The Case for Implementing an Enterprise-wide Risk Management Strategy
2008 will be remembered as the year when risk management moved from being a check-box for compliance officers and regulators to a fundamental pre requisite for operating a trading business. As recent events show, if not addressed effectively, poor risk management can lead to catastrophic events at corporate and even systemic levels. Despite past investment in sophisticated risk management tools and practices, today organisations are beginning to realise that risk management at the product, portfolio or even business unit level does not necessarily scale well to provide an adequate view of enterprise risk.
As never before, the imperative for corporates to align business goals and desired risk profile with information and technology strategy is paramount. Establishing a roadmap to achieve true enterprise-wide and cross-asset class risk management best practices and policies is therefore essential and requires the chief information officer (CIO) and chief risk officer (CRO) to work in unison with board level scrutiny.
Despite the need for a more holistic approach to risk management, corporates are struggling to keep their risk management systems relevant to the rapid innovation that is the modus operandi of their front office businesses. The creation of new, exotic products to fuel growth has put a strain on legacy systems, which do not lend themselves to the trading characteristics, associated data inputs, outputs and workflows, and reporting requirements of non-vanilla markets. In addition to this, the amount of M&A activity that has been taking place means firms face significant integration issues resulting in a piecemeal approach to systems development and procurement taken by different businesses. Finally, regulatory requirements are taking their toll – demanding detailed reporting at increased frequencies. Moreover, they are setting increasingly stringent requirements on trading firms to engage in proactive risk management – understanding risk impact before a trade is executed – and set best practices and procedures. Truly, a new risk management paradigm is upon us.
This new way of thinking requires organisations to ensure they are adopting the right approach to risk management. The approach should involve focusing on a framework that aligns with the overall business objectives and reporting requirements and then deploying solutions that fit within the firm-specific constraints. It is also crucial to integrate risk management effectively throughout a firm’s culture – something that requires a bottom-up view of existing systems as well as a top-down approach. In bottom-up, cross-functional project teams are escalating the required actions to consolidate and connect disparate systems upward; in top-down, senior management needs to establish the risk management process so that it facilitates overall convergence across business objectives and becomes an endemic part of the culture and decision making structure.
To fit today’s model, enterprise risk management has to be incorporated into global, cross-asset platforms and oversee the entire trade life cycle and/or investment process. Challenges aside, management is expected to accelerate its move to protect the firm and themselves by re-engineering enterprise-wide risk management systems and data management infrastructure that supports those systems. Each firm will need to develop and enhance its risk management approach in a way that best accommodates the enterprise’s investment style and business structure.
Recent events impacting global financial markets have underscored the need for firms to review their current practices and develop an enterprise vision for risk and cost management as a business imperative. But the reality is that many firms still rely on systems and business processes that cannot meet today’s requirements for efficiency, transparency and agility. If firms are to implement effective support infrastructures, they need to conduct systematic reviews of all risk processes, policies and systems – from board-level governance and reporting through to trading and operations.