EZ

Eduzan

Learning Hub

Eduzan
Eduzan / 01 Foundations of Risk Management

FRM 8: Enterprise Risk Management and Future Trends

Worked examples are fully visible. Check-yourself items are study aids you can reveal one at a time.

Enterprise risk management, almost always shortened to ERM, brings the viewpoint and the resources at the top of a company to bear on the whole collection of risks that company runs, and lets that view shape strategy. The older habit is to handle each exposure wherever it arises. Industry shorthand for it is silo-based risk management, sometimes stove-pipe risk management, and under either name a business unit owns whatever risks it generates and reports on them alone.

Silos are not stupid. Working inside one category at a time makes definition and measurement tractable, since financial models are built around a single risk type, aggregation is clean inside a business line, and derivative instruments, the usual hedging tool, are themselves risk specific. Regulators lean the same way: under Pillar I of Basel III, banks hold minimum capital separately against credit risk, market risk and operational risk, while Pillar II, the supervisory review process, catches what remains.

Where the silo view runs out

The trouble starts as soon as a firm asks how its exposures compare. Ranking tells a company where to spend its effort first, and no ranking is possible while each unit reports in its own units of measurement. At the level of the whole company, exposures also cancel out, through netting and diversification, or pile up, through concentrations, through contagion, and through the way a weakness in one risk type surfaces as a loss in another.

Those effects are invisible from inside a business line, which is the gap ERM fills. An enterprise risk is any risk big enough to leave the outcomes of the whole firm materially short of its goals. ERM also makes the treatment of risk consistent from the boardroom to the branch, through a shared risk culture and common risk appetites and governance. Without it, one unit turns down a transaction on risk grounds while a comparable one is welcomed a floor away.

Figure 1: Silo-based risk management compared with the enterprise view
Silo based risk management Market risk Credit risk Operational risk Liquidity risk No common metric across the four boxes, so no ranking and no total Enterprise view Board, chief risk officer, risk committee Market risk Credit risk Operational risk Liquidity risk Enterprise risk portfolio netting, diversification, concentration
What changes is whether anyone above the four can compare, add and rank them.

Cross-over risk and the Northern Rock example

A soft spot in one area of risk management is often a soft spot somewhere else, and the connection only becomes obvious after the loss. Northern Rock learned this early in the global financial crisis of 2007-2009. The bank had grown quickly on funding drawn from wholesale markets and investors rather than from its own customers’ deposits, and it tried to dilute that concentration by geography, reaching past the United Kingdom into continental Europe and the United States. Geographic spread was no defence once investors backed away from banks judged to have risky lending books. Officials afterwards called a shutdown on that scale “unforeseeable”, in evidence recorded by the House of Commons, Treasury Committee, in “The Run on the Rock”, January 2008, p. 16.

Check yourself
A bank measures and holds capital against credit, market and operational risk inside each department. What can it still not see?
The relationships between the three. Nothing there reveals whether the exposures offset one another, whether the same name or region sits in several departments, or whether trouble in one risk type will surface as a loss in another.
End of lesson.