Author Interview: Kannan Subramanian R
Book Title: Risk Adjusted Operational Performance
From the Editor: Welcome to the latest in our series of interviews with leading authors of books in Architecture and related disciplines.
In this edition, we speak to Kannan Subramanian R about his new book, Risk Adjusted Operational Performance. We hope you enjoy reading this interview.
EAPJ: Can you tell our readers a little bit about yourself and your professional history?
Kannan: I am a Chartered Accountant (CA) with about 35 years of experience indesigning and implementing banking systems. I focus on risk management systems. During my CA apprenticeship, I also completed a course in system design and programming. I have successfully leveraged my banking, auditing and technology skills to deliver value for my customers. I worked for Standard Chartered Bank and have been with leading banking solution vendors. I am presently with Prospero Systems Switzerland, a leading advanced analytical solutions provider.
I interact with Banking Industry Architecture Network, BIAN. They offer enterprise architects a wide range of ready-made building blocks to ensure business agility based on loose coupling, reusability, interoperability, simplicity, and transparency. My approach is aligned with internationally accepted frameworks and standards.
https://bian.org/event-driven-architecture/
EAPJ: What inspired you to write Risk Adjusted Operational Performance, and why did you feel this was the right time to publish it?
Kannan: I specialise in process improvement, process re-engineering and process automation. I have been contributing to the global banking industry by introducing process-based methodologies for improving banking operations. Although services-oriented architecture (SOA) / Micro-SOA, is not a prerequisite for process automation, evidence suggests the two approaches are complementary. I realised that banks lack an accurate method to measure and manage operational efficiency and operating effectiveness. Efficiency scoring includes measuring resource utilisation and effectiveness taking into account the bank’s competitive score. I am a data-driven person. I assessed the data available in banks that use process automation and formulated a scoring methodology for measuring risk adjusted operating efficiency and effectiveness. It is a ground-breaking concept that uses both operational data (data from logs) and book-keeping data. I applied for a patent in the USA for systems & methods to compute risk adjusted operational performance measures. Systems: Event driven, Data centric, Services based loosely coupled, interoperable Enterprise architecture, Zero Trust Architecture, Cloud & Virtualisation, AI driven intelligent process orchestration;
Methods: Bill of Resources, Process based enterprise operating model with the Treasury as the hub, Three Lines of Defence, Time Driven activity-based costing, Enterprise risk adjusted return model and Risk adjusted Operational Performance management at the process level.
The link provides the details: https://www.raop.org/Welcome/patent Soon thereafter, I started to write this book on the subject to cover the topic comprehensively.
EAPJ: Who is the primary audience for this book, and what value will different stakeholders, such as CROs, CTOs, and regulators, gain from it?
Kannan: Government-Finance Ministry, Banking Supervisors, Banks and Finance Companies. Within a bank: the Risk Committees, Audit Committee, Chief Data Officer and Chief Technology Officer. Within the banking & finance ecosystem: Banking Consultants, Auditors and Risk Management Consultants.
EAPJ: The book argues that commonly used metrics like cost-to-income ratios are insufficient. What are their key limitations, and what is missing from current industry approaches?
Kannan: The cost to income ratio does not provide an insight into:
- the implications of a high fixed cost base (operating cost structure)
- activity and process cost
- process efficiency
- operational resilience
- operational support for market, credit and liquidity risk management
- enterprise operating model efficiency
- resource utilisation and
- competitive position and operating model effectiveness.
The calculation of the cost to income ratio is non-standard. Some banks make adjustments for loan provisions and write offs. The cost to income ratio, mistakenly referred to ‘efficiency ratio’, is not risk-adjusted.
A small number of banks report operating leverage. The underlying calculation uses the same financial variables (bookkeeping data items) that go into the calculation of the cost to income ratio. Operating leverage is calculated as the year-over-year percentage change of growth in revenue vis-à-vis Growth in operating cost.
Silicon Valley Bank’s Cost to Income ratio
| Q4 2022 | Q4 2021 | FY 2022 | FY 2021 |
| 34.11% | 32.31% | 31.98% | 35.16% |
| Based on the ratio above, many stakeholders would have believed that the bank was efficient. | |||
Even Credit Suisse’s Cost to Income ratio was not alarming prior to its collapse. My five-risk adjusted operational performance measures are fit for purpose. Operational Resilience is a subset of Enterprise Resilience.
Moody’s Deutsche Bank AG: Update to Credit Analysis 13 November 2024, Report Number 1427078:
The swift rundown in the bank’s operating cost base, as transformation plan generated around €3 billion of run-rate savings from yearend 2018 until the end of 2022, helped restore DB’s operating leverage, making it more resilient to setbacks in its revenue performance.
This was a major leap forward from DB’s previous restructurings, in which it suffered greater revenue attrition and did not generate any additional operating leverage.
| Deutsche | E 2025 | 2024 | 2023 |
| Cost to Income Ratio | The new target, a 14.5% improvement, highlights the limitations of using the cost-to-income ratio. The operational efficiency and effectiveness are still unclear – refer to Financial Times March 2025 report. | 76% | 75% |
Figure 1 Deutsche Bank – Adapted Moody’s data

- It fluctuates from a Negative of -8% in Q3 2019 to a positive of 19%. In Q3 2022;from 19% in Q3 2022 to drops to 0% Q2 2024;
- Comparing positive operating leverage: the 5% in Q4 2019, is followed by 9 quarters until Q4 2024, where the operating leverage is below 5% i.e. Q3 2021, Q42021, Q1 2022, Q1 2023, Q3 2023, Q4 2023, Q2 2024, Q3 2024, Q4 2024.
| This raises several questions on the bank’s operational efficiency, operating effectiveness, operational resilience, residual risk and operating cost management. |
EAPJ: You introduce several new measures such as risk adjusted process efficiency and Risk Adjusted Operating Leverage (RAOL). Could you explain these concepts in simple terms and how they differ from traditional metrics?
Kannan: Risk adjusted operational performance evaluation is based on (i)process fulfilment, operational resilience, (ii)risk, control and residual risk and (iii) operating costs. It is a bottom-up approach. Risk Adjusted Process Efficiency is the foundation layer. At the management level is the fifth measure, risk adjusted operating leverage.
My approach makes a distinction between profits and profitability, cost control and cost reduction, maturity and optimisation.
(1) Risk adjusted process efficiency
The risk adjusted process efficiency evaluations has four variables (i)Performance Fulfilment (ii) Risk & (iii) Control and (iv)operating cost and three measures, i)fulfilment, ii) residual risk and iii) operating cost.
Fulfilment includes the resilience aspect. Operational Readiness is regulatory requirement in some countries. This is influenced by the quality of the enterprise operating model i.e. architecture, data, technology. The evaluation is done on basis of:
Time taken for successful execution – this is linked to technology, staff skills. Time and Quality of output influences customer experience;
Business Disruption (process disrupted) – this is linked to architecture, technology – resilience and security;
Internal data: Customer support or Bank’s survey.
Residual Risk The seven types: Internal Fraud, External Fraud, Damage to asset, staff employment incident, business practice, business disruption & business delivery;
(note: business delivery is linked to Process fulfilment but fulfilment is about performance, not just the risk aspect)
The residual risk should be below risk appetite. This depends on the effectiveness of the control.
Operating Cost: The activity cost is determined using time driven activity-based costing. The time driven by the activity and the cost of resources consumed by the activity, drive the activity cost. The sum of all activity costs is the process cost.
(2) Risk adjusted process based Enterprise Operating Model Efficiency
Risk adjusted process-based Enterprise Operating Model Efficiency is a measure that reflects how well a bank’s process-based enterprise operating model performs. It is goal-oriented and takes into account performance, residual risk and operating costs. The score is rolled up from the scores for the lines of business and support departments.
(3) Risk and Resource Utilisation adjusted; process-based Enterprise Operating Model Efficiency is a measure that reflects how well a bank’s process-based enterprise operating model performs. It is goal-oriented and takes into account performance, residual risk, operating costs and resource utilisation.
(4) Risk and Resource Utilisation adjusted; process-based Enterprise Operating Model Effectiveness is a measure that reflects the competitive position of a bank’s process-based enterprise operating model.
(5) Risk Adjusted Operating Leverage is a goal-oriented, forward-looking measure that takes into account the growth in income, growth in operating cost and risk & resource utilisation adjusted process-based EOM effectiveness score.
The three lines of defence own the risk adjusted operational performance evaluation process.
EAPJ: The RAOP framework is described as process-based and data-driven. How does this approach improve operational efficiency and effectiveness compared to existing models?
Kannan: Process-based enterprise operating model refers to the business activity-flow driven, business and technical architecture. A process-based enterprise operating model comprises the front, middle and back-office functions of Treasury, Corporate Banking and Retail Banking. It also includes the support departments: Finance, Technology, Human Resources, Governance, Risk & Compliance, Legal and Premises. The architecture facilitates the intelligent automation of processes. Process automation provides data for measuring and managing (i)process fulfilment, operational resilience, (ii) residual enterprise risk and (iii) operating cost.
The design of process models aligns with data flows. The data and process flows are aligned with events. This is relevant for implementing an event driven architecture. The classification of data as offensive and defensive is situational.
The purpose of data usage is what determines the defensive or offensive play. Spotting opportunities and maximisation of return, are examples of offensive plays, the risk management aspect is the defensive usage of data.
In the content of operational resilience, a data-driven approach, (i) improves the assessment of critical processes (ii) significantly improves the enterprise security program and (iii) facilitates the creation of value for customers. Thus, using the RAOP framework, operational efficiency and operating effectiveness can be measured, managed, improved and optimised.
EAPJ: The book emphasises the role of technologies such as AI, machine learning, and cloud computing. How do these technologies enable better risk-adjusted performance management in banks?
Kannan: Managing the enterprise operating model is about having the ability to focus on a given process, even as the bank keeps the big picture in its view. Enterprise operating model includes outsourced functions.
Cloud computing increases a bank’s accessibility to applications and databases. Virtualisation can be considered part of cloud computing but virtualization is not necessary for implementing cloud technology. The RAOP framework recommends using virtualisation. Using this approach, banks invest less in their hardware infrastructure.
AI tools can continuously monitor processes, enabling real-time insights and the ability to capture process changes and variations over time. A.I. algorithms are adept at analysing and visualising complex, interconnected processes, providing insights that might be difficult to discern through manual analysis.
AI is still in its early stages. Banks must integrate optimisation methods and machine learning as a unified framework to enhance efficiency and effectiveness. Agents and agentic systems, set tasks, make decisions, and act autonomously to achieve defined goals. They are reasoning engines that can understand context, plan business processes, connect to external data, and act with limited or no human intervention.
The agentic AI concurrent orchestration pattern runs multiple AI agents simultaneously on the same task. This approach allows each agent to provide independent analysis from its unique specialisation e.g. market, liquidity, credit, operational risk. This is very useful in managing an internal or external crisis or periods of high volatility in financial markets. This improves processing efficiency, resource utilisation and creates value for users / customers.
EAPJ: Operational resilience is a recurring theme in your work. How does RAOP help banks strengthen resilience in an environment of increasing digital and systemic risks?
Kannan: It is important for banks and finance companies to remember that (i) operational resilience is a subset of enterprise resilience. The efficiency and effectiveness of the enterprise operating model is stress tested when banks manage a crisis situation that has a significant probability of transforming from a liquidity risk into a solvency risk (ii) the scope of operational resilience risk management goes beyond technology risks. There are issues related to the quality of the management, policies, procedures and human capital.
RAOP framework includes the following aspects:
1. Methodology: Threat-Vulnerability-Asset (TVA) approach is important. Enterprise Control Framework (ECF) is important. Controls are linked to the quantified risk and should factor in the risk evolution path. Banks should derive a proprietary ECF from the following: COSO, SOX, ICC, ISDA, FATF, COBIT, GAIT. From a digital-TVA perspective: NIST, TARA, OCTAVE, CRAMM and ISO31000. Most of these are process-based.
2. Policies – At the bank level, policy clarity for single vendor and 3rd party risks are important. Process automation facilitates the roll-down of KPIs and KRIs to process / activity level
3. Mission Critical can refer to a process or a system (e.g., treasury system), the failure of which will result in the failure of business operations, causing high severity losses. High availability is typically thought to be about technology but downtime is often a result of human error or inadequate processes to prevent or properly manage incidents.
Banks with good governance use internal resources for mission critical processes and outsource less critical and sensitive functions.
3a. Risk Appetite
Two important risk appetite measures are: (i) Recovery time objective (RTO) is the time it takes to recover from an outage (scheduled, unscheduled, or disaster) and resume normal operations for an application or a set of applications. (ii) Recovery point objective (RPO) is the point in time relative to the failure to which the bank needs to preserve data. Data changes preceding the failure or disaster by at least this time period are preserved by recovery processing. Zero is a valid value and is equivalent to a “zero data loss” requirement.
3b BCP testing: Process and attack-path based thinking is useful for business continuity planning. Impact Analysis is the foundation layer on which the process models are built. It quantifies the impact over time of a disruption and provides the rationale upon which appropriate continuity and recovery strategies can be formulated
4. Zero Trust Architecture: ZTA is a response to a changing network character that includes remote users, ‘bring your own device’ environment, and cloud-based assets that are not located within an enterprise-owned network boundary. In a ZTA environment, access to the bank’s resources is granted on a per-session basis i.e. during process orchestration. Trust in the requester (data requester, service requester) is evaluated before the access is granted. No requester is inherently trusted. Every asset must have its security posture evaluated before access is granted, as per the policy enforcement point directive.
Services / micro services-based enterprise architecture, bill of resources and process automation, are well aligned with the zero-trust architecture concept.
5. BCP should include Operational Readiness testing
Operational Readiness or Operational Continuity in Resolution, is a regulatory requirement in some countries. This is direct linked to the quality of the enterprise operating model, i.e. architecture, system, staff and data.
Resolvability Assessment Framework is an important aspect of Operational readiness and requires banks to achieve three resolvability outcomes on an ongoing basis:
- have adequate financial resources in the context of resolution;
- be able to continue to do business through resolution and restructuring; and
be able to coordinate and communicate effectively within the firm and with the authorities and markets so that resolution and subsequent restructuring are orderly.
EAPJ: The book highlights the growing complexity of risks, from cyber threats to third-party dependencies. How should banks rethink their enterprise operating models in response to this changing risk landscape?
Kannan: DORA is a framework that guides European financial institutions on digital operational resilience. It is to be understood in the context of the amendments to the European financial services legislation and MiFID II. The framework mandates the management of financial entities to implement comprehensive internal governance and control frameworks for managing information and communication technology (ICT) risks.
The framework is recommended for banks outside Europe.
Bank of Ireland Recommendation
The central bank recommends implementing a strong outsourcing risk management framework. The Central Bank expects that banks to:
Conduct comprehensive risk assessments in respect of any proposed outsourcing arrangement;
Ensure that the outsourcing arrangements are within the bank’s risk appetite and compliant with all regulations and laws;
Specific outsourcing risks include:
- Sub-outsourcing risks;
- Sensitive data risks; (this is a data-centric approach to managing enterprise security)
- Concentration risks, including over-dependence on a single or small number of OSPs who cannot easily be substituted;
- Offshoring risks;
- Step-in risk, which is the risk that the bank may need to ‘step-in’ to provide financial support to an OSP in distress or to take over its business operations.
EAPJ: Your book includes numerous case studies and practical frameworks. How can senior banking leaders practically implement RAOP in their organisations?
Kannan: Banking processes are at the core of my approach. Banks willing to automate their processes using an event & data driven, enterprise services-based architecture will find it easy to measure, monitor and optimise their efficiency levels.
Several banks are adopting the BIAN approach. Maybe some others are adopting something similar. My recommendations is not pure theory or just academic. My books are for practitioners. I provide a proof-of-concept in my portal for a better appreciation of intelligent process automation.
Large banks should transform their siloed business models into a services-based, loosely coupled, interoperable enterprise architecture. I do not have a recommendation for management unwilling to leverage their human capital and relevant technology, or for those who do not make the necessary commitment to stay competitive. I wish to add a caveat here. The lesson that we should learn from the failures of many neo-banks, is that the business model is the primary factor that determines sustainable profitability and survival.
EAPJ: Where can readers go to learn more about you, your research, and Risk Adjusted Operational Performance (including your website and other resources)?
Kannan: My portals are www.BankERRM.org www.PBORM.org and www.RAOP.org. I am passionate about banking, banking technology and risk management. I am happy to discuss related issues. My email id is kannansubramanianr@bankerrm.org.







