There are five critical elements in our independent risk control process:
– we identify risk, through the continuous monitoring of portfolios, by assessing new businesses and complex or unusual transactions, and by
reviewing our risk profile in the light of market developments and external events
– we measure quantifiable risks, using methodologies and models which have been independently verified and approved
– we establish risk policies to reflect our risk principles, risk capacity and risk appetite, consistent with evolving business requirements and international
best practice
– we have comprehensive risk reporting to stakeholders, and to management at all levels, against the approved risk control framework and, where applicable, limits
– we control risk by monitoring and enforcing compliance with the risk principles, our policies and limits, and regulatory requirements.
Our risk policies are principle-based, specifying minimum requirements, high level controls and standards, and broad authorities
and responsibilities. They are never a substitute for the exercise of common sense and good business judgment but, rather,
guide and determine actions and decisions to ensure the safe and sound conduct and control of our business. Our risk policies
have widespread application, cover ongoing activities, and are developed in close consultation between the business and control
functions.
Before starting any new business, making a significant change to an existing business or the way it is conducted, or executing
any transaction which is complex or unusual in its structure or is sensitive to tax, legal, regulatory or accounting considerations,
we thoroughly review and assess all the implications. The process involves the business, risk control, legal, compliance,
treasury, finance, tax and logistics functions as necessary, and ensures that all critical elements are comprehensively addressed
across disciplines, including the assurance that transactions can be booked in a way that will permit appropriate ongoing
risk monitoring, reporting and control.