Risk management is a critical aspect of banking operations, but it doesn’t always come easily. For newcomers, it can be intimidating. Others find the ongoing nature of risk management challenging. But there’s one area where I find more resistance than any other: risk management controls.
Bankers really don’t like talking about risk management controls. It's not that they don’t understand them. They know what a control is, but they find the practice of evaluating controls a bit overwhelming.
Let’s take a closer look at risk management controls and what bankers can do to make them less intimidating.
A risk management control is a measure, process, or mechanism put in place to mitigate risk. Controls aim to reduce the likelihood of a risk event occurring and/or minimize the impact if the event does occur.
Controls can be preventive, detective, or corrective in nature:
Preventive controls. Preventative controls are proactive controls designed to prevent a risk event from happening. Examples include: automated software controls requiring data or a specific process to be followed, employee training, access controls, and firewalls.
Detective controls. Detective controls identify and detect risk events or issues that have already occurred. These controls help to ensure that incidents are quickly discovered and addressed to reduce the impact. Examples include: audits, monitoring systems, and fair lending data analysis.
Corrective controls. Corrective controls resolve issues once they have been identified through preventive or detective controls. Their goal is to reduce the impact of risk events and prevent them from recurring. Examples include incident response, root cause analysis, and contingency plans.
Effective risk management involves implementing a combination of these controls to address potential risks in a comprehensive and balanced manner.
While the concept of controls is simple, they can still be a source of stress. I’ve discovered five common reasons:
When we understand the challenges that make people want to avoid risk management controls, it’s easier to help people overcome these objections.
Let’s look at each objection.
Want to learn more about how controls influence risk management? Download our free whitepaper Creating Reliable Risk Assessments.
Yes, there are many controls, but they aren’t all created or managed by those tasked with assessing the controls. Many controls are activities a financial institution is already engaging in. Let’s take a look at some common operational risk controls.
As mentioned, not all controls provide the same amount of risk mitigation. Controls that mitigate risk the most might be considered your "key" controls.
Which controls mitigate risk more than others? It helps to consider the control types.
For example, an automated control that is expected to prevent something may be a candidate to be identified as a "key" control and weigh more than a manual control and corrects a deficiency, issue, or finding.
Weighing controls helps prioritize which controls require more frequent monitoring and review (i.e. a risk-based approach to control monitoring).
Related: Expert Q&A: How to Build a Risk Assessment
There is data to help assess controls. Audit and QA regularly evaluate the effectiveness of control, providing useful data that makes it easier to measure controls.
Related: Risk Management 101 - Risk Assessments for Financial Institutions
No one knows everything about a financial institution, including those tasked with assessing controls. It’s not just okay to ask for input from people familiar with a control area. It’s encouraged. In fact, it can be smart to train individuals in other departments or business lines to evaluate their own controls – or offer feedback on an outside evaluation. Risk management is collaboration.
Related: Q&A - Understanding IT Audits at Financial Institutions
We live in a dynamic risk environment, as events like COVID-19 and the collapse of Silicon Valley Bank regularly remind us. New risks, increased risk, or decreased risk all impact controls. An open mind is a must for successful risk management.
This goes back to the idea of controls as simply the everyday activities of a financial institution. Yes, risk management requires expertise, but training and support can help employees understand controls. There are tools that make it simpler by providing the content to understand what’s needed and provide a framework to put it into action. Training and support can help employees understand controls.
Risk management controls don’t have to be intimidating. With the right framework and training, employees can do better than understand risk controls – they can leverage them for information to make the institution stronger and more resilient.
Ncontracts’ Nrisk solution is the perfect foundation for a robust and effective risk management program. Nrisk is a highly customizable integrated risk management solution that helps financial institutions continuously evaluate, measure, and report on risk in real time. Nrisk streamlines internal controls management, providing objective metrics for quantifying risk to take out the guesswork and subjectivity from control assessments.
It's more than a tool. It’s a system of support. Whether employees are new to risk management or are more experienced, Nrisk offers extensive training and support to help them understand and effectively implement controls. Employees across the organization to contribute to risk management efforts.
Finally, Nrisk helps to shift the perception of risk management from a technical, complicated subject to an integral part of day-to-day operations. By engaging employees across the organization and providing them with the tools and knowledge they need to contribute to risk management, Nrisk helps to foster a strong risk management culture.
In a dynamic risk environment, Nrisk is a comprehensive solution that addresses the key challenges associated with risk management controls.
Want to master risk management controls?