Showing posts with label Risk. Show all posts
Showing posts with label Risk. Show all posts

Thursday, March 6, 2014

Do We Need Ratings Agencies?


TED.com recently published a talk by Annette Heuser about ratings agencies. She argues that the current ratings agencies need to be replaced with a new, non-profit one. This, she feels, will resolve current potential conflicts of interest and will, presumably, lead to better ratings. Specifically, her focus is on giving sovereign debts higher ratings in order to reduce borrowing costs for countries which have a poor credit history.

Unfortunately, her proposal suffers from a misunderstanding of basic economics. The issue is not public vs. private. The issue is who pays. Currently, as she says, the issuers (who are being rated) pay, causing the potential for conflict of interest. The potential conflict obviously doesn't go away if the rating agency is non-profit. A non-profit still needs to cover the costs of their research and rating process. Thus, the very very simple fix is to switch the payer from the issuer (country or company) to the lenders and buyers of the securities (banks or investors). This could take the form of a transaction fee, or it could take the form of a consortium whose budget is covered annually by buyers/investors. I would strongly suggest that Annette refocus her attention on this aspect and ensure that INCRA is funded thus. Her focus on non-profitism, transparency, breaking the grip is just a set of side-shows.

But wait, there's more. An achilles heel of any ratings agency is their reliance on their chosen rating methodology/algorithm. As we saw in 2007, securities with AAA ratings crashed. This objectively demonstrated that the prevailing rating methodologies were inadequate because they did not accurately factor in all risks and probabilities and/or did not accurately represent them to consumers. Ms. Heuser's proposal to clone the current (flawed) rating-agency structure would no correct this problem. A far better solution would be to empower investors.

How?

Replace ratings (the conclusion of one entity's analysis) with the ability to rate. In other words, give investors the ability to formulate their own conclusion, and to see what others have concluded. To do so, empower investors with powerful analytical tools that can access rich, diverse, open-source data.

Now is the time. All of the component pieces are proliferating today. OpenGovernment info can be combined with open-source historical markets and financial data, open-source regression models, data analytics, data visualization tools.

Of course, there are issues to be sorted out. The first to get these right will have a massively winning business model:

  • Making money - who pays? for what? how is it priced?
  • Messy data - to be valuable, the platform needs data from a multitude of sources. Necessarily, data will thus be heterogenous in terms of structure, quality, accuracy, completeness, encoding, and definitions. To be useful, the platform will need to provide ways of using a heterogeny of data without degrading quality of outcomes
  • Source Neutrality - are certain data sources "better" than others? Should certain data providers be made preferential? Should opinions or interpretations or results of analytics be included in the data? If so, how should they be differentiated from raw facts?
  • User Neutrality - should all users have access to all data? Should users have to subscribe to specific data sources/quality levels/time periods?
  • Modeling skills - Will users have the ability to create their own valid ratings? Will they have the requisite knowledge of data, probability concepts, risk concepts, details of financial products? How can the platform abstract these concepts? 

Bottom line, ratings agencies are relics of a prior age, just like Encyclopedias and farriers.

Sunday, March 2, 2014

How Your Customers Should Think About Bitcoin

Bitcoin reminds me of the Gold Standard or UN SDRs. They're great in concept, but probably needs to weather a good crisis or two before I'll trust it.

The first thing to understand is that it is a bearer-owned stored-value mechanism like gold, dollars, or bearer bonds. It's not a payment network like paypal. It's not a payment mechanism like a credit card. It's not an account. Whoever physically "holds" the bitcoins owns their value.

This leads to one great benefit: Unlike the USD or other national currencies, no politician can use them as a political tool by using inflation to ruin the value or using executive orders to inflate the value of Bitcoins. So, like gold, they should be safe stores of value, immune to a specific country's situation.

But the reality is far less sanguine or simple. There are problems:

  • The notion that it is outside the influence of governments hasn't been tested. I'm sure government lawyers are working on this. Every single time a bitcoin changes hands, its authenticity is verified at the central database. This means every transaction and transfer can be monitored. The amount of data is too juicy for the NSA to ignore. But will other parts of the government (executive branch, for example) also get ahold of the info? 
  • The way they determine the value of the currency. Bitcoin is based on supply and demand. Because it is a small market with relatively few traders, it is easily manipulated. The issuing company says they are increasing the supply steadily based on the size of the economy. The good news is that, since 
  • Counterfeit. Every computer system has weaknesses. Even the most secure networks have been attacked, and most of them have been compromised at some point. I don't trust that Bitcoin is secure enough, if for no other reason than because it hasn't been attacked hard enough. 
  • Fraud. There are system-administrators in the Bitcoin foundation who must have special system access in order to do their jobs. These people could certainly be bought off for the right price. We haven't invented a really technologically fool-proof way to avoid this yet. Mt. Gox is the obvious example of what can go wrong here.
  • and, of course, not many places accept bitcoins as payment (currently)

Friday, June 29, 2012

Is the Future More or Less Secure?

The Economist online is currently hosting a debate about cybersecurity and specifically the question of whether we are headed for a more or less secure world as interconnectivity increases. My vote is "no" for the following reason which I posted to their debate site:
It would be quite difficult to compromise security if we each existed entirely in our own hermetically-sealed network like an egg in a carton or a standalone PC on a desk. Each connection with the outside world creates a perforation in the egg shell and creates a security risk in the form of a point of potential compromise. The perforation can be compromised or the "tube" connecting me to the next "egg" can be compromised. Further, the "egg" I'm connecting to can be compromised. Or an "egg" connected to the one I'm connected to can be compromised. As you can imagine, hyperconnectivity increases the number of points of potential compromise exponentially with time. 
Our current risk-mitigation approach tries to hermetically seal all the perforations, joints, and pipes by wrapping them in a "fortress firewall." This becomes exponentially more difficult with the increase in points of potential compromise. Attacks are inevitable, as are compromises until and unless our approach to risk mitigation shifts from a "fortress firewall" approach to one in which we can examine, wrap, and filter actual bytes of information as they float around cyberspace. 
While I don't know what this approach will look like in practice, I predict it will include a strong focus on data provenance. Imagine an "HTTPS 2.0" in which we not only wrap packets of data in an encrypted security layer, but also give that packet the ability to either reveal its contents or self-destruct based on who/what/where/when/WHY it is accessed. 
Until then, data security risk shall continue to increase.

Thursday, January 5, 2012

Food for New Years Thought: The Future of Banking

Every consultant worth his salt is busy trying to write something prescient on the future business model for banks. GLG Research recently published a report calling out the following key parameters, with a focus on retail banking:
1. Peer-to-Peer (P2P) Lending: An advanced technology that eliminates middlemen and directly connects borrowers and lenders.

2. Prepaid General Purpose Reloadable (GPR) cards: In return for modest commissions, a global agency network of convenience stores and retailers are now enabling cards to be “loaded” with cash. When equipped with remote deposit check capture, direct deposit, bill payment and ancillary credit, savings and investment accounts, these cards make traditional bank branching redundant. eWallets such as those touted by ISIS, Google, Visa, Amex, Paypal and FaceCash are the offspring of GPR built on the same infrastructure; similar economics but a different, arguably more convenient, access device.

3. Social Media: Social media like Facebook and LinkedIn can offer insight into customer behavior that can be applied to enhance customer acquisition, retention, and even underwriting (http://www.freepatentsonline.com/20110112957.pdf).
Banks which are early movers in this area have a great opportunity to reverse the post-2007 profitability decline. Success, in my opinion, will depend on three things:
  • Getting it done quickly
  • Getting the customer experience right
  • Getting the risk management right
Those aims are, in many areas, conflicting. A balancing act is required. Wading too timidly into these areas might cause impatient "early adopter" customers to defect, or at least decrease their activity level. Making a big splash in these areas without consideration of risk factors invites the wrong kind of customers and is sure to balloon losses.

Critical to all three of these emerging trends are the "Three Risk-Management A's of Next-Generation Banking"
  1. Analytics: Collecting the necessary data about behavior as well as customer preferences to objectively understand and address behavior in a consolidated, risk-based, customer-centric manner 
  2. Authorization: Making an informed, risk-based decision about what the bank allows the customer to do
  3. Authentication: Making sure the transaction is being done by the customer, not a fraudster
Periodically on this blog, I will individually look at these trends, highlighting the risk implications for the future banking business model.


Monday, June 13, 2011

The Convergence of Data, Identity, and Regulatory Risks

This blog started 2011 with a post arguing for the inclusion of financial crime as a type of risk:
"Financial Crime (including topics like Money Laundering, Identity Theft, Fraud, Unauthorized Access, and Data Theft) is the next frontier in the evolution of Risk Management." 1/3/2011
Halfway through the year, this has been borne out in the headlines. While no institution is immune, headlines this week have given one clear example of what I was talking about:
"Citibank has revealed that it detected a data breach last month that exposed fully 1% of all its North American credit card customers’ account details. Citi has about 21.2 million credit card customers in North America according to its annual report, implying that close to 210,000 accounts may have been hit." Andy Greenberg, Forbes Blog.
Only 11 months ago, the remnants of Countrywide Financial settled a class-action lawsuit by setting aside $56.5 million (not including court costs) to cover claims of anyone impacted by an alleged data breach of 2.5m identity records. They, like Citi, were particularly criticized for delaying disclosure. This presumably allowed them time to assess vulnerability, fortify security controls, and perhaps get their legal arguments in order. At the same time, their delay gave identity thieves extra time to use the stolen data to defraud Countrywide's unsuspecting customers.

Countrywide's negotiated settlement puts the average hard-dollar cost of losing an identity record at $22. Many analysts estimate that the all-in number is four times as much once you factor in the soft costs such as reputation damage, lost business, and cost of additional controls. As a result, the rule of thumb I and many of my clients use to size up the cost of a data breach is $100 per identity. That makes Citi's breach quite costly!

In fact, Citi's latest incident comes atop a tide of recent compromises at a number of global firms, including a particularly disturbing breach of the "gold standard" RSA SecurID tokens which are used by many firms as an enhanced security measure for things like sensitive network access and large-dollar online banking transactions.

To pretend that these events "won't happen here" or "are black swans" and thus don't need to be factored into the price of doing business is as negligent as saying that mortgages never go underwater. Blithe assumptions like these are precisely why big, smart firms end up in catastrophe.

Finstitutions need to view financial crimes including data theft, identity theft, and fraud as risks which:
  • are intrinsic to their business, just like credit and market risks
  • are not outlier events, but rather are inevitable (and growing more frequent)
  • must be mitigated, monitored, and controlled
That's lesson one of 2011.

Today, 47 states have data privacy laws. It's the Internet, people! State-by-state laws don't make sense in this context. The good news is that, without a doubt, legislators and regulators alike have noticed these headlines and have stepped up their efforts to develop additional regulatory requirements to address the issue.

The Forbes blog goes on to say:
"The White House’s proposed cybersecurity policy outlined last month would include a mandatory federal breach disclosure law, and another bill proposed by Senator Patrick Leahy would similarly make concealing a data breach a federal crime."
These legislative proposals are atop upcoming FDIC regulations and FFIEC standards on authentication which will likely contain provisions addressing:
  • More frequent risk assessments focusing on authentication and related controls at least every 12 months and prior to implementing new electronic financial services
  • More robust controls as the risk level of transactions increases.
  • Layered security to detect and effectively respond to suspicious or anomalous activity both at initial login access and at initiation of online transaction
  • Multi-factor authentication, well beyond simple device identification and easily answered challenge questions
  • Increased customer education and awareness
Therefore, lesson two of 2011 is that regulatory compliance is another risk which should be incorporated into every FI's risk management framework, policy, and practice.

Monday, January 3, 2011

A Risk by Any Other Name Would Burn as Bad

Risk management is bread-and-butter for Corporate-level execs, Line-of-Business leaders, and Risk Managers. Crises like 2008 provide hard evidence that rock-solid risk management is an integral part of the business of finance. Those financial institutions (FIs) that had a comprehensive, objective, and disciplined risk management framework survived. Those that outsourced their risk management to their business partners, trading desks, LOB leaders, or customers found their balance sheets pushed into risky and turbulent waters. Most did not survive the voyage.

What follows is a brief and anecdotal discussion of the evolution of how FIs view, and therefore address risk. My objective in trawling this history is to demonstrate:
  1. That risks mutate as rapidly as ( the evolution of the business model * the increase in the complexity of the industry )
  2. That, before managing risk, it is necessary to clearly define and measure it (but that failing to measure it doesn't mean it doesn't exist)
  3. That the industry is always at least a step (or 3) behind
  4. That Financial Crime (including topics like Money Laundering, Identity Theft, Fraud, Unauthorized Access, and Data Theft) is the next frontier in the evolution of Risk Management
In the 60's and '70's, and thanks in part to the likes of George Soros, FIs discovered that credit risk was a relative measure. A whole market could go up ... or down, taking even good credits with it. FIs realized they were in a race to catch and control a previously-unidentified form of risk: Market Risk. Thanks to Latin American dictators and Mideastern ayatollahs, FIs learned that sudden political shifts can lead to unexpected moves in currencies, tax regimes, and regulatory structures, which in turn ruin individual customers or whole markets. Hello, Sovereign Risk.

The '80's started with rampant inflation, which deeply submerged many loans, bonds, swaps, and other fixed-income instruments. FIs realized they needed to be able to manage the risk related to the overall prevailing interest rates. In order to manage it, they had to identify and measure it. Thus emerged Interest Rate Risk. By mid-decade, Volcker had tamed rates, leading to an explosion in leveraged trading activity by a rapidly-growing list of firms across an ever-diversifying spectrum of markets. Every once in a while, one of those firms couldn't pay up when their margin call or loan came due, or couldn't deliver the securities which they had sold. It was time again to start managing new types of risk: Settlement Risk, Counterparty Risk, Liquidity Risk, Concentration Risk.

The rip-roaring '90's grew business size and complexity to levels which far outstripped managers' ability to even understand the risks to the business, much less manage those risks. Authority was implicitly devolved to the front office, for whom risk management is just a hurdle between them and their sale. Rather than deeply and objectively analyzing risks to new products and services, they outsourced the effort to the market; if a competitor did it, it must be OK. If a smart customer bought it, it must be OK. If the risk management rules and models flashed red with warnings, they were "re-calibrated" to shut up. Welcome to the era of Operational Risk.

For quite some time, there was no consensus about what Operational Risk was, how to measure it, or what to do about it. The Basel Committee defined it as "The risk of loss resulting from inadequate or failed internal processes, people and systems or from external events." This was far too abstract for most people to convert into real-world risk management strategies, but at the highest level, most understood that the way they ran their business might come back to bite them. The news provided a steady stream of examples of bone-headed moves by large companies which sent their stock prices into free-fall. Investors got burned. Managers got fired. Risks continued to be piled on. Risk Management was absent.

The first 10 years of this century proved that fact. FIs, governments, academics, and talking heads in the news spent a lot of time talking about all the risks a business face: headline risk, bad business model risk, rogue employee risk, reputational risk, legal risk, political risk, act-of-God risk. Without finishing the task of defining what it was, the industry shifted focus to building "something" to manage Operational Risk. Risks were inventoried, abstracted, debated, categorized. Laws (such as Sarbanes-Oxley) were implemented saying that "something" had to be done. "Someone" had to be held accountable. Regulators began prodding their FIs for evidence of compliance. For most FIs, their best evidence was not in results, but in large amounts of money they were allocating to large, ambitious projects, the details and timing of which were TBD.

Unfortunately, 2008 showed that, for most firms, the risks beat the projects to the finish line, to tremendously expensive effect. We learned about a new type of risk: Systemic Risk.

House prices, over-indebted Americans, Chinese exchange rates, and greedy bankers got most of the headlines, but embedded within the rubble of that crisis were a vast array of crimes. These crimes led to hard-dollar losses which contributed to the gravity of the crisis. The economic downturn, coupled with the globalization effects of the Internet, have led to an increase and diversification in financial crime.

While not yet fully emerged from the previous crisis, FIs are once again in a race to head off the next crisis: Welcome to Financial Crime Risk. While many FIs see this as an operational problem, or a law-enforcement problem, it is indeed a risk management problem, just like all the other types mentioned above. It is an intrinsic part of the business of finance, just as the others are. To prevent 100% of Financial Crime is to stop doing business. FIs must instead manage and mitigate it as a risk, making informed decisions about the resources they allocate to the task. FIs must recognize and measure the cost of residual risks which they choose not to mitigate. This is not a one-time decision, but an ongoing process of objectively assessing the cost and benefit of their choices.