vavgupta@gmail.com

Framework for risk exceptions

A stylish contrast of wooden letters 'Yes' and 'No' on dark marble background.

Requests for exceptions to risk policies are inevitable at every financial institution. What should be the criteria to evaluate and decide on them?

“Can we make this one-time exception to onboard this strategically important customer?”

Every risk professional has encountered this request more than a handful of times during their career. Usually such requests are accompanied by strong arguments – targets, growth mindset, risk as a blocker, strategic importance, market practices, etc. – and there may be some truth to it.

Risk policies and controls exist to safeguard the business but they are also designed to be applicable to a broad segment. They cannot account for all scenarios, edge cases and customer peculiarities. If the Risk teams are too pliant, they will render any controls ineffective. If they are too rigid, they could block beneficial business or create unnecessary friction.

So, how should such requests be evaluated?

“Exceptional risks must generate exceptional returns.”

I normally employ three tests when assessing such requests.

1. Does this breach any ‘red lines’?

There are several gatekeeping criteria to ensure that the business stays compliant with the laws and regulations, partner agreements, internal risk appetite, and the company’s values and ethics. An exception must not breach any strictly prohibited activities and customer profiles.

2. Are expected returns sufficient?

Making an exception can mean taking on exceptional risks, and exceptional risks must generate exceptional returns. If the value of the customer, the deal or the product is not sufficiently greater than the acceptable business to justify the higher risk being taken, then there is very little justification for making an exception.

Of course, the value needs to be considered holistically in some cases where longer-term or collateral benefits accruing from an exception can be substantial. In general, the risk-reward ratio should present a strong value proposition, and something that cannot be gained without making the exception.

3. What kind of precedent does this set?

Every exception can be used as a precedent for future. So, one has to evaluate if this situation is unique enough that any similar requests would be rare. Otherwise, there is a possibility that the exception becomes the norm and the governance is undermined.

If the situation is not unique but genuinely warrants an exception to the policy, then it is time to reevaluate the policy itself. Perhaps it has outlived its purpose.

Risk management is an elastic function and it can unlock significant business growth by identifying the instances where additional risk should be taken because the returns justify it, subject to reasonable and necessary constraints.

Framework for risk exceptions Read More »

Is Trust & Safety a technology risk or a financial risk?

online banking, online, bank, banking, username, password, computer, laptop, finance, money, pay, transaction, financial, credit, online banking, online banking, online banking, online banking, online banking

While Trust & Safety focuses a lot on technology and operations, it is intricately linked to financial risks for digital banks and fintechs which rely on customer confidence.

Trust is the cornerstone of all consumer finance businesses and, increasingly, safety of consumers is becoming an additional area of responsibility for financial institutions. Trust and Safety describes the combined strategies, policies, and technologies used to protect customers’ funds, private data, and digital transactions.

Customers often treat their deposits and investments like their children – expecting them to stay safe, grow well, and avoid trouble. In addition to money, banks also hold sensitive identity data on their customers and even a simple bank statement can reveal intimate details about the customer’s life. Therefore, trust in their bank’s ability to safeguard their money and their data is a fundamental tenet of the customers’ relationship with their bank.

Banks realize this and, both as an industry as well as individually, they spend a lot of effort to try and win their customers’ trust. There are elaborate policies, procedures, account access authentications, systems monitoring, pattern and behavior analysis and so on to identify and stop any unauthorized transactions on the bank systems and customer accounts.

“Bank’s ability to safeguard their money and their data is a fundamental tenet of the customers’ relationship with their bank.”

Occasionally, the criminals, scammers and fraudsters succeed in their constant attempts to access this money and data through technology hacks, social engineering, manipulation of product gaps or other methods. Typically, the banks treat that as a technology or operational issue and address it with stricter controls, process changes, forced password rotations, tech patches etc.

However, if this happens more frequently, then it becomes a reputational and financial risk. Trust with a faceless digital bank in particular, with no physical branches and human interfaces, is based on their reputation. As it is, the digital banks pay a premium for customer deposits, but if they lose the trust of their customers, then they are at the risk of losing their deposits as well.

This can impact them in two ways: higher cost of capital and, in severe cases, liquidity issues driven by sudden mass withdrawals. Lower deposit base forces the banks to borrow more money or offer higher interest rates to attract and retain the deposits, both of which will compress the net interest margins. If there is a sudden and severe event such as a mass account breach, the customers may try to withdraw their balances en masse, leading to a liquidity crunch.

Therefore, the banks should view their Trust & Safety risks as a financial risk as well and prepare their stressed scenarios to account for financial impact of adverse events.

Is Trust & Safety a technology risk or a financial risk? Read More »

Third party risk in lending

How end use of a consumer loan impacts the credit risk

credit, bank, money-4516068.jpg

Many lenders extend loans to consumers for specific uses – auto, property, education, etc. – and often in partnership with sellers and service providers. How does the performance of these partners impact the credit risk and repayment of such loans? 

I recently read about a major Indian ed-tech firm’s local lending partners pulling back on providing loans to their customers for purchasing their educational products. These are big ticket loans provided to a captive customer base for a product that most Indian families hold in high esteem. So, seems like a low-risk, high-demand loan product for the lenders. Then, why are the lenders moving away from this partnership? While we do not know the terms of their partnership agreement and how palatable it is for the lenders, but could it also relate to the negative sentiment developing around the ed-tech major’s sales practices and could that, perhaps, impact the willingness of some of the borrowers to repay the loan?

The delivery performance of the seller-partners has an impact on the repayment risk of the loans in such situation. This has been seen in other industries as well, such as housing. Many borrowers in China stopped repaying their home loans when the construction of their apartments stalled last year and the same has been repeated in many other countries and industries. What are some of the ways in which lenders can mitigate these risks?

Ideally, lenders should have a default-guarantee clause in their agreements with the seller partners, whereby some of the default is absorbed by the partners. This can be structured in many different ways – such as, first X% of default or any default beyond Y% – depending on mutual agreement and the economics of lending. Second, where possible, the lenders should avoid making lumpsum payments for products that are not fully delivered and should tie the disbursement to the delivery schedule.

It is also important that the lenders keep a close tab on the performance of their seller partners. While an objective credit risk assessment of the borrowers is imperative, the willingness to repay will be impacted by the perceived satisfaction of the borrowers to some extent. And if the borrowers feel cheated, pressured or misled, they may decide to stop repayments in protest, especially if the loans were fronted by the sellers and the borrowers do not fully realize that they are indebted to a third party. So, another thing to consider would be to be more visible in loan sourcing and ensuring that the borrowers understand who they are contracting with and what their obligations are.

The lenders may or may not have the leverage to force their seller partners to change tack, but they would do well to limit their exposure if there are concerns about delivery or reputation of the sellers. In the case of the ed-tech major, it seems that they are forced to lend from their own balance sheet to maintain their enrollment numbers and that has had an impact on their liquidity and financial performance.

What are some other methods that you have employed or seen in practice in such lending agreements?

Third party risk in lending Read More »

Governance in early stages

Senior leader presenting growth charts in a business meeting with colleagues in a modern office setting.

Is it too soon to emphasize governance at early-stages of companies?

A string of scandals at celebrated start-ups have brought the spotlight on the lack of visibility into the operations of early-stage companies and their founders. Is it time for investors to focus on better governance at start-ups?

Start-up companies and their founders have captured the popular imagination and achieved the rock star status. But, sometimes this celebrity culture masks the dark side of things. A spate of scandals in recent years – Theranos, FTX, WeWork, to name a few – have illuminated the dodgy operations underpinning some of the most sought-after businesses. Many investors have lost a lot of money and some element of criminality cannot be ruled out. However, this also raises the question of whether investors need to start insisting on better governance at early-stage companies to protect their investment.

There are several reasons why start-ups get a long rope from the investors. They often deal with innovative business ideas that may have no precedent, they need to stay focused on their solutions, stay lean and agile, the investment is usually smaller and, generally, the higher risk of business failure is well accepted and even expected. However, this landscape has also changed with the global liquidity glut of the last 15 years. The investment sizes became bigger even in early rounds, investors chased higher returns and their risk appetite grew, there was a fear of missing out and investors were entering segments they didn’t understand well and had to rely on the representations of the founders. At the same time, there has been an exponential increase in the number of entrepreneurs and that has increased the competition among start-ups for funding and visibility.

All of this created an environment where raising ever larger funding rounds itself became a sign of success and the investors were either spread thin or only too eager to go after rock star companies and founders. But eventually when the day of reckoning came, many of these businesses were exposed as mismanaged, misrepresented, misguided or purely fraudulent. While many of the investors can afford to write off these losses and move on, what would it take to create a playing field that provides reasonable assurances to investors?

Good governance is not a luxury of the large, public companies. It needs to be a part of the DNA of every organization. While regulated industries try to ensure that through laws and regulations that create a Compliance burden, businesses of all sizes need to focus on checks and balances for probity. Investors must help instill the proper values in their portfolio companies – tracking of funds, investments and expenses, regular reviews of business results and practices and visibility into the activities and commercial interests of the management teams. For specialized sectors, involving experts would be crucial for critical evaluation of the products and technology. Start-ups at experimental stage or ones that may be at the seed stage may yet dispense with some of this structure as their viability is most uncertain. However, as soon as they take steps towards commercialization or raise significant rounds, they should start building the needed internal controls and proactively work to create visibility into their operations for their investors. Having proactive investors who keep a keen eye on the businesses they support will help reduce the chances of malicious, incompetent or disinterested founders damaging the start-up ecosystem.

Governance in early stages Read More »

A seat at the table

How do you make the Risk teams an effective partner?

meeting, adults, business-4784909.jpg

While many organizations agree on the need for specialists to manage risk in the business, very few actually focus on how to make them successful. Does your Risk team deal with fait accompli all the time or do they have a seat at the table? 

The role of the risk teams and the Chief Risk Officer has evolved rapidly over the last few years. There was a time when risk management was a disjointed exercise with business units managing risks independent of each other and centralized teams such as Enterprise Risk and Internal Audit serving the senior leadership and the Board. However, over time there has been a recognition of the synergies, cost benefits and the impact that a combined Risk function can bring to the organization through standardized and consistent methods and a 360-degree view of the variety of risks faced.

As the businesses come to terms with dealing with a Risk team outside of their direct reporting line and with an independent mandate and point of view, there are also some challenges cropping up. The Risk teams are increasingly viewed as service providers to the business and many business owners tend to deal with them transactionally. The loss of control also tends to create a certain distance and the closeness that risk managers might have enjoyed earlier with business units also gets impacted. As a result, the business units might fret over the priorities of the Risk team, which may now be driven by overall risk concerns across the organization, and how well their risk partners understand their specific business model and objectives. At the same time, the Risk teams complain that risk management is no longer at the same level of priority for the business teams as before and that they always come into the picture when everything has already been decided or even executed.

A Risk team is most effective when they are not just securing the perimeter against threats but rather working in concert with the business units and leadership to help build a resilient strategy that can deal with future uncertainties. They should be helping the businesses leverage risk as a strategic advantage wherever possible (more on that in a future post). But, to do that they need to understand the business really well and need to have visibility to the working of the business – their objectives, strategy, product decisions, etc. Most of all, they need a seat at the table so that they can bring the Risk perspective during discussion and decision-making.

It is only fair for businesses to expect the Risk managers to align with the business targets and enable growth but on the flip side they also need to reciprocate with more risk awareness and consideration in their decisions. I guess a good place to start is with intentionally involving your risk partners in conversations, brainstorming and discussions and holding them accountable for active participation and inputs. Many organizations take a more structured approach through formal product reviews, audits and operational controls which are a legitimate part of the ERM framework but bigger benefits will accrue through close working relationships and a genuine say for your Risk professionals in the business matters.

A seat at the table Read More »

Risk Management as a strategic advantage

football, quarterback, sport-67701.jpg

Often, Risk management is viewed as a control function intended to prevent loss or failure. As such, most organizations expect their risk managers to focus on what can go wrong. But can they also create a competitive advantage?

The role of Risk Management in the modern organizations is evolving in a fascinating way. From being support teams minding the fences for specific business units, risk managers have now become resources for senior management to understand and mitigate the key risks that run across their businesses. As such, there has been a rising demand for professionals who can help companies identify, evaluate and address risks at both business unit level – first line risk – as well as at a corporate level – Enterprise Risk. But while they focus on protecting the business from foreseen and unforeseen risks, they can also be valuable resources for creating competitive advantages.

Enterprise Risk teams enjoy a unique vantage point where they have a fairly good overview of the businesses – how they run, what risks they face, how these aggregate at the corporate level, and best practices for mitigating common risks. And they can bring this view to create strategic advantages for the business in various ways.

First, the Risk teams can help the businesses review their view of risks applicable to them along multiple dimensions – financial, operational, market, reputational, technology, etc. – and help ensure completeness of their risk assessment. This can help uncover not-so-obvious risks for a business, such as impact of geopolitical risks on their reputation. Second, they can help them differentiate the consequential risks from inconsequential ones. This is important as the resources are usually constrained and understanding what to prioritize will enable the business optimize resources for growth.

Lastly, risk managers can help the businesses decide what, if anything, they should do about the various risks. This is a less recognized but very powerful activity that Risk teams can play for the organizations. The typical thinking about risk management is that once a risk has been identified as material, the business should try to avoid it through whatever means available. However, there are many different risk treatments that are each perfectly acceptable and can help the business take informed bets, optimize capital allocation and improve returns.

A business may choose to accept risk. For example, in restaurant business reservation cancellation is a known risk and most restaurants accept that risk as it is. Some restaurants may choose to avoid risk by not taking reservations at all. Others may even try to mitigate the risk by overbooking, expecting a certain number of cancellations. Some restaurants, especially the sought after ones, price that risk by taking a non-refundable booking guaranty. And if they’re using third party reservation services, they may even transfer the risk by asking their service providers to guaranty a certain number of reservations. The right course of action will differ for each business based on a variety of factors, but understanding the options and choosing the right one can meaningfully impact the business.

As with many business functions, it is really up to the organizations to decide how they want to utilize their risk management teams. However, those who can leverage their Risk teams beyond their traditional roles of putting up guardrails and enforcing policies can realize strategic benefits that give them an advantage over their competitors.

Risk Management as a strategic advantage Read More »

Getting started

race track flag, flag, black and white-2035566.jpg

Risk management means different things to different people. Some like it, many don’t, but everyone remembers it when things go wrong. I’ve had the opportunity to observe, experience and hear disparate views on the role of risk management in business. So, who is right?

Some people thrive on uncertainty, some get unnerved and most would like to get rid of it altogether. However, one things is certain, every business has to deal with uncertainty and the world today looks a lot more uncertain than it has been in a long time. This has brought the focus back on Risk Management, or lack of it at some of the troubled businesses. However, what is the role of Risk Management in different types of businesses? Does it change with changing business and economic climate? Is it a proactive or a reactive activity? Can Risk managers actually help businesses grow? Do organizations in different industries, geographies, of different sizes have different Risk Management needs? Is Risk and Governance the same?

These are just some of the questions that I have encountered and pondered over through my career and I have developed a point of view on this matter. Now, through this blog, I will attempt to share my views and, hopefully, initiate a dialogue that can bring together other, different views. As an advocate for good decision-making, I believe in the power of looking at a situation holistically and incorporating multiple, even contrarian, perspectives. I hope this blog can help its readers discover a new perspective and also enable me to educate myself and refine my own views.

I look forward to engaging in an enriching dialogue and exploring some of the less understood aspects of Risk and Governance. I will also try and incorporate posts on other topics of interest to me, such as climate action and developments in the business world. Happy reading!

Getting started Read More »