SBL Notes Risk Strategy & Pankaj Khandelwal
Chapter 14 Identification CA, CFA, CIA
What is Risk?
• COSO framework: Risk is the possibility that an event will negatively affect the achievement of
objectives.
• Institute of Risk Management: Risk is the combination of the likelihood of an event and its impact.
Risk Management Strategy
• A risk management strategy explains how risks will be identified, assessed, monitored, and
managed.
• Risk management is an organisation-wide responsibility, led by senior management and the board.
• Leaders must identify, assess, and control risks when making strategic decisions.
• Frameworks such as COSO help integrate risk management into business strategy.
• After addressing strategic risks, organisations must identify and manage operational risks.
• Organisations should also assess environmental and climate-related risks.
• Good risk management protects and creates value for stakeholders.
Examples of Risk Management Failures: Global Financial crisis, BP Oil spill, Cyber-attack on NHS
Relationship Between Risk Management and Organisational Strategy
Risk management and business strategy should work together because:
• Business objectives determine risk appetite (how much risk stakeholders are willing to accept).
• Management should choose strategies that fit the organisation's risk appetite.
• Each strategic option should be evaluated for its risk profile.
• Strategy should never be developed without considering risk.
Risk Profile
• A risk profile shows the relationship between risk and expected return.
• Generally:
1. Higher risk → Higher expected reward
2. Lower risk → Lower expected reward
• The organisation chooses the level of risk that matches its risk appetite.
• The preferred balance of risk and reward is called the target risk level.
Golden Rule: Accept only the level of risk that aligns with the organisation's willingness and ability to bear it.
Risk Attitude:
• Risk Seeker → Accepts high risk for higher returns.
• Risk Averse → Prefers lower risk, even with lower returns
SBL Notes Risk Strategy & Pankaj Khandelwal
Chapter 14 Identification CA, CFA, CIA
Risk Appetite
Risk appetite is the amount of risk an organisation is willing to accept to achieve its objectives.
• Higher risk → Higher potential return
• Lower risk → Lower potential return
Risk appetite defines how much risk the organisation is willing to take.
Factors Affecting Risk Appetite
Risk appetite depends on:
• Stakeholders' attitudes
• Organisational culture
• Current risk profile
• Risk capacity (maximum risk the organisation can bear)
• Importance of objectives (more important objectives = lower risk)
• Management's risk management capability
Risk Capacity
Risk capacity is the maximum level of risk an organisation can absorb without threatening its survival.
• Risk Appetite > Risk Capacity → High chance of failure.
• Risk Appetite < Risk Capacity → Missed growth opportunities.
Remember: Appetite = Willing to take | Capacity = Able to take
Risk Policy
A risk policy (or risk appetite statement) provides guidelines on acceptable risk levels. It includes:
• Strategic limits – Which strategies/products to avoid.
• Financial limits – Acceptable financial risk.
• Operational limits – Safety and operational standards.
The policy should be communicated throughout the organisation.
Quantitative Targets
Risk policies may set:
• Targets – Desired risk levels (e.g., bad debts below 2%).
• Ceilings – Maximum acceptable risk; activities above this limit are rejected.
Risk Controls
Risk appetite determines the strength of controls:
• Low risk appetite → Simpler controls.
• High risk appetite → Stronger and more sophisticated controls.
SBL Notes Risk Strategy & Pankaj Khandelwal
Chapter 14 Identification CA, CFA, CIA
Risk Management Frameworks
Elements of the Risk Management Process
Step Meaning
1. Identify Find the risks that could prevent the organisation from achieving its objectives.
2. Evaluate Assess the likelihood and impact of each risk.
3. Manage Decide and implement actions to reduce, avoid, transfer, or accept the risks.
4. Monitor & Review Continuously monitor risks, review controls, and improve the process through feedback.
Enterprise Risk Management (ERM)
Enterprise Risk Management (ERM) is an organisation-wide approach that integrates risk management with
strategy and performance to create, protect, and increase value.
Key Features of ERM (COSO)
• Continuous process (not a one-time activity)
• Creates and protects value for stakeholders
• Uses policies, systems, and practices to manage risks
• Suitable for organisations of all sizes
• Supports better decision-making
Benefits of ERM
• More opportunities by considering both risks and rewards.
• More positive outcomes and fewer unexpected problems.
• Proactive rather than reactive risk management.
• Better identification and management of organisation-wide risks.
• Better allocation of resources.
• Improved discussions between management and the board about risks.
COSO Framework
• COSO (Committee of Sponsoring Organisations of the Treadway Commission) developed one of the
world's most widely used Enterprise Risk Management (ERM) frameworks.
• It provides guidance on risk management, internal controls, and fraud prevention.
• The latest version (2017) integrates risk management with strategy and performance.
Purpose of the COSO Framework
The framework helps organisations:
• Integrate risk management into strategy and decision-making.
• Identify and manage risks across the organisation.
• Improve performance while creating and protecting stakeholder value.
• Continuously monitor and improve risk management.
SBL Notes Risk Strategy & Pankaj Khandelwal
Chapter 14 Identification CA, CFA, CIA
Five Components of the COSO Framework
Component Simple Meaning
1. Governance & Culture Build a strong ethical culture, leadership, and accountability.
Consider risks when setting strategy, objectives, and risk
2. Strategy & Objective Setting
appetite.
3. Performance Identify, assess, prioritise, and respond to risks.
4. Review & Revision Monitor risks and continuously improve the ERM system.
5. Information, Communication & Share accurate risk information for better decisions and
Reporting transparency.
Tip to remember: GRIPS
COSO Framework – Keys to Success
Key Simple Meaning
The board and senior management must lead by setting the right risk culture and
1. Start at the Top
ethical behaviour ("tone at the top").
2. Understand ERM's ERM is not just for compliance-it helps management make better decisions and
Purpose create value.
3. Integrate ERM into the Risk management should be part of strategy, operations, and performance
Business management, not a separate activity.
Begin with the organisation's key strategies and objectives, then identify the related
4. Focus on Strategy First
risks.
Give the most attention to risks that could affect strategic objectives, as these have
5. Prioritise Strategic Risks
the greatest impact.
6. Implement Gradually Introduce ERM step by step instead of trying to implement everything at once.
Build on existing risk processes and controls rather than creating entirely new
7. Use Existing Resources
systems.
Tip to remember: SUIFPIU - Successful Unicorns Inspire Fearless People In Universities.
Criticism of the COSO Framework
• The framework still gives limited attention to external risks, such as risks arising from external events or
third parties.
SBL Notes Risk Strategy & Pankaj Khandelwal
Chapter 14 Identification CA, CFA, CIA
Identifying Risks
Risk Categorisation
Organisations face many different risks. These are commonly grouped into:
Risk Type Meaning
Strategic Risk Risks affecting long-term goals and strategy.
Operational Risk Risks from daily operations, people, processes, systems, or external events.
Market Risk Risks from changes in market conditions (e.g., interest rates, exchange rates, prices).
Credit Risk Risk that customers or borrowers fail to pay.
Other ways to classify risks:
• Common business risks (e.g., falling sales)
• Sector/Industry-specific risks
• Country risks (political, economic, legal)
Strategic Risk
Strategic risk is the risk that an organisation fails to achieve its strategic objectives.
Causes
• Poor strategic decisions
• Poor implementation
• Changes in the external environment
• New competitors, technology, regulations, or economic conditions
Characteristics
• Top-down approach (board level)
• Usually low probability but high impact
• Often unexpected and complex
• Requires continuous monitoring of the external environment
Key Point: Strategic risks threaten the organisation's long-term success or survival.
Operational Risk
Operational risk is the risk of loss from failed people, processes, systems, or external events.
Types of Operational Risks
Type Examples
People Fraud, theft, employee errors, loss of key staff
Processes Poor procedures, supplier delays
Systems IT failures, cyberattacks, system breakdowns
External Events Natural disasters, strikes, power failures
SBL Notes Risk Strategy & Pankaj Khandelwal
Chapter 14 Identification CA, CFA, CIA
Sector-Specific (Industry-Specific) Risks
These risks affect only certain industries or sectors.
Examples
• Banks → Financial regulations
• Listed companies → Stock exchange regulations
• Charities → Charity laws
• All companies → Company law
Dynamic Nature of Risk
Risk is constantly changing, so risk management must be continuous.
Why Risks Change?:
Economic conditions; Technology; Competition; Climate change; Pandemics; Government; regulations;
Stakeholder; expectations; Internal changes (new products, expansion, financing)
Static Environment Dynamic Environment
Little change Frequent change
Risks remain stable Risks constantly change
Easier to predict Harder to predict
Risk Changes in Two Ways
• Probability changes – The likelihood of a risk occurring
• Impact changes – The consequences of the risk.
Type of Risks
Market Risk
Risk that the value of investments or liabilities changes due to market movements such as share prices, interest
rates, exchange rates, or commodity prices.
Credit Risk
Risk that a customer or borrower fails to repay money owed, causing financial loss.
Liquidity Risk
Risk that an organisation cannot meet its payment obligations or raise cash when needed.
Technological Risk
Risk of failing to adopt or manage technology, resulting in loss of efficiency or competitive advantage.
Legal & Regulatory (Compliance) Risk
Risk of breaking laws or regulations, leading to fines, legal action, licence loss, or reputational damage.
Health & Safety Risk
Risk of injury or illness to employees or others due to unsafe working conditions.
SBL Notes Risk Strategy & Pankaj Khandelwal
Chapter 14 Identification CA, CFA, CIA
Environmental (Sustainability) Risk
Risk that the organisation harms the environment or is affected by environmental issues such as pollution,
climate change, or natural disasters.
Climate-Related Risk
Risk arising from climate change, including:
• Transition risk – Moving to a low-carbon economy (new laws, technology, customer preferences).
• Physical risk – Damage from extreme weather and climate events.
Reputation Risk (mother of all risks)
Risk that negative publicity or loss of trust damages the organisation's brand, customers, revenue, or market
value.
Derivative Risk
Risk of financial losses from derivative contracts due to unexpected market movements or speculative trading.
Risk Evaluation
After identifying risks, the organisation must evaluate, respond to, and monitor them.
Step Summary
1. Risk Assessment Assess the likelihood and impact of risks.
2. Risk Response Avoid, reduce, transfer, or accept the risk.
3. Control Activities Use internal controls to manage risks.
4. Information & Communication Collect and share accurate risk information.
5. Monitoring Continuously review and improve risk management.