Session Six: Risk Mitigation and Controls

Session Six: Risk Mitigation and Controls — Enterprise Risk Management in Practice

Enterprise Risk Management in Practice

A Practitioner's Course

Session Six

Risk Mitigation and Controls

The four basic responses to an identified risk, what makes a control environment genuinely effective, and how institutions manage concentration risk

Session Six: Risk Mitigation and Controls

Identifying and assessing risk is necessary, but it is not enough. The work only matters when the institution makes a deliberate decision about how the risk will be managed, and then tests whether that response keeps the exposure within appetite.

Four response options

For any risk, the institution has four basic choices.

Accept. Some risks are accepted because the cost of mitigation is higher than the benefit, or because they are inherent in the business the institution has chosen to pursue. Acceptance is a legitimate decision. It should be conscious and documented, not the result of nobody making an active choice.

Mitigate. Most risks are managed through controls designed to reduce their likelihood, impact, or both. Internal controls, credit limits, diversification requirements, and operating procedures are all mitigation measures.

Transfer. Some risks can be transferred to third parties through insurance, derivatives, or contractual arrangements. Banks use hedging instruments to manage market risk, and insurance to manage certain operational risks. Transfer reduces exposure; it does not remove it. Basis risk, counterparty risk, and coverage gaps remain, so transferred risk still needs monitoring.

Avoid. Some risks are avoided by choosing not to enter certain activities or markets. An institution might decide not to enter a particular geography or offer a product because the risk profile sits outside appetite. Avoidance has an opportunity cost, but it is a legitimate strategic choice and, sometimes, the only sound one.

Internal controls and the control environment

Internal controls are the mechanisms through which risk is managed in the normal course of business. They include policies and procedures for how activities should be conducted, segregation of duties so one person cannot both initiate and approve a transaction, authorisation frameworks for significant decisions, reconciliation processes to detect errors and discrepancies, and monitoring systems that track activity against expected patterns.

The control environment is the culture, values, and tone set by senior management. It underpins everything else. Controls that exist on paper but are routinely bypassed, or ignored when they are inconvenient, are not effective controls. A strong control environment is one where following controls is normal, breaches are taken seriously, and the people responsible for controls have enough standing to enforce them.

Hedging and risk transfer

Banks use financial instruments to manage market and credit risk. Interest rate swaps can manage the interest rate risk that arises from mismatches between fixed-rate loans and variable-rate funding. Foreign exchange hedges manage currency risk in international operations. Credit derivatives can transfer credit risk to other parties.

These instruments are powerful, but they introduce risks of their own. Basis risk arises when a hedge does not fully offset the underlying exposure. Counterparty risk arises when the hedge provider may itself default. A hedging programme needs specialist expertise and robust monitoring. It is not a one-off decision to hedge and move on.

Concentration risk management

One of the most important, and most easily overlooked, aspects of credit and market risk management is concentration risk. This is exposure weighted too heavily in one direction, whether by borrower, sector, geography, or instrument type. A well-diversified portfolio is more resilient to shocks than a concentrated one. Concentration risk can look acceptable on individual metrics while creating vulnerability at portfolio level.

Institutions manage concentration risk through individual exposure limits, sector limits, geographic limits, and regular portfolio analysis. The aim is to identify concentrations before they become a problem. Stress testing concentrated portfolios is particularly important because the relevant scenario is often a correlated shock across a whole sector or geography. Individual exposure limits alone will not catch that.

Coming up in Session Seven

Session Seven covers monitoring, stress testing, and internal capital and liquidity assessment: how continuous monitoring differs from periodic review, what makes stress testing a genuine management tool rather than a regulatory submission, and what a strong internal assessment actually demonstrates.

Further reading and resources

Enterprise Risk Management in Banking. The published Ārai Tika guide that this session draws on, with a fuller treatment of controls, hedging, and concentration risk.