5.1 Corporate governance
▼OECD definition syllabus 1.1
Corporate governance = the SYSTEM by which companies are DIRECTED and CONTROLLED. Includes relationships between management, board, shareholders, and stakeholders, and structures through which company objectives are set and performance monitored.
Widely-cited standard (OECD, 1999, revised 2004, 2015, 2023).
UK Corporate Governance Code — comply or explain syllabus 1.3
Applies to premium-listed companies on a "COMPLY OR EXPLAIN" basis — either adhere to each provision, or explain deviation in the annual report.
Principles-based (unlike US SOX rules-based). Deviation isn't automatically wrong — but requires meaningful explanation shareholders can assess.
5.2 Board — composition + committees
▼What the board does syllabus 1.4
- Sets STRATEGY and risk appetite
- APPOINTS and oversees senior management
- Ensures EFFECTIVE risk management and internal control
- Approves CULTURE and values
- Oversees FINANCIAL reporting, audit, disclosure
- Accountable to shareholders (and where relevant, other stakeholders)
Does NOT manage day-to-day. That's the exec team.
Composition syllabus 1.5
- MIX of executive + non-executive directors
- MAJORITY (or significant minority) INDEPENDENT non-execs
- Distinct CHAIR (independent, separate from CEO in most jurisdictions)
- SENIOR INDEPENDENT DIRECTOR (SID) for shareholder engagement
Independence definitions typically exclude: employed within 5 years, material business relationships, cross-directorships, tenure >9 years.
Board committees syllabus 1.6
| Committee | Focus |
|---|---|
| AUDIT | Financial reporting oversight, external auditor, internal audit |
| RISK | Risk appetite, risk framework, key risks |
| REMUNERATION | Executive pay (risk-adjusted, malus, clawback) |
| NOMINATION | Board appointments, succession |
Each with NED / independent-director majority and clear terms of reference.
5.3 Risk fundamentals + appetite
▼Risk — ISO definition syllabus 2.1
Risk = EFFECT of UNCERTAINTY on OBJECTIVES — includes UPSIDE and DOWNSIDE. (ISO 31000.)
Financial services tends to focus on downside — but the broader definition matters for strategic risk-taking (which is how firms make money).
Appetite vs capacity vs tolerance syllabus 2.2
| Term | Meaning |
|---|---|
| Risk APPETITE | Amount + type of risk the org WILLS to accept in pursuit of objectives (BOARD-set) |
| Risk CAPACITY | Max risk the firm COULD bear without failure |
| Risk TOLERANCE | Acceptable DEVIATION from appetite |
Risk Appetite Statement (RAS) translates board-level appetite into measurable metrics (capital ratios, exposure limits, VaR, breach counts).
5.4 Types of risk
▼Major categories syllabus 2.4
- Credit (default risk)
- Market (interest rate, FX, equity, commodity price moves)
- Liquidity (funding + market liquidity)
- Operational (processes, people, systems, external events)
- Compliance / conduct (regulatory, mis-selling)
- Reputational
- Strategic
- Model risk
- Cyber risk
- Climate / environmental (rising rapidly post-2019)
Operational risk — Basel 7 categories syllabus 2.5
Basel definition: risk of loss from inadequate/failed internal processes, people, systems, or external events. Seven categories:
- Internal fraud
- External fraud
- Employment practices
- Clients, products & business practices
- Damage to physical assets
- Business disruption & system failures
- Execution, delivery & process management
Basel EXCLUDES strategic and reputational risk from op risk (they matter separately).
Climate financial risk syllabus 2.9 / post-2019
PHYSICAL risks — acute events (floods, storms), chronic changes (sea-level, temperature).
TRANSITION risks — policy, technology, market shifts driven by decarbonisation (stranded assets, business-model obsolescence).
Frameworks: TCFD (voluntary → mandatory), ISSB IFRS S1/S2 (2023), PRA SS3/19 → SS1/23.
5.5 Operational Resilience (2022+)
▼UK Op Res — PS21/3 post-workbook
Regulatory framework introduced by UK FCA/PRA (in force 31 March 2022). Requires firms to:
- Identify IMPORTANT BUSINESS SERVICES delivered to clients
- Set IMPACT TOLERANCES — max tolerable disruption
- MAP the people, processes, technology, facilities, third parties supporting each
- TEST via severe-but-plausible scenarios
- Take remedial action to remain within impact tolerances by 31 March 2025
Shifts focus from "avoid disruption" (impossible) to "remain within tolerance during disruption".
Impact tolerance syllabus 3.2
Impact tolerance = maximum tolerable LEVEL of disruption to an important business service. Expressed as TIME (e.g. "no more than 4 hours unavailability") plus other metrics (data loss, transaction count, error rate).
BOARDS SET impact tolerances. Based on CLIENT / MARKET impact, not internal preference.
Third-party / outsourcing risk syllabus 3.3
- Risk-based DUE DILIGENCE pre-engagement
- Contractual PROTECTIONS (SLAs, audit rights, data access, exit rights)
- ONGOING monitoring
- INCIDENT reporting
- EXIT strategy planning
- CONCENTRATION risk oversight (over-reliance on single provider)
- Regulator NOTIFICATION for material outsourcing
UK PRA SS2/21, FCA SYSC outsourcing chapters. EU DORA expanded third-party ICT rules.
5.6 Risk culture + reporting
▼Risk culture syllabus 4.1
Combination of individual + corporate VALUES, ATTITUDES, COMPETENCIES, and BEHAVIOURS that determine a firm's commitment to and style of risk management. Reflects how risk is ACTUALLY treated day-to-day — not just as stated in policies.
FSB has consistently identified weak risk culture as root cause of major failures.
Board risk reporting syllabus 6.1
Effective board MI balances:
- HISTORIC data (losses, breaches, near-misses) + LEADING indicators (culture surveys, control-test outcomes, staff concerns)
- QUANTITATIVE metrics + QUALITATIVE narrative
- AGGREGATE (RAS metrics, capital) + SPECIFIC deep-dives
Provides ACTIONABLE info, not just status descriptions.
5.7 Compliance within GRC + assurance
▼Where compliance sits syllabus 5.1
Compliance = 2nd line, oversight of REGULATORY compliance risk specifically. Alongside risk management (other risk types). Coordinated with — not merged into — risk management.
Structural variants:
- CCO reports directly to board / CEO (independence)
- CCO under CRO (coordination)
- Split compliance (each BU has embedded compliance overseen by group)
Assurance mapping syllabus 5.2
Structured overview of sources of assurance the board / audit committee receives on key risks and controls. Spans:
- MANAGEMENT (1st line self-attestation)
- OVERSIGHT (2nd line compliance / risk monitoring)
- INDEPENDENT ASSURANCE (internal audit + external audit + regulator / skilled-person reviews)
Identifies gaps + duplications. Prevents multiple sources testing the same thing (waste) or nothing testing a critical thing (gap).
Internal audit — 3rd line syllabus 5.3
Independent + objective assurance activity assessing effectiveness of RISK MANAGEMENT, CONTROL, and GOVERNANCE processes (including the compliance function itself).
Reports independently to the AUDIT COMMITTEE (not CEO). Standards: IIA IPPF, CIIA Financial Services Code.
5.8 Regulator interaction
▼How regulators evaluate governance syllabus 7.1
- SUPERVISORY meetings with board, chair, independent directors
- ASSESSMENT of board minutes, committee papers
- INDIVIDUAL fit-and-proper assessments of Senior Managers
- PERIODIC governance reviews / thematic work
- Skilled-person reviews (UK s.166) where concerns identified
Much more intensive than pre-2008 model. FCA culture reviews (Barclays 2016+) shifted lens to culture explicitly.
Prudential vs conduct — "twin peaks" syllabus 7.3
| Country | Prudential | Conduct |
|---|---|---|
| UK | PRA | FCA |
| Australia | APRA | ASIC |
| South Africa | PA | FSCA |
| Netherlands | DNB | AFM |
Alternative: single regulator (Singapore MAS, Ireland CBI). Federal fragmented (US: OCC + Fed + SEC + CFTC + FINRA + state).
5.9 All the numbers (cheat sheet)
▼Ch 5 quick-reference
| Item | Answer |
|---|---|
| OECD governance definition | System by which companies are directed and controlled |
| UK Code basis | "Comply or explain" — premium-listed |
| Board committees (4) | Audit · Risk · Remuneration · Nomination |
| Chair-CEO separation | Standard in UK; norm in most jurisdictions |
| Risk (ISO 31000) | Effect of uncertainty on objectives |
| Risk appetite | Board-set — how much risk the org WILLS to take |
| Risk capacity | Max risk the firm COULD bear |
| Risk tolerance | Acceptable deviation from appetite |
| Basel op risk categories | 7 (EXCLUDES strategic + reputational) |
| UK Op Res in force | 31 March 2022 |
| UK Op Res compliance deadline | 31 March 2025 |
| EU DORA in force | January 2025 |
| ISSB standards | IFRS S1 / S2 (2023) |
| UK Twin Peaks regulators | PRA (prudential) + FCA (conduct) |
| Internal audit reports to | Audit committee (NOT CEO) |
| 3 lines of defence | Business (owns) · Compliance+Risk (oversee) · Internal Audit (assures) |
| UK s.166 | Skilled person review (regulator-mandated, firm-paid) |