Time to shift gears in Technology Risk and Compliance

Don’t have time to read everything? Spend five minutes scanning whatever is red.

Boiling Frog

We all have heard about the boiling frog analogy. The story is that when the frog is dropped into the boiling water, it will jump out. However, if the frog is put in warm water which is then slowly boiled, the frog will not perceive the danger soon enough and will be died.

This analogy when applied in the risk context refers a business situation where small changes in the context are not noticed or their significance not well understood. A somewhat relevant real life example can be found in the Westpac Advisory Panel Report into Board Governance of AML/CTF Obligations.

Observing trends can be helpful in identifying changes in the context which can help in updating organisation’s approach towards risk.

Technology Risk

I believe ISACA’s Risk IT Framework 2nd Edition outlines the Technology Risk scope really well.

The Risk IT Framework concerns the entire spectrum of I&T risk—any business or mission risk related to the use of, or dependence on, information and communications technology (ICT), operational technology (OT), network or internet of things (IOT), electronic data, and digital or electronic communications. The framework is founded on the core principle of serving stakeholders and enhancing business value through effective enterprise governance and management of all types of I&T-related risk. In this publication, information security, information assurance and cybersecurity are treated as subdomains of I&T-related risk.

ISACA Risk IT Framework Page 9 of 46

Trends in Technology Risk

I have observed below trends in relation to technology risk:

1. Industries have embraced digital transformation. The technology changes are rapid particularly in the banking and financial services industry. Dependency on technology in delivering the banking and financial services are increasing day by day. A cyberattack can result in prolonged disruption of business activities.

2. Information security incidents continue to rise. With increased use of IOT devices, operational security is gaining prominence. The financial cost of cyberattacks are rising.

3. The regulatory focus on information security in the financial services industry is increasing. APRA has mandated information security standard CPS 234 Information Security since July 2019. Australian privacy principles have been updated in 2019. NPP Australia and SWIFT has issued clear information security controls expectations.

4. Increasing expectations to meet “social license obligations” changing the “purpose” of the Bank from shareholders’ return maximisation to a broader set of stakeholders including employees, community, customers, suppliers and regulators. (Source: Westpac Advisory Panel Report into Board Governance of AML/CTF Obligations).

5. Increasing expectations about what boards can and should do evident by the larger and growing statement of duties of a director which poses a challenge for non-executive directors – how to cover large scope of matters that have to be addressed. (Source: Westpac Advisory Panel Report into Board Governance of AML/CTF Obligations)

Questions

Each business in unique. However, the below questions will help in identifying the need to revisit your technology risk and compliance strategy.

1. Has your technology risk and compliance team capability and capacity grown in proportion to the digital transformation projects pipeline? (If your organisation doesn’t have any digital transformation project then it may be a serious question 🤔.) When you hear your project managers complaining about the time taken by technology risk and compliance teams in various activities, it may be an indicator that your technology risk and compliance teams do not have sufficient resources or there is an uplift needed in capability.

2. Does your organisation have adequate risk framework which guides in taking effective risk based decisions for technology risk? I believe it is a fundamental step to recognise technology risk and compliance as a material risk in the risk framework. This will help in setting up appropriate risk appetite as well as policies and procedures to aid decision making. No organisation has unlimited budget for technology risk. Accordingly, it is important to set up risk framework which can help in decision making.

3. Has your technology risk policy framework operationalised effectively / embedded in IT activities? Effective implementation requires a balance of systems, processes, people along with empowerment and encouragement. A reliance on internal controls framework alone will have limited traction. When you see key technology risk indicators remaining Amber or Red for a prolonged time period, it may be an indicator that technology risk policies are not effectively implemented. Another indicator may be repetition of issues in technology risk and compliance space.

4. Does your third party risk program covers technology risk considerations effectively? Your business will be relying on your third party internal controls to manage technology risk. The performance of these controls are out of your control. Your third party may be your weakest link (e.g. SolarWinds Hack – it was a highly sophisticated one or recent website outage).

If your answer is yes to every question above, then either the technology risk has got its prominence in your organisation or there is a need to ask yourself is it really a resounding YES?

Notes on Advisory Panel Review Report in Westpac Board Governance

Introduction

Westpac released the Advisory Panel Report into Board Governance of AML/CTF Obligations on 4 June 2020. While the report appears to be focusing on Westpac’s AML/CTF compliance issues, the report provides valuable insights into management of non-financial risks.

Below are my notes summarising the report. I am focused on key lessons from this report and sharing my understanding on risk governance.

Don’t have time to read everything? Spend five minutes scanning whatever is red.

Background

AUSTRAC alleged Westpac Board for inadequate oversight in the statement of claim covering serious AML /CTF contraventions. As part of Westpac’s response and investigation into the AML/CTF non-compliance, Westpac conducted two separate reviews: (1) Advisory Panel Review on Board Governance of AML/CTF Obligations, and, (2) External independent review on management accountability assessment.

Both the reviews looked at Board governance and management practices in reference to AML/CTF compliance over 10 years. Westpac imposed remuneration consequences to 38 employees. The AML/CTF contraventions resulted in some significant leadership and governance changes: Westpac CEO resigned, Board Chairman brought forward his retirement and Chairman of Board Risk and Compliance Committee decided not to seek re-election to the Board.

Advisory Panel Report into Board Governance of AML/CTF Obligations:

Westpac appointed an advisory panel to review Board Governance of AML/CTF Obligations. The scope of their review was to answer below questions:

  • Were the formal Board processes, including information flows, adequate to ensure informed oversight of compliance with the requirements of the AML/CTF Act?
  • Whether the level of diligence exercised by Directors within these processes was appropriate?

Key Points from the Advisory Panel Report

Context

a. The report sets out the context with four trends in the last decade which could have been recognised by Westpac earlier in setting its approach for managing financial crimes risk. The four trends are:

1. Rapid technology changes in the banking industry which not only plays a major role as a growth and governance enabler, puts an upward cost pressure and also changes the risk profile of the Bank.

2. A decade of increased regulatory focus upon financial crimes evident by new regulations and high profile litigations in the US, UK and Europe.

3. Increasing expectations to meet “social license obligations” changing the “purpose” of the Bank from shareholders’ return maximisation to broader set of stakeholders including employees, community, customers, suppliers and regulators.

4. Increasing expectations about what boards can and should do evident by larger and growing statement of duties of a director which poses a challenge for non-executive directors – how to cover large scope of matters that have to be addressed.

b. Westpac has 10 non-executive directors and CEO as part of the Board. The Board is balanced with three directors having technology and transformation experience. The governance structure of the Board is mainstream and fit for purpose but has capacity issues.

c. Westpac follows 3 lines of defence risk governance structure but has accountability issues.

d. The report indirectly acknowledges the 2017 Commonwealth Bank’s AML non-compliance as a defining event and provides a comparison of the Board’s role before and after 2017.

Before 2017

a. The report noted shortcomings were evident in the monitoring of financial crime risk management and related controls particularly early in the years under review. Prior to 2017, the Board and management attention to financial crimes risk was less even though there were some warnings about the importance of the financial crimes risk management particularly from overseas.

b. While the Board was getting the information reports, there was a problem with the content of the information. There is absolutely no evidence that these errors / omissions were intentional. The simple fact is that management did not know and hence could not inform the Board until they did know.

c. There appears to have been no attempts to sugar-coat the assessments. Summary traffic light assessments moved between ‘amber’ and ‘red’ and never to ‘green’. The Bank’s own risk assessment was constantly rated ‘out of appetite’. While the matters were reported to be getting management attention, the long period of time that unacceptable risk appetite persisted is notable.

d. Problems around correspondent bank due diligence were noted by management along with remediation requirements as far back as 2011-12. Later on in 2019, AUSTRAC noted in the statement of claim that though Westpac conducted 47 correspondent banking assessments, these assessments had various shortcomings which mean Westpac didn’t comply with the law.

e. The AUSTRAC assessments in 2012 and 2016 recommended improvements.

f. While Internal Audit conducted reviews in 2011 and 2014 in relation to IFTI reporting compliance, and suggested improvements, there was no conclusion that the reporting of IFTIs was not compliant.

g. The improvements suggested by Internal Audit were not adequately followed up by the first line of defence nor did the third line appear to check whether or not this had been done.

h. Internally it was known that to meet compliance obligations in the financial crimes area, the IT systems and how they are used had to be fit for purpose. Significant resources had been invested in IT systems however the way systems were used may have contributed to ineffective regulatory reporting.

i. The extent of the issues became clear during 2017, when dealing with individual issues became wider task and it became clear that ‘band aid’ solutions were inadequate.

After 2017

a. A financial crime workshop and deep dive were held for all members of the Board Risk and Compliance Committee.

b. Westpac conducted an investigation in the institutional banking division which made the extent of the problems clearer.

Once the under-reporting of IFTI reported to AUSTRAC in 2018, the communications from the regulator made very clear their view of the seriousness of the issue and the fact that it had persisted so long. They flagged a concern about the control environment and began seeking more detailed information. At the same time the Chief Risk Officer noted in a memo to the Board that a key message from different regulators and reviews was that Westpac had been slow to act on certain long outstanding issues.

c. It is clear that the level of diligence applied by the Board to financial crimes risk management increased significantly around 2017.

d. A series of executive appointments, change in processes and reporting lines were approved.

e. Internal resourcing dedicated to financial crime (including financial crime operations) increased substantially, doubling to 750 people in past three years with a commitment to add 200 more people.

f. The Board approved developed a detailed plan and resolved to implement Part A program in 2018.

g. A Financial Crime Strategic Plan was approved by the Board in March 2019 after extensive work in 2018.

h. An IT system upgrade was planned to be delivered at a cost of $60 Million.

i. Management of non-financial risk was embedded in Westpac’s senior management remuneration scorecard.

Report Recommendations

a. While the incoming leadership of Westpac has quickly assumed ownership of AUSTRAC issues, the time it takes for implementation is a clear problem and the blurred accountability that results from management through committees is a recognised concern.

b. There are many strengths of matrix management model but end to end visibility and ownership of the processes is not one of them. This is a bigger risk for those processes which do not have a loud corporate voice and are characterised by non-financial KPIs which are not monitored daily as are financial metrics, customer statistics and like. Clear accountabilities must be developed and enforced.

c. Continued effort is needed to clarify the responsibilities within three lines of defence and make the model work. Each line of defence has a role and care should be taken that line one does not delegate its responsibility to line two.

d. There is a need to rebuild relationship with AUSTRAC.

e. Benchmarking with domestic competitors is useful but not sufficient.

f. Every board needs to periodically review its own processes as directors can be overwhelmed with detailed papers, meetings get longer and issues lose visibility given the number of agenda items and shifting priorities.

g. The way in which Board monitors their need to meet AML/CTF obligations should be reviewed. There are three types of monitoring required:

1. Monitoring the many financial crime risks facing Westpac,

2. Monitoring the risk management framework to ensure it remains appropriate and proportionate to those risks, and,

3. Monitoring the transactions and activities of customers.

h. The ‘traffic light scoring system’ for conforming to risk appetite is one monitoring tool used but deeper issues also need routine consideration and perhaps different types of reporting.

i. The Westpac Culture, Governance and Accountability Self-Assessment caused a large number of improvement initiatives to be undertaken from 2019 onwards. This work should be focused and accelerated with clear accountabilities for delivery, including a more pressing timetable.

What’s this website all about?

Hi. I am Ripal Shah. I work as a risk manager in the financial services industry in Australia. This is my blog.

It is about how we can make things easy and fun in the world of Governance, Risk Management, Technology Risk, Compliance and Internal Audit. (Who yawned?? 😉)

Though everyone agrees with the strategic importance of these topics in the success of organisations, the trouble starts with its implementation and particularly applying various tools and techniques. 😜

There is a wide variety of literature and standards available on what ultimate goal on Governance and Risk Management looks like (which also creates a wave of confusion🤦‍♂️ but that’s a different topic😊), however the implementation of these standards need to be in a situational context.

Without exception, the implementation / improvement in governance and risk management frameworks involves behaviour change. I believe that technology and psychology can be very useful here. I don’t claim to be a psychology / technology expert. I consider myself fortunate that I got an opportunity to see the world from psychology and technology perspective and its possible application in risk framework implementation by standing on the shoulders of giants.

I have a keen interest in financial markets, investments, spiritual growth, probability and management. I haven’t decided anything on that yet but I may post some stuff here. Who knows.😊 Just in case I post some stuff here, all routine disclaimers of personal finance world applies.

I intend to write one post every fortnight. I welcome your views and opinions on my posts. You can send me your views at ripal.ca@gmail.com

I was born in India. I am currently living in Australia. Accordingly, my spellings follow Australian and Indian English style rather than American English.

If you would liked to know more about me, please refer my LinkedIn profile.