Summary Investment firms and asset managers face a distinctive risk governance challenge: their principal obligation is fiduciary — acting in clients' best interests — while operating in markets where investment outcomes are inherently uncertain. This article sets out a framework that keeps fiduciary duty at the centre while integrating investment, operational and conduct risk.
Fiduciary framing Every governance decision in an asset manager should be traceable to client outcomes. Product design, investment mandates, distribution channels, fees and reporting are all governance surfaces where fiduciary duty is either honoured or eroded. A governance framework that treats fiduciary duty as a compliance topic rather than an organising principle is structurally weak.
Investment risk Investment risk governance covers mandate compliance, risk limits, liquidity of underlying holdings, counterparty exposures, use of derivatives, and stress testing. The second-line risk function should be independent of portfolio management and have the authority to challenge, not merely to report.
Operational risk Operational risk in asset management is concentrated in trade execution, valuation, custody, fund accounting and outsourced services. Errors compound quickly and often affect clients directly. Operational resilience frameworks — increasingly a regulatory expectation — apply here as much as in banking.
Conduct Conduct risk covers product suitability, disclosure quality, distributor oversight, and treatment of vulnerable clients. Product governance frameworks require target market definition, distribution strategy, and outcome monitoring throughout the product lifecycle.
Governance structures A typical structure includes an investment committee (portfolio and mandate decisions), a risk committee (framework, appetite, limit oversight), a product and pricing committee, and a management committee. The board provides ultimate oversight, with the risk function reporting directly on material matters.
CRO and board implications Boards should test whether risk challenge has real weight against investment performance narratives. Independence of the risk function from the front office is the structural precondition.
Practical implementation Documented investment risk framework with independent limits and escalation; operational resilience programme aligned to important business services; product governance framework covering the full lifecycle; conduct MI tied to client outcomes; annual review of governance effectiveness.
Limitations This article does not address specific regulatory regimes (UCITS, AIFMD, MiFID, US Investment Advisers Act, etc.). Application should be confirmed with qualified counsel.
Related reading See [Enterprise Risk](/expertise/enterprise-risk), [Regulatory Compliance](/expertise/regulatory-compliance), [Corporate Governance](/expertise/corporate-governance) and [Financial Risk](/expertise/market-liquidity).
Frequently asked questions
What should risk leaders know about fiduciary framing?
Every governance decision in an asset manager should be traceable to client outcomes. Product design, investment mandates, distribution channels, fees and reporting are all governance surfaces where fiduciary duty is either honoured or eroded. A governance framework that treats fiduciary duty as a compliance topic rather than an organising principle is structurally weak.
What should risk leaders know about investment risk?
Investment risk governance covers mandate compliance, risk limits, liquidity of underlying holdings, counterparty exposures, use of derivatives, and stress testing. The second-line risk function should be independent of portfolio management and have the authority to challenge, not merely to report.
What should risk leaders know about operational risk?
Operational risk in asset management is concentrated in trade execution, valuation, custody, fund accounting and outsourced services. Errors compound quickly and often affect clients directly. Operational resilience frameworks — increasingly a regulatory expectation — apply here as much as in banking.
What should risk leaders know about conduct?
Conduct risk covers product suitability, disclosure quality, distributor oversight, and treatment of vulnerable clients. Product governance frameworks require target market definition, distribution strategy, and outcome monitoring throughout the product lifecycle.
What should risk leaders know about governance structures?
A typical structure includes an investment committee (portfolio and mandate decisions), a risk committee (framework, appetite, limit oversight), a product and pricing committee, and a management committee. The board provides ultimate oversight, with the risk function reporting directly on material matters.