CySEC Advanced · Chapter 9 · Topic 4 of 13

Who governs risk in a CIF: the board, the risk committee and the risk management function?

The board's duties on risk, the risk committee, rules now limited to CRR firms, the risk management function, recovery plans, pay disclosure and model benchmarking.

By the ExamPass CY editorial teamLast reviewed 8 min read

Short answer

The board of directors sets and regularly reviews the firm's risk strategy and policies, gives risk enough time and resources, and keeps overall responsibility for it. A risk committee of non-executive directors advises the board on risk appetite and strategy; for Class 2 CIFs it is required once average assets exceed €100 million. An independent risk management function identifies, measures and reports all material risks. Firms in the top initial capital band keep recovery plans; Class 2 CIFs disclose pay in aggregate and report high earners to CySEC, which passes the data to the EBA.

Risk governance at a glance

BoardSets and regularly reviews risk strategies and policies; gives risk enough time and resources; keeps overall responsibility
Risk committee (exam material)Required for significant CIFs; non-executive board members with the knowledge, skills and expertise to monitor risk strategy and appetite
Risk committee today (Class 2)Required where average on- and off-balance-sheet assets exceeded €100 million over four years; not for Class 3
CRR firms onlyRemedy plan on client pricing; merged risk and audit committee with permission; head of risk removable only with prior board approval
Risk management functionIndependent; identifies, measures and reports all material risks; runs the ICAAP stress tests; for CRR firms, may report directly to the board
Recovery plansTop initial capital band and certain group entities; updated at least annually; simplified obligations possible
Pay disclosure (Class 2)Aggregate figures, including fixed and variable pay with the number of beneficiaries
High earnersNumber earning €1 million or more reported in €1 million bands; each board member's pay on CySEC's request; CySEC sends both to the EBA
Benchmarking (CRR firms with internal models)Results to CySEC at least annually; unexplained underestimation leads to corrective action

Source: Law 165(I)/2021, sections 22, 28 and 30; Law 97(I)/2021, sections 37 and 39; Directive 2013/36/EU, Articles 76 and 78; Regulation (EU) 2019/2033, Articles 46 and 51; Law 20(I)/2016, sections 3–5.

In the exam

The exam is written from the exam material, which predates the changes below. Expect its answer. If that answer is not among the options and the current rule is, choose the current rule.

  • Risk committee trigger

    Exam material: A CIF that is significant because of its size, organisation or the complexity of its business must set up a risk committee of non-executive board members.

    Current law (since 5 November 2021 (Law 165(I)/2021, section 22)): A Class 2 CIF needs one only if its on- and off-balance-sheet assets averaged more than €100 million over the previous four years. Class 3 CIFs need none.

  • Committee and risk-head rules

    Exam material: Every CIF follows three rules: a remedy plan from the risk committee when client pricing is out of line, merged risk and audit committees for a non-significant CIF with CySEC's permission, and removal of the head of risk only with the board's prior approval.

    Current law (since 5 November 2021 (Law 165(I)/2021)): These CRD rules bind only banks and Class 1-minus CIFs (for CIFs, Law 97(I)/2021 section 37). Law 165(I)/2021, which governs Class 2 and Class 3 CIFs, has no equivalent.

  • Who keeps recovery plans

    Exam material: Every CIF needs recovery and resolution plans, scaled to its size and business, which CySEC may reduce where a failure would do little harm.

    Current law (since 18 March 2016 (Law 20(I)/2016)): Only CIFs in the top initial capital band, and certain group entities, must keep recovery plans, which CySEC may simplify. Resolution plans are the resolution authority's work.

What must the board and the risk committee do?

The exam material takes these rules from the CRD, applied through CySEC Directive DI144-2014-14. Since 5 November 2021 the core duties for Class 2 CIFs have come from Law 165(I)/2021 (section 22), for Class 1-minus CIFs from Law 97(I)/2021 (section 37) and for banks from the banking law. The board sets and regularly reviews the firm's strategies and policies on how risks are taken, managed, monitored and mitigated, including risks from the wider economy and the business cycle. It gives risk issues enough time and resources, and reporting lines to it cover all material risks and risk policies.

The exam material says a CIF that is significant because of its size, internal organisation or the nature, scope and complexity of its activities must set up a risk committee. Its members are board members with no executive role and with the knowledge, skills and expertise to understand and monitor its risk strategy and appetite. It advises the board on its risk appetite and strategy, now and for the future, and helps it oversee how senior management carries out that strategy. The board keeps overall responsibility. Since 5 November 2021, Law 165(I)/2021 has required a risk committee of non-executive directors in Class 2 CIFs whose on- and off-balance-sheet assets averaged more than €100 million over the previous four years.

The exam material adds three rules for all CIFs: the committee reviews whether the prices of the assets and liabilities offered to clients reflect the business model and risk strategy and, if not, presents a remedy plan to the board; a firm that is not significant may, with CySEC's permission, merge the risk and audit committees; and the head of risk cannot be removed without the board's prior approval. Since 5 November 2021 these have applied only to banks and Class 1-minus CIFs (for CIFs, Law 97(I)/2021 section 37); Law 165(I)/2021 has no equivalent.

Terms used in this note

Risk appetite
The level and types of risk a firm is willing to take to meet its objectives.
Non-executive director
A board member with no management role in the firm, who can therefore challenge management.
Recovery plan
The firm's own plan for restoring its financial position after a significant deterioration.
Supervisory benchmarking
Comparing the results of firms' internal models on standard portfolios to spot outliers that understate capital.

What does the risk management function do?

The risk management function is independent of the operational functions and has enough authority, standing, resources and access to the board. It identifies, measures and reports all material risks, takes part in setting risk strategy and in material risk decisions, and where necessary reports directly to the board, independently of senior management. Its head is an independent senior manager; in a smaller firm another senior person may take the role if there is no conflict of interest. These details are CRD rules, now in Law 97(I)/2021 section 37 for Class 1-minus CIFs. For every CIF, MiFID II requires an independent risk management function where this is appropriate and proportionate; see What organisation, risk management and internal audit must an investment firm have?. In the ICAAP, CySEC's 2012 guidelines give it the job of identifying the risks, preparing the assessment and applying the stress tests, while internal audit reviews independently.

What does the chapter require on recovery plans, pay disclosure and internal models?

The exam material says CIFs need recovery and resolution plans proportionate to their size and business, which CySEC may reduce where a failure would not harm markets, other institutions or funding conditions. Law 20(I)/2016 requires recovery plans from CIFs in the top initial capital band and certain group entities. The board approves the plan, which is updated after material changes and at least annually; CySEC may set simplified obligations, having regard to the effect a failure could have. Resolution plans are the resolution authority's work, with the firm's cooperation.

For Class 2 CIFs, IFR Article 51 requires public disclosure of the pay policy's main features, the ratios the firm sets between fixed and variable pay, and aggregate figures for senior management and material risk-takers, including amounts split into fixed and variable pay with the number of beneficiaries, forms of variable pay, deferred amounts and severance. Class 3 firms make no pay disclosure; if they issue AT1 instruments, they disclose only their risk management objectives, own funds and own funds requirements. Separately, a Class 2 CIF reports to CySEC the number of people paid €1 million or more, in €1 million bands, and on request the total pay of each board member or senior manager; CySEC passes both to the EBA.

The exam material says firms permitted to use internal approaches report their results for benchmark portfolios, with their methods explained, at least annually. CySEC assesses the approaches at least annually and takes corrective action if one underestimates own funds requirements for reasons not explained by the underlying risks. The exam material's wording leaves out a 'not', so it reads as if such action should bring wrong incentives and herd behaviour; the CRD says corrective action must not lead to standardisation, must not create wrong incentives and must not cause herd behaviour. Benchmarking is a CRD rule for banks and Class 1-minus CIFs; IFR firms may use an internal model only for net position risk, and CySEC reviews that permission at least every three years.

How to think about it

Picture three layers. The board decides and remains accountable. The risk committee, made up of non-executives, advises and challenges. The risk management function does the daily work of finding, measuring and reporting risk, and runs the stress tests, while internal audit checks independently. Then ask which regime: the extra CRD rules on client pricing, merged committees and the head of risk now bind only banks and Class 1-minus CIFs.

Common mistakes

  1. Letting a committee take over the board's accountability. Committees advise and prepare; the board keeps overall responsibility for risk.

  2. Treating the CRD committee rules as universal. The remedy plan, merged committees and board consent to remove the head of risk come from the CRD, for banks and Class 1-minus CIFs.

  3. Mixing up the lines of defence. The risk function identifies, measures and stress-tests; internal audit reviews independently; the board decides.

  4. Assuming benchmarking applies to every CIF. It covers CRD firms with internal approaches; an IFR firm's only internal model, for net position risk, is reviewed at least every three years.

Practise this topic

Test what you just read

The Chapter 9 pack has 198 exam-style questions, 13 of them on this topic. Every question has a hint before you answer and a full explanation after.

Try the free demo

Or revise the numbers first with 48 free Chapter 9 flashcards →

Last reviewed on by the ExamPass CY editorial team against the law in force on that date. Study notes help you prepare for the CySEC exams; they are not legal advice. ExamPass CY is not affiliated with CySEC.

How we write study notesReport an error