4.3 GARP Code of Conduct
Key Takeaways
- GARP’s Code binds FRM holders and candidates to professional integrity, ethical behavior, conflict management, confidentiality, and generally accepted risk-management practices
- Conflicts of interest must be identified, disclosed, and managed—not hidden behind technical jargon or informal side deals
- Confidential information and client/employer data require protection; misuse for personal trading or favors violates the Code
- Violations can bring disciplinary sanctions up to suspension or permanent ban from GARP programs and association with the FRM designation
- Exam vignettes reward the action that preserves integrity and transparency even when it reduces short-term P&L or career convenience
GARP Code of Conduct
Technical skill without ethics is how several disaster cases in the previous sections began. GARP’s Code of Conduct (often discussed alongside related professional standards materials provided to candidates) establishes expectations for people who earn or pursue the FRM designation. Part I tests whether you can apply those expectations to workplace vignettes—not whether you can recite a preamble from memory.
Why a code exists in a risk credential
Risk managers influence limit breaches, model approvals, disclosures, and capital conversations. Their errors or conflicts can harm clients, employers, markets, and the public. A professional code:
- Sets a minimum behavioral baseline above “not illegal.”
- Gives individuals cover to escalate when commercial pressure demands silence.
- Protects the FRM brand so the designation signals trustworthiness as well as competence.
When exam questions pit bonus culture against transparency, the Code-aligned answer almost always favors honest risk reporting and disclosure.
Pillars you must operationalize
GARP’s standards emphasize themes that appear repeatedly in candidate materials. Memorize them as actionable duties:
| Theme | Practical meaning for an FRM professional |
|---|---|
| Professional integrity | Be honest in analysis, reporting, and representations; do not falsify risk metrics, backtests, or disclosures |
| Ethical standards | Place ethical obligations above personal gain when they conflict; refuse instructions to mislead |
| Conflicts of interest | Identify actual and apparent conflicts; disclose and manage them (recusal, oversight, transparency) |
| Confidentiality | Protect non-public employer, client, and counterparty information; no misuse for trading or gossip |
| Generally accepted risk practices | Apply sound methods; acknowledge limitations; do not present known-weak models as definitive truth |
| Professional competence | Maintain skills; do not claim expertise you lack; escalate when issues exceed your mandate |
These pillars overlap. Hiding a known model flaw to protect a bonus is simultaneously an integrity failure, an ethics failure, and a departure from accepted risk practice.
Conflicts of interest — the exam favorite
Conflicts arise when personal, firm, or third-party interests could bias risk judgment. Examples:
- A risk officer owns a material stake in a fund the bank is about to prime-broker.
- A model validator’s promotion depends on the trading desk that owns the model under review.
- An FRM candidate moonlights for a vendor bidding on the firm’s risk system RFP.
- Gifts, entertainment, or soft-dollar arrangements create apparent obligation.
Correct pattern: disclose promptly to the appropriate party (compliance, manager, client as applicable), document the conflict, and follow mitigation (recusal, independent review, declining the gift). Incorrect pattern: “I can stay objective silently” or “everyone does it.”
Apparent conflicts matter. If a reasonable third party would question your objectivity, treat it as a conflict even if you feel unbiased.
Confidentiality and information barriers
Risk roles see position-level data, stress results, client names, M&A-sensitive exposures, and non-public supervisory findings. Confidentiality duties typically require that you:
- Share information only with those who have a legitimate need.
- Avoid discussing sensitive exposures in public spaces or on insecure channels.
- Never trade (or tip others to trade) on material non-public information obtained through work.
- Handle vendor and cloud data with the same care as internal files.
Confidentiality is not a shield for fraud: codes and laws generally do not require you to hide illegal activity from proper authorities. Escalation paths (internal whistleblowing channels, regulators where mandated) exist precisely so confidentiality is not abused to conceal wrongdoing.
Generally accepted risk-management practices
“Generally accepted” does not mean “whatever my desk prefers.” It means methods and governance consistent with professional risk management: independent challenge, appropriate model validation, transparent assumptions, complete risk reporting, and respect for limits and regulatory requirements. Practical implications:
- Do not silently switch VaR methods to avoid a limit breach.
- Do not omit known risk factors from reports to “reduce noise.”
- Document limitations when data are poor; do not overstate precision.
- Support a culture where raising risk issues is duty, not disloyalty.
This pillar connects directly to disaster lessons: LTCM-style model complacency and Barings-style control gaps violate the spirit of accepted practice even before any Code citation is quoted.
Consequences of violations
GARP may investigate alleged violations and impose disciplinary sanctions. Depending on severity and findings, outcomes can include private or public admonishment, suspension, or permanent ban from GARP membership and from using the FRM designation. Candidates should assume that cheating on exams, falsifying experience, or serious professional misconduct can end their path to certification.
Employers and regulators may impose parallel consequences (termination, fines, industry bans). The Code is therefore not a “soft” appendix—it is part of the credential’s enforcement ecosystem.
Practical FRM-candidate scenarios
Work each scenario to a Code-aligned decision.
Scenario A — Pressure to “adjust” the risk report
Your desk head asks you to exclude a new concentrated issuer from the weekly risk pack until after bonuses are set, calling it a “temporary data issue.” You know the position is real and material.
Aligned action: Refuse to falsify or omit material risk information; escalate through risk hierarchy/compliance; document the request. Integrity and accepted risk practice forbid cosmetic risk reports.
Scenario B — Friend asks for a “peek” at client stress results
A former colleague at a hedge fund asks whether your bank’s stress test shows large losses on a named sector, “just for macro research.”
Aligned action: Decline. Stress results and client/book details are confidential. Sharing would breach confidentiality and could constitute misuse of non-public information.
Scenario C — Gift from a model vendor
During an RFP, a vendor offers expensive tickets and hints that “friends help friends” on scoring.
Aligned action: Refuse the gift; disclose the offer to compliance; continue evaluation on documented criteria only—or recuse if impartiality is compromised. This is a conflict and ethics issue.
Scenario D — Exam and study integrity
A classmate offers a compiled file of “real FRM questions from last window” obtained in violation of exam rules.
Aligned action: Refuse; do not use or redistribute; report through proper GARP channels if required. Misconduct in the exam process strikes at professional integrity and can destroy candidacy.
Scenario E — Dual role without disclosure
You advise on limit exceptions by day and, undisclosed, receive advisory fees from a fund that benefits from looser limits.
Aligned action: This undisclosed conflict is incompatible with the Code. Disclose, unwind the arrangement, and recuse from related decisions. Continuing silently is a clear violation.
Decision checklist for exam day
When a vignette feels messy, ask:
- Is anyone being misled (client, employer, regulator, public)?
- Is there an undisclosed conflict or misuse of confidential information?
- Would the action violate sound risk practice (hiding risk, gaming metrics, skipping validation)?
- What option discloses, escalates, or declines rather than conceals?
Pick the option that preserves integrity even if it is politically costly inside the fictional firm. That is the consistent GARP Code answer pattern.
Closing link to Foundations
Disasters and the GFC show what happens when incentives, complexity, and weak challenge dominate. The Code of Conduct is the professional counterweight: it tells FRM holders and candidates that measuring risk is not enough—you must also tell the truth about risk, manage conflicts, protect information, and uphold practices worthy of public trust.
A market-risk analyst is told to remove a known, material FX exposure from the official risk report so the desk can stay inside limits for bonus season. Under GARP Code-aligned conduct, the analyst should:
Which situation is the clearest conflict-of-interest problem for an FRM professional?
A colleague asks you to share a client’s non-public liquidity stress results so the colleague’s brother can ‘position his fund.’ Your best Code-aligned response is to:
Which statement about consequences of serious GARP Code violations is most accurate for FRM candidates and certificants?