Risk Assessment: From Identification to a Rated Position
A risk assessment turns something an institution is exposed to into a described, rated entry that a named person is accountable for on a stated date. The procedure runs identification, description, an inherent rating, the controls actually in place, a residual rating, then the owner and the review date. The output is a position on a scale, and the first step set the ceiling on all of it.
Everything in this sequence has been building one machine. The naming structure says what exists and makes a claim that the list is complete. Then come the two measures, size and chance. Then the grid those two measures land on, and the record that holds what landed there. A risk assessment is the procedure that pushes an exposure through all four of them in order and comes out the other end with an entry somebody has to look at again.
The illustration throughout is Vindhya Commercial Bank Limited, an invented bank, holding forty six assessed entries at month 12 rated on its own five by five grid: 4 red, 12 amber and 30 green, being 8.7, 26.1 and 65.2 per cent, and those three shares sum to 100.0. Every rating, band and threshold shown is that bank's own choice rather than a rule written for it by anybody outside. The four risks behind its four reds illustrate a procedure rather than a subject: credit, market, liquidity and operational risk each have their own account elsewhere, and the machine works the same way whichever of them it processes.
What does a risk assessment actually produce?
Ask most people what an assessment produces and a number comes back. High, or twelve, or red. The colour is not wrong so much as it is the smallest part of the truth, and mistaking a rating for the whole output is why so many records are full of ratings nobody can act on. A risk assessmentThe procedure that turns an exposure into a described, rated entry with a named person accountable for it and a date on which it is looked at again. produces four things at once, and a rating without the other three is an opinion with a colour attached.
Take the everyday version first. A household living on one salary knows, if it thinks about the question for ten seconds, that the salary stopping is what would hurt. Saying so out loud is not an assessment. The exercise becomes an assessment when somebody in that household writes down what would cause it, what would happen in the month after, how bad that would be, how likely it seems, what is already standing between them and it such as savings or a second earner, who is responsible for keeping that in place, and when they will sit down and look at the question again. The rating is the only part of that list a stranger can argue with, and it is the part that matters least.
Seven steps, in one order, and the order is not a preference
The procedure runs the same way at a bank as at that kitchen table. Identify what is exposed. Describe it. Rate the size the consequence would have. Rate the chance of the event. Count the controls that are actually there. Record the position left over once those controls are counted. Attach a named owner and a review date. Seven steps, and they run in that order because each one consumes what the step above produced. The size of something that has not been described cannot be rated, and something that has not been found certainly cannot be described.
What does a risk assessment produce?
Where does an assessment start, and why is that the step everybody skips?
An assessment starts with identificationFinding the exposures that actually exist and filing each one against a name, which sets the ceiling on the quality of every later step., the work of finding what is there. Identification is skipped more often than any other step, and it is skipped for a reason that is almost sympathetic: it does not feel like work. Rating something feels like analysis. Describing something feels like writing. Finding things feels like standing in a room asking people what worries them, and it produces no artefact anybody can admire.
Skip it anyway and the whole procedure still runs. That is the trap. A list that is missing a third of what exists can be described beautifully, rated carefully, controlled thoughtfully, owned properly and reviewed on time. Every later step operates on what identification handed it, so a perfect rating procedure applied to an incomplete list produces a perfectly rated incomplete list. Nothing downstream can put back an exposure the first step never found, because nothing downstream is even looking.
Identifying against the taxonomy, so that what is found has somewhere to be filed
Identification is not simply noticing things. Identification is noticing things and then filing each one against a name that already exists on the institution's naming structure. Vindhya Commercial Bank Limited runs seven level one categories, numbered TX1 to TX7, with 31 sub-categories beneath them, split 6 under TX1, 5 under TX2, 4 under TX3, 9 under TX4, 3 under TX5, 2 under TX6 and 2 under TX7, and 6 plus 5 plus 4 plus 9 plus 3 plus 2 plus 2 is 31. The naming structure itself is covered separately. Filing does one thing to identification that matters here: it turns a vague worry into an entry that can be counted.
Filing also does something less comfortable, and the whole procedure turns on it. An exposure that has no category to be filed under does not become a small entry or a badly filed entry; it becomes nothing at all. The person who noticed it has nowhere to put it, the record has no row for it, no rating is produced and no owner is attached. Committee G2 recorded the gap in month 8 as one to close. Climate risk still appears nowhere in this bank's structure at either level, and at month 12 it is 0 of 7 at level one and 0 of 31 at level two. So there is no entry for it on the register of 46, and there could not be one.
Notice how much that one fact costs, and notice that it costs it silently. Nobody at this bank made a decision to leave climate risk unrated. The category was simply not there, so the question was never asked in a form that could produce an answer. A naming structure is a claim that the list is complete, and the only way to test that claim is to go looking for what is not on it. That is a different activity from reviewing what is on it, it takes different people, and almost nobody does it.
Why is identification the step that decides the quality of everything after it?
How is a risk described so that two assessors rate the same thing?
Here is an experiment worth running in any institution. Take one entry off the record, hand the title to two competent people in different rooms, ask each to rate it, and compare. The ratings will differ, often by a lot, and everybody will conclude that rating is subjective. Rating usually is not subjective. The two of them have rated two different objects that happen to share a title.
Take register entry RR3 at Vindhya Commercial Bank Limited, the collateral valuation control. The entry shows up in the loss record as incident I10 and in the control testing as the single material weakness. Written on the record as a title it reads something like collateral valuation risk. One assessor reads that title and pictures a data feed that stops arriving, an operational nuisance somebody notices in a morning. The other reads it and pictures a loan book carried at the wrong value for weeks, and that reaches provisions and reported figures. Their ratings differ because the object differs, and no amount of calibration training fixes a problem that is really a writing problem.
Cause, event, consequence: three clauses that pin the object down
The fix is a sentence with three parts. Cause, event and consequenceThe three part structure of a risk description: what could set it off, what would then happen, and what that would do to the institution. is the standard shape, and it works because each clause closes off one way of reading the title differently. Because the valuation feed can go stale without anybody noticing, loans may be carried at the wrong value for a stretch of days, so provisions and reported figures may be wrong until somebody catches it. A description in three clauses, read twice, cannot be made to picture two different objects, and that is the entire point of writing it.
There is a second reason the three clauses earn their space, and it only shows up later. The cause clause is where controls attach. The event clause is what the likelihood rating is about. The consequence clause is what the impact rating is about. Write the description properly and the next three steps of the procedure already know what they are measuring; write a title instead and all three of them quietly invent their own subject. That is why the description sits at step two and not at step six, where a tidy mind might prefer to put the writing up.
Two assessors give the same register entry very different ratings. What is most likely missing?
What is the Risk Matrix, and how does a described risk reach a cell?
Steps three and four of the procedure produce two ratings, and those two ratings have to land somewhere. The place they land is the risk matrixThe grid of impact against likelihood on which a rated risk lands as a pair of coordinates, one from each axis.. At Vindhya Commercial Bank Limited it is five points on each axis, giving twenty five cells, and the assessment of any one exposure ends as a pair of coordinates on it. A matrix is no more than that: an address system with two axes. The grid is not a decision, it is not a policy, and it does not tell anybody what to do.
The two axes come from two different questions, and that is why they are two axes and not one. The impact axis asks how big the consequence would be if the event happened, and it is rated on the consequence clause of the description. The likelihood axis asks how often the event happens over a stated period, and it is rated on the event clause. Impact and likelihood are each set out under their own names, and neither measure is re-derived here. The joining step is the one held here: two independent ratings meet, and where they meet is the whole of what the assessment produced.
Reaching a cell, and what the cell then means
Run it forward once. An entry has been described. Somebody rates the consequence and gets 4 on the impact axis. Somebody rates the chance of the event and gets 3 on the likelihood axis. Those two numbers pick a row and a column, and the entry now sits at impact 4, likelihood 3. That pair is its position. The pair carries both facts, in an order anybody can read back, and it can be compared to any other entry rated the same way.
Now the part that matters about what the cell means, and it is a limit rather than a power. A cell says where an assessment landed. A cell does not say the entry is acceptable, it does not say the entry is urgent, and it does not say anybody must act. Those are separate judgements made by people with authority, using the position as an input. A grid is a scale and not a container, and that is why this bank can hold 46 entries across 25 cells at an average of 1.84 entries a cell. Several entries can share one address without any of them being the same risk, and the record is what tells them apart.
Why the pair of coordinates travels better than the score made from it
Almost every institution eventually multiplies the two ratings together and reports the product. The habit is understandable: one number sorts, and a pair does not. Multiplying also destroys information, and the destruction is measurable rather than a matter of taste. Twenty five cells produce only fourteen distinct products, being 1, 2, 3, 4, 5, 6, 8, 9, 10, 12, 15, 16, 20 and 25. Eleven of the twenty five cells therefore land on a score that another cell has already taken, and the product cannot say which of them it came from.
Take a score of 12, arising from impact 3 with likelihood 4 and from impact 4 with likelihood 3. Those are different situations. One is a moderate consequence that turns up often; the other is a serious consequence that turns up a little less often. Take a score of 4, arising three ways: impact 1 with likelihood 4, impact 4 with likelihood 1, and impact 2 with likelihood 2. A nuisance that happens constantly, a serious event that almost never happens, and something middling on both counts all report as a four. A reader given only the product cannot get back to the two facts that made it, so report the pair first and the score second, or report the pair alone.
An entry is reported as a matrix score of 12. What would have been more useful to be told?
The two objects get run together constantly, so one boundary is worth marking. The grid is a scale; the record that holds the entries is a document. Comparing the two as objects, and asking what each is for, is set out under the risk register and the risk matrix, and is not re-run here. The grid enters only as what an assessment lands on, at the fifth of the seven steps.
What sits between an inherent and a residual rating?
Steps three and four produced a rating with nothing subtracted. The rating before anything is taken off is the inherent ratingThe rating of a risk before the effect of any control is counted, which is why it is the same for two institutions facing the same exposure.: how bad this would be, and how often it would happen, if nothing at all stood in the way. Then step five counts what actually stands in the way. Step six records what is left, the residual ratingThe rating after the controls actually in place have been counted, which is why it differs between two institutions facing the same exposure..
The everyday version makes the distinction obvious. A shop on a busy street faces the same inherent risk of theft as the shop next door. One of them has a shutter, a camera and a person who counts the till twice a day; the other has none of those. The inherent position is a fact about the street. The residual position is a fact about the shop. Two institutions facing exactly the same exposure should record the same inherent rating and different residual ratings, and if they do not, one of them has confused a fact about the world with a fact about itself.
The distance between the two ratings is a claim, not a measurement
Here is where assessments quietly go wrong. An entry rated at step 5 before controls and step 3 after them has moved two steps, and that movement is not something anybody measured. The movement is an assertion: the institution believes the controls it has listed reduce this by two steps. The assertion can be perfectly reasonable and it can also be completely unfounded, and the record looks identical either way. The gap between an inherent and a residual rating is the institution's claim about its own controls, and the only thing that makes it believable is evidence that those controls actually operated.
Vindhya Commercial Bank Limited has a live instance of exactly that gap, and it is register entry RR3, the collateral valuation control. Whatever residual position that entry carried before month 10, the control it relied on failed for 11 working days and no monitoring control noticed. The failure is incident I10 in the loss record and the single material weakness in the control testing. The controls were listed, they were counted, and one of them was not operating. A residual rating that counted them was therefore describing an institution that did not exist on those days, and nothing in the record itself could have shown that.
An entry moves two steps between its inherent and its residual rating. What is that claim resting on?
How is an assessment tested for whether it found everything?
Now the output. Vindhya Commercial Bank Limited holds 46 assessed entries at month 12, and every one of them went through all seven steps: found and filed against one of the seven level one names, described in three clauses, rated on both axes, weighed against the controls actually in place, recorded at its residual position, and given a named owner with a date. Rated on the bank's own five by five grid they come out like this.
| Rating on the record | Entries | Share of the 46 |
|---|---|---|
| Red | 4 | 8.7 per cent |
| Amber | 12 | 26.1 per cent |
| Green | 30 | 65.2 per cent |
| Total assessed entries | 46 | 100.0 per cent |
The count of reds, ambers and greens is where most treatments stop, and it is where the interesting work starts. A count of reds says nothing about whether the assessment behind it is any good. The one test that does say something, and which almost nobody runs, is to take the four reds and go looking for each of them somewhere else in the same institution. ReconciliationChecking an assessment outward against the institution's other records, to see whether they agree about what is serious. outward is the completeness test, and it is cheap.
| Register red | What the entry is | Where the same object turns up elsewhere |
|---|---|---|
| RR1 | Sector concentration | Breach B1 on limit L3, open since month 5 |
| RR2 | Dependence on wholesale funding | Breach B3 on limit L10, open since month 11 |
| RR3 | The collateral valuation control | Incident I10 in the loss record, and the single material weakness in control testing |
| RR4 | The behavioural deposit assumption | Model V1, one of three in the inventory never validated |
| Four of four | reconcile | each red is an object another record already knows about |
Four of four. A record whose reds are all corroborated by the breach log, the loss record and the model inventory is a working record, and this one is right because it was rebuilt in month 6. Contrast what a broken record looks like: reds that appear nowhere else, and objects that everybody in the institution already treats as serious appearing nowhere on the record. Neither of those is a rating problem. Both are identification problems wearing a rating disguise.
Three records, five objects, and only one of them on both red lists
Then comes the uncomfortable part, and it is worth going slowly because it looks at first like a finding against the bank. Alongside the register, this bank runs a dashboard of 16 key risk indicators of which 9 are green, 5 amber and 2 red, and it runs a set of twelve limits of which three are in live breach. The two reds on the dashboard are the sector concentration behind breach B1 and the depositor concentration behind breach B4. The three live breaches are B1, B3 and B4.
Line the three up. The objects flagged red anywhere in this institution are B1, B3, B4, incident I10 and model V1: five distinct objects. Only breach B1 appears on both red lists, being 1 of 5, or 20.0 per cent agreement. Breach B4 is red on the dashboard and is not one of the register's four reds. Incident I10 and model V1 are red on the register and are on neither of the dashboard's two.
The instinct at this point is to call that a failure of joined-up thinking and ask somebody to make the three lists agree. Resist it. A limit breach says a measured number went over a cap, an indicator says a watched measure crossed a trigger, and an assessment rating says a described risk landed in a particular cell, and those are three different questions with no reason to produce the same answer. Model V1 has never breached anything, because there is no limit on a model. Incident I10 crossed no trigger, because nothing was watching that feed. An institution that forces the three records to agree has not improved any of them; it has thrown away whatever two of them were telling it.
The reconciliation is aimed the other way. The object of the search is not perfect agreement. The ones worth hunting are the objects the rest of the institution plainly treats as serious and that appear nowhere on the record at all, and those are precisely what identification missed. Four out of four reconcile outward here, and that is a good sign. Reconciling outward says nothing whatever about what identification never found.
The register has four reds, the dashboard has two reds and the limit set has three live breaches, and together they name five distinct objects. Is something wrong?
What does a finished assessment look like once it is written down?
Everything so far has been the procedure. A great deal of argument about assessments turns out to be argument about what a row is supposed to contain, so here is the artefact, field by field. Nine fields, and they divide neatly into two groups that behave very differently in practice.
The first five fields are the analysis: what it files under, the three clause description, the inherent rating, the controls relied on, and the residual rating. The last four are the accountability: a named owner, a review date, the agreed action and the date that action is due. The first five are what people enjoy writing and the last four are what makes the row do anything, and that is exactly why the last four are the ones that go missing. A row carrying the first five and none of the last four is a well argued opinion about a size and a chance, and nobody anywhere is obliged to act on it.
What can be said about the risks identification never found?
The record says 46. The 46 is exact and auditable and, on its own, almost meaningless: it is a count out of a total nobody knows. CoverageThe share of what actually exists that identification found. It is unknown by construction, because counting it would require knowing what was missed. is the share identification actually found, and no institution can measure its own coverage from inside its own record. Nothing that went unnoticed can be counted. A coverage nobody can measure sounds like a dead end, and it is not: two useful things can still be done.
The first is to bound it from below. Vindhya Commercial Bank Limited does not have to estimate anything to know its coverage is under 100 per cent: climate risk appears nowhere in its naming structure at either level, its own committee G2 recorded the gap in month 8, and at month 12 it is still 0 of 7 and 0 of 31. There was nowhere to file it, so at least one thing could not have been identified. An institution that has found a single category missing from its own naming structure has proved its coverage is incomplete without estimating a single number.
The second is to size what a given coverage would imply, and that is arithmetic rather than estimation. If a record holds 46 entries and identification found a share of what exists, the implied true population is 46 divided by that share, and the missing count is what is left over. At 92 per cent, 46 over 0.92 is exactly 50, so four entries are missing. At 79.3 per cent it is 58.0 and twelve are missing. At 80 per cent it is 57.5 and 11.5 are missing. At 50 per cent it is 92, and there are as many entries outside the record as inside it.
The record holds 46 entries. Before the control below is touched: if identification found 92 per cent of what exists, how many entries are missing?
Turn the coverage of identification, and watch what it says about the record
The record holds 46 entries, of which 4 are red, 12 amber and 30 green, and those are the invented bank's own. The one thing the control moves is the share of what actually exists that identification found. Nobody knows this bank's coverage and the case does not state one, so the share is set on the dial rather than read off the record. The direction is not hypothetical: climate risk sits nowhere in this bank's naming structure, so its coverage is known to be below 100 per cent without anybody estimating anything.
If identification found 80.0 per cent of what exists, this register of 46 is missing about 11.5 entries, of which perhaps 1.0 would be red.
The failure: auditing the ratings and never auditing the identification
Assessments get reviewed constantly, and the reviews are almost always useful and almost never find what matters. The reason is structural rather than a matter of effort. Everything downstream of identification leaves an artefact. A description can be read and judged. An impact rating can be challenged and argued down. A residual position can be tested against the control evidence sitting beneath it. A review date can be checked for being overdue. All of it is on the record, so all of it gets reviewed.
Identification leaves nothing behind to review, because a risk that was never identified is not on the record at all. There is no row to challenge, no rating to disagree with, no owner to question and no date to find overdue. So every review of an assessment comes back with the same class of finding, being ratings that are arguable and descriptions that could be sharper, and no review ever comes back with the entry that was never created.
Vindhya Commercial Bank Limited has a known instance, and it is not hypothetical. Its own committee G2 recorded the gap in month 8 as one to close. Climate risk still appears nowhere in its naming structure at either level, and at month 12 it is 0 of 7 at level one and 0 of 31 at level two. An entry for it cannot exist on the record, because identifying it would produce something with nowhere to be filed. So the record reads 46 entries, and it is 46 out of a number nobody knows. Nothing in the four reds reconciling perfectly outward says anything at all about that.
The habit that follows is worth more than any of the arithmetic in this guide. The first ten minutes with an assessment are better spent on what is not on it than on what is: what the institution talks about in corridors that has no row, what its own committees have recorded as a gap, and what has no category to be filed under. The review that finds the missing entry is a different activity from the review that improves the existing ones, and only one of them is ever scheduled.
Why does reviewing an assessment reliably fail to find the biggest problem with it?
Where does any of this show up outside a risk function?
All of it, and under other names. A lender reading a borrower's own account of what could go wrong is running exactly this test: not is the list well written, but is anything obviously absent from it, and does the list agree with what the borrower's other records already say. A borrower whose stated worries never mention the one customer that supplies most of the revenue has told the lender something, and it is not about risk management.
An analyst reading a company's principal risks section has the same job and usually does the opposite: reads the section carefully and stops. The section is the output of somebody's identification step. The useful reading is outward: does the list agree with what the notes to the accounts, the borrowing terms and the last three years of surprises already show, and what is conspicuously not on it. A list of risks is only as informative as the reader's willingness to notice what it does not contain.
And for a household it is smaller and identical. Sit down once a year and write what would hurt, in three clauses each, with a name against every line and a date to look again. Most households can produce five or six entries in twenty minutes. The five or six are not the interesting part. The interesting part is the seventh, whatever nobody wanted to write down, and it is the one the whole exercise exists to surface.
What can an assessment not do?
Three things, and every one of them gets asked of assessments regularly. An assessment cannot say what to do. A rated position is an input to a decision, and choosing whether to accept, avoid, reduce or transfer is a separate act by a different person, covered in the sequence on managing risk across an institution. Running the two together turns a rating quietly into a recommendation nobody agreed to make.
An assessment cannot rate what identification did not find, and that is the whole procedure in one sentence. And it cannot convert uncertainty into risk. Frank Knight drew that line in Risk, Uncertainty and Profit in 1921: a risk is something a size and a chance can be put against, while an uncertainty is something that resists both, and the second does not become the first because somebody wrote it in a box on a form. An assessment that puts a confident coordinate pair against something genuinely unknowable has not measured it, it has decorated it.
An assessment can do a great deal, and that is worth saying plainly after all of that. An assessment makes a worry into an object that two people can discuss without arguing about definitions. It records who is accountable while the question is calm rather than after something has happened. It puts a date on the next conversation. And it produces a record that can be tested against every other record in the institution, the only external check any of it has.
Does an assessment say what to do about a risk?
Who decides any of this for a bank in India
The procedure in this guide is jurisdiction free. Identify, describe, rate, count the controls, rate again, own it, review it, and that sequence is the same in any country and in any institution. The obligations are not jurisdiction free: what an institution must assess, record, report or hold capital against differs from country to country. For a bank in India that comes from the Reserve Bank of India at rbi.org.in, and the framework structures an Indian requirement implements originate with the Basel Committee at the Bank for International Settlements at bis.org. Rating scales, banding rules, review frequencies, thresholds and effective dates are set by the supervisor and by each institution's own policy, so two banks in one country can run different scales and both satisfy the rules. Which scale binds a particular bank is therefore a question about that bank, answered in its own policy and in the supervisor's published rules.
What the assessment step covers, and where its neighbours live. The naming structure identification files against is the prerequisite for this guide and is covered separately, so it is used here rather than rebuilt. The record as a document, and the comparison between a record and a scale, are covered separately too, and the grid appears here only as the thing an assessment lands on. Impact and likelihood as measures are covered separately. Deciding what to do about a rated position, being accept, avoid, reduce or transfer, belongs to the sequence on managing risk across an institution. Who approves a rating, who escalates a red, how often an entry must be reviewed and what a policy says about any of it belongs to the governance sequence. How a control is designed, tested and found deficient belongs to the controls sequence, and a control that failed is named here and taken no further. Every risk behind the four reds belongs to a later sequence, and instruments are explained separately.
Sources
| Source | Document | Publisher or site |
|---|---|---|
| Reserve Bank of India | What actually binds a bank in India on risk management arrangements, recording and reporting | rbi.org.in |
| Bank for International Settlements | The Basel Committee framework that Indian risk management requirements implement | bis.org |
| Frank Knight | Risk, Uncertainty and Profit, 1921, where the line between a measurable risk and an unmeasurable uncertainty is drawn | Houghton Mifflin |
Vindhya Commercial Bank Limited is invented.
Educational material. Not advice on any investment, tax, budget or market position.
