Framework for risk exceptions

Requests for exceptions to risk policies are inevitable at every financial institution. What should be the criteria to evaluate and decide on them?
“Can we make this one-time exception to onboard this strategically important customer?”
Every risk professional has encountered this request more than a handful of times during their career. Usually such requests are accompanied by strong arguments – targets, growth mindset, risk as a blocker, strategic importance, market practices, etc. – and there may be some truth to it.
Risk policies and controls exist to safeguard the business but they are also designed to be applicable to a broad segment. They cannot account for all scenarios, edge cases and customer peculiarities. If the Risk teams are too pliant, they will render any controls ineffective. If they are too rigid, they could block beneficial business or create unnecessary friction.
So, how should such requests be evaluated?
“Exceptional risks must generate exceptional returns.”
I normally employ three tests when assessing such requests.
1. Does this breach any ‘red lines’?
There are several gatekeeping criteria to ensure that the business stays compliant with the laws and regulations, partner agreements, internal risk appetite, and the company’s values and ethics. An exception must not breach any strictly prohibited activities and customer profiles.
2. Are expected returns sufficient?
Making an exception can mean taking on exceptional risks, and exceptional risks must generate exceptional returns. If the value of the customer, the deal or the product is not sufficiently greater than the acceptable business to justify the higher risk being taken, then there is very little justification for making an exception.
Of course, the value needs to be considered holistically in some cases where longer-term or collateral benefits accruing from an exception can be substantial. In general, the risk-reward ratio should present a strong value proposition, and something that cannot be gained without making the exception.
3. What kind of precedent does this set?
Every exception can be used as a precedent for future. So, one has to evaluate if this situation is unique enough that any similar requests would be rare. Otherwise, there is a possibility that the exception becomes the norm and the governance is undermined.
If the situation is not unique but genuinely warrants an exception to the policy, then it is time to reevaluate the policy itself. Perhaps it has outlived its purpose.
Risk management is an elastic function and it can unlock significant business growth by identifying the instances where additional risk should be taken because the returns justify it, subject to reasonable and necessary constraints.





