Skip to content

Risk Management Framework

Back to Governance & Accountability

Previous Next


Overview

Financial institutions (FIs) are required by MAS to establish and maintain a comprehensive risk management framework that identifies, assesses, monitors, and mitigates risks across all business activities. For institutions that appoint and manage representatives, this framework must specifically address the operational, conduct, and reputational risks arising from representative activities. The three lines of defence model provides the foundational structure for organising risk management responsibilities.

Three Lines of Defence Model

First Line of Defence: Business Operations

The first line of defence comprises the business units and front-line managers who own and manage risk on a day-to-day basis.

Responsibilities for representative management: - Direct supervision: Branch managers and team leaders supervise representative activities, including client interactions, product recommendations, and transaction execution - Compliance with policies: Ensuring representatives follow the institution's policies, procedures, and codes of conduct - Self-assessment: Conducting periodic self-assessments of controls within their business units - Incident reporting: Identifying and reporting risk events, near-misses, and compliance breaches promptly - Remediation: Implementing corrective actions when issues are identified

Key controls operated by the first line: - Pre-trade and post-trade checks on representative transactions - Client suitability assessments before product recommendations - Call monitoring and supervision of client interactions - Document verification for representative onboarding (Form 3A/3B/3C) - Performance monitoring against conduct and compliance metrics

Second Line of Defence: Risk and Compliance Functions

The second line of defence comprises the risk management and compliance functions that provide independent oversight of the first line.

Risk management function responsibilities: - Developing the operational risk framework covering representative activities - Defining risk appetite and tolerance levels for representative conduct risk - Monitoring key risk indicators (KRIs) and reporting to senior management and the board - Conducting risk assessments of new products, channels, and business initiatives involving representatives - Maintaining the risk event database and conducting root cause analysis

Compliance function responsibilities: - Operating the compliance monitoring programme (as detailed in the Compliance Function Requirements document) - Providing compliance advisory services to business units - Managing regulatory filings and relationships with MAS - Monitoring regulatory changes and ensuring timely implementation

Third Line of Defence: Internal Audit

The third line of defence is the internal audit function, which provides independent assurance on the effectiveness of governance, risk management, and internal controls.

Internal audit responsibilities: - Conducting risk-based audits of the representative management framework - Assessing the effectiveness of first and second line controls - Testing compliance with MAS regulations, notices, and guidelines - Reporting findings directly to the board audit committee - Following up on the implementation of audit recommendations

Representative-specific audit areas: - Licensing and appointment processes (Form 3A compliance) - Supervision and monitoring frameworks - Training and CPD compliance - Remuneration and incentive structures - Complaints handling and dispute resolution - Record-keeping and data management

Operational Risk Management for Representative Activities

Risk Categories

Operational risks from representative activities fall into several categories:

Risk Category Description Examples
Conduct risk Risk of inappropriate behaviour by representatives Mis-selling, unauthorised transactions, churning
Legal risk Risk from failure to comply with laws and regulations Unlicensed activities, breach of fiduciary duties
Process risk Risk from inadequate or failed internal processes Incomplete onboarding, missed licence renewals
People risk Risk from human error, fraud, or inadequate resources Forgery, identity fraud, incompetent advice
System risk Risk from IT systems failures Surveillance system downtime, data breaches
External risk Risk from external events Regulatory changes, market disruptions, cyber attacks

Risk Assessment Methodology

FIs should conduct regular risk assessments of representative activities:

Inherent risk assessment: - Identify all significant risks from representative activities - Assess the likelihood and impact of each risk materialising, before considering controls - Consider both financial impact and non-financial consequences (reputational, regulatory)

Control effectiveness assessment: - Evaluate the design and operating effectiveness of controls mitigating each risk - Identify control gaps and weaknesses - Consider the reliability of manual versus automated controls

Residual risk determination: - Calculate the remaining risk after accounting for controls - Compare residual risk against risk appetite and tolerance levels - Identify risks that require additional mitigation or management attention

Key Risk Indicators (KRIs)

FIs should define and monitor KRIs for representative activities:

KRI Threshold Example Escalation
Client complaints per representative >3 per quarter Compliance review triggered
Lapse/cancellation ratio >15% within 6 months Business unit investigation
Unauthorised trading incidents Any occurrence Immediate escalation to CCO
Overdue CPD hours >10% of representatives Training team remediation plan
Licence renewal failures Any occurrence Immediate cessation and reporting
Mystery shopping failures >20% failure rate Process review and retraining
Compliance monitoring exceptions >5% of sample Root cause analysis required
Supervisory review backlogs >2 weeks overdue Resource reallocation

Risk Event Management

When risk events involving representatives occur:

  1. Identification and reporting: The event is identified and reported through the incident reporting system
  2. Initial assessment: The risk and compliance functions conduct an initial assessment of severity and impact
  3. Investigation: A proportionate investigation is conducted to establish the facts
  4. Root cause analysis: The underlying causes of the event are identified
  5. Remediation: Corrective actions are implemented to address the immediate issue and prevent recurrence
  6. Lessons learned: Findings are shared across the organisation to improve controls
  7. Regulatory reporting: Events that meet regulatory reporting thresholds are reported to MAS

Risk Appetite

Defining Risk Appetite for Representative Activities

The board must define the institution's risk appetite for representative-related risks:

Qualitative risk appetite statements: - "The institution has zero tolerance for deliberate misconduct by representatives" - "The institution accepts that operational errors will occasionally occur but expects them to be promptly identified and remediated" - "The institution will not pursue business strategies that create unacceptable conduct risk"

Quantitative risk appetite metrics: - Maximum acceptable client complaint rate per representative - Maximum acceptable mis-selling rate (as identified through compliance monitoring) - Maximum acceptable regulatory findings from MAS inspections - Maximum financial loss from representative misconduct (per event and aggregate)

Risk Appetite Governance

  • The board approves the risk appetite framework and reviews it at least annually
  • Senior management translates board-level risk appetite into operational limits and tolerances
  • Risk appetite breaches are escalated promptly through defined escalation procedures
  • The risk appetite framework is updated when there are significant changes to the business or regulatory environment

Risk Reporting

Management Reporting

Senior management should receive regular risk reports covering:

  • Monthly: Key risk indicators dashboard, incident summary, compliance monitoring results
  • Quarterly: Comprehensive operational risk report, trend analysis, emerging risk assessment
  • Ad hoc: Immediate reporting of significant risk events or regulatory actions

Board Reporting

The board risk committee should receive:

  • Quarterly: Comprehensive risk report including representative risk profile, risk appetite utilisation, and significant risk events
  • Annual: Risk management effectiveness assessment, risk appetite review, and forward-looking risk assessment
  • Ad hoc: Immediate notification of material risk events or regulatory enforcement actions

Report Content

Risk reports should include:

  • Current risk profile compared to risk appetite
  • Key risk indicators with trends and threshold breaches
  • Significant risk events and their root causes
  • Status of remediation actions from previous findings
  • Emerging risks and their potential impact
  • Regulatory developments and their risk implications

Emerging Risk Identification

Sources of Emerging Risk

FIs should maintain processes for identifying emerging risks to representative management:

Regulatory risks: - New MAS notices, guidelines, or consultation papers - Changes to the SFA, FAA, or related legislation - International regulatory developments that may influence MAS policy - Enforcement actions against other FIs that signal changing regulatory expectations

Technology risks: - Cybersecurity threats targeting representative systems or client data - Risks from digital distribution channels and robo-advisory - Data privacy and protection risks from new technologies - Risks from reliance on third-party technology providers

Market and business risks: - Changes in market conditions affecting product suitability - New product types or distribution models - Competitive pressures that may incentivise risk-taking by representatives - Macroeconomic conditions affecting client vulnerability

People risks: - Talent shortages in representative recruitment - Generational shifts in representative workforce - Remote working and supervision challenges - Mental health and wellbeing of representatives

Emerging Risk Process

  1. Scanning: Regular scanning of internal and external sources for emerging risks
  2. Assessment: Evaluation of the potential impact and likelihood of emerging risks materialising
  3. Communication: Briefing senior management and the board on significant emerging risks
  4. Response planning: Developing mitigation strategies for the most significant emerging risks
  5. Monitoring: Ongoing tracking of emerging risks as they develop
  6. Integration: Incorporating confirmed emerging risks into the established risk framework

Stress Testing and Scenario Analysis

FIs should conduct periodic stress testing and scenario analysis covering representative-related risks:

  • Misconduct scenarios: Impact of widespread mis-selling or unauthorised trading by representatives
  • Regulatory scenarios: Impact of significant regulatory changes on the representative business model
  • Operational scenarios: Impact of major system failures on representative supervision and compliance
  • Reputational scenarios: Impact of a high-profile representative misconduct case on the institution's reputation and business
  • Pandemic/disruption scenarios: Impact of business continuity events on representative supervision and client service

Results should inform the institution's risk appetite, capital planning, and contingency arrangements.


Previous Next

Back to Governance & Accountability