Overview
I spent eight years in bilateral DFI credit committee sessions before moving to advisory work. The deals that troubled me most were rarely the ones with an obvious red flag—sovereign downgrades, contested expropriation headlines, a contractor bankruptcy in the news. They were the portfolios where each asset looked acceptable in isolation while platform-level concentrations quietly built: municipal payment stress across three availability PPPs, merchant storage exposure creeping above stated fund limits, model assumptions drifting from independent engineer benchmarks without a validation trigger.
That experience shapes how I talk to boards and LP advisory committees about enterprise risk management. ERM is not an annual report checkbox. It is the architecture that connects risk appetite to capital allocation, deal approval, and—crucially—evidence that risk culture matches risk policy.
When I walk into a first meeting
Sponsors often open with org charts showing three lines of defense. I ask for the last example of a deal declined on risk grounds. Silence is common. Not because teams ignore risk, but because frameworks catalogue hazards without influencing decisions. European institutional DDQs now ask explicitly for declined deals. LPACs treat absence of examples as a signal that appetite statements are decorative.
Capital-intensive mandates—sovereign programmes, infrastructure platforms, multi-asset funds—need ERM that aggregates project risk into portfolio view while preserving asset-level granularity. A single underperforming hospital PPP may not breach fund NAV limits; correlated authority fiscal stress across a regional portfolio might.
ERM connects strategic risk (policy shifts, market design changes), financial risk (rates, currency, liquidity, counterparty exposure), operational risk (construction, O&M, cyber, supply chain failure), political and sovereign risk, and ESG and reputational risk. Each category needs distinct metrics, owners, and escalation paths. European regulatory baselines—AIFMD risk management, CSRD reporting expectations, NIS2 for critical infrastructure cyber resilience—raise the floor but do not replace mandate-specific identification.
Risk appetite that committees can use
I push clients to quantify appetite: maximum single-asset concentration, geographic caps by regulatory regime, construction exposure as a percentage of committed capital, leverage ceilings, counterparty limits for offtakers and EPC firms. Heat maps linking pipeline deals to breach thresholds before IC approval are more useful than narrative statements about " prudent risk-taking."
Stress design matters. Correlated scenarios— inflation spike plus regulatory tariff reset, construction delay plus contractor insolvency—surface exposures single-factor sensitivities miss. In a recent fund review, a combined public-sector payment deferral scenario across four assets drove aggregate DSCR below policy limits even though no single asset tripped covenants. The platform had no KRI watching correlated municipal stress; it watched asset-level coverage only.
Typical infrastructure fund limits I see in institutional mandates include 10–15% single-asset NAV concentration at commitment, geographic caps, and construction exposure limits with documented board approval for breaches.
Risk identification workshops populate mandate-specific taxonomies—not generic banking templates—with pre-construction development, construction completion, operational performance, revenue and counterparty credit, refinancing and exit liquidity, regulatory and state aid exposure, and ESG and community risk. Each entry should assign likelihood, impact, velocity, owner, and mitigant status, mapped to IC memo sections so diligence feeds portfolio aggregation instead of living in disconnected spreadsheets.
Three lines of defense in mid-sized platforms
First line: project managers, operators, deal teams own day-to-day controls.
Second line: risk and compliance sets policy, challenges models, conducts independent reviews. LPACs often require evidence this function is independent of fee-generating teams—a recurring pain point for European GPs scaling institutional capital.
Third line: internal audit validates effectiveness; external audit adds market credibility.
Project platforms holding multiple PPP or renewable assets need roll-up methodology with documented correlation assumptions. ESG incidents—biodiversity enforcement, labour disputes, greenwashing investigations—belong on the same dashboard as financial KRIs, not in parallel sustainability reports. SFDR and taxonomy compliance failures can trigger redemption rights or mandate ineligibility; escalation protocols should give ESG leads equal authority to financial risk committees where DFIs co-invest.
KRIs I actually calibrate
Key risk indicators only work with threshold discipline. Too sensitive creates alert fatigue; too lax misses renegotiation windows. Examples from mandates we support:
- DSCR deterioration beyond covenant headroom at asset level
- Permitting milestone slippage exceeding defined days
- ESG grievance escalation rates against safeguard policies
- Counterparty rating downgrades for offtakers or guarantors
- Model assumption drift versus independent engineer updates
- Cyber severity scores for operational technology on grid and digital assets
Second-line functions should review thresholds annually and after major portfolio events. NIS2 and sector standards raise baseline cyber expectations for critical infrastructure; business continuity testing should cover capital calls, NAV reporting, and asset monitoring under disruption.
Model risk is credit risk
Infrastructure and energy mandates live inside financial models, dispatch simulations, and lifecycle cost projections. Frameworks should specify ownership, change control, independent validation frequency (annual for IC-grade models), assumption standards aligned with model audit scope, and version control linking IC approval to specific iterations.
Committees lose confidence when post-close performance diverges from approved models without documented assumption updates. I treat model validation policy as part of ERM maturity scoring alongside legal diligence completeness.
Reporting LPACs read versus boards skim
Quarterly risk packs should include KRI trends, open mitigation actions, incident logs, model validation status, and ESG incident summaries. Digital dashboards accelerate review but must reconcile to audited financial statements. ILPA-style transparency on fees and conflicts aligns with risk incident disclosure across the LP base.
Development finance partners may require social grievance tracking beyond commercial LP norms. Bilingual reporting helps when DACH pension allocators sit alongside international co-investors on the same LPAC.
Integrating ERM with IC workflow
Deal approval should embed checkpoints: pipeline screening against appetite, pre-IC risk register review, post-close KRI baseline establishment, annual portfolio re-underwriting. DFIs sometimes require ERM evidence before anchor commitment—particularly where safeguard and PCM reporting depend on platform controls, not single-asset diligence alone.
Credit enhancement decisions must appear in the risk register with guarantor credit assessment. Guarantees transfer counterparty risk; they do not eliminate it from scenario analysis. Double-counting mitigants in stress tests is a common modelling error I flag in committee prep.
For debt and hybrid strategies, ERM must capture covenant risk across loans and bonds—not only equity asset operations. AIFMD liquidity rules apply stress to redemption scenarios even in closed-end structures when subscription lines or warehoused assets create interim exposure.
Board risk committees should receive standing ERM reports with decision-grade summaries, not data dumps. LPACs reviewing conflicts and valuations need context on whether risk concentration drove valuation disputes or fee-generating affiliated transactions. Munich-based managers serving DACH institutional LPs face detailed DDQ scrutiny on valuation policy, conflicts management, and business continuity—ERM documentation should anticipate those questions at first close, not at year-three LPAC review.
Fund managers should document risk culture through compensation design, deal team authority limits, and post-mortem reviews of exited or impaired assets. Integration with internal audit plans ensures third-line validation of second-line effectiveness at least annually.
ERM maturity belongs in annual LP reports through risk incident summaries, KRI trends, and appetite breach disclosures—not only in private board packs. Where DFIs co-invest, safeguard compliance gaps may constitute credit events under finance documents; platform-level control maturity matters as much as single-asset diligence.
What changed my mind about "ERM projects"
Implementing a baseline framework typically takes six to twelve months for first-time fund managers; refinement continues indefinitely. ERM does not replace project-level diligence—it enforces consistency and aggregation. Minimum viable maturity at first close, in my experience, includes numeric appetite limits, an independent second line, quarterly KRI reporting, and published model validation policy.
External advisors can support model validation and specialist reviews. LPACs still expect in-house accountability as AUM scales.
AIFMD mandates risk management functions for authorised managers; ERM in the sense institutional LPs expect extends beyond regulatory minimums to portfolio aggregation, LP reporting consistency, and evidence that risk appetite influenced at least one negative investment decision in the last cycle. That evidence is awkward to manufacture retrospectively—which is why I ask for it in the first meeting.
Cyber resilience for digital infrastructure, grid control systems, and financial services mandates belongs in ERM registers with incident playbooks and third-party vendor tiering for administrators and custodians. Concentration in a single depositary or administrator triggers LPAC questions under AIFMD operational requirements.
I left credit committee work because I wanted to help sponsors build systems that surface correlated stress before defaults—not after headlines. ERM maturity is increasingly a gating factor for institutional capital and DFI anchors alike. The frameworks that satisfy me are boring on paper: limits, owners, thresholds, and evidence that someone said no when appetite was breached.
Disclaimer: Commentary only. This article reflects observed market practice and advisory experience from Consultinghouse GWB; it is not legal, tax, or investment advice. Readers should obtain independent professional counsel before acting on any structure described.



