Enterprise Risk Management in Practice
A Practitioner's Course
Session Five
Risk Identification and Assessment
How banks surface risk before it materialises, and why the risks that cause the most damage are usually the ones they did not adequately anticipate
|
Disclaimer This course is provided for general information and education only. It is not legal advice. Legislation, rules and regulatory guidance change, sometimes quickly. Readers should confirm the current position and obtain jurisdiction-specific professional advice where needed. The views and experience expressed are Russel Fielding's own and do not represent any employer or client organisation. |
Session Five: Risk Identification and Assessment
Knowing what risks an institution faces is the starting point for managing them. That sounds straightforward, but risk identification is one of the hardest parts of ERM in practice. Risks that are well understood and easily quantified are usually managed reasonably well. The risks that cause the most damage are often the ones the institution did not adequately anticipate.
Risk identification approaches
Effective ERM draws on multiple sources of identification rather than relying on any single method.
Historical analysis reviews past losses, near misses, market disruptions, and industry incidents. It grounds risk identification in what has actually gone wrong. It is most useful for risks that occur with some frequency, such as credit defaults or operational incidents, and least useful for tail risks and novel threats that have not yet materialised anywhere.
Scenario analysis constructs plausible adverse scenarios and assesses their potential impact. It is particularly valuable for low-frequency, high-impact risks where historical data is sparse. Regulatory stress testing is a form of mandated scenario analysis in many banking regimes, but effective ERM also uses internal scenario analysis that reflects the institution's own risk profile, not only the standardised scenarios a supervisor requires.
Forward-looking assessment monitors the external environment for emerging threats: macroeconomic trends, geopolitical developments, regulatory change, technological developments, and competitive dynamics. Long-horizon risk categories, including climate-related risk, are examples where forward-looking assessment matters more than historical data, because the most significant impacts may lie ahead rather than behind.
Business and process reviews surface the risks embedded in products, processes, and business models by working directly with the people who run them. Risk identification workshops, process walkthroughs, and new product approval processes all serve this purpose. None of them can be done properly from a spreadsheet alone.
Assessing likelihood and impact
Once identified, risks need to be assessed. The standard approach considers two dimensions: likelihood, or how probable the risk is, and impact, or how severe the consequences would be. Multiplying the two can give a rough sense of priority. In practice, the relationship is more complex, particularly for risks where the impact is catastrophic, and the likelihood is genuinely hard to estimate.
For quantifiable risks, banks use statistical models and historical data to estimate probability and impact. Value at Risk is a widely used market risk measure that estimates a loss threshold over a given time horizon at a given confidence level, under the assumptions used in the model. Credit risk models estimate default probabilities and loss given default across lending portfolios.
These quantitative tools are valuable, and they have a well-documented limitation: they tend to perform well in normal market conditions and poorly in the tail events that matter most. The global financial crisis exposed the danger of relying too heavily on models calibrated to recent historical data, because those models may not capture extreme scenarios. An ERM framework that treats a model's output as fact rather than an estimate, particularly at the tail, repeats that mistake. Quantitative measures need to be complemented by qualitative judgement, not replaced by it.
For risks that cannot be readily quantified, reputational risk, strategic risk, and some aspects of operational risk, assessment relies more heavily on expert judgement, structured debate at risk committees, and scenario analysis. The fact that a risk resists precise measurement does not mean it should be managed with less care.
Risk registers: live documents or dead ones
Most institutions maintain risk registers to document identified risks, their assessed severity, the controls in place, and the residual risk after those controls are applied. Registers exist at multiple levels: enterprise-wide, business unit, and function-specific, with the enterprise register capturing the institution's most significant risks.
A risk register is only as useful as the process behind it. Registers updated annually as a compliance exercise, without genuine engagement from the people who own the risks, quickly become stale and inaccurate. The most effective registers are live documents: reviewed regularly, actively challenged, and connected to the decisions that determine how the institution manages its exposures. A simple test distinguishes the two. A register that gets argued over is alive. A register that gets signed off without discussion is dead, whatever its contents say.
|
Key takeaways from Session Five
|
Coming up in Session Six
Session Six covers risk mitigation and controls: the four basic responses to an identified risk, what makes an internal control environment genuinely effective rather than merely documented, and how institutions manage concentration risk.
Further reading and resources
Enterprise Risk Management in Banking. The published Ārai Tika guide this session draws on, with a fuller treatment of identification techniques and assessment tools including Value at Risk. Available through Ārai Tika.