Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Risk Management Program · CoreTrack
1Risk, Treasury & Financial Control
iRisk Foundations
Risk Appetite, Tolerance, Capacity…The Risk Taxonomy and UniverseRisk Register vs Risk MatrixStress TestingScenario Analysis vs Stress TestingImpact and LikelihoodLikelihoodThe Risk EventRisk Assessment
iiEnterprise Risk Management
Enterprise Risk ManagementThe Four Risk TreatmentsRisk CultureRisk MaturityRisk Monitoring
iiiRisk Governance
Risk GovernanceHow to set a…The Risk PolicyThe Risk OwnerThe Risk Committee and Its CharterThe Risk Limit FrameworkRisk EscalationHow to set a…
ivCredit and Counterparty Risk
Collateral AgreementsCollateral vs NettingProbability of DefaultExposureCounterparty ExposureConcentration Risk vs Wrong Way RiskCounterparty Risk vs Credit RiskHow to assess Counterparty ExposureHow to assess Concentration Risk
vMarket Risk
Market RiskSensitivity MeasuresThe Hedging PolicyInterest Rate Risk in the Banking BookIRRBB vs Market RiskExpected ShortfallEconomic Value of EquityVaR BacktestingOpen PositionValue at RiskValue at Risk and Expected ShortfallEconomic Value SensitivityFX ExposureValue at Risk vs Expected ShortfallEarnings at Risk vs…FX Transaction Risk vs…How to measure Interest…How to measure Foreign…
viLiquidity Risk
Liquidity Stress TestingLiquidity Gap vs Liquidity BufferMaturity MismatchThe Debt Maturity ProfileFunding ConcentrationSurvival HorizonThe Contingency Funding PlanNet Stable Funding RatioLiquidity Risk vs Funding RiskLiquidity Coverage RatioLiquidity Gap and BufferHow to run a Liquidity Gap Analysis
viiOperational Risk
Operational LossThe Loss EventRisk and Control Self AssessmentException ManagementInformation Security as a…Segregation of DutiesIssue ManagementThe Near MissRoot Cause Analysis in RiskThe Fraud TriangleCyber Risk vs Third Party RiskHow to run a…How to assess Third…
viiiRisk Reporting, Data and Model Risk
Model RiskModel Validation vs BacktestingHow to run Model ValidationData Governance in RiskModel Risk vs Data RiskKey Risk IndicatorsManagement InformationRisk ReportingRisk ScoreEarnings at RiskRisk Adjusted ReturnEarly Warning IndicatorsHow to build a KRI Dashboard
ixTreasury
Corporate TreasuryAsset Liability ManagementIntragroup FundingThe Treasury PolicyThe Treasury Management SystemThe Cash ForecastCash Pooling and ConcentrationHow to build a Cash Forecast
xFinancial Controls and Assurance
Control AssuranceThe Control LifecycleThe Assurance MapThe Audit FindingIssue RemediationInternal Financial ControlsControl Design vs Control EffectivenessHow to map Internal Financial ControlsHow to test Control…Control DeficiencyMaterial Weakness
xiOperational Resilience
Operational ResilienceBusiness Continuity and Disaster RecoveryBusiness Continuity vs Operational…Crisis ManagementDisaster RecoveryIncident Management

The Risk Policy: The Document That Binds Practice

A risk policy is the document that fixes how one kind of risk is to be run, and it binds practice from the day somebody with the authority approves it. The document names a policy owner, an approver, a review cycle and the limits it cascades into. A policy is a rule about behaviour rather than a description of one, and it works in one direction only: forward.

A policy is a promise about the future written in the present tense, and that single grammatical fact explains everything the document can and cannot do. A policy can require a validation cycle from the day it is signed. The same policy cannot reach the models that were already running when somebody signed it. A promise written in the present tense binds the future and leaves the past exactly as it was, and one set of nine policies shows what that costs.

Vindhya Commercial Bank Limited, invented, is a mid-sized Indian commercial bank with a balance sheet of Rs 96,000 crore. Every policy, approval month, trigger, limit and count below is the bank's own internal arrangement, read at its own month 12 reporting date. No authority anywhere requires any of them, and the real expectations for a bank in India sit with the Reserve Bank of India.

What is a risk policy, and what does it actually do?

At household scale the shape is identical and all of it is visible at once. A household runs on one salary and keeps deciding, every week, whether the second-hand scooter can wait another month. One evening somebody writes four lines on the back of an envelope: nothing above a stated amount is bought without both of them agreeing, the amount is reviewed every Diwali, the person who keeps the accounts is the one who has to bring it up, and anything above twice that amount waits for the year-end bonus. The four lines are a policy. The envelope is short, it is boring, and from the evening it was written the household argues about a different thing than it argued about before.

Notice what changed and what did not. Nothing about the household's income moved. Nobody learned anything new about scooters. The change is that a decision which used to be taken fresh every week is now read off a written rule, and the reading is the same whoever is tired that evening. A risk policyThe document that fixes how one kind of risk is to be run, binding practice from the date it is approved. does exactly that at institutional scale. An institution writes one because certain behaviours are too consequential to settle case by case, so it puts down in advance what is to be done, and hands the writing to a body with enough authority to make it stick.

A policy is therefore not a description. Plenty of documents in any institution describe how work is currently done, and every one of them is useful and none of them binds anybody. The test is simple and it is worth applying out loud: after this document exists, is there somebody who must now do something they were not required to do before? If the answer is no, the document is a description, a summary or a record, and calling it a policy does not change what it is.

THREE DOCUMENTS THAT LOOK ALIKE ON A SHELF AND DO ENTIRELY DIFFERENT WORK Apply one test to each: after it exists, must somebody now do something they were not required to do before? A NOTE THAT DESCRIBES PRACTICE this is how the desks currently work written by whoever knows the process true on the day it was written BINDS NOBODY useful, and not a rule A POLICY THAT REQUIRES PRACTICE this is how this risk is to be run approved by a body with the authority true from the day it is approved, onwards BINDS FROM ITS DATE the only one of the three that is a rule A RECORD OF WHAT HAPPENED this is what was done last month produced after the fact evidence, and it changes nothing BINDS NOBODY essential, and still not a rule ONLY THE MIDDLE DOCUMENT CHANGES WHAT ANYBODY HAS TO DO TOMORROW The three documents are drawn generically. Nothing here is a requirement of anybody, and no document type is prescribed to any institution.
A description, a rule and a record can sit on the same shelf in the same binding, and only the rule alters what somebody is obliged to do the following morning.

Which four parts is a policy load bearing on?

Any risk policy anywhere is mostly prose, and almost all of it is elaboration. Four things in it are structural. There is a policy ownerThe named person accountable for the policy being right and current, who is not the person who signs it., a named person accountable for the document being right and current. There is an approverThe body whose authority makes the policy binding, which for the enterprise risk policy at this invented bank is the board., the body whose authority makes it binding. There is a review cycleThe stated interval at which the policy must be looked at again whether or not anything has changed., an interval at which the thing gets read again. And there are the limits it cascades into, the sentences that turn into numbers somebody is measured against.

Taking away any one of the four stops the document working in a specific, predictable way. The four are worth memorising; the table of contents is not. Without the owner nobody is accountable for it being wrong. Without the approver nothing made it binding. Without the review cycle it ages quietly on a shared drive, still approved and slowly describing an institution that no longer exists. Without the cascade nothing measurable ever follows from it, so no report on earth can show whether it is being complied with. Each of Vindhya Commercial Bank Limited's nine policies names all four, and that is what makes each of them a policy rather than a paper.

THE FOUR PARTS A POLICY CANNOT WORK WITHOUT, AND WHAT EACH ONE IS HOLDING UP Left, the document. Right, what is left standing if that band is taken out of it. 1 THE NAMED POLICY OWNER the person accountable for this document being right and current, named by role and by name STRIP IT AND nobody is accountable for the document being wrong, and a wrong policy is a great deal worse than no policy at all 2 THE NAMED APPROVER the body whose authority makes it binding, which for the enterprise risk policy PL1 is the board G1 STRIP IT AND nothing made it binding, so what is left is a strong opinion circulated by the people it was meant to bind 3 THE REVIEW CYCLE the stated interval at which it is read again, whether or not anything has changed STRIP IT AND it ages quietly: still approved, still filed, and slowly describing an institution that no longer exists 4 THE LIMITS IT CASCADES INTO the sentences that become numbered limits somebody is measured against every month STRIP IT AND nothing measurable follows from it, so no report ever shows whether the policy is being complied with FOUR PARTS. TAKE AWAY ANY ONE AND WHAT IS LEFT CANNOT BE ENFORCED, REVIEWED OR MEASURED Policy PL1 and committee G1 are Vindhya Commercial Bank Limited's own, invented. No structure here is required of any institution.
Strip the owner and accountability goes, strip the approver and authority goes, strip the cycle and currency goes, and strip the cascade and nothing measurable is left behind.
Try it out

A document sets out how the bank runs its collateral, names a head of credit risk as accountable for it, is approved by a board committee, and says it will be read again at a stated interval. Which of the four load-bearing parts is still missing?

Why is the person who maintains a policy not the person who signs it?

At Vindhya Commercial Bank Limited the enterprise risk policy PL1 sits with the chief risk officer, Sunanda Ravikumar, and the board, committee G1, approves it. Two people, two entirely different jobs, and the separation is deliberate. The policy owner is answerable for the document being right and current: for the wording being accurate, for it coming back at the review cycle, for somebody noticing when the business it describes has changed shape. The approver does none of that work, and supplies instead the one thing the owner cannot: authority the document does not have on its own.

Collapsing the two shows what is at stake. The head of a trading desk writes the market risk policy, and the head of the same trading desk approves it. Nothing in the text needs to change for the document to have quietly stopped being a rule. The document has become a statement of intent by the person it was written to constrain, revisable by that person on any morning when the constraint is inconvenient. Self-approval is precisely the arrangement a policy exists to prevent, and the approver is therefore always further from the risk than the owner is.

The everyday version is the housing society again. One resident can write the rule about parking. If that same resident also approves it, the other flats have not agreed to anything; they have been told something. The signature has to come from somewhere the writer does not control, or the writing does no work at all.

TWO ROLES ON ONE DOCUMENT, AND NEITHER CAN DO THE OTHER JOB Read the verb in each card before anything else. Maintaining and making binding are separate acts. THE POLICY OWNER the chief risk officer, for policy PL1 MAINTAINS answerable for the document being right and current brings it back at the review cycle it names cannot make it binding on a single person THE APPROVER the board, committee G1, for policy PL1 MAKES IT BINDING lends the document authority it has none of alone did not write it and does not maintain it signing is the act that starts the clock POLICY PL1, THE ENTERPRISE RISK POLICY one document, maintained on the left and made binding on the right COLLAPSE THE TWO ROLES AND A POLICY BECOMES A STATEMENT OF INTENT BY THE PEOPLE IT CONSTRAINS Policy PL1, committee G1 and the chief risk officer are Vindhya Commercial Bank Limited's own, invented. No arrangement here is required of anybody.
One document carries two roles, and the person who keeps it right is deliberately not the body that makes it bind, because authority has to arrive from outside the reach of the author.
Try it out

The chief risk officer is the policy owner of the enterprise risk policy and the board approves it. Why not have one of them do both?

How do a policy, a standard and a procedure differ?

Three documents, three altitudes, and one test that separates them cleanly: who is the sentence addressed to? A policy addresses the institution and says this is how this risk is to be run. A standardThe layer below a policy, saying what good enough looks like in a particular area. addresses a function and says this is what good enough looks like here. A procedureThe layer below a standard, saying what a named person actually does, in order. addresses a person and says do this, then this.

The reason the three layers are kept apart is not tidiness, it is the cost of changing each one. A policy changes only when the approver approves it again, and at this invented bank that means getting on a board agenda. A standard changes inside the function that holds it. A procedure changes when the desk is rearranged. Writing the procedure into the policy means taking the seating plan of a dealing room to the board, so either the board approves trivia or, far more likely, nobody bothers and the policy is wrong within a quarter. A document that mixes all three altitudes gives everybody something to ignore, and once a reader has learned to skip one paragraph they have learned to skip the document.

ONE TEST SEPARATES THE THREE: WHO IS THE SENTENCE ADDRESSED TO? The narrower the band, the smaller the audience of the sentence and the cheaper it is to change. THE POLICY ADDRESSED TO THE INSTITUTION the bank does not run a trading position it cannot value daily to change it: the approver has to approve it again THE STANDARD ADDRESSED TO A FUNCTION every position is valued daily against an independent price source to change it: the function that holds it changes it THE PROCEDURE ADDRESSED TO A PERSON the dealer enters the trade in the system before leaving the desk to change it: the desk changes it when the desk changes PUT A PROCEDURE IN A POLICY AND THE POLICY IS WRONG WITHIN A QUARTER The three example sentences belong to Vindhya Commercial Bank Limited, invented. None is required of any institution.
Each layer down addresses a smaller audience and is cheaper to change, which is the practical reason an institution keeps the three apart rather than writing one long document.
Try it out

A document says a dealer must enter the trade in the system before leaving the desk. Policy, standard or procedure?

Risk Management Program Bootcamp — Fin Maverick

How does a policy reach a number somebody is measured against?

Compliance needs something countable, so a policy that only states an intent cannot be complied with at all. The bridge is a single line of text, and it is worth learning to look for it. Call it the cascade sentenceThe line in a policy that turns a rule into a numbered limit somebody is measured against.: the sentence in the document that hands a number to somebody else to set and then to monitor. Everything above that line is language. Everything below it is a report.

Follow one at Vindhya Commercial Bank Limited. The bank's own market risk policy, PL3 in its set of nine, says the trading book is run inside a value at risk limit. The sentence binds nobody on its own, and it does not need to. The sentence hands off. Limit L5 is what it hands to: one day, 99 per cent, measured on the bank's own historical simulation, Rs 18.0 crore, all of which is this invented bank's own arrangement. The position is then measured against Rs 18.0 crore every day and read at committee G7. In month 3, on days 21 and 22, the measured figure came in at Rs 19.2 crore and Rs 18.6 crore, and because a sentence had become a number, the crossing was a fact rather than an argument.

FROM A SENTENCE TO A NUMBER TO A READING TO A CONSEQUENCE Follow it left to right. Each arrow is a translation, and a policy with no first arrow stops at the first box. 1 THE SENTENCE a line in the bank's own market risk policy PL3 says the trading book is run inside a value at risk limit binds nobody by itself 2 THE NUMBER limit L5: one day, 99 per cent, on the bank's own historical simulation, Rs 18.0 crore set by committee G2 3 THE READING the position is measured every day against that number and reported to committee G7 now it is countable 4 THE CONSEQUENCE breach B5, month 3, days 21 and 22, measured at Rs 19.2 crore and then at Rs 18.6 crore a fact, not an argument UNTIL THE SENTENCE BECOMES A NUMBER, THERE IS NOTHING A REPORT CAN SAY ABOUT IT Policy PL3, limit L5 at Rs 18.0 crore, breach B5 and committees G2 and G7 are Vindhya Commercial Bank Limited's own, invented, at its month 12 reporting date.
The cascade runs in four steps and only the second one produces something countable, which is why a policy with no handoff to a number can never be reported on at all.

What does a policy buy by writing its own trigger before the event?

Here is the same machinery doing its best work. The bank's own policy on its trading book does not stop at naming a limit. The policy says what happens at particular counts: at five backtesting exceptions in 250 days the matter goes to the market risk committee G7, and at seven a model review is forced. Both numbers were written down while the year was still quiet and nobody knew what the count would be.

Over the 250 observation days, seven exceptions were observed, numbered X1 to X7, being 2.8 per cent of days against the 1.0 per cent the bank's own 99 per cent measure implies. Read the sequence and watch the policy work twice. The fifth, X5 in month 9, made the escalation automatic. The seventh, X7 in month 11, forced the review. The institution had already answered whether seven was a lot, in a room where nothing was at stake. Nobody had to argue about it when the seventh arrived.

The same policy written the other way reads: the committee will consider whether the exception count is elevated and take appropriate action. Every word of that is defensible and it decides nothing. The count arrives, the discussion begins from zero, and the person whose desk produced the exceptions is in the room explaining why this particular seven is different. A trigger written in advance converts a judgement made under pressure into a number read off a written rule, and that conversion is most of what a policy is for.

A COUNT CLIMBING INTO TWO NUMBERS THAT WERE WRITTEN DOWN FIRST Both dashed lines existed before the first exception. Neither was chosen after seeing the count. FIVE EXCEPTIONS: ESCALATE TO COMMITTEE G7 SEVEN EXCEPTIONS: A MODEL REVIEW IS FORCED 0 1 2 3 4 5 6 7 X1 month 2 day 9 X2 month 3 day 14 X3 month 3 day 15 X4 month 6 day 3 X5 month 9 day 2 X6 month 9 day 3 X7 month 11 day 22 the seven exceptions in the order they occurred, over 250 observation days A NUMBER WRITTEN BEFORE THE EVENT TURNS A DECISION INTO A READING The five and seven exception triggers, the 250 days and exceptions X1 to X7 are Vindhya Commercial Bank Limited's own, invented. Neither number is a standard.
The count climbs one step per exception and meets two lines that were already in the policy, so the escalation at the fifth and the review at the seventh required no judgement from anybody.
Try it out

Seven backtesting exceptions were observed in 250 days. Why did nobody at the invented bank have to argue about whether seven was a lot?

India

Which arrangements are the bank's own, and where the binding version lives

The nine policies PL1 to PL9, the month 4 approval of PL6, the five and seven exception triggers, limit L5 at Rs 18.0 crore, the twelve month validation cycle and every count of models, categories and months are Vindhya Commercial Bank Limited's own choices. An institution picks its own review cycles, thresholds and triggers, so no review cycle, threshold, trigger or approval date carries across from one bank to another.

The international standards behind capital, liquidity, large exposures, interest rate risk in the banking book and the treatment of a backtesting exception count come from the Basel Committee on Banking Supervision at the Bank for International Settlements, bis.org. A standard is where an idea was defined and it is not what binds anybody.

The rules that actually bind a bank operating in India, including anything expected of a risk policy, a policy approval, a review cycle, an outsourcing arrangement or a risk function, come from the Reserve Bank of India at rbi.org.in. Where the duties of a board and its individual directors are the subject, including responsibility for internal financial controls, those sit in the Companies Act, whose text, applicability and exemptions come from the Ministry of Corporate Affairs at mca.gov.in, with the assurance and audit side from the Institute of Chartered Accountants of India at icai.org. Confirm every requirement at source before relying on it.

Breaking Into Quants Bootcamp — Fin Maverick

What does a whole set of policies look like at one bank?

Vindhya Commercial Bank Limited holds nine, numbered PL1 to PL9, and the shape of the set is worth reading before any single document in it. PL1 is the enterprise risk policy and sits above the others. PL2 to PL6 are named for one kind of risk each: credit, market, liquidity, operational and model. PL7, PL8 and PL9 are named for subjects rather than for a kind of risk: information security, outsourcing and third party, and business continuity. Each of the nine names an owner, an approver, a review cycle and the limits it cascades into, so on the four load-bearing parts the set reads 9 of 9, being 100.0 per cent.

PolicyWhat it is named forWhat the bank's own record adds against it
PL1Enterprise riskThe policy owner is the chief risk officer, Sunanda Ravikumar; the approver is the board, committee G1
PL2Credit riskNothing beyond the four parts
PL3Market riskThe trading book limit and the five and seven exception triggers cascade from here
PL4Liquidity riskNothing beyond the four parts
PL5Operational riskNothing beyond the four parts
PL6Model riskApproved in month 4, requires a validation cycle, and models V1, V2 and V3 predate it
PL7Information securityNothing beyond the four parts
PL8Outsourcing and third partyNo committee is named for this policy anywhere in the record
PL9Business continuityNothing beyond the four parts
9 policiesAll four parts present in each9 of 9, being 100.0 per cent

Two things in that table are worth pausing on, and both are about what is absent rather than what is written. The first is PL8. The bank's record names a committee against PL1 and against no other policy in the set, and for outsourcing and third party in particular no body is named anywhere at all. The honest reading is that the gap exists, and anybody holding the real set would go and find out which body fills it.

The second is that the record carries no approval month for eight of the nine and no length for any review cycle. Only PL6 has a date, month 4, and that single date is what the rest of this guide turns on.

Cleaning Financial Data — free micro-course from Fin Maverick

What happens to practice that already existed on the day the policy was approved?

PL6 is the model risk policy and it was approved in month 4. Nothing about it is deficient. PL6 names a policy owner, it names an approver, it names a review cycle, and it cascades into a requirement that models be validated on the bank's own twelve month cycle. From month 5 onward the institution ran with a model risk policy in force. Months 1 to 4 ran without one, so 4 of the 12 months, being 33.3 per cent, sat outside it, and 8 of the 12, being 66.7 per cent, sat inside.

Now go and look at what the policy landed on. At month 12 the bank holds 28 registered models: 19 validated and current, 6 overdue, and 3 that have never been validated at all, being 10.7 per cent of the 28. The three unvalidated models carry the numbers V1, V2 and V3. V1 is the behavioural deposit life model. The model sets the 0.5 year assumption on Rs 36,000 crore of non-maturity deposits, and that one assumption decides the sign of the bank's headline interest rate risk number, moving it from minus Rs 840 crore to plus Rs 240 crore across the range of lives the bank could reasonably assume. V2, the collateral haircut model, sets the 35.0 per cent haircut used on eligible collateral. V3 is a spreadsheet early warning scorecard maintained by one person with no documented specification.

All three predate month 4, and that single fact is the whole lesson: eight months of a policy that requires a validation cycle have passed over them and moved none of them. Not because anybody ignored PL6. Because PL6 created a cycle going forward, and running that cycle against what was already in the building is a separate act that nobody was asked to perform.

ONE APPROVAL DATE ON A LINE, AND EVERYTHING THAT WAS ALREADY THERE The twelve numbered months of the case year. Look at which side of the red line the three models sit on. PL6 APPROVED IN MONTH 4 1 2 3 4 5 6 7 8 9 10 11 12 NO MODEL RISK POLICY: MONTHS 1 TO 4 PL6 IN FORCE: MONTHS 5 TO 12, BEING 8 OF 12, 66.7 PER CENT V1 the behavioural deposit life model sets the 0.5 year assumption on Rs 36,000 crore V2 the collateral haircut model sets the 35.0 per cent haircut on eligible collateral V3 a spreadsheet early warning scorecard maintained by one person, no documented specification THE POLICY DOES NOT REACH LEFT OF THIS LINE All three models were already running when PL6 was approved, and all three are still unvalidated at month 12. The record does not date V1, V2 or V3. It says only that each was in use before PL6, so none is placed in a numbered month here. A POLICY REACHES FORWARD FROM ITS APPROVAL AND NOT ONE DAY BACKWARDS The twelve numbered months, the month 4 approval of PL6 and models V1 to V3 are Vindhya Commercial Bank Limited's own, invented. No date here is a real one.
Everything the policy governs lies to the right of one red line, and the three things it most needed to reach were already in the building on the left of it.
Try it out

PL6 was approved in month 4 and requires a validation cycle. Before the control below is touched: how many of the twelve months does it govern, and how many of the three models that were already running does it reach?

Play with it

Give the policy a grace period and watch which line refuses to move

Institutions often soften a new policy by giving existing practice a stated period before it bites. Moving the dial draws two things at once: the months of the year PL6 actually governs, and the number of registered models it can never reach. One of them responds to the setting. The other one does not.

NO GRACE AT ALL, WHICH IS WHAT PL6 ACTUALLY HAD
ONE DIAL, TWO CONSEQUENCES, AND ONLY ONE OF THEM MOVES Top, the case year. Bottom, both consequences plotted against every grace period from none to a full year. 1 2 3 4 5 6 7 8 9 10 11 12 PL6 BITES FROM HERE PL6 governs 8 of the 12 months, being 66.7 per cent of the year MONTHS OF THE YEAR GOVERNED BY PL6 MODELS THE POLICY CANNOT REACH: 3 AT EVERY SETTING 0 2 4 6 8 THE TWO LINES MEET HERE AND IT MEANS NOTHING One line counts months and the other counts models. 0 1 2 3 4 5 6 7 8 9 10 11 12 months of grace the policy gives to practice that already existed At no grace at all, PL6 governs 8 of the 12 months and cannot reach 3 registered models. The grace period is set on the dial. PL6, its month 4 approval, the 28 registered models and V1, V2 and V3 are the invented bank's own. No grace period, and no approval month, is recommended to any institution anywhere on this drawing.
Months of 12 governed
8
Share of the year
66.7 per cent
Models out of reach
3

Educational illustration. The default reproduces what this invented bank actually did: no grace period at all, policy PL6 approved in month 4, 8 of the 12 months governed, being 66.7 per cent of the year, and 3 registered models out of reach, being V1, V2 and V3, or 10.7 per cent of the 28 models on the register at month 12. The length of the grace period is set on the dial and is not a figure from the case. A grace period changes when a policy starts to bite and changes nothing at all about what came before it, so the count of three does not depend on the dial. Two months of grace puts the governed share at exactly 50.0 per cent, and five months makes the two lines meet at three. The meeting is a coincidence of counts and not two quantities agreeing.

The same readings as static text, so they survive without the control. Read down the first column and the second, then look at the third and notice that it never changes.

Months of graceMonths of 12 governed by PL6Share of the yearRegistered models out of reach
0, the setting PL6 had866.7 per cent3
2650.0 per cent3
5325.0 per cent3
8 and beyond00.0 per cent3
Every setting from 0 to 12falls one for onefalls with it3, always

The flat line is the teaching, and the crossing at five months of grace is the trap. At five, the months governed reads three and the models out of reach reads three, and the two lines touch. Nothing has agreed with anything. One line counts months and the other counts models, and two lines meeting on a chart is a coincidence of units. Being able to say that out loud while looking at the picture is the habit that stops a great many wrong readings of a great many charts.

Cleaning Financial Data teaches you to find the errors that survive every check and break every model.

What does the missing sentence actually cost?

A complete policy, correctly approved, that reached nothing it most needed to reach

Read PL6 against the four load-bearing parts and it passes on every one. PL6 names a policy owner. PL6 names an approver. PL6 names a review cycle. PL6 cascades into a stated validation requirement, and a stated validation requirement is exactly the measurable consequence a policy is supposed to produce. PL6 has been in force for 8 of the 12 months. On any register of policies, PL6 shows as current, complete and compliant.

Now read the model inventory at month 12. Of the 28 registered models, 3 have never been validated, being 10.7 per cent, and the model that decides the sign of the bank's headline interest rate risk number is one of the three. Nobody broke PL6. The failure is that nobody asked the one question a new policy always raises: what happens to everything that was already running on the day it was signed. The unasked question has a name worth keeping: the transition sentenceThe line that says what happens to practice that already existed on the day the policy was approved.. PL6 does not carry one.

Notice how quietly this fails. A policy with no transition sentence does not produce an incident, a breach or a control finding. The policy sits in the register, approved and current. The three things it most needed to reach carry on exactly as before, and at month 12 the inventory reports 3 of 28 never validated as though that were a routine ageing statistic. An ageing statistic is a fact about a queue; this is a fact about a policy that was never pointed at the past, and only the approval month tells the two apart. The fix costs one sentence, and it has to be written before approval. After approval the same sentence is an admission.

Try it out

PL6 has been in force for eight months and three models have still never been validated. What was missing from the document?

Debt Capital Markets Bootcamp — Fin Maverick

How can a missing policy be spotted in a set of nine?

Here is a question the set cannot answer from inside itself. Nine documents, each complete, each approved, each with an owner and a cycle. Is anything absent? A document cannot report a subject nobody wrote about, so reading the nine settles nothing. A gap in a policy set is never visible from inside the set; it becomes visible only when the set is read against the list it is supposed to cover.

The bank publishes its own risk taxonomy with seven level one categories, numbered TX1 to TX7: credit, market, liquidity and funding, operational, compliance and conduct, strategic and business, and reputational. Lay the nine policies against those seven. PL2 answers to TX1, PL3 to TX2, PL4 to TX3 and PL5 to TX4. Then the pointing stops. Nothing in the set is named for TX5 compliance and conduct risk, nothing for TX6 strategic and business risk and nothing for TX7 reputational risk, being 3 of the 7 categories, or 42.9 per cent. All three are reached by PL1 the enterprise risk policy, and only in the way that a policy about everything reaches everything.

The other three documents need care. PL7 information security, PL8 outsourcing and third party and PL9 business continuity are named for subjects rather than for a level one category, and the record asserts no category for any of the three. The record places only model risk, under operational risk, and that placement is this institution's choice rather than a law. The record names no committee for PL8 and no category for PL9.

NINE POLICIES LAID AGAINST THE BANK'S OWN SEVEN CATEGORIES Read across each row and count the rows where nothing is pointing back at the category. THE BANK'S OWN LEVEL ONE RISK CATEGORIES THE POLICY NAMED FOR IT TX1 credit risk PL2 the credit risk policy TX2 market risk PL3 the market risk policy TX3 liquidity and funding risk PL4 the liquidity risk policy TX4 operational risk PL5 the operational risk policy TX5 compliance and conduct risk no policy in the set is named for it TX6 strategic and business risk no policy in the set is named for it TX7 reputational risk no policy in the set is named for it PL1 REACHES ALL SEVEN, AND ONLY BECAUSE PL1 IS ABOUT EVERYTHING PL7 information security, PL8 outsourcing and third party and PL9 business continuity are named for subjects rather than for a level one category, and no category is asserted for any of the three here, because the record places only model risk. THREE OF THE SEVEN CATEGORIES, BEING 42.9 PER CENT, HAVE NO POLICY NAMED FOR THEM The taxonomy TX1 to TX7 and the policies PL1 to PL9 are Vindhya Commercial Bank Limited's own, invented. No category list is required of anybody.
Four categories have a policy pointing back at them and three have nothing at all, which is a reading available only by holding the set against the list it is meant to cover.
Try it out

How can a missing policy be spotted in a set of nine that all look complete?

Where does a policy set sit in an institution's internal control?

The five component structure of internal control belongs to the Committee of Sponsoring Organizations of the Treadway Commission, published in 1992 and updated in 2013, and the attribution matters because the structure is used everywhere and credited almost nowhere. Its components are the control environment, risk assessment, control activities, information and communication, and monitoring activities. The control environment is the first of the five and the one the other four rest on.

Readers usually treat the control environment as the soft one: tone at the top, culture, the way people behave when nobody is looking. The soft reading is not wrong and it is not usable. The policies are the part of the control environment that has been written down, given a named owner and signed by somebody. Seeing a control environment rather than talking about one means going and reading the policy set. Nine documents with nine owners, nine approvers and nine review cycles is a control environment that can be held in the hand and audited line by line. Everything else in the component is inference.

The month 4 problem sits in that same first component, and the placement is why it costs so much. There is no control to test, so a weakness in the control environment never shows up as a failed control test. The weakness shows up instead as three models sitting quietly outside a cycle, in the component the other four are standing on.

THE COMPONENT EVERYBODY CALLS SOFT, DRAWN AS THE DOCUMENTS IT IS MADE OF The five components belong to the Committee of Sponsoring Organizations of the Treadway Commission, 1992, updated 2013. MONITORING ACTIVITIES INFORMATION AND COMMUNICATION CONTROL ACTIVITIES RISK ASSESSMENT CONTROL ENVIRONMENT, AND HERE IS WHAT IT IS MADE OF PL1 PL2 PL3 PL4 PL5 PL6 PL7 PL8 PL9 THE FIRST COMPONENT IS NOT AN ATTITUDE. IN A BANK IT IS NINE DOCUMENTS WITH NAMES AND DATES ON THEM The nine policies PL1 to PL9 are Vindhya Commercial Bank Limited's own, invented. The five component structure is named, and nothing about it is stated as a requirement.
Four components stand on the widest band at the bottom, and in a bank that band is a countable stack of approved documents rather than an attitude.
Try it out

Whose is the five component structure of internal control, and which component does a policy set mostly sit in?

What can a policy not do?

Three things, and each of them is a way institutions lose a year. A policy cannot perform the work it requires. PL6 requires a validation cycle. Approving a rule and running the cycle the rule creates are two separate jobs, and only the first one produces a document with a date on it. Eight months of PL6 passed over V1, V2 and V3 and validated none of them.

A policy cannot close a breach. A policy can say what counts as one, who must be told and how fast, and saying so is worth a great deal. Bringing an exposure back inside a limit takes somebody selling something, refusing something or renegotiating something, and no document does any of the three. A rule can make a fact visible and cannot make the fact smaller.

And a policy cannot make anybody read it. Of the three, the last is the least discussed and the most expensive. The document that binds practice binds it through people who have usually seen a summary once. A cascade into a small number of limits therefore matters far more than the length of the text. A number on a monthly report is read by people who have never opened the policy that produced it, and that is the policy working exactly as designed.

Try it out

Would approving a better written version of PL6 have validated model V1?

What does somebody outside the risk function do with any of this?

Three readers, three uses, and none of them requires access to anything confidential. A newly appointed independent director is handed a set of policies in the first week and cannot possibly read them properly. A new director can still do three things in an afternoon: check the four load-bearing parts on each policy, ask which body approved each, and ask for the approval month of the most recent one. The last question is the sharp one. An approval month identifies every policy young enough to have practice sitting behind it.

An analyst or a lender assessing an institution reads the same set differently. An outsider cannot verify culture and should not try. The same outsider can ask which risk categories in the institution's own taxonomy have a policy named for them and which do not, and a gap of 3 in 7 is a specific, answerable question rather than a general impression. The absence of a document is one of the very few things about an institution's internal workings that an outsider can establish cleanly.

And the household version stays useful. One rule written for household spending needs the four parts. Who is accountable for the rule being current. Who has to agree before it changes. When it gets read again. And the one number it produces. A rule with no number is a mood. Then the fifth line the bank forgot: what happens to the commitments already made before the rule was written.

Risk appetite, tolerance, capacity and a limit are defined as words under risk appetite, and used on sight above. Who decides, who oversees and who reports, and the calendar those bodies sit on, are set out under risk governance structure; the eight committees and the twelve limits are named above and never rebuilt. A charter is not a policy: a charter fixes what a body may decide and a policy fixes what practice must be. The named person a policy appoints, the committee that approves one, the cascade from an appetite clause into a limit, and the route a raised issue travels are each set out under risk governance. Model risk is covered separately: a model's definition, what validation asks that backtesting does not, why a model that cannot be backtested most needs validating, and how an inventory is built and swept all belong to risk reporting, data and model risk. The inventory is used above as a record and the backtest as a count. How value at risk is measured, how an economic value change is computed and what a behavioural assumption does to either belong to market risk. The Companies Act duties on a board in respect of internal financial controls, and anything a regulator requires a policy to contain, belong to Indian markets and regulation.

Sources

SourceDocumentSite
Reserve Bank of IndiaWhat actually binds a bank operating in India, including anything expected of a risk policy, its approval, its review cycle, an outsourcing arrangement or a risk functionrbi.org.in
Bank for International SettlementsThe Basel Committee on Banking Supervision standards behind capital, liquidity, large exposures, interest rate risk in the banking book and the treatment of a backtesting exception countbis.org
Ministry of Corporate AffairsThe Companies Act duties placed on a board and its individual directors, including responsibility for internal financial controls, with the text, applicability and exemptionsmca.gov.in
Institute of Chartered Accountants of IndiaThe assurance and audit standards behind reporting on internal financial controlsicai.org
Committee of Sponsoring Organizations of the Treadway CommissionInternal Control - Integrated Framework, 1992 and updated 2013, where the five component structure of internal control is definedcoso.org

Vindhya Commercial Bank Limited is invented.
Educational material. Not advice on any investment, tax, budget or market position.

← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.