Risk Management Framework¶
Back to Governance & Accountability
Overview¶
Financial institutions (FIs) are required by MAS to establish and maintain a comprehensive risk management framework that identifies, assesses, monitors, and mitigates risks across all business activities. For institutions that appoint and manage representatives, this framework must specifically address the operational, conduct, and reputational risks arising from representative activities. The three lines of defence model provides the foundational structure for organising risk management responsibilities.
Three Lines of Defence Model¶
First Line of Defence: Business Operations¶
The first line of defence comprises the business units and front-line managers who own and manage risk on a day-to-day basis.
Responsibilities for representative management: - Direct supervision: Branch managers and team leaders supervise representative activities, including client interactions, product recommendations, and transaction execution - Compliance with policies: Ensuring representatives follow the institution's policies, procedures, and codes of conduct - Self-assessment: Conducting periodic self-assessments of controls within their business units - Incident reporting: Identifying and reporting risk events, near-misses, and compliance breaches promptly - Remediation: Implementing corrective actions when issues are identified
Key controls operated by the first line: - Pre-trade and post-trade checks on representative transactions - Client suitability assessments before product recommendations - Call monitoring and supervision of client interactions - Document verification for representative onboarding (Form 3A/3B/3C) - Performance monitoring against conduct and compliance metrics
Second Line of Defence: Risk and Compliance Functions¶
The second line of defence comprises the risk management and compliance functions that provide independent oversight of the first line.
Risk management function responsibilities: - Developing the operational risk framework covering representative activities - Defining risk appetite and tolerance levels for representative conduct risk - Monitoring key risk indicators (KRIs) and reporting to senior management and the board - Conducting risk assessments of new products, channels, and business initiatives involving representatives - Maintaining the risk event database and conducting root cause analysis
Compliance function responsibilities: - Operating the compliance monitoring programme (as detailed in the Compliance Function Requirements document) - Providing compliance advisory services to business units - Managing regulatory filings and relationships with MAS - Monitoring regulatory changes and ensuring timely implementation
Third Line of Defence: Internal Audit¶
The third line of defence is the internal audit function, which provides independent assurance on the effectiveness of governance, risk management, and internal controls.
Internal audit responsibilities: - Conducting risk-based audits of the representative management framework - Assessing the effectiveness of first and second line controls - Testing compliance with MAS regulations, notices, and guidelines - Reporting findings directly to the board audit committee - Following up on the implementation of audit recommendations
Representative-specific audit areas: - Licensing and appointment processes (Form 3A compliance) - Supervision and monitoring frameworks - Training and CPD compliance - Remuneration and incentive structures - Complaints handling and dispute resolution - Record-keeping and data management
Operational Risk Management for Representative Activities¶
Risk Categories¶
Operational risks from representative activities fall into several categories:
| Risk Category | Description | Examples |
|---|---|---|
| Conduct risk | Risk of inappropriate behaviour by representatives | Mis-selling, unauthorised transactions, churning |
| Legal risk | Risk from failure to comply with laws and regulations | Unlicensed activities, breach of fiduciary duties |
| Process risk | Risk from inadequate or failed internal processes | Incomplete onboarding, missed licence renewals |
| People risk | Risk from human error, fraud, or inadequate resources | Forgery, identity fraud, incompetent advice |
| System risk | Risk from IT systems failures | Surveillance system downtime, data breaches |
| External risk | Risk from external events | Regulatory changes, market disruptions, cyber attacks |
Risk Assessment Methodology¶
FIs should conduct regular risk assessments of representative activities:
Inherent risk assessment: - Identify all significant risks from representative activities - Assess the likelihood and impact of each risk materialising, before considering controls - Consider both financial impact and non-financial consequences (reputational, regulatory)
Control effectiveness assessment: - Evaluate the design and operating effectiveness of controls mitigating each risk - Identify control gaps and weaknesses - Consider the reliability of manual versus automated controls
Residual risk determination: - Calculate the remaining risk after accounting for controls - Compare residual risk against risk appetite and tolerance levels - Identify risks that require additional mitigation or management attention
Key Risk Indicators (KRIs)¶
FIs should define and monitor KRIs for representative activities:
| KRI | Threshold Example | Escalation |
|---|---|---|
| Client complaints per representative | >3 per quarter | Compliance review triggered |
| Lapse/cancellation ratio | >15% within 6 months | Business unit investigation |
| Unauthorised trading incidents | Any occurrence | Immediate escalation to CCO |
| Overdue CPD hours | >10% of representatives | Training team remediation plan |
| Licence renewal failures | Any occurrence | Immediate cessation and reporting |
| Mystery shopping failures | >20% failure rate | Process review and retraining |
| Compliance monitoring exceptions | >5% of sample | Root cause analysis required |
| Supervisory review backlogs | >2 weeks overdue | Resource reallocation |
Risk Event Management¶
When risk events involving representatives occur:
- Identification and reporting: The event is identified and reported through the incident reporting system
- Initial assessment: The risk and compliance functions conduct an initial assessment of severity and impact
- Investigation: A proportionate investigation is conducted to establish the facts
- Root cause analysis: The underlying causes of the event are identified
- Remediation: Corrective actions are implemented to address the immediate issue and prevent recurrence
- Lessons learned: Findings are shared across the organisation to improve controls
- Regulatory reporting: Events that meet regulatory reporting thresholds are reported to MAS
Risk Appetite¶
Defining Risk Appetite for Representative Activities¶
The board must define the institution's risk appetite for representative-related risks:
Qualitative risk appetite statements: - "The institution has zero tolerance for deliberate misconduct by representatives" - "The institution accepts that operational errors will occasionally occur but expects them to be promptly identified and remediated" - "The institution will not pursue business strategies that create unacceptable conduct risk"
Quantitative risk appetite metrics: - Maximum acceptable client complaint rate per representative - Maximum acceptable mis-selling rate (as identified through compliance monitoring) - Maximum acceptable regulatory findings from MAS inspections - Maximum financial loss from representative misconduct (per event and aggregate)
Risk Appetite Governance¶
- The board approves the risk appetite framework and reviews it at least annually
- Senior management translates board-level risk appetite into operational limits and tolerances
- Risk appetite breaches are escalated promptly through defined escalation procedures
- The risk appetite framework is updated when there are significant changes to the business or regulatory environment
Risk Reporting¶
Management Reporting¶
Senior management should receive regular risk reports covering:
- Monthly: Key risk indicators dashboard, incident summary, compliance monitoring results
- Quarterly: Comprehensive operational risk report, trend analysis, emerging risk assessment
- Ad hoc: Immediate reporting of significant risk events or regulatory actions
Board Reporting¶
The board risk committee should receive:
- Quarterly: Comprehensive risk report including representative risk profile, risk appetite utilisation, and significant risk events
- Annual: Risk management effectiveness assessment, risk appetite review, and forward-looking risk assessment
- Ad hoc: Immediate notification of material risk events or regulatory enforcement actions
Report Content¶
Risk reports should include:
- Current risk profile compared to risk appetite
- Key risk indicators with trends and threshold breaches
- Significant risk events and their root causes
- Status of remediation actions from previous findings
- Emerging risks and their potential impact
- Regulatory developments and their risk implications
Emerging Risk Identification¶
Sources of Emerging Risk¶
FIs should maintain processes for identifying emerging risks to representative management:
Regulatory risks: - New MAS notices, guidelines, or consultation papers - Changes to the SFA, FAA, or related legislation - International regulatory developments that may influence MAS policy - Enforcement actions against other FIs that signal changing regulatory expectations
Technology risks: - Cybersecurity threats targeting representative systems or client data - Risks from digital distribution channels and robo-advisory - Data privacy and protection risks from new technologies - Risks from reliance on third-party technology providers
Market and business risks: - Changes in market conditions affecting product suitability - New product types or distribution models - Competitive pressures that may incentivise risk-taking by representatives - Macroeconomic conditions affecting client vulnerability
People risks: - Talent shortages in representative recruitment - Generational shifts in representative workforce - Remote working and supervision challenges - Mental health and wellbeing of representatives
Emerging Risk Process¶
- Scanning: Regular scanning of internal and external sources for emerging risks
- Assessment: Evaluation of the potential impact and likelihood of emerging risks materialising
- Communication: Briefing senior management and the board on significant emerging risks
- Response planning: Developing mitigation strategies for the most significant emerging risks
- Monitoring: Ongoing tracking of emerging risks as they develop
- Integration: Incorporating confirmed emerging risks into the established risk framework
Stress Testing and Scenario Analysis¶
FIs should conduct periodic stress testing and scenario analysis covering representative-related risks:
- Misconduct scenarios: Impact of widespread mis-selling or unauthorised trading by representatives
- Regulatory scenarios: Impact of significant regulatory changes on the representative business model
- Operational scenarios: Impact of major system failures on representative supervision and compliance
- Reputational scenarios: Impact of a high-profile representative misconduct case on the institution's reputation and business
- Pandemic/disruption scenarios: Impact of business continuity events on representative supervision and client service
Results should inform the institution's risk appetite, capital planning, and contingency arrangements.