
Vinay R. Singh
Chief Risk Officer
Vinay R. Singh serves as the Chief Risk Officer and is a Chartered Accountant (ICAI), Chartered Wealth Manager and B.Com graduate. He brings experience across multiple investment platforms and investment strategies with expertise in investment risk, regulatory risk, portfolio monitoring and control frameworks. As CRO, he leads the implementation and governance of the Risk Management Framework across the AMC and mutual fund schemes. His responsibilities encompass identification, assessment and monitoring of AMC- and scheme-level risks, investment, credit and liquidity risk management, stress testing, early-warning mechanisms, risk appetite and tolerance limits, RCSA and risk reporting. He also oversees third-party risk, fraud and incident risk frameworks and corrective-action monitoring, and provides independent risk oversight and reporting to senior management, risk committees, the Board and Trustees.
Roles and Responsibilities for Risk Management
- Ensure all risk related policies are defined, reviewed, and updated periodically and placed at the relevant risk management committee for approval.
- Responsible for implementation and governance of Risk Management Framework (“RMF”) across Asset Management Company (“AMC”) and Mutual Fund Schemes.
- Responsible for overall risk management related activities of the AMC and Mutual Fund Schemes.
- Establishing an organization wide risk conscious culture.
- Formulate and implement structured reporting process for risk monitoring and reporting to CEO, Risk Committees and Board of AMC and Trustee.
- Monitor and ensure adherence and compliance to RMF across AMC and Mutual Fund Operations.
- Define and delegate roles to key personnel within the risk function for identifying, monitoring and reporting risks.
- Put in place adequate numbers of appropriately trained personnel to discharge risk management responsibilities in line with the SEBI RMF Framework.
- Perform periodic review and update the RMF defined by the AMC and place the same to the Risk Management Committee (“RMC”) for approval.
- Formulate and recommend changes to roles and responsibilities including KRAs relating to risk management activities and place these at the RMCs for approval.
- Formulate, design & review the Third-Party Risk management Framework. The Framework will include aspects for evaluating risk, control robustness and regulatory compliance obligations of third party service providers.
- Periodically review the DoP covering the following: daily risk management; daily risk reporting; corrective actions at the level of Fund manager, CIO and CEO.
- Review and suggest changes to the risk appetite and risk metrics for AMC and scheme as defined by the CEO.
- Ensure formulation and implementation of adequate mechanism for: generating early warning signals; conducting stress testing for investment, credit and liquidity risks basis approved parameters; defining the tolerance limits for each of the risk parameters; measurement and review of AMC and scheme specific risks including RCSA and the person responsible to monitor the risks; assessment and review of credit risk policies; assessing liquidity risk at a scheme level; alerts pertaining to asset liability mismatch; formulation of Fraud Risk Registers and Frauds response plan / strategies; escalation matrix for reporting and resolution of incidents (loss, near miss, fraud etc.); review of operations for material outsourced activities at least on an annual basis; adequate framework to detect and prevent security market violation, frauds and malpractices by the AMC and reporting framework on the same to the ERMC and board Trustee on half yearly basis.
- Review and report the following to the ERMC and Board Risk Committee of AMC and Trustee: risk reports and dashboards capturing deviations to risk thresholds, risk appetite across AMC and Scheme; results of monitoring of early warning signals by respective functions; result of stress testing based on defined parameters for investment, credit and liquidity risks, etc.; internal and external fraud incidents reported / identified by CXOs including evaluation of fraud risk scenarios; near miss and loss incidents identified and reported by the respective departments; liquidity risk including asset liability mismatch at a scheme and portfolio level vis-à-vis internally approved and defined liquidity model on a monthly basis; major findings and corrective actions prepared by the CXOs; delays in implementation of corrective actions by CXOs; control breaches as a result of periodic RCSA review and mitigating actions put in place by the management and risk function.
- Independently assess reporting of risks to various committees and CEO.
- Ensure insurance cover is maintained based on AMC and Trustee approval for the MF operations and third-party losses.
- Report outcomes of the risk management function to the management at least once a month.
- Review and provide opinion on the investment limit setup such as minimum number of stocks/securities, cash (net of derivatives), stocks/securities vis-a-vis benchmark and Beta range, regulatory limits.
- Define process to assess the control against each of the identified risk capturing following elements: measurement tool for each risk (RCSA, Stress Testing etc.); monitoring and reporting frequency; reporting of breaches.
- Identify, assess and estimate emerging risks and their possible impact on AMC and mutual fund schemes.
- Report existing and emerging risks associated with the MF and AMC activities in a structured manner to the Board Risk Management Committee of the AMC and Trustee.
Data Privacy and DPDPA Compliance
- Ensure compliance with the Digital Personal Data Protection Act (DPDPA), 2023 - personal data mapping, implementation of technical and organizational data protection measures, management of Data Principal rights (access, correction, erasure) within defined timelines and notification of personal data breaches to the Data Protection Board within prescribed timelines.
- Coordinate with the CCO & Legal on regulatory compliance obligations under the DPDPA.
- Coordinate with the Chief Information Security Officer (CISO) and oversee compliance with data protection and data security obligations under the Digital Personal Data Protection Act (DPDPA).
Key Result Areas (KRAs) for Risk Management
- Adherence to the requirements of SEBI risk management circular
- Timely reporting of the results from monitoring of AMC and scheme specific risks such as: RCSA testing; stress testing; monitoring risk thresholds and risk appetite; monitoring of investment and liquidity risks; monitoring of EWS by functions
- Monitor and timely report implementation status of the actions plan committed by the respective functions/ CXOs and reporting of delays, if any
- Timely reporting of risk events to the ERMC and Board Risk Committees
- Adherence to the defined roles and responsibilities and Delegation of Power (DoP)
- Availability of adequate insurance coverage for MF operations and third-party losses