Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Risk Management Program · CoreTrack
1Risk, Treasury & Financial Control
iRisk Foundations
Risk Appetite, Tolerance, Capacity…The Risk Taxonomy and UniverseRisk Register vs Risk MatrixStress TestingScenario Analysis vs Stress TestingImpact and LikelihoodLikelihoodThe Risk EventRisk Assessment
iiEnterprise Risk Management
Enterprise Risk ManagementThe Four Risk TreatmentsRisk CultureRisk MaturityRisk Monitoring
iiiRisk Governance
Risk GovernanceHow to set a…The Risk PolicyThe Risk OwnerThe Risk Committee and Its CharterThe Risk Limit FrameworkRisk EscalationHow to set a…
ivCredit and Counterparty Risk
Collateral AgreementsCollateral vs NettingProbability of DefaultExposureCounterparty ExposureConcentration Risk vs Wrong Way RiskCounterparty Risk vs Credit RiskHow to assess Counterparty ExposureHow to assess Concentration Risk
vMarket Risk
Market RiskSensitivity MeasuresThe Hedging PolicyInterest Rate Risk in the Banking BookIRRBB vs Market RiskExpected ShortfallEconomic Value of EquityVaR BacktestingOpen PositionValue at RiskValue at Risk and Expected ShortfallEconomic Value SensitivityFX ExposureValue at Risk vs Expected ShortfallEarnings at Risk vs…FX Transaction Risk vs…How to measure Interest…How to measure Foreign…
viLiquidity Risk
Liquidity Stress TestingLiquidity Gap vs Liquidity BufferMaturity MismatchThe Debt Maturity ProfileFunding ConcentrationSurvival HorizonThe Contingency Funding PlanNet Stable Funding RatioLiquidity Risk vs Funding RiskLiquidity Coverage RatioLiquidity Gap and BufferHow to run a Liquidity Gap Analysis
viiOperational Risk
Operational LossThe Loss EventRisk and Control Self AssessmentException ManagementInformation Security as a…Segregation of DutiesIssue ManagementThe Near MissRoot Cause Analysis in RiskThe Fraud TriangleCyber Risk vs Third Party RiskHow to run a…How to assess Third…
viiiRisk Reporting, Data and Model Risk
Model RiskModel Validation vs BacktestingHow to run Model ValidationData Governance in RiskModel Risk vs Data RiskKey Risk IndicatorsManagement InformationRisk ReportingRisk ScoreEarnings at RiskRisk Adjusted ReturnEarly Warning IndicatorsHow to build a KRI Dashboard
ixTreasury
Corporate TreasuryAsset Liability ManagementIntragroup FundingThe Treasury PolicyThe Treasury Management SystemThe Cash ForecastCash Pooling and ConcentrationHow to build a Cash Forecast
xFinancial Controls and Assurance
Control AssuranceThe Control LifecycleThe Assurance MapThe Audit FindingIssue RemediationInternal Financial ControlsControl Design vs Control EffectivenessHow to map Internal Financial ControlsHow to test Control…Control DeficiencyMaterial Weakness
xiOperational Resilience
Operational ResilienceBusiness Continuity and Disaster RecoveryBusiness Continuity vs Operational…Crisis ManagementDisaster RecoveryIncident Management

Risk Assessment: From Identification to a Rated Position

A risk assessment turns something an institution is exposed to into a described, rated entry that a named person is accountable for on a stated date. The procedure runs identification, description, an inherent rating, the controls actually in place, a residual rating, then the owner and the review date. The output is a position on a scale, and the first step set the ceiling on all of it.

Everything in this sequence has been building one machine. The naming structure says what exists and makes a claim that the list is complete. Then come the two measures, size and chance. Then the grid those two measures land on, and the record that holds what landed there. A risk assessment is the procedure that pushes an exposure through all four of them in order and comes out the other end with an entry somebody has to look at again.

The illustration throughout is Vindhya Commercial Bank Limited, an invented bank, holding forty six assessed entries at month 12 rated on its own five by five grid: 4 red, 12 amber and 30 green, being 8.7, 26.1 and 65.2 per cent, and those three shares sum to 100.0. Every rating, band and threshold shown is that bank's own choice rather than a rule written for it by anybody outside. The four risks behind its four reds illustrate a procedure rather than a subject: credit, market, liquidity and operational risk each have their own account elsewhere, and the machine works the same way whichever of them it processes.

What does a risk assessment actually produce?

Ask most people what an assessment produces and a number comes back. High, or twelve, or red. The colour is not wrong so much as it is the smallest part of the truth, and mistaking a rating for the whole output is why so many records are full of ratings nobody can act on. A risk assessmentThe procedure that turns an exposure into a described, rated entry with a named person accountable for it and a date on which it is looked at again. produces four things at once, and a rating without the other three is an opinion with a colour attached.

Take the everyday version first. A household living on one salary knows, if it thinks about the question for ten seconds, that the salary stopping is what would hurt. Saying so out loud is not an assessment. The exercise becomes an assessment when somebody in that household writes down what would cause it, what would happen in the month after, how bad that would be, how likely it seems, what is already standing between them and it such as savings or a second earner, who is responsible for keeping that in place, and when they will sit down and look at the question again. The rating is the only part of that list a stranger can argue with, and it is the part that matters least.

Seven steps, in one order, and the order is not a preference

The procedure runs the same way at a bank as at that kitchen table. Identify what is exposed. Describe it. Rate the size the consequence would have. Rate the chance of the event. Count the controls that are actually there. Record the position left over once those controls are counted. Attach a named owner and a review date. Seven steps, and they run in that order because each one consumes what the step above produced. The size of something that has not been described cannot be rated, and something that has not been found certainly cannot be described.

SEVEN STEPS, AND EVERY ONE OF THEM OPERATES ON WHAT THE STEP ABOVE HANDED IT The order is structural rather than a preference. Nothing later can recover an exposure the first step never found. 1 Identify find what is exposed and file it against a name that exists 2 Describe write the cause, the event and the consequence as one sentence 3 Size it rate the impact the consequence would have if the event happened 4 Rate the chance rate the likelihood of the event over a stated period 5 Count controls count only the controls actually in place, never the planned ones 6 Record residual record the position left once those controls have been counted 7 Own and date it attach a named owner and a date on which somebody looks again EVERY STEP BELOW INHERITS THE CEILING STEP 1 SET
Seven steps in one order, each consuming the output of the one above it, so a flawless rating applied to a list that missed something produces a flawlessly rated incomplete list.
Try it out

What does a risk assessment produce?

Where does an assessment start, and why is that the step everybody skips?

An assessment starts with identificationFinding the exposures that actually exist and filing each one against a name, which sets the ceiling on the quality of every later step., the work of finding what is there. Identification is skipped more often than any other step, and it is skipped for a reason that is almost sympathetic: it does not feel like work. Rating something feels like analysis. Describing something feels like writing. Finding things feels like standing in a room asking people what worries them, and it produces no artefact anybody can admire.

Skip it anyway and the whole procedure still runs. That is the trap. A list that is missing a third of what exists can be described beautifully, rated carefully, controlled thoughtfully, owned properly and reviewed on time. Every later step operates on what identification handed it, so a perfect rating procedure applied to an incomplete list produces a perfectly rated incomplete list. Nothing downstream can put back an exposure the first step never found, because nothing downstream is even looking.

Identifying against the taxonomy, so that what is found has somewhere to be filed

Identification is not simply noticing things. Identification is noticing things and then filing each one against a name that already exists on the institution's naming structure. Vindhya Commercial Bank Limited runs seven level one categories, numbered TX1 to TX7, with 31 sub-categories beneath them, split 6 under TX1, 5 under TX2, 4 under TX3, 9 under TX4, 3 under TX5, 2 under TX6 and 2 under TX7, and 6 plus 5 plus 4 plus 9 plus 3 plus 2 plus 2 is 31. The naming structure itself is covered separately. Filing does one thing to identification that matters here: it turns a vague worry into an entry that can be counted.

Filing also does something less comfortable, and the whole procedure turns on it. An exposure that has no category to be filed under does not become a small entry or a badly filed entry; it becomes nothing at all. The person who noticed it has nowhere to put it, the record has no row for it, no rating is produced and no owner is attached. Committee G2 recorded the gap in month 8 as one to close. Climate risk still appears nowhere in this bank's structure at either level, and at month 12 it is 0 of 7 at level one and 0 of 31 at level two. So there is no entry for it on the register of 46, and there could not be one.

IDENTIFICATION FILES WHAT IT FINDS, AND WHAT CANNOT BE FILED IS NOT RECORDED The naming structure of Vindhya Commercial Bank Limited, invented. Seven level one categories, thirty one at level two. CLIMATE RISK noticed, and there is no category on this list an exposure with nowhere to be filed never becomes an entry, so it is never rated at all TX1 credit risk 6 at level two TX2 market risk 5 at level two TX3 liquidity and funding risk 4 at level two TX4 operational risk 9 at level two TX5 compliance and conduct risk 3 at level two TX6 strategic and business risk 2 at level two TX7 reputational risk 2 at level two 6 + 5 + 4 + 9 + 3 + 2 + 2 = 31 SUB-CATEGORIES BENEATH SEVEN LEVEL ONE NAMES Climate risk is 0 of 7 at level one and 0 of 31 at level two. Committee G2 recorded it in month 8 as a gap to close.
Filing is what converts a noticed exposure into a countable entry, so an exposure that matches no name on the structure produces no row, no rating and no owner.

Notice how much that one fact costs, and notice that it costs it silently. Nobody at this bank made a decision to leave climate risk unrated. The category was simply not there, so the question was never asked in a form that could produce an answer. A naming structure is a claim that the list is complete, and the only way to test that claim is to go looking for what is not on it. That is a different activity from reviewing what is on it, it takes different people, and almost nobody does it.

Try it out

Why is identification the step that decides the quality of everything after it?

Derivatives Foundation Bootcamp — Fin Maverick

How is a risk described so that two assessors rate the same thing?

Here is an experiment worth running in any institution. Take one entry off the record, hand the title to two competent people in different rooms, ask each to rate it, and compare. The ratings will differ, often by a lot, and everybody will conclude that rating is subjective. Rating usually is not subjective. The two of them have rated two different objects that happen to share a title.

Take register entry RR3 at Vindhya Commercial Bank Limited, the collateral valuation control. The entry shows up in the loss record as incident I10 and in the control testing as the single material weakness. Written on the record as a title it reads something like collateral valuation risk. One assessor reads that title and pictures a data feed that stops arriving, an operational nuisance somebody notices in a morning. The other reads it and pictures a loan book carried at the wrong value for weeks, and that reaches provisions and reported figures. Their ratings differ because the object differs, and no amount of calibration training fixes a problem that is really a writing problem.

Cause, event, consequence: three clauses that pin the object down

The fix is a sentence with three parts. Cause, event and consequenceThe three part structure of a risk description: what could set it off, what would then happen, and what that would do to the institution. is the standard shape, and it works because each clause closes off one way of reading the title differently. Because the valuation feed can go stale without anybody noticing, loans may be carried at the wrong value for a stretch of days, so provisions and reported figures may be wrong until somebody catches it. A description in three clauses, read twice, cannot be made to picture two different objects, and that is the entire point of writing it.

A TITLE IS NOT A DESCRIPTION, AND THE DIFFERENCE SHOWS UP AS DISAGREEMENT Register entry RR3 at Vindhya Commercial Bank Limited, invented, written the two ways. THE ENTRY AS A TITLE collateral valuation risk ASSESSOR A IS RATING a data feed that stops arriving ASSESSOR B IS RATING a loan book carried at the wrong value two different objects, one title the ratings differ and it looks like judgement THE ENTRY AS A DESCRIPTION CAUSE the valuation feed can go stale without anybody noticing EVENT loans are carried at the wrong value for a stretch of days CONSEQUENCE provisions and reported figures are wrong until somebody catches it one object, and both assessors can see it Disagreement about a rating is very often disagreement about what is being rated, and the three clauses are what settles it.
Two assessors handed only a title rate two different objects, while the three clause version fixes what is being rated before anybody argues about how bad it is.

There is a second reason the three clauses earn their space, and it only shows up later. The cause clause is where controls attach. The event clause is what the likelihood rating is about. The consequence clause is what the impact rating is about. Write the description properly and the next three steps of the procedure already know what they are measuring; write a title instead and all three of them quietly invent their own subject. That is why the description sits at step two and not at step six, where a tidy mind might prefer to put the writing up.

Try it out

Two assessors give the same register entry very different ratings. What is most likely missing?

What is the Risk Matrix, and how does a described risk reach a cell?

Steps three and four of the procedure produce two ratings, and those two ratings have to land somewhere. The place they land is the risk matrixThe grid of impact against likelihood on which a rated risk lands as a pair of coordinates, one from each axis.. At Vindhya Commercial Bank Limited it is five points on each axis, giving twenty five cells, and the assessment of any one exposure ends as a pair of coordinates on it. A matrix is no more than that: an address system with two axes. The grid is not a decision, it is not a policy, and it does not tell anybody what to do.

The two axes come from two different questions, and that is why they are two axes and not one. The impact axis asks how big the consequence would be if the event happened, and it is rated on the consequence clause of the description. The likelihood axis asks how often the event happens over a stated period, and it is rated on the event clause. Impact and likelihood are each set out under their own names, and neither measure is re-derived here. The joining step is the one held here: two independent ratings meet, and where they meet is the whole of what the assessment produced.

Reaching a cell, and what the cell then means

Run it forward once. An entry has been described. Somebody rates the consequence and gets 4 on the impact axis. Somebody rates the chance of the event and gets 3 on the likelihood axis. Those two numbers pick a row and a column, and the entry now sits at impact 4, likelihood 3. That pair is its position. The pair carries both facts, in an order anybody can read back, and it can be compared to any other entry rated the same way.

THE RISK MATRIX: TWO AXES, FIVE POINTS EACH, AND TWENTY FIVE ADDRESSES The five by five grid used by Vindhya Commercial Bank Limited, invented. Every cell is written impact first, then likelihood. 5,1 5,2 5,3 5,4 5,5 4,1 4,2 4,3 4,4 4,5 3,1 3,2 3,3 3,4 3,5 2,1 2,2 2,3 2,4 2,5 1,1 1,2 1,3 1,4 1,5 IMPACT, RATED 1 TO 5 5 4 3 2 1 1 2 3 4 5 LIKELIHOOD, RATED 1 TO 5 a described risk rated 4 on impact and 3 on likelihood THE PAIR IS ITS ADDRESS The two ratings meet in one cell and that cell is the whole of what the assessment produced. The pair travels; a single score made from it does not. Five points on each axis gives twenty five cells. It is a scale rather than a container: this bank holds 46 entries across 25 cells, an average of 1.84 a cell.
A rating on each axis picks a row and a column, and the entry ends up at one address on the grid rather than at a single number.

Now the part that matters about what the cell means, and it is a limit rather than a power. A cell says where an assessment landed. A cell does not say the entry is acceptable, it does not say the entry is urgent, and it does not say anybody must act. Those are separate judgements made by people with authority, using the position as an input. A grid is a scale and not a container, and that is why this bank can hold 46 entries across 25 cells at an average of 1.84 entries a cell. Several entries can share one address without any of them being the same risk, and the record is what tells them apart.

Why the pair of coordinates travels better than the score made from it

Almost every institution eventually multiplies the two ratings together and reports the product. The habit is understandable: one number sorts, and a pair does not. Multiplying also destroys information, and the destruction is measurable rather than a matter of taste. Twenty five cells produce only fourteen distinct products, being 1, 2, 3, 4, 5, 6, 8, 9, 10, 12, 15, 16, 20 and 25. Eleven of the twenty five cells therefore land on a score that another cell has already taken, and the product cannot say which of them it came from.

Take a score of 12, arising from impact 3 with likelihood 4 and from impact 4 with likelihood 3. Those are different situations. One is a moderate consequence that turns up often; the other is a serious consequence that turns up a little less often. Take a score of 4, arising three ways: impact 1 with likelihood 4, impact 4 with likelihood 1, and impact 2 with likelihood 2. A nuisance that happens constantly, a serious event that almost never happens, and something middling on both counts all report as a four. A reader given only the product cannot get back to the two facts that made it, so report the pair first and the score second, or report the pair alone.

TWENTY FIVE CELLS COLLAPSE ONTO FOURTEEN DISTINCT SCORES Each square is one cell of the grid. Its position on the line is the product of the two ratings. 1 2 3 4 5 6 8 9 10 12 15 16 20 25 THE SCORE, BEING IMPACT TIMES LIKELIHOOD a score of 4 arises three ways impact 1 by 4, impact 4 by 1, impact 2 by 2 a score of 12 arises two ways impact 3 by 4 and impact 4 by 3 Eleven of the twenty five cells land on a score another cell has already taken, so the product cannot say which cell it came from.
Stacking every cell above the product it makes shows the collapse directly: three cells pile onto a score of four and two onto a score of twelve.
Try it out

An entry is reported as a matrix score of 12. What would have been more useful to be told?

The two objects get run together constantly, so one boundary is worth marking. The grid is a scale; the record that holds the entries is a document. Comparing the two as objects, and asking what each is for, is set out under the risk register and the risk matrix, and is not re-run here. The grid enters only as what an assessment lands on, at the fifth of the seven steps.

What sits between an inherent and a residual rating?

Steps three and four produced a rating with nothing subtracted. The rating before anything is taken off is the inherent ratingThe rating of a risk before the effect of any control is counted, which is why it is the same for two institutions facing the same exposure.: how bad this would be, and how often it would happen, if nothing at all stood in the way. Then step five counts what actually stands in the way. Step six records what is left, the residual ratingThe rating after the controls actually in place have been counted, which is why it differs between two institutions facing the same exposure..

The everyday version makes the distinction obvious. A shop on a busy street faces the same inherent risk of theft as the shop next door. One of them has a shutter, a camera and a person who counts the till twice a day; the other has none of those. The inherent position is a fact about the street. The residual position is a fact about the shop. Two institutions facing exactly the same exposure should record the same inherent rating and different residual ratings, and if they do not, one of them has confused a fact about the world with a fact about itself.

The distance between the two ratings is a claim, not a measurement

Here is where assessments quietly go wrong. An entry rated at step 5 before controls and step 3 after them has moved two steps, and that movement is not something anybody measured. The movement is an assertion: the institution believes the controls it has listed reduce this by two steps. The assertion can be perfectly reasonable and it can also be completely unfounded, and the record looks identical either way. The gap between an inherent and a residual rating is the institution's claim about its own controls, and the only thing that makes it believable is evidence that those controls actually operated.

THE MOVE FROM INHERENT TO RESIDUAL IS A CLAIM ABOUT CONTROLS A generic five step axis, shown to make the movement visible. It is not the position of any entry on this bank's record. step 5 step 4 step 3 step 2 step 1 INHERENT the rating before any control is counted RESIDUAL the rating once those controls are counted two steps WHAT THE MOVE RESTS ON a check that runs every day did it run, and did anyone read the output a second pair of eyes on release were they two different people, every time monitoring over the first two what happened on the days the feed stopped The two steps between the markers were not measured by anybody. They were asserted, and the record looks the same whether the assertion holds or not. A RESIDUAL RATING IS NEVER BETTER THAN THE EVIDENCE UNDERNEATH THE CONTROLS IT RELIES ON
Two steps of movement down the axis is an assertion about three named controls, and each of those controls raises a question that only testing evidence can answer.

Vindhya Commercial Bank Limited has a live instance of exactly that gap, and it is register entry RR3, the collateral valuation control. Whatever residual position that entry carried before month 10, the control it relied on failed for 11 working days and no monitoring control noticed. The failure is incident I10 in the loss record and the single material weakness in the control testing. The controls were listed, they were counted, and one of them was not operating. A residual rating that counted them was therefore describing an institution that did not exist on those days, and nothing in the record itself could have shown that.

Try it out

An entry moves two steps between its inherent and its residual rating. What is that claim resting on?

Breaking Into Quants Bootcamp — Fin Maverick

How is an assessment tested for whether it found everything?

Now the output. Vindhya Commercial Bank Limited holds 46 assessed entries at month 12, and every one of them went through all seven steps: found and filed against one of the seven level one names, described in three clauses, rated on both axes, weighed against the controls actually in place, recorded at its residual position, and given a named owner with a date. Rated on the bank's own five by five grid they come out like this.

Rating on the recordEntriesShare of the 46
Red48.7 per cent
Amber1226.1 per cent
Green3065.2 per cent
Total assessed entries46100.0 per cent

The count of reds, ambers and greens is where most treatments stop, and it is where the interesting work starts. A count of reds says nothing about whether the assessment behind it is any good. The one test that does say something, and which almost nobody runs, is to take the four reds and go looking for each of them somewhere else in the same institution. ReconciliationChecking an assessment outward against the institution's other records, to see whether they agree about what is serious. outward is the completeness test, and it is cheap.

Register redWhat the entry isWhere the same object turns up elsewhere
RR1Sector concentrationBreach B1 on limit L3, open since month 5
RR2Dependence on wholesale fundingBreach B3 on limit L10, open since month 11
RR3The collateral valuation controlIncident I10 in the loss record, and the single material weakness in control testing
RR4The behavioural deposit assumptionModel V1, one of three in the inventory never validated
Four of fourreconcileeach red is an object another record already knows about

Four of four. A record whose reds are all corroborated by the breach log, the loss record and the model inventory is a working record, and this one is right because it was rebuilt in month 6. Contrast what a broken record looks like: reds that appear nowhere else, and objects that everybody in the institution already treats as serious appearing nowhere on the record. Neither of those is a rating problem. Both are identification problems wearing a rating disguise.

Three records, five objects, and only one of them on both red lists

Then comes the uncomfortable part, and it is worth going slowly because it looks at first like a finding against the bank. Alongside the register, this bank runs a dashboard of 16 key risk indicators of which 9 are green, 5 amber and 2 red, and it runs a set of twelve limits of which three are in live breach. The two reds on the dashboard are the sector concentration behind breach B1 and the depositor concentration behind breach B4. The three live breaches are B1, B3 and B4.

Line the three up. The objects flagged red anywhere in this institution are B1, B3, B4, incident I10 and model V1: five distinct objects. Only breach B1 appears on both red lists, being 1 of 5, or 20.0 per cent agreement. Breach B4 is red on the dashboard and is not one of the register's four reds. Incident I10 and model V1 are red on the register and are on neither of the dashboard's two.

THREE RECORDS INSIDE ONE BANK, AND THEY DO NOT NAME THE SAME THINGS Vindhya Commercial Bank Limited, invented, at month 12. Each column is a different record answering a different question. THE REGISTER, FOUR REDS THE DASHBOARD, TWO REDS THE LIMIT SET, THREE BREACHES RR1, sector concentration, which is breach B1 ON THIS RECORD ON THIS RECORD ON THIS RECORD RR2, wholesale funding dependence, breach B3 ON THIS RECORD not on it ON THIS RECORD depositor concentration, which is breach B4 not on it ON THIS RECORD ON THIS RECORD RR3, the collateral valuation control, incident I10 ON THIS RECORD not on it not on it RR4, the behavioural deposit assumption, model V1 ON THIS RECORD not on it not on it how many objects each record names 4 2 3 Five distinct objects across the three records, and only breach B1 sits on both red lists, being 1 of 5 or 20.0 per cent agreement.
Reading the five flagged objects across all three records at once shows the overlap is a single row, which is what three different questions produce.

The instinct at this point is to call that a failure of joined-up thinking and ask somebody to make the three lists agree. Resist it. A limit breach says a measured number went over a cap, an indicator says a watched measure crossed a trigger, and an assessment rating says a described risk landed in a particular cell, and those are three different questions with no reason to produce the same answer. Model V1 has never breached anything, because there is no limit on a model. Incident I10 crossed no trigger, because nothing was watching that feed. An institution that forces the three records to agree has not improved any of them; it has thrown away whatever two of them were telling it.

The reconciliation is aimed the other way. The object of the search is not perfect agreement. The ones worth hunting are the objects the rest of the institution plainly treats as serious and that appear nowhere on the record at all, and those are precisely what identification missed. Four out of four reconcile outward here, and that is a good sign. Reconciling outward says nothing whatever about what identification never found.

Try it out

The register has four reds, the dashboard has two reds and the limit set has three live breaches, and together they name five distinct objects. Is something wrong?

What does a finished assessment look like once it is written down?

Everything so far has been the procedure. A great deal of argument about assessments turns out to be argument about what a row is supposed to contain, so here is the artefact, field by field. Nine fields, and they divide neatly into two groups that behave very differently in practice.

The first five fields are the analysis: what it files under, the three clause description, the inherent rating, the controls relied on, and the residual rating. The last four are the accountability: a named owner, a review date, the agreed action and the date that action is due. The first five are what people enjoy writing and the last four are what makes the row do anything, and that is exactly why the last four are the ones that go missing. A row carrying the first five and none of the last four is a well argued opinion about a size and a chance, and nobody anywhere is obliged to act on it.

A FINISHED ASSESSMENT IS NINE FIELDS, AND THE LAST FOUR ARE THE ONES PEOPLE DROP The shape of one entry on the record of Vindhya Commercial Bank Limited, invented. The fields, not the values. 1 The category it files under which of the seven level one names, and which of the thirty one beneath it 2 The three part description the cause, the event and the consequence, written out as one sentence 3 The inherent rating impact and likelihood before any control has been counted 4 The controls relied on the ones actually in place and named, never the ones somebody intends to build 5 The residual rating impact and likelihood once those controls have been counted 6 The named owner one person, named, accountable for the position this entry now holds 7 The review date the date on which somebody is due to look at this entry again 8 The agreed action what is being done about it, if anything, written in plain words 9 The date that action is due the date by which that action is meant to have been finished Fields 6 to 9 are what turn a rating into an entry. Without them the row is an opinion about a size and a chance, and nobody has to do anything with it.
Splitting the row into the five analytical fields and the four accountability fields shows which half a hurried assessment quietly leaves empty.
Debt Capital Markets Bootcamp — Fin Maverick Writing an Investment Thesis — free micro-course from Fin Maverick

What can be said about the risks identification never found?

The record says 46. The 46 is exact and auditable and, on its own, almost meaningless: it is a count out of a total nobody knows. CoverageThe share of what actually exists that identification found. It is unknown by construction, because counting it would require knowing what was missed. is the share identification actually found, and no institution can measure its own coverage from inside its own record. Nothing that went unnoticed can be counted. A coverage nobody can measure sounds like a dead end, and it is not: two useful things can still be done.

The first is to bound it from below. Vindhya Commercial Bank Limited does not have to estimate anything to know its coverage is under 100 per cent: climate risk appears nowhere in its naming structure at either level, its own committee G2 recorded the gap in month 8, and at month 12 it is still 0 of 7 and 0 of 31. There was nowhere to file it, so at least one thing could not have been identified. An institution that has found a single category missing from its own naming structure has proved its coverage is incomplete without estimating a single number.

The second is to size what a given coverage would imply, and that is arithmetic rather than estimation. If a record holds 46 entries and identification found a share of what exists, the implied true population is 46 divided by that share, and the missing count is what is left over. At 92 per cent, 46 over 0.92 is exactly 50, so four entries are missing. At 79.3 per cent it is 58.0 and twelve are missing. At 80 per cent it is 57.5 and 11.5 are missing. At 50 per cent it is 92, and there are as many entries outside the record as inside it.

Try it out

The record holds 46 entries. Before the control below is touched: if identification found 92 per cent of what exists, how many entries are missing?

Play with it

Turn the coverage of identification, and watch what it says about the record

The record holds 46 entries, of which 4 are red, 12 amber and 30 green, and those are the invented bank's own. The one thing the control moves is the share of what actually exists that identification found. Nobody knows this bank's coverage and the case does not state one, so the share is set on the dial rather than read off the record. The direction is not hypothetical: climate risk sits nowhere in this bank's naming structure, so its coverage is known to be below 100 per cent without anybody estimating anything.

IDENTIFICATION COVERAGE 80.0 PER CENT
WHAT A RECORD OF 46 ENTRIES IMPLIES ABOUT WHAT WAS NEVER FOUND The 46 entries and the 4, 12 and 30 split belong to the invented bank. Coverage is set on the dial and is not a figure from the case. the 46 entries actually recorded 11.5 missing 0 23 46 69 92 ENTRIES: THE 46 RECORDED, AND THE IMPLIED MISSING BESIDE THEM REDS TO EXPECT AMONG THE MISSING, AT THE RECORD'S OWN 8.7 PER CENT RATE 0 1 2 3 4 four is as many reds as this record already carries This is the worked default: 11.5 entries missing, and about one red among them.
Coverage chosen
80.0 per cent
Implied true population
57.5
Entries missing
11.5
Reds among them
1.0

If identification found 80.0 per cent of what exists, this register of 46 is missing about 11.5 entries, of which perhaps 1.0 would be red.

Educational illustration. Invented figures throughout. The 46 entries and the 4 red, 12 amber and 30 green split are the bank's own record; the coverage share is set on the dial and is not a figure from the case, and no coverage figure for this bank exists anywhere. The worked default is 80.0 per cent, implying a true population of 57.5 and 11.5 entries missing, with about 1.0 red among them at the record's own 8.7 per cent red rate. Two crossings are exact and worth landing on: at 92.0 per cent exactly four entries are missing, as many as this record has reds, and at 79.3 per cent exactly twelve are missing, as many as it has ambers.
THE ENTRIES MISSING FROM A RECORD ARE A CURVE IN THE COVERAGE OF IDENTIFICATION A record of 46 entries against the share of what exists that identification found. Coverage is set on the dial and is not a figure from the case. 0 12 24 36 46 50 60 70 80 90 100 ENTRIES MISSING IDENTIFICATION COVERAGE, PER CENT 50 per cent coverage: forty six missing, as many outside the record as inside it 79.3 per cent coverage: twelve missing, as many as the ambers 92 per cent coverage: four missing, as many as the reds the default of the control below The curve turns steeply exactly where an institution feels safe: the fall from a hundred per cent to ninety two already costs four entries.
Plotting the same relationship as a curve shows it is not linear: the last few points of coverage cost very little, and the middle of the range costs a great deal.

The failure: auditing the ratings and never auditing the identification

Assessments get reviewed constantly, and the reviews are almost always useful and almost never find what matters. The reason is structural rather than a matter of effort. Everything downstream of identification leaves an artefact. A description can be read and judged. An impact rating can be challenged and argued down. A residual position can be tested against the control evidence sitting beneath it. A review date can be checked for being overdue. All of it is on the record, so all of it gets reviewed.

Identification leaves nothing behind to review, because a risk that was never identified is not on the record at all. There is no row to challenge, no rating to disagree with, no owner to question and no date to find overdue. So every review of an assessment comes back with the same class of finding, being ratings that are arguable and descriptions that could be sharper, and no review ever comes back with the entry that was never created.

Vindhya Commercial Bank Limited has a known instance, and it is not hypothetical. Its own committee G2 recorded the gap in month 8 as one to close. Climate risk still appears nowhere in its naming structure at either level, and at month 12 it is 0 of 7 at level one and 0 of 31 at level two. An entry for it cannot exist on the record, because identifying it would produce something with nowhere to be filed. So the record reads 46 entries, and it is 46 out of a number nobody knows. Nothing in the four reds reconciling perfectly outward says anything at all about that.

The habit that follows is worth more than any of the arithmetic in this guide. The first ten minutes with an assessment are better spent on what is not on it than on what is: what the institution talks about in corridors that has no row, what its own committees have recorded as a gap, and what has no category to be filed under. The review that finds the missing entry is a different activity from the review that improves the existing ones, and only one of them is ever scheduled.

Try it out

Why does reviewing an assessment reliably fail to find the biggest problem with it?

Forty six, out of a total nobody knows. See what identification never reached.

Where does any of this show up outside a risk function?

All of it, and under other names. A lender reading a borrower's own account of what could go wrong is running exactly this test: not is the list well written, but is anything obviously absent from it, and does the list agree with what the borrower's other records already say. A borrower whose stated worries never mention the one customer that supplies most of the revenue has told the lender something, and it is not about risk management.

An analyst reading a company's principal risks section has the same job and usually does the opposite: reads the section carefully and stops. The section is the output of somebody's identification step. The useful reading is outward: does the list agree with what the notes to the accounts, the borrowing terms and the last three years of surprises already show, and what is conspicuously not on it. A list of risks is only as informative as the reader's willingness to notice what it does not contain.

And for a household it is smaller and identical. Sit down once a year and write what would hurt, in three clauses each, with a name against every line and a date to look again. Most households can produce five or six entries in twenty minutes. The five or six are not the interesting part. The interesting part is the seventh, whatever nobody wanted to write down, and it is the one the whole exercise exists to surface.

What can an assessment not do?

Three things, and every one of them gets asked of assessments regularly. An assessment cannot say what to do. A rated position is an input to a decision, and choosing whether to accept, avoid, reduce or transfer is a separate act by a different person, covered in the sequence on managing risk across an institution. Running the two together turns a rating quietly into a recommendation nobody agreed to make.

An assessment cannot rate what identification did not find, and that is the whole procedure in one sentence. And it cannot convert uncertainty into risk. Frank Knight drew that line in Risk, Uncertainty and Profit in 1921: a risk is something a size and a chance can be put against, while an uncertainty is something that resists both, and the second does not become the first because somebody wrote it in a box on a form. An assessment that puts a confident coordinate pair against something genuinely unknowable has not measured it, it has decorated it.

An assessment can do a great deal, and that is worth saying plainly after all of that. An assessment makes a worry into an object that two people can discuss without arguing about definitions. It records who is accountable while the question is calm rather than after something has happened. It puts a date on the next conversation. And it produces a record that can be tested against every other record in the institution, the only external check any of it has.

Try it out

Does an assessment say what to do about a risk?

Jurisdiction

Who decides any of this for a bank in India

The procedure in this guide is jurisdiction free. Identify, describe, rate, count the controls, rate again, own it, review it, and that sequence is the same in any country and in any institution. The obligations are not jurisdiction free: what an institution must assess, record, report or hold capital against differs from country to country. For a bank in India that comes from the Reserve Bank of India at rbi.org.in, and the framework structures an Indian requirement implements originate with the Basel Committee at the Bank for International Settlements at bis.org. Rating scales, banding rules, review frequencies, thresholds and effective dates are set by the supervisor and by each institution's own policy, so two banks in one country can run different scales and both satisfy the rules. Which scale binds a particular bank is therefore a question about that bank, answered in its own policy and in the supervisor's published rules.

What the assessment step covers, and where its neighbours live. The naming structure identification files against is the prerequisite for this guide and is covered separately, so it is used here rather than rebuilt. The record as a document, and the comparison between a record and a scale, are covered separately too, and the grid appears here only as the thing an assessment lands on. Impact and likelihood as measures are covered separately. Deciding what to do about a rated position, being accept, avoid, reduce or transfer, belongs to the sequence on managing risk across an institution. Who approves a rating, who escalates a red, how often an entry must be reviewed and what a policy says about any of it belongs to the governance sequence. How a control is designed, tested and found deficient belongs to the controls sequence, and a control that failed is named here and taken no further. Every risk behind the four reds belongs to a later sequence, and instruments are explained separately.

Risk Management Program Bootcamp — Fin Maverick

Sources

SourceDocumentPublisher or site
Reserve Bank of IndiaWhat actually binds a bank in India on risk management arrangements, recording and reportingrbi.org.in
Bank for International SettlementsThe Basel Committee framework that Indian risk management requirements implementbis.org
Frank KnightRisk, Uncertainty and Profit, 1921, where the line between a measurable risk and an unmeasurable uncertainty is drawnHoughton Mifflin

Vindhya Commercial Bank Limited is invented.
Educational material. Not advice on any investment, tax, budget or market position.

Covered in this topic

Subtopics

Risk Matrix
← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.