Three Stages of Risk Management: Defense, Uncertainty, and Performance
Book: Enterprise Risk Management: From Incentives to Controls
Author: James Lam
ISBN: 978-1-118-41361-6
Risk Management Grew Up in Three Acts
Chapter 15 steps back from credit, market, and operational mechanics. Lam asks a bigger question: how do companies actually use risk management over time?
Insurance and hedging are thousands of years old. Modern risk management as a business discipline really took off in the 1970s. Deregulation, shareholder pressure, regulation, and computing power pushed it forward.
Lam sees three major applications that mirror both history and how most firms mature:
- Loss reduction
- Uncertainty management
- Performance optimization
Together they become enterprise risk management.
Stage I: Minimizing the Downside (1970s-1980s)
Early risk work was defensive. Credit controls, conservative investment policies, audit, and insurance aimed to stop bad outcomes.
- Credit: approve carefully, recover after default
- Market: favor government bonds, avoid liquidity crunches
- Operational: accurate books, compliance, insurance as main transfer tool
Downside focus alone proved too narrow. Portfolio insurance in 1987 is the poster child. Professors Leland and Rubinstein designed strategies to sell stocks into cash as markets fell. About $60 billion was insured by October 1987. When the crash hit, sell programs could not keep pace. Insured investors barely beat uninsured ones. The product faded and was blamed for deepening the crash.
Loss reduction still matters. But pure defense created the “offense vs defense” war between business lines and risk functions that Chapter 6 described. Risk teams looked like deal killers. Something had to shift.
Stage II: Managing Uncertainty (1990s)
Stage II targets volatility around earnings and cash flow. Floating exchange rates, oil shocks, inflation, derivatives blowups, and cross-market contagion made results swing harder. Investors punished earnings surprises.
Tools evolved:
- Credit scoring and migration models for sharper provisions
- VaR and economic capital for trading and balance sheets
- Operational risk attention after Kidder, Exxon Valdez, Perrier benzene, and governance reports (Treadway, Dey, Turnbull)
Risk transfer exploded. Derivatives and complex insurance helped, but Barings, Metallgesellschaft, and Bankers Trust showed levered structures plus control failures still wreck companies. Alternative risk transfer (ART) bundled risks that traditional policies ignored.
Silos started integrating. Counterparty credit began including market exposures. Holistic views set up Stage III.
Stage III: Performance Optimization (ERM)
Stage III merges risk and return inside business decisions. Partial silo integration becomes full enterprise integration. Risk management stops being only control. It influences pricing, capital allocation, and strategy.
Examples Lam highlights:
- Credit - risk-based pricing, concentration limits, active portfolio management, splitting origination from distribution
- Market - firm-wide asset allocation across assets, liabilities, and off-balance sheet items, not just treasury portfolios
- Operational - process maps from reengineering plus activity-based costing reveal true cost drivers
RAROC and similar metrics let management compare businesses on risk-adjusted terms and guide acquisitions.
ERM is the offensive use of risk tools: take the right risks on purpose, shed the wrong ones, price both honestly.
What Comes Next?
Business change reshapes risk practice. Lam lists mega-trends:
- Globalization and networked operations
- Technology-driven new operational risks
- Deregulation, privatization, new entrants
- M&A, alliances, outsourcing, reengineering
These trends interact. Better communications accelerated globalization, which forced deregulation, which pushed restructuring. Treating them as separate silos is a step backward.
The chapter closes by pivoting to industry-specific applications in financial institutions, energy firms, and non-financial corporations. The universal lesson is already stated: integrated response beats piecemeal controls.
My Take
This is one of the clearest maturity models in the book. You can map your company quickly:
- Still arguing about whether risk is the “business prevention department”? Stage I hangover.
- Running VaR and provisioning but not linking to product pricing? Stage II.
- Allocating economic capital to desks and deals, with risk in strategic planning? Stage III territory.
Portfolio insurance is a humbling reminder that clever products fail when liquidity and human behavior do not match the model.
The shift from defense to performance is not about taking more risk. It is about taking risk deliberately and measuring whether you get paid for it.
Previous: Previous: Operational Risk Measurement (Chapter 14, Part 2)
Next: Next: ERM for Financial Institutions (Chapter 16)