Risk Governance And Culture
Expert-defined terms from the Postgraduate Certificate in Risk Management for Central Banks (Bangladesh) course at LearnUNI. Free to read, free to share, paired with a professional course.
Adequacy of Capital – related terms #
capital buffers, solvency ratio – The amount of capital a central bank must hold to absorb losses while continuing operations. It is measured against risk‑weighted assets. Example: Bangladesh Bank maintains a minimum Tier 1 capital of 8 % of its risk‑weighted assets. Practical application: Regular stress‑testing to verify capital sufficiency. Challenge: Forecasting extreme macro‑economic shocks that could erode capital quickly.
Aggregated Risk Profile – related terms #
risk aggregation, risk appetite – A consolidated view of all material risks across the institution, expressed in a common metric such as monetary value or risk‑adjusted return. Example: Combining credit, market, liquidity, and operational risks into a single heat map. Practical application: Informs strategic decision‑making and resource allocation. Challenge: Ensuring consistent data quality across disparate risk lines.
Anti‑Money Laundering (AML) Framework – related terms #
KYC, SAR, FATF – A set of policies, procedures, and controls designed to detect, prevent, and report illicit financial activities. Example: Implementing transaction monitoring systems that flag suspicious transfers above a threshold. Practical application: Protects the central bank’s reputation and supports compliance with international standards. Challenge: Balancing thoroughness with the burden on regulated institutions.
Asset‑Liability Management (ALM) – related terms #
duration gap, liquidity mismatch – The process of coordinating the timing and currency of assets and liabilities to manage interest‑rate, liquidity, and funding risks. Example: Using forward contracts to hedge foreign‑exchange exposure of foreign‑currency reserves. Practical application: Maintaining stability of the monetary base. Challenge: Forecasting interest‑rate movements in volatile markets.
Audit Committee – related terms #
board oversight, internal audit – A sub‑committee of the board tasked with reviewing the effectiveness of risk governance, internal controls, and audit findings. Example: The Audit Committee of Bangladesh Bank reviews quarterly internal audit reports on cyber‑risk. Practical application: Provides independent assurance to senior management. Challenge: Ensuring committee members possess sufficient technical expertise.
Baseline Scenario – related terms #
stress testing, forward‑looking analysis – The reference macro‑economic projection used as a starting point for scenario analysis. Example: A baseline GDP growth of 6 % for Bangladesh in the next fiscal year. Practical application: Calibrates risk models and capital planning. Challenge: Accurately capturing emerging trends such as climate‑related disruptions.
Behavioural Risk – related terms #
culture risk, human error – Risks arising from the actions, attitudes, or incentives of individuals that may lead to sub‑optimal decisions. Example: Traders taking excessive positions due to performance‑linked bonuses. Practical application: Embedding risk‑aware behaviours through training. Challenge: Measuring intangible cultural factors.
Board Risk Appetite Statement – related terms #
risk tolerance, strategic objectives – A formal declaration by the board outlining the level and types of risk the institution is willing to assume to achieve its goals. Example: A statement that the bank tolerates moderate market risk but low operational risk. Practical application: Guides risk limits and performance metrics. Challenge: Translating qualitative statements into quantitative limits.
Business Continuity Planning (BCP) – related terms #
disaster recovery, resilience – A structured approach to ensure critical functions can continue during and after a disruptive event. Example: Alternate data‑center sites for the central bank’s payment system. Practical application: Reduces downtime and protects financial stability. Challenge: Maintaining up‑to‑date recovery procedures amid rapid technology changes.
Capital Conservation Buffer – related terms #
Basel III, regulatory capital – An additional capital reserve above minimum requirements intended to absorb losses during periods of financial stress. Example: A 2.5 % Buffer mandated for Bangladesh’s banking sector. Practical application: Strengthens solvency under adverse conditions. Challenge: Allocating capital without impairing lending capacity.
Cash Flow at Risk (CFaR) – related terms #
VaR, liquidity risk – A statistical measure of the potential variability in cash‑flow projections over a defined horizon at a given confidence level. Example: A 5 % CFaR indicating a possible shortfall of BDT 200 million over three months. Practical application: Informs liquidity buffer sizing. Challenge: Modelling non‑linear cash‑flow dynamics.
Change Management – related terms #
risk culture, transformation – The discipline of managing the human and organisational aspects of transitioning to new processes, technologies, or strategies. Example: Rolling out a new risk‑reporting platform across all departments. Practical application: Mitigates implementation risks. Challenge: Overcoming resistance and ensuring consistent adoption.
Climate‑Related Financial Risk (CFRR) – related terms #
physical risk, transition risk – Risks to financial stability arising from climate change, including acute events and the shift to a low‑carbon economy. Example: Assessing exposure of sovereign bond holdings to flood‑prone regions. Practical application: Integrating climate scenarios into stress testing. Challenge: Limited data on climate impacts in emerging markets.
Compliance Risk – related terms #
regulatory risk, legal risk – The risk of legal or regulatory sanctions, financial loss, or reputational damage due to failure to comply with applicable laws. Example: Non‑adherence to the Foreign Exchange Regulation Act. Practical application: Regular compliance reviews and training. Challenge: Keeping pace with rapidly evolving regulations.
Concentration Risk – related terms #
credit concentration, sectoral exposure – The risk that a large portion of exposures is concentrated in a single borrower, sector, or geography, amplifying potential losses. Example: 30 % Of the central bank’s investment portfolio in textile sector bonds. Practical application: Setting exposure limits per sector. Challenge: Balancing diversification with strategic focus.
Control Environment – related terms #
tone at the top, governance – The set of standards, processes, and structures that provide the basis for carrying out internal control across the organization. Example: A code of conduct that emphasizes integrity and risk awareness. Practical application: Forms the foundation for risk assessments. Challenge: Maintaining effectiveness as the organization grows.
Counterparty Risk – related terms #
credit risk, settlement risk – The risk that a counterparty will fail to meet its contractual obligations. Example: A foreign central bank defaulting on a currency swap. Practical application: Netting agreements and collateral management. Challenge: Assessing sovereign risk in volatile political environments.
Credit Risk Rating – related terms #
PD, rating agencies – An assessment of the likelihood that a borrower will default on its obligations, often expressed as a grade or probability of default. Example: Assigning a ‘B‑’ rating to a commercial bank based on its asset quality. Practical application: Determines risk‑adjusted pricing. Challenge: Rating models may be less predictive for non‑bank borrowers.
Culture Assessment – related terms #
risk culture, employee surveys – Systematic evaluation of the organisation’s attitudes, values, and behaviours towards risk. Example: Conducting an annual questionnaire measuring risk awareness among staff. Practical application: Identifies gaps for targeted interventions. Challenge: Obtaining candid responses without fear of reprisal.
Cyber‑Risk Framework – related terms #
information security, threat intelligence – A structured set of policies, processes, and technologies to protect digital assets from cyber attacks. Example: Implementing multi‑factor authentication for all privileged accounts. Practical application: Reduces probability of data breaches. Challenge: Evolving threat landscape and limited specialised talent.
Data Governance – related terms #
data quality, data stewardship – The overall management of data availability, usability, integrity, and security. Example: Establishing a master data repository for all risk‑related metrics. Practical application: Ensures reliable inputs for risk models. Challenge: Coordinating across multiple legacy systems.
Delegated Authority – related terms #
risk limits, empowerment – The formal permission given to individuals or units to act within predefined risk boundaries without seeking higher‑level approval. Example: A regional director authorized to approve operational risk incidents up to BDT 5 million. Practical application: Speeds decision‑making. Challenge: Monitoring compliance with delegated limits.
Deposit Insurance Scheme – related terms #
financial stability, systemic risk – A protection mechanism that guarantees depositors’ funds up to a certain amount, mitigating panic withdrawals. Example: Bangladesh’s Deposit Insurance Fund covering deposits up to BDT 500 000. Practical application: Enhances confidence in the banking system. Challenge: Funding the scheme without distorting market discipline.
Derivatives Risk – related terms #
market risk, counterparty risk – The risk arising from the use of derivative contracts, including valuation volatility and potential losses. Example: Exposure to interest‑rate swaps used for monetary policy operations. Practical application: Mark‑to‑market and collateral posting. Challenge: Complex valuation under stressed market conditions.
Emerging Risk Identification – related terms #
horizon scanning, scenario analysis – Process of detecting new or evolving risks that may affect the institution’s objectives. Example: Monitoring fintech innovations that could disrupt payment systems. Practical application: Early‑warning alerts for senior management. Challenge: Limited historical data to quantify impact.
Enterprise Risk Management (ERM) – related terms #
risk framework, risk appetite – A holistic approach to identifying, assessing, and managing all material risks in a coordinated manner. Example: Bangladesh Bank’s ERM policy integrates credit, market, operational, and reputational risks. Practical application: Aligns risk with strategic objectives. Challenge: Achieving consistent implementation across all units.
Escalation Protocol – related terms #
risk reporting, governance – Defined steps for raising risk issues to higher authority levels when thresholds are breached. Example: Escalating a liquidity shortfall above BDT 2 billion to the Risk Committee within 24 hours. Practical application: Ensures timely corrective action. Challenge: Avoiding “alert fatigue” from excessive escalations.
External Audit – related terms #
independent assurance, compliance – An examination performed by an outside firm to verify the accuracy of financial statements and adequacy of controls. Example: A Big‑Four audit of the central bank’s annual report. Practical application: Provides credibility to stakeholders. Challenge: Coordinating audit scope with internal risk priorities.
Financial Stability Assessment (FSA) – related terms #
macro‑prudential, systemic risk – Evaluation of the resilience of the financial system to shocks, often conducted by the central bank. Example: The FSA for Bangladesh examining bank capital adequacy under a severe recession scenario. Practical application: Informs macro‑prudential policy decisions. Challenge: Integrating diverse data sources and modelling inter‑connections.
Fraud Risk – related terms #
operational risk, internal controls – The risk of intentional deception causing financial loss. Example: Falsified invoices submitted by a vendor to the procurement department. Practical application: Segregation of duties and whistle‑blower mechanisms. Challenge: Detecting sophisticated schemes that bypass standard controls.
Governance Structure – related terms #
board, committees – The arrangement of roles, responsibilities, and authority that defines how decisions are made and overseen. Example: A three‑tier governance model comprising the Board of Governors, Risk Committee, and Business Unit Risk Officers. Practical application: Clarifies accountability for risk outcomes. Challenge: Preventing overlap and ambiguity in responsibilities.
Heat Map – related terms #
risk dashboard, risk matrix – A visual tool that displays risk severity (likelihood vs impact) using colour coding. Example: A quarterly heat map showing high operational risk in IT systems. Practical application: Facilitates rapid risk prioritisation. Challenge: Ensuring data behind the visual is current and accurate.
Internal Audit – related terms #
risk assurance, control testing – Independent, objective assurance activity designed to evaluate and improve the effectiveness of risk management, control, and governance processes. Example: Internal audit reviews of the central bank’s payment‑system security. Practical application: Identifies control gaps and recommends remediation. Challenge: Maintaining audit independence while being embedded in the organisation.
Interest‑Rate Risk (IRR) – related terms #
duration gap, market risk – The risk that changes in interest rates will affect the value of assets, liabilities, or earnings. Example: A mismatch between the duration of foreign‑exchange reserves and short‑term liabilities. Practical application: Hedging with interest‑rate swaps. Challenge: Modelling non‑linear effects during rapid rate movements.
Key Risk Indicators (KRIs) – related terms #
metrics, thresholds – Quantitative measures used to monitor changes in risk exposure and performance. Example: A KRI tracking the number of failed login attempts per day. Practical application: Triggers alerts when thresholds are breached. Challenge: Selecting indicators that are predictive rather than merely reactive.
Liquidity Coverage Ratio (LCR) – related terms #
high‑quality liquid assets, Basel III – A regulatory standard requiring banks to hold enough high‑quality liquid assets to survive a 30‑day stress scenario. Example: Maintaining an LCR of 120 % for the central bank’s commercial banking subsidiaries. Practical application: Ensures short‑term funding resilience. Challenge: Sourcing sufficient liquid assets without compromising profitability.
Loss‑Absorbing Capacity (LAC) – related terms #
capital buffers, resolution planning – The ability of an institution to absorb losses and continue operating without external assistance. Example: A 10 % LAC requirement for systemically important banks. Practical application: Guides capital planning and recovery strategies. Challenge: Aligning LAC with business growth.
Macro‑Prudential Policy – related terms #
systemic risk, counter‑cyclical capital – Regulatory measures aimed at safeguarding the financial system as a whole, rather than individual institutions. Example: Imposing a counter‑cyclical capital buffer when credit growth exceeds 15 % YoY. Practical application: Dampens pro‑cyclical lending. Challenge: Calibrating tools to avoid unintended credit contraction.
Management Information System (MIS) – related terms #
reporting, data analytics – A system that collects, processes, and disseminates information needed for decision‑making. Example: An MIS dashboard displaying real‑time exposure across risk categories. Practical application: Supports timely risk monitoring. Challenge: Integrating data from legacy and new platforms.
Market Risk – related terms #
price risk, interest‑rate risk – The risk of losses arising from movements in market prices, rates, or volatilities. Example: Exposure to fluctuations in the BDT/USD exchange rate affecting foreign reserve valuation. Practical application: VaR calculations and stress testing. Challenge: Capturing tail events and illiquid market dynamics.
Operational Risk – related terms #
process risk, fraud risk – The risk of loss resulting from inadequate or failed internal processes, people, systems, or external events. Example: A system outage causing delayed settlement of interbank payments. Practical application: Risk‑control self‑assessment (RCSA) and loss event databases. Challenge: Quantifying low‑frequency, high‑impact events.
Operational Resilience – related terms #
business continuity, risk culture – The ability of an organisation to continue delivering critical services during disruptions. Example: Maintaining payment‑system operations during a cyber‑attack. Practical application: Resilience testing and recovery time objectives. Challenge: Balancing resilience investments with cost constraints.
Outsourcing Risk – related terms #
third‑party risk, vendor management – Risks associated with delegating essential functions to external service providers. Example: Reliance on a cloud‑service provider for data storage. Practical application: Due‑diligence, service‑level agreements, and periodic reviews. Challenge: Ensuring contractual clauses cover regulatory expectations.
Policy‑Level Risk Appetite – related terms #
risk tolerance, governance – The overarching stance on risk expressed in policy documents, guiding the setting of limits and controls. Example: A policy stating a “low” appetite for operational risk in core monetary‑policy functions. Practical application: Cascades into unit‑level risk limits. Challenge: Translating broad statements into measurable targets.
Probability of Default (PD) – related terms #
credit risk, loss given default – The likelihood that a borrower will fail to meet its debt obligations within a specified time horizon. Example: A PD of 2 % assigned to a medium‑size commercial bank. Practical application: Used in credit risk modelling and pricing. Challenge: Calibrating PD models for new sectors with limited historical data.
Quantitative Risk Modelling – related terms #
statistical analysis, simulation – The use of mathematical techniques to estimate risk exposures and potential losses. Example: Monte‑Carlo simulation of foreign‑exchange reserve returns. Practical application: Supports capital allocation and scenario analysis. Challenge: Model risk arising from incorrect assumptions or data errors.
Regulatory Stress Testing – related terms #
scenario analysis, capital adequacy – A supervisory tool that evaluates how institutions would fare under adverse macro‑economic or financial conditions. Example: Bangladesh’s central bank conducting a severe recession stress test on its banking sector. Practical application: Informs supervisory actions and capital planning. Challenge: Designing scenarios that are both plausible and severe.
Risk Appetite Framework – related terms #
board statement, limits – The set of structures, processes, and documentation that define, communicate, and monitor the institution’s willingness to assume risk. Example: A framework linking risk appetite to key performance indicators. Practical application: Ensures alignment of risk‑taking with strategy. Challenge: Maintaining relevance as business models evolve.
Risk Culture – related terms #
behavioural risk, tone at the top – The shared values, beliefs, and attitudes that shape how risk is understood and acted upon throughout the organisation. Example: A culture where staff feel empowered to raise concerns without fear. Practical application: Reinforced through training, incentives, and leadership messaging. Challenge: Measuring culture objectively and driving change.
Risk Committee – related terms #
governance, oversight – A senior‑level body responsible for reviewing risk exposures, policies, and the effectiveness of risk management. Example: The Risk Committee of Bangladesh Bank meets quarterly to review the heat map and KRIs. Practical application: Provides strategic direction and oversight. Challenge: Ensuring members have sufficient risk expertise.
Risk Event – related terms #
loss event, incident – An occurrence that could lead to a loss, either realized or potential. Example: A data breach affecting confidential monetary‑policy information. Practical application: Recorded in an event database for analysis. Challenge: Distinguishing between minor incidents and those with systemic implications.
Risk Governance – related terms #
board, committees, policies – The system of rules, practices, and processes by which an organisation directs and controls risk management. Example: A governance charter outlining roles of the Board, Risk Committee, and Business Unit Risk Officers. Practical application: Establishes clear accountability. Challenge: Avoiding governance fatigue and ensuring effective communication.
Risk Limit – related terms #
risk appetite, tolerance – A quantitative or qualitative boundary set to restrict the amount of risk an entity can assume. Example: A limit of BDT 500 million on foreign‑exchange exposure for a specific trading desk. Practical application: Triggers alerts when breached. Challenge: Calibrating limits to be neither too restrictive nor too lax.
Risk Management Information System (RMIS) – related terms #
risk reporting, data warehouse – A technology platform that aggregates risk data, supports analysis, and generates reports for decision‑makers. Example: An RMIS that consolidates operational loss events, KRIs, and stress‑test results. Practical application: Enhances transparency and speed of reporting. Challenge: Ensuring data integrity across multiple sources.
Risk Ownership – related terms #
accountability, risk champion – The assignment of responsibility for managing a specific risk to an individual or unit. Example: The Head of Treasury owning market‑risk exposure. Practical application: Clarifies who must act to mitigate risk. Challenge: Avoiding diffusion of responsibility in complex structures.
Risk Policy – related terms #
risk appetite, governance – A formal document that outlines the principles, objectives, and approaches for managing risk. Example: A policy mandating annual risk assessments for all new projects. Practical application: Provides a consistent framework for risk decisions. Challenge: Keeping policies up‑to‑date with emerging threats.
Risk Register – related terms #
risk inventory, mitigation plan – A structured repository that records identified risks, their assessment, owners, and mitigation actions. Example: A register listing 150 operational risks with associated control owners. Practical application: Facilitates tracking and reporting. Challenge: Maintaining completeness and relevance over time.
Risk Self‑Assessment (RSA) – related terms #
risk identification, internal controls – A process where business units evaluate their own risk exposures and control effectiveness. Example: A quarterly RSA completed by each department to update the risk register. Practical application: Promotes ownership and early detection. Challenge: Ensuring objectivity and consistency across units.
Risk Tolerance – related terms #
risk appetite, limits – The acceptable level of variation around risk‑taking objectives, often expressed as a range. Example: A tolerance of ±5 % around the target capital adequacy ratio. Practical application: Guides setting of risk limits. Challenge: Measuring tolerance accurately in a dynamic environment.
Scenario Analysis – related terms #
stress testing, forward‑looking – The process of evaluating the impact of plausible future events on the institution’s risk profile. Example: Assessing the effect of a 30 % depreciation of the BDT on foreign‑currency reserves. Practical application: Informs strategic planning and contingency measures. Challenge: Selecting scenarios that capture tail risks without excessive speculation.
Sectoral Risk – related terms #
concentration risk, industry exposure – The risk arising from exposure to a particular economic sector, such as agriculture or manufacturing. Example: Heavy reliance on textile‑sector bonds in the investment portfolio. Practical application: Sector‑limit policies and diversification strategies. Challenge: Rapidly shifting sector dynamics due to policy changes.
Service Level Agreement (SLA) – related terms #
outsourcing risk, vendor management – A contract that defines the performance standards and responsibilities of a service provider. Example: An SLA guaranteeing 99.9 % Uptime for the central bank’s payment‑processing system. Practical application: Provides measurable expectations and remedies. Challenge: Aligning SLA terms with regulatory requirements.
Strategic Risk – related terms #
business risk, governance – The risk that the institution’s strategic objectives will not be achieved due to poor decision‑making or external forces. Example: Mis‑alignment of monetary‑policy tools with inflation targets. Practical application: Regular strategic risk reviews by senior management. Challenge: Quantifying strategic risk and linking it to operational metrics.
Stress Testing – related terms #
scenario analysis, regulatory stress – A forward‑looking risk assessment technique that evaluates the impact of adverse conditions on financial position. Example: A severe liquidity stress test assuming a 40 % withdrawal of deposits. Practical application: Tests resilience of capital and liquidity buffers. Challenge: Modelling complex interactions and ensuring data quality.
Supervisory Review and Evaluation Process (SREP) – related terms #
regulatory oversight, risk assessment – The European‑style framework for assessing banks’ risk management and capital adequacy, adapted in many jurisdictions. Example: Bangladesh’s adaptation of SREP to evaluate systemic banks. Practical application: Guides supervisory actions and capital requirements. Challenge: Aligning local practices with international standards.
Sustainable Finance Risk – related terms #
climate risk, ESG – Risks associated with the transition to a sustainable economy, including regulatory, reputational, and physical risks. Example: Exposure to coal‑financing projects that may become stranded assets. Practical application: Integrating ESG criteria into credit underwriting. Challenge: Limited data on long‑term sustainability impacts.
Systemic Risk – related terms #
macro‑prudential, contagion – The risk that the failure of one or more institutions could trigger a collapse of the entire financial system. Example: A major bank’s default leading to a liquidity crunch across the market. Practical application: Macro‑prudential tools such as capital surcharges. Challenge: Identifying hidden interconnections and feedback loops.
Technology Risk – related terms #
cyber‑risk, operational risk – The risk of loss or disruption arising from failures in hardware, software, or IT processes. Example: A software bug causing incorrect calculation of interest rates. Practical application: Regular system testing and change‑control procedures. Challenge: Rapid pace of technology evolution outpacing control mechanisms.
Third‑Party Risk – related terms #
outsourcing risk, vendor management – The risk that a third‑party provider fails to deliver services as expected, potentially causing operational or reputational harm. Example: A data‑center outage affecting the central bank’s real‑time gross settlement system. Practical application: Comprehensive due‑diligence and ongoing monitoring. Challenge: Managing risk across a growing ecosystem of fintech partners.
Threshold Breach – related terms #
risk limit, escalation protocol – An event where a measured risk indicator exceeds a pre‑defined limit. Example: A KRI indicating that daily transaction failures exceed 0.5 % Of total volume. Practical application: Triggers automatic alerts and escalation. Challenge: Setting thresholds that are sensitive enough to prompt action without causing unnecessary alarms.
Transaction Monitoring – related terms #
AML, fraud detection – The systematic review of financial transactions to identify suspicious or non‑compliant activity. Example: Real‑time monitoring of large foreign‑exchange transfers for potential money‑laundering patterns. Practical application: Generates alerts for investigation by compliance staff. Challenge: Balancing detection accuracy with false‑positive rates.
Value‑at‑Risk (VaR) – related terms #
risk metric, market risk – A statistical technique that estimates the maximum loss over a specified horizon at a given confidence level. Example: A 1‑day VaR of BDT 1 billion at 99 % confidence for the foreign‑exchange portfolio. Practical application: Risk limit setting and capital allocation. Challenge: VaR does not capture tail‑risk events beyond the confidence level.
Vendor Risk Management (VRM) – related terms #
third‑party risk, SLA – The process of identifying, assessing, and controlling risks associated with vendors and service providers. Example: A VRM program that requires annual security audits of cloud providers. Practical application: Reduces exposure to external failures. Challenge: Maintaining oversight as the vendor landscape expands.
Yield Curve Risk – related terms #
interest‑rate risk, market risk – The risk that changes in the shape or level of the yield curve will affect the value of fixed‑income assets. Example: A steepening of the BDT yield curve reducing the value of long‑dated government bonds. Practical application: Duration matching and hedging strategies. Challenge: Forecasting complex curve movements under stress.