Deutsche Bank

Annual Report 2017

Risk Identification and Assessment

We face a variety of risks as a result of our business activities; these risks include credit risk, market risk, business risk, liquidity risk, operational risk and reputational risk as described in the following sections below. Our risk identification and assessment processes utilize our three lines of defense (3LoD) operating model with the first line identifying the key risks and the second line complementing and aggregating identified risks into our global risk type taxonomy and assessing identified risks for their materiality. Operating processes are in place across the organization to capture relevant measures and indicators. The core aim of all processes is to provide adequate transparency and understanding of existing and emerging risk issues, and to ensure a holistic cross-risk perspective. We update the risk inventory at least once a year or at other times if needed, by running a risk identification and materiality assessment process.

We categorize our material risks into financial risks and non-financial risks. Financial risks comprise credit risk (including default, migration, transaction, settlement, exposure, country, mitigation and concentration risks), market risk (including interest-rate, foreign exchange, equity, credit-spread, commodity and other cross asset risks), liquidity risk and business (strategic) risk. Non-financial risks comprise operational risks and reputational risks (with important sub-categories compliance risk, legal risk, model risk and information security risk captured in our operational risk framework). For all material risks common risk management standards apply including having a dedicated risk management function, defining a risk type specific risk appetite and the decision on the amount of capital to be held.

Credit risk, market risk and operational risk attract regulatory capital. As part of our internal capital adequacy assessment process, we calculate the amount of economic capital for credit, market, operational and business risk to cover risks generated from our business activities taking into account diversification effects across those risk types. Furthermore, our economic capital framework embeds additional risks, e.g. reputational risk and refinancing risk, for which no dedicated economic capital models exist. We exclude liquidity risk from economic capital.