## _wp1634

## Source details

**Canonical URL:** [_wp1634](https://www.imf.org/-/media/websites/imf/imported-full-text-pdf/external/pubs/ft/wp/2016/_wp1634.pdf)

## Other formats

- [Markdown version](/-/media/websites/imf/imported-full-text-pdf/external/pubs/ft/wp/2016/_wp1634.pdf.md)
- [Structured JSON version](/-/media/websites/imf/imported-full-text-pdf/external/pubs/ft/wp/2016/_wp1634.pdf.json)

---

### I. Introduction and paper objectives
- Effective governance is "of the utmost importance for central banks trying to achieve their goals."
- Governance pillars identified: mandates, independence, accountability and transparency, and internal governance.
- Independence types emphasized: political, operational, and financial.
- Paper objectives (funnel structure):
  - (i) Outline the issue of central bank governance in general;
  - (ii) Zoom in on internal governance and organization issues of central banks;
  - (iii) Highlight the main issues with nonfinancial risk management;
  - (iv) End with a number of recommendations for future work.

### II. Prerequisites for improved nonfinancial risk management
- Global financial crisis effects:
  - Extended governance thinking from monetary policy to supervisory/regulatory functions.
  - Shifted emphasis toward behavior and culture in addition to organization.
- Key observation: nonfinancial risk management of central banks has been examined the least, despite internal-audit, compliance, board structure, and decision-making processes being well-charted.
- Drivers for attention to nonfinancial risks:
  - Central banks acting as investors and being in the public spotlight.
  - Potential for nonfinancial risks to cause large adverse (financial) effects.

### III. Governance: definition and applicability to central banks
- OECD (2004) governance definition applied to central banks:
  - Governance is "a set of relationships between a company’s management, its board, its shareholders, and other stakeholders."
  - Provides structure for setting objectives, attaining them, and monitoring performance.
  - Provides incentives for board and management to pursue stakeholder interests and facilitates effective monitoring.
  - Effective corporate governance "helps provide a degree of confidence that is necessary for the proper functioning of a market economy."
- Applicability emphasis: build confidence and trust within the organization and across society.

### IV. Distinctive characteristics of central banks and governance implications
- BIS (2009) definition: central banks are "public policy institutions whose main goals are to preserve monetary stability and promote financial stability".
- Typical central bank functions:
  - Provide core components of payment systems.
  - Often manage the country’s gold and foreign exchange reserves.
  - Play a major role in the oversight and development of the financial system.
  - In some countries: banking services, asset and debt management to the state, and general economic advice to government.
- Four common characteristics:
  - (1) Public policy objectives (which can vary);
  - (2) Lender of last resort role;
  - (3) Balance sheet structure (including the fact that central banks do not go bankrupt);
  - (4) Need to "lead by example" (fiduciary responsibility to society).
- From these derive four main governance issues relevant to all central banks:
  - (a) mandates;
  - (b) independence;
  - (c) accountability and transparency;
  - (d) internal governance.
- Note: Issues on mandates, accountability and transparency are not discussed further in detail in this paper.

### V. Accountability and transparency of financial supervisors (Box 1 summary)
- Basel Committee Task Force guidance: accountability and transparency are core drivers for effective financial supervision.
- Purported benefits:
  - Strengthen supervisors' willingness to act and deliver sound outcomes.
  - Strengthen technical independence and help counter institutional capture.
- Accountability:
  - Reinforces democratic checks and balances for high-quality supervision.
  - Requires objective and transparent procedures to call board members and senior staff to account.
  - Text: "As Figure 1 demonstrates, lack of accountability will erode support credibility of/trust in the central bank."
- Transparency:
  - Enables public scrutiny to make accountability feasible.
  - Must respect confidentiality but cannot be used to avoid scrutiny.
  - Transparency "limits the arbitrariness of supervisors, exposes undue government and industry interference, and encourage good and effective supervisory practices."

### VI. Central bank independence (Box 1 — expanded)
- Distinctions and components:
  - Legal independence (cross-cutting) indicates legislative intent and underpins systematic characterizations.
  - Political independence:
    - Formulate and execute monetary policy without undue political influence.
    - Checks include clear rules on approval and dismissal of governors/board members; some countries apply a "double veto".
    - Reasons for firing a governor should be clearly laid down in law.
  - Operational independence:
    - Central banks should be limited/prohibited from financing public sector expenditure.
    - Freedom to formulate interest rate policy; execution exclusive to the central bank.
    - Some countries require central bank agreement with government on inflation target (no target/goal independence).
  - Financial independence:
    - Government should ensure central bank capital integrity.
    - Central bank profit transfers to government occur after accumulating appropriate legal reserves.
    - Central banks should not engage in quasi-fiscal operations that deteriorate financial position.
    - Financial independence and transparency of financial relations facilitate accountability.

### VII. Internal governance: structure, culture, control functions
- Internal governance includes structure, decision-making, risk management arrangements, control mechanisms, and internal audit.
- Behavior and culture are fundamental; behavioral insights from psychology, sociology, and behavioral economics matter for policy success.
- Board effectiveness (FRC attributes):
  - Provide direction for management;
  - Demonstrate ethical leadership;
  - Create performance culture that drives value without excessive risk;
  - Make well-informed, high-quality decisions;
  - Create frameworks for statutory duties;
  - Be accountable;
  - Embrace evaluation of effectiveness.
- Board composition should reflect central bank functions; "soft skills" and organizational skills increasingly relevant.
- Control functions and the Three Lines of Defense:
  1) First line: business departments — risk owners and first assessment;
  2) Second line: centralized Risk Management Department (RMD) — challenge and monitor;
  3) Third line: Internal Audit Department (and possibly external auditor) — assurance on identification and control of risks.
- Separation recommended: avoid combining internal audit and risk management; combined assurance approaches can add value where appropriate.

### VIII. Risk management: financial and nonfinancial risks
- Financial risk categories: market, credit, interest rate, liquidity.
  - Liquidity risk can be mitigated by money-printing rights but may shift risks to price and financial stability.
  - Credit risk arises from lender of last resort and fiscal agent roles.
  - Expanded QE, sovereign bond purchases, and retail lending schemes increased financial risk scale and volatility.
- Evolution and standards:
  - Historically decentralized; trend toward centralized independent departments with integrated overviews.
  - ISO 31000 (2009) provides principles/guidelines for organizational risk management.
  - Risk management: “the coordinated activities to direct and control an organization with regard to risks.”
- Nonfinancial risk management is underdeveloped relative to financial risk management.
  - BIS post-2008 report noted nonfinancial risks handled less advancedly.
  - Nonfinancial risks often lack historical data for validation; even financial risk models generate operational risks (fraud, human error, IT problems).

### IX. Nonfinancial risk: categories and definitions
- Three subcategories:
  - (a) Operational risk;
  - (b) Policy risk;
  - (c) Reputational risk.
- Operational risk:
  - Linked to failures in processes, systems, people or external events.
  - ECB definition: “the risk of negative business, reputational or financial impact for the bank which derives from specific risk events due to or facilitated by root causes pertaining to governance, people, processes, infrastructure, information systems, legal, communication and changes in the external environment”.
  - Basel II event categories (7):
    1) Internal Fraud;
    2) External Fraud;
    3) Employment Practices and Workplace Safety;
    4) Clients, Products, and Business Practice;
    5) Damage to Physical Assets;
    6) Business Disruption and Systems Failures;
    7) Execution, Delivery, and Process Management.
- Policy risk:
  - Arises from central bank policy activities (monetary policy; financial stability/supervision; banking resolution; market supervision; financial integrity).
  - FIU issues:
    - FATF FIU definition: national centre for receipt/analysis of suspicious transaction reports and related information.
    - Typical FIU locations: ministry of finance, the central bank, or a regulatory agency.
    - About 50 countries have some "cohabitation" of the FIU and the central bank.
    - Examples of large bank fines: BNP Paribas paid 8.9 billion USD; Credit Suisse paid 2.6 billion USD; HSBC paid $1.9 billion U.S.
  - Reserve management governance needs:
    - IMF (2013) objectives: (1) adequate foreign exchange reserves; (2) liquidity, market, credit, legal, settlement, custodial, and operational risks controlled prudently; (3) subject to constraints, reasonable risk-adjusted returns over the medium to long term.
    - IMF-listed operational risks in reserve management:
      a) Control system failure risks (fraud, money laundering, theft, weak controls, inadequate skills, poor separation of duties, collusion);
      b) Financial error risk (incorrect measurement of net foreign currency position);
      c) Financial misstatement risk (incorrect inclusion of non-reserve assets as reserves);
      d) Loss of potential income (failure to reinvest nostro balances timely).
  - FMIs:
    - PFMI (2012) address systemic risks and mitigation for FMIs.
    - Conflict-of-interest concerns if central bank is both operator and overseer of FMIs (e.g., RTGS systems).
    - PFMI Principle 17 assigns board responsibility for operational risk, business continuity, security, outsourcing, and monitoring.
- Reputational risk:
  - Encompasses all financial and nonfinancial risks; can be direct (conduct/transparency) or indirect (consequence of other risks).
  - Only the Central Bank of the Netherlands (DNB) among mentioned central banks applies GRI sustainability reporting standards.
  - Central banks' high public trust increases reputational vulnerability.

### X. Interrelationships and illustrative frameworks
- Examples: Figures cited for interrelationships (Bank Negara Malaysia; Bank of Canada) show operational, policy, reputational and financial risk linkages.
- Bank of Canada places operational risks in both organizational (enterprise risks) and policy (business risks) areas and links financial and nonfinancial risks in an integrated context.

### XI. Risk management elements — three necessary elements
- (1) Strong risk culture;
- (2) Clear and well-defined risk governance;
- (3) Proper risk tools.
- Risk culture:
  - IIF: "the way risks are identified, understood, discussed, and acted upon in the organization.... It is, above all, about actual behavior – what you do, not just what you say."
  - FSB: sound risk culture ensures emerging material risks are recognized, escalated, and addressed timely.
  - IMF/Viñals et al (2014) and GFSR links risk taking to corporate culture; FSB "culture indicators": (a) integrity by board/management, (b) accountability of staff, (c) communication/discussion of decision-making, (d) consistency of incentives with values.
  - "Tone at the top" essential (examples: governor suspending staff for breaches).
  - Quantitative indicators from sample (IMF Central Bank Legislation Database, August 2014):
    - 15 out of 93 central banks have any specific reference to "risk management" in legislation.
    - 1 out of 4 monetary unions has such a reference.
    - No central bank or monetary union in the sample references nonfinancial or operational risk or a specific Risk Management Department.
  - Historic survey: in 1999 only 15 percent of central banks examined had an independent risk management unit.
- Risk governance terminology (FSB (2013)):
  - Risk appetite framework (RAF): policies, processes, controls, and systems for establishing, communicating, and monitoring risk appetite.
  - Risk appetite statement: written articulation of aggregate level/types of risk willing to accept; should address hard-to-quantify risks such as reputation and conduct.
  - Risk capacity: maximum level of risk given resources and statutory capital.
  - Risk appetite: aggregate level/types of risk assumed within risk capacity.
  - Risk limits: quantitative measures allocating aggregate risk appetite.
  - Risk profile: point-in-time assessment of gross and net risk exposures.
- ERM:
  - Process steps: risk identification -> assessment/measurement -> prioritization/management -> monitoring/reporting -> identification.
  - Popular frameworks: COSO (2004) and ISO 31000 (2009).
  - COSO components: Internal Environment; Objective Setting; Event Identification; Risk Assessment; Risk Response; Control Activities; Information and Communication; Monitoring.
- Risk tools and methodology (BCBS Sound Practices basis):
  - Internal loss data collection and analysis (losses, near misses, root cause analysis);
  - External loss data collection and analysis;
  - Audit findings integration;
  - Risk & control assessments (RSA/RCSA) with threat libraries and residual risk scoring;
  - Business Process Mapping to identify steps and interdependencies;
  - Risk and Performance Indicators (KRIs and KPIs) with escalation triggers;
  - Scenario Analysis (expert-driven; governance needed to manage subjectivity);
  - Measurement and comparative analysis across tools.
- ECB example: financial buffer exercise (FBE) uses about 20 stress scenarios (exposures on (corporate) bonds, equity, gold, currency risk) — currently excludes operational risks but could be extended.
- ECB developed an operational risk taxonomy to create a common language and consistent reporting.

### XII. Appendix I — Examples of good practices (selected central bank cases)
- NY Fed (Operational Risk Management):
  - Operational risk regarded as predominant risk; framework development since 2005.
  - Hired external firm in 2009/2010; established Chief Risk Officer (CRO), Risk Oversight Committee, Risk Group (2013-2014).
  - Practices: link operational to credit risk; foster "reporting mistakes" culture; risk champions; Risk Advisory Council; Board Audit and Risk Committee involvement.
- De Nederlandsche Bank (DNB) — Information Security Policy:
  - 2013 governance strengthening: three-layer governance (Information Security Expert Team; Information Security Coordination Group; Governance Board Information Management).
  - Installed CISO and Information Security Risk Manager within Operational Risk Management Unit.
  - Results: centralized quarterly reporting beginning 2014; investigations and maturity assessments by Q2 2014; renewed permanent Awareness Campaign by Q2 2014; by end-2014 information security topics addressed at all levels.
  - Three information security gates: (a) social gate, (2) technical gate, (3) physical port.
- Bank Al-Maghrib (BAM):
  - Operational risk framework since 2004; decentralized risk organization with network of risk managers in each business unit.
  - Bank-wide consolidated risk map; input to strategic and budgeting planning; linkage to internal audit.
  - Project Risk Approach mandatory for strategic projects (10 to 12 per 3 years strategic cycle).
  - Considering completion of global integrated risk approach covering strategic, operational, projects and financial risks.
  - Strategic plans contain 10 to 15 strategic objectives.
- Central Bank of Jordan (CBJ):
  - Since 2014 set up Risk Management Department (RMD); permanent Risk Management Committee chaired by Governor.
  - Implemented three lines of defense and "risk champions".
  - Developed bottom-up risk appetite process.
  - Loss data collection methodology: "If you see it, you must ensure someone reports it."
  - Mandatory Training Framework and innovative training methods.
  - Business Continuity Plan pillars: (a) Business Impact Analysis, (b) scenario-analysis, (c) empowering business departments to develop partial BCPs.
  - Treated strategy and policy risks as part of ERM and began a registry methodology for strategic/policy risks.

### XIII. Appendix II — Examples of recent operational risk incidents (selected)
- Stealing of banknotes:
  - Netherlands: DNB employee stole 1,250,000 euros (September 2008); perpetrator abroad; DNB improved controls (Volkskrant, June 27, 2011).
  - Albania: employee confessed to stealing LEK 710 million over four years; parliament dismissed central bank governor; 19 employees arrested (FT, September 18, 2014).
- Money-printing bribery and money laundering:
  - Austria: OeBS case; $18 million paid through offshore accounts; seven defendants convicted (Washington Post, November 15, 2014).
  - Australia: Securency/Note Printing Australia bribery allegations; arrests and court hearings (Washington Post, November 15, 2014).
- Manipulation of auctions:
  - United Kingdom: Bank of England investigation into possible manipulation of money-market auctions (no specific date in excerpt).
- Regulatory capture and supervisory failures:
  - USA (NY Fed): reviews of regulatory capture and supervisory information flows; examples include Goldman Sachs access allegations and "London Whale" supervisory shortcomings (FT, November 20, 2014).
- Internal fraud and improper payments:
  - Swaziland: E7.5 million fraud in Central Bank of Swaziland (Swazi Observer, December 2, 2014).
  - Tanzania: Ernst & Young audit found more than TSh133 billion-worth ($116m) of improper payments; governor sacked (Centralbanking.com, January 11, 2008).
  - Kuwait: central bank governor denied illicit share trading allegations; reported purchase of 7,000 and later 2,172 shares (Reuters, February 5, 2015).
- Misconduct, political pressure, legal threats:
  - Turkey: central bank head faced potential criminal sanction and lawsuit alleging "serious material damage" due to interest rate policy; prosecutor sought up to two years imprisonment (Zerohedge, February 17, 2015).

### XIV. Conclusions, recommendations and directions for future work
- Central conclusion:
  - Effective governance (mandates, independence, accountability/transparency, internal governance) is critical for central banks irrespective of mandate scope.
- Nonfinancial risk management observations:
  - Received the least attention relative to financial risk; internal audit and compliance better charted than nonfinancial risk management.
- Policy recommendations (selected):
  - Integrate nonfinancial risk management into central bank strategic planning and governance frameworks.
  - Integrate financial and nonfinancial risk management where feasible.
  - Quantify nonfinancial risks where possible and adapt tools/frameworks from outside central banking (ERM, ISO 31000, COSO, BCBS practices).
  - Consider public-sector nature and legal monopoly objectives when designing risk frameworks.
  - International financial institutions (in particular the IMF) should integrate nonfinancial/internal governance matters into surveillance, safeguards, and advisory work and consider adding them to existing Codes and Practices.
  - Encourage experience-sharing among central banks with extensive experience (examples cited: Bank Negara Malaysia, Bank of Canada, ECB) and those transforming risk management (examples cited: Federal Reserve New York, Central Bank of Jordan) through forums such as the IORWG, BIS central bank governance forum, and IMF/WB technical assistance programs.

*Source: _wp1634 (selected content extracted from the source PDF).*

### References .............................................................................................................

### _wp1634 - References

### I. Introduction: role of governance and focus of paper
- Effective governance is "of the utmost importance for central banks trying to achieve their goals."
- Governance pillars identified: mandates, independence, accountability and transparency, and internal governance.
- Empirical emphasis:
  - Independence types mentioned: political, operational, and financial.
  - Mandates have received increasing attention since the global financial crisis (e.g., solvency and liquidity issues of commercial banks).
- Paper objectives (funnel structure):
  - (i) Outline the issue of central bank governance in general;
  - (ii) zoom in on internal governance and organization issues of central banks;
  - (iii) highlight the main issues with nonfinancial risk management;
  - (iv) end with a number of recommendations for future work.

### II. Prerequisites for proper nonfinancial risk management
- The global financial crisis prompted new thinking on central bank governance by:
  - Extending traditional governance ideas from monetary policy to supervisory/regulatory functions.
  - Moving discussions beyond organization to elements of behavior and culture.
- References cited in this section include: Eijffinger (2014), Lybek (2004a, 2004b), Sullivan (2014), Bayoumi (2014), World Bank (2014), FSB (2014), BIS (2009).
- Key observation: nonfinancial risk management of central banks has been examined the least, despite internal-audit, compliance, board structure, and decision-making processes being well-charted.
- Drivers for increased attention to nonfinancial risk management:
  - Central banks acting as investors and being in the public spotlight.
  - The potential for nonfinancial risks to carry large adverse (financial) effects for central banks.

### III. Governance: definition and applicability to central banks
- OECD (2004) definition of governance cited and applied:
  - Governance is "a set of relationships between a company’s management, its board, its shareholders, and other stakeholders."
  - Governance "provides the structure through which the objectives of the company are set, and the means of attaining those objectives and monitoring performance."
  - Governance "provides proper incentives for the board and management to pursue objectives that are in the interest of the company and its shareholders and should facilitate effective monitoring."
  - The presence of effective corporate governance "helps provide a degree of confidence that is necessary for the proper functioning of a market economy."
- Applicability:
  - The governance definition is treated as generic and applicable to companies and central banks alike.
  - Emphasis on building confidence and trust both within the organization and across society.

### IV. Distinctive characteristics of central banks and governance implications
- BIS (2009) definition: central banks are "public policy institutions whose main goals are to preserve monetary stability and promote financial stability".
- Additional typical central bank functions listed:
  - Provide core components of payment systems.
  - Often manage the country’s gold and foreign exchange reserves.
  - Play a major role in the oversight and development of the financial system.
  - In some countries, tasks also include banking services, asset and debt management to the state, and providing general economic advice to the government.
- Four specific characteristics common to all central banks:
  - (1) the public policy objectives (which can vary),
  - (2) the lender of last resort role,
  - (3) balance sheet structure (including the fact that central banks do not go bankrupt),
  - (4) the need to "lead by example" (which includes a certain fiduciary responsibility to society).
- Legal structures can be complicated and differentiated, with both public and private corporate elements.
- From these characteristics derive four main governance issues relevant to all central banks:
  - (a) mandates;
  - (b) independence;
  - (c) accountability and transparency;
  - (d) internal governance.
- Note: The paper states that "Issues relating to mandates, accountability and transparency will not be discussed further in this paper: they have been discussed in central bank literature over the years."

### V. Box 1 — Accountability and Transparency of Financial Supervisors (summary of BIS/BCBS guidance)
- The Basel Committee on Banking Supervision Task Force on Impact and Accountability provides guidance to central banks with supervisory mandates, seeing accountability and transparency as core drivers for effective financial supervision.
- Purported benefits of accountability and transparency:
  - Strengthen supervisors' willingness to act and deliver sound supervisory outcomes.
  - Strengthen supervisors' technical independence and help counter institutional capture.
- Accountability:
  - Reinforces democratic checks and balances to ensure high-quality supervision as a public service.
  - Requires objective and transparent procedures to call board members and senior staff to account for poor performance.
  - The text: "As Figure 1 demonstrates, lack of accountability will erode support credibility of/trust in the central bank."
- Transparency:
  - Puts supervisors’ actions and decisions under public scrutiny to enable accountability.
  - Must respect confidentiality but cannot be used as an excuse to avoid public scrutiny.
  - Transparency in supervisory outcomes and decision-making "limits the arbitrariness of supervisors, exposes undue government and industry interference, and encourage good and effective supervisory practices."

*Source: _wp1634 - References*

### Box 1 gives an example of thought

### Box 1 gives an example of thought

### Overview
- Presents development on accountability and transparency for central banks that are also financial supervisors.
- Emphasizes distinctions among various forms of independence and the close link between independence and internal governance.
- Uses Figures (Figure 1, Figure 2, Figure 3, Figure 4, Figure 5) to illustrate governance and risk frameworks (sources: IMF staff; ISO 31000).

### A. Central Bank Independence
- Independence is multifaceted; Lybek (2004a) distinguishes “autonomy” (operational freedom) and “independence” (lack of institutional constraints) and four types of autonomy: goal, target, instrument and limited.
- Paper’s operational distinction of independence includes:
  - Political independence:
    - Central banks formulate and execute monetary policy without undue political influence of the executive and/or legislative power.
    - Checks and balances include legal requirements on approval and dismissal procedures for governors/board members.
    - Some countries require a “double veto” (executive and legislative or judicial involvement) for hiring/firing governors.
    - Reasons for firing a governor should be clearly laid down in the central bank’s law.
  - Operational independence:
    - Central banks should be severely limited in / prohibited to financing public sector expenditure to avoid inflationary impact of financing fiscal deficits with central bank money.
    - Central banks are free to formulate interest rate policy; execution is an exclusive responsibility of the central bank.
    - Some countries require the central bank to agree with the government on the inflation target (no target or goal independence).
  - Financial independence:
    - Government should ensure the central bank’s capital integrity to support policy independence.
    - Central bank transfers profits to government after accumulating appropriate legal reserve provisioning.
    - Central banks should not engage in quasi-fiscal operations which often deteriorate financial position.
    - Financial independence and transparency of financial relations with government facilitate accountability.
- Legal independence is a cross-cutting component indicating legislative intent about the degree of independence and is the basis of many systematic characterizations of independence.

### B. Internal Governance
- Internal governance covers structure, decision-making processes, risk management arrangements and control mechanisms, internal audit — everything influencing decision-making within the central bank.
- Behavior and culture are fundamental drivers of governance issues; behavioral insights from psychology, sociology, and behavioral economics matter for policy success and organizational performance (reference: World Bank’s World Development Report 2015).
- Board effectiveness:
  - Measured by collective vision of mandate/purpose, culture, values and behaviors.
  - British Financial Reporting Council (FRC) attributes of an effective board:
    - provides direction for management (both on form and in substance);
    - demonstrates ethical leadership, displaying—and promoting—behaviours consistent with the culture and values it has defined;
    - creates a performance culture that drives value creation without exposing it to excessive risk of value destruction;
    - makes well‐informed and high‐quality decisions based on a clear line of sight into the business;
    - creates the right framework for helping directors meet their statutory duties;
    - is accountable; and
    - thinks carefully about its governance arrangements and embraces evaluation of their effectiveness.
  - Board composition should reflect central bank functions; qualification requirements include good moral standing and relevant experience; “soft skills” and organizational skills are increasingly relevant.
  - Board behavior is influenced by group dynamics; issues such as peer pressure, groupthink, and dominance of individuals (e.g., Governor/President) can affect decision making.
  - Board evaluations are a relatively new practice but may provide useful tools.
- Accounting and reporting:
  - Accounting affects central bank operations for monetary policy and financial stability.
  - Larger balance sheets (post-GFC, unconventional monetary policy, large scale quantitative easing) increase exposure to additional risks and (re)capitalization issues.
  - Complex new rules for financial instruments represent a massive shift in treasury, product, financial and operational risk management techniques.
- Control functions:
  - Include risk management, compliance/legal and internal audit (assurance).
  - Roles under the Three Lines of Defense model:
    1) First line (business departments): risk owners responsible for activities that create risk and first assessment;
    2) Second line (centralized Risk Management Department (RMD)): responsible for controlling risks from the first line by challenging and monitoring;
    3) Third line (Internal Audit Department; some consider external auditor part of third line): responsible for assurance that risks are properly identified, controlled and monitored by first and second lines.
  - The paper focuses on risk management; compliance and internal audit are left out of scope except where distinctions are highlighted.
  - Separation of functions is recommended; central banks should avoid combining internal audit and risk management to preserve independent assurance, though close cooperation and combined assurance approaches can add value.

### III. RISK MANAGEMENT
- Financial risk management covers market, credit, interest rate, and liquidity risks.
  - Liquidity risk may be mitigated by money-printing rights but can shift risks to price and financial stability.
  - Interest rate risk arises from domestic and foreign rates.
  - Credit risk relates to lender of last resort and fiscal agent roles; credit and market risk often stem from foreign exchange/reserves exposure.
  - Expanded use of quantitative easing, sovereign bond purchases, and retail lending schemes has increased financial risk scale and volatility.
- Evolution of risk management:
  - Historically decentralized; trend toward centralized, independent departments with integrated overview of all risks.
  - Many central banks still separate financial and nonfinancial risk management.
  - Limited incentives exist to reshape risk management due to negative capital possibilities, state guarantees, and seigniorage rights.
  - Rethinking of central bank risk management has developed slowly over the past 15 to 20 years; the GFC provided added impetus.
- Risk management definition and standards:
  - Risk management: “the coordinated activities to direct and control an organization with regard to risks.”
  - Governance arrangements relate to (1) overall responsibility, (2) day-to-day management and (3) systems.
  - ISO 31000 (published in 2009) provides principles and guidelines to design, implement and maintain risk management processes across organizations.
- Nonfinancial risk management is underdeveloped relative to financial risk management.
  - BIS post-2008 crisis report noted nonfinancial risks are handled less advancedly than financial risks.
  - Nonfinancial risks are diverse and often lack historical data for validation; even financial risk models generate operational risks (fraud, human error, IT problems).
- Roles of Risk Management vs Internal Audit:
  - Risk management: middle-office, centralized function identifying, assessing, prioritizing and monitoring risks and mitigation measures.
  - Internal audit: independent assurance function conducting audits of risk management procedures, systems, and RM department functioning.
  - Combining both functions in one department is discouraged; combined assurance (internal assurance providers, management assurance, external assurance connected to key risks) can be effective.

### Nonfinancial Risk: Categories and Definitions
- Nonfinancial risk is broken down into three subcategories:
  - (a) Operational risk
  - (b) Policy risk
  - (c) Reputational risk
- Operational risk:
  - Linked to failures due to internal processes, systems, people or external events.
  - ECB wider definition: “the risk of negative business, reputational or financial impact for the bank which derives from specific risk events due to or facilitated by root causes pertaining to governance, people, processes, infrastructure, information systems, legal, communication and changes in the external environment”.
  - Examples: remuneration controversies, expensive business travel, IT problems affecting payment systems, clearance and settlement, protection of classified information, and failures to follow internal procedures (e.g., employer duties).
  - Basel II event categories for operational risk (7 event categories):
    1) Internal Fraud: misappropriation of assets, tax evasion, intentional mismarking of positions, bribery;
    2) External Fraud: theft of information, hacking damage, third-party theft and forgery;
    3) Employment Practices and Workplace Safety: discrimination, workers compensation, employee health and safety;
    4) Clients, Products, and Business Practice: market manipulation, antitrust, improper trade, product defects, fiduciary breaches, account churning;
    5) Damage to Physical Assets: natural disasters, terrorism, vandalism;
    6) Business Disruption and Systems Failures: utility disruptions, software failures, hardware failures; and,
    7) Execution, Delivery, and Process Management: data entry errors, accounting errors, failed mandatory reporting, negligent loss of client assets.

*Source: _wp1634 - Box 1 gives an example of thought*

### Appendix 1 gives an overview of some well-known and less well-known cases of recent

### _wp1634 - Appendix 1 gives an overview of some well-known and less well-known cases of recent

### Overview of operational and reputational incidents
- Appendix 1 lists recent central bank cases (as published in (inter)national press and/or on central bank websites) including: Albania (stealing of banknotes), The Netherlands (stealing of banknotes), Austria (money-printing bribes and money laundering), Australia (money-printing bribes), Bank of England (manipulation of auctions), New York Fed (regulatory capture), Swaziland (internal Fraud), and Tanzania (internal Fraud). These serve as examples of reputational risks without judgment on press accuracy.
- Definition: operational risks are all the nonfinancial risks any organization—including a central bank—will run, and unlike other risk categories they do not have an upside of higher yield from increased exposure.
- Note: legal risk is often included in operational risk definitions but can be viewed as a consequence of other operational failures rather than a standalone category.

### International coordination and practice-sharing
- The International Operational Risk Working Group (IORWG) was set up in 2005 and "promote[s] the exchange of operational risk management best practices in central banking".
- The IORWG currently has 61 central bank members and shares experiences and best practices in operational risk and related areas such as compliance, internal audit, and training.
- The BIS facilitates the Central Bank Governance Group and network.

### Policy risk: key areas and manifestations
- Policy (or strategy) risk arises from central bank policy activities (monetary policy; expanded mandates such as financial stability/financial supervision and regulation, banking resolution, market supervision, and financial integrity).
- Most central banks include monetary policy risks in monetary policy committee decision-making; some integrate policy risk into general risk management frameworks.
- Monetary policy operations often have strict risk control criteria (e.g., collateral requirements) to contain risks.

Subsection: Policy Risk and Financial Integrity Units (FIUs)
- FIU role (FATF definition): national centre for receipt/analysis of suspicious transaction reports and other information relevant to money laundering, predicate offences and terrorist financing; should obtain additional information and have timely access to financial, administrative and law enforcement information.
- Typical FIU administrative locations: ministry of finance, the central bank, or a regulatory agency.
- Conflict potential: when housed within central banks, FIUs handle sensitive information on banks that may interest central bank policy areas (financial stability, supervision), especially if the FIU also acts as an integrity supervisor.
- Independence rationale: central bank independence can be a reason to house an FIU to safeguard independence from government.
- Prevalence: about 50 countries have some form of "cohabitation" of the FIU and the central bank.
- Risks: mandate/objective clashes, transparency differences, incompatibility of functions, and budgetary matters (including FIU budget autonomy).
- Examples of large bank fines mentioned: BNP Paribas paid 8.9 billion USD; Credit Suisse paid 2.6 billion USD; HSBC paid $1.9 billion U.S.

Subsection: Policy Risk and Reserve Management
- IMF definition: reserve management relates to ensuring adequate official public sector foreign assets that are readily available and controlled by the authorities for predefined objectives.
- Reserve management objectives (IMF (2013), Article 8): (1) adequate foreign exchange reserves for a defined range of objectives; (2) liquidity, market, credit, legal, settlement, custodial, and operational risks controlled prudently; (3) subject to constraints, reasonable risk-adjusted returns over the medium to long term.
- Governance needs: clear allocation and separation of responsibilities and accountabilities; appropriate hierarchical levels; committee structure; separation of investment and risk control; internal audits and well-trained staff.
- IMF Guidelines note importance of identifying authority to reconcile inconsistencies/interferences between reserve management and other central bank functions and avoiding unwanted signaling effects.
- IMF-listed operational risks in reserve management:
  a) Control system failure risks: fraud, money laundering, theft enabled by weak controls, inadequate skills, poor separation of duties, and collusion.
  b) Financial error risk: incorrect measurement of net foreign currency position leading to large unintended exchange rate risks and losses.
  c) Financial misstatement risk: incorrect inclusion of funds lent to domestic banks, placements with own foreign subsidiaries, or other non-reserve assets as reserves.
  d) Loss of potential income: failure to reinvest nostro account balances timely due to inadequate monitoring/reconciliation.

Subsection: Policy Risk and Financial Market Infrastructures (FMIs)
- FMIs facilitate clearing, settlement, and recording of monetary and other financial transactions and can strengthen markets or pose systemic contagion risks in stress.
- 2012 BIS/IOSCO Principles for Financial Market Infrastructures (PFMI) address systemic risks and mitigation for FMIs.
- If a central bank is an FMI operator and an overseer of private-sector FMIs, it must consider possible/perceived conflicts of interest between those functions.
- Common central bank FMI: Real Time Gross Settlement (RTGS) payment systems, where transfers are real time and on a gross basis; RTGS systems are essential to banking system efficiency.
- PFMI Principle 17: board of directors is responsible for defining operational risk, endorsing frameworks, business continuity plans, physical and information security policies, outsourcing risk management, and monitoring.
- PFMI note: commercial standards on information security, business continuity, and project management are applicable and useful for FMIs and central banks.

### Reputational risk
- Reputational risk encompasses all financial and nonfinancial risks; it can emerge directly from conduct/transparent reporting or indirectly as a consequence of other risks.
- Direct manifestation: manner of central bank operations and degree of transparency (e.g., sustainability reporting). Only the Central Bank of the Netherlands (DNB) applies Global Reporting Initiative (GRI) sustainability reporting standards among central banks mentioned.
- Reputational incidents cited: central banks' unconventional crisis roles, market manipulation events (Libor), faulty impairments on nonperforming loans, discussions on bankers’ remuneration.
- Central banks are often among the most trusted institutions, increasing reputational vulnerability.

### Interrelationships and illustrations
- Figures cited (Figure 6 Bank Negara Malaysia; Figure 7 Bank of Canada) illustrate interrelationships among operational risk, policy risk, reputational risk, and financial risk.
- Bank of Canada approach places operational risks in both organizational (enterprise risks) and policy (business risks) areas and links financial and nonfinancial risks in an integrated context.

### Risk management elements (three necessary elements)
- Three necessary elements: (1) a strong risk culture, (2) a clear and well-defined risk governance, and (3) proper risk tools. These apply to financial and nonfinancial risks.

Subsection: Risk Culture
- IIF definition: "the way risks are identified, understood, discussed, and acted upon in the organization.... It is, above all, about actual behavior – what you do, not just what you say."
- FSB: a sound risk culture ensures emerging risks with material impact and activities beyond risk appetite are recognized, escalated, and addressed timely.
- IMF/Viñals et al (2014) links structural measures to steering culture away from excessive risk taking; 2014 GFSR links risk taking to corporate culture and references FSB "culture indicators": (a) integrity by board/management, (b) accountability of staff, (c) communication/discussion of decision-making, (d) consistency of financial and nonfinancial incentives with values.
- "Tone at the top" is essential; examples: governor actions suspending staff for breaches and visible governor support for risk management.
- Quantitative indicators: only 15 out of 93 central banks and 1 out of 4 monetary unions have any specific reference to "risk management" in central bank legislation (sample from IMF Central Bank Legislation Database, August 2014).
- No central bank or monetary union in the sample has a specific reference to nonfinancial or operational risk or a specific Risk Management Department.
- Historical survey: in 1999 only 15 percent of central banks examined had an independent risk management unit.

Subsection: Risk Governance
- Key terminology (FSB (2013)) applicable to central banks:
  - Risk appetite framework (RAF): policies, processes, controls, and systems for establishing, communicating, and monitoring risk appetite; includes risk appetite statement and risk limits; should consider material risks and reputation.
  - Risk appetite statement: written articulation of aggregate level/types of risk willing to accept, including qualitative and quantitative measures; should address hard-to-quantify risks such as reputation and conduct risks.
  - Risk capacity: maximum level of risk the central bank can assume given resources and statutory capital; must consider technical infrastructure, capabilities, expertise, and obligations to stakeholders and society.
  - Risk appetite: aggregate level/types of risk central bank is willing to assume within risk capacity.
  - Risk limits: quantitative measures allocating aggregate risk appetite to business lines, legal entities, risk categories, concentrations, etc.
  - Risk profile: point-in-time assessment of gross and net risk exposures aggregated across categories based on forward-looking assumptions.
- Example governance mechanism: Risk Committee at Board level, paired with Audit Committees.
- Board-level committees add perspectives and legitimacy but can increase bureaucracy and workload; mandates and composition should be context-specific.

Subsection: Enterprise Risk Management (ERM)
- ERM process steps: risk identification -> assessment/measurement -> prioritization/management -> monitoring/reporting -> back to identification.
- Popular ERM frameworks: COSO (Enterprise Risk Management-Integrated Framework, 2004) and ISO 31000 (2009); no specific preference recommended.
- COSO components (illustrative): Internal Environment; Objective Setting; Event Identification; Risk Assessment; Risk Response; Control Activities; Information and Communication; Monitoring; across levels Entity-level, Division, Business unit, Subsidiary.
- ERM provides common risk language facilitating cross-institution best practice sharing.

Subsection: Risk Tools and Methodology (based on BCBS Sound Practices for Operational Risk Management)
- Tools and practices listed:
  - Internal loss data collection and analysis: report actual losses, near misses, root cause analysis, and corrective action plans.
  - External loss data collection and analysis: learn from other banks/central banks (Appendix 1 example: Federal Reserve examination of potential regulatory capture at the New York Fed).
  - Audit findings: insights into control weaknesses and inherent risks.
  - Risk & control assessments (RSA/RCSA): assess processes against threat libraries; RCSA evaluates inherent risk, control effectiveness, and residual risk; scorecards weight residual risks.
  - Business Process Mapping: identify key steps and risk points, interdependencies, and prioritization.
  - Risk and Performance Indicators (KRIs and KPIs): metrics with escalation triggers to warn when thresholds are approached/exceeded.
  - Scenario Analysis: expert-driven identification and assessment of potential operational risk events; requires robust governance due to subjectivity.
  - Measurement: quantify operational risk exposure using assessment outputs in models.
  - Comparative Analysis: compare outputs of assessment tools for comprehensive operational risk profile.
- ECB example: financial buffer exercise (FBE) for financial stresses (currently excludes operational risks but approach could be applied); uses about 20 stress scenarios (e.g., exposures on (corporate) bonds, equity, gold, currency risk).
- ECB developed a taxonomy of operational risks with three objectives: common language, robust mutually exclusive and exhaustive categorizations, and reporting consistency.

### Conclusions and challenges ahead
- Effective governance (mandates, independence, accountability/transparency, internal governance) is critical for central banks irrespective of mandate scope.
- Nonfinancial risk management has received the least attention relative to financial risk; functions like internal audit and compliance are better charted than nonfinancial risk management.
- Recommendations and directions from the text:
  - Integrate nonfinancial risk management into central bank strategic planning and governance frameworks.
  - Integrate financial and nonfinancial risk management where feasible.
  - Quantify nonfinancial risks as much as possible and adapt tools/frameworks developed outside central banking (e.g., ERM, ISO 31000, COSO, BCBS practices).
  - Consider the public-sector nature and legal monopoly objectives of central banks when designing risk frameworks.
  - International financial institutions (in particular the IMF) should integrate nonfinancial/internal governance matters into surveillance, safeguards, and advisory work and consider adding them to existing Codes and Practices.
  - Encourage experience-sharing among central banks with extensive experience (examples cited: Bank Negara Malaysia, Bank of Canada, ECB) and those transforming risk management (examples cited: Federal Reserve New York, Central Bank of Jordan) through forums such as the IORWG, BIS central bank governance forum, and IMF/WB technical assistance programs.

*Source: _wp1634 - Appendix 1 gives an overview of some well-known and less well-known cases of recent (PDF).*

### REFERENCES

### _wp1634 - REFERENCES

### References (selected entries)
- Apps, P., “The role and importance of internal audit,” in Sullivan, K., M. Horáková (eds.), Financial Independence and Accountability for Central Banks, 2014 (London: Central Banking Publications).
- Bayoumi, T, G. Dell’Ariccia, K. Habermeier, and others, “Monetary Policy in the New Normal,” IMF Staff Discussion Note No. 14/3, 2014.
- BCBS, 2006, Joint Forum High-level Principles for Business Continuity.
- BCBS, 2010, Principles for Enhancing Corporate Governance.
- BCBS, 2011, Principles for the Sound Management of Operational Risk.
- BCBS, 2012, Principles for the Internal Audit Function in Banks.
- BIS, 2009, Issues in the Governance of Central Banks – A Report from the Central Bank Governance Group (Basel: Bank for International Settlements).
- BIS, 2013, “Central bank finances,” BIS paper no. 71.
- Camilleri, M-T., T. Lybek, K. Sullivan, 2007, “Audit Committees in Central Banks,” IMF Working Paper no. 07/73.
- Committee of Sponsoring Organizations of the Treadway Commission, 2004, Enterprise Risk Management – Integrated Framework (Committee of Sponsoring Organizations of the Treadway Commission).
- Deloitte, 2011, Combined assurance: taking corporations to the next level of maturity (Johannesburg: Deloitte).
- Eijffinger, S., D. Masciandaro, (eds.), 2014, Modern Monetary Policy and Central Bank Governance (London: Edward Elgar Publishing).
- FATF, 2012, International Standards On Combating Money Laundering And The Financing Of Terrorism and Proliferation - The FATF Recommendations (Paris: FATF).
- FSB, 2013, Principles for An Effective Risk Appetite Framework.
- IMF, 1999, Good Practices on Transparency in Monetary and Financial Policies.
- IMF, 2013, Guidelines on FX Reserve Management.
- IMF, 2014, Global Financial Stability Report: Risk Taking, Liquidity, and Shadow Banking: Curbing Excess While Promoting Growth.
- Lybek, T., 2004a, “Central Bank Autonomy, Accountability, and Governance: Conceptual Framework,” IMF Legal Department Seminar August 2004.
- Lybek, T., J. Morris, 2004b, “Central Bank Governance: A Survey of Boards and Management,” IMF Working Paper No. 04/226.
- OECD, 2004, Principles of Corporate Governance.
- World Bank, 2014, World Development Report 2014: Risk and Opportunity – Managing Risk for Development.
- World Bank, 2015, World Development Report 2015: Mind, Society, and Behavior.

### APPENDIX I — Examples of Good Practices in Central Bank Risk Management (summary)
- Note: “The following examples give illustrative insights into what a number of central banks consider as their own good practices in different areas of risk management. These are not meant to be indicative of general best practices.”

H3: (1) NY Fed’s Operational Risk Management
- Context:
  - The New York Federal Reserve considers operational risk one of its predominant risks and has been developing an operational risk framework since 2005.
- Key actions and practices:
  - In 2009/2010 it hired an external firm to build risk management expertise and subsequently established the role of a Chief Risk Officer (CRO), as well as a Risk Oversight Committee, which incorporated 5 previously separate committees.
  - Currently (2013-2014) it established a Risk Group under the CRO with responsibility for both operational and financial risk.
  - Transforming the Risk Oversight Committee to be the Bank’s overall risk subcommittee (including both financial and operational risks); main challenge is to align the ‘languages’ and involved staff and their expertise.
  - Operational risk function strives to demonstrate and quantify the link between operational risk and the NY Fed’s credit risk.
  - Involvement of Internal Audit and the Board’s Audit and Risk Committee (“tone at the top”) is crucial to an integrated view of risk management.
  - Fostering a culture of “reporting mistakes”; use of ‘risk champions’ at management level to stimulate behavior organization-wide.
  - Established a Risk Advisory Council—an informal council with participants from all NY Fed departments to provide information and discussion input to risk managers and create buy-in.
  - The NY Fed currently does not conduct “stress testing” with oprisk scenarios, though its Business Continuity Department is examining possibilities.
  - The newly developed Strategic Planning Office should ensure alignment between operational risk assessments and strategic choices by the NY Fed’s Board of Directors.

H3: (2) De Nederlandsche Bank (DNB) — Information Security Policy
- Rationale:
  - Given the sensitive nature of central bank activities, information security is a key area; DNB strengthened governance and coordination of information security in 2013.
- Governance model (three layers):
  - (1) Information Security Expert Team (operational level—IS experts).
  - (2) Information Security Coordination Group (tactical level—middle management).
  - (3) Governance Board Information Management (strategic level – top management).
- Objectives:
  - Promote consistency in protection of DNB’s three “information security gates”.
- Organization and roles:
  - Installed within its Operational Risk Management Unit a dedicated Information Security Function (“CISO”) and an Information Security Risk Manager for centralized coordination; both work closely with business management, support functions and internal audit.
- Concrete results:
  - Begin 2014: centralized quarterly reporting about information risks covering security incidents, information risks, information security projects, and information security successes across the bank.
  - End of the second quarter of 2014: multiple investigations started using DNB’s supervision model for measuring maturity levels and behavior embedding.
  - End of the second quarter of 2014: renewed and permanent Information Security Awareness Campaign launched with tailored practical guidance for employees and increased management involvement.
  - By end-2014: information security topics were addressed at all levels within DNB, leading to a consistent approach to protection of the “gates”.
- Note on “three information security gates”:
  - (a) the social gate (through an employee), (2) the technical gate (breaking into ICT systems), and (3) the physical port (unauthorized access to an area of DNB). Each gate has specific security measures and weaknesses.

H3: (3) Bank Al-Maghrib (BAM) — Risk Management Approach
- Background:
  - BAM implemented its operational risk management framework in 2004, focusing on rooting a risk culture in day-to-day management and increasing internal control efficiency.
- Key elements:
  - Decentralized risk organization: network of risk managers in each business unit reporting to the unit’s head; role is to help the business unit (as “risk owner”) identify, assess, and mitigate risks linked to specific activities.
  - Bank-wide consolidated risk map prepared by the RMD Management based on each business unit’s risk map; identifies top risks, the bank’s global risk appetite and tolerance, and risk mitigating actions reviewed and adopted by the governor/board.
  - Risk map serves as input for BAM’s strategic and budgeting planning and for internal audit’s yearly audit planning; audit findings feed into updates of units’ risk maps.
  - Risk Framework combines a bottom-up approach (risks identified by business operators) with a top-down approach (involvement of top managers) to match operational-level risks with bank-wide risks.
  - Specific Project Risk Approach for strategic projects: mandatory rollout for each strategic project (10 to 12 per 3 years’ strategic cycle); consolidated and common project risks reviewed annually as part of the bank’s global risk map.
  - Considering completion of a global and integrated risk approach starting with global consolidated reporting covering strategic, operational, projects and financial risks.
  - BAM’s three year strategic plans usually contain 10 to 15 strategic objectives.

H3: (4) Central Bank of Jordan (CBJ) — Risk Management Department
- Context:
  - Since 2014 CBJ initiated development of an operational risk management framework and set up a Risk Management Department (RMD) integrating risk management into CBJ’s goals and strategy.
- Main steps and practices:
  - Risk governance:
    - Permanent Risk Management Committee chaired by the Governor established.
    - Examination and implementation of the three lines of defense throughout the organization.
    - Assignment of “risk champions” in business departments to share experiences across departments.
  - Risk Appetite:
    - Developed a risk appetite based on a bottom-up approach (input from operational levels) rather than solely top-down; enabled board to better understand specific CBJ risks and decide on risk appetite accordingly.
  - Risk culture:
    - Designed a loss data collection methodology based on “If you see it, you must ensure someone reports it”, creating risk responsibility for all CBJ staff and management.
    - Implemented a mandatory Training Framework including innovative methods (case workshops, quizzes before accessing the password portal, screensavers) to gain and prove competencies in risk management, increasing understanding and autonomy at departmental and centralized levels.
  - Business Continuity Plan:
    - Identified business continuity as a key part of risk management with three pillars: (a) Business Impact Analysis (determining critical business departments, operating systems and processes), (b) working with scenario-analysis, and (c) empowering business departments to develop their own partial BCPs.
  - Strategy and Policy Risk:
    - Treated strategy and policy risks as important components of ERM and initiated work on a methodology to build a registry of strategic and policy risks.

*Source: _wp1634 - REFERENCES (selected content from the source PDF).*

### APPENDIX II. EXAMPLES OF SOME RECENT OPERATIONAL RISK RELATED CENTRAL BANK CASES

### APPENDIX II. EXAMPLES OF SOME RECENT OPERATIONAL RISK RELATED CENTRAL BANK CASES

### Stealing of banknotes
- Netherlands
  - An employee of DNB in September 2008 stole 1,250,000 euros from DNB’s vault, according to an investigation by DNB and local police. The former employee was already abroad when the theft was discovered and has not been traced down yet. "DNB regrets this incident. The existing high level of care and safety is further improved. Use is being made of the latest technology in this field", DNB reported on its website.
  - Source: Volkskrant, June 27, 2011
- Albania
  - Albania’s parliament voted to dismiss the country’s central bank governor for alleged abuse of office. The governor was arrested in his office on September 5, five weeks after a central bank employee confessed to stealing LEK 710 million in banknotes from the vault where he worked. Investigators arrested 19 central bank employees, including all those who worked at the bank vaults outside Tirana, after uncovering irregularities in treasury and bank supervision operations. The employee admitted stealing new banknotes delivered from Switzerland as well as old ones being withdrawn from circulation over a four-year period. He told investigators he stole daily during the World Cup in Brazil in order to place large bets on matches being played. “As a result of the theft several governance issues emerged. The vault operation was not correctly handled because of a lack of personnel, including the lack of a deputy governor responsible for supervision,” said a person with knowledge of the investigation.
  - Source: FT, September 18, 2014

### Money-printing bribery and related money laundering
- Austria
  - Prosecutors put nine people on trial earlier this year, with charges including bribery and money laundering. The defendants included the co-chief executives of Oesterreichische Banknoten-und Sicherheitsdruck, or OeBS, the printing subsidiary of Oesterreichische Nationalbank. Austrian prosecutors said the central-bank employees jacked up the price of the currency so the surplus could be used for bribes. A total of $18 million was paid through offshore accounts to officials at Azerbaijan’s and, later, Syria’s central banks to win printing contracts, prosecutors say. On Oct. 3, seven of the defendants were convicted in Vienna’s criminal court. Azerbaijan’s central-bank governor, and Central Bank of Syria Governor were never charged with crimes in Austria. Witnesses at the Vienna trial alleged payments; prosecutors traced a money trail through Panama, Lebanon, Abu Dhabi and the British Virgin Islands. One of the bribes, prosecutors said, consisted of several hundred tons of malt that was delivered to Azerbaijan in 2005. Auditors found OeBS had paid millions of euros to offshore shell companies and received nothing in return.
  - Source: Washington Post, November 15, 2014
- Australia
  - Australian police alleged in 2011 that Securency International Pty paid kickbacks to government officials in Indonesia, Malaysia, Nepal and Vietnam to persuade them to buy the company’s weather-resistant plastic bank notes. Securency was at the time a joint venture between privately owned, British-based Innovia Group and Note Printing Australia, a wholly owned subsidiary of the Reserve Bank of Australia. In one instance, Securency employees delivered suitcases full of cash to Indonesian officials, the newspaper The Age in Melbourne reported in December 2013. At least eight former managers and other employees at Securency and Note Printing Australia have been arrested and face court hearings in Melbourne next year to determine whether there’s enough evidence for a trial under Australian bribery laws.
  - Source: Washington Post, November 15, 2014

### Manipulation of auctions
- United Kingdom
  - The Bank of England opened a formal investigation into whether its officials knew of – and even facilitated – the possible manipulation of auctions designed to inject money into the credit markets to alleviate the financial crisis. Lord Grabiner QC was asked by the BoE to head the investigation to probe whether a series of money-market auctions held by the central bank in late 2007 and early 2008 were rigged, and whether officials were party to any manipulation. The investigation focused on auctions run as firefighting measures at the start of the financial crisis when the BoE lent money for various time periods against low and even negative interest rates in exchange for a wide range of collateral such as asset-backed securities.
  - Source: (no specific date provided in source excerpt)

### Regulatory capture and supervisory failures
- USA (NY Fed)
  - The Federal Reserve board conducted a major review of how the regulator and its reserve banks supervise large financial institutions amid criticism that it is too close to and too lenient with the Wall Street groups it oversees. “One subset of this system-wide inquiry will analyse regulatory capture,” the NY Fed president said in written testimony. The Fed examined whether board members receive the information they need to make sound oversight decisions, and whether it has adequate methods to receive information needed to resolve differing views about bank supervision. The Fed and the New York Fed were criticised for not being tough enough; examples cited include Goldman Sachs firing an investment banker who allegedly accessed confidential information from the New York Fed, the Fed’s inspector general finding that the agency had identified risks in the JPMorgan unit that lost more than $6bn in the “London Whale” incident but did not act or share information with the OCC, and secret recordings of New York Fed officials declining to press Goldman about a 2012 deal. Former New York Fed bank examiner Carmen Segarra filed a lawsuit claiming she was fired after criticising Goldman; the lawsuit was dismissed by a US federal judge in April.
  - Source: FT, November 20, 2014

### Internal fraud and improper payments
- Swaziland
  - The Central Bank of Swaziland General Manager was implicated by an internal investigation report in a E7.5 million fraud scandal in his department. The Central Bank of Swaziland Governor revealed that in September and October last year, the bank was defrauded a sum of E7.5 million. The bank commissioned an internal review "to look at systems and policies within the Bank to ascertain if there were any deficiencies and/or flaws which had given rise to the fraud" and to consider individual managers’ roles and appropriate remedial steps. This exercise touched on the functions of the implicated manager as the fraud had been carried out in his department.
  - Source: Swazi Observer, December 2, 2014
- Tanzania
  - The president of Tanzania sacked the governor of the Bank of Tanzania after external auditors found massive fraud at the central bank. An audit by Ernst & Young revealed the central bank had made more than TSh133 billion-worth ($116m) of improper payments to 22 companies in the country, many of which are said to be fictitious. The payments were made in 2005. The president said he was "saddened and angered" by the use of central bank funds to pay off the debts of the companies in question and said he would look to take legal action against those involved. Local news reports said the governor had been in hiding for the past month as a result of the investigation.
  - Source: Centralbanking.com, January 11, 2008
- Kuwait
  - Kuwait's central bank governor denied illicit share trading after a local newspaper reported the securities regulator had decided to refer him to prosecutors on suspicion of violating investment rules. The governor stated he had never traded shares in any listed company during his years in senior posts at the central bank, and that data from the Kuwait Clearing Company confirmed this. He said he had bought 7,000 shares in a local bank "many years ago" before he held a senior central bank post and before the CMA was created, and later subscribed to a capital increase buying 2,172 more shares, but denied using internal information or any conflicts of interest.
  - Source: Reuters, February 5, 2015

### Misconduct, political pressure, and legal threats
- Turkey
  - Turkey Central Bank Head faced potential criminal sanction after the president filed a lawsuit accusing the governor of causing "serious material damage inflicted to Turkey’s citizens as a result of an erroneous interest rate policy of the central bank." The prosecutor said the governor could be imprisoned for up to two years. The president criticized the governor’s work and said that if the central bank’s head can’t cope with his duties, he will be held accountable, claiming inflation is due to high interest rates. Turkey’s deputy prime minister for economic affairs said the central bank pursues right monetary policy.
  - Source: Zerohedge, February 17, 2015

*Content taken from the source document: APPENDIX II. EXAMPLES OF SOME RECENT OPERATIONAL RISK RELATED CENTRAL BANK CASES*

---


_Source: https://www.imf.org/-/media/websites/imf/imported-full-text-pdf/external/pubs/ft/wp/2016/_wp1634.pdf_
