Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Risk Management Program · CoreTrack
1Risk, Treasury & Financial Control
iRisk Foundations
Risk Appetite, Tolerance, Capacity…The Risk Taxonomy and UniverseRisk Register vs Risk MatrixStress TestingScenario Analysis vs Stress TestingImpact and LikelihoodLikelihoodThe Risk EventRisk Assessment
iiEnterprise Risk Management
Enterprise Risk ManagementThe Four Risk TreatmentsRisk CultureRisk MaturityRisk Monitoring
iiiRisk Governance
Risk GovernanceHow to set a…The Risk PolicyThe Risk OwnerThe Risk Committee and Its CharterThe Risk Limit FrameworkRisk EscalationHow to set a…
ivCredit and Counterparty Risk
Collateral AgreementsCollateral vs NettingProbability of DefaultExposureCounterparty ExposureConcentration Risk vs Wrong Way RiskCounterparty Risk vs Credit RiskHow to assess Counterparty ExposureHow to assess Concentration Risk
vMarket Risk
Market RiskSensitivity MeasuresThe Hedging PolicyInterest Rate Risk in the Banking BookIRRBB vs Market RiskExpected ShortfallEconomic Value of EquityVaR BacktestingOpen PositionValue at RiskValue at Risk and Expected ShortfallEconomic Value SensitivityFX ExposureValue at Risk vs Expected ShortfallEarnings at Risk vs…FX Transaction Risk vs…How to measure Interest…How to measure Foreign…
viLiquidity Risk
Liquidity Stress TestingLiquidity Gap vs Liquidity BufferMaturity MismatchThe Debt Maturity ProfileFunding ConcentrationSurvival HorizonThe Contingency Funding PlanNet Stable Funding RatioLiquidity Risk vs Funding RiskLiquidity Coverage RatioLiquidity Gap and BufferHow to run a Liquidity Gap Analysis
viiOperational Risk
Operational LossThe Loss EventRisk and Control Self AssessmentException ManagementInformation Security as a…Segregation of DutiesIssue ManagementThe Near MissRoot Cause Analysis in RiskThe Fraud TriangleCyber Risk vs Third Party RiskHow to run a…How to assess Third…
viiiRisk Reporting, Data and Model Risk
Model RiskModel Validation vs BacktestingHow to run Model ValidationData Governance in RiskModel Risk vs Data RiskKey Risk IndicatorsManagement InformationRisk ReportingRisk ScoreEarnings at RiskRisk Adjusted ReturnEarly Warning IndicatorsHow to build a KRI Dashboard
ixTreasury
Corporate TreasuryAsset Liability ManagementIntragroup FundingThe Treasury PolicyThe Treasury Management SystemThe Cash ForecastCash Pooling and ConcentrationHow to build a Cash Forecast
xFinancial Controls and Assurance
Control AssuranceThe Control LifecycleThe Assurance MapThe Audit FindingIssue RemediationInternal Financial ControlsControl Design vs Control EffectivenessHow to map Internal Financial ControlsHow to test Control…Control DeficiencyMaterial Weakness
xiOperational Resilience
Operational ResilienceBusiness Continuity and Disaster RecoveryBusiness Continuity vs Operational…Crisis ManagementDisaster RecoveryIncident Management

The Risk Owner: The Named Person Accountable for a Risk

A risk owner is one named individual who is answerable for a particular risk being run inside its limit, and for what happens when it is not. The word doing the work is named: not a team, not a function, not a job title with nobody in it. Answering for the outcome is one job, operating the control is another, and being told when it goes wrong is a third.

Three separate questions sit on every risk an institution runs, and most registers ask only one. Who is answerable for the outcome. Who performs the control. Who is informed when it goes wrong. Merge any two of the three and the register still looks full. Who has to answer for this has quietly lost its home.

Vindhya Commercial Bank Limited, invented, is a mid-sized Indian commercial bank with a balance sheet of Rs 96,000 crore. Its registers, counts, limits and crossings are all read at its own month 12 reporting date.

The three are merged so easily that the bench below exists to pull them apart. The bench carries the six limit crossings of the case year, three columns against each, and a reading of what each row becomes once the entries are in.

Work it out

Fill the three columns for the six crossings of the case year, and read what each row becomes

Each row is one limit crossing at the invented bank. Set who answers for the outcome, who runs the control, and who is told when it crosses. Every row then lands in exactly one of five states, and the five counts are added up beneath the drawing so that all six crossings are always accounted for once. The bench opens on the record exactly as this case holds it.

Where each column is read from. Who answers for the outcome: the breach log, the column headed risk owner. Who runs the control: the process register, the control operator line for that limit. Who is told when it crosses: the breach log, the escalated-to column.
B1 limit L3, sector concentration
Breach log, row B1. The risk owner column, then the escalated-to column.
One name answers, no control recorded
B2 limit L7, open currency position
Breach log, row B2. The risk owner column, then the escalated-to column.
One name answers, no control recorded
B3 limit L10, wholesale funding share
Breach log, row B3. The risk owner column, then the escalated-to column.
One name answers, no control recorded
B4 limit L12, depositor concentration
Breach log, row B4. The risk owner column, then the escalated-to column.
One name answers, no control recorded
B5 limit L5, trading book value at risk
Breach log, row B5. The risk owner column, then the escalated-to column.
One name answers, no control recorded
B6 limit L4, sub-investment grade share
Breach log, row B6. The risk owner column, then the escalated-to column.
One name answers, no control recorded
SIX CROSSINGS, THREE COLUMNS EACH, AND THE ONE STATE EACH ROW LANDS IN Read a row across. The last column is not a judgement on anybody; it is what the three entries in front of it add up to. CROSSING ANSWERS FOR THE OUTCOME RUNS THE CONTROL IS TOLD WHAT THE ROW BECOMES B1 not recorded not recorded not recorded Answers, no control recorded B2 not recorded not recorded not recorded Answers, no control recorded B3 not recorded not recorded not recorded Answers, no control recorded B4 not recorded not recorded not recorded Answers, no control recorded B5 not recorded not recorded not recorded Answers, no control recorded B6 not recorded not recorded not recorded Answers, no control recorded EVERY CROSSING LANDS IN EXACTLY ONE OF FIVE STATES, AND THE STRIP IS ALWAYS SIX WIDE state state state state state 2 plus 0 plus 0 plus 4 plus 0 = 6 crossings, every one counted exactly once status The six crossings, the limits they crossed and every person named are Vindhya Commercial Bank Limited's own, invented. Whatever is set in the three columns is an arrangement built at the bench, is not a figure from the case, and is not recommended to anybody.
One individual answers
4 of 6
Share of the six
66.7 per cent
Nobody answerable
2
A control run, nobody answering
0

Educational illustration. The bench opens on the record exactly as this case holds it: Manjari Sondhi against B1 and B6, Devendra Achar against B3 and B4, nobody against B2 and B5, a control operator against none of the six, and Devendra Achar named as told on B2. The count is 4 of 6 crossings naming one individual who answers, being 66.7 per cent, and 2 naming nobody. The five states are read in a fixed order and the first one that fits takes the row, so a row belongs to one state and never to two.

Read the record exactly as this case holds it: 4 of the 6 crossings name one individual who answers, being 66.7 per cent, and 2 of them, B2 and B5, name nobody. The record names a control operator against none of the six, so all four named rows read as one name answering with no control recorded. No row is yet in the shape of the central failure: a control run while nobody answers for its outcome. Incident I10 at the invented bank is exactly that failure, and it is set out below. The five states account for the six crossings exactly once: 2 with nobody answerable, 0 with two names answering, 0 answering for a check they run themselves, 4 answering with no control recorded, and 0 answering while somebody else runs it.

The failure is built at the bench by taking row B1, putting the first line of the business into who runs the control, putting a name into who is told, and setting who answers for the outcome back to not recorded. The row then reads nobody answerable, and the count of rows with a control run and nobody answering moves from 0 to 1: a control being run, a person informed, and nobody to ask whether the check could work. The middle button does that to all six rows at once.

What is a risk owner, and what is that person answerable for?

A household has the identical shape, small enough to see whole. Start there. A household of four decides the electricity bill has become too large, everybody agrees, everybody switches something off for a fortnight, and the bill arrives three months later larger again. The conversation that follows goes nowhere because there is nobody it can be addressed to. Now change one thing. One person, by name, is answerable for the bill staying under a stated amount, and may change the geyser timer and bring the meter reading to the table. Nothing about the house changed, and the question stopped being unanswerable.

Naming one person is the whole of it. A risk ownerOne named individual answerable for a particular risk being run inside its limit and for what happens when it is not. is one named individual answerable for one particular risk being run inside the limit set for it. Answerable is narrow and demanding: when the number is outside the limit, that person has to explain what happened, say what is being done, and carry the consequence of the answer being thin. Being accountableAnswerable for the outcome, whether or not the person named performed the activity that produced it. does not mean having performed the activity. Accountability means answering for the outcome of the activity.

Two things follow. The person must have standing to change the arrangement: somebody answerable for a sector concentration who cannot influence what the lending desks write next quarter is a postbox with a title. And a risk owner is attached to a risk rather than to a department. One person may hold several risks, and one risk has exactly one such person. Put two names in that column and who answers has been reopened rather than settled.

THREE QUESTIONS SIT ON EVERY RISK, AND A REGISTER WITH ONE COLUMN ASKS ONE OF THEM Read the verb in each card first. Answering, doing and hearing are three separate acts and only one of them is accountability. ANSWERABLE FOR THE OUTCOME ANSWERS FOR IT one named individual, never a team has standing to change the arrangement has to explain the reading at month 12 the only column that carries an answer THE RISK OWNER PERFORMS THE CONTROL DOES THE WORK runs the check on the day it is due reports that the check was done usually cannot redesign the check cannot say whether it was enough THE CONTROL OPERATOR IS TOLD WHEN IT GOES WRONG RECEIVES THE NEWS named on the route a crossing travels may be senior, may be junior a role about information, not answers being told answers for nothing THE ESCALATED-TO PERSON MERGE ANY TWO COLUMNS AND THE REGISTER STILL LOOKS COMPLETELY FULL The three roles are drawn generically. No register design is required of any institution, and nothing here is prescribed to anybody.
Answering for an outcome, performing a check and hearing the news are three different jobs, and a register carrying one column for them cannot show which of the three is absent.
Try it out

A risk register at an institution records, against its largest sector exposure, the words wholesale banking. Can a department be a risk owner?

Is the risk owner the person who runs the control?

No, and this is the distinction the rest of this guide turns on. The control operatorThe person who actually performs a control and reports that it was done, who cannot answer for whether the control was enough. performs the check: reconciles the account, reviews the exception list, revalues the collateral, signs the sheet. The operator's work is essential, and it is a different job. An operator can answer for having performed the control and cannot answer for whether the control was capable of catching the thing it was built to catch.

Month 10 at Vindhya Commercial Bank Limited makes the distinction concrete. The collateral valuation feed went stale and stayed stale for 11 working days, and 340 loans were wrongly marked as a result. The bank's own loss record carries the episode as incident I10. Through all 11 of those days the first line of the business was running the control it had been given, and could truthfully report that it had been performed. The control was not built to notice that the arriving numbers were yesterday's, and nobody was answerable for asking whether it was.

The two roles are separated on purpose. If the person answerable for an outcome is also the only person performing the activity, the institution has asked somebody to grade their own homework and given them no standing to change the homework either. The separation puts the design question in front of somebody whose job is the outcome, and who can go and get the control rebuilt.

INCIDENT I10: A CONTROL PERFORMED ON EVERY SINGLE DAY, AND AN OUTCOME NOBODY CAUGHT Both rows describe the same eleven working days in month 10 at the invented bank. Read the top row, then the bottom one. THE CONTROL ACTIVITY, ELEVEN WORKING DAYS 1 2 3 4 5 6 7 8 9 10 11 the same eleven working days, read again below THE OUTCOME OF THOSE ELEVEN WORKING DAYS 340 LOANS WERE WRONGLY MARKED the valuation feed was stale and no monitoring control noticed WHAT THE OPERATOR CAN TRUTHFULLY SAY the control was performed on every day it was due the sheet was signed and the record is complete and every word of that is accurate WHAT NOBODY IN THE ARRANGEMENT SAID whether the control could catch a stale feed at all, which is a question about its design and only an answerable person asks it PERFORMING A CONTROL AND ANSWERING FOR ITS OUTCOME ARE TWO DIFFERENT JOBS Incident I10, the 11 working days, the 340 loans and the feed are Vindhya Commercial Bank Limited's own, invented. No control design is prescribed here.
Eleven days of a control faithfully performed sit directly above eleven days of an outcome nobody caught, and only the second row needs somebody who can be asked about it.
Try it out

The collateral valuation control in process PR3 was being operated by the first line of the business on every one of the 11 working days the feed was stale. Was the operator accountable for the outcome?

Derivatives Foundation Bootcamp — Fin Maverick

If somebody is told about a breach, does that make them the risk owner?

Being told does not make somebody the risk owner. In the invented bank's own breach log the same name appears in both roles inside one year. The escalated-toThe person a crossing is reported to, which is a role about information rather than about answerability. person is whoever a crossing is reported to on detection. Somebody has to be told quickly and by name, and a route with no name on it ends in an inbox nobody reads. Being told is not an answer to who is answerable.

Breach B2 is the case. On month 9 day 2 the net overnight open foreign exchange position reached Rs 276 crore against the bank's own limit L7 of Rs 240 crore, an excess of Rs 36 crore, being 15.0 per cent over the limit. The end of day position report found it, Devendra Achar, the head of treasury, was told that evening, and the position was squared on the morning of day 3. He is on that record as the person informed.

Now read two other rows in the same log. Breach B3, the wholesale funding share crossing limit L10, and breach B4, the depositor concentration crossing limit L12, both record Devendra Achar as risk owner. The same invented person sits in the escalated-to column on one record and in the risk owner column on two others, and a register with a single column called Devendra Achar cannot show which of the three rows is which. They coincide here, and there is no reason why they must.

Try it out

Breach B2's record names Devendra Achar. Breaches B3 and B4 name Devendra Achar. Is that the same entry three times?

What does it take to name somebody properly?

Five things, and a naming missing any one of them is decoration: a person, meaning an individual human being rather than a department; the risk, stated narrowly enough that two people would agree on what it is; the limit it is run against; a date from which the person holds it; and a place the name is written down. A naming that lives only in somebody's memory of a meeting is not a naming at all.

Take away the limit and the naming survives on paper while becoming impossible to fail, and that is the part institutions drop most often. Somebody is answerable for reputational risk, in general, for ever, with no reading anywhere against which that person is doing well or badly. Take away the date and there is no reconstructing who was answerable when the crossing happened. Take away the individual and what remains is the failure covered next.

Here is a complete one at the invented bank. Manjari Sondhi, head of wholesale banking, is the named person for the sector concentration risk, run against limit L3 at 12.0 per cent of gross advances, from month 5, recorded in the breach log. Five parts, one line, all of it checkable by somebody who was not in the room.

FIVE SLOTS IN A NAMING, AND WHAT IS LEFT WHEN THREE OF THEM ARE EMPTY Both rows would print without complaint. Across the slots, the two differ in what can be checked afterwards. A NAMING THAT WORKS 1 THE PERSON Manjari Sondhi head of wholesale banking PRESENT 2 THE RISK sector concentration infrastructure and power PRESENT 3 THE LIMIT limit L3, 12.0 per cent of gross advances PRESENT 4 FROM WHEN from month 5 the month it first crossed PRESENT 5 WRITTEN WHERE the breach log a record, not a memory PRESENT A NAMING THAT DECORATES 1 THE PERSON wholesale banking a department, not a person NOT THERE 2 THE RISK sector concentration the one part that is fine PRESENT 3 THE LIMIT nothing at all so it cannot be failed NOT THERE 4 FROM WHEN ongoing which is not a date NOT THERE 5 WRITTEN WHERE the risk register it is written down PRESENT THREE OF THE FIVE SLOTS EMPTY, AND THE ROW STILL PRINTS WITHOUT COMPLAINT Manjari Sondhi, limit L3 and the two register rows are Vindhya Commercial Bank Limited's own, invented. No register format is required of anybody.
Both rows sit in a register and print identically, and only the upper one lets somebody who was not in the room check whether the naming is being honoured.
Try it out

A register row reads, in full: sector concentration, wholesale banking, ongoing. Which parts of a proper naming are missing?

Debt Capital Markets Bootcamp — Fin Maverick

Why does a name work where a department does not?

Because a department cannot be asked a question and cannot answer one. The point sounds like wordplay and it is the entire mechanism. When the sector concentration is still at 13.0 per cent of gross advances at month 12, seven months after it crossed limit L3 at 12.2 per cent in month 5, somebody has to sit in a meeting and say what has happened and what is being done. Manjari Sondhi is a person and can do that. Head of wholesale banking is a description of a chair. Wholesale banking is a department, and a department has no view, no diary and no obligation.

The everyday version is a rota saying the kitchen is cleaned by everyone. The kitchen never is cleaned, and not because anybody is lazy. An unaddressed instruction lets each person reasonably assume somebody else has it. Write four names against four days and the same four people produce a clean kitchen. The question now has an address.

Naming a department costs something else, and it appears the moment somebody leaves. A department name looks durable and is the fragile option. Nobody notices when the last person who thought it was theirs moves teams. An individual naming visibly breaks when the individual goes, and a visible break gets fixed. Reviewing a register is therefore not clerical work.

Who is the named person for each crossing at this invented bank?

Six limits were crossed at Vindhya Commercial Bank Limited during its twelve numbered months. Manjari Sondhi, head of wholesale banking, is the named person on breach B1, the sector concentration crossing limit L3, and on breach B6, the sub-investment grade share crossing limit L4. Devendra Achar, head of treasury, is named on breaches B3 and B4. Two invented people carry four of the six crossings, being 66.7 per cent, and for breaches B2 and B5 the record names nobody at all.

Read that last clause exactly as it is written. The case record does not name a risk owner for B2 or B5. Not naming is a fact about the record, not a claim that the invented bank appointed nobody, and half of what an outside reader can honestly say about an institution turns on keeping those two statements apart. The record does show one thing worth sitting with. The two crossings with no name recorded are also the only two the record times in days, B2 inside one business day and B5 in two. Orphan riskA risk carried on a register with no named individual against it. hides most easily where the thing resolved itself before anybody needed to ask.

THE SIX CROSSINGS OF THE CASE YEAR, AND THE TWO COLUMNS THAT LOOK ALIKE Read the last two columns together. One name appears in both of them and means something different in each. CROSSING THE LIMIT CROSSED AT MONTH 12 RISK OWNER THE RECORD NAMES ESCALATED TO, IN THE RECORD B1 limit L3, sector concentration still open Manjari Sondhi not recorded B2 limit L7, open currency position closed, 1 day nobody recorded Devendra Achar, month 9 day 2 B3 limit L10, wholesale funding still open Devendra Achar not recorded B4 limit L12, depositor concentration still open Devendra Achar not recorded B5 limit L5, trading book value at risk closed, 2 days nobody recorded not recorded B6 limit L4, sub-investment grade closed, month 9 Manjari Sondhi not recorded Not recorded is a statement about what the case record contains. It is not a claim that the invented bank appointed nobody. 4 OF 6 CARRY A NAMED PERSON, BEING 66.7 PER CENT, AND ONE NAME SITS IN BOTH COLUMNS Breaches B1 to B6, limits L3 to L12 and both named people are Vindhya Commercial Bank Limited's own, invented. No breach record here is real.
Four of the six crossings carry a named person, two carry none in the record, and Devendra Achar appears once as somebody told and twice as somebody answerable.

One line has to be said out loud before anything else. A named person is not a blamed person. Manjari Sondhi is on breach B1 because somebody has to be answerable for the sector concentration, and the position at month 12 follows a decision the board risk management committee G2 took in month 6, which was to accept the excess with a plan running to month 18. Devendra Achar is on breaches B3 and B4 because the funding side of a balance sheet needs an address, and both crossings came from the structure of that balance sheet rather than from anybody doing anything wrong. Naming exists so that somebody can act, not so that somebody can be punished.

Can one name sit above a set of other names?

One name can sit above others, it has to, and the two levels do different work. At Vindhya Commercial Bank Limited, Zoya Kalbagh is the data ownerThe named business person accountable for a data element being right, distinct from the steward who maintains it day to day. for the risk data set as a whole. Beneath that, 147 data elements feed the invented bank's monthly risk report, and 103 of them carry a named owner of their own, being 70.1 per cent. The remaining 44 elements, being 29.9 per cent, have a name above them and no name of their own.

Notice what each level can answer. Accountability over a set of 147 elements is a real job: whether the set is complete, whether the definitions hang together, whether it gets reviewed. Accountability over a set cannot answer whether one element was wrong on one day. Nobody holding 147 elements has one of them in their hands. A name above a set is not a substitute for the names below it, and 44 elements at this invented bank have exactly the accountability that produces.

Keep the data stewardThe person who maintains a data element day to day, usually sitting in the source system rather than in the business. separate from both. The stewards here sit in the source systems and maintain the elements day to day. Maintaining is the operating role in different clothes. Same three questions, same three answers, different vocabulary, and the pattern repeats in every register an institution keeps.

ONE NAME OVER A SET, AND 44 HOLES IN THE LEVEL BENEATH IT Every small square is one risk data element feeding the invented bank's monthly risk report. Count the outlined ones. ZOYA KALBAGH, DATA OWNER FOR THE RISK DATA SET AS A WHOLE answerable for the shape and completeness of the set, and not for any one element on any one day THE 147 RISK DATA ELEMENTS BENEATH HER 103 elements carrying a named owner of their own, being 70.1 per cent 44 with a name above them and none of their own, being 29.9 per cent A NAME OVER 147 CANNOT ANSWER FOR ONE ELEMENT BEING WRONG ON ONE DAY Zoya Kalbagh, the 147 elements and the count of 103 are the invented bank's own. Which elements carry no owner is not recorded, so the 44 are drawn at the end for legibility.
One hundred and three squares are filled and forty four are outlined, and every outlined square is an element whose only accountability sits two levels above it.
Try it out

Zoya Kalbagh is the data owner for the whole risk data set at this invented bank. Does that cover the 44 elements with no owner of their own?

Investment Banking Analyst Bootcamp — Fin Maverick Bond Pricing and Yield Mechanics — free micro-course from Fin Maverick

How is real naming told apart from decorative naming in an institution?

The test is to read more than one register, and to read the number of rows in each before its completeness. Three registers at Vindhya Commercial Bank Limited carry a named person, and together 116 of 162 objects carry one, being 71.6 per cent. The remaining 46 objects have nobody named.

The registerRows in itRows carrying a named personShare
The policy set, PL1 to PL999100.0 per cent
The risk data elements14710370.1 per cent
The breach log, B1 to B66466.7 per cent
All three added together16211671.6 per cent

The register with the perfect score is the one with nine rows in it, and that is not a coincidence. Nine documents, each approved by somebody, each carrying a name in a field the approval process refuses to leave blank. Completeness is cheap where the population is small and the object is created deliberately. The 147 data elements accumulated over years from a dozen source systems, and the 6 crossings appeared unplanned. Naming there has to be maintained rather than established once, and that is where the holes are.

So the diagnostic is not the headline percentage. The diagnostic is the shape of the gap. The analyst asks which register the institution quotes, counts its rows, then asks for the completeness of its largest and messiest population. If the second number is never produced, that silence has taught something without anybody saying anything.

THREE REGISTERS IN ONE INSTITUTION, AND THE SIZE OF EACH POPULATION Read the row count on the left before the bar on the right. The two are related, and not in the direction most readers expect. THE REGISTER SHARE OF ITS OBJECTS CARRYING A NAMED PERSON The policy set, PL1 to PL9 9 rows 9 of 9, being 100.0 per cent The risk data elements 147 rows 103 of 147, being 70.1 per cent The breach log, B1 to B6 6 rows 4 of 6, being 66.7 per cent 3.4 points apart 100 per cent THE REGISTER WITH THE PERFECT NUMBER IS THE ONE WITH NINE ROWS IN IT COMBINED: 9 plus 147 plus 6 = 162 objects, of which 9 plus 103 plus 4 = 116 carry a name, being 71.6 per cent The nine policies, the 147 elements and the six crossings are Vindhya Commercial Bank Limited's own, invented. No completeness level is recommended to anybody.
The three bars are drawn to the same scale, and the one that reaches the dashed line belongs to a population of nine deliberately created documents rather than to either of the two that accumulated without anybody planning them.
Try it out

Across the policy, data and breach registers at this invented bank, how many of the 162 objects carry a named person?

Try it out

Two of the six crossings carry no recorded risk owner, and 44 of the 147 data elements carry none. Before the switches below are touched: which of those two gaps moves the combined naming figure more?

Play with it

Closing the naming gaps in any order, and where the arithmetic lands

Three registers, 162 objects between them, and 46 of those objects carry nobody's name. The switches below work in whichever order they are flipped. Two things are drawn at once: the share of all 162 objects that carry a named person, and the number of the year's limit crossings for which the record names nobody answerable. One switch moves the headline; the other is worth reading for what it actually is.

162 OBJECTS IN THREE REGISTERS, AND THE 46 WITH NOBODY NAMED Filled means the record names a person. Outlined means it does not. The bar at the bottom is all three registers added together. THE POLICY SET, 9 OBJECTS THE BREACH LOG, 6 OBJECTS B1 B2 B3 B4 B5 B6 B2 and B5 carry no recorded risk owner and both of them closed within days THE RISK DATA ELEMENTS, 147 OBJECTS ALL 162 OBJECTS TOGETHER where the record stands today, 71.6 per cent 116 of 162 objects carry a named person, being 71.6 per cent, and 2 of the year's limit crossings name nobody. A policy, a data element and a limit crossing are treated as comparable objects here only to make one reading. They are not equally important, and that is the point. The case records no risk owner for B2 or B5, which is a fact about the record and not a claim that the invented bank appointed nobody.
Objects carrying a name
116 of 162
Combined share
71.6 per cent
Crossings naming nobody
2

Educational illustration. The default reproduces the record exactly as the case holds it: 9 of 9 policies, 103 of 147 risk data elements and 4 of 6 crossings, being 116 of 162 objects, or 71.6 per cent, with 2 of the year's six limit crossings naming nobody. Closing the data register adds 44 names and moves the combined reading 27.2 points, to 160 of 162, being 98.8 per cent. Closing the breach register adds 2 names and moves it 1.2 points, to 118 of 162, being 72.8 per cent. The policy register is already complete and adds nothing at all. The two moves are additive. Since 1.2 plus 27.2 is 28.4, the whole gap, the order they are flipped in cannot change the finishing point. There is no crossing point to find: one contribution is worth 1.2 points and the other 27.2, and neither can ever overtake the other. Which registers are closed is a setting at the bench and is not a figure from the case.

The same readings as static text, so they survive without the switches. Read the last column against the second one, and notice that they rank the two moves in opposite orders.

What is closedObjects named, of 162Combined shareMove from todayCrossings naming nobody
Nothing, which is the record today11671.6 per centnone2
The policy set only11671.6 per cent0.0 points2
The breach log only11872.8 per cent1.2 points0
The risk data set only16098.8 per cent27.2 points2
All three162100.0 per cent28.4 points0

The row that moves the headline by 27.2 points closes 44 numbers in a report, and the row that moves it by 1.2 points closes two limit crossings for which nobody has to answer. A completeness percentage measures how much of a population has been processed. A completeness percentage was never a ranking of what matters, and an institution that manages its naming by watching one number will spend its effort where the arithmetic is loudest.

The failure: a risk with every control in place around it and nobody answerable for the outcome

The collateral valuation control at Vindhya Commercial Bank Limited sits in process PR3. The invented bank had drawn an assurance map across its nine processes PR1 to PR9 and the three lines of defence. The three lines of defence structure belongs to the Institute of Internal Auditors and was restated by them in 2020, and it is taught properly under controls and assurance. Nine processes against three lines gives 27 assurance cellsOne process crossed with one line of defence, which either carries assurance over that process or does not., and exactly 2 of those 27 carried nothing at all: second line over PR5 trade finance, and second line over PR3 collateral management.

Then month 10 arrived. The collateral valuation feed was stale for 11 working days, 340 loans were wrongly marked, and no monitoring control detected any of it. Incident I10 is the record of it. Its net loss was small, Rs 1.4 crore, and the loss figure is the least interesting thing about it. The same control is the invented bank's one material weakness of the year, rated D4 on the bank's own four point scale, and it affects the valuation of Rs 8,640 crore of secured advances. Every part of the arrangement worked except the part that names somebody answerable for the outcome.

Two details make it sharper. The first line was running the control, so the activity was happening and could be evidenced. And in the data dictionary, the collateral valuation element carried a definition, a source system, permitted values, a refresh frequency and its lineage, and did not carry the attribute that says what happens when the value is absent. So when the value stopped arriving, nothing was defined to happen and nothing did, for 11 working days. The assurance map had recorded the hole in advance by leaving that cell blank, and blank cells do not raise themselves.

TWENTY SEVEN CELLS, AND THE TWO WITH NOTHING IN THEM Nine processes across, three lines of defence down. Find the two outlined cells before reading anything else. PR1 PR2 PR3 PR4 PR5 PR6 PR7 PR8 PR9 FIRST LINE SECOND LINE THIRD LINE NOBODY I10 SITS HERE NOBODY I13 SITS HERE The two blank cells are second line over PR3 collateral management, where incident I10 sits, and second line over PR5 trade finance, where incident I13 sits. The map was drawn before either event happened. 2 BLANK CELLS OF 27, AND BOTH WERE FOUND OUT INSIDE THE SAME TWELVE MONTHS Processes PR1 to PR9, incidents I10 and I13 and the assurance map are Vindhya Commercial Bank Limited's own, invented. No assurance structure is required of anybody.
Twenty five cells carry assurance from somebody and two carry nothing, and both of the empty ones sat over processes that produced a serious event inside the same twelve months.
Try it out

Two of the 27 assurance cells carried nothing at all. One sat over PR5 trade finance, where incident I13 produced the year's largest net loss at Rs 15.4 crore. The other sat over PR3 collateral management, where incident I10 produced the year's one material weakness on a net loss of Rs 1.4 crore. What does that pair show about naming?

Forty six objects carry nobody's name. See which register an institution quotes first.

What can naming somebody not achieve?

Naming cannot make a risk smaller, and breach B1 is the proof. The sector concentration crossed limit L3 in month 5 at 12.2 per cent of gross advances against a limit of 12.0 per cent, and has carried a named person, Manjari Sondhi, since that month. At month 12 the reading is 13.0 per cent, being Rs 7,644 crore of infrastructure and power exposure against gross advances of Rs 58,800 crore. The naming was complete throughout, and the number moved away from the limit rather than towards it.

Before that is read as a failure, consider what happened in month 6. The board risk management committee G2 accepted breach B1 as a temporary excess, with a remediation plan running to month 18. Month 6 therefore records an acceptance: a decision taken by the body with the authority to take it, recorded, dated, and carrying a plan with an end. An accepted crossing is one somebody decided about, and it still has a named person on it. The name is what keeps the decision reviewable until it closes.

So two things hold at once. Naming buys an answerable person and an address to send the question to. Naming buys nothing about the size of the exposure, the speed of the remediation or the quality of the decision taken over it. An institution that reads a complete register as evidence of a controlled risk has promoted a filing achievement into a control. The register shows who to ask. The register never shows what the answer will be.

BREACH B1: SEVEN MONTHS WITH A NAMED PERSON, AND THE READING WENT THE OTHER WAY The case records two readings of limit L3 and no others. Everything between them is drawn, not measured. A NAMED PERSON FROM MONTH 5: MANJARI SONDHI 13.0 12.5 12.0 limit L3, 12.0 per cent of gross advances month 6: committee G2 accepted it with a plan running to month 18 12.2 per cent 13.0 per cent 1 2 3 4 5 6 7 8 9 10 11 12 the twelve numbered months of the case year, and the dashed join is a construction between two readings rather than a measured path NAMING DECIDES WHO ANSWERS FOR A RISK, NOT HOW BIG THE RISK IS Breach B1, limit L3, the month 6 acceptance and both readings are Vindhya Commercial Bank Limited's own, invented. No limit or plan length here is required of anybody.
The named person was in place from the first crossing onward, and across the seven months that followed the reading moved further from the limit rather than back inside it.
Try it out

Breach B1 has had a named risk owner since month 5 and the reading went from 12.2 per cent to 13.0 per cent by month 12. Did the naming fail?

How does somebody outside the institution actually use any of this?

Three readers, three uses, and none of them needs anything confidential. A newly appointed independent director is handed a stack of registers in the first week and cannot read them properly. In one afternoon that director can pick the largest register in the pile, ask what share of its rows carry an individual rather than a department, then ask the same of the smallest. The shape of that answer says more about whether naming is maintained than any policy statement will.

An analyst or a lender cannot see the registers at all, and reads the arrangement differently. The analyst listens instead for the level at which accountability is described. When an institution answers a question about a specific exposure with the name of a committee, a function or a department, that is information. Committees decide. Functions run. Neither can be asked, six months later, why the number is where it is, and an institution that only ever speaks at that level may have nobody below it who can be.

And the household version is the most useful of the three. A single financial rule written for a household carries the same five parts. The part a household skips most often is the one thing the invented bank did not do for 44 of its 147 data elements: a check a year later that the person is still there.

India

What is a rule here, and what is one invented bank's own arrangement?

A bank's own arrangement binds nobody outside it. The eight committees G1 to G8, the nine policies PL1 to PL9, the twelve limits L1 to L12, the six crossings B1 to B6, the nine processes PR1 to PR9, the 147 risk data elements, the 27 assurance cells and every person named are Vindhya Commercial Bank Limited's own invented arrangement at its own month 12 reporting date. No naming ratio, register design, committee structure, threshold or effective date here is a fact about any real institution.

For what actually binds a bank operating in India, including anything expected of a board, a board committee, a risk function or the accountability arrangements inside one, the Reserve Bank of India at rbi.org.in is the source and the only source. For the international standards behind capital, liquidity, large exposures and the operational risk event categories, the Basel Committee publishes through the Bank for International Settlements at bis.org, and naming the global standard alone is the common and confident error. For the duties the Companies Act places on a board and on individual directors, including responsibility for internal financial controls, the Ministry of Corporate Affairs at mca.gov.in holds the text, the applicability and the exemptions, with the assurance and audit side from the Institute of Chartered Accountants of India at icai.org. Confirmation on any of these comes from the source itself.

Risk Management Program Bootcamp — Fin Maverick

Where does this record simply say nothing, and why does that matter?

An honest reading of any register separates what is recorded as absent from what is merely not recorded, and this case gives three examples of the second kind. The record names no risk owner for breaches B2 and B5. The record does not say which of the 147 risk data elements are the 44 with no owner of their own. And of the nine policies PL1 to PL9, only PL1, the enterprise risk policy, has a committee named against it. Policy PL8, outsourcing and third party, is the sharpest of those silences: no committee is named for it anywhere in this case, and inventing one would be a fabrication.

The temptation, when something is missing from a governance record, is to fill it in with what would obviously be there. Filling it in destroys the only signal the gap carried. The one reporting line this case locks is that the information security committee G8 reports into the operational risk management committee G6 rather than into the board, and that line is interesting precisely because it is recorded while the others are not. A full chart drawn out of a record holding one line is a chart of assumptions.

The discipline that follows is small and worth practising. Not recorded rather than none. The record names no committee rather than no committee exists. The distinction reads as pedantry until the first time somebody acts on the chart, and then it reads as the only thing done right.

This guide holds one object, the named person, and stops there. What risk appetite, tolerance, capacity and a limit are as words is covered separately and used here on sight, as are the risk register, the taxonomy and the four treatments of a risk, so the acceptance of breach B1 is used here as a record rather than re-explained. Who decides and who oversees, the eight committees themselves, and the calendar they sit on are covered separately; what a policy binds is covered separately too, and the nine policies are named here rather than rebuilt. The charter that appoints a committee, the cascade from an appetite clause into a numbered limit, when a risk must go up and the route it travels are four separate subjects. The three lines of defence, the assurance map as an instrument, control design against operating effectiveness, control testing, the audit finding and issue remediation all belong to controls and assurance; one empty cell is named here as evidence and nothing further. What the eight risk data attributes are, how lineage works and what data governance is belong to risk reporting, data and model risk, and two counts from that set are used here as a record. How a sector concentration, a funding share or an open currency position is measured belongs to credit, liquidity and market risk. Any duty the Companies Act places on a director personally, and anything a regulator expects of an accountability arrangement, belong to Indian markets and regulation; both are named here and neither is stated.

Sources

SourceDocumentSite
Reserve Bank of IndiaWhat actually binds a bank operating in India, including anything expected of a board, a board committee, a risk function or the accountability arrangements inside onerbi.org.in
Bank for International SettlementsThe Basel Committee on Banking Supervision standards behind capital, liquidity, large exposures and the operational risk event categoriesbis.org
Ministry of Corporate AffairsThe Companies Act duties placed on a board and on individual directors, including responsibility for internal financial controls, with the text, applicability and exemptionsmca.gov.in
Institute of Chartered Accountants of IndiaThe assurance and audit standards behind reporting on internal financial controls and a material weaknessicai.org
Institute of Internal AuditorsThe three lines of defence model, restated in 2020, which the assurance map read here is built ontheiia.org

Vindhya Commercial Bank Limited, Manjari Sondhi, Devendra Achar and Zoya Kalbagh are invented.
Educational material. Not advice on any investment, tax, budget or market position.

← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.