Treasury Committee 

Oral evidence: Appointment of Julia Black as external member of the Prudential Regulation Committee, HC 704

Wednesday 12 September 2018

Ordered by the House of Commons to be published on 12 September 2018.

Watch the meeting 

Members present: Nicky Morgan (Chair); Rushanara Ali; Mr Simon Clarke; Charlie Elphicke; Stephen Hammond; Stewart Hosie; Wes Streeting.

Questions 1 - 31

              Witnesses             

I: Professor Julia Black, Appointed External Member of the Prudential Regulation Committee.

 

Written evidence from witnesses:

 CV, Questionnaire


 

Examination of witness

Witness: Professor Julia Black.

 

Q1                Chair: Thank you very much indeed for being here this afternoon for our second session, on your appointment to the PRC.  Thank you very much for sending in your questionnaire and your CV as well.  I want to start with the same point I raised in the previous session, about operational resilience and threat from cyber.  The PRA annual report notes that 50% of firms put cyber crime in their top five risks and, in your response, you commented that you thought that 50% was pretty low.  Why do you think that the other 50% do not think it should be one of their top five?

Professor Black: To be honest, I do not know why they think that.  I just do not think that they should be making that assessment.  Why they are making it, to be honest, I do not know.  Everywhere you look and every report you listen to gets increasingly sobering, if not frightening, to be honest, on this very issue.  The head of the National Cyber Security Centre was on the Today programme this morning, highlighting the scale of cyber risks to which both firms and all sorts of elements of our critical infrastructure are exposed, hence I was surprised that only 50% of firms see cyber as one of their major risks.  I really do not think you can understate the risks.

Q2                Chair: As a member of the committee, what would you like to see and how would you approach it?  Let me take a step back.  Do you think it is the PRA’s responsibility to find out what the other 50% think and why they do not think it is a risk and then what would you like to do, as a board member, about that?

Professor Black: Yes, I do think it is the responsibility of the PRA/PRC to be asking firms that question.  It may be that when they come back with the answers one can say, “Okay, in your circumstance, perhaps yes, perhaps no”.  Not having had that conversation yet with them, I am not in a position to be able to assess; as I say, it is a red flag, to me, that comes up.  Is it the business of the PRC?  Yes.  Within the overall financial services system, the PRA/PRC and all the regulators and committees are completely aligned on this. You have a response pyramid: a cyber attack comes, then one of the initial things that is going to happen is business outage, which is going to hit customers, which is an FCA conduct issue.  However, it could get to the point that it becomes a safety and soundness issue, which is a PRC issue and, obviously, there are issues at the interface there where you need close cooperation and coordination.  At its very worst, it becomes a systemic issue, in which case that is the FPC then running all the way down the system. 

There is awareness in the overall regulatory system, as a whole, of the need to pay attention to this and the roles, importantly, that each actor would have in responding to it, working very closely with the National Cyber Security Centre and building that into really strong and severe systems testing, including all the techniques that are used in that, whether that be tame hackers trying to hack your system to test itand make sure it is in line with all the safety protocols that there need to be.  You cannot be underprepared in that area.

Q3                Chair: How do you think operational resilience ranks alongside financial resilience?  Should they be treated the same, as we were exploring previously?  How is operational resilience measured?

Professor Black: I agree very much with what Jill was saying in this area.  Operational risk has been on the regulatory agenda for a long time; it goes back to the revision of the Basel Accords prior to the crisis.  It had a rule-of-thumb number stuck against it and then was characterised in terms of legal risk largely, and therefore was not really conceptualised as being anything more than that.  I am absolutely in agreement for bringing it on to the agenda and in a very targeted way so that, as has been said, you ask firms to look very carefully across all their different business processes and test each one for critical points of failure, outage times, et cetera.  By then, you can start to work back to think what that impact would be and, therefore, what the metric would need to be against it. 

One of the issues in relation to operational resilience is that just putting a capital number against it is not going to be the way you are going to be able to address the problem.  You are going to have to have other measures in addition to having enough money to throw at the problem, to be honest.  As Lyndon Nelson says, you need to be on that WAR footing, which is quite a nice acronym, to be able to withstand, absorb and react.  You need to have those backup systems in place and all the operational structures and processes that you will need in order to be able to react. 

As to whether cyber or operational risk are the biggest, TSB has shown us that it can be really straightforward things; I know no IT programme is straightforward, but there was nothing particularly elaborate about the TSB failure.  There was no cyber involved there and yet you have a significant operational failure that has cost in the region of £200 million, so it does not have to be fancy.

Q4                Chair: Previously, we touched on legacy IT systems.  Different regulated firms that the PRA oversees will have different levels of IT, some more modern than others, some fairly ancient.  Is that something that you would want the PRA, let alone if something happened, but just to look at how people’s system are working?

Professor Black: Yes, absolutely.  Some of them I know and I am beginning to look at specific ones, but having spoken to those around the industry, some of them are pretty Heath Robinson.  You need good IT systems from an operational point of view, but also what was shown, for example, in the crisis was that the IT systems were not able to give a single customer view.  You went to Northern Rock and said, “Okay, what is the single customer view of Mrs Miggins’ relationship with you?” and it would be, “We do not know.  The current account books are over here and the mortgage books are over here and the small lenders’ books are over there”.  Whilst we talk, on the one hand, about the fabulous advantages of AI and distributed ledger technology over here,  there is the reality back here, where there is a fair amount of work to do even to be able to get that data.

Q5                Chair: In your answers to the questionnaire, you talked about people having the right skillset and often requiring skills that were in short supply.  The flip side is, obviously, the PRA/PRC has to have skills and you will have heard me say previously that Sam Woods has said to us that just 42 people at the Bank are working on operational resilience.  Again, can you take us through how you, as a new nonexec board member, would be able to challenge and potentially ask the right questions to check where the Bank and the PRA are on that?

Professor Black: I do not know, at the moment, whether 42 is the right number; I have not started in the role yet.  The question will be whether 42 the right number, and how you know and how you are going to assure me that it is.  Moreover, are they the right people doing the right things?  It is really taking it apart, as it were, element by element and testing out, down from both their skills but it is also about what proportion of their time is being spent on that.  If you had to step them into a particular crisis, where is the backfill going to come from in operational terms?  How agile are people?  What is your turnover in that sector, in that area?  Again, gross turnover figures across an organisation do not really tell you where the pressure points are.  Where are your recruitment gaps?  What is your time to appointment in these different areas?  It is those kinds of questions.

Q6                Stephen Hammond: Good afternoon, Professor Black.  In your article of 2012 in the Modern Law Review about the paradoxes and failures of the regulatory system, while it is commentating on the political allocation of blame in the previous systems, you also say that the principlesbased system has suffered a fatal blow.  You also comment on the coalition’s analysis that it was due to tick-box regulation.  How far do you think the current model overcomes all those issues and what, in the current framework of regulatory architecture, needs to be strengthened, if anything?

Professor Black: It is difficult to understate the impact that the crisis had on every single part of the financial services sector, including the supervisors and academics, such as myself, who were looking and analysing this at the time. I am always a little sceptical of annual reports and statements as to everything is all fine now, because it is my job to be sceptical.  That said, I do think an awful number of lessons have been learned in terms of that critical scepticism and critical inquiry in how a supervisor and a firm relationship gets built up and the issues around forbearance and the, “Well, it will be okay”, and just more and more, “It will be okay”.  It is very important to ensure that you always have an internal challenge within the organisation, within supervisors, to say, “But why?  What are you doing? What are you going to do?  How are you going to respond to this?”

One of the things I will be very keen to do when I do start, at the end of the calendar year, is to talk very closely with supervisors, because supervision is the daytoday business of regulation.  That is when the rubber hits the road.  Policy is a series of hypotheses, enforcement is the A&E department, as it were, to mix metaphors, and the supervision is where it really happens.  One of the questions I always like to ask regulators or inspectors when I meet with them in different areas and different fora is to say, “Okay, what do you look for?  What is your smell test, as it were, when you go into an organisation?”  I remember talking once to somebody from the Health and Safety Executive who said, “If I am going on site, the things I look at most closely are the men’s loos, because the state of the men’s loos will tell me if this is a management that takes its workforce seriously.  Are they clean?  Do they have showers?  Do they have places to change, et cetera, or is it just a portacabin that last saw bleach in 2012?”  Obviously, it is not going to be a direct analogy, but I like to go in and find out from supervisors, “What are you looking at?  How do you know?  Are you testing properly?  What is your system of internal challenge to your own assessment?”

Q7                Stephen Hammond: I take it from that answer that you regard scepticism and challenge as the key part and the key characteristics of your role.

Professor Black: In a constructive and supportive way.

Chair: That sounded like a government Whip’s answer.

Q8                Stephen Hammond: Goodness knows what is going to happen there.  In your response to question 6, you said, “The PRA has succeeded in establishing itself as a separate and respected regulator”.  Are you aware, from your history of looking at financial services, that there was a culture in financial services for a long period of time, which has changed a little bit, that those who could did financial services and those who could not did regulation?  Do you think there is adequate regulatory resource or is there a suitable level of regulatory resource now dedicated to prudential supervision in the UK?

Professor Black: One of the core arguments for taking prudential supervision out of the integrated regulatory structure and organising this “twin peaks” with the new “plus” model was so that you could have dedicated resource, focus and attention.  The tradeoff of that was argued to be that you lose the integration.  We have gone in cycles or in different iterations of financial regulation in the UK, from the separation to the integration and then back out to a different form of separation.  What it does mean, where it is helpful, in terms of the PRA, is you have a clear mandate, a clear remit and clarity over exactly what resources are being put on prudential regulation, because you can see exactly the budget, the staffing levels and you have separate accountability on that very important aspect of the overall regulatory agenda and regulatory mandate.  That is absolutely helpful.  At the moment, the staff is around 1400; I forget the exact figure now for the budget.  Is that the right number?  I do not know, from this distance.  That will be one of the things that it is absolutely one of the roles of the nonexec to check and we have to report on separately, in fact, as to whether or not we do think that resourcing is adequate.  Again, that is a very good thing: that nonexecs have to do that in a circumstance where the PRA is part of the Bank.  There are other execs on the board and it is not entirely a nonexec board, so it is important that the nonexecs do have an ability to report separately on the adequacy of the resources.

Q9                Stephen Hammond: Do you think it is necessarily a failure of the prudential regulatory regime if a firm fails?

Professor Black: I refer back again.  The PRA is a riskbased regulator, but it is not a zero-risk tolerance regime.  It is not food safety, which operates on a very different basis for very obvious reasons: you do not tolerate a certain level of salmonella.  What is important is that, yes, firms are allowed to fail, but they do so, again, as has been said, in orderly fashion.  This is why you have to have very close relationships and yet some independence as well, between the supervisor and the resolution regime.  As Jill was saying, you need to look very closely.  You have a lot of scrutiny and levels of supervisory response that go on before you get to the point of failure, but at the point where it is absolutely clear that this firm is going to fail—and remember what that means is the impact is going to be on customers and policyholders—then the obligation can be also that it has to go into resolution.  It is important that that is done in an orderly manner, you have client continuity and you have your deposit protection scheme and your policyholder protection scheme to make sure that, if necessary, policyholders and consumers are protected.

Q10            Stephen Hammond: I take it from that that if it is done in an orderly fashion with consumer protection, it is appropriate within a riskbased system.

Professor Black: Yes.

Q11            Stephen Hammond: You will have seen the comments from the Basel Committee on Banking Supervision about the threat to retail banking profits because of the rise of fintech.  It was suggesting something like 60% of retail banking profits being at risk.  I have two final questions.  First, do you think that is the right order of magnitude?  Secondly, would you agree with the analysis that suggests that, given the rise of fintech, there is a greater prudential risk, on the basis that they are moving from large entities, and given the protections there are to the consumer associated with large entities, if there are smaller entities for the PRA to look at?

Professor Black: It is a question in two parts, really.  60% of profits at risk, again, is a bit of a finger in the air.  When I was looking at figures recently, I was looking at areas such as foreign exchange payments and entities such as TransferWise, I do not know about you, but if you book on Airbnb and somebody says, “Do you want to use TransferWise to pay or go through a bank?” one is very much a cheaper option, which is taking £16 billion, which is the latest figure I read, in terms of fee income off those entities, which is great for consumers but not so great for those whose businesses are being eaten into. 

China always does things on many multiples of scale than anybody else, but in the last five years the rise in mobile banking there has gone up 100 times.  That is fast. 

I was looking in the last few days at Monzo, which is a challenger bank; it has come out with something that looks very interesting, which is “If This Then That”.  That is, if you do something in relation to your bank account, such as take a transfer or make a payment or do X, then you can develop your own little applet—I did not know about the word “applet”—which means that then certain things happen.  What you cannot do, however, through this is take money out of your account, but you can, for example, say, if I went to the gym and you could see me pay something there, then you can record a reward for me in my reward fund, or something like that, or if I had a coffee you can record the calories I consumed on my calorie app or whatever.  The point is that the customer designs what those things are going to be.  That is a completely different model.  I do not know about you, but with my bank I cannot make a payment out of my savings account; I have to transfer the money into my current account to make a payment out of my savings account.  That is quite a distance from where we are now.

The answer to your question is, to be honest, who knows?  Are the risks there?  Yes, they are.  One just needs to think of Nokia and Kodak to know that these things can happen very quickly.  Are banks reacting?  Yes, in interesting ways.  Barclays, for example, is investing itself in some of the fintech startups; if you cannot beat them, eat them, as it were, which is a Facebook attitude as well.  It has also invested recently in an innovation platform, Beacon, which is even further upstream.  It is clearly a really interesting space to watch and there could be enormous benefits for consumers and the market more widely.  From a prudential point of view, yes, you therefore have to look very closely at the business models of the firms that you are regulating, because one of the things that might then happen is excessive risktaking behaviour to compensate for the loss of that lowhanging fruit, as it were, of business that just came in.

Chair: Thank you.  I am going to bring in Charlie.  I am going to ask for answers to be just a little shorter and then we can cover more ground.

Professor Black: Sorry.

Chair: No, it is fascinating.  The trouble is it is far too fascinating for all of us.

Q12            Charlie Elphicke: Professor Black, good afternoon.  Turning to risks and stress tests and those sorts of issues, my constituents in Dover and Deal feel that the lessons of the financial crash have not been learned.  They feel that they have paid the price while the bankers have simply got away with it.  Are my constituents wrong?  How can we be sure that banks are resilient enough that we are not going to have a repeat?

Professor Black: Are they wrong in the sense of, “Did people get away with it who should not have got away with it?”  To be honest, in terms of levels of investigation and people being taken to task who should have been taken to task, one of the important things to recognise for your constituents is that even if the system for holding people to account certainly was not perfect then, it is certainly much better now.  The actions that have been taken against individuals at senior levels within firms do demonstrate that regulators are very prepared to take action against the most senior individuals and to take enforcement action against them. The PRA, unusually for a prudential supervisor—it is not usual for a prudential supervisor to take an enforcement action; it is usually very quiet—has opened 38 different enforcement actions, so far, since 2013.  The majority—25—of these have been against individuals and, of the open cases, very interestingly and importantly, it is conducting them jointly with the FCA, both firm and individuals.  That is the point on the individuals.

Coming to the prudential and the resilience and the stress testing, the system as a whole is significantly better capitalised than it was in 200708.  Three times as much capital is being held.  The leverage ratios are double what they used to be.  In terms of reliance on shortterm funding in the markets, banks would be relying for about 16%, roughly, of their funding in the shortterm money markets, excluding repos, and it is now down to about 4%.  Practices have changed and resilience is greater. 

In terms of ability to cover their risks, on a liquidity basis, prior to the crisis their ability to cover liquidity needs through own assets and access to central bank resources was to cover 10% of their overall riskweighted assets; it is now over 100%.  Are things better and stronger?  Yes. 

In terms of the stress tests and the parameters that you were talking about and drawing attention to before, the role of a stress test is to prepare for the worst, and so if one is using extreme scenarios then that is really putting the system under strain.  Arguably, a weak stress test is a stress test that uses quite comfortable scenarios.  One of the lessons that was learned, again precrisis, was they used to have war games between the Bank and the Treasury, and one of the scenarios was incredibly close, by chance, to the scenario that happened.  That is, there was a failure of a northern bank and a failure of a US bank, et cetera, and the reaction was, “It is so bad it cannot possibly happen”.  We have learned that just because it looks really bad does not mean it cannot possibly happen.  One can argue about whether the scenarios are too robust.  I would be much more comfortable defending something that looks too extreme than defending something that looks too comfortable.

Q13            Charlie Elphicke: Is that not the issue, though?  You want to have the black swan type risk, the risk on the edge of the fan chart, and you want to say, “We need to be prepared for these kinds of risks as well”, but to go around saying that serious risks are at the centre of the fan chart, like the Treasury running around the other day saying that GDP will fall by 10% and borrowing will rise by £80 billion is just alarmist but not entirely credible and one should not be extreme.  Would you agree with that?

Professor Black: Should one always be trying to be credible?  Yes.  One of the difficulties in the Brexit estimations is one person’s credibility is the other one’s alarmism and is the other one’s conservatism.  We do not know the range of “we do not knows”.

Q14            Charlie Elphicke: That brings me neatly to your 2016 paper, where you discuss the challenges regulators face in deciding which risks to prioritise and focus on.  To what extent do you think stress testing should be focusing on one set of metrics rather than another set of metrics?  Should they also be taking into account the risk of IT and IT failure?

Professor Black: Your stress test has to be multifactorial, because things do not happen one at a time.  If things happen one at a time, we are usually more able to cope with them.  It is the fact that they are all happening pretty much at once and coming in directions we did not anticipate.  One of the things you need in scenario building for your stress test is quite a lot of diversity and imagination and people coming in probably from outside or from other areas to help you design a stress test.  That is quite important, to get that cognitive diversity you were talking about before into the design.

Should operational risk be in there?  Yes, it should.  There is an element in there already.  Obviously, there are sights on increasing the testing on the op risk and cyber risk elements as well, indeed, as climate risks.

Q15            Charlie Elphicke: Should stress testing take into account the resilience of standard IT?  Let us say you have a major bank that does an IT upgrade, which turns out to be completely catastrophic.  Of course, I am sure that could never happen; perish the thought.  Do you think that should be built into the work that the PRA does or would you say that is for the FCA?

Professor Black: No, I think it goes to the work of the PRA as well.  That is an area where they need to cooperate.  It is the same IT system and it is the same institution, so it would be good if they could—and I am sure they do—work very closely on those kinds of things.  As I was saying before, because the level of risk can go from the frontline consumer, then, if it is very severe, it gets to safety and soundness, so yes, absolutely.

Q16            Charlie Elphicke: In a 2016 paper, you also talk about the linkage of risks and there is this issue about the pragmatic path of collecting data that is collectable.  Is there a risk that regulators will just go for what they can collect and it is nice and easy, and think if they have to look at things like culture, it is all just a bit tricky and complicated?

Professor Black: It is the “drunk looking for a wallet under the streetlamp” problem.  That is always a concern and always a risk and, in a way, the drive to have measurable indicators means that you can end up looking for things that are easy to measure; they are the things that get counted and we do not go to the “is that too fluffy to be looked at?” box.  It is very important to be looking at both the quantitative metrics and the more qualitative metrics in order to be able to get that fuller picture, so you do not get distracted by what we can measure being what matters.

Q17            Charlie Elphicke: Finally, if it was down to you and you had a blank sheet of paper and it was your project, as the NED, to lead, how would you rework stress testing methodology and make it really great?

Professor Black: That is a very good question.

Chair: There is a certain assumption in that question, Charlie.

Professor Black: In my case, I have some really good people back at base at the LSE who work on this stuff in terms of game theory.  I know the kind of stuff they are doing and I would phone a friend, as it were.

Q18            Charlie Elphicke: Are there any particular changes you would make?

Professor Black: To be fair, in terms of looking at the parameters of them, I know the parameters are  being published, and I know also that, encouragingly, they have changed.  The very first ones focused on domestic risk; they then expanded in complexity.  In terms of the design and exactly the parameters that are put in around these things, yes, it is an issue for scrutiny, but importantly, getting outsiders in to give an additional point of view, an additional perspective and a bit of credible challenge would be one thing I would hope to be able to bring to the exercise.

Q19            Rushanara Ali: Good afternoon.  I wanted to just pick up, first, on the resilience question.  You mentioned the 50% attached to cyber security risk.  You also mentioned the estimated cost of about £200 million to TSB following the technology failure and the combination of these risks: technology, data breaches, cyber security and increasingly the threat of foreign Governments trying to attack our financial system, potentially.  That context is quite a challenging one now.  Do you think that there is more that needs to be done—and perhaps you will be able to add a particularly strong perspective in light of what you both said, in terms of your evidence today—about linking those elements together? 

The reason why I mention this is because what we are finding, and certainly my impression, in the evidence sessions we have had with the FCA versus TSB and how they hold different things to account, is there is still a problem of siloes.  There needs to be more joining up, more integration in thinking about these crosscutting problems.  How do you think we can improve on those so that, at the frontline, consumers are not treated the way that TSB customers have been treated?  We are being told in evidence sessions—the FCA is telling us—it is probably FOS that has to deal with it, with the individual complaints.  These things fall in different parts and that is pretty frustrating and worrying for consumers, but also for committees like this and other agencies. 

How are we going to see a radical improvement to the joining-up process so that we do not end up with a bigger problem brewing?  The modern day challenge, if we were drawing parallels between the financial crisis and what might happen in the future, might not be about better capitalisation that is dealing with a past problem; it might be about this perfect storm that is coming together that hurts consumers, and the institutions are still not capable of addressing the problems quickly.  It is already months since the TSB problems and well over 100,000 people have been affected and you know the rest of it.  I would just like some reflections on that, first of all.

Professor Black: There are two issues there: there are siloes within the organisations themselves and then there is the UK regulatory system and all its parts, wonderous and varied though they are.  I do not know the extent to which any of this is happening; as I say, I have not been able to dive into this yet.  When going back to scenario analysis, for example, there is integration on some of these aspects, as I was saying before, between the FCA, PRA and FPC on that, but there is a need to bring in to those scenarios FOS, the Financial Services Compensation Scheme, the National Cyber Security Centre, and to say, “Across agencies, let us work through the scenario analysis and let us work out stress testing, so that we are really clear who is going to do what when”.  Moreover, we need to communicate that out to customers, consumers, firms, et cetera, so that they know what to expect from the regulatory system should something happen.  Either they know that their deposits are going to be secure or whatever, because the compensation scheme is there, or they know how to complain and get redress through the Financial Ombudsman Service. 

It is really about getting those crossorganisational groups.  It is always phenomenally difficult to get horizontal—everybody is very keen on sticking to the vertical—but you should make a really conscious effort to make sure that you have that and, as one regulator said to me in the course of the crisis, “Just make sure that everybody has everybody’s phone number”.  It is pretty basic, but it is that on a slightly more elaborate scale.

Q20            Rushanara Ali: You used a quote earlier about it being so bad it could not possibly happen.  Imagine a simultaneous situation with a number of banks with data breaches and technology failures that affects hundreds of thousands of people and the effects of that.  You will have heard some of the stories about how people’s lives have been affected.  I certainly do not feel confident that we are there and it would be helpful to have much more of a drive to bring all that together and, perhaps, in future responses we will be able to see how that progresses.

On the question of the Bank of England, I am going to pick up on some questions relating to Brexit.  The Bank has expressed confidence that the 2017 stress test proved that firms could withstand the impact of a no-deal Brexit.  You heard these questions earlier on and I just wondered what your reflections were.  Do you agree with the assessment?  Let us start with that.

Professor Black: To be honest, not having been in and looked at the books and at exactly what the contingency plans are, if the PRA says that it is confident, at the moment, I do not have any reason to contest that.

Q21            Rushanara Ali: Regarding the 2017 stress test on house prices that we heard about earlier in Charlie’s questioning, is the price fall of 33% too pessimistic a figure in a no-deal scenario?  Do you have a different view on it?

Professor Black: Again, as Jill was saying, this is incredibly difficult to assess.  33% is a rapid decline, and one of the issues about these estimates is always over what time period and for how long.  Is it a sudden drop down and, in fact, it then recovers again very rapidly?  Is it a slow kill off and, in fact, it then plateaus at a significantly lower level?  From a prudential regulation point of view, the issue for a prudential regulator is about what the firm’s exposure is to property assets and, therefore, the capital they need to hold against that?  If you have insurance companies, for example, moving into property, holding increasing amounts of property on their books, then any decline in property price is basically an impairment on the asset value.  Ringfenced banks are heavily concentrated now in UK residential and commercial property.  Again, to go back to the hope for the best and prepare for the worst scenario, from a PRA perspective it is, “Let us take that as a real worst case; how is that going to play out across the business models of our regulated constituency?  What are the implications of that going to be?”

Q22            Rushanara Ali: On the 2017 stress test modelled on UK GDP falling to a 4.7% figure, do you have a view on that?  Is that a realistic parameter in a no-deal scenario?

Professor Black: Again, it is very difficult to know what the counterfactuals are going to be.

Q23            Rushanara Ali: That is great, thank you.  Could you put all of this under the quote of, “It is so bad it cannot possibly happen”?

Professor Black: No, it is always fallacious to think it is so bad it can never possibly happen.

Q24            Rushanara Ali: Yes, I was going to come on to that.  Should be more confident that even if these figures do not turn out to be the actual figures in a no-deal scenario, because the thinking and the number crunching is being done now under the bracket of “It is so bad it cannot possibly happen”, these institutions are looking very closely at it and are learning from the prefinancial crisis period, perhaps, and that it is prudent to do that, to look at the worst-case scenarios so that you can mitigate against the risks, as well as the best-case scenarios?  Perhaps politicians can learn from that approach, looking at all eventualities in an attempt to try to insulate the economy and the population from bad things happening.

Professor Black: Absolutely.  I could not agree more.

Q25            Wes Streeting: I just want to pick up on the themes begun by Stephen Hammond and Charlie Elphicke.  To what extent do you believe the culture of firms has changed since the crisis?  Do you think the culture of firms has changed far enough?

Professor Black: It is a very good and incredibly pressing question.  At this distance, I would not be able to say for sure.  Again, going to objective metrics, we know that pay structures changed considerably.  We know that around about the time of the crisis and, in fact, even just after the crisis, 2010, 2011, 70% of the remuneration structure was paid through bonuses and it is now down to about 46%. We know there has clearly been change on a measurable dimension there.

You were talking earlier with Jill about the metrics on gender diversity.  BME diversity is obviously critical as well.  Again, metrics on there indicate some improvement, but not as fast as many of us would like.

Where you then turn that into culture, as I say, from this distance, I would not feel confident saying either yes or no to that particular question.  However, there has been the Senior Managers and Certification Regime and the need, most importantly, for attestation; it is really important that there has been a galvanising shift, a focusing of the mind, shall we say, on the individual liability of those at the top.  What is really important about the Senior Managers Regime is the attestation part.  If you were to look at the rules of the approved persons regime prior to the crisis, they said everything you probably wanted them to say. They covered the bases off. They said what should happen.  There was just one key problem, which was that it was not happening.  It was through the attestation and the signoff and the clear assignment of responsibilities—“This is what you are responsible for, are you not?  Sign here”—and the certification regime cascading down that has galvanised a step change in that regard.

Q26            Wes Streeting: There are two questions that follow from that.  You mentioned it is difficult, from your distance, to make a judgment about whether culture had changed far enough. I just wonder how much more clued up you would be with proximity.  How do we properly measure culture?

Professor Black: Again, this is an absolutely fascinating question in terms of how you can go in and assess different cultures and different cultural distances.  I have a bunch of colleagues at the LSE who work exactly on this and on developing schemas that can help organisations do just this.  It is really about trying to understand the firm going outside of the compliance regime and the compliance system.  That is one of the challenges for supervisors, because the people they see are the people who do compliance.  The issue then internally is how distant or integrated is the compliance function into the rest of the organisation?  Compliance may give you a lovely view of what is going on that may or may not really reflect what is going on within a firm. 

There is quite a lot of interesting work now that is looking not just at individuals such as the rogue trader and that kind of thing, but looking at groups and group dynamics and how groups can become, shall we say, dysfunctional within organisations.  It is about how you start to get identifiers for that and the analytics you can start to get in terms of behaviours and the ways that things are operating to be able to get really quite forensic in your analysis of the organisation.  There is an interesting bunch of work that is going on in that area, which again enables you to take something that is quite general and a bit amoebalike and start to pin it down into something that is a bit more tangible that you can get to grips with.

Q27            Wes Streeting:  We will have to invite some of your LSE colleagues in and then they will be really grateful to you for mentioning that.  The second follow up is on attestation.  You have clearly demonstrated your view that the Senior Managers Regime has had a demonstrable and positive impact.  Do you think it is the solution?  Are there adjustments or extensions to that regime that you would like to see?

Professor Black: Again, it is a really good question.  It is not a solution on its own; it only works when part of a wider suite of tools and regulatory requirements.  In terms of the adjustment and evolution, the inclusion now of a COO as having a senior manager role and the recognition of who are the critical risktakers and who are the critical players within an organisation do show that it evolves.  Also, there is a reflection of the shifting nature of organisations’ critical risks and challenges within the organisations themselves and, therefore, the need to incorporate that function that looks after that particular issue within the Senior Managers Regime to signal its importance and ensure sufficient focus within the organisation upon it.  It is always important to make sure it is continually evolving.

Q28            Wes Streeting: Turning to a specific issue, you referenced, in respect of the SMCR, the fine issued to Jes Staley at Barclays.  That decision attracted widespread criticism for being too weak a punishment.  I just wondered if you think, for that fine in particular, whether the criticism was justified and makes the SMCR look a bit like a paper tiger.  To what extent does the perception of the strength of enforcement really matter?

Professor Black: On the specifics, again, I only know the facts of the case as I read them in the papers, so it is hard to say on that metric.  However, I do know one of the things that plays into a decision on the level of enforcement is the level of wilful criminal intent, as it were, that plays in, which was not seen to be apparent in this particular instance.

Moving on from that to the wider question of the deterrent effect of signalling, enforcement and sanctions can have a significant signalling effect.  That is one of the things that the PRA, as well as other regulators, take into account when deciding when to take enforcement action and the level of fine to impose. You are absolutely right that if you set that too low then you weaken your deterrence and you can undermine the credibility of the regime, but also, at the same time, if you set the level of sanction so high that it is like a nuclear deterrent, nobody ever uses it.  It is about having that range and getting that appropriately calibrated and, if you are imposing a fine at a certain level, being able to justify that in a way that renders it credible to the wider both regulated community and the public, on whose behalf you are regulating.

Q29            Wes Streeting: That is one of the things I was getting at, really: not just the deterrent impact of fines, but in terms of public perception, how far do you think that matters?  This goes to Charlie’s point.  I do think, fairly or unfairly, there is a perception out there.  My constituents would say the same: “Why do the bankers get off the hook?”

Professor Black: I completely understand that perception.  I remember appearing before the Parliamentary Commission on Banking Standards just after the crisis, where again I was advocating there that it should be for the managers themselves to demonstrate safety and soundness of their systems and reverse the burden of proof.  There was a bit of debate around that for a little while, but I did not get that one through. It is really important and one of the things, from a public point of view, is that there is just so much money going on and at stake there that one of the things really is about where the public accountability is.  The Senior Managers and Certification Regime is a massive step in the right direction and it absolutely does need to be backed up by credible fines.

Q30            Wes Streeting: Finally, your experience researching and analysing regulatory regimes gives you an international perspective as well as a UK perspective.  Would you characterise the UK banking culture as distinct from those found in other countries?  Perhaps most importantly, do you think there is anything that UK banks and insurers could learn from their counterparts overseas?

Professor Black: Again, that is a very good question.  One of the qualifications has to be that these are multinational institutions, so they are global banks.  All four of our UK banks are globally systemic, important institutions with worldwide operations. In terms of the banks themselves learning from other parts, possibly yes, possibly no.  Certainly regulators can learn an awful lot from each other and from each other’s failures as well.  That is not just regulators in the financial sector; that is regulators more generally. There are groups of regulators that do get together quite frequently to learn lessons, as it were, from each other outside of the formal structures of the international regulatory organisations.  Is there that possibility for learning within banks?  When banks have moved into different markets, they have realised there are very different cultures operating, sometimes to their cost—for example, in relation to HSBC and money laundering—so you might find that there are cultures that you might not want to learn from or only in a way to eradicate them.  But yes, that kind of crosslearning, certainly at a regulatory level, does go on and is incredibly important.

Q31            Charlie Elphicke: I have a supplementary question that Wes’s excellent questions brought to my mind.  We have talked about risks that never happen.  Just as the risk that a bank will do an IT upgrade that will go catastrophically wrong is a “never happen” risk, the other potential risk is a bank is owned by a large overseas parent that pushes it about and tells it what to do and orders it around the place and effectively acts like a shadow director.  How do you deal with that in terms of the finingtype regime or holding that overseas parent to account so that it cannot do that to a domestic bank?

Professor Black: This is about extraterritorial regulation when you are a territorially bound regulator.  If you are in the position of being, in effect, a shadow director, then the regulatory regime has purchase on you.  In a way, the harder version of your question is if you cannot quite demonstrate that they fall within the regulatory definition of shadow director, et cetera, and so you do not really have very clear jurisdiction.  The important thing there is that you cannot regulate a multinational bank on your own as a single-jurisdiction regulator and so it works through the supervisory colleges.  In fact, those supervisory colleges continue Brexit or no Brexit.  We will continue to be part of those supervisory colleges for all the banks that are subject to UK regulation whether they are headquartered in the UK or not.  It is that supervisory college network where you cannot go to the bank, but you go to the bank supervisor and say, “Oi”, obviously in more eloquent language.

Chair: You have managed to boil the whole PRC work down to “Oi”, which is very good.  Professor Black, thank you very much indeed for your evidence this afternoon.  We are very grateful for your time.  We will consider our report, but we wish you very well.  Thank you.

Professor Black: Thank you very much and thank you very much for your questions.