Risk Register vs Risk Matrix: A Record Against a Rating Scale
A risk register is a record: rows, each with a description, an owner, a rating, a date and an agreed action. A risk matrix is a scale: a grid of impact against likelihood that produces the rating a row carries. At Vindhya Commercial Bank Limited, invented, the register holds 46 rows and the matrix holds 25 cells, so one cannot be the other.
A register and a matrix turn up together so often that most people meet them as one thing. Somebody puts a coloured grid on a slide, calls it the risk register, and nobody in the room stops them. The grid does have colours on it and the register does have colours on it, and that seems like enough. Colour is not enough. The two objects do different work, they fail in opposite directions, and an institution can keep a flawless example of either one while keeping nothing at all of the other.
Are a risk register and a risk matrix two names for the same thing?
Start with an example that has nothing to do with a bank. A household keeps a list on the back of a door: the roof leaks in heavy rain, the scooter needs new brakes, the youngest starts school fees in June, the landlord has hinted at raising the rent. Four lines, and beside each line somebody has written who is chasing it and by when. The list on the door is a record. Now suppose the same household argues about which of the four is worst, and settles it by agreeing that anything costing more than a month's income counts as serious and anything likely within the year counts as soon. The agreement about what counts as serious is a scale. The list and the agreement are two different objects, and the household could plainly keep the list without ever agreeing the scale, or agree the scale and never write the list down.
A risk registerThe institution's record of the risks it has identified, one row each, with an owner, a rating and a date. is the list on the back of the door at institutional scale. A risk matrixA grid of impact against likelihood used to convert an assessment into a rating. is the agreement about what counts as serious, drawn as a grid so that two people can point at the same square and mean the same thing. The register is maintained; the matrix is held up against things. The register grows and shrinks as the institution changes; the matrix sits still unless somebody deliberately redraws it.
Take Vindhya Commercial Bank Limited, a mid-sized Indian commercial bank. At month 12, the reporting date in this case, its register carries 46 entries. Every one of them has been rated on the bank's own five by five matrix of impact against likelihood, and the result is 4 red, 12 amber and 30 green. The three shares are 8.7 per cent, 26.1 per cent and 65.2 per cent of the register, and 4 plus 12 plus 30 is 46, so nothing is missing and nothing is double counted.
Now do the arithmetic that settles the question in one line. The matrix has 25 cells. The register has 46 rows. Spread 46 rows across 25 cells and the average is 1.84 rows a cell. Cells hold more than one entry each. The matrix is not a container that the register is poured into; it is the ruler the register is measured with, and a ruler with 25 marks on it can measure 46 things or 4,600 without ever changing shape. So 46 against 25 is not a mismatch to be tidied up. A record measured by a scale is the ordinary relationship between the two.
Somebody hands over a five by five grid with coloured cells and says it is the risk register. What is missing?
What is actually on a row of a risk register?
Six fields, and the reason it is worth counting them is that most of what people call a register in practice has three. A register entryOne row: a described risk with an owner, a current rating, a review date and an agreed action. carries the description of what could go wrong, the named owner, the current rating, the date it was last reviewed, the agreed action and the date that action is due. A row carrying a rating and no owner is a rating rather than an entry, and the whole difference between a register and a worry list is which of those six fields survived the last time somebody was pressed for time.
Work RR1 through all six. The case at this bank gives every one of them. The description is that infrastructure and power exposure stands at Rs 7,644 crore against a limit of Rs 7,056 crore. The exposure is 108.3 per cent of the limit, an excess of Rs 588 crore. The owner is Manjari Sondhi, head of wholesale banking, who is recorded as the risk ownerThe named individual who is accountable for that row, as against the person who wrote it down. of the underlying breach. The rating is red on the bank's own scale. The review date is month 12, the reporting date. The agreed action is a remediation plan that the board risk management committee accepted in month 6 as a temporary excess. The due date on that plan is month 18.
The last two fields do what the first four cannot. The description and the rating give the position. The action and the due date show whether anything is moving, and the fact that this bank's committee accepted the excess with a dated plan is a decision rather than a failure to act. A position and a decision are different facts, and a reader who sees only a colour has been shown one of them.
What does a single cell of a risk matrix actually mean?
A cell means one thing and no more: a position on two axes. The horizontal axis is likelihood, the vertical axis is impact, and the cell says the assessor placed this entry at the third mark on one and the fourth mark on the other. The cell does not say what the loss would be in rupees. It does not say the chance in per cent. It does not say who decided, when, or on what evidence. A cell is a coordinate, and everything anybody wants to do with it beyond reading off that coordinate is an extra step somebody has to justify.
The trouble starts because both axes are ordinal scalesA scale whose points are ordered but not evenly spaced, so the distance between 2 and 3 is not a known quantity.. Ordinal means ordered and nothing else. Mark 4 is worse than mark 3, and mark 3 is worse than mark 2, and that is the whole of the information the scale carries. An ordinal scale does not say that the gap between 3 and 4 is the same size as the gap between 2 and 3, and in practice it never is. On most impact scales the step from 4 to 5 is far bigger than the step from 1 to 2. The top of the scale is where the interesting losses live.
Frank Knight drew the line this rests on in Risk, Uncertainty and Profit, published in 1921: some things can be measured and some things can only be judged, and treating a judgement as a measurement is how confident errors get made. An impact rating of 4 is a judgement. Rs 7,644 crore of sector exposure is a measurement. The matrix takes the measurement, converts it into the judgement, and from that point onward the rupee figure has left the room. Losing the rupee figure is a trade made on purpose. A credit exposure and a stale data feed can then sit side by side and be compared at all, and the trade costs exactly what a trade like that would be expected to cost.
A five by five grid has twenty five cells. Before the control below is touched: how many different scores can impact times likelihood produce?
Move the red threshold and watch the scale change while the bank stands still
One control: the score at or above which a cell counts as red, anywhere from 1 to 25. One consequence: how many of the 25 positions on the grid turn red. The default is a threshold of 16, at which exactly 4 of the 25 cells count as red. The number of red positions moves. The bank stands exactly where it stood before the dial was touched.
At a red threshold of 16, 4 of the 25 positions on this scale are red, and not one thing the bank is exposed to has changed.
What happens when two ordinal scales are multiplied together?
A colour is hard to sort and a number is easy, so almost everybody who draws a matrix eventually scores it. Scoring a cell as impact times likelihood produces products running from 1 up to 25. The products look like a twenty five point scale. Nothing of the kind. The products of a five by five grid take only fourteen distinct values, so twenty five distinguishable positions collapse onto fourteen scores before anybody has made a single judgement about anything.
The fourteen reachable values are 1, 2, 3, 4, 5, 6, 8, 9, 10, 12, 15, 16, 20 and 25. Everything else between 1 and 25 is unreachable: 7, 11, 13, 14, 17, 18, 19, 21, 22, 23 and 24 cannot be produced by any pair of whole numbers from 1 to 5. Eleven numbers sit in the middle of the range that no assessment can ever land on. A scale that will be sorted, averaged and put in a report is a strange place for eleven holes.
Count the collapse from the other side. Only four cells have a score nobody else shares: 1 at the bottom corner, 9 in the middle, 16 and 25. The other twenty one cells all sit on a score they share with at least one other cell. Twenty five positions minus fourteen scores is eleven distinctions lost, and those are two different counts of the same event, so it is worth saying both slowly: twenty one cells sit on a shared score, and eleven distinctions disappear. A reader who has seen the phrase eleven cells share their score has met the second number wearing the first number's clothes.
Now take the score that does the most damage. Four arises three separate ways: impact 1 with likelihood 4, impact 4 with likelihood 1, and impact 2 with likelihood 2. In plain words those are a small thing that happens often, a severe thing that almost never happens, and a middling thing of middling frequency. Three situations, one number, and the three responses a sensible institution would choose for them have nothing in common with each other. The first is fixed with a process change, the second is carried with capital or insurance, and the third is argued about at a meeting. A report that shows the score of 4 and not the coordinates behind it has taken those three decisions and printed them as one.
Two entries on the register both score 4 on the matrix. Does that mean they are the same size of problem?
Which is worse, a rare catastrophe or a moderate everyday event?
A room asked the question produces an argument. The argument is healthy: the answer is a judgement, and reasonable people differ. A scored matrix produces an answer instantly, and the answer will not be a judgement anybody made. Impact 5 at likelihood 1 scores 5. Impact 2 at likelihood 2 scores 4. So the grid ranks the catastrophe that almost never happens above the moderate event that happens sometimes. Nobody in the institution decided that, and nobody was asked. Multiplication decided it: five times one is more than two times two.
The leap is worse than the ordering. Move that catastrophe one step along the likelihood axis, from 1 to 2, and its score goes from 5 to 10. On the ranked list of the fourteen reachable scores that is a jump from fifth place to ninth, past four other scores, on the strength of one assessor moving one mark on an ordinal axis where the distance between marks is undefined. The same one-step move at the bottom of the grid, from impact 1 likelihood 1 to impact 1 likelihood 2, takes the score from 1 to 2 and moves it one place. Identical inputs, wildly different consequences. Multiplication is not a flat operation, and the axes were never numbers in the first place.
Impact 5 at likelihood 1 scores 5, and impact 2 at likelihood 2 scores 4. Did anybody decide that the first was worse than the second?
Rebanding the scale and calling it risk reduction
The next move takes no bad intent from anybody at all. Suppose an institution raised the score at which an entry counts as red. BandingThe rule that turns a position on the grid into a colour, set by the institution and changeable by it. is the rule that turns a position into a colour, and unlike the exposures underneath it, that rule can be changed in one meeting by the people who report on it.
The arithmetic of the grid is exact and every step of it can be checked against the control above. At a threshold of 25 one of the twenty five cells is red. At 20 it is three. At 16 it is four. At 15 it is six. At 12 it is eight. At 10 it is ten. Across four settings of a single dial the number of red positions goes from one to ten, a tenfold change, and not one thing the institution is actually exposed to has moved by a single rupee. Sector concentration is still Rs 7,644 crore against a Rs 7,056 crore limit whatever colour the row is printed in, and the excess of Rs 588 crore is still there when the ink dries.
The reason this is worth naming is that it is the cheapest improvement available to anybody under pressure to show fewer reds. Rebanding requires no remediation, no capital and no conversation with a business head. One meeting is enough. And it is completely invisible in a report that shows the register without the banding rule printed beside it. Most registers are shown exactly that way.
There is one more trap sitting on top of that one, and this case walks straight into it on purpose. At a threshold of 16, exactly four of the twenty five cells count as red. The register at Vindhya Commercial Bank also holds exactly four reds. The two fours are unrelated. One counts positions on a scale and the other counts rows in a record, and a reader who takes them for the same fact has just mistaken a scale for a record in a single glance.
An institution raises its red threshold by one setting and its register now shows fewer reds. What has changed?
How does an analyst test whether a risk register is working?
Counting the reds does not answer this. A register can show four reds and be a work of fiction, and it can show forty and be excellent. The test that does work is reconciliationChecking that what one record says is also said by the other records that should know about it.: take each red entry and go looking for the same thing somewhere else in the same institution, in a record kept by different people for a different purpose. A register that agrees with the records that should already know about its worst entries is doing its job, and a register whose worst entries appear nowhere else is a document rather than a record.
Run it on this bank, and run it out loud. RR1 is sector concentration, and the limit set carries it as breach B1, open since month 5 and standing at 108.3 per cent of limit L3 at month 12. RR2 is dependence on wholesale funding, and the limit set carries it as breach B3, open since month 11 at 112.8 per cent of limit L10. RR3 is the collateral valuation control, and it appears twice more: in the operational loss record as incident I10, where a valuation feed was stale for 11 working days and 340 loans were wrongly marked at a net loss of Rs 1.4 crore, and in the control testing record as the bank's single material weakness. RR4 is the behavioural deposit assumption, and the model inventory carries it as model V1, one of three models in use that have never been validated.
Four of four reconcile. The result is good and it did not happen by luck. The register was rebuilt in month 6, and a register recently rebuilt against the institution's other records is exactly the kind that survives the test. The test needs remarkably little, and the shortness of that list matters just as much. Running the test takes no agreement with the ratings, no understanding of the risk types and no knowledge of collateral valuation. The test takes the register, three other records, and the willingness to look four things up.
How would an analyst test whether a risk register is working?
Can an institution have one of them without the other?
An institution can, in both directions, and the two failures look so different from the outside that nobody would guess they are the same missing part seen twice.
A register with no scale behind it produces ratings nobody can compare. Row four says high and row thirty says high, and the two authors mean different things. Nobody ever agreed what high means. Without a shared scale a register stops being a record and becomes a collection of opinions set in a common font. The mismatch is quick to spot: two people who wrote different rows are asked what they would need to see for their row to move from amber to red, and the test is whether the two answers have anything in common.
A matrix with no register behind it produces something that looks a great deal better and is worth less. The grid is well drawn, the axes are defined, the colours are agreed, and it is attached to nothing: no rows, no owner, no review date and no action. The grid is a beautifully calibrated instrument in a drawer. The failure is quick to spot too, and the question is even shorter: what is in the darkest cell? If the answer is a category rather than a row with a person's name against it, there is no register underneath.
What does a register with no scale behind it produce?
Who actually reads these two objects, and what do they do with them?
Three very different readers pick up the same pair, and each of them is doing something the other two are not.
An independent director on a board committee reads the register for the count and the movement, not the detail. Four reds this time against how many last time, and which rows have not moved. But the useful director does one thing more, and it takes ten seconds: she asks for the banding rule to be shown alongside the count. A count of reds without the rule that produced it is a number whose units are unknown, and asking for the units is the cheapest question in the room.
A credit analyst at another institution, looking at this bank as a borrower or a counterparty rather than as an employer, cannot see the register at all and knows it. The analyst runs the reconciliation test in reverse instead: take what is publicly visible about concentration and funding, and ask whether the institution's own account of itself is consistent with it. An institution whose disclosures describe a comfortable position while its own structure shows a sector at Rs 7,644 crore against a Rs 7,056 crore internal limit is telling two stories, and the analyst's job is to notice that there are two.
And a lender or a treasurer inside the institution reads it for one thing only: whether the row that will cost money next has an owner and a date on it. Not a colour. Not a score. A name and a date. A name and a date is the household version too, and it is exactly the list on the back of the door: the roof, the brakes, the fees, the rent. Whoever writes serious next to the roof has produced a rating. Whoever writes the plumber's name and the fifteenth of the month next to it has produced an entry, and only one of those two people will have a repaired roof.
What does neither the register nor the matrix show?
Both objects describe a position and neither describes movement. The register says 4 red, 12 amber and 30 green at month 12, and the matrix says what those colours mean. Between them they give the state of the institution's own account of itself on one day. Neither of them shows whether anything is actually being done. A rating is a state at a point in time, an action has a start, an owner and a due date, and those three live in the two fields most likely to be blank.
The gap shows in the case's own records. For RR1 the case records a dated plan: accepted by the board risk management committee in month 6, running to month 18. For the other three reds it records no dated action at all. The three missing dates are not a criticism of the bank; they are what a register looks like from outside once the second question is asked. Two institutions could show identical colours, 4 red and 12 amber and 30 green, and differ completely on whether their open actions are on time, and it is the second fact that predicts what the colours look like next time.
Keeping both objects properly yields this much and no more. The matrix makes 46 different things comparable. The register makes them countable, ownable and dateable. Neither makes them fixed. The fixing is a separate activity with its own record, and an institution that mistakes a well maintained register for progress has made a subtler version of the same error as the one that mistakes a coloured grid for a register.
The register shows 4 red, 12 amber and 30 green. What cannot be told from that?
Which text actually binds, and where that text lives
Whether an institution must keep a register or a matrix at all is settled by the body that supervises it, and not by the mechanism. The mechanism itself is jurisdiction free: a record, a scale, a rule that turns a position into a colour, and a reconciliation.
Where an Indian bank's risk management arrangements, its internal capital and liquidity assessment, its stress testing and its reporting to a board are actually prescribed, the source is the Reserve Bank of India at rbi.org.in, and the text there is the one that binds. Where a risk management framework of the kind described here originates in an international standard that an Indian rule implements, the source is the Basel Committee on Banking Supervision at the Bank for International Settlements at bis.org.
A rating scale, a banding rule, a red threshold and a review frequency are each set by the institution itself and approved inside it. Two banks in the same city can therefore run the same five by five grid and count a different number of reds. A supervisor prescribes that such arrangements exist and are reported on, and the numbers inside them stay the institution's own.
Sources
| Source | Document | Site |
|---|---|---|
| Reserve Bank of India | What actually binds a bank in India on risk management arrangements, internal assessment, stress testing and reporting to a board | rbi.org.in |
| Bank for International Settlements | The Basel Committee standards that originate the risk management practices an Indian rule implements | bis.org |
| Frank Knight | Risk, Uncertainty and Profit, 1921, for the separation of what can be measured from what can only be judged | named in the text |
Vindhya Commercial Bank Limited and Manjari Sondhi are invented.
Educational material. Not advice on any investment, tax, budget or market position.
