Cybersecurity Risk Management

How Risk-Aware Leaders Build What Lasts

You’ve done the hard part—built the roadmap, aligned the teams, launched the platforms. But too often, transformation hits resistance where it wasn’t expected. Credit shifts pull funding. Compliance reviews delay go-lives. A policy change in one market forces rework across others. The tech didn’t fail—the assumptions did.

In a time of AI acceleration, geopolitical uncertainty, and capital discipline, risk has moved upstream. The leaders who are navigating this best aren’t just reacting faster—they’re designing with risk in the room from the start. Not to slow down innovation, but to make sure it actually lands. What if risk was more than a checkpoint? What if it was your unfair advantage in building transformation that holds?

Transcript

Sanjog Aul [00:00:00]:
Hello and welcome to CTN. To learn more about the show, please visit ciotalknetwork.com and the topic for today is How Risk-Aware Leaders Build What Lasts. Why we talk about risk. We’ve got AI. You’ve got all the political, geopolitical, socioeconomic, type of upheavals happening and there are other business model disruptions happening as well. So when you got that much going on, you might be trying to do transformation in your business, in your technology, and all of them in different variations and combinations but then are you sure about what the outcome that you are seeking will actually happen because you don’t always know what is going to be a disruption that might be caused at the spur of the moment but how do you prepare for it or are you preparing it the right way because if you don’t, then you get something which is less than desired.

Sanjog Aul [00:01:00]:
So what does that do to you? You remain uncertain, but that’s where perhaps risk management could come in and what are essentially the top leaders who are looking at risk first approach doing to make sure that whatever they plan out so far, they’re able to manage to make it happen with minimal deviations from what they had to do. So they are essentially being proactive, but it’s easier said than done. So what we wanted to understand on this discussion is what are the top risks that are coming up given the disruptions, how are the leaders, progressive leaders, dealing with it and what’s working and what’s not working and given the things are also going to become more uncertain and more volatile going forward, how are the risk leaders thinking and how should the technology and business leaders thinking with a risk first approach? With that said, I have a fundamentally an amazing guest for this discussion. He’s Dr. Ramesh Gopal, who’s the Chief Risk Officer for United Arab Emirates and Saudi and he’s the head of credit risk at CEEMEA for Deutsche Bank. Hey Ramesh, how are you sir?

Dr. Ramesh Gopal [00:02:11]:
Hi to everyone. I’m fine. Hope things are fine at your end.

Sanjog Aul [00:02:17]:
Very good, thanks for you to joining us because we needed this discussion at a level which is not tech people talking for the tech, but let’s give it a business spin. So let’s start with the basic question. A lot of times I’m sure you’re dealing with these initiatives all the time. Give me an instance where you might have made an assumption and that came and haunted you when it came downstream and when you were in the thick of things. When it’s an initiative going on which is mission critical for the organizations.

Dr. Ramesh Gopal [00:02:49]:
I will go back to the global meltdown dating back to 2008 for this. The two years that the financial industry experienced 2008 to 2010 and in fact a part of 2011 was, that was very unprecedented, so to say. People were taken aback as to how their models failed them in the financial industry and in the risk management to mind, be it the subprime crisis or be it the factoring of derivatives or the hedges that lasted in the industry, that were basically structured in the industry. So models went wrong in estimating the losses for the financial institutions and so came that knee jerk reaction once the peak of the global meltdown started receding. Every model was being urgently recalibrated to factor in the changed environment between 2008 and 2011, because people felt their models were wrong, since the assumptions basically were wrong. Now the industry entered say 2011-2012 into the migration phase from the global meltdown, trying to recover from it

Dr. Ramesh Gopal [00:04:16]:
and as model readers, we find that the output that the model was throwing out did not make sense. The pricing was distorted, the risk premiums didn’t make sense, either they were low or they were high. They were not specific to the segment which were being looked at. So something was clearly wrong and this was because negative sentiment of the human minds were getting into assumptions into these models based on the hallow effect of the global meltdown and people realized that this was contributing to things not making sense. When the models recalibrated, models were actually throwing out the output.

Dr. Ramesh Gopal [00:05:07]:
So technology was there, but the assumptions that we input into the models were throwing the wrong results when we actually wanted them to factor in the downside risk and throw us the result. So assumptions that we have input into the models also can go wrong because it depends on what gets factored into a model in which scenario and you’re reading that particular output under which context. So that’s very important. So these are certain instances where assumptions have really failed us, although technology prevailed to handle it.

Sanjog Aul [00:05:53]:
So given the example that you gave of a meltdown and that was like really a tough time for all of us and to be very frank, the way at least what we all heard in the news in the mainstream media was to some extent it was self inflicted. The other, other thing was that it was something with nobody. It was unprecedented essentially. So let’s go back to this function of risk management and everyone at all times when thinking about risk, they first think, okay, what is the tolerance that we have and based on that, you decide which all assumptions we can afford to make which all things we have to validate and then put in practice. So if you took that example, and I’m sure there would be other parallel examples, maybe not that grave of examples, but who goes and checks and is there a more of a numeric measure to say that are we really living at the risk tolerance level that we ought to be and who police is it to make sure that the world doesn’t suffer because of some people got comfortable, lazy or whatever other flavors that might be where they took the liberty of going with lot many more assumptions which they should have not gone with.

Dr. Ramesh Gopal [00:07:12]:
Thresholds have always prevailed to monitor a particular appetite as to how much can an institution take? The policing of those threshold starts in the form of a top down approach. It gets approved by the board or its nominated committee and then it cascades down to the departments which have been mandated to monitor and police such thresholds but when an unprecedented event like this happens, or a black swan type of an event happen, it’s ultimately the human mind which is impacted by the negative sentiment. So people start questioning what they did wasn’t right because you experienced an unprecedented situation and then comes the review of the thresholds which were we right here? Where we wrong here? Can we correct it to factor in such a negative scenario going forward? So when that negative sentiment sets in, you try to revisit, review your thresholds, your policy, rather your thinking process itself because that defensive mechanism makes you once bitten, twice shy philosophy comes in and that makes you very, very defensive that you should not face the same issue in future. So although thresholds prevail, policing prevails, the impact of a hit makes you revisit those and that basically distorts your future decision making.

Dr. Ramesh Gopal [00:08:50]:
I’m not saying do not revisit or review anything, but do not revisit or review anything as a knee jerk reaction. As a reaction where you are still in that situation of being hit and you have not yet come out of it. It’s only in such situations you tend to commit mistakes and this is what happens despite all policies, thresholds and policing that prevails in an institution as a matter of framework itself.

Sanjog Aul [00:09:20]:
So that brings up to me to the next question which would be very much tied in because you in a way said is that you cannot react. Yes, you have to respond, but you cannot have a knee jerk reaction and there should be some level of preparedness and no matter how much somebody prepares, a black swan event is a black swan event but then not every day a black swan event event happens either so what is that benchmark that you would have, said we should all have and for the preparedness and secondly, are there any illusions people have that yes, we are ready for it, and if those are, what are those and how does somebody get out of those because nobody wants to wait for the dark things to happen and then wake up. It’s painful for everyone involved.

Dr. Ramesh Gopal [00:10:09]:
I think this is a very profound question because this is something which we see very commonly and frequently in today’s world. So if you ask me, the biggest illusion of preparedness is a lopsided understanding of what risk is all about. So it’s the lopsided understanding of risk which is the biggest illusion with which several leaders suffer. For example, we live in a world where we are presented with huge growth opportunities and you need to target those pockets of growth to grow as an institution. So this is what we call the opportunity of growth. You’re tempted not to leave these opportunities, but at the same time, when there is growth, there is also risk element that comes with it, which is what we call the risk of growth. So being tempted towards growth, you should not be ignoring the risk of growth that is out over there. On the other hand, we live in a world where new facets of risk, new dimensions of risk are emerging faster than ever before.

Dr. Ramesh Gopal [00:11:34]:
So this is what we call the growth of risk. You cannot get so conservative and run away just because the new dimensions of risk are growing. Where leaders fail is basically in either focusing just on the risk of growth or the growth of risk. This is the illusion which I say, a lopsided understanding of risk. An efficient leader is one who will know and who will try to balance the risk of growth and the growth of risk because even if one is not handled effectively, that’s very clear sign of an incomplete preparedness to growth that you’re going to win.

Sanjog Aul [00:12:35]:
So if I were to take the two extremes, on one hand, you could be complacent, you could be lazy, or you could be overconfident and on the other extreme, you could be paranoid. So when any organization is working with it, what would your calibration say they should be at on that sliding scale, for them to do a good job with risk assessment, risk tolerance, level determination, and then risk management.

Dr. Ramesh Gopal [00:13:05]:
Yes. So first comes the aspect of setting your risk appetite and then defining what are the tolerance levels. Let’s get it very clear. We live in a very practical world where things are changing rapidly. You cannot set an appetite and say, this is hard coded. Nothing can deviate from this you cannot set a framework and say you are supposed to operate only within this particular hard born framework. Yes, framework needs to be adhered to, respected to but that’s where the next thing comes, which you mentioned rightly, risk appetite

Dr. Ramesh Gopal [00:13:51]:
then comes risk tolerance. How much of a deviation can you take, northward or southward, east or west? It’s very important to give that flexibility within your organization to people to whom you have cascaded the mandate to manage the risk because when that flexibility is given, you know that you’re operating within a framework, but with very clear risk tolerance level. Now when you integrate risk appetite and risk tolerant into an execution methodology, that’s where risk management comes into picture. So when risk management is done with this very clear top down approach, an institution can be confident that it is well prepared to basically manage the kind of new risk elements that can emerge and at the same time reduce the illusion of preparedness, which you mentioned rightly, that illusion of preparedness, when it is reduced with the help of your risk management, things can go right with the highest probability or with the maximum probability that you can expect it to go. So I would summarize a long answer short to say start with risk appetite, bring in your risk tolerance and overlay it with execution methodology called the risk management. Now that risk management itself, how to run it is a different question but this is an overall way to run a risk management to handle the illusion of preparedness that you are alluding to.

Sanjog Aul [00:15:33]:
See very frankly the risk and governance, GRC group, if you will, if you talk to them, they are the most fascinating set of people who are almost looking at making sure that the business risk and the technology risks don’t outweigh the benefits and that’s their job but interestingly, when they take the same message to the technology and business leaders, they get a lot of resistance, sometime passive, sometimes active because those other people while in the corner of their mind they think yes, I have to take care of it but they get their paychecks because of the growth they deliver and the value creation they do. So if somebody’s performance appraisal is not connected to be cautious and that job is left to you, then that could become a tug of war and the organization suffers. So what have you seen companies do to make sure that tug of war is limited and either you neither you as a risk management leader and or your department slows the organization down but at the same time there is no recklessness, reckless behavior shown or demonstrated by IT and business.

Dr. Ramesh Gopal [00:16:54]:
I would say let’s go back to the basics in terms of you’re in a race and when we talk about race, the first thing that comes to our mind is the horse racing. How does a horse race with the highest speed, but at the same time it has to be controlled speed. So organizations basically go back to those principles. Allow the horse to race, else you’re not in the race at all but at the same time ensure that you have the right control mechanism to stop the speed when it is required, or sometimes even to alter the speed in a way you need. Now, I’m not saying that it’s a division like a risk management or it, whatever we call the technology is a division wherein they stop your speed or they reduce your speed. No, that’s not the case. Infrastructure functions like technology, risk management and business have coexisted and will coexist

Dr. Ramesh Gopal [00:18:07]:
but it’s the question of the lines of defense that you establish, wherein each one understands their role and responsibility in the right spirit, in the right manner that will make an organization deliver its deliverables. So business should be racing, else you are not in this business at all but at the same time empower the control functions to ensure they’re controlled in the right way. When I say control, don’t get me wrong, I’m not using it in the wrong sense, but to direct them, to guide them, to ensure their focus still remains out over there. It’s like a GPS. The infra functions basically are like the GPS that you use. It guides you in the right direction so that you don’t go away. If you misunderstand it to be controlling the way you drive, then you miss the route somewhere.

Dr. Ramesh Gopal [00:19:04]:
So the way we understand an organization is set up. Each function is being mandated, each function is being empowered. If that is put into the right perspective, I think organizations will not have the this issue of resistance from different units, either in terms of governance, in terms of risk, or in terms of control. Whatever it is, business and GRC have coexisted and will coexist and they are not opposite terms, they are coexisting terms. They are not oxymorons.

Sanjog Aul [00:19:40]:
So when you come up with your risk management policies and other frameworks, et cetera, the assumption, and you can correct me if I’m wrong, that you do it based on a snapshot, some historical data, that this is what we have to do, et cetera, and then you arm with those benchmarks, those thresholds, those assumptions, these IT and business leaders who are supposed to charge ahead but then more than ever, there is volatility, there’s fluidity, There is uncertainty in the way the business and the IT landscape is evolving. So imagine you gave them a set of weapons, you told them to go to a war, but the assumptions you made on what kind of war it’s going to be, and based on which, how would you handle risk that keeps changing by the day. Then what is your mechanism to be embedded somehow in their daily war, that you keep changing your benchmarks, you keep tweaking your thresholds, et cetera, so that you are optimally allowing them to use all the resources available to them, minimizing risk and maximizing growth. First of all, is this a pipe dream or is this even possible to do?

Dr. Ramesh Gopal [00:20:51]:
Risk, as I said and growth are not two opposite terms. They will definitely coexist. It’s just that you need to sharpen the axe before you start cutting the tree, sharpen your risk management framework, your internal controls before you start growing. When you do that, both of them can definitely coexist. Coming to the metaphor that we used on giving the required ammunition to your business partners to go and fight the war, what happens if you load them with outdated weapons? Do they fight the war or you try to manage it in such a way that you get dynamic? I would say we have evolved as risk management across the financial industry in a way that we have migrated from a ground war scenario, which is the orthodox war methodology, to a very clear remotely controlled aerial war scenario, these days. Practically in the conflicts that are happening in the world, same thing is happening in the financial industry as well. If we code this as a war that we are basically fighting, exactly the same thing is happening. The risk management units do not give the ammunition or the weapons to any of the other departments be the business or the technology to go and fight the war.

Dr. Ramesh Gopal [00:22:27]:
Rather, it’s more like a remotely controlled aerial war in wherein it’s dynamically updated based on the inputs that you’re getting on a real time basis. This is where blockchain, AI, machine learning, advanced data analytics have all been embedded into risk management to ensure that you don’t live in an outdated world of giving them something with which they get into the act of business or act of war and then later on you and them realizing I think we were outdated. Rather it’s now real time risk management inputs that come in and on real time basis they are being recalibrated and passed on either in the form of a risk appetite or in the form of risk approvals or controlled by overall risk management framework. So I think we have as risk management unit and GRC evolved over a period of time, yes, it has been not an easy experience evolving into where we are today. Not everyone has also evolved, so let us be very honest about that fact but many leading financial institutions have evolved and are here in this state right now wherein they can very happily say that we are in the modern warfare era of business.

Sanjog Aul [00:24:04]:
So think of situations where there was a traditional command and control IT department where everything would go through them and business will come with a requirement and now more than ever, two things are happening. One is IT is becoming the DNA of all business functions. Second, there is a huge shift towards allowing business the autonomy to build their own apps and basically go ahead and run with the business. Now, with that shifting landscape, the plumbing, if you will, that existed earlier where you could intercept and say, okay, before anything is rolled out, I would want to have a set of checklists or you would shift left and embed yourself in that environment or in that process so that you become a risk aware and risk first approach to anything and everything was built and you had a process but now you are almost allowing a wild west to the business leaders who would want to spit out apps on a daily basis and they want to go agile and they want to experiment and do all of that in such an environment where agility, so one is growth, which is more of an outcome, but agility is more of a mindset which is to be embraced on a daily basis for you to achieve what you want to achieve but within that agility are you able to inject, embed risk management in such a way where people are still coming to you for approvals and still agreeing to what you want them to do

Sanjog Aul [00:25:38]:
and even if you’re not watching over their shoulder, they still are taking responsibility that at no point, whatever applications they create, whatever data that they start using or whatever way they are using technology or business assumptions, it is not crossing the line. Is management reasonably possible when you are shifting or giving autonomy to the business leaders who want to do things at a drop of a hat?

Dr. Ramesh Gopal [00:26:08]:
I think that is where the world is headed to. I would put it this way like usually what we say about leadership, success of a leader lies in how many leaders he builds, not in he showing his leadership and treating others as subordinates. Risk management over a period of time has basically evolved and is where it is not it evolved, it is evolving on this philosophy. Meaning the success of a risk manager lies in how many risk managers he creates downstream and upstream as well as horizontally and not just treating himself as the only risk manager who will control the entire situation, keep all the decisions close to his chest and then take the pride that I’m responsible for the best decisions in this institution. So we are emerging into a world where we are creating multiple lines of defense. The first line of difference is where the business units come there.

Dr. Ramesh Gopal [00:27:20]:
So we are basically trying to create and train as many risk managers as possible because at the end of the day, the responsibility of risk management is not that you should be the sole authority handling risk, but handle risk for the institution in a way where the risk can be implemented proactively and at the root, where it gets onboarded into an institution and what’s better than guiding, directing and helping the business guys who onboard the risk at the first moment of truth for an institution, guiding them on risk and allowing them and enabling and facilitating them, rather empowering them to handle risk and take the right risk decisions. You’re always there if something goes wrong. You’re always there to see if that empowerment, if that delegation to the first line of defense is operating well or not. So it’s the question of are you okay with the decentralized risk managed handling approach or do you still want a centralized control approach? As a risk professional, I will opt for the first one, which is a decentralized risk handling and risk management always works better for any institution which is more concerned about risk handling from the root all the way to the top and not just centralizing it at one node within an organization to show the power that we are risk management. So that would be my preference.

Dr. Ramesh Gopal [00:29:11]:
Delegate risk management to different levels. You should not have just one risk manager or one risk management unit. It should be a culture in an organization that people think as if they are risk managers in whichever profile they are. Then risk management unit becomes a mere facilitating unit and overseeing unit. This is where we need to migrate. If we need to take risk management to the next level with the help of empowerment, with the help of technology that is coming in, in today’s world.

Sanjog Aul [00:29:54]:
See, wouldn’t that be beautiful if the business and IT leaders embrace the risk management principles and almost a mindset of a risk manager? I want you to keep your job, but at the same time, I don’t want it to make it more difficult where you have this constant tussle. Have you attempted bringing that sentiment? Besides of course educating them within them as leaders so that they start thinking and acting like risk managers as well and what are on the ground challenges that you saw when you attempted, if you attempted, and what were the ways you were able to get them to think in that manner so that they help you help them.

Dr. Ramesh Gopal [00:30:41]:
We have attempted not just in my current profile, but in the previous institutions that I have been there. Two common things that we have faced as a problem. First is resistance to change. Why should I do your role? To explain to people that it’s not just my role taking on the risk hat is a part of everyone’s role that becomes a challenging task. So this concept of decentralized risk management faces an issue on the resistance to change and people questioning on the roles and responsibility if that is falling between the cracks or if it is actually being relegated rather than delegated. So that’s the first issue that has been faced in terms of resistance to change. Then comes, even if you tackle the resistance to change, the extent of understanding of risk we have understood it’s not everyone’s cup of tea. It still remains a very specialized zone which interests only a section of people.

Dr. Ramesh Gopal [00:32:05]:
So to expect that everyone should know risk, risk handling, risk identification and risk management the way a specialized risk department should know, I think that seems to be still a far reach because if that is the system we want to see across organizations, it needs to start right from recruitment policies wherein we recruit people with a flare to handle risk, to identify risk if they are expected to do that but to recruit people based on their core job which is running a specific department like technology or business or finance and to expect them to have a risk mindset gets difficult because it is not in everyone’s skill set to handle it or not everyone’s interest, even if you have skill set, even if you have the ability, you should have the willingness. You may have willingness, but you may not have the ability. So we have seen both lacking in certain cases. So these are the two main problems. Resistance to change and the interest to identify and handle even if you’re expected to handle. So it has been tried, it has been successful in few pockets

Dr. Ramesh Gopal [00:33:24]:
but where it has not been successful, these are the issues that we have faced.

Sanjog Aul [00:33:29]:
So see when IT became mainstream, so even the business functions, the job descriptions and the KRAs and KPIs which HR and organizational design folks had put together, they actually embedded those things as responsibilities and things that they have to bring and or have to develop. Do you think the risk management function has been able to exert influence on these HR and organizational folks and the executive management so that any people who come from different functions, including IT, they get risk management related education, the adoption and evangelism as part of their KPIs and KRAs has that been attempted if at all, then what happened as a result of that because people only behave based on what’s in it for me and what am I measured on?

Dr. Ramesh Gopal [00:34:22]:
That’s right. Honestly speaking, I have not attempted this, number one, I haven’t come across many people who have tried to attempt this because that becomes too much of a requirement that risk management should be a part of KRAs or KPIs of every other division within an organization and honestly, if you ask me, if we get to that level of detail to bring in risk management across the unit as a culture, then that might face resistance and the idea may actually fade away. So probably we need to take it in faces to bring in people on board, try to see who is interested and then probably train them on it rather than making it a KRI for them. Then it will be too much demanding and there might be resistance. I’ve not seen this widely happening and I don’t think implementing this would be that easy a task in today’s world.

Sanjog Aul [00:35:28]:
So let’s take today’s scenario, the way the speed is speed of change in all different dimensions, financial, the fiscal policies around the globe, the trade wars, et cetera and then of course the technology innovation. If you had to give a blueprint or if some form of a vision around how risk management should morph to accommodate not only what’s happened till now, but in the next three months, six months, one year, two year, how would you have defined the blueprint and if this was a book, what chapters would you put in there?

Dr. Ramesh Gopal [00:36:08]:
First chapter is understanding risk. Many people fail in even knowing what we are talking about when we talk about risk. The second chapter would be differentiating and similarizing risk. What do I mean when I say this? Risk is different 100%, but at the same time. Risk exists everywhere. It is omnipresent, it is perennial. You need to establish the similarities of what you understand about risk and what exists in what you’re doing. That’s very important.

Dr. Ramesh Gopal [00:36:58]:
Sometimes we know what risk is, but we don’t identify that, “Oh yes, I am sitting on a risky proposition”, that’s because one is knowing something and the other is able to identify it when it actually matters. So the second chapter would be how do you differentiate risk from what you’re doing at the same time, how do you establish a similarity of what you’re doing and what risk is all about. The third chapter that I would rather put here is collaborative risk, ERM, or enterprise risk management is no more a new word, it’s no more a buzzword. This has been there for long, at least in well established institutions. That’s because they take a holistic approach of all the risk. I would go one step further. Instead of a risk division, taking a holistic approach of multiple risk factors and propositions in an organization, bring in something called a collaborative risk.

Dr. Ramesh Gopal [00:38:06]:
Bring in technology, bring in finance, bring in HR, bring in business, bring in other units also, if you want. Let’s put our heads together, define what risk means to each and everyone, and try to handle that intersecting collaborative risk that we all need to handle. Yes, that intersection may not take care of other risks that are there in the peripheral. Leave that to the specialized risk management. Let them handle it what comes within the collaborative sandbox. Let’s handle it together. What doesn’t come within that intersection. Leave it to the specialized departments to handle that and I believe in reading short books if I’m going to author, author a short book.

Dr. Ramesh Gopal [00:38:55]:
So my last chapter would be the fourth chapter, not beyond that and that would be without fail, telling people, how do you come back if you fail to identify, handle, manage or monitor the risk that has been discussed in the first three chapters because if you don’t fail, you’re not a risk manager. You will fail someday, somewhere, some form or shape, it may not be called a failure, but you will know that you could have done better. If something like that happens, how do you get back to track? How do you ensure you don’t repeat that mistake which you have identified for yourself? So that would be the fourth chapter because if you’re talking about risk management, never ever be in a utopian world that you will be right all the time. You might go wrong, but till such time the probability of you going wrong doesn’t exceed 0.1 or 0.2. I think you are still on the right track.

Dr. Ramesh Gopal [00:40:00]:
So these would be my four chapters in the book that I would rather prescribe for the scenario that you mentioned.

Sanjog Aul [00:40:10]:
If you had to appeal to the business and technology leaders around the world because this show reaches globally, what would be your appeal? Given the context that they are dealing with today, the different variety, the new more or different risks that they are likely to encounter.

Dr. Ramesh Gopal [00:40:30]:
Multiple risk propositions prevail in today’s world. My appeal to them will be do not underestimate the risk that underlines your business or it can be any other business. What’s the common mistake people commit in today’s world is they question preventative controls. Why should I be doing this when nothing has happened till date? Why are you restricting us on a simulated scenario which has not happened, which has not manifested at all. My appeal to such thinkers, whoever is thinking that way, would be understand the risk mindset is like the security guards in your community. You don’t remove them or do away with them just because there has been no theft for one full year.

Dr. Ramesh Gopal [00:41:45]:
It is because they were there, there were no thefts for that one full year that you have analyzed. Risk management and risk managers are exactly like those security guards in your community. So the appeal to technology or any other business leader would be treat risk the right way so that you view them in the right perspective. Whether it be a centralized risk function or a decentralized risk function. You need to understand the importance of what you are doing and why you’re doing in managing and treating risk like the security guards of that community. With this appeal, what I intend is when you think of this function in the right perspective, you will definitely minimize the losses or the accidents in your respective areas and for your institution as a whole.

Sanjog Aul [00:42:56]:
One last question is for you that if you had to fix one thing in you which will help you become better, more equipped, more capable risk leader, risk manager and risk leader for the times that are ahead of us, what would be that one thing that you would work on?

Dr. Ramesh Gopal [00:43:16]:
Road to improvement in the area in which I am is a continuous path. So there are multiple things, but rather I would want to sharpen my skills in what I call is G square-R square. What’s G square, that’s basically good growth. What’s R square, that’s basically the right risk. A successful finance person is one who knows how to identify good growth and the right risk. Good growth is basically one which has no shortcuts, comes organically, and helps you build a sustainable and a resilient model for your institution. It’s like it’s so tempting for a bodybuilder to take an injection and build muscles

Dr. Ramesh Gopal [00:44:09]:
but we all know that’s not the right way. Although it’s tempting exactly the same way. An institution should not be attracted by tempting shortcuts, rather go the right way to grow. So I want to sharpen the skills in identifying good growth. People might ask, is it so difficult? Let me tell you, it’s extremely difficult. Right risk, what’s right risk, I would put it technically saying where the probability of occurrence is low and the intensity of impact is slow, if it were to occur but let me simplify that to say you cannot run away from risk. Risk has to be taken. If there is no risk, there is no business.

Dr. Ramesh Gopal [00:44:58]:
So take such risk which will basically enable growth. At the same time bring in caution within the business. The technical definition of right risk I already gave you. So for those who want to remember that, that can also be the case. I again want to sharpen my skills in identifying the right risk so that I need to run away from risk nor aggressively onboard risk either into my personal life or professional life or into the institution’s books. If I can succeed in sharpening these two skills going forward, I think that would make me a much better holistic risk professional, finance professional, and more than anything else, an informed professional in the days to come.

Sanjog Aul [00:45:53]:
That is so beautifully said Ramesh, that you are looking at yourself to make yourself a better person. It’s a great message for all the risk managers and I think the same philosophy and same approach could be even utilized by the IT and the business leaders because they in a way can embrace the same mindset and help the organizations grow and also grow themselves as a leader. So thank you so much for taking the time Ramesh and talk about this interesting subject where the good leaders, the great leaders, how are they leveraging risk to build something that lasts and also faces the test like it is testing, the times are testing and it really becomes a resilient organization and a growth driven organization. So thank you so much again.

Dr. Ramesh Gopal [00:46:37]:
You’re welcome. It was my pleasure being part of this show.

Sanjog Aul [00:46:41]:
Absolutely and our audience around the globe, I hope you got some nuggets. Please come to our YouTube channel, subscribe to our podcast. This is Sanjog Aul your host signing off. Till next time, take care and god bless.

Contributors

Ramesh Gopal

Ramesh Gopal, Chief Risk Officer & Head of Credit, Deutsche Bank

Dr. Ramesh Gopal is an accomplished banking professional with over 23 years of experience in risk management and relationship management across corporate, sovereign, structured financing, investment, and retail banking, spanning both conven... More   View all posts

Advertisement

AVI-SPL-Service Banner-MPU-300x250
Ramesh Gopal