
UOB (Malaysia) is a subsidiary of UOB, a leading bank in Asia with a global network.
Find out more
At UOB, we believe that art transcends language, culture, geographies and time.
Find out more
Tap on our strategic ecosystem partnerships to thrive in today's digital economy.
Find out moreyou are in Stakeholder Relations
Managing risks, increasing enterprise value
A strong risk culture is vital to the long-term sustainability of the Bank’s business franchise. Specifically, risk culture refers to the norms, attitudes and behaviours related to risk awareness, risk-taking and risk management, and controls that shape decisions on risks*. Our risk culture is based on our values. A strong risk culture ensures that our decisions and actions are considered and focused on our stakeholders, and that we are not distracted by short-term gains.
* Basel Committee on Banking Supervision: Guidelines on Corporate Governance Principles for Banks (July 2015)
UOBM’s Risk Culture Statement
Managing risk is integral to how we create long-term value for our customers and other stakeholders. Our risk culture is built on four principles: enforcing robust risk governance; balancing growth with stability; ensuring accountability for all the risk-based decisions and actions; and encouraging awareness, engagement and consistent behaviour in every employee. Each of these principles is based on our distinctive set of values that guides every action we take. In entrenching our risk culture further across our franchise, we uphold the commitment to financial safety and soundness; fair outcomes and appropriate support for our stakeholders; sustainable and prudent business approach; and performance based on integrity, ethics and discipline.

Our risk frameworks, policies and appetite provide the principles and guidance for the Bank’s risk management activities. They guide our key decisions for capital management, strategic planning and budgeting, and performance management to ensure that the risk dimension is appropriately and adequately considered. Risk reports are submitted regularly to senior management committees and the Board to keep them apprised of the Bank's risk profile.
Responsibility for risk management starts with Board oversight of the Bank's governance structure, which ensures that the Bank’s business activities are:
The Board is assisted primarily by the Risk Management Committee (RMC) on risk-related matters, including reviewing the overall risk appetite and level of risk capital to be maintained for the Bank.
Our Chief Executive Officer (CEO) has established senior management committees to assist her in making business decisions with due consideration for risks and returns. The main senior management committees involved in specific risk-related matters are the Executive Committee (EXCO), Asset and Liability Committee (ALCO), Management Committee (MC), In-Country Credit Committee (ICCC), Credit Management Committee (CMC), Operational Risk Management Committee (ORMC), Information & Technology Committee (ITC), Risk and Capital Committee (RCC) and Anti-Financial Crime Committee (AFCC). These committees also assist the Board committees.
Management and the senior management committees are authorised to delegate risk appetite limits by location, business units and/or broad product lines.
Risk management is the responsibility of every employee in the Bank. We strive to instil awareness of the risks created by their actions and the accountability for the consequences of those actions in our employees. We have established frameworks and policies to ensure appropriate oversight, accountability and management of all risk types encountered in the course of our business. The Bank adopts and adapts the parent bank's risk management governance structure, frameworks and policies to comply with local regulatory requirements. This ensures that the approach across the Group is consistent and sufficiently adaptable to suit local operating environments.
Our organisational control structure is based on the Three Lines Model as follows:

The business and support units own and have primary responsibility for implementing and executing effective controls to manage the risks arising from their business activities. This includes establishing adequate managerial and supervisory controls to ensure compliance with risk policies, appetite, limits and controls and highlight control breakdowns, inadequacy of processes and unexpected risk events.
The risk and control oversight functions (i.e. Risk Management and Compliance) and the Chief Risk Officer and Country Head of Compliance, as the Second Line, support the Bank's strategy of balancing growth with stability by establishing risk frameworks, policies, appetite and limits which the business functions must adhere to and comply with in their operations. They are also responsible for the independent review and monitoring of the Bank's risk profile and for highlighting any significant vulnerabilities and risk issues to the respective senior management committees. The independence of risk and control oversight functions from business functions ensures that the necessary checks and balances are in place.
Internal auditors conduct risk-based audits covering all aspects of the First and Second lines to provide independent assurance to the CEO, Shariah Committee, Audit Committee and the Board on the adequacy and effectiveness of our system of risk management and internal controls. The internal auditor's overall opinion of the internal controls and risk management system is provided to the AC and the Board annually.
Our risk appetite framework defines the amount of risk we are able and willing to take in the pursuit of our business objectives. It ensures that the Bank’s risk profile remains within well-defined and tolerable boundaries. The framework has been formulated based on the following key criteria:
Our risk appetite defines suitable thresholds and limits across the key risk areas including credit risk, country risk, market risk, liquidity risk, operational risk, and conduct risk. Our risk-taking approach is focused on businesses which we understand and whose risks we are well-equipped to manage. This approach helps us to minimise earnings volatility and ensures that our high credit ratings, strong capital and stable funding base remain intact. This enables us to remain a steadfast partner to our customers through changing economic conditions and cycles.
Our risk appetite framework and risk appetite are reviewed and approved annually by the Board. Management monitors and reports the Bank's risk profiles and compliance with the established risk appetite to the Board on a regular basis.
Our business strategies, products, customer profiles and operating environment expose us to a number of financial and non-financial risks. Identifying and monitoring key risks are integral to the Bank’s approach to risk management, enabling us to make effective assessments of these risks and mitigate them proactively across the Bank. The table below summarises the key risks that could impact the achievement of the Bank’s strategic objectives. Details of these key risks can be found in the pages that follow.
| Material Risk | Definition | How risk is managed |
| Credit risk | The risk of loss arising from failure by a borrower or counterparty to meet its financial obligations when they are due. | Through our credit risk management framework, policies, models and limits. |
| Market risk | The risk of loss from movements in the market rates or prices (such as changes in interest rates, foreign exchange rates, equity prices, commodity prices and credit spreads) of the underlying asset. It includes interest rate risk in the banking book (IRRBB) which is the potential loss of capital or reduction in earnings due to changes in the interest rates environment. | Through our market risk management framework, policies, Value-at-Risk (VaR) models and limits. IRRBB is managed through the Bank’s balance sheet risk management framework and interest rate risk in the banking book management policies and limits. |
| Liquidity risk | The risk that arises from our inability to meet our obligations, or to fund increases in assets as they fall due. | Through our balance sheet risk management framework, liquidity risk management policies, ratios and limits. |
| Operational risk | The risk of loss resulting from inadequate or failed internal processes, people and systems or from external events. Such loss may be in the form of financial loss or other damage, for example, loss of reputation and public confidence that will impact our creditability and/or ability to transact, to maintain liquidity and/or obtain new business. Operational risk includes banking operations risk, fraud risk, legal risk, regulatory compliance risk, Shariah non-compliance (SNC) risk, reputational risk, third-party and outsourcing risk, and technology risk but excludes strategic and business risk. | Through the respective risk management frameworks, policies and operational risk management programmes, including Key Risk and Control Self-assessments, Key Operational Risk Indicators, Incident Reporting, Management Risk Awareness, Outsourcing Risk Assessment, Third-Party Non-outsourcing Risk Assessment, Product Programme and Scenario Analysis. |
| Conduct Risk | The risk of improper employee behaviour or action that results in unfair stakeholder outcomes, negative impact on market integrity and other issues that damage the reputation of the Bank. | Through a multi-faceted approach leveraging the frameworks, policies and procedures on operational risk management, whistle-blowing, employee discipline, individual accountability, code of conduct, remuneration, fair dealing and anti-financial crime. |
| Financial Crime risk | Financial crime risk is defined as the risk of regulatory sanctions, financial loss, or damage to the Bank’s reputation and franchise value that may arise when the Bank fails to comply with anti-financial crime laws, regulations, rules, standards, or codes of conduct (established by industry associations) that are applicable to the Bank’s business activities and operations. Financial crime risk types include money laundering, terrorism financing, internal fraud, mules and scams, bribery and corruption, and all other illegal or unethical dealings. | Through our financial crime risk management framework, policies, procedures and management tolerance. |
| Strategic and Business risks | Strategic risk refers to the current or prospective negative impact on earnings, capital or reputation arising from adverse strategic decisions, improper implementation of decisions or a lack of responsiveness to industry, economic or technological changes. Business risk refers to the adverse impact on earnings or capital arising from changes in business parameters such as volume, margin and cost. | Through our strategic and business risk management policy. |
| Model risk | The risk arising from: • the use of an inappropriate model that is unable to accurately evaluate market prices or that is not a mainstream model in the market (such as pricing models); or • inaccurately estimating the probability or magnitude of future losses (such as risk measurement models) and the use of those estimates. |
Through our model risk governance framework and managed under the respective material risk types for which there is a quantitative model. |
| Environmental, Social and Governance (ESG) risk | ESG risk refers to both financial risks (i.e., credit risk, market risk and liquidity risk) and non-financial risks (e.g., operational risk and reputational damage) arising from ESG issues, including climate change. While a key component of ESG risk arises indirectly from the financial services we provide to our customers, it can also result directly from our own operations. | The different aspects of ESG risk are managed through relevant frameworks, policies and guidelines, including our Environmental Risk Management Framework and Responsible Financing Policy. |
| Material Risk |
| Credit risk |
| Market risk |
| Liquidity risk |
| Operational risk |
| Conduct Risk |
| Financial Crime risk |
| Strategic and Business risks |
| Model risk |
| Environmental, Social and Governance (ESG) risk |
We use cookies in order to provide you with better services on our website. By continuing to browse the site, you agree to our privacy notice and cookie policy.