Skip to content

FRM Part II · FRM Exam Part II

Governance in FRM Part II: Credit Risk Governance Study Guide

Governance is the set of structures, roles, policies and controls that a bank uses to take credit risk deliberately and keep it within appetite. To solve questions, identify who owns the risk, who challenges it, who oversees it, and which control failed or is missing. Then pick the answer that restores that role.

What this chapter covers

This chapter covers how a bank organises itself to manage credit risk. It starts with the board, risk appetite and the credit risk framework. It then moves to the three lines of defense, credit policies, limits and underwriting standards, reporting and monitoring, model governance, and finally risk culture, compensation and regulatory expectations.

The content is mostly conceptual. You will rarely calculate anything. Instead you read a short case, such as a global bank with rising concentrations or a model that nobody validates, and decide which governance element is weak. Questions test whether you can assign responsibilities correctly and spot conflicts of interest.

The chapter connects to the rest of the paper. Credit risk measurement tools such as probability of default, loss given default and exposure at default only work if the data, models and limits around them are controlled. Operational risk and resilience shares the same ideas of ownership and challenge. Model governance also links to market risk models and to the Current Issues topics, such as artificial intelligence and private credit, where oversight gaps are a recurring theme.

Governance questions are among the most readable in the exam, so they are marks you can win with clear thinking rather than heavy calculation. The same ideas, ownership, independence, escalation and accountability, also help you on case questions in other topics. Time spent here builds a vocabulary that lets you eliminate wrong options fast and save minutes for the calculation-heavy topics later in the paper.

Governance: topics in the order to study them

  1. 1Credit Risk Governance FrameworkStart here because the board, risk appetite and overall framework set the context for every other topic.
  2. 2Three Lines of Defense ModelNext, learn who does what: business ownership, independent risk oversight and internal audit assurance.
  3. 3Credit Policies, Limits and Underwriting StandardsNow see how the framework becomes daily rules that control which risks the bank takes on.
  4. 4Credit Risk Reporting, Monitoring and Model GovernanceThen study how the bank tracks exposures after approval and controls the models behind ratings and decisions.
  5. 5Risk Culture, Compensation and Regulatory ExpectationsFinish with culture, incentives and supervisors, which explain why good structures still fail and tie the earlier topics together.

How to prepare Governance

Treat this chapter as a set of roles and controls, not a list to memorise. Aim to explain each idea in your own words and apply it to a short scenario.

  1. Read each topic once and write a one-line job description for each party: board, senior management, business line, risk function, audit.
  2. Draw the credit lifecycle from origination to approval, monitoring, reporting and recovery. Mark which control sits at each stage.
  3. Learn the purpose of each control, such as limits, underwriting standards, validation and escalation, and what failure looks like when it is missing.
  4. Practise case questions. For each, name the weakness first, then choose the option that fixes it at the right level of the organisation.
  5. Compare similar-sounding answers. Ask whether the action belongs to the first line, second line or board, and whether it preserves independence.
  6. Revisit the Current Issues readings and note any governance angle, such as oversight of AI models or private credit exposures.
  7. In the last week, review your notes and redo questions you got wrong until you can state the reason in one sentence.

Common mistakes in Governance

  • Mixing up the second and third lines of defense.

    Fix: Remember that the second line sets policy and monitors risk in real time, while the third line audits whether the first two lines work.

  • Giving the first line the job of independent oversight.

    Fix: Ownership sits with the first line, but challenge and monitoring must come from a function that is independent of revenue targets.

  • Choosing answers that add more reports when the real problem is ownership or incentives.

    Fix: Find the root cause first. If the issue is pay or culture, better reporting alone will not solve it.

  • Treating limits and risk appetite as the same thing.

    Fix: Appetite is the board-level statement of acceptable risk. Limits are the operational tools that keep activity within it.

  • Assuming a model is governed well once it has been validated one time.

    Fix: Governance is continuous: ongoing monitoring, periodic revalidation, change control and clear model ownership.

  • Skipping this chapter as theory and relying on calculation topics.

    Fix: Allocate fixed time to governance and practise case questions, because these are quick marks when your concepts are clear.

Last-day revision: Governance

  • The board approves risk appetite and holds management accountable; it does not run daily credit decisions.
  • Risk appetite sets how much risk the bank is willing to take; limits turn that appetite into usable numbers.
  • First line owns and manages the risk it creates.
  • Second line, independent risk management, sets the framework, monitors and challenges the first line.
  • Third line, internal audit, gives independent assurance to the board on the other two lines.
  • Independence matters: those who approve or validate should not be rewarded purely for volume the business generates.
  • Underwriting standards define who qualifies for credit, on what terms and with what documentation.
  • Limits cover single names, sectors, countries and portfolios, and breaches need defined escalation.
  • Reporting must be timely, accurate and aimed at the right audience, with early warning indicators.
  • Model governance includes development standards, independent validation, ongoing monitoring and documentation.
  • Compensation tied only to short-term volume encourages excessive risk taking.
  • Strong risk culture means open challenge, clear accountability and escalation without fear.

Governance practice questions

Governance in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Governance: frequently asked questions

Is the Governance chapter calculation based?

No. It is mainly conceptual and case based. You are asked to judge roles, controls and failures rather than compute figures.

How do I tell the three lines of defense apart in a question?

Ask who is doing the activity. If it is taking or managing the risk, it is the first line. If it is setting rules, monitoring and challenging independently, it is the second line. If it is giving independent assurance to the board, it is the third line.

How much time should I give this chapter?

Less than calculation-heavy topics, but do not skip it. A few focused sessions plus regular case practice is usually enough to make the concepts automatic.

Does governance link to the Current Issues readings?

Yes. Topics such as artificial intelligence and private credit raise questions about oversight, model risk and accountability, which use the same governance ideas.