Skip to content

Banking and Insurance - Laws and Practice · Risk Management in Banks and Basel Accords

Risk Management Framework in Banks: Process and RBI Guidelines

Updated 11 October 2026 · Fact-checked

A bank risk management framework is the set of policies, structures and controls through which a bank identifies, measures, monitors and controls the risks it takes. It runs from the Board down to business units. You answer questions by naming the risk, the process stage, the responsible body and the RBI expectation.

Understand Risk Management Framework in Banks

A bank earns by taking risk. It takes deposits and lends them, often for longer periods. Things can go wrong: borrowers may not repay, interest rates may move, cash may run short, or staff and systems may fail. Risk is the possibility that an event causes loss or reduces earnings or capital.

Risk management does not mean avoiding risk. It means taking risk knowingly, within limits, and being paid for it. A bank that cannot measure its risk cannot price its loans or hold enough capital against them. That is why regulators treat risk management as central to bank safety.

The usual process has five stages: identification, measurement, monitoring and reporting, control or mitigation, and review. You first find out what risks exist. You then size them using tools such as ratings, gap statements and stress tests. You set limits, report exposures against those limits, and reduce risk through collateral, diversification, hedging or exit.

Governance matters as much as tools. The Board of Directors carries final responsibility. It approves the risk strategy, policies and risk appetite. Usually a Risk Management Committee of the Board oversees them. Below this sit management-level committees, commonly the Credit Risk Management Committee, the Asset Liability Management Committee (ALCO) and the Operational Risk Management Committee. A Chief Risk Officer (CRO) heads the independent risk function, which must be separate from business units that earn revenue.

RBI has pushed banks towards enterprise-wide (integrated) risk management. This means viewing credit, market, liquidity and operational risk together, not in silos. RBI's guidance on risk management systems, and the Basel-based capital framework, expect banks to have board-approved policies, independent risk functions, a capital assessment process (ICAAP) and regular stress testing. Check the exact circular names and current limits in the ICSI study material before the exam.

Key rules to remember

Risk management process
Identify → Measure → Monitor and report → Control or mitigate → Review
Use this sequence as the skeleton of any descriptive answer.
Three lines of defence
1st: business units; 2nd: risk and compliance functions; 3rd: internal audit
Business units own risk, the risk function oversees it, and audit gives independent assurance.
Main risk categories
Credit risk + Market risk + Liquidity risk + Operational risk (plus others such as reputational and strategic)
Credit and market risk were the original Pillar 1 capital risks under Basel I. Basel II added operational risk. Liquidity risk is not a Pillar 1 capital charge. It is covered by separate liquidity standards, the LCR and NSFR, under Basel III.
Governance chain
Board → Risk Management Committee of the Board → Management committees (credit, ALCO, operational risk) → CRO and risk department
State who approves, who oversees and who executes.

How to solve Risk Management Framework in Banks questions

Most questions ask you to explain, discuss or evaluate a part of the framework, sometimes on a short case. Use one structure every time.

  1. 1Read the question and mark the keyword: concept, process, governance, RBI guidelines, or a case.
  2. 2Define risk or the framework in one or two lines.
  3. 3Name the relevant risk type or stage of the process.
  4. 4Explain who is responsible: Board, committee, CRO, business unit or audit.
  5. 5Add the RBI expectation, such as board-approved policy, independent risk function, limits, stress testing or capital assessment.
  6. 6For a case, apply each point to the facts and say which control failed or is missing.
  7. 7Close with a one-line conclusion on what the bank should do.

Quickest way: The PGRC check

When to use it: Use when you have only five to seven minutes for a theory question.

  1. P: Process stage or risk type involved.
  2. G: Governance, meaning who owns it.
  3. R: RBI requirement or guideline linked to it.
  4. C: Control or conclusion, meaning the practical action.
  5. Write one short paragraph or two to three bullets under each letter.

Common mistakes in Risk Management Framework in Banks

  • Saying risk management means eliminating risk.

    Students link the word management with control and assume zero loss.

    Fix: Write that banks take risk to earn returns and manage it within an approved risk appetite and limits.

  • Placing responsibility only on the risk department.

    The CRO is visible, so students overlook the Board.

    Fix: State that the Board is ultimately responsible, committees oversee, and business units own day-to-day risk.

  • Treating each risk in isolation.

    Chapters teach credit, market and operational risk separately.

    Fix: Mention the integrated, enterprise-wide view and how risks interact, for example a rate rise raising credit defaults.

  • Skipping the review stage of the process.

    Students remember identify, measure and control but forget the loop.

    Fix: Always close with monitoring, reporting and periodic review of policies, limits and models.

  • Quoting circular numbers, dates or limits from memory.

    Students try to sound precise.

    Fix: Describe the requirement in plain words unless you are certain of the reference. A correct principle scores better than a wrong number.

  • Mixing up committees, such as ALCO and the Credit Risk Committee.

    Names look similar.

    Fix: Link ALCO to liquidity and interest-rate risk on the balance sheet, and the credit committee to loan policy, limits and portfolio quality.

Worked examples

Example 1

Explain the risk management process in a bank and the governance structure that supports it.

Show the solution
  1. Define: risk is the possibility of loss to earnings or capital, and a bank manages it within a risk appetite approved by the Board.
  2. Process: identification of risks in products, loans and operations; measurement through ratings, gap analysis, value-at-risk style tools and stress tests; monitoring and reporting against limits; control through collateral, diversification, hedging, exposure caps or exit; review of policies and models.
  3. Governance: the Board approves risk strategy and policies; the Risk Management Committee of the Board oversees them; management committees such as the credit committee, ALCO and operational risk committee implement them; the CRO leads an independent risk function.
  4. Assurance: internal audit independently tests whether controls work and reports to the Audit Committee.
  5. Conclude that effective risk management needs both a sound process and clear accountability.

Answer: The process has five stages: identify, measure, monitor and report, control, and review. It is supported by Board-level approval and oversight, management committees, an independent CRO-led risk function and internal audit as the third line of defence.

Example 2

A mid-sized bank has a strong lending team that also approves its own credit limits. The CRO reports to the head of retail lending. Comment on the gaps in the risk framework.

Show the solution
  1. Identify the issue: the business unit sets and approves limits for its own exposures, so there is no independent check.
  2. Apply the principle: the risk function must be independent of revenue-generating units, and the three lines of defence must be separate.
  3. Identify the second gap: a CRO reporting to a business head cannot challenge that head freely. The CRO should have direct access to the Board or its Risk Management Committee.
  4. Recommend: approve limits through a credit committee with risk-function representation; place the CRO reporting line to the CEO and the Board committee; have internal audit review compliance.
  5. Link to RBI expectations: board-approved policies, independent risk oversight and regular reporting of exposures against limits.

Answer: The framework is weak because approval and risk oversight are not independent and the CRO lacks independence. The bank should separate approval from origination, make the CRO report to the CEO with direct access to the Board's Risk Management Committee, and have internal audit test the controls.

Exam tips

  • Structure answers as definition, process, governance, RBI expectation, conclusion. It earns marks even when your details are incomplete.
  • In case questions, point to the specific failure, such as no independence or no limits, then give the fix.
  • Use the exact terms Board, Risk Management Committee, ALCO, CRO and three lines of defence.
  • Do not quote circular numbers or limits you are unsure of. Describe the requirement in words.
  • Link this topic to credit, market and operational risk and to Basel in the same answer when the question allows.

Practice questions from Risk Management in Banks and Basel Accords

Risk Management Framework in Banks in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Risk Management Framework in Banks: frequently asked questions

What are the stages of risk management in a bank?

The stages are identification, measurement, monitoring and reporting, control or mitigation, and review. Write them in this order and give one practical tool for each.

Who is responsible for risk management in a bank?

The Board of Directors is ultimately responsible. It works through a Risk Management Committee, management committees and the Chief Risk Officer. Business units own risks day to day, and internal audit gives independent assurance.

What does enterprise-wide risk management mean?

It means managing credit, market, liquidity, operational and other risks together across the whole bank. The bank looks at how risks interact and at its total capital needs, not at each risk separately.

Do I need to remember RBI circular numbers for this topic?

Usually the answer rewards the principle and the practical requirement. Use circular details only if you are sure of them, and check the ICSI study material for the references it emphasises.