CBA-CRP · sample lesson
Chapter 1 · Free sample
Emerging risk
2 min read
Two things that both feel new, and are not the same
Growing risk
- Already on the register, with an owner and a score
- Getting larger because volumes, channels or products are growing
- Verity's inherent onboarding exposure rose 40% with no control changed
- Handled by the refresh triggers, which is exactly what they are for
Emerging risk
- Not on the register, and cannot yet be scored honestly
- The exposure, the obligation, or both, are not in settled form
- A requirement under consultation, a technology just adopted, a business model just met
- Handled by a watchlist carrying a written promotion rule
Slide 1 of 6. Two things that both feel new, and are not the same
The same lesson, in full
Emerging risk is not the same as growing risk. A growing risk is on the register and getting bigger, and the refresh triggers handle it. An emerging risk is one where the exposure, the obligation, or both, do not yet exist in a settled form: a regime under consultation, a technology the firm has just adopted, a business model the firm has just met, a pattern of enforcement that suggests supervisory attention is moving.
Emerging risks do not belong on the main register, because they will distort it: they cannot be scored honestly, and forcing a score produces either a spurious number or another amber. Keep a watchlist, with four columns and nothing else: what it is, why it might matter to this firm specifically, who owns watching it, and what would have to be true for it to move onto the register. That last column is the discipline. "Promote when the final rules are published" or "promote when we exceed 500 customers in that segment" turns a vague anxiety into a decision rule.
For Verity, a watchlist would reasonably include the following, each described in terms of structure and intent rather than detailed provisions, because the provisions are exactly what is unsettled. The safeguarding regime for payments and e-money firms has been the subject of regulatory consultation aimed at moving it closer in structure to a client assets regime, with stronger record keeping, reconciliation and reporting expectations; whether that has been finalised, and in what form, is precisely the kind of thing you must confirm for yourself rather than take from a textbook. The mandatory reimbursement arrangements for authorised push payment fraud allocate cost between the sending and the receiving firm, which matters for Verity because it supplies accounts to small businesses and therefore carries receiving-side exposure that a purely outbound view of its business would miss entirely. Operational resilience frameworks require firms to identify important business services, set impact tolerances and test their ability to remain within them; Verity's dependence on a single outsourced card processor is squarely in scope. Use of automated decisioning or machine learning in onboarding raises questions of explainability, bias, model governance and, where the firm operates into the EU, the requirements of the EU's AI regime, which applies in phases. And the perimeter question of whether requirements designed for consumers reach a firm's micro-enterprise customers is unsettled enough that it deserves a watchlist row and legal advice rather than an assumption.
Horizon scanning sources worth having, in rough order of signal: the regulator's publications addressed to your sector, including portfolio letters and thematic reviews; enforcement notices, which tell you what the regulator considers unacceptable rather than what it says it wants; consultations, which give you lead time; industry body guidance; peer incidents; and your own complaints and incident data, which is the most underused source of all because it is the only one that describes your firm.
How this fails, and what it costs: watchlists fail by becoming lists, reviewed by nobody, with no promotion rule. The cost is arriving at a new requirement with no lead time, which converts a planned change into a project, and projects at a firm with nine compliance staff consume the monitoring plan. That is how a firm ends up testing nothing for a quarter because everybody was implementing something.
The full contents
Every chapter and lesson of the CBA-CRP study material, with reading times and where the assessed workbooks fall.
