Rifat Rahman
Assistant Professor, BUET
[Link]
▪ Hazard, a chance of bad consequences, loss or exposure to mischance [The
Concise Oxford English Dictionary]
▪ Any event or action that may adversely affect an organization’s ability to achieve its
objectives and execute its strategies [For financial risks]
▪ The quantifiable likelihood of loss or less-than-expected returns
While these definitions capture some of the elements of risk, no single one-sentence
definition is entirely satisfactory in all contexts
▪ Independently of any context, risk relates strongly to uncertainty, and hence to the
notion of randomness and probability.
▪ Consider the following examples:
▪ An investor who holds stock in a particular company; [Uncertainty: the investor holds
today an asset with an uncertain future value]
▪ An insurance company that has sold an insurance policy; [Uncertainty: the policy sold
may or may not be triggered by the underlying event covered]
▪ A home owner who decides to convert a fixed-rate mortgage into a variable one.
[Uncertainty: our decision today to enter into this refinancing agreement will change (for
better or for worse) the future repayments]
So randomness plays a crucial role in the valuation of current products held by the
investor, the insurance company or the home owner.
Here, we discuss risk in the context of finance and insurance.
▪ Market risk: The risk of a change in the value of a financial position due to
changes in the value of the underlying components (factors) on which that position
depends, such as stock and bond prices, exchange rates, commodity prices, etc.
▪ Credit risk: The risk of not receiving promised repayments on outstanding
investments such as loans and bonds, because of the “default” of the borrower.
▪ Operational risk: The risk of losses resulting from inadequate or failed
internal processes, people and systems, or from external events.
▪ Liquidity risk refers to the risk that a financial institution or individual may not be
able to meet short-term financial obligations due to an inability to convert
assets into cash without significant loss. It arises when there is a lack of market
activity, leading to difficulty in selling assets at their fair value. For example, a bank
that has a large amount of long-term loans but limited short-term cash reserves
may struggle to meet withdrawal demands, causing potential instability.
▪ Model risk is the risk that a financial model used to assess the value of assets,
liabilities, or risks may be incorrect or misapplied, leading to inaccurate
predictions and, consequently, poor decision-making. For instance, during the 2008
financial crisis, the reliance on flawed models that underestimated the risk of
mortgage-backed securities was a major contributor to market collapse.
▪ Underwriting risk refers to the risk that a financial institution faces when it
underwrites a policy or loan, specifically the possibility that the actual losses
or claims may exceed the expected ones. This can occur if the underwritten
entity defaults.
We should stress that the only viable way forward for a successful handling of
financial risk consists of a holistic approach, i.e. an integrated approach taking
all types of risk and their interactions into account.
▪ Risk measurement/assessment is essentially a statistical issue; based on
historical observations and given a specific model, a statistical estimate of the
distribution of the change in value of a position, or one of its functionals, is
calculated.
▪ In a very general answer to the question of what risk management is about,
Kloman (1990) writes that:
▪ To many analysts, politicians, and academics, it is the management of environmental and
nuclear risks, those technology-generated macro-risks that appear to threaten our
existence.
▪ To bankers and financial officers it is the sophisticated use of such techniques as currency
hedging and interest-rate swaps.
▪ To insurance buyers or sellers it is coordination of insurable risks and the reduction of
insurance costs.
▪ To hospital administrators it may mean “quality assurance”.
▪ To safety professionals it is reducing accidents and injuries.
In summary, risk management is a discipline for living with the possibility that future events
may cause adverse effects.
▪ Babylon (circa 1750 BC): Early risk management practices appeared with
Hammurabi's Code, where laws addressed financial risks, offering protections to
merchants through risk-sharing agreements.
▪ Ancient Greece & Rome: Introduction of marine insurance and risk-sharing
contracts, where shipowners and merchants would spread the risks of sea voyages.
▪ Medieval Europe: The development of guilds and insurance systems to manage
risks related to trade, commerce, and craftsmanship, ensuring protection from
accidents and losses.
▪ Renaissance (15th-16th Century): Mathematical probability theory emerged,
laying the foundation for modern risk management through the works of Blaise
Pascal and Gerolamo Cardano.
▪ 17th Century: The rise of formal insurance markets in London, such as Lloyd's
of London, to insure ships and cargo against loss, a significant step in commercial
risk management.
▪ 18th Century: Development of life insurance companies in response to
epidemics and the increasing understanding of life expectancy and mortality risks.
▪ 19th Century: The Industrial Revolution spurred the need for better risk
management practices, with the growth of corporate insurance and the
establishment of actuarial science.
▪ 20th Century: Introduction of modern portfolio theory (Markowitz, 1950s) and
financial derivatives, revolutionizing how firms and investors manage market
risks.
▪ 21st Century: Risk management becomes central to global finance, with
regulatory frameworks (e.g., Basel III) and the growth of sophisticated models for
credit, market, and operational risks after the 2008 financial crisis.
▪ Basel III (2010): Introduced after the 2008 financial crisis to strengthen global
bank capital requirements, liquidity risk, and leverage management. Key reforms
include:
▪ Higher capital requirements: Banks must hold more and higher-quality capital to
absorb shocks.
▪ Leverage ratio: Imposes a cap on the amount of leverage banks can take on.
▪ Liquidity coverage ratio (LCR): Requires banks to hold enough high-quality liquid
assets to cover 30 days of cash outflows.
▪ Net stable funding ratio (NSFR): Ensures that banks maintain stable funding relative to
the liquidity of their assets.
▪ Dodd-Frank Act (2010): US legislation aimed at reducing systemic risks in the
financial industry, focusing on:
▪ Volcker Rule: Limits proprietary trading by banks and restricts their investments in
hedge funds and private equity.
▪ Increased oversight: Establishment of the Financial Stability Oversight Council (FSOC)
to monitor systemic risks.
▪ Derivatives regulation: Requires greater transparency and regulation in over-the-
counter (OTC) derivatives trading.
▪ General Data Protection Regulation (GDPR, 2018): Focuses on data privacy and
security, affecting risk management in:
▪ Data governance: Requires firms to implement stronger controls on personal data
protection, with fines for breaches.
▪ Operational risk: Increased scrutiny over how firms manage risks related to data
handling and cyber threats.
▪ BCBS 239: Enhances risk data aggregation and reporting standards for orgs,
aimed at improving risk management processes and decision-making.
▪ Principle-based approach: Focuses on governance, data accuracy, timeliness, and
comprehensiveness of risk data across organizations.
▪ Cybersecurity Regulations: Global regulations are evolving with frameworks like
NIST (US) and ISO 27001, requiring firms to implement strong cybersecurity
measures to mitigate operational risks related to data breaches and cyberattacks.
▪ Solvency II (2016): EU regulation for insurance companies, focusing on:
▪ Risk-based capital requirements: Ensures that insurers hold capital proportional to the
risks they face.
▪ Own Risk and Solvency Assessment (ORSA): Requires insurers to regularly assess their
solvency and risk profile under stressed conditions.
▪ Corporate Finance & Business
▪ Prevent Financial Losses: Effective risk management helps businesses avoid or mitigate
losses from market volatility, poor investments, or operational issues.
▪ Improve Decision-Making: Risk management ensures informed decisions by
understanding potential downsides and preparing for uncertainties.
▪ Enhance Profitability: By reducing risks, companies can focus on maximizing growth
and profitability through calculated risk-taking.
▪ Ensure Compliance: It helps meet regulatory requirements, preventing penalties and
legal liabilities.
▪ Safeguard Reputation: Managing risks related to fraud, data breaches, or product
failures protects a company’s brand and trust with stakeholders.
▪ Banking & Financial Institutions
▪ Maintain Stability: Managing credit, market, and operational risks helps banks stay
solvent and avoid defaults.
▪ Capital Allocation: Proper risk management ensures that capital is used efficiently and
that adequate reserves are maintained for potential losses.
▪ Prevent Systemic Risk: Risk management across the banking sector reduces the
possibility of widespread financial crises.
▪ Insurance Industry
▪ Accurate Pricing of Policies: Effective risk assessment allows insurers to set premiums
that reflect the true risk of insuring individuals or businesses.
▪ Minimize Payout Risks: By managing underwriting risks, insurers ensure that they can
cover claims without financial strain.
▪ Portfolio Diversification: Risk management helps insurance companies diversify their
policies to spread out risks and avoid concentration in one area.
▪ Client Trust: It ensures that the insurer remains financially stable and capable of paying
claims, fostering long-term relationships with policyholders.
▪ Engineering & Construction
▪ Ensure Project Success: Identifying and managing risks related to cost overruns, delays,
or accidents helps projects stay on time and within budget.
▪ Safety Management: Risk management in engineering minimizes hazards to workers
and ensures safety standards are met, reducing legal liabilities.
▪ Quality Control: Managing risks in design and materials ensures that the project meets
quality and functional specifications.
▪ Contract Risk: Ensures that contractual risks, such as disputes or non-compliance, are
minimized to prevent costly legal battles.
▪ Healthcare
▪ Patient Safety: Managing clinical risks helps reduce medical errors, improving patient
outcomes and reducing legal liabilities
▪ Operational Efficiency: Effective risk management can streamline operations, reducing
costs and improving service quality.
▪ Financial Stability: Helps healthcare organizations manage financial risks, such as
reimbursement delays or rising costs.
▪ Information Technology (IT)
▪ Cybersecurity: Managing risks related to data breaches, hacks, or system failures
protects sensitive data and infrastructure.
▪ Operational Continuity: Risk management ensures that IT systems remain operational
and downtime is minimized.
▪ Compliance with Data Protection Laws: Ensures adherence to regulations like GDPR or
CCPA, preventing legal consequences and fines.
▪ Innovation and Scalability: Managing technological risks allows for scaling IT systems
without compromising security or performance.
▪ Environmental & Sustainability
▪ Minimize Environmental Impact: Risk management helps businesses and governments
reduce their ecological footprint and adhere to environmental regulations.
▪ Climate Change Resilience: Helps organizations plan for and mitigate the effects of
climate change, such as extreme weather or resource scarcity.
▪ Sustainability in Operations: Incorporating environmental risk management ensures
long-term sustainability of natural resources and minimizes reputational risks.
▪ Supply Chain Management
▪ Resilience to Disruptions: Identifying risks in the supply chain (e.g., natural disasters,
supplier failures) allows companies to implement contingency (ad-hoc) plans and
maintain operations.
▪ Cost Control: Managing procurement and logistical risks helps companies control costs
by preventing delays or price spikes.
▪ Supplier Relationship Management: Ensures the reliability of suppliers and fosters
strong partnerships, reducing the risk of supply failures.
▪ Extremes Matter (Tail Risks)
▪ Rare but Catastrophic Events: Traditional risk models often underestimate extreme,
low-probability events (e.g., market crashes, natural disasters), leading to insufficient
preparation for tail risks.
▪ Fat-Tailed Distributions: Financial markets and other systems exhibit fat-tailed
distributions, where extreme events occur more frequently than predicted by normal
distributions.
▪ Stress Testing Limitations: Simulating extreme scenarios accurately is challenging, as
historical data may not fully capture the range or impact of such events.
▪ The Interdependence and Concentration of Risks
▪ Risk Correlation: Risks in different sectors or asset classes often behave
interdependently, especially in times of crisis (e.g., market risks, credit risks, and liquidity
risks can spike simultaneously).
▪ Concentration of Risks: In a globally interconnected economy, the concentration of risks
in a few key entities or markets can lead to systemic failures (e.g., 2008 financial crisis).
▪ Modeling Correlations: Accurately modeling correlations between different risk types
is complex, especially when interdependencies evolve dynamically over time.
▪ The Problem of Scale
▪ Large Data and Complex Models: Quantitative risk models often require processing
vast amounts of data and using sophisticated algorithms, which can be difficult to scale
efficiently.
▪ Computational Costs: Large-scale risk management models, such as Monte Carlo
simulations, can be computationally expensive and time-consuming to run, especially in
real-time risk assessments.
▪ Granularity vs. Aggregation: Aggregating risk data from different sources and scales
(e.g., individual asset-level vs. portfolio-level) while preserving useful insights is
challenging.
▪ Interdisciplinarity
▪ Bridging Different Fields: Effective quantitative risk management requires knowledge
from multiple disciplines (finance, statistics, mathematics, economics, behavioral
science), making collaboration essential but challenging.
▪ Differing Assumptions: Risk models often rely on assumptions from various fields, which
can conflict or be difficult to harmonize, leading to inconsistent risk estimates.
▪ Communication Gaps: Translating complex quantitative risk findings into actionable
insights for non-specialist stakeholders (e.g., managers, regulators) can be difficult,
leading to misunderstandings in decision-making.
▪ Model Uncertainty
▪ Model Risk: Overreliance on mathematical models that may not fully capture market
behavior or external shocks can result in inaccurate risk assessments.
▪ Parameter Estimation: Identifying the right parameters for risk models is challenging
due to the evolving nature of markets and risks, leading to potential estimation errors.
▪ Overfitting: Complex models that perform well on historical data might fail to predict
future risks, especially if they are overfitted to past events.
▪ Data Quality and Availability
▪ Incomplete or Noisy Data: The accuracy of risk models depends on high-quality,
complete data, but often, data is either missing, incomplete, or contains errors.
▪ Short Historical Records: For certain risks (e.g., pandemics, climate change), historical
data may not be sufficient to develop reliable models.
▪ Data Privacy and Security: In some contexts, data access is limited due to privacy
concerns, making it difficult to build comprehensive risk models.
▪ Behavioral Factors
▪ Market Participant Behavior: Quantitative models often assume rational behavior, but in
reality, market participants exhibit behavioral biases, such as overconfidence or herd
behavior, which affect risk.
▪ Nonlinear Feedback Loops: Financial markets and systems are prone to nonlinear
feedback, where participants’ actions in response to risk can amplify the original risks
(e.g., fire sales or liquidity crunches).
▪ Regulatory Complexity
▪ Regulatory Variations: Different regions have different regulations, making it hard to
develop a one-size-fits-all quantitative risk model.
▪ Compliance Costs: Ensuring that quantitative risk management adheres to all applicable
regulations can add significant complexity and cost to risk models.
▪ Enhanced Decision-Making: QRM provides data-driven insights that enable
organizations to make informed decisions about investments, capital allocation,
and risk exposure, minimizing potential losses.
▪ Accurate Risk Assessment: By utilizing mathematical models and statistical
methods, QRM allows for precise measurement of various risks, including credit,
market, operational, and liquidity risks.
▪ Regulatory Compliance: QRM helps organizations adhere to regulatory
requirements by ensuring that they maintain adequate capital reserves and risk
management practices, thereby avoiding penalties and maintaining credibility.
▪ Efficient Resource Allocation: Through risk quantification, QRM aids in
prioritizing risk mitigation efforts and allocating resources effectively to areas with
the highest risk impact.
▪ Scenario Analysis and Stress Testing: QRM enables organizations to simulate
extreme market conditions and assess their potential impact, helping to prepare
for adverse scenarios and enhance resilience.
▪ Improved Risk Mitigation Strategies: By identifying correlations and
dependencies between risks, QRM supports the development of effective hedging
and diversification strategies to manage risk exposure.
▪ Continuous Monitoring and Adaptation: QRM facilitates the ongoing assessment
of risk landscapes, allowing organizations to adapt to changing conditions and
emerging risks proactively.