Strategic Enterprise Risk
Architecture
Sandeep Maira
October 19, 2017
Head, Enterprise Risk & Compliance Technology
The Bank of New York Mellon
2 Information Classification: General
Enterprise Risk Architecture Objectives
E2E Architecture for risk (and beyond) including data, processing and reporting
Benefits include -
• Satisfy regulatory as well as internal risk management objectives. Support CCAR but also
internal risk analysis.
• Reduce overall costs
• Improve enterprise wide data consistency
• Leverage advances in Big Data and computing power to provide advanced and predictive
analysis
3 Information Classification: General
Regulatory
Risk
Ad-hoc
Data Science
Control Framework :Data Governance, System Monitoring
Classification
Model
Development
Data Sourcing &
Staging
Model Dev/
Management
Aggregation
Credit Risk
Ops Risk
Liquidity Risk
Market Risk
Model
Management
Scenario
Management
CCAR
Calculators
Model
Parameters
Reporting/
Analysis
DataLake
CommonStagingDB
Reference Data
Collateral
Positions
Transactions
Credit Liquidity Basel
Business Process Management: Reviews, Handoffs
Target State Logical Architecture – Component View
VaR
4 Information Classification: General
3
1
4
5
Architecture
Components
Design Approach Benefits Challenges
Data • Leverage shared
position, transaction,
collateral and reference
data services across risk,
finance, treasury
• Provides data consistency
and traceability. Reduces
costs.
• Helps satisfy BCBS 239
and SR14-1
• Provides the basis for
advanced analysis
• Organizational
boundaries
• Upfront expense
Model
development
• Sandbox for model
development purposes
• Model registry for model
definitions and approval
• Scenario registry for
regulatory & internal
scenarios
• Scalable infrastructure for
model development
• Improve controls and
governance
• Reduce costs through
model re-use
• Ownership model
between business
and technology
• Multiple coding
languages
Calculators • Calculators as services • Consistent results for
given inputs
• Reusability and cost
reduction
• Integrating disparate
technologies
• Retrofitting can be
difficult
Risk Architecture Design Objectives and Approach
5 Information Classification: General
1
Architecture
Components
Design Approach Benefits Challenges
Aggregations • Configurable
aggregations for risk
measures
• Flexibility to aggregate and
drill down at all levels
• Deep and accurate
datasets
Workflow • Integrated workflows for
handoffs, approvals and
validations
• Single inbox for all tasks
• Streamline and reduce
operational overhead
• Improved data validation
• Enforce risk policies
• Integration of different
platforms
Reporting • Support static and flexible
ad-hoc capabilities
• Ability to slice and dice
on all major dimensions
and support rich
visualizations
• Threshold capabilities on
all required measures
• In-depth analysis of all
types of risk events
• Early and easy
identification of outliers
• Helps satisfy BCBS 239
and SR 14-1
• Acquiring breadth
and depth of data
Control • Support data lineage,
validations and glossaries
• Data reconciliations
• Robust exception
handling and alerting
• Satisfy BCBS 239 and
ensure data consistency,
accuracy and
completeness
• Monitor health of
production infrastructure
• Operational
ownership across
multiple business
lines
• Agreement on terms
Risk Architecture Design Objectives and Approach
6 Information Classification: General
Use Case - CCAR
• Acquire data from
master data sources into
common data staging
• Handoffs are validated
Models are developed
• Model risk management
approves models
• Scenarios are updated
• Models move to
production and source
data
• Results are aggregated
• Results are available for
reporting
• Data quality and system
monitoring checks
CCAR Process
1
1
2
6
3
4
5
7
8
9
2
3
4
5
6
7
8
9
7 Information Classification: General
What is my ‘exposure’ to Greece?
What is my credit risk?
What is my market risk?
What potential exposure will I
have with a further worsening?
Do I have any compliance
issues?
What ‘Greek’ counterparties do I have?
What is the current exposure and future
potential exposure?
What collateral do I have?
What Greek instruments do I have?
What hedges do I have in place?
Are there any AML issues?
For counterparty ABC with
high credit exposure, what
instruments do I hold? Do I
have any AML concerns ?
With further worsening of
conditions what might
happen?
What is my exposure with a 30
percent drop in Greek bonds?
More Interesting Q’s……..
8 Information Classification: General
Regulatory
Risk/Finance/
Treasury/
Compliance
Business
Intelligence
Reporting / Analysis
Risk
Treasury
Finance
‘Big Data’
DB
Regulatory
• The data lake can provide ‘Business Intelligence’ within and
across domains
• The ‘Big Data’ DB has very wide depth and breadth of data, for
advanced analysis. Data science analytics, including (for
example) statistical analysis and machine learning, can be
performed in this environment. This DB can also be used for
model development.
Compliance
Target State Logical Architecture – Modeling and Data
Science
Historical
Data
9 Information Classification: General
Appendix
10 Information Classification: General
Regulatory
Risk/Finance/
Treasury/
Compliance
Business
Intelligence
Reporting / Analysis
Risk
Treasury
Finance
‘Big Data’
DB
Regulatory
Compliance
Data Pathway
Control Frame Work :Data Governance Tools
• Data governance tools including data lineage, glossaries
• The ‘Big Data’ environment can also be used for ad-hoc
analysis
Target State Logical Architecture – Data Lineage

More Related Content

PPTX
Strategic Enterprise Risk and Data Architecture
PDF
Big data and Process Safety
PPTX
Data Quality Presentation
PPTX
Hm 418 harris ch11 ppt
ODP
Data quality overview
PPTX
Тестирование данных с помощью Data Quality Services (MS SQL 12)
PDF
Data Quality Management - Data Issue Management & Resolutionn / Practical App...
PDF
( Big ) Data Management - Governance - Global concepts in 5 slides
Strategic Enterprise Risk and Data Architecture
Big data and Process Safety
Data Quality Presentation
Hm 418 harris ch11 ppt
Data quality overview
Тестирование данных с помощью Data Quality Services (MS SQL 12)
Data Quality Management - Data Issue Management & Resolutionn / Practical App...
( Big ) Data Management - Governance - Global concepts in 5 slides

What's hot (20)

DOCX
Michael Patterson Combinatorial Resume
PPT
Building a Data Quality Program from Scratch
PPTX
3 Reasons Why Manufacturing Companies are Moving to Dynamics 365FO
PPTX
Enterprise Threat Management
PPTX
Information Security Risk Management
PPT
comesa cybersecurity
PPT
Data Quality Integration (ETL) Open Source
PDF
BBOX Business Risk
PDF
Big Data Analytics
PPT
Cyber Security 2016 Cade Zvavanjanja1
PDF
CHIME Lead Forum - Seattle 2015
PDF
CHIME Lead Forum - Seattle 2015
PPTX
Advantage ppt data breaches km approved - final (djm notes)
PDF
Blockchain for Auditors
PDF
Technology Issues and Cybersecurity Strategies
PDF
The Machine Learning Audit
PPTX
Risk View - InfoSec intro
PDF
( Big ) Data Management - Data Quality - Global concepts in 5 slides
PPTX
Data Mining
PPT
Data Quality Testing Generic (http://www.geektester.blogspot.com/)
Michael Patterson Combinatorial Resume
Building a Data Quality Program from Scratch
3 Reasons Why Manufacturing Companies are Moving to Dynamics 365FO
Enterprise Threat Management
Information Security Risk Management
comesa cybersecurity
Data Quality Integration (ETL) Open Source
BBOX Business Risk
Big Data Analytics
Cyber Security 2016 Cade Zvavanjanja1
CHIME Lead Forum - Seattle 2015
CHIME Lead Forum - Seattle 2015
Advantage ppt data breaches km approved - final (djm notes)
Blockchain for Auditors
Technology Issues and Cybersecurity Strategies
The Machine Learning Audit
Risk View - InfoSec intro
( Big ) Data Management - Data Quality - Global concepts in 5 slides
Data Mining
Data Quality Testing Generic (http://www.geektester.blogspot.com/)
Ad

Similar to Strategic Enterprise Risk and Data Architecture (20)

PPTX
Implementing bcbs 239 rdarr
PDF
DCAM_Overview.pdf_______________________
PDF
¿En qué se parece el Gobierno del Dato a un parque de atracciones?
PDF
Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...
PDF
Bridging Data Gaps with a Solid Data Foundation - A Key Imperative for Today’...
PPTX
Data Governance
PDF
KASHTECH AND DENODO: ROI and Economic Value of Data Virtualization
PDF
ARKM-Presentation-Risk-Summit-London-Sept2014.pdf
PPT
PCI DSS Compliance and Security: Harmony or Discord?
PPTX
Risk Product.pptx
PPTX
PPT 1.1.4.pptx_PPT 1.1.4.pptx_PPT 1.1.4.pptx
PPTX
PPT 1.1.4.pptx_PPT 1.1.4.pptx_PPT 1.1.4.pptx
PDF
Maclear’s IT GRC Tools – Key Issues and Trends
PPTX
Aicpa tech+panel presentation t6 managing risks and security 2014 v3
PDF
(CISOPlatform Summit & SACON 2024) Cyber Insurance & Risk Quantification.pdf
PPTX
Presentation1 (1).pptx
PDF
A Successful Data Strategy for Insurers in Volatile Times (ASEAN)
PPTX
Mergers Acquisitions and Tech Due Diligence
PDF
A Successful Data Strategy for Insurers in Volatile Times (EMEA)
PDF
DoD Data Quality Challenges
Implementing bcbs 239 rdarr
DCAM_Overview.pdf_______________________
¿En qué se parece el Gobierno del Dato a un parque de atracciones?
Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...
Bridging Data Gaps with a Solid Data Foundation - A Key Imperative for Today’...
Data Governance
KASHTECH AND DENODO: ROI and Economic Value of Data Virtualization
ARKM-Presentation-Risk-Summit-London-Sept2014.pdf
PCI DSS Compliance and Security: Harmony or Discord?
Risk Product.pptx
PPT 1.1.4.pptx_PPT 1.1.4.pptx_PPT 1.1.4.pptx
PPT 1.1.4.pptx_PPT 1.1.4.pptx_PPT 1.1.4.pptx
Maclear’s IT GRC Tools – Key Issues and Trends
Aicpa tech+panel presentation t6 managing risks and security 2014 v3
(CISOPlatform Summit & SACON 2024) Cyber Insurance & Risk Quantification.pdf
Presentation1 (1).pptx
A Successful Data Strategy for Insurers in Volatile Times (ASEAN)
Mergers Acquisitions and Tech Due Diligence
A Successful Data Strategy for Insurers in Volatile Times (EMEA)
DoD Data Quality Challenges
Ad

Recently uploaded (20)

PPTX
TRAINNING, DEVELOPMENT AND APPRAISAL.pptx
PDF
533158074-Saudi-Arabia-Companies-List-Contact.pdf
PDF
Tortilla Mexican Grill 发射点犯得上发射点发生发射点犯得上发生
DOCX
Hand book of Entrepreneurship 4 Chapters.docx
PDF
Engaging Stakeholders in Policy Discussions: A Legal Framework (www.kiu.ac.ug)
PDF
Vinod Bhatt - Most Inspiring Supply Chain Leader in India 2025.pdf
DOCX
80 DE ÔN VÀO 10 NĂM 2023vhkkkjjhhhhjjjj
PDF
THE COMPLETE GUIDE TO BUILDING PASSIVE INCOME ONLINE
PPTX
CTG - Business Update 2Q2025 & 6M2025.pptx
PDF
Robin Fischer: A Visionary Leader Making a Difference in Healthcare, One Day ...
DOCX
Center Enamel A Strategic Partner for the Modernization of Georgia's Chemical...
PPTX
chapter 2 entrepreneurship full lecture ppt
PDF
Immigration Law and Communication: Challenges and Solutions {www.kiu.ac.ug)
PDF
Satish NS: Fostering Innovation and Sustainability: Haier India’s Customer-Ce...
PPTX
IMM marketing mix of four ps give fjcb jjb
DOCX
Emerging Dubai Investment Opportunities in 2025.docx
PDF
Susan Semmelmann: Enriching the Lives of others through her Talents and Bless...
PPTX
Astra-Investor- business Presentation (1).pptx
PDF
Cross-Cultural Leadership Practices in Education (www.kiu.ac.ug)
PDF
Sustainable Digital Finance in Asia_FINAL_22.pdf
TRAINNING, DEVELOPMENT AND APPRAISAL.pptx
533158074-Saudi-Arabia-Companies-List-Contact.pdf
Tortilla Mexican Grill 发射点犯得上发射点发生发射点犯得上发生
Hand book of Entrepreneurship 4 Chapters.docx
Engaging Stakeholders in Policy Discussions: A Legal Framework (www.kiu.ac.ug)
Vinod Bhatt - Most Inspiring Supply Chain Leader in India 2025.pdf
80 DE ÔN VÀO 10 NĂM 2023vhkkkjjhhhhjjjj
THE COMPLETE GUIDE TO BUILDING PASSIVE INCOME ONLINE
CTG - Business Update 2Q2025 & 6M2025.pptx
Robin Fischer: A Visionary Leader Making a Difference in Healthcare, One Day ...
Center Enamel A Strategic Partner for the Modernization of Georgia's Chemical...
chapter 2 entrepreneurship full lecture ppt
Immigration Law and Communication: Challenges and Solutions {www.kiu.ac.ug)
Satish NS: Fostering Innovation and Sustainability: Haier India’s Customer-Ce...
IMM marketing mix of four ps give fjcb jjb
Emerging Dubai Investment Opportunities in 2025.docx
Susan Semmelmann: Enriching the Lives of others through her Talents and Bless...
Astra-Investor- business Presentation (1).pptx
Cross-Cultural Leadership Practices in Education (www.kiu.ac.ug)
Sustainable Digital Finance in Asia_FINAL_22.pdf

Strategic Enterprise Risk and Data Architecture

  • 1. Strategic Enterprise Risk Architecture Sandeep Maira October 19, 2017 Head, Enterprise Risk & Compliance Technology The Bank of New York Mellon
  • 2. 2 Information Classification: General Enterprise Risk Architecture Objectives E2E Architecture for risk (and beyond) including data, processing and reporting Benefits include - • Satisfy regulatory as well as internal risk management objectives. Support CCAR but also internal risk analysis. • Reduce overall costs • Improve enterprise wide data consistency • Leverage advances in Big Data and computing power to provide advanced and predictive analysis
  • 3. 3 Information Classification: General Regulatory Risk Ad-hoc Data Science Control Framework :Data Governance, System Monitoring Classification Model Development Data Sourcing & Staging Model Dev/ Management Aggregation Credit Risk Ops Risk Liquidity Risk Market Risk Model Management Scenario Management CCAR Calculators Model Parameters Reporting/ Analysis DataLake CommonStagingDB Reference Data Collateral Positions Transactions Credit Liquidity Basel Business Process Management: Reviews, Handoffs Target State Logical Architecture – Component View VaR
  • 4. 4 Information Classification: General 3 1 4 5 Architecture Components Design Approach Benefits Challenges Data • Leverage shared position, transaction, collateral and reference data services across risk, finance, treasury • Provides data consistency and traceability. Reduces costs. • Helps satisfy BCBS 239 and SR14-1 • Provides the basis for advanced analysis • Organizational boundaries • Upfront expense Model development • Sandbox for model development purposes • Model registry for model definitions and approval • Scenario registry for regulatory & internal scenarios • Scalable infrastructure for model development • Improve controls and governance • Reduce costs through model re-use • Ownership model between business and technology • Multiple coding languages Calculators • Calculators as services • Consistent results for given inputs • Reusability and cost reduction • Integrating disparate technologies • Retrofitting can be difficult Risk Architecture Design Objectives and Approach
  • 5. 5 Information Classification: General 1 Architecture Components Design Approach Benefits Challenges Aggregations • Configurable aggregations for risk measures • Flexibility to aggregate and drill down at all levels • Deep and accurate datasets Workflow • Integrated workflows for handoffs, approvals and validations • Single inbox for all tasks • Streamline and reduce operational overhead • Improved data validation • Enforce risk policies • Integration of different platforms Reporting • Support static and flexible ad-hoc capabilities • Ability to slice and dice on all major dimensions and support rich visualizations • Threshold capabilities on all required measures • In-depth analysis of all types of risk events • Early and easy identification of outliers • Helps satisfy BCBS 239 and SR 14-1 • Acquiring breadth and depth of data Control • Support data lineage, validations and glossaries • Data reconciliations • Robust exception handling and alerting • Satisfy BCBS 239 and ensure data consistency, accuracy and completeness • Monitor health of production infrastructure • Operational ownership across multiple business lines • Agreement on terms Risk Architecture Design Objectives and Approach
  • 6. 6 Information Classification: General Use Case - CCAR • Acquire data from master data sources into common data staging • Handoffs are validated Models are developed • Model risk management approves models • Scenarios are updated • Models move to production and source data • Results are aggregated • Results are available for reporting • Data quality and system monitoring checks CCAR Process 1 1 2 6 3 4 5 7 8 9 2 3 4 5 6 7 8 9
  • 7. 7 Information Classification: General What is my ‘exposure’ to Greece? What is my credit risk? What is my market risk? What potential exposure will I have with a further worsening? Do I have any compliance issues? What ‘Greek’ counterparties do I have? What is the current exposure and future potential exposure? What collateral do I have? What Greek instruments do I have? What hedges do I have in place? Are there any AML issues? For counterparty ABC with high credit exposure, what instruments do I hold? Do I have any AML concerns ? With further worsening of conditions what might happen? What is my exposure with a 30 percent drop in Greek bonds? More Interesting Q’s……..
  • 8. 8 Information Classification: General Regulatory Risk/Finance/ Treasury/ Compliance Business Intelligence Reporting / Analysis Risk Treasury Finance ‘Big Data’ DB Regulatory • The data lake can provide ‘Business Intelligence’ within and across domains • The ‘Big Data’ DB has very wide depth and breadth of data, for advanced analysis. Data science analytics, including (for example) statistical analysis and machine learning, can be performed in this environment. This DB can also be used for model development. Compliance Target State Logical Architecture – Modeling and Data Science Historical Data
  • 9. 9 Information Classification: General Appendix
  • 10. 10 Information Classification: General Regulatory Risk/Finance/ Treasury/ Compliance Business Intelligence Reporting / Analysis Risk Treasury Finance ‘Big Data’ DB Regulatory Compliance Data Pathway Control Frame Work :Data Governance Tools • Data governance tools including data lineage, glossaries • The ‘Big Data’ environment can also be used for ad-hoc analysis Target State Logical Architecture – Data Lineage