FRM 3 – The Governance of Risk Management
Banks entered the 2007-2009 crisis with boards that approved strategies they could not describe, risk functions reporting to the people they were meant to restrain, and capital rules calibrated for a quieter world. A decade of overlapping reform followed, covering how much capital a bank holds, how it is governed, and who inside it can say no.
Corporate governance before the crisis
Corporate governance describes the way a company is run, setting out what shareholders, the board of directors and senior management are each answerable for. Banking took it seriously only after a run of collapses early in the twenty-first century, when Enron, WorldCom, Global Crossing and Parmalat SpA all failed on accounting or financial fraud that auditors and boards never checked. The United States answered with the Sarbanes-Oxley Act, which makes chief executive officers and chief financial officers certify that filed reports are accurate and free of any untrue statement of a material fact, holds them responsible for internal controls, and requires disclosure of significant control deficiencies and of fraud involving anyone with a material role in those controls. Europe declined to legislate, revising voluntary corporate codes and running a comply-or-explain regime for departures from them. That work reached internal controls, governance mechanisms and financial disclosure, but not risk management. Neither approach prevented what came next.
At the centre of the capital story sits the Basel Committee on Banking Supervision, or BCBS, whose members are the central banks and bank supervisors of 27 jurisdictions and whose output is a body of international standards for prudential banking regulation. Nothing it publishes is legally binding: a standard acquires force only where a jurisdiction writes it into national law, so the framework travels by voluntary adoption.
Three strands of the post-crisis response
Reform then ran along three tracks: prudential rules on capital and liquidity, jurisdictional statutes such as the Dodd-Frank Act in the United States and the Supervisory Review and Evaluation Process, known as SREP, in Europe, and governance, where the BCBS moved onto ground previously left to company law and market convention.
That governance track opened in October 2010 with principles meant to raise corporate governance across the banking industry, covering what the board owes the firm, what qualifies somebody to sit on it, and why the risk management function must be independent of the businesses it watches. The 2015 revision pushed boards towards active collective oversight and named the parties whose roles it defines: the board itself, its risk committees, senior management, chief risk officers and internal auditors.
Behind that guidance lies a broader debate. Enquiries into the crisis found little attention paid to tail risks or to genuinely worst-case outcomes, and five concerns recur.
| Concern | What is at issue |
|---|---|
| Stakeholder priority | Deposits, debt and implicit government guarantees sit alongside equity, so depositors, debtholders and taxpayers want failure risk minimised while shareholders press for short-term results. |
| Board composition | Balancing independence, engagement and financial industry expertise. Analyses of failed banks show no clear pattern of insiders or outsiders, and Northern Rock, which collapsed, counted several banking experts among its directors. |
| Board risk oversight | Educating directors about risk and keeping a direct link to the risk infrastructure, for instance a chief risk officer reporting line to the board. |
| Risk appetite | A formal, board-approved appetite stating what threat to solvency the firm tolerates, translated into enterprise-wide limits. |
| Compensation | Whether pay structures encourage risk-taking and whether risk adjustment reaches the long-term risks. |
Source: the post-crisis governance debate in banking.
Basel I, 1988
The first accord followed the Latin American debt crisis of the preceding decade, and its ambition was modest: one method for judging whether a bank held enough capital. Credit risk was almost the sole focus. Risk weighting was the innovation, since it stopped treating a government bond and an unsecured corporate loan as equivalent, and the prescribed minimum was 8% of risk-weighted assets.
Basel II, begun in 1999 and finalised in 2006
Work on a replacement began at the BCBS in 1999 and finished in 2006. Basel II left the 8% headline alone and rebuilt what sat underneath it, bringing trading activity into the risk calculation alongside lending and refining the weighting methodology, which made it more risk-sensitive than its predecessor. Two additions came with it: standards for supervisory review, and disclosure requirements meant to reinforce market discipline through transparency.
Basel III, a direct answer to the crisis
Many jurisdictions were still implementing Basel II when the crisis broke, so Basel III landed on a framework that had never fully arrived. Its aim was systemic resiliency, addressing firm-specific risk and systemic risk together. Systemic risk here means the danger that one major financial institution fails, drags down the interconnected institutions around it, and inflicts major harm on the economy.
Most of the reforms phased in under Basel III still concern capital adequacy: what regulatory capital must cover, how much there must be, and what it consists of. Core Tier 1 capital is restricted to common equity and retained earnings, which absorb losses in a way hybrid debt does not. Tier 1 capital, also called core capital or primary capital, is the sum of common stock, retained earnings and certain reserves.
Liquidity requirements were new to Basel III, and two ratios cover two horizons: the 30-day Liquidity Coverage Ratio, or LCR, and the one-year net stable funding ratio, or NSFR. The NSFR has a second purpose. Cutting reliance on wholesale short-term funding counters pro-cyclicality, since funding of that kind disappears exactly when a credit crisis arrives, forcing banks to dump assets at depressed prices and pushing prices down further.
Capital adequacy alone treats each bank as an island, and the crisis showed that the dangerous exposures were the ones running between institutions. Basel III therefore added the macroprudential overlay, a layer of requirements aimed at the system as a whole, with two objectives: cut systemic risk, and lessen procyclicality.
The five elements of the overlay
Five items make up the list. First, a leverage ratio of 3%, a simple backstop that does not depend on risk weights, which can be modelled downward. Second, a countercyclical capital buffer, which builds capital in good years so that it can be released in bad ones. Third, total loss-absorbing capital standards, abbreviated TLAC, which apply to global systemically important banks, the G-SIBs. Fourth, systemically important markets and infrastructures, the SIMIs; in over the counter derivatives the Basel Committee has pushed the market towards centralised clearing and trade reporting. Fifth, the capture of systemic risk and tail events inside risk modelling and stress testing.
Capital markets exposures and market risk
Risk-based capital requirements carried over from Basel II were widened to handle risks emanating from capital markets activity. Four are named: exposure to central counterparties, margins on non-centrally cleared derivatives, counterparty credit risk, and securitisation.
Market risk got its own overhaul through the Fundamental Review of the Trading Book, or FRTB, issued as minimum capital requirements for market risk in January 2016. Disclosure requirements were strengthened so that a bank describes and calculates risk more comprehensively and comparative risk analysis across banks becomes possible.
American banking law had been rewritten once already. Until 1999 the Glass-Steagall Act separated commercial banking from investment banking by statute. The Graham-Leach-Bliley Act of that year lifted most of those restrictions and let bank holding companies become financial services holding companies, or FSHCs, combining investment banking, commercial banking, insurance and broker-dealer businesses under one roof to encourage universal banking in the United States.
In practice the two industries stayed apart, and so did their regulatory regimes. Banking regulation covered conduct of business, meaning investor protection, alongside prudential regulation aimed at bank stability. Investment banks fell outside the reach of bank regulators and escaped prudential oversight entirely, on the view that they hardly mattered to American banking stability. The 2007-2009 crisis disposed of that view.
What the crisis did to the industry structure
The competitive landscape was rearranged inside a few months. Bear Stearns and Merrill Lynch, both investment banking giants, were merged under duress into banking institutions. Lehman Brothers went bankrupt. Goldman Sachs and Morgan Stanley, the last two major investment banks, became bank holding companies, taking on the full weight of banking regulation and gaining access to Federal Reserve System credit.
Seven things the Act attempted
The Dodd-Frank Act was signed into law in July 2010. Across 2,300 pages it reworked financial regulation in the United States with two aims, better consumer protection and greater systemic stability, and is usually summarised in seven elements.
Strengthening the Fed widened Federal Reserve authority over systemic risk and brought the systemically important financial institutions, the SIFIs, under its regulation; a SIFI meant a bank holding firm with more than USD 50 billion of assets, a threshold Congress raised to USD 250 billion in 2018, and the Fed mandate now covers macroprudential supervision. Ending too-big-to-fail was attempted through an orderly liquidation authority, the OLA. Resolution planning requires each SIFI to lodge a living will with the Federal Reserve and the Federal Deposit Insurance Corporation, the FDIC. Derivatives markets got a transparency-focused overhaul aimed at counterparty risk. The Volcker Rule bans proprietary trading and bars banking entities from owning or partnering in hedge funds and private equity funds; named for former Federal Reserve Chairman Paul Volcker, it took effect in July 2015, and a proposed 2018 reform would exempt banks below USD 10 billion in assets. Consumer protection arrived as the Consumer Financial Protection Bureau, the CFPB. Stress testing, the seventh element, changed enough to need separate treatment.
Dodd-Frank instituted a radically new approach to scenario analysis and stress testing. It is top-down, built on macroeconomic scenarios running over several quarters, and it traces a downturn through credit, liquidity, market and operational risk at once. Non-stationary risk drivers make it computationally demanding, and it is realistic in letting portfolios be actively managed rather than frozen. It sits inside a bank’s own planning, and it examines banks collectively, so supervisors can see how one scenario would strike the largest institutions together.
The two Federal Reserve Board exercises
The Federal Reserve Board runs two exercises. The Dodd-Frank Act Stress Test, or DFAST, covers banks above USD 10 billion of assets, and the Comprehensive Capital Analysis and Review, or CCAR, covers those above USD 50 billion, though the 2018 reform made it mandatory only above USD 250 billion.
CCAR is annual and uses five scenarios: three supervisory ones plus a BHC baseline and a BHC adverse case the bank holding company generates itself. Each BHC files a capital plan covering every planned action across a planning horizon of nine quarters, dividend increases, share repurchases and major acquisitions included, and must hold a Tier 1 ratio of 4.5% or better throughout. Beside that hurdle sits a qualitative assessment of the internal processes behind the plan, which a bank can fail after clearing the arithmetic.
The European response
Europe took its own path through the Supervisory Review and Evaluation Process, SREP, which applies to banks inside the Single Supervisory Mechanism. Three principles define it: a forward-looking focus on whether each business model is sustainable; an assessment methodology drawn from industry best practices; and the expectation that every bank eventually meets the same standards. ICAAP, the internal capital adequacy assessment process, shows how scenario analysis and stress testing support capital planning, and ILAAP covers liquidity, meaning losses from asset liquidations and costlier funding under stress.
Any European bank holding EUR 30 billion of assets or more must also sit European Banking Authority stress tests, run at consolidated banking group level and excluding insurance. The regulator supplies a baseline and an adverse macroeconomic scenario over a three-year period. Unlike CCAR, the EBA approach is static: a bank measures only the immediate effect of the cumulative shocks.
A bank holding company with total assets of USD 60 billion, above the original CCAR threshold, reports risk-weighted assets of USD 30 billion and Tier 1 capital of USD 2.1 billion. Its capital plan proposes dividends and buybacks of USD 200 million over the horizon. Under the severely adverse supervisory scenario, projected cumulative losses cut Tier 1 capital by USD 900 million while risk-weighted assets stay at USD 30 billion.
Risk governance is the organisational infrastructure that turns intentions about risk into procedures somebody follows. Two components define it. One is structural: formal procedures for defining risk, implementing risk management and overseeing both. The other is informational: transparency, plus communication inside the organisation and outward to stakeholders and regulators.
How far these arrangements are written into law varies between jurisdictions. In 2012 the World Bank set out standards for risk governance in financial institutions, aimed at making risk management and control more effective.
Three questions the infrastructure has to answer
Three questions organise the design. Are corporate governance best practices connected to best practice in risk management, and by what mechanism? Through what route is risk management delegated, and what do executive staff and board committees each contribute? By what path does risk policy reach business managers and shape ordinary business? The setting here is banking, but the concepts carry over to other corporations.
The four basic choices
Boards sometimes treat risk management as too technical to supervise, although the strategic principles underneath it are simple. Only four choices exist for any corporate risk. The first is whether to undertake the activity at all. The second is whether to transfer all or part of the risk to a third party, through insurance policies, hedging activities and similar arrangements. The third is whether to mitigate it pre-emptively by early detection and prevention. The fourth is whether to assume it, fully aware of the upside and the downside.
Whichever combination a firm picks, implementation runs across the whole enterprise under unified policies and methodologies, an approach known as enterprise risk management. The supporting infrastructure, physical resources and operational processes alike, has to be built for that scope.
A corporate board exists first to protect the interests of shareholders, and has traditionally been cast as their gatekeeper. Many analysts now argue for a wider remit covering every corporate stakeholder, debtholders and employees included. That is difficult, because debtholders care mainly about extreme downside risk while equity holders may prefer the gamble.
Overseeing executive management is the other founding duty, and analysing the risks and returns thrown off by corporate activity is fundamental to it. Where management assumes a risk, the board has to grasp the type of threat and its likely size.
Strategy, risk appetite and capital planning
In risk governance the board’s first responsibility is to weigh the fundamental risks and rewards engendered by the business strategy, which only works if it understands where the institution is heading and why. So it joins strategic planning proactively and outlines the appropriate risk appetite.
Risk appetite is bound up with business strategy and capital planning. Some activities are categorically inappropriate for a given enterprise because of the type of risk they carry. Others depend on their scope relative to total asset value, which makes size rather than the activity the deciding factor. Business planning therefore takes risk management into account from the outset, and matching strategic objectives to appetite belongs inside that process. Communicating appetite and the current risk position allows limits to be set on individual risk-bearing activities.
Oversight, transparency and accountability
Oversight and risk transparency belong to the board as well. It has to satisfy itself that any major transaction fits the authorised risk and the attached business strategies, and that disclosure to managers and relevant stakeholders is adequate and compliant with internal rules and external regulation. The board is ultimately responsible whenever risk policy is ignored or violated.
That means judging whether the firm has an effective risk management system for pursuing its objectives inside its appetite, and confirming that procedures exist for identifying, assessing and handling each type of risk: business, operational, reputational, market, liquidity, compliance and credit. Wilful excessive risk-taking lies behind many corporate failures, as does failure to spot a risk in time.
Conflicts between management and shareholders sit at the centre of what a board is for. The financial literature calls them agency problems, and they surface most often as unwarranted risk taken for short-term profits, which sets management directly against longer-term stakeholders. An agency problem is not a dispute between senior management and other internal management: it runs between management and the owners and other long-term stakeholders.
Conflicts of interest are cheap to create, which makes agency risk permanent rather than episodic. Stock options show the mechanism: an option pays only once the share price clears a certain level, so granting them can encourage actions that lift the price temporarily while damaging the firm later. No compensation system fully removes the temptation to chase short-term results, which is why executive compensation became a major concern after the crisis.
The agency risk this produces is the main argument for a board independent of executive management, and for the recommended practice of separating the role of CEO from that of board chairman.
MF Global, 2010 and 2011
The bankruptcy of the brokerage firm MF Global in 2011 shows what happens when that independence is doubtful. In 2010 the firm appointed Jon Corzine as both chairman of the board and CEO, combining the two roles that best practice keeps apart. As a United States Senator, Corzine had worked on drafting the Sarbanes-Oxley Act in 2002. Liquidity and compliance problems already troubled MF Global when he arrived.
Under his leadership, and over repeated warnings from the firm’s chief risk officer, MF Global built very large proprietary positions in European sovereign debt. Those positions soured in 2011 and worsened the liquidity problems. Shareholders and clients lost confidence, and the firm collapsed. It allegedly misappropriated client funds along the way in an effort to stay solvent, which brought action by the United States Commodity Futures Trading Commission against Corzine and the firm’s assistant treasurer. The failure was a chain: combined chairman and CEO roles, warnings without authority, a concentrated position, and client money used to plug the hole.
Judging whether a risk management system is fit for purpose looks daunting and is not impossible. One practical route ignores the models and looks at the people: who is employed to manage risk, and where they sit in the hierarchy.
Four questions do most of the work. Does the risk manager belong to the executive staff, and does the job lead anywhere, or is it a terminal posting? Where does the role report, what authority comes with it, and how independent is it in practice? Is the pay competitive against employees rewarded for performance, traders above all? Is the ethical culture strong enough to resist bad actors, are the standards clear, and does anybody enforce them?
Metrics, pay and the quality of information
The board evaluates the performance metrics and the compensation strategy too, confirming that executives are paid for risk-adjusted performance and that the incentives buried in their pay do not collide with shareholder interests.
Information quality is the other board-level concern. The board should satisfy itself that what it hears about the implementation of risk management is accurate and reliable, drawing on the chief executive, other senior executives, internal auditors and external auditors. Directors also build their own knowledge, since a tough question is worth little if the answer cannot be tested.
Oversight without daily involvement
Comprehensive scope does not mean running the function: the board makes sure the processes for delegating and implementing risk decisions perform as planned. Directors need training on risk issues and on defining risk appetite, and they must gauge the firm’s risk capacity over a stated horizon while weighing the mix of business activities, earnings goals, strategic objectives and competitive position.
A board risk committee is expected as well, staffed by members with the analytic sophistication and business experience to take apart the key risks, and kept separate from the audit committee.
Publishing a risk appetite statement, or RAS, is a component of corporate governance. The Financial Stability Board, the FSB, describes an RAS as “a written articulation of the aggregate level and types of risk that a firm will accept or avoid in order to achieve its business objectives.” Qualitative and quantitative statements both belong in it, and the FSB adds that it should reach risks that resist quantification, naming reputation and conduct risks along with money laundering and unethical practices.
Objectives are stated plainly. A published statement typically commits the bank to safeguarding its reputation and brand, doing right by clients and other stakeholders, entering client-oriented businesses only once the risks and rewards are understood, balancing risk against return, keeping a prudent stance on tail and event risk, meeting regulatory expectations, holding a target credit rating, and meeting stakeholder expectations on environmental, social and governance criteria. On content, the FSB position is that an effective statement carries the assumptions behind the approved strategic and business plans, and connects to the short-term and long-term strategic, capital and financial plans as well as to compensation programmes.
The measures inside it cap risk at the level of the individual business unit and of the organisation. Shareholders should also see a summary of the key risk policies and limits, running down each risk type, from credit and trading credit through market, operational, reputation, liquidity, regulatory and strategic risk, with the framework or policy that governs it, the limits that bind it, whether concentration limits, delegated approval authorities, key risk indicators or funding limits, and the committee accountable for oversight.
Capacity, appetite, tolerance and profile
Four related terms blur easily. Risk capacity is the maximum the firm could absorb. Risk appetite is a broad aggregate measure of the amount at risk the firm has chosen to accept, set far enough beneath capacity that actual risk never approaches it. Risk tolerance is the range of acceptable outcomes around a business objective, tactical rather than aggregate. The risk profile is where the firm stands today.
Holding the profile inside the tolerance bands is the operating goal, which gives management reasonable comfort that the desired risk-adjusted returns are reachable while the amount at risk stays capped.
Directors cannot oversee a firm they see only through management’s own reporting, and the audit committee solves that problem. An audit gives the board independent verification of what the firm is genuinely doing, which marks the committee off from every other risk committee in the structure.
Accuracy and completeness of financial and regulatory disclosure fall to it, as does compliance with best-practice standards in non-financial matters, since regulatory, legal, compliance and risk management activities all sit inside its purview. Preparing the annual financial report is not one of its duties; the committee assures instead that the process behind it was properly controlled and produced accurate results.
Quality as well as accuracy
Hunting discrepancies is only half the job, because the committee also judges the quality of financial reporting, of compliance, of internal controls and of the risk management process, not merely whether each is truthful. A review of the financial statements shows the difference: it confirms the statements are accurate, and separately confirms that the firm has dealt adequately with the risk of a material misstatement.
The crisis showed how often this failed: audit committees at many firms never uncovered the excess risk in proprietary trading, and never warned their boards about disproportionately large holdings of structured credit products.
Who sits on it
Members have to be knowledgeable, financially literate, capable of independent judgement, and of the highest integrity, with the temperament to challenge management when the moment demands it. Sarbanes-Oxley made part of that explicit for listed firms: the names of the audit committee directors are disclosed, and they are expected to understand accounting principles, read financial statements, and have experience of internal audits and of the committee’s own functions. In most banks the chair is a director from outside the executive staff, and most other members are independent too. Relations with management can turn adversarial, and both sides still need open communication.
In most firms the audit and risk management committees of the board approve the important risk policies, review how they are implemented, and test whether they work. Their translation job matters most: they cut the approved appetite into practical limitations that executive staff and department heads spread through the organisation.
Two responsibilities define the board risk management committee. It sets the firm’s risk appetite, and it independently reviews the governance of every material risk, working through policy guidelines, methodologies and infrastructure. Direct contact with external and internal auditors is part of the design, since it improves communication between board and management.
The board usually delegates approval and review of risk levels to this committee, with its role formally documented. It watches financial, operational, business, reputational and strategic risks, and reports on matters such as extending special credit beyond the limits the board has set.
Why a risk advisory director helps
Expecting a whole board to analyse the financial condition of a complex risk-taking corporation is unrealistic, and financial institutions are exactly that. The problem grows where independent directors come from industries outside financial services, since executives have historically found it easy to baffle non-executives who lack the skill or confidence to push back. Director training and outside professional support both help.
Another route is to seat a risk specialist on the board, normally an independent and not necessarily voting member whose field is risk analysis and management and whose purpose is to make the executive risk committee and the audit committee more effective. The work means examining risk governance against the policies the board approved and the methodologies used to execute them. Such risk advisory directors keep colleagues current on best practice and give a professional opinion on the risks in the core business model and in areas the firm wants to enter.
Below the board, authority runs downward and reports run back up. Once a year the board risk committee approves the firm’s appetite, expressed in broad but clearly defined risk metrics such as the total interest rate risk the bank will carry. The senior risk committee, chaired by the CEO and normally including the CRO, the CFO, the treasurer, the chief compliance officer and the heads of the business units, is then empowered by the board to implement and oversee the risk appetite framework.
Acting on that authority, the senior risk committee fixes the limiting parameters for financial risk such as credit and market risk, and for nonfinancial risk such as business and operational risk. Sub-committees may take one risk type each, so a credit risk committee would cap the size and type of credit risk taken and supervise its reporting. The committee then returns to the board with recommendations on the total risk it judges prudent.
What the chief risk officer does
Establishing, documenting and enforcing corporate risk policies belongs to the senior risk committee, as does setting limits for particular business activities, which pass to the CRO. Usually a member of that committee, the CRO designs the risk management programme and owns the policies, the analysis methodologies and the infrastructure behind them.
Day-to-day decisions are delegated to the CRO, including approval of risks above the preset limits on individual activities, so long as the exceptions stay inside the board-approved ceiling. A business unit may be authorised to run risk up to a stated maximum, its mandate monitored by the CRO and reviewed periodically by the senior risk committee. An approval normally lasts a year, though the CRO may extend a mandate to fit the committee calendar.
Authority and independence
CROs generally sit on the management team, so their authority and independence have to be granted deliberately rather than assumed. A CRO should help set risk strategy from the outset, share in implementation and managerial oversight, report straight to the CEO, sit on the board risk committee, and have a say in approving new financial instruments and new lines of business. The essential piece is a clear mandate to escalate anything that might compromise the appetite guidelines or the risk policy.
Many banks also use the CRO as a liaison, keeping directors informed about risk tolerance and programme performance, and carrying the board view back through the firm. Monitoring is continuous, and the CRO may instruct a unit to reduce or close positions where exposure warrants it.
Firms may add a business risk committee for each significant line of business, staffed by business and risk personnel together, so unit decisions match the risk and reward tradeoff the organisation wants. Such a committee can be given authority over policies for business-specific risks and over detailed reviews of business-level limits.
Limits are how risk governance reaches the trading desk, and suitable ones are needed for each business, for the risks that business runs, and for the whole portfolio of the enterprise.
Market risk limits constrain what price, interest rate and currency movements can do to the firm. Credit risk limits cap exposure to default and to deterioration in credit quality, from lending or from derivative transactions. Other categories reach the policy agenda too: asset and liability management, liquidity, even catastrophe risk. The form a limit takes follows the risk in question and the range of the firm’s activities, and best practice documents the processes for setting limits, reviewing exposures, approving exceptions and analysing methodologies.
Measurement is analytical where it can be. Credit exposure can be broken out by risk grade, and risk-sensitive methods such as VaR work well for typical portfolios in normal markets. They work poorly under stress and for specialised portfolios, which is why scenario analysis and stress testing belong inside the limit framework.
Two tiers
Banking entities generally run two kinds of limit. Tier 1 limits are specific, normally an overall ceiling for each asset class, an overall stress-test ceiling and a maximum drawdown. Tier 2 limits are broader, covering areas of business activity and aggregated exposures sorted by rating, industry, maturity or region. Once limits are computed on one basis and stated in economic capital or another common unit, Tier 2 ceilings apply across business lines.
The CRO proposes the standards for the metrics behind the limits and the internal risk committee approves them. A limit should be pitched so that breaching it in the normal course of business is unlikely, which means studying how the unit has behaved historically and leaving it a margin for error.
A bank designs its Tier 1 market risk limits so that ordinary exposures run between 40% to 60% of the ceiling under normal market conditions, with peak utilisation at 75% to 85% of it. Other organisations may set these illustrative levels higher or lower. A currency trading desk has averaged daily exposure of USD 6.0 million over the past year, peaking at USD 9.6 million.
Setting a meaningful limit begins the risk management process rather than ending it, since an unchecked limit is only a statement of intent. Market risk, the most time-sensitive category, needs continual watching.
Daily valuation of asset positions is the foundation. Profit and loss statements should be produced outside the trading department and delivered to executive management on the non-trading side, and every assumption inside the valuation models verified independently. How closely the trading team follows its market risk ceilings should be documented promptly, and the procedures separating an acceptable exception from an unacceptable violation belong in writing.
Judging the valuation methods is part of the same work. The gap between the volatility a portfolio actually shows and the volatility the methodology predicted should be reviewed regularly, and stress tests should establish what a material move in market or credit risk would do to earnings.
Where the data comes from
Intra-day trading exposures may have to be pulled from the accumulated client orders of the day, since where speed matters the front office is often the only feasible source. Data for monitoring market limits should instead come from consolidated market data feeds unconnected to front office systems, reconciled against the bank’s own books and formatted so that VaR calculations can run on it.
Exceptions and escalation
Under limits of either tier, business units follow strict protocols on disclosing an expected violation before it happens. The CRO has to hear about a potential deviation well in advance, and an excess flagged early stands a better chance of approval than one discovered afterwards.
Where a limit is breached, the risk function records every excess at once on a daily limit exception report, separating the two tiers and stating the circumstances, the rationale and the remedy. A Tier 1 exceedance is cleared or corrected immediately; a Tier 2 exceedance may be resolved over a few days or a week. All of them then reach an enterprise exception report from the CRO, which gathers exceptional risk activity firm-wide for the daily risk meeting, and nobody, the CEO included, may keep an exceedance off it.
Limits carry an opportunity cost, since blocking risk means forfeiting profitable business, so the bank weighs cost, benefit and risk before granting an exception.
The currency desk above now works under a Tier 1 limit of USD 12.0 million. Unit heads must raise an alert once exposure reaches 85% of a limit. A client transaction would lift the desk to USD 11.5 million for four trading days.
A clear lesson of the global financial crisis is that the compensation schemes then prevailing at many financial institutions rewarded short-term risk-taking, which led management to underestimate long-term risks and at times to ignore them. Bonuses geared to short-term profit, or to the volume of business written, gave bankers and traders every reason to front load income and push risk into the future.
The payoff shape explains the behaviour. These schemes were structured like call options: unlimited upside, capped downside. Executives collected when the bank posted profits, and losses carried no real penalty. Add heavy leverage, and staff could bet the bank.
Many jurisdictions now oblige public firms to run a dedicated board compensation committee, because chief executives have long been well placed to talk directors into generous awards at the expense of shareholders.
What good practice looks like
Compensation is now accepted as part of a sound risk culture. It should line up with the long-term interests of shareholders and with risk-adjusted return on capital, pushing employees towards calculated rather than reckless risks, and building risk into performance milestones has become leading practice. Pressure runs the other way as well, since firms will always pay heavily for the rainmakers who generate revenue, and without international cooperation that market invites regulatory arbitrage.
The G-20 recommendations
In September 2009 the G-20 countries asked their central bank governors and finance ministers to build an international framework for financial stability, compensation reform included. Endorsing the FSB implementation standards, the recommendations ran to five points: no more multi-annual guaranteed bonuses; downside exposure for executives, through deferral of part of the award, share-based remuneration rewarding long-term value creation, and clawback provisions requiring repayment where longer-term losses follow the payout; a ceiling on variable compensation relative to total net revenues; disclosure requirements to improve transparency; and independence for the committees overseeing executive pay.
By 2014 the FSB reported implementation essentially complete across almost all its jurisdictions, and some went further than the standards asked. European Union regulators adopted bonus caps of 100% of an executive salary, rising to 200% where two-thirds of shareholders approve.
Why share-based pay is not a complete answer
Share-based compensation is meant to put executives in the same boat as shareholders, which in theory restrains excessive risk-taking. Practice is untidier: employees of Lehman Brothers held approximately one third of the firm’s shares before it collapsed. Owning shares can even encourage risk-taking, since the gain has no ceiling while the loss stops at the amount invested.
One remedy makes employees creditors as well as owners, through restricted notes or bonds tied to compensation. The Swiss bank UBS did this in 2013, paying its most highly compensated staff partly in bonus bonds forfeited if the regulatory capital ratio drops below 7.5% or the firm needs a bailout. The European Banking Authority had argued similarly in December 2012, proposing that senior bankers take part of the annual bonus in bonds that would absorb losses in a crisis.
An executive at a European Union bank has a fixed salary of EUR 400,000. The bank works under the local bonus cap regime and pays part of variable compensation in bonus bonds forfeited if the regulatory capital ratio falls below 7.5%.
Implementing risk management at nearly every level of the enterprise is staff work rather than board committee work. Executives and line business managers act together to manage, monitor and report the risks being run.
Senior management sets business level risk tolerances, designs and manages policy, and evaluates performance. The business line takes on and manages exposure to approved risks and verifies valuations. Risk management drives the development and implementation of risk policy, monitors limits, controls model implementation risks, and hands senior management independent risk assessments. Finance and operations sets valuation and finance policy, oversees official valuations including independent verification, supports the analyses business planning requires, and ensures proper settlement, deal capture and documentation. Business managers also verify timely, accurate and complete deal capture and affirm official profit and loss statements.
Operations does more than implement, since it carries oversight of its own. Inside an investment bank it independently executes, records and settles trades, reconciles front and back office positions, and prepares earnings reports and independent valuations of positions, mark-to-market among them. The finance group writes valuation and finance policy, vouches for the accuracy of reported earnings, reviews independent valuation methodologies, and manages business planning.
A risk management process that conforms to risk governance keeps unbridled risk from accumulating. What it cannot do by itself is establish whether the policies the board approved, and the external regulations binding the firm, are genuinely being complied with. Filling that gap is the audit function, and ensuring the set-up, implementation and efficacy of risk management and governance falls to internal audit.
Regulators generally expect internal audit to review every process, policy and procedure attached to risk management. A comprehensive review assesses how the risk control unit is organised and documented, then analyses the integrity of risk governance and how well the risk management process works, including how far risk measures reach daily business management. Auditors also review monitoring procedures, track progress on risk management system upgrades, judge whether application controls adequately generate and secure data, affirm that vetting processes work, and compare compliance documentation against the qualitative and quantitative criteria set in regulatory guidelines.
What the audit examines in market risk
Market risk shows the pattern. Auditors examine the vetting process for the derivative valuation models used by the front office and the back office, sign off on significant changes to risk quantification, and validate the range of risks the measurement models capture. They inspect the reliability of information systems and the completeness of the data behind the metrics, and they judge how far a VaR reporting framework can be relied on. The central task, though, is judging whether risk measurement is well designed and conceptually sound: back testing investment strategies to validate market risk models, evaluating the risk management information systems that quantify risk across the enterprise, and questioning the assumptions behind volatility, correlations and other parameter estimates.
Standards and the independence boundary
A risk management function can be rated, internally or by third parties such as rating agencies comparing several firms. No single formula defines excellence, and a rating still makes comparison possible. The Institute of Internal Auditors supplies the professional backbone through its International Professional Practices Framework, where mandatory standards and an ethical code define what professional practice requires while recommended guidance explains how to apply them. Whether audit should also oversee operational risk management is argued both ways. Implementing risk management stays separate from auditing it, because auditor independence from the activity under review is what gives any opinion offered to the board its value.