Basel Core Principles for Effective Banking Supervision (2024)
Principles 14 to 16: corporate governance, risk management process and capital adequacy – Basel Core Principles for Effective Banking Supervision (2024)

Basel Core Principles for Effective Banking Supervision (2024) P15: Principle 15: risk management process

The bank has a comprehensive risk management process, with effective board and senior management oversight, to identify, measure, evaluate, monitor, report and control or mitigate all material risks (including digitalisation, climate-related financial and emerging risks) on a timely basis, and to assess the adequacy of its capital and liquidity and the sustainability of its business model against its risk profile and conditions. The board approves risk strategies and an effective risk appetite statement and framework, and ensures a sound risk culture, risk-taking policies consistent with appetite, recognition of measurement uncertainty, limits consistent with appetite, profile, capital and liquidity that staff understand, and senior management control of material risks. Policies give a bank-wide view across risk types, assess macroeconomic risks and longer-horizon risks (with scenario analysis where appropriate), are documented, aligned with appetite, reviewed, communicated, and handle limit breaches with prompt escalation and remediation. The board and senior management receive and understand risk information and its limits; the bank runs internal capital and liquidity adequacy assessments and business model sustainability analysis; models meet supervisory standards, their limitations are understood by the board and they are independently validated; information systems measure exposures bank-wide in normal and stress times and report to the board on time; risk data aggregation and reporting capabilities are proportionate and approved and resourced by the board; new products, material changes and major initiatives are risk-assessed and approved by the board or a committee; risk management functions are resourced, independent, segregated from risk-taking, report directly to the board and are reviewed by internal audit; larger banks have a dedicated risk unit under a chief risk officer whose removal needs board approval, is generally disclosed and is discussed with the supervisor; contingency arrangements, with credible recovery plans where warranted, address stress threatening viability; forward-looking stress testing covers at least credit, market, banking book interest rate, liquidity, country and transfer, operational risk and significant concentrations, with results used in decisions, contingency plans and capital and liquidity assessment; and risks, including liquidity impacts, are reflected in internal pricing, performance measurement and new product approval.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 4 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BCBS 239 · 2 controls

  • P1 Principle 1: governance of risk data aggregation and risk reporting
  • P8 Principle 8: comprehensiveness of risk reports
  • SRP20-ICAAP Operate an ICAAP that relates capital to all material risks
  • SRP30 Maintain a firm-wide risk management framework with stress testing, concentration, reputational and valuation controls

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Principles 14 to 16: corporate governance, risk management process and capital adequacy – Basel Core Principles for Effective Banking Supervision (2024)

Query this from an agent

The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.