Enterprise Risk Management in Practice
A Practitioner's Course
Session Two
Governance, the Board and Risk Appetite
What active board oversight of risk actually looks like, the documents a real ERM programme produces, and why so many risk appetite statements fail to constrain anything
|
Disclaimer This course is provided for general information and education only. It is not legal advice. Legislation, rules and regulatory guidance change, sometimes quickly. Readers should confirm the current position and obtain jurisdiction-specific professional advice where needed. The views and experience expressed are Russel Fielding's own and do not represent any employer or client organisation. |
Session Two: Governance, the Board and Risk Appetite
Risk management frameworks and control systems matter, but they do not make ERM effective on their own. What matters is the governance structure that turns risk information into decisions, challenge and action.
Board responsibilities
The board bears ultimate responsibility for risk governance. This responsibility cannot be delegated, though it can be discharged through appropriate committee structures and management reporting.
The board's risk responsibilities include setting the institution's risk appetite, ensuring the risk management framework is adequate and properly resourced, receiving regular reporting on the risk profile, challenging management's risk assessments and decisions, and overseeing the independence and effectiveness of internal audit.
Most large institutions maintain a dedicated board risk committee alongside the audit committee. Done well, it gives the board deeper oversight of risk appetite, major exposures and significant risk policies. Done badly, it adds a meeting. A committee that receives the same information as the full board, is staffed by the same generalists and lacks deeper technical grounding is not adding oversight capacity.
Senior management and the Chief Risk Officer
Senior management implements the board's risk appetite and runs the risk management framework day to day. This includes the Chief Risk Officer, who leads the risk function and owns the overall ERM framework, and business heads, who own the risks in their areas.
The CRO needs sufficient independence and authority to raise risk concerns at the highest level. A CRO who cannot challenge business heads effectively, or who faces pressure not to escalate concerns to the board, cannot perform the role, regardless of the title on their contract. Independence here is structural, not aspirational: it depends on reporting lines, remuneration structure, and whether the CRO can reach the board directly without a business head's permission.
Management risk committees provide the forums where risk issues are discussed and decided. These may include the executive risk committee, credit committee, asset and liability committee and operational risk committee. The quality of these committees, including the quality of information they receive and the rigour of the challenge they apply, is a strong indicator of the overall health of an ERM programme.
ERM documentation
A functioning ERM programme produces a recognisable set of documents. Their quality shows whether the programme is operating, or only documented.
The ERM policy and risk appetite statement set out the institution's approach to risk and how much risk it is willing to take, in terms specific enough to guide decisions. The strategic risk register lists the institution's principal risks and how it plans to manage them. It should be reviewed and challenged at board level, not filed once a year. Department risk registers and plans set out the risks within each business area and the controls applied to them, owned by the people who actually run those areas. Guidelines and procedures describe how controls should operate and who is responsible for them.
None of these documents is valuable in isolation. A risk appetite statement disconnected from the strategic risk register, or a department register nobody at board level ever sees, produces the appearance of governance without the substance.
What makes a risk appetite framework real
Risk appetite is the amount and type of risk an institution is willing to accept in pursuit of its objectives. In practice, it only matters when it is specific enough to guide choices before they are made.
A well-developed risk appetite framework does several things. It defines the types of risk the institution is willing to accept and those it is not. It sets quantitative limits for key risk categories, such as credit loss scenarios, market risk exposures or tolerable operational loss events. It also connects those limits to strategy and capital capacity, so appetite is not set independently of the institution's ability to absorb loss.
Statements of the form "we have a moderate appetite for credit risk and a low appetite for reputational risk" are common, board-approved, and largely useless. They cannot be breached because they cannot be operationalised. The test of a real risk appetite framework is whether it actually constrains decisions. When a new business proposal is rejected because it exceeds the credit risk appetite, or a trading strategy is modified because it approaches a market risk limit, the framework is doing its job. If nobody in the institution can remember the last time a commercial decision was changed because of a risk appetite limit, the framework is not constraining anything, whatever the policy document says.
The board is responsible for setting risk appetite. Management is responsible for operating within it. The risk function is responsible for monitoring whether the institution is doing so, and for escalating promptly when limits are approached or breached. Where those three responsibilities blur, usually because the risk function has been drawn into owning appetite decisions rather than monitoring adherence to them, the framework loses its independence and, eventually, its credibility.
|
Key takeaways from Session Two
|
Coming up in Session Three
Session Three covers the Three Lines Model in detail: how risk responsibility is distributed across an institution, what genuine independence looks like for the second and third lines, and the most common way this model quietly breaks down in practice.
Further reading and resources
Enterprise Risk Management in Practice. The published Ārai Tika article this session draws on, including the practical test of whether a risk appetite framework actually constrains decisions. Available at araitika.com.
Internal governance guidance for financial institutions. Supervisory guidance on governance arrangements, including the roles of governing bodies, risk committees, control functions and risk appetite. Use the current version applicable to the relevant jurisdiction.