A word from Giansimone Ghiottone, Risk Manager of Banca Popolare di Puglia e Basilicata
21/11/2017 2022-11-23 11:34A word from Giansimone Ghiottone, Risk Manager of Banca Popolare di Puglia e Basilicata
Giansimone Ghiottone has been Head of Risk Management at Banca Popolare di Puglia e Basilicata since late 2014. He is the focus of this November's column "La Parola A" (The Word A). In his interview, he explains the importance and dignity of risk management in the current operational and institutional context of the banking industry.
What specific skills should a risk manager have? How important is their role within your bank and in the banking environment in general?
The professional role of risk manager emerged in banking in the late 80s, parallel to the development and proliferation of mathematical and statistical models dedicated to risk measurement. These were the years in which the VAR (value-at-risk) model for measuring market risks became widespread, and several banks and consulting firms were instrumental in introducing increasingly sophisticated and complex models to serve their business lines. From that point on, modeling and the financial market developed hand in hand: consider the emergence of the securitization and derivatives market, the revision of framework supervisory framework which, particularly with regard to capital adequacy, recognised the value and merit of internal models for risk measurement (Basel 2).
The topic of risk management and enterprise risk management returned to the forefront with the 2007/2008 crisis, which exposed widespread shortcomings in the risk assumption, governance, and control processes of many intermediaries. Indeed, the risk management process primarily involves corporate governance, as the Board of Directors is responsible for defining risk objectives, monitoring their achievement, and making decisions based on established targets. It is no coincidence that the term "risk appetite" is used to define the risk appetite. framework which informs the correct declination of the maximum risk that can be assumed in relation to the expected results, taking into account the main constraint regulatory requirements on the one hand and the different expectations of the company's stakeholders. After the outbreak of the crisis, questions were raised about the "market failure" of risk controllers: the risk manager, however, was not yet a hierarchically independent figure from the risk takersToday, however, the risk manager (or Chief Risk Officer) holds a managerial role on a par with the business functions, answering for his or her actions directly to the company bodies (Board of Directors and CEO, if applicable).
The main driver The key factors behind this cultural revolution are the introduction of a process logic within organizational models that has impacted the second-level control function, the evolution of the risk manager's role from a laboratory to a function participating in strategic processes and management control processes, and, finally, the integration of risks, which has replaced the "silo" logic typical of previous operational models. The risk manager's mission is, in fact, to ensure integrated control of corporate risks by assuming responsibility for the proper identification, assessment, measurement, and mitigation of assumed risks. He or she must therefore possess the organizational standing and independence to assess the impact of corporate decisions on risk ex ante, interact regularly and systematically with the board, and maintain a relationship of equal dialogue with both other senior managers and the sales chain.
Cybersecurity has recently become a central topic for businesses around the world, including banks. Can risk management help mitigate the risk of cyber attacks?
Cyber risks represent one of the most difficult threats to address, capable of producing extremely negative economic and reputational consequences for businesses. The intangible and complex nature of cyber threats, combined with their rapid evolution, make it increasingly difficult to identify effective and timely mitigation measures. remedy, given that skills on the one hand and technical tools on the other change and evolve much more rapidly than security systems. Cyber risk affects all companies regardless of their size, sector of activity, or geographical area of operation. Therefore, a key aspect of cyber risk management is a comprehensive, circular process aimed at identifying IT system vulnerabilities, potential threats, and their likelihood of occurrence, estimating their potential economic, financial, reputational, and strategic impacts.
The contribution a risk manager can make to mitigating the risk of cyber attacks lies primarily in a methodological and operational approach, which must be broader and more vertical: first, avoiding certain risks must be addressed, followed by the possibility of transferring all or part of the risk to other specialized entities, and then mitigating and accepting the risk and associated costs. Risk managers can play a key role thanks to their experience and specialized skills in risk quantification. While not an IT specialist, they can provide expert advice ("risk opinion") to support the board and CEO, working closely with IT and other operational units (application managers, business users, etc.), including through scenario-based assessments and the resulting adaptation of residual risk management plans to the maximum acceptable risk level.
As in all sectors, training plays a crucial role in risk management. It's no coincidence that you chose to pursue an executive master's degree in risk management. How and why did you choose the European School of Banking Management?
The decision to attend the Master's in Risk Management at the European School of Banking Management is primarily due to the long-standing collaboration between BPPB and the ESB, resulting primarily from the ability to focus on the most relevant and innovative topics, where knowledge and ongoing training are undeniable success factors. Specifically, regarding the Master's in Risk and Cyber Security, the decision to attend classes fits precisely with this perspective, with knowledge undoubtedly representing the primary added value in a context of highly turbulent environments, technological disruption, and the reshaping of the role of certain sectors of economics and finance. My experience with the ESB's training programs has been very positive, so much so that it has encouraged many of my colleagues to undertake the same program, which I would wholeheartedly recommend.