Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Risk, Treasury & Financial Control
1Risk Foundations
Risk Appetite, Tolerance, Capacity…The Risk Taxonomy and UniverseRisk Register vs Risk MatrixStress TestingScenario Analysis vs Stress TestingImpact and LikelihoodLikelihoodThe Risk EventRisk Assessment
2Enterprise Risk Management
Enterprise Risk ManagementThe Four Risk TreatmentsRisk CultureRisk MaturityRisk Monitoring
3Risk Governance
Risk GovernanceHow to set a…The Risk PolicyThe Risk OwnerThe Risk Committee and Its CharterThe Risk Limit FrameworkRisk EscalationHow to set a…
4Credit and Counterparty Risk
Collateral AgreementsCollateral vs NettingProbability of DefaultExposureCounterparty ExposureConcentration Risk vs Wrong Way RiskCounterparty Risk vs Credit RiskHow to assess Counterparty ExposureHow to assess Concentration Risk
5Market Risk
Market RiskSensitivity MeasuresThe Hedging PolicyInterest Rate Risk in the Banking BookIRRBB vs Market RiskExpected ShortfallEconomic Value of EquityVaR BacktestingOpen PositionValue at RiskValue at Risk and Expected ShortfallEconomic Value SensitivityFX ExposureValue at Risk vs Expected ShortfallEarnings at Risk vs…FX Transaction Risk vs…How to measure Interest…How to measure Foreign…
6Liquidity Risk
Liquidity Stress TestingLiquidity Gap vs Liquidity BufferMaturity MismatchThe Debt Maturity ProfileFunding ConcentrationSurvival HorizonThe Contingency Funding PlanNet Stable Funding RatioLiquidity Risk vs Funding RiskLiquidity Coverage RatioLiquidity Gap and BufferHow to run a Liquidity Gap Analysis
7Operational Risk
Operational LossThe Loss EventRisk and Control Self AssessmentException ManagementInformation Security as a…Segregation of DutiesIssue ManagementThe Near MissRoot Cause Analysis in RiskThe Fraud TriangleCyber Risk vs Third Party RiskHow to run a…How to assess Third…
8Risk Reporting, Data and Model Risk
Model RiskModel Validation vs BacktestingHow to run Model ValidationData Governance in RiskModel Risk vs Data RiskKey Risk IndicatorsManagement InformationRisk ReportingRisk ScoreEarnings at RiskRisk Adjusted ReturnEarly Warning IndicatorsHow to build a KRI Dashboard
9Treasury
Corporate TreasuryAsset Liability ManagementIntragroup FundingThe Treasury PolicyThe Treasury Management SystemThe Cash ForecastCash Pooling and ConcentrationHow to build a Cash Forecast
10Financial Controls and Assurance
Control AssuranceThe Control LifecycleThe Assurance MapThe Audit FindingIssue RemediationInternal Financial ControlsControl Design vs Control EffectivenessHow to map Internal Financial ControlsHow to test Control…Control DeficiencyMaterial Weakness
11Operational Resilience
Operational ResilienceBusiness Continuity and Disaster RecoveryBusiness Continuity vs Operational…Crisis ManagementDisaster RecoveryIncident Management

Risk Culture: What People Do When Nobody Is Checking

Risk culture is what people do with a risk when no procedure tells them to act. A culture is measured rather than described. At Vindhya Commercial Bank Limited, invented, a data quality check caught a stale feed in month 6 and nobody raised it, and a checker refused a forged document set in month 7 and nobody linked it. Both controls worked. Neither signal was ever connected to the loss it matched.

Almost everything written about culture is written as adjectives. Open. Accountable. Speaking up. An adjective has no test attached to it, so adjectives can be printed on a wall while nothing in the building changes. The opposite approach starts with one invented bank, opens the records it already keeps, and reads four numbers out of them that nobody had to be surveyed to produce.

The reason this is worth an afternoon is narrow and practical. A control that fires and is cleared correctly can still be the beginning of a loss, and no control report will ever say so. The control did its job. The report says so. The money was in the hour afterwards, and there is no field on the form for the hour afterwards.

What is risk culture, and how is it different from values on a wall?

Start with a kitchen. A smoke alarm chirps at two in the morning because the battery is low. The alarm worked. The alarm did exactly what it was fitted to do. The next step is not in the alarm's instructions: the household either gets up and changes the battery, or takes the alarm down off the ceiling because the chirping is unbearable and work starts in five hours. Both households have a working alarm. Only one of them has a working arrangement.

Risk cultureWhat people do with a risk when no procedure tells them to act. is that difference, stated for an organisation instead of a household. A procedure tells somebody what to do at the moment a control fires. Nothing tells them what to do in the hour afterwards. Culture is the whole of that next hour. Because it is behaviour rather than belief, it can be counted.

The claim that culture is behaviour is the one people resist, so it is worth being blunt about it. If culture were a belief, measuring it would mean asking people what they believe, and the answer would be whatever they think the asker wants to hear. If culture is a set of things people did when nothing compelled them, then those things left marks in records the organisation already keeps. Nobody has to be asked anything. The marks are counted.

WHERE THE PROCEDURE STOPS AND THE CULTURE STARTS THE CONTROL FIRES WRITTEN DOWN SOMEWHERE NOT WRITTEN DOWN ANYWHERE THE PATH THIS BANK TOOK, TWICE The check is cleared and the record is closed. Nobody asks why it fired in the first place. Nothing is compared with any other record. THE PATH THAT COST ALMOST NOTHING The check is cleared and the record is closed. Somebody asks what else has looked like this. One record is read beside another record. Vindhya Commercial Bank Limited is invented. The control fired correctly on both occasions described here.
A procedure covers only the moment a control fires, and everything after that moment is unwritten, which is why two organisations with identical controls and identical control reports can behave completely differently in the hour that follows.

Notice what is missing from the drawing. The drawing does not say the people on the left were careless and the people on the right were diligent. Both paths are entirely reasonable behaviour for somebody with a queue in front of them and no instruction telling them to do the second thing. The difference between the two boxes is a design difference, not a character difference, and every useful thing in this guide follows from taking that seriously.

Try it out

A data quality check fires, and the person on the desk clears it correctly and closes the record, exactly as the procedure says. Which part of that sequence is the culture reading?

Risk Management Program Bootcamp — Fin Maverick

How is a culture measured rather than described?

The place to look is wherever somebody had a choice and no rule. Vindhya Commercial Bank Limited, invented, keeps nine separate records of risk, and four of them contain a count of exactly that kind. The four counts are the culture readings CU1 to CU4, and the whole of their virtue is that the bank was already holding every one of them before anybody asked a question about culture.

CU1 is linkingConnecting a near miss to the cause it shares with something else the organisation already knows about.: 2 of the 5 near misses N1 to N5 turned out to be the same failure as an incident that followed, being 40.0 per cent. CU2 is optimism in the self assessmentThe business rating its own controls, used here only for its two counts.: the business rated 196 of 214 controls effective and independent testingThe same controls rated by somebody who does not run them day to day. found 172 of the same 214 effective, a difference of 24 controls. CU3 is keeping a date the bank set for itself: 31 of the 92 open issues are past dueBeyond the date the organisation itself agreed for fixing something., being 33.7 per cent, and the oldest is 412 days past. CU4 is reading the paper before the meeting: 6 of the 8 attendees at the month 12 meeting had read the monthly risk report before arriving, being 75.0 per cent.

Not one of those four required a new system, a new form, a new committee or a single question put to a single person. Every one of them is a division of two counts the bank was already writing down for other reasons. Dividing two counts the records already hold is the whole trick, and it is available to any organisation that keeps records at all.

FOUR READINGS, FOUR RECORDS THE BANK ALREADY HELD CU1 LINKING 2 of 5 40.0 per cent near misses that came back as an incident afterwards FROM THE NEAR MISS LOG CU2 SELF RATING 24 11.2 points on 214 controls the business and the testers disagree about FROM THE TESTING RECORD CU3 KEEPING A DATE 31 of 92 33.7 per cent open issues past a date the bank agreed itself FROM THE ISSUE LOG CU4 READING IT 6 of 8 75.0 per cent attendees who read the paper before arriving FROM THE MEETING RECORD QUESTIONNAIRES SENT TO PRODUCE THESE FOUR READINGS: NONE Every count above was already sitting in a record the bank keeps for another reason entirely. The four readings are counts at month 12 of one invented bank, and not one of them is a measure required by anybody. Vindhya Commercial Bank Limited and every figure attached to it are invented.
The four culture readings are two of five near misses that came back, 24 controls of 214 in dispute, 31 of 92 issues past a self-set date and 6 of 8 attendees having read the paper, and producing all four took no survey at all.

What does it mean when a control works and nothing happens next?

The record of the year will show a control operating exactly as designed, and the loss log will show a loss, and no document anywhere will connect the two. Near miss N3 is the cleanest example in this bank's whole year, so take it slowly.

In month 6, the collateral valuation feed at Vindhya Commercial Bank Limited was staleA data feed still delivering yesterday's values as though they were today's. for 2 working days. A data quality check caught it. The check firing is the control doing precisely what a data quality check exists to do, and a control testing report would show nothing wrong on that line at all. The feed was corrected and the record was closed. Nobody raised it as an issue. No cause was written down, no owner was named, and no other record was ever read beside it.

Four months later, in month 10, the same feed was stale again. The second time the feed ran stale for 11 working days, being 5.5 times as long, and 340 loans were wrongly marked. The loss is incident I10: gross Rs 1.4 crore, no recovery, net Rs 1.4 crore. Incident I10 is also the single deficiency rated D4 on the bank's four point scale D1 to D4, and it touches the valuation of Rs 8,640 crore of secured advances. The event that cost the most in reputation terms began as a two day nuisance that a control caught perfectly.

ONE FEED, TWO EVENTS, FOUR MONTHS APART NEAR MISS N3, MONTH 6 the check caught it INCIDENT I10, MONTH 10 340 loans wrongly marked 1 2 3 4 5 6 7 8 9 10 11 12 FOUR MONTHS. NO ISSUE RAISED, NO CAUSE WRITTEN, NO LINK MADE. HOW LONG THE SAME FEED WAS STALE, DRAWN ON ITS OWN SCALE Month 6, near miss N3 2 working days Month 10, incident I10 11 working days, being 5.5 times as long Vindhya Commercial Bank Limited, near miss N3 and incident I10 are invented, and so is every figure attached to them. The lower panel is drawn in working days and is deliberately not on the month scale above it.
The same collateral valuation feed was stale for 2 working days in month 6 and for 11 working days in month 10, and across the four months between those two events nothing at all was written down about the first one.
Try it out

A data quality check caught a stale feed after 2 working days and nobody raised it. The control worked. What failed?

Derivatives Foundation Bootcamp — Fin Maverick

Why does a near miss that is recorded and never linked teach nobody anything?

Near miss N4 makes the same point from a harder angle, and it is harder because the person in the story did something visibly right. In month 7, a trade finance document set carrying the same forgery pattern as incident I13 was put in front of a checker, and the checker refused it. The refusal is the control working in the most direct sense there is: somebody looked at a set of papers and said no.

The refusal was recorded as a routine refusal. Trade finance desks refuse document sets constantly, for missing endorsements, for dates that do not agree, for a hundred ordinary reasons, and a routine refusal is exactly the right classification for almost all of them. Nothing in any procedure said to hold this one refusal up against the open investigations, so nothing did, and the refusal went into the count of refusals and stayed there.

One month later, incident I13 was discovered when a beneficiary bank claimed. Nine letters of credit had been issued against forged shipping documents over fourteen months ending in month 8. Gross Rs 22.4 crore, recovery Rs 7.0 crore, net Rs 15.4 crore, and that Rs 15.4 crore net loss is the largest of the bank's year, being 35.2 per cent of the Rs 43.8 crore net operational loss total.

THE REFUSAL WAS REAL, AND IT ARRIVED ALMOST AT THE END THE FOURTEEN MONTHS THE FRAUD RAN, ENDING IN MONTH 8 MONTHS 1 TO 12 OF THE FOURTEEN 14 THE SAME TWELVE MONTHS THE BANK NUMBERS 1 TO 12 1 2 3 4 5 6 7 8 9 10 11 12 NEAR MISS N4, MONTH 7 13 OF THE 14 MONTHS HAD ALREADY RUN 1 LEFT, BEING 7.1% NEAR MISS N4, MONTH 7 A checker refused a document set carrying the same forgery pattern. Filed as a routine refusal and never linked to anything. INCIDENT I13, DISCOVERED MONTH 8 9 letters of credit against forged shipping documents. Gross Rs 22.4 crore, recovery Rs 7.0 crore, net loss Rs 15.4 crore. The case records no split of the loss across the fourteen months, so the 7.1 per cent above measures time and never money. Vindhya Commercial Bank Limited, near miss N4 and incident I13 are invented, and so is every figure attached to them.
The checker refused the forged document set in month 7 with one month of a fourteen month fraud left to run, so the warning was entirely real and it was also very nearly too late.
Try it out

A checker refused a forged document set in month 7. The fraud it belonged to had been running for fourteen months and was discovered in month 8. How much of that fraud could linking the refusal have reached?

Were the two warnings worth the same?

No, and this is the part that gets dropped when the story is told well rather than told honestly. Near miss N3 arrived in month 6 and incident I10 happened in month 10, so the whole of that incident was still in the future when the warning landed. Near miss N4 arrived in month 7 with thirteen of fourteen months of the fraud already behind it. One of those was a chance at prevention and the other was, at best, a chance at slightly earlier detection, and calling them both a missed near miss flattens a real difference.

Why insist on the distinction? Because telling a trade finance team that a routine refusal in month 7 would have saved Rs 15.4 crore says something the record does not support, and the first person who checks the dates will stop believing the rest of the argument. The honest version is stronger anyway. Two controls fired, both times the organisation learned nothing, and only one of the two occasions was a genuine chance to stop a loss before it existed. The smaller claim is the true one.

TWO NEAR MISSES, TWO VERY DIFFERENT AMOUNTS OF WARNING NEAR MISS N3, MONTH 6 NEAR MISS N4, MONTH 7 Warning ahead of the event Four months before incident I10 One month before I13 was discovered How much was still ahead All of it, since I10 had not happened 1 month of 14, being 7.1 per cent What it would have been PREVENTION DETECTION, VERY LATE What was done with it Cleared, closed, not raised Filed as routine, not linked Only the bottom row is the same in both columns, and it is the only row that is a reading of the culture. All figures are invented.
Near miss N3 arrived four months before the incident it matched and near miss N4 arrived with about seven per cent of the fraud's fourteen months left, so one was a chance at prevention and the other was barely a chance at detection.

If linking is nearly free, why is skipping it a cultural fact?

Because cost is the usual excuse and it is not available here. A near missA failure that started and was stopped before it cost anything. costs nothing to collect. There is no loss to quantify, no recovery to chase, no customer to compensate, no provision to raise. The bank recorded both N3 and N4 without difficulty, along with N1, N2 and N5, so the register was working exactly as a register should.

Linking costs almost nothing either. Both records already existed and both were already written. The missing step was somebody reading one record beside another and asking whether anything else had looked like this. Reading one record beside another is minutes, not a project, and it needs no system, no vendor and no budget line. When the missing step is free, the reason it was skipped cannot be resourcing, and the only remaining explanation is that nothing in the way the work was arranged made anybody expect to take it.

Think of a shopkeeper who notices one bad note in the till on a Tuesday and puts it aside, and notices another on the Friday and puts that aside too. Neither Tuesday nor Friday costs anything. The loss arrives on the day somebody would have spotted, had they laid the two notes side by side, that both came from the same customer at the same hour. Laying two things side by side is the entire technique, and almost nobody has a procedure that requires it.

Try it out

No money was lost, so collecting a near miss costs nothing. What does linking one cost?

Debt Capital Markets Bootcamp — Fin Maverick

What does a gap between a self assessment and independent testing say?

The second culture reading is about optimism, and it comes out of two counts that are easy to state and easy to get wrong. Vindhya Commercial Bank Limited has 214 key controls across the nine processes PR1 to PR9. The business assessed all 214 of them and rated 196 effective. Independent testers looked at the same population of 214 and, at the end of their work, found 172 effective.

Put those two counts on the same base and the arithmetic is short. 196 of 214 is 91.6 per cent. 172 of 214 is 80.4 per cent. The difference is 11.2 percentage points. Because 196 less 172 is 24, the difference is also 24 controls, and 24 of 214 is itself 11.2 per cent. The percentage gap and the control count are the same fact stated twice. An argument about points can therefore always be converted back into an argument about a specific number of controls.

Twenty four controls is a concrete object. A count of controls is not a mood, a tone or a sentiment. Somebody can go and get the list, and the list will name a process from PR1 to PR9 for every row on it. The list is what makes CU2 a culture reading rather than a debate: two sets of people looked at the same things and disagreed about two dozen of them, and the disagreement has an address.

ONE POPULATION OF 214 CONTROLS, TWO COUNTS ON IT THE BUSINESS RATED 196 OF 214 EFFECTIVE, BEING 91.6 PER CENT 196 INDEPENDENT TESTING FOUND 172 OF THE SAME 214, BEING 80.4 PER CENT 172 24 CONTROLS 11.2 POINTS ON 214 Both bars run the full width of the same 214 controls, so the two fill ends can be read against each other. 24 divided by 214 is 11.2 per cent, which is exactly the gap in percentage points: one fact written down two ways. Vindhya Commercial Bank Limited is invented and neither count is a measure required by anybody.
The business rated 196 of 214 controls effective and independent testing found 172 of the same 214, so 24 controls are the whole of the difference between the two views.
Where the record stops

The bank's record gives two counts and no map between them. The record does not say that the 172 controls the testers found effective are a subset of the 196 the business rated effective, and the subset cannot be assumed. Putting both counts on the same base of 214 compares two rates on one population. Comparing two rates does not match control to control, and anybody who needs the actual list of 24 has to go and build it from the two records rather than subtract one number from another.

Which base is the division made by, and why does that matter more than the number?

Here is where a completely honest set of records produces a misleading sentence, so read this slowly. The testers did their work in two stages. First they tested design on all 214 controls, and found 198 designed effectively and 16 carrying a design gap. Then they tested operating effectiveness on the 198 that had passed the design stage, and found 172 effective and 26 not. Both stages tie: 198 plus 16 is 214, and 172 plus 26 is 198.

So a perfectly truthful sentence is available: independent testing found 172 of the 198 it tested for operating effectiveness, being 86.9 per cent. Nothing in that sentence is false. The two rates are not measured on the same population, so printing 86.9 per cent next to the business's 91.6 per cent makes a comparison that means nothing.

One is 172 out of 198. The other is 196 out of 214. Set side by side, the two rates show an apparent gap of 4.7 percentage points. A committee paper reads that as broad agreement with a bit of noise. The full 214 is the only like for likeTwo rates put on the same base, so that the comparison between them means something. reading available, and the gap is 11.2 points. The flattering version understates the real gap by 6.5 percentage points, and nobody had to type a single wrong digit to produce it.

The everyday version is a school that reports a 95 per cent pass rate, having excluded from the count every student it advised not to sit the examination. Each number in that sentence can be checked and none of them is a lie. The baseThe count a percentage is divided by, which is also the population being described. is doing all the work, and the base is the part nobody reads aloud.

THE COMPARISON THAT LOOKS REASONABLE AND IS NOT HOW THE TWO RATES GET PRINTED Business 91.6% Testers 86.9% LOOKS LIKE A GAP OF 4.7 POINTS WHAT SITS UNDERNEATH EACH OF THEM Base 214 ALL 214 KEY CONTROLS Base 198 THE 198 TESTED FOR OPERATION 16 NEVER TESTED 16 controls carried a design gap and never reached the operating test, so the lower base is 16 controls shorter than the upper one. Two rates measured on two different populations are not a comparison, however carefully each one was computed. All counts belong to one invented bank.
86.9 per cent is 172 out of 198 and 91.6 per cent is 196 out of 214, so printing the two side by side compares two different populations and hides 16 controls that never reached the operating test.
Try it out

Independent testing found 172 controls effective. The business rated 196 of 214. Before anything moves: how far apart are those two, in percentage points?

Play with it

Move the base and watch a number that never changed change

The count of controls the testers found effective is fixed at 172 throughout. The business rate is fixed at 196 of 214, being 91.6 per cent. Only the base the 172 is divided by moves, from 198 up to 214.

READING AS A RATE Business 91.6% Testers 80.4% GAP 11.2 POINTS, BEING 24 CONTROLS THE BASE BEING DIVIDED BY 198 205 214 188 IS OFF SCALE Only 198 controls were ever tested for operating effectiveness, so no base below 198 exists to be used.

Base: 214 controls

Base
214
Testers report
80.4%
Gap against 91.6
11.2

Educational illustration. Invented figures throughout. The numerator of 172 is fixed and only the base moves. The business rate of 196 of 214 is fixed. Both counts belong to Vindhya Commercial Bank Limited, invented, and neither is a measure required by anybody. The two counts are put on one base for comparison, and that does not claim the 172 are a subset of the 196. Three readings can be checked by hand: at a base of 198 the testers report 86.9 per cent and the gap is 4.7 points; at 205, 83.9 per cent and 7.7 points; at 214, 80.4 per cent and 11.2 points. The gap reaches zero only at a base of about 188, where 172 divided by the base equals 91.6 per cent, and 188 is 10 fewer controls than were ever tested. No honest base closes it.

Try it out

Which base would make the gap disappear entirely?

The crossing point is worth holding on to. Knowing it makes the trap safe to walk into and out of. The gap can be shrunk by choosing a smaller base. Closing it would need a base of 188, and only 198 were ever put through the operating test, so no base that actually exists closes it. Solving for the crossing before the argument begins is what turns a disagreement into arithmetic.

THE GAP IS A FUNCTION OF THE BASE, NOT OF THE TESTING NO CONTROL WAS EVER TESTED ON A BASE IN HERE 0 4.7 11.2 GAP IN POINTS 188 THE ONLY BASE THAT CLOSES IT 198 4.7 205 7.7 214 11.2 AT 214, LIKE FOR LIKE The 172 never moves along this whole curve. Invented figures throughout.
Holding the 172 fixed and moving the base from 198 to 214 moves the reported rate from 86.9 per cent to 80.4 per cent and the gap from 4.7 points to 11.2, so the reported difference is a property of the base rather than of the testing.

The failure: the flattering base, and why it is a culture reading rather than a slip

Picture the paper being assembled the evening before the meeting. Two numbers have to go on one slide. One of them, 91.6 per cent, arrives from the business as a finished rate. The other arrives from the testers as a finished rate too, 86.9 per cent, computed correctly on the population they tested for operation. Both are put on the slide because both are what the two teams reported. The slide now says the two views differ by 4.7 points.

Nobody typed a wrong number, nobody hid anything and nobody would fail an audit of that slide, and the slide is still wrong. The 24 controls that two sets of people actively disagree about have been reported as a rounding difference, and a committee reading 4.7 points has no reason to ask for the list.

The reason this belongs with culture rather than with arithmetic is that the correction is free and available. Both counts and both bases sit in the same record. Recomputing 172 over 214 takes seconds. The deciding factor is whether anybody in the chain treats an unlike comparison as their problem when no procedure names them as responsible for it. The two near misses asked the same question in a different register.

Set against that, the reading is 11.2 points and 24 controls, stated on one base, every single time these counts appear.

Financial Analyst Program Bootcamp — Fin Maverick

What does an issue past a date the bank set for itself reveal?

CU3 is the plainest of the four readings and it is the one most organisations already have on a slide without knowing what they are looking at. Vindhya Commercial Bank Limited is carrying 92 open issues. The 92 issues age in five buckets AG1 to AG5, from 28 in the newest bucket down to 9 that are over a year old. The buckets are the ageing profile, and the ageing profile is the number that usually gets reported.

Now the second reading. Of those 92, 31 are past their agreed remediation due date, being 33.7 per cent, and the oldest is 412 days past. Age shows that the problem was hard; past due shows that a date the organisation set for itself was allowed to go by, and only the second one is a statement about what people did.

The distinction matters because the two readings can point in opposite directions on the same issue. A complicated system change raised eleven months ago, with a two year agreed date and monthly evidence of progress, is old and entirely on track. A small procedural fix raised three weeks ago with a two week date is new and already late. Report ageing alone and the first one looks bad and the second is invisible. Nobody set the ageing date; somebody, by name, agreed the remediation one.

TWO READINGS OF THE SAME 92 OPEN ISSUES READING ONE: HOW OLD THEY ARE AG1, 0 to 30 days 28 AG2, 31 to 90 days 22 AG3, 91 to 180 days 18 AG4, 181 to 365 days 15 AG5, over 365 days 9 28 + 22 + 18 + 15 + 9 = 92, measured from the date raised. Nobody chose these dates. They are just elapsed time. READING TWO: HOW MANY PASSED A DATE THE BANK AGREED 31 PAST DUE 61 WITHIN DATE 33.7 per cent, and the oldest is 412 days past its agreed date. OLD NEW WITHIN DATE PAST DUE old and on track old and late new and on track new and already late The record locks the two readings above and does not record how the 92 split across the four cells, so no count is drawn inside them. Vindhya Commercial Bank Limited is invented, and so is every count on this drawing.
Of the 92 open issues, 31 are past a date the bank agreed itself and the oldest is 412 days past due, and because age and overdue are independent an issue can be old and on track or new and already late.
Try it out

Thirty one of 92 open issues are past their agreed due date and the oldest is 412 days past. Which of those two numbers is the culture reading?

And what do 6 of 8 attendees mean?

CU4 is the smallest count here and it takes four words to state. At the month 12 meeting, 6 of the 8 attendees had read the monthly risk report before arriving, being 75.0 per cent. The report runs 38 printed sides and goes out 5 working days ahead, so nobody was ambushed.

Resist two temptations here. The first is to treat 75.0 per cent as a good score because it is a large number. The second is to treat the 2 as a character judgement about two people. The useful question is what a paper has to be like before a quarter of the room arrives without having opened it, and that is a question about the paper, the diary and the meeting rather than about the two. A pack of 38 printed sides landing in an inbox already holding a hundred others is a design, and the design produced the 2.

Reading a Fund Factsheet Properly — free micro-course from Fin Maverick

What is none of these four readings?

Not one of CU1 to CU4 is a survey. Not one of them is a values statement. Not one of them is a training completion rate. Surveys, values statements and training rates get called culture measurement constantly, and here is the test that separates them: does the number record a decision somebody made when no procedure required it?

A survey records what people were willing to write down about themselves in a form with their department on it. A values statement records what a drafting group agreed to print. A training completion rate records that a course was clicked through to the end, and a click is a record of attendance and nothing more. All three describe intentions, and the four readings describe what happened, and only one of those two categories has a loss log sitting behind it.

None of that is an argument against ever asking people anything. The argument is about order. Because counting is free and nobody can flatter it, count first, then go and ask questions about the specific twenty four controls, the specific thirty one issues, or the specific near miss nobody linked. Questions asked after a count are about something. Questions asked instead of a count are about nothing.

Try it out

Which of these is not a risk culture measurement?

Reading a Fund Factsheet Properly teaches you to extract the four things on a fund factsheet that carry information and ignore the rest.

What would have to change in exactly the same records?

A recommendation that starts with a new system is a recommendation nobody acts on this year, and not one of the four steps below needs one. Taken in order, each of the four readings raises one question: what single step would move it?

ReadingWhere it standsThe step that would move it
CU1 near misses that came back2 of 5Check every near miss against the loss log and the open investigations before it is closed
CU2 controls in dispute24 of 214Compute both rates on one base before either reaches a paper, and attach the list of 24
CU3 issues past a self-set date31 of 92Report past due beside ageing, so the date somebody agreed is as visible as elapsed time
CU4 papers read before the meeting6 of 8Put the decisions the meeting has to take on the front sheet of the pack

Every one of those four steps connects two records the bank already keeps, and not one of them creates a new record. The first one alone would have caught both N3 and N4: N3 because the loss log would have shown the same feed, and N4 because the open investigations would have shown the same forgery pattern. Checking a near miss against the loss log is one habit, applied to a log with five rows in it, and it is the whole of the difference between the year this bank had and a better one.

Try it out

The culture reading has to move next year without adding a single new record. Which of these would do it?

How does anybody actually use this?

What four different readers do with the same four counts

An internal auditor uses the readings to choose where to look next year rather than to write a paragraph about tone. The list of 24 disputed controls names a process from PR1 to PR9 on every row, so it is a work plan. The near miss log with 5 rows is an afternoon of reading, and it is the cheapest place in the whole bank to find a loss that has not happened yet.

A board or committee member uses them to test the paper in front of her. Two counts and a percentage arrive on a slide; the useful question in the room is what the base of each one is, and whether both were divided by the same thing. Asking about the base would have caught the 4.7 point version before it was ever discussed.

A lender or an analyst doing diligence on an institution cannot see any of this from outside, and should be honest that this is a limitation rather than pretending a published statement substitutes for it. Three things are visible from outside: whether disclosures separate age from overdue, whether rates come with their bases attached, and whether losses are ever discussed alongside the events that preceded them.

A person running a team of six uses the same technique at a much smaller scale, and it works exactly as well. Count how many times something was caught and nothing followed. Count how many commitments went past dates the team set for itself. Both are countable on one sheet of paper, and neither requires anybody to be asked how they feel about risk.

India

Who sets the expectations that sit behind any of this

Supervisory expectations on risk culture, governance and the operational risk framework originate with the Basel Committee at the Bank for International Settlements. The Committee publishes at bis.org, and the seven operational risk event categories behind a loss log like I1 to I13 come from there too. The binding requirements for a bank in India, including anything on internal control, operational risk and the reporting of losses, come from the Reserve Bank of India at rbi.org.in, and naming only the global standard is the confident error worth avoiding.

Control testing and a deficiency rated a material weakness both appear here, so one further pointer: the reporting duty on internal financial controls sits in the Companies Act, and its text, applicability, exemptions and form come from the Ministry of Corporate Affairs at mca.gov.in, with the assurance standard and guidance note from the Institute of Chartered Accountants of India at icai.org. The current position is the one held by the issuing body.

Whose job a culture is, who is accountable for it and what a policy says about it are each covered separately. A culture has to be defined before responsibility for it can be placed. The risk and control self assessment as an instrument, how it is run and by whom, is covered separately, and two of its counts are used here. The near miss as an operational risk record, root cause analysis and issue management are each covered separately. Control testing, the four point finding scale D1 to D4 and what makes a deficiency a material weakness are covered separately, and the D4 rating is named here rather than taught. How the monthly risk report is designed and what belongs on its front sheet is covered separately. Every figure belongs to one bank, and the four readings are a finding about that bank rather than a claim about how institutions in general behave.

Sources

SourceDocumentSite
Reserve Bank of IndiaWhat actually binds a bank in India on internal control, operational risk and loss reportingrbi.org.in
Bank for International SettlementsBasel Committee material on risk culture, the operational risk framework and the event categoriesbis.org
Ministry of Corporate AffairsThe Companies Act reporting duty on internal financial controls, with its applicability and formmca.gov.in
Institute of Chartered Accountants of IndiaThe assurance standard and guidance note behind an internal financial controls opinionicai.org

Vindhya Commercial Bank Limited is invented.
Educational material. Not advice on any investment, tax, budget or market position.

← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.