PILLAR 2 OF 3

Risk.

Identifying, measuring, and mitigating threats before they cause loss — the discipline that turns “what could go wrong” into a number, an owner, and a decision.

Workflow categories

Operational Risk4 workflows
BCPDRResilienceDORA
  • Business Continuity Plan (BCP) Review
  • Disaster Recovery Gap Report
  • Operational Resilience Testing
  • Incident & Loss Data Collection

Includes all 4 workflows above.

Third-Party / Supply Chain Risk4 workflows
TPRMVendor Due DiligenceFourth Party
  • Vendor Onboarding Risk Assessment
  • Third-Party Risk Register
  • Fourth-Party Supply Chain Review
  • Vendor Contract Compliance Audit

Includes all 4 workflows above.

Cybersecurity4 workflows
NIST CSF 2.0Zero TrustVuln Mgmt
  • Zero Trust Architecture Gap Report
  • Vulnerability Management Program
  • Incident Response Plan Review
  • Security Awareness Training Audit

Includes all 4 workflows above.

The definition

What risk is

In 1998, a hedge fund called Long-Term Capital Management had two Nobel laureates, flawless models, and 99%-confidence math saying it couldn't lose more than a fixed amount in a day. Then Russia defaulted, correlations snapped to one, and the fund lost $4.6 billion in four months — a failure large enough that the Federal Reserve had to coordinate its rescue to protect the system.¹ The models weren't stupid. They were precise answers to the wrong question: what usually happens, instead of what could.

That's the eternal tension of risk management. Here's the discipline itself:

Risk is the possibility that an outcome differs from what you expect — and in finance, that difference is measured in money. Risk management is the practice of finding those exposures before they find you: naming them, quantifying them, assigning an owner, and deciding what to do about them.

A financial institution is, by design, a machine for taking risk — it borrows short, lends long, and stands between parties who don't trust each other. Risk management is what keeps that machine from taking more than it can survive.

Where it came from

Risk management is a young science with expensive tuition.

1952

Risk becomes math.

Harry Markowitz's Portfolio Selection defined risk as measurable variance — for the first time, diversification was a calculation, not a hunch. It eventually won him a Nobel Prize.¹

The mechanics

The cumbersome part: turning threats into numbers

Risk calculation is genuinely hard because it forces uncertain futures into fixed formats. The main instruments:

  • The basic equation

    Risk = Likelihood × Impact

    Scored 1–5 on both, producing a tier.

  • Credit risk

    PD × LGD × EAD

    Probability of default, loss given default, exposure at default.

  • Market risk

    Value at Risk (VaR)

    How much can we lose in a day, at a given confidence level?

  • Scenario analysis

    Stress testing

    Not what usually happens — what happens in a specific disaster.

  • The basic equation. Nearly every framework reduces to Risk = Likelihood × Impact. A risk register scores each exposure on both dimensions (typically 1–5), producing a tier — High, Medium, Low — that determines who owns it and how fast it must close.
  • Credit risk: PD × LGD × EAD. Expected loss on a loan is the Probability of Default (PD), times the Loss Given Default (LGD), times the Exposure at Default (EAD). Three estimates, each with its own model, multiplied into one number that drives how much capital the lender must hold — the engine under Basel capital rules.¹
  • Value at Risk (VaR). VaR answers one question: how much can we lose in a day, at a given confidence level? It became the industry standard for market risk in the 1990s — and its overconfidence became one of the lessons of 2008.
  • Stress testing. Instead of asking what usually happens, stress tests ask what happens in a specific disaster: unemployment spiking, rates up 400 basis points, a key vendor gone. The Federal Reserve's annual stress-test regimes now make scenario analysis mandatory for large U.S. banks.²
  • Risk appetite. The board-set boundary: the types and quantities of risk the institution is willing to take in pursuit of its strategy. Everything above is ultimately measured against this line.

The factors that go in: historical loss data, counterparty financials, market volatility, vendor and fourth-party dependencies, regulatory change, geographic and product concentration, operational error rates, and cyber exposure — weighted, scored, and re-scored on a cycle that never really ends.

1 of 4