2.3 Governance of Risk Management

Key Takeaways

  • Post-GFC reforms strengthened board accountability, capital/liquidity standards, and expectations for independent risk oversight
  • The board sets risk appetite and oversees culture; management executes; the risk function provides challenge and escalation
  • Misalignment among appetite, strategy, and incentives recreates pre-crisis failure modes even with better models
  • Audit committees and internal audit test controls and data integrity; they do not replace the chief risk officer’s ownership of the risk framework
  • Business units are interdependent: funding, collateral, and reputation shocks transmit across supposedly separate silos
Last updated: August 2026

Governance of Risk Management

Models and hedges fail quietly when governance is weak. The global financial crisis (GFC) of 2007–2009 made that lesson expensive: boards that did not understand structured-credit exposures, risk functions without escalation power, and incentive systems that paid for volume over risk-adjusted return. FRM–3 focuses on how firms reorganized oversight afterward—and what still goes wrong when form replaces substance.

Post-GFC Governance Changes

After the crisis, regulators and market practice pushed several durable shifts:

  • Stronger board accountability for risk appetite, culture, and major risk decisions—not rubber-stamping management packs.
  • Independent risk management with a chief risk officer (CRO) who has stature, access to the board, and authority to challenge revenue producers.
  • Higher capital and liquidity standards (Basel reforms) that made governance failures more expensive in regulatory terms.
  • Stress testing and recovery/resolution planning that force forward-looking, firm-wide views rather than siloed daily VaR.
  • Compensation reforms aiming to defer pay, claw back losses, and reduce heads-I-win / tails-you-lose structures.

None of these changes eliminate risk-taking. They try to ensure risk-taking is visible, challengeable, and owned.

The Board’s Role

The board of directors (or equivalent) is responsible for:

  1. Approving risk appetite and ensuring it fits strategy and capital.
  2. Overseeing the risk governance framework, including independence of risk and audit.
  3. Understanding the firm’s material risk profile—at least at a level that supports informed challenge.
  4. Setting the tone for risk culture (escalation is rewarded; hiding breaches is career-limiting).
  5. Hiring/firing senior risk leaders and ensuring management incentives do not undermine appetite.

Boards need not recalculate every Greek. They must ask the right questions: Where could we lose a multiple of annual earnings? What assumptions sit under “AAA” labels or model AAA outputs? What happens if funding markets close for 30 days?

Three Lines and Challenge

A common organizing model is the three lines of defense:

LineWhoRole
1stBusiness units / front officeOwn and manage risks in day-to-day decisions
2ndRisk management & complianceSet frameworks, monitor, challenge, escalate
3rdInternal auditIndependent assurance on design and operating effectiveness

Governance breaks when the first line outsources ownership to the second (“risk said it was fine”), when the second line is captured by the business, or when the third line lacks skills for model and data risk. Healthy tension—documented dissent and escalation—is a feature, not a bug.

Risk Appetite Versus Strategy and Incentives

Appetite statements that are ignored by the bonus pool are decorative. Classic misalignments include:

  • Strategy pushing into complex products while appetite documents still describe a “vanilla” bank.
  • Desk P&L bonuses without capital or liquidity charges.
  • Growth targets that can only be hit by breaching concentration limits.
  • “Temporary” limit exceptions that become permanent.

Incentives must reinforce appetite: risk-adjusted return metrics, deferred compensation tied to multi-year outcomes, and accountability for limit breaches. If originators are paid on volume and risk officers are paid to keep quiet, models will not save the firm.

Audit Committee and Assurance

The audit committee typically oversees financial reporting integrity, internal control, and the internal/external audit relationship. In risk governance it matters because:

  • Risk numbers enter capital, provisions, and disclosures.
  • Valuation and model controls affect reported P&L.
  • Data lineage and IT general controls underpin every risk system.

Internal audit should review whether risk policies operate as written—limit monitoring, exception handling, independent price verification, and model validation follow-through. Audit does not set risk appetite or replace the CRO; it provides assurance and reports gaps to the board committee structure.

Unit Interdependence: Siloed Risk Is Fiction

Business units look separate on org charts and share fate on the balance sheet:

  • A trading desk’s collateral calls drain group liquidity.
  • Credit losses in one portfolio trigger rating actions that raise funding costs for everyone.
  • Operational failure at a payment utility creates reputation and franchise damage firm-wide.
  • Legal-entity firewalls may not hold under resolution stress or when guarantees and booking practices create contagion.

Governance therefore requires enterprise views: consolidated risk reporting, shared stress scenarios, and escalation paths that cut across divisions. Committees (risk committee, ALCO, credit committee) exist to force those cross-unit conversations before markets force them.

Mini case: limit exception cascade

A structured-credit desk receives a “temporary” limit increase to warehouse assets for an imminent securitization. The securitization slips. Inventory ages, marks gap lower, and collateral calls rise. Treasury’s liquidity buffer shrinks; the bank’s CDS widens; other businesses face higher funding spreads. What began as a desk exception becomes a firm-wide capital and liquidity event—exactly the interdependence boards must anticipate.

Information Flow and Escalation Discipline

Governance also depends on what gets reported, how fast, and to whom. Material risk reports should reach the board risk committee with enough lead time for challenge—not as a last-minute appendix before approval. Escalation triggers (limit breaches, model breaks, liquidity early-warning indicators, conduct red flags) must be predefined so that bad news does not wait for a convenient committee calendar. Firms that punish messengers learn to hide exceptions; firms that treat timely escalation as performance-positive catch problems while options remain open.

Governance Takeaway for Candidates

When FRM questions describe a failure, ask: Was appetite clear? Did someone with power to say no have incentive and authority to say no? Were incentives aligned? Did audit and risk have independence? Did units understand shared funding and reputation risk? Was escalation timely and protected? Weak answers to those questions explain more disasters than a single bad VaR number.

Loading diagram...
Risk Governance Roles (Simplified)
Test Your Knowledge

After the global financial crisis, which governance expectation became a central theme for large financial firms?

A
B
C
D
Test Your Knowledge

In the three-lines model, which statement is correct?

A
B
C
D
Test Your Knowledge

Which situation best illustrates misalignment among risk appetite, strategy, and incentives?

A
B
C
D
Test Your Knowledge

Why is unit interdependence a governance issue rather than only a modeling detail?

A
B
C
D