Entire Section
PIB 6.3 PIB 6.3 Risk Identification and Assessment
PIB 6.3.1 PIB 6.3.1
An
Authorised Firm must:(a) ensure that it identifies and assesses theOperational Risks inherent in all theAuthorised Firm's products, activities, processes and systems;(b) ensure the inherent risks in (a) are understood by relevantEmployees of theAuthorised Firm ;(c) systematically trackOperational Risk events and any financial impact associated with such events; and(d) ensure that the tracking in (c) is consistent with theOperational Risk event types described in the Basel III framework.Derived from RM111/2012 (Made 15th October 2012). [VER20/12-12]PIB 6.3.1 Guidance
1. AnAuthorised Firm should record allOperational Risk events, including near misses and events which result in a positive financial outcome.2. These Rules complement relatedRules in GEN section 5.3 relating to risk management systems and controls. For example, GEN Rule 5.3.6 requires anAuthorised Firm to appoint an individual to advise itsGoverning Body and senior management as to risks.Derived from RM111/2012 (Made 15th October 2012). [VER20/12-12]PIB 6.3.2 PIB 6.3.2
An
Authorised Firm must ensure that itsOperational Risk policy in PIB Rule 6.2.1:(a) includes an approval process for all new products, activities, processes and systems; and(b) incorporates the requirement in PIB Rule 6.3.1(a).Derived from RM111/2012 (Made 15th October 2012). [VER20/12-12]PIB 6.3.2 Guidance
1. AnAuthorised Firm should have policies and procedures that address the process for review and approval of new products, activities, processes and systems. The review and approval process should include consideration of:a. inherent risks in any new product, service, or activity;b. resulting changes to theAuthorised Firm's Operational Risk profile, appetite and tolerance, including changes to the risk of existing products or activities;c. necessary controls, risk management processes, and risk mitigation strategies;d. residual risk;e. changes to relevant risk limits;f. procedures and metrics to measure, monitor, and manage the risk of the new product or activity; andg. appropriate investment in human resources and technology infrastructure.2. Tools that anAuthorised Firm may employ for identifying and assessingOperational Risk include:a. internal loss data collection and analysis;b. external data collection and analysis;c. risk assessments;d. business process mapping;e. risk and performance indicators; andf. scenario analysis.Derived from RM111/2012 (Made 15th October 2012). [VER20/12-12]