Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Risk, Treasury & Financial Control
1Risk Foundations
Risk Appetite, Tolerance, Capacity…The Risk Taxonomy and UniverseRisk Register vs Risk MatrixStress TestingScenario Analysis vs Stress TestingImpact and LikelihoodLikelihoodThe Risk EventRisk Assessment
2Enterprise Risk Management
Enterprise Risk ManagementThe Four Risk TreatmentsRisk CultureRisk MaturityRisk Monitoring
3Risk Governance
Risk GovernanceHow to set a…The Risk PolicyThe Risk OwnerThe Risk Committee and Its CharterThe Risk Limit FrameworkRisk EscalationHow to set a…
4Credit and Counterparty Risk
Collateral AgreementsCollateral vs NettingProbability of DefaultExposureCounterparty ExposureConcentration Risk vs Wrong Way RiskCounterparty Risk vs Credit RiskHow to assess Counterparty ExposureHow to assess Concentration Risk
5Market Risk
Market RiskSensitivity MeasuresThe Hedging PolicyInterest Rate Risk in the Banking BookIRRBB vs Market RiskExpected ShortfallEconomic Value of EquityVaR BacktestingOpen PositionValue at RiskValue at Risk and Expected ShortfallEconomic Value SensitivityFX ExposureValue at Risk vs Expected ShortfallEarnings at Risk vs…FX Transaction Risk vs…How to measure Interest…How to measure Foreign…
6Liquidity Risk
Liquidity Stress TestingLiquidity Gap vs Liquidity BufferMaturity MismatchThe Debt Maturity ProfileFunding ConcentrationSurvival HorizonThe Contingency Funding PlanNet Stable Funding RatioLiquidity Risk vs Funding RiskLiquidity Coverage RatioLiquidity Gap and BufferHow to run a Liquidity Gap Analysis
7Operational Risk
Operational LossThe Loss EventRisk and Control Self AssessmentException ManagementInformation Security as a…Segregation of DutiesIssue ManagementThe Near MissRoot Cause Analysis in RiskThe Fraud TriangleCyber Risk vs Third Party RiskHow to run a…How to assess Third…
8Risk Reporting, Data and Model Risk
Model RiskModel Validation vs BacktestingHow to run Model ValidationData Governance in RiskModel Risk vs Data RiskKey Risk IndicatorsManagement InformationRisk ReportingRisk ScoreEarnings at RiskRisk Adjusted ReturnEarly Warning IndicatorsHow to build a KRI Dashboard
9Treasury
Corporate TreasuryAsset Liability ManagementIntragroup FundingThe Treasury PolicyThe Treasury Management SystemThe Cash ForecastCash Pooling and ConcentrationHow to build a Cash Forecast
10Financial Controls and Assurance
Control AssuranceThe Control LifecycleThe Assurance MapThe Audit FindingIssue RemediationInternal Financial ControlsControl Design vs Control EffectivenessHow to map Internal Financial ControlsHow to test Control…Control DeficiencyMaterial Weakness
11Operational Resilience
Operational ResilienceBusiness Continuity and Disaster RecoveryBusiness Continuity vs Operational…Crisis ManagementDisaster RecoveryIncident Management

Risk Score: Compressing Two Judgements Into One Number

A risk score is impact multiplied by likelihood on an institution's own scale, produced so that a register can be sorted and a dashboard can show a colour. The score is a reporting device and not an assessment. On a five by five grid the 25 cells produce only 14 distinct scores, and only 4 of the 25 can be recovered from the number they produce.

A risk score is arithmetic anybody can check with a pencil, and the check is worth making. The multiplication does something to the information that nobody announces when the report is handed over. Two judgements go in. One number comes out. The number is easier to work with in every way that matters to a meeting, and it has quietly stopped being able to say what to do.

What is a risk score, and what is it actually for?

A risk scoreA single number formed from two judgements, usually impact multiplied by likelihood, so that a list can be ordered. is a single number formed from two separate judgements so that a list of risks can be put in an order. Nothing else is going on. The score is not a measurement of anything, it does not come from a model, and it carries no unit. The score exists because a list has to be sortable and two numbers cannot sort a list.

Take it out of a bank for a moment. A household has four jobs waiting and one free Sunday. The roof has a slow leak that would ruin a ceiling if the monsoon caught it, and it has held for two years. A bulb on the stairs fuses about once a month and somebody replaces it in four minutes. The gate latch sticks. The geyser makes an unwelcome sound. All four cannot be done, so they have to be ranked, and ranking them means squashing two thoughts into one: how bad would it be, and how often is it going to happen. Squashing two thoughts into one is a risk score. The leaking roof and the fusing bulb can very easily come out of it with the same rank, and that is the whole problem.

Vindhya Commercial Bank Limited, invented, does the same thing at a balance sheet of Rs 96,000 crore. The bank keeps a record of the risks it has identified, rates each one for how much it would hurt and how probable it is, multiplies the two, and reports the result.

There are exactly three things the resulting number does well, and they are all things a single value can do that a pair cannot. The number can order a list, and 46 entries acquire a top. A score can drive a colour, turning a band of scores into red, amber or green on a dashboard. And a score can carry an escalation levelA score at or above which something is reported upward, which is one of the few genuine uses of the compressed number.. Anything at or above a chosen value goes upward to a committee without anybody having to argue the case again. There is a fourth thing people use it for, deciding what to actually do about an entry, and it is the one thing the number cannot support.

THREE THINGS ONE NUMBER DOES WELL, AND THE ONE IT CANNOT DO AT ALL The first three need a single sortable value. The fourth needs the two judgements that made it. USE 1 Order a list Forty six entries get a top and a bottom. A NUMBER DOES THIS WELL USE 2 Colour a dashboard A band of scores becomes one colour. A NUMBER DOES THIS WELL USE 3 Set a level for escalation At or above a chosen score, it goes upward. A NUMBER DOES THIS WELL NOT A USE Decide what to do The response depends on which pair made it. A NUMBER CANNOT DO THIS Three of these are things one number does well. The fourth depends on the pair the multiplication threw away.
Ordering, colouring and escalating are jobs a single value does well, and deciding what to do is not one of them.
Try it out

A colleague reads a score off the register and uses it to decide what to do about that entry. What is wrong with that?

How is the number computed, and who decides the scale?

The computation is one multiplication. ImpactHow much it would hurt if the thing happened, rated on the institution's own scale and estimated elsewhere. is rated from 1 to 5. LikelihoodHow probable the thing is over a stated horizon, rated on the institution's own scale and estimated elsewhere. is rated from 1 to 5. Multiplying the two gives a score somewhere between 1 and 25. Both ratings are taken here as given inputs: how each one is arrived at, what a five point scale means and how an entry gets onto a register in the first place are covered separately.

Now the question people almost never ask. Where does five by five come from? Nowhere. No external body prescribes a risk scoring scale, so every scale in use anywhere is the institution's own choice. Five by five is common because an odd number gives a middle option and five rows stay readable at a glance. Three by three, four by four and six by six all exist and all work. Nothing in the arithmetic requires five, and an institution that chose four by four would get a different set of possible scores, a different amount of crowding and a different answer to every question below. Crowding, holes and lost pairs are properties of the scale somebody picked, not properties of risk.

There is an honest technical caution to put beside the multiplication. A rating of 4 for impact is not twice a rating of 2 in any measurable sense. A rating is a rank chosen from a ladder of descriptions, and multiplying two ranks produces a number that looks arithmetical and is really an ordering convention. Frank Knight, in Risk, Uncertainty and Profit, published in 1921, separated the risk that can be measured from the uncertainty that cannot, and a five by five rating sits closer to the second than most reports admit. The score is still useful. The score is useful as a sorting key and not as a quantity.

Try it out

Where does a five by five scale come from?

Try it out

A five by five grid has 25 cells. How many different scores can it produce?

How many different scores can twenty five cells actually produce?

Write the grid out and put the score inside every cell. Almost nobody does that, and nothing else anybody can do with a scoring scheme is half as useful. Twenty five cells go in. Fourteen distinct numbers come out: 1, 2, 3, 4, 5, 6, 8, 9, 10, 12, 15, 16, 20 and 25. 7, 11, 13, 14, 17, 18, 19, 21, 22, 23 and 24 are simply not products of two whole numbers from 1 to 5, so eleven of the values between 1 and 25 cannot be produced at all. The grid produces 14 values out of 25, being 56.0 per cent, and 11 that never can, being 44.0 per cent.

THE INVENTED BANK'S OWN FIVE BY FIVE GRID, WITH THE SCORE WRITTEN INTO EVERY CELL Score is impact multiplied by likelihood. Read the numbers inside and count how often they repeat. LIKELIHOOD, 1 TO 5 1 2 3 4 5 IMPACT, 1 TO 5 IMPACT 5 IMPACT 4 IMPACT 3 IMPACT 2 IMPACT 1 5 10 15 20 25 4 8 12 16 20 3 6 9 12 15 2 4 6 8 10 1 2 3 4 5 THE FOURTEEN SCORES THAT OCCUR: 1, 2, 3, 4, 5, 6, 8, 9, 10, 12, 15, 16, 20 and 25 THE ELEVEN THAT NEVER DO: 7, 11, 13, 14, 17, 18, 19, 21, 22, 23 and 24
Twenty five cells on the invented bank's own grid produce only fourteen distinct scores, and the numbers repeat.

Look at what that does to a scale nobody thought to check. A report that speaks of a risk scoring range of 1 to 25 sounds continuous, sounds fine grained, and sounds like it has twenty five settings on the dial. The dial has fourteen settings, with holes scattered all through the upper half. A committee member who asks whether anything on the register scores 13 is asking a question the scheme can never answer yes to, and nothing in the scheme tells them so.

A SCALE THAT READS AS 1 TO 25 AND HAS ELEVEN HOLES IN IT Every value from 1 to 25, marked by whether two whole numbers from 1 to 5 can multiply to it. 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 A SCORE THIS GRID CAN PRODUCE, AND THERE ARE 14 A VALUE THAT CANNOT OCCUR AT ALL, AND THERE ARE 11 Fourteen of the twenty five values occur, being 56.0 per cent, and eleven cannot occur at all, being 44.0 per cent.
Eleven values inside a range that looks continuous can never be produced by any pair on the grid.

The same finding is set out below as a table, to be looked up rather than taken on trust. Read the middle column as the pairs that produce each score, impact first and likelihood second.

ScoreThe pairs that produce it, impact firstCellsRecoverable from the score alone
11 with 11Yes
21 with 2, 2 with 12No
31 with 3, 3 with 12No
41 with 4, 2 with 2, 4 with 13No
51 with 5, 5 with 12No
62 with 3, 3 with 22No
82 with 4, 4 with 22No
93 with 31Yes
102 with 5, 5 with 22No
123 with 4, 4 with 32No
153 with 5, 5 with 32No
164 with 41Yes
204 with 5, 5 with 42No
255 with 51Yes
14Every pair on the grid254 cells, being 16.0 per cent
Derivatives Foundation Bootcamp — Fin Maverick

Where on the scale does the crowding sit?

Counting the cells behind each score is where the shape of the thing appears. Four scores come from a single cell. Nine scores come from two cells each. One score, and only one, comes from three cells, and that score is 4. Check the total: 4 single cells plus 18 in pairs plus 3 at the score of 4 gives 4 plus 18 plus 3, and that is 25, so every cell is accounted for exactly once.

HOW MANY CELLS PRODUCE EACH OF THE FOURTEEN SCORES Taller means more different situations wearing the same number. The four short bars are the only recoverable ones. 1 2 3 CELLS THAT PRODUCE IT 11 22 23 34 25 26 28 19 210 212 215 116 220 125 Four scores come from one cell, nine come from two and one comes from three, and 4 plus 18 plus 3 is 25.
The tallest bar sits at a score of 4, which is the only value in the whole grid produced by three cells.

Where do the four single cell scores sit? At 1, at 9, at 16 and at 25. Two of those are the absolute extremes of the scale, the corner where nothing much is at stake and the corner where everything is. The other two sit high. Every score in the busy part of the range, the 4s and 5s and 6s and 8s and 10s and 12s where the ordinary business of a register actually lives, comes from two or three cells. The compression bites hardest exactly where the population is, and the parts of the scale where the number is trustworthy are the parts almost nothing lands on.

One more number for shape. The average of all 25 scores is 225 divided by 25, being exactly 9.0, and the middle value when all 25 are lined up in order is 8. So the arithmetic centre of the scheme sits at 8 and 9. The value 9 is one of the four that identify their cell, and 8 comes from two cells. Nothing designed that. The centre is what falls out of multiplying two ladders together.

Try it out

Where on the scale does the compression do the most damage?

Try it out

Impact 2 with likelihood 2 scores 4. Which other cells give exactly the same score?

Can impact and likelihood be recovered from a score?

The question has an exact answer, and the calculator below is built around it. Where two cells produce a score there are two candidates, and the number offers no way to choose between them. So the pair can be recovered only where exactly one cell produces the score. A recoverable cellA combination of impact and likelihood that can be identified from its score alone, because no other combination produces it. is therefore a cell whose score is 1, 9, 16 or 25 and nothing else.

Four of the 25 cells are recoverable, being 16.0 per cent, and 21 are not, being 84.0 per cent. That second figure needs its object named every time it is used. The 84.0 per cent is the share of grid cells that cannot be identified from their score and nothing else: this same invented bank carries an 84.8 per cent somewhere else in its papers that means a limit utilisation, and another 84.8 per cent that means how complete a register of models is, and the three have no relationship whatsoever beyond looking alike in a report.

Now the part that is easy to get backwards, and worth being careful about. All four recoverable cells sit on the diagonalThe cells where impact equals likelihood, which is where almost all the recoverable scores sit.. Impact equals likelihood there: 1 with 1, 3 with 3, 4 with 4 and 5 with 5. But the diagonal has five cells, not four. The fifth is impact 2 with likelihood 2. 1 times 4 and 4 times 1 also make 4, so that cell is not recoverable. So the rule runs one way and not the other: every recoverable cell is on the diagonal, and one cell on the diagonal is not recoverable.

THE ONLY FOUR CELLS A SCORE CAN IDENTIFY, AND THE ONE THAT LOOKS LIKE A FIFTH A small square in the corner of a cell marks the diagonal, where impact equals likelihood. LIKELIHOOD, 1 TO 5 1 2 3 4 5 IMPACT, 1 TO 5 IMPACT 5 IMPACT 4 IMPACT 3 IMPACT 2 IMPACT 1 5 10 15 20 25 4 8 12 16 20 3 6 9 12 15 2 4 6 8 10 1 2 3 4 5 EVERY CELL ON THE GRID, SPLIT BY WHETHER ITS SCORE IDENTIFIES IT 4 CELLS 21 CELLS, BEING 84.0 PER CENT, NOT RECOVERABLE FROM THEIR SCORE The four dark cells are the only ones whose score identifies them. Impact 2 with likelihood 2 sits on the diagonal and is not one of them, because 1 times 4 and 4 times 1 also make 4. 84.0 per cent here is the share of grid cells not recoverable from their score, and it means nothing else here.
Only four cells can be identified from their score, and all four sit on the diagonal that has five.

There is a smaller way to say the same thing that is worth holding on to. Of the 14 distinct scores, 4 identify their cell. Printed as a percentage that is 28.6 per cent, and it is the share of distinct scores that identify a cell and not any of the other things 28.6 per cent stands for elsewhere in this invented bank's papers. Same fraction, different object, and naming the object is the whole discipline.

Try it out

An entry scores 12. What does that establish about its impact and its likelihood?

Play with it

Set the pair and watch every other cell that makes the same number

Two controls, and any cell in the grid can also be clicked directly. The slider moves impact, the buttons pick likelihood, and the grid shows the chosen cell in dark and every other cell producing the identical score in green. The default is impact 2 with likelihood 2, scoring 4. The two green cells that appear beside it are the fastest demonstration of what the compression costs. CompressionTurning two values into one, which is what makes sorting possible and what makes the pair unrecoverable. is not a metaphor here; it can be watched happening.

IMPACT 1IMPACT 2IMPACT 5
Likelihood
CLICK ANY CELL, OR USE THE CONTROLS ABOVE Dark is the chosen cell. Green is every other cell in this invented bank's grid that makes the identical score. LIKELIHOOD 1 2 3 4 5 IMP 5 IMP 4 IMP 3 IMP 2 IMP 1 5 10 15 20 25 4 8 12 16 20 3 6 9 12 15 2 4 6 8 10 1 2 3 4 5 SCORE 4 CELLS SHARING IT 3 of 25 FROM THE SCORE ALONE NOT RECOVERABLE Impact 2 with likelihood 2 scores 4, and so do impact 1 with likelihood 4 and impact 4 with likelihood 1.
The selected pair
2 and 2
Score
4
Cells at this score
3

Impact 2 with likelihood 2 scores 4, which is also produced by impact 1 with likelihood 4 and by impact 4 with likelihood 1, so this cell is not recoverable from a score of 4 alone.

Educational illustration. The five by five scale shown here is Vindhya Commercial Bank Limited's own, and no external body prescribes one. Impact and likelihood are judgements estimated elsewhere and this calculator takes them as given inputs. The bank's register carries 46 entries rated 4 red, 12 amber and 30 green on the bank's own count, and the record does not fix a score for each entry, so the 46 cannot be spread across the fourteen scores.
Bond Pricing and Yield Mechanics — free micro-course from Fin Maverick

What does a score of 4 actually hide?

A score of 4 puts the whole argument on one screen. Three cells make it, and they are three completely different situations that a register orders as equals.

Three entries score 4, and they need three different responses

Impact 4 with likelihood 1 is a rare severe event. The event will probably not happen, and if it does it hurts a great deal. In this bank's own loss record that shape is incident I13, the trade finance fraud in which a member of staff and an outside party issued nine letters of credit against forged shipping documents over fourteen months ending in month 8. The fraud happened once and cost Rs 15.4 crore net, the largest net loss of the year.

Impact 1 with likelihood 4 is a frequent trivial one. Such an event happens all the time and each occurrence is small. The frequent trivial shape is incident I1, card-not-present fraud on the debit card portfolio, many small events across the year adding to Rs 4.8 crore net. This bank's record fixes no impact or likelihood rating for any incident, so the two incidents illustrate the two shapes and carry no rating of their own.

Impact 2 with likelihood 2 is neither, and it is the one nobody argues about at a meeting.

The response each one calls for differs. A rare severe event is an argument for a control that stops it happening at all, or for a reserve, or for insurance. The purchase is protection against a tail that may never be seen. Stopping every instance costs more than the instances do, so a frequent trivial one is an argument for reducing the cost of each occurrence or for accepting it as an ordinary operating expense. The middling one argues for neither in particular. Three responses, one number. A register sorted by score puts all three at the same rank, and a dashboard paints all three the same colour. The multiplication did precisely what it was asked to do. The limit lies in what a sorted list can carry.

ONE SCORE OF 4, THREE SITUATIONS, THREE DIFFERENT RESPONSES A sorted register shows these three at the same rank and a coloured dashboard paints them the same colour. IMPACT 4, LIKELIHOOD 1 SCORE 4 Rare and severe. It will probably not happen. If it does, it hurts badly. The shape of incident I13: one event, Rs 15.4 crore net. WHAT IT ARGUES FOR A preventive control, a reserve, or insurance. IMPACT 1, LIKELIHOOD 4 SCORE 4 Frequent and trivial. It happens constantly. Each occurrence is small. The shape of incident I1: many events, Rs 4.8 crore net. WHAT IT ARGUES FOR A lower unit cost, or accepting it as a cost. IMPACT 2, LIKELIHOOD 2 SCORE 4 Neither of the above. Middling on both counts. Nobody argues about it. It sits on the diagonal and is still not recoverable. WHAT IT ARGUES FOR Neither in particular, and that is a finding too. The incidents illustrate the two shapes. This bank's record fixes no impact or likelihood rating for any incident.
The same score of 4 covers a rare severe event, a frequent trivial one and something in between.
Try it out

Three entries on the register all score 4. What might the three of them be?

One score covers three situations a register orders as equals. See which.

What does this bank's own register look like?

The registerThe record of risks an institution has identified, each carrying a rating, an owner and a status. at month 12 carries 46 entries, each rated on the bank's own five by five scale, and the result is 4 red, 12 amber and 30 green. The check: 4 plus 12 plus 30 is 46. As shares that is 8.7 per cent red, 26.1 per cent amber and 65.2 per cent green, and those three rounded figures do sum to 100.0. One honest limitation before anything is read into the shape: this bank's record fixes the colour of each entry and does not fix the score of each entry, so there is no distribution of the 46 across the fourteen scores to show.

The four reds are worth looking at, and not because of the number 4. Every one of the four is already written down somewhere else in this bank's own records. A register that is actually working looks exactly like that. RR1 is sector concentration, and it is also open breach B1. RR2 is the dependence on wholesale funding, and it is also open breach B3. RR3 is the collateral valuation control, and it is also incident I10 and the year's single material weakness. RR4 is the behavioural deposit assumption, and it is also model V1, one of the three models in this bank that have never been validated. A register that agrees with the breach log, the loss log and the model inventory is doing its job; one that disagrees with them is itself the finding.

FORTY SIX ENTRIES ON ONE SCALE, AND WHERE THE FOUR REDS ALREADY LIVE The colour split is the invented bank's own count at month 12. The record fixes no score for any single entry. 4 RED 8.7 per cent 12 AMBER 26.1 per cent 30 GREEN 65.2 per cent RR1 Sector concentration already in the breach log as breach B1, open since month 5 RR2 Dependence on wholesale funding already in the breach log as breach B3, open since month 11 RR3 The collateral valuation control already in the loss log as incident I10, and the year's one material weakness RR4 The behavioural deposit assumption already in the model inventory as model V1, which has never been validated Not one of the four reds is news. The register's contribution is that all four sit on one scale at the same time.
Every one of this bank's four red entries is already recorded somewhere else in its own papers.
Try it out

This bank's register has 46 entries with 4 red. What is notable about those four?

What goes wrong when a register is sorted by score?

Sorting is why a score exists, and sorting is also the moment the information leaves the report. The loss is a design problem and not a mistake anybody made. A committee cannot read 46 entries with equal attention. Members read from the top and stop when the meeting runs out of time, and the sorting was built to support exactly that behaviour. So what rises is anything with a big product, meaning anything rated high on both judgements. Anything rated high on one and low on the other falls, no matter how much of a problem it is. And what becomes invisible is the difference between entries that share a rank.

Think about what that does to the two shapes above. The rare severe event, impact 4 with likelihood 1, sorts at 4 and sits in the lower half of any register. The frequent trivial one, impact 1 with likelihood 4, sorts at exactly the same place. If the committee reads down to the score of 8 and stops, both of them are below the line together, and the only fact that distinguishes them, that one of them is the shape that produced the largest single net loss in this bank's year, never reaches the room. A ranking is trusted and a pile of unsorted entries is not, so a ranking that hides the one thing deciding the response is worse than no ranking at all.

How can the sorting be kept while none of the information is lost?

The fix is so small it is faintly embarrassing, and that is the best possible property for a fix to have. Print the two judgements next to the score. A reported pairShowing impact and likelihood beside the score, which is the cheapest way to keep the sorting and lose none of the information. costs one extra column on a report line and recovers everything the multiplication removed.

Compare the two lines directly. A line reading score 4 tells a reader nothing they can act on. A line reading score 4, impact 4, likelihood 1 tells them it is the rare severe one, and that points at a preventive control or a reserve. The second line still sorts by its first figure exactly as well as the first line does, so the trade between sorting and knowing was never a real trade at all. The trade only looks real if somebody has decided in advance that a report line can carry one number and not three. Nothing about the arithmetic forces that choice, and nothing about a report layout does either.

THE SAME THREE REGISTER LINES, WITH AND WITHOUT THE PAIR BESIDE THE SCORE Both sets sort identically by the score. Only one of them tells the reader what kind of thing each entry is. THE SCORE ON ITS OWN Register entry A score 4 Register entry B score 4 Register entry C score 4 THREE IDENTICAL LINES. NOTHING TO ACT ON. THE SCORE WITH THE PAIR BESIDE IT Entry A score 4 impact 4 likelihood 1 Entry B score 4 impact 1 likelihood 4 Entry C score 4 impact 2 likelihood 2 STILL SORTS ON THE FIRST FIGURE. AND THE KIND IS NOW VISIBLE. One extra column recovers everything the multiplication threw away, and costs the report nothing in sortability.
One extra column on the line recovers the pair and the line still sorts on its score.
Try it out

How can the sorting be kept while none of the information is lost?

What does a committee member actually do with a scored register?

Three habits are worth having, and none of them needs any authority to adopt. The first is to ask, of any entry being discussed, what the pair was. Rating is somebody else's craft and is covered separately, so the question is not a challenge to it. The pair shows whether the conversation should be about prevention or about unit cost. If the answer is not on the paper, that is the finding, and it is a cheap one to fix.

The second is to distrust a comparison between two entries with the same score and to make the meeting say which is which. Two entries at 12 are 3 with 4 and 4 with 3, and those are genuinely different arguments even though the number refuses to distinguish them.

The third is for whoever maintains the record. When a score changes between one meeting and the next, say which of the two judgements moved. A score falling from 12 to 8 could be impact 4 with likelihood 3 becoming impact 4 with likelihood 2, meaning the thing became less probable, or it could be impact 3 with likelihood 4 becoming impact 2 with likelihood 4, meaning the thing became less damaging. The two are opposite stories about the same fall, and a movement column carrying only the product cannot tell them apart. Every score change with no stated cause is a claim nobody has to defend, so an internal auditor reading a register can find real work in the movement column alone. The same discipline serves a lender reading a borrower's own risk record, or anybody reading a supplier's: the score shows where somebody put the entry, and the pair shows what they were worried about.

India

What is named here, and where the binding version lives

No external body prescribes a risk scoring scale. There is no standard five by five, no standard escalation level and no standard colour boundary. Every scale, rating, colour and count here belongs to the invented Vindhya Commercial Bank Limited.

Where a score feeds a report that goes to a board, what an Indian bank must actually compute, report and place before its board comes from the Reserve Bank of India at rbi.org.in. The principles on risk data aggregation and risk reporting that sit behind how a bank assembles such a report were published by the Basel Committee on Banking Supervision at the Bank for International Settlements at bis.org, and what binds in India is the Reserve Bank of India's version and not the international text.

A threshold, ratio, escalation level, colour boundary or effective date that binds is published by the issuing body itself, and the wording on that body's own site is the wording that binds.

Impact and likelihood as judgements, how either one is estimated, and what a five point rating scale means are covered separately and are taken here as given inputs. The matrix as an instrument and the register as a record are covered separately too; the bank's own 46 entries and its four reds are used here as a worked count and derived nowhere. An institution's four ways of treating a risk once it has rated something are covered separately and only named here. Every underlying risk mentioned belongs to whichever subject holds it: the sector concentration to credit, the wholesale funding dependence to liquidity, the collateral valuation control to operational risk, and the behavioural deposit assumption to model risk. How a dashboard is built is covered separately as well.
Risk Management Program Bootcamp — Fin Maverick

Sources

SourceDocumentSite
Reserve Bank of IndiaWhat an Indian bank must actually compute, report and place before its board on risk management arrangementsrbi.org.in
Bank for International SettlementsThe Basel Committee principles on risk data aggregation and risk reporting that sit behind how a report is assembledbis.org
Ministry of Corporate AffairsThe Companies Act duty on a board in respect of the risk management policy it reports on, and the form of that reportmca.gov.in
Frank KnightRisk, Uncertainty and Profit, 1921, where measurable risk is separated from the uncertainty that cannot be measuredHoughton Mifflin

Vindhya Commercial Bank Limited is invented.
Educational material. Not advice on any investment, tax, budget or market position.

Calculator

Other calculators in Risk Reporting, Data and Model Risk

Calculator

Earnings at Risk: What a Rate Move Does to Interest Income

Calculator

Risk Adjusted Return: Return Measured Against Capital Held

← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.