Skip to content
Maxwell PartnersLimited · Consulting

Risk & Governance

Risk understood in layers, decisions made under policy

Sound outcomes depend less on selecting instruments than on understanding dependencies and deciding under a stated policy. Our risk and governance work makes both explicit and reviewable.

Risk framework

Six layers, examined in sequence

Each layer is assessed on its own terms and then in combination, since risks rarely present themselves one at a time.

Layer 01

Market

Price, rate, currency and volatility exposure; sensitivity of the position to changing regimes rather than to single forecasts.

  • Directional exposure
  • Rate and inflation sensitivity
  • Currency mismatch
  • Drawdown scenarios
Layer 02

Liquidity

The ability to realise value when needed, at an acceptable cost, including under stressed market and banking conditions.

  • Liquidity laddering
  • Illiquidity budget
  • Settlement and on/off-ramp reliability
  • Cash buffer adequacy
Layer 03

Counterparty

Dependency on institutions and platforms: banks, brokers, custodians, exchanges, issuers and administrators.

  • Provider concentration
  • Segregation of assets
  • Disclosure quality
  • Substitutability planning
Layer 04

Operational

Process, control and human factors — the most common practical source of loss, particularly in digital assets.

  • Access and authorisation control
  • Dual approval and signing policy
  • Key management and recovery
  • Incident response
Layer 05

Regulatory

Exposure to legal and regulatory change across the jurisdictions relevant to the client, entities and assets held.

  • Jurisdictional mapping
  • Reporting obligations
  • Eligibility and access changes
  • Documentation adequacy
Layer 06

Governance

The decision architecture around the position: who decides, under what policy, with what evidence and what review.

  • Investment policy statement
  • Decision and approval protocols
  • Reporting cadence
  • Periodic review cycle

The framework is an analytical tool for structuring discussion. It does not eliminate risk, predict outcomes or guarantee any result.

Governance practice

From identification to periodic review

Governance is what keeps a framework alive after the first review is filed away.

01

Risk Identification

A structured inventory of exposures across the whole balance sheet, including those that sit outside conventional reporting such as wallets, private commitments and entity-level obligations.
02

Scenario Analysis

Adverse but plausible scenarios examined for their combined effect: a market drawdown occurring alongside a liquidity squeeze, a provider failure or a regulatory change.
03

Investment-Policy Guidance

Support in drafting a written policy that states objectives, permitted exposures, limits, approval thresholds, review triggers and the rationale behind each.
04

Decision Protocols

Clear definition of who may decide what, within which limits, and what evidence must exist before a decision is taken or an exception granted.
05

Reporting Structures

Consolidated reporting design so that exposure, concentration and liquidity can be reviewed consistently across accounts, entities, venues and asset classes.
06

Periodic Review

An agreed review cycle with defined inputs, so frameworks are tested against actual circumstances rather than left to drift.

Concentration and custody

Where losses actually originate

In practice, severe outcomes are rarely caused by a single market move. They emerge from concentration, dependency and procedural failure.

  • Concentration risk: a single position, sector, currency, entity or provider on which too much depends.
  • Liquidity risk: assets that cannot be realised when required, or only at a materially impaired value.
  • Counterparty risk: insolvency, misappropriation or restriction imposed by an institution or platform.
  • Operational risk: authorisation gaps, undocumented procedures, single points of human failure.
  • Custody risk: unclear ownership, inadequate segregation, weak key management or absent recovery planning.

Deliverables

Typical outputs include a written risk map, scenario summaries, a draft investment-policy framework, a counterparty review schedule and an agreed review calendar.

Boundaries

We provide consulting and documentation support. We do not act as auditor, compliance function, legal adviser or regulated risk manager, and we do not certify compliance with any regulatory regime.