The Risk Taxonomy and Universe: Naming Everything in Scope
A risk taxonomy is the set of names an institution keeps for risk, arranged in levels so that everything it carries files in exactly one place. The risk universe is wider, holding whatever could hurt the institution, named or not. So the list asserts one thing only, that nothing in scope was left off it, and reading it never checks that. Hunting absences does.
Hunting absences is the whole of the method, and it is worth sitting with for a moment because it runs against the instinct. When somebody hands an analyst a list and asks whether it is any good, the analyst reads it. The items get checked, the wording gets argued over, one that seems misplaced gets noticed. The only claim the list actually makes is that there are no others, and every one of those checks tests the items instead. An item that is absent leaves no mark on the list. An absent item cannot be read, so it has to be hunted.
Everything below is worked on Vindhya Commercial Bank Limited, invented, a mid-sized Indian commercial bank with a balance sheet of Rs 96,000 crore. Its seven level one risk categories, its thirty one level two sub-categories and the way they are split are the bank's own choices and nobody else's. The seven counts and the thirty one are not a standard structure and not a requirement, and a different bank of the same size could sensibly draw the list a completely different way and be equally right.
One more thing at the outset, and it governs everything below. A taxonomy teaches no individual risk type. Credit risk, market risk, liquidity risk and operational risk are each a full subject of their own, taught later and at length. On the taxonomy they are names, and the list of names is the subject. The language is built before any specific exposure is named. Run the other order and two people cannot even agree what they are counting.
What is a risk taxonomy, and what is it a claim about?
Start somewhere ordinary. A household keeps its monthly spending in a notebook, and the notebook has headings: rent, food, school, transport, medical, everything else. The notebook is a taxonomy. The notebook has a small number of names, every rupee that goes out has to be written under one of them, and the household chose the headings rather than receiving them from anybody. Notice the silent claim the notebook makes. The notebook is not claiming that rent is large or that medical is small. The claim is that no kind of spending in this household has nowhere to go.
Now watch the claim fail. A wedding comes along, and wedding spending is not rent, not food, not school, not transport and not medical. The wedding spending goes into everything else, where it sits beside a torch battery and a bus ticket, and at the end of the year nobody can say what the wedding cost. Nothing in the notebook was wrong. Every entry was filed correctly. The notebook simply had no name for the largest outlay of that year, and the missing name destroyed the answer.
A risk taxonomyAn institution's own structured list of the names it uses for risk, arranged in levels. is that notebook at the scale of a bank. A taxonomy is a structured list of names, arranged in levels, with one rule attached: every exposure the institution carries files in exactly one place on it. The taxonomy is the least glamorous object in risk management and every aggregate number in the institution rests on it. A record of risks cannot be sorted, a cap cannot be added up across businesses, a report cannot be compared with the same report three months later, and two committees cannot discuss the same exposure, unless all of them are using the same name for the same thing.
So the first thing to fix is what kind of object a taxonomy is. A taxonomy is not a measurement. Nor is it a ranking. Nothing on it says that one category is bigger or more dangerous than another. A taxonomy is a naming structure, and its single claim is completenessThe claim a list of names makes, and the only claim it makes, which is that nothing in scope is missing from it.: nothing in scope is missing. The completeness claim is the one worth testing.
What is the Risk Universe, and how is it different from the taxonomy?
Here is the distinction most often collapsed, and everything below depends on it. The risk universeEverything that could affect the institution, whether or not it has been given a name. is everything that could affect the institution. Every way it could lose money, lose customers, lose a licence or lose the ability to keep operating. The universe exists whether anybody has written it down or not. The taxonomy is the set of names the institution has chosen to keep. Universe and taxonomy are two different objects, and the taxonomy is always the smaller of the two.
The household version makes the shape obvious. The things that could go wrong for a household are not a list somebody wrote. The salary could stop, the landlord could raise the rent, a parent could fall ill, the school could put its fees up, a scooter could be stolen, the street could flood. All of that is the universe, and it is out there whatever the notebook says. The notebook headings are the taxonomy. When the flood comes and there is no heading for it, the flood does not politely wait outside. The flood happens, it costs money, and it gets written under everything else or under nothing at all.
So the gap between the two is not an academic curiosity. The gap is a specific place where things live. Anything sitting in the difference between the universe and the taxonomy is real, is capable of costing money, and has no name inside the institution. Having no name is not the same as being small, and it is not the same as being unlikely. The absence of a name only means nobody has given the risk somewhere to go. A risk in the universe with no name in the taxonomy is invisible to every process that works by reading names. Most of the processes work that way.
The honest thing to say about the universe is that its size is unknown. The universe cannot be counted, it cannot be drawn to scale, and any institution claiming to have enumerated everything that could affect it has misunderstood the word. Work at the edge instead: take the names the institution keeps, and go looking for things that are real and have no name. Hunting for the unnamed is the completeness test, and it is run on the invented bank below.
What is the difference between the risk universe and the risk taxonomy?
Why does a taxonomy need two levels rather than one?
Ask the question the other way round and it answers itself. Could the invented bank stop at seven names? The bank could, and a board paper would then say something like operational risk, and everybody in the room would nod, and not one person would be able to say what had just been agreed. Operational risk at a bank of this size covers processing mistakes, people leaving with knowledge in their heads, a supplier failing, a system outage, an internal fraud and half a dozen other things that have nothing in common except that none of them is a borrower failing to pay. No single person has a day that a category that broad describes, so it can be discussed but never given to anybody.
Level oneThe small set of categories a board discusses, usually fewer than ten. exists for the conversation. Level one has to be small enough that seven names fit in one paper and one hour, and broad enough that nothing in the institution falls outside them. Level twoThe sub-categories beneath level one, cut to the size somebody can actually be accountable for. exists for the work. Level two has to be cut fine enough that each name describes a real piece of somebody's job. A named person can then own it, be asked about it, and be expected to know its current state.
Conversation at the top and accountability at the bottom is the whole argument for two levels, and the same test shows when a third would be needed. If a level two name is still too broad for one person to hold, it splits again. If it is so narrow that its owner has nothing to say about it most quarters, it should not have been split. There is no correct number of levels any more than there is a correct number of headings in a household notebook. There is only a test: can a board discuss the top of it, and can a person be held to the bottom of it?
Vindhya Commercial Bank Limited, invented, has settled on seven level one categories, numbered TX1 to TX7, and thirty one level two sub-categories beneath them. The split is six under TX1, five under TX2, four under TX3, nine under TX4, three under TX5, two under TX6 and two under TX7, and those seven counts add to thirty one.
| Level one category | Level two sub-categories | Share of the thirty one |
|---|---|---|
| TX1 credit risk | 6 | 19.4 per cent |
| TX2 market risk | 5 | 16.1 per cent |
| TX3 liquidity and funding risk | 4 | 12.9 per cent |
| TX4 operational risk | 9 | 29.0 per cent |
| TX5 compliance and conduct risk | 3 | 9.7 per cent |
| TX6 strategic and business risk | 2 | 6.5 per cent |
| TX7 reputational risk | 2 | 6.5 per cent |
| Seven level one categories | 31 | 100.1 per cent |
The total in the third column reads 100.1 per cent, and that is rounding rather than an error: each share is stated to one decimal place and the seven rounded figures add to one tenth of a point more than a hundred. A table that has been forced to add up has had something done to it nobody can see, and the tenth of a point is better left visible than quietly taken off one row.
What is the rule that makes a taxonomy work?
One rule, stated in two halves. Every item in scope has some place to be filed, and every item has only one such place. The first half is the property of being collectively exhaustiveA property of a good list: everything in scope has some place to be filed. and it is the completeness claim. The second is the property of being mutually exclusiveA property of a good list: an item has exactly one place to be filed, never two., and it is what stops the same exposure being counted twice.
Both halves fail in ordinary ways. A list fails the first half when something real arrives and there is nowhere to put it. The wedding was exactly that failure. A list fails the second half when two names overlap and the same thing can be honestly filed under either. The overlap is the commoner and much quieter failure. Nobody notices, both filings look correct, and the only symptom is a total somewhere that is either too big or too small with no one able to say which.
The field that decides whether the second half holds is the one people leave out. A taxonomy line is four fields, not one. The name. The level it sits at. The parent it files under. And the definition, meaning the sentence that says what falls inside this name and what does not. A list of bare names, however elegant, is not a taxonomy. A list of bare names is a vocabulary, and two competent people using the same vocabulary with no definitions behind it will file the same exposure in two different places and both will be able to defend it.
Test it on yourself with the notebook. Is a school uniform school or is it a household purchase? Is the fuel for the scooter that takes a child to school transport or school? There is no fact of the matter. There is only whatever the household decided and wrote down, and if it never wrote anything down then the answer changes depending on who is holding the pen that month. Now scale that to an institution where the totals reach a committee and somebody sets a cap against them.
Two people file the same exposure in two different sub-categories, and neither of them has made a mistake. What is missing from the taxonomy?
Where does a risk that could sit in two places actually go?
Some things file themselves. A borrower failing to repay goes under credit risk and nobody argues. But a good many candidates could honestly sit under two different level one names, and when that happens somebody has to decide, write the decision down, and live with it. The decision is a filing choiceA decision about where an item sits when two categories could both hold it, made by the institution and not by any rule., and no rule makes it for the institution.
The invented bank's clearest example is model risk. Model risk sits under TX4 operational risk at level two in this bank, as one of the nine level two sub-categories hanging beneath that one category. What model risk actually is, how a model goes wrong and what validating one involves, is a full subject taught later. On the list it is simply a name that had to be filed somewhere, and this bank filed it there.
The filing of model risk is a choice and not a law. The same name could have been placed beside market risk, on the argument that the models that matter most are the ones pricing and measuring market positions. Model risk could equally have been lifted out and given a level one category of its own, on the argument that it cuts across every other category and belongs to none of them. Institutions genuinely do all three, and none of the three is wrong.
Now the consequence, and it is not academic at all. Because model risk files beneath operational risk, the bank's model inventory is reported to committee G6, the operational risk management committee, rather than to G2, the board risk management committee that sets every limit from L1 to L12. A line on a list decided which room a subject gets discussed in, and therefore who hears about it, how often, and against what. Nobody voted on that outcome. The outcome fell out of a filing choice that was probably made in an afternoon.
The household version is smaller and exactly the same shape. Decide that a school uniform is a school expense and it turns up in the conversation about school fees, where it competes with tuition. Decide it is clothing and it turns up in the conversation about clothes, where it competes with a winter jacket. The uniform has not changed. The conversation it enters has, and so has the question it will be asked.
Model risk is filed beneath operational risk in this bank. Is that a rule?
What does the shape of the list reveal about the institution that drew it?
Here is a habit worth building. When somebody hands over a taxonomy, the place to start is not the names but the count. The distribution of sub-categories across the top level is itself a statement about where the institution believes its risk sits, and it is readable before a single word of anybody's commentary has been read.
Run the count on the invented bank. Thirty one level two sub-categories spread across seven level one categories is an average of 4.43 sub-categories each. TX4 operational risk holds nine of them. Nine is 29.0 per cent of the whole level two list, 2.03 times the average, and 4.5 times the smallest count on the list. The smallest count is two, held by TX6 strategic and business risk and by TX7 reputational risk.
Read that as a sentence and it says: this bank thinks operational risk comes in many more distinguishable varieties than anything else it faces, and it thinks reputational risk comes in almost none. Nobody wrote that down. The statement fell out of the counting. Put the same statement in a board paper as a paragraph and it would be argued over for an hour. In the shape of the list nobody thought to defend it at all. Counting is what pulls it back out.
Now the caveat, and it matters more than the observation. The shape is about variety, not about size. Nine level two names under one category does not mean most of the money is there, most of the losses are there, or most of the danger is there. Nine names mean the bank distinguishes nine kinds of thing inside that category. A category with two sub-categories beneath it could carry the largest exposure on the balance sheet. Counting names measures how finely the institution has cut something up, and nothing else.
TX4 operational risk holds nine of the thirty one level two sub-categories and TX7 reputational risk holds two. What has the bank said?
How can the list be tested for completeness?
Now the payoff, and it is the whole reason the universe and the list had to be separated. There are two ways to review a taxonomy and only one of them tests anything.
The first way is to read it. Take the invented bank's list and go down it. Seven level one categories, each sensibly drawn and each covering a genuine part of what a commercial bank does. Thirty one level two sub-categories, sensibly allocated, each sitting under a parent that makes sense. Nothing misfiled. Every review of this taxonomy that proceeded by reading it found nothing wrong, and here is the uncomfortable part: every one of those reviews was correct. There was nothing wrong with the list. The reviews were not lazy and they were not incompetent. The reviews answered the question they asked, and they asked the wrong one.
The second way is to hunt. The list goes face down and the search is for things that are real, capable of costing the bank money, and carrying no name anywhere on it. Done here, something turns up immediately. Climate risk appears nowhere in this bank's taxonomy, at either level. The count is nought of seven at level one and nought of thirty one at level two. Committee G2 recorded it in month 8 as a gap to close, and at month 12, the reporting date for everything in this guide, it is still nought of seven and nought of thirty one.
Nothing about that is a criticism of the list, and it is worth being precise about why. The taxonomy was not wrong about anything it contained. A taxonomy is not a claim about the items on it. A taxonomy is a claim that there are no others. An absent item is not a faint entry or a badly worded one, and the claim leaves no trace on the list. An absence is nothing at all. No amount of reading will reach it.
So what does hunting actually look like on a Tuesday morning? Four moves, none of them clever. The first move takes the record of what has actually gone wrong in the last year and asks, for each event, which level two name it would file under. Note every event where the honest answer is none of them. The second is to take a published category structure from outside the institution and difference it against the institution's own, looking only at what theirs has and this one does not. The third is to ask the people doing the work what they worry about that has no name in the system. The fourth asks what changed in the last three years that the list predates. A list drawn in one world quietly keeps describing that world after it has gone.
How would this bank's taxonomy be tested for completeness?
What happens to a risk that has no name on the list?
The comforting answer would be that an unnamed risk gets handled informally, or that somebody keeps an eye on it. The real answer is more mechanical and much worse. An absent name silently removes a subject from six separate processes in order, and each step follows from the one before it with no judgement involved anywhere.
Follow it down. Filing means writing something under a name, so a risk with no level two name cannot be filed at all. Ownership in an institution attaches to a named thing rather than to a worry, and an unfiled risk never acquires an owner. With no owner there is nobody to ask, and nobody is ever asked to rate it. Without a rating it cannot take a place among the forty six entries on the bank's record of risks. Not being on that record, it has no line in any report built from it. And with no report line, no cap can be written against it and no indicator can be defined that would turn red about it.
Six processes, all silently empty, and not one of them produced an error message. Silence is what makes this failure different from an ordinary control failure. A control that breaks leaves a trace: an exception, a rejected entry, a reconciliation that will not tie. An absent name leaves the entire machine running smoothly on a slightly smaller world. In this bank the only visible trace anywhere is one sentence in a committee minute in month 8.
The error that gets made, and what it costs
The error is reviewing a taxonomy by reading it. Lists invite reading, and reading produces a clean result every time. A clean result feels like a good outcome, and that is what makes the error easy. On the invented bank it produced a clean result repeatedly and the list really was clean.
The cost is not that a wrong name went unnoticed; it is that a missing name removed a whole subject from the institution's machinery while every part of that machinery reported normal. Climate risk at this bank is nought of seven at level one and nought of thirty one at level two, so no exposure to it can be filed, nobody is its owner, nothing about it is rated, it is not among the forty six entries on the record of risks, it appears in no report and no cap or indicator exists for it. Six absences, one cause, and the only trace is a single line in the month 8 minute of committee G2.
The fix is not more review. The fix is a different review, run in the opposite direction, by somebody willing to arrive with a candidate the list does not contain and ask where it would go.
A risk is real and has no name at level two. Which of these describes what actually happens to it?
How is a taxonomy changed, and what does adding a name cost?
Adding a name looks like drafting. Somebody types a word into a list, the list is one line longer, and nothing appears to have happened. Adding a name is a governance act. The moment the name exists, all six of those processes switch on behind it. Something has to be filed under it. Somebody has to be its owner. The new name has to be rated. A rating puts it on the record of risks. A report line follows. And a conversation begins about whether a cap should be written against it.
The hidden cost is why lists get shorter arguments than they deserve. Everybody in the room can feel that the word costs something, even if nobody says so, and the cheapest outcome for the meeting is to leave it out and note it for later. Which committee is entitled to make the change, what a policy has to say about it and how the change gets approved are governance questions, and they belong to the governance sequence. The change is a governance act rather than a drafting one.
The arithmetic is available before the decision is taken, and almost nobody does it. Suppose the invented bank adds one new level one category, for something the list does not currently name, with k level two sub-categories beneath it. The list runs to thirty one plus k sub-categories across eight level one categories, and TX4 operational risk still holds nine of them.
Two points on that curve are worth holding. At five sub-categories the list runs to thirty six, and TX4 holding nine of thirty six is exactly a quarter, down from 29.0 per cent. At ten sub-categories the new category holds ten, one more than TX4's nine, and it is the largest thing at level two on the whole list. Between those two the shape of the bank's stated beliefs has been rewritten, and all anybody did was add a word and decide how finely to cut it.
TX4 operational risk holds nine of the thirty one level two sub-categories. Before the control below is touched: how many sub-categories would a new eighth category need before TX4 falls to exactly a quarter of the level two list?
Add one category the list does not have, and watch the whole shape move
Everything about the invented bank stays fixed: seven level one categories TX1 to TX7, thirty one level two sub-categories split six, five, four, nine, three, two and two, and TX4 operational risk holding nine of them at 29.0 per cent. The seven current shares are 19.4, 16.1, 12.9, 29.0, 9.7, 6.5 and 6.5 per cent. Each is rounded to one decimal place, and the seven add to 100.1. Climate risk is nought of seven at level one and nought of thirty one at level two. Only one thing moves below: k, the number of level two sub-categories placed under a new eighth level one category for something the list does not currently name. At k of 5 the list runs to thirty six and TX4 holds exactly 25.0 per cent of it; at k of 10 the new category holds ten against TX4's nine and is the largest thing at level two.
With no new category added, TX4 operational risk holds 29.0 per cent of a list of 31 level two sub-categories, which is this bank's position at month 12.
Educational illustration. The seven level one categories, the thirty one level two sub-categories and the split six, five, four, nine, three, two and two belong to Vindhya Commercial Bank Limited, invented. The number k is set by the control and is not a figure from the case: this bank has not added a category, and its record does not say how many sub-categories one would need. The default setting reproduces the bank's actual position at month 12.
What does a taxonomy not do?
Almost everything, and the bluntness is deliberate: a well drawn taxonomy has a way of looking like an answer. A taxonomy does not size a risk, it does not rank one against another, and it says nothing whatever about how likely any of them is. It files. Sizing and rating come afterwards, from an assessment, and an assessment needs the name to exist before it can begin.
Nor does the list make the institution safer. Naming a thing is the precondition for managing it and is not itself an act of management. Vindhya Commercial Bank Limited, invented, could add a level one category tomorrow and be no better protected on the day after, unless somebody then becomes its owner, rates it, records it, reports it and sets something against it. The name switches the machinery on. The name does not do the work.
And a taxonomy does not certify itself. Seven sensibly drawn level one categories, thirty one sensibly allocated level two sub-categories and nothing misfiled is a description of a list that is internally tidy. Internal tidiness and completeness are unrelated properties, and a tidy list is no evidence of a complete one. One thing is worth carrying away: a taxonomy is a claim that the list is complete, and the only way to test the claim is to look for what is not on it.
Does a taxonomy state how big or how likely a risk is?
Where this stops. How a named risk is then sized, rated and turned into a position is a subject of its own later in this sequence, and it starts from the material above. Nothing can be assessed until it has a name. The record of risks and the rating scale used against it are a separate subject, also later in this sequence: the forty six entries are counted here, and how any entry got its rating belongs there.
The one view across every risk type, the four ways a risk can be treated, culture, maturity and monitoring belong to the enterprise risk sequence. Which committee may change a taxonomy, what a policy has to say about it and how a change is approved belong to the governance sequence; changing the list is a governance act. And every level one name here is a full subject elsewhere: credit, market, liquidity and operational risk are each taught at length in their own sequences.
Where do the published category structures actually come from?
The mechanism described here is jurisdiction free. A list of names, two levels, one filing rule and a completeness claim would work the same way in any country and in an institution that is not a bank at all. Jurisdiction decides something else: what an institution has to classify, report or hold capital against. Only a national regulator answers that.
Which requirement actually binds, and who publishes the vocabulary
Institutions drawing a taxonomy often borrow structure from published category sets rather than inventing every name. The best known of those, for operational risk event types, is published by the Basel Committee at the Bank for International Settlements, at bis.org.
The Reserve Bank of India, at rbi.org.in, sets what an Indian bank must classify, what it must report and what it must hold capital against. Naming only the global standard is the common and confident error on this subject: the standard is where the vocabulary came from, and the Indian requirement is the thing an Indian bank is held to. Neither text is stable, and both are amended from time to time by the bodies that issue them.
Committee G2 of Vindhya Commercial Bank Limited noted the absence in month 8 as a gap to close, and at month 12 the position was unchanged at nought of seven and nought of thirty one.
Who actually reads a taxonomy, and what do they do with it?
Four readers, and none of them reads it the way it was written to be read.
Somebody assessing an institution from outside counts before reading. Handed a taxonomy, an analyst or a supervisor goes straight to the shape: how many level one names, how many beneath each, where the mass sits. Two minutes of counting produces a statement about what the institution thinks it is dealing with, and that statement can then be set against what the institution actually does. A bank whose largest business line has the thinnest sub-category list has said something without meaning to.
An internal auditor treats the level two list as a population. If there are thirty one names, then coverage is a fraction with thirty one in the denominator, and the plan can be argued about honestly. Without the list there is no denominator, and a coverage claim becomes a matter of opinion. Coverage arithmetic is the least glamorous use of a taxonomy and probably the most valuable.
A person newly responsible for something reads it as a map of what they will be asked about. The level two name they have been given is the unit they will be held to at a meeting, and the definition beneath it is the boundary of the questions they can reasonably be asked. If that definition is missing, they will be asked about things they did not know were theirs.
And a household running the same exercise gets the same benefit at a smaller scale. The six or seven headings the household's money actually goes to get written down. Then, separately, ten minutes goes on listing the things that could go wrong this year, and each one is checked against the headings. Anything with no heading is exactly the thing the household has no plan for, no set-aside against and no early warning of. The household test is the same one committee G2 ran in month 8, and it takes an evening.
Sources
| Source | Document | Site |
|---|---|---|
| Reserve Bank of India | What actually binds a bank in India on what it must classify, report and hold capital against | rbi.org.in |
| Bank for International Settlements | The Basel Committee material naming the published operational risk event categories an institution may borrow structure from | bis.org |
| Frank Knight | Risk, Uncertainty and Profit, 1921, where measurable risk is separated from unmeasurable uncertainty, the separation the idea of a universe wider than any list rests on | Houghton Mifflin, 1921 |
Vindhya Commercial Bank Limited is invented.
Educational material. Not advice on any investment, tax, budget or market position.
