FRM Part II · FRM Exam Part II
Governance: formula sheet
Key formulas
- Hierarchy of risk control
- Risk capacity ≥ Risk appetite ≥ Risk tolerance ≥ Limits
- Capacity is the maximum risk the bank can bear. Appetite is set below it. Limits are set so that breaches are caught before tolerance is exceeded.
- Allocation of duties
- Board: approves and oversees | Management: implements | Risk function: monitors and challenges | Audit: assures
- Use this as a quick sort for any question asking who is responsible for what.
- Three lines of defense
- 1st line: business owns risk | 2nd line: risk and compliance oversee | 3rd line: internal audit assures
- The CRO belongs to the second line and needs independence and direct access to the board.
- Limit utilisation
- Utilisation = Current exposure ÷ Approved limit
- A ratio above 100% is a limit breach and must be escalated under policy.
- First line
- Business units = risk ownership and day-to-day management
- Originate, underwrite, monitor borrowers and stay within limits.
- Second line
- Independent risk management = framework, oversight and effective challenge
- Sets policy, proposes limits, validates models, reports. Must be independent of revenue generation.
- Third line
- Internal audit = independent assurance to the board
- Reviews both other lines. Reports to the board or audit committee. Does not own or manage risk.
- Single-name limit utilisation
- Utilisation = Current exposure ÷ Limit
- Above 100% is a breach. Banks often set an early-warning trigger at a lower level, such as a set share of the limit.
- Concentration as share of capital
- Concentration ratio = Exposure to name, group or sector ÷ Tier 1 capital
- Compare with the policy limit. The denominator is whatever capital measure the policy specifies, so read the question.
- Excess over limit
- Excess = Exposure − Limit (if positive)
- A breach needs escalation and approval or a remedy plan. Do not treat it as a routine exception.
- Aggregate exposure to a connected group
- Group exposure = Σ exposure to each connected borrower
- Connected borrowers are treated as one risk where one's problems would likely hurt the others. Add them before testing the limit.
- Debt service coverage (common underwriting test)
- DSCR = Cash flow available for debt service ÷ (Interest + Scheduled principal)
- Below 1 means cash flow does not cover scheduled payments. Minimum levels vary by bank policy.
- Accuracy ratio (Gini)
- AR = 2 × AUC − 1
- Measures discriminatory power. AUC of 0.5 gives AR = 0 (no power); AUC of 1 gives AR = 1 (perfect).
- Binomial backtest of a grade PD
- Expected defaults = N × PD; standard deviation = √(N × PD × (1 − PD))
- Compare observed defaults with this range. It assumes independent defaults, so correlation makes it too strict (too many false alarms).
- Calibration vs discrimination
- Discrimination = ranking; Calibration = level of PD
- A model can rank well yet have PDs that are too low. Check both.
- SR 11-7 model risk sources
- Model risk = fundamental errors + incorrect or inappropriate use
- Validation needs independence, and effective challenge needs competence, influence and incentives.
- Risk-adjusted performance (RAROC)
- RAROC = (Revenue − Costs − Expected loss) ÷ Economic capital
- Used to link pay and performance to risk taken. Pay on raw profit ignores the capital consumed.
- Bonus adjustment mechanisms
- Deferral + payment in equity or similar instruments + malus + clawback
- Malus applies to unpaid (deferred) awards; clawback applies to amounts already paid.
- Basel credit risk principle areas
- Environment → Granting → Administration and monitoring → Controls → Supervisory role
- A way to recall the structure: board and management set the environment, then sound credit granting, ongoing administration, adequate controls.
- Lines of defence
- 1st: business owns risk; 2nd: independent risk and compliance; 3rd: internal audit
- Culture failures often show up as a weak or overruled second line.
Quick revision
- The board approves risk appetite and holds management accountable; it does not run daily credit decisions.
- Risk appetite sets how much risk the bank is willing to take; limits turn that appetite into usable numbers.
- First line owns and manages the risk it creates.
- Second line, independent risk management, sets the framework, monitors and challenges the first line.
- Third line, internal audit, gives independent assurance to the board on the other two lines.
- Independence matters: those who approve or validate should not be rewarded purely for volume the business generates.
- Underwriting standards define who qualifies for credit, on what terms and with what documentation.
- Limits cover single names, sectors, countries and portfolios, and breaches need defined escalation.
- Reporting must be timely, accurate and aimed at the right audience, with early warning indicators.
- Model governance includes development standards, independent validation, ongoing monitoring and documentation.
- Compensation tied only to short-term volume encourages excessive risk taking.
- Strong risk culture means open challenge, clear accountability and escalation without fear.
Common mistakes
- Saying the board approves individual loans. Fix: The board sets appetite and policy and oversees. Management and credit committees approve transactions within delegated authority.
- Treating risk appetite and limits as the same thing. Fix: Appetite is the board-level amount and type of risk the bank accepts. Limits are the operational tools that keep activity inside it.
- Saying risk management owns credit risk. Fix: The business unit owns the risk. The second line oversees and challenges it.
- Putting internal audit in the second line. Fix: Audit is the third line. It gives independent assurance to the board and does not run daily oversight.
- Treating risk appetite and credit policy as the same thing. Fix: Appetite is how much and what kind of risk the bank will accept. Policy is the rules for lending within it.
- Testing a single-name limit without adding connected borrowers. Fix: Combine entities that are economically connected, then compare the total with the limit.
- Confusing discrimination with calibration Fix: Discrimination is how well grades rank risk. Calibration is whether PD levels match realized defaults.
- Letting developers validate their own model Fix: SR 11-7 expects validation independent of development and use, with ability to challenge.
- Treating risk culture as a written policy or a training programme. Fix: Look for evidence in behaviour: challenge, escalation, consequences and rewards.
- Confusing malus and clawback. Fix: Malus cuts unvested or deferred pay. Clawback recovers pay already received.
Exam tips
- Most questions are role-allocation. Sort the duty by level before reading the options.
- Watch for options that break independence, such as business heads controlling the risk function. These are usually wrong.
- Know the difference between risk capacity, appetite, tolerance and limits, as questions test the order.
- Expect case-style questions about weak governance in a failed bank. Look for missing escalation, poor incentives and an overpowered business line.
- Use precise words: board oversight, management implementation, independent challenge, independent assurance.
- Expect scenario questions where one line does another's job. Spot the conflict first.
- Watch for words like owns, challenges, oversees and assures. They point to the line.
- Independence is the most tested idea. Check reporting lines and incentives.