Enterprise Risk Management in Practice
A Practitioner's Course
Session One
Introduction: Why Enterprise Risk Management Is the Central Discipline of Banking
Why ERM is not a compliance exercise sitting alongside banking, and how the nine sessions in this course are organised
|
Disclaimer This course is provided for general information and education only. It is not legal advice. Legislation, rules and regulatory guidance change, sometimes quickly. Readers should confirm the current position and obtain jurisdiction-specific professional advice where needed. The views and experience expressed are Russel Fielding's own and do not represent any employer or client organisation. |
Session One: Introduction: Why Enterprise Risk Management Is the Central Discipline of Banking
Every loan a bank makes, every market position it holds, every system it relies on, and every product it offers carries risk. In practice, the question is not whether a bank accepts risk. It is whether the bank understands that risk, prices it properly, and manages it within limits the institution can sustain. Enterprise risk management is the discipline that connects those judgements across the institution, rather than leaving them to separate functions.
This course is written from inside the governance, risk, and delivery work of large regulated institutions, not as an external commentary on it. It treats ERM as a management discipline first and a compliance framework second, because that is the order that determines whether an institution manages risk well.
From siloed to integrated risk management
For much of banking history, risk was managed through functional silos. Credit teams assessed lending risk. Treasury managed market and liquidity risk. Operations handled process failures. Compliance managed regulatory risk. Each function had its own tools, reporting line, and view of the institution.
The 2007-09 financial crisis exposed the weakness in that approach. Risks that looked manageable in isolation were deeply connected. Mortgage credit risk became market risk. Market risk became liquidity risk. Liquidity risk became systemic risk. Institutions with controls in each silo still lacked a consolidated view of how those risks interacted.
Enterprise risk management emerged as a deliberate response to that failure. It does not replace functional risk management: credit teams still manage credit risk, and market risk teams still manage market risk. What ERM does is connect those functions within a common framework, give the board and senior management a consolidated view of risk across the organisation, and ensure that risk appetite is set and monitored at the enterprise level rather than negotiated separately in each silo.
A working definition
Enterprise risk management in banking can be defined as an integrated, organisation-wide approach to identifying, assessing, managing, monitoring, and reporting on the risks that could affect an institution's ability to achieve its objectives. Three parts of that definition carry the weight.
Integrated means risks are not assessed in isolation from each other or from strategy. A bank's credit risk profile is connected to its funding strategy. Its operational risk profile is connected to its technology investment decisions. Its reputational risk is connected to how it manages financial crime. ERM requires those connections to be visible and actively managed, not simply acknowledged.
Organisation-wide means ERM covers all material risks across all business lines, geographies, and functions. It cannot be confined to the risk department, and an ERM programme that lives only inside the risk function has already failed the definition.
Objectives mean risk management is connected to what the institution is actually trying to achieve. Risk is not managed for its own sake. It is managed so the institution can pursue its strategy, serve its customers, and meet its obligations to shareholders, regulators, and the wider financial system.
The core risk categories
Banks face a wide range of risks, but they are typically grouped into categories that form the basis of any ERM framework.
Credit risk
The risk that a borrower or counterparty fails to meet its obligations. This is the most fundamental risk in banking and historically the one that has caused the largest losses. It includes lending risk, counterparty risk in derivatives and capital markets activity, and concentration risk, where exposures are weighted too heavily towards particular sectors, geographies, or counterparties.
Market risk
The risk of losses arising from movements in market prices, including interest rates, exchange rates, equity prices, and commodity prices. Market risk is most significant for banks with trading books, but it affects every bank through interest rate risk in the banking book, which arises from the mismatch between the repricing of assets and liabilities.
Liquidity risk
The risk that a bank cannot meet its financial obligations as they fall due without incurring unacceptable losses. It has two dimensions: funding liquidity risk, the risk of being unable to raise funds to meet obligations, and market liquidity risk, the risk of being unable to sell assets without significantly moving their price. The 2007-09 crisis demonstrated how quickly liquidity risk can become existential for an institution that looked solvent on paper.
Operational risk
The risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events. This broad category includes legal risk but excludes strategic and reputational risk. In practice, it covers technology failure, fraud, human error, process breakdown, cyber incidents, and external shocks such as natural disasters.
Compliance and regulatory risk
The risk of financial loss, regulatory sanction, or reputational damage arising from a failure to comply with laws, regulations, rules, and standards. In banking this spans capital adequacy, conduct of business rules, financial crime obligations, and consumer protection requirements.
Strategic risk
The risk that a bank's business strategy proves incorrect, or that the organisation fails to execute its strategy effectively. This includes the risk of entering markets or products that prove unprofitable, the risk of technological disruption, and the risk that an acquisition destroys value rather than creating it.
Reputational risk
The risk of damage to a bank's standing with customers, investors, regulators, and the public. Reputational risk is often a consequence of other risks materialising, but it can also arise independently from how the institution is perceived to behave.
Climate and environmental risk
A material category for many banks, covering both physical risk, losses from acute weather events and longer-term environmental change, and transition risk, losses arising from the move to a lower-carbon economy, including stranded assets and regulatory change. Session Eight covers how supervisory expectations in this area continue to develop.
How this course is organised
The nine sessions build in a deliberate order. Sessions Two and Three cover governance: the board's responsibilities, risk appetite, and the three lines model. Session Four covers the regulatory capital framework. Sessions Five and Six cover the operational core of ERM: identifying and assessing risk, then mitigating and controlling it. Session Seven covers monitoring, stress testing, and internal capital and liquidity assessment. Session Eight covers risk culture, maturity, and the emerging risks reshaping the landscape. Session Nine consolidates the course into a working implementation checklist.
The course is principle-led. The discipline of enterprise risk management travels across the UK, New Zealand, and Australia, even though the specific rules and supervisors differ. Examples are drawn from whichever jurisdiction illustrates the point most clearly, with the Basel Framework as the common international reference point for prudential banking regulation.
|
Key takeaways from Session One
|
Further reading and resources
This course draws on primary regulatory sources and supervisory publications. For this session, the most useful companions are the Basel Committee's current Basel Framework and its guidance on operational risk, corporate governance, capital adequacy, liquidity, and risk management.
Basel Committee on Banking Supervision. The primary global standard setter for prudential banking regulation. Its Basel Framework brings together current and forthcoming standards on capital, credit risk, market risk, operational risk, liquidity, leverage, and large exposures. Available at bis.org.
Ārai Tika resources on enterprise risk management. The published article and guide on ERM practice that this course draws on and expands into a structured nine-session format. Available at araitika.com.