The bank must have a firm-wide risk management framework, proportionate to its size and complexity, that defines risk appetite and captures all material risks including concentrations, securitisation, off-balance sheet exposures and valuation, with ongoing stress testing and internal standards for allowances, capital and contingency funding (SRP30.4, SRP30.5). Key features are active board and senior management oversight, policies and limits, comprehensive risk identification and reporting, adequate MIS and internal controls (SRP30.7). The board and senior management set risk appetite and firm-wide limits and review new products, and the chief risk officer is independent of business lines and reports to the CEO and board (SRP30.8 to SRP30.13). MIS must aggregate exposures firm-wide and capture limit breaches promptly, with independent testing (SRP30.14 to SRP30.19). Risk concentrations, including wrong-way risk, must be aggregated across entities, stress tested, limited and reported to the board, with capital in the ICAAP (SRP30.20 to SRP30.28). Reputational risk and implicit support must be measured and stress tested (SRP30.29 to SRP30.36). Valuation needs board-overseen governance and stress-tested models (SRP30.37 to SRP30.44). Stress testing is to be embedded as a core risk management tool in line with the Committee's October 2018 Stress testing principles (SRP30.45 to SRP30.47), and liquidity risk needs a board risk tolerance, regular stress tests and a contingency funding plan (SRP30.48 to SRP30.52).
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.