Enterprise Risk Management in Practice
A Practitioner's Course
Session Nine
Implementation Summary
A consolidated checklist across governance, the three lines, capital, identification, controls, monitoring, and culture. A working reference to return to
|
Disclaimer This course is provided for general information and education only. It is not legal advice. Legislation, rules and regulatory guidance change, sometimes quickly. Readers should confirm the current position and obtain jurisdiction-specific professional advice where needed. The views and experience expressed are Russel Fielding's own and do not represent any employer or client organisation. |
Session Nine: Implementation Summary
This checklist draws together the eight sessions that precede it. It covers the questions boards, senior risk professionals, and anyone assessing an ERM programme should be able to answer with confidence. Use it as a working reference when reviewing a live programme, briefing a board, or benchmarking an institution's own maturity, not as a one-off exercise.
Who benefits from this checklist. Anyone who has worked through the preceding eight sessions and wants a single reference to carry back into their own institution, whether that is a board member preparing for a risk committee, a CRO benchmarking their own programme, or a risk professional assessing a new area of the business.
Governance and risk appetite
- Does the board understand, and actively discharge, its non-delegable responsibility for risk governance?
- Does the CRO have structural independence, reporting lines, and remuneration that do not depend on the commercial performance of the units they oversee?
- Is there a risk appetite statement specific enough to constrain a decision, rather than a vague statement of moderate or low appetite?
- Can anyone recall the last time a commercial decision was changed because it approached or breached a risk appetite limit?
- Are the ERM policy, risk appetite statement, strategic risk register, and department risk registers connected to each other, rather than existing as separate, unlinked documents?
The three lines
- Are first-line risk ownership, second-line oversight, and third-line assurance clearly and separately understood, without overlap or gaps?
- Is the second line structurally independent, in reporting lines and remuneration, rather than independent in name only?
- Does internal audit have a direct reporting line to the board or audit committee, with unfettered access to resources, personnel, and data?
- Is there evidence the second line has recently escalated something the first line did not want escalated?
Regulatory capital
- Is the institution's implementation of the final Basel III reforms, including Basel 3.1 where that term is used, tracked jurisdiction by jurisdiction, rather than assumed to follow a single global timetable?
- Is the ICAAP, and ILAAP where applicable, treated as a genuine management tool rather than a regulatory submission produced once a year?
- Are stress testing scenarios built around the institution's actual risk concentrations, not just standardised regulatory scenarios?
- Can anyone recall the last time a stress test result changed a capital, lending, or strategic decision?
Identification, assessment and controls
- Does risk identification draw on historical analysis, scenario analysis, forward-looking assessment, and direct business engagement, rather than one method alone?
- Are quantitative risk models treated as estimates subject to real limitations, particularly in tail scenarios, rather than as settled facts?
- Is every material risk assigned a conscious, documented response: accept, mitigate, transfer, or avoid?
- Is the control environment tested by what actually happens when a control is inconvenient, not only by what the policy document says should happen?
- Are concentration limits, by exposure, sector, and geography, actively monitored and stress tested?
Monitoring, culture and emerging risk
- Does risk reporting focus on what matters, with clear escalation triggers, rather than aiming for exhaustive coverage nobody reads in full?
- Is risk data of sufficient quality to produce a consolidated view across business lines quickly enough to be useful?
- Would people across the institution say they can raise a risk concern without fear of career consequences?
- Has the institution assessed its own maturity against a recognised model, honestly and by attribute, rather than by a single blended impression?
- Are climate, cyber, third-party concentration, and geopolitical risk integrated into the same governance and reporting structure as traditional financial risks, rather than managed as separate side projects?
A final note
The frameworks behind enterprise risk management, including COSO, ISO 31000, the Three Lines Model, and Basel, are well documented. What separates institutions that manage risk effectively from institutions that produce excellent risk documentation is something this course has returned to repeatedly: whether the framework shapes the decisions people make, or whether it exists alongside those decisions as a defensible record of good intentions.
That distinction is not settled once, at implementation, and then left alone. It is tested every time a credit officer reviews a marginal loan, a trader considers a position near a limit, or a technology team decides whether to release a change under pressure. The checklist above is a working tool for making that test explicit, in your own institution, on an ongoing basis, rather than something to complete once and file away.
Further reading and resources
This session draws together the sources cited across the preceding eight sessions.
Enterprise Risk Management in Practice. The published Ārai Tika article underpinning this course's central thesis, that the discipline matters more than the framework. Available at araitika.com.
Enterprise Risk Management in Banking. The published Ārai Tika guide covering the full framework end to end, including regulatory context, governance, mitigation, and monitoring. Available at araitika.com.
Basel Committee on Banking Supervision. The international standard-setting body behind the Basel Accords. Available at bis.org.
Institute of Internal Auditors, the Three Lines Model. The current governance model for distributing risk responsibility across an institution. Available at theiia.org.
RIMS Risk Maturity Model. A practitioner tool for assessing and improving risk management maturity. Available at rims.org.