PILLAR 2 OF 3
Risk.
Identifying, measuring, and mitigating threats before they cause loss — the discipline that turns “what could go wrong” into a number, an owner, and a decision.
Workflow categories
Operational Risk4 workflows
- Business Continuity Plan (BCP) Review
- Disaster Recovery Gap Report
- Operational Resilience Testing
- Incident & Loss Data Collection
Includes all 4 workflows above.
Third-Party / Supply Chain Risk4 workflows
- Vendor Onboarding Risk Assessment
- Third-Party Risk Register
- Fourth-Party Supply Chain Review
- Vendor Contract Compliance Audit
Includes all 4 workflows above.
Cybersecurity4 workflows
- Zero Trust Architecture Gap Report
- Vulnerability Management Program
- Incident Response Plan Review
- Security Awareness Training Audit
Includes all 4 workflows above.
Operational Risk
- Business Continuity Plan (BCP) Review
- Disaster Recovery Gap Report
- Operational Resilience Testing
- Incident & Loss Data Collection
Includes all 4 workflows above.
Third-Party / Supply Chain Risk
- Vendor Onboarding Risk Assessment
- Third-Party Risk Register
- Fourth-Party Supply Chain Review
- Vendor Contract Compliance Audit
Includes all 4 workflows above.
Cybersecurity
- Zero Trust Architecture Gap Report
- Vulnerability Management Program
- Incident Response Plan Review
- Security Awareness Training Audit
Includes all 4 workflows above.
The definition
What risk is
In 1998, a hedge fund called Long-Term Capital Management had two Nobel laureates, flawless models, and 99%-confidence math saying it couldn't lose more than a fixed amount in a day. Then Russia defaulted, correlations snapped to one, and the fund lost $4.6 billion in four months — a failure large enough that the Federal Reserve had to coordinate its rescue to protect the system.¹ The models weren't stupid. They were precise answers to the wrong question: what usually happens, instead of what could.
That's the eternal tension of risk management. Here's the discipline itself:
Risk is the possibility that an outcome differs from what you expect — and in finance, that difference is measured in money. Risk management is the practice of finding those exposures before they find you: naming them, quantifying them, assigning an owner, and deciding what to do about them.
A financial institution is, by design, a machine for taking risk — it borrows short, lends long, and stands between parties who don't trust each other. Risk management is what keeps that machine from taking more than it can survive.
Where it came from
Risk management is a young science with expensive tuition.
Select a year
1952
Risk becomes math.
Harry Markowitz's Portfolio Selection defined risk as measurable variance — for the first time, diversification was a calculation, not a hunch. It eventually won him a Nobel Prize.¹
1988
Basel I.
The first international capital accord: banks must hold capital proportional to the riskiness of their assets. Risk measurement became a regulatory requirement, not a preference.²
1994
VaR goes mainstream.
J.P. Morgan released its RiskMetrics methodology and data to the public, and daily loss quantification became standard practice across trading desks.³
1998
LTCM.
The best models in the world, defeated by the assumption that the future resembles the past. The tuition payment for the story above.¹
2008
The models fail again, at scale.
VaR assumed liquidity that vanished and correlations that spiked to one. Diversification failed exactly when it was needed. The rebuild — Basel III, mandatory stress testing, living wills, the OCC's heightened standards — is the regime U.S. institutions operate under today.⁴
Sources
- 1. The Nobel Prize — Harry M. Markowitz, Prize in Economic Sciences 1990
- 2. Bank for International Settlements — Basel I (1988 Capital Accord)
- 3. J.P. Morgan / MSCI — RiskMetrics methodology, first published 1994 (archived methodology document)
- 4. Bank for International Settlements — Basel III frameworkBoard of Governors — stress testing (DFAST/CCAR) overview
The mechanics
The cumbersome part: turning threats into numbers
Risk calculation is genuinely hard because it forces uncertain futures into fixed formats. The main instruments:
The basic equation
Risk = Likelihood × Impact
Scored 1–5 on both, producing a tier.
Credit risk
PD × LGD × EAD
Probability of default, loss given default, exposure at default.
Market risk
Value at Risk (VaR)
How much can we lose in a day, at a given confidence level?
Scenario analysis
Stress testing
Not what usually happens — what happens in a specific disaster.
- The basic equation. Nearly every framework reduces to Risk = Likelihood × Impact. A risk register scores each exposure on both dimensions (typically 1–5), producing a tier — High, Medium, Low — that determines who owns it and how fast it must close.
- Credit risk: PD × LGD × EAD. Expected loss on a loan is the Probability of Default (PD), times the Loss Given Default (LGD), times the Exposure at Default (EAD). Three estimates, each with its own model, multiplied into one number that drives how much capital the lender must hold — the engine under Basel capital rules.¹
- Value at Risk (VaR). VaR answers one question: how much can we lose in a day, at a given confidence level? It became the industry standard for market risk in the 1990s — and its overconfidence became one of the lessons of 2008.
- Stress testing. Instead of asking what usually happens, stress tests ask what happens in a specific disaster: unemployment spiking, rates up 400 basis points, a key vendor gone. The Federal Reserve's annual stress-test regimes now make scenario analysis mandatory for large U.S. banks.²
- Risk appetite. The board-set boundary: the types and quantities of risk the institution is willing to take in pursuit of its strategy. Everything above is ultimately measured against this line.
The factors that go in: historical loss data, counterparty financials, market volatility, vendor and fourth-party dependencies, regulatory change, geographic and product concentration, operational error rates, and cyber exposure — weighted, scored, and re-scored on a cycle that never really ends.
The limitations
What risk models cannot tell you
- They assume the future resembles the past. Every model is trained on history. Tail events — the ones that actually kill institutions — are by definition the ones history underrepresents.
- Correlations break in a crisis. Assets that move independently in calm markets move together in panics. Diversification math fails at the exact moment it matters — 1998 and 2008 both taught this the expensive way.
- Garbage in, garbage out. A risk score is only as good as its inputs — and the most dangerous exposures (fourth-party vendors, new products, novel counterparties) are precisely the ones with the thinnest data.
- Measurement is point-in-time; threats are continuous. A risk register reviewed quarterly describes the institution as it was, not as it is. That gap is why periodic monitoring and scheduled recertification exist.
- Models inform judgment; they don't replace it. Every framework says this in its fine print. The institutions that fail are usually the ones that forgot it.
Why it matters
Risk measurement isn't defensive. It decides what you're allowed to do.
- Capital allocation. Basel-style capital ratios determine how much lending a balance sheet can support. Riskier assets consume more capital — so the risk model literally prices the growth strategy.¹
- Growth thresholds. In U.S. banking, crossing asset-size lines triggers different rulebooks — the OCC's heightened standards for risk governance apply at $50 billion in average consolidated assets today, with a 2025 proposal to raise that threshold to $700 billion.² Either way: risk planning determines not just how an institution grows, but what it's allowed to become.
- Product and market decisions. New products trigger risk assessments before launch. Vendor selection runs through concentration limits. M&A requires diligence on the target's exposures.
- The strategic frame. Risk management done well is not the department that says no — it's the system that tells the board which yes it can afford.
From signal to accountable remediation
Risk you can see, own, and close
Detection is the easy part. This pillar shows the evidence, the owner, and the path to done.
NIST CSF 2.0 — the six functions
Illustrative mappingGovern
Security policy library & oversight
Identify
Vulnerability management program
Protect
Zero Trust gap report; awareness-training audit
Detect
Continuous control-testing schedule
Respond
Incident response plan review
Recover
Disaster recovery gap report
Function names are exact to NIST CSF 2.0. Workflow mapping is illustrative and not a claim of full coverage.
Technology Platform Concentration Risk — Galileo Client Exit
- Evidence status
- Confirmed (public signal)
- Affected obligation
- Operational / Third-Party Risk — concentration & resilience
Recommended action
Request top-10 client concentration analysis; review vendor exit/termination plans; assess revenue diversification.
Risk register (excerpt)
Illustrative| Risk | Tier | Last reviewed | Evidence | Gap | Owner |
|---|---|---|---|---|---|
| Vendor — Galileo (Tier 1, platform) | High | 2026-06 | SOC 2 requested | Concentration — exit plan | Vendor Mgmt |
| Vendor — PaymentCo (Tier 1) | High | 2026-06 | SOC 2 on file | None open | Vendor Mgmt |
| Fourth-party — CloudHost | Medium | 2026-05 | Partial | DR test overdue | IT Risk |
| Internal — Access reviews | Medium | 2026-06 | Complete | None open | Security |
| Crypto — SoFiUSD operations | High | 2026-06 | Requested | New (Dec 2025) — controls TBD | CRO |
Third-party dependency chain
IllustrativeInstitution
SoFi Bank, N.A.
Primary vendor
Galileo — technology platform
Subprocessor
Cloud & data providers
Concentration and resilience risk follow the chain — fourth-party exposure is where it usually hides.
Open remediation — path to done
Illustrative- F-001 HighKYC / CIP program gap Overdue
- Owner
- BSA Officer
- Deadline
- Q1 2026
- Aging
- 74 days
- Evidence
- FINRA AWC on record
Closure criteria CIP gap-assessment closed against current FFIEC / FinCEN standards. - F-005 High$50B OCC heightened-standards uplift Monitoring
- Owner
- CRO / Governance
- Deadline
- Q3 2026
- Aging
- New
- Evidence
- Board charter under review
Closure criteria Heightened-standards program documented and board-approved. - F-006 MediumGalileo platform concentration Due
- Owner
- Vendor Mgmt
- Deadline
- Q2 2026
- Aging
- 32 days
- Evidence
- Top-10 client analysis requested
Closure criteria Concentration analysis and a vendor exit plan on file.
Continuity, recovery, and resilience — how they relate
Business Continuity (BCP)
The plan — how the business keeps running through disruption.
Disaster Recovery (DR)
The technical restore — systems and data brought back within targets.
Operational Resilience Testing
The proof — stress-testing that BCP and DR actually hold under pressure.
1 of 4