News · 2023-09-24
Risk Management in the Financial World: UBS Payment and the Role of PRINCE2 and OWASP
Multimillion-Dollar Fine for UBS: The Consequences of Inadequate Risk Management Structures
Multimillion-Dollar Fine for UBS: The Consequences of Inadequate Risk Management Structures
UBS, one of the world's leading investment banks and financial services companies, has paid over $380 million in fines in the US and the UK for its recently acquired rival Credit Suisse. This was due to inadequate risk management, inexperienced staff, and failure to resolve previously identified deficiencies. This case serves as a prime example of the importance of corporate governance structures. We have already written an article on this topic, which can be read at the following link.
To protect oneself from potential consequences, it is therefore necessary to take preventive measures and comply with legal regulations.
Compliance with IT Requirements (BAIT) for Banks
In 2017, the Federal Financial Supervisory Authority (BaFin) issued a circular defining specific IT requirements. This catalogue now comprises 12 chapters covering governance and organizational duties as well as technical measures. The background to BAIT is Section 25a of the German Banking Act (KWG), which specifies the special organizational duties of credit institutions regarding risk management and the establishment of internal control procedures.
Introduction to the Project Management Method: PRINCE2
PRINCE2 stands for "Projects In Controlled Environments". This approach comprises 7 principles, 7 themes, and 7 processes. The method uses a comprehensive waterfall approach and defines various phases within a project. An essential aspect of this model is risk management, which is considered, continued, and documented right from the start. A risk register is created to comprehensively identify, assess, and delegate all risks. This makes the method suitable for executing various projects and gaining an overview of all risks.
Consideration of Identified Risks According to OWASP
OWASP stands for "Open Web Application Security Project" and is an organization of experts dealing with web application security. The group annually publishes a report on the "Top 10 list of the most common attacks and main risks in web applications". This should prompt companies to check whether their own applications are protected against such attacks or to take measures to protect against them. Additionally, OWASP has developed a methodology for assessing and prioritizing risks. A detailed description and implementation can be found at the following link.
Conclusion
In summary, meeting legal requirements, conducting effective risk analyses, and making sustainable decisions remain a challenge. However, they can be overcome through suitable processes and IT support.
The pursuit of transparency, clear reporting, and independent decision-makers is one response to this issue. The introduction of professional documentation with the help of innovative technical solutions also contributes to achieving this goal.
Take the opportunity to get and stay in touch with us via social networks
See how MeJuvante products can help your team.
Explore the store