0% found this document useful (0 votes)
2 views6 pages

SBL Chapter 15 Notes

The document outlines the principles and techniques of risk measurement, assessment, and management, emphasizing the importance of understanding both the likelihood and impact of risks. It introduces various risk assessment techniques, the role of a Risk Manager, and tools like Risk Registers and Heat Maps for monitoring risks. Additionally, it discusses risk response strategies using the TARA model and the significance of assurance in effective risk management.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views6 pages

SBL Chapter 15 Notes

The document outlines the principles and techniques of risk measurement, assessment, and management, emphasizing the importance of understanding both the likelihood and impact of risks. It introduces various risk assessment techniques, the role of a Risk Manager, and tools like Risk Registers and Heat Maps for monitoring risks. Additionally, it discusses risk response strategies using the TARA model and the significance of assurance in effective risk management.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

SBL Notes Risk Measurement, Assessment Pankaj Khandelwal

Chapter 15 and Management CA, CFA, CIA

What is Risk Assessment?


Risk assessment helps an organisation understand:

• How likely a risk is to occur (Probability/Likelihood).


• How serious its impact or consequences would be.

Risk assessment can use:

• Quantitative methods (numbers and data)


• Qualitative methods (judgement and experience)
• A combination of both

Risk Assessment Techniques

Technique Purpose

Benchmarking Compare with similar organisations or industry standards.

Probabilistic Modelling Uses historical data and statistics (e.g., Value at Risk) to estimate future risks.

Non-Probabilistic Uses judgement, stress tests, sensitivity analysis, and scenario analysis when data is
Modelling limited.

Measuring Risk
Risk is measured using two factors:

1. Impact (Consequences) - Measures how serious the effect would be.

Level Meaning

High Large financial loss, major effect on strategy, high stakeholder concern.

Medium Moderate financial and operational impact.

Low Minor financial and operational impact.

Points to remember:

• Consider both Threats (losses) and Opportunities (gains).


• Use reliable data where available.
• Stakeholder impact should also be considered.
• Some judgement is needed when data is unavailable.

2. Likelihood (Probability) - Measures the chance that the risk will occur.

Level Meaning

High Very likely to happen.

Medium May happen.

Low Unlikely to happen.

The time period (e.g., 1 year, 5 years, 10 years) should also be clearly defined.
SBL Notes Risk Measurement, Assessment Pankaj Khandelwal
Chapter 15 and Management CA, CFA, CIA

Risk Matrix (Likelihood × Impact)


A 2×2 Risk Matrix ranks risks based on their likelihood and impact.

Low Impact High Impact

High Likelihood Monitor & Manage Highest Priority

Low Likelihood Low Priority Monitor & Prepare

Related and Correlated Risks


Risks rarely occur alone. One risk can trigger another, creating a domino effect. Therefore, organisations should
assess how risks are connected, not just individual risks.

1. Related Risks: Two risks are related when the presence of one affects the impact or likelihood of the other.
They should be managed together. (e.g., political instability increases security risk).

2. Correlated Risks: Correlated risks move together.

Type Meaning Example

Both risks increase or decrease Higher environmental risk → Higher reputational


Positive Correlation
together. risk.

One risk increases while the other Borrowing to reduce pollution lowers
Negative Correlation
decreases. environmental risk but increases financial risk.

• The total impact of linked risks can be greater than the sum of individual risks.
• Effective risk management considers individual, related, and correlated risks.

Monitoring Risk
1. Risk Manager

A Risk Manager identifies, assesses, and manages risks to protect the organisation.

Key Responsibilities:

• Identify and assess risks.


• Decide how to avoid, reduce, transfer, or prepare for risks.
• Set the organisation's risk appetite.
• Report risks to management and the board.
• Develop risk management, business continuity, and insurance plans.
• Ensure compliance through audits.
• Train staff to improve risk awareness.

Key Goal: Protect the organisation, its people, assets, reputation, and stakeholders from potential risks.

2. Risk Register

A Risk Register is a document that records and monitors an organisation's key risks. It helps management
understand and control the overall risk profile.
SBL Notes Risk Measurement, Assessment Pankaj Khandelwal
Chapter 15 and Management CA, CFA, CIA

It includes:

• Risk description
• Likelihood and impact (risk score)
• Risk priority/ranking
• Person responsible
• Risk response/control plan
• Date identified
• Related risks

Key Point: A risk register is an important internal control tool used to identify, prioritise, assign ownership, and
monitor risks

Risk Register Scoring Methodology

• Risk Score = Likelihood × Impact


• Likelihood: Rated 1–5 (1 = Very Unlikely, 5 = Very Likely).
• Impact: Rated 1–5 (1 = Low Impact, 5 = Severe Impact). The final risk score ranges from 1 to 25,
where 1 = Very Low Risk and 25 = Very High/Significant Risk.

3. Heat Maps

A Heat Map is a visual tool that shows and prioritises risks based on their Likelihood (Probability) and Impact.

• Uses a colour-coded matrix (green → yellow → red) to highlight risk severity.


• Helps management identify high-priority risks quickly.
• Usually shows Residual Risk-the risk that remains after controls have been implemented.

Key Point: A heat map helps organisations visualise, prioritise, and monitor residual risks also, using a likelihood–
impact matrix

Risk Response
Embedding Risk Awareness

Risk Awareness is understanding the nature, likelihood, and impact of risks in different situations.
SBL Notes Risk Measurement, Assessment Pankaj Khandelwal
Chapter 15 and Management CA, CFA, CIA

Importance

• Risk awareness should exist at all levels, not just management.


• It creates a risk-aware culture.
• This makes risk management:
o Integrated (not fragmented)
o Proactive (not reactive)
o Continuous (not ad hoc)
o Value-focused (not just cost-focused)
o Organisation-wide (not narrowly focused)

How to Embed Risk Awareness

• Provide risk training for all employees.


• Include risk responsibilities in job descriptions and contracts.
• Make risk policies and procedures easily available.
• Hold regular training, workshops, meetings, and communications on risks.

TARA Model
After identifying and assessing risks, organisations choose the best risk response using the TARA model. The
response depends on the likelihood, impact, costs, benefits, and risk appetite.

TARA
When Used Meaning / Example
Response

T – Transfer High Impact, Low


Shift the risk to others (e.g., insurance, outsourcing, hedging, joint ventures).
(Share) Likelihood

High Impact, High Eliminate the risk by stopping or avoiding the activity (stop producing, exit
A – Avoid
Likelihood the market).

Low Impact, High Reduce the likelihood and/or impact using internal controls, monitoring,
R – Reduce
Likelihood diversification, etc (Reducing the production to maintain the demand)

Low Impact, Low Accept the risk if it is within the organisation's risk tolerance or the cost of
A – Accept
Likelihood control exceeds the risk.
SBL Notes Risk Measurement, Assessment Pankaj Khandelwal
Chapter 15 and Management CA, CFA, CIA

Spreading and Diversifying Risk


Organisations can reduce risk by sharing it or spreading it.

1. Insurance (Risk Sharing)

• Risk is shared among many people through insurance premiums.


• The insurance company compensates those who suffer losses.
• This spreads the cost of major losses across all policyholders.

2. Diversification

• Spread investments across different products, markets, or businesses.


• Avoid relying on a single source of income ("Don't put all your eggs in one basket").
• Diversification reduces overall risk, especially when investments are negatively correlated.

Accepting Risk
Accepting Risk means choosing to take no action to avoid, reduce, or transfer a risk because it is considered
acceptable.

When is Risk Accepted?

• The cost of controlling or transferring the risk is higher than the expected loss.
• The potential rewards outweigh the risks.
• The risk cannot be transferred or avoided.

Residual Risk - Residual Risk is the remaining risk after all risk controls have been applied

ALARP Principle
ALARP (As Low As Reasonably Practicable) means reducing risk as much as reasonably possible, considering the
cost, time, and effort involved.

Risk vs. cost, time, and effort

Key Points

• Risk should be reduced until further reduction costs more than the benefit gained.
• ALARP does not mean zero risk - some residual risk is acceptable.
• It requires management judgement to balance risk and the cost of controls.
• As technology and business conditions change, ALARP must be reviewed regularly.

Assurance in Risk Management


Assurance provides confidence that an organisation's risk management, governance and internal controls are
effective.

• It involves an independent review of risk management processes.


• Assurance helps identify whether risks are being properly managed.

Assurance Maps

An Assurance Map is a tool that shows:


SBL Notes Risk Measurement, Assessment Pankaj Khandelwal
Chapter 15 and Management CA, CFA, CIA

• The organisation's key risks and activities.


• Who provides assurance (using the Four Lines of Assurance/Defence).

Four Lines of Defence


The Four Lines of Defence model explains who is responsible for managing risks and providing assurance in an
organisation.

Line of Defence Role

1st Line – Operational


Identify, manage, and control risks during daily operations.
Management

2nd Line – Risk & Compliance


Monitor the first line, provide guidance, and ensure compliance.
Functions

Independently assess the effectiveness of risk management and internal


3rd Line – Internal Audit
controls.

4th Line – External Provide independent external assurance on governance, risk management,
Audit/Regulators and compliance.

Benefits of Assurance Maps

• Identify gaps and duplication in assurance.


• Improve coordination and risk awareness.
• Align assurance activities with the organisation's risk appetite.

Limitations

• Difficult to define what counts as assurance.


• Independence of assurance providers may vary.
• Maps can be misleading if users misunderstand their scope

You might also like