SBL Notes Risk Measurement, Assessment Pankaj Khandelwal
Chapter 15 and Management CA, CFA, CIA
What is Risk Assessment?
Risk assessment helps an organisation understand:
• How likely a risk is to occur (Probability/Likelihood).
• How serious its impact or consequences would be.
Risk assessment can use:
• Quantitative methods (numbers and data)
• Qualitative methods (judgement and experience)
• A combination of both
Risk Assessment Techniques
Technique Purpose
Benchmarking Compare with similar organisations or industry standards.
Probabilistic Modelling Uses historical data and statistics (e.g., Value at Risk) to estimate future risks.
Non-Probabilistic Uses judgement, stress tests, sensitivity analysis, and scenario analysis when data is
Modelling limited.
Measuring Risk
Risk is measured using two factors:
1. Impact (Consequences) - Measures how serious the effect would be.
Level Meaning
High Large financial loss, major effect on strategy, high stakeholder concern.
Medium Moderate financial and operational impact.
Low Minor financial and operational impact.
Points to remember:
• Consider both Threats (losses) and Opportunities (gains).
• Use reliable data where available.
• Stakeholder impact should also be considered.
• Some judgement is needed when data is unavailable.
2. Likelihood (Probability) - Measures the chance that the risk will occur.
Level Meaning
High Very likely to happen.
Medium May happen.
Low Unlikely to happen.
The time period (e.g., 1 year, 5 years, 10 years) should also be clearly defined.
SBL Notes Risk Measurement, Assessment Pankaj Khandelwal
Chapter 15 and Management CA, CFA, CIA
Risk Matrix (Likelihood × Impact)
A 2×2 Risk Matrix ranks risks based on their likelihood and impact.
Low Impact High Impact
High Likelihood Monitor & Manage Highest Priority
Low Likelihood Low Priority Monitor & Prepare
Related and Correlated Risks
Risks rarely occur alone. One risk can trigger another, creating a domino effect. Therefore, organisations should
assess how risks are connected, not just individual risks.
1. Related Risks: Two risks are related when the presence of one affects the impact or likelihood of the other.
They should be managed together. (e.g., political instability increases security risk).
2. Correlated Risks: Correlated risks move together.
Type Meaning Example
Both risks increase or decrease Higher environmental risk → Higher reputational
Positive Correlation
together. risk.
One risk increases while the other Borrowing to reduce pollution lowers
Negative Correlation
decreases. environmental risk but increases financial risk.
• The total impact of linked risks can be greater than the sum of individual risks.
• Effective risk management considers individual, related, and correlated risks.
Monitoring Risk
1. Risk Manager
A Risk Manager identifies, assesses, and manages risks to protect the organisation.
Key Responsibilities:
• Identify and assess risks.
• Decide how to avoid, reduce, transfer, or prepare for risks.
• Set the organisation's risk appetite.
• Report risks to management and the board.
• Develop risk management, business continuity, and insurance plans.
• Ensure compliance through audits.
• Train staff to improve risk awareness.
Key Goal: Protect the organisation, its people, assets, reputation, and stakeholders from potential risks.
2. Risk Register
A Risk Register is a document that records and monitors an organisation's key risks. It helps management
understand and control the overall risk profile.
SBL Notes Risk Measurement, Assessment Pankaj Khandelwal
Chapter 15 and Management CA, CFA, CIA
It includes:
• Risk description
• Likelihood and impact (risk score)
• Risk priority/ranking
• Person responsible
• Risk response/control plan
• Date identified
• Related risks
Key Point: A risk register is an important internal control tool used to identify, prioritise, assign ownership, and
monitor risks
Risk Register Scoring Methodology
• Risk Score = Likelihood × Impact
• Likelihood: Rated 1–5 (1 = Very Unlikely, 5 = Very Likely).
• Impact: Rated 1–5 (1 = Low Impact, 5 = Severe Impact). The final risk score ranges from 1 to 25,
where 1 = Very Low Risk and 25 = Very High/Significant Risk.
3. Heat Maps
A Heat Map is a visual tool that shows and prioritises risks based on their Likelihood (Probability) and Impact.
• Uses a colour-coded matrix (green → yellow → red) to highlight risk severity.
• Helps management identify high-priority risks quickly.
• Usually shows Residual Risk-the risk that remains after controls have been implemented.
Key Point: A heat map helps organisations visualise, prioritise, and monitor residual risks also, using a likelihood–
impact matrix
Risk Response
Embedding Risk Awareness
Risk Awareness is understanding the nature, likelihood, and impact of risks in different situations.
SBL Notes Risk Measurement, Assessment Pankaj Khandelwal
Chapter 15 and Management CA, CFA, CIA
Importance
• Risk awareness should exist at all levels, not just management.
• It creates a risk-aware culture.
• This makes risk management:
o Integrated (not fragmented)
o Proactive (not reactive)
o Continuous (not ad hoc)
o Value-focused (not just cost-focused)
o Organisation-wide (not narrowly focused)
How to Embed Risk Awareness
• Provide risk training for all employees.
• Include risk responsibilities in job descriptions and contracts.
• Make risk policies and procedures easily available.
• Hold regular training, workshops, meetings, and communications on risks.
TARA Model
After identifying and assessing risks, organisations choose the best risk response using the TARA model. The
response depends on the likelihood, impact, costs, benefits, and risk appetite.
TARA
When Used Meaning / Example
Response
T – Transfer High Impact, Low
Shift the risk to others (e.g., insurance, outsourcing, hedging, joint ventures).
(Share) Likelihood
High Impact, High Eliminate the risk by stopping or avoiding the activity (stop producing, exit
A – Avoid
Likelihood the market).
Low Impact, High Reduce the likelihood and/or impact using internal controls, monitoring,
R – Reduce
Likelihood diversification, etc (Reducing the production to maintain the demand)
Low Impact, Low Accept the risk if it is within the organisation's risk tolerance or the cost of
A – Accept
Likelihood control exceeds the risk.
SBL Notes Risk Measurement, Assessment Pankaj Khandelwal
Chapter 15 and Management CA, CFA, CIA
Spreading and Diversifying Risk
Organisations can reduce risk by sharing it or spreading it.
1. Insurance (Risk Sharing)
• Risk is shared among many people through insurance premiums.
• The insurance company compensates those who suffer losses.
• This spreads the cost of major losses across all policyholders.
2. Diversification
• Spread investments across different products, markets, or businesses.
• Avoid relying on a single source of income ("Don't put all your eggs in one basket").
• Diversification reduces overall risk, especially when investments are negatively correlated.
Accepting Risk
Accepting Risk means choosing to take no action to avoid, reduce, or transfer a risk because it is considered
acceptable.
When is Risk Accepted?
• The cost of controlling or transferring the risk is higher than the expected loss.
• The potential rewards outweigh the risks.
• The risk cannot be transferred or avoided.
Residual Risk - Residual Risk is the remaining risk after all risk controls have been applied
ALARP Principle
ALARP (As Low As Reasonably Practicable) means reducing risk as much as reasonably possible, considering the
cost, time, and effort involved.
Risk vs. cost, time, and effort
Key Points
• Risk should be reduced until further reduction costs more than the benefit gained.
• ALARP does not mean zero risk - some residual risk is acceptable.
• It requires management judgement to balance risk and the cost of controls.
• As technology and business conditions change, ALARP must be reviewed regularly.
Assurance in Risk Management
Assurance provides confidence that an organisation's risk management, governance and internal controls are
effective.
• It involves an independent review of risk management processes.
• Assurance helps identify whether risks are being properly managed.
Assurance Maps
An Assurance Map is a tool that shows:
SBL Notes Risk Measurement, Assessment Pankaj Khandelwal
Chapter 15 and Management CA, CFA, CIA
• The organisation's key risks and activities.
• Who provides assurance (using the Four Lines of Assurance/Defence).
Four Lines of Defence
The Four Lines of Defence model explains who is responsible for managing risks and providing assurance in an
organisation.
Line of Defence Role
1st Line – Operational
Identify, manage, and control risks during daily operations.
Management
2nd Line – Risk & Compliance
Monitor the first line, provide guidance, and ensure compliance.
Functions
Independently assess the effectiveness of risk management and internal
3rd Line – Internal Audit
controls.
4th Line – External Provide independent external assurance on governance, risk management,
Audit/Regulators and compliance.
Benefits of Assurance Maps
• Identify gaps and duplication in assurance.
• Improve coordination and risk awareness.
• Align assurance activities with the organisation's risk appetite.
Limitations
• Difficult to define what counts as assurance.
• Independence of assurance providers may vary.
• Maps can be misleading if users misunderstand their scope