Corporate Governance
- Corporate Governance refers to the processes established to operate a business, including the roles and responsibilities of shareholders, senior managers, and the board of directors.
- This discipline evolved from a vague principle to a series of well-defined best practices during the rise of corporate governance failures such as Enron in 2001 and WorldCom in 2002.
- SOX - Sarbanes-Oxley Act
- These major frauds were discovered let to SOX - Sarbanes-Oxley Act in 2002, this led the regulators to strengthen internal controls and strict financial reporting and auditing parameters on public companies.
- CFO and CEOs must personally verify and certify the accuracy of the financial statements of the firm.
- CFO and CEOS must attest all the disclosures provided are accurate.
- Any internal control deficiencies or failures must be reported accurately to investors and regulators.
- The firm's reporting procedures and internal controls must be audited annually.
- Audit committee member names must be disclosed publicly and must have :
- audit experience professionals
- able to understand accounting principles
- able to comprehend financial statements
- Less crimes would occur due to strict internal controls.
- 2007-2009 Financial Crisis
- Several risk management failures.
- Too many securitised mortgage products were linked to subprime (high-risk and low-borrower-quality) loans.
- Stakeholder priority
- Diverse set of stakeholders makes risk management challenging.
- Board composition
- Showed no difference in outcome whether board directors were internal or external stakeholders.
- Board risk oversight
- Reactive to risk management rather proactive.
- Risk appetite
- Board did not clearly articulate and communicate the firm's risk appetite to stakeholders which should be translated into an enterprise risk system.
- Compensation
- Board did not exercise control over management compensation regimes to not incentivize underised risk-taking behaviour.
- Ideally the compensation structures using deferred bonus payments and clawback provisions should be considered.
- Dodd-Frank Act
- Before the Dodd-Frank Act Before 1999 banks operated under the Glass-Steagall Act which prohibited commercial banks from operating investment banking divisions in the same firm, the core idea was to protect depositors from trading volatility.
- The Graham-Leach-Bliley Act introduced in 1999 removed this barrier and permitted bank holding companies to reform as financial services holding companies(FSHCs).
- After the 2007 financial crisis, the Dodd-Frank Act addressed several issues related to financial consumer protection and market stability.
- Seven key elements:
- Strengthen the FED - The Federal Reserve Bank
- FED became more powerful
- Need to oversight all the Systemically Important Financial Institutions - SIFIs with assets greater than $50 billion.
- Ending too big to fail
- Ended the too-big-to-fail theory and created orderly liquidation authority to deal with the failure of large financial institutions.
- Resolution plan
- All SIFIs need to provide a living will, stating the plan to survive during the event of distress.
- Derivatives market
- Created transparency in derivatives markets via clearing exchange and reducing counterparty risk.
- The Volker Rule
- Re-impose some of Glass-Steagall by prohibiting banks from engaging in proprietary trading where trading with the banks' money. Reassuring banks are not allowed to trade with consumers' money.
- Consumer protection
- Created the Consumer Financial Protection Bureau to regulate consumer-facing financial products.
- Stress testing
- Robust and dynamic stress testing must include a top-down approach incorporating macroeconomic shocks and their impact on several risk types.
- This stress testing must be incorporated into the bank's liquidation planning process and the outcome must be evaluated at the bank and economic levels.
- Two stresses performed by FED
- Assets above $10 billion - Dodd-Frank Act Stress Test -DFAST
- Assets above $50 billion - Comprehensive Capital Analysis and Review -CCAR
- BCBS - Basel Committee on Banking Supervision
- This organization is comprised of banking regulators from 27 jurisdictions.
- Series of standards were devised, although they are not legally binding but do present sound risk management best practices for files willing to apply the guidance.
- Basel I
- In 1988 post-Latin American debt crisis created a uniform approach to bank capital adequacy standards.
- Focused on managing credit risk by recommending minimum capital of 8% of a bank's risk-weighted assets.
- Basel II
- In 2006 replaced Basel I, here included both trading and lending activities in capital adequacy standards.
- Also imposed disclosure suggestions and standards for bank supervision by regulators.
- Basel III
- Post-financial crisis of 2007-2009, created system factors for handling both company-specific (idiosyncratic) risk and market-level (systematic) risk.
- Limits Tier I capital which is the core measure of a bank's strength to include common equity and related earnings (reserves of the bank).
- Imposes a LCR - Liquidity coverage ratio, where banks must hold enough highly liquid assets to fund 30-day's worth of cash needs.
- A net stable funding ratio to encourage banks to have at least one year's worth of stable cash flow to fund required operations.
- Macroprudential overlay (one bank failing other banks) to lessen systematic risk and procyclicality. This overlay consists of 5 elements:
- A leverage ratio - Tier I capital/total consolidated assets cap of 3%.
- CCCR - A countercyclical capital buffer/requirement.
- Global systemically important banks (G-SIBs) have implementation of minimum total loss-absorbing capital (TLAC) standards.
- TLAC standards are designed to ensure that G-SIBs have sufficient loss-absorbing capital to withstand financial stress and maintain their critical functions without requiring taxpayer bailouts or causing disruptions to the wider financial system.
- TLAC consists of a combination of equity, long-term debt, and other instruments that can be used to absorb losses in the event of a bank's failure.
- Risk modelling and stress testing modified to better capture tail risks and minimize counterparty risk
- Revised Guidelines in 2015 by BCBS to make better Basel III
- The guidelines are for banking sector risk management making BOD responsible for risk management.
- Responsibility of the board of directors:
- Oversee senior management implementation of the firm's risk appetite strategic objectives and governance framework.
- Board composition
- All board members should be qualified, topical knowledge and skillsets for their supervisory responsibility and to execute their duties.
- Policies of the board
- The board should establish policies strategically for their own operations to reinforce their objectives.
- Senior management
- Should conduct the day-to-day business operations and implement risk management as per the policy approved by the board.
- Governance for a conglomerate
- Conglomerate is a combination of several businesses, often structured like a parent and several child firms.
- The board of the parent firm needs to have ultimate oversight over the operations of all the members of the conglomerate.
- Risk management function
- Should always be an independent risk management function that reports to the board under the daily supervision of a CRO.
- Risk identification, monitoring and control
- Oversee risk mapping (identification)
- Once identified need to direct if the risk needs to be retained, avoided, mitigated or transferred.
- Incumbent is the process of monitoring dynamic risk on an ongoing basis.
- Risk communication
- Effective communication about the firm's risk appetite to all levels of the firm.
- Compliance
- Oversee compliance risk management.
- Internal audit
- Perform periodic audits to inform the board of the firm's progress on risk management.
- Compensation
- Board should organize and supervise the firm's compensation structure such that management is held financially accountable for risk decision-making.
- Disclosure
- Firm's risk management process should be adequately disclosed to stakeholders.
- Revised Guidelines in 2016 by BCBS to make better Basel III
- Expanded to include the FRTB - Fundamentals Review of the Trading Book.
- Intended to broaden the inclusion of market risk exposures.
- Risk management through a bank's trading desks in banks engage in various activities involving derivatives, futures, currencies, indices, and other complex financial assets, which introduce several types of risks.
Risk Governance Implementation
Risk Advisory Director
- In terms of risk governance, risk advisory directed is the specialized role of risk management and separate duties.
- Recommended to have an independent risk advisory director(industry expert who understands risk factors very well) when the board of directors come from various backgrounds.
- Risk Advisory Directors build the bridge between the board of directors and senior management.
- Role involves educating members on the best practices in both corporate governance and risk management.
- With or without the assistance of a risk advisory directory, the board's duties include the review and analysis of the following:
- The firm's risk management process
- The firm's periodic risk management reports
- The firm's risk appetite and its impact on business strategy
- The firm's internal controls
- The firm's financial statements and disclosures
- The firm's related parties and related party transactions
- Any audit reports from internal or external audits
- Corporate governance best practices for the industry
- Risk management practices of competitors and the industry
Risk Management Committee
- Risk management committee which is a subset of the full board of directors, and is responsible for setting the firm's risk appetite.
- Independently monitor ongoing risk management.
- Members will maintain contact with both internal and external auditors to ensure compliance with all relevant policies, (e.g., regulations and internal risk limits).
- Approving credit facilities that are above certain limits or within limits but above a specific threshold.
Compensation Committee
- Independent of management.
- The Compensation Committee typically consists of independent directors who do not have any material relationship with the company or its executives.
- This independence ensures objectivity in decision-making and helps prevent conflicts of interest.
- To ensure appropriate risk-taking concerning the Long-term risks assumed.
- While short-term performance is important, remuneration structures should also consider long-term sustainable growth.
- Including a mix of short-term and long-term incentives, such as stock options or equity-based awards, can encourage a focus on both immediate results and the company's future prospects.
- Discuss and approve the remuneration of key management personnel.
- Incorporating performance-based incentives ensures that remuneration is tied to the achievement of specific goals and targets.
- This helps align the interests of key management personnel with those of shareholders and encourages a focus on value creation and operational excellence.
- Clawback
- Remuneration decisions should be mindful of potential risks, such as excessive risk-taking or short-termism, that may arise from incentive structures.
- Implementing appropriate risk controls and clawback provisions can help mitigate these risks and promote responsible behaviour among key management personnel.
- Bonus bonds
- A bond that only pays a benefit if certain thresholds are met.
- In simple terms, "bonus bonds" used as compensation might be subject to regulatory restrictions designed to ensure banks maintain certain levels of stability and financial health.
- If these regulations are breached, the distribution of such bonds might be restricted or halted.
- Let's unpack this with a straightforward example to illustrate how such a scenario might occur:
- Scenario:
- Bonus Bonds as Part of Compensation Packages Imagine a bank decides to offer special bonds, let's call them "bonus bonds," to its employees as part of their compensation package.
- These bonds might be an additional perk, providing employees with a potential return if the bank performs well.
- Regulatory Capital Ratios
- Banks are required to maintain certain levels of capital relative to their risk—their regulatory capital ratios.
- These ratios are critical safeguards implemented by financial regulators to ensure that banks have enough buffer to absorb losses and protect depositors' money.
- Breach of Regulatory Requirements
- Suppose the bank faces significant financial losses due to a downturn in the economy.
- As a result, the bank’s capital levels begin to fall close to or below the minimum requirement set by the regulators (known as the capital adequacy ratio).
- Supervisory Intervention
- In such a case, regulators would scrutinize the bank's practices, including compensation schemes involving "bonus bonds."
- If regulators determine that issuing these bonds could further jeopardize the bank's capital position (i.e., reduce the bank’s capital even more because these bonds might be counted as liabilities or require cash reserves), they may prohibit or limit the distribution of these bonds.
- The rationale is to conserve the bank's capital to ensure it remains stable and capable of covering its risks and obligations.
- Layman’s Term Example: Think of it like a family budget scenario:
- The family (bank) has a rule to always maintain a savings buffer of $1,000 for emergencies.
- They also have a practice of giving special gift coupons (bonus bonds) to family members as rewards.
- However, the family faces unexpected expenses (financial losses) and their savings are down to $1,100.
- The rule (regulatory requirement) says, if savings fall below $1,000, no more spending on extras until they replenish their buffer.
- Therefore, the family decides to stop issuing the coupons to ensure they don’t risk dipping below their necessary savings level.
- This simplified example mirrors how bonus bonds might be restricted to ensure the bank remains financially healthy and compliant with regulatory capital requirements.
Audit Committee
- Audit committee a subcommittee of the full board, is responsible for the accuracy of financial statements and its regulatory reporting requirements.
- Responsible for the firm's risk management process, ensuring the board-established policies are followed and that those policies are sufficient to adequately monitor and control risk exposures.
- Oversee internal auditors, and they are responsible for the below:
- monitoring risk management procedures
- tracking the progress of existing systems
- affirming the efficacy of the existing policies/systems
- verify adherence to compliance standards
- validate calculated risk metrics
- validate any pricing models
- offer opinion on the assumption used in internal risk estimation
- Audit committee is largely meant to be independent of management, but it should work with management and communicate frequently to ensure that any issues arising are addressed and resolved.
Interdependence of Functional Units
- For risk management and reporting various functional units are dependent on each other.
- Risk committee
- Oversees the firm's risk management process.
- CRO
- Monitors day-to-day limits.
- It is the frontline managers and employees who implement the firm's risk policy.
- Responsible for day-to-day risk supervision.
- Approve temporary breaches of communicated risk limits as long as the enterprise-level risk limits are still within the board-established tolerance bands.
- CRO liaison between the board and senior management.
- Senior management
- With supervision of the risk committee sets the firm's risk appetite.
- Design and oversee risk policy and evaluate performance relative to risk limits.
- Business unit level
- Risk policy is implemented
- Finance and operations functions
- Physically execute the risk mitigation and transfer transaction.
- Analyze current risk management tools to ensure the risk limits are maintained.
- Help in the risk and business planning process.
- Risk management
- Led by CRO.
- Monitors risk limits and controls.
- Manage risk management process.
- Regular communications with senior management and risk committee.
Corporate Governance vs. Risk Management
- Corporate governance and risk management are interrelated concepts that are crucial for a well-functioning organization. Here's a breakdown of their distinctions and how they work together:
- Corporate Governance:
- Corporate governance establishes the principles and structures that guide how a company is directed and controlled. It defines the roles and responsibilities of the board of directors, management, and shareholders.
- Promote transparency and accountability
- Protect shareholder interests
- Ensure compliance with laws and regulations
- Foster ethical business practices
- Key elements:
- Board of directors: Provides strategic oversight, appoints management, and monitors risk management practices.
- Management: Implements the company's strategy, manages day-to-day operations, and executes risk management plans.
- Internal controls: A system of policies, procedures, and safeguards to ensure accurate financial reporting, operational efficiency, and regulation adherence.
- Compliance: Adherence to relevant laws, regulations, and industry standards.
- Best practices:
- Board of directors should have sufficient knowledge of the firm's business and industry to make and approve management decisions independently.
- Agency risk, in corporate governance arises from a fundamental conflict of interests between two key parties:
- Principals: These are the owners of the company, typically represented by shareholders. Their primary interest lies in maximizing the value of their investment, which translates to increasing the company's profitability and stock price.
- Agents: These are the managers or executives entrusted with running the company on behalf of the shareholders. While they should act in the best interests of the company and its shareholders, their motivations might not always perfectly align with those of the principals.
- How Agency Risk Creates Problems:
- Self-dealing: Managers might prioritize their own interests over the company's by taking actions that benefit them personally, such as excessive compensation packages or pursuing risky ventures that could jeopardize the company's financial health.
- Shirking and moral hazard: Managers might not exert the necessary effort to manage the company effectively, or they might engage in risky behaviour knowing they are somewhat insulated from the consequences (moral hazard). This can lead to inefficiencies and decreased profitability.
- Horizon problem: Managers might focus on short-term goals and financial performance to meet quarterly earnings expectations, even if it comes at the expense of long-term growth and shareholder value.
- Consequences of Agency Risk:
- Reduced profitability and shareholder value: If managers don't prioritize the company's best interests, it can lead to inefficiencies, missed opportunities, and ultimately, lower profits and reduced shareholder returns.
- Loss of investor confidence: If shareholders perceive a high level of agency risk, they might be less willing to invest in the company, potentially hindering its ability to raise capital and grow.
- Regulatory scrutiny and potential legal issues: Excessive agency risk can attract unwanted regulatory attention and potentially lead to legal repercussions for the company and its management.
- Mitigating Agency Risk:
- Corporate governance practices aim to establish a framework that aligns the interests of managers with those of shareholders and reduces agency risk. Here are some key mechanisms:
- Strong Board of Directors: An independent and competent board can provide oversight of management and hold them accountable for their actions.
- Clear Performance Measures: Establishing clear and measurable performance metrics that align with long-term shareholder value can help guide management decisions.
- Compensation Plans: Structuring executive compensation packages to reward performance that benefits shareholders, such as stock options or performance-based bonuses, can incentivize managers to act in the best interests of the company.
- Transparency and Disclosure: Regular and transparent communication with shareholders about the company's performance and strategy helps to build trust and reduce information asymmetry.
- Shareholder activism: Shareholders can use their voting rights and engage with management to advocate for practices that promote long-term value creation.
- Roles of the CEO and the chairperson of the board are two different people and should be separate and independent for stakeholder protection.
- Risk Management:
- Risk management is the process of identifying, assessing, and mitigating potential risks that could threaten the company's objectives. It involves developing strategies to minimize the impact of these risks.
- Identify and analyze potential threats to the organization
- Assess the likelihood and potential impact of these risks
- Develop strategies to avoid, reduce, transfer, or accept risks
- Implement controls and monitoring procedures to manage risks effectively
- Key elements:
- Risk identification: Proactive search for potential threats to the organization's financial performance, reputation, or operations.
- Risk assessment: Evaluating the likelihood and severity of identified risks.
- Risk mitigation: Developing strategies to address risks, such as implementing controls, acquiring insurance, or diversifying investments.
- Risk monitoring: Continuously monitoring risks and updating risk management strategies as needed.
- Best practices:
- Communicate risk appetite enterprise level clearly.
- Determine known risks needed to be retained, avoided, mitigated or transferred.
- Establish and maintain a CRO role reporting to the CEO but retains full access to the board.
- Establish a risk committee who are knowledgeable of the risks faced by the firm.
- Connect the work of the compensation committee with the firm's risk appetite and the work of the risk committee.
- Maintain an independent audit committee that can monitor relevant actions.
- How They Work Together:
- Corporate governance provides the framework for effective risk management. The board of directors sets the risk tolerance for the organization and ensures a robust risk management system is in place.
- Risk management informs decision-making within corporate governance. By identifying and analyzing potential risks, risk management helps the board and management make informed decisions about the company's strategy, resource allocation, and overall direction.
- Effective communication between these two functions is critical. The risk management team needs to communicate potential risks and mitigation strategies clearly to the board and management.
- Here's an analogy:
- Think of a company as a ship navigating a sea full of potential hazards (icebergs, storms, etc.). Corporate governance establishes the course, crew roles, and navigation tools (maps, compass). Risk management identifies potential hazards on the route, assesses their threat level, and recommends strategies to avoid or navigate them safely (detours, increased vigilance, lifeboats).
- Corporate governance sets the stage for good decision-making, while risk management provides the vital information and tools to navigate potential threats and ensure the company's long-term success.
Risk Appetite vs. Business Strategy
- There must be consistency between the firm's risk appetite and its business strategy.
- If the firm's strategic goal is to make profitable loans, then the risk limits will impose credit risk parameters.
- If the firm's strategic goal is smooth operations, needs to address operational risks or foreign currency risks.
- Risk appetite and business strategy are two critical components of an organization's approach to risk management and decision-making, but they serve distinct purposes:
- Risk Appetite
- Definition: Risk appetite refers to the level of risk that an organization is willing to accept or tolerate in pursuit of its objectives. It represents the amount and type of risk that the organization considers acceptable in achieving its strategic goals.
- Scope: Risk appetite applies across the entire organization and encompasses various types of risks, including strategic, financial, operational, compliance, and reputational risks.
- Establishment: Risk appetite is typically defined and articulated by the organization's board of directors or senior management in consultation with key stakeholders. It reflects the organization's risk tolerance, risk appetite statement, risk appetite framework, and risk appetite metrics.
- Alignment: Risk appetite should align with the organization's mission, vision, values, and overall risk culture. It provides guidance to decision-makers at all levels regarding the acceptable level of risk-taking in pursuit of organizational objectives.
- Monitoring and Reporting: Risk appetite is monitored and reported on regularly to assess adherence to established risk thresholds, identify emerging risks, and inform strategic decision-making.
- Business Strategy:
- Definition: Business strategy outlines the organization's overall approach to achieving its objectives, including its goals, priorities, initiatives, and resource allocation decisions. It defines how the organization plans to create value, differentiate itself from competitors, and sustain long-term success.
- Scope: Business strategy focuses on defining the direction and scope of the organization's activities, including market positioning, product development, geographic expansion, mergers and acquisitions, and other strategic initiatives.
- Development: Business strategy is developed by senior management in collaboration with key stakeholders, taking into account internal capabilities, market dynamics, competitive landscape, customer needs, and other relevant factors.
- Alignment: Business strategy should be aligned with the organization's mission, vision, values, and risk appetite. It considers risk factors and uncertainties inherent in the business environment and seeks to capitalize on opportunities while managing and mitigating potential risks.
- Execution and Performance Measurement: Business strategy is executed through operational plans, projects, and initiatives, and performance is measured against predefined strategic objectives, key performance indicators (KPIs), and financial targets.
- While risk appetite provides overarching guidance on the level of risk that an organization is willing to accept, business strategy defines the direction and priorities for achieving organizational objectives. Both risk appetite and business strategy are integral to effective risk management and decision-making, and they should be aligned to ensure that risk-taking activities support the organization's strategic goals and long-term success.
Credits and References
- https://media.licdn.com/dms/image/D5612AQFm_1l6-JLwTg/article-cover_image-shrink_720_1280/0/1693782550842?e=2147483647&v=beta&t=4oMK7yPqbZfLSudw-_6sMH5HFkedpP3EyURSy-0rSgE
- FRM 2023 Notes
- Chapter 3
- https://chatgpt.com/
- https://gemini.google.com/



