily with lawyers, are not well positioned to monitor the arcane trading strategies that helped produce the crisis.
The story of the oil crisis is still being written, but it seems clear that BP underestimated the risk of an accident. Tony Hayward, its C.E.O., called this kind of event a “one-in-a-million chance.” And while there is no way to know for sure, of course, whether BP was just extraordinarily unlucky, there is much evidence that people in general are not good at estimating the true chances of rare events, especially when human error may be involved. There was another major blow-out in the gulf 31 years ago by the Mexican rig Ixtoc I. So was this really a one-in-a-million risk?
In the current spill, the problems of assessing risk were complicated by the teamwork required among BP; Transocean, which owned the rig; and Halliburton, which had provided services like concrete work. “Of the 126 people present on the day of the explosion, only eight were employees of BP,”reported Ian Urbina in The New York Times. “The interests of the workers did not always align.”
Certainly, before a company can fully understand the growing web of internal and external risks inherent in their business activities, the company must have a disciplined approach to risk management. A strong enterprise risk management program can help in this regard. If your company is looking to implement or improve its enterprise risk management program, Wheelhouse Advisors can help. Visit www.WheelhouseAdvisors.com to learn more.
Tuesday, May 18, 2010
Who Can Afford Not to Have an ERM Program?
Without adequately planning for trouble, the oil business (financial services industry) has focused on developing experimental equipment (complex derivatives) and techniques (synthetic asset backed securities) to drill (operate) in ever deeper waters (more opaque markets), according to a Wall Street Journal examination of previous deepwater accidents (financial meltdowns). As drillers (bankers) pushed the boundaries, regulators didn't always mandate preparation for disaster recovery or perform independent monitoring.
The Minerals Management Service (Federal Reserve, OCC, OTS, FDIC, etc.), the government agency that oversees offshore drilling (financial services), in recent years moved away from requiring specific safety measures (capital requirements) in offshore drilling (trading activities) and instead set broad performance goals (guidance for internal risk modeling) that it was up to the industry to meet. In joint MMS-Coast Guard (Federal Reserve, OCC, OTS, FDIC, etc.) hearings into the Deepwater Horizon accident (Bear Stearns, Lehman Brothers, AIG insolvency), Michael Saucier, an MMS official, testified that the agency "highly encouraged," but didn't require, companies to have back-up systems (specified risk limits) to trigger blowout preventers (increases in capital) in case of an emergency.
While there are many estimates of the cost to British Petroleum to deal with the Deepwater Horizon oil spill, the minimum consensus estimate right now is around $12-13 billion. Add to that estimate the recent market capitalization loss of nearly $50 billion and the case for having a robust ERM program seems fairly straightforward.
Thursday, May 13, 2010
Diagnosing ERM Problems
In reality, most organizations have been focused purely on survival and have allowed their more forward-looking risk management practices to take a back seat. In addition, in order to weather the financial storm, some companies looked to risk management organizations for cost savings and scaled back their infrastructure and resources. Ironically, it is the companies that have survived the crisis relatively unscathed that may be the least prepared and the most at risk for a future loss event.
So, how do you know how healthy your ERM program is today? The best and most reliable way is to conduct an independent, diagnostic review of the program. A diagnostic review should focus on two main components of the ERM program – the level of desired maturity and the core foundational elements. First, a company needs to determine what level of maturity they are seeking to achieve. This is based on a number of factors including the size of the company, the nature and complexity of the business, and the external environment in which the business operates.
After determining the desired maturity, the company should examine the core foundational elements that form the ERM program itself. A comprehensive review of these elements will help the company understand both the progress toward the desired maturity level as well as the major gaps that may exist in the foundational elements.
Much like an annual physical check-up exam, it is a good idea to perform a diagnostic review of your ERM program on a periodic basis to ensure that it is providing the expected level of risk management discipline within your organization. Wheelhouse Advisors has designed a quick and effective review to provide companies an independent view at a reasonable cost. For more information, feel free to email us at navigatesuccessfully@wheelhouseadvisors.com.
Tuesday, May 11, 2010
How Mature is Your Risk & Control Program?
Much of the fallout from the financial crisis of 2008 can be attributed to the lack of coordination and integration of risk management practices at individual firms as well as across entire industries. To be successful at managing risk going forward, companies must begin to examine how they are currently focusing their efforts and how they need to evolve their overall risk and control program.
The evolution path for most risk and control programs can be broken into four distinct stages – Developing, Implementing, Improving and Integrating (see figure below). As companies begin to take a more focused approach to managing risk, they usually begin by simply reacting to regulatory demands or recent negative events that have occurred. In this initial “Developing” stage, companies may create ad hoc task forces or assign individual teams to address the risks.
However, most companies begin to see the need for a more formal, enterprise-wide approach and enter the “Implementing” stage. Here, a risk champion is typically named, standards are created and the various teams begin to align and share information. Once the sharing of information begins, both horizontally and vertically through the company, inefficiencies and gaps become apparent.
Companies then move to the “Improving” stage in order to streamline processes and adopt best practices. Finally, once the program has matured into an efficient mechanism on its own, it should be fully integrated into the business itself – at all levels. It is this “Integrating” stage of evolution that is the holy grail of Enterprise Risk Management.
Where is your company on the evolution path? What obstacles are you facing as you look to progress from one stage to another? Wheelhouse Advisors can provide both unique insight and practical solutions to help you reach the desired level of maturity. To learn more, visit www.WheelhouseAdvisors.com.
Wednesday, March 24, 2010
Risk Management Moving to the Fore at Board Meetings
With board members more concerned about risk management and succession planning these days, CFOs should make sure they — and their staffs — have a strong presence in the boardroom, a group of retired CFOs-turned-board members told financial executives attending the CFO Rising conference in Orlando last Wednesday. "The board wants to make sure they hear all opinions," said Ellen Richstone, former finance chief of several public companies, including Sonus Networks, and now on the board of Blue Shift Technologies. "They don't want to hear just the CEO." If the CFO and other members of the management team aren't available to the board, it sends up a red flag, she said.
Any red flags at your company's board meetings due to a lack of involvement by the finance team? If so, there is no time like the present to remedy the situation.
Wednesday, January 20, 2010
Back to the Future for Banks
President Barack Obama on Thursday is expected to propose new limits on the size and risk taken by the country's biggest banks, marking the administration's latest assault on Wall Street in what could mark a return – at least in spirit – to some of the curbs on finance put in place during the Great Depression, according to congressional sources and administration officials.
The proposal represents a sharply different philosophical shift from the view of banking over the last decade, which saw widespread consolidation among large financial institutions to create huge banking titans. If Congress approves the proposal, the White House plan could permanently impose government constraints on the size and nature of banking.
With this move, the President is certainly looking to overcome his health care disappointment by garnering public support for a return to tighter restrictions on the nation's banks. Given the current mood among the electorate, his probability for success in this arena is high.
Thursday, January 7, 2010
Getting Ahead of the Risk Curve
The Bank for International Settlements will gather top central bankers and financiers for a meeting in Basel this weekend amid rising concern about a resurgence of the “excessive risk-taking” that sparked the financial crisis. In its invitation, the BIS cited concerns that “financial firms are returning to the aggressive behaviour that prevailed during the pre-crisis period”. The meeting comes at a moment of intense uncertainty, with the global economy’s tentative recovery shadowed by “the overhang of private-sector debt and rapidly rising public debt”, and high unemployment.
It is a good sign that the BIS and others are looking to get ahead of the risk curve. What remains to be seen is the reaction from the leadership of major financial institutions and the resulting behavior within the markets.
Thursday, October 29, 2009
Rude Lesson in Risk Management
Kevin Blakely, senior executive vice president of Huntington Bancshares Inc. in Columbus and its chief risk officer said years ago, things were relatively simple. “Most of our risk was centered in credit risk – lending to individuals and companies, and gauging our ability to get that money back,” he said. Until this past summer, Blakely had been president of the Philadelphia-based Risk Management Association. But as companies got bigger and financial products got more complex, financial institutions developed mathematical models to measure risk. They worked well, he said, but by the mid-1990s banks were depending on them too much. “We began to view them as the answer, rather than as one more input before you get to the answer,” Blakely said. “That was one of the rude lessons we learned over the last couple of years. As an industry, we weren’t as smart in the business of risk management as we thought we were.”
The false sense of security placed in risk management was certainly a rude lesson for many companies as they focused on quantitative models that told them what they wanted to believe. A balanced view of both quantitative and qualitative factors is critical to an effective enterprise risk management program.
Wednesday, October 28, 2009
JP Morgan Chase CEO Discusses Risk Management
Jamie Dimon speaks with Charlie Rose at SIFMA Annual Meeting
Thursday, October 8, 2009
Back to the Drawing Board on Derivatives Regulation
A plan offered by the Obama administration would subject all swaps dealers and “major market participants” to new regulations for capital, business conduct, record-keeping and reporting. Frank’s version would exempt corporations from that definition if they use derivatives for “risk management” purposes.
While Frank’s proposal is a “step in the right direction,” its “ambiguous” definition of risk management may leave a large number of corporations unregulated, Henry T.C. Hu, director of the SEC’s new division of risk, strategy and financial innovation, told the committee.
“As just about all swaps could be defined as being used for risk management purposes, we’re concerned that unintentionally the category of ‘major swap participant’ could have been narrowed so significantly, or even to a null set,” CFTC Chairman Gary Gensler told reporters after the hearing.
“Major hedge funds” may be excluded from oversight, as may the mortgage-finance companies Fannie Mae and Freddie Mac “because of course the government-supported enterprises use swaps for risk management purposes,” Gensler said.
It looks like Chairman Frank may need to re-educate himself on the use of derivatives and go back to the drawing board on this proposal.