Wesleyan University-Philippines
Maria Aurora, Aurora
College of Business and Accountancy
INTRODUCTION TO RISK MANAGEMENT
Risk refers to the possibility that an event or condition may occur that could adversely affect the
achievement of an organization’s objectives. Risk can arise from internal factors (such as employee error or
system failure) or external factors (such as economic changes, natural disasters, or regulatory changes).
Definition of Risk Management
Risk Management is a systematic and continuous process of identifying, analyzing, evaluating,
and managing potential risks to minimize losses and protect the organization’s resources,
profitability, and sustainability. According to Cabrera, risk management is a shared responsibility of
management and the board of directors, not merely an operational activity.
Risk management is intentionally proactive, not reactive. It can be as simple as one crew member
mentioning that a coworker needs to wear her safety glasses, or it may involve something as complex as a
full asset allocation modeling of all of your organization’s capital assets. Risk management practices can
even be applied to events as broad and far-reaching as the loss of a major employer in the community.
Different situations and events can simultaneously result in both good and bad consequences. Each
consequence may require a different risk management strategy. As an example, let’s say that a new 300-
home subdivision is planned for your community. On the positive side, an event like this will likely be
welcomed as it will mean more tax revenues, increased population to support local business, and vitality for
the community. On the negative side, however, it may also result in increased traffic and added demands on
law enforcement and fire services, and it may upset neighbors who are averse to change. Each issue will
require a separate risk management strategy.
Importance of Risk Management
Risk management is a fundamental management function and an essential component of good
corporate governance, particularly in organizations exposed to financial, operational, legal, and reputational
uncertainties. According to Cabrera, the importance of risk management lies in its ability to protect
organizational objectives while allowing businesses to pursue opportunities responsibly.
1. Protection of Organizational Assets and Resources
One of the primary reasons risk managements is important is its role in safeguarding an organization’s
assets, including cash, investments, property, and information.
Without proper risk management, assets may be exposed to:
Theft and fraud
Poor investment decisions
Operational losses
Misuse or misappropriation
*Risk management identifies threats to assets and establishes controls to prevent or minimize losses.
Example: Banks implement strict segregation of duties and authorization controls to prevent employees
from misappropriating cash or manipulating customer accounts.
2. Reduction of Financial Losses and Business Failures
Risk management helps organizations anticipate potential losses and take preventive action before risks
materialize. Financial losses often arise from unmanaged risks such as loan defaults, market volatility, or
operational failures.
*Cabrera emphasizes that unmanaged risks can accumulate and eventually threaten the survival of the
business.
Example: A bank that fails to manage credit risk may experience a high level of non-performing loans,
leading to liquidity problems and possible closure.
3. Improvement of Decision-Making
Risk management improves the quality of management decisions by ensuring that decisions are made with
full awareness of potential consequences. Managers who understand risks are better able to:
Compare alternatives
Balance risk and return
Avoid impulsive or uninformed decisions
*Risk management does not eliminate risk but ensures that risks are understood and consciously accepted.
Example: Before approving a large corporate loan, a bank evaluates the borrower’s financial condition,
industry risk, and repayment capacity to make an informed lending decision.
4. Support for Business Continuity and Stability
Another vital importance of risk management is ensuring business continuity. Unexpected events such as
system failures, natural disasters, or economic crises can interrupt operations if risks are not anticipated.
Risk management helps organizations:
Identify critical operations
Prepare contingency plans
Minimize downtime and disruption
Example: Banks maintain disaster recovery plans and backup systems to continue operations even during
power outages or cyber-attacks.
5. Compliance with Laws, Regulations, and Standards
Cabrera highlights those financial institutions operate in highly regulated environments. Risk management
ensures compliance with legal and regulatory requirements and reduces exposure to fines, penalties, and
legal action.
Failure to manage compliance risk can result in:
Regulatory sanctions
Loss of operating licenses
Criminal liability
Example: Banks implement anti-money laundering (AML) systems to manage regulatory risk and avoid
penalties imposed by central banks and government regulators.
6. Protection of Reputation and Public Trust
Reputation is one of the most valuable—but fragile—assets of an organization. Risk management helps
prevent events that may cause reputational damage, such as fraud scandals, data breaches, or unethical
conduct.
According to Cabrera, reputational risk can lead to:
Loss of customer confidence
Withdrawal of deposits
Decline in market value
Example: A data breach in a bank may result in customers closing accounts due to loss of trust, even if
financial losses are limited.
7. Alignment with Corporate Governance and Accountability
Risk management is closely linked with corporate governance. The board of directors is responsible for
overseeing risk and ensuring that management establishes effective risk management systems.
Cabrera stresses that effective risk management promotes:
Transparency
Accountability
Ethical behavior
Example: A Board Risk Oversight Committee regularly reviews risk reports to ensure management is
addressing major financial and operational risks appropriately.
8. Achievement of Organizational Objectives and Sustainability
Ultimately, the importance of risk management lies in its contribution to the achievement of organizational
goals. By managing uncertainty, organizations are able to:
Protect profitability
Support long-term growth
Sustain operations in volatile environments
*Risk management allows organizations to take calculated risks necessary for success while avoiding
catastrophic losses.
Example: Banks balance risk and return by diversifying loan portfolios across industries rather than
concentrating loans in a single high-risk sector.
NAME: __________________________ DATE:
YEAR&COURSE: ____________
ACTIVITY 1: Identify the term or concept being described in each statement. Write only the most
appropriate answer on your answer sheet.
1) _____________________ A condition where potential adverse outcomes arise from both internal
failures such as human error and external forces such as regulatory changes or natural disasters that
may prevent an organization from achieving its objectives.
2) _____________________ The managerial process that is systematic, continuous, and proactive,
involving the identification, analysis, evaluation, and control of uncertainty to safeguard profitability
and long-term sustainability.
3) _____________________ The characteristic of risk management that emphasizes anticipation of
potential problems before losses occur, rather than acting only after damage has already happened.
4) _____________________ The principle that risks management is not solely an operational function,
but requires oversight and accountability from the highest level of corporate leadership.
5) _____________________ The concept illustrated when a single event; such as the development of a
large residential subdivision—creates both opportunities and threats, each requiring different
management responses.
6) _____________________ The role of risk management that focuses on protecting tangible and
intangible assets, including cash, data, investments, and property, from theft, misuse, and
misappropriation.
7) _____________________ The accumulation of unmanaged uncertainties that can gradually escalate
into liquidity problems and possible organizational collapse.
8) _____________________ The managerial benefit gained when decisions are made with full
awareness of risk–return trade-offs, allowing executives to consciously accept uncertainty rather than
acting impulsively.
9) _____________________ The function of risk management that ensures an organization can
continue critical operations despite unexpected disruptions such as cyberattacks, system failures, or
natural disasters.
10) _____________________ The risk management purpose that minimizes exposure to penalties,
sanctions, license revocation, and criminal liability by ensuring adherence to laws and regulatory
standards.
11) _____________________ A fragile but highly valuable organizational asset that, once damaged by
fraud, unethical conduct, or data breaches, can result in loss of confidence, withdrawal of funds, and
declining market value.
12) _____________________ The governance mechanism through which directors regularly review risk
reports to ensure management is addressing major financial, operational, and compliance risks.
13) _____________________ The management approach that allows organizations to pursue growth
opportunities while preventing catastrophic losses through calculated and controlled exposure to
uncertainty.
14) _____________________ The long-term organizational outcome supported by effective risk
management when uncertainty is controlled and resources are protected despite volatile
environments.
15) _____________________ The strategic technique illustrated when a bank spreads its loan portfolio
across multiple industries to avoid excessive exposure to any single high-risk sector.
Basic Principles of Risk Management
Risk management is not a one-time activity but a continuous and structured discipline that
supports effective management, good governance, and sustainable organizational performance. Cabrera &
Cabrera emphasize that risk management must be guided by a set of basic principles to ensure it is effective
and value-adding, particularly in complex and highly regulated environments such as financial institutions.
1. Risk Management Should Be Systematic and Structured
Risk management must follow a systematic and structured approach rather than being done randomly or
on an ad hoc basis. This means that risks should be identified, analyzed, evaluated, treated, and monitored
using established procedures and frameworks.
A systematic approach ensures:
Consistency in assessing risks
Avoidance of overlooking significant risks
Proper documentation and accountability
Example: Banks use formal Enterprise Risk Management (ERM) frameworks and risk registers to
consistently identify and assess credit, market, and operational risks instead of relying on management
intuition alone.
2. Risk Management Should Be Integrated into All Business Processes
Cabrera explains that risk management should not be treated as a separate function but must be embedded
in all organizational activities, including planning, operations, decision-making, and performance
evaluation.
When risk management is integrated:
Every department becomes risk-aware
Risks are addressed at their source
Decision-making improves at all levels
Example: In loan approval processes, banks integrate risk assessment directly into credit evaluation rather
than reviewing risks only after loans have been released.
3. Risk Management Should Be Continuous and Dynamic
Risks are not static; they evolve due to changes in:
Economic conditions
Technology
Regulations
Business strategies
Therefore, risk management must be continuous and dynamic, allowing organizations to adjust controls
and responses as new risks emerge or existing risks change.
Example: Cybersecurity risks continuously evolve. Banks regularly update security systems and controls to
respond to new forms of cybercrime and online fraud.
4. Risk Management Should Be Forward-Looking
According to Cabrera, effective risk management must focus not only on past and present risks but also on
future uncertainties. Organizations must anticipate potential events that could affect objectives.
Forward-looking risk management:
Promotes preparedness
Reduces surprise losses
Improves strategic resilience
Example: Banks conduct stress testing to assess how their financial position would be affected by future
economic downturns, interest rate increases, or liquidity crises.
5. Risk Management Should Be Proportionate to the Organization’s Size and Complexity
Risk management practices should be appropriate to the organization’s nature, size, and risk profile.
Overly complex systems may be inefficient for small entities, while weak systems are inadequate for large
or high-risk organizations.
Example: A small rural bank may use simpler risk assessment tools, while a universal bank requires
advanced modeling, separate risk departments, and specialized risk committees.
6. Risk Management Should Balance Risk and Opportunity
Risk management does not mean eliminating all risks. Cabrera stresses that risk is inherent in business, and
excessive risk avoidance may cause organizations to miss growth opportunities.
Effective risk management:
Encourages informed risk-taking
Balances potential losses against expected returns
Supports innovation and growth
Example: Banks accept calculated credit risks by lending to startups with viable business models instead of
rejecting all non-traditional borrowers.
7. Risk Management Should Be Aligned with Organizational Objectives
Risk management must be linked directly to the achievement of organizational goals. Risks are assessed
based on how they may hinder strategic, operational, financial, or compliance objectives.
Example: If a bank’s objective is to expand digital banking, it must manage technology, cybersecurity, and
reputational risks that could undermine that goal.
8. Risk Management Should Promote Accountability and Responsibility
Effective risk management requires clearly defined roles and responsibilities, including:
Board oversight of risk
Management responsibility for implementation
Assigned risk owners for specific risks
This principle ensures that risks are actively managed rather than ignored.
Example: Banks assign risk owners for credit risk, operational risk, and compliance risk to ensure
accountability and timely response.
9. Risk Management Should Support Good Corporate Governance
Cabrera highlights that risk management is an essential component of good corporate governance. The
board of directors must ensure that:
A sound risk management framework is in place
Significant risks are identified and monitored
Internal controls are effective
Example: A Board Risk Oversight Committee regularly reviews risk reports to ensure major threats to the
bank’s stability are properly addressed.
10. Risk Management Should Encourage a Risk-Aware Culture
Finally, risk management should foster a risk-aware organizational culture, where employees understand
risks relevant to their roles and act responsibly.
A strong risk culture:
Promotes ethical behavior
Reduces negligence and errors
Encourages early reporting of risks
Example: Bank employees are trained to identify suspicious transactions and report them promptly as part
of anti-money laundering risk management.
Risk Management Process
The risk management process refers to the systematic and logical sequence of activities
undertaken by an organization to identify, assess, manage, and monitor risks that may affect the achievement
of its objectives. Cabrera emphasizes that risk management is not a single action but a continuous cycle
that must be embedded in management decision-making and corporate governance.
1. Risk Identification
Risk identification is the first and most critical step in the risk management process. It involves
recognizing and identifying all possible risks—both internal and external—that may threaten the
organization’s objectives. These risks may relate to finance, operations, compliance, strategy, or reputation.
At this stage, management asks the question:
“What could go wrong?”
*Failure to properly identify risks may result in significant threats being ignored until losses already occur.
Common Sources of Risk
Economic changes
Human error or fraud
Technological failure
Regulatory changes
Natural disasters
Example: A bank identifies risks related to loan defaults, cyber-attacks, employee fraud, and sudden
withdrawal of deposits. Recognizing these risks allows management to prepare appropriate controls.
2. Risk Assessment and Risk Analysis
Once risks are identified, the organization must analyze and assess them to determine:
Likelihood – the probability that the risk will occur
Impact – the severity of consequences if the risk occurs
This step helps management prioritize risks according to their significance. Not all risks are equally
dangerous; some risks may be tolerable, while others require immediate attention.
*Cabrera emphasizes that proper risk assessment ensures that management resources are focused on the
most critical risks.
Example: A financial institution assesses that credit risk in unsecured consumer loans has a high
probability and high financial impact, while minor clerical errors may have low impact.
3. Risk Evaluation and Prioritization
Risk evaluation involves comparing assessed risks against the organization’s:
Risk appetite (the level of risk it is willing to accept), and
Risk tolerance (acceptable variation from objectives).
After evaluation, risks are ranked or prioritized based on urgency and potential damage.
This ensures that management does not overreact to minor risks while ignoring major threats.
Example: A bank prioritizes liquidity risk over office equipment damage because liquidity problems can
threaten the institution’s survival, while equipment damage can be insured or replaced.
4. Risk Treatment / Risk Response
Risk treatment refers to the actions taken to manage identified risks. According to Cabrera, management
can choose from four main risk responses:
A. Risk Avoidance
Eliminating activities that expose the organization to unacceptable risk.
Example: A bank avoids lending to industries with extremely high default rates.
B. Risk Reduction (Mitigation)
Reducing the likelihood or impact of the risk through controls, policies, or procedures.
Example: Banks reduce fraud risk by implementing internal controls, employee training, and segregation of
duties.
C. Risk Transfer (Risk Sharing)
Shifting risk to another party through insurance, outsourcing, or hedging.
Example: A bank purchases insurance to cover losses from robbery or fire.
D. Risk Acceptance
Accepting the risk when its costs are minimal or unavoidable.
Example: Minor operational errors are accepted because preventing them entirely would be too costly.
5. Risk Monitoring and Review
Risk management does not end after controls are implemented. Risks must be continuously monitored and
reviewed to ensure that:
Controls remain effective
New risks are identified
Risk levels have not increased
*Cabrera stresses that risk monitoring allows management to adapt to changes in the business and external
environment.
Example: Banks regularly monitor delinquent loan accounts to detect early warning signs of borrower
default.
6. Risk Communication and Reporting
An effective risk management process includes clear communication and reporting of risk information to:
Management
Risk committees
Board of directors
*Timely reporting ensures transparency and accountability and allows the board to provide proper
oversight.
Example: A Chief Risk Officer submits monthly risk reports to the Board Risk Oversight Committee
highlighting major financial and operational risks.
7. Continuous Improvement of the Risk Management Process
Explanation
Cabrera emphasizes that risk management should be continually improved based on:
Audit findings
Risk incidents
Changes in regulations
Lessons learned from past failures
*This ensures that the organization remains resilient and responsive to uncertainty.
Example: After experiencing a data breach, a bank strengthens cybersecurity controls and updates its risk
assessment framework.
RISK TREATMENT / RISK RESPONSE
Risk Treatment, also called Risk Response, refers to the strategic actions taken by management
after risks have been identified, analyzed, and prioritized. Its purpose is to bring risk levels within an
acceptable range consistent with the organization’s risk appetite and objectives.
Cabrera emphasizes that risk treatment does not aim to eliminate all risks, but to control risks intelligently
so that business objectives can still be achieved without exposing the organization to catastrophic losses.
Types of Risk Response
1. Risk Avoidance
Risk avoidance involves eliminating the activity that gives rise to the risk, usually when the risk is too
severe or unacceptable.
Used when potential losses outweigh benefits
May limit growth opportunities if overused
Example: A bank refuses to provide loans to businesses operating in illegal or highly unstable industries to
avoid very high default and reputational risks.
2. Risk Reduction (Risk Mitigation)
Risk reduction involves taking steps to lessen the likelihood or impact of risks, rather than eliminating
them entirely. This is the most commonly used risk response.
Methods include:
Policies and procedures
Internal controls
Training and supervision
Technology solutions
Example: To reduce fraud risk, banks introduce segregation of duties, internal audits, and automated
transaction monitoring systems.
3. Risk Transfer (Risk Sharing)
Risk transfer shifts the financial impact of risk to another party through:
Insurance
Outsourcing
Hedging
*Cabrera notes that risk transfer does not remove risk entirely but reduces the organization’s direct
exposure.
Example: Banks purchase insurance to cover losses arising from fire, robbery, or natural disasters.
4. Risk Acceptance
Risk acceptance occurs when management consciously decides to retain the risk, usually because:
The risk impact is minimal
Mitigation costs exceed benefits
The risk is unavoidable
Accepted risks must still be monitored.
Example: A bank accepts small clerical errors in processing transactions, since eliminating them completely
would be impractical and too costly.
RISK MONITORING AND REVIEW
Risk Monitoring and Review is the process of continuously tracking identified risks and
evaluating the effectiveness of existing controls. Cabrera stresses that risk management is dynamic, and
risks can increase, decrease, or change in nature over time.
Monitoring ensures that:
Controls remain effective
New risks are promptly identified
Risk responses remain appropriate
Importance of Risk Monitoring and Review
Risk monitoring is important because:
Business environments constantly change
Controls may weaken or become obsolete
New threats may emerge
*Without monitoring, even well-designed risk controls can fail.
Key Activities in Risk Monitoring and Review
1. Monitoring Risk Indicators
Organizations monitor risk indicators such as:
Non-performing loan levels
Liquidity ratios
System downtime
Compliance breaches
Example: Banks track loan delinquency rates to detect early signs of borrower default.
2. Reviewing Effectiveness of Controls
Management assesses whether controls are:
Operating as intended
Adequate to manage current risk levels
Example: Internal audit reviews whether loan approval procedures are being followed and remain effective
in managing credit risk.
3. Identifying Emerging Risks
New risks may arise due to:
Technology changes
Economic shifts
Regulatory developments
Example: With the rise of online banking, banks began identifying cybersecurity threats as a major
emerging risk.
4. Reporting and Feedback
Risk information must be reported to:
Senior management
Risk committees
Board of directors
Example: The Chief Risk Officer submits periodic risk reports to the Board Risk Oversight Committee for
governance oversight.
ELEMENTS OF RISK MANAGEMENT
The Elements of Risk Management refer to the key components that make a risk management
system effective and sustainable. Cabrera identifies these elements as essential for integrating risk
management into the organization.
1. Risk Appetite
Risk appetite is the amount and type of risk an organization is willing to accept in pursuit of its
objectives.
Set by the board of directors
Guides decision-making across the organization
Example: A bank may be willing to accept moderate credit risk but very low liquidity risk to protect
depositor funds.
2. Risk Tolerance
Risk tolerance defines the acceptable level of variation from objectives and provides specific limits for
different risk areas.
Example: A bank sets a maximum acceptable percentage of non-performing loans to prevent excessive
credit risk.
3. Risk Governance and Oversight
Risk governance refers to the roles and responsibilities involved in risk management, including:
Board oversight
Risk committees
Senior management accountability
Example: A Board Risk Oversight Committee ensures that management is effectively addressing major
financial and operational risks.
4. Risk Ownership and Accountability
Each significant risk must have a designated risk owner responsible for managing and monitoring it.
Example: The credit department head is assigned responsibility for managing credit risk in lending
operations.
5. Risk Culture
Risk culture represents the organization’s shared attitudes, values, and behaviors toward risk.
A strong risk culture:
Encourages ethical behavior
Promotes early reporting of risks
Discourages reckless decision-making
Example: Bank employees are encouraged and trained to report suspicious transactions without fear of
retaliation.
6. Risk Communication and Reporting
Effective risk management requires clear, timely communication of risk information across all levels of
the organization.
Example: Regular risk dashboards are shared with management and the board to support informed
decision-making.
ACTIVITY 2: From Risk Identification to Risk Control
Read the given scenario carefully and answer all questions completely. Answers must be brief but
well-reasoned.
You are a Risk Officer of ABC Bank, a medium-sized commercial bank expanding its digital services.
Recently, the bank has experienced the following issues:
- A rise in online fraud attempts
- Occasional system downtime during peak banking hours
- A small but increasing number of loan defaults in unsecured consumer loans
- Increasing regulatory scrutiny on anti-money laundering (AML) compliance
- Minor clerical errors in transaction processing that rarely result in material losses
*The Board of Directors has asked you to evaluate the risks and appropriate risk management actions.
For each risk listed below, identify the most appropriate type of risk response (Risk Avoidance, Risk
Reduction, Risk Transfer, or Risk Acceptance) and briefly justify your answer (2–3 sentences).
A. Online fraud attempts
Risk Response: __________________________
Justification:
B. System downtime during peak hours
Risk Response: __________________________
Justification:
C. Unsecured consumer loan defaults
Risk Response: __________________________
Justification:
D. AML-related regulatory penalties
Risk Response: __________________________
Justification:
E. Minor clerical processing errors
Risk Response: __________________________
Justification:
RISKS ASSOCIATED WITH FINANCIAL INSTITUTIONS
Financial institutions face unique and complex risks because they primarily handle money, credit,
and public trust. Unlike ordinary business entities, banks and other financial institutions operate in a highly
regulated environment and deal with funds entrusted to them by depositors and investors. Because of this,
effective risk management is critical to maintain financial stability, protect stakeholders, and preserve
confidence in the financial system.
Cabrera emphasize that failure to manage these risks can lead not only to institutional collapse but also to
systemic risk that may affect the entire economy.
CREDIT RISK
Credit risk is the risk that a borrower will fail to meet contractual loan obligations—either principal,
interest, or both—resulting in financial loss for the financial institution.
Credit risk arises mainly from:
Loans and advances
Credit card accounts
Guarantees and letters of credit
This risk is considered the most significant risk faced by banks because lending represents a major portion
of their assets.
When borrowers fail to repay loans, banks experience non-performing loans (NPLs). High levels of NPLs
reduce profitability, weaken capital, and threaten solvency. Credit risk may be influenced by economic
conditions, borrower behavior, and weaknesses in credit evaluation processes.
Example: A borrower defaults on a housing loan after losing employment. The bank suffers losses because
mortgage repayments stop while legal foreclosure proceedings take time and incur additional costs.
MARKET RISK
Market risk arises from adverse movements in market prices that affect the value of financial
instruments held by financial institutions. These include fluctuations in:
Interest rates
Foreign exchange rates
Equity prices
Financial institutions are exposed to market risk when they invest in securities, trade financial instruments,
or maintain positions sensitive to market movements. Changes in interest rates, for example, can
significantly affect bond prices, loan valuations, and profitability.
Example: A bank holding long-term government bonds suffer losses when interest rates rise, because bond
prices fall as newer bonds offer higher yields.
LIQUIDITY RISK
Liquidity risk is the risk that a financial institution will be unable to meet its short-term financial
obligations as they fall due, even if it owns sufficient assets.
Liquidity risk occurs when assets cannot be quickly converted into cash without substantial loss. Banks must
ensure sufficient liquid funds to honor withdrawals and maturing obligations. Loss of depositor confidence
can rapidly escalate liquidity problems.
Example: During a panic, depositors withdraw funds simultaneously, forcing a bank to sell investment
securities at a loss to generate cash, worsening its financial position.
OPERATIONAL RISK
Operational risk results from failures in:
Internal processes
Human error
Systems and technology
External events
Operational risk includes losses from fraud, system breakdowns, procedural errors, cyber-attacks, or natural
disasters. Unlike credit or market risk, operational risk arises from day-to-day activities and can occur even
in the absence of financial market movements.
Example: A bank employee commits internal fraud by creating fake loan accounts and diverting funds,
resulting in financial loss and regulatory investigation.
LEGAL AND REGULATORY RISK
Legal and regulatory risk is the risk of loss arising from failure to comply with laws, regulations,
contractual obligations, or supervisory requirements governing financial institutions.
Financial institutions operate under strict regulatory frameworks imposed by central banks, securities
regulators, and other government agencies. Non-compliance may result in:
Fines and penalties
License suspension or revocation
Litigation and legal costs
Compliance failures often expose banks to financial and reputational damage.
Example: A bank is penalized for violating anti-money laundering (AML) regulations after failing to detect
suspicious transactions, resulting in heavy fines and closer regulatory scrutiny.
REPUTATIONAL RISK
Reputational risk refers to the potential loss arising from negative public perception of a financial
institution. Public confidence is essential to the survival of financial institutions. Even a single scandal,
whether financial, ethical, or operational—can significantly damage reputation. Reputational risk often
arises as a consequence of other risks such as fraud, regulatory violations, or service failures.
Example: A data breach exposing customer information damages public trust, leading to account closures
and reduced deposits as customers transfer funds to other banks.
RELATIONSHIP OF RISK MANAGEMENT TO CORPORATE GOVERNANCE
Cabrera emphasizes that risk management is a core responsibility of corporate governance. The
Board of Directors must actively oversee how risks are identified, assessed, and managed.
This oversight is commonly exercised through:
Enterprise Risk Management (ERM) frameworks
Board Risk Oversight Committees
Chief Risk Officers (CROs)
Strong governance ensures that:
Major risks are identified early
Risk responses align with organizational objectives
Ethical standards are upheld
Management remains accountable
Effective governance integrates risk management with strategic planning rather than treating it as a purely
operational function.
Example: A bank’s Board Risk Oversight Committee regularly reviews risk reports on credit, market, and
liquidity risks to ensure that management actions are aligned with the bank’s risk appetite and regulatory
requirements.
ACTIVITY 3: Write TRUE if the statement is correct. Write FALSE if it is incorrect.
1) ______ Because financial institutions primarily manage deposits and public trust, failure to manage
risk may result in consequences that extend beyond the institution itself and affect the wider
economy.
2) ______ Credit risk exists only when borrowers completely stop paying both principal and interest,
and not when payments are delayed or partially settled.
3) ______ A rising level of non-performing loans (NPLs) directly weakens a bank’s capital position and
may threaten its long-term solvency.
4) ______ Credit risk is considered less significant for banks than market risk because market prices
fluctuate more frequently than loan repayments.
5) ______ When a borrower defaults due to external economic conditions such as unemployment, the
resulting loss is still classified as credit risk rather than market or operational risk.
6) ______ Market risk affects financial institutions only when they actively traded securities and does
not apply to banks holding long-term investment instruments.
7) ______ An increase in interest rates generally causes the market value of existing fixed-income
securities held by banks to decline.
8) ______ Foreign exchange risk is a form of market risk that may arise even if the bank’s domestic
currency position remains stable.
9) ______ Liquidity risk occurs only when a bank has insufficient total assets to cover its liabilities.
10) ______ A bank may experience liquidity problems even if it is solvent, particularly when depositor
confidence deteriorates rapidly.
11) ______ Forced liquidation of assets at unfavorable prices during a bank run is an example of
liquidity risk materializing into actual financial loss.
12) ______ Operational risk cannot arise independently and must always be triggered by market or credit
risk events.
13) ______ Losses arising from internal fraud, system outages, or cyberattacks are classified as
operational risk even if market conditions are stable.
14) ______ Legal and regulatory risk arises only when a financial institution intentionally violates laws
and regulations.
15) ______ Failure to comply with anti-money laundering (AML) regulations may expose a bank to both
financial penalties and reputational damage.
16) ______ Reputational risk is insignificant if a bank remains profitable despite negative media
coverage.
17) ______ Reputational risk often originates from the consequences of other risks such as operational
failures, fraud, or regulatory violations.
18) ______ Risk management is considered a purely operational responsibility and does not require
direct involvement of the Board of Directors.
19) ______ The use of Enterprise Risk Management (ERM) frameworks reflects the integration of risk
management into strategic planning and governance oversight.
20) ______Regular review of credit, market, and liquidity risk reports by a Board Risk Oversight
Committee demonstrates the link between risk management and corporate governance.