NISM Professor

Risk framework

Also written Portfolio manager risk framework · Investment risk framework · Risk management process

The risk structure a portfolio manager sets at the strategic level, in line with the investment objective — it names the risks, ranks them, decides how each will be treated, and is monitored and modified continuously.

In plain language

Investing is a risky activity, and return is the reward for taking risk. So a portfolio manager cannot simply avoid risk. She has to decide which risks she is willing to run, and how much.

A risk framework is where those decisions are written down. It is set at the strategic level, and it has to match the portfolio's investment objective.

Its first job is cultural. The framework creates awareness across the team, on the investment side and the operations side alike.

Its second job is harder. It has to be followed, as a continuous process, and kept up to date. A framework that is drafted once and filed is worth nothing.

Everything else in risk work hangs off it: which risks get listed, how each is measured, what action is taken when one occurs, and who is told.

How it works

Where it comes from (section 17.2). At the strategic level the portfolio manager shall create a risk framework in accordance with the investment objective. The workbook stresses that following the framework matters even more than writing it, as a continuous process that needs to be maintained, monitored and modified to stay relevant.

The six steps of the risk management process:

StepWhat it involves
Setting objectivesInvestment objectives defined with their respective risks — which also drives risk tolerance, performance measurement, rebalancing and reporting
Identification of risksListing all major and minor risks, with the portfolio objective in view
Analysing the risksAssessing each risk's impact; some are overwhelming, some negligible, some quantifiable and some not
Evaluating the risksRanking them by impact, using two metrics — severity of risk and frequency of occurrence
Treatment of riskActing on a risk event: tolerate, mitigate, transfer, or terminate
Control and monitorCapturing, analysing and reporting data to the concerned authorities, and modifying the framework where needed

What the framework buys the manager. The workbook lists the benefits: aligning risks with the investment objective; making the portfolio's risk profile and tolerance easy for investors to understand, which helps manage expectations; limiting the amount of risk the portfolio takes and avoiding unwarranted risks; avoiding the likelihood of excessive risks that can lead to large losses or even bankruptcy; better information flow across teams, with more transparency and quicker action; early detection of risks, frauds and capital requirements; improved compliance and audit; and, not least, creating value for the portfolio.

What the framework actually controls (section 17.5.1). A combination of risk parameters and their thresholds, scenario analysis, stress testing results and Value at Risk guides how much capital is maintained (risk budgeting), how much leverage, what position limits apply at country, sector, security, trader, investment manager and counterparty level, what stop-loss limits apply, which parameters are controlled such as beta and duration, and which tools are bought — protective puts, futures, swaps.

The framework is not a guarantee. Section 17.5.3 makes the point bluntly: during the 2008 financial crisis many large financial institutions failed, and some of them had detailed and functional risk frameworks in place. For such events the workbook offers scenario planning, tail risk assessment, stress testing and simulation — preparedness, not prevention.

No figure attaches to the framework itself. Section 17.2 sets no minimum review frequency, no required number of risk officers and no threshold. The numbers in the chapter belong to the measurement sections, not to the framework.

A worked example

Illustrative figures. Ratnagiri Portfolio Managers writes the risk framework for a Rs 500 crore equity strategy whose stated objective is long-term capital appreciation with a moderate risk tolerance.

Objective and risks. Benchmark Nifty 50 total return; tracking error tolerance 6%; no derivatives except protective puts.

Identified and ranked on severity and frequency:

RiskSeverityFrequencyTreatment
Market riskHighHighTolerate within limits
Concentration riskHighMediumMitigate — limits below
Liquidity risk in mid capsMediumMediumMitigate
Cyber intrusionHighLowTransfer, plus controls
Key-person exitMediumLowMitigate

The limits the framework sets:

  • no single stock above 8% of the portfolio, that is Rs 40,00,00,000
  • no single sector above 25%, that is Rs 125,00,00,000
  • minimum 15 stocks
  • at least 85% of assets in stocks with daily turnover above Rs 5 crore
  • stop-loss review triggered on any holding down 20% from cost

Control and monitoring. The risk officer reports limit usage to the investment committee monthly; any breach is reported within one working day.

One month later, a holding runs from 6.5% to 8.4% on price alone. The framework does not ask whether the manager still likes the stock. It requires the position to be brought back under 8%, that is a sale of about Rs 2,00,00,000 — because the limit, not the view, is what was promised to the client.

Why NISM asks about it

Chapter 17 (Risk), section 17.1 defines risk as the variability of outcomes, and section 17.2 (Process of Risk Management) sets out the framework and its six steps. Section 17.5 returns to it under managing risk, and 17.5.1 lists the parameters a framework controls. The phrase risk framework recurs throughout the chapter — in operational risk (17.3.4), country risk (17.3.9), concentration risk (17.3.10) and credit risk (17.4.5).

Expect a question on the order or content of the six steps, one on the two metrics used to evaluate risks (severity and frequency), and one on what the framework is required to be aligned with (the investment objective).

Common exam traps

  • This is the portfolio manager's own framework, not SEBI's Risk Management Framework for AMCs. That RMF is a regulatory requirement about dedicated risk officers for investment, compliance, operational and cyber security risk in a mutual fund AMC. Different paper, different obligation.
  • It is also not the Alternative Risk Management Framework, which is a commodity-derivatives margining regime for contracts prone to near-zero prices. Only the words overlap.
  • Evaluating and analysing are separate steps. Analysing assesses impact; evaluating ranks and prioritises using severity and frequency.
  • Treatment comes after evaluation, not before. A framework that jumps from identification to action skips the ranking that decides what is worth acting on.
  • The process is iterative. The workbook says so twice — the framework is modified to stay aligned with the investment objective, so a static document is a failed one.
  • A good framework does not make a portfolio safe. Section 17.5.3's 2008 example exists precisely to make that point.

Where this is taught

Free preparation for NISM Series XXI-B

Related terms

← All terms
Something look wrong? Report it