FINAL ONLINE SUMMATIVE ASSESSMENT
PROGRAMME Postgraduate Diploma in Risk Management
MODULE Risk Management Framework and Measuring
YEAR 1
INTAKE July 2024
DATE 5 December 2024
SECTION A [40 MARKS]
Read the case study below and answer ALL the questions that follow.
RISK APPETITE- HOW HUNGRY ARE YOU?
Regulatory pressures, such as Basel II and a greater focus on corporate governance, have been a stimulus for many
changes in the industry – one of these has been the recognition of the need to articulate risk appetite more clearly. On the
face of it, this may seem easy to do. After all, is it not simply a combination of an institution’s desired credit rating,
regulatory capital structure and the relevant solvency needs which set the ability of the institution to withstand shocks and
therefore represent its risk appetite? For some smaller firms this approach may well be enough, but for others risk appetite
is a more complicated affair at the heart of risk management strategy and indeed the business strategy. Defined well, risk
appetite translates risk metrics and methods into business decisions, reporting and day-to-day business discussions. It sets
the boundaries which form a dynamic link between strategy, target setting and risk management. Risk appetite is of course
in the eye of the beholder. Different parts of the organisation and external stakeholders have different perspectives. Equity
investors’ appetite for risk will differ from that of the rating agencies. Equity investors want to see a return; rating agencies
want to minimise risk of default. The regulator’s perspective differs from management’s which differs from that of
customers, employees, bondholders etc. Consequently, articulating risk appetite is a complex task which requires the
balancing of many views. Some elements can be quantified but ultimately it is a question of judgement. All too often many
parties take false comfort from purely quantitative risk measures which, if they were actually attained, would in practice
result in huge reputational damage and job losses for the CEO and the chief risk officer (CRO).
There are considerable benefits in taking the time to articulate risk appetite properly. If a financial institution (or indeed any
corporate) has arrived at a crisp definition of its risk appetite it will have achieved:
Clarity over the risks that the organisation wishes to assume;
The basis for consistent communication to different stakeholders; and
Explicit articulation of the attitudes to risk of the senior management.
As CROs play a fuller role at board level, initiating a risk appetite discussion can be an ideal way to engage senior
colleagues and the board on risk issues and strategy. From experience, a top-down approach is usually the best way to
begin to tackle the problem of defining risk appetite. A top-down approach makes the requirements of the various external
stakeholders explicit and stimulates debate in the executive team. The process can also be used to engage board and non-
executive directors on the subject. The result is a robust framework that can be used to articulate appetite throughout the
group and to external stakeholders. The top-down view of risk appetite leads typically into an assessment of the desired risk
profile and an action plan to achieve it. Consultants have developed several tools and concepts to help clients cut through
the complexities of multi-dimensional problems. For example, they have found it helpful to introduce the concept of risk
capacity. An organisation’s risk capacity is the maximum amount of risk that it can assume. This is an important concept
because risk appetite must be set at a level within the capacity limit. Capacity needs to be considered before appetite.
Stakeholder views will differ on the desired safety margin, and it is crucial to understand this in setting and understanding
appetite. It is also necessary to assess other factors such as the potential impact of a risk incident, as well as the ability of
the organisation to control the activity and the market’s perception of the ‘fit’ with the institution’s other activities. These
qualitative factors, when combined with risk capacity and risk measures, enable a balanced appetite to be articulated and
monitored. A top-down approach works better than a detailed bottom-up assessment. The reason for this is that it is really
the only way to bring in the views of external stakeholders and to create a proactive statement of what management
believes its risk appetite should be. In our experience, bottom-up approaches tend to endorse the status quo and the
existing risk profile. They do not take the thinking forward. The result is often a passive description of risk appetite today
rather than a proactive view of where management wants to take the organisation. Another benefit of the top-down
approach is that it ensures that senior management are ‘on the same page’ on risk appetite. This may require more
investment at the start, but it pays dividends by making subsequent roll-out much easier.
At one client the first appointee to the newly created role of CRO has used risk appetite discussions to engage the business
unit heads in defining the links between risk and strategy. This is the first time that risk has been considered as an integral
part of the business agenda. Previously risk was treated primarily as a compliance issue to be monitored by internal audit.
Risk, Return and Reputation
It is also important to look at other aspects of risk. For example, it is essential to discuss risk in the context of a company’s
desired levels of return and growth. At corporate level in a quoted company this might involve a Total Shareholder Return
(TSR) target. Many companies set targets for these and publicise them – usually in terms of outperforming a peer group. If
we turn this around and look at it from the risk perspective, it could be interpreted that management wishes to outperform its
peers in assuming risk. We have yet to see a company set risk adjusted TSR targets. If management, however, is clear
about its risk appetite and develops a core competence in risk management it should, everything else being equal, be able
to deliver superior returns to its shareholders. Similar arguments apply to unquoted companies such as mutual institutions
and cooperative banks. By building a risk management competence, returns to members should improve. Hunger for
returns without a defined appetite for risk can lead to disaster. Many apparent risk management failures have been caused
by profits being chased and risks being assumed that were poorly understood. Often management makes the mistake of
focusing on the appetite of one group of stakeholders without giving sufficient weight to the appetites of others. Experience
shows that reputation can be damaged even if the firm survives. Sometimes severe reputational damage can be caused by
an incident in one part of the group leading to contagion and damage elsewhere. This can be particularly acute in financial
institutions which require the trust of their depositors or policyholders to remain solvent. Without a top-down perspective,
such risks can be missed. It is essential to take a multi-dimensional and balanced view of risk appetite and periodically to
refresh it. Admittedly this can be difficult, as it is often very hard for management to be objective about how others see the
institution.
Sources: Barfield, R (2020) and Towers Watson (2023).
Answer ALL the questions in this section.
QUESTION 1 (40 Marks)
1.1 As outlined in the case study, equity investors and rating agencies have differing risk appetites, equity (20 marks)
investors prioritize returns, while rating agencies focus on minimizing the risk of default.
As a risk practitioner, demonstrate the significance of clearly defining risk appetite for both equity investors
and rating agencies, providing relevant examples to support your discussion.
1.2 You have been requested by Mr Hlubi a banking executive in one of the leading banks in South Africa to (20 marks)
recommend the approach and or strategies that he needs to consider in effectively presenting the
organisation’s risk profile. Provide a comprehensive evaluation of the proposed methods.
SECTION B [60 MARKS]
Answer ANY THREE (3) questions in this section.
QUESTION 2 (20 Marks)
Sanlam, a leading financial services group based in South Africa with a significant presence across Africa and global
markets, has embraced advanced technology as part of its digital transformation to improve customer experience and
operational efficiency. However, the rapid growth of technology has also exposed Sanlam to challenges, such as
cybersecurity threats. For example, the company identified vulnerabilities in its online portal due to increasing cyberattacks
targeting financial institutions. In this context, critically examine the standards and or frameworks that Sanlam can adopt to
manage risks associated with technology and artificial intelligence.
QUESTION 3 (20 Marks)
G4S is a global security company that, among other services, specializes in the secure transportation of cash. In South
Africa, G4S is responsible for moving large sums of money between banks, ATMs, retail outlets, and other financial
institutions. This critical service ensures the smooth functioning of the economy by facilitating the flow of cash. Given their
business model they are exposed to numerous risks including the threat of robbery and armed attacks. As a risk
management expert, examine the various techniques that you will utilise in identifying the risks that the organisation can be
potentially exposed to.
QUESTION 4 (20 Marks)
SteelProof Manufacturers CEO, Jane Doe, is alerted to irregularities in the company's financial statements. The company's
external auditors, during a routine audit, notice discrepancies between reported revenues and bank deposits. Further
investigation reveals that the discrepancies span several years, amounting to a significant loss of funds. As the lead
specialist in enterprise risk management, advise Jane Doe on the framework that the organisation needs to prioritize and its
benefits. Your response should make use of relevant examples.
QUESTION 5 (20 Marks)
Standard Bank, a prominent financial institution offering a wide range of services such as retail banking, corporate banking,
and wealth management, has been operating for over 50 years and holds a strong domestic and international presence.
Despite its success, the rapidly evolving financial landscape and increasing regulatory requirements highlight the need for a
comprehensive approach to risk management. In a meeting convened by the CEO with the executive management team
and key department heads, including the Chief Risk Officer (CRO), Chief Financial Officer (CFO), Chief Information Officer
(CIO), and Head of Internal Audit, the CEO stresses the importance of creating detailed documentation to guide risk
management practices. In this context, outline the key components that should be included in these documents.
END OF PAPER