Search interesting materials

Showing posts with label risk management. Show all posts
Showing posts with label risk management. Show all posts

Friday, July 24, 2026

Supervising what you cannot inspect

by Maninder Singh Juneja and Renuka Sane.

In traditional financial regulation, supervisors are able to inspect the thing being regulated. For example, a scorecard by a bank was usually a short list of factors that one could comprehend. These factors could be traced to key documents within the bank, banks had a stated rationale for why they were being used, and there was some common sense in making weighted averages. The scorecard itself was static - the same weighted factors were applied over a period of time. Inspecting this process of constructing the scorecard and using it for management decisions was how trust was built. The AI world is different. Models are rented rather than built, change continuously, and behave probabilistically. They cannot be fully inspected even by the institution deploying them let alone by the regulator.

How should we then think of regulation?

One approach is to intensify the traditional approach where regulators demand more explainability, more documentation, and more validation. This will drive up the costs of compliance. But more importantly, this is ill suited to the new world where the technology changes rapidly, where the bank does not control the AI it uses, where there is no clear artefact that the bank can give the supervisor such as a model or a document (Board of Governors et al 2026). When regulators push traditional approaches, banks will respond by choosing AI models which are easy to document rather than the ones best for them, or defer AI deployments altogether. All these are unhappy consequences. What we need are policy makers who understand the live systems of the new world.

In this article, we analyse these emerging problems from first principles. We start from scratch, understand the landscape of market failure in the world of AI in banking, and think about how regulators can grapple with this world.

Our key idea is that AI systems resist replicability. Regulatory strategies that demand replicability will flounder or choke technology deployment. We suggest the regulatory standard applied should be AI deployments that are "supervisable" - the outcomes should be observable, they should be attributable to causes, and reversible by humans.

How AI is actually deployed

Before we get to the puzzles faced by regulators, we need to describe what AI in banking is. This categorisation is not unique to banking. Banking is simply where their consequences are regulated. Five modes span the range.

AI as Tool: AI augments a step, a search, a calculation, a first draft that the human controls. The human is cognitively engaged.

AI as Collaborator: The human and AI co-produce iteratively, and the human participates at every stage.

AI as Recommender: AI generates scores or options, and the human makes the decision. This is the classic human-in-the-loop, but credible only if the human can meaningfully interrogate the recommendation and not degenerate into cognitive surrender.

AI as Preparer: AI does the work and the human signs off. The approval here is closer to a check by a supervisor rather than a re-derivation.

AI as Autonomous executor (agentic AI): AI executes autonomously inside guardrails and the human monitors on exception. Emerging forms of agentic AI for banking run from single-task agents (a payment released, a service query resolved) to multi-step workflows and customer-facing agents that transact.

A central issue here is the true (de facto) role of the human. A reviewer who approves a thousand recommendations a day is not overseeing a model, the model is overseeing her. A feature of any deployment is the measured divergence between the model recommendation (and estimated uncertainty) vs. the human decision. Managers of banks will need to worry about relapses of human behaviour inside the organisation, a bit like how hospital managers worry about bad behaviour by doctors within their organisation.

What AI does to market failure in banking

We now shift gears to look at the standard knowledge on market failure in banking. Regulation may be justified when (and only when) there exist market failures which cannot self-correct fast enough, and there is adequate state capability in banking regulation to be able to correctly identify them and intervene. AI's distinctive feature is that it can cure several classic failures. Better default prediction reduces credit rationing, better fraud detection cuts deadweight loss, richer risk assessment lets banks serve customers they previously could not price, AI advisors help customers avoid some malpractices by the bank. But there are also some new problems that are anticipated.

Information asymmetry: This happens in banking at two levels: borrower-to-lender (adverse selection, hence credit rationing) and firm-to-consumer (product complexity, hence mis-selling). AI narrows the first through alternative data and may widen the second. On one hand, the customer armed with AI can see through many things proposed by the bank which are not in her best interest. But the consumer cannot observe why they were shown a product, offered a price, or steered toward a specific insurance plan. The sales process itself becomes more opaque. Personalised pricing approaches first-degree price discrimination, extracting consumer surplus. A single flawed model can mis-sell to millions simultaneously, converting isolated conduct failures of the pre-AI world into a big correlated event. And redress weakens when a denial comes from a model the firm itself cannot explain.

Systemic externalities from shared infrastructure: Each bank chooses its models, data sources and vendors to optimise its own performance. When multiple entities choose the same ones, the sector's exposures become correlated, which is a cost no individual bank prices in. We list the vulnerabilities below:

Correlated model risk: banks on similar models and the same foundation providers respond identically to an event. The regulator, at the system level, has to manage what happens when institutions move together, because no single entity has experience of such behaviour or of the impact synchronisation adds.

Third party concentration: one vendor's failure propagates everywhere at once. India has already run this experiment, when a ransomware attack on one shared technology provider knocked roughly three hundred cooperative and regional rural banks off the payments network.

Correlated cyber breach: shared stacks mean one exploited vulnerability is every institution's vulnerability. AI lowers the attacker's costs (automated vulnerability discovery, deepfake social engineering) and adds new attack surfaces (data poisoning, model inversion, prompt injection against agents that can move money).

Runs on banks at level 3. The bank runs of old were a queue on the pavement. Then we got to Silicon Valley Bank where over a weekend, customers took away money from the bank. Now we can be at level 3: autonomous agents managing customer cash can turn a shared signal into a self-reinforcing run at machine speed.

The various market failures listed above behave differently across the five modes of AI use. For example, when a human constructs the offer, opaque pricing can get contained. However, when an agent personalises autonomously at scale, this may become severe. Systemic correlation is moderate when AI advises and severe when fleets of similar agents act simultaneously. Any regulation that grades by model type alone, or by use case alone, misses half the object. The next question is the mode of regulation itself.

Regulatory strategy

Regulation can work in two ways. Process-based regulation is ex ante: it prescribes how the firm must operate, defines required controls, mandates oversight, validation standards, limits on autonomy. Outcome-based regulation is ex post: it prescribes ends, fair treatment, solvency, and judges results, leaving the choice of methods to the firm.

Outcome-based regulation is the efficient default. It is technology-neutral, so it does not ossify as methods change; it lets firms find the least cost route to compliance; and it does not require the regulator to understand the firm's production function better than the firm does. But it has important preconditions: the outcome must be observable and measurable; it must be attributable to the firm and, ideally, to the cause; and the harm must be reversible or compensable. Process regulation is the right departure from the default when those preconditions fail and where outcomes are unobservable, harm is catastrophic or irreversible, or damage manifests only systemically or with a lag.

Traditional doctrine treats these preconditions as given: examine the activity, choose the mode. This does not work for AI. Whether an AI deployment's outcomes are observable, attributable, and reversible is an engineering choice, which needs to be settled at design time. We suggest that regulation should mandate observability. This makes it possible to have an "outcome-based supervision" model. There are three ways to ensure observability.

  1. Telemetry implies that the institution keeps a track of every decision such that the system records which version of itself it was using, what information it was given, and any time a person stepped in to overrule it. This makes outcomes attributable. That way if a certain group starts getting more (or less) approvals than before, the organisation can evaluate what caused the shift - was it the model, or the group itself. Such a capability is being mandated elsewhere in the world for similar use-cases (European Parliament and Council of the European Union, 2024). The regulator should also consider if it wants to set a minimum common telemetry standard.

  2. Boundaries and rollback include putting caps on what the system is allowed to do, rolling out new updates to just a small number of cases first (instead of everyone at once), and having a tested plan for switching back to the older version if something goes wrong. This ensures that if a bad update slips through, it only affects a small slice of decisions.

  3. Probes make bias observable. One way is "paired testing": one submits two applications that are exactly the same except for details that hint at things like someone's race or gender, and see if they get treated differently. One can also compare approval rates against the company's own normal levels. Together, these checks can catch an unfair credit model in just a few weeks, instead of waiting years to see who actually pays back their loans. One can also check rejected applicants against credit-bureau data to see which ones got approved by someone else, and how they fared.

These are similar to the idea of decision receipts that record which rules were applied to which facts and in what sequence for every decision made by a government or public system (Srivastava, 2026).

Over time, the supervisor should also build a repertoire of its own test cases drawn from incidents, complaints and examinations across the system and run it against every material AI deployment, much as stress-test scenarios are run against every balance sheet today. This will ensure that what surfaces in one institution becomes a probe for all others. It thus allows the regulator to set its own observability layer.

Process regulation is then reserved for the harms that are systemic, correlated, or irreversible at machine speed. For such events there need to be protections such as circuit breakers that halt things before they cause damage, limits on how much the systems can do on their own, model diversity so they don't all fail the same way, and rehearsed back-up plans.

What follows for the supervisor, the board, and the customer

For the supervisor: The unit of examination shifts from the model to the deployment, and the examiner's question shifts from "show me the validation report" to "show me the behaviour": what boundaries were set, what exceptions were thrown, what overrides were exercised, how far the system drifted from its baseline. Supervisors will also need to find the intellectual clarity to avoid a wide variety of extraneous claims about regulation of AI, e.g. the push for economic nationalism which has nothing to do with market failure.

For the board: A board cannot certify systems it cannot inspect or understand. Its role is to govern the framework which includes the limits on what the system is allowed to do, and making the rules for when a decision must be escalated to a human. The board then needs to continuously check the exceptions and overall performance.

Exception-handling should also be written into policy. If a problem stays unresolved beyond a defined size or time limit, it automatically gets escalated to the board. Internal auditors should double-check that the numbers are real. The board sticks to this audited framework and does not inspect the system directly.

If a board is asked to approve something they can't understand, they will default to saying no. But if you let them govern the limits and the exceptions instead, they can say yes.

The customer: The customer becomes part of the supervisory architecture. The widening firm-to-consumer asymmetry has a structural corrective the pre-AI world lacked: the customer now has AI too. Mainstream assistants abroad have begun connecting directly to users' accounts. If product terms (rates, fees, eligibility criteria) are mandated to be structured and machine-readable, the customer's own AI does the comparing, the explaining, and the policing of mis-selling, continuously and at zero supervisory cost. The redress channel weakened by opacity is restored the same way: an adverse decision should carry its reason to the customer, and what would have had to be different for the answer to change. This restores the ability to contest. The same asymmetry that AI widened, AI-equipped customers can close, but only if regulation hands them the data.

An example

Consider a debt-collection example. When borrowers fall behind on payments, the bank has to decide how to chase each overdue account. Contact methods differ in cost. Automated SMS and IVR (the automated phone system - "press 1 to pay") are cheap; having an employee actually phone the customer is expensive. So the bank builds a model that allocates accounts: cheap automated nudges for most, and the costly human call reserved for the accounts where the model predicts that talking to a person will actually "cure" the account (get it back to paying). Human calling works better but it costs more. The model is rationing an expensive resource to where it thinks it'll pay off.

With AI, the collection systems would retrain continuously or run reinforcement-style optimisation against a live reward (cure rate per rupee spent). The model would be moving on its own, faster than the review cycle, toward a target that is a proxy for what the bank may actually want. Under the conventional "inspect-the-artifact" approach, the model is checked before deployment, signed off, and reviewed on a schedule (say quarterly or annually). However, if AI is an active optimiser, a quarterly review discovers deterioration only after it has touched thousands of accounts. It may drift toward a mis-specified target in a way no one can read off the model itself. Further, if the collections model is a shared vendor product, or several banks fine-tune the same foundation model on similar data, they all go bad the same way at the same time when borrower behaviour shifts. In contrast, in a "supervisability-built in by design" approach, a small slice of accounts is deliberately kept on the previous allocation method, running live alongside the new model. This allows comparison between the old and the new in real time.

Every decision should keep a record of a few things: which version of the AI was used, what action it chose, which group of customers it was dealing with, and how things turned out in the end. This is how it helps: Say the AI's overall success rate is going up, but one particular group is quietly getting fewer phone calls from real people and doing way worse because of it. With all that recorded, that gap shows up right as it's happening. You can compare it against what's going well elsewhere, trace it back to a specific version of the AI, and undo it that same day, because the older setup is still up and running as a backup.

The company should never have to dig into the AI's inner "thought process" to realize its behaviour has taken a bad turn. None of this replaces the normal testing that the firm would do anyway. The difference is that here, the ability to observe what's happening, pin down what caused it, and shut it down are all built right into the system from the start, instead of being things you have to go do to the AI afterward.

Conclusion

AI deployments sit uneasily in conventional mores of banking regulation. The intelligence is rented, the behaviour is probabilistic, and harms can move at machine speed. We suggest that the response should not be more inspection of what cannot be inspected, nor blind faith in outcomes that arrive too late. Efficient regulation will emerge from observability, attributability, and reversibility. Regulators should require banks to build these.

References

Board of Governors of the Federal Reserve System, Federal Deposit Insurance Corporation, and Office of the Comptroller of the Currency. "Supervisory Guidance on Model Risk Management." SR Letter 26-2. April 17, 2026. https://www.federalreserve.gov/supervisionreg/srletters/SR2602.pdf.

European Parliament and Council of the European Union. Regulation (EU) 2024/1689 (Artificial Intelligence Act), arts. 12, 26(6), and Annex III(5)(b). https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-12.

Srivastava, Manish. "Digital Governance Needs Decision Receipts." Episode 73 of Big Ideas. XKDR Forum, June 1, 2026. Podcast, video, 13:06. https://youtu.be/WFX4ITb9yok

Friday, May 21, 2021

India's supply chain vulnerability with Chinese APIs: Industrial policy vs. sophisticated policy design

by Gautam Bambawale, Vijay Kelkar, Raghunath Mashelkar, Ganesh Natarajan, Ajit Ranade, Ajay Shah.

India has a remarkable drugs industry. This involves a high dependence upon Chinese manufacturers of `active pharmaceutical ingredients' (APIs). Given the willingness of the Chinese state to behave in unusual ways in economic engagement (e.g. rare earths), there is a certain supply chain risk that is faced by Indian firms.

Should state power be used in addressing this problem? And if so, how should this be done? How do we avoid the long decades of failure in industrial policy, i.e. the experiments with policy pathways where a government picks winners, with a government that claims to know the correct ways in which production should be organised? Today we saw a fascinating article: Drugmakers cry ‘monopoly’ as Modi govt picks 1 firm each to make over 20 key raw materials by Himani Chandna in The Print. This narrates the story of a 1960s style Indian industrial policy intervention played out poorly.

Our book Checkmate China: Winning through strategic patience and accelerated economic growth is forthcoming from Rupa Publications later this year. A paper based on this book has been released in the public domain and summarises our strategic thinking for India about the China question. In the book, we have a treatment of the API question. This text is excerpted ahead. It represents our attempt at learning from 75 years of failure with industrial policy. This approach would have likely avoided the difficulties described in Himani Chandna's article.

Book excerpt: Designing a government intervention to address the supply chain risk faced by Indian firms that import APIs from China

The Indian drugs industry is a heavy user of Active Pharmaceutical Ingredients (APIs) sourced from China. In an environment where we see China as a bad actor in the global economy, where Chinese nationalism can harm counterparties abroad, this presents a risk to the supply chain. It is easy to design Indian economic nationalism which can combat this. However, as with all aspects of industrial policy, such use of state power raises many concerns. It is difficult for a government agency to know whether a certain industry merits subsidies and whether certain firms merit subsidies. There is a long history, in India, of “infant industry” arguments being used for decades, in which some well-connected Indian firms stay infants and continuously collect fiscal subsidies. Similarly, trade barriers in the form of quantity restrictions are prohibited under the WTO and tariffs are harmful and should best be avoided.

Thus, we face a puzzle: How can state intervention be designed, which can make a difference to India’s China problem with the supply of APIs? Given the failures of industrial policy as it was practiced in previous decades, how can this one sharp problem (supply chain risk faced by Indian pharma companies who rely on Chinese producers of APIs) be addressed by state action? How can this state action be done at the minimum fiscal cost, and while imposing the minimum distortions upon the economy? How can the risk of central planning – of officials determining the outcomes of the market-based competitive process – be avoided?

When faced with supply chain risk with a certain API from China, we should not jump to the conclusion that the answer lies in making the API in India. Perhaps the efficient solution is to import the API from a country other than China. Perhaps the efficient solution is to make it in India. Policy makers cannot assume that India has competitive advantage in making the API, when private persons have thus far chosen to not build such factories in India.

The first step in every policy analysis must be a thorough understanding of the behaviour of the private sector assuming there is zero state intervention. When faced with this new supply chain risk, what are Indian drug companies likely to do out of self interest:

  1. Customers of these bulk drugs would be conscious about the business risk that they carry. They would watch the rise of nationalism in China with concern.
  2. They would increasingly seek to diversify their sourcing. As an example, we are seeing Fortune 500 companies increasingly reduce the share of China in their global production.
  3. One important response by the firms will be to buy APIs from countries other than China, e.g. Taiwan or Japan or Brazil. This is perfectly adequate solution, from the viewpoint of an Indian firm, to the threat of Chinese nationalism. Our problems with Chinese nationalism only imply that we should diversify away from China; this does not justify self-reliance.
  4. One element of the process of looking for non-China sourcing is higher demand for firms in India that make APIs, which would kick off a supply response. Ordinarily, this market process will work itself out. But it is a difficult and slow journey. A government program can be designed that addresses this problem, which has a few key features: (a) We do not assume that in the long run India will be a successful producer of APIs, but we consider this possible; (b) The intervention is pre-announced and in a few years, liquidates itself; (c) The intervention imposes zero trade barriers upon imports or exports of APIs or drugs with respect to any country.

This proposed intervention would involve the following steps:

  • A government agency would identify the top 50 APIs and the quantities $q = (q1, q2, .. q50)$ which are being imported from China.
  • We establish the objective of domestic production that comes up to half of the imports from China over a five year period. This suggests escalation of quantities as: $0.1q, 0.2q, 0.3q, 0.4q, 0.5q$ over a period of five years.
  • We put out a binding commitment on the part of the state that the government will run procurement restricted to domestic producers only, where there will be purchases over the next five years of these quantities. The government will commit to placing orders with 3 lowest-cost firms that produce in India, in each year’s bidding. The requirement from a bidder should be that production is done in India. Foreign or Indian firms should be permissible, subject to a restriction against firms controlled by the Chinese state e.g. bar a firm where any one member of the board of directors is an employee of the Chinese state or the CCP.
  • These commitments about a rising scale of GOI procurement will create incentives for Indian/foreign firms, located in India, to build knowledge and physical capacity to produce APIs at a large scale.
  • The government agency has only one objective: to trigger off economies of scale and competition by producers in India. Once the goods are purchased by the Indian government agency, what is it to do with them? Indian firms might not like to buy these APIs at the purchase price, as the purchase price may well be higher than the world price of these APIs. Once the goods are purchased, this agency would run a global auction to sell the same goods off, at the highest possible price. Indian drug companies could potentially choose to buy these goods, but these purchases would be at an import-parity-pricing price. As a consequence, through this program, the Indian government would be drop shipping the goods, purchased in the make-in-India auction to buyers who came into the sell-from-India auction.

This scheme constitutes a promise to buy from Indian firms, at rising quantities over five years, at the lowest prices that Indian firms are able to muster (3 firms for each product in each year). At first, the price in India will be high. Under this proposal, GOI will instantly turn around and sell off the goods at the highest possible price through a global tender. The gap between the two prices will be the fiscal subsidy that is being put down, to spark off API production in India.

At the end of five years, the domestic firms would be on their own. If the theory of change is correct – that there is a fixed cost of building knowledge and facilities to make APIs – then this is the minimum intervention that gets the job done. If the theory of change is incorrect – that India is not actually a good platform for making APIs – then in five years, this fiscal outgo would end, and India would not be a producer of APIs.

There are many strengths of this design:

  1. Private persons face no new coercion, other than the coercion implicit in mobilising tax resources which are the source of government spending on this program.
  2. There is no tariff; there is no interference in international trade. This program is layered on top of a free trade system.
  3. It is a simple and transparent intervention. What it requires is the bureaucratic capability in the Indian state to do procurement: to run these auctions, to buy APIs in India, and to sell the same goods globally, doing high volumes of non-complex commodities. Indian officials are not asked to form a judgement about what APIs are important, about whether an API can efficiently be made in India, about the technology through which an API can be made, about whether public money should be used to build factories to make APIs.
  4. There is a lack of fudge factors where there can be lobbying and negotiations.
  5. No central planner should ever assume s/he knows the way forward. This design respects the possibility that India might actually have no place in API production. In this case, at the end of this program, there will be no API manufacturing in India. The program would have wasted taxpayer resources, but it would not distort the economy.

However, there are four main difficulties of this design:

  1. For the desired impact upon incentives of private firms who should commit themselves to investing in building large scale API production, the private sector would have to believe that the deeds of the government will match the words of the government over the coming five years. If private persons feel that the Indian state cannot be trusted to stay the course for five years, then the incentive impact of the government program would not materialise.
  2. The private sector has to feel safe engaging with government procurement; it has to believe that the procurement will be done correctly, that payments will be made on time, that there will be no investigations by agencies.
  3. If this works, at the end of five years, Indian API vendors will lobby to not shut this down. Every policy designed to support an infant industry ends up with entrenched infants who like to wield state power in their favour.
  4. While the objective of the program should be to foster Indian or foreign firms who choose to produce in India, there is the possibility that this could be skewed to favour Indian firms.

Tuesday, November 13, 2018

There be dragons: Off-balance-sheet liabilities of the Indian State

by Ila Patnaik and Ajay Shah.

Conventional fiscal stability analysis looks at the stock of debt and wonders whether a country can pay off this debt, under reasonable scenarios for future interest rates and fiscal surpluses. In many countries, though, the fiscal sustainability story has turned on promises made by a government which were not explicitly counted in the debt. There are obvious liabilities that are kept off the books - such as debt in public sector companies or state electricity boards. In this article we look deeper, at less obvious ways in which off-balance-sheet liabilities have arisen, and the checks and balances that can contain them.

Off balance sheet liabilities of the government


Off balance sheet items come in two kinds.

  1. A promise that looks like the cashflows on a bond. Example: A pension promise to a person is no different from a series of coupons that are paid out every year. Promising a pension is exactly like issuing that comparable bond.
  2. A promise that looks like an option payoff. Example: If a government is in hock to pay the lenders of a firm when it goes bankrupt, it is much like being the seller of an option. When governments write guarantees, this changes the risk profile of the exchequer and generates possibilities of large payouts when those options mature in the money.
    It should be noted that organisations backed by statute are not automatically backed by a government guarantee. As an example, in the UTI crisis of 2001, the government had no legal obligation to make good the losses of investors, but a political decision was made to use fiscal resources to pay half the loss. There is a mixture of financial risk ("Will X get into trouble?") and political risk ("Will the government backstop X?").

A correct reckoning of the liabilities of a government should add in these off-balance-sheet liabilities of both kinds. The FRBM Act brought control on one kind of off-balance-sheet liability of the Indian State: explicit guarantees given by the government. But there is more to the problem of off-balance-sheet liabilities than explicit guarantees.

Differences in cost versus differences in transparency


In the field of pensions, an interesting distinction is made between an unfunded defined benefit program vs. a funded defined benefit program that has assets invested in government bonds. In the conventional wisdom, a funded DB program is always superior to a pay-as-you-go unfunded program.

However, these two approaches are exactly the same in terms of the cashflows: both involve a highly predictable set of claims on the exchequer at future dates. To promise a pension is to implicitly issue a bond. This equivalence, between the cashflows of a bond and the cashflows of a pension, has an interesting implication. Consider a funded DB public pension program that invests in government bonds. The two streams of cashflows cancel out.

This approach to funding (holding government bonds) does not make things cheaper: it is only superior in that it is transparent and connects into the fiscal planning process. Cost savings only come about when a funded DB program invests in higher return assets, such as equities, through which the claims upon the exchequer at future dates are reduced on expectation.

What are the important off-balance-sheet liabilities of the Indian State?


Some important components of the off-balance-sheet liabilities are:

  • Promises made for defined benefit pensions of civil servants, in particular the new `one rank one pension' (i.e. wage indexed) pensions for uniformed folk, and the underfunded `Employee Pension Scheme' (EPS) that is run by the EPFO. For the civil servants recruited after 1/1/2004, there is no such problem, as these new recruits are in the New Pension System.
  • Promises made in a variety of health-related entitlement programs (Patnaik et. al., 2018).
  • The temptation to make good the promises made by public sector financial firms, that experience distress in the future, even when there is no explicit guarantee. Of these, LIC has a balance sheet of Rs.28 trillion.
  • The temptation to make good the promises made by private financial firms that experience distress in the future, even when there is no explicit guarantee. As an example, will the failure of IL&FS -- a private financial firm -- induce a direct or indirect fiscal impact upon the exchequer? So far, the government has not put money on the table, but could this change?
  • The use of fiscal resources in responding to a full blown financial crisis, that may occur at a future date.
  • The Parliament has enacted many laws, which could potentially evolve into large inflexible expenditures. These include `Right to education', `Right to food' and NREGS. On a similar note, the promises which are being made under `minimum support price' (MSP) could turn into large expenditures if the future brings together a certain combination of political pressures, jurisprudence and development of State capacity. Until repeal, these laws are a genotype that could, under the right combination of events at future dates, get expressed in a way that involves major fiscal risk.

These liabilities add up to large sums of money, of the same order of magnitude as the overt stock of public debt. Hence, off-balance-sheet liabilities should become more prominent in the Indian fiscal discourse.

How do the incentives of politicians and officials change?


At present, there is no check-and-balance influencing these opaque promises and risks. Each party in power looks to enter into greater off-balance-sheet obligations so as to get re-elected. How might this change?

The key thing that shapes these incentives is financial repression. At present, government debt is mostly sent into involuntary lenders. When the fiscal system graduates from financial repression to voluntary lenders, off-balance sheet liabilities would matter. There are numerous gains from removing financial repression: voluntary borrowing is more efficient than forced borrowing, the magnitude of resources available in a crisis would become greater, etc. But this requires a government that faces a skeptical bond buyer who demands a risk premium based on the extent to which the Indian State may engineer inflation or default.

In India today, there are many loose ends, which periodically induce fiscal surprises. This creates an adverse risk profile of Indian government bonds, and would drive up the required interest rate for borrowing when faced with voluntary buyers of bonds. In such a world of market discipline, when a government dips into LIC's resources, this would induce a higher cost of borrowing.

In India today, most of the attention in fiscal reforms lies upon tax policy reforms, such as the GST and the Direct Tax Code, and there is some interest in FRBM. There is much more to a mature fiscal system, including the issues of tax administration, debt management, the bond-currency-derivatives nexus, off-balance-sheet liabilities, accrual-based accounting, and the budget process. We need to broaden our research and policy work to address this full range of problems.

Tracking and understanding off-balance-sheet liabilities, communicating them to lenders, and communicating these concerns back into the budget process, is part of the work program of the future Public Debt Management Agency (PDMA) (Pandey and Patnaik, 2017). A Fiscal Council will help. Accrual based accounting will help.

Once we start paying attention to off-balance-sheet obligations, this creates fresh impetus for economic reform in many areas. As an example, if a monsoon failure induces a farm loan waiver paid for by the government, this is like a monsoon derivative that has (maybe) been written by the government. When reforms of personal insolvency and reforms of agriculture remove this possibility, the risk profile of the Indian exchequer will improve, and the cost of borrowing will go down.

Off-balance-sheet liabilities and financial reform


There is a close connection between public finance and finance, centering around the government bond market and the PDMA. For public finance, PDMA and the government bond market are the source of debt. For finance, the PDMA is the biggest investment banker of the country and the government bond market is the tool for low risk transfers of resources across time. What is less widely noticed is the intimate connection, between public finance and finance, through the question of off-balance-sheet liabilities.

How will off-balance-sheet liabilities change when micro-prudential regulation improves and the resolution corporation is setup? Financial firms will face distress less often, we will discern that distress early, and we will have an institutional mechanism to put the distressed firm down. Conversely, under present conditions, we get surprised by the difficulties in an IL&FS or in a UTI. These crises lead to a political question being thrust upon the leadership: Will you make liability-holders happy by using taxpayer money? We should, of course, have a mature political system which is able to turn down such requests most of the time, but we should have a mature financial regulatory system so that these situations do not arise in the first place.

Governments worldwide have faced claims on fiscal resources when dealing with full blown financial crises. The probability of occurrence of such crises, and the severity of such crises, is shaped by the institutional capacity in systemic risk regulation. The FSLRC apparatus for systemic risk regulation -- the Financial Stability and Development Council (FSDC) and its information system, the Financial Data Management Centre (FDMC) -- will reduce fiscal risk and thus the cost of government borrowing. As an example of the work program which should take place through FSDC/FDMC: At present, we have the possibility of runs on mutual funds (Sane et. al., 2018), which can lead to a full blown financial crisis, which requires policy thinking and reforms on a financial system scale.

Our objective in financial economic policy should be: to be as sparing as possible in ever asking for resources from public finance policy. For a sound fiscal system, we require financial sector reform. This will have a beneficial impact upon contingent off-balance-sheet liabilities and thus the cost of borrowing.

The need for a research community and a research literature


A remarkable feature of the existing Indian policy process is that no fiscal estimation was done in the policy process that led up to the announcements  about one rank one pension, or the various health insurance programs.

Even if policy makers had tried to reach into the research community to obtain such estimates, the state of data and knowledge is weak, and it is difficult for policy makers to obtain policy support from researchers. Some early work on the civil servant's defined benefit pension (Bhardwaj and Dave, 2005), one rank one pension (Sane and Shah, 2015) and banking (Shah and Thomas, 2000) is available. Much more needs to be done in this important field.

In an ideal world, record level data would be available from the government which would permit estimation of the value of the implicit debt or the implicit derivatives that the government has issued. The state of information systems and transparency of government is often a bottleneck, and creative research strategies have to be employed. As an example, Bhardwaj and Dave, 2005, utilise data from a national scale household survey to identify present and future beneficiaries of the traditional DB civil servants pension, and extrapolate the sample estimates to an estimate of the implicit pension debt associated with the traditional civil servant's DB pension. Similarly, Shah and Thomas, 2000, exploit information in stock prices to estimate the equity capital gap in banks, which helps overcome the opacity of banks and banking regulation.

A research community is required, which will build a research literature in estimating these expenditures based on exploiting diverse datasets. There will, of course, be multiple different estimates, as different researchers search for useful approximations through different assumptions and modelling strategies. A coherent picture will emerge from these debates. The PDMA, and buyers of government bonds, will be important users of this research community.

Off balance sheet liabilities and GDP growth volatility: A conjecture


There is a big gap between short spurts of GDP growth and sustained GDP growth. A mature market economy is a turtle, it plods along for a century, obtaining a low rate of growth on average, and harnessing the power of compounding. Poor countries fail to get sustained growth. The striking fact in cross-country comparisons is how volatile the GDP growth of poor countries is.

What might be going on? An analogy from a different field is useful. A well known problem in financial portfolio management is the returns that can be obtained, in the short term, by selling out-of-the-money options. For some time, the option seller seems to make a lot of money. But in time, some of those options get exercised and the portfolio gets into a lot of trouble. In similar fashion, for some time, a government that takes on option-like off-balance-sheet liabilities can gain votes and possibly accelerate economic activity, at the cost of sustainability.

Perhaps one element of the high GDP growth volatility of poor countries runs as follows. Mature fiscal systems create checks-and-balances which reduce the extent to which debt or off-balance-sheet liabilities can surge. Perhaps less developed countries have weak institutions, and then the political leadership sees a different optimisation. Short bursts of GDP growth can then be achieved in many bad ways, such as a surge in debt, piling up off-balance-sheet liabilities, etc. But this is not sustained growth: We get a spurt of high growth, and then things go wrong. This yields one more element of the translation of bad institutions into high GDP growth volatility.

References


Bhardwaj, Gautam and Surendra A. Dave, 2005. Towards estimating India's implicit pension debt, Working paper.

Pandey, Radhika and Ila Patnaik, 2017. Legislative strategy for setting up an independent debt management agency. NUJS Law Review, 10(3).

Patnaik, Ila, Shubho Roy and Ajay Shah, 2018. The rise of government-funded health insurance in India. NIPFP Working paper.

Sane, Renuka and Ajay Shah, 2015. What is the cost of one-rank-one-pension? The Leap Blog.

Sane, Renuka, Ajay Shah, Bhargavi Zaveri, 2018. Runs on mutual funds, The Leap Blog.

Shah, Ajay and Susan Thomas, 2000. Systemic fragility in Indian banking: Harnessing information from the equity market. IGIDR Working Paper.



The authors are researchers at the NIPFP in New Delhi. We are grateful to Shubho Roy, M. Govinda Rao and Arbind Modi for useful discussions.

Monday, August 06, 2018

Placing surveillance reforms in the data protection debate

by Rishab Bailey, Vrinda Bhandari, Smriti Parsheera and Faiza Rahman.

Introduction

On July 27, 2018, the Committee of Experts constituted by the Government under the chairpersonship of (Retd.) Justice B.N. Srikrishna (Srikrishna Committee) released its report and the Personal Data Protection Bill, 2018. The Committee's recommendations make some headway in proposing legal reforms governing the use of personal data by intelligence and law enforcement agencies (LEAs), but fall short of offering a comprehensive solution (Bhandari, 2018).

Against this backdrop, our working paper on "Use of personal data by intelligence and law enforcement agencies" provides an overview of the existing framework on surveillance in India followed by an inquiry into how these laws and practices fare against the tests that were endorsed by the judges in Puttaswamy, the Supreme Court's right to privacy verdict. As we have previously noted on this blog, India currently does not have a comprehensive law regulating intelligence agencies/ LEAs, including on aspects such as the creation, composition, powers, functions and accountability of such bodies. What we have instead are separate provisions contained in the Telegraph Act, the Information Technology Act (IT Act), and the Criminal Procedure Code that enable government agencies to initiate lawful search and interception activities, based on the fulfilment of certain parameters. While assessing these laws and practices against the tests of legality, legitimate aim, proportionality and procedural safeguards identified in the Puttaswamy decision, we find the existing framework to be lacking in many respects.

The inadequacies of our current system become all the more evident when examined against the laws and practices of other jurisdictions that have worked harder to strike a balance between the civil liberties of individuals and the State's requirement to pursue legitimate surveillance activities. The general practice across jurisdictions is that privacy and data protection laws are also applicable to state intelligence and security agencies, albeit subject to certain exceptions (ICDPPC Census, 2017). It is important to keep in mind however, that exceptions are not all-encompassing or generic, and are usually to be applied in a proportionate manner.

In this post we highlight what can be regarded as legitimate and fair surveillance practices that are appropriate for the functioning of a democratic system. Based on a review of the current framework against the Puttaswamy tests and identified fair practices, we offer some recommendations on the next steps towards implementing holistic surveillance reforms in India. We also map these recommendations against the recommendations in the Srikrishna Committee report and the provisions of the draft law, and delineate how the draft law needs to be strengthened.

Principles of fair surveillance: International experience

International frameworks on surveillance have seen considerable development over the last decade. This has been due to changing technology and law enforcement needs, as well as instances such as the Snowden revelations that have led to greater global awareness about the need to adapt surveillance laws and practices to the modern communication era. Attempts have been made, at both the global and national level, to enhance the respect for privacy rights, through changes to statutes as well as through advocacy instruments such as the Necessary and Proportionate principles. Nevertheless, as observed by the UN Special Rapporteur on the right to privacy, no single surveillance related legislation perfectly complies with, and respects privacy rights (Joseph Cannataci, 2018).

The most commonly seen mechanisms used to ensure that LEAs/intelligence agencies act within their remit and with due respect to privacy rights include:

  1. Judicial oversight: As a general rule, countries such as the United States (US), the United Kingdom (UK), New Zealand, Australia, Germany and Canada require prior judicial authorisation for initiating surveillance activities. Often greater protections are put in place for the protection of rights of citizens as compared to foreign subjects, although both cases may require a certain level of judicial scrutiny. For instance, in the US designated courts under the Foreign Intelligence Surveillance Act have been created to authorise foreign surveillance activities. While this ensures a certain degree of oversight it should be kept in mind that these proceedings have been criticised for the lack of transparency and accountability.
  2. Oversight by legislature and independant bodies: Institutions such as Parliaments and Congress generally have extremely wide powers of supervision over the activities of LEAs/intelligence agencies, often through specific committees of panels charged with oversight. For instance, the US Congress has general powers of review over intelligence agencies. In Germany, the Parliament has a panel known as the Kontrollgremiumgesetz, while the UK has established an Intelligence and Security Committee. Both these countries have also established independant regulators to oversee the activities of LEAs/ intelligence agencies - the Office of the Investigatory Powers Commissioner and the G-10 Commission, respectively. Importantly, in addition to having access to the activities of agencies (which can extend to ex-ante reporting requirements), these bodies also publish regular public reports in pursuance of their oversight role. Further, the LEAs/ intelligence agencies themselves may also be subject to reporting requirements. In addition, transparency reports are often put out by intermediaries who receive information requests from these agencies.
  3. Implementation of redress mechanisms: While some countries such as Canada, Germany, Belgium and Austria, provide notice of surveillance to the subject in certain cases (thereby allowing processes to be challenged by the concerned individual), others create mechanisms to enable challenges to illegal surveillance through other means. For instance, the US, empowers electronic communications service providers to file petitions before the FISA Court to set aside directives issued by intelligence agencies under the FISA Act. In Europe however citizens may approach redress forums without concrete evidence of having been the subject of surveillance measures. (Klass v Germany, (1979-80) 2 EHRR 214).
  4. Implementation of organisational safeguards: The US, Germany and the UK have also implemented various administrative and technical safeguards to ensure adherence to privacy norms - ranging from embedding privacy/ethics officers within agencies, to implementing masking and other technical measures to ensure intrusions into privacy are minimised.

Key design principles for India

On mapping the legal framework and practices on surveillance in India against the Puttaswamy tests and globally recognised surveillance principles, we find our current framework to be lacking in many respects. The present set up is not well suited to meet the requirements of a system that guarantees the constitutional right to privacy or, for that matter, one that has limited state capacity in carrying out effective surveillance activities. We therefore need a system that is designed in a manner where the resources of the surveillance machinery can be optimally utilised without undue infringements into the right to privacy. Addressing these issues requires both a reassessment of the current legal framework as well as a re-evaluation of the philosophy that drives surveillance related activities by intelligence agencies and LEAs in India.

A risk-based approach to surveillance

The broad path towards safeguarding civil liberties in a system with limited state capacity lies in adopting a risk-based approach to surveillance. Countries such as the US and the UK have already moved in this direction by embedding certain risk management techniques within their surveillance architecture (Omand, 2010). This approach recognises that any country's resources are limited and therefore the surveillance architecture should focus on credible risks, whether they be reputational or operational. Apart from calibrating responses to the risk posed by different threats, this sort of an approach also takes into account broader risks such as the risks to privacy and other civil liberties, reduction of international trust in domestic firms and the impact of intelligence operations on relationships with other countries (Clarke et al., 2013).

We recommend that the Indian surveillance framework should also adopt systematic risk management as a key design principle to balance national security and privacy on one hand and limited state capacity issues on the other. The report of the Srikrishna Committee also endorses this recommendation, although the draft Bill, notably, is silent on this aspect.

Changes to the legal framework

India needs to build a robust legal framework governing the functioning of intelligence agencies. This requires the creation of a statutory framework governing intelligence agencies and LEAs, including their constitution, composition, powers and the accountability measures expected to be followed by them. The Srikrishna Committee's report recommends that the "Central Government carefully scrutinise the question of oversight of intelligence gathering and expeditiously bring in a law to this effect". It then goes on to state that although these recommendations are not directly made a part of the data protection law proposed by the Committee, they are important for the effective implementation of data protection principles and must be urgently considered.

While a data protection law may not be an appropriate site for pursuing a comprehensive reform of intelligence agencies and LEAs, there are several critical changes that can be adopted through the data protection law as well as amendments to existing laws that impact surveillance. We set out below specific recommendations that will help to ensure that any intrusion into an individual's right to privacy by state surveillance is in consonance with the principles in the Puttaswamy case.

  1. Prior judicial review: Present Indian laws confer wide powers on the executive in terms of deciding the scope and manner of surveillance. Intelligence agencies and LEAs initiate requests for surveillance, which are then authorised by another executive agency - the Home Secretary in the Central and State Governments). Oversight of authorisation is also done by an executive agency - the Review Committee established under the Telegraph Rules. The decision in Puttaswamy held that any intrusion by the state in an individual's privacy rights is permissible only if it is supported by a "fair, just and reasonable procedure established by law". A process that is driven solely by one arm of the state mitigates from the system of checks and balances that is necessary to satisfy this criteria. We therefore recommend that the current processes need to be amended to incorporate an element of prior judicial review (or post-facto judicial scrutiny in emergency cases). This review may be conducted through specialised courts designated for this purpose or by judicial members of an independent body, such as a Data Protection Authority. The role of this body would be to apply the principles of legality, lnecessity and proportionality in each and every case to ensure that the nature of surveillance, its duration and scope is in line with the purpose that is sought to be achieved. Further, a mechanism for filing an appeal against the decision of the judicial body must be provided. The adoption of the proposed structure would require corresponding amendments to the Telegraph Act, IT Act and the rules thereunder.
  2. Reporting and transparency by LEAs: Current laws need to be amended to ensure appropriate reporting and transparency requirements are implemented pertaining to all surveillance activities. These requirements may differ depending on the nature of information and the entity to which it is being provided (for instance, to the Parliament or the public). Reporting must be on both ex-ante and post facto basis, as may be relevant to the circumstances. Further, oversight bodies must also be required to publish periodic reports of their activities and that of LEAs/ intelligence agencies under their supervision, while service providers must be permitted to publish aggregated statistics detailing volume and nature of surveillance requests.
  3. Implementation of data retention norms, principles of fair processing: Principles of fair processing must be applicable even to data processed by intelligence bodies/LEAs. They must also ensure that as far as possible, personal data is up to date and accurate, while data retention norms need to be appropriately designed to ensure only relevant data is stored by the authorised agencies.
  4. Notice to the data subject: In order to achieve a balance between the objectives of surveillance and the rights of the data subject, the law should provide for an obligation to ensure that the affected data subjects are notified after completion of the surveillance. However, the agency may seek the approval of the judicial body to delay or avoid the requirement of notice under certain exceptional circumstances, for instance if it can be established that such a disclosure would defeat the purpose of surveillance.
  5. Right to seek redress: The requirement of notice to the data subject must be accompanied by a right to challenge and seek appropriate redress against surveillance activities. This right should extend to a person who is, or has reasonable apprehension of being, the subject of surveillance. In addition, intermediaries that are required by law to facilitate access to information by LEAs should also have the legal right to question the scope and purpose of the orders received by them.
  6. Privacy officers in LEAs: Independent officials must be appointed to the intelligence agencies and LEAs to scrutinise requests for surveillance (before they are placed before the sanctioning judicial body). Such scrutiny must be recorded in writing and available to relevant oversight bodies (if not the public).
  7. Technical measures to enhance privacy: Technical measures and privacy by design principles must be used to inform surveillance procedures and ensure proportionality and due process. This may imply for instance, the use of masking techniques to protect identities of citizens caught up in bulk surveillance of foreign intelligence, ensuring collected data is encrypted, acess controls, etc.
  8. Evidentiary value of information collected in breach of data protection law: Illegality in conducting search and surveillance activities does not lead to a bar on the admissibility of that evidence in subsequent proceedings under Indian law. Consequently, the incentives of LEAs are not fully aligned with the objective of ensuring that the legal processes governing surveillance are strictly followed. This will continue to pose a challenge even if privacy safeguards are introduced in the law. We therefore recommend that relevant laws should be amended to bar the admissibility of any information that is obtained by the agencies in breach of the proposed data protection law and other surveillance related laws.
  9. Revisiting telecom licenses: Telecom licenses contain specific provisions relating to the obligations of telecom service providers (TSPs) to facilitate lawful interception activities. We recommend that to the extent that any of the provisions contained in telecom licenses create additional restrictions on the privacy rights of individuals, these provisions need to adopted through legislative instruments. Further, we recommend that the terms of telecom licences also need to be revisited in so far as they contain restrictions on the encryption standards that can be adopted by TSPs, which in turn limits the privacy rights of their users. The Telecom Regulatory Authority of India's (TRAI) recent recommendations on data protection indicate a positive move in this direction. The regulator recommended that the Department of Telecommunication needs to reexamine the encryption standards laid down in the telecom license conditions. It noted the need for personal data of telecom consumers to be encrypted, both during storage and in motion. Further, TRAI recommended that decryption by authorised entities should be permitted on a needs basis, either with the consent of the consumer or in accordance with legal requirements.
  10. Transparency regarding standard operating procedures (SOPs): We recommend that any SOPs formulated by the Government to give effect to the provisions governing surveillance must be made publicly available and stakeholders should also be given an opportunity to contribute to their framing. To the extent that the SOPs might create any independent obligations on individuals or intermediaries, we recommend that the same should be supported by a legislative instrument.
  11. Amendments to other laws: Provisions of the Whistleblowers Protection Act, 2011 need to be revisited to ensure adequate protection is given to whistleblowers who expose mala fides or illegalities in surveillance procedures. In particular, the general exemptions granted under the statute (to matters impinging on sovereignty or strategic interests of the state, disclosures under the Official Secrets Act, 1923, etc) may need to be revisited. Similarly, revisions may be required to the generic exemptions granted under the Right to Information Act, 2005, to various LEAs.

Reviewing the Srikrishna Committee's proposals

The Srikrishna Committee's draft law proposes protections relating to the collection, processing and use of personal data of individuals (referred to as data principals) and offers remedies from related harms. The draft law defines "harms" to include (i) any restriction placed or suffered directly or indirectly on speech, movement or any other action arising out of a fear of being observed or surveilled; and (ii) any observation or surveillance that is not reasonably expected by the data principal.

Sections 42 and 43 of the draft law deal with the processing of personal data in the (i) interests of the security of the state; and (ii) for prevention, detection, investigation and prosecution of any offence or any other contravention of law, respectively. In both these cases the identified activities are exempted from the requirements under the draft law if they satisfy the requirements of legality, necessity and proportionality. The exemption, however, does not include the requirement to ensure that any personal data is processed in a fair and reasonable manner (Section 4) and in accordance with reasonable security standards, including methods such as de-identification and encryption of the data and prevention of misuse and unauthorised access (Section 31).

In drafting these provision, the Committee has reiterated the position laid down by the judges in Puttaswamy, but without addressing the related structural and procedural elements required to make these principles work. For instance, the requirement of legality is incomplete without a description on what constitutes legality in case of access by intelligence agencies/ LEAs. Should it include only legality of the means of access or also require the need for a legislative basis for the agencies to whom such access is provided? Similarly, what factors should be taken into account to judge whether a proposed intervention is "necessary and proportionate" in the facts of the case? Who should be making this determination?

In the context of discussing the exemption of measures taken to ensure "security of the state", the Committee proposes that the law should provide for ex-ante access controls by designating a district judge to hear requests for processing of personal information by intelligence agencies in closed door proceedings. It also proposes that such approvals should be time-bound and require periodic renewal, subject to the judge being satisfied that the purpose for processing remains relevant. Further, the report talks about ensuring accountability through ex-post periodic reporting and review by a parliamentary committee.

The recommendations of the Committee point in the right direction, but their effectiveness is marred by the suggestion that such measures be adopted if and when the Government decides to pursue a comprehensive law governing intelligence agencies. Given that surveillance activities are already taking place, the immediate requirement would be to make amendments to the laws that enable such access to personal information by intelligence agencies and LEAs, namely the Telegraph and IT Act and the rules thereunder. The draft law proposed by the Committee already suggests some amendments to provisions contained in the IT Act and the Right to Information Act, 2005. The logical step would have been to at least incorporate similar suggestions on amendments to existing surveillance related laws to build in the safeguards suggested in its report regarding ex-ante analysis and ex-post accountability for surveillance related activities.

In terms of our other suggestions, the draft law includes an obligation of fair and reasonable processing and ensuring security of data even when such processing takes place under the given exemptions. It, however, fails to recognise other important requirements like having data protection officers inside intelligence agencies and LEAs; (deferred) notice to the concerned individual, and the right to seek appropriate redress. Further, the draft law also fails to address the issue of the evidentiary value of information collected in breach of the proposed data protection law.

Conclusion

The draft law proposed by the Srikrishna Committee has tremendous scope for improvement, both in terms of strengthening the protections available to individuals who are subjected to surveillance activities as well as the structural and procedural safeguards governing such access. Having said that, we also believe that the recommendations contained in the report, particularly on ex-ante and ex-post safeguards against surveillance, are an important starting point for this discussion. To take these suggestions to their logical conclusion, it is important that corresponding amendments should be made to the draft before it shapes into a bill that can be placed before the Parliament.

References

Committee of Experts under the Chairmanship of Justice B.N. Srikrishna, A Free and Fair Digital Economy: Protecting Privacy, Empowering Indians, 2018.

Committee of Experts under the Chairmanship of Justice B.N. Srikrishna, Personal Data Protection Bill, 2018.

David Omand, Securing the State: A Question of Balance, Chatham House, 8 June, 2010.

International Conference of Data Protection Privacy Commissioners (ICDPPC), Counting on Commissioners: High level results of the ICDPPC Census 2017, September, 2017.

Joseph Cannataci, Working Draft Legal Instrument on Government-led Surveillance and Privacy, 2018.

Richard A. Clarke, Michael J. Morell, Geoffrey R. Stone, Cass R. Sunstein and Peter Swire, Report and Recommendations of The President's Review Group on Intelligence and Communications Technologies, Obama White House, 12 December, 2013.

TRAI, Recommendations on Privacy, Security and Ownership of the Data in the Telecom Sector, 16 July, 2018.

Vrinda Bhandari, Data Protection Bill: Missed Opportunity for Surveillance Reform, The Quint, 28 July, 2018.

 

Vrinda Bhandari is a practicing advocate in Delhi. Rishab Bailey, Smriti Parsheera and Faiza Rahman are researchers in the technology policy team at the National Institute of Public Finance & Policy.

Thursday, November 10, 2016

Early trends in election results and financial trading

by Rajeeva Karandikar and Ajay Shah.

Financial markets and the Trump victory


Donald Trump's election victory was an unpleasant surprise for the financial markets:


On equity index futures markets, the NASDAQ and S&P e-mini futures hit their price limits and for some time, effectively stopped trading. These are dangerous situations, for as is well known in the field of risk management, these `circuit breakers' convert price risk into liquidity risk, which is in many ways a bad deal. When a market stops trading, all risk management stops.

Financial markets in the Indian general elections


On 17 May 2004, when the UPA won the election, this was quite unexpected; most people had expected five more years for the NDA. Nifty crashed dramatically and the risk management systems of financial market infrastructure institutions were tested like never before (or after). High frequency data for that episode is presently not available, hence we're not able to look inside that day.

In 2009, the election result was a positive surprise, when the UPA made it across the finish line with a weakened CPI(M). We have decent data for this day, so here are some pictures. The market was ecstatic:


The turnover on the equity index derivatives market surged:


This reminds us how important trading on such days is to financial market participants, and to the managers of financial market infrastructure institutions. These were also turbulent times, with wide fluctuations of the spot-futures basis and violations of put-call parity on options markets.

Experiences in state level elections


In November 2015, the Bihar elections threw up a surprise. Till about 10am (two hours after counting started), most TV channels were reporting that BJP and allies are ahead of JDU-RJD. Only after about 11 am, a stable picture emerged.

The early hours of counting have been misleading many times. In the last UP elections (in 2012), till about noon (4 hours after counting started) it appeared that the SP would fall well short of the majority mark and BJP would do rather well. By 10 AM, NDTV and Times Now were projecting 180 seats for SP and 100 seats for BJP. There were celebrations at the BJP HQ. In the end SP got 225 seats and BJP 50.

Can elections overwhelm financial markets infrastructure?


Imagine if, on 15th May 2014, when the counting of votes for the Lok Sabha elections had begun, the early picture as reported on TV stations was very different from final outcome. Imagine if the early indicators were showing that we were headed towards a hung Parliament. The market would have crashed. Later in the day, when the full picture emerged, the market would have swung dramatically.

Even with state elections, sometimes, the stakes are very high. Consider the coming UP elections. The BJP won 73 of 80 seats from UP in 2014. The possibilities for the BJP in 2019 critically hinge on their being popular in UP. The market will thus be watching UP closely, interpreting it as a leading indicator about the 2019 general elections.

Why might early results diverge from the final answer?


Before 1999, when elections worked with pieces of paper, early trends were a statistically good predictor. The counting methodology was to first mix all the ballot papers, and divide them in 10-12 parts which would be counted, one at a time, over roughly two days. Each of these lots (which was called "a round") was a large random sample of votes from each constituency. It is not surprising that early trends often prevailed. In 1998 and 1999, we (Rajeeva Karandikar and Yogendra Yadav) had done well by making predictions on Doordarshan about the national tally based on early counting trends.

Things have changed with the induction of Electronic Voting Machines (EVMs). They now take up one booth at a time, which is not random sampling.

Most TV channels get the counting data from one syndicated source. Viewers see the same message in numerous channels, and get lulled into the feeling that the answer is correct as it has come from multiple sources. However, this one source has had methodological problems. This is also introducing errors in the early trends.

This appears to have been at work in the surprises of the UP election in 2012. A similar situation prevailed on the counting day in Bihar 2016 elections, the difference being that on TV channel which was using its own reporters were able to report the correct picture early on.

The way forward


This article is a plea to participants in financial markets to use early trends more carefully. Wait till noon before believing what you are seeing.

Alternatively, the risk management system of clearinghouses may find it useful to have larger collateral for these few days. After all, the only day when the modern Indian financial market system was really stressed was 17 May 2004.

With EVM-based elections, the counting process is pretty rapid. Perhaps we are better off with a brief pause in trading from the start of counting to its end. The Election Commission, and the exchange institutions, should think about these possibilities.



Rajeeva L. Karandikar is Director at Chennai Mathematical Institute. Ajay Shah is a resarcher at the National Institute for Public Finance and Policy.

Monday, January 20, 2014

The problem of unhedged currency risk of corporate India: Comments on the recent RBI `regulation' on the unhedged currency exposure of the customers of banks

How do firms get exposed to currency risk?


Many people think that a firm gets exposed to currency risk owing to imports, exports and foreign borrowing. This is an incomplete picture.

Suppose a firm switches from importing steel to buying imported steel from a domestic dealer. Does this change anything about its exposure to the world price of steel, expressed in rupees? The key insight is that things that can be traded across the border easily have `import parity pricing': the Indian price is just the world price multiplied by the exchange rate. There is no Indian price of steel. There is only the London Metals Exchange (LME) price of steel, multiplied by the exchange rate. An Indian firm may buy or sell steel against a domestic counterparty, but it experiences currency exposure exactly as if it were importing or exporting steel.

For all products where cross-border goods arbitrage works well, i.e. for all `tradeables', the Indian domestic price is close to the world price expressed in rupees. These product prices fluctuate with the exchange rate. These transactions are influenced by the exchange rate -- even if the buyer and seller are both domestic firms.

What is the currency exposure of the representative firm that processes tradeables? We can obtain intuition through a simplified calculation. Let's assume a firm consumes tradeable raw materials and makes a tradeable output. The typical values for an Indian non-financial firm in 2011-12 were:

Total income100
Raw materials purchased58.45
Other operating expenses27.66
Operating profit13.88

I'm making the simplifying assumption that this is a firm like an engineering firm, which consumes tradeable raw materials and sells a tradeable like a ball bearing. Simplifying assumptions have been used above, such as merging the purchase of finished goods into the `raw materials purchased', and treating all energy expenses as `other operating expenses' even though some of this is tradeable.

By the logic of import parity pricing, for all practical purposes, this firm imports Rs.58.45 and exports 100. This is because there is no difference between selling Rs.100 of ball bearings on the domestic market vs. exporting ball bearings as the Indian price of ball bearings is the same as the world price of ball bearings (as ball bearings are tradeable and goods arbitrage is feasible). Similarly, for all practical purposes, this firm is an importer of Rs.58.45 of imported raw materials. That is, it's in the tradeables processing business; what it does is tantamount to importing raw materials, adding value, and re-exporting the output.

For all practical purposes, this firm has the currency exposure owing to its net exports, i.e. the exposure of someone who exports Rs.41.55. Suppose the INR/USD depreciated by 10%. The total income of the firm would go up to 110 and the raw materials purchased would go up to Rs.64.295. Other operating expenses are non-tradeable and would not budge, in partial equilibrium. Hence, the operating profit would become 110-64.295-27.66 or 18.045. This is an increase of Rs.4.16 which is the same as 10% of the net exposure of Rs.41.55. For all practical purposes, the firm is a plain and simple exporter with exports of Rs.41.55.

This gives us one useful insight: If all raw materials are tradeable and if all finished goods are tradeable, on average, the non-financial firms of India have the currency exposure of an exporter, and stand to gain from depreciation.

This analysis helps us think about measurement of currency exposure. To understand the currency exposure of a firm, you have to:

  • Classify all outputs as tradeable vs. non-tradeable (this has nothing to do with their being exported by the firm or not).
  • Classify all raw materials as tradeable vs. non-tradeable (this has nothing to do with their being imported by the firm or not).
  • Work out projections for these.
  • This gives the net unhedged exposure owing to the natural business of the firm.
  • Layer on top of this the cashflows emanating from foreign currency denominated borrowing.
  • This gives the overall picture for the exchange rate exposure of the firm.

Analysing what RBI said on 15 January


On 15 January, RBI put out a "regulation' titled Capital and provisioning requirements for exposures to entities with unhedged foreign currency exposure. In this, they ask banks to do greater provisioning and hold more capital when faced with a borrower who has unhedged currency exposure.

I have a few concerns with what has been done here.

  1. This is unsound micro-prudential regulation. The risk faced by a lender is about only two numbers: Pr(default) and loss given default. That's it. Everything else is an input that goes into making these two numbers. If unhedged foreign currency exposure impacts upon the failure probability or upon the LGD, then it's correct to use it in internal models that generate a failure probability or the LGD. It is wrong to think of an additional layer of prudential regulation to address unhedged foreign currency exposure. For an analogy, greater leverage means that Pr(default) goes up. Does this mean that banks will now have enhanced provisioning or increased capital required to cope with the increased leverage? For another example, the volatility of cashflow impacts upon Pr(default). Does this mean that banks will now have enhanced provisioning or increased capital required to cope with firms that have more volatile cashflows? I could go on and on.
  2. This is unsound measurement of unhedged currency exposure. The words `import parity pricing' do not occur in the RBI document. They think in terms of direct exports and imports. Further, they say "export revenues (booked as receivable) may offset the exchange risk". For a firm like Infosys, it's perfectly safe to borrow in dollars for a 10 year horizon, knowing that for the next 10 years, export revenues are going to come along, even if this is from clients who are not known today.
  3. This is unsound regulation-making process. If the due process in the Handbook had been followed, the quality of regulations would go up. In part, this is about the basic hygiene of the rule of law. As an example, under the Handbook, a regulation would not be a letter. In addition, the formal process of identifying the market failure, stating a clear objective, doing the cost benefit analysis and consultation would have caught the mistakes. The formal regulation-making process from the draft Indian Financial Code, and the Handbook, is the process design for a superior financial agency.

Suppose we believe that unhedged currency exposure is a problem for India, and not for banks, and that we're merely using the regulation of banks as a mechanism to attack that problem. This would stave off the first problem (`this is unsound micro-prudential regulation of banks'): RBI could respond saying "we know this is unsound micro-prudential regulation, but this isn't micro-prudential regulation". But it would not solve the other two problems, and it raises two fresh concerns.

First, if there is a concern on the scale of India, and an intervention is undertaken in one part of the financial system (Banking), it will have little impact on the economy as a whole -- all that will happen is that the market share of banks in the credit market will go down. This shift in market share will be a distortion as it will constitute industrial policy in the form of RBI favouring one technology (non-bank lending) over another (bank lending).

Second, this raises concerns about accountability. The powers obtained by a financial agency for a specific purpose should not be misappropriated for other purposes. Once we start going down this slippery slope, we will get powers of micro-prudential regulation getting used to foster GDP growth in Himachal Pradesh. A few paragraphs down, I argue that the problem of unhedged currency exposure is rooted in inappropriate monetary policy (i.e. exchange rate management) and inappropriate regulation of organised financial trading. The problem of unhedged currency exposure was not born in mistakes of banking regulation and should not be addressed by modifying banking regulation.

How to combat unhedged currency exposure


I have been closely associated with enterprise hedging of certain firms and even to the management of the firm, it is not easy to precisely understand currency risk and hedge it. The true extent of exchange rate exposure for a non-financial firm is very hard to observe for an external observer such as a bank.

Unhedged currency exposure of firms is a real problem. Many countries have experienced serious problems with non-financial firms that got damaged as they had borrowed in foreign currency and hoped that the government would prevent depreciation. We should not ignore it. There are two channels to fighting this:

  1. The problem of moral hazard. Firms will be careful about unhedged currency exposure when they know that the government will not manage it for them. As long as a government promises that extreme volatility of the INR will be prevented, it is advantageous for firms to leave tail risk unhedged. By doing this, the firm that has unhedged foreign exchange exposure free rides on RBI; its private gains from not doing risk management are offset against the costs to society of RBI having an exchange rate policy. The paper Does the currency regime shape unhedged currency exposure? by Ila Patnaik and Ajay Shah, Journal of International Money and Finance, 2010, finds there is this kind of moral hazard in India. To solve the problem of moral hazard, RBI should stop having a currency policy and should clearly say so in order to ensure that the firms of India know they are on their own, and have to do their own currency risk management.
  2. The problem of incomplete markets and barriers to hedging. Even if a firm was sensible and wanted to hedge, RBI is working hard to prevent the firm from hedging. The rules about the use of the OTC market prevent correct measurement of enterprise-risk based on import parity pricing. The onshore market is illiquid, but Indian firms are prevented from getting their hedging work done on the superior NDF market. The exchange-traded currency futures market has been damaged by RBI, to make sure that it is not a viable venue for currency hedging. If Infosys tried to obtain a 3-year hedge from the private market, the prices are quite adverse.

This is a good example of the problems that come from mixing up multiple functions inside one agency. A financial agency which did micro-prudential regulation for banking would be technically sound and not make the mistakes identified above on provisioning and capital. A financial agency which dealt with organised financial trading would deliver a sound Bond-Currency-Derivatives Nexus without conflicts of interest, and the problem of incomplete markets and barriers to hedging would go away. If RBI had no role in banking regulation and no role in organised financial trading, the quality of monetary policy would go up. When each agency has clear objectives, each one will be accountable and more likely to deliver results without conflicts of interest.

Conclusion


The unhedged currency exposure of Indian firms is a big problem. It is an important concern for policy makers. But it makes no sense to go after it by asking banks to hold greater capital when lending to firms that are considered unhedged, based on an incorrect framework for thinking about the currency risk of firms.

We must address the root cause. If RBI had no currency policy -- and clearly said so -- the moral hazard would be removed. If RBI got out of the way, then the Bond-Currency-Derivatives Nexus would find its feet and firms would be able to hedge. The problem of unhedged currency exposure of firms is caused by inappropriate macro/finance policy at RBI, and the solutions lie there.

Wednesday, June 16, 2010

Structural change in the Indian exchange rate regime

The rupee/dollar rate has gained in flexibility. In order to visualise what has changed, it's useful to look at a graph of the time-series of weekly percentage changes, expressed in absolute terms. That is, a change of -3% or +3% is shown as a bar of height 3 in this graph:


The vertical blue lines show the dates of structural change in the exchange rate regime. These are taken from our recent paper The Exchange Rate Regime in Asia: From Crisis to Crisis, which is forthcoming in International Review of Economics and Finance, and is part of our work on measurement of the de facto exchange rate regime. As an aside, a recent article in The Economist about Asian currency flexibility talks about this in a larger context.

The vertical blue lines break the overall experience into six distinct periods: a first period of high flexibility, then the shift to a nearly fixed rate in April 1994, then the higher flexibility at the time of the Asian crisis followed by a return to very low flexibility, and then two moves of increasing flexibility.

These movements towards flexibility -- and away from administered prices -- require corresponding adjustments on the part of the economy. If firms are coddled with an administered price and thus think that currency risk does not exist, or if exporters are coddled with a distorted exchange rate, then this generates the wrong behaviour on their part. See Ila Patnaik in the Indian Express on learning to live with a genuinely market determined exchange rate. Also see T. B. Kapali, of the Shriram Group of Companies, in the Hindu Business Line arguing in favour of greater flexibility for corporations in hedging currency risk.

Monday, September 07, 2009

How useful are the new interest rate futures?

The path to interest rate futures was afflicted by important mistakes in policy. I wrote a piece in Financial Express today about how, ironically, the damage caused by these mistakes is smaller than meets the eye, given that we have a stunted bond market in the first place.

Friday, September 04, 2009

Corporations and OTC derivatives

Central counterparty for OTC derivatives

Jayanth Varma is astounded that some corporate treasurers think that their derivatives positions should not be backed by collateral. I am too. On a related track, there is news today that RBI is pushing banks to report interest rate swap transactions through CCIL. This is in the right direction.

The futures clearing corporation as the role model

The role model here is the futures clearing corporation, e.g. NSCC. Futures clearing corporations are designed to enable safe trading between strangers, which makes possible the nice efficiencies of the anonymous electronic market. In doing this, futures clearing corporations demand the identical collateral from all customers. There is no question of NSCC exempting SBI from collateral requirements because SBI is para-statal. It is through such toughness on collateral requirements that NSCC has built up a 13-year track record, of surviving quite some market turbulence, as central counterparty.

More generally, the `recipe' of how clearing corporations work has fared well in the last 100 years, barring a few failures which are really about operational risk, corporate governance, malpractice etc. If someone is serious about running a clearing corporation properly, it can be made to work. All that one has to do is to ensure sound ownership and governance in the exchange business.

Rule of law

I have a disagreement with the mechanism adopted by RBI, on the issue of rule of law. If the newspaper story mentioned above is accurate, RBI officials met a few banks and asked them to do something different. If we respect the concept of rule of law, then it is better to run through the full set of steps:

  1. Put out a draft rule change for comments.
  2. Genuinely, substantively, listen to the comments. Consider it possible you may be mistaken.
  3. Put out a modified rule on the website, after which everyone should be obeying it regardless of whether there has been a meeting with RBI officials or not.
  4. Rule changes should be appealable at an SAT.

This is a better process flow, one that expresses the goal of having rule of law. SEBI is the most advanced financial regulator in India today, in having developed the closest approximation to this process.

A real problem with corporations and OTC derivatives in India

I am not a legal expert, but in my understanding, at present, if two corporations enter into an OTC derivative against each other, this is not enforceable. Enforceability is limited to the class of transactions where one of the two counterparties is a bank.

This is reminiscent of 1970s vintage rules of the game in exchanges. Here, exchanges forced the public order flow to only go to market makers. Public orders could not match against each other. Or to say it differently, public orders could not compete with the quotes posted by the market maker. This was a way to rig the rules of the game so as to favour the market makers.

In similar fashion, the existing rules with banks and OTC derivatives in India (if I have understood them correctly) are a way to prop up the profitability of banks at the expense of customers of banks. This is anti-competitive. It helps ensure that the inter-bank OTC market is a rigged game, one that favours banks at the expense of corporate customers. It is one more reason why exchange-traded derivatives are so important in India. It is only on the NSE screen that, for the first time in India's history, we are getting a genuine, competitive, transparent market for the currency or interest rate futures.

These kinds of efforts at rigging the game, in the context of corporations and OTC derivatives, help increase the chances that India will be a pioneer by world standards on the shift of the currency and bond markets to the exchange platform. In terms of the ratio of the size of the OTC currency forward to the size of the exchange-traded currency futures, India is already one of the remarkable places in the globe.

Where corporations are different

While futures clearing corporations should give no quarter to corporate customers as far as collateral requirements are concerned, I think there is a case for having bigger position limits for corporate hedgers.

There is a genuine tension here. If small position limits are used, this reduces the usefulness of the derivatives market for society, because the most important customers of hedging (corporations) are blocked from using it. If special rules are applied for corporate hedgers, there will inevitably be certain shades of gray on what gets done. Yet, when regulators swing over to the other direction and blindly force tiny position limits, it imposes a cost on society. There is a bias towards such over-reaction given that regulators have a different personal perspective on the risk and return from a rational rule set, when compared with the welfare gains to society.

I think the real answer lies in more principles based regulation. For physically settled contracts, there should be no dislocation in the delivery process and for cash settled contracts there should be no artificial distortion of the market price. An excessive attempt at writing down rules does not get the job done.