ERM Introduction
- Risk management is the process of identifying, assessing, and prioritising potential risks and taking actions to mitigate or avoid them. There are two ways to handle this situation:
- Traditional
- Silo Based:
- Risk assessment, management and mitigation will be performed separately for each division within the firm.
- Advantages:
- Adequate in a less volatile market environment.
- Disadvantages:
- Ignores the dynamic nature of risks and their interdependencies.
- Costly overhedging of risks at the firm level.
- Different risk measurement methodologies and formats across units may result in fragmented information for senior management and the board.
- Risk management decisions are often made independently, without a comprehensive and strategic approach to enterprise-wide risk.
- Modern
- ERM
- Risk assessment, management and mitigation will be performed in an integrated and centralized framework for the firm.
- It's essential to keep in mind that risks are interconnected, and one type of risk can have a ripple effect on other areas of the company. However, when risks are evaluated from a company-wide perspective, they can sometimes offset each other. Therefore, it's crucial to consider risks holistically to create a robust risk management strategy.
- Advantages:
- Optimizing the total cost of risk expenses is better managed by avoiding overhedging and scaling various risks in a single umbrella (credit, regulatory, market, and so on).
- Understand the correlation risks between specific risk types and the crossover risks where one risk creates additional risks.
- Serves as a foundation for incorporating risk into business model selection and strategic decision-making, helping banks achieve their objectives while managing risks effectively.
- Helps risk managers define risk appetite to the entire company and can put constraints on enterprise-level risk.
- Managers and the board of directors can focus on the largest risk faced by the firm and not focus on day-to-day business divisions.
- Identifies threats to the entire operation that arise from individual business lines.
- Manage emerging risks such as cyber threats, reputation risks and anti-money laundering (AML) risks at the enterprise level.
- Regulatory compliance.
- Reassure stakeholders, stockholders and debtholders.
- Saving capital by incorporating stress testing into pricing and decision-making.
- Disadvantages:
- Limited foresight, might struggle to predict entirely new or unforeseen risks, especially those arising from rapid technological advancements or significant economic shifts.
- The effectiveness of ERM can be challenging to measure quantitatively.
- Silo-Based Risk Management VS ERM
- Visualization
![]() |
Credits: https://analystprep.com/study-notes/wp-content/uploads/2020/01/Enterprise_Risk_Management_ERM-1536x1273.jpg |
- Silo-Based
- Managing risks within the line of business
- Isolated risk managers
- Multiple risk metrics that cannot be compared
- Difficult to see enterprise-wide risk
- Hedging risk with specific risk transfer tools
- Risk management and risk transfer are not integrated with balance sheet management and financing strategies
- ERM
- Risk managers review all business lines, functional areas, and risk types for diversification and concentration to avoid overhandling costs.
- Integrated risk managers and a chief risk officer.
- Integrated risk metrics can be compared.
- Aggregate risk across business lines and potentially across types of risk.
- Could lead to potential cost savings.
- Risk management is integrated with the bank's capital management strategy, balance sheet management strategy, and financing strategies.
Scenario Analysis and Stress Testing
- Definitions
- Sensitivity Analysis involves in changing one variable at a time to assess the impact on the model. The resulting impact is the net income for that variable.
- Scenario Analysis examines multiple variables to understand their impact and the developing narrative to explain why they changed and their effects.
- Advantages:
- The frequency of a risk occurrence is not as important as its plausibility.
- Scenarios can be intuitive and transparent.
- Firms should anticipate the worst-case scenario and evaluate its potential consequences.
- Helps firms focus on key risk types and their exposures.
- Firms can see potential warning signals and develop contingency plans to manage risk events.
- Scenarios can be created either by imagining hypothetical events or by using historical data.
- Scenarios analysis is utilized to establish the firm's risk appetite, define risk limits, and inform capital adequacy planning.
- Disadvantages
- Probabilities of the adverse events are difficult to estimate.
- Scenario analysis cannot quantify risk because it is qualitative.
- It is possible to underestimate the occurrence of possible events and the potential impact they may have.
- It is important to develop the right scenario, as only a limited number can be fully developed.
- Most scenarios are based on past crises, not future possibilities.
- The effectiveness of scenario analysis relies on its accuracy and comprehensiveness, which should encompass both past and future risks.
- Could be challenging to determine the credibility of a situation since the scenarios can vary in their complexity.
- Scenarios may be intuitive and transparent which are advantage but are necessarily complex which is a disadvantage.
- Stress testing is a crucial evaluation method to ensure a firm's sustainability. It assesses extreme scenarios that may occur rarely but can have a significant impact on losses. On the other hand, probabilistic risk metrics, such as VaR, ES, or Standard Deviation, are suitable when the frequency of losses is high, and the severity of losses is low.
- Reverse stress tests, banks can identify worst-case outcomes on the key performance indicators and do the reverse engineering to see which scenarios could lead to these outcomes.
- History
- Before the 2007-2009 financial crisis, banks used to create historical scenarios based on actual past events. However, this approach failed to predict the crisis.
- Banks didn't understand the risk interaction and market behaviour changes during the crisis, as the correlation between assets and asset classes increased.
- Bank stress test scenarios were mild, regulators demanded banks demonstrate the ability to withstand more realistic stress test scenarios. Hence multiple regulatory changes were announced, as noted below.
- Regulatory Requirement
- SCAP: Supervisory Capital Assessment Program
- Stress testing is performed to review whether there is sufficient capital available or not.
- DFAST: Dodd-Frank Act Stress Tests
- A mid-year review will be conducted for all banks with assets of $10 Billion or more.
- Devised by supervisors.
- The approach is more prescriptive, involves less reporting, and requires fewer assumptions about capital action.
- CCAR: Comprehensive Capital Analysis and Review
- A year-end review will be conducted for all banks with assets of $50 Billion or more.
- Complex than SCAP.
- Encompassed of 28 scenarios, considering all the factors that might affect their portfolio (allowing interlinking factors).
- Mandated by regulators.
- Requires projections over 9-quarters i.e. 2.25yrs.
- Requires banks to dynamically forecast balance sheets and income sheets.
- Forecast must include:
- Actual loss
- Revenues
- Loan loss provisions
- Credit losses related to defaulting loans and downgrades on debt scenarios
- Rules for making new loans
- Regulatory ratios
- Capital plans based on each scenario/stress tests:
- Forecast expected capital sources
- Capital use over 9 quarter horizon
- Describe methodologies that will be used to determine capital adequacy
- Minimum capital standards required
- How to raise capital if necessary
- Plans for dividend payments, share repurchases and other factors that will affect the bank's capital
- In the CCAR report about capital planning example:
- CoCos - Contingent convertible bonds, in the event of trouble, bonds could be converted to equity and ease the bank's cash outflows in times of stress.
- These bonds have the characteristic of being convertible into equity shares of the issuing company under certain conditions, typically triggered by predefined events related to the financial health of the issuer.
- One of the key features of CoCos is that they come with contingent conversion triggers. These triggers are often tied to the issuer's capital levels or financial health.
- The bonds act as insurance for banks thus a risk transfer from ERM perspective.
- Tier 1
- Tier 1 typically refers to the highest level of risk within an organization.
- Organizations prioritize these risks due to their potential to cause substantial harm or disruption.
- Examples of Tier 1 risks may include major regulatory changes, economic downturns, catastrophic events, or severe cybersecurity breaches.
- The capital ratio is like a measure of how safe a bank is. The higher the ratio, the safer the bank; the lower the ratio, the riskier it might be and may face regulatory scrutiny to improve its capital adequacy.
- Stress test cannot dip below it:
- Minimum common equity capital ratio is 4.5%.
- Minimum capital requirement is 6%.
- Total risk-based capital ratio is 8% and Tier 1 leverage ratio is 4%.
- If banks fail to meet minimum capital standards under stress testing, the bank must lower its risk appetite.
- CCAR requires banks to engage in exercises that require business line managers to come together and discuss risks, which is the key to the ERM process.
- Different banks are testing the same scenarios, for regulators have a better sense of systematic risks and can compare bank risk exposures, which would be impossible if each bank had its own scenarios.
- Federal Reserve Annual Stress Tests
- Mandated by regulators.
- Below are three macroeconomic scenarios that need to be considered:
- Baseline: Normal
- Adverse: Moderately declining economy
- Severely Adverse: Global recession or depression with the corresponding decline in demand for fixed-income investments.
- While all these are used for compliance issues, it is also used for below:
- Develop warning signals
- Specify risk appetites and risk limits
- Check the reasonableness of capital plans
- Put in contingency plans to manage different risks such as liquidity, and credit.
- Stress tests focus on macroeconomics and can be used in day-to-day business planning.
- Scenarios analysis can be in strategic decision-making.
Risk Culture
- Risk culture
- It is the heart of the ERM
- It defines the behaviour and response towards risk.
- It is the firm's goals, customs, values and beliefs both implicit and explicit that influence the behaviour of employees.
- Corporate norms guide individuals in their understanding and responses to risk and were identified as primary contributors to bank failures in the 2007-2009 financial crisis.
- Risk culture happens at the enterprise level, group level and individual level.
- Measure risk culture
- Measuring risk culture is a problem because it is multi-layered and complex. Individuals have their own risk attitudes because they come from different backgrounds and the risk behavior is as well influenced by peers and management.
- Measures of risk culture help the firm to understand the changes in the risk culture but they do not quantify the losses associated with failures related to the firm's risk culture.
- To measure progress in terms of risk culture there are different methods, one such method is to identify key risk culture indicators of the firm. The Financial Stability Board (FSB) has specified four risk indicators:
- Tone of top management
- Actions of management conflict with stated risk appetite or goals.
- Board of directors communicate the fit between risk appetite and firm strategies and goals.
- Effective communication and challenge
- Firm is valuing whistleblower
- Opposing views are valued
- Right to disagree
- Incentives
- Compensation plans supportive of and in alignment with risk appetite and risk culture.
- Accountability
- Expectations are clear
- Escalation process used
- Survey and other data can be used to develop a risk culture score.
- Factors that can be used to build a robust risk culture.
- Knowledge of the firm's risk appetite and ability to answer questions about its application in day-to-day business operations.
- Risk literacy through training programs and knowledge of the language used to describe risks and the consequences of risk-taking.
- The flow of risk information, and the details about risk flow across the firm with clarity on the discussions of risk and decisions made.
- Risk/reward decisions of managers.
- Risk management stature typically refers to the level of maturity or sophistication of an organization's risk management practices. It reflects how effectively an organization identifies, assesses, mitigates, and monitors risks to achieve its objectives and protect its interests.
- Whistleblowing and escalation, to report enterprise risks and methods in place to blow the whistle.
- Priorities of the board.
- Action against offenders.
- Identification of risk culture concerns and incidents, that were taken in response to violations.
- Factors that prevent firms from developing robust risk cultures that can withstand fluctuations and recover from setbacks relatively quickly.
- Risk education
- Throughout the organization risk education should be provided including the board of directors.
- The board must be able to list key enterprise risks and relate key risks to the firm's risk appetite.
- Having common risk language across the organization would be useful.
- Risk indicators become risk levers
- Firms identify risk indicators, but in many cases, it is easier to manage the risk indicator than to actually improve the firm's risk culture.
- Curse of data
- Growing amount of data available for analyzing risk.
- Culture cycle
- During a crisis behaviour towards risk will be very low due to the feelings and fear, but that fades away over time.
- Risk across the organization and across time
- Risks are generally established in business lines and often develop an internal risk culture rather than at the enterprise level.
- By proactively identifying and managing risks that span multiple business lines, enterprises can strengthen their resilience and enhance their ability to achieve their strategic objectives despite potential challenges and uncertainties.
- External factors also influence risk culture, a few factors are the economic cycle, industry and professional norms, changing industry practices, professional and regulatory standards, country risk and corruption indices.
ERM Best Practices
- Corporate governance (CG) refers to the system of rules, practices, and processes by which a company is directed and controlled.
- It encompasses the relationships and responsibilities among a company's management, its board of directors, its shareholders, and other stakeholders.
- Effective corporate governance is essential for the success of Enterprise Risk Management (ERM) initiatives
- CG ensures senior management and the board have the requisite organizational practices and processes to adequately control risks.
- CG practices have evolved considerably through recent regulatory initiatives including the Turnbull Report and the Sarbanes-Oxley Act.
- A successful corporate governance framework requires the senior management and the board to adequately define the firm's risk appetite and risk and loss tolerance.
- The firm should have the required management skills and organization structure to successfully implement the ERM program.
- All key risks are successfully integrated into the ERM program.
- Risk roles and responsibilities should be clearly defined including the role of the chief risk officer (CRO).
- Audit and monitoring targets are crucial components of the ERM governance process.
ERM Program Dimensions
ERM programs typically encompass several dimensions that collectively contribute to effective risk management across an organization. The following are five important dimensions.
- Targets
- Set correct risk targets.
- Targets should be in sync with strategic goals.
- Targets includes:
- Risk appetite operational mechanism and global risk limits are linked to the risk appetite of the firm.
- Strategic goals are linked to the firm's risk appetite.
- Structure
- The roles along with a description of the firm's governance structure needs to be defined for chief risk officer, global risk committee and other risk committees.
- Ensure enterprise wide risks are identified contributing to direct or indirect losses.
- Establish reporting lines and frequency.
- Identification and metrics
- Identification of risks
- impact on the firm
- severity of the risks
- frequency of the occurrence
- concentration
- Right metrics used to capture whole firm's risks
- scenario analysis
- stress testing
- sensitivity analysis
- standard deviation
- value at risk (VaR)
- total cost of risk approaches
- enterprise-wide risk mapping
- risk specific metrics
- risk flagging tools
- ERM Strategies
- Communicate risk to the entire organization
- Decisions must be made at the enterprise level regarding accept, avoid, mitigate or transfer.
- Culture
- Strong risk culture is the heart and soul of ERM
- Top-down approach in instilling the importance of risk through goals, practices and behaviours.
Credits and References
- https://st4.depositphotos.com/2547605/40711/v/450/depositphotos_407115488-stock-illustration-erm-enterprise-risk-management-business.jpg
- FRM Book 1 - Chapter 8
- https://gemini.google.com/
- https://chatgpt.com/



