The Management of Operational Risk Through Appropriate Insurance Schemes
Para. 4.4Status unknownSaudi ArabiaRegulation
Issued by Saudi Central Bank (SAMA) Rulebook
If yes to 4, does the operational scope of the Committee include consideration of: * Fraud, forgery, and other criminal risks ? * Professional and client related liability exposures ? * Risk associated with legal and regulatory non-compliance ? * Political risk ? Risk Assessment 2. YES NO COMMENTS Is there any inventory of the institution's tangible and nontangible resources which may be subject to operational risks. These may include the following: Physical Assets (i.e. physical plant, systems, real estate, etc) Financial Assets (i.e. cash, securities, negotiable instruments, etc.) Human Assets (i.e. employees, officers, directors, customers, shareholders, vendors and contractors, etc.) Intangible Assets (i.e. reputation, good will; etc.) Are operational risks with respect to new acquisitions, divestitures, expansions, or downsizing been identified. These may include the following: Physical Assets (i.e. physical plant, systems, real estate, etc.) Financial Assets (i.e. cash securities, negotiable instruments, etc.) Human Assets (i.e. employees, officers, customers, share holders, vendors and contractors, etc.) Intangible Assets (i.e., reputation, goodwill, etc.) Can the bank identify actual and potential loss exposures and risk events for all products and services currently being offered or proposed for implementation. Such risks may include the following: Criminal acts including fraud, forgery, robbery, burglary and counterfeiting ? Direct loss of injury to or sickness of personnel ? * Loss or compromise of information / data ? * Direct loss of or damage to physical property ? * Consequential loss and or loss of use ? * Customer Contractual Liability ? * Tort and Product Liability ? * Statutory and Regulatory Liability (Legal and Regulatory Compliance ) ? * Political risk and regulatory instability ? On at least an annual basis, are formal qualitative and quantitative analyses conducted to measure the level of current operational risk? Does this analyses include. * Judgmental risk estimates by senior staff and operational managers based on probable and maximum severity costs of a single occurance and / or aggregate losses in a single year ? * Assessment of risk event probabilities by senior managers and operational personnel ? * Review of available loss data from other banks institutions both within the Kingdom and internationally ? * Maintenance of a data base of incident reports and exposure and loss history for both insured and uninsured losses ? * Comparison of past losses and loss ratios to the premium and exposure bases ? * Analysis of trends, reporting, and payment patterns for past losses ? * Decision and event tree analysis ? * Scenario development (including "worse case" analyses) ? * Frequency and severity analyses and projections ? * Preventive measures in place ? Operational Risk Reduction and Control 3. YES NO COMMENTS 1. Have formal written programs of operational risk and loss control including risk assessment and control matrices been developed for all operational and staff areas ? If yes 1, do these programs include: * Proprietary and confidential data ? * Physical security of the bank's premises ? * Branch fraud prevention and awareness ? * Credit card, ATM, trading, and payment systems fraud ? * Software piracy and patent / copyright infringement ? * Information Systems Security ? * Product and service quality assurance ? * A dherence to customer contractual obligations ? * Compliance with regulatory and statutory requirements within Saudi Arabia ? * Others as applicable ? 2. Does the Operational Risk Management function provide central direction and coordination for operational risk management and loss control and risk financing programs within the institution ? Does its scope include: * Timely reporting of losses to senior management, SAMA, insurance carriers, and law enforcement (when appropriate) ? * Complete investigation of losses in conjunction with internal audit, bank's security department, insurance carriers and law enforcement (when appropriate) ? * Written claims handling procedures for line and staff personnel as well as both in-house claims personnel and external claims handling services ? * Review of claims files and investigative procedures ? * Coordination of claims and periodic qualitative evaluation of the overall claims handling process ? * Follow-up on all open claims and periodic qualitative evaluation of the overall claims handling process? 3. Has the institution developed penalty/reward systems ? Do these systems include: * Regular scheduled comparative evaluation of loss records of various units. * Monetary and non-monetary incentives 4. Has a formal program of operational risk control training been established which emphasizes responsibility and accountability for the control of operational losses ? Insurance Policies 4. YES NO COMMENTS Is there a written corporate risk financing policy which defines the methods to be used by the bank for insuring itself by considering all the methods available i.e. conventional insurance, loss retention guidelines, parent captive, risk retention group, finite insurance etc.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded