Risk Management in Banking and Insurance · Introduction to Risk Management
Risk Management Process and Framework in Banks
Updated 11 October 2026 · Fact-checked
The risk management process in a bank is a repeating cycle: identify risks, measure them, monitor them against limits, control them through mitigation, and report to management and the Board. A framework supplies the policies, roles, limits and systems that make this cycle work across the whole bank.
Understand Risk Management Process and Framework
A bank earns by taking risk. It lends, borrows, trades and runs payments. Each activity can lose money. Risk management does not remove risk. It makes sure the bank takes only the risks it understands, can afford and is paid for.
The process has five linked steps. Identification finds what can go wrong and where. Measurement puts a size on it, such as expected loss, exposure or sensitivity. Monitoring tracks the measured risk against approved limits on a regular basis. Control acts when risk is too high: reduce, transfer, hedge, avoid or accept with capital. Reporting tells the right people, in time and in a usable form.
The process is a loop, not a line. Reports and losses feed back into identification. A new product, a new market or a change in the economy sends you back to step one.
A framework is the structure around the process. It usually has a Board-approved risk policy and risk appetite, a clear organisation with defined roles, limits and delegation of powers, systems and data, independent review, and a risk culture. The Board sets appetite. Senior management runs it. An independent risk function checks it. Internal audit tests it.
In an enterprise-wide view, the bank looks at credit, market, liquidity and operational risk together, not in silos. Risks interact. A rate rise can hurt trading gains, raise defaults and strain liquidity at once. Exam answers should show this link.
Key rules to remember
- Risk management cycle
- Identify → Measure → Monitor → Control → Report (then repeat)
- Learn the order. Questions often ask you to place an activity in the correct step.
- Expected loss (credit risk measure)
- EL = PD × LGD × EAD
- A common measurement example. PD is probability of default, LGD is loss given default, EAD is exposure at default.
- Risk appetite and limits
- Risk appetite (Board) → Risk limits (management) → Actual exposure (monitored)
- Actual exposure must stay within limits, and limits within appetite.
How to solve Risk Management Process and Framework questions
Use this method for any descriptive or case question on the risk process or framework.
- 1Read the case and note the bank, the activity and the risk type involved.
- 2Name the step of the process the question is about, or walk through all five if asked for the full process.
- 3For each step, state what is done and give one tool or example from the case.
- 4Link the process to the framework: policy, appetite, limits, roles and independent review.
- 5Show feedback: how reporting and losses lead to revised limits or new identification.
- 6Apply to the numbers or facts given, such as exposure against a limit.
- 7Close with a clear conclusion or recommendation for the Board or management.
Quickest way: Five-word memory chain
When to use it: For 2-mark MCQs and when you must list the process quickly in a long answer.
- Write I-M-M-C-R: Identify, Measure, Monitor, Control, Report.
- Ask: is the action finding, sizing, tracking, acting or telling?
- Finding a risk is identification. A number or rating is measurement. Comparing to limits is monitoring. Hedging, collateral or reducing exposure is control. Sending MIS to the Board is reporting.
- Check if the question needs a framework element instead: policy, appetite, organisation or audit.
Common mistakes in Risk Management Process and Framework
Mixing up monitoring and control.
Both deal with limits, so they look alike.
Fix: Monitoring only tracks and flags a breach. Control is the action taken to bring risk back within limits.
Treating the process as a one-time line.
Lists of steps look linear.
Fix: State that it is a continuous cycle and show how reports feed back into identification and limits.
Describing each risk type separately and ignoring the enterprise view.
Chapters are taught risk by risk.
Fix: Add a line on how risks interact and why the bank needs integrated, enterprise-wide management.
Saying risk management aims to eliminate risk.
Everyday meaning of the word risk is negative.
Fix: Say the aim is to take risk within appetite, with adequate capital and proper pricing.
Giving the framework without roles.
Students focus on tools and forget governance.
Fix: Name the Board, senior management, independent risk function and internal audit, and state what each does.
Worked examples
Example 1
A private bank lends to many mid-sized firms. Explain how it would apply the five steps of the risk management process to its credit exposure.
Show the solution
- Identification: review each borrower's business, sector, concentration and weak signals such as delayed payments.
- Measurement: assign internal ratings and estimate PD, LGD and EAD to get expected loss.
- Monitoring: track exposure against borrower, sector and portfolio limits and watch early warning signals.
- Control: reduce exposure, take collateral or guarantees, tighten covenants, or transfer risk where permitted.
- Reporting: send periodic reports on limit breaches, rating migration and asset quality to senior management and the Board.
- Feedback: use the findings to revise policy and limits.
Answer: The bank identifies credit risks, measures them with ratings and PD, LGD and EAD, monitors against limits, controls through mitigation and reports to the Board. The cycle then repeats.
Example 2
A bank has a single-borrower exposure limit of ₹200 crore. Its exposure to a borrower is ₹215 crore. PD is 2%, LGD is 40%, EAD equals the exposure. Identify the process steps involved and compute the expected loss.
Show the solution
- Comparing ₹215 crore with the ₹200 crore limit is monitoring. The excess is ₹15 crore.
- Computing expected loss is measurement: EL = PD × LGD × EAD.
- EL = 0.02 × 0.40 × ₹215 crore.
- 0.02 × 0.40 = 0.008.
- 0.008 × 215 = ₹1.72 crore.
- Bringing exposure down by ₹15 crore through sell-down or participation is control.
- Informing the Board of the breach and the action is reporting.
Answer: Expected loss is ₹1.72 crore. The breach is found in monitoring, then controlled by cutting ₹15 crore of exposure and reported to the Board.
Exam tips
- Always list the five steps in order, then explain each with a bank example. Marks follow the steps.
- In case questions, tie each step to facts in the case rather than giving generic text.
- For framework questions, include appetite, policy, limits, roles, independent review and culture.
- In MCQs, check whether the action is tracking (monitoring) or acting (control).
- Where numbers are given, show the limit comparison and a clear recommendation.
Practice questions from Introduction to Risk Management
- Under the Basel framework, the risk that a bank may be unable to meet its payment obligations as they fall due without incurring unacceptabl…
- A bank's asset-liability team finds that its rupee assets reprice mostly after three years, while most of its deposits reprice within one ye…
- Case: Kaveri Bank has an exposure at default (EAD) of Rs 200 crore to a corporate borrower group. The probability of default (PD) over one y…
- Mahalakshmi Bank has funded a 10-year fixed-rate housing loan book mainly through 1-year deposits that reprice every year. Market interest r…
- A bank has lent funds to a manufacturing firm, and the firm fails to pay instalments on the due dates because its cash flows have weakened. …
Risk Management Process and Framework in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Risk Management Process and Framework: frequently asked questions
What are the steps of the risk management process in a bank?
The steps are identification, measurement, monitoring, control and reporting. They run as a continuous cycle. Results from reporting feed back into identifying new or changed risks.
What is the difference between monitoring and control?
Monitoring tracks risk against limits and flags breaches. Control is the action taken, such as hedging, reducing exposure or taking collateral, to bring risk back within limits.
What is an enterprise risk management framework?
It is a bank-wide structure of policies, risk appetite, limits, roles, systems and reviews. It manages credit, market, liquidity and operational risk together instead of separately.
Who is responsible for risk in a bank?
The Board sets risk appetite and approves policy. Senior management implements it. An independent risk function measures and monitors, and internal audit tests the system.