Enterprise Risk Oversight

Heat Maps & Portfolio Dashboard

Residual position after 2nd LoD control effectiveness testing. Every tile and bar is clickable and drills into the register.

Inherent → Residual heat maps 5×5 per ERM Policy v4.0 · click any cell to open the underlying risks

Inherent (pre-control)
risks downgraded
held at High/VH
mitigation rate
Residual (post-control) · assessed only

Residual likelihood L′ = roundup( L × (1 − CEL) ), residual impact I′ = roundup( I × (1 − CEI) ). CE mapping: 1 Very Effective → 0.80 · 2 Effective → 0.60 · 3 Moderate → 0.40 · 4 Not Effective → 0.20 · 5 Absent → 0.00. Residual never falls to zero.

Inherent vs residual distribution 5-level, policy matrix bands

Residual risk by L1 taxonomy click to filter register

Assessment entities — residual profile High / Medium / Low residual counts per department

Risk Aggregation · L1 / L2

Taxonomy Aggregation & Final Ratings

Per policy: High Residual % = High RR ÷ High IR × 100. Medium Residual % = Med RR ÷ (High IR + Med IR) × 100. Rating rule: High % > 20 → High; else Medium % > 20 → Medium; else Low. Alphanumeric = max residual impact × max residual likelihood.

L1 principal risk categories

L2 sub-taxonomies within selected L1

RCSA · Risk & Control Self-Assessment

Risk Register

Q4 FY26 universe. Inherent assessment, control mapping, 1st/2nd LoD testing scores and residual grading per policy engine.

RefEntityRisk statementTaxonomyIRCERRCellΔ QoQ
ERM Policy §13 · ORM Annexure I

Loss Event Database

Internal and external loss events with occurrence / discovery / accounting dates and Basel Type 1 / Type 2 classification. Near misses tracked for KRI refinement.

IDOccurredDiscoveredDepartmentType 1Type 2Gross ₹Recovery ₹Net ₹Status
Forward-looking Indicators

KRI Monitor

Key risk indicators with green / amber / red thresholds. Latest reading drives RAG. Breaches escalate to RMCB per policy monitoring framework.

KRIDeptTaxonomyDirGreen ≤Amber ≤Red >LatestRAGTrend
Board-approved RAS · Q4 FY26 RMCB

Risk Appetite Statement

28 board metrics with appetite / trigger / tolerance bands, Q1–Q4 FY26 actuals and the FY27 annual-review proposal placed before RMCB. Quarter chips are RAG-graded against the band; tolerance breaches escalate to RMCB / Board.

#CategoryKey indicator / KRIDirRefAppetiteTriggerToleranceLast 4 quartersΔLatest statusFY27 proposal

Annual review notes as placed before Q4 FY26 RMCB

Credit & ECL: thresholds recalibrated to the revised FY27 AOP product construct, planned informal-segment expansion, forward GNPA movement and Q4 portfolio behaviour, retaining the 20% ECL tolerance floor. Capital & liquidity: CAR and LCR bands recalibrated for stronger headroom above regulatory minimums (Q4 CAR 42.14%, LCR 180%). Strategy: ROE / ROA / cost-to-income / AUM and PAT growth bands aligned to projected FY27 AOP (ROE 11.2%, ROA 2.90%, C:I 36.4%, AUM +20%, PAT +24%), keeping management triggers where performance deviates.

Risk Taxonomy

Risk Universe on a Page

Every L2 sub-taxonomy as a live card: residual Low / Medium / High counts from the current register and the max residual heat-map cell. Click a card to open the filtered register.

Risk treatment & remediation

Action Tracker

Action plans against any risk in the register — elevated or low. Each plan carries an owner, department, priority, target date, status and a progress log; overdue plans age automatically and roll up to the dashboard and board pack.

IDRaisedRisk refResidualAction planOwnerDept / functionPriorityDueAgeingStatusProgress
Reference data governance

Master Data & Taxonomy

Archer-style reference data behind every dropdown: taxonomy L1 / L2, assessment units, entities / departments and processes. Add, rename (cascades to all linked risks) or retire values; in-use values show their usage count and cannot be deleted until reassigned.

Risk taxonomy — L1 principal risks & L2 sub-taxonomies

Assessment units

Assessment entities / departments

Processes

Board & regulator outputs

Reports & Export

One-click board pack and CSV extracts for every register, plus the full JSON database for archival, hand-over or migration. Everything is generated locally from the live state — nothing leaves this file.

Board pack (RMCB view)

Executive summary: KPIs, risk appetite grid, taxonomy aggregation and elevated high-residual list, formatted for print / PDF.

Risk Appetite Statement

All RAS metrics with bands, Q1–Q4 FY26 actuals, Q4 status and FY27 proposal.

Risk Register (RCSA)

Full universe with inherent, control-effectiveness and residual grading per the policy engine.

Taxonomy aggregation

L1 final ratings with High / Medium residual percentages under the 20% rule.

Action tracker

All action plans with linked risk, owner, priority, due date, ageing, status and latest progress note.

Loss event database

Internal and external loss events with gross, recovery and net amounts.

Full database (JSON)

Complete state — risks, RAS, KRIs, losses, issues — for backup or restore on any machine.

Persistence: records auto-save to this browser (localStorage key mv_erm_studio_v1) on every change. Export the JSON before distributing the file or switching machines.

Issue Governance

Issues & Corrective Action Plans

Issues raised from 2nd LoD testing with CAP ownership, target dates, ageing and sustainability testing status.

IDRisk refIssueRoot causeCAP ownerTargetAgeingStatus
Administration

Data & Backup

All records live in this browser (localStorage) when opened locally. Export a JSON backup before distribution or machine change; import restores the full state.

Entity

State

Storage key mv_erm_studio_v1. If the file is opened in a sandboxed preview, persistence falls back to in-memory for the session — export JSON to keep changes.

Embedded methodology

Policy Reference

Operative extracts wired into this console's calculation engine.

Risk rating methodology (ERM Policy v4.0 §12)

Inherent score
IRS = Impact (1–5) × Likelihood (1–5); cell code = Impact digit + Likelihood letter A–E
Control effectiveness
1 Very Effective → 0.80 · 2 Effective → 0.60 · 3 Moderate → 0.40 · 4 Not Effective → 0.20 · 5 Absent → 0.00. Assessed for design and operating effectiveness; consolidated CE = weaker of 2nd LoD design / operational scores.
Residual
L′ = roundup(L×(1−CE)); I′ = roundup(I×(1−CE)); RRS = L′×I′. Residual is floored at 1 — no control eliminates all consequences.
Banding
5-level band read from the policy heat-map matrix cell; 3-level: VL/Low → Low Risk, Medium → Medium Risk, High/VH → High Risk.
Aggregation
High RR% = High RR ÷ High IR ×100; Med RR% = Med RR ÷ (High IR + Med IR) ×100. >20% High → High; else >20% Med → Medium; else Low.

Loss event data standards (ORM Policy v2.0 §15.1, Annexure I)

Dates captured
Occurrence, discovery and accounting date per event
Classification
Basel-aligned Loss Type 1 (7 categories) with Type 2 sub-classification per Annexure I
Scope
Includes near misses; excludes opportunity cost, reputational damage and expected future losses from operational loss quantum
Use
Frequency/severity analysis, expected vs unexpected loss, KRI refinement, RMCB reporting

Three lines of defence (ORM Policy §7.1)

1st LoD — business units own risks and controls, run RCSA testing, maintain evidence and report loss events. 2nd LoD — Risk Management Department and 1068: independent challenge of design and operating effectiveness, KRI framework, loss database, RMCB reporting. 3rd LoD — Internal Audit: independent validation and verification of the ORMF, reporting to ACB.