FRM 1: The Building Blocks of Risk Management
Stripped back to essentials, risk means that bad things might happen. Risk therefore deals in outcomes still ahead of us, and calling an outcome bad is a judgement anchored to whatever somebody values.
Behavioural science finds that gut feeling carries more weight in our judgements than it deserves, that reasoning bends under bias, and that appetite shifts with the wording of a question alone, so whether dangers get spotted and whether anything is genuinely managed turn on the quality of thought applied.
Risk management is an old craft and a young profession
Traders in antiquity split exposures with financiers through maritime loans, where repayment depended on cargo reaching port intact. Northern Italy pulled lending and insuring apart by the fourteenth century, and the insurance contract became the earliest instrument built purely to move financial risk. A systematic mathematics follows from the seventeenth century onward, agricultural futures across the eighteenth and nineteenth centuries carried transfer onto exchanges, financial theory advanced during the 1950s, transfer markets multiplied from the 1970s, and cyber risk insurance appeared once the twenty-first century opened.
Risk management is not the same as risk avoidance
To manage an exposure is not to shrink it. Companies accept exposures on purpose, because payment comes attached, and the role is to confirm that whatever has been taken on is understood, is priced, sits inside the appetite the firm has set, and earns a return. Spending on the function buys room to hold larger exposures wherever the firm is paid to hold them, so wealth creation across an economy leans on the discipline.
Ten building blocks
Ten building blocks are singled out here, in no order of rank. Catastrophes almost always trace to a missed basic rather than to a broken model: a category of exposure goes unnoticed, links between exposures are read wrongly, or a stage of the process is left out.
Exposures come in many shapes, yet one classification holds nearly everything a company meets. An organisation uses it to work down into the drivers inside each category, to lay its risk management processes over the whole map so nothing is left unattended, and to put a named individual in charge of each domain. Banks and large corporations arrange departments along these lines, and those teams ran in near isolation until the mid-1990s.
New risk types are born out of structural change
Cyber risk, above all the danger that hackers steal or wreck data and break into systems, and data privacy risk are recent additions. A new category is nearly always born out of a deep alteration in how a market or an industry works: rogue trading followed the expansion of derivatives desks and proprietary books, bank liquidity exposure surfaced in the crisis after a drift in funding and leverage, class actions made legal risk heavier, and digitisation produced cyber exposure. Practice shifts first, and the label follows. A typology therefore has to stay flexible rather than settled. Drawn up for a bank a few decades ago, one would very probably have carried no line for rogue trading and no operational risk class at all, and fresh varieties of operational risk are climbing the agenda again now.
Risk flows
Under acute stress exposure can run out of credit risk, into liquidity risk, and onward into market risk, the sequence seen in the global financial crisis of 2007-2009. Inside one company a mistyped order is an operational event, it leaves a hazardous position behind, which is market risk, and it may wreck how the firm is regarded, which is reputational risk. Competence within each heading will not save a company from the route a loss takes between them.
Each risk type demands its own skills and philosophy
Market risk and credit risk strike most banks as intrinsic to what they do, so reward rises in step with exposure. The stance towards operational risk runs the other way, since a collapsed system or a dishonest dealer pays nobody anything.
Quotations and rates never stop shifting, and holdings rise and fall behind them, so volatility in prices is what powers market risk. A financial institution deals mainly with four underlyings: equity risk, interest rate risk, currency risk and commodity price risk. Two components drive the exposure throughout.
- General market risk. The danger that an entire asset class declines, pulling down with it whatever single holding or portfolio sits inside.
- Specific market risk. The danger that one particular holding declines further than its asset class as a whole.
The two call for different handling. The first is a wager on the market at large and can be offset with wide instruments such as index futures. The second is a wager on one name, cut chiefly by diversification.
Relationships between positions cut both ways
Investment risk management rests on the diversification benefit a sizeable equity portfolio delivers: specific components of separate holdings partly offset each other, and what survives is largely the general component. Those relationships also manufacture exposure. Track a benchmark and the tracking may prove inexact, which is a variety of market risk; set one position against another and the offset may again be inexact, which is basis risk.
An airline must be shielded from jet fuel growing more expensive, and its commodity risk manager is charged with arranging that. No futures contract on jet fuel trades with enough liquidity to serve, so crude oil futures are chosen instead, the justification being the way the two prices have moved together in the past.
When one side does not meet what it owes financially to the other side, credit risk is the result. It appears in three recognisable shapes.
- Interest or principal on a loan goes unpaid by the borrower. That is bankruptcy risk, otherwise called default risk.
- An obligor or counterparty suffers a downgrade. That is downgrade risk, and a credit-linked security can lose value at once with no default.
- Whoever stands on the other side of a market trade does not perform. That is counterparty risk, and settlement risk, otherwise called Herstatt risk, falls inside it.
That label traces to Herstatt bank in Germany, active in foreign exchange and shut by regulators in 1974. Because of when the shutdown fell, settlement broke: counterparties had delivered Deutsche Marks on their half of the currency deals, then found the dead bank could not deliver the US dollars owed on its half. Settlement risk therefore concerns the interval between the two halves of a trade, not creditworthiness across the years of a loan.
The three levers
Three quantities determine the exposure: how likely the obligor or counterparty is to default, how much is outstanding when default arrives, and how much can be recovered once it does. The levers on them are whom the firm lends to, the design of the credit instrument, covering pledged security, the sort of collateral, the creditor’s place in the queue should bankruptcy follow and whether covenants shelter the lender, and the limits placed on exposure. A derivative may carry none of this exposure on day one, having no market value yet, and a substantial counterparty credit exposure once market moves hand a gain to one side.
From a single obligor to a portfolio
An obligor is customarily judged by weighing a handful of drivers, chiefly leading financial ratios and the industry sector. At portfolio level what matters is concentration by obligor, meaning each obligor exposure measured against the value of the portfolio, together with how the risk factors relate to one another. Any of the conditions below makes a portfolio more dangerous.
- The book is a few large loans rather than many modest ones.
- Positive correlation links the returns, or the default probabilities, across the loans, perhaps because the borrowers share an industry or a region.
- Positive correlation also links exposure amount, probability of default and loss given default, as when recovery amounts shrink in the very period when defaults multiply.
The last is the hardest to anticipate and the most punishing, since all three levers swing against the lender at once. Credit portfolio models exist to expose what such combinations produce.
Liquidity risk covers two problems with very little in common.
Funding liquidity risk
Funding liquidity risk is the danger that a firm cannot reach enough cash, and assets readily convertible into cash, to settle what it owes. Every type of firm is exposed, not only banks. Profit is no protection: a business can collapse purely because receipts arrive after payments fall due.
For banks the exposure is structural, because their trade consists of manufacturing mismatches in maturity and funding on purpose. Deposits are gathered at short tenors and advanced for longer periods at a wider rate of interest. That gap is the commercial model itself, which is why asset and liability management, abbreviated to ALM, sits at the centre of banking, using techniques such as gap analysis and duration analysis.
Many institutions that went under in the 2007-2009 global financial crisis had accumulated wide mismatches in maturity, leaving them exposed to whatever view the wholesale funding market took of their creditworthiness.
Market liquidity risk
Market liquidity risk, also called trading liquidity risk, is the exposure to a drop in what an asset is worth when a market briefly freezes. Should participants be unable or unwilling to trade, a seller can be pushed into accepting a price far below normal, or find no price at all. The two are linked: a bank leaning on fragile wholesale markets can see one become the other within a night, because assets that will not sell produce no cash.
Why market liquidity risk is hard to measure
The usual gauges examine transaction counts, volumes, and the gap separating bid price from ask price, and none of them signals whether liquidity will survive a crisis.
The Basel Committee on Banking Supervision defines operational risk as the “risk of loss resulting from inadequate or failed internal processes, people, and systems or from external events.” Legal risk falls inside that boundary; business risk, strategic risk and reputational risk all fall outside it.
The scope is wide on purpose. Anti-money laundering risk, cyber risk, terrorist attacks and rogue trading all sit inside it, and it was the rogue trading episodes of the 1990s that first convinced regulators to bring operational risk into bank capital calculations. Outside banking it covers physical mishaps in operations and governance scandals of the kind that engulfed the energy giant Enron in 2001, where risk managers commonly address the category through insurance.
Measure or manage
Quantifying operational risk is where the difficulty lies. Banks began the effort towards the end of the 1990s, since capital against operational risk was the natural companion to capital already held against credit and market risk. It produced sizeable loss databases, statistical analysis, scorecard systems, key risk indicators and scenario analysis.
Many banking supervisors stayed unconvinced that such instruments could underpin an accurate allocation of risk capital, and the Basel Committee shifted direction in 2016. Banks would still build an understanding of their operational risk through an assortment of tools, yet the capital figure itself would now come from a plainer standardised method: bank size, weighted, with a multiplier keyed to the institution’s history of larger operational risk losses.
The category holds the enormous legal actions and compensation claims that have dogged banks ever since the global financial crisis of 2007-2009, an expanding cyber risk, and fines arising from data privacy infringements. Operational risk stays among the gravest dangers facing large corporations, and its true cost cannot properly be measured.
At the core of any enterprise sit its business risks: what customers will demand, how to price, how negotiations with suppliers will go, what rivals are doing, and how product innovation is handled.
Strategic risk is a separate category, covering big decisions with long horizons about where the firm is heading, choices that carry substantial commitments of capital, of people, and of the reputation of management. Running the business day by day is business risk; deciding to change what the business is amounts to strategic risk. Banks facing competition from financial technology companies must choose between building the equivalent services in house, buying the companies, or forming partnerships, and no market risk model contributes to that decision.
If general management owns these risks, what is the risk manager for
Demand can drop away, a new product can fail, and a large capital investment can be aimed at the wrong thing, any of which can put the survival of a firm in question. General management, not the risk function, owns these exposures. The chapter offers three observations.
- Risk appetite must be defined holistically. Management has to set out its appetite across the exposures created by weighty business and strategic choices. A firm can be extremely cautious about credit risk and adventurous about business risk at once, and should spell out the reasoning rather than let the split arise by accident.
- The risk function has transferable skills. Abilities held by the chief risk officer and the team behind them can be applied to putting numbers on parts of business and strategic risk. Credit specialists are regularly drawn into supply chain risk, the same structural problem in unfamiliar clothing, and macroeconomic scenario analysis can sharpen strategic decisions.
- Business decisions create exposures elsewhere. A commercial choice reappears further along the balance sheet as an exposure to credit or to commodity prices, so the risk function belongs in the planning discussion from the beginning. Funding a power station may prove unachievable without a strategy for hedging energy prices, and enlarging a bank’s lending book may require loosening standards, making it a risk decision in the costume of a growth decision.
Reputation risk
Reputation risk is the possibility of an abrupt decline in how a firm stands in the market, or in its brand, carrying economic damage through the loss of customers or of counterparties. It typically originates in a breakdown elsewhere in risk management that undermines belief in the firm’s soundness or fair dealing. Let credit risk management fail on a large scale and rumours follow, and rumours alone are capable of killing: investors and depositors pull their support because they expect everyone else to pull theirs. Plans for calming markets and repairing standing need to exist well before they are needed.
Standing as a fair dealer counts every bit as much, and a firm that gives a false account of the risks in a product may find that valuable customers depart. Standing with regulators matters enormously, because alongside formal authority they hold much informal power. Should a bank forfeit that trust, wide-ranging examinations may follow, and what it does may be publicly criticised or cut back. Since the damage falls on the firm as a whole and not on one desk, reputation risk is monitored by the board rather than handed to the head of any single risk discipline.
Reward is what drives us to accept risk. Does the risk match the reward, and might it be reduced while the reward is kept? Answering that produces the classic risk management process, in which the risk manager identifies a risk, analyses and measures it, assesses what effects a risk event would have, and manages the risk last of all.
Identification is not a formality
Naming a risk can steer the response as forcefully as measuring it, because some exposures strike firms as native to what they do and others as foreign. A manufacturer will actively run the operational hazards of a production line while shifting large market or credit exposures off its books. An identical loss provokes far more shareholder anger when it comes from a speculative derivatives position inside a non-financial corporation than from core operations.
The four choices
The process ends in a set of choices that manage the risk and help define what the firm is.
- Avoid risk. Drop the activity or conduct it along a different strategy. A firm might decline to sell into particular markets, or to move production offshore, to keep political or foreign exchange risk to a minimum.
- Retain risk. Keep the exposure inside the firm’s risk appetite. Even sizeable ones can be held using allocation of risk capital, self-insurance, and captive insurance.
- Mitigate risk. Cut the exposure back in size, frequency, or severity. Better operational infrastructure lowers the frequency of some operational risk, hedging an unwanted foreign currency position mitigates market risk, and collateral lessens how severe a default would prove.
- Transfer risk. Pass the exposure to another party through derivative or structured products, or by paying a premium to an insurer.
How risks are identified in the first place
The opening moves in identification and triage tend to take classic forms.
- Brainstorming. Gather the key professionals, business leaders and audit professionals among them, into one room and question them about the exposures confronting their divisions.
- Structured interviews, questionnaires, and surveys. These carry the inquiry outwards to a broader set of professionals in the company or the industry, and should feature open-ended questions.
- Industry resources. Unless an activity is one of a kind, checklists, professional and regulatory standards, industry surveys and expert opinion all exist to enrich the brainstorming.
- Loss data analysis. The analyst turns to the categories the wider industry uses, and to internal and external loss records, to judge how often loss events occur, how damaging they are, and which risk factors they attach to.
- Basic risk triage. Exact quantification is beyond some risks, yet a risk manager ought still to reach a view on frequency and severity.
- Hypothetical what-if analysis. Early research can throw up worst-case scenarios, which the brainstorming team is then invited to weigh.
- Front line observation. Nothing replaces walking into the business line and watching how the work is actually carried out.
- Following the trail. How are the key processes run, and which risks come attached? Are weaknesses or gaps visible?
The second building block sorts risk by how much is genuinely understood about it. Concentrating on visible, quantifiable hazards while ignoring invisible ones is among the simplest errors an analyst can make.
Frank Knight supplied the first origin, in a celebrated 1921 paper separating risk that admits measurement from uncertainty that does not. The second came from Donald Rumsfeld, then United States Secretary of Defense, at a NATO press conference during June 2002: “There are things we know that we know. There are known unknowns … But there are also unknown unknowns.”
The labels Knight himself used are worth keeping. Measurable risk, which he also called risk proper, covers a decision whose outcome is unknown while the decision maker can still attach a fairly accurate probability to each outcome that might follow from it. Unmeasurable uncertainty, or true uncertainty, covers the case where the information needed to obtain those probabilities cannot be had. John Maynard Keynes drew a parallel line, separating risk that can be calculated from what he called irreducible uncertainty, on the ground that calculating certain risks would force a modeller to lean on assumptions about the future with no basis in probability theory.
Uncertainty of that kind can be vast and still refuse to be counted. Nuclear war threatens the world and no credible estimate of its likelihood exists, yet even that remains manageable, because avoidance does not depend on measurement: multilateral disarmament would remove the exposure whether or not anybody can price it. Difficult actions of that sort need agreement that the uncertainty is plausible and severe, which is a harder case to argue when frequency cannot be stated. The boundary also shifts over time. The health threat from smoking was once an unquantified worry, and sustained research later converted it into a statistical risk that can be worked with directly.
People gravitate toward whichever exposures arrive with a data set attached, and they set aside the poorly understood ones, which may well be bigger.
What the risk manager actually does with this
Whenever feasible, a risk manager drags badly understood exposures toward the middle. One firm rule follows: an exposure that resists measurement must never be handled as though it were a settled quantity. A figure built on sparse data and aggressive assumptions deserves less weight than one resting on a deep record.
Unknown risks and merely unseen ones
A genuinely unknown risk arrives out of the blue, like a meteor. Speaking for the Bank of England, Alex Brazier argued that most risks are better described as unseen, and separated them into moonwalking bears and underwater icebergs. The bear takes its name from a video in which viewers absorbed in a basketball game fail to notice someone in a bear costume crossing the screen, and the financial version is a risk in plain sight: through a stretch of compressed yields the evidence that risk is being bought far too cheaply sits on every screen in the market, and investors carry on buying. Underwater icebergs are the harder ones to spot, the build-up of leverage at some financial firms ahead of the global financial crisis of 2007-2009 being the standard illustration, and after the event they look obvious, because they usually rest on some fundamental weakness. Then there is the elephant in the room, an exposure many people inside a firm can see and none of them will name in public. Responsibility runs across all three kinds and not only across the measurable ones.
Building block three separates expected loss from unexpected loss.
Expected loss
Expected loss, written EL, is the mean loss a position or portfolio is anticipated to suffer. Three ingredients drive it: the likelihood of the risk event, how much the firm has riding on it, and how severe the loss becomes if it arrives. For a loan those become probability of default (PD), exposure at default (EAD) and loss given default (LGD).
Once the estimate carries genuine confidence, the quantity acts less like a risk and more like a cost of goods sold. The risk function must then get the number right and watch for signs that the portfolio is shedding that predictability.
A term loan sits on a bank’s books with an exposure at default of USD 40 million. The internal rating assigned to the borrower puts the one-year probability of default at 2 percent. Between collateral and seniority, recovery in a default would come to 65 percent of the exposure, which leaves loss given default at 35 percent.
Unexpected loss
However far an outcome strays from the average, that distance is the unexpected loss level. What drives it in a credit book is mundane: the number of loans and the size of each. Spread the book across many small exposures and no single default moves the total far; diversify across industries and regions and defaults stop arriving in clusters.
From unexpected to extreme
Other credit books swing violently across a decade, their average assembled from long stretches of good years interrupted by brief runs of bad ones. Portfolios shaped this way invite complacency and oblige banks to hold substantial risk capital against outsized unexpected losses, on top of pricing expected loss into the product.
Nothing illustrates variability in loss levels better than the boom and bust cycle in commercial real estate markets worldwide.
Appetite for commercial property picks up, ordinarily alongside a broad economic upswing, while supply stays inelastic because buildings take time to put up. Prices climb, drawing in investors and lenders, some of whom loosen loan-to-value ratios to chase market share.
Prices soften in time, pushed down by cyclical oversupply and a worsening economy. Banks pull credit back from developers and investors, deepening the decline. Developers who stretched too far hit cash flow trouble, collateral values sag, lenders find their own finances weakening, and a fire sale or two tips the market into a ruinous feedback cycle.
Wrong way risk
Lenders face developer default probabilities that climb just as the worth of their collateral slides, and wrong way risk is the name for that pairing. EL multiplies PD, EAD and LGD together and assumes each input can be estimated on its own; wrong way risk degrades two of them at once, leaving the realised loss well beyond anything independent averages would predict. Derivative markets supply another case, where a contract’s value against a counterparty climbs just as that counterparty’s default risk climbs.
Dennis Weatherstone took over as chief executive of J.P. Morgan and, in January 1990, asked for a single document covering his bank’s total risk to reach him each day at 4:15 p.m. That instruction drove momentum behind value at risk, abbreviated VaR, whose methodology reached publication across 1993 and 1994.
What VaR says
Jorion puts it this way: VaR is “the worst expected loss over a given horizon under normal market conditions at a given level of confidence.”
Take a trading portfolio whose weekly VaR at 95% confidence comes to $10 million. With markets in their normal state, the chance of that book dropping more than $10 million across the coming week is 5%. For a fund whose monthly VaR at 99% confidence is a 3% loss, the reading is a 1% chance of losing beyond 3%.
VaR works from the loss distribution attaching to a position or portfolio. Relax the confidence level to 95% and the figure tends to drop; fatten the tail and unexpected loss increases, so the VaR figure comes out larger.
Management at a bank receives the following figure: assuming markets behave normally, daily VaR for the trading portfolio at 97.5% confidence stands at USD 14 million.
Expected shortfall
Useful though VaR is, it puts no number on the risk lodged in the tail. Expected shortfall, written ES and equally known as conditional value at risk or CVaR, fixes a tail probability and takes the mean across every VaR figure beyond the VaR at that probability. VaR marks the doorway; expected shortfall reports the average of what waits beyond it.
The commercial real estate cycle showed why it pays to split risk into components. This fourth building block is that act of separation.
Underneath every primary risk factor sits a deeper layer of factors. Whether a company defaults depends on core financial indicators, the industry it operates in, and the calibre of its management. Isolating those factors, ranking how much loss each accounts for, and mapping how they connect to one another and to the wider economy sits at the centre of the risk manager’s job.
How granular should the analysis be
Scoring a risk factor often means descending to the sub-factors beneath it: management quality may rest on years of experience at the top of the company, and exposure to cyber risk runs to systems, processes, or people. In practice, analytical capacity may be lacking, and the loss records needed to test each variable are often thin, unreliable, or too coarse.
Ahead of the Basel II banking reform, supervisors told banks to log probability of default, loss given default, and credit exposure as distinct risk factors. All three had previously sat fused inside one rating, and the rebuild of credit rating systems ran into millions of dollars. A loss record becomes far more predictive once its dynamics are visible, but only if the data is organised to permit that.
Data science and the identification of risk factors
Data science, meaning big data, artificial intelligence, and machine learning, promises a much larger set of separable risk factors. Insurance analysts fuse public databases with social data, credit rating data, and unstructured data in order to read risk one person at a time, an approach the industry labels the segment of one.
Because unsupervised machine learning locates clusters and correlations without anyone nominating the area of interest beforehand, it gives the risk manager a route to the unknown unknowns.
Either a risk event is extremely scarce, or the market has quietly shifted its structure. The two look alike in the data yet demand very different responses, and separating them is the fifth building block.
Rare events in a stable system
A complex system such as the global climate or financial markets can, over long horizons, throw up wildly improbable events while its structure stays intact. Such risks are unexpected loss carried to an extreme, and so few instances exist that spotting them is hard. Stretch the time series far enough and outliers, or tail risk events, should leave traces. Where the record stays thin, practice falls back on statistical tail risk techniques drawn from Extreme Value Theory, or EVT, a branch of statistics whose purpose is to bring tails into view and extract the most from few observations.
When the structure itself changes
Risk climbs whenever the structure sitting under a system shifts. Big losses can arrive more often or arrive larger, factors that used to move independently can begin marching together, and brand new risk types can materialise. More history then buys the manager nothing. What was billed as a once-in-100-year event can surface as often as once in a decade, and will keep doing so until either the structural fault is repaired or sound risk management processes are put in place.
Why human systems are worse
Mechanical and natural systems mostly hold still. Human systems, financial markets included, are pushed into continual structural change by social behaviour, industry trends, regulatory reforms, and product innovations, so the system is rebuilt beneath the analyst.
US mortgage lending from the early 2000s onward, and its role in the crisis of 2007-2009, is the sharpest modern example. Interest-only structures and teaser rates pitched below the market grew from marginal designs into a substantial portion of new origination, while a rising share of borrowers counted as subprime. For several years no losses materialised, so the loss series registered neither change: the book had moved on while the record still described the old one.
Financial systems hold a second wild card besides structural change: human systems are populated by intelligent participants whose response to change can be self-reflective, or frankly calculating. Rival traders can second guess a trader’s forecast of a market reform, and a regulator who helped draft that reform may join a consulting firm and coach the industry on routes around it.
Inside the firm the dynamic repeats. Whoever grasps how risk gets created and controlled holds the strongest position from which to game it, and the weakest reason for putting it on display, since advertising the scope for unexpected loss or tail risk cuts against their own interests.
Three lines of defence
Partly for this reason, three lines of defence are a common arrangement at financial firms.
- First line: the business line which creates the risk, owns it, and manages it.
- Second line: risk managers whose specialism is risk management and oversight on a day-to-day basis.
- Third line: independent oversight and assurance conducted periodically, internal audit being the usual example.
The business holds first place because it manufactures the risk, and ownership follows. Put the risk function at the front and risk becomes the property of the risk team rather than of the business, the very failure the structure was designed to head off.
The safeguards do not always work
No risk management system is free of gaps, and industry innovation dates each one quickly. A troubling proportion of banking rogue trading episodes share a feature: the trader had served an earlier stint in the middle or back office and knew where the gaps in the risk management infrastructure lay. Traders and business heads have at times set out to erode confidence in risk management systems.
Grasping what human agency, self-interest, and conflict of interest contribute makes up the sixth building block.
With so many risk types and metrics in play, one central difficulty is seeing the whole: which businesses carry the most risk, and when is total firm risk nearing a level that cannot be tolerated?
Market risk lends itself best to being measured and added up, and even there control is difficult. Until a few decades ago, comparing market risk exposures meant comparing the notional held in each asset, USD 10 million of a large capitalisation stock for instance, with volatility left out. Volatility differs enormously between stocks and sectors, so two matching notionals carried nothing like matching risk, and the practice looked worse still when notional weighed a US Treasury trading desk against one trading a volatile commodity.
Why derivatives broke the notional approach completely
Once derivatives markets appeared in the 1970s, that habit became a pressing problem. Such instruments can be extraordinarily volatile, a large exposure takes little time to build, and the drivers of their value and risk relate only loosely to the notional the contract states. Portfolios are often built so that one instrument cancels the market risk of another, so positions summing to a billion of notional might carry virtually no net exposure, or an enormous one.
The Greeks, and why they do not add up
Delta captures how responsive an option’s value is when the underlying moves in value, while theta captures how that value shifts as expiration draws nearer. Known collectively as the Greeks, they remain indispensable on the options trading desk, yet two things restrict them across a whole enterprise. Summing them is not possible, and an identical reading does not mean an identical amount of risk from one market to the next, since delta in foreign exchange means something different from delta in commodity markets.
VaR as an aggregation measure, and its limits
Before the crisis, VaR enjoyed wide popularity as a way of aggregating risk, though no single fixed methodology stood behind it: three principal methodologies existed at minimum, each implementable in numerous ways, and the concept rests on a long list of simplifying assumptions. It proved too handy for its own good, pressed into service over far longer horizons, across whole industries, and at risk types unlike the setting for which it was built.
Documentation of these weaknesses predates 2007 comfortably, so the crisis discovered none of them, it merely lifted them into plain view. VaR still counts as an important tool, and supervisors responded by tightening the mechanics of the calculation and pushing complementary measures into use beside it, expected shortfall and worst-case scenario analysis included.
Taking account of tail risk
VaR delivers the loss at a single chosen likelihood threshold and says nothing about losses beyond it, hence the charge that it ignores tail risk, the contribution of events both severe and rare. Expected shortfall, the remedy with the greatest staying power, attaches a figure to the average risk in the distribution’s tail, past the point where VaR ceases to look.
Scenario stress testing and reverse stress testing spread more widely over the same stretch, and both leave probability unattached. A scenario test assembles a worst case severe enough to matter yet still believable, then traces what it would do to the institution given the exposures on its books. Every figure describes severity, and never frequency.
Reverse stress testing runs the other way. Modelling capability pins down a tail risk scenario and names a target loss level, and the institution reasons backwards to how those losses connect to its exposures and activities, which risk factors sit behind them, and what it might do differently to avoid the outcome.
Aggregate risk measures have a proper place, yet important dimensions of risk always escape them, and the eighth building block is an understanding of what risk aggregation does well and badly.
VaR makes exposures in separate parts of a business comparable. Knowing the expected and unexpected loss each activity throws off lets a firm hold risk capital, otherwise labelled economic capital, against the unexpected portion.
Economic capital and regulatory capital
Economic capital, or risk capital, is the capital a firm judges it needs once it has assessed its own economic risks in its own way. Regulatory capital is a separate idea, since that figure follows rules laid down by regulators, and the two line up only on occasion.
Once economic capital is available, the profit earned by each activity can be set against the capital standing behind it, and those charges feed into product pricing and into any ranking of business lines.
Why this comparison is necessary
Picture two divisions. Business A carries sizeable expected loss year after year, yet its unexpected loss stays small. Business B reverses that, with minimal expected loss but enormous hits whenever a business cycle ends.
Judged on unadjusted profitability, Business B looks the stronger performer through the benign stretch of the cycle, purely because its losses have yet to arrive. A firm may then cut prices there to win volume, adding exposure when the figures inform least.
RAROC
A bank that wants both categories of loss priced into its performance figures turns to risk-adjusted return on capital.
One further adjustment is required, since expected losses come out of that return figure, giving the version used in practice.
Value accrues to shareholders only where an activity delivers RAROC above the cost of equity capital. That threshold is the hurdle rate, the minimum return shareholders demand for bearing risk.
Across a single year, a bank sets two divisions against each other. Before any deduction for expected loss, Division A earns an after-tax risk-adjusted expected return of USD 30 million; its expected loss runs to USD 12 million and it receives an allocation of USD 120 million in economic capital. On the identical basis Division B earns USD 26 million, its expected loss is only USD 2 million, and its allocation reaches USD 200 million in economic capital, since the losses it takes bunch up at the close of the cycle. Cost of equity capital for the bank stands at 11 percent.
Four day-to-day applications
- Business comparison. Where business lines soak up unequal quantities of economic capital, RAROC still lets a firm rank their performance against one another.
- Investment analysis. Forecast figures fed into the formula gauge what a prospective investment might return, launching an unfamiliar credit product being one such case. Run on historical returns instead, RAROC shows whether a business line is beating the hurdle rate set by the equity investors who supply its risk capital.
- Pricing strategies. Prices on particular products and customer segments can be revisited. One segment may be priced so cheaply that no risk-adjusted profit is possible, while elsewhere there is scope to charge less and capture more of the market.
- Risk management cost and benefit analysis. What risk management costs, insurance as a means of risk transfer being one instance, can be weighed through RAROC against what the firm gains from it.
Everything rests on the risk calculations underneath, so divisional managers frequently challenge the figures, at times out of self-interest.
Hard numbers
Risk reports are filled with figures that carry an objective, empirical air. Some analyses put risk on an absolute scale, multiplying risk probability by exposure by severity, on data of uneven quality.
Elsewhere a report follows one element of that product, usually risk exposure. A fall in that element does not mean risk is falling, since the inference holds only where nothing else has moved. A bank losing market share may relax credit standards, so a smaller loan book is no evidence of lower credit risk.
Third comes the key risk indicator, or KRI, a quantitative measurement employed to gauge some potential exposure, such as staff turnover as a monitor for operational risk. Judgement, rather than a proven statistical relationship, normally links indicator to risk, so a committee watching a KRI move may believe the risk itself is in view when the object of observation is a stand-in of unproven usefulness.
By calculation or by judgement, a business has to balance risk against reward, and that is the ninth building block.
Firm-wide risk management runs into an obstacle wherever divisions handle risk inside silos, each looking after its own exposures and paying no attention to what the others carry.
Breaking down those silos is the precondition for seeing risk across every risk type and business line. Enterprise risk management, or ERM, is that broad view, and it is the tenth building block. Its instruments include an explicit statement of corporate risk appetite and unified handling of risk through global risk committees.
The mistake ERM efforts have historically made
Past ERM work often placed too much weight on reducing risk to one figure, usually economic capital or VaR. That proved too crude, since a single aggregate misses key dimensions of risk, stays silent on risks that resist measurement, and may rest on proxies of doubtful value.
Why risk cannot be reduced to a single number
Perhaps the largest lesson of the global financial crisis of 2007-2009 was that risk resists compression into any one figure. It has several dimensions at once, so it needs approaching from a number of angles and with more than one methodology. It also develops and crosses between risk types, which means that even a wide view of the typology, taken at one moment in time, can miss the point. And it calls for expert judgement set alongside statistical science. Economic capital still matters for balancing risk against reward, yet the analysis that saves an institution may come from elsewhere entirely, from a worst case scenario or from some newer digital technique. A range of tools and a good deal of curiosity are both needed.
Insight of that kind usually comes from somebody digging. A risk manager works out what a structural change in a market implies, or looks at the competition and sees that industry-wide behaviour could precipitate a crisis, or reads a market derived credit indicator flagging deterioration at a major counterparty early enough for something to be done. None of it is worth anything unless action follows, so ERM also examines the processes carrying information through to a decision, and behind those processes the firm’s corporate governance and its risk culture. If a push for aggressive growth turns out to have outrun the firm’s grasp of the risks, what is the procedure for changing course, and has that fire drill ever been run?
So ERM has stopped being an exercise in adding risk up across risk types and business units. It is a holistic view of the whole risk management process and of how that process bears on strategic decisions: across businesses and risk types, over a range of time horizons, using the full set of risk tools, with an eye on the environment and on the industry as a whole. How a firm thinks about risk becomes part of its corporate identity, the way it does things.
Risk management in the digital era
Digitisation is changing how firms meet their customers, through mobile devices and sensors, and it carries its own hazards in cyber risk and privacy regulation. Survey work on financial institutions has found the digital transformation of risk functions moving slowly, since banks have concentrated on customer facing operations, but the direction is clear enough. Risk measurement draws on a wider set of sources, with big data analytics applied to credit and operational risk. Decisions come faster as risk processes are automated, corporate credit scoring being one example, and productivity improves as document based review gives way to automated workflow. Legacy infrastructure, thin data and a shortage of digital skills are the obstacles, which is why the data scientist is becoming as sought after inside a risk function as the quantitative modeller once was.
Held as a checklist, the ten building blocks repay the effort, because most risk management disasters follow a failure in one of them rather than a broken model.
| Block | Name | The failure it prevents |
|---|---|---|
| 1 | The risk management process | Skipping identification, analysis, assessment or the choice of response |
| 2 | Identifying risk: knowns and unknowns | Treating an unmeasurable risk as a known quantity |
| 3 | Expected loss, unexpected loss and tail loss | Pricing for the average and holding no capital for the departure from it |
| 4 | Risk factor breakdown | Missing that two factors deteriorate together, as in wrong way risk |
| 5 | Structural change | Adding more historical data to a system that has changed shape |
| 6 | Human agency and conflicts of interest | Assuming controls are operated by people without incentives of their own |
| 7 | Typology of risks and risk interactions | Managing each category well and missing the path a loss takes between them |
| 8 | Risk aggregation | Over-depending on one aggregate metric such as VaR |
| 9 | Balancing risk and reward | Judging a business on return without charging it for the capital it consumes |
| 10 | Enterprise risk management | Letting divisions manage risk in silos |
Source: the ten building blocks as set out in the chapter. The third column is an interpretation for study purposes.