Skip to content

FRM Exam Part I · The Governance of Risk Management

Risk Governance and Risk Management Framework for FRM Part I

Updated 11 October 2026 · Fact-checked

Risk governance is the structure of authority, roles and accountability through which a firm sets, oversees and controls risk-taking. The board sets direction and oversight, the CRO runs an independent risk function, and management owns risks day to day. To answer questions, identify who decides, who oversees and who executes.

Understand Risk Governance and Risk Management Framework

Risk governance is the set of structures, policies and responsibilities that decide how much risk a firm takes and who answers for it. It sits above day-to-day risk management. Governance answers: who sets the rules, who checks them, and who is accountable when things go wrong.

Risk management is the set of activities that follow those rules: identifying, measuring, monitoring, controlling and reporting risk. Governance is the framework of authority. Risk management is the work done inside it. This difference is a common exam theme.

The board of directors carries ultimate responsibility for risk. It approves the firm's risk appetite and strategy, oversees senior management, and makes sure the firm has adequate resources and independent risk control. Many boards delegate detailed work to a risk committee, ideally made up largely of independent, non-executive directors with some risk expertise. The committee reviews risk reports, challenges management and advises the board. The board remains accountable even when it delegates.

The chief risk officer (CRO) leads the independent risk management function. The CRO should have enough stature, access to the board and risk committee, and independence from business lines. Reporting lines matter: the CRO should not report only to a revenue-generating head, and compensation and removal should not be controlled by the business the CRO oversees. Senior management carries out the strategy and keeps risk within appetite. Business lines own the risks they take.

A risk management process is structured as a cycle: identify risks, assess and measure them, decide a response (avoid, reduce, transfer or accept), implement controls, then monitor and report. Results feed back into appetite and strategy. Good governance makes this cycle independent, documented and challenged.

Key formulas to remember

Governance versus management
Governance = who decides, oversees and is accountable; Risk management = identify, measure, monitor, control, report
Use this to separate the two terms in definition questions.
Risk management process cycle
Identify → Assess/Measure → Respond (avoid, reduce, transfer, accept) → Control → Monitor and Report → Review
The process is continuous, not one-off.
Responsibility split
Board: appetite and oversight | Risk committee: detailed review | CRO: independent risk function | Management: execution within appetite | Business lines: own risks
Most exam questions test matching a duty to the right party.

How to solve Risk Governance and Risk Management Framework questions

Governance questions are mostly scenario or definition based. Use the same sequence each time.

  1. 1Read the stem and decide whether it asks about governance (authority, accountability) or risk management (process activities).
  2. 2Identify the party in the scenario: board, risk committee, CRO, senior management or business line.
  3. 3Recall the core duty of that party from the responsibility split.
  4. 4Check independence: does the person or function have stature, access and freedom from business-line pressure?
  5. 5Check where the process step belongs: identify, measure, respond, monitor or report.
  6. 6Eliminate options that give the board day-to-day tasks or give business lines sole control of risk oversight.
  7. 7Pick the option that keeps accountability at the top and oversight independent.

Quickest way: Role-matching shortcut

When to use it: Use for any multiple-choice item that asks who should do something or what is the weakness in a governance setup.

  1. Board = sets appetite and oversees; it does not run daily risk.
  2. CRO = independent measurement, monitoring and escalation.
  3. Management and business lines = take and own risk within limits.
  4. Look for an independence failure, such as a CRO reporting to a trading head or pay tied to desk profit.
  5. Choose the answer that restores independence or clear accountability.

Common mistakes in Risk Governance and Risk Management Framework

  • Treating risk governance and risk management as the same thing.

    Both terms appear together and sound alike.

    Fix: Remember governance is the structure of authority and accountability; risk management is the process carried out within it.

  • Saying the risk committee replaces the board's responsibility.

    Delegation seems to transfer accountability.

    Fix: The board delegates work but stays ultimately accountable for risk.

  • Assigning the CRO the job of taking or owning business risk.

    The CRO is senior and close to the business.

    Fix: Business lines own risk. The CRO provides independent oversight, measurement and challenge.

  • Ignoring independence of the risk function.

    Candidates focus on duties, not reporting lines or pay.

    Fix: Check reporting lines, access to the board and whether pay or dismissal is controlled by the business.

  • Treating the risk process as a one-time sequence.

    Lists of steps look linear.

    Fix: Describe it as a cycle with monitoring and review feeding back into appetite and controls.

Worked examples

Example 1

A bank's CRO reports to the head of trading, and the CRO's bonus depends on trading profit. Which is the most significant governance weakness? (A) The risk committee meets quarterly (B) The CRO lacks independence from the business (C) The board approves risk appetite (D) Business lines own their risks

Show the solution
  1. Identify the party: the CRO, who leads the independent risk function.
  2. Recall the key requirement: independence, stature and board access.
  3. Test each option. (A) Quarterly meetings are not in themselves a flaw. (C) Board approval of appetite is good practice. (D) Business lines owning risk is correct.
  4. (B) matches the facts: reporting to trading and pay linked to trading profit compromise independence.

Answer: (B) The CRO lacks independence from the business.

Example 2

Match the duty to the party: approving the firm's risk appetite, and monitoring risk independently and escalating limit breaches. Which pair is correct? (A) Board; CRO (B) CRO; board (C) Business lines; risk committee (D) Senior management; internal audit

Show the solution
  1. Approving risk appetite is a board duty, usually supported by the risk committee.
  2. Independent monitoring and escalation of breaches is a CRO duty.
  3. Check (B): it reverses the roles, so it is wrong.
  4. Check (C) and (D): business lines do not set appetite, and internal audit gives assurance rather than daily monitoring.
  5. Only (A) matches both duties.

Answer: (A) Board approves appetite; CRO monitors independently and escalates.

Exam tips

  • Expect scenario questions that hide an independence flaw in the reporting line or pay structure.
  • When two answers look right, prefer the one that keeps final accountability with the board.
  • Know the exact split between governance and risk management; definition questions use it.
  • Learn the process cycle in order, including the feedback step.
  • Watch for options that give the risk committee or CRO ownership of business risks; these are usually wrong.

Practice questions from The Governance of Risk Management

Risk Governance and Risk Management Framework in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Risk Governance and Risk Management Framework: frequently asked questions

What is the difference between risk governance and risk management?

Risk governance is the structure of authority, roles and accountability for risk-taking. Risk management is the process of identifying, measuring, monitoring, controlling and reporting risk. Governance sets the framework; management operates within it.

What is the role of the board in risk management for FRM Part I?

The board approves risk appetite and strategy, oversees senior management and ensures the firm has independent risk control and adequate resources. It may delegate detail to a risk committee but remains ultimately accountable.

Why must the CRO be independent?

The CRO must be able to challenge business lines and report problems without fear of pressure. Independence comes from reporting lines, direct board access and pay and removal not controlled by the business.

Is this topic calculation based?

No. It is conceptual, so questions test roles, reporting lines and process steps rather than formulas. Practise spotting the governance flaw in a short scenario.