The Risk Policy: The Document That Binds Practice
A risk policy is the document that fixes how one kind of risk is to be run, and it binds practice from the day somebody with the authority approves it. The document names a policy owner, an approver, a review cycle and the limits it cascades into. A policy is a rule about behaviour rather than a description of one, and it works in one direction only: forward.
A policy is a promise about the future written in the present tense, and that single grammatical fact explains everything the document can and cannot do. A policy can require a validation cycle from the day it is signed. The same policy cannot reach the models that were already running when somebody signed it. A promise written in the present tense binds the future and leaves the past exactly as it was, and one set of nine policies shows what that costs.
Vindhya Commercial Bank Limited, invented, is a mid-sized Indian commercial bank with a balance sheet of Rs 96,000 crore. Every policy, approval month, trigger, limit and count below is the bank's own internal arrangement, read at its own month 12 reporting date. No authority anywhere requires any of them, and the real expectations for a bank in India sit with the Reserve Bank of India.
What is a risk policy, and what does it actually do?
At household scale the shape is identical and all of it is visible at once. A household runs on one salary and keeps deciding, every week, whether the second-hand scooter can wait another month. One evening somebody writes four lines on the back of an envelope: nothing above a stated amount is bought without both of them agreeing, the amount is reviewed every Diwali, the person who keeps the accounts is the one who has to bring it up, and anything above twice that amount waits for the year-end bonus. The four lines are a policy. The envelope is short, it is boring, and from the evening it was written the household argues about a different thing than it argued about before.
Notice what changed and what did not. Nothing about the household's income moved. Nobody learned anything new about scooters. The change is that a decision which used to be taken fresh every week is now read off a written rule, and the reading is the same whoever is tired that evening. A risk policyThe document that fixes how one kind of risk is to be run, binding practice from the date it is approved. does exactly that at institutional scale. An institution writes one because certain behaviours are too consequential to settle case by case, so it puts down in advance what is to be done, and hands the writing to a body with enough authority to make it stick.
A policy is therefore not a description. Plenty of documents in any institution describe how work is currently done, and every one of them is useful and none of them binds anybody. The test is simple and it is worth applying out loud: after this document exists, is there somebody who must now do something they were not required to do before? If the answer is no, the document is a description, a summary or a record, and calling it a policy does not change what it is.
Which four parts is a policy load bearing on?
Any risk policy anywhere is mostly prose, and almost all of it is elaboration. Four things in it are structural. There is a policy ownerThe named person accountable for the policy being right and current, who is not the person who signs it., a named person accountable for the document being right and current. There is an approverThe body whose authority makes the policy binding, which for the enterprise risk policy at this invented bank is the board., the body whose authority makes it binding. There is a review cycleThe stated interval at which the policy must be looked at again whether or not anything has changed., an interval at which the thing gets read again. And there are the limits it cascades into, the sentences that turn into numbers somebody is measured against.
Taking away any one of the four stops the document working in a specific, predictable way. The four are worth memorising; the table of contents is not. Without the owner nobody is accountable for it being wrong. Without the approver nothing made it binding. Without the review cycle it ages quietly on a shared drive, still approved and slowly describing an institution that no longer exists. Without the cascade nothing measurable ever follows from it, so no report on earth can show whether it is being complied with. Each of Vindhya Commercial Bank Limited's nine policies names all four, and that is what makes each of them a policy rather than a paper.
A document sets out how the bank runs its collateral, names a head of credit risk as accountable for it, is approved by a board committee, and says it will be read again at a stated interval. Which of the four load-bearing parts is still missing?
Why is the person who maintains a policy not the person who signs it?
At Vindhya Commercial Bank Limited the enterprise risk policy PL1 sits with the chief risk officer, Sunanda Ravikumar, and the board, committee G1, approves it. Two people, two entirely different jobs, and the separation is deliberate. The policy owner is answerable for the document being right and current: for the wording being accurate, for it coming back at the review cycle, for somebody noticing when the business it describes has changed shape. The approver does none of that work, and supplies instead the one thing the owner cannot: authority the document does not have on its own.
Collapsing the two shows what is at stake. The head of a trading desk writes the market risk policy, and the head of the same trading desk approves it. Nothing in the text needs to change for the document to have quietly stopped being a rule. The document has become a statement of intent by the person it was written to constrain, revisable by that person on any morning when the constraint is inconvenient. Self-approval is precisely the arrangement a policy exists to prevent, and the approver is therefore always further from the risk than the owner is.
The everyday version is the housing society again. One resident can write the rule about parking. If that same resident also approves it, the other flats have not agreed to anything; they have been told something. The signature has to come from somewhere the writer does not control, or the writing does no work at all.
The chief risk officer is the policy owner of the enterprise risk policy and the board approves it. Why not have one of them do both?
How do a policy, a standard and a procedure differ?
Three documents, three altitudes, and one test that separates them cleanly: who is the sentence addressed to? A policy addresses the institution and says this is how this risk is to be run. A standardThe layer below a policy, saying what good enough looks like in a particular area. addresses a function and says this is what good enough looks like here. A procedureThe layer below a standard, saying what a named person actually does, in order. addresses a person and says do this, then this.
The reason the three layers are kept apart is not tidiness, it is the cost of changing each one. A policy changes only when the approver approves it again, and at this invented bank that means getting on a board agenda. A standard changes inside the function that holds it. A procedure changes when the desk is rearranged. Writing the procedure into the policy means taking the seating plan of a dealing room to the board, so either the board approves trivia or, far more likely, nobody bothers and the policy is wrong within a quarter. A document that mixes all three altitudes gives everybody something to ignore, and once a reader has learned to skip one paragraph they have learned to skip the document.
A document says a dealer must enter the trade in the system before leaving the desk. Policy, standard or procedure?
How does a policy reach a number somebody is measured against?
Compliance needs something countable, so a policy that only states an intent cannot be complied with at all. The bridge is a single line of text, and it is worth learning to look for it. Call it the cascade sentenceThe line in a policy that turns a rule into a numbered limit somebody is measured against.: the sentence in the document that hands a number to somebody else to set and then to monitor. Everything above that line is language. Everything below it is a report.
Follow one at Vindhya Commercial Bank Limited. The bank's own market risk policy, PL3 in its set of nine, says the trading book is run inside a value at risk limit. The sentence binds nobody on its own, and it does not need to. The sentence hands off. Limit L5 is what it hands to: one day, 99 per cent, measured on the bank's own historical simulation, Rs 18.0 crore, all of which is this invented bank's own arrangement. The position is then measured against Rs 18.0 crore every day and read at committee G7. In month 3, on days 21 and 22, the measured figure came in at Rs 19.2 crore and Rs 18.6 crore, and because a sentence had become a number, the crossing was a fact rather than an argument.
What does a policy buy by writing its own trigger before the event?
Here is the same machinery doing its best work. The bank's own policy on its trading book does not stop at naming a limit. The policy says what happens at particular counts: at five backtesting exceptions in 250 days the matter goes to the market risk committee G7, and at seven a model review is forced. Both numbers were written down while the year was still quiet and nobody knew what the count would be.
Over the 250 observation days, seven exceptions were observed, numbered X1 to X7, being 2.8 per cent of days against the 1.0 per cent the bank's own 99 per cent measure implies. Read the sequence and watch the policy work twice. The fifth, X5 in month 9, made the escalation automatic. The seventh, X7 in month 11, forced the review. The institution had already answered whether seven was a lot, in a room where nothing was at stake. Nobody had to argue about it when the seventh arrived.
The same policy written the other way reads: the committee will consider whether the exception count is elevated and take appropriate action. Every word of that is defensible and it decides nothing. The count arrives, the discussion begins from zero, and the person whose desk produced the exceptions is in the room explaining why this particular seven is different. A trigger written in advance converts a judgement made under pressure into a number read off a written rule, and that conversion is most of what a policy is for.
Seven backtesting exceptions were observed in 250 days. Why did nobody at the invented bank have to argue about whether seven was a lot?
Which arrangements are the bank's own, and where the binding version lives
The nine policies PL1 to PL9, the month 4 approval of PL6, the five and seven exception triggers, limit L5 at Rs 18.0 crore, the twelve month validation cycle and every count of models, categories and months are Vindhya Commercial Bank Limited's own choices. An institution picks its own review cycles, thresholds and triggers, so no review cycle, threshold, trigger or approval date carries across from one bank to another.
The international standards behind capital, liquidity, large exposures, interest rate risk in the banking book and the treatment of a backtesting exception count come from the Basel Committee on Banking Supervision at the Bank for International Settlements, bis.org. A standard is where an idea was defined and it is not what binds anybody.
The rules that actually bind a bank operating in India, including anything expected of a risk policy, a policy approval, a review cycle, an outsourcing arrangement or a risk function, come from the Reserve Bank of India at rbi.org.in. Where the duties of a board and its individual directors are the subject, including responsibility for internal financial controls, those sit in the Companies Act, whose text, applicability and exemptions come from the Ministry of Corporate Affairs at mca.gov.in, with the assurance and audit side from the Institute of Chartered Accountants of India at icai.org. Confirm every requirement at source before relying on it.
What does a whole set of policies look like at one bank?
Vindhya Commercial Bank Limited holds nine, numbered PL1 to PL9, and the shape of the set is worth reading before any single document in it. PL1 is the enterprise risk policy and sits above the others. PL2 to PL6 are named for one kind of risk each: credit, market, liquidity, operational and model. PL7, PL8 and PL9 are named for subjects rather than for a kind of risk: information security, outsourcing and third party, and business continuity. Each of the nine names an owner, an approver, a review cycle and the limits it cascades into, so on the four load-bearing parts the set reads 9 of 9, being 100.0 per cent.
| Policy | What it is named for | What the bank's own record adds against it |
|---|---|---|
| PL1 | Enterprise risk | The policy owner is the chief risk officer, Sunanda Ravikumar; the approver is the board, committee G1 |
| PL2 | Credit risk | Nothing beyond the four parts |
| PL3 | Market risk | The trading book limit and the five and seven exception triggers cascade from here |
| PL4 | Liquidity risk | Nothing beyond the four parts |
| PL5 | Operational risk | Nothing beyond the four parts |
| PL6 | Model risk | Approved in month 4, requires a validation cycle, and models V1, V2 and V3 predate it |
| PL7 | Information security | Nothing beyond the four parts |
| PL8 | Outsourcing and third party | No committee is named for this policy anywhere in the record |
| PL9 | Business continuity | Nothing beyond the four parts |
| 9 policies | All four parts present in each | 9 of 9, being 100.0 per cent |
Two things in that table are worth pausing on, and both are about what is absent rather than what is written. The first is PL8. The bank's record names a committee against PL1 and against no other policy in the set, and for outsourcing and third party in particular no body is named anywhere at all. The honest reading is that the gap exists, and anybody holding the real set would go and find out which body fills it.
The second is that the record carries no approval month for eight of the nine and no length for any review cycle. Only PL6 has a date, month 4, and that single date is what the rest of this guide turns on.
What happens to practice that already existed on the day the policy was approved?
PL6 is the model risk policy and it was approved in month 4. Nothing about it is deficient. PL6 names a policy owner, it names an approver, it names a review cycle, and it cascades into a requirement that models be validated on the bank's own twelve month cycle. From month 5 onward the institution ran with a model risk policy in force. Months 1 to 4 ran without one, so 4 of the 12 months, being 33.3 per cent, sat outside it, and 8 of the 12, being 66.7 per cent, sat inside.
Now go and look at what the policy landed on. At month 12 the bank holds 28 registered models: 19 validated and current, 6 overdue, and 3 that have never been validated at all, being 10.7 per cent of the 28. The three unvalidated models carry the numbers V1, V2 and V3. V1 is the behavioural deposit life model. The model sets the 0.5 year assumption on Rs 36,000 crore of non-maturity deposits, and that one assumption decides the sign of the bank's headline interest rate risk number, moving it from minus Rs 840 crore to plus Rs 240 crore across the range of lives the bank could reasonably assume. V2, the collateral haircut model, sets the 35.0 per cent haircut used on eligible collateral. V3 is a spreadsheet early warning scorecard maintained by one person with no documented specification.
All three predate month 4, and that single fact is the whole lesson: eight months of a policy that requires a validation cycle have passed over them and moved none of them. Not because anybody ignored PL6. Because PL6 created a cycle going forward, and running that cycle against what was already in the building is a separate act that nobody was asked to perform.
PL6 was approved in month 4 and requires a validation cycle. Before the control below is touched: how many of the twelve months does it govern, and how many of the three models that were already running does it reach?
Give the policy a grace period and watch which line refuses to move
Institutions often soften a new policy by giving existing practice a stated period before it bites. Moving the dial draws two things at once: the months of the year PL6 actually governs, and the number of registered models it can never reach. One of them responds to the setting. The other one does not.
Educational illustration. The default reproduces what this invented bank actually did: no grace period at all, policy PL6 approved in month 4, 8 of the 12 months governed, being 66.7 per cent of the year, and 3 registered models out of reach, being V1, V2 and V3, or 10.7 per cent of the 28 models on the register at month 12. The length of the grace period is set on the dial and is not a figure from the case. A grace period changes when a policy starts to bite and changes nothing at all about what came before it, so the count of three does not depend on the dial. Two months of grace puts the governed share at exactly 50.0 per cent, and five months makes the two lines meet at three. The meeting is a coincidence of counts and not two quantities agreeing.
The same readings as static text, so they survive without the control. Read down the first column and the second, then look at the third and notice that it never changes.
| Months of grace | Months of 12 governed by PL6 | Share of the year | Registered models out of reach |
|---|---|---|---|
| 0, the setting PL6 had | 8 | 66.7 per cent | 3 |
| 2 | 6 | 50.0 per cent | 3 |
| 5 | 3 | 25.0 per cent | 3 |
| 8 and beyond | 0 | 0.0 per cent | 3 |
| Every setting from 0 to 12 | falls one for one | falls with it | 3, always |
The flat line is the teaching, and the crossing at five months of grace is the trap. At five, the months governed reads three and the models out of reach reads three, and the two lines touch. Nothing has agreed with anything. One line counts months and the other counts models, and two lines meeting on a chart is a coincidence of units. Being able to say that out loud while looking at the picture is the habit that stops a great many wrong readings of a great many charts.
What does the missing sentence actually cost?
A complete policy, correctly approved, that reached nothing it most needed to reach
Read PL6 against the four load-bearing parts and it passes on every one. PL6 names a policy owner. PL6 names an approver. PL6 names a review cycle. PL6 cascades into a stated validation requirement, and a stated validation requirement is exactly the measurable consequence a policy is supposed to produce. PL6 has been in force for 8 of the 12 months. On any register of policies, PL6 shows as current, complete and compliant.
Now read the model inventory at month 12. Of the 28 registered models, 3 have never been validated, being 10.7 per cent, and the model that decides the sign of the bank's headline interest rate risk number is one of the three. Nobody broke PL6. The failure is that nobody asked the one question a new policy always raises: what happens to everything that was already running on the day it was signed. The unasked question has a name worth keeping: the transition sentenceThe line that says what happens to practice that already existed on the day the policy was approved.. PL6 does not carry one.
Notice how quietly this fails. A policy with no transition sentence does not produce an incident, a breach or a control finding. The policy sits in the register, approved and current. The three things it most needed to reach carry on exactly as before, and at month 12 the inventory reports 3 of 28 never validated as though that were a routine ageing statistic. An ageing statistic is a fact about a queue; this is a fact about a policy that was never pointed at the past, and only the approval month tells the two apart. The fix costs one sentence, and it has to be written before approval. After approval the same sentence is an admission.
PL6 has been in force for eight months and three models have still never been validated. What was missing from the document?
How can a missing policy be spotted in a set of nine?
Here is a question the set cannot answer from inside itself. Nine documents, each complete, each approved, each with an owner and a cycle. Is anything absent? A document cannot report a subject nobody wrote about, so reading the nine settles nothing. A gap in a policy set is never visible from inside the set; it becomes visible only when the set is read against the list it is supposed to cover.
The bank publishes its own risk taxonomy with seven level one categories, numbered TX1 to TX7: credit, market, liquidity and funding, operational, compliance and conduct, strategic and business, and reputational. Lay the nine policies against those seven. PL2 answers to TX1, PL3 to TX2, PL4 to TX3 and PL5 to TX4. Then the pointing stops. Nothing in the set is named for TX5 compliance and conduct risk, nothing for TX6 strategic and business risk and nothing for TX7 reputational risk, being 3 of the 7 categories, or 42.9 per cent. All three are reached by PL1 the enterprise risk policy, and only in the way that a policy about everything reaches everything.
The other three documents need care. PL7 information security, PL8 outsourcing and third party and PL9 business continuity are named for subjects rather than for a level one category, and the record asserts no category for any of the three. The record places only model risk, under operational risk, and that placement is this institution's choice rather than a law. The record names no committee for PL8 and no category for PL9.
How can a missing policy be spotted in a set of nine that all look complete?
Where does a policy set sit in an institution's internal control?
The five component structure of internal control belongs to the Committee of Sponsoring Organizations of the Treadway Commission, published in 1992 and updated in 2013, and the attribution matters because the structure is used everywhere and credited almost nowhere. Its components are the control environment, risk assessment, control activities, information and communication, and monitoring activities. The control environment is the first of the five and the one the other four rest on.
Readers usually treat the control environment as the soft one: tone at the top, culture, the way people behave when nobody is looking. The soft reading is not wrong and it is not usable. The policies are the part of the control environment that has been written down, given a named owner and signed by somebody. Seeing a control environment rather than talking about one means going and reading the policy set. Nine documents with nine owners, nine approvers and nine review cycles is a control environment that can be held in the hand and audited line by line. Everything else in the component is inference.
The month 4 problem sits in that same first component, and the placement is why it costs so much. There is no control to test, so a weakness in the control environment never shows up as a failed control test. The weakness shows up instead as three models sitting quietly outside a cycle, in the component the other four are standing on.
Whose is the five component structure of internal control, and which component does a policy set mostly sit in?
What can a policy not do?
Three things, and each of them is a way institutions lose a year. A policy cannot perform the work it requires. PL6 requires a validation cycle. Approving a rule and running the cycle the rule creates are two separate jobs, and only the first one produces a document with a date on it. Eight months of PL6 passed over V1, V2 and V3 and validated none of them.
A policy cannot close a breach. A policy can say what counts as one, who must be told and how fast, and saying so is worth a great deal. Bringing an exposure back inside a limit takes somebody selling something, refusing something or renegotiating something, and no document does any of the three. A rule can make a fact visible and cannot make the fact smaller.
And a policy cannot make anybody read it. Of the three, the last is the least discussed and the most expensive. The document that binds practice binds it through people who have usually seen a summary once. A cascade into a small number of limits therefore matters far more than the length of the text. A number on a monthly report is read by people who have never opened the policy that produced it, and that is the policy working exactly as designed.
Would approving a better written version of PL6 have validated model V1?
What does somebody outside the risk function do with any of this?
Three readers, three uses, and none of them requires access to anything confidential. A newly appointed independent director is handed a set of policies in the first week and cannot possibly read them properly. A new director can still do three things in an afternoon: check the four load-bearing parts on each policy, ask which body approved each, and ask for the approval month of the most recent one. The last question is the sharp one. An approval month identifies every policy young enough to have practice sitting behind it.
An analyst or a lender assessing an institution reads the same set differently. An outsider cannot verify culture and should not try. The same outsider can ask which risk categories in the institution's own taxonomy have a policy named for them and which do not, and a gap of 3 in 7 is a specific, answerable question rather than a general impression. The absence of a document is one of the very few things about an institution's internal workings that an outsider can establish cleanly.
And the household version stays useful. One rule written for household spending needs the four parts. Who is accountable for the rule being current. Who has to agree before it changes. When it gets read again. And the one number it produces. A rule with no number is a mood. Then the fifth line the bank forgot: what happens to the commitments already made before the rule was written.
Sources
| Source | Document | Site |
|---|---|---|
| Reserve Bank of India | What actually binds a bank operating in India, including anything expected of a risk policy, its approval, its review cycle, an outsourcing arrangement or a risk function | rbi.org.in |
| Bank for International Settlements | The Basel Committee on Banking Supervision standards behind capital, liquidity, large exposures, interest rate risk in the banking book and the treatment of a backtesting exception count | bis.org |
| Ministry of Corporate Affairs | The Companies Act duties placed on a board and its individual directors, including responsibility for internal financial controls, with the text, applicability and exemptions | mca.gov.in |
| Institute of Chartered Accountants of India | The assurance and audit standards behind reporting on internal financial controls | icai.org |
| Committee of Sponsoring Organizations of the Treadway Commission | Internal Control - Integrated Framework, 1992 and updated 2013, where the five component structure of internal control is defined | coso.org |
Vindhya Commercial Bank Limited is invented.
Educational material. Not advice on any investment, tax, budget or market position.
