Presentation on theme: "Contents Point of view Brief history"— Presentation transcript:
0 Rogue Trading How to successfully manage this risk DateRogue Trading How to successfully manage this riskInformational presentation for our clientsFebruary Strictly private and confidentialPwC*connectedthinking
1 Contents Point of view Brief history DateContentsPoint of viewBrief historySome messages highlighted by recent eventsSocGen—a recent rogue trading incidentRegulatory response to dateFinancial Institution responseFirm qualificationsAppendixA sample of current control frameworksLessons learnedFINRA Regulatory Notice 08-18: Unauthorized Proprietary Trading
2 Point of viewRogue trading is common—On any given day, it is possible for traders to operate outside of the established rules of an institution. The vast majority do not get caught. In fact, many are profitable as a result of their rogue trading, but they have nonetheless not followed the rules and put the institution at risk by their actions. A few begin to lose money, are caught and dismissed quietly. A much smaller group loses large amounts of money before they are caught. These are the ones that make the headlines.“Tone at the top” is key—Recent examples of large losses from unauthorized trading emphasizes the need for additional and consistent focus by management and boards on creating the proper culture, sound risk management practices and the functioning of robust end-to-end controls.The risk profile of financial institutions has increased—Development of derivatives and growing sophistication of electronic trading strategies has increased the risk profile of financial institutions.Rogue trading cannot be completely prevented—It has been a problem since the beginning of organized trading, but it can be managed in an acceptable manner similar to other types of risks. It is very difficult to design preventive controls absent real-time monitoring, which is under discussion at a number of institutions.Most fraudulent behavior is caught by the detective controls in place—Large failures tend to occur when controls are not operating effectively.Emphasis should be placed on improving execution of controls—Most organizations have already implemented controls over unauthorized trading.Understanding the history of large frauds is an important component of your risk mitigation strategy—This includes scenarios known in the market and scenarios that your organization has experienced or may be susceptible to based on your business.Management should make a practice of investigating performance outliers, positive and negative—Performance far above goals is a risk indicator.Carefully calibrate your response—Improperly calibrated response (both from a review and implementation perspective) can be counterproductive to a firm’s business and cost structure without appreciably reducing risk in the business. We see a number of institutions potentially heading down this path.
3 Brief history Terrible Traders DateBrief historySome historical patterns in the most recent well-known frauds are instructive (note: these patterns tend to exist at some level in the smaller un-reported frauds that we have seen in our client base):Frauds occurred over a long period of time in businesses where large positions are carried in the course of normal business (mostly derivatives areas).Frauds were all front office individuals (as opposed to multiple persons) with knowledge and access to the middle and back office systems and/or processes.Red flags were either dismissed, ignored or undetected (e.g., lack of mandatory vacation policy/lack of enforcement, working excessively outside trading hours and operational and risk management irregularities).Structural issues existed, such as lack of segregation of duties and proper oversight.Terrible TradersThe writedown Societe Generale is attributing to one trader’s bad bets dwarfs previous banks’ troubles.Corporate losses attributed to trades by:Jerome Kerviel, SocGen (2008)Brian Hunter, Amaranth (2006)Chen Jiulin, China Aviation Oil (2004)John Rusnak, Allied Irish Bank (2002)Yasuo Hamanaka, Sumitomo (1996)Nick Leeson, Barings Bank (1995)Toshihide Iguchi, Daiwa (1995)Juan Pablo Davila, Codelco (1994)$7.16 billion$6.6 billion$550 million$691 million$2.6 billion$1.3 billion$1.1 billion$170 millionNote: Amounts are converted to U.S. dollars at date reported.Source: WSJ research
4 Some messages highlighted by recent frauds DateSome messages highlighted by recent fraudsSome messages from these disasters include:It doesn’t take just complex derivatives to get an institution into troubleThe size of the operations is not the issue—small operations can create large lossesPeople and cultural aspects are keyVery basic controls can fail and end to end reviews of risk management and front, middle and back offices must be undertaken regularlyRemuneration should be related to profit and levels of risk takenThere should be clear accountability—who “owns” the risk and who is accountable for implementing the risk management frameworkIt is vital to have an expert, robust and probing risk management function that is capable of understanding, identifying and measuring all key risksTechnological advances mean that the possibility of real-time monitoring and surveillance are being consideredThere should be direct supervision of traders and unacceptable behaviors should be identified and addressedPolicies around taking an annual leave of at least a two week period should be in place and enforcedIt is important to heed and follow-up internal and external warning signsRapid, decisive action coupled with a good communication strategy is key to effectively managing the crisis
5 SocGen—a recent rogue trading incident DateSocGen—a recent rogue trading incidentIt is early, but some facts and patterns appear to be emerging. Key facts derived from public sources include:$7.2 billion trading loss, the largest in history, was committed by a 31-year old junior trader in the firm’s Paris headquarters who had joined SocGen in He was not a senior trader (annual salary is reportedly €100,000) as in some of the other frauds. He moved to the trading floor from the risk control group in 2006.His role was to hedge exposures using futures on European stock-market indexes, including Euro Stoxx 50 ($50 billion daily volume), Germany’s DAX Index and France’s CAC-40.By the end of December, the positions were significantly in the money, but became unprofitable after the market turmoil occurred at the beginning of 2008.Risk control specialists first discovered the suspicious trades when investigating an outside trading partner of the bank, whose account showed unusually high finance levels. The client, when asked by the bank about the account’s finances, denied knowing of it. The full extent of the fraud was known within a day or two.The trader does not appear to have profited from the fraudulent trades and his motivations are unclear.It has been reported that such trading raised supervisory/risk management suspicions in the past, but that the trader had successfully addressed any questions/suspicions.
6 SocGen—a recent rogue trading incident DateSocGen—a recent rogue trading incidentAccording to the London Times, an independent report to SocGen’s Board includes the following information:SocGen missed 75 alerts between June 2006 and January 2007 on the activities of rogue trader Jerome Kerviel (JK).Risk control procedures were followed correctly, but compliance officers rarely went beyond routine checks and did not inform managers of anomalies, even when large sums were concerned. “No initiative was taken to check JK’s assertions and corrections he suggested, even when they lacked plausibility. . . When the hierarchy was alerted, they did not respond”.The panel supported JK’s claim that he acted alone and that he did not profit personally from the trades.The investigation found that JK started building up non-authorized trading positions in 2005 and 2006 for small amounts but the positions he took grew in size from March 2007 onwards.According to JK, by Christmas he was in profit by €1.4 billion but his activities were discovered on January 8, fully identified by January 18 and SocGen was forced to secretly unwind the positions between January 21 and 23 in falling markets, taking it to a €4.9 billion loss.The red flags that should have alerted bosses to the rogue trades included:A trade with a maturity date that fell on a SaturdayBets without identified counterpartiesTrades with counterparties within SocGen itselfTrades that exceeded the limits of counterpartiesMissing broker names and large increases in broker feesThere were also differences of up to €1.1 billion during reconciliations of JK's trading books with SocGen's online derivatives broker. The panel found seven false s sent by JK that attempted to explain his trading and counterparties.
7 SocGen—a recent rogue trading incident Some of the conclusions derived from public sources include:Large speculative positions were concealed by equal and opposite fictitious trades, thus concealing the MTM effect and market risk exposure.Unauthorized trades were possibly booked across a large number of either dormant or "dummy" accounts thus were not necessarily monitored on a regular basis.As exchanges impose daily margining on all participants, this raises significant questions about SocGen's margin process.The trader possibly entered into transactions with multiple large counterparties thus staying within PSE limits and possibly benefiting from cross-product netting for margin.Massive open positions would have been rolled-forward to avoid settlements.The trader may have used cancels and/or amendments on the fictitious trades to maintain the real trades within limits.In anticipation of periodic reviews by Risk Control, the trader may have used book-entry transfers to move the massive real positions between accounts.The trader most likely had access to both front and back systems through potential ID/password theft and/or sharing or continued access from his previous role in Risk Control that should have been terminated. Such access could have enabled manipulation of credit, market risk and trade-size controls.Trader most likely did not take any vacation during this period and frequently worked late into the night or on weekends.It remains possible, despite SocGen’s management’s declaration otherwise, that collusion with either external or internal parties were involved. At a minimum, friendships established during years in risk management were maintained and used to obtain information.
8 Regulatory response to date Regulatory response to this issue is in the early days:SEC sent a letter to the major investment banks with a February 8th response date. Most firms are outlining in broad terms their internal post-mortems and ongoing programs to manage this risk.The banking regulators have responded in a less consistent manner, with the OCC and the Fed appearing to be the most active, posing similar questions as the SEC, however there has been no formal public pronouncements.Non-US regulators are also requesting responses to various questions/concerns.Regulators are likely to review the measures put in place by financial institutions to manage these risks.We believe that they are likely to raise questions regarding previous internal audit findings, review previous rogue trading situations and to examine the effectiveness of controls as well as understand any projects (active, delayed or cancelled) impacting these areas. We are advising our clients to be well-prepared to address these and other questions that are likely to be raised by the regulators in the coming months.We also expect regulators to encourage clients to strengthen controls across the board in the trading areas and execute on previously identified projects to remedy known weaknesses.
9 Financial Institution response DateFinancial Institution responseFinancial institution sentiments and responses have varied. Here are some key points:All clients agree “this could happen” to them and, in fact, has happened to many. They differ in the extent that they are comfortable that they would be able to detect such activity and limit the losses.Senior management and boards are very sensitive regarding the effectiveness of controls and managing the risk of large losses in this area in the wake of the subprime situation and lack of confidence in the financial system post-SocGen.Most investment and sophisticated money center banks with large proprietary trading businesses appear to be comfortable with their risk management capabilities and are undertaking their own investigations with limited outside assistance. Many have had a number of rogue trading incidents over the last several years that resulted in losses that were not material to the institution.Other Financial Institutions are generally less confident in their risk profile and some are seeking external assistance in reviewing the quality of the control environment and recommending improvements.There is a general acknowledgement that improvements could be made in the control and technology infrastructure and that projects that have either not been funded or fully committed to will be budgeted for and executed. These programs are generally focused in the areas of automation of trading, risk management and information security processes and systems.
10 Examples of recent bank responses Financial Institution response Even some of the most sophisticated financial institutions have modified their approaches after consultation with the firm.Examples of recent bank responsesOur AdviceLarge Investment BankUS Regional BankGlobal Money Center BankOverallFocus on front officeCoverage of front, middle, back officeLargely focused on front officeRisk-based approach to determining businesses coveredAll desks across the globeLeveraging self-assessment processCalibrated according to riskLook at previous firm scenariosNot includedIndependent investigation leadInternal Audit/Risk ManagementRisk ManagementCurrent ScenariosDummy account reviewIncludedVacation policy/patternsTransfers to front officeComputer-savvy tradersAccess rightsOff-hours work patternsUnknownHigh levels of cancels/correctsOtherInclude the treasury areaUnusual patterns
11 Financial Institution response Risk review must consider a front office threat assessment, plus IT access/entitlements“Front office” threat assessmentRisk profile of each business and deskIncentives for rogue tradingManagement oversight practicesSegregation of dutiesRisk management practicesIT access/entitlementsKnowledge of middle, back office and risk management processes and systemsInformation technology capabilityPassword strengths, access rights and authorizationIntrusion monitoringPattern recognitionIn addition to these areas above, poor detective controls plus lax enforcement of existing controls compounds the risk of large fraud
12 Financial Institution response DateFinancial Institution responseWe are recommending that a focus on the front office risk profile, behavior and capabilities allows for a targeted investigation of business practices to assess current risk levels and identify necessary enhancements to fraud prevention controls.Specific areas of focus will include:Average price accountsSyndicate accountsError accountsSuspense accountsInappropriate use of brokers (excessive volume to single broker)Rolled trades around period-end or trades done away from market pricesExcessive cancelled and corrected or re-billed tradesUnverified vendor paymentsLarge numbers of client exceptions; cancelled trades, borrow issues, etc.Ownership for these control objectives and processes span multiple departments across the organization. For example:Entitlements—data owned by business unit, process owned by information securityRisk monitoring—credit and market risk owned by business unit, operational risk owned and administered by corporate departmentFraud risk—detecting is owned by compliance, deterrence is owned by regulatory and audit
13 Financial Institution response DateFinancial Institution responseWe are also encouraging our clients to look at this issue on an end-to-end basis.Incentive compensation of traders and other front office management based directly on P&LPerformance measurement not linked to risk profile of trading account/activitiesFront office regulatory and compliance incentive based on P&LLimited insight into the activities being executed by front office personnelIneffective escalation of incidentsLimited authority to affect transactional activitiesControls needed not effectively put in place by operationsIdentification of risks not dynamic or completeControls overridden based on performanceControl not linked to risk or performance objectivesOperations unable to effectively inform risk management of issuesControls not designed to implement risk management needsPerformance ManagementRisk ManagementOperations Management
14 Financial Institution response The most sophisticated institutions are beginning to examine the current trading model in greater depth:Excessive profits are rarely examined—making money that is significantly above plan or market conditions may not be good news and is a risk factor.Problems often start in the budget cycle—traders pressured to “make my numbers”, which may be unrealistic and may lead to risky behavior. Hitting targets = my bonus.Trading managers are rarely trained in fraud detection or rogue trading behaviors—continual and consistent hands-on interaction and management is critical.Functions within trading departments are often blurred—poor differentiation between market making and dealer functions versus proprietary risk taking.Compensation models often give traders a “free option”—gains are rewarded with bonuses, but there is no give back for losses.Trading managers trade rather than manage—maintaining a proprietary account focuses managers on their account rather than oversight and involvement.Many institutions lack a true long term incentive model:Annual compensation cycle often leads to boom/bust results.Trading managers/departments need to understand and challenge how “their” capital is being allocated in the market.Traders view internal risk management group as the bad cop—they can be a valuable tool in proactive risk decision making.
15 Financial Institution response DateFinancial Institution responseFinancial institutions are beginning to consider the types of efforts they need to undertake to better manage these risks, including:Better enforcement of existing controlsImplementation of quick fixes where possible, sometimes in anticipation of longer term automation or control improvement effortsAdjustment of internal audit and risk management team focus and plansFunding/acceleration of selected projects in the following areas:Information securityAutomation around tradingControlsRisk managementMonitoring technologyDiscussion of real time monitoring in some firms
16 DateFirm qualificationsThe firm has an outstanding track record of working with clients in investigating and responding to rogue trading activities:Current response assistance at SocGen and several other institutionsProvided our points of view and advice to a number of leading firmsHistorical investigation assistance regarding a number of prior trading scandalsNumerous trading risk and control reviews with leading clientsDeep implementation experience in key areas of client focus (e.g., IT risk, security, policy, governance, etc.)Publication a number of years ago of Generally Accepted Risk Principles (“GARP”) which includes a comprehensive view of trading risk management and controls
17 Appendix A sample of current control frameworks How various banks have developed their control frameworks in response to risk issues identified and past fraudulent activityLessons learnedSome lessons learned by functional areaRegulatory Notice: Unauthorized Proprietary TradingSound practices for preventing and detecting unauthorized proprietary trading
18 A sample of current control frameworks: Global Investment Bank A DateA sample of current control frameworks: Global Investment Bank ADespite Bank A’s established controls throughout its operations, fraudulent activity resulting in approximately $30MM in losses was identified between 2002 and 2007.Summary (issues identified and fraudulent activity found)Bank A manages risk through internal controls across all levelsSegregation of duties between front, middle and back officesMandatory vacation policySystem entitlement reviewsPeriodic password resetsA review of established controls resulted in the following issues identified in Q3 and Q4 2007:Loss of liquidity and disagreements about model assumptions triggered an above average level of margin disputesA backlog of unconfirmed tradesCorrelation exceeded market risk limits of both European and US desksPrice verification: significant growth of unverified instruments as a percentage of total inventoryGeneralPlans of supervisionRisk limits for select desksList of authorized brokers by trade and monitoringTrader mandates outlining approvedinstruments and currenciesCounterparty Review, including KYC/AMLFront OfficeMarket risk limit monitoring (trackingof market risk data quality)Counterparty credit monitoringModel validation process, includingmonthly input reviewP&L TriggersOff-market trade monitoringDaily, monthly P&L analysisTrade reconciliationAccount maintenance and monitoringMiddle OfficeMargin process, monitoring ofdisputed marginsConfirmationsCash break monitoringSettlement reconciliationLate trade booking/monitoringTracking of trade modifications andamendmentsTracking of back dated adjustmentsAccount set-upBack Office
19 A sample of current control frameworks: Global Investment Bank B DateA sample of current control frameworks: Global Investment Bank BBank B has the controls listed below in place for each line of business. Potential control gaps have been identified, though these controls have yet to be reviewed and issues have yet to be identified.Summary (issues identified and fraudulent activity found)Summary (issues identified and fraudulent activity found)Bank B manages risk through internal controls across all levelsSegregation of duties, betweenfront, middle and back officesInformation wallsAdequate system access/entitlements to funds wiring systemsMandatory 2 week vacation policyAccess and entitlements controlsChange management controlsReconciliations of risk systems, P&Land balance sheetBank B has outlined the controls to be reviewed and has created three metrics on which to judge control effectiveness: assessment of design, manual involvement and effectiveness. In addition, Bank B has identified the potential control gaps to which they believe the Bank’s businesses could be exposed. These include:Forging of books and recordsPassword sharingSystem access entitlements conflictsBreach of limitsBypass of limit detection controlsCreation of fictitious portfolios, dummy counterparties, or “pending” tradesRemote trading without supervision or systems of recordFictitious trades/cancel and correctsPending/unsettled transactionsConfirmation suppression capabilitiesSegregation of duties over cash movementsGeneralTrader mandates outlining approvedproducts and limitsRisk limits and systematic feeds formonitoringFront OfficeCounterparty/portfolio—set-upcontrolsTrade activities review—cancels andcorrects, as of, forward settlements,off-premisesPrice verification processesMiddle OfficeStraight-through processingCounterparty confirmation controlsInternal trade confirmationsManual journal entry controlrequiring 4 peopleInternal/external system threat andvulnerability controlsClearing and settlement controlsAdequate Standard SettlementsInstructions Controls (SSI)Back Office
20 A sample of current control frameworks: Global Investment Bank C Bank C has the controls listed below in place for each line of business in both the Investment Bank and other wholesale business units. These controls have yet to be reviewed and issues have yet to be identified.Summary (issues identified and fraudulent activity found)Bank C manages risk through internal controls across all levelsMandatory vacation policyIdentification and follow-up on anyregulatory inquiriesIdentification of high risk accessconflicts and users with this accessPassword sharing reviewReview of transfers between frontand back office and associatedaccess rightsBank C has outlined the controls to be reviewed and plans to document the results of the review, the issues and gaps identified, and the action plan to remediate each issue.There is both a front office focused work plan and an operations, finance, and technology focused work plan. The reviews are to be conducted across the Bank’s various lines of business (i.e., rates, commodities, equities) within the Investment Bank and the other wholesale business units (i.e., Asset Management, Treasury Services).GeneralRisk Limits by DeskReview of trade activity by Desk Head for appropriatenessFront OfficeTrade Activity Review—cancellations and amendments andforward-dated tradesVerification of P&L/positions sign-off by appropriate personReview of client valuations indispute with external counterpartiesCollateral movement reviewMiddle OfficeConfirmations reviewAffirmations reviewMonth-end close/reversing tradeentry reviewsNostro reviewsReview of dummy, blocked andoffline books not feeding to risk or G/LReview of cash wash itemsBack Office
21 A Comparison of Controls: Global Investment Bank D Bank D is evaluating operational risk management’s self-assessment process to determine if significant control gaps are appropriately identified. In addition, Bank D has mapped out what took place at SocGen relative to their control objectives.SummaryBank D manages risk through internal controls across all levelsChange management controlsIT business continuity infrastructureRisk data classification to ensure to allow identification of highly sensitive dataConfidential information management and trainingIsolation of business units with material non-public informationSegregation of dutiesBank D is in the process of conducting end-to-end self assessments of its trading desks. The Bank’s internal audit function will work to provide feedback, review and testing of the self-assessments. In addition, the Bank has an independent firm doing external validation of its assessment process. A report containing details of the SocGen event, effectiveness of the evaluation process and current state findings will be provided to the Board upon completion.GeneralRisk Limits by Desk, including counterparty, country, and product exposuresDue diligence requirements set by Desk to ensure internal approvals, conflicts of interest, and clients are appropriateFront OfficeLimit monitoringPrice verification processesModel validation and back-testingProduct suitability managementClient and transaction due diligenceMiddle OfficeTransactions management reviewTransactions documentation controlsTransactions processing reviewsLimit reportingSystem access restrictions (need to know basis)Reporting of modeled factorsBack Office
22 Overall risk management framework Lessons learned A PwC recommended framework for trading and treasury operations.Risk management strategyRisk management philosophyRisk appetiteRisk cultureRole of the BoardRisk management functionOrganisationLimits structureReporting linesRoles and responsibilitiesSkills resourcesRisk measurement reportingRisk identificationRisk assessmentRisk measurementException reportingRegulatory reportingPeople and cultureRecruitment and trainingTransparencyIntegrity and accountabilityComplianceSkills and resourcesRemuneration based on risk and rewardOperations, systems and controlsRobust operations and controls (front, middle, back office)Adequate systemsReliable informationAccountingOverall risk management frameworkCommunication
23 Lessons learned Risk management strategy The Board of Directors must take responsibility forOverall cultureEstablishing risk strategy and appetiteEnsuring that hard side of RM (policies, limits and systems) and soft side (people, culture and incentives) receive equal attentionEnsuring that management have mechanisms to identify, measure, capture and report risksThe Board and its committees should be probingRisk management functionDedicated function that has authorityClear lines of responsibility between function and BUAdequate skillsMeaningful and comprehensive limits structureStress testing
24 Lessons learned People and culture Recruitment policies Adequate trainingHigh performance culture, based on integrity and complianceSwift penalties for those who don’t comply with policiesStar performers should not be given special treatmentOperations and systemsSegregation of duties is a key operational risk controlRobust operational controls must be in place in front, middle and back officesEnsure that the back office groups have real influence over trading activitiesPricesOff market prices should be a warning flagSystems should capture prices outside a rangeModels from third parties should always be sourced by BOBrokers from whom prices are obtained should be rotated
25 Lessons learned Risk management reporting and controls Risk reporting should be comprehensive, yet comprehensibleNo single measure adequately covers all eventualities and satisfies all management requirementsA range of complementary measures should be usedThe escalation of bad news should be encouragedAudit reports should not be “dumbed down” by management. Issue reporting should be multi-dimensionalAll regulatory reports should be shared with the Board
26 Regulatory Notice 08-18: Unauthorized Proprietary Trading April 2008 Sound Practices for Preventing and Detecting Unauthorized Proprietary TradingExecutive SummaryIn the wake of several recent cases involving allegations of unauthorized or “rogue” trading resulting in substantial losses by firms both in the United States and abroad, many FINRA firms are undertaking comprehensive reviews of their internal controls and risk management systems designed to prevent such trading activity. FINRA is issuing this Notice to highlight sound practices for firms to consider as they undergo that process. We also remind firms that even profitable unauthorized trading can result in regulatory exposure if it involves falsification of the firm’s books and records, failures in supervisory control systems, market manipulation or fraud. Therefore, internal control systems should be designed to address regulatory as well as business and reputational risk.Questions regarding this Notice may be directed to:Laura Gansler, Associate Vice President, Emerging Regulatory Issues, at (202) ; orRosemarie Fanelli, Surveillance Director, Risk Oversight and Operational Regulation, at (646) ;Kathryn Mahoney, Director, Emerging Regulatory Issues, at (212)Background and DiscussionThe risks associated with unauthorized proprietary trading by “rogue” traders are not new, and most firms that allow traders to commit the firms’ capital already have policies and procedures in place designed to prevent unauthorized trading. In 1999, the SEC, NYSE and NASD issued a Joint Regulatory Notice Statement on Broker-Dealer Risk Management Practices that summarized weak and strong risk management practices identified through a survey of mid-sized and large firms.1 In it, the regulators concluded that senior management must play a significant role in the adoption and maintenance of a comprehensive system of internal controls and risk management systems, and that those controls and systems must be adequately funded, independent of revenue-generating activities, and updated as changes in technology, the firm’s business activities or other circumstances warranted.Since then, many firms have refined and strengthened their internal controls around unauthorized trading. However, recent events highlight the importance of routinely reassessing the adequacy and effectiveness of those systems, particularly in light of the increasingly global nature of the financial services industry, the highly competitive trading environment and the complexity of many of the products being traded. In particular, the immediacy required as a result of pervasive electronic trading and market linkages has increased pressure on some firms to relax internal controls that might arguably affect a trader’s competitive advantage in the short run, but protect the firm from undue risk in the long term.Unauthorized trading under any circumstances, but especially in the case of proprietary trading, can pose significant risk from a business perspective, and it can create serious regulatory risk as well, even when the trading generates profits for the firm. Substantial losses can affect financial viability and several recent incidents appear to raise other regulatory concerns, including falsification of the firm’s books and records, lapses in supervisory controls and fraud. Moreover, it is sometimes difficult to tell from early red flags whether suspicious trading activity is generating profits or losses; vigilance against regulatory exposure as opposed to simply focusing on business risk can help protect the firm against both. Therefore, a firm’s internal controls around unauthorized proprietary trading should be designed to deter and detect all unauthorized trading by the firm’s employees.2 This deterrence is important even when the firm profits from that trading; firms that “look the other way” or reward profitable unauthorized trading are creating incentives for this prohibited behavior and the potential for future risk of loss.
27 Regulatory Notice 08-18: Unauthorized Proprietary Trading April 2008 Sound PracticesTo assist firms in the process of reviewing and, where necessary, modifying, their current internal controls against unauthorized trading, we have recently solicited input from a range of firms regarding their internal controls, as well as the preliminary results of internal reviews. We are publishing those practices now with the expectation that doing so will help other firms as they undergo their own review process. While FINRA believes that these practices are worthy of consideration, we understand that their relevance and feasibility will vary depending on a firm’s size and business model. We also note that this is not an exhaustive list, and is not intended to create a safe harbor from regulatory exposure or to discourage firms from completing their own comprehensive internal audits.Mandatory Vacation PoliciesAn increasing number of broker-dealers have identified “sensitive” jobs, and adopted mandatory policies requiring employees in those positions, including traders, to be away from the office for a minimum amount of time, typically ten consecutive trading days. During that time away, the employee is barred from having physical or electronic access to the firm, its facilities, or systems. The theory behind this policy, which has been common in the banking industry, is that if an employee has engaged in unauthorized activity and is concealing it, the activity will likely be exposed in the firm’s trade reconciliation process within that time, because the employee is not able to continue the concealment while away from the firm and its systems.A mandatory vacation policy must be enforced in order to be effective. In at least one recent well-publicized case, the firm had such a policy, but the trader involved had not taken the full, mandatory, consecutive vacation in several years. Exemptions should not be granted except in unusual circumstances and repeated requests for exemptions should be considered a red flag warranting additional monitoring. Firms also should assure that their systems support blocking employees on mandatory vacation from accessing firm systems.A mandatory vacation policy may not be feasible or reasonable for all firms. However, we urge firms to consider it as part of their risk management procedures. If a firm determines not to adopt such a policy, it should consider other methods of identifying and reviewing the trading activity of traders who have not taken an extended vacation in the past year.Heightened Scrutiny of Red FlagsAs firms review their internal controls, they should pay attention to whether they are both adequately mining available trade data for red flags and following up on those red flags where appropriate. Among other things, firms should monitor, and, when necessary, conduct heightened scrutiny of:Trading limit breaches. At least one firm surveyed recently has implemented a tool that allows for monitoring of limit breaches by a trading book or individual trades in real-time, and can be set to generate alerts based on a range of parameters, including the notional value of a trade, share size (net/gross position), amount of orders or traders per day and total dollar value per day.Unrealized profit and loss (P&L) on unsettled transactions. Trading desk managers and financial control managers should pay careful attention to sizeable amounts of unrealized P&L and should understand the nature of the transactions creating these amounts.Unusual patterns of cancellations and corrections, particularly those involving multiple cancellations or corrections by the same trader or involving the same counter-party. Certain firms prohibit a front-office trader or salesperson from entering cancels and corrects into the trading system and limit the entry of these transactions to mid-office (e.g., those involved in risk management) or back-office (e.g., those involved in settlement services) personnel.
28 Regulatory Notice 08-18: Unauthorized Proprietary Trading April 2008 Transactions in which confirmation and settlement do not occur on a timely basis, or where settlement is outside of normal cycles.Reports of aged unresolved reconciling items and aged outstanding confirmations.Reports of P&L that exceed a certain de minimis amount by traders who are supposed to be flat, or unusually large one-day P&L reports.The details underlying a trader’s Value at Risk (VaR), including the long and short positions, on a daily or intra-day basis, as appropriate. Firms should also consider other risks associated with a trader’s positions, such as liquidity risk, the adequacy of hedges and the risks associated with imperfect hedges. This includes understanding and reviewing the valuation of all positions, particularly positions in exotic instruments or instruments that have little or no market.Repeated or unusual requests by a trader to relax existing controls, including position or P&L limits.Trading in products that are outside of a trader’s known expertise, without prior approval.Any other unusual or significant differences between a trader’s account positions and the account activity, such as might be detected by comparison of gross and/or net position to the cash flows of positions; i.e., margin/collateral calls to and from counterparties to the trades.A pattern of aged fails to deliver for long or short sales.Whether these data points are reviewed manually, or with the use of automated surveillance tools, or some combination, a firm’s controls should not just note deviations from normal trading patterns as red flags that might signal proprietary business risk, but as signals of possible regulatory risk as well. And, to the extent that firms use automated surveillance tools to identify such items, their internal control systems should include adequate and routine maintenance and testing of those systems.Protection of Systems and Risk Management InformationIn some cases, rogue traders have been able to falsify a firm’s books and records to conceal illicit trading activity due to lapses in password security and other systems protections. Firms should make certain that each employee’s access to systems is limited strictly to what is appropriate for the employee’s function within the firm. This control should not be limited to traders; it should be in place for any employee whose role includes access to trading systems. If an employee’s function changes within the firm, the firm should make sure that the employee’s access changes accordingly. For example, if an employee moves from the back office to a trading desk, that employee’s access should be changed to reflect his or her new role, and access to the back-office functions should be revoked. Firms should also make sure that access is suspended during any mandatory vacation period and cancelled promptly if the employee leaves the firm.Firms also should protect information about surveillance or monitoring systems and procedures that might help employees circumvent those systems. For example, knowledge that the firm divides responsibility for reviewing certain trade monitoring functions by product type might help a trader who is creating fictitious trades to avoid detection by creating trades involving different products, so that the trades would not all be reviewed by the same personnel. In at least one recent case, a trader’s intimate knowledge of back-office procedures and risk management procedures, including what would—and what would not—trigger heightened scrutiny, may have allowed him to avoid detection for a much longer period than he otherwise might have. Therefore, firms should limit knowledge about the details of their risk management procedures and systems to the extent possible and consider modifying them in response to personnel changes, such as a back office employee becoming a trader. Firms also should consider whether there are appropriate mechanisms in place to review all activity of a given trader.
29 Regulatory Notice 08-18: Unauthorized Proprietary Trading April 2008 Firms may want to consider more than a single password to allow access to certain systems. More sophisticated systems require three-factor authentication before access is allowed, including not only a password but also a security card or other I.D. such as a token ring, and a unique identifier such as a fingerprint. Firms need to weigh both the inconvenience and the cost of these additional security measures in determining which controls are appropriate.Supervision and AccountabilityCertain financial services companies have established matrix management structures such that employees may have both direct and dotted line reporting to multiple managers. While matrix management may make sense for an organization, it is important for employees to understand who they report to and what they are held accountable for in their day-to-day job responsibilities. Correspondingly, both the dotted line and the direct manager must have a clear sense of who is responsible for each aspect of the business. It is critical that responsibility for supervision of each aspect of the business be allocated to a specific manager and that these managers have frequent communications to understand their respective businesses. Documenting these supervisory responsibilities in writing is recommended.Intercompany TransactionsMany FINRA firms are part of larger, complex financial services organizations. The FINRA member firm generally conducts a large number of intercompany transactions with its affiliates. Often the basic controls that are in place for third parties, including controls around credit risk and market risk, are waived for affiliated transactions. In light of the recent cases of unauthorized trading, firms may want to reevaluate whether certain third-party controls that limit their exposure would be appropriate for affiliated transactions. Further, reconciliations of intercompany transactions and balances should be performed on a regular basis.Compliance CultureAs recent events have demonstrated, even the most rigorous internal controls and risk management procedures can fail if they are not effectively enforced and the effectiveness of that enforcement is directly related to the “tone at the top.” A corporate culture that marginalizes the individuals or departments responsible for trade reconciliation and risk management will undermine the effectiveness of even the most elaborate policies and procedures. In reviewing the adequacy of their internal controls around unauthorized proprietary trading by individual traders, firms should pay attention to any systemic or cultural dynamics that may undermine the effectiveness of those systems. For example:Do mid- and back-office functions have sufficient independence, clout and profile within the organization? To whom do they report?Are mid- and back-office personnel adequately trained and encouraged to raise issues about suspicious activity, even if it involves successful traders or activity that is generating profits for the firm, or doesn’t technically violate any limits?If operations, compliance or internal audit personnel receive a questionable or inadequate response by a trader, are they encouraged to challenge such a response and/or raise the issue to their supervisors where appropriate?If the firm operates in a global context, do its internal controls take into account any cultural differences that might discourage adequate internal oversight or reporting? For example, anonymous reporting might be appropriate in certain environments.
30 Regulatory Notice 08-18: Unauthorized Proprietary Trading April 2008 Do traders who have incurred losses have incentives to disclose them and limit the damage because they understand that the failure to disclose will be considered an egregious violation of the firm’s policies and procedures and dealt with accordingly, or are they encouraged, even implicitly, to incur more risk in order to avoid disclosure?Are internal control functions adequately funded, and are those who perform them adequately compensated, in relation to the role that they are asked to perform within the firm?ConclusionAs firms review their internal controls around unauthorized trading in the wake of recent incidents, FINRA urges them to consider the practices described above, and to rigorously examine the broader compliance culture within which those controls are enforced. FINRA also reminds firms of the importance of ensuring that program areas tasked with detecting and preventing unauthorized trading possess sufficient independence, clout and funding, especially during challenging market conditions.Endnotes1 See NASD NTM99-92 (November 1999) and NYSE Information Memo (September 1999).2 FINRA member firms that are also members of the NYSE are subject to incorporated Rules and 351(e), which require firms to review proprietary, employee and employee related trading in NYSE-listed securities and related financial instruments, and to conduct “internal investigations” of trades that may violate securities laws and rules prohibiting insider trading and manipulative and deceptive devices. Members and member organizations are further required to file with the Exchange reports relating to such internal investigations pursuant to Rule 351(e).