The Risk Owner: The Named Person Accountable for a Risk
A risk owner is one named individual who is answerable for a particular risk being run inside its limit, and for what happens when it is not. The word doing the work is named: not a team, not a function, not a job title with nobody in it. Answering for the outcome is one job, operating the control is another, and being told when it goes wrong is a third.
Three separate questions sit on every risk an institution runs, and most registers ask only one. Who is answerable for the outcome. Who performs the control. Who is informed when it goes wrong. Merge any two of the three and the register still looks full. Who has to answer for this has quietly lost its home.
Vindhya Commercial Bank Limited, invented, is a mid-sized Indian commercial bank with a balance sheet of Rs 96,000 crore. Its registers, counts, limits and crossings are all read at its own month 12 reporting date.
The three are merged so easily that the bench below exists to pull them apart. The bench carries the six limit crossings of the case year, three columns against each, and a reading of what each row becomes once the entries are in.
Fill the three columns for the six crossings of the case year, and read what each row becomes
Each row is one limit crossing at the invented bank. Set who answers for the outcome, who runs the control, and who is told when it crosses. Every row then lands in exactly one of five states, and the five counts are added up beneath the drawing so that all six crossings are always accounted for once. The bench opens on the record exactly as this case holds it.
Educational illustration. The bench opens on the record exactly as this case holds it: Manjari Sondhi against B1 and B6, Devendra Achar against B3 and B4, nobody against B2 and B5, a control operator against none of the six, and Devendra Achar named as told on B2. The count is 4 of 6 crossings naming one individual who answers, being 66.7 per cent, and 2 naming nobody. The five states are read in a fixed order and the first one that fits takes the row, so a row belongs to one state and never to two.
Read the record exactly as this case holds it: 4 of the 6 crossings name one individual who answers, being 66.7 per cent, and 2 of them, B2 and B5, name nobody. The record names a control operator against none of the six, so all four named rows read as one name answering with no control recorded. No row is yet in the shape of the central failure: a control run while nobody answers for its outcome. Incident I10 at the invented bank is exactly that failure, and it is set out below. The five states account for the six crossings exactly once: 2 with nobody answerable, 0 with two names answering, 0 answering for a check they run themselves, 4 answering with no control recorded, and 0 answering while somebody else runs it.
The failure is built at the bench by taking row B1, putting the first line of the business into who runs the control, putting a name into who is told, and setting who answers for the outcome back to not recorded. The row then reads nobody answerable, and the count of rows with a control run and nobody answering moves from 0 to 1: a control being run, a person informed, and nobody to ask whether the check could work. The middle button does that to all six rows at once.
What is a risk owner, and what is that person answerable for?
A household has the identical shape, small enough to see whole. Start there. A household of four decides the electricity bill has become too large, everybody agrees, everybody switches something off for a fortnight, and the bill arrives three months later larger again. The conversation that follows goes nowhere because there is nobody it can be addressed to. Now change one thing. One person, by name, is answerable for the bill staying under a stated amount, and may change the geyser timer and bring the meter reading to the table. Nothing about the house changed, and the question stopped being unanswerable.
Naming one person is the whole of it. A risk ownerOne named individual answerable for a particular risk being run inside its limit and for what happens when it is not. is one named individual answerable for one particular risk being run inside the limit set for it. Answerable is narrow and demanding: when the number is outside the limit, that person has to explain what happened, say what is being done, and carry the consequence of the answer being thin. Being accountableAnswerable for the outcome, whether or not the person named performed the activity that produced it. does not mean having performed the activity. Accountability means answering for the outcome of the activity.
Two things follow. The person must have standing to change the arrangement: somebody answerable for a sector concentration who cannot influence what the lending desks write next quarter is a postbox with a title. And a risk owner is attached to a risk rather than to a department. One person may hold several risks, and one risk has exactly one such person. Put two names in that column and who answers has been reopened rather than settled.
A risk register at an institution records, against its largest sector exposure, the words wholesale banking. Can a department be a risk owner?
Is the risk owner the person who runs the control?
No, and this is the distinction the rest of this guide turns on. The control operatorThe person who actually performs a control and reports that it was done, who cannot answer for whether the control was enough. performs the check: reconciles the account, reviews the exception list, revalues the collateral, signs the sheet. The operator's work is essential, and it is a different job. An operator can answer for having performed the control and cannot answer for whether the control was capable of catching the thing it was built to catch.
Month 10 at Vindhya Commercial Bank Limited makes the distinction concrete. The collateral valuation feed went stale and stayed stale for 11 working days, and 340 loans were wrongly marked as a result. The bank's own loss record carries the episode as incident I10. Through all 11 of those days the first line of the business was running the control it had been given, and could truthfully report that it had been performed. The control was not built to notice that the arriving numbers were yesterday's, and nobody was answerable for asking whether it was.
The two roles are separated on purpose. If the person answerable for an outcome is also the only person performing the activity, the institution has asked somebody to grade their own homework and given them no standing to change the homework either. The separation puts the design question in front of somebody whose job is the outcome, and who can go and get the control rebuilt.
The collateral valuation control in process PR3 was being operated by the first line of the business on every one of the 11 working days the feed was stale. Was the operator accountable for the outcome?
If somebody is told about a breach, does that make them the risk owner?
Being told does not make somebody the risk owner. In the invented bank's own breach log the same name appears in both roles inside one year. The escalated-toThe person a crossing is reported to, which is a role about information rather than about answerability. person is whoever a crossing is reported to on detection. Somebody has to be told quickly and by name, and a route with no name on it ends in an inbox nobody reads. Being told is not an answer to who is answerable.
Breach B2 is the case. On month 9 day 2 the net overnight open foreign exchange position reached Rs 276 crore against the bank's own limit L7 of Rs 240 crore, an excess of Rs 36 crore, being 15.0 per cent over the limit. The end of day position report found it, Devendra Achar, the head of treasury, was told that evening, and the position was squared on the morning of day 3. He is on that record as the person informed.
Now read two other rows in the same log. Breach B3, the wholesale funding share crossing limit L10, and breach B4, the depositor concentration crossing limit L12, both record Devendra Achar as risk owner. The same invented person sits in the escalated-to column on one record and in the risk owner column on two others, and a register with a single column called Devendra Achar cannot show which of the three rows is which. They coincide here, and there is no reason why they must.
Breach B2's record names Devendra Achar. Breaches B3 and B4 name Devendra Achar. Is that the same entry three times?
What does it take to name somebody properly?
Five things, and a naming missing any one of them is decoration: a person, meaning an individual human being rather than a department; the risk, stated narrowly enough that two people would agree on what it is; the limit it is run against; a date from which the person holds it; and a place the name is written down. A naming that lives only in somebody's memory of a meeting is not a naming at all.
Take away the limit and the naming survives on paper while becoming impossible to fail, and that is the part institutions drop most often. Somebody is answerable for reputational risk, in general, for ever, with no reading anywhere against which that person is doing well or badly. Take away the date and there is no reconstructing who was answerable when the crossing happened. Take away the individual and what remains is the failure covered next.
Here is a complete one at the invented bank. Manjari Sondhi, head of wholesale banking, is the named person for the sector concentration risk, run against limit L3 at 12.0 per cent of gross advances, from month 5, recorded in the breach log. Five parts, one line, all of it checkable by somebody who was not in the room.
A register row reads, in full: sector concentration, wholesale banking, ongoing. Which parts of a proper naming are missing?
Why does a name work where a department does not?
Because a department cannot be asked a question and cannot answer one. The point sounds like wordplay and it is the entire mechanism. When the sector concentration is still at 13.0 per cent of gross advances at month 12, seven months after it crossed limit L3 at 12.2 per cent in month 5, somebody has to sit in a meeting and say what has happened and what is being done. Manjari Sondhi is a person and can do that. Head of wholesale banking is a description of a chair. Wholesale banking is a department, and a department has no view, no diary and no obligation.
The everyday version is a rota saying the kitchen is cleaned by everyone. The kitchen never is cleaned, and not because anybody is lazy. An unaddressed instruction lets each person reasonably assume somebody else has it. Write four names against four days and the same four people produce a clean kitchen. The question now has an address.
Naming a department costs something else, and it appears the moment somebody leaves. A department name looks durable and is the fragile option. Nobody notices when the last person who thought it was theirs moves teams. An individual naming visibly breaks when the individual goes, and a visible break gets fixed. Reviewing a register is therefore not clerical work.
Who is the named person for each crossing at this invented bank?
Six limits were crossed at Vindhya Commercial Bank Limited during its twelve numbered months. Manjari Sondhi, head of wholesale banking, is the named person on breach B1, the sector concentration crossing limit L3, and on breach B6, the sub-investment grade share crossing limit L4. Devendra Achar, head of treasury, is named on breaches B3 and B4. Two invented people carry four of the six crossings, being 66.7 per cent, and for breaches B2 and B5 the record names nobody at all.
Read that last clause exactly as it is written. The case record does not name a risk owner for B2 or B5. Not naming is a fact about the record, not a claim that the invented bank appointed nobody, and half of what an outside reader can honestly say about an institution turns on keeping those two statements apart. The record does show one thing worth sitting with. The two crossings with no name recorded are also the only two the record times in days, B2 inside one business day and B5 in two. Orphan riskA risk carried on a register with no named individual against it. hides most easily where the thing resolved itself before anybody needed to ask.
One line has to be said out loud before anything else. A named person is not a blamed person. Manjari Sondhi is on breach B1 because somebody has to be answerable for the sector concentration, and the position at month 12 follows a decision the board risk management committee G2 took in month 6, which was to accept the excess with a plan running to month 18. Devendra Achar is on breaches B3 and B4 because the funding side of a balance sheet needs an address, and both crossings came from the structure of that balance sheet rather than from anybody doing anything wrong. Naming exists so that somebody can act, not so that somebody can be punished.
Can one name sit above a set of other names?
One name can sit above others, it has to, and the two levels do different work. At Vindhya Commercial Bank Limited, Zoya Kalbagh is the data ownerThe named business person accountable for a data element being right, distinct from the steward who maintains it day to day. for the risk data set as a whole. Beneath that, 147 data elements feed the invented bank's monthly risk report, and 103 of them carry a named owner of their own, being 70.1 per cent. The remaining 44 elements, being 29.9 per cent, have a name above them and no name of their own.
Notice what each level can answer. Accountability over a set of 147 elements is a real job: whether the set is complete, whether the definitions hang together, whether it gets reviewed. Accountability over a set cannot answer whether one element was wrong on one day. Nobody holding 147 elements has one of them in their hands. A name above a set is not a substitute for the names below it, and 44 elements at this invented bank have exactly the accountability that produces.
Keep the data stewardThe person who maintains a data element day to day, usually sitting in the source system rather than in the business. separate from both. The stewards here sit in the source systems and maintain the elements day to day. Maintaining is the operating role in different clothes. Same three questions, same three answers, different vocabulary, and the pattern repeats in every register an institution keeps.
Zoya Kalbagh is the data owner for the whole risk data set at this invented bank. Does that cover the 44 elements with no owner of their own?
How is real naming told apart from decorative naming in an institution?
The test is to read more than one register, and to read the number of rows in each before its completeness. Three registers at Vindhya Commercial Bank Limited carry a named person, and together 116 of 162 objects carry one, being 71.6 per cent. The remaining 46 objects have nobody named.
| The register | Rows in it | Rows carrying a named person | Share |
|---|---|---|---|
| The policy set, PL1 to PL9 | 9 | 9 | 100.0 per cent |
| The risk data elements | 147 | 103 | 70.1 per cent |
| The breach log, B1 to B6 | 6 | 4 | 66.7 per cent |
| All three added together | 162 | 116 | 71.6 per cent |
The register with the perfect score is the one with nine rows in it, and that is not a coincidence. Nine documents, each approved by somebody, each carrying a name in a field the approval process refuses to leave blank. Completeness is cheap where the population is small and the object is created deliberately. The 147 data elements accumulated over years from a dozen source systems, and the 6 crossings appeared unplanned. Naming there has to be maintained rather than established once, and that is where the holes are.
So the diagnostic is not the headline percentage. The diagnostic is the shape of the gap. The analyst asks which register the institution quotes, counts its rows, then asks for the completeness of its largest and messiest population. If the second number is never produced, that silence has taught something without anybody saying anything.
Across the policy, data and breach registers at this invented bank, how many of the 162 objects carry a named person?
Two of the six crossings carry no recorded risk owner, and 44 of the 147 data elements carry none. Before the switches below are touched: which of those two gaps moves the combined naming figure more?
Closing the naming gaps in any order, and where the arithmetic lands
Three registers, 162 objects between them, and 46 of those objects carry nobody's name. The switches below work in whichever order they are flipped. Two things are drawn at once: the share of all 162 objects that carry a named person, and the number of the year's limit crossings for which the record names nobody answerable. One switch moves the headline; the other is worth reading for what it actually is.
Educational illustration. The default reproduces the record exactly as the case holds it: 9 of 9 policies, 103 of 147 risk data elements and 4 of 6 crossings, being 116 of 162 objects, or 71.6 per cent, with 2 of the year's six limit crossings naming nobody. Closing the data register adds 44 names and moves the combined reading 27.2 points, to 160 of 162, being 98.8 per cent. Closing the breach register adds 2 names and moves it 1.2 points, to 118 of 162, being 72.8 per cent. The policy register is already complete and adds nothing at all. The two moves are additive. Since 1.2 plus 27.2 is 28.4, the whole gap, the order they are flipped in cannot change the finishing point. There is no crossing point to find: one contribution is worth 1.2 points and the other 27.2, and neither can ever overtake the other. Which registers are closed is a setting at the bench and is not a figure from the case.
The same readings as static text, so they survive without the switches. Read the last column against the second one, and notice that they rank the two moves in opposite orders.
| What is closed | Objects named, of 162 | Combined share | Move from today | Crossings naming nobody |
|---|---|---|---|---|
| Nothing, which is the record today | 116 | 71.6 per cent | none | 2 |
| The policy set only | 116 | 71.6 per cent | 0.0 points | 2 |
| The breach log only | 118 | 72.8 per cent | 1.2 points | 0 |
| The risk data set only | 160 | 98.8 per cent | 27.2 points | 2 |
| All three | 162 | 100.0 per cent | 28.4 points | 0 |
The row that moves the headline by 27.2 points closes 44 numbers in a report, and the row that moves it by 1.2 points closes two limit crossings for which nobody has to answer. A completeness percentage measures how much of a population has been processed. A completeness percentage was never a ranking of what matters, and an institution that manages its naming by watching one number will spend its effort where the arithmetic is loudest.
The failure: a risk with every control in place around it and nobody answerable for the outcome
The collateral valuation control at Vindhya Commercial Bank Limited sits in process PR3. The invented bank had drawn an assurance map across its nine processes PR1 to PR9 and the three lines of defence. The three lines of defence structure belongs to the Institute of Internal Auditors and was restated by them in 2020, and it is taught properly under controls and assurance. Nine processes against three lines gives 27 assurance cellsOne process crossed with one line of defence, which either carries assurance over that process or does not., and exactly 2 of those 27 carried nothing at all: second line over PR5 trade finance, and second line over PR3 collateral management.
Then month 10 arrived. The collateral valuation feed was stale for 11 working days, 340 loans were wrongly marked, and no monitoring control detected any of it. Incident I10 is the record of it. Its net loss was small, Rs 1.4 crore, and the loss figure is the least interesting thing about it. The same control is the invented bank's one material weakness of the year, rated D4 on the bank's own four point scale, and it affects the valuation of Rs 8,640 crore of secured advances. Every part of the arrangement worked except the part that names somebody answerable for the outcome.
Two details make it sharper. The first line was running the control, so the activity was happening and could be evidenced. And in the data dictionary, the collateral valuation element carried a definition, a source system, permitted values, a refresh frequency and its lineage, and did not carry the attribute that says what happens when the value is absent. So when the value stopped arriving, nothing was defined to happen and nothing did, for 11 working days. The assurance map had recorded the hole in advance by leaving that cell blank, and blank cells do not raise themselves.
Two of the 27 assurance cells carried nothing at all. One sat over PR5 trade finance, where incident I13 produced the year's largest net loss at Rs 15.4 crore. The other sat over PR3 collateral management, where incident I10 produced the year's one material weakness on a net loss of Rs 1.4 crore. What does that pair show about naming?
What can naming somebody not achieve?
Naming cannot make a risk smaller, and breach B1 is the proof. The sector concentration crossed limit L3 in month 5 at 12.2 per cent of gross advances against a limit of 12.0 per cent, and has carried a named person, Manjari Sondhi, since that month. At month 12 the reading is 13.0 per cent, being Rs 7,644 crore of infrastructure and power exposure against gross advances of Rs 58,800 crore. The naming was complete throughout, and the number moved away from the limit rather than towards it.
Before that is read as a failure, consider what happened in month 6. The board risk management committee G2 accepted breach B1 as a temporary excess, with a remediation plan running to month 18. Month 6 therefore records an acceptance: a decision taken by the body with the authority to take it, recorded, dated, and carrying a plan with an end. An accepted crossing is one somebody decided about, and it still has a named person on it. The name is what keeps the decision reviewable until it closes.
So two things hold at once. Naming buys an answerable person and an address to send the question to. Naming buys nothing about the size of the exposure, the speed of the remediation or the quality of the decision taken over it. An institution that reads a complete register as evidence of a controlled risk has promoted a filing achievement into a control. The register shows who to ask. The register never shows what the answer will be.
Breach B1 has had a named risk owner since month 5 and the reading went from 12.2 per cent to 13.0 per cent by month 12. Did the naming fail?
How does somebody outside the institution actually use any of this?
Three readers, three uses, and none of them needs anything confidential. A newly appointed independent director is handed a stack of registers in the first week and cannot read them properly. In one afternoon that director can pick the largest register in the pile, ask what share of its rows carry an individual rather than a department, then ask the same of the smallest. The shape of that answer says more about whether naming is maintained than any policy statement will.
An analyst or a lender cannot see the registers at all, and reads the arrangement differently. The analyst listens instead for the level at which accountability is described. When an institution answers a question about a specific exposure with the name of a committee, a function or a department, that is information. Committees decide. Functions run. Neither can be asked, six months later, why the number is where it is, and an institution that only ever speaks at that level may have nobody below it who can be.
And the household version is the most useful of the three. A single financial rule written for a household carries the same five parts. The part a household skips most often is the one thing the invented bank did not do for 44 of its 147 data elements: a check a year later that the person is still there.
What is a rule here, and what is one invented bank's own arrangement?
A bank's own arrangement binds nobody outside it. The eight committees G1 to G8, the nine policies PL1 to PL9, the twelve limits L1 to L12, the six crossings B1 to B6, the nine processes PR1 to PR9, the 147 risk data elements, the 27 assurance cells and every person named are Vindhya Commercial Bank Limited's own invented arrangement at its own month 12 reporting date. No naming ratio, register design, committee structure, threshold or effective date here is a fact about any real institution.
For what actually binds a bank operating in India, including anything expected of a board, a board committee, a risk function or the accountability arrangements inside one, the Reserve Bank of India at rbi.org.in is the source and the only source. For the international standards behind capital, liquidity, large exposures and the operational risk event categories, the Basel Committee publishes through the Bank for International Settlements at bis.org, and naming the global standard alone is the common and confident error. For the duties the Companies Act places on a board and on individual directors, including responsibility for internal financial controls, the Ministry of Corporate Affairs at mca.gov.in holds the text, the applicability and the exemptions, with the assurance and audit side from the Institute of Chartered Accountants of India at icai.org. Confirmation on any of these comes from the source itself.
Where does this record simply say nothing, and why does that matter?
An honest reading of any register separates what is recorded as absent from what is merely not recorded, and this case gives three examples of the second kind. The record names no risk owner for breaches B2 and B5. The record does not say which of the 147 risk data elements are the 44 with no owner of their own. And of the nine policies PL1 to PL9, only PL1, the enterprise risk policy, has a committee named against it. Policy PL8, outsourcing and third party, is the sharpest of those silences: no committee is named for it anywhere in this case, and inventing one would be a fabrication.
The temptation, when something is missing from a governance record, is to fill it in with what would obviously be there. Filling it in destroys the only signal the gap carried. The one reporting line this case locks is that the information security committee G8 reports into the operational risk management committee G6 rather than into the board, and that line is interesting precisely because it is recorded while the others are not. A full chart drawn out of a record holding one line is a chart of assumptions.
The discipline that follows is small and worth practising. Not recorded rather than none. The record names no committee rather than no committee exists. The distinction reads as pedantry until the first time somebody acts on the chart, and then it reads as the only thing done right.
Sources
| Source | Document | Site |
|---|---|---|
| Reserve Bank of India | What actually binds a bank operating in India, including anything expected of a board, a board committee, a risk function or the accountability arrangements inside one | rbi.org.in |
| Bank for International Settlements | The Basel Committee on Banking Supervision standards behind capital, liquidity, large exposures and the operational risk event categories | bis.org |
| Ministry of Corporate Affairs | The Companies Act duties placed on a board and on individual directors, including responsibility for internal financial controls, with the text, applicability and exemptions | mca.gov.in |
| Institute of Chartered Accountants of India | The assurance and audit standards behind reporting on internal financial controls and a material weakness | icai.org |
| Institute of Internal Auditors | The three lines of defence model, restated in 2020, which the assurance map read here is built on | theiia.org |
Vindhya Commercial Bank Limited, Manjari Sondhi, Devendra Achar and Zoya Kalbagh are invented.
Educational material. Not advice on any investment, tax, budget or market position.
