Enterprise Risk Management: One View Across Every Risk Type
Enterprise risk management is the practice of holding every risk type in one view instead of one view for each. At Vindhya Commercial Bank Limited, invented, that view is a seven category taxonomy TX1 to TX7 and a 46 entry register whose 4 reds RR1 to RR4 come from four other records. No single one of those records shows all four. Only the register does.
One risk type at a time is how a bank is organised, and it is not how a bank fails. Credit, market, liquidity and operational risk each keep a record of their own, and each record is complete on its own terms and blind the moment anything past its edge comes into question. The one view is not a bigger record. The one view is a single place where entries from all of them sit on one scale and can be counted together.
What does enterprise risk management do that managing each risk type separately does not?
Start with the word that does the work. Enterprise risk managementHolding every risk type in one view instead of one view for each. is not a harder kind of risk management. Enterprise risk management is ordinary risk management with the word enterprise bolted on the front, and that word means only one thing: the unit of account is the whole institution rather than one desk, one product or one exposure type. Everything that is difficult about it follows from that single change of unit. A credit team knows everything about its borrowers and nothing about the funding that pays for them. A treasury team knows everything about the funding and nothing about the model that decides how long a deposit stays. Neither team is being careless. Each is answering the question it was given.
The bank version is the same shape at a larger scale. Here is the everyday version, and it is worth holding on to. A household runs on one salary, has a home loan, has a parent whose medical bills arrive without warning, and has one car that the salary earner needs to reach work. Each of those is watched separately and each is fine separately. The salary is paid on time. The loan instalment clears. The medical fund has money in it. The car is serviced. Nobody in that household has a single sheet on which the salary, the loan, the parent and the car appear together on one scale, and so nobody has ever noticed that three of the four fail in exactly the same week if the salary earner is ill. The failure is not in any of the four records; it is in the absence of a fifth place where all four sit side by side.
Vindhya Commercial Bank Limited, invented, is that household at Rs 96,000 crore. And it does not lack records. Quite the opposite: at month 12 it keeps nine of them, numbered RC1 to RC9, and every single one is complete, current and reported to somebody. The risk register RC1 carries 46 entries. The limit set RC2 carries twelve limits L1 to L12 with utilisation against each. The breach log RC3 carries six breaches B1 to B6 in the twelve months, three of them still open. The operational loss log RC4 carries thirteen incidents I1 to I13 totalling Rs 43.8 crore net for the year. The near miss log RC5 carries five near misses N1 to N5. The control testing record RC6 carries 214 key controls and 42 findings rated D1 to D4. The issue log RC7 carries 92 open issues aged in five buckets AG1 to AG5. The model inventory RC8 carries 28 registered models against 33 found in use. The indicator dashboard RC9 carries 16 indicators at 9 green, 5 amber and 2 red. Every figure there belongs to the invented bank and to nothing else.
The strip along the bottom of each tile in the drawing above is the whole subject of this guide. Four of the nine records cannot show a single one of the four things this bank has decided are its worst. Not because they are badly kept, but because a limit set records utilisation and a red entry is not a utilisation, and a near miss log records events that did not cost anything and a red entry is not an event. A record can only ever surface the kind of thing it was built to hold, and every one of these nine was built to hold a different kind of thing. A tenth place is needed for exactly that reason, and the tenth place is what enterprise risk management produces.
How does a risk taxonomy make one view possible, and what does this one leave out?
Before entries from nine different records can sit on one scale, somebody has to decide what the categories are. The list of categories is the risk taxonomyThe bank's own list of the risk categories it says it faces., and this bank's has two layers. At the top there are seven level one categoriesThe top layer of that list, which this bank has seven of., numbered TX1 to TX7: TX1 credit risk, TX2 market risk, TX3 liquidity and funding risk, TX4 operational risk, TX5 compliance and conduct risk, TX6 strategic and business risk, and TX7 reputational risk. Underneath them sit 31 sub-categories, split 6, 5, 4, 9, 3, 2 and 2, and 6 + 5 + 4 + 9 + 3 + 2 + 2 = 31. The taxonomy is not a filing convenience: it is the set of buckets into which every entry on the register must fall, so anything the taxonomy has no name for cannot be registered at all.
The split says something before a word of it is read. Operational risk is the category that absorbs everything an institution does rather than everything it trades, so TX4 carries 9 of the 31 sub-categories, more than twice the average of about 4.4. TX6 and TX7 carry 2 each. A bank's taxonomy usually looks like that when the categories with rupee measurements have had the most attention. And model risk, in this bank, sits at level two underneath TX4 rather than as a category of its own. The placement is a choice the bank made and not a law, and it is why the model inventory RC8 is reported to the operational risk committee.
Now the part that a list can never do. A taxonomy is a claim, and the claim is completeness: these seven categories and these 31 sub-categories are everything this institution can be hurt by. A list has no way of testifying about what is not on it, so reading the list confirms nothing about that claim. Reading TX1 to TX7 all afternoon leaves every category looking sensible and brings the reader no closer to knowing whether the set is closed. The only test is to go looking for what is missing, and the only way to do that is to hold the list up against things happening outside it.
At this bank the answer is climate risk. Climate risk appears at neither level, and the board risk management committee noticed in month 8 and recorded it as a gap to close. Nobody had suppressed it. The list had simply been built from the categories the bank already measured. Most lists get built that way, and that is exactly how a list ends up complete on its own terms and incomplete against the world.
Frank Knight, in Risk, Uncertainty and Profit, published in 1921, drew the line this depends on: measurable risk, where the outcomes and something about their odds can be written down, is a different animal from uncertainty, where they cannot. A taxonomy is a machine for turning the second into the first. Every category that is named becomes a thing with a register entry, an impact rating and somebody's name against it. Everything left unnamed stays in Knight's second bucket, and stays there for exactly as long as nobody goes looking. The gap in a taxonomy is not a measurement problem, it is the boundary between the part of the world this institution has agreed to measure and the part it has not.
A taxonomy lists seven risk categories and 31 sub-categories. What is the one thing to check about it that reading the list will never reveal?
How does a register hold every risk type in one place?
The risk registerThe single record where entries from every risk type sit on one scale. is where the categories become countable. At month 12 this bank's register carries 46 entries, and every entry has been rated on the bank's own five by five matrix of impact against likelihood. The result is 4 red, 12 amber and 30 green, and 4 + 12 + 30 = 46, so the reds are 4 over 46, being 8.7 per cent of the register. The register was not built for the 4. All 46 sat on one scale before anybody knew which 4 they were.
One note before the drawing changes how this bank should be read. The register reconciles with the other records because it was rebuilt in month 6. A register that agrees with the breach log, the loss log and the model inventory is the working state and not the normal one, and the usual finding at an institution of this size is a register that quietly disagrees with all three. The habit worth taking from this guide is the habit of checking whether a register handed over was reconciled or merely inherited.
The four reds, and the record each one came from
One fact governs everything that follows. Not one of the four red entriesA register entry in the top band of the bank's own impact and likelihood scale. is new. Every single one of them was already written down somewhere in the bank, by somebody whose job it was, in a record that was current and reported. Nobody was hiding anything, and the register did not discover a thing: it collected four findings that four different records were each holding one piece of.
| Red entry | What it is at month 12 | The record it already sat in |
|---|---|---|
| RR1 | Sector concentration. Infrastructure and power at Rs 7,644 crore against a limit L3 of Rs 7,056 crore, being 108.3 per cent utilisation and an excess of Rs 588 crore | RC3 the breach log, as breach B1, open since month 5 |
| RR2 | Dependence on wholesale funding. 22.6 per cent of total liabilities against a limit L10 of 20.0 per cent, being 112.8 per cent utilisation | RC3 the breach log, as breach B3, open since month 11 |
| RR3 | The collateral valuation control. A feed stale for 11 working days, 340 loans wrongly marked, net loss Rs 1.4 crore, and it touches the valuation of Rs 8,640 crore of secured advances | RC4 the loss log, as incident I10, and RC6 control testing, as the single D4 rated finding |
| RR4 | The behavioural deposit assumption. The model that sets an average life on Rs 36,000 crore of non-maturity deposits, and it has never been validated | RC8 the model inventory, as model V1 |
Read the right-hand column and count the records: RC3, RC4, RC6, RC8. Four records, and the breach log RC3 appears twice because two of the reds are open breaches. RR3 appears in two records at once, and that fact is worth holding on to for two minutes from now. And RR4 is the quietest of the four and the largest in reach: the model that sets an average life on Rs 36,000 crore of non-maturity deposits decides whether this bank's headline interest rate risk reading is a fall of Rs 840 crore in economic value or a rise of Rs 240 crore, and how that computation is built belongs to a different subject entirely. Only this belongs here: a material weaknessThe most serious rating on the bank's own four point finding scale. and an unvalidated model are both red entries on one register, rated on the same two axes, sitting four rows apart.
Sector concentration, wholesale funding, a collateral valuation control and a behavioural deposit assumption are the four reds. Which single record shows all four together?
What appears if the records are read one at a time instead?
The register is one way to get to the four reds. There is an obvious alternative, and it is what most institutions actually do: read the records themselves, one after another, and build the picture up. Reading the records one after another sounds like the same thing done the long way. The two methods are not the same, and the difference is measurable on this bank's own figures. Opening the four records in the order RC3 the breach log, RC4 the loss log, RC6 the control testing record, RC8 the model inventory, and counting the reds visible after each one, gives the picture. The count goes 2, then 3, then 3, then 4, and the flat third step is the part that teaches.
Four risk records are opened one at a time: the breach log, the loss log, control testing, then the model inventory. Before the first is opened, how many of the four red register entries will the breach log alone show?
Each step is a different kind of gain. Opening RC3 the breach log moves the count from nothing to two reds, RR1 and RR2, and that is the biggest single jump on the drawing: one record, half the picture. Opening RC4 the loss log adds RR3, and RR3 arrives wearing the name incident I10, a collateral valuation feed that went stale for 11 working days and cost Rs 1.4 crore net. Three of four, being 75.0 per cent, from two records. So far the method looks efficient.
Then comes RC6, the control testing record. The control testing record is not a small document. RC6 holds 214 key controls and 42 findings rated on the bank's own four point scale D1 to D4, and inside it is the year's single D4, a material weakness. And the count of visible reds stays at three. The material weakness is not a second problem alongside incident I10; it is incident I10, described from the control side instead of the loss side, and it was already counted. A whole record, properly kept and independently produced, added nothing that was not already there, and there is no way to know that in advance without a place where both entries land on top of each other and turn out to be one row.
The breach log and the loss log are open and three reds are visible. The control testing record holds 42 findings including the one material weakness, and it is opened next. How many reds are visible?
Open the records one at a time and watch the red entries light up
One control: how many of the four records are open, from none to all four, in the fixed order RC3 the breach log, RC4 the loss log, RC6 the control testing record, RC8 the model inventory. One consequence: how many of the four red register entries RR1 to RR4 are visible. Every reading is fixed by the invented bank's own records. With no record open the visible count is 0 reds, being 0.0 per cent. With RC3 open the count is 2, being 50.0 per cent. With RC3 and RC4 open the count is 3, being 75.0 per cent. Adding RC6 leaves the count at 3, still 75.0 per cent. Adding RC8 takes it to 4, being 100.0 per cent. The default below is two records open, and that is where most limit-driven reading stops.
With two records open three of the four red entries are visible, being 75.0 per cent, and the one that is not is a model that has never been validated.
What tests whether the one view is real or only a document?
Every institution of any size claims to have enterprise risk management, and most of them have a document saying so. The document is not the test. The test that can actually be run takes an afternoon and works on the register itself: every entry in the top band is taken in turn, the other record it already sits in is named, and the two are checked for agreement on what happened, when, and how big. An entry that cannot be traced back to a record with its own author is not a risk the institution has found; it is a sentence somebody wrote in a register. An entry that traces back but disagrees with its source is worse, because now two documents are in circulation with two versions of one fact.
Run it on this bank and all four trace. RR1 to breach B1 in the breach log, RR2 to breach B3, RR3 to incident I10 in the loss log and to the year's single D4 finding in control testing, RR4 to model V1 in the model inventory. Four of four, and that is the reason to trust the count of 46 as well as the count of 4. Four of four is also the direct result of the register being rebuilt in month 6, so the honest reading is that this bank passes a test many institutions of this size do not.
A risk function reads only the breach log every month, very carefully. How much more careful would it have to be to see the model risk entry?
The reader who has one record, and what it costs
Take the breach log RC3 and read it alone. A limit driven function reports on that record every month. The breach log shows RR1 and RR2, being 2 of the 4 reds, and it is silent on the other two. RR3 is the collateral valuation control that failed for 11 working days with no monitoring control detecting it, touching the valuation of Rs 8,640 crore of secured advances and costing Rs 1.4 crore net as incident I10. RR4 is model V1, the behavioural deposit life assumption on Rs 36,000 crore of non-maturity deposits, and it has never been validated.
Neither of those appears in a breach log at all, because neither of them is a breach. Nothing was crossed. No cap was exceeded. A control stopped working and a model was never checked, and a log built to record limits being crossed has no column that either fact could sit in.
So the cost is not that somebody was careless, and this is the part that is uncomfortable. A function reading RC3 every month with total attention would have arrived at exactly the same two reds. The function did not read half the picture badly. It read a different question completely, and read it well.
How is the risk function different from internal audit?
Risk Management vs Internal Audit: five things that differ at once
The difference confuses almost everybody the first time, and it confuses them for a good reason: both functions look at controls, both write reports about things that went wrong, and both sit outside the business unit taking the exposure. The Institute of Internal Auditors restated its three lines model in 2020, and the vocabulary for telling the two functions apart comes from that model. This bank uses it. The business lends the money and runs the 214 key controls, and that makes it the first line. The risk and compliance functions under Sunanda Ravikumar, the chief risk officer, are the second lineThe risk and compliance functions, which set policy and limits and challenge the business.. Internal audit under Rustom Batliwala is the third lineInternal audit, which checks the first two and reports outside management..
The shortest way to hold the difference is that the risk function builds the instrument and internal audit reads the instrument to see whether it was built properly. The register running through this guide is a second line product. Sunanda Ravikumar's function decided the taxonomy had seven categories, set the five by five matrix, rated the 46 entries and produced the 4 reds. Internal audit did not produce any of that. Internal audit asks whether the taxonomy was complete, whether the 46 entries were rated on the criteria the policy specifies, and whether anybody actually did anything about RR1 through RR4 afterwards.
Which of the two functions designs the limits, and which one checks them?
Now the third row, the one that carries the whole comparison. Both functions are paid by the same institution. Both are staffed by people whose careers are inside it. Intelligence, seniority and method do not separate a third line opinion from a very good second line opinion. The separation is that the people whose work is being judged do not decide what happens to the judgement. At this bank internal audit reports to the audit committee. The committee has four members and every one of them an independent director, and that is the whole mechanism.
Turn it round and the point lands harder. Suppose Rustom Batliwala found that a limit was being measured on the wrong base, and suppose the finding went to the head of the function that set the limit. The finding would then be settled by the people it is about. The finding might be settled honestly. But nobody outside would ever be able to tell the honest settlement from the convenient one, and a report that cannot be told apart from a convenient report carries no information at all. The value of the third line is not that its people are cleverer, it is that its findings survive contact with the people they embarrass.
Internal audit finds that a limit is being measured on the wrong base. Who does that finding go to, and why does the answer matter more than the finding?
One more object belongs here by name rather than by construction. The two functions meet on paper in that object, the assurance mapA grid of who checks what; how one is built is covered separately.: a grid of every process against every line, filled in with who actually checks what. The bank has nine processes PR1 to PR9 and three lines, so 27 cells. Of those, 6 carry assurance from all three lines, 14 from two, 5 from one and 2 from nobody at all, and 6 + 14 + 5 + 2 = 27, so the uncovered cells are 2 over 27, being 7.4 per cent. How such a grid is built and scored is a separate subject and is not taught here.
Read that grid the way a map of a dark room is read: not for the places where somebody has a torch, but for the places where nobody does. The two empty cells at this bank are second line assurance over PR3 collateral management and second line assurance over PR5 trade finance. Incident I10 sits in PR3. Incident I13, the largest net operational loss of the year at Rs 15.4 crore, sits in PR5. Two cells out of twenty seven were covered by nobody, and those two cells produced the year's two most expensive failures. Together those two incidents cost Rs 1.4 crore plus Rs 15.4 crore, being Rs 16.8 crore of the year's Rs 43.8 crore net operational loss, or 38.4 per cent of it out of 7.4 per cent of the grid.
Two of the 27 assurance cells are covered by nobody, and both turned out to sit under the year's two most expensive failures. What does that show about a map of who is checking what?
What does the one view cost to produce?
The arithmetic deserves blunt treatment. The objection is a real one and it gets raised in real committees. To surface 4 red entries this bank rated 46. The other 42 entries, being 91.3 per cent of the register, came out amber or green and produced no action of any kind. Somebody wrote each of the 42. Somebody rated each of them on impact and on likelihood. Somebody reviewed the ratings. And the output of all that work, for those 42, was the word amber or the word green.
The objection dissolves the moment the alternative register is described. A register listing only the things somebody already knew were serious is not a cheaper version of this one, it is a worry list, and a worry list has a fatal property: it can only contain what was already worried about. Red is a position relative to the other 42 and not a property an entry carries on its own, so which four entries are red cannot be known until all 46 are rated on the same two axes. The 30 green entries are not waste. The greens are the comparison that makes red mean something, and they are also the record that says somebody looked at those thirty things this year and formed a view.
There is a second return on the 42 that is easy to miss, and it is the one a chief risk officer will name when asked. Next year, the 46 rows get rated again. Any of the 30 greens that moves to amber is a change. A change costs nothing beyond the rating that was going to happen anyway, and that makes it the cheapest early signal an institution has. A worry list has no stable population to compare against, so it cannot produce that signal.
Forty six register entries produced four that are red. Is a register that is 91.3 per cent not red a waste of effort?
Who actually picks up the one view, and what do they do with it?
Three different people read this register, and they read it for three different things. The three uses together say more about the object than a definition would.
The independent director on the board risk management committee reads it for the count and the movement. She has six meetings a year and a board paper of 38 printed sides each time, and she is not going to re-derive anybody's arithmetic. In the time she has she can ask why 4 are red rather than 2 or 9, ask which of the four were red last time, and ask what changed. RR1 has been red since month 5 and RR2 since month 11, and that difference in age is a question she can ask without any technical preparation at all. The register is the only document in her pack on which a movement means the same thing across credit, funding, controls and models.
The credit analyst at another institution, looking at Vindhya Commercial Bank Limited as a counterparty rather than from inside it, reads it for the shape of the reds. Two of the four are concentrations, one on the asset side and one on the funding side, and concentrations built into the structure of a balance sheet do not run off by themselves the way a trading position does. One is a control that failed. One is a model nobody has checked. The shape of those four is a different profile from four reds that were all trading losses, and it tells the analyst which questions are worth asking on the call.
The mechanism is the same at every scale, so here is the household version. A person with a salary, a home loan, an elderly parent and one car does not need a matrix. The household needs one sheet with all four on it, rated on the same two questions: how bad if it goes wrong, and how likely. The moment those four sit on one sheet, the thing the four have in common becomes visible, and it is usually a single point of failure that no individual line item was ever going to reveal. The bank version costs 46 rows of work. The household version costs an evening. Neither of them discovers anything new. Both of them make what was already known countable in one place.
What does enterprise risk management not decide?
Enterprise risk management is most often oversold at exactly this point, so the limits are worth stating plainly. Enterprise risk management produced a register with four red entries on it. The register did not decide that the sector concentration should be accepted with a plan running to month 18, it did not decide that Manjari Sondhi is the person accountable for it, it did not set the limit that was breached, and it will not decide what happens if RR1 is still red at month 18. The one view is an instrument, and an instrument gives a reading rather than what to do about it.
The one view undertakes to deliver one thing, and that is its whole claim: the reading covers everything the institution said it could be hurt by, on one scale, at one moment, in one place. Whether anybody then acts is a question about decision rights, committees, policies, limits and escalation, and every one of those is a separate subject with its own machinery. The order matters, though: there is no sensible argument about who should decide something until there is a single document on which the something appears.
What is named here, and where the binding version lives
A bank's own taxonomy, matrix and register bind nobody: an institution writes them for itself, and a requirement anybody must meet is a different kind of object. Every figure, rating, category, limit and count belongs to Vindhya Commercial Bank Limited and is its own internal choice, labelled as such throughout.
Where an international standard sits behind something named here, it comes from the Basel Committee on Banking Supervision at the Bank for International Settlements, bis.org. The Committee publishes the standards behind capital, liquidity and the seven operational risk event categories the loss log I1 to I13 uses. A standard is not what binds an Indian bank, so naming only the global standard is the confident and common error. The binding text for an Indian bank, including anything to do with capital, liquidity, large exposures, provisioning and risk management arrangements, comes from the Reserve Bank of India at rbi.org.in.
Where this guide touches control testing and the word material weakness, the reporting duty on internal financial controls sits in the Companies Act, and its text, applicability, exemptions and the form of the report all come from the Ministry of Corporate Affairs at mca.gov.in, with the assurance standard and the guidance note from the Institute of Chartered Accountants of India at icai.org. Section numbers, rule numbers, ratios, thresholds, exemptions and effective dates all move, and the text that binds is the one the issuer has in force on the day.
Sources
| Source | Document | Site |
|---|---|---|
| Reserve Bank of India | What actually binds a bank in India on capital, liquidity, large exposures, provisioning and risk management arrangements | rbi.org.in |
| Bank for International Settlements | The Basel Committee standards behind capital and liquidity, and the seven operational risk event categories used by the loss log | bis.org |
| Ministry of Corporate Affairs | The Companies Act duty on internal financial controls, its applicability and the form of the report | mca.gov.in |
| Institute of Chartered Accountants of India | The assurance standard and guidance note behind reporting on internal financial controls | icai.org |
| Frank Knight | Risk, Uncertainty and Profit, 1921, the separation of measurable risk from unmeasurable uncertainty | Houghton Mifflin, Boston |
| Institute of Internal Auditors | The three lines model, restated in 2020, and the vocabulary of first, second and third line | theiia.org |
Vindhya Commercial Bank Limited, Sunanda Ravikumar, Manjari Sondhi and Rustom Batliwala are invented.
Educational material. Not advice on any investment, tax, budget or market position.
