Enterprise Risk Management in Practice
A Practitioner's Course
Session Eight
Risk Culture, Maturity and Emerging Risks
Why culture is where most ERM programmes ultimately succeed or fail, how a maturity model helps an institution see where it genuinely stands, and the risk categories reshaping the landscape
|
Disclaimer This course is provided for general information and education only. It is not legal advice. Legislation, rules and regulatory guidance change, sometimes quickly. Readers should confirm the current position and obtain jurisdiction-specific professional advice where needed. The views and experience expressed are Russel Fielding's own and do not represent any employer or client organisation. |
Session Eight: Risk Culture, Maturity and Emerging Risks
An institution can have excellent policies, sophisticated models, and clear governance structures, and still experience serious risk failures if the culture underneath does not support honest risk assessment and open escalation. Culture is where most ERM programmes ultimately succeed or fail, and it is the hardest part of the discipline to build, because it cannot be produced by a programme in the way a policy or a model can.
What a healthy risk culture looks like
A healthy risk culture is one where people feel able to raise concerns without fear of career consequences, where bad news travels up the organisation as fast as good news, where risk considerations genuinely shape business decisions rather than validating them after the fact, and where there is real accountability when risk management fails.
Building and sustaining that culture requires active, sustained effort from senior management and the board. It requires demonstrated behaviour, not statements: actual decisions that show risk discipline is taken seriously, not a values slide in an induction deck. It requires incentive structures that reward risk-adjusted performance rather than raw revenue or growth. And it requires an honest, uncomfortable assessment of where the culture currently falls short, rather than an assumption that a strong culture is what the institution already has because it says so in its risk policy.
Four simple questions tend to surface an honest reading of culture faster than any formal review. When was a commercial decision changed because of a risk appetite limit? When did the second line last escalate something the first line did not want escalated? When was a risk register last argued over rather than signed off without discussion? When did a stress test result last change a capital, lending, or strategic decision? These are the questions a thoughtful supervisor asks, and the questions an experienced risk professional learns to ask before believing what the policy manual says.
Maturity models as a diagnostic
A risk management maturity model provides a structured way for an institution to assess how developed its risk management practices are, rather than relying on impression or the volume of documentation. Most models define levels of maturity, from ad hoc or reactive practice through to a more embedded discipline, and assess those levels against defined capabilities rather than a single overall impression.
The RIMS Risk Maturity Model is a widely used example. Public RIMS material describes the model as a structured assessment of risk management maturity across defined pillars, attributes, and maturity levels. Its usefulness is not the score itself. It is the discipline of assessing capabilities honestly and separately, since an institution can be strong on process documentation while weak on whether risk appetite actually constrains decisions.
No single maturity model fits every institution, and different frameworks emphasise different things. What most agree on is that risk management is ongoing rather than a one-time achievement, that it needs to be holistic across the whole institution rather than siloed, that it should draw on both data and judgement, and that it should be as alert to opportunity as it is to downside. A maturity assessment is a snapshot against those principles, useful for identifying where to invest next, not a certificate to file away.
Cyber and technology risk
The emerging risk categories below are not a catalogue of every material risk. They are examples of risks that test whether an ERM framework is genuinely embedded: each crosses business lines, depends on judgement as well as data, and can move faster than standard governance cycles.
Technology risk has become one of the most significant categories of operational risk facing banks. Cyber attacks, including ransomware, data theft, and attacks on critical infrastructure, are a material and growing threat. Reliance on digital channels, cloud infrastructure, and third-party technology providers has also expanded the attack surface considerably.
Regulators have responded with operational resilience frameworks and more detailed expectations for cyber and technology risk. Institutions are expected to identify their most important business services, set impact tolerances, map dependencies, test severe but plausible disruption scenarios, and address vulnerabilities rather than simply assert they can recover.
Third-party and concentration risk in technology
Banks increasingly rely on a small number of large technology providers for critical functions, including cloud infrastructure, core banking systems, and payment processing. This creates concentration risk at a systemic level. A significant outage at a major provider could affect many firms at once, which is a different problem from an individual institution's own resilience.
Regulators are paying increasing attention to this risk, requiring banks to map their critical third-party dependencies, assess the risks those dependencies create, and develop contingency plans for significant failures. Third-party risk management has become a substantial component of operational risk frameworks rather than a procurement afterthought.
Climate risk
Climate risk is now supervised as a mainstream prudential risk rather than a disclosure obligation. In the UK, the PRA has updated its supervisory expectations for climate-related financial risk, with expectations covering governance, risk management, climate scenario analysis, data, disclosures, and sector-specific issues for banking and insurance.
The direction of travel, if not the exact timetable, is broadly consistent across major prudential regulators: firms are expected to show traceable board oversight of climate risk, to use scenario analysis as an ongoing governance tool rather than a one-off exercise, and to maintain a documented gap analysis against current expectations. Institutions that have treated climate risk primarily as a disclosure exercise, something to report on rather than something to manage, are increasingly exposed as supervisory expectations mature.
Digital assets and geopolitical risk
The growth of digital assets, decentralised finance, and fintech competition presents both opportunity and risk for banks. Regulatory frameworks for digital assets continue to develop and vary significantly by jurisdiction. Institutions with exposure to digital asset markets face risks around custody, counterparty credit quality, financial crime controls, and operational resilience.
Geopolitical tensions, trade disputes, and expanding sanctions regimes create significant risk management challenges for internationally active banks. Sanctions compliance has become more complex as regimes have expanded in scope and frequency of change. Geopolitical disruption can also alter the risk profile of markets quickly, creating correlated exposures that historical risk models may not capture well.
|
Key takeaways from Session Eight
|
Coming up in Session Nine
Session Nine consolidates the course into an implementation checklist, bringing together governance, the three lines, capital, risk identification, controls, monitoring, and culture.
Further reading and resources
Enterprise Risk Management in Practice. The published Ārai Tika article this session draws on, including the four diagnostic questions for reading risk culture honestly. Available at araitika.com.
RIMS Risk Maturity Model. A widely used maturity assessment framework for ERM practice. Available at rims.org.
PRA supervisory expectations on climate-related financial risk. The PRA's current expectations for banks and insurers on managing climate-related financial risks. Available at bankofengland.co.uk.