CISI UAE FRR Risk Management Frameworks 4 — Questions and Answers
Question 1: Under CBUAE guidance, a bank's risk governance framework must ensure that:
- The Board sets and oversees risk appetite and that risk culture is embedded throughout the organisation (Correct answer)
- Risk management is the exclusive responsibility of the CRO
- Risk limits are set by the front office in consultation with the Board
- External consultants validate all risk policies annually
Correct answer: The Board sets and oversees risk appetite and that risk culture is embedded throughout the organisation
Effective risk governance requires the Board to own risk appetite, with a strong risk culture embedded from the top down throughout the organisation, supported by appropriate structures and accountability.
Question 2: The CBUAE's framework for 'Systemically Important Banks' (D-SIBs) requires them to hold:
- Additional capital buffers (D-SIB surcharge) above standard Basel III minimums (Correct answer)
- Lower capital ratios due to their systemic importance
- Reduced liquidity requirements
- Exemption from stress testing requirements
Correct answer: Additional capital buffers (D-SIB surcharge) above standard Basel III minimums
Domestic Systemically Important Banks must hold additional capital surcharges (D-SIB buffers) reflecting their systemic importance — the larger the systemic footprint, the higher the additional buffer.
Question 3: Under UAE risk management frameworks, 'scenario analysis' differs from VaR because it:
- Evaluates the impact of specific stress scenarios rather than relying on historical statistical distributions (Correct answer)
- Calculates the maximum loss at a 95% confidence level
- Focuses exclusively on normal market conditions
- Measures only credit risk, not market risk
Correct answer: Evaluates the impact of specific stress scenarios rather than relying on historical statistical distributions
Scenario analysis examines the impact of specific hypothetical or historical stress events on the portfolio, capturing tail risks and non-linear relationships that VaR's statistical approach may miss.
Question 4: The CBUAE requires banks to have a 'Liquidity Contingency Plan' (LCP) that includes:
- Early warning indicators, escalation procedures, and contingency funding sources (Correct answer)
- Plans for profitable deployment of surplus liquidity
- Arrangements for interbank lending to peer banks
- Monthly reporting to shareholders on liquidity position
Correct answer: Early warning indicators, escalation procedures, and contingency funding sources
LCPs must include monitoring indicators for emerging liquidity stress, escalation and decision-making procedures, and pre-identified contingency funding sources to be activated in a liquidity crisis.
Question 5: Under the CBUAE's framework, 'climate-related financial risks' are classified as:
- Physical risks (climate change impacts) and transition risks (policy/technology changes) (Correct answer)
- A separate standalone risk category not covered by Basel III
- Exclusively reputational risks with no financial impact
- Risks only relevant to environmental companies
Correct answer: Physical risks (climate change impacts) and transition risks (policy/technology changes)
Climate-related financial risks comprise physical risks (extreme weather, rising sea levels) and transition risks (policy changes, technology shifts, stranded assets) that can materialise as credit, market, and operational risks.
Question 6: What is 'risk appetite' versus 'risk tolerance' in UAE banking governance?
- Appetite is the level of risk the bank is willing to take; tolerance is the acceptable variance around that level (Correct answer)
- They are identical terms used interchangeably in UAE regulation
- Appetite applies to credit risk; tolerance applies to operational risk only
- Appetite is set by management; tolerance is set by the regulator
Correct answer: Appetite is the level of risk the bank is willing to take; tolerance is the acceptable variance around that level
Risk appetite defines the amount and type of risk the institution is willing to accept in pursuit of its objectives; risk tolerance defines the acceptable deviation from appetite thresholds before escalation is required.
Under CBUAE guidance, a bank's risk governance framework must ensure that: