| 1. | Board’s Overall Responsibilities | The board has overall responsibility for the bank, including approving and overseeing management’s implementation of the bank’s strategic objectives, governance framework and corporate culture. |
| 2. | Board Qualifications and Composition | Board members should be and remain qualified, individually and collectively, for their positions. They should understand their oversight and corporate governance role and be able to exercise sound, objective judgment about the affairs of the bank. |
| 3. | Board’s Own Structure and Practices | The board should define appropriate governance structures and practices for its own work and put in place the means for such practices to be followed and periodically reviewed for ongoing effectiveness. |
| 4. | Senior Management | Under the direction and oversight of the board, senior management should carry out and manage the bank’s activities in a manner consistent with the business strategy, risk appetite, remuneration, and other policies approved by the board. |
| 5. | Governance of Group Structures | In a group structure, the board of the parent firm has the overall responsibility for the group and for ensuring the establishment and operation of a clear governance framework appropriate to the structure, business, and risks of the group and its entities. The board and senior management should know and understand the bank group’s organizational structure and the risks that it poses. |
| 6. | Risk Management Function | Banks should have an effective independent risk management function, under the direction of a chief risk officer (CRO), with sufficient stature, independence, resources, and access to the board. |
| 7. | Risk Identification, Monitoring, and Controlling | Risks should be identified, monitored, and controlled on an ongoing bank-wide and individual entity basis. The sophistication of the bank’s risk management and internal control infrastructure should keep pace with changes to the bank’s risk profile, the external risk landscape, and to industry practice. |
| 8. | Risk Communication | An effective risk governance framework requires robust communication within the bank about risk, both across the organization and through reporting to the board and senior management. |
| 9. | Compliance | The bank’s board of directors is responsible for overseeing the management of the bank’s compliance risk. The board should establish a compliance function and approve the bank’s policies and processes for identifying, assessing, monitoring, reporting, and advising on compliance risk. |
| 10. | Internal Audit | The internal audit function should provide independent assurance to the board and should support the board and senior management in promoting an effective governance process and the long-term soundness of the bank. |
| 11. | Compensation | The bank’s remuneration structure should support sound corporate governance and risk management. |
| 12. | Disclosure and Transparency | The governance of the bank should be adequately transparent to its shareholders, depositors, other relevant stakeholders, and market participants. |
| 13. | Role of Supervisors | Supervisors should provide guidance for and supervise corporate governance at banks, including through comprehensive evaluations and regular interaction with boards and senior management; should require improvement and remedial action as necessary; and should share information on corporate governance with other supervisors. |
The internal capital adequacy assessment process (ICAAP) and the internal liquidity adequacy assessment process (ILAAP) are the two key components of SREP.
| Risk Committee of the Board | Approves risk tolerance each year |
| Board Risk Management Committee | Approves risk tolerance , stress and performance limits each year, reviews business unit mandates and new business initiatives |
| Senior Risk Committee | Delegates authority to the CRO and holds additional authority in reserves approved by the risk committee of the board |
| CRO | Does independent monitoring of limits; may order positions closed or reduced for market, credit, or operational risk concerns |
| Heads of Business Units | Share responsibility for risk of all activities of that unit |
| Business unit Manager | Responsible for risk and performance of the business. Must ensure limits are delegated to traders |

Corporate governance refers to the system by which companies are directed and controlled, outlining the roles and responsibilities of shareholders, the board of directors, and senior management.
The significance of risk governance increased due to a series of high-profile corporate scandals, leading to regulatory reforms aimed at enhancing corporate governance, increasing transparency, and improving financial controls and oversight.
The Sarbanes-Oxley Act (SOX) is a US legislation passed in 2002 that established stricter legal requirements for boards, senior management, and auditors to enhance corporate governance and risk management.
Under SOX, CEOs and CFOs must ensure the accuracy of financial reports filed with the SEC, affirm the completeness of disclosures, and take responsibility for internal controls, including their design and maintenance.
European regulators pursued a voluntary reform of corporate codes with a "comply-or-explain" regime, rather than implementing legislative changes like the US.
The global financial crisis was triggered by a downturn in the real estate market and unsound mortgage practices. It highlighted failures in risk management, including a decline in underwriting standards and a reliance on complex credit instruments.
Basel III is a regulatory framework developed in response to the global financial crisis, aimed at increasing the resiliency of the banking system through stricter capital and liquidity requirements.
Basel III includes raising capital quality, imposing new liquidity ratios, and introducing a macroprudential overlay to reduce systemic risk and procyclicality.
The Dodd-Frank Act, signed into law in 2010, aims to improve consumer protection and systemic stability in the US financial industry through various measures, including ending "too-big-to-fail" and overhauling derivatives markets regulation.
The CRO is responsible for designing and implementing the firm's risk management program, including risk policies, analysis approaches, and ensuring the risk management infrastructure aligns with the organization's governance framework.