Credit & Risk
By: Tom Hannagan As I'm preparing for traveling to the Baker Hill Solution Summit next week, I thought I would revisit the ideas of risk-based loan pricing. Risk Adjusted Loan Pricing – The Major Parts I have referred to risk-adjusted commercial loan pricing (or the lack of it) in previous posts. At times, I’ve commented on aspects of risk-based pricing and risk-based bank performance measurement, but I haven’t discussed what risk-based pricing is -- in a comprehensive manner. Perhaps, I can begin to do that now, and in my next posts. Risk-based pricing analysis is a product-level microcosm of risk-based bank performance. You begin by looking at the financial implications of a product sale from a cost accounting perspective. This means calculating the revenues associated with a loan, including the interest income and any fee-based income. These revenues need to be spread over the life of the loan, while taking into account the amortization characteristics of the balance (or average usage for a line of credit). To save effort (and in providing good client relationship management), we often download the balance and rate information for existing loans from a bank’s loan accounting system. To “risk-adjust” the interest income, you need to apply a cost of funds that has the same implied market risk characteristics as the loan balance. This is not like the bank’s actual cost of funds for several reasons. Most importantly, there is usually no automatic risk-based matching between the manner in which the bank makes loans and the term characteristics of its deposits and/or borrowing. Once we establish a cost of funds approach that removes interest rate risk from the loan, we subtract the risk-adjusted interest expense from the revenues to arrive at risk-adjusted net interest income, or our risk-adjusted gross margin. We then subtract two types of costs. One cost includes the administrative or overhead expenses associated with the product. Our best practice is to derive an approach to operating expense breakdowns that takes into account all of the bank’s non-interest expenses. This is a “full absorption” method of cost accounting. We want to know the marginal cost of doing business, but if we just apply the marginal cost to all loans, a large portion of real-life expenses won’t be covered by resulting pricing. As a result, the bank’s profits may suffer. We fully understand the argument for marginal cost coverage, but have seen the unfortunate end-result of too many sales -- that use this lower cost factor -- hurt a bank’s bottom line. Administrative cost does not normally require additional risk adjustment, as any risk-based operational expenses and costs of mitigating operation risk are already included in the bank’s general ledger for non-interest expenses. The second expense subtracted from net interest income is credit risk cost. This is not the same as the bank’s provision expense, and is certainly not the same as the loss provision in any one accounting period. The credit risk cost for pricing purposes should be risk adjusted based on both product type (usually loan collateral category) and the bank’s risk rating for the loan in question. This metric will calculate the relative probability of default for the borrower combined with the loss given default for the loan type in question. We usually annualize the expected loss numbers by taking into account a multi-year history and a one- or two-year projection of net loan losses. These losses are broken down by loan type and risk rating based on the bank’s actual distribution of loan balances. The risk costs by risk rating are then created using an up-sloping curve that is similar in shape to an industry default experience curve. This assures a realistic differentiation of losses by risk rating. Many banks have loss curves that are too flat in nature, resulting in little or no price differentiation based on credit quality. This leads to poor risk-based performance metrics and, ultimately, to poor overall financial performance. The loss expense curves are fine-tuned so that over a period of years the total credit risk costs, when applied to the entire portfolio, should cover the average annual expected loss experience of the bank. By subtracting the operating expenses and credit risk loss from risk-adjusted net interest income, we arrive at risk-adjusted pre-tax income. In my next post we’ll expand this discussion further to risk-adjusted net income, capital allocation for unexpected loss and profit ratio considerations.
1. Portfolio Management – You should really focus on this topic in 2009. With many institutions already streamlining the origination process, portfolio management is the logical next step. While the foundation is based in credit quality, portfolio management is not just for the credit side. 2. Review of Data (aka “Getting Behind the Numbers”) – We are not talking about scorecard validation; that’s another subject. This is more general. Traditional commercial lending rarely maintains a sophisticated database on its clients. Even when it does, traditional commercial lending rarely analyzes the data. 3. Lowering Costs of Origination – Always a shoe-in for a goal in any year! But how does an institution make meaningful and marked improvements in reducing its costs of origination? 4. Scorecard Validation – Getting more specific with the review of data. Discuss the basic components of the validation process and what your institution can do to best prepare itself for analyzing the results of a validation. Whether it be an interim validation or a full-sized one, put together the right steps to ensure your institution derives the maximum benefit from its scorecard. 5. Turnaround Times (Response to Client) –Rebuild it. Make the origination process better, stronger and faster. No; we aren’t talking about bionics here -- nor how you can manipulate the metrics to report a faster turnaround time. We are talking about what you can do from a loan applicant perspective to improve turnaround time. 6. Training – Where are all the training programs? Send in all the training programs! Worry, because they are not here. (Replace training programs with clowns and we might have an oldies song.) Can’t find the right people with the right talent in the marketplace? 7. Application Volume/Marketing/Relationship Management – You can design and execute the most efficient origination and portfolio management processes. But, without addressing client and application volume, what good are they? 8. Pricing/Yield on Portfolio – “We compete on service, not price.” We’ve heard this over and over again. In reality, the sales side always resorts to price as the final differentiator. Utilizing standardization and consistency can streamline your process and drive improved yields on your portfolio. 9. Management Metrics – How do I know that I am going in the right direction? Strategize, implement, execute, measure and repeat. Learn how to set your targets to provide meaningful bottom line results. 10. Operational Risk Management – Different from credit risk, operational risk and its management, operational risk management deals with what an institution should do to make sure it is not open to operational risk in the portfolio. Items totally in the control of the institution, if not executed properly, can cause significant loss. What do you think? As the end of April approaches, are these still hot topics in your financial institution?
The debate continues in the banking industry -- Do we push the loan authority to the field or do we centralize it (particularly when we are talking about small business loans)? A common argument for sending the loan authority to the field is the improved turnaround time for the applicant. However reality is that centralized loan authority actually provides a decision time almost two times faster than those of a decentralized nature. The statistics supporting this fact are from the Small Business Benchmark Study created and published by Baker Hill, a Part of Experian, for the past five years. Based upon the 2008 Small Business Benchmark Study, those institutions with assets of $20 billion to $100 billion used only centralized underwriting and provided decisions within 2.5 days on average. In contrast, the next closest category ($2 billion to $20 billion in assets) took 4.4 days. Now, if we only consider the time it takes to make a decision (meaning we have all the information needed), the same disparity exists. The largest banks using solely centralized underwriting took 0.8 days to make a decision, while the next tier ($2 billion to $20 billion) took an average 1.5 days to make a decision. This drop in centralized underwriting usage between these two tiers was simply a 15 percent change. This means that the $20 billion to $100 billion banks had 100% usage of centralized underwriting while the $2 billion to $20 billion dropped only to 85% usage. Eighty-five percent is still a strong usage percentage, but it has a significant impact on turnaround time. The most perplexing issue is that the smaller community banks are consistently telling me that they feel their competitive advantages are that they can respond faster and they know their clients better than bigger, impersonal banks. Based upon the stats, I am not seeing this competitive advantage supported by reality. What is particularly confusing is that the small community banks, that are supposed to be closest to the client, take twice as long overall from application receipt to decision and almost three times as long when you compare them to the $20 billion to $100 billion category (0.8 days) to the $500 million to $2 billion category (2.2 days). As you can see - centralized underwriting works. It is consistent, provides improved customer service, improved throughput, increased efficiency and improved credit quality when compared to the decentralized approach. In future blogs, I will address the credit quality component.
I was recently asked in a comment, "What do we have to do to become compliant?" Great question. There is not a single path to compliance when it comes to Red Flags compliance. Effectively, an institution that has covered accounts under the Rule must implement both a written and operational Identity Theft Prevention Program. The Red Flags Rule requires financial institutions and creditors to establish and maintain a written Program designed to detect, prevent and mitigate identity theft in connection with their covered accounts. The Program is a self-prescribed system of checks and balances that each financial institution and creditor implements to reach compliance with the Red Flags Rule. The goal of the provisions is to drive organizations to put into place a system that identifies patterns, practices and forms of activities that indicate the possible existence of identity theft. The provisions are not designed to steer the market to a “one size fits all” compliance platform. In essence, how businesses choose to meet the requirements will depend on the business size, operational complexity, customer transaction processes and risks associated with each of these characteristics. A compliant Program must contain reasonable policies and procedures to address four mandatory elements: Identifying Red Flags applicable to covered accounts and incorporating them into the Program Detecting and evaluating the Red Flags included in the Program Responding to the Red Flags detected in a manner that is appropriate to the degree of risk they pose and Updating the Program to address changes in the risks to customers, and to the financial institution’s or creditor’s safety and soundness, from identity theft The Red Flags Rule includes 26 illustrative examples of possible Red Flags financial institutions and creditors should consider when implementing a written Program. While implementation of any predetermined number of the 26 Red Flag examples is not mandatory, financial institutions and creditors should consider those that are applicable to their business processes, consumer relationships and levels of risk. The Red Flags Rule requires financial institutions and creditors to focus on identifying Red Flags applicable to their account opening activities, existing account maintenance, and new activity on an account that has been inactive for two years or more. Some mandatory requirements include: Keeping a current, written Identity Theft Prevention Program that contains reasonable policies and procedures to identify, detect and respond to Red Flags, and keeping the Program updated Confirming that the consumer reports requested from consumer reporting agencies are related to the consumer with whom the financial institution or creditor are doing business Reviewing address discrepancies
As we approach the FTC's May 1, 2009 Red Flags Rule enforcement deadline, we are still working with many of our existing and prospective clients to support their Red Flags Identity Theft Prevention Program. In my opinion, the May 1, 2009 extension did much good on two fronts: 1. It brought to light the need for all institutions, particularly in markets outside of traditional financial services arenas, to re-evaluate the expectation of their being 'covered' under the Red Flag guidelines. 2. It allowed 'covered' institutions the opportunity to take additional steps to not only create and operationalize their programs, but to spend time making those programs efficient and in line with business and regulatory objectives. In the spirit of information gathering and sharing, we at Experian are conducting a quick survey to gauge how 'helpful' the May 1, 2009 extension was to your organization. We're also trying to informally keep our finger on the pulse of market readiness, as the enforcement deadline is upon us. Via the link below, please take about 60 seconds to answer a few questions that will help us better understand the current state of the market's Red Flags Rule readiness. Experian Red Flags Survey We certainly appreciate your time.
I encourage all of you to have a look at this newly launched Federal Trade Commission Web site dedicated to the Red Flags Rule guidelines. It is a good resource to that organizes the requirements of the Rule in a user-friendly manner. It also looks to be an ongoing resource for the posting of updates and related commentary. I suggest you make this site one of your bookmarks today: The Federal Trade Commission has launched a Web site to help entities covered by the Red Flags Rule design and implement identity theft prevention programs. The Rule requires “creditors” and “financial institutions” to develop written programs to identify the warning signs of ID theft, spot them when they occur, and take appropriate steps to respond to those warning “red flags.” Of particular interest, is the "Read the Guide" tab, where you can view and download the new FTC guide to Red Flag Rules. For those in the telecommunications and utilities spaces, check out the "Publish the Articles" tab where you will find two bulletins on Red Flags in these arenas. Enjoy.
By: Tom Hannagan Beyond the financial risk management considerations related to a bank’s capital, which would be directly impacted by Troubled Asset Relief Program (TARP) participation, it should be clear that TARP also involves business (or strategic) risk. We have spoken in the past of several major categories of risk: credit risk, market risk, operational risk and business risk. Business risk includes a variety of risks associated with the outcomes from strategic decision making, corporate governance considerations, executive behavior (for better or worse), management succession events (Apple and Steve Jobs, for instance) or other leadership occurrences that may affect the performance and financial viability of the business. Aside from the monetary impact on the bank’s capital position, TARP involves a new capital securities owner being in the mix. And, with a roughly 20 percent infusion of added tier one capital, we are almost always talking about a very large, new owner relative to existing shareholders. The United States Department of the Treasury is the investor or holder of the newly issued preferred stock and warrants. The Treasury Department says it does not seek voting rights, but none-the-less has gotten them in at least some cases. The real “kicker” is embedded in the Treasury’s Securities Purchase Agreement – Standard Form. The most interesting clause, that appears to represent a very open-ended business risk to management decision making, is one relatively small paragraph, named Amendment, in the middle of Article V - Miscellaneous, just ahead of governing law (which is federal law, backed up by the laws of the State of New York). Amendment begins normally enough, requiring the usual signed agreement of each party, but then states: “provided that the Investor may unilaterally amend any provision of this Agreement to the extent required to comply with any changes after the Signing Date in applicable federal statutes.” Wow. My reading of this is that if in the future Congress enacts anything that Treasury finds applicable to any aspect of the previously signed TARP Agreement, the bank is bound to go along. Regardless of whether the Treasury negotiates any voting rights, once the TARP Agreement is executed by the bank, management is not only bound by what is in the document to begin with, it is subject to future federal law as long as the TARP shares are held by the government. As a result, many banks have said no thank you to TARP. At least four banks have recently paid back $340 million to repurchase the government’s shares. And, apparently another bank has offered to pay back $1 billion but, according to Andrew Napolitano at Fox Business Channel, the offer was turned down and the bank was threatened with adverse consequences if it persisted in its attempt to get out. More pointed and public, and much larger in size, is the dance taking place now between Chrysler Corporation, Fiat, the UAW, four lead lenders and, you guessed it, the federal government. The secured loans in question total almost $7 billion and the government wants J.P. Morgan Chase, Goldman Sachs, Citicorp and Morgan Stanley to exchange $5 billion of the loans for Chrysler stock. The banks know they would do better (for their shareholders) by selling off Chryslers assets. This is an example of why bankruptcy exists. The stakes are large and so is the business risk of the influence from the government. It will be interesting to see how things turn out. So, this new major owner does have a voice. If Congress wants certain lending volumes or terms, or they want certain compensation levels, it needs to be enacted into federal law. Short of having to pass a law, there is the implied threat of the big stick in the TARP agreement. The Purchase Agreement covers what the new owner wants now and may decide it wants in the future. This a form of strategic business risk that comes with accepting the capital infusion from this particular source.
This post continues the feature from my colleague and guest blogger, Mark Sofietti, Associate Process Architect in Advisory Services at Baker Hill, a part of Experian. In today’s market, the banking industry seems to be changing at a very rapid pace. The current crisis that we are in, as an industry and as a nation, is forcing institutions to revisit risk management policies and procedures to make the appropriate changes needed to remain healthy and profitable. However, the current crisis is not the only reason why institutions should focus on change management. Change management needs to be appropriately handled in bad and good times. Understanding change management is always a necessity to a well-run organization. Whether it is a reorganization, a new software system, a new policy or moving to a new building, change can cause a great deal of stress and uncertainty -- but it can also cause benefits. So, as managers, you may be asking, “What can I do to ensure that positive changes are happening within my organization? What are some of the items that I should consider when I am bringing about organizational change?” There are four necessary steps that need to be taken in order to improve the success of an initiative that is causing change to an institution. I covered two in my last post. Here are the additional steps. 3. Consider methods of change One method of change is the education of individuals about new ways of operating. This method should be used when there is more resistance to change and when individuals lack a clear understanding or knowledge of the change being made. Education may cause the implementation to take longer, but those involved will better understand the effects of the change. A second method is gathering participation from different levels and skill sets within the organizations. Building a team should be used when there is the highest risk of failure due to change resistance and when more information needs to be gathered before an effective implementation can be completed. Negotiation is a method that is used when a group or person is going to be negatively affected by the change. This method could alleviate the discomfort by giving the person or group some other benefit. Negotiations could allow an organization to avoid resistance, but it may be very costly and time consuming to implement the change. The coercion change method is when a change is implemented with little room for diversion from the plan. Employees are told what the change is going to be and they have to accept it. This method should be used when speed is of the utmost importance, or if the change is not going to be easily accepted. Most employees do not like this approach and it may cause resentment or it might cause staff members to leave. The final method of change uses manipulation, the conscious decision to share limited information about the change that is taking place. This method should only be used when no other tactic will work, or if time or cost is major issues. This approach is dangerous because it can lead to more problems in the future. 4. Create plan of action A plan should be created for the implementation of change to clearly address reservations and define the change strategy. It should include internal and external audiences who can be affected by the change. It is common to forget those who are indirectly impacted by the change -- and these audiences (customers, for example) may be the most important. Objectives of the change need to be clearly outlined in the plan in order to understand how the new future state of the organization will look and operate. The plan needs to be communicated to all those involved so that the transition can be understood and everyone can be held accountable. The plan should be periodically revisited after implementation in order to review progress. Creating a plan of action is a very important step to ensure that those who resisted the change do not revert back to their old habits. Achieving change is not an easy process, especially when time is not on your side. If you take a second look at the change that you are trying to implement and do the necessary planning, you have a greater chance for success than if you or your organization fails to fully evaluate the consequences. Effective change management should be part of any financial risk management process. Take charge of your institution’s future through a calculated approach to change management and your organization will be in a better position for the next change that is coming around the bend.
Regardless of the specific checks and overall processes incorporated into your Red Flags Identity Theft Prevention Program, the use of an automated decisioning strategy or strategies will allow you to: Deliver consistent responses based on objective authentication results, while eliminating subjectivity often found in more manual review processes. Save time and money associated with a manual review process currently attributed to Red Flag Rule referrals. Provide examiners a detailed process flow including decision elements. Create champion / challenger flows to test, compare and alter new strategies over time. Revise, over time, the specific elements used in your decisioning to appropriately weight each from a fraud detection and/or compliance perspective. Experian's consumer authentication products provide hosted decisioning strategies that alleviate the burden on our clients associated with maintenance and development of those processes. Whether you facilitate your own strategies or use a service provider's hosted strategies, it is important to ensure you are maximizing their ability to balance pass rates, fraud detection and compliance requirements.
We have talked about: the creation of the vision for our loan portfolios (current state versus future state) – e.g. the strategy for moving our current portfolio to the future vision. Now comes the time for execution of that strategy. In changing portfolio composition and improving credit quality, the discipline of credit must be strong (this includes in the arenas of commercial loan origination, loan portfolio monitoring, and credit risk modeling of course). Consistency, especially, in the application of policy is key. Early on in the change/execution process there will be strong pressure to revert back to the old ways and stay in a familiar comfort zone. Credit criteria/underwriting guidelines will have indeed changed in the strategy execution. In the coming blogs we will be discussing: assessment of the current state in your loan portfolio; development of the specific strategy to effect change in the portfolio from a credit quality perspective and composition; business development efforts to affect change in the portfolio composition; and policy changes to support the strategy/vision.
If the business is a creditor or a “financial institution” (defined as a depository institution) that offers covered accounts, you must develop a Program to detect possible identity theft in the accounts and respond appropriately. The federal banking agencies, the NCUA and the FTC have issued Guidelines to help covered entities identify, detect and respond to indicators of possible identity theft, as well as to administer the Program. A copy of the Red Flag Guidelines can be found: Federal Reserve Board – 12 C.F.R. pt 222, App. J Federal Deposit Insurance Corporation – 12 C.F.R. pt 334, App. J FTC – 16 C.F.R. pt 681, App. A NCUA – 12 C.F.R. pt 717, App. J Office of the Comptroller of the Currency - 12 C.F.R. pt 41, App. J Office of Thrift Supervision - 12 C.F.R. pt 571, App. J
The credit reporting agencies will not identify Red Flags, as such, on a credit report. However, there may be certain information on a credit report that you have determined to be an indicator of possible identity theft and have incorporated into your Program, such as a consumer fraud alert or a notice of address discrepancy. In addition, the Red Flag Guidelines specify that a credit report indicating a pattern of inconsistent or unusual recent activity might be a Red Flag.
By: Tom Hannagan Part 6 Peer Group 2 fee income Non-interest income again, as a percent of average total assets, declined to .86 percent from .95 percent in 2007. For Peer Group 2 (PG2), fees have also been steadily declining relative to asset size, down from 1.04 percent of assets in 2005. A smaller, non-interest bearing deposit base with no other new and offsetting sources of fee income will lead to increased pressure on this metric. Operating expenses Operating expenses also put more pressure on earnings on these smaller banks. They increased from 2.79 percent to 2.83 percent of average assets. That’s four basis points on the negative. Historically, this metric has been flattering for this size bank and usually moves up or down from year-to-year. It was almost equal at 2.82 percent of assets in 2004. As a result of the sizeable decline in margins, the continued decline in fee income and the slight increase in operating expenses PG2’s efficiency ratio lost ground from 59.52 percent in 2007 to only 64.72 percent in 2008. That means that every dollar in gross revenue cost them almost 65 cents in administrative expenses this year. This metric averaged 56 cents in 2005/2006. It’s amazing how close these numbers are for banks of very different size where you would expect clear economies of scale. The total impact of margin performance, fee income and operating expenses, plus the huge increase in provision expense of 59 basis points leads us to a total decline in pre-tax operating income of .96 percent on total assets. That is a total decline from 1.58 percent pre-tax ROA in 2007 to .64 percent pre-tax ROA, a loss of 61 percent from the pre-tax performance in 2007. My same conclusion as above would hold regarding the pricing of risk into bank lending (although the smaller banks didn’t perform a badly as the larger in this regard). Although all 490 banks are declining in all profit metrics, the smaller banks seem to have an edge in pricing loans, but not deposits. Although up dramatically in 2007, and even more in 2008 for both groups, the PG2 banks seem to be suffering fewer credit losses relative to their asset size than their larger brethren. Both groups have resulting huge profit declines, but the largest banks are under the most pressure through this period. An interesting point, with higher loan yields and fewer apparent losses, is whether PG2 banks are somewhat better at risk-based pricing (for whatever reason) than the largest bank group. Results are results. The 2009 numbers aren’t expected to show a lot of improvement as the general economy continues to slow and credit and financial risk management issues continue. We’ll probably comment on 2009 as the quarterlies become available this year.
For all you folks who, like me, waited until the last minute to knock out a term paper or class project in school, here is a friendly reminder…Yes, the Federal Trade Commission (FTC) pushed out the enforcement deadline of the Red Flags Rule to May 1, 2009. Yes, a sigh of relief was heard across compliance officers and operations managers nationwide. However, you should still keep a few things in mind as we approach May 1. First, per the FTC, "many entities also noted that because they generally are not required to comply with FTC rules in other contexts, they had not followed or even been aware of the rulemaking, and therefore learned of the requirements of the rule too late to be able to come into compliance by November 1, 2008." Those of you, who have not been subject to FTC enforcement in the past are quite possibly still subject to the Red Flags Rule based on your institution maintaining 'covered accounts' per the definition in the Red Flags Rule itself. Double check if you think otherwise. Second, the FTC was clear in stating that "this delay in enforcement is limited to the Identity Theft Red Flags Rule (16 CFR 681.2), and does not extend to the rule regarding address discrepancies applicable to users of consumer reports (16 CFR 681.1), or to the rule regarding changes of address applicable to card issuers (16 CFR 681.3)." So, while May 1 is still a few weeks away, if you are accessing consumer credit reports, for example, you should already have a formal written and operational process to detect and respond to address discrepancies on those credit reports.
Red Flags Rule I've heard more than one institution claim that they may limit and even reduce the identity elements (perhaps down to just name and address) that are captured during consumer applications or other transactions. Their rationale is that the fewer identity elements they request or require during these processes, the less information they will need to authenticate as part of their Red Flags Identity Theft Prevention Program. While this argument seems logical on the surface, I would suggest that if securely gathered/stored and appropriate to the nature of your business, additional data elements such as Social Security Number (SSN), date of birth and phone number can actually allow you to accomplish a few things to your benefit. 1. Analysis of our consumer authentication products shows that contributing SSN, date of birth, and phone (in addition to name and address) to an authentication process, will actually improve your ability to positively authenticate a consumer via an overall risk-based strategy. 2. The use of additional data elements, such as the phone number, can unlock additional data sources for use in verifying not only that phone number, but the inquiry name and address as well. 3. Just because you don't capture certain identity elements, doesn't mean the risk goes away. In providing additional identity elements for authentication, you can gain a more holistic view of a consumer - be that good, bad or ugly. It’s better to figure this out up front versus down the road when bills go unpaid and the bad guys scatter.