Copy of Incident Management Procedures & Guidance
Total Page:16
File Type:pdf, Size:1020Kb
CONFIDENTIAL WBC.100.118.8029 Incident Management Procedures & Guidance FOR INTERNAL USE ONLY Document Owner: Group Head of Operational Risk & Insurance Date updated: December 2015 Version: 2.9 Location: Risk Document Library Incident Management Procedures & Guidance Page 1 of 62 CONFIDENTIAL WBC.100.118.8030 Document version control No. Date Version Author Description 1 - 5 11/06 V0.1 Mike Purvis Drafting to support introduction of new process at 1 Dec 06. 6 8/1/07 V0.2 Mike Purvis Drafting to reflect introduction of new processes at 31 Dec 06 7 22/1/07 V0.3 Mike Purvis Drafting to reflect new systems in February 07 8 06/02/07 V1.0 Steven Bardy Drafting to reflect Business Unit input and changes to reflect migration to new Policy Framework 9 15/02/07 V1.1 Aislinn Strang ORMF review amendments 10 07/08/07 V1.2 Maebehe Garcia Drafting to clarify issues related to credit and market risks and other amendments 11 24/04/08 V1.5 Andrew Leslie Annual Review Update for Rapid Recovery, Insurance Threshold and APS115 12 23/12/08 V1.6 Dung Thien Tran Update for the implementation of ACCORD 13 22/04/09 V1.7 Andrew Leslie Add hand written marked up edits to electronic version 14 15/05/09 V1.8 Andrew Leslie Simplified content. Integrated version to include SGB. 15 27/07/09 V2.0 Luke Tazelaar Updated from BU feedback 16 01/03/12 V2.1 Nadine Schaefer- Updated to reflect Policy updates and add additional Medappa guidance 17 02/04/12 V2.2 David Tan Updated to include operational risk related to project costs 18 24/04/12 V2.3 David Tan Updated to clarify about the treatment of near misses 19 05/06/12 V2.4 David Tan . Greater clarification to the Basel Business Lines section of the appendix for Retail and Commercial Banking having regard to Divisional input. Minor modifications to the Corporate Items Basel Business Line title to reflect the *Not otherwise allocated* categorisation in ACCORD. 20 20/08/12 V2.5 Juliette Lemaire . Include Lean incident Management Workshop Quick Wins : o Incident Ownership *Circuit breaker* o *Lite* treatment for incidents with potential or actual financial impact under $50,000 and $1,000 tolerance for GL/ACCORD reconciliation differences 21 07/03/13 V2.6 Juliette Lemaire/ . Updated to include AML / CTF management of David Tan incidents 22 03/06/13 v.2.7 Juliette Lemaire Updated to include Industry standards agreed at the Interbank forum with regards to the treatment of boundary losses Incident Management Procedures & Guidance Page 2 of 62 CONFIDENTIAL WBC.100.118.8031 Document version control No. Date Version Author Description 23 30/05/14 v.2.8 Juliette Lemaire/ Annual Review Derek Byrne . Updated to include Legal Risk related Operational Risk incidents (LOPs) and Outsourced Service Provider related Operational Risk incidents . Add a reference to the role of ACCORD support team . Updated to include a new section on Internal Escalation reporting . Updated to rationalise the list of Mandatory stakeholders . Updated to simplify appendices with regards to Reconciliation processes . Removal of appendix relating to ACCORD process on relocating incidents to support business restructure 24 11/12/15 v.2.9 Derek Byrne . Inclusion of a roles and responsibilities section and process flow . Reference to the new escalation process for incidents not owned within 5 days of identification. The inclusion of an exception for Technology, HS&W and Fraud incidents, which will now require ownership within 5 days of reporting in ACCORD, given that there are subsystems in place to manage the ownership of these incidents . Additional examples of Credit related Operational Risk incidents (CROPs) provided . Inclusion of additional industry guidance on the treatment of Legal Risk related Operational Risk incidents (LOPs) prior to capture in ACCORD Distribution Title/Function Sign-off/review Group Head of Operational Risk & Insurance Sign-off Head of Regulatory Affairs Review Enterprise Compliance Review Business Unit Heads of Operational Risk Review Head of Systems & Data Review Financial Crime and Fraud Review Group Health, Safety and Wellbeing Review Incident Management Procedures & Guidance Page 3 of 62 CONFIDENTIAL WBC.100.118.8032 Table of Contents 1 Purpose .....................................................................................................................6 2 Operational Risk Incidents .........................................................................................7 2.1 What is Operational Risk? .....................................................................................................7 2.2 What is an Operational Risk Incident? .....................................................................................7 2.3 Incident Reporting Thresholds ...............................................................................................8 2.3.1 Financial threshold ...........................................................................................................8 2.3.2 Non-compliance threshold.................................................................................................9 2.4 Related Incidents ...............................................................................................................10 2.5 Money Laundering (ML) / Terrorism Financing (TF) incidents ....................................................10 2.6 Boundary Losses ................................................................................................................12 2.6.1 Credit Risk-related incidents caused by Operational Risk (CROPs).........................................12 2.6.2 Market Risk-related incidents caused by Operational Risk (MOPs) .........................................15 2.7 Legal Risk related Operational Risk incidents (LOPs) ...............................................................16 2.8 Outsourced Service Provider related Operational Risk incidents ................................................17 2.9 Operational Risk incidents related to projects .........................................................................18 3 Incident Management Process..................................................................................19 3.1 Incident Management Metric................................................................................................19 3.2 Incident Management * key roles & responsibilities.................................................................20 4 Incident Identification and Recording.......................................................................23 4.1 Incident Identification and Recording * Example.....................................................................24 5 Incident Verification.................................................................................................26 5.1 Incident Verification * Example ............................................................................................29 5.2 Rejecting an incident ..........................................................................................................30 6 Incident Ownership..................................................................................................31 7 Assessments............................................................................................................32 8 Incident Rectification ...............................................................................................32 8.1 Incident rectification * Example ...........................................................................................34 9 Incident Closure ......................................................................................................36 10 Re-Opening of Incidents..........................................................................................36 11 Data Quality.............................................................................................................37 12 External Reporting...................................................................................................38 13 Internal Escalation Reporting ...................................................................................38 Appendix 1 Direct vs. Indirect Financial Impact...............................................................39 Appendix 2 Basel Business Lines ....................................................................................40 Appendix 3 Basel Event Types ........................................................................................45 Appendix 4 Product........................................................................................................47 Appendix 5 Process........................................................................................................49 Appendix 6 Mandatory Stakeholders ..............................................................................51 Appendix 7 Rectification Procedures on Financial Impact................................................52 Appendix 8 ACCORD financial reconciliation performed by Risk Systems & Data.............57 Appendix 9 ML/TF incident significant /systemic criteria................................................58 Appendix 10 Glossary of terms ......................................................................................59 Incident Management Procedures & Guidance Page 4 of 62 CONFIDENTIAL WBC.100.118.8033 Incident Management Procedures & Guidance Page 5 of 62 CONFIDENTIAL WBC.100.118.8034 1 Purpose The Operational Risk Incident Management (IM) Policy outlines the minimum