Risk Management in Banking and Insurance · Introduction to Risk Management
Risk Governance, Organisation and Risk Culture in Banks
Updated 11 October 2026 · Fact-checked
Risk governance is the structure that decides who owns risk in a bank and who checks it. The board sets risk appetite, a risk committee oversees it, the CRO runs the risk function, and three lines of defence (business, risk and compliance, internal audit) divide the work. Risk culture makes people follow it.
Understand Risk Governance, Organisation and Risk Culture
A bank earns money by taking risk. So the question is not how to avoid risk. It is who decides how much risk to take, who watches it, and who stops it when it goes too far. Risk governance answers this.
At the top is the board of directors. The board is ultimately responsible for the risks the bank runs. It approves the risk strategy, the risk appetite and the main risk policies, and it makes sure the bank has enough capital and a capable risk function. Most work is delegated to board-level committees, such as the Risk Management Committee (often with sub-committees for credit, market and operational risk) and the Audit Committee. Senior management then carries out the board's policies day to day. In many banks an executive-level committee such as the Asset Liability Management Committee (ALCO) handles balance sheet and liquidity risk.
The Chief Risk Officer (CRO) heads the risk function. The CRO is a senior officer who should be independent of business lines, have enough seniority and access to the board or its risk committee, and should not be given business targets that conflict with the role. The CRO identifies, measures, monitors and reports risk across the bank, and challenges business decisions that breach limits.
The three lines of defence model separates ownership from oversight. The first line is the business and operations units. They take risk and own it, and they run controls day to day. The second line is risk management and compliance. It sets frameworks and limits, monitors and independently challenges the first line. The third line is internal audit. It gives independent assurance to the board that the first two lines work.
Risk appetite is the amount and type of risk the bank is willing to accept to meet its goals. It is usually written as a risk appetite statement with measurable limits, for example a minimum capital ratio, a ceiling on gross NPAs, or a cap on exposure to one sector. Risk culture is the shared values and behaviour around risk. A bank can have perfect policies and still fail if staff hide problems or chase targets ignoring limits. A good culture shows in tone from the top, open escalation of bad news, clear accountability and incentives that reward prudent risk-taking.
Key rules to remember
- Three lines of defence
- 1st line = business owns and manages risk; 2nd line = risk and compliance oversee and challenge; 3rd line = internal audit gives independent assurance
- Learn the role of each line in one phrase: own, oversee, assure.
- Risk capacity, appetite and limits
- Risk limits ≤ Risk appetite ≤ Risk capacity
- Capacity is the maximum the bank can bear. Appetite is what the board chooses to accept, below capacity. Limits are the operating controls that keep the bank within appetite.
- Board and management split
- Board: sets strategy, appetite and policy and oversees; Management: implements and reports
- The board does not run daily risk decisions. It approves and oversees.
- CRO independence
- CRO reports independently of business lines, with access to the board or its risk committee
- Independence is the key point examiners test.
How to solve Risk Governance, Organisation and Risk Culture questions
Governance questions reward structured answers that tie each body or person to a clear role. Use this method for any question on the topic.
- 1Read the question and mark what is asked: a role (board, CRO, committee), a model (three lines), a concept (appetite, culture) or a case judgement.
- 2Define the key term in one sentence before anything else.
- 3List the responsibilities in a clear order, from the top (board) down to the operating level.
- 4State the independence or separation point: who must not be checking their own work.
- 5Link to a bank example with numbers or limits if you can, such as a gross NPA ceiling or a sector cap.
- 6For a case, identify which line or body failed, name the breach, and give the corrective action.
- 7Close with one line on risk culture or why the structure matters for the bank's stability.
Quickest way: Own, oversee, assure
When to use it: Use for MCQs and for short answers when you have only a few minutes.
- Business unit that takes the risk and runs controls: first line.
- Risk function or compliance that sets limits and challenges: second line.
- Internal audit that reviews both and reports to the audit committee or board: third line.
- Board sets appetite and approves policy; CRO runs the risk function independently.
- If an option says a line checks its own work, or the CRO earns from business targets, it is wrong.
Common mistakes in Risk Governance, Organisation and Risk Culture
Placing internal audit in the second line.
Audit and compliance both sound like control functions.
Fix: Compliance and risk are second line. Internal audit is third line because it gives independent assurance on the other two.
Saying the first line is only the front office or sales team.
Students think of the business as customer-facing staff only.
Fix: The first line is every unit that takes or originates risk and owns its controls, including operations and credit origination.
Treating risk appetite and risk limits as the same thing.
Both use numbers and sound alike.
Fix: Appetite is the board's broad level of acceptable risk. Limits are the detailed operating thresholds set to keep the bank within it.
Giving the CRO business targets or a reporting line to the head of sales.
Students think a senior executive can wear both hats.
Fix: State that the CRO must be independent of business lines, with direct access to the board or its risk committee.
Writing that the board manages daily risk decisions.
Confusing oversight with execution.
Fix: The board approves strategy, appetite and policy and oversees. Management implements and reports.
Defining risk culture as a written policy.
Students look for a document-based answer.
Fix: Culture is behaviour and values: tone from the top, open escalation, accountability and incentives. Policies support it but do not equal it.
Worked examples
Example 1
Explain the three lines of defence model in a bank and give one example of each line. (6 marks)
Show the solution
- Define: the model divides risk responsibility into three separate layers so that taking risk, overseeing it and auditing it are not done by the same people.
- First line: business and operating units own and manage the risks they take. Example: a branch or credit origination team ensures a loan follows the sanction terms and documentation.
- Second line: risk management and compliance set frameworks and limits and independently monitor and challenge. Example: the credit risk department checks that sector exposure stays within the approved limit and reports breaches.
- Third line: internal audit gives independent assurance to the board or audit committee on whether the first two lines work. Example: an audit of the loan portfolio to test whether limits and controls were followed.
- Conclude: the separation prevents a unit from marking its own work and strengthens accountability.
Answer: First line owns and manages risk (business units), second line oversees and challenges (risk and compliance), third line provides independent assurance (internal audit). Separation of these roles avoids self-review.
Example 2
A bank's risk appetite statement caps gross NPAs at 4% of gross advances. At the quarter end, gross advances are ₹50,000 crore and gross NPAs are ₹2,300 crore. The CRO finds that a regional head has been pushing for more loans in a stressed sector. Compute the position against appetite and state what governance steps follow. (6 marks)
Show the solution
- Gross NPA ratio = 2,300 ÷ 50,000 = 0.046 = 4.6%.
- Compare with the cap of 4%. The ratio is 0.6 percentage points above the appetite, so the limit is breached.
- Maximum NPAs allowed at the cap = 4% × 50,000 = ₹2,000 crore. The excess is 2,300 − 2,000 = ₹300 crore.
- The CRO should escalate the breach to the Risk Management Committee and the board, since appetite is set by the board.
- Management should present a remediation plan: freeze new exposure to the stressed sector, intensify recovery, and review the incentives of the regional head.
- Internal audit, as third line, should review whether the first line followed the sanction and monitoring policy, and the board should consider the culture signal of target-driven lending.
Answer: Gross NPA ratio is 4.6% against a 4% cap, a breach of ₹300 crore of NPAs above the allowed ₹2,000 crore. The CRO must escalate to the risk committee and board, which should require a remediation plan, restrict the sector exposure, and review incentives and culture.
Exam tips
- Draw the three lines as a simple list of own, oversee, assure in your answer. Examiners look for the role and the independence point together.
- In case scenarios, find the line that is conflicted, such as a business head overriding a risk limit, and say which principle it breaks.
- When asked about the CRO, always mention independence, seniority and access to the board.
- Use one numeric example of an appetite limit to show you understand it is measurable.
- Mention risk culture in the conclusion of long answers. It earns marks that policies alone do not.
Practice questions from Introduction to Risk Management
- A bank's payment system fails for several hours because of a software glitch, and customers incur penalties for delayed transfers which the …
- A bank holds a Rs 200 crore portfolio with a one-year probability of default of 2%, loss given default of 45% and exposure at default equal …
- A bank grants a 5-year fixed-rate loan funded by 3-month deposits. If deposit rates rise sharply after a few months, the bank's net interest…
- A bank's treasury holds a large portfolio of government securities. Following a sudden rise in market yields, the market value of the portfo…
- Case: Sundaram Finance Bank has a loan portfolio where the borrower's exposure at default is Rs 50 crore, the probability of default is 4%, …
Risk Governance, Organisation and Risk Culture in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Risk Governance, Organisation and Risk Culture: frequently asked questions
What are the three lines of defence in a bank?
The first line is the business units that own and manage risk. The second line is risk management and compliance, which set limits and challenge the first line. The third line is internal audit, which gives independent assurance to the board.
What does the board do in bank risk governance?
The board approves the risk strategy, risk appetite and key policies, and oversees whether management follows them. It usually works through a Risk Management Committee and an Audit Committee. It does not take daily risk decisions.
What is a risk appetite statement with an example?
It is a board-approved statement of the type and amount of risk the bank is willing to take to meet its goals. An example is a cap on gross NPAs at 4% of advances or a limit on exposure to one industry sector.
Why must the Chief Risk Officer be independent?
The CRO must be able to challenge business decisions without pressure from revenue targets. Independence, seniority and direct access to the board or risk committee let the CRO report breaches honestly.