Showing posts with label CFO. Show all posts
Showing posts with label CFO. Show all posts

Wednesday, 20 November 2013

Financial Stability Board - Principles for an Effective Risk Appetite

Christmas has come early everyone - the Financial Stability Board have released their Principles for an Effective Risk Appetite Framework today, and I'm greedily ripping in to it before JC's birthday like a spoilt, yet handsome child...

FSB's RAF Principles published
send the car back lads...
There has been a reasonable amount of traffic on Risk Appetite this year (here, here and here for a start), after the FSB but announced their consultation earlier in the year, I've been on tenterhooks. This was following of the back of a thematic review on Risk Governance as a whole by the FSB, which they published back in February.

So where do they take this deep dive into Risk Appetite? Other than awkwardly shoehorning in the soup de jour of "SIFIs", they stick to the hard areas which will get every risk practitioners' attention (namely, Risk Appetite Framework, Risk Appetite Statements, Risk Limits and Roles and Responsibilities), though "for clarity and simplicity", they jettison the use of Risk Tolerance. Definitions are supplied on p2-3, which you may find useful as anchor references.

They somehow make room for anodyne flannel in this very short document, for example;

Risk Appetite Frameworks
  • Should "facilitate embedding risk appetite into the financial institution’s risk culture
  • Development and establishment is an "...iterative and evolutionary process that requires ongoing dialogue throughout the financial institution to attain buy-in across the organisation" (groan)
Risk Appetite Statements
  • "Risk appetite may not necessarily be expressed in a single document; however, the way it is expressed and the manner in which multiple documents form a “coherent whole” need to be carefully reviewed to ensure that the board obtains a holistic, but compact and easy to absorb, view of the financial institution’s risk appetite"
Risk Limits
  • "Having risk limits that are measurable can prevent a financial institution from unknowingly exceeding its risk capacity as market conditions change and be an effective defence against excessive risk-taking" - tell that to Lehmans!
However, the salient points for me were as follows;

Risk Appetite Frameworks

  • RAF "...sets the financial institution’s risk profile" - not convinced on that one, but may be semantic issue
  • "explicitly defines the boundaries within which management is expected to operate when pursuing the institution’s business strategy"
  • Should "be adaptable to changing business and market conditions" to allow for limit increases where appropriate


Risk Appetite Statements

  • "[should] address the institution’s material risks under both normal and stressed market and macroeconomic conditions"
  • "...should establish quantitative measures of loss or negative outcomes that can be aggregated and disaggregated"
  • "...include key background information and assumptions"
  • "...include quantitative measures that can be translated into risk limits"
  • "...be forward looking and, where applicable, subject to scenario and stress testing"

Risk Limits

  • "[should] be set at a level to constrain risk-taking within risk appetite"
  • "...should not be strictly based on comparison to peers or default to regulatory limits"
  • "[should] not be overly complicated, ambiguous, or subjective"

Roles and Responsibilities

The Board

  • ...must establish the institution-wide RAF and approve the risk appetite statement, which is developed in collaboration with the chief executive officer (CEO), chief risk officer (CRO) and chief financial officer (CFO)
  • FSB specifically comment that Boards who "receive" or "note" Risk Appetite Statements have a lower understanding of risk appetite (so don't sponsor it!)
  • " [should] regularly review and monitor the actual risk profile and risk limits against the agreed levels (e.g. by business line, legal entity, product, risk category), "including qualitative measures of conduct risk"
  • " [should] ensure risk management is supported by adequate and robust IT and MIS to 
  • enable identification, measurement, assessment and reporting of risk in a timely 
  • and accurate manner."
CEO should
  • "...be accountable, together with the CRO, CFO, and business lines for the integrity of the RAF"
  • "...ensure that the institution-wide risk appetite statement is implemented by senior management"
  • "...provide leadership in communicating risk appetite to internal and external stakeholders" 
  • "...establish a policy for notifying the board and the supervisor of serious breaches of risk limits and unexpected material risk exposures"

While there are specific sections for the obligations of CRO, CFO, Internal Audit and Business Unit Management, they don't necessarily expand much further than what I consider to be normal functional expectations, so I haven't elaborated on them.

One should certainly therefore expect a much more aggressive approach from supervisors in future off the back of this - combing through strategy and board papers for evidence of Risk Appetite in application, and making sure that Risk Appetite Statements are not just 'rubber stamped', for example.

I certainly don't see much in this for stakeholders. Nothing particularly new is brought to the table here, and if this is the results of peer review and shared experiences, then clearly there is concurrence on how an RAF should be constructed, what a RAS looks like, and who should do what in regard to continuous monitoring.

The skill will be for risk practitioners to convince their CEOs/NEDs that, this is no longer a sidecar activity in the ERM best practice space, but a nascent global minimum standard which will invariably surface in national regulations in the forthcoming moths and years.

Wednesday, 23 November 2011

CFOs, CROs, conflicting messages and strategy - FERMA paper

A couple of pieces of work caught my eye this week on the subject of risk leadership and participation in strategy, with a distinctly financial twist.

The first, a joint effort between FERMA and Finance Director Europe covers a number of themes leading on from FERMA's conference a month back. Some of this report seemed to fly in the face of best practice ERM (for example, broader strategic ERM has evolved through executives realising they need to manage downside risk better? Does it perhaps represent a little more than that in 2011?).

A FERMA board member is cited as believing risk should be "supporting strategy development" rather than participating (which would leave a CRO where exactly?). The next article indeed directly contradicts this view, quoting a risk executive who actively participated in the GRC strategy formulation for his firm, followed swiftly by the AIRMIC/Cass Business School research which bemoans the 'glass ceiling' which prevents risk managers addressing issues in a company's top echelons!

That article also has the UK "...leading the way in enterprise risk management and corporate governance" (I would probably go US and Ireland respectively with a 2011/12 hat on).

The VP of FERMA is then quoted in day-job mode  noting "risk management...is partly about comforting non-executive directors so that they are less risk-averse" - personally I like a bit of conservatism in my NEDs, and I wouldn't like to think I am employed to teach them how to gamble! This is accompanied by the CFO of the same firm notes "the CFO and CRO may have natural conflict, the former driving growth and the latter controlling risk" - again, are Risk, as the second line of defence, really there to 'control' risk?

Finally, the CFO at Old Mutual is quoted as suggesting the complexity of proposed EU regulation (citing Solvency II specifically) might be contributing to elements of risk it is supposed to be preventing.

Thursday, 4 August 2011

The Risk Intelligent CFO - Deloitte

Don't believe you need a subscription, so dive in to Deloitte's (US-centric) research on how to make your CFO more "Risk Intelligent". It is light in certain areas (reputation in particular), and outlandish in others (the CFO is apparently "a catalyst, strategist, operator and steward with respect to risk decision making") but has some neat touches such as;
  • Concept of Strategy Risk being split between "Risks to" and "Risks of"
  • Refining risk reporting/metrics down to the "vital few"
It does however cross over into other Insurance-entity disciplines (CRO, Chief Actuary etc), and it provides 4 "major risk categories" that are wholly unsuited to insurers and banks, but it doesn't purport to be for financial services only - take whatever you can from it, and certainly don't be afraid to wave it under your CFO's nose.