Why financial risk management exists
Financial institutions are in the business of taking risk for a return. A bank lends money and earns interest — but risks non-repayment. A trading desk takes positions and earns a spread — but risks adverse price moves. An insurance company collects premiums and risks paying out more than it collected. Risk is not something to eliminate; it is something to measure, price, and manage.
The discipline of financial risk management grew rapidly after a series of high-profile failures — Barings (1995), LTCM (1998), Lehman Brothers (2008) — each of which demonstrated that an institution's internal risk models had badly underestimated the true exposure. Modern risk management combines quantitative measurement, regulatory oversight, and institutional governance to prevent any single risk from becoming an existential threat.
The four main types of financial risk
1. Market risk
Market risk is the risk of loss from changes in market prices — interest rates, equity prices, foreign exchange rates, commodity prices. It is the most visible form of risk for trading books and investment portfolios.
| Sub-type | Source | Key metric |
|---|---|---|
| Interest rate risk | Rate moves affect bond prices, loan values, swap P&L | Duration, DV01 |
| Equity risk | Stock price moves affect portfolio values and equity derivatives | Beta, VaR |
| FX risk | Exchange rate moves affect cross-currency positions, earnings translation | Delta, notional exposure |
| Commodity risk | Oil, gas, metals price volatility | Commodity VaR, hedge ratio |
The standard tool for measuring aggregate market risk is Value at Risk (VaR) — the maximum expected loss over a given time horizon at a given confidence level. A £10m 1-day 99% VaR means the desk should lose no more than £10m in a single day 99% of the time (though it tells you nothing about what happens in the 1% of cases where the loss exceeds that figure).
2. Credit risk
Credit risk is the risk of loss from a borrower's or counterparty's failure to meet their obligations. It has two distinct flavours:
Default risk is the probability that a borrower simply does not repay — the most classic form of credit risk in lending. Banks hold regulatory capital against this, calculated using probability of default (PD), loss given default (LGD), and exposure at default (EAD).
Counterparty risk is the risk that the other side of a financial contract — a derivative, a repo, a securities trade — fails to perform. Unlike loan default risk, counterparty risk is bilateral and the exposure fluctuates with market prices.
Spread risk is the risk that a borrower's credit spreads widen — reducing the market value of their bonds — even if they don't default. A portfolio of corporate bonds loses value when credit conditions deteriorate, even without a single default occurring.
3. Liquidity risk
Liquidity risk comes in two forms that are conceptually distinct but often hit simultaneously:
Funding liquidity risk is the risk that a firm cannot meet its short-term obligations — that it runs out of cash, even if it is technically solvent. This is what killed Northern Rock in 2007: the bank was not necessarily insolvent, but it could no longer fund itself in the overnight market. The remedy is holding sufficient liquid assets (a liquidity buffer) and managing the maturity profile of liabilities.
Market liquidity risk is the risk that a position cannot be closed at its quoted price — because the market is too thin, bid-offer spreads have blown out, or buyers have disappeared. In a crisis, assets that appeared liquid in normal times can become virtually untradeable. The 2008 mortgage-backed securities market was the extreme version: these instruments had been rated and traded as liquid assets, but when confidence evaporated, there were no buyers at any reasonable price.
4. Operational risk
Operational risk is everything else — loss from inadequate or failed internal processes, people, systems, or from external events. It is the hardest to quantify. Under Basel III, banks must hold capital against operational risk, calculated using either a standardised approach (based on income) or internal loss models. Major operational risk categories include fraud, IT failures, legal risk, and human error.
The £6.2bn "London Whale" loss at JPMorgan Chase in 2012 combined market risk (bad derivatives positions) with operational risk (inadequate risk oversight, mismarked books, and a failure of internal governance).
Two more types worth knowing
Systemic risk
Systemic risk is the risk that the failure of one institution triggers cascading failures across the financial system. It is not a risk any single firm manages for itself — it is a macroprudential concern managed by central banks and regulators through capital requirements, stress testing, and resolution frameworks. The 2008 crisis was fundamentally a systemic risk event: the interconnectedness of institutions meant that Lehman's failure froze credit markets globally.
Model risk
Model risk is the risk that financial models are wrong — either because they make incorrect assumptions, are applied to situations outside their valid range, or are implemented incorrectly. Every risk metric (VaR, CVA, option prices) depends on models. If the model is flawed, the risk measurement is flawed. This is why regulators require banks to have independent model validation functions and to stress-test their models against scenarios the models were not designed to handle.
How the types of risk interact
In practice, risk types do not stay in separate boxes. The 2008 crisis showed how they compound:
- Market risk (falling house prices) triggered credit risk (mortgage defaults)
- Credit risk destroyed the value of MBS, triggering market risk in structured credit portfolios
- Market and credit losses impaired bank capital, triggering funding liquidity risk
- Liquidity risk caused fire sales, which further worsened market risk
- The whole cycle was amplified by systemic risk — interconnectedness meant every institution was exposed to every other
This feedback loop — risk types reinforcing each other in stress — is why risk management teams increasingly use integrated frameworks (economic capital models, stress testing under correlated scenarios) rather than managing each risk type in isolation.
The risk management framework
Risk management at a financial institution is organised around three lines of defence:
The first line is the business — traders, relationship managers, lenders — who own and manage the risk they take on. They are responsible for staying within approved limits and for flagging risks they cannot manage.
The second line is the risk function — Market Risk, Credit Risk, Operational Risk, Treasury — which sets limits, monitors exposures, challenges the business, and reports to the board and regulators.
The third line is internal audit, which independently assesses whether the first and second lines are functioning as intended.
Go Deeper — Related Articles
- → Counterparty risk management — bilateral exposure in derivatives
- → Value at Risk (VaR) — the standard tool for measuring market risk
- → Tail risk — the extreme scenarios VaR doesn't capture
- → Model risk — when the measurement itself is the problem
- → Credit spreads — the market's real-time pricing of credit risk
- → Interest rate risk — and how fixed income investors hedge it