This lesson focuses on the specific controls and monitoring processes used to manage credit risk, from individual loans to the portfolio level.

4.1 The Credit Risk Control Framework
Given that credit risk is the most significant risk for most banks, a robust control framework is essential. This framework is built on clear credit policies, independent underwriting, and rigorous ongoing monitoring. The credit risk management framework is structured similarly to the three lines of defense: business units provide initial identification and operational monitoring (1st line), while risk management and compliance provide independent oversight through key risk indicators (KRIs) and limits (2nd line).

4.2 Control Activities in the Credit Process

  • Underwriting Standards: Clear, documented criteria for accepting new credit exposures.

  • Credit Approval Authorities: Limits on who can approve loans of a certain size.

  • Segregation of Duties: Separating the roles of relationship manager (who sells the loan) and the credit officer (who approves it).

  • Collateral Management: Procedures for valuing, perfecting, and monitoring collateral.

4.3 Monitoring and Control Tools

  • Early Warning Systems: Identifying borrowers showing signs of financial stress through traffic-light systems, missed covenant compliance, or deteriorating financial ratios.

  • Portfolio Limits: Establishing stop-loss limits on product parameters to manage concentration risk.

  • Escalation Protocols: Procedures triggered by limit breaches, requiring remediation plans within a set timeframe (e.g., 14-21 days) for supervisory board review.

4.4 The Risk Appetite Framework (RAF)
Credit risk appetite is defined as the aggregate risks acceptable for strategic goals, as mandated by regulations like NBU Regulation No. 64. A hierarchical monitoring model aligns this high-level risk appetite to operational controls, linking risk capacity, risk appetite, risk tolerance, and risk profile to specific monitoring objects and decisions..