FRM 8: Enterprise Risk Management and Future Trends
Enterprise risk management, almost always shortened to ERM, brings the viewpoint and the resources at the top of a company to bear on the whole collection of risks that company runs, and lets that view shape strategy. The older habit is to handle each exposure wherever it arises. Industry shorthand for it is silo-based risk management, sometimes stove-pipe risk management, and under either name a business unit owns whatever risks it generates and reports on them alone.
Silos are not stupid. Working inside one category at a time makes definition and measurement tractable, since financial models are built around a single risk type, aggregation is clean inside a business line, and derivative instruments, the usual hedging tool, are themselves risk specific. Regulators lean the same way: under Pillar I of Basel III, banks hold minimum capital separately against credit risk, market risk and operational risk, while Pillar II, the supervisory review process, catches what remains.
Where the silo view runs out
The trouble starts as soon as a firm asks how its exposures compare. Ranking tells a company where to spend its effort first, and no ranking is possible while each unit reports in its own units of measurement. At the level of the whole company, exposures also cancel out, through netting and diversification, or pile up, through concentrations, through contagion, and through the way a weakness in one risk type surfaces as a loss in another.
Those effects are invisible from inside a business line, which is the gap ERM fills. An enterprise risk is any risk big enough to leave the outcomes of the whole firm materially short of its goals. ERM also makes the treatment of risk consistent from the boardroom to the branch, through a shared risk culture and common risk appetites and governance. Without it, one unit turns down a transaction on risk grounds while a comparable one is welcomed a floor away.
Cross-over risk and the Northern Rock example
A soft spot in one area of risk management is often a soft spot somewhere else, and the connection only becomes obvious after the loss. Northern Rock learned this early in the global financial crisis of 2007-2009. The bank had grown quickly on funding drawn from wholesale markets and investors rather than from its own customers’ deposits, and it tried to dilute that concentration by geography, reaching past the United Kingdom into continental Europe and the United States. Geographic spread was no defence once investors backed away from banks judged to have risky lending books. Officials afterwards called a shutdown on that scale “unforeseeable”, in evidence recorded by the House of Commons, Treasury Committee, in “The Run on the Rock”, January 2008, p. 16.
Set the two approaches side by side and the differences fall into a short list, running from what each one looks at to how it connects with the balance sheet.
| Traditional risk management | ERM view | |
|---|---|---|
| Field of view | Each business line, risk type and function examined alone | Exposures read across lines, functions and types, with diversification and concentration in view |
| People | Risk staff work apart | One team under a global risk management committee and a chief risk officer |
| Metrics | Measures that will not compare, apples against oranges | Cross-risk metrics such as Value-at-Risk and scenario analysis, so comparisons run apples to apples |
| Aggregation | Totals formed inside a line or risk type if at all, and the whole picture stays out of focus | Integrated tools track enterprise risk accurately, potentially across several risk types at once |
| Risk transfer | A separate instrument for each risk type | Transfer costs cut firm-wide, and one integrated multi-trigger instrument covering several risks |
| Choice of response | Avoiding, retaining, mitigating and transferring treated separately, and the mix rarely optimized | Each response is a component of a total cost of risk in one currency, and the mix is optimized in risk and reward terms |
| Balance sheet | Managing and transferring risk cannot be joined to balance sheet management | Joined up with balance sheet management, capital management and financing strategy |
Source: the chapter comparison of ERM with silo-based risk management.
Firms do not build an ERM function because the theory is attractive, but because specific problems keep arriving on the chief executive’s desk and none of them belongs to a single business line.
| Benefit | The problem it answers | |
|---|---|---|
| 1 | Defining enterprise risk appetites and adhering to them | Appetite exists on paper but never reaches risk takers |
| 2 | Pointing oversight at the most threatening risks | Committee time spread evenly over unequal risks |
| 3 | Identifying enterprise-scale risks generated at business line level | A decision that looks small locally is large firm-wide |
| 4 | Managing risk concentrations across the enterprise | One name, sector, region or supplier held in several units |
| 5 | Managing emerging enterprise risks such as cyber risk, anti-money laundering (AML) risk and reputation risk | New risks have no natural owner among the silos |
| 6 | Supporting regulatory compliance and reassuring stakeholders | Supervisors and investors ask firm-wide questions |
| 7 | Understanding risk-type correlations and cross-over risks | Losses travel between risk types unwatched |
| 8 | Optimizing risk transfer expenses against risk scale and total cost | Cover bought piecemeal and duplicated |
| 9 | Putting stress scenario capital costs into pricing and business decisions | Products priced as if stressed capital were free |
| 10 | Carrying risk into the choice of business model and into strategy | Strategy set first, risk function consulted later |
Source: the top ten benefits of ERM in the chapter. The right column is an interpretation for study.
If the case for a joined-up view is as strong as it looks, why is ERM still a work in progress? The task is genuinely hard, and risk management grew up one specialism at a time.
From the insurance buyer to the chief risk officer
An early version of the same move happened outside banking. Large corporations in the United States spent the 1950s and 1960s pulling together insurance purchasing that had been scattered across divisions. Pooling risk through an insurer is expensive for a firm with a good claims record, and once buying was centralized the choice became visible: pay an outside insurer, or hold part of the exposure against the firm’s own capital through self-insurance or a captive insurance company. Retaining a risk means understanding it, which pushed firms into collecting risk data, and the job title risk manager dates from this wider role.
Financial market liberalization during the 1970s raised price volatility and brought new derivative instruments into interest rate, commodity and foreign exchange markets. By the 1990s, financial institutions had concluded that derivatives books and the economic exposures behind them had to be managed together. Banks built global risk management divisions first and large corporations followed, appointing chief risk officers (CROs) responsible for every type of risk and adopting universal metrics, Value-at-Risk (VaR) above all, so exposures across the firm could be compared and added.
The mid-1990s supplied a warning in the form of derivatives disasters, Barings Bank among them, showing that one individual outside any real control framework could destroy an institution. Credit risk management widened over the same period from the ratings of individual obligors to active management of whole credit portfolios, using credit derivatives among other tools. By the late 1990s operational risk was being tracked and measured, and some institutions were trading newly transferable exposures such as weather risk and political risk. New global risk committees then did for enterprise risk what VaR had done for market risk.
What the crisis exposed, and what surveys show now
Integrating ERM across a large enterprise remains difficult, because firms prefer to leave responsibility with the business line, which sits closest to the source of the risk. They keep returning to it anyway, since managing risk properly demands a portfolio manager’s perspective. Some benefits were visible by the early 2000s. Then the crisis of 2007-2009 exposed what was missing: aggregate risk measures were not applied properly, concentrations spanning several business lines went unidentified, and some business models contained risks nobody had seen. Regulators afterwards pressed harder on risk appetite and risk capacity, on data aggregation and reporting, and on enterprise-level scenario analysis and risk culture.
Adoption has climbed. Deloitte surveyed 94 financial institutions in 2018 and found 83% running an ERM program, against 73% in 2016, with 95% having a CRO. Reporting lines were the sore point: 25% of respondents placed no line from the CRO to the chief executive officer, and roughly half placed none to the board or a board sub-committee, although the surveyed view was that the CRO should answer to both. Aside from data and information technology problems, three issues were rated extremely urgent or high priority by more than half of those asked: regulatory requirements and expectations that keep growing, collaboration between business units and the risk function, and establishing risk culture across the enterprise.
How ERM is organized depends heavily on the size and type of firm, so there is no single blueprint. Programs often run through the senior management risk committee, and other committees such as the credit risk committee may take on ERM work of their own. Non-financial firms without elaborate committee structures sometimes create a dedicated ERM committee. Any program can be read along five dimensions.
| Dimension | The question it answers | Examples |
|---|---|---|
| Targets | What are the enterprise goals? | Enterprise risk appetite, enterprise limit frameworks, risk-sensitive business goals and strategy formulation |
| Structure | How is ERM organized? | Board risk oversight, global risk committee, risk officer, ERM subcommittee, reporting lines and reporting structures |
| Identification and metrics | How is enterprise risk measured? | Enterprise-level metrics, enterprise stress testing, aggregate measures such as Value-at-Risk, Cash-Flow-at-Risk and Earnings-at-Risk, total cost of risk approaches, risk mapping and flagging, choice of limit metrics |
| ERM strategies | How is enterprise risk managed? | Enterprise level risk transfer strategies and instruments, and enterprise monitoring of how business lines handle enterprise-scale risks |
| Culture | How are things actually done? | Tone at the top, accountability for key enterprise risks, openness and effective challenge, risk-aligned compensation, staff risk literacy, whistle-blowing mechanisms |
Source: the five key ERM dimensions in the chapter.
Targets are where risk appetite meets strategic goals, and appetite only becomes real once it is wired into machinery such as global limit frameworks and incentive compensation schemes. Structure covers the board, the risk committees, the CRO and the governance framework, and ERM asks that every part of it becomes sensitive to enterprise-scale risks, indirect losses included.
Identification and metrics come third because target setting and a redrawn committee map achieve nothing if the firm cannot name its enterprise-scale risks and gauge their severity, impact and, where possible, frequency. ERM strategies are the choices about what to do with such a risk, whether to avoid, mitigate or transfer it. Culture gives the other four their life, growing out of goals, practices and behaviors shared widely enough to be felt everywhere.
It is tempting to score a firm’s commitment to ERM by counting attributes: an appetite statement exists, a CRO has been appointed, a stress testing program runs. Counting is the wrong instrument, because what decides whether a program works is the way the dimensions act on one another.
Appointing a CRO is the clearest illustration. That appointment can produce a genuine improvement in enterprise stress testing, or it can amount to cynical re-badging that alters nothing, and the organizational chart looks identical either way. Equally, better metrics will not improve risk management inside a firm whose risk culture is unhealthy, because the results will be filed rather than acted on.
Programs that look mature often have holes in them. Surveys suggest only around half of CROs review what compensation plans are doing to the firm’s risk appetite and culture, which is hard to defend given that pay is one of the few levers that reliably changes behavior. Good practice has specific markers: appetite that reaches both the limit framework and the bonus pool, a CRO reporting to the chief executive officer and the board, and enterprise-scale risks with named owners.
Does ERM actually work?
The honest test is whether wider adoption produces fewer unpleasant surprises. Empirical research returns mixed answers. Some studies find positive effects, measured for instance in bank default swap spreads, while others have not yet found tangible benefits. Two ordinary explanations account for much of the ambiguity: a reliable marker of successful adoption is hard to identify, since the label covers programs of very different quality, and the time series available to researchers are short.
The strongest single argument for ERM is about priorities. Only a view from the top allows risks to be ranked and effort aimed where it does most good, since size is not a fixed property of an exposure. A risk that barely registers inside a business line can grow into a threat to the whole firm, and one that alarms a business line can look trivial against the diversified portfolio of everything else the firm holds.
Large risks usually begin a long way from the board
Take a car manufacturer. A poor design choice, or a component sourced from the wrong supplier, puts a part that can fail dangerously into production. That single decision is engineered into a very large number of vehicles, and the threat reaches the manufacturer, its suppliers and their insurers through recall costs, compensation, lost sales and damage to the name. Nothing about it looked like an enterprise risk when it was taken.
Financial institutions have product factories that behave the same way. Selling a poor investment product need not look serious while the business selling it is small, but the accumulated stock of badly sold product grows with the business. Misconduct issues of exactly this shape have troubled large financial firms in recent years.
The remedy may be cheap, such as adjusting a design, or painful, such as closing a product line and dismissing the manager who ran it. Sometimes the honest answer is that the risk came from poor target setting at the top, since short-term business line priorities are usually set by headquarters. A unit cutting corners on components to protect a reported margin is responding to instructions. So ERM is also about agency risk, and about bringing risk decisions across time and across the organization into line with the appetite the firm has stated.
A line manager sees one business clearly. What that manager cannot see is the same exposure sitting in three other places. Credit concentrations are the obvious case and the largest lever in a credit portfolio: lend too much to one borrower and a single default becomes a serious loss, which is name concentration, and lend to too many borrowers in one industry and a sector downturn damages the whole loan book.
Concentrations build up quietly because the connections run between businesses rather than inside them. A bank may lend to a company in one division and, separately, take on a counterparty exposure to it in another. The usual forms are worth naming:
- Geographical and industry concentrations. Production sites clustered in one region, core information technology in one place, or over-exposure to one local economy or industry.
- Product concentrations. A derivative or retail product that has been mispriced, sold through several divisions at once.
- Supplier concentrations. Dependence on one link in a global supply chain, or on a single technology or data provider.
A bank limits total enterprise exposure to any single counterparty to USD 300 million. Four units deal with the same industrial company. Corporate lending holds a drawn term loan of USD 120 million and an undrawn revolving commitment of USD 100 million, converted at a credit conversion factor of 50 percent. The derivatives desk holds an interest rate swap with a positive mark to market of USD 18 million and a potential future exposure add-on of USD 42 million. Trade finance has issued letters of credit for USD 35 million. Treasury holds USD 25 million of the company’s bonds.
Concentrations cannot always be avoided. Insurers and banks have been wary of placing key systems, infrastructure and data with cloud computing providers, since that creates dependence on a few firms, yet the security investment those providers can afford is very large, so the cloud may be among the better answers to cyber risk and to strategic technology risk. Trade-offs of this kind are managed rather than resolved, and ERM finally asks that concentration risks are held where the firm’s risk appetite permits.
Concentration is one half of the enterprise picture. The other half is diversification, visible only from the same vantage point, and diversification across risk types matters most, because market risk, credit risk and operational risk rarely deliver their worst outcomes on the same day.
Recognizing that reduces the aggregate risk capital a firm needs to hold, and it changes the shape of the loss distribution. Many operational risk exposures are badly behaved, with long quiet stretches broken by very large single events. Combine enough of them and the enterprise loss distribution moves closer to a normal distribution, which is far easier to hold capital against.
A bank measures one-year Value-at-Risk separately in three functions: market risk USD 180 million, credit risk USD 260 million, operational risk USD 120 million. The correlations used are 0.40 between market and credit risk, 0.15 between market and operational risk, and 0.20 between credit and operational risk.
Where risk types reinforce each other
Thinking past the silos also reveals the opposite effect. Stronger consumer protection in the United States since the crisis has opened wide cross-over risks that tie credit risk to legal and reputational risk, so a lending practice that once produced only credit losses can now produce a legal claim and a reputational problem from the same facts. Northern Rock showed the same mechanism through funding, where a perceived weakness in lending quality became a funding liquidity crisis.
Consumers are almost always right to refuse insurance on inexpensive goods. If a kettle catches fire, the policy that matters is the home insurance. Firms have applied that logic at enterprise scale since the 1960s, using self-insurance and captive insurance to keep parts of their property, liability and other exposures on their own books. A captive insurance company is an insurer wholly owned by the firm or firms it insures, none of which is itself an insurance business.
Scale drives the decision. Around 20% of firms with revenue between USD 1 billion and USD 5 billion run a captive insurance unit, and that share rises above 50% among firms with revenue of at least USD 10 billion. Captives also collect risk information centrally, letting a firm check its risk taking against its stated risk appetite. The decision to retain belongs at the enterprise level, the only place the aggregate exposure is visible.
A manufacturer suffers small property damage incidents averaging 40 a year at USD 25,000 each. A commercial insurer quotes USD 1,600,000 for full cover. The alternative is a captive retaining aggregate annual losses up to USD 2,000,000, with excess cover above that costing USD 450,000 and administration USD 60,000 a year.
The same process is running now with cyber risk. Only around 12% of firms using captives write cyber cover through them, while 23% intended to do so by 2020. Growth of that kind follows understanding: enterprise assessments of cyber dependencies and vulnerabilities, then metrics for the financial impact of an event, then a decision about how much to keep. Firms that understand an enterprise risk convert that understanding into money saved, most visibly for insurable risks, where the insurer can calculate likely claims. A firm that knows its exposure after netting and diversification retains the right amount and points its resources at the risks that threaten the enterprise.
Risk culture is the set of goals, values, beliefs, procedures, customs and conventions, explicit and implicit, that shapes how people in a firm create risk, notice it, handle it and think about it. A widely used definition from the Institute of International Finance calls it “the norms and traditions of behavior of individuals and of groups within an organization” that decide how they identify, understand, discuss and act on the risks the organization faces and takes.
The word culture makes the thing sound too soft to manage. It is in fact a firm’s surest handle on ERM, in the way a strong safety climate keeps accident rates down in physically dangerous industries. Supervisory reports after the crisis of 2007-2009 identified culture as a driver of risk management failure at large financial institutions, and the years that followed supplied more evidence: the mis-selling of consumer financial products, the payment protection insurance scandal in the United Kingdom, the Libor manipulation, money laundering, and embargo breaches. The banks involved paid very large penalties and their share prices were marked down, so embedding risk culture is now a high priority for the great majority of institutions responding to industry surveys.
Culture is built in layers
Part of what makes risk culture hard to address is that it forms at three levels at once. People arrive with mindsets shaped by personality, demographics, professional standards and experience, then take on the behaviors of the group they join, complete with its local targets. Enterprise statements of appetite and values sit above both.
Financial firms are expected to form a view of the risk culture inside their institutions, and of how far it helps them stay within their risk appetites. The usual instrument is a set of key risk culture indicators. The Financial Stability Board (FSB) has specified four, not meant to be exhaustive: accountability, effective communication and challenge, incentives, and tone from the top.
| Indicator | What is tracked |
|---|---|
| Leadership tone | Whether board and executive pay supports core values, whether management actions back the risk message, and whether the board monitors strategy against risk appetite |
| Accountability and risk monitoring | Whether accountability for key risks is clear and escalation processes get used |
| Openness and effective challenge | Whether opposing views are valued, dissent is assessed, and risk management has stature |
| Risk-aligned compensation | Whether pay and performance metrics support the risk appetite and the desired culture |
| Risk appetite knowledge | Whether staff know the enterprise risk appetite and can apply it |
| Risk literacy and common language | Whether staff describe risk in shared terms and training is attended |
| Risk information flows | Whether information moves upward and sideways so that enterprise-scale risks surface |
| Risk and reward decisions | Whether executives answer benchmark risk and reward questions consistently with the appetite |
| Risk stature | Whether ERM staff have direct access to the board, and who appoints and removes them |
| Escalation and whistle blowing | Whether staff know how to escalate a suspected enterprise risk, and whether a whistle-blowing mechanism exists and is used |
| Board risk priorities | Whether the board can name the top ten enterprise risks and the disasters associated with them |
| Action against risk offenders | Whether staff who breached the appetite were disciplined, and whether people believe action follows even when the breach made money |
| Risk incident and near miss responses | Whether the firm can show what culture issues it found inside incidents |
Source: the illustrative key risk culture indicators in the chapter, a discussion list and not a regulatory checklist.
Drivers from outside the firm
A firm’s environment presses on its culture too. External risk culture drivers include economic cycles such as the credit cycle and the industry cycle, industry practices and guidelines, professional standards, regulatory standards, and country risk and corruption indices.
Firms assess culture using indicators together with internal evidence from surveys, interviews and focus groups, asking staff how they rate their own business line and how colleagues behave when facing risk and control decisions. Methodologies exist for turning those results into an overall risk culture score. Such scores track changes in quality, but they do not put a number on the losses a culture failing will produce. Some supervisors go further: the Netherlands’ DNB has run detailed assessments of individual institutions drawing on organizational psychologists, and in 34 of 54 assessments run from 2010 to 2015 it identified fundamental risks in how people behaved.
Risk indicator or risk lever? The industry badly wants indicators that prove risk culture is improving. The difficulty appears as soon as those indicators are also used to change behavior, for example when survey results feed into the performance assessment of senior managers, since managing or manipulating an indicator is far easier than managing a culture.
Education for everyone? A common enterprise language of risk is worth building, through agreed terms, concepts and procedures and a clear statement of the key ERM roles held by the board, the CRO and business line leaders. One large financial institution built a web-based game around a fictional character to bring risk-taking decisions to life, which drew mixed responses. Education has to include the board, and the test is whether it can list the top enterprise risks and relate each to the risk appetite.
Time and space. Do the same attitudes hold everywhere in the firm, and do they hold over time? Empirical work suggests risk culture forms mostly inside local business lines and not at the enterprise level, following the example of local team leaders. There is a second problem in the same family: if several business lines produce similar signals, near misses of a similar kind in conduct for instance, does the firm notice the pattern, or is each incident closed on its own?
The culture cycle. A risk culture is only fully visible under stress, so one that looks robust today may not survive a real crisis. Regulators want risk managers to carry enough weight to withstand that buffeting, but history suggests the weight drains away as the memory of the last crisis fades.
The curse of data. Firms will soon collect enormous quantities of culture-related data from surveys, indicator scores and human resources records, sick days among them, and combine it with wider risk data to hunt for patterns. Finding the warning sign inside a data set that large may need machine learning technologies rather than analysts reading reports.
Three related exercises are easy to confuse. Sensitivity testing moves one parameter in a risk model and observes how much the result moves, which identifies the variables that matter. Stress testing moves one or more key variables to stressed values and looks at what the model reports. Scenario analysis is larger: it imagines a whole situation, builds a coherent narrative explaining why the variables move as they do, and works out what that does to the firm’s portfolios. It can be entirely qualitative, though firms increasingly model the effect of each scenario quantitatively.
Scenario analysis, alongside stress and sensitivity testing, has become the leading risk identification tool in many ERM programs, because the crisis exposed the weaknesses of probabilistic metrics such as VaR. When markets stop behaving normally, relationships between risk factors break down and produce moves a VaR calculation would call inconceivable. During the market turmoil of August 2007, the chief financial officer of Goldman Sachs, David Viniar, described the firm as seeing “25-standard deviation moves, several days in a row”. Scenario analysis lets a firm reason about what an abnormal event would do across the whole enterprise, including events with no historical record at all.
| Advantages | Disadvantages |
|---|---|
| Frequency need not be estimated beyond plausibility | Probabilities are hard to gauge, so risk is not quantified |
| A scenario can be written as a transparent, intuitive narrative | Narratives grow complicated as choices multiply |
| Forces the firm to imagine the worst and gauge its effects | Imagination may fall short, understating an extreme loss or omitting an exposure |
| Concentrates attention on key exposures, key risk types and how risk develops | Only a handful of scenarios can be worked out fully, and picking the right ones is the hard part |
| Produces warning signals and contingency plans | Whether they are the right ones depends on the same selection problem |
| Needs no historical data, and works from past or hypothetical events | Choices are often prompted by the last crisis, and imaginative scenarios get dismissed as improbable |
| Sophistication is the firm’s own choice outside regulator-defined programs | Quality varies, and credibility and assumptions are hard to assess from outside |
| Results can move risk appetite, risk limits and capital adequacy | Usefulness depends on the accuracy, breadth and forward-looking quality of the program |
Source: the advantages and disadvantages of scenario analysis in the chapter.
Before the crisis, banks generally chose a short selection of historical and hypothetical scenarios to run against their portfolios. Commonly used historical credit scenarios included the Asian crisis of 1997, the Russian debt moratorium of 1998, the market effects of 9/11 in 2001, the US subprime debt crisis of 2007, the Lehman Brothers counterparty crisis of 2008 and the European sovereign debt crisis of 2010. Judgment enters at every step, since the bank decides which variables to apply to today’s portfolios and how far to carry the narrative, for instance whether a simulation of the Russian default of 1998 should also include the near-collapse of Long-Term Capital Management. Banks also build scenarios outside credit, covering equity, commodity, foreign exchange and interest rate markets, and operational events such as cyber attacks and natural catastrophes.
Regulators concluded after the crisis that the hypothetical scenarios banks had been running were far too mild, and that banks had ignored cumulative exposures across business lines, interactions between risk types, and the way market participants change behavior under stress. Supervisors now require large, systemically important banks to show that they survive scenarios that are more severe, more dynamic and more realistic. In the United States, larger banks run regulator-defined macroeconomic scenarios, set out through variables such as falls in gross domestic product, employment, equity markets and housing prices, across their whole enterprise exposure.
The sequence began with the Supervisory Capital Assessment Program (SCAP), conducted in May 2009 while the crisis was still being cleared up, and its results did much to steady market confidence in the banking system. Two annual exercises followed from 2011 onward under the Dodd-Frank Act. Dodd-Frank Act stress tests (DFAST) run at mid-year and cover banks whose assets exceed USD 10 billion. Comprehensive Capital Analysis and Reviews (CCAR) run at year end and cover banks whose assets exceed USD 50 billion, with the population defined to include firms under Large Institution Supervision Coordinating Committee oversight and firms classed as large and complex, meaning those with USD 250 billion or more in total consolidated assets, average total nonbank assets of USD 75 billion or more, or status as a US global systemically important bank holding company. In all, 18 firms took part in the CCAR exercise of 2018.
Both exercises apply the same supervisor-devised scenarios. DFAST is the more prescriptive, works with more limited capital action assumptions, and asks for less reporting. Both oblige banks to generate their own scenarios alongside the supervisory ones. The Federal Reserve produces three macroeconomic scenarios: a baseline matching the consensus forecast among major bank economists, an adverse scenario representing a moderately declining economy, and a severely adverse scenario representing a severe, broad global recession or depression alongside weaker demand for long-term fixed-income investment. The variables describing them run to output growth, unemployment, price indices for housing and for commercial real estate, equity market volatility measured by the VIX, and rate measures including the three-month Treasury bill and yields on BBB corporate bonds.
Imposing one standard set of scenarios on the largest banks also lets regulators see systemic effects and compare exposures across firms, which no individual bank’s own program could deliver.
CCAR requires each bank to trace a scenario through its own income statement and balance sheet across a horizon of nine quarters. Revenues have to be projected dynamically, along with provisions, credit losses from defaults and downgrades, management rules for new loan issuance, and regulatory ratios, all changing as the scenario unfolds. Firms also submit capital plans covering the expected sourcing and use of capital over the planning horizon, the method used to gauge capital adequacy, capital policy, and expected business plan changes likely to affect capital adequacy or liquidity materially.
For every scenario, a bank must show that it stays above the minimum capital ratios, explain how it would raise capital if it had to, and state its intentions on dividends and share buybacks. One way to hedge a potential capital shortage over the horizon is to issue contingent convertible bonds (CoCos), which are written down or converted into common equity if the institution gets into a precarious position, easing its obligations exactly when it is in a tight spot. Most existing CoCos use accounting triggers, the level of Tier 1 capital being the common one, though the trigger can also be a market-based event such as a drop in the share price. CoCos are effectively a form of insurance, and so of ERM risk transfer, that can be set off by credit, operational or systemic events alike, so the source of the risk does not have to be defined in advance. Because they lose value after a major shock, they can also support risk-sensitive bonuses that expose executives to the downside.
A bank starts a stress test with common equity tier 1 capital of USD 42 billion and risk-weighted assets of USD 480 billion, and its board has set an internal floor of 8.0 percent. Under the severely adverse scenario, cumulative pre-provision net revenue over the nine quarters is USD 24 billion, credit losses are USD 33 billion, trading and counterparty losses are USD 6 billion, and planned distributions are USD 3 billion. Risk-weighted assets end the horizon at USD 500 billion.
Other supervisors run their own programs with mixed results. The European Banking Authority (EBA) has seen less immediate success than the authorities in the United States. Set against CCAR, its exercise is more static, less sophisticated, and allows less latitude to alter risk and business strategies as a scenario unfolds, largely because the EBA covers a far wider range of banks. The bigger improvement in Europe may come instead through the European Central Bank’s Supervisory Review and Evaluation Process (SREP), which examines how banks test the sustainability of their business models under stress, capital and liquidity adequacy included.
The direction of travel is away from a limited number of deterministic tests and toward a dynamic and stochastic approach, in which simulation explores many scenarios playing out over time, macroeconomic and geopolitical shocks among them. A bank might define its own core shocks, a sharp slowdown in China or a drop in the oil price for instance, and let those work through drivers such as interest rates and the spreads on credit default swaps (CDS), with the link specified either by the judgment of business leaders or by statistical analysis of the historical record.
Running thousands of scenarios yields a whole distribution of results for the key performance indicators (KPIs) that matter: expected profits, regulatory capital, risk-weighted assets (RWAs) and credit losses. A firm can treat the average as its base case, or concentrate on the worst results, which correspond to the adverse and severely adverse cases.
Reverse stress testing
A distribution of outcomes also supports reverse stress testing, which runs the logic backwards. The firm picks out the tail of that distribution using its own KPIs, then examines the scenarios behind those results and traces how the shocks became losses. That lights up the business lines and portfolios contributing most to a worst-case loss and identifies the risk factors that matter most. A firm can also measure how sensitive a KPI such as loan losses is to each risk driver.
Many banks still treat stress testing as a compliance function and leave the results out of day-to-day planning. Newer technologies make that harder to justify, since the same output can specify risk appetites and limit frameworks, check business and capital planning for reasonableness, develop early warning signals, and support contingencies for credit, funding and liquidity shocks.
Enterprise risk managers belong in the formulation of strategy. Banking supplies examples of strategies built without reference to ERM, such as raising lending volume by loosening standards, or growing through successive acquisitions. Current thinking, set out in the COSO framework published in June 2017 among other places, pushes firms to use ERM to tie risk more tightly to reward inside corporate planning.
Stochastic stress testing gives that ambition a practical tool. A bank can test what growing its lending to one industry would do to the risk it carries, and may find that the plan spreads risk more evenly, or instead that it deepens a concentration. Simulation makes positive scenarios equally easy to examine, so a bank may find it would benefit from a fall in oil prices, having already reduced lending to oil producers in favor of manufacturers who gain from cheaper inputs. Strategic risks arising from technology, social behavior and new kinds of competition are harder, because they have no historical parallel in the way a fall in gross domestic product does. The stakes are large: a study covering enterprise value lost at listed United States companies from 2002 to 2012 traced the damage to strategic blunders 81 percent of the time, far ahead of operational mishaps, fraud and governance failures.
Three themes for the years ahead
Risk management is a young discipline, and three themes describe where it is going. The first is that risk is multidimensional and requires holistic thinking, and the main advance has been new forms of scenario analysis and stress testing alongside summary statistics such as VaR. Future stress testing will be more dynamic, will reach across one to three years, and will sit inside capital planning, helping set risk appetite and confirm that business models can survive severely adverse conditions. Holistic thinking also demands a sophisticated approach to uncertainty. Economists debated almost a century ago whether uncertainty is really the same thing as risk, and newer research addresses a further dimension, ambiguity, meaning uncertainty about the risk factors and probabilities themselves. Decision makers may be averse to ambiguity when they expect good returns, demanding a premium for ambiguous risks that is potentially measurable in financial markets.
The second theme is that risk jumps across risk types inside business models and markets. Before the crisis, too many institutions grew on business models built on high leverage or on naive assumptions about third-party credit assessments, and growth plans were often written with no input from the risk function or the CRO. The future risk function has to help set risk appetite, analyze the risks of each business model with worst-case simulations, explain how risks interact, and plan contingencies, which becomes more pressing as digital businesses grow on machine learning and new data streams.
The third theme is the balance between numbers and judgment. Cloud-based analytical capacity and machine learning look set to transform risk analysis, though progress has been slower than in the customer-facing digital revolution because of legacy systems and habit. Risk managers will command new streams of integrated enterprise data, identify correlations currently out of reach, and collect information live during business processes. The challenge is keeping automated risk decisions transparent and open to human review, since an opaque model is model risk with more horsepower. Behavioral science, meanwhile, explains why investors and risk managers depart from the decisions traditional economics assumes.
| Concept | What it describes |
|---|---|
| Anchoring and referencing | Judging a decision against a mental reference point such as an existing price, which can bias it and leave related decisions incoherent. |
| Feedback effects | Frequent positive feedback, or its absence, irrationally affecting whether a decision maker holds to a decision |
| Framing | Presentation pushing the decision, as when a buyer works hard to shave a small sum off a cheap item and ignores the identical sum on an expensive one |
| Groupthink | Suppressing doubts about a risky decision in favor of a consensus that a dominant person or a poor target may have shaped |
| Herding | Copying others when investing and when cutting losses, crowding firms into the same metrics and stop-losses |
| Home bias | Preferring domestic securities to a globally diversified portfolio, perhaps because foreign markets feel uncertain |
| Loss aversion | Weighting a loss above an equivalent gain, producing excessive caution or a wild bet taken to avoid booking a loss |
| Mental accounting | Treating money in separate categories as though it were not fungible, and resisting a closure that would confirm a loss |
| Ostrich effect | Avoiding bad news that would force an uncomfortable decision, such as watching a rising market closely and a falling one barely |
Source: the behavioral concepts selected in the chapter.
It would be wrong to set silo-based risk management against ERM as opposites, because the new emphasis supplements continuing work on the granular understanding of specific risks. Risk managers will end up working at the intersection of risk, data science, human behavior and business judgment, and their firms must react to risk signals even when those signals are ambiguous.