Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Risk, Treasury & Financial Control
1Risk Foundations
Risk Appetite, Tolerance, Capacity…The Risk Taxonomy and UniverseRisk Register vs Risk MatrixStress TestingScenario Analysis vs Stress TestingImpact and LikelihoodLikelihoodThe Risk EventRisk Assessment
2Enterprise Risk Management
Enterprise Risk ManagementThe Four Risk TreatmentsRisk CultureRisk MaturityRisk Monitoring
3Risk Governance
Risk GovernanceHow to set a…The Risk PolicyThe Risk OwnerThe Risk Committee and Its CharterThe Risk Limit FrameworkRisk EscalationHow to set a…
4Credit and Counterparty Risk
Collateral AgreementsCollateral vs NettingProbability of DefaultExposureCounterparty ExposureConcentration Risk vs Wrong Way RiskCounterparty Risk vs Credit RiskHow to assess Counterparty ExposureHow to assess Concentration Risk
5Market Risk
Market RiskSensitivity MeasuresThe Hedging PolicyInterest Rate Risk in the Banking BookIRRBB vs Market RiskExpected ShortfallEconomic Value of EquityVaR BacktestingOpen PositionValue at RiskValue at Risk and Expected ShortfallEconomic Value SensitivityFX ExposureValue at Risk vs Expected ShortfallEarnings at Risk vs…FX Transaction Risk vs…How to measure Interest…How to measure Foreign…
6Liquidity Risk
Liquidity Stress TestingLiquidity Gap vs Liquidity BufferMaturity MismatchThe Debt Maturity ProfileFunding ConcentrationSurvival HorizonThe Contingency Funding PlanNet Stable Funding RatioLiquidity Risk vs Funding RiskLiquidity Coverage RatioLiquidity Gap and BufferHow to run a Liquidity Gap Analysis
7Operational Risk
Operational LossThe Loss EventRisk and Control Self AssessmentException ManagementInformation Security as a…Segregation of DutiesIssue ManagementThe Near MissRoot Cause Analysis in RiskThe Fraud TriangleCyber Risk vs Third Party RiskHow to run a…How to assess Third…
8Risk Reporting, Data and Model Risk
Model RiskModel Validation vs BacktestingHow to run Model ValidationData Governance in RiskModel Risk vs Data RiskKey Risk IndicatorsManagement InformationRisk ReportingRisk ScoreEarnings at RiskRisk Adjusted ReturnEarly Warning IndicatorsHow to build a KRI Dashboard
9Treasury
Corporate TreasuryAsset Liability ManagementIntragroup FundingThe Treasury PolicyThe Treasury Management SystemThe Cash ForecastCash Pooling and ConcentrationHow to build a Cash Forecast
10Financial Controls and Assurance
Control AssuranceThe Control LifecycleThe Assurance MapThe Audit FindingIssue RemediationInternal Financial ControlsControl Design vs Control EffectivenessHow to map Internal Financial ControlsHow to test Control…Control DeficiencyMaterial Weakness
11Operational Resilience
Operational ResilienceBusiness Continuity and Disaster RecoveryBusiness Continuity vs Operational…Crisis ManagementDisaster RecoveryIncident Management

Enterprise Risk Management: One View Across Every Risk Type

Enterprise risk management is the practice of holding every risk type in one view instead of one view for each. At Vindhya Commercial Bank Limited, invented, that view is a seven category taxonomy TX1 to TX7 and a 46 entry register whose 4 reds RR1 to RR4 come from four other records. No single one of those records shows all four. Only the register does.

One risk type at a time is how a bank is organised, and it is not how a bank fails. Credit, market, liquidity and operational risk each keep a record of their own, and each record is complete on its own terms and blind the moment anything past its edge comes into question. The one view is not a bigger record. The one view is a single place where entries from all of them sit on one scale and can be counted together.

What does enterprise risk management do that managing each risk type separately does not?

Start with the word that does the work. Enterprise risk managementHolding every risk type in one view instead of one view for each. is not a harder kind of risk management. Enterprise risk management is ordinary risk management with the word enterprise bolted on the front, and that word means only one thing: the unit of account is the whole institution rather than one desk, one product or one exposure type. Everything that is difficult about it follows from that single change of unit. A credit team knows everything about its borrowers and nothing about the funding that pays for them. A treasury team knows everything about the funding and nothing about the model that decides how long a deposit stays. Neither team is being careless. Each is answering the question it was given.

The bank version is the same shape at a larger scale. Here is the everyday version, and it is worth holding on to. A household runs on one salary, has a home loan, has a parent whose medical bills arrive without warning, and has one car that the salary earner needs to reach work. Each of those is watched separately and each is fine separately. The salary is paid on time. The loan instalment clears. The medical fund has money in it. The car is serviced. Nobody in that household has a single sheet on which the salary, the loan, the parent and the car appear together on one scale, and so nobody has ever noticed that three of the four fail in exactly the same week if the salary earner is ill. The failure is not in any of the four records; it is in the absence of a fifth place where all four sit side by side.

Vindhya Commercial Bank Limited, invented, is that household at Rs 96,000 crore. And it does not lack records. Quite the opposite: at month 12 it keeps nine of them, numbered RC1 to RC9, and every single one is complete, current and reported to somebody. The risk register RC1 carries 46 entries. The limit set RC2 carries twelve limits L1 to L12 with utilisation against each. The breach log RC3 carries six breaches B1 to B6 in the twelve months, three of them still open. The operational loss log RC4 carries thirteen incidents I1 to I13 totalling Rs 43.8 crore net for the year. The near miss log RC5 carries five near misses N1 to N5. The control testing record RC6 carries 214 key controls and 42 findings rated D1 to D4. The issue log RC7 carries 92 open issues aged in five buckets AG1 to AG5. The model inventory RC8 carries 28 registered models against 33 found in use. The indicator dashboard RC9 carries 16 indicators at 9 green, 5 amber and 2 red. Every figure there belongs to the invented bank and to nothing else.

NINE SEPARATE RECORDS OF RISK, AND EVERY ONE OF THEM ALREADY EXISTS The strip on each tile says how many of the four red register entries RR1 to RR4 that record on its own can show. RC1 the risk register 46 entries: 4 red, 12 amber, 30 green SHOWS ALL 4 RED ENTRIES IN ONE STEP RC2 the limit set L1 to L12 with utilisation at month 12 SHOWS 0 OF THE 4 RED ENTRIES RC3 the breach log B1 to B6, and three of them still open SHOWS 2 OF THE 4 RED ENTRIES RC4 the operational loss log I1 to I13, net Rs 43.8 crore in the year SHOWS 1 OF THE 4 RED ENTRIES RC5 the near miss log N1 to N5, no loss booked against any SHOWS 0 OF THE 4 RED ENTRIES RC6 the control testing record 214 key controls, 42 findings D1 to D4 SHOWS 1 OF THE 4 RED ENTRIES RC7 the issue log 92 open issues, aged AG1 to AG5 SHOWS 0 OF THE 4 RED ENTRIES RC8 the model inventory 28 registered against 33 found in use SHOWS 1 OF THE 4 RED ENTRIES RC9 the indicator dashboard 16 indicators: 9 green, 5 amber, 2 red SHOWS 0 OF THE 4 RED ENTRIES
Nine complete records of risk already exist inside the invented bank, and the strip on each tile counts how many of the four red register entries that record alone can ever show: four for the register, two for the breach log, one each for the loss log, control testing and the model inventory, and none at all for the other four.

The strip along the bottom of each tile in the drawing above is the whole subject of this guide. Four of the nine records cannot show a single one of the four things this bank has decided are its worst. Not because they are badly kept, but because a limit set records utilisation and a red entry is not a utilisation, and a near miss log records events that did not cost anything and a red entry is not an event. A record can only ever surface the kind of thing it was built to hold, and every one of these nine was built to hold a different kind of thing. A tenth place is needed for exactly that reason, and the tenth place is what enterprise risk management produces.

Derivatives Foundation Bootcamp — Fin Maverick Tax Aware Portfolio Decisions — free micro-course from Fin Maverick

How does a risk taxonomy make one view possible, and what does this one leave out?

Before entries from nine different records can sit on one scale, somebody has to decide what the categories are. The list of categories is the risk taxonomyThe bank's own list of the risk categories it says it faces., and this bank's has two layers. At the top there are seven level one categoriesThe top layer of that list, which this bank has seven of., numbered TX1 to TX7: TX1 credit risk, TX2 market risk, TX3 liquidity and funding risk, TX4 operational risk, TX5 compliance and conduct risk, TX6 strategic and business risk, and TX7 reputational risk. Underneath them sit 31 sub-categories, split 6, 5, 4, 9, 3, 2 and 2, and 6 + 5 + 4 + 9 + 3 + 2 + 2 = 31. The taxonomy is not a filing convenience: it is the set of buckets into which every entry on the register must fall, so anything the taxonomy has no name for cannot be registered at all.

The split says something before a word of it is read. Operational risk is the category that absorbs everything an institution does rather than everything it trades, so TX4 carries 9 of the 31 sub-categories, more than twice the average of about 4.4. TX6 and TX7 carry 2 each. A bank's taxonomy usually looks like that when the categories with rupee measurements have had the most attention. And model risk, in this bank, sits at level two underneath TX4 rather than as a category of its own. The placement is a choice the bank made and not a law, and it is why the model inventory RC8 is reported to the operational risk committee.

SEVEN LEVEL ONE CATEGORIES, THIRTY ONE AT LEVEL TWO, AND ONE THING ON NEITHER LEVEL TX1 Credit 6 TX2 Market 5 TX3 Liquidity and funding 4 TX4 Operational 9 TX5 Compliance and conduct 3 TX6 Strategic and business 2 TX7 Reputational 2 Sub-categories at level two: 6 + 5 + 4 + 9 + 3 + 2 + 2 = 31, and operational risk TX4 carries nine of them on its own. CLIMATE RISK: NOT AT LEVEL ONE, NOT AT LEVEL TWO, NOT ANYWHERE ON THIS LIST Noted by the board risk management committee in month 8 as a gap to close. Reading the list would never have shown it.
Seven level one categories TX1 to TX7 carry 31 sub-categories at 6, 5, 4, 9, 3, 2 and 2, and climate risk appears on neither level of the invented bank's own list, which is a gap found by looking for what is absent rather than by reading what is present.

Now the part that a list can never do. A taxonomy is a claim, and the claim is completeness: these seven categories and these 31 sub-categories are everything this institution can be hurt by. A list has no way of testifying about what is not on it, so reading the list confirms nothing about that claim. Reading TX1 to TX7 all afternoon leaves every category looking sensible and brings the reader no closer to knowing whether the set is closed. The only test is to go looking for what is missing, and the only way to do that is to hold the list up against things happening outside it.

At this bank the answer is climate risk. Climate risk appears at neither level, and the board risk management committee noticed in month 8 and recorded it as a gap to close. Nobody had suppressed it. The list had simply been built from the categories the bank already measured. Most lists get built that way, and that is exactly how a list ends up complete on its own terms and incomplete against the world.

Frank Knight, in Risk, Uncertainty and Profit, published in 1921, drew the line this depends on: measurable risk, where the outcomes and something about their odds can be written down, is a different animal from uncertainty, where they cannot. A taxonomy is a machine for turning the second into the first. Every category that is named becomes a thing with a register entry, an impact rating and somebody's name against it. Everything left unnamed stays in Knight's second bucket, and stays there for exactly as long as nobody goes looking. The gap in a taxonomy is not a measurement problem, it is the boundary between the part of the world this institution has agreed to measure and the part it has not.

Try it out

A taxonomy lists seven risk categories and 31 sub-categories. What is the one thing to check about it that reading the list will never reveal?

Value at Risk and What It Hides teaches you to compute value at risk three ways, interpret the figure, and say precisely what it refuses to describe.

How does a register hold every risk type in one place?

The risk registerThe single record where entries from every risk type sit on one scale. is where the categories become countable. At month 12 this bank's register carries 46 entries, and every entry has been rated on the bank's own five by five matrix of impact against likelihood. The result is 4 red, 12 amber and 30 green, and 4 + 12 + 30 = 46, so the reds are 4 over 46, being 8.7 per cent of the register. The register was not built for the 4. All 46 sat on one scale before anybody knew which 4 they were.

One note before the drawing changes how this bank should be read. The register reconciles with the other records because it was rebuilt in month 6. A register that agrees with the breach log, the loss log and the model inventory is the working state and not the normal one, and the usual finding at an institution of this size is a register that quietly disagrees with all three. The habit worth taking from this guide is the habit of checking whether a register handed over was reconciled or merely inherited.

ONE PLANE, AND ENTRIES FROM ALL SEVEN CATEGORIES TX1 TO TX7 LAND ON IT A credit entry and an operational entry become comparable only once both carry a rating on the same two axes. 1 2 3 4 5 5 4 3 2 1 IMPACT, THE BANK'S OWN FIVE POINT SCALE LIKELIHOOD WHAT SITS ON THE PLANE AT MONTH 12 4 red, and these are RR1 to RR4 12 amber 30 green 4 + 12 + 30 = 46 ENTRIES The reds are 4 over 46, being 8.7 per cent. The band shape is the invented bank's own. No entry is drawn in a cell here, because this case fixes the counts in each band and not the cell any single entry sits in, and a marker in a cell would assert something the bank never stated.
Forty six entries plotted on one five by five matrix give 4 red, 12 amber and 30 green, and the 4 reds are 8.7 per cent of the register, which is only knowable because all 46 were rated on the same two axes first.

The four reds, and the record each one came from

One fact governs everything that follows. Not one of the four red entriesA register entry in the top band of the bank's own impact and likelihood scale. is new. Every single one of them was already written down somewhere in the bank, by somebody whose job it was, in a record that was current and reported. Nobody was hiding anything, and the register did not discover a thing: it collected four findings that four different records were each holding one piece of.

Red entryWhat it is at month 12The record it already sat in
RR1Sector concentration. Infrastructure and power at Rs 7,644 crore against a limit L3 of Rs 7,056 crore, being 108.3 per cent utilisation and an excess of Rs 588 croreRC3 the breach log, as breach B1, open since month 5
RR2Dependence on wholesale funding. 22.6 per cent of total liabilities against a limit L10 of 20.0 per cent, being 112.8 per cent utilisationRC3 the breach log, as breach B3, open since month 11
RR3The collateral valuation control. A feed stale for 11 working days, 340 loans wrongly marked, net loss Rs 1.4 crore, and it touches the valuation of Rs 8,640 crore of secured advancesRC4 the loss log, as incident I10, and RC6 control testing, as the single D4 rated finding
RR4The behavioural deposit assumption. The model that sets an average life on Rs 36,000 crore of non-maturity deposits, and it has never been validatedRC8 the model inventory, as model V1

Read the right-hand column and count the records: RC3, RC4, RC6, RC8. Four records, and the breach log RC3 appears twice because two of the reds are open breaches. RR3 appears in two records at once, and that fact is worth holding on to for two minutes from now. And RR4 is the quietest of the four and the largest in reach: the model that sets an average life on Rs 36,000 crore of non-maturity deposits decides whether this bank's headline interest rate risk reading is a fall of Rs 840 crore in economic value or a rise of Rs 240 crore, and how that computation is built belongs to a different subject entirely. Only this belongs here: a material weaknessThe most serious rating on the bank's own four point finding scale. and an unvalidated model are both red entries on one register, rated on the same two axes, sitting four rows apart.

Try it out

Sector concentration, wholesale funding, a collateral valuation control and a behavioural deposit assumption are the four reds. Which single record shows all four together?

What appears if the records are read one at a time instead?

The register is one way to get to the four reds. There is an obvious alternative, and it is what most institutions actually do: read the records themselves, one after another, and build the picture up. Reading the records one after another sounds like the same thing done the long way. The two methods are not the same, and the difference is measurable on this bank's own figures. Opening the four records in the order RC3 the breach log, RC4 the loss log, RC6 the control testing record, RC8 the model inventory, and counting the reds visible after each one, gives the picture. The count goes 2, then 3, then 3, then 4, and the flat third step is the part that teaches.

Try it out

Four risk records are opened one at a time: the breach log, the loss log, control testing, then the model inventory. Before the first is opened, how many of the four red register entries will the breach log alone show?

READING THE FOUR RECORDS ONE AT A TIME, IN A FIXED ORDER Each bar is the running count of red register entries visible once that record has been opened. 2 reds RC3 THE BREACH LOG 50.0 per cent 3 reds RC4 THE LOSS LOG 75.0 per cent 3 reds RC6 CONTROL TESTING 75.0 per cent 4 reds RC8 MODEL INVENTORY 100.0 per cent 4 reds RC1 THE REGISTER 100.0 per cent IN ONE STEP ONE MORE RECORD, AND THE COUNT DOES NOT MOVE the material weakness and incident I10 are one event
Read the breach log and 2 reds are visible; add the loss log and it is 3; add control testing and it is still 3; add the model inventory and it is 4, while the register reaches all four in a single step.

Each step is a different kind of gain. Opening RC3 the breach log moves the count from nothing to two reds, RR1 and RR2, and that is the biggest single jump on the drawing: one record, half the picture. Opening RC4 the loss log adds RR3, and RR3 arrives wearing the name incident I10, a collateral valuation feed that went stale for 11 working days and cost Rs 1.4 crore net. Three of four, being 75.0 per cent, from two records. So far the method looks efficient.

Then comes RC6, the control testing record. The control testing record is not a small document. RC6 holds 214 key controls and 42 findings rated on the bank's own four point scale D1 to D4, and inside it is the year's single D4, a material weakness. And the count of visible reds stays at three. The material weakness is not a second problem alongside incident I10; it is incident I10, described from the control side instead of the loss side, and it was already counted. A whole record, properly kept and independently produced, added nothing that was not already there, and there is no way to know that in advance without a place where both entries land on top of each other and turn out to be one row.

ONE EVENT: THE COLLATERAL VALUATION FEED WAS STALE FOR 11 WORKING DAYS 340 loans wrongly marked, no customer lost money, net loss Rs 1.4 crore RC4 THE OPERATIONAL LOSS LOG recorded as incident I10 one of thirteen incidents I1 to I13 net Rs 1.4 crore of the year's Rs 43.8 crore RC6 THE CONTROL TESTING RECORD recorded as the single D4 finding one of 42 findings on 214 key controls the one material weakness of the year RR3 ON THE REGISTER RC1 one entry, rated red, counted once Two records, two correct entries, and adding the second one to the first says nothing new about the bank.
Incident I10 and the invented bank's one material weakness are the same failure counted in two records and carried as one entry, RR3, on the register, which is why opening a third record moved the count of visible reds by nothing at all.
Try it out

The breach log and the loss log are open and three reds are visible. The control testing record holds 42 findings including the one material weakness, and it is opened next. How many reds are visible?

Play with it

Open the records one at a time and watch the red entries light up

One control: how many of the four records are open, from none to all four, in the fixed order RC3 the breach log, RC4 the loss log, RC6 the control testing record, RC8 the model inventory. One consequence: how many of the four red register entries RR1 to RR4 are visible. Every reading is fixed by the invented bank's own records. With no record open the visible count is 0 reds, being 0.0 per cent. With RC3 open the count is 2, being 50.0 per cent. With RC3 and RC4 open the count is 3, being 75.0 per cent. Adding RC6 leaves the count at 3, still 75.0 per cent. Adding RC8 takes it to 4, being 100.0 per cent. The default below is two records open, and that is where most limit-driven reading stops.

NO RECORD OPEN2 RECORDS OPENALL FOUR OPEN
THE FOUR RECORDS, OPENED IN A FIXED ORDER FROM LEFT TO RIGHT RC3 the breach log OPENED RC4 the loss log OPENED RC6 control testing NOT OPENED RC8 the model inventory NOT OPENED THE FOUR RED REGISTER ENTRIES RR1 TO RR4 RR1 sector concentration VISIBLE RR2 dependence on wholesale funding VISIBLE RR3 the collateral valuation control VISIBLE RR4 the behavioural deposit assumption NOT VISIBLE RED ENTRIES VISIBLE BY READING RECORDS ONE AT A TIME 75.0 per cent RC1 THE REGISTER, WHICH SHOWS ALL FOUR IN ONE STEP 100.0 per cent The reading order is fixed and stated. Every record here is the invented bank's own. The four reds are that bank's own rating and not any regulatory classification.
Records open
2 of 4
Red entries visible
3 of 4
Share of the reds
75.0 per cent

With two records open three of the four red entries are visible, being 75.0 per cent, and the one that is not is a model that has never been validated.

Educational illustration. Invented figures throughout. Every record, rating and count shown belongs to Vindhya Commercial Bank Limited and to nothing else. The reading order RC3, RC4, RC6, RC8 is fixed for this illustration; a different order changes which step is flat but never changes the total of four. The red rating is the bank's own five by five matrix and is not a regulatory classification of anything.

What tests whether the one view is real or only a document?

Every institution of any size claims to have enterprise risk management, and most of them have a document saying so. The document is not the test. The test that can actually be run takes an afternoon and works on the register itself: every entry in the top band is taken in turn, the other record it already sits in is named, and the two are checked for agreement on what happened, when, and how big. An entry that cannot be traced back to a record with its own author is not a risk the institution has found; it is a sentence somebody wrote in a register. An entry that traces back but disagrees with its source is worse, because now two documents are in circulation with two versions of one fact.

Run it on this bank and all four trace. RR1 to breach B1 in the breach log, RR2 to breach B3, RR3 to incident I10 in the loss log and to the year's single D4 finding in control testing, RR4 to model V1 in the model inventory. Four of four, and that is the reason to trust the count of 46 as well as the count of 4. Four of four is also the direct result of the register being rebuilt in month 6, so the honest reading is that this bank passes a test many institutions of this size do not.

Try it out

A risk function reads only the breach log every month, very carefully. How much more careful would it have to be to see the model risk entry?

The reader who has one record, and what it costs

Take the breach log RC3 and read it alone. A limit driven function reports on that record every month. The breach log shows RR1 and RR2, being 2 of the 4 reds, and it is silent on the other two. RR3 is the collateral valuation control that failed for 11 working days with no monitoring control detecting it, touching the valuation of Rs 8,640 crore of secured advances and costing Rs 1.4 crore net as incident I10. RR4 is model V1, the behavioural deposit life assumption on Rs 36,000 crore of non-maturity deposits, and it has never been validated.

Neither of those appears in a breach log at all, because neither of them is a breach. Nothing was crossed. No cap was exceeded. A control stopped working and a model was never checked, and a log built to record limits being crossed has no column that either fact could sit in.

So the cost is not that somebody was careless, and this is the part that is uncomfortable. A function reading RC3 every month with total attention would have arrived at exactly the same two reds. The function did not read half the picture badly. It read a different question completely, and read it well.

RC3 THE BREACH LOG, READ ALONE AND READ CAREFULLY OUTSIDE IT: NOT A BREACH OF ANYTHING RR1 sector concentration breach B1, open since month 5 VISIBLE HERE RR2 dependence on wholesale funding breach B3, open since month 11 VISIBLE HERE RR3 the collateral valuation control a control that stopped working NO COLUMN IT COULD SIT IN RR4 the behavioural deposit assumption a model that was never validated NO COLUMN IT COULD SIT IN RC3 shows RR1 and RR2, being 2 of the 4 reds, which is 50.0 per cent of them. Nothing was crossed in either of the two on the right, so no reading of a breach log, however careful, arrives at them.
The breach log shows RR1 and RR2 and can never show RR3 or RR4, because neither of those is a breach, and that is a property of the record rather than a failure of the person reading it.
Breaking Into Quants Bootcamp — Fin Maverick

How is the risk function different from internal audit?

Risk Management vs Internal Audit: five things that differ at once

The difference confuses almost everybody the first time, and it confuses them for a good reason: both functions look at controls, both write reports about things that went wrong, and both sit outside the business unit taking the exposure. The Institute of Internal Auditors restated its three lines model in 2020, and the vocabulary for telling the two functions apart comes from that model. This bank uses it. The business lends the money and runs the 214 key controls, and that makes it the first line. The risk and compliance functions under Sunanda Ravikumar, the chief risk officer, are the second lineThe risk and compliance functions, which set policy and limits and challenge the business.. Internal audit under Rustom Batliwala is the third lineInternal audit, which checks the first two and reports outside management..

The shortest way to hold the difference is that the risk function builds the instrument and internal audit reads the instrument to see whether it was built properly. The register running through this guide is a second line product. Sunanda Ravikumar's function decided the taxonomy had seven categories, set the five by five matrix, rated the 46 entries and produced the 4 reds. Internal audit did not produce any of that. Internal audit asks whether the taxonomy was complete, whether the 46 entries were rated on the criteria the policy specifies, and whether anybody actually did anything about RR1 through RR4 afterwards.

ON THIS THE RISK FUNCTION, SECOND LINE INTERNAL AUDIT, THIRD LINE WHAT IT DOES designs the limits, the policies and the register, and challenges the business checks that those were designed properly and that they actually operated WHERE IT SITS inside management, as the second line outside the management chain, third line WHO IT ANSWERS TO the chief risk officer, and through her into executive management the audit committee, which is made of independent directors WHAT IT PRODUCES a limit, a register, a view of the whole a finding with a cause, an owner and a date WHEN IT ACTS before and during the exposure after it, on a plan of its own choosing The highlighted row is the one that makes the other four worth anything. An opinion on an employer's controls is worth what its reporting line makes it worth.
The risk function designs the limits and sits inside management, while internal audit checks them and reports to a body outside management, and that reporting line is what makes its opinion worth reading at all.
Try it out

Which of the two functions designs the limits, and which one checks them?

Now the third row, the one that carries the whole comparison. Both functions are paid by the same institution. Both are staffed by people whose careers are inside it. Intelligence, seniority and method do not separate a third line opinion from a very good second line opinion. The separation is that the people whose work is being judged do not decide what happens to the judgement. At this bank internal audit reports to the audit committee. The committee has four members and every one of them an independent director, and that is the whole mechanism.

Turn it round and the point lands harder. Suppose Rustom Batliwala found that a limit was being measured on the wrong base, and suppose the finding went to the head of the function that set the limit. The finding would then be settled by the people it is about. The finding might be settled honestly. But nobody outside would ever be able to tell the honest settlement from the convenient one, and a report that cannot be told apart from a convenient report carries no information at all. The value of the third line is not that its people are cleverer, it is that its findings survive contact with the people they embarrass.

Try it out

Internal audit finds that a limit is being measured on the wrong base. Who does that finding go to, and why does the answer matter more than the finding?

One more object belongs here by name rather than by construction. The two functions meet on paper in that object, the assurance mapA grid of who checks what; how one is built is covered separately.: a grid of every process against every line, filled in with who actually checks what. The bank has nine processes PR1 to PR9 and three lines, so 27 cells. Of those, 6 carry assurance from all three lines, 14 from two, 5 from one and 2 from nobody at all, and 6 + 14 + 5 + 2 = 27, so the uncovered cells are 2 over 27, being 7.4 per cent. How such a grid is built and scored is a separate subject and is not taught here.

NINE PROCESSES, THREE LINES, TWENTY SEVEN CELLS, AND TWO OF THEM EMPTY PR1 PR2 PR3 PR4 PR5 PR6 PR7 PR8 PR9 FIRST LINE the business SECOND LINE risk and compliance 1 2 THIRD LINE internal audit ALL THREE LINES 6 TWO LINES 14 ONE LINE 5 NOBODY AT ALL 2 1 Second line assurance over PR3 collateral management. Incident I10, the year's one material weakness, happened here. 2 Second line assurance over PR5 trade finance. Incident I13, the year's largest net loss at Rs 15.4 crore, happened here. The two outlined cells are the only ones this case names. The other twenty five are drawn plain,because the counts above are fixed and which cell carries how many lines is not.
Twenty seven cells across nine processes and three lines carry assurance from all three in 6 cases, from two in 14, from one in 5 and from nobody in 2, and the two empty cells sat over the year's two most expensive failures.

Read that grid the way a map of a dark room is read: not for the places where somebody has a torch, but for the places where nobody does. The two empty cells at this bank are second line assurance over PR3 collateral management and second line assurance over PR5 trade finance. Incident I10 sits in PR3. Incident I13, the largest net operational loss of the year at Rs 15.4 crore, sits in PR5. Two cells out of twenty seven were covered by nobody, and those two cells produced the year's two most expensive failures. Together those two incidents cost Rs 1.4 crore plus Rs 15.4 crore, being Rs 16.8 crore of the year's Rs 43.8 crore net operational loss, or 38.4 per cent of it out of 7.4 per cent of the grid.

Try it out

Two of the 27 assurance cells are covered by nobody, and both turned out to sit under the year's two most expensive failures. What does that show about a map of who is checking what?

Risk Management Program Bootcamp — Fin Maverick

What does the one view cost to produce?

The arithmetic deserves blunt treatment. The objection is a real one and it gets raised in real committees. To surface 4 red entries this bank rated 46. The other 42 entries, being 91.3 per cent of the register, came out amber or green and produced no action of any kind. Somebody wrote each of the 42. Somebody rated each of them on impact and on likelihood. Somebody reviewed the ratings. And the output of all that work, for those 42, was the word amber or the word green.

The objection dissolves the moment the alternative register is described. A register listing only the things somebody already knew were serious is not a cheaper version of this one, it is a worry list, and a worry list has a fatal property: it can only contain what was already worried about. Red is a position relative to the other 42 and not a property an entry carries on its own, so which four entries are red cannot be known until all 46 are rated on the same two axes. The 30 green entries are not waste. The greens are the comparison that makes red mean something, and they are also the record that says somebody looked at those thirty things this year and formed a view.

There is a second return on the 42 that is easy to miss, and it is the one a chief risk officer will name when asked. Next year, the 46 rows get rated again. Any of the 30 greens that moves to amber is a change. A change costs nothing beyond the rating that was going to happen anyway, and that makes it the cheapest early signal an institution has. A worry list has no stable population to compare against, so it cannot produce that signal.

Try it out

Forty six register entries produced four that are red. Is a register that is 91.3 per cent not red a waste of effort?

Who actually picks up the one view, and what do they do with it?

Three different people read this register, and they read it for three different things. The three uses together say more about the object than a definition would.

The independent director on the board risk management committee reads it for the count and the movement. She has six meetings a year and a board paper of 38 printed sides each time, and she is not going to re-derive anybody's arithmetic. In the time she has she can ask why 4 are red rather than 2 or 9, ask which of the four were red last time, and ask what changed. RR1 has been red since month 5 and RR2 since month 11, and that difference in age is a question she can ask without any technical preparation at all. The register is the only document in her pack on which a movement means the same thing across credit, funding, controls and models.

The credit analyst at another institution, looking at Vindhya Commercial Bank Limited as a counterparty rather than from inside it, reads it for the shape of the reds. Two of the four are concentrations, one on the asset side and one on the funding side, and concentrations built into the structure of a balance sheet do not run off by themselves the way a trading position does. One is a control that failed. One is a model nobody has checked. The shape of those four is a different profile from four reds that were all trading losses, and it tells the analyst which questions are worth asking on the call.

The mechanism is the same at every scale, so here is the household version. A person with a salary, a home loan, an elderly parent and one car does not need a matrix. The household needs one sheet with all four on it, rated on the same two questions: how bad if it goes wrong, and how likely. The moment those four sit on one sheet, the thing the four have in common becomes visible, and it is usually a single point of failure that no individual line item was ever going to reveal. The bank version costs 46 rows of work. The household version costs an evening. Neither of them discovers anything new. Both of them make what was already known countable in one place.

Financial Analyst Program Bootcamp — Fin Maverick

What does enterprise risk management not decide?

Enterprise risk management is most often oversold at exactly this point, so the limits are worth stating plainly. Enterprise risk management produced a register with four red entries on it. The register did not decide that the sector concentration should be accepted with a plan running to month 18, it did not decide that Manjari Sondhi is the person accountable for it, it did not set the limit that was breached, and it will not decide what happens if RR1 is still red at month 18. The one view is an instrument, and an instrument gives a reading rather than what to do about it.

The one view undertakes to deliver one thing, and that is its whole claim: the reading covers everything the institution said it could be hurt by, on one scale, at one moment, in one place. Whether anybody then acts is a question about decision rights, committees, policies, limits and escalation, and every one of those is a separate subject with its own machinery. The order matters, though: there is no sensible argument about who should decide something until there is a single document on which the something appears.

India

What is named here, and where the binding version lives

A bank's own taxonomy, matrix and register bind nobody: an institution writes them for itself, and a requirement anybody must meet is a different kind of object. Every figure, rating, category, limit and count belongs to Vindhya Commercial Bank Limited and is its own internal choice, labelled as such throughout.

Where an international standard sits behind something named here, it comes from the Basel Committee on Banking Supervision at the Bank for International Settlements, bis.org. The Committee publishes the standards behind capital, liquidity and the seven operational risk event categories the loss log I1 to I13 uses. A standard is not what binds an Indian bank, so naming only the global standard is the confident and common error. The binding text for an Indian bank, including anything to do with capital, liquidity, large exposures, provisioning and risk management arrangements, comes from the Reserve Bank of India at rbi.org.in.

Where this guide touches control testing and the word material weakness, the reporting duty on internal financial controls sits in the Companies Act, and its text, applicability, exemptions and the form of the report all come from the Ministry of Corporate Affairs at mca.gov.in, with the assurance standard and the guidance note from the Institute of Chartered Accountants of India at icai.org. Section numbers, rule numbers, ratios, thresholds, exemptions and effective dates all move, and the text that binds is the one the issuer has in force on the day.

Who approves a risk decision, which body sees which paper, how a risk policy is written, how a limit framework cascades from an appetite statement, and what happens when a limit is crossed are all covered separately, and what enterprise risk management is comes before who does it. A taxonomy, a register and a five by five matrix are each settled separately as objects, and the bank's own are used here without re-deriving them. Credit, market, liquidity and operational risk each get their own treatment elsewhere. The construction of the assurance map is covered separately, as are how an internal audit is planned and run and how the four ways of treating a risk are chosen between.

Sources

SourceDocumentSite
Reserve Bank of IndiaWhat actually binds a bank in India on capital, liquidity, large exposures, provisioning and risk management arrangementsrbi.org.in
Bank for International SettlementsThe Basel Committee standards behind capital and liquidity, and the seven operational risk event categories used by the loss logbis.org
Ministry of Corporate AffairsThe Companies Act duty on internal financial controls, its applicability and the form of the reportmca.gov.in
Institute of Chartered Accountants of IndiaThe assurance standard and guidance note behind reporting on internal financial controlsicai.org
Frank KnightRisk, Uncertainty and Profit, 1921, the separation of measurable risk from unmeasurable uncertaintyHoughton Mifflin, Boston
Institute of Internal AuditorsThe three lines model, restated in 2020, and the vocabulary of first, second and third linetheiia.org

Vindhya Commercial Bank Limited, Sunanda Ravikumar, Manjari Sondhi and Rustom Batliwala are invented.
Educational material. Not advice on any investment, tax, budget or market position.

Covered in this topic

Subtopics

Risk Management vs Internal Audit
Next →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.