Risk management is the process of identifying the principal business risks, including regulatory compliance risks, to the group achieving its strategic objectives, establishing appropriate controls to manage those risks and ensuring that appropriate monitoring and reporting systems are in place. The group's risk management process balances cost against risk within the constraints of the group's risk appetite and is consistent with the prudent management required of a large financial organisation.
The risk management framework is based on the concept of “three lines of defence”:
- Risk management: Primary responsibility for strategy, performance and risk management lies with the board, the chief executive and the heads of each division and operating business.
- Risk oversight: Risk management oversight is provided by the Group Risk and Compliance Committee ("GRCC") and the head of group risk working with counterparts in the divisions and operating businesses and with group Compliance.
- Independent assurance: Independent assurance on the effectiveness of the risk management systems is provided by group internal audit reporting to the Audit Committee.
There are clear reporting lines and defined areas of responsibility at board, divisional and business level. This structure is designed to ensure, amongst other things, that key issues and developments are escalated on a timely basis. The group's risk management framework requires that all of the group's divisions and operating businesses establish a process for identifying, evaluating and managing the key risks that they face.
The GRCC is a committee established by the chief executive to assist him in the discharge of his responsibility for the group wide management of risk comprising the executives of the group board supported by the head of group risk, the head of group compliance and the head of group internal audit. It meets monthly and is responsible for:
- Recommending for board approval the group's risk appetite;
- The group's risk management strategy, approach and policy;
- The approval of group wide policies in respect of risk management and regulatory compliance; and
- Receiving regular reports on significant risk management, regulatory compliance and internal control issues and for monitoring their analysis and resolution.