Who governs risk in a CIF: the board, the risk committee and the risk management function?
The board's duties on risk, the risk committee, rules now limited to CRR firms, the risk management function, recovery plans, pay disclosure and model benchmarking.
By the ExamPass CY editorial teamLast reviewed 8 min read
On this page
Short answer
The board of directors sets and regularly reviews the firm's risk strategy and policies, gives risk enough time and resources, and keeps overall responsibility for it. A risk committee of non-executive directors advises the board on risk appetite and strategy; for Class 2 CIFs it is required once average assets exceed €100 million. An independent risk management function identifies, measures and reports all material risks. Firms in the top initial capital band keep recovery plans; Class 2 CIFs disclose pay in aggregate and report high earners to CySEC, which passes the data to the EBA.
Risk governance at a glance
| Point | Rule |
|---|---|
| Board | Sets and regularly reviews risk strategies and policies; gives risk enough time and resources; keeps overall responsibility |
| Risk committee (exam material) | Required for significant CIFs; non-executive board members with the knowledge, skills and expertise to monitor risk strategy and appetite |
| Risk committee today (Class 2) | Required where average on- and off-balance-sheet assets exceeded €100 million over four years; not for Class 3 |
| CRR firms only | Remedy plan on client pricing; merged risk and audit committee with permission; head of risk removable only with prior board approval |
| Risk management function | Independent; identifies, measures and reports all material risks; runs the ICAAP stress tests; for CRR firms, may report directly to the board |
| Recovery plans | Top initial capital band and certain group entities; updated at least annually; simplified obligations possible |
| Pay disclosure (Class 2) | Aggregate figures, including fixed and variable pay with the number of beneficiaries |
| High earners | Number earning €1 million or more reported in €1 million bands; each board member's pay on CySEC's request; CySEC sends both to the EBA |
| Benchmarking (CRR firms with internal models) | Results to CySEC at least annually; unexplained underestimation leads to corrective action |
Source: Law 165(I)/2021, sections 22, 28 and 30; Law 97(I)/2021, sections 37 and 39; Directive 2013/36/EU, Articles 76 and 78; Regulation (EU) 2019/2033, Articles 46 and 51; Law 20(I)/2016, sections 3–5.
In the exam
The exam is written from the exam material, which predates the changes below. Expect its answer. If that answer is not among the options and the current rule is, choose the current rule.
Risk committee trigger
Exam material: A CIF that is significant because of its size, organisation or the complexity of its business must set up a risk committee of non-executive board members.
Current law (since 5 November 2021 (Law 165(I)/2021, section 22)): A Class 2 CIF needs one only if its on- and off-balance-sheet assets averaged more than €100 million over the previous four years. Class 3 CIFs need none.
Committee and risk-head rules
Exam material: Every CIF follows three rules: a remedy plan from the risk committee when client pricing is out of line, merged risk and audit committees for a non-significant CIF with CySEC's permission, and removal of the head of risk only with the board's prior approval.
Current law (since 5 November 2021 (Law 165(I)/2021)): These CRD rules bind only banks and Class 1-minus CIFs (for CIFs, Law 97(I)/2021 section 37). Law 165(I)/2021, which governs Class 2 and Class 3 CIFs, has no equivalent.
Who keeps recovery plans
Exam material: Every CIF needs recovery and resolution plans, scaled to its size and business, which CySEC may reduce where a failure would do little harm.
Current law (since 18 March 2016 (Law 20(I)/2016)): Only CIFs in the top initial capital band, and certain group entities, must keep recovery plans, which CySEC may simplify. Resolution plans are the resolution authority's work.
What must the board and the risk committee do?
The exam material takes these rules from the CRD, applied through CySEC Directive DI144-2014-14. Since 5 November 2021 the core duties for Class 2 CIFs have come from Law 165(I)/2021 (section 22), for Class 1-minus CIFs from Law 97(I)/2021 (section 37) and for banks from the banking law. The board sets and regularly reviews the firm's strategies and policies on how risks are taken, managed, monitored and mitigated, including risks from the wider economy and the business cycle. It gives risk issues enough time and resources, and reporting lines to it cover all material risks and risk policies.
The exam material says a CIF that is significant because of its size, internal organisation or the nature, scope and complexity of its activities must set up a risk committee. Its members are board members with no executive role and with the knowledge, skills and expertise to understand and monitor its risk strategy and appetite. It advises the board on its risk appetite and strategy, now and for the future, and helps it oversee how senior management carries out that strategy. The board keeps overall responsibility. Since 5 November 2021, Law 165(I)/2021 has required a risk committee of non-executive directors in Class 2 CIFs whose on- and off-balance-sheet assets averaged more than €100 million over the previous four years.
The exam material adds three rules for all CIFs: the committee reviews whether the prices of the assets and liabilities offered to clients reflect the business model and risk strategy and, if not, presents a remedy plan to the board; a firm that is not significant may, with CySEC's permission, merge the risk and audit committees; and the head of risk cannot be removed without the board's prior approval. Since 5 November 2021 these have applied only to banks and Class 1-minus CIFs (for CIFs, Law 97(I)/2021 section 37); Law 165(I)/2021 has no equivalent.
Terms used in this note
- Risk appetite
- The level and types of risk a firm is willing to take to meet its objectives.
- Non-executive director
- A board member with no management role in the firm, who can therefore challenge management.
- Recovery plan
- The firm's own plan for restoring its financial position after a significant deterioration.
- Supervisory benchmarking
- Comparing the results of firms' internal models on standard portfolios to spot outliers that understate capital.
What does the risk management function do?
The risk management function is independent of the operational functions and has enough authority, standing, resources and access to the board. It identifies, measures and reports all material risks, takes part in setting risk strategy and in material risk decisions, and where necessary reports directly to the board, independently of senior management. Its head is an independent senior manager; in a smaller firm another senior person may take the role if there is no conflict of interest. These details are CRD rules, now in Law 97(I)/2021 section 37 for Class 1-minus CIFs. For every CIF, MiFID II requires an independent risk management function where this is appropriate and proportionate; see What organisation, risk management and internal audit must an investment firm have?. In the ICAAP, CySEC's 2012 guidelines give it the job of identifying the risks, preparing the assessment and applying the stress tests, while internal audit reviews independently.
What does the chapter require on recovery plans, pay disclosure and internal models?
The exam material says CIFs need recovery and resolution plans proportionate to their size and business, which CySEC may reduce where a failure would not harm markets, other institutions or funding conditions. Law 20(I)/2016 requires recovery plans from CIFs in the top initial capital band and certain group entities. The board approves the plan, which is updated after material changes and at least annually; CySEC may set simplified obligations, having regard to the effect a failure could have. Resolution plans are the resolution authority's work, with the firm's cooperation.
For Class 2 CIFs, IFR Article 51 requires public disclosure of the pay policy's main features, the ratios the firm sets between fixed and variable pay, and aggregate figures for senior management and material risk-takers, including amounts split into fixed and variable pay with the number of beneficiaries, forms of variable pay, deferred amounts and severance. Class 3 firms make no pay disclosure; if they issue AT1 instruments, they disclose only their risk management objectives, own funds and own funds requirements. Separately, a Class 2 CIF reports to CySEC the number of people paid €1 million or more, in €1 million bands, and on request the total pay of each board member or senior manager; CySEC passes both to the EBA.
The exam material says firms permitted to use internal approaches report their results for benchmark portfolios, with their methods explained, at least annually. CySEC assesses the approaches at least annually and takes corrective action if one underestimates own funds requirements for reasons not explained by the underlying risks. The exam material's wording leaves out a 'not', so it reads as if such action should bring wrong incentives and herd behaviour; the CRD says corrective action must not lead to standardisation, must not create wrong incentives and must not cause herd behaviour. Benchmarking is a CRD rule for banks and Class 1-minus CIFs; IFR firms may use an internal model only for net position risk, and CySEC reviews that permission at least every three years.
How to think about it
Picture three layers. The board decides and remains accountable. The risk committee, made up of non-executives, advises and challenges. The risk management function does the daily work of finding, measuring and reporting risk, and runs the stress tests, while internal audit checks independently. Then ask which regime: the extra CRD rules on client pricing, merged committees and the head of risk now bind only banks and Class 1-minus CIFs.
Common mistakes
Letting a committee take over the board's accountability. Committees advise and prepare; the board keeps overall responsibility for risk.
Treating the CRD committee rules as universal. The remedy plan, merged committees and board consent to remove the head of risk come from the CRD, for banks and Class 1-minus CIFs.
Mixing up the lines of defence. The risk function identifies, measures and stress-tests; internal audit reviews independently; the board decides.
Assuming benchmarking applies to every CIF. It covers CRD firms with internal approaches; an IFR firm's only internal model, for net position risk, is reviewed at least every three years.
Legal references
- The Prudential Supervision of Investment Firms Law of 2021 (Law 165(I)/2021), Greek text on CyLaw (opens in a new tab)
Section 22 (role of the board in risk management; risk committee) · Section 28 (high earners and board pay reported to CySEC and the EBA) · Section 30 (review of internal models)
- The Capital Adequacy of Investment Firms Law of 2021 (Law 97(I)/2021), consolidated Greek text on CyLaw (opens in a new tab)
Section 37 (treatment of risks, risk committee and head of risk for CRR firms) · Section 39 (supervisory benchmarking)
- Directive 2013/36/EU on access to the activity of credit institutions and prudential supervision (CRD), consolidated version of 11 July 2026 (opens in a new tab)
Article 76 (treatment of risks) · Article 78 (supervisory benchmarking of internal approaches)
- Regulation (EU) 2019/2033 on the prudential requirements of investment firms (IFR), consolidated version of 9 January 2024 (opens in a new tab)
Article 46 (disclosure scope) · Article 51 (remuneration disclosure)
- The Recovery of CIFs and Other Entities Supervised by CySEC Law of 2016 (Law 20(I)/2016), consolidated Greek text on CyLaw (opens in a new tab)
Section 3 (scope) · Section 4 (recovery plans, board approval, annual update) · Section 5 (simplified obligations)
- CySEC Circular C026: Guidelines GD-IF-02 for the Internal Capital Adequacy Assessment Process (issued 12 July 2012) (opens in a new tab)
Roles in the ICAAP: risk management function and internal audit
Practise this topic
Test what you just read
The Chapter 9 pack has 198 exam-style questions, 13 of them on this topic. Every question has a hint before you answer and a full explanation after.
Or revise the numbers first with 48 free Chapter 9 flashcards →