Op Risk Capital Models, Cyber Threats, and Heller Financial's ERM Turn

Book: Enterprise Risk Management: From Incentives to Controls
Author: James Lam
ISBN: 978-1-118-41361-6


Measuring Operational Risk Is Messy. Do It Anyway.

Lam picks up Chapter 14 with capital allocation. Market and credit models are mature. Operational risk models are not one-size-fits-all. Use a blend.

Top-down approaches infer op risk from what is left after credit and market capital or income volatility. Fast, but they ignore correlations, cause-and-effect, and tail events. The implied-capital and income-volatility models suffer those limits. The economic pricing model (CAPM-style) uses stock volatility minus credit/market volatility to capture reputation and opportunity cost, but lacks granular control incentives. The analog model benchmarks peers, which skeptics call wishful thinking when culture and incentives differ.

Bottom-up loss distribution models classify risks, gather internal and external loss data, and estimate capital at a confidence level. They support ongoing monitoring of error rates and turnover. Mapping external data is hard. Low-frequency catastrophes rarely appear in databases. Extreme value theory (EVT) focuses on tail losses, using monthly maxima over rolling windows.

Scenario analysis captures expert judgment and cause-effect chains on risk maps. Subjective, but essential for black swans. Post-2008 critics argue models create risk-reward arbitrage for unethical managers who game tolerances.

Multiple models together beat one false precision.

Mitigation, Transfer, and Best Practice

Measurement without action is pointless. Mitigation means people, training, process fixes, structure changes, controls, and system upgrades. Fidelity used “turbo teams” when indicators fell below minimum acceptable performance, reporting back in days.

Business units set goals, limits, and MAPs. Economic capital charges should nudge better behavior. Fix root causes, not symptoms.

Expected operational losses belong in reserves and pricing. Ten thousand transactions with $80,000 expected annual loss suggests an $8 risk adjustment per trade.

For tail exposures, combine internal controls with insurance. Workers comp pairs safety programs with policies. Cyber policies backstop IT controls. ERM asks you to quantify probability, severity, and capital, integrate with credit and market risk, set limits, then compare retention vs transfer using ceded RAROC.

Risk transfer vs risk finance differs: insurance pays between deductible and cap; financed structures reimburse over time.

Practice levels:

  • Basic - defined taxonomy, op risk manager to CRO, monthly committee, annual self-assessments, audit as checker
  • Standard - full indicator sets with MAPs, process maps, external loss databases, contingency plans, training, post-mortems
  • Best - economic capital by risk type, external early warnings (politics, regulation, tech), scenario simulation, insurance integrated with op risk, risk analysis in business plans and M&A

Emerging IT Risks

Cyber security - Nation-state attention shifted from terrorism to cyber crime. Energy sector losses run into tens to hundreds of billions annually. Denial-of-service attacks can freeze customer access for days (Charles Schwab, 2013). Defense is not isolation. Public-private ISACs share intelligence. DoD-style guidance translates to continuous testing, executive priority, automated defense, culture training, and lifecycle security.

Cloud computing - Cuts IT spend and adds flexibility, but dilutes control. Vendor clouds expose you to other tenants’ risks. One breach can hit many customers on a shared cloud. Extend your risk framework to the provider’s universe.

Social media - Productivity drains, malware vectors, insider leaks, and brand crises (Nestlé vs Greenpeace on palm oil). Policies need cross-functional ownership, not IT alone.

Case Study: Heller Financial

Heller went public in 1998 after Fuji Bank sold 42% for over $1 billion. CFO Lauralee Martin said benchmarks were now the entire market, not internal standards. Goals: 15%+ ROE, single-A ratings, 15% earnings growth, strong credit discipline.

Change exploded risk. Project BEST cut 15% of staff. Acquisitions and reorganizations shifted from buy-and-hold credit to originate-and-distribute hybrids and flow businesses like small-ticket leasing. Chief Credit Officer Mike Litwin warned operational risk dominates during transformation.

Litwin became Chief Credit and Risk Officer. An Operational Risk Officer role centralized measurement. ERM assessment, benchmarking, framework docs, pilot op risk reports in two units, enterprise risk reporting templates, and economic capital proof-of-concept followed.

Litwin’s key insight: many future write-offs are operational causes mislabeled as credit problems. Treat the cause, not only the effect.

GE Capital bought Heller in 2001 for $5.3 billion, citing risk management as a core asset.

My Take

Part 2 of Chapter 14 is where operational risk grows up. Lam admits models are imperfect and still insists on capital linkage, mitigation discipline, and insurance economics.

The Heller story mirrors every post-IPO or post-merger shop: credit culture is strong, everything else is chaos. Naming a CRO and ORO is symbolic unless incentives and reporting change with them.

Cyber and cloud sections feel even more current now. The Nestlé Facebook fight is a template for how not to handle stakeholder backlash.

If you implement one thing, make it a loss database plus MAP triggers with turbo-team escalation. Measurement can mature over time. Silent failures cannot.


Previous: Previous: Operational Risk Basics (Chapter 14, Part 1)
Next: Next: Three Stages of Business Risk (Chapter 15)