Showing posts with label Budgeting Process. Show all posts
Showing posts with label Budgeting Process. Show all posts

Saturday, November 19, 2011

What the C-suite Needs to Know about Fraud: Elevator Pitches

Over the coming weeks, I'll be using this blog to suggest a set of "elevator pitches" relating to bank fraud management. This episode gives some background, as well as Pitch #1.

For most of my colleagues in banking, this is a stressful time of year. Yeah, the holidays are upon us. Yeah, the kids have holiday shows and final projects to prepare for. Yeah, there is a long list of presents to buy. Yeah, the home team is one game away from a bowl. For bankers, atop all of that, this is prime-time budget and planning season. Their fate is determined for at least the next 12 months through a gauntlet of analysis and discussion about prioritization, roadmaps, and funding.

The same is equally true for my colleagues in the software industry as they determine what the future holds for their products. Even us consultants get together for tealeaf-reading sessions, trying to anticipate the coming needs of our clients.

This period can be exhausting, but one great side-effect is that a bunch of senior people put their heads together. This is a perfect opportunity for people across the organization to educate each other and especially the C-suite on "whats hot" in their area.

In between discussions, in halls, elevators, conference rooms, and on conference calls, there is inevitably some idle time. If you find yourself in one of those moments with your boss's boss's boss, don't blow the moment by hiding in your Blackberry to avoid the awkward silence. Tell them something that will stick with them ... give them your elevator pitch!

Wednesday, April 13, 2011

You Get What You Pay For: Building Business Cases for Risk Management Investments

In 1993, I visited a factory in the (recently) former Soviet Union.

On the books, the place had a staff of 5,000 making 10,000 lenses a month. In reality, only about 1,000 turned up on any given day. That was fine with management. See, a few years back, Moscow had some extra budget and they let the factory buy some incredibly cheap used lens polishing machines. This meant that the army of 1,000 human polishers were no longer needed, but since nobody "up the chain" cared, the management just kept these folks on the payroll. It made the operation look bigger on paper, and therefore they got a bigger budget from Moscow.

Sadly, they could never get the machines to work quite right, so they kept a few hundred human polishers to "touch up" the lenses before they were shipped. They apparently assumed the machines were good, since they had previously been owned by a well-known Japanese lens manufacturer. In fact, they were heavily used, out-of-date models producing lenses so low in quality the Japanese couldn't sell them at any price point. After installing these machines at the Russian factory, quality went down overall, but was at least consistent, which made managers happy. Nobody at the factory asked if this would help them sell cameras, since their only customer was the Central Government in Moscow. What this intermediary did with the cameras afterward was not their problem.

Until the Soviet Union collapsed.

Their first question to my group was: Who will buy these lenses which are twice the price and half the quality of the competition?
Answer: Nobody.

Second question was: OK, we learned our lesson. Never again. We want to become state-of-the-art. How? Who will give us the money?
Answer: Fuggedaboutit. By the time you catch up, the competition will have improved again. Nobody bets on a losing horse.

Third question was: If we were to give you the factory and a 3-year supply of aluminum for free, would you at least keep paying our staff of 5,000?

It was a desperate situation, a totally reactive management, and a totally losing business case. After some analysis, my delegation told them to make car antennas with the aluminum and we walked away. Instead, the factory closed, the staff stopped getting paychecks, and the managers became "full-time pension administrators" since pension liabilities were all that was left of the once-bustling company.

Wait, what does this have to do with risk management in financial services?

If we in the Financial Services industry don't want to become "full-time pension administrators" presiding over gutted, non-productive zombie firms, we shouldn't act like Soviet factory managers.

Unfortunately, in certain ways, we do. Look at your organization's decision-making process through the lens of my anecdote. How similar is it? Does the annual budgeting process rule? How are those budgets determined? Then look at your process through a different lens. Imagine your department as a standalone business. Would you turn a profit? Would you be competitive? Would it change the way you spend? Would your customers be satisfied, or would they go elsewhere?

If you don't know the answers, read on...

I don't know the answers either, but here's how I think about the problem when I talk to my clients. Viewed very simplistically, FIs make risk management decisions in response to events and losses, either at their own institution or at a competitor. In other words: they're reactive. They don't want to waste money to manage a risk which is never going to happen. When it comes to incorporating risk management into their business cases, they rarely go much further than the camera factory managers did: "won't happen" or "can't happen here" meaning that their firm is somehow special or smart enough to avoid that risk.

Few organizations bother to invest enough time for a comprehensive cost-benefit analysis (CBA) of internal investment projects. Many manager don't even want a CBA because that would require them to familiarize themselves with each individual investment proposal. They prefer to operate at an overall budgetary level. As long as they have unspent budget and you can win the political fight for money, they'll let you have it.

Just like Moscow did for the camera factory managers. They had to change, and so will FIs.

Structurally (ie: permanently) smaller margins are already forcing FIs to be more discerning in their investments. Value for money can no longer be taken for granted. CBA is already taking over.

That may leave your head spinning with questions. How can I do a CBA in risk management? What is the "price" of a risk? How would I quantify the benefit of preventing something from happening? All good questions.

Start with what you already know. You can't assess what you can't measure, so make sure your operational metrics are up to the task. Enhance your processes as necessary to have comprehensive and high-confidence numbers on the all-in average cost per type of work item. Make sure this is broken down into roles. Investigators' time is important, but don't forget about their team leaders and managers, the QA review team, the auditors, the analytical team, etc. Make sure your per-item metrics add up to 100% of your total labor costs for the function or department.

Layer on technology costs, not by vendor or by solution, but by investigative work item. How much does it cost all-in to get an AML alert? or a card fraud alert? Again, this has to add up to 100% of your spend on technology. Often, shared technology costs are tough to measure, so work with your technology partners to really understand your use of those shared pieces as a percentage of the whole.

If, due to your company's budget allocation methodology, your department gets some or all technology services for "free" don't think you're off the hook.

Those services are paid for by someone, somewhere. Find out who. Get them on board. They also need to think in terms of business cases. If you can reach across organizational boundaries and collaborate with other departments to reduce overall IT costs, you're likely to appear on the promotion radar at high levels of the organization. Senior managers view this type of behavior as alchemy and tend to reward it well.

Now look at your impact on the institution's profitability. What business do you stop/prevent? What business do you monitor? What business is outside your scope? For each of those categories, what are the historical losses and recoveries?

Similarly, look at customer impact. What is the current attrition/retention rate of business? Talk to customers to find out why. Collaborate with your lines of business to assess customer satisfaction, especially among those who are "touched" by your group. On the fraud side, find out how many defrauded customers leave the institution within 6 months. How happy are they by your handling of their fraud event? On the AML side, the "customer" might be a regulator. Find out what their risk assessments say. What are they concerned about? What kinds of fines or orders are they hitting competitors with?

Get your statistical gurus to slice and dice the results and find differences. The end of this effort should be a "marginal contribution to profitability" percentage.

In other words, how many basis points do your activities add to (or remove from) overall profitability of each line of business?

Benchmark these stats against industry (or at least peer) numbers. Analyst reports and consulting firms are good at helping with this cross-industry view.

By following a framework like the one described here, the "benefit" side of the CBA can be fully understood. The initial effort might be high, but this work is reusable for every subsequent CBA. Individual metrics might change, but the overall benefit-assessment framework will not.

Monday, March 14, 2011

What Amazon Can Teach Banks About Fraud May Surprise You

While they do not always succeed, FIs constantly fight a very expensive battle against fraud attack. Across the US industry, FIs spend $250-300M a year on IT alone. Spending on Fraud Prevention Operations averages 6x-10x this number. That's nearly 1% of industry revenues (using numbers from Fortune Magazine). Sadly, despite this significant investment, fraud losses are estimated by Gartner Group to be 5-8% of revenues. This goes straight to the bottom line as a write-off, especially painful in an industry that hasn't turned a profit in 3 years.

Let's focus for a moment on the ratio of spending between IT and Ops. Across the industry, FIs spend far less than a third of their Anti-Fraud budget on technology and projects. If you include actual fraud losses in the numbers, that percentage drops well below a tenth of all spend.

This tells me that FIs don't trust their technology. When the rubber hits the road, they fall back on laborious manual processes. Step onto the floor of an FI's Anti-fraud department and you'll see why: reams of paper, hundreds of phone conversations, managers prowling the aisles, quants debating math on whiteboards, and armies of data-crunchers building ad-hoc reports in Excel. Look more closely and you'll see that the investigators have multiple PC monitors so they can switch among the dozens of bank systems, each of which contains a few small pieces of the client's overall behavior puzzle. I call this "swivelware" or "alt-tab-ware" and I see it as a clear symptom of a larger problem in the industry.

Swivelware is simply the human response to a failing of technology. Investigators need a full picture of the client's profile: "one-stop-shopping" access to all the client's identifying details, relationships, transactions, historical behavior, and other info. To put all this info on one screen requires a deep and comprehensive level of IT system integration. That's not easy or cheap even under stable conditions. It's nearly impossible in the real world of booms and busts, economic cycles, industry consolidation, new products, new client segments, new fraud patterns, new IT systems, and constant transformation. In fact, this is a never-ending initiative. Unfortunately, most IT spending is driven by corporate budgeting cycles, not by business objectives. This leads to a myopic, fire-fighting, quarter-by-quarter approach in which managers try to constrain the life of these initiatives by breaking them into discrete, well-bounded projects. Unfortunately, the sum of those parts does not add up to the whole business objective, and the result is swivelware.

When I hear a client say they have a "never-ending project" I know that, like it or not, they're really talking about a mis-categorized permanent business process, just like Accounts Payable, HR, or Accounting. It is often a tough sell, but my objective in these cases is to convince my client that they must create a permanent capability to address the business need, including permanent staff, permanent funding, and permanent management with permanent objectives, authority, and accountability.

FIs which have the foresight to do this will lead the industry in establishing competitive advantages through unique and advanced capabilities. Said another way, if you stand up a department whose objective is ongoing integration in order to develop a holistic view of each client, that department will develop capabilities and skills required to fulfill their stated objective. They will also quite likely find other creative ways to use those capabilities and skills to create additional unanticipated value for the institution.

One telling example of this is Amazon, which started as a bookseller, but realized its ingenious supply-chain was a competitive advantage. It leveraged this capability to become a marketplace for all sorts of products, and grew exponentially as a result. More recently, the Amazonians have realized that the infrastructure they built to link millions of customers to thousands of merchants is another competitive advantage. They are now leveraging this to offer "cloud computing" services to businesses.