Boards
role in risk oversight
We believe that risk oversight responsibility rests with the full Board of Directors. Therefore, the Board has principal responsibility
for oversight of the companys risk management processes and for understanding the overall risk profile of the company. Though Board committees routinely address specific risks and risk processes within their purview, the Board has not
delegated primary risk oversight responsibility to a committee.
The company has in place an enterprise risk management committee consisting of executive and senior
management. The committee meets regularly and maintains dialogue with the Board of Directors regarding the top risks of the company and mitigating actions to address them. By receiving quarterly reports, the Board maintains a practical understanding
of the risk philosophy and risk appetite of the company.
In addition, since the company is externally managed, we also rely upon the operational and investment risk
oversight functions of our manager and its affiliates. Invescos risk management framework provides the basis for consistent and meaningful risk dialogue. Our managers global performance and risk committee oversees the management of core
investment risks, while our managers enterprise risk management committee oversees the management of all other business and strategic related risks. A network of regional, business unit and specific risk management committees, under the
guidance and standards of the enterprise risk management committee, provides ongoing identification, assessment, management and monitoring of risks that provides a bottom-up perspective on the specific risk areas existing in various domains of our
managers business.
Oversight of technology and cyber security risk: The Global Security Oversight Committee, one of our managers risk management
committees, provides executive level oversight and monitoring of the end-to-end programs dedicated to managing information security and cyber related risk. Important to these programs is our managers investment in threat-intelligence, its
active engagement in industry and government security-related forums and its utilization of external experts to challenge our managers program maturity, assess its controls and routinely test its capabilities as discussed in more detail below
under Cyber security. Our board receives an annual update on our managers global security program, with a focus on cyber security.
Through this regular
and consistent risk communication, the Board seeks to maintain reasonable assurance that all material risks of the company are being addressed and that the company is fostering a risk-aware culture in which effective risk management is embedded in
the business.
Environmental, social and governance matters
We are primarily focused on
investing in, financing and managing mortgage-backed securities and other mortgage-related assets. These investments provide capital to the housing market and help support home ownership, which can advance the important social impacts of individual
wealth creation and community development.
Our manager believes its workforce should reflect the diversity of people and perspectives of the communities it serves,
and that diversity and inclusion are both moral and business imperatives. Our manager also values corporate stewardship and actively partners with non-profits, start-ups and other organizations to strengthen its communities.
Cyber security
Cyber threats are considered one of the most significant risks
facing financial institutions. To mitigate that risk, our manager and its Invesco affiliates have a designated Global Chief Security Officer and have a global security program that brings together key components of our managers and its Invesco
affiliates security, privacy and business continuity functions. The structure supports a more comprehensive, holistic approach to keeping our managers clients, employees, and critical assets safe, upholding their privacy rights, while
enabling a secure and resilient business.
Our managers and its Invesco affiliates information security program, led by its Chief Information Security
Officer, is designed to oversee, and maintain all aspects of information security risk and seeks to ensure the confidentiality, integrity, and availability of information assets. This includes the implementation of controls aligned with industry
guidelines and applicable statutes and regulations to identify threats, detect attacks and protect these information assets. Our manager and its Invesco affiliates have an incident response program that includes periodic testing and is designed to
restore business operations as quickly and as orderly as possible in the event of a breach or third-party incident. Our manager and its Invesco affiliates conduct mandatory annual employee security awareness training, which focuses on cyber threats
and security in general. Our manager and its Invesco affiliates also conduct regular cyber phishing tests throughout the year to measure and raise employee awareness against cyber phishing threats.