OCC Heightened Standards (12 CFR Part 30, Appendix D)
Independent Risk Management

OCC Heightened Standards (12 CFR Part 30, Appendix D) OCCHS-4: Independent Risk Management: CRO, Charter, Authority, and Oversight

Operate Independent Risk Management per 12 CFR Part 30 Appendix D Section II.C.2. Independent Risk Management must (a) be a function or set of functions separate from the front line units with authority and independence to oversee the design and implementation of the covered banks risk management framework, (b) report to a Chief Risk Officer or equivalent who reports directly to the Chief Executive Officer + with unfettered access to the Board, (c) maintain a charter approved by the Board defining scope + authority + reporting + escalation + budget + staffing, (d) include functions for credit + market + operational + liquidity + interest rate + price + compliance + reputational + strategic risk oversight + with specialised expertise per risk category, (e) review and challenge front line unit risk-taking and risk management activities including new products + significant transactions + significant changes + acquisitions + outsourcing arrangements, (f) provide independent risk reporting to executive management and the Board covering risk profile vs appetite + emerging risks + control effectiveness + remediation status. CRO must (a) be appointed with documented qualifications including risk management experience + commensurate with the covered banks risk profile, (b) be retained with appropriate compensation structure independent of front line unit revenue or profit performance.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.