Enterprise Risk Management in Practice
A Practitioner's Course
Session Six
Risk Mitigation and Controls
The four basic responses to an identified risk, what makes a control environment genuinely effective, and how institutions manage concentration risk
|
Disclaimer This course is for general information and education only. It is not legal advice. Legislation, rules, and regulatory guidance can change quickly. Readers should confirm the current position and obtain jurisdiction-specific professional advice where needed. The views and experience expressed are Russel Fielding's own and do not represent any employer or client organisation. |
Session Six: Risk Mitigation and Controls
Identifying and assessing risk is necessary, but it is not enough. The work only matters when the institution makes a deliberate decision about how the risk will be managed, and then tests whether that response keeps the exposure within appetite.
Four response options
For any risk, the institution has four basic choices.
Accept. Some risks are accepted because the cost of mitigation is higher than the benefit, or because they are inherent in the business the institution has chosen to pursue. Acceptance is a legitimate decision. It should be conscious and documented, not the result of nobody making an active choice.
Mitigate. Most risks are managed through controls designed to reduce their likelihood, impact, or both. Internal controls, credit limits, diversification requirements, and operating procedures are all mitigation measures.
Transfer. Some risks can be transferred to third parties through insurance, derivatives, or contractual arrangements. Banks use hedging instruments to manage market risk, and insurance to manage certain operational risks. Transfer reduces exposure; it does not remove it. Basis risk, counterparty risk, and coverage gaps remain, so transferred risk still needs monitoring.
Avoid. Some risks are avoided by choosing not to enter certain activities or markets. An institution might decide not to enter a particular geography or offer a product because the risk profile sits outside appetite. Avoidance has an opportunity cost, but it is a legitimate strategic choice and, sometimes, the only sound one.
Internal controls and the control environment
Internal controls are the mechanisms through which risk is managed in the normal course of business. They include policies and procedures for how activities should be conducted, segregation of duties so one person cannot both initiate and approve a transaction, authorisation frameworks for significant decisions, reconciliation processes to detect errors and discrepancies, and monitoring systems that track activity against expected patterns.
The control environment is the culture, values, and tone set by senior management. It underpins everything else. Controls that exist on paper but are routinely bypassed, or ignored when they are inconvenient, are not effective controls. A strong control environment is one where following controls is normal, breaches are taken seriously, and the people responsible for controls have enough standing to enforce them.
Hedging and risk transfer
Banks use financial instruments to manage market and credit risk. Interest rate swaps can manage the interest rate risk that arises from mismatches between fixed-rate loans and variable-rate funding. Foreign exchange hedges manage currency risk in international operations. Credit derivatives can transfer credit risk to other parties.
These instruments are powerful, but they introduce risks of their own. Basis risk arises when a hedge does not fully offset the underlying exposure. Counterparty risk arises when the hedge provider may itself default. A hedging programme needs specialist expertise and robust monitoring. It is not a one-off decision to hedge and move on.
Concentration risk management
One of the most important, and most easily overlooked, aspects of credit and market risk management is concentration risk. This is exposure weighted too heavily in one direction, whether by borrower, sector, geography, or instrument type. A well-diversified portfolio is more resilient to shocks than a concentrated one. Concentration risk can look acceptable on individual metrics while creating vulnerability at portfolio level.
Institutions manage concentration risk through individual exposure limits, sector limits, geographic limits, and regular portfolio analysis. The aim is to identify concentrations before they become a problem. Stress testing concentrated portfolios is particularly important because the relevant scenario is often a correlated shock across a whole sector or geography. Individual exposure limits alone will not catch that.
|
Key takeaways from Session Six
|
Coming up in Session Seven
Session Seven covers monitoring, stress testing, and internal capital and liquidity assessment: how continuous monitoring differs from periodic review, what makes stress testing a genuine management tool rather than a regulatory submission, and what a strong internal assessment actually demonstrates.
Further reading and resources
Enterprise Risk Management in Banking. The published Ārai Tika guide that this session draws on, with a fuller treatment of controls, hedging, and concentration risk.