Beware when “Risk Management” becomes “Risk Process”...

...or “The Illusion of Control”

We are all familiar with the story of Credit Suisse, the Swiss-domiciled bank that managed itself to the point of unviability and ignominious demise.

The bank got there because of decisions they made. Remember, no other G-SIB bank failed in 2023. It wasn’t external factors that caused its failure directly – it was its own internal decision-making over a long period of time that caused the bank to fail.

How was that possible, when, as befits a G-SIFI bank, it had risk management frameworks and three lines of defence and thousands of pages of risk policies and procedures and a Chair of Risk and a Chair of Audit and a CRO and intense prescriptive regulatory scrutiny from more than one regulatory authority and the great-and-good populating its Board and consultants to confirm it was compliant with the more than 1500 pages of “Basel III” guidance…and on and on and on.

How indeed.

My colleague and close personal friend Prof. Dr. Michael Eichhorn has an expression that helps answer this question. He refers to “The Illusion of Control”, the title of a book authored by Jon Danielsson. (The book discusses issues at a systemic, macro level.)

I have an explanation for it as well. Because I think Dr. Danielsson’s concept applies equally, and possibly even more importantly, at individual bank level.

I call it “When Risk Management becomes Risk Process”. I’ve observed this first-hand over the years at a number of firms, both in the banking sector and in the voluntary sector

Beware of process over management

When risk management is more process than value

It is understandable, indeed unavoidable, that in any corporate organisation over a certain size (let’s say, more than 200 employees, although I’ve come across more than a few badly run firms smaller than that!) many processes become “bureaucratised”.

It’s no different with a “risk management” process. When the process is more important – or more highly valued – than the actual outcome, or the conclusions reached, or the practical value added, then we’ve arrived at process over management. When this happens, a bank – of any size – has ended up placing more importance on the process activity itself than on what the process is actually achieving.

That’s the illusion of control.

The risk management team, up to and including CRO level, is no more immune to this bureaucratisation danger than any other team in the firm.

Why is this a problem? In essence, because it raises the risk of a bank walking itself into failure over a period of time. Not just Credit Suisse, although that’s a great example. Every bank in the world had to deal with central bank interest rate rises during 2022-2023, but only those well-known ones from Q1 2023 went bust as a result. More than a decade after Basel III, we still have banks managing to make the same ALM mistakes that they did in 2007-08. Lessons learned forgotten or never learned in the first place. At least in 2008 we had a market-wide crash to manage through. That didn’t happen in 2023, but all the banks that failed had more or less the same dense “risk management framework” in place as every other bank.

For failed banks after 2008, in more than one jurisdiction, risk management had become risk process. When we prize process itself the value added is diminished, even though optically it looks like there is considerable work being done “managing” risk.

Danger signs

Here we aren’t referring to risk dashboards and key risk indicators at “red” levels. We’re talking about something more subtle. Remember, this happens insidiously, over time. And some people will not have any problem with it in any case.

In no particular order, here are some warning signs, all observed firsthand around the world:

  • Very dense 400-slide Board and Risk Committee packs: everyone says the Board pack is too long, at every meeting, but nothing ever happens – the pack never reduces in length, in fact, it increases in size over time

  • By the same token: every other slide is very busy, small font size, tables and charts everywhere, page after page after page of “risk metrics”. The opposite of accessible

  • Over-long Board meetings and sub-committee meetings: A 4.5-hour Board meeting is understandable if the firm operates in multiple countries, has hundreds of millions of customers, and a complex balance sheet. Otherwise, we are prioritising process over management

  • Excessive verbosity in presentations or when answering questions: executives taking 10 minutes to answer something that could be answered in three

  • The quantity of review comments on a document is more valued than their quality, irrespective of what value is added (“There’s a typo on page 237….”)

  • An Audit Committee meeting that is requested to be finished in 90 minutes is a source of complaint from the Committee Chair

  • The same themes appear again and again at Board meetings

  • More junior attendees at a committee meeting, or more recent senior exec or non-exec joiners, go quiet when anything remotely controversial or uncomfortable is raised

  • More than just once or twice during the year, senior executives who are found wanting are made to fall on their sword, but the CEO – who hired them – remains untouched and his/her judgement is not called into question

  • Board agenda items are presented by executives skilled in the art of talking a lot without saying anything

  • Internal Audit has a starring role at every Board meeting.

  • The CRO takes a long time to implement an agreed request from an INED (“It’ll be ready at the next meeting”, said more than once)

  • A balance sheet KRI is in “red”, but there is no indication of this until the CRO’s report, which is a few hundred pages into the MI pack: no summary dashboard is presented at the front

  • The turnover ratio of senior execs is very high, implying only a certain type of conformist is acceptable to the company

  • At the Board Risk Committee, around 70-80% of the conversation is solely between the Committee Chair and the CRO; hardly anyone else makes any comments

  • There is a good APPEARANCE of management and control through frequent Board meetings, sub-committee meetings, regular additional ad hoc briefings, regular Board training sessions and monthly Board Dinners (attendance compulsory!)……

  • …..while over the same time period key metrics such as funding concentration, cost-income ratio and net interest income continue to move in the wrong direction.

How many of these do we recognise? If it’s more than a few, then the bank is clearly more obsessed with risk process than genuine risk management.

The opposite of accessible

There are two other danger signs:

Complexity in risk management frameworks and dashboards

Despite what some commentators would have us believe, banking and finance are not complex topics. Arcane, perhaps, and (like all industries) infused with their own specialist terms and processes, but not complex. (For genuine complexity, consider the work required to implement the European Space Agency’s Rosetta mission, and associated Philae lander, in 2004. Now compare this to the work required to accept a deposit from someone and lend money to someone. What’s the real “rocket science”?!).

It is more than possible to discuss and manage bank risk using plain and simple language and clear, accessible dashboards. Complexity in bank risk frameworks, not to mention intricate and elaborate regulator guidelines, has become an industry in itself, and is a big driver of risk management turning into risk process.

My friend Michael Eichhorn again:

“In my view…..rigid application [to risk processes] exacerbates…weaknesses and complexity. It invites banks to manage the [risk] metrics as opposed to managing the actual risk….

Generally, I think, too many regulations and [CROs] succumb to…“The illusion of control.”

Spot on 100%.

I’ve left the best for last, but it’s a common refrain:

Excessive use of consultants

I’ve lectured at banks in about 40 countries around the world, and in every one of them I’ve come across banks that engage consultants. Ubiquitous is an understatement. In itself, this is neither here nor there.

But when it comes to “risk” or “strategy” consultants, their output can cause the bureaucratisation of process to be raised to industrial levels.

At one Board meeting I attended, the bank received a concluding summary from the senior exec of a strategy consulting firm it had engaged. Here, verbatim, are seven pearls of wisdom this consultant actually said out loud:

  • “Failure is not an option". (Understandable if you’re Col. Gene Krantz or otherwise employed at NASA mission control. Otherwise quite unforgivable for its pretension and bombast…)

  • “Your people are depending on you. Don’t let them down!”

  • “Your strategy has got to be sustainable!”

  • “If you can balance the risk with the reward – it works. But you’ve got to be able to balance that!”

  • “There are people here proud to be in the organisation. Don’t let them down!”

  • “The responsibility is on you!”

  • “It will be harder than you think it will be!”

Just imagine – the consulting firm was paid several hundred thousand pounds to deliver this profundity. Is this a Board practicing "risk management", or just going through the motions ("risk process")?

Or is it more a case of, “We've brought in the consultants, look what they had to say!”

To bring value, a consultant should tell me something I didn’t know already, something I can take away and action, something I can implement that impacts my strategy setting in a positive way.

Not cliches or airy platitudes of no practical value whatsoever.

Don't waste your team's attention

Full circle: risk process and failure

Of course, often consultants are retained precisely in order to magnify the illusion of control. This is nothing new.

Consultants are hired at great expense to run "leadership capability assessments" and "team effectiveness workshops." These are followed by a “phased implementation roadmap" and "change management best practices."

At the same time the Board attends 3-day “offsites” doing trust exercises and defining values, after which the Exec emerges feeling validated and transformed.

But nothing about the business model actually changes.

Was this not exactly how Credit Suisse operated for years? Quite possibly, deep down, its Executive knew that their risk culture was flawed. Whistleblowers raised alarms. Internal teams identified problems. They also hired consultants – multiple firms, actually. A “Big 4” firm undertook organisational reviews. Another well-known firm assessed their risk frameworks. They and others produced substantial reports with, in some cases, genuinely practical recommendations. The bank’s exec nodded and launched "transformation initiatives," but in reality, things continued exactly as before.

The performance of addressing problems is very effective at avoiding the discomfort of actually doing anything about them.

Risk management as risk process.

Recommendations

It’s always easy to point out what one thinks is wrong. Solutions to a problem are harder to come by.

Here, again in no particular order, are my suggestions:

  • A summary dashboard at the start of the committee pack that is accessible: easy to understand by anyone in the room, regardless of their technical background;

  • Genuine openness in committee meetings. Everyone preaches “psychological safety,” but only a minority of execs and Chairs actually practice it

  • 2-hour maximum for committees, 2.5 hours for Board ( I know a bank that schedules its Board RiskCo for 90 minutes. It has over 100 million customers and a balance sheet of over USD 50bln. If that works for them, it can work for most banks!).

  • Drop the 400-page PowerPoint decks and try the 6-pager Word approach (it works for Amazon, and works brilliantly for at least one bank I know).

  • The Chair obtains feedback informally 1-to-1 from each committee member afterwards, rather than by a formal feedback invite round the table at end of each meeting. Let it occur naturally

  • Watch out for the level of input and comment from more junior execs and more recent joiners to the team. If it’s low or practically non-existent, that’s telling you something

  • It’s quality, not quantity, whether it’s the number of slides, the number of review comments, or the number of comments made at a meeting

  • Be wary of CROs allowed to become masters of their own fief, immune to challenge or change in the way they’ve always done things because of their “technical expertise.”

  • Welcome individual differences in approach and interaction. Make room for both the person who only wants to raise or discuss very high-level issues, as well as the pedant who likes to point out typos on page 237. Otherwise, we risk a Board that contains only conformists, mediocrities, apparatchiks, and time servers.

This is by no means an exhaustive list. And it’s only a start.

In fact, the hardest part is recognising that there is a problem in the first place. Bureaucrats always value process over end result: to them the above probably isn’t any issue at all. Credit Suisse writ large. Just identifying that risk process has taken over from risk management is the crucial first step towards moving to a more effective risk management culture.

Less, but better

Going forward….

It can be challenging to bridge the gap between complex financial theories and practical, actionable strategies. We combine academic rigour with practical application in The Moorad Choudhry Anthology, a useful read for bankers, auditors, regulators, and anyone aspiring to influential roles within the financial industry. The book follows a pragmatic approach, supported by real-world templates and policy guidelines, presenting  senior bank executives with tools to steer their institutions toward sustainable practice. It’s essentially a guide for those seeking to understand both the art and science of modern finance. “The Moorad Choudhry Anthology is an extremely thorough and readable book on asset–liability management and bank risk management. It covers such a wide spectrum of topics affecting a treasury and risk function that this is always the first resource I look into if I have to brush up my knowledge or look up something properly in any particular area. I find this book very authentic and relevant as it covers the latest issues in the market and is written by a practitioner who is very well regarded in the industry.”

—Nehal Saghir  Head of Asset and Liability Management,  Mizuho Capital Markets (UK) Ltd, London For beginners and veterans alike, this book will act as a reference point, guide and friend.

Previous
Previous

The Map is Not the Territory: The One Thing Markets Will Never Price

Next
Next

Things I Wish I'd Known About a City Career in my 20s