Chapter 5 · Governance, Risk Management and Compliance

17 of 100 exam questions · governance · risk appetite · Op Resilience · climate · cyber · culture
← Back to quiz
Why this chapter matters. 17 of 100 exam questions (17%) — the "lightest" of the 5 but with the biggest post-2019 additions to be aware of: UK Op Resilience (PS21/3, in force March 2022), EU DORA (Jan 2025), climate financial risk (TCFD → ISSB), cyber-risk elevation. Trap zones: governance is DIRECTION+CONTROL, not day-to-day management, risk appetite ≠ risk capacity ≠ risk tolerance, op risk EXCLUDES strategic + reputational in Basel definition, impact tolerance is a BOARD-SET outcome, not internal aspiration, outsourcing accountability retained.

5.1 Corporate governance

OECD definition syllabus 1.1

Corporate governance = the SYSTEM by which companies are DIRECTED and CONTROLLED. Includes relationships between management, board, shareholders, and stakeholders, and structures through which company objectives are set and performance monitored.

Widely-cited standard (OECD, 1999, revised 2004, 2015, 2023).

Trap: governance is not just about "management" — it's DIRECTION + CONTROL at the top level. Managers execute; boards govern.

UK Corporate Governance Code — comply or explain syllabus 1.3

Applies to premium-listed companies on a "COMPLY OR EXPLAIN" basis — either adhere to each provision, or explain deviation in the annual report.

Principles-based (unlike US SOX rules-based). Deviation isn't automatically wrong — but requires meaningful explanation shareholders can assess.

5.2 Board — composition + committees

What the board does syllabus 1.4

  • Sets STRATEGY and risk appetite
  • APPOINTS and oversees senior management
  • Ensures EFFECTIVE risk management and internal control
  • Approves CULTURE and values
  • Oversees FINANCIAL reporting, audit, disclosure
  • Accountable to shareholders (and where relevant, other stakeholders)

Does NOT manage day-to-day. That's the exec team.

Composition syllabus 1.5

  • MIX of executive + non-executive directors
  • MAJORITY (or significant minority) INDEPENDENT non-execs
  • Distinct CHAIR (independent, separate from CEO in most jurisdictions)
  • SENIOR INDEPENDENT DIRECTOR (SID) for shareholder engagement

Independence definitions typically exclude: employed within 5 years, material business relationships, cross-directorships, tenure >9 years.

Board committees syllabus 1.6

CommitteeFocus
AUDITFinancial reporting oversight, external auditor, internal audit
RISKRisk appetite, risk framework, key risks
REMUNERATIONExecutive pay (risk-adjusted, malus, clawback)
NOMINATIONBoard appointments, succession

Each with NED / independent-director majority and clear terms of reference.

5.3 Risk fundamentals + appetite

Risk — ISO definition syllabus 2.1

Risk = EFFECT of UNCERTAINTY on OBJECTIVES — includes UPSIDE and DOWNSIDE. (ISO 31000.)

Financial services tends to focus on downside — but the broader definition matters for strategic risk-taking (which is how firms make money).

Appetite vs capacity vs tolerance syllabus 2.2

TermMeaning
Risk APPETITEAmount + type of risk the org WILLS to accept in pursuit of objectives (BOARD-set)
Risk CAPACITYMax risk the firm COULD bear without failure
Risk TOLERANCEAcceptable DEVIATION from appetite

Risk Appetite Statement (RAS) translates board-level appetite into measurable metrics (capital ratios, exposure limits, VaR, breach counts).

Trap: these three are often conflated. Appetite = what you CHOOSE to take. Capacity = the ceiling. Tolerance = wiggle room.

5.4 Types of risk

Major categories syllabus 2.4

  • Credit (default risk)
  • Market (interest rate, FX, equity, commodity price moves)
  • Liquidity (funding + market liquidity)
  • Operational (processes, people, systems, external events)
  • Compliance / conduct (regulatory, mis-selling)
  • Reputational
  • Strategic
  • Model risk
  • Cyber risk
  • Climate / environmental (rising rapidly post-2019)

Operational risk — Basel 7 categories syllabus 2.5

Basel definition: risk of loss from inadequate/failed internal processes, people, systems, or external events. Seven categories:

  1. Internal fraud
  2. External fraud
  3. Employment practices
  4. Clients, products & business practices
  5. Damage to physical assets
  6. Business disruption & system failures
  7. Execution, delivery & process management

Basel EXCLUDES strategic and reputational risk from op risk (they matter separately).

Trap: "which is NOT an op risk category?" Distractors usually include strategic or reputational. Correct — these are separate.

Climate financial risk syllabus 2.9 / post-2019

PHYSICAL risks — acute events (floods, storms), chronic changes (sea-level, temperature).

TRANSITION risks — policy, technology, market shifts driven by decarbonisation (stranded assets, business-model obsolescence).

Frameworks: TCFD (voluntary → mandatory), ISSB IFRS S1/S2 (2023), PRA SS3/19 → SS1/23.

5.5 Operational Resilience (2022+)

UK Op Res — PS21/3 post-workbook

Regulatory framework introduced by UK FCA/PRA (in force 31 March 2022). Requires firms to:

  1. Identify IMPORTANT BUSINESS SERVICES delivered to clients
  2. Set IMPACT TOLERANCES — max tolerable disruption
  3. MAP the people, processes, technology, facilities, third parties supporting each
  4. TEST via severe-but-plausible scenarios
  5. Take remedial action to remain within impact tolerances by 31 March 2025

Shifts focus from "avoid disruption" (impossible) to "remain within tolerance during disruption".

Not in the 2019 workbook. Entirely post-workbook. EU DORA (in force Jan 2025) is broadly parallel.

Impact tolerance syllabus 3.2

Impact tolerance = maximum tolerable LEVEL of disruption to an important business service. Expressed as TIME (e.g. "no more than 4 hours unavailability") plus other metrics (data loss, transaction count, error rate).

BOARDS SET impact tolerances. Based on CLIENT / MARKET impact, not internal preference.

Third-party / outsourcing risk syllabus 3.3

  • Risk-based DUE DILIGENCE pre-engagement
  • Contractual PROTECTIONS (SLAs, audit rights, data access, exit rights)
  • ONGOING monitoring
  • INCIDENT reporting
  • EXIT strategy planning
  • CONCENTRATION risk oversight (over-reliance on single provider)
  • Regulator NOTIFICATION for material outsourcing

UK PRA SS2/21, FCA SYSC outsourcing chapters. EU DORA expanded third-party ICT rules.

5.6 Risk culture + reporting

Risk culture syllabus 4.1

Combination of individual + corporate VALUES, ATTITUDES, COMPETENCIES, and BEHAVIOURS that determine a firm's commitment to and style of risk management. Reflects how risk is ACTUALLY treated day-to-day — not just as stated in policies.

FSB has consistently identified weak risk culture as root cause of major failures.

Board risk reporting syllabus 6.1

Effective board MI balances:

  • HISTORIC data (losses, breaches, near-misses) + LEADING indicators (culture surveys, control-test outcomes, staff concerns)
  • QUANTITATIVE metrics + QUALITATIVE narrative
  • AGGREGATE (RAS metrics, capital) + SPECIFIC deep-dives

Provides ACTIONABLE info, not just status descriptions.

Bad MI = 200 slides of green ticks. Good MI = focused, forward-looking, action-oriented.

5.7 Compliance within GRC + assurance

Where compliance sits syllabus 5.1

Compliance = 2nd line, oversight of REGULATORY compliance risk specifically. Alongside risk management (other risk types). Coordinated with — not merged into — risk management.

Structural variants:

  • CCO reports directly to board / CEO (independence)
  • CCO under CRO (coordination)
  • Split compliance (each BU has embedded compliance overseen by group)

Assurance mapping syllabus 5.2

Structured overview of sources of assurance the board / audit committee receives on key risks and controls. Spans:

  • MANAGEMENT (1st line self-attestation)
  • OVERSIGHT (2nd line compliance / risk monitoring)
  • INDEPENDENT ASSURANCE (internal audit + external audit + regulator / skilled-person reviews)

Identifies gaps + duplications. Prevents multiple sources testing the same thing (waste) or nothing testing a critical thing (gap).

Internal audit — 3rd line syllabus 5.3

Independent + objective assurance activity assessing effectiveness of RISK MANAGEMENT, CONTROL, and GOVERNANCE processes (including the compliance function itself).

Reports independently to the AUDIT COMMITTEE (not CEO). Standards: IIA IPPF, CIIA Financial Services Code.

5.8 Regulator interaction

How regulators evaluate governance syllabus 7.1

  • SUPERVISORY meetings with board, chair, independent directors
  • ASSESSMENT of board minutes, committee papers
  • INDIVIDUAL fit-and-proper assessments of Senior Managers
  • PERIODIC governance reviews / thematic work
  • Skilled-person reviews (UK s.166) where concerns identified

Much more intensive than pre-2008 model. FCA culture reviews (Barclays 2016+) shifted lens to culture explicitly.

Prudential vs conduct — "twin peaks" syllabus 7.3

CountryPrudentialConduct
UKPRAFCA
AustraliaAPRAASIC
South AfricaPAFSCA
NetherlandsDNBAFM

Alternative: single regulator (Singapore MAS, Ireland CBI). Federal fragmented (US: OCC + Fed + SEC + CFTC + FINRA + state).

5.9 All the numbers (cheat sheet)

Ch 5 quick-reference

ItemAnswer
OECD governance definitionSystem by which companies are directed and controlled
UK Code basis"Comply or explain" — premium-listed
Board committees (4)Audit · Risk · Remuneration · Nomination
Chair-CEO separationStandard in UK; norm in most jurisdictions
Risk (ISO 31000)Effect of uncertainty on objectives
Risk appetiteBoard-set — how much risk the org WILLS to take
Risk capacityMax risk the firm COULD bear
Risk toleranceAcceptable deviation from appetite
Basel op risk categories7 (EXCLUDES strategic + reputational)
UK Op Res in force31 March 2022
UK Op Res compliance deadline31 March 2025
EU DORA in forceJanuary 2025
ISSB standardsIFRS S1 / S2 (2023)
UK Twin Peaks regulatorsPRA (prudential) + FCA (conduct)
Internal audit reports toAudit committee (NOT CEO)
3 lines of defenceBusiness (owns) · Compliance+Risk (oversee) · Internal Audit (assures)
UK s.166Skilled person review (regulator-mandated, firm-paid)