This lesson explores the rapidly evolving landscape of banking risk, focusing on climate risk, third-party risk, and the role of technology in the future of risk management.

8.1 Climate Risk
Climate risk is the risk of financial losses or operational disruption resulting from climate change. It is increasingly recognized as a major prudential risk, a core focus of organizations like the ECB and NGFS, and banks are expected to embed it into their credit assessment . Climate risk is typically broken down into two categories:

  • Physical Risk: The risks from the physical effects of climate change, such as extreme weather events (floods, storms) or chronic changes (sea-level rise, long-term temperature changes). These can directly damage physical assets and disrupt supply chains.

  • Transition Risk: The risks arising from the transition to a low-carbon economy. This includes policy changes (e.g., carbon taxes), technological disruption, and shifts in market sentiment that could devalue assets in carbon-intensive sectors.

8.2 Third-Party and Technology Risk
The digitalization of finance has made banks increasingly dependent on third-party service providers, from cloud computing companies to FinTechs. In response, the Basel Committee published a new set of principles for the sound management of third-party risk in December 2025 . These principles establish a common baseline for banks and supervisors to manage outsourcing and third-party relationships, superseding the 2005 guidelines .

  • Cybersecurity Risk: The risk of loss from a failure in an organization’s cybersecurity. This can lead to operational disruption, financial theft, and significant reputational damage. It is a critical concern for banks and a focus of both internal control and regulatory supervision .

8.3 The Future of Risk Management
The future of risk management is being shaped by technology and data. The Basel 2025 credit risk principles require “forward-looking” risk management and have strengthened expectations on data and management information (MI), aligning credit-risk data aggregation with BCBS 239 standards . This means banks must ensure end-to-end data traceability, timely reconciliation, and near real-time monitoring of exposures. The ability to integrate forward-looking analytics, predictive modeling, and automated escalation protocols is no longer a “nice-to-have” but a necessity for regulatory compliance and resilient performance