SlideShare ist ein Scribd-Unternehmen logo
1 von 15
Banks’
Korean Banks’ Efforts to Prepare for BCP :
 Effective Operational Risk Management




                27th August 2007

                   Yeong Sik Ohn
           Head of New Basel Accord Office,
             Financial Supervisory Service
Table of Contents



1 BCP as a means to manage operational risk


2 Korean banks’ awareness and readiness of BCP


3 ‘Supervisory Guidelines for BCP’ by the FSS


4 Tasks ahead for Korean banks in building BCP

                        -1-
1. BCP as a means to manage operational risk

◈ Business Continuity Planning [Management] :

  A whole-of-business approach that includes policies,
  standards, and procedures for ensuring that specified
  operations can be maintained or recovered in a timely
  fashion in the event of a disruption. Its purpose is to
  minimise the operational, financial, legal, reputational and
  other material consequences arising from a disruption
                 High-
                 High-level principles for business continuity (BCBS, August 2006)

                               BCP concept

                                              DRP concept


                               Disaster
     Business Part                                       Other IT Part
                             Recovery Part

                                -2-
◈ Operational Risk Management vs. BCP/BCM (1)


                               Loss Distribution of Operational Risk
        Frequency




              Bank’s
             Expense                        BCP And
             Coverage                      Insurance                              Capital
               area                        Coverage                            Coverage area
                                              area




                                                                                         Severity

                    Expected Loss                               Insurance
                        level                                 Coverage level

                                            -3-
◈ Operational Risk Management vs. BCP/BCM (2)


           ORM                              BCP/BCM


             Firm-wide business         -   Disruption of Core
 Scope                                      businesses/Core activities
             process



             To minimise the            -   To minimise the impact to
Purpose      operational risk               businesses due to
                                            operational disruptions



             Identify,                  -   Prevent, Prepare,
Process                                     Response, Restore, Pilot
             Assess/Measure,
             Monitor, Report, Control       test, maintain

                                -4-
banks’
2. Korean banks’ awareness and readiness of BCP

◈ Limited BCP focusing on IT Disaster Recovery Planning

 - Only a few banks have firm-wide BCP
 - Gap exists in awareness and capability of BCP among
   business units

◈ Various kinds of Contingency plans different in scope,
  purpose and procedure

 - Fire Protection Plan, War Emergency Plan, Contingency
   Plans in business unit level
 - No control tower for all contingency plans
 - The scarcity of the detailed guidelines and information
 - The lack of prevention/preparation functions
                            -5-
(AS-
◈ Contingency Plans for Disaster (AS-IS)
1. Disaster Recovery Plan
 - FSS require DRC (Disaster Recovery Center) (Jan. 2004)
 - Focusing on IT system only

2. War Emergency Plan and Fire Protection Plan
 - To protect tangible assets & people and to minimize loss

3. Contingency Plans in business unit level
 - The different scope, purpose and method by the maker


                            -6-
(TO-
◈ BCP for Disaster (TO-BE)


                   BCP
                          War Emergency Plan


             DRP          Fire Protection Plan


                     Other Contingency Plans




                    -7-
BCP’
3. ‘Supervisory Guidelines for BCP’ by the FSS

◈ Governance for BCP
  (Board and Senior Management)
  - The ultimate Responsibility for Business Continuity Plan
    and the effectiveness of BCP
  (BCP Function)
   - To manage the entire process of BCP
  - To assist the Board and Senior Management
  (Independent Review Function)
  - To review the effectiveness of BCP and compliance
    of all levels of staff
  - To conduct periodic review of BCP : at least annually

                           -8-
◈ BCP Development Steps


                            Risk
                           Analysis


                                                 Business
    Testing           Feedback                    Impact
                                                 Analysis


               Business
                                        BCM
              Continuity
                                      Strategy
                 Plan



                               -9-
◈ Risk Analysis

 - To identify the various potential risk factors and
   the priority of order in the event of a disruption
 - To assess the existing control means for risk factors

◈ Business Impact Analysis

 - To identify critical business services and functions
   to be delivered in the event of a disruption
 - To determine the priority of order, Recovery Time
   Objective, Recovery Point Objective and etc


                            - 10 -
◈ BCM strategy Formulation
 - To formulate recovery strategies for continuity of
   critical business services and functions in the event
   of a disruption
 - including BCM Model, Alternate site, recovery personnel,
   office facilities, technology requirements and etc
◈ Business Continuity Plan (BCP) Development
 - To provide detailed guidance and procedures to respond
   and manage a crisis
 - including Crisis Management Plan (crisis management
   team, crisis management process, communication
   strategy), Business Resumption Process, Technology
   recovery, Vital Record Management and etc.
                            - 11 -
◈ Alternate Sites
 - To establish the recovery sites for continuity of critical
   business services/functions and technology recovery
 - Alternate sites should be sufficiently distanced to avoid
   being affected by the same disaster
◈ Testing
 - To ensure that the BCP is operable
 - To verify the awareness and preparedness of staff
 - The scope of testing
   ㆍstaff evacuation and communication arrangement
   ㆍalternate sites, recovery services provided by vendors
   ㆍlinkage of back-up IT systems, recovery of vital records
 - To conduct testing of BCP at least annually
                            - 12 -
4. Tasks ahead for Korean banks in building BCP


◈ Active involvement of the BOD and senior management
 - Essential to Firm-wide BCP

◈ Linkage with the various kinds of contingency plans
 - DRP, Fire Protection Plan, War Emergency Plan, etc

◈ Modifications through periodic testing
 - Update their business continuity plan, as appropriate.

◈ BCP for other financial sectors
 - Sharing experience with Security firms, insurance firms, etc

                                - 13 -
Q&A



 - 14 -

Weitere ähnliche Inhalte

Andere mochten auch

Business Continuity Management System ISO 22301:2012 An Overview
Business Continuity Management System ISO 22301:2012 An OverviewBusiness Continuity Management System ISO 22301:2012 An Overview
Business Continuity Management System ISO 22301:2012 An OverviewAhmed Riad .
 
ISO 22301 Business Continuity Management
ISO 22301 Business Continuity ManagementISO 22301 Business Continuity Management
ISO 22301 Business Continuity ManagementRamiro Cid
 
ISO 22301: The New Standard for Business Continuity Best Practice
ISO 22301: The New Standard for Business Continuity Best PracticeISO 22301: The New Standard for Business Continuity Best Practice
ISO 22301: The New Standard for Business Continuity Best PracticeMissionMode
 
An Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery PlanningAn Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery PlanningNEBizRecovery
 
Disaster Recovery Plan for IT
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IThhuihhui
 

Andere mochten auch (6)

9 Bcp+Drp
9 Bcp+Drp9 Bcp+Drp
9 Bcp+Drp
 
Business Continuity Management System ISO 22301:2012 An Overview
Business Continuity Management System ISO 22301:2012 An OverviewBusiness Continuity Management System ISO 22301:2012 An Overview
Business Continuity Management System ISO 22301:2012 An Overview
 
ISO 22301 Business Continuity Management
ISO 22301 Business Continuity ManagementISO 22301 Business Continuity Management
ISO 22301 Business Continuity Management
 
ISO 22301: The New Standard for Business Continuity Best Practice
ISO 22301: The New Standard for Business Continuity Best PracticeISO 22301: The New Standard for Business Continuity Best Practice
ISO 22301: The New Standard for Business Continuity Best Practice
 
An Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery PlanningAn Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery Planning
 
Disaster Recovery Plan for IT
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IT
 

Ähnlich wie Korean Banks Efforts To Prepare For Bcp.Effective Operational Risk Management

Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planningalanlund
 
Business continuity & Disaster recovery planing
Business continuity & Disaster recovery planingBusiness continuity & Disaster recovery planing
Business continuity & Disaster recovery planingHanaysha
 
Business Continuity Strategy Benchmarking April 8th, 2009
Business Continuity Strategy Benchmarking April 8th, 2009Business Continuity Strategy Benchmarking April 8th, 2009
Business Continuity Strategy Benchmarking April 8th, 2009Mauro Giorgi
 
Business continuity planning
Business continuity planningBusiness continuity planning
Business continuity planningSandeep Kashyap
 
Assess Your Business Continuity Management Process
Assess Your Business Continuity Management ProcessAssess Your Business Continuity Management Process
Assess Your Business Continuity Management ProcessAnand Subramaniam
 
BCM Roadmap
BCM RoadmapBCM Roadmap
BCM Roadmapbtrmuray
 
Business Continuity Detailed Plan
Business Continuity Detailed PlanBusiness Continuity Detailed Plan
Business Continuity Detailed PlanWissam Abdel Baki
 
Managing and Implementing a National BCM Programme: A World's First
Managing and Implementing a National BCM Programme: A World's FirstManaging and Implementing a National BCM Programme: A World's First
Managing and Implementing a National BCM Programme: A World's FirstBCM Institute
 
Business Continuity Management (BCM, BCP) Smaple (Animations don't work in Sl...
Business Continuity Management (BCM, BCP) Smaple (Animations don't work in Sl...Business Continuity Management (BCM, BCP) Smaple (Animations don't work in Sl...
Business Continuity Management (BCM, BCP) Smaple (Animations don't work in Sl...Alexander Larsen
 
Solvency II IT Impacts
Solvency II   IT ImpactsSolvency II   IT Impacts
Solvency II IT ImpactsAli BELCAID
 
Business continuity management and the extended enterprise
Business continuity management and the extended enterpriseBusiness continuity management and the extended enterprise
Business continuity management and the extended enterpriseGeorge Coutsoumbidis
 
Solvency II - Programme Assurance
Solvency II - Programme AssuranceSolvency II - Programme Assurance
Solvency II - Programme Assurancegainline
 
Virtualisation:- Business Continuity Solution or Enabler
Virtualisation:- Business Continuity Solution or EnablerVirtualisation:- Business Continuity Solution or Enabler
Virtualisation:- Business Continuity Solution or Enablersubtitle
 
From Objective to Reliability
From Objective to ReliabilityFrom Objective to Reliability
From Objective to ReliabilityCyrus Sorab
 
A Review of BCBS 239: Helping banks stay compliant
A Review of BCBS 239: Helping banks stay compliantA Review of BCBS 239: Helping banks stay compliant
A Review of BCBS 239: Helping banks stay compliantHEXANIKA
 
Resume copy riskpro hotel industry jay[1]
Resume copy riskpro hotel  industry jay[1]Resume copy riskpro hotel  industry jay[1]
Resume copy riskpro hotel industry jay[1]Jayakumar Subramaniam
 

Ähnlich wie Korean Banks Efforts To Prepare For Bcp.Effective Operational Risk Management (20)

Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
Business continuity & Disaster recovery planing
Business continuity & Disaster recovery planingBusiness continuity & Disaster recovery planing
Business continuity & Disaster recovery planing
 
Business Continuity Strategy Benchmarking April 8th, 2009
Business Continuity Strategy Benchmarking April 8th, 2009Business Continuity Strategy Benchmarking April 8th, 2009
Business Continuity Strategy Benchmarking April 8th, 2009
 
BCP Awareness
BCP Awareness BCP Awareness
BCP Awareness
 
SAMA BCM Framework
SAMA BCM Framework SAMA BCM Framework
SAMA BCM Framework
 
Business continuity planning
Business continuity planningBusiness continuity planning
Business continuity planning
 
Assess Your Business Continuity Management Process
Assess Your Business Continuity Management ProcessAssess Your Business Continuity Management Process
Assess Your Business Continuity Management Process
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity Management
 
BCM Roadmap
BCM RoadmapBCM Roadmap
BCM Roadmap
 
Business Continuity Detailed Plan
Business Continuity Detailed PlanBusiness Continuity Detailed Plan
Business Continuity Detailed Plan
 
Managing and Implementing a National BCM Programme: A World's First
Managing and Implementing a National BCM Programme: A World's FirstManaging and Implementing a National BCM Programme: A World's First
Managing and Implementing a National BCM Programme: A World's First
 
Business Continuity Management (BCM, BCP) Smaple (Animations don't work in Sl...
Business Continuity Management (BCM, BCP) Smaple (Animations don't work in Sl...Business Continuity Management (BCM, BCP) Smaple (Animations don't work in Sl...
Business Continuity Management (BCM, BCP) Smaple (Animations don't work in Sl...
 
Solvency II IT Impacts
Solvency II   IT ImpactsSolvency II   IT Impacts
Solvency II IT Impacts
 
Business continuity management and the extended enterprise
Business continuity management and the extended enterpriseBusiness continuity management and the extended enterprise
Business continuity management and the extended enterprise
 
Solvency II - Programme Assurance
Solvency II - Programme AssuranceSolvency II - Programme Assurance
Solvency II - Programme Assurance
 
Virtualisation:- Business Continuity Solution or Enabler
Virtualisation:- Business Continuity Solution or EnablerVirtualisation:- Business Continuity Solution or Enabler
Virtualisation:- Business Continuity Solution or Enabler
 
From Objective to Reliability
From Objective to ReliabilityFrom Objective to Reliability
From Objective to Reliability
 
A Review of BCBS 239: Helping banks stay compliant
A Review of BCBS 239: Helping banks stay compliantA Review of BCBS 239: Helping banks stay compliant
A Review of BCBS 239: Helping banks stay compliant
 
009.itsecurity bcp v1
009.itsecurity bcp v1009.itsecurity bcp v1
009.itsecurity bcp v1
 
Resume copy riskpro hotel industry jay[1]
Resume copy riskpro hotel  industry jay[1]Resume copy riskpro hotel  industry jay[1]
Resume copy riskpro hotel industry jay[1]
 

Mehr von Enterprise Security Risk Management

Critical Infrastructure and Systems of National Significance (Australia)
Critical Infrastructure and Systems of National Significance (Australia)Critical Infrastructure and Systems of National Significance (Australia)
Critical Infrastructure and Systems of National Significance (Australia)Enterprise Security Risk Management
 
Critical Infrastructure & Systems of National Significance: Security Risk Man...
Critical Infrastructure & Systems of National Significance: Security Risk Man...Critical Infrastructure & Systems of National Significance: Security Risk Man...
Critical Infrastructure & Systems of National Significance: Security Risk Man...Enterprise Security Risk Management
 
Why drunk driving, untested medicines and wild guesses are SAFER then your tr...
Why drunk driving, untested medicines and wild guesses are SAFER then your tr...Why drunk driving, untested medicines and wild guesses are SAFER then your tr...
Why drunk driving, untested medicines and wild guesses are SAFER then your tr...Enterprise Security Risk Management
 
Sydney terrorism.media fear and facts.security risk management. tony ridley. ...
Sydney terrorism.media fear and facts.security risk management. tony ridley. ...Sydney terrorism.media fear and facts.security risk management. tony ridley. ...
Sydney terrorism.media fear and facts.security risk management. tony ridley. ...Enterprise Security Risk Management
 
Security risk management as a sport.tony ridley.security consultant
Security risk management as a sport.tony ridley.security consultantSecurity risk management as a sport.tony ridley.security consultant
Security risk management as a sport.tony ridley.security consultantEnterprise Security Risk Management
 
Security regulation, standards and governance.security risk management.tony r...
Security regulation, standards and governance.security risk management.tony r...Security regulation, standards and governance.security risk management.tony r...
Security regulation, standards and governance.security risk management.tony r...Enterprise Security Risk Management
 
Security expert witness.what is it.tony ridley.security risk mangement.securi...
Security expert witness.what is it.tony ridley.security risk mangement.securi...Security expert witness.what is it.tony ridley.security risk mangement.securi...
Security expert witness.what is it.tony ridley.security risk mangement.securi...Enterprise Security Risk Management
 
Security expert witness.preparations.enquiries.tony ridley.security risk mana...
Security expert witness.preparations.enquiries.tony ridley.security risk mana...Security expert witness.preparations.enquiries.tony ridley.security risk mana...
Security expert witness.preparations.enquiries.tony ridley.security risk mana...Enterprise Security Risk Management
 
Security and risk management. from subject matter expert to business leader.t...
Security and risk management. from subject matter expert to business leader.t...Security and risk management. from subject matter expert to business leader.t...
Security and risk management. from subject matter expert to business leader.t...Enterprise Security Risk Management
 
Security and risk management in emerging and developing markets.tony ridley.s...
Security and risk management in emerging and developing markets.tony ridley.s...Security and risk management in emerging and developing markets.tony ridley.s...
Security and risk management in emerging and developing markets.tony ridley.s...Enterprise Security Risk Management
 
8 security masters degrees compared.security risk management.tony ridley.se...
8  security  masters degrees compared.security risk management.tony ridley.se...8  security  masters degrees compared.security risk management.tony ridley.se...
8 security masters degrees compared.security risk management.tony ridley.se...Enterprise Security Risk Management
 
Appreciation process.time critical decision making.security risk management.t...
Appreciation process.time critical decision making.security risk management.t...Appreciation process.time critical decision making.security risk management.t...
Appreciation process.time critical decision making.security risk management.t...Enterprise Security Risk Management
 
Cheap and nasty.security certification.tony ridley.security consultant
Cheap and nasty.security certification.tony ridley.security consultantCheap and nasty.security certification.tony ridley.security consultant
Cheap and nasty.security certification.tony ridley.security consultantEnterprise Security Risk Management
 
Educational levels of professionals.a guide.tony ridley.security risk managem...
Educational levels of professionals.a guide.tony ridley.security risk managem...Educational levels of professionals.a guide.tony ridley.security risk managem...
Educational levels of professionals.a guide.tony ridley.security risk managem...Enterprise Security Risk Management
 
Fat tail distribution hypothesis.tony ridley.security risk management.securit...
Fat tail distribution hypothesis.tony ridley.security risk management.securit...Fat tail distribution hypothesis.tony ridley.security risk management.securit...
Fat tail distribution hypothesis.tony ridley.security risk management.securit...Enterprise Security Risk Management
 
Forecastings.intelligence.predictions.experts.accuracy.security science.risk ...
Forecastings.intelligence.predictions.experts.accuracy.security science.risk ...Forecastings.intelligence.predictions.experts.accuracy.security science.risk ...
Forecastings.intelligence.predictions.experts.accuracy.security science.risk ...Enterprise Security Risk Management
 
Educational levels of professionals.a guide.tony ridley.security risk managem...
Educational levels of professionals.a guide.tony ridley.security risk managem...Educational levels of professionals.a guide.tony ridley.security risk managem...
Educational levels of professionals.a guide.tony ridley.security risk managem...Enterprise Security Risk Management
 
Takes a thief to catch a thief.security ethics.tony ridley.security risk mana...
Takes a thief to catch a thief.security ethics.tony ridley.security risk mana...Takes a thief to catch a thief.security ethics.tony ridley.security risk mana...
Takes a thief to catch a thief.security ethics.tony ridley.security risk mana...Enterprise Security Risk Management
 

Mehr von Enterprise Security Risk Management (20)

Post Pandemic Travel: Terrorism and Security Risks for Tourists
Post Pandemic Travel: Terrorism and Security Risks for TouristsPost Pandemic Travel: Terrorism and Security Risks for Tourists
Post Pandemic Travel: Terrorism and Security Risks for Tourists
 
Critical Infrastructure and Systems of National Significance (Australia)
Critical Infrastructure and Systems of National Significance (Australia)Critical Infrastructure and Systems of National Significance (Australia)
Critical Infrastructure and Systems of National Significance (Australia)
 
Critical Infrastructure & Systems of National Significance: Security Risk Man...
Critical Infrastructure & Systems of National Significance: Security Risk Man...Critical Infrastructure & Systems of National Significance: Security Risk Man...
Critical Infrastructure & Systems of National Significance: Security Risk Man...
 
Why drunk driving, untested medicines and wild guesses are SAFER then your tr...
Why drunk driving, untested medicines and wild guesses are SAFER then your tr...Why drunk driving, untested medicines and wild guesses are SAFER then your tr...
Why drunk driving, untested medicines and wild guesses are SAFER then your tr...
 
Sydney terrorism.media fear and facts.security risk management. tony ridley. ...
Sydney terrorism.media fear and facts.security risk management. tony ridley. ...Sydney terrorism.media fear and facts.security risk management. tony ridley. ...
Sydney terrorism.media fear and facts.security risk management. tony ridley. ...
 
Security risk management as a sport.tony ridley.security consultant
Security risk management as a sport.tony ridley.security consultantSecurity risk management as a sport.tony ridley.security consultant
Security risk management as a sport.tony ridley.security consultant
 
Security regulation, standards and governance.security risk management.tony r...
Security regulation, standards and governance.security risk management.tony r...Security regulation, standards and governance.security risk management.tony r...
Security regulation, standards and governance.security risk management.tony r...
 
Security expert witness.what is it.tony ridley.security risk mangement.securi...
Security expert witness.what is it.tony ridley.security risk mangement.securi...Security expert witness.what is it.tony ridley.security risk mangement.securi...
Security expert witness.what is it.tony ridley.security risk mangement.securi...
 
Security expert witness.preparations.enquiries.tony ridley.security risk mana...
Security expert witness.preparations.enquiries.tony ridley.security risk mana...Security expert witness.preparations.enquiries.tony ridley.security risk mana...
Security expert witness.preparations.enquiries.tony ridley.security risk mana...
 
Security and risk management. from subject matter expert to business leader.t...
Security and risk management. from subject matter expert to business leader.t...Security and risk management. from subject matter expert to business leader.t...
Security and risk management. from subject matter expert to business leader.t...
 
Security and risk management in emerging and developing markets.tony ridley.s...
Security and risk management in emerging and developing markets.tony ridley.s...Security and risk management in emerging and developing markets.tony ridley.s...
Security and risk management in emerging and developing markets.tony ridley.s...
 
8 security masters degrees compared.security risk management.tony ridley.se...
8  security  masters degrees compared.security risk management.tony ridley.se...8  security  masters degrees compared.security risk management.tony ridley.se...
8 security masters degrees compared.security risk management.tony ridley.se...
 
Appreciation process.time critical decision making.security risk management.t...
Appreciation process.time critical decision making.security risk management.t...Appreciation process.time critical decision making.security risk management.t...
Appreciation process.time critical decision making.security risk management.t...
 
Cheap and nasty.security certification.tony ridley.security consultant
Cheap and nasty.security certification.tony ridley.security consultantCheap and nasty.security certification.tony ridley.security consultant
Cheap and nasty.security certification.tony ridley.security consultant
 
Educational levels of professionals.a guide.tony ridley.security risk managem...
Educational levels of professionals.a guide.tony ridley.security risk managem...Educational levels of professionals.a guide.tony ridley.security risk managem...
Educational levels of professionals.a guide.tony ridley.security risk managem...
 
Fat tail distribution hypothesis.tony ridley.security risk management.securit...
Fat tail distribution hypothesis.tony ridley.security risk management.securit...Fat tail distribution hypothesis.tony ridley.security risk management.securit...
Fat tail distribution hypothesis.tony ridley.security risk management.securit...
 
Forecastings.intelligence.predictions.experts.accuracy.security science.risk ...
Forecastings.intelligence.predictions.experts.accuracy.security science.risk ...Forecastings.intelligence.predictions.experts.accuracy.security science.risk ...
Forecastings.intelligence.predictions.experts.accuracy.security science.risk ...
 
Get to the point..faster.tony ridley.security risk management
Get to the point..faster.tony ridley.security risk managementGet to the point..faster.tony ridley.security risk management
Get to the point..faster.tony ridley.security risk management
 
Educational levels of professionals.a guide.tony ridley.security risk managem...
Educational levels of professionals.a guide.tony ridley.security risk managem...Educational levels of professionals.a guide.tony ridley.security risk managem...
Educational levels of professionals.a guide.tony ridley.security risk managem...
 
Takes a thief to catch a thief.security ethics.tony ridley.security risk mana...
Takes a thief to catch a thief.security ethics.tony ridley.security risk mana...Takes a thief to catch a thief.security ethics.tony ridley.security risk mana...
Takes a thief to catch a thief.security ethics.tony ridley.security risk mana...
 

Kürzlich hochgeladen

GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in managementchhavia330
 
Unlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfUnlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfOnline Income Engine
 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurSuhani Kapoor
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageMatteo Carbone
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Lviv Startup Club
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Roland Driesen
 
Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Roland Driesen
 
Grateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfGrateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfPaul Menig
 
Sales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessSales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessAggregage
 
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒anilsa9823
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Dave Litwiller
 
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 DelhiCall Girls in Delhi
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst SummitHolger Mueller
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...Paul Menig
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMANIlamathiKannappan
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Neil Kimberley
 

Kürzlich hochgeladen (20)

GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in management
 
Unlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfUnlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdf
 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...
 
Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...
 
Grateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfGrateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdf
 
Sales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessSales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for Success
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through Cartoons
 
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
 
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst Summit
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 

Korean Banks Efforts To Prepare For Bcp.Effective Operational Risk Management

  • 1. Banks’ Korean Banks’ Efforts to Prepare for BCP : Effective Operational Risk Management 27th August 2007 Yeong Sik Ohn Head of New Basel Accord Office, Financial Supervisory Service
  • 2. Table of Contents 1 BCP as a means to manage operational risk 2 Korean banks’ awareness and readiness of BCP 3 ‘Supervisory Guidelines for BCP’ by the FSS 4 Tasks ahead for Korean banks in building BCP -1-
  • 3. 1. BCP as a means to manage operational risk ◈ Business Continuity Planning [Management] : A whole-of-business approach that includes policies, standards, and procedures for ensuring that specified operations can be maintained or recovered in a timely fashion in the event of a disruption. Its purpose is to minimise the operational, financial, legal, reputational and other material consequences arising from a disruption High- High-level principles for business continuity (BCBS, August 2006) BCP concept DRP concept Disaster Business Part Other IT Part Recovery Part -2-
  • 4. ◈ Operational Risk Management vs. BCP/BCM (1) Loss Distribution of Operational Risk Frequency Bank’s Expense BCP And Coverage Insurance Capital area Coverage Coverage area area Severity Expected Loss Insurance level Coverage level -3-
  • 5. ◈ Operational Risk Management vs. BCP/BCM (2) ORM BCP/BCM Firm-wide business - Disruption of Core Scope businesses/Core activities process To minimise the - To minimise the impact to Purpose operational risk businesses due to operational disruptions Identify, - Prevent, Prepare, Process Response, Restore, Pilot Assess/Measure, Monitor, Report, Control test, maintain -4-
  • 6. banks’ 2. Korean banks’ awareness and readiness of BCP ◈ Limited BCP focusing on IT Disaster Recovery Planning - Only a few banks have firm-wide BCP - Gap exists in awareness and capability of BCP among business units ◈ Various kinds of Contingency plans different in scope, purpose and procedure - Fire Protection Plan, War Emergency Plan, Contingency Plans in business unit level - No control tower for all contingency plans - The scarcity of the detailed guidelines and information - The lack of prevention/preparation functions -5-
  • 7. (AS- ◈ Contingency Plans for Disaster (AS-IS) 1. Disaster Recovery Plan - FSS require DRC (Disaster Recovery Center) (Jan. 2004) - Focusing on IT system only 2. War Emergency Plan and Fire Protection Plan - To protect tangible assets & people and to minimize loss 3. Contingency Plans in business unit level - The different scope, purpose and method by the maker -6-
  • 8. (TO- ◈ BCP for Disaster (TO-BE) BCP War Emergency Plan DRP Fire Protection Plan Other Contingency Plans -7-
  • 9. BCP’ 3. ‘Supervisory Guidelines for BCP’ by the FSS ◈ Governance for BCP (Board and Senior Management) - The ultimate Responsibility for Business Continuity Plan and the effectiveness of BCP (BCP Function) - To manage the entire process of BCP - To assist the Board and Senior Management (Independent Review Function) - To review the effectiveness of BCP and compliance of all levels of staff - To conduct periodic review of BCP : at least annually -8-
  • 10. ◈ BCP Development Steps Risk Analysis Business Testing Feedback Impact Analysis Business BCM Continuity Strategy Plan -9-
  • 11. ◈ Risk Analysis - To identify the various potential risk factors and the priority of order in the event of a disruption - To assess the existing control means for risk factors ◈ Business Impact Analysis - To identify critical business services and functions to be delivered in the event of a disruption - To determine the priority of order, Recovery Time Objective, Recovery Point Objective and etc - 10 -
  • 12. ◈ BCM strategy Formulation - To formulate recovery strategies for continuity of critical business services and functions in the event of a disruption - including BCM Model, Alternate site, recovery personnel, office facilities, technology requirements and etc ◈ Business Continuity Plan (BCP) Development - To provide detailed guidance and procedures to respond and manage a crisis - including Crisis Management Plan (crisis management team, crisis management process, communication strategy), Business Resumption Process, Technology recovery, Vital Record Management and etc. - 11 -
  • 13. ◈ Alternate Sites - To establish the recovery sites for continuity of critical business services/functions and technology recovery - Alternate sites should be sufficiently distanced to avoid being affected by the same disaster ◈ Testing - To ensure that the BCP is operable - To verify the awareness and preparedness of staff - The scope of testing ㆍstaff evacuation and communication arrangement ㆍalternate sites, recovery services provided by vendors ㆍlinkage of back-up IT systems, recovery of vital records - To conduct testing of BCP at least annually - 12 -
  • 14. 4. Tasks ahead for Korean banks in building BCP ◈ Active involvement of the BOD and senior management - Essential to Firm-wide BCP ◈ Linkage with the various kinds of contingency plans - DRP, Fire Protection Plan, War Emergency Plan, etc ◈ Modifications through periodic testing - Update their business continuity plan, as appropriate. ◈ BCP for other financial sectors - Sharing experience with Security firms, insurance firms, etc - 13 -
  • 15. Q&A - 14 -