Before 2008, most major banks had a Chief Risk Officer who reported into the head of trading or the CFO. After 2008, regulators forced the line straight to the board. That single org-chart change (moving the CRO out from under the people whose risks were being measured) is the most concrete governance lesson of the crisis. Every other governance reform downstream of it is implementation detail.
By 2007, almost every major bank had sophisticated risk models. VaR was institutionalized, stress tests existed, capital was allocated through internal models. None of it prevented the collapse. The post-mortem from regulators, the Senior Supervisors Group, and academics converged on the same answer: the failures were governance failures, not technical failures.
Three patterns recurred. First, CROs reported to people whose risks they were supposed to challenge (heads of trading, CFOs, business-line presidents), so escalation died in the chain of command. Second, risk limits existed on paper but were exceeded routinely without consequence; "temporary" overrides became permanent.
Common mistakes
- Treating the CRO reporting line as administrative. Where the CRO reports determines whether escalation works. CRO-to-CEO with a board risk committee dotted line is the post-crisis standard. CRO under a business head is non-compliant. Trap: a question describes a "robust risk function" but the CRO reports to the head of trading.
- Confusing the audit committee and the risk committee. Audit verifies the integrity of financial reporting and oversees internal audit. Risk owns the risk-appetite framework and reviews material exposures. They serve different functions and at major banks must be separate.
- Treating risk appetite as a slogan. "We take prudent risk" is not a risk appetite statement, because it carries no operational content. The framework must contain numerical limits the board approved. Trap: choices that describe vague mission language as the firm's risk appetite are wrong.
Bottom line
- Governance failures, not model failures, drove the 2007-09 crisis. CROs reported to the wrong people, limits were exceeded without consequence, and boards lacked the technical literacy to challenge management.
- Three lines of defense: business units own risk, an independent risk function challenges and validates models, internal audit verifies. Each is independent, not subordinate to another.
- CRO reporting line: the CRO reports to the CEO with a dotted line to the board risk committee chair. Reporting through a business-line head is non-compliant at any major bank.
- Risk appetite framework translates strategy into board-approved numerical limits (VaR caps, stress thresholds, concentration ceilings, capital ratios) that management is accountable to. Vague language is non-compliant.
Exam shortcut
When a question asks whether governance is adequate, run the four-question screen: Does the CRO report independently? Are limits enforced or aspirational? Is there a separate risk committee with a quantitatively literate member? Does compensation include deferral AND clawback? A "no" on any of these likely makes the structure inadequate. Memory aid: "Independent line, separate committee, hard limits, paid for outcomes." Four pillars; if any is missing, governance is decorative.
The full lesson (about 2,784 words, 19 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
Browse all free FRM Part I lessons or jump into free FRM Part I practice questions.