SFC Internal Control Guidelines: Risk Reports and Escalation
The SFC's Management, Supervision and Internal Control Guidelines expect a licensed or registered firm to provide management with appropriate exposure reports regularly and to report significant variances promptly.
More key points
- Risk policies, measurements, and reporting methods should also be reviewed regularly, especially before new services or products begin or when material changes may affect exposure.
On this page13 sections
- Regular reports and prompt escalation
- Reports should support decisions
- Review the methods when the business changes
- Scenario application
- Exam distinctions
- Design reports around decisions
- Set an exception path beyond the calendar
- Choose cadence proportionate to exposure
- Review controls when the business changes
- Scenario: limit breach discovered after hours
- Independent challenge improves reliability
- Governance when a limit is breached
- Key takeaway
A risk framework is only useful if information reaches people who can act on it. The SFC Internal Control Guidelines connect ongoing risk measurement with management reporting and timely escalation. A firm should be able to identify exposures, measure them in a way suited to its business, and communicate material changes without waiting for the next routine report.
Regular reports and prompt escalation
The Guidelines call for exposure reports to be submitted regularly to management. A significant variance is an additional trigger: it should be reported promptly, rather than held until the next scheduled report. The firm should define what counts as significant in light of its activities, limits, clients, products, and risk appetite.
Reports should support decisions
Useful reporting gives management a current view of the firm's financial and operational position, material exposures, breaches or near-breaches of limits, and weaknesses in controls. The aim is not simply to create a dashboard. Management needs enough context to decide whether to reduce a position, obtain more information, change a control, or pause an activity.
Review the methods when the business changes
Risk policies, measurement techniques, and reporting methods need regular review. Revisit them before launching a new service or product and when significant changes in services, products, laws, rules, or regulations could affect exposure. A method appropriate for a cash-equities business may miss risks introduced by derivatives, custody, electronic trading, or a new client segment.
Scenario application
Suppose a firm's normal exposure report is produced monthly, but intraday market moves push a proprietary position far beyond its approved limit. Waiting for month-end would not satisfy the guideline's escalation logic: a significant variance calls for prompt reporting so management can take timely action. The routine schedule and the exception process work together.
Exam distinctions
- Regular exposure reporting is expected; significant variances require prompt escalation.
- The firm should review risk methods when products, services, or relevant rules materially change.
- Risk reporting supports management accountability; it does not transfer management's responsibility to the risk function.
- The Guidelines are regulatory guidance and should be read with the SFC's current rules and the firm's activity-specific obligations.
Design reports around decisions
A useful exposure report shows the metric, limit, current exposure, trend, material assumptions and the person accountable for action. It should explain whether figures are actual, estimated or delayed, and identify positions or activities that management cannot see through an aggregate total. The right format depends on the firm: market, credit, liquidity, operational and client-asset exposures may need different measures. Reports should answer what changed, why it matters and what decision is needed.
Set an exception path beyond the calendar
A scheduled report is not a substitute for escalation of a significant variance. Define who receives an exception, how quickly, and what happens if the normal recipient is unavailable. A limit breach, rapidly deteriorating collateral, failed settlement or significant control outage may demand a same-day alert even where the ordinary committee pack is monthly. The firm should preserve the alert, acknowledgement and management response so it can show that material information reached someone able to act.
Choose cadence proportionate to exposure
The Guidelines use a principles-based expectation rather than prescribing one universal daily or monthly interval. A highly leveraged position or fast-moving electronic business can require intraday monitoring; a slower, less material exposure may be reported less often, with periodic review. Consider volatility, concentration, liquidity, client impact, settlement cycle and how quickly management can reduce risk. If data arrives late, the report should state that limitation and provide another control for the gap.
Review controls when the business changes
Before launching a product or entering a market, assess whether existing measures capture its risk and whether management receives the information needed to set limits. A new derivative, custody arrangement or outsourced technology can create exposures not visible in an old dashboard. Revisit assumptions, data feeds, limit owners and escalation thresholds after material business or regulatory changes, and test whether the report can identify a simulated breach.
Scenario: limit breach discovered after hours
If a trading desk exceeds a limit near the close and a standard committee report is scheduled for next week, the firm should use its exception path rather than wait. The initial alert should state the breach, data timestamp, uncertainty and immediate exposure; management can direct a freeze, reduction or further verification. Follow-up reporting should document the decision and monitor whether exposure returned within limits. The escalation itself does not replace root-cause review of why the limit was crossed.
Independent challenge improves reliability
Where practical, a person independent of the risk-taking unit should review key exposure measures and exceptions. Independence helps detect optimistic assumptions, omitted positions or pressure to reclassify a breach. The reviewer should have access to underlying data and authority to escalate unresolved disagreements. Management reporting should make clear where estimates or model limitations affect the result. Independent challenge does not replace the business owner’s responsibility to manage exposures; it strengthens the information on which senior decisions depend.
Governance when a limit is breached
An over-limit response should be consistent with the firm’s approved escalation procedure. Management may authorize temporary action only within its authority and with a documented reason, duration and mitigation plan. A repeated waiver can undermine the limit system and should prompt review of either the business decision or the threshold. Report the breach and waiver transparently so senior management can judge whether actual risk remains acceptable.
Key takeaway
Routine reports keep management informed. A material variance cannot wait for the routine cycle, and new business can require a fresh look at the measurement and reporting design.
Common questions
Can a significant risk variance wait for the next scheduled report?
The Guidelines call for significant variances to be reported promptly in addition to regular exposure reporting.
When should a firm review its risk reporting methods?
Regularly, and particularly before beginning new services or products or when significant changes could affect the firm's risk exposure.
Does SFC guidance require every firm to report daily?
It expects regular reporting suited to the firm’s business and prompt reporting of significant variances; it does not prescribe one interval for every exposure.
Can a risk team own the report and the risk?
The team can measure and report risk, but management retains oversight and decision-making responsibilities.
What should a variance report include?
At minimum, enough reliable context to identify the exposure, its significance, uncertainty, escalation and action owner.