A daily dose of odds and sods, some interesting, some bizarre, some funny, some thought provoking items which I have stumbled across the web. All to be taken with a grain of daily salt!!
Monday, February 25
A million messages per second
Broader institutional participation, increased volatility, advancements in technology, remote market making, and regulatory changes are driving options quote volumes to higher and higher peaks. The six options exchanges in the U.S send their quote data to the Options Price Reporting Authority, which merges it into one feed and pushes it out to the market. During periods of heavy market activity, Opra sends out as many as 300,000 messages per second, far above what was seen just a few years ago.
To stay ahead of the curve, Opra has repeatedly advised the industry to boost its capacity to receive these market data messages. At the beginning of 2007, the required capacity level set by Opra was 359,000 messages per second. At the beginning of 2008, Opra had increased that level to 701,000 messages per second, and it is targeting 907,000 by the middle of 2008.
If you are interested in risk management (market, credit, operational and legal as well), do sign up to this site, very useful indeed.
All this to be taken with a grain of piquant salt!!!
Thursday, December 6
Scaling a flue epidemic
I talked earlier about how financial institutions would react to a flu or terrorist outbreak on say the communications networks. But you might very well wonder what is the probability of such a thing happening? Well, here's one opinion.
Read and Worry
THE Government's chief spook and threat watcher has warned that a repeat of the 1918 Spanish flu pandemic, which killed up to 100 million people, was "real". Head of the Office of National Assessments Peter Varghese said changes in the flu virus, and in the human and animal populations it could effect, raised the threat of a fresh outbreak.
"The economic, social, political and security impacts would be very large,"Mr Varghese said. The 1918 pandemic claimed up to 20 per cent of people infected by the virus and about half those were aged between 20 and 40 years.
The ONA boss told a security in government conference in Canberra yesterday that the list of issues affecting the nation's security until 2025 was "long and will keep growing". He played down the threat from climate change in the pre-2025 period, but said resource security, including oil supplies, water scarcity and fish stocks, would be massive preoccupations of governments.
"This will heighten tension among major and emerging powers, but shouldn't by itself cause war," he said. And he predicted that Australian forces would be in Afghanistan for at least 10 more years. Meanwhile ASIO boss Paul O'Sullivan used his speech to warn that "non-state actors" such as al-Qaeda would continue to be a major threat.
He said that since 9/11 al-Qaeda had created new connections between its hard core frontier militants and urban radicals throughout the world. "The existence of intricate, dynamic networks linking frontier militants . .. and small groups of urban radicals . . . has globalised insecurity in a new way," Mr O'Sullivan said.
He said al-Qaeda and the global jihad Islamic extremist movement in general had shown that it was possible for networked extremists to operate simultaneously across the globe from war-torn nations to western capital cities.
"If this situation continues the future we face will be one where significant national security threats coexist with . . . relative stability and order." The ONA boss predicted terrorism would remain a destabilising force for at least a generation and Islamic extremism would be a threat in our region for a decade.
ONA was set up in 1977 to provide the prime minister of the day and his national security ministers with independent assessments of global threats. In just his second public speech in 18 months, Mr Varghese highlighted the emergence of China and India as key strategic and military drivers for the next 20 years.
Monday, December 3
Terrorism / Influenza - impact on networks
But I have some comments: network congestion might well happen, but looking at what happened in 9/11, the level of trading falls off dramatically as people look to close out their books and do not take any further customer orders. They might also just go back to relying on their capital and take any pending orders on the firm's books rather than risk taking it to market and find that its lost in the ether or worse, the price formation process has had some eddies and the prices is stuffed.
So the situation is not that much of an issue, but what might be required to think about is the capability of the firm's capital to handle what amount of trading? Also, if that is the case, then the sales trader will be pushing trades away and will need better voice rather than data connectivity, while on the other hand, the market facing trader might as well as take the trades on his own book.
Still read and consider!
Nothing but Net?
For years, the financial services industry has led the way when it comes to business continuity, participating in a number of industry-wide tests. The most recent US test, conducted by the Financial and Banking Information Infrastructure Committee (FBIIC) and the Financial Services Sector Coordinating Council (FSSCC), simulated a global H5N1 influenza pandemic. By Rob Daly
The sponsors are still poring over about 300,000 data points gathered during the three-week test, but the early results are interesting.
The good news is that Wall Street can withstand a pandemic. The industry's performance was unfazed by an absenteeism rate of 25 percent and only saw performance degradation when the absenteeism rate approached 49 percent-a higher rate than estimates by the World Health Organization (WHO) and the US Centers for Disease Control and Prevention.
Most participating firms, 54.5 percent, tackled their business and regulatory obligations by setting up their employees with telecommuting capabilities. The next most popular response, 40.8 percent, was dividing business groups into a number of units and dispersing them geographically.
An interesting aspect of the test was the amount of stress a pandemic would have on other critical infrastructure, such as the Internet. During one portion of the test, residential Internet throughput was reduced by half due to network congestion, which reduced the real-time performance of market data feeds by several minutes and caused intermittent outages of non-real-time applications, such as e-mail.
This level of network performance doesn't bode well for traders. Operating their bandwidth-hungry trading and market data applications over a residential Internet connection would be like sucking a beach ball through a garden hose. Traders would need to come into the office to take advantage of their firms' financial extranets to get low-latency market data.
However, two types of traders could make the work-from-home strategy work: those who operate in the over-the-counter world and rely solely on voice brokerage, where latency isn't as critical as in electronic execution; and algo-based traders, whose systems are co-located within the market centers.
Since their low-latency connection would be a local network hop or less away from the market, their traffic wouldn't compete with other network traffic from the outside world. It would also mean that algo traders would have to turn over more control to the local servers and keep trader-to-algorithm communication to a minimum.
Local fat-client applications would work the best in this environment compared to applications incorporating service-based architecture or relying on Citrix connections that depend on network availability. But how many firms have taken reduced bandwidth availability into consideration in their business continuity plans?
Of course, overcoming the network latency issue is just one hurdle to trading from home. Firms need approval from the proper regulatory bodies and must be willing to pay the additional licensing fees to application and market data providers to set up the necessary remote trading positions.
To keep trading desks up and running, working from home just doesn't seem to be a practical solution. Instead, firms should plan to keep their traders close and be prepared to feed and lodge them for extended periods.
All this to be taken with a grain of piquant salt!!!
Monday, October 29
The Most Expensive IT Mistake in Financial Markets?
This seems to be an apocryphal story. 20% of the world's equity trades? The closest firm that comes to that % can only be Merrill's and they do not have a system like this. So no, I think this is being stretched a bit too far.
Plus, a hot DR system? Errr, surely you are joking! Adding/Replacing a disk on the main production system? Nope, cannot believe it. And why would it impact the Euro? Very confusing and doesn't make sense at all.
Wednesday, October 24
Do big banks need more capital?
See this article from Risk Centre. I quote:
With all due respect to the Nout Wellink and the other members of the BCBS, we do not believe that the implementation of the Basel II proposal or anything that looks remotely like it would have alleviated the ongoing collapse of the market for complex structured assets. When an entire asset class literally dies in a matter of weeks, the risk is infinite. To us, measuring the liquidity or market risk of a Structured Investment Vehicle ("SIV"), with or without the Basel II framework, makes about as much sense as using statistics to predict corporate credit defaults.
Remember too that most of Basel II is based upon the very quantitative models and rating agency methods which caused the subprime crisis, thus offers of assistance from Basel II's creators within the BCBS should be viewed with caution. Basel II merely mimics the business processes of the Sell Side investment houses, systems which are intended first to enable new financial transactions and, as a secondary matter, manage the risk.
Without going into too much detail, I agree with the above sentiments. You see, I have a slightly different perspective on this. Based upon my previous research on extreme events, I am firmly of the belief that the relationships between various factors in these extreme events becomes dramatically non-linear in nature.
So a structure such as Basel II which relies on linear modeling to provide an indication of risk capital is ok for stable, linearly correlated markets but fails miserably when it moves into the fat tails. If you just look at the investment banks, they are taking billions of dollars in losses. My question, if you still are quibbling about it, why did the risk management models not pick up this problem?
Now the fact that the risk management models did not pick up the sub-prime mess leads me to wonder whether it makes sense to provide estimates of capital adequacy based upon these very same risk management models? No Sir.
The answer is that the banks need MORE capital, not less capital. More capital has the downside of implied opportunity cost, less capital has the downside of shaking the entire financial system through systemic risk. If I was a central banker, I would take a hard close look at Basel II.
Monday, October 8
Ignore Risk Management at your peril, your entire bank might be at risk
How many times have we seen this? Risk management underinvestment and then traders take wrong posititions or mis vale or mark to model or something like that and then it blows up, usually bringing down the very management who did not pay money or attention to their risk management systems.
After thinking about it for 2 seconds, I came up with some questions arise which I would ask to the CEO
1. Who does the chief risk officer report to? If the CEO with NO dotted lines, then fine. If there are any dotted lines or matrix management, then there is a disaster waiting to happen. This is applicable to market, credit, ops, liquidity risk
2. Are each division's capital allocated based upon risk?
3. Do you match the divisional RoE with their P &L? On a monthly basis?
4. How do you base your bonus pool allocations? On revenue or adjusted risk levels?
5. Who develops your risk scenario's? How often do you do war gaming? Do your head of trading attend? What is your definition of comfort values?
6. Why are you not making your divisional risk and RoE transparent?
7. What is your investment in IT? What is the ratio of risk investments to trading investments? If less than 20 percent, why?
8. When was the last time you had an independent risk and trading systems audit? And seen the results? And acted upon them? And reviewed them? And fired somebody for not following them?
9. Where does product control fit it? Do they report to trading or risk heads?
10. Who is looking after your model risk? Do you know the stress scenario results? Under what circumstances do they fail? Negative interest rates? Liquidity risk? Spreads very wide? Exchange stops trading? A dr death scenario?
But I am afraid this will happen again and again and again, people just do not listen and short term profits will again overwhelm the risk manager's warnings. And then the bank will again drop into the muck!
All this to be taken with a grain of piquant salt!!!
Friday, September 21
I hate spreadsheets
I hate spreadsheets because I think they are reaching the tipping point where they create bigger problems than they solve. And intelligence is no guarantee that you will not make whoppers. In the dim and distant past, I audited about 200 spreadsheets used by traders on the fixed income department of one of the leading investment banks of the world.
These spreadsheets were very complex ones, being used to price structured products which have loads of credit, fixed income, derivatives, long complicated power structures, etc. etc. And I did not find a single spreadsheet which was error free. Some had date issues, some had data issues, presentation issues, logical problems, etc. etc.
Why is this? this is because spreadsheets are too easy to use and give you AN ANSWER. And the tendency of a human being is to believe the damn thing shown on the screen. The same reason we tend to believe stuff on the Internet. Or why I still get crappy forwards of some poor bugger who is facing imminent destruction if I do not forward the email to 20 million other buggers!.
Also, because of the way spreadsheets are constructed, they lend themselves to silly problems, something which you wouldn't see in a proper program or computer system. This is why I firmly believe that if a spreadsheet is to be used for more than 3 cycles (deals, reports, months, whatever) we need to convert that into an application. And believe you me, you will find that it is cost effective once you put in the problems of updating it, losing it, documenting it, losing the chap who made it, etc. etc.
Incidentally, I was sent this link to a spreadsheet engineering research project at the Tuck Business School in Darthmouth, USA. Quite an interesting project. In particular, read this document which lays out a survey of people on awareness, risk and control aspects of spreadsheets.
Tuesday, September 4
Company Boards lack understanding of IT risks
All this leads to a situation where the senior management and boards do not understand what technology is doing to their business, what risks they face, what can they do and what questions to ask. This is the reason why boards are very rarely able to manage reputational risk arising from technology led operational risk. Such as loss of customer data, downtime of customer service technology (such as POS terminals, ATM machines, etc.). very difficult to manage.
I would think a solution would be to have the CIO brief the board regularly along with the CEO if the firm has a large technology component.
I quote from the report
It found that in three-quarters organisations, IT-related risk, in particular the potential for complex projects to fail, has risen higher up the board agenda. Indeed almost nine out of 10 senior management respondents said that it is a major challenge to respond to the pace of change in IT.
The survey also highlights a lack of mutual understanding between the board and IT professionals over how to assess risk. Over a third of senior management respondents and almost half of internal audit heads feel that IT professionals lack the ability to communicate IT risk and its potential business impact in a way that the board understands.
"Assessing risk is a team game," he said. "Boards, in particular most non-executive directors, simply don't have inherent practical experience of IT risk, as one of our internal audit heads reminds us, and this means they are unlikely to understand the full extent of the risks and opportunities that technology presents to their companies."
All this to be taken with a grain of piquant salt!!!
Thursday, August 2
Ten Things Your IT Department Won't Tell You - WSJ.com
1. HOW TO SEND GIANT FILES
2. HOW TO USE SOFTWARE THAT YOUR COMPANY WON'T LET YOU DOWNLOAD
3. HOW TO VISIT THE WEB SITES YOUR COMPANY BLOCKS
4. HOW TO CLEAR YOUR TRACKS ON YOUR WORK LAPTOP
5. HOW TO SEARCH FOR YOUR WORK DOCUMENTS FROM HOME
6. HOW TO STORE WORK FILES ONLINE
7. HOW TO KEEP YOUR PRIVACY WHEN USING WEB EMAIL
8. HOW TO ACCESS YOUR WORK EMAIL REMOTELY WHEN YOUR COMPANY WON'T SPRING FOR A BLACKBERRY
9. HOW TO ACCESS YOUR PERSONAL EMAIL ON YOUR BLACKBERRY
10. HOW TO LOOK LIKE YOU'RE WORKING
This blog has talked about facebook in the past and has referenced JP Rangaswami's excellent series of articles on this subject. But this is a serious issue because organisations expend a huge amount of energy, resources and money on how to get controls in place. You see, in this day and age, we are having more and more processes which are automated. Supply chains are giant, long, complicated and very often do not have any human intervention. So breaks in the chain are extremely difficult to resolve, so IT and operations departments try to keep things as safe as possible.
Take an example of an operating theater. The human body is complicated and they keep the doors sealed, with no dust or infection coming in. They ask doctors to wash and clean their hands and wear masks. Now a doctor might skip the wash and might not shampoo, so in some cases, the controls do not work and the downside is, the patient gets sick and in some worst cases, the patient dies!. its the same concept, nobody dies, but there is a huge amount of issue and IT controls are to provide a nice, clean, low risk environment for everybody to work in. Operational Risk CAN bring down firms (remember Barings?) so for people circumventing controls (whetehr IT, operational or process), be warned, the controls are there for a reason. See here for a survey on Rogue IT.