Non-financial risk management is carried out within the framework of the Bank’s Organizational Risk Management Policy. This covers the management of risks arising from shortcomings and errors committed by bank employees, process violations, issues and deficiencies in information systems and technologies, as well as external events.
Non-financial risk management at PASHA Bank OJSC is organized for the following purposes:
- The main purpose of non-financial risk management is to support the implementation of the Bank’s strategy, effectively prevent expected and unexpected losses that may affect profit and capital, and define the organization and principles of managing these risks
- Non-financial risk management performs the function of the second line of defense, helping reduce potential and current losses that may arise from internal bank processes, human errors, technology and external impacts. For this purpose, a unified risk framework, policy and effective governance mechanisms are applied
The areas of activity of non-financial risk management at PASHA Bank OJSC are as follows:
- Risk and incident management
- Information Technology / Cyber risk management
- Fraud risk management
- Operational and regulatory risk management
Providing opinions on all processes, products and services, as well as other regulatory documents covering the Bank’s activities;
- Managing the Bank’s non-financial loss database, scenario modeling and stress testing;
- Conducting awareness trainings annually, as well as additional trainings for new employees and risk coordinators;
- Continuously reviewing the risk status within the limit of the Risk Appetite Statement (RAS);
- Monitoring indicators related to non-financial risks under the Risk Appetite Statement (RAS) and providing proposals on the non-financial part of the Bank’s RAS in accordance with the Organizational Risk Management Policy;
- Implementing and monitoring an insurance program to ensure risk management, determining insurance amounts and fees, and managing the insurance claims payment process;
- Providing opinions on the granting of internal powers and limits and managing the relevant processes;
- Managing the annual Risk and Control Self-Assessment (RCSA) process;
- Assessing the risk level of internal audit findings and the action plan submitted, and providing additional recommendations and action plans when necessary;
- Managing incidents, identifying root causes, updating incident information in a timely manner, analyzing the effectiveness of action plans submitted for incidents and monitoring their implementation;
- Submitting reports on risks and incidents to the Bank’s authorized decision-making bodies
Since it is impossible to eliminate non-financial risks completely, the non-financial risk management team focuses on reducing and managing risks related to daily banking processes. Non-financial risk management is a continuous process and consists of the summarized stages below:
Risk identification - The first step in risk mitigation is identifying risks across all areas of the Bank’s activities and business processes.
Risk assessment - After all risks are identified, they are assessed based on potential consequences and likelihood of occurrence. This helps prioritize risk management.
Risk response options (treatment methods):
- Risk avoidance
- Risk reduction
- Risk transfer
- Risk acceptance
Defining and assessing control mechanisms and preparing an action plan - Determining the appropriate control mechanism and action plan for risks plays an important role in risk management. An additional action plan is defined and implemented to improve inadequate or ineffective control mechanisms.
Risk monitoring and reporting - Non-financial risks are regularly assessed to determine whether the impact or likelihood of the risk has changed. The list of identified risks must be continuously updated. Key risk indicators and metrics allow the control environment to be monitored and the likelihood of risk occurrence to be determined.