Risk Impact Assessment
Operational & Reputation & Member
Rating Description Financial Impact
Compliance Impact Confidence Impact
• Major operational
disruptions, regulatory • Significant loss of
non-compliance member trust, leading to
leading to license mass withdrawals and
• Financial losses revocation, or severe decreased membership.
threaten 100% of penalties.
the Total Reserve • Non-existent controls
4 CRITICAL Fund (after APLL) or systemic control
• Threatens the
or result in severe weaknesses that
cooperative’s existence.
liquidity issues. enable fraud or asset
misappropriation.
• Legal action involving
• Adverse media
government or
coverage with long-term
regulatory agencies.
reputational damage.
• Significant operational • Probable loss of
• Financial losses
inefficiencies, major member confidence,
threaten 75% of
regulatory penalties, or leading to a decline in
the Total Reserve
repeated non- loan availments and
Fund (after APLL).
compliance. share capital growth.
• Runs significantly • Controls are
over budget and incomplete, unclear,
• Moderate media or
3 HIGH does not achieve inconsistent, or
regulatory scrutiny.
any of the outdated leading to
expected substantial fraud risk.
outcomes and/or
Cooperative • Audit findings require
finances are not urgent corrective action
effectively to avoid escalation.
managed.
• Moderate operational
disruptions, regulatory • Possible decrease in
non-compliance member confidence and
• Financial losses resulting in fines or engagement.
threaten 50% of corrective actions.
the Total Reserve
Fund (after APLL).
• Policies or
procedures are not
• Cooperative runs
proactively • Internal concerns
over budget and
2 MODERATE communicated to raised by management
achieves minimal
relevant stakeholders or members.
expected
that could lead to future
outcomes and/or
fraud risks.
Cooperative
finances are not
effectively
managed • System inefficiencies
that impact service
delivery.
• Financial losses • Minor inefficiencies or
• Minimal or no impact
threaten 15% of isolated instances of
on member trust.
the Total Reserve non-compliance.
Fund (after APLL). • No direct fraud risk
• No media or regulatory
but minor procedural
• Cooperative runs concern.
gaps.
within budget and
1 LOW
achieves key
expected
• Findings require
outcomes and/or
process improvement
Cooperative
but do not pose an
finances are
immediate risk.
effectively
managed
Risk Likelihood Assessment
Rating Description Frequency Internal Indicators
More than 1 event • Continuous or recurring audit findings
occurred within 1 despite corrective actions.
year prior to the
ALMOST
assessment period. • Repeated history of fraud or major
4 compliance violations.
CERTAIN
Audit findings were
identified in 75-100%
of the samples • High system or control failure rate.
reviewed.
An event occurred
within 1 year prior to • Similar issues identified in past audits,
the assessment with incomplete remediation.
period. • Industry trends indicate high-risk
3 LIKELY exposure.
Audit findings were
identified in 50-74% • System or control weaknesses present
of the samples but not yet exploited.
reviewed.
More than 1 event • Past findings in similar areas, but no
has occurred within 2 recent recurrence.
years prior to the
assessment period. • Changes in processes or policies that
2 POSSIBLE could reintroduce risk.
Audit findings were
identified in 25-49% • Weaknesses noted in non-critical
of the samples controls.
reviewed.
An event occurred • No history of similar findings in recent
once but more than 3 audits.
years prior to the
assessment period. • Strong controls and oversight in place.
1 UNLIKELY
Audit findings were
identified in 1-24% of • Low inherent risk based on current
the samples operations.
reviewed.
Risk Rating Matrix
LIKELIHOOD
RISK RATING Almost
Unlikely (1) Possible (2) Likely (3)
Certain (4)
Critical (4) 4 8 12 16
IMPACT
High (3) 3 6 9 12
Moderate
2 4 6 8
(2)
Low (1) 1 2 3 4
Low (1-2) Moderate (3-6) High (7-11) Critical (12-16)
Risk Level Definitions:
Critical – Immediate action required; escalated to senior
management and audit committee.
High – Requires prompt corrective action by management.
Moderate – Management must address this within a reasonable
timeframe.
Low – Minor issue; can be resolved through standard process
improvement
This classification system ensures that the risk-based audit approach aligns
with both financial and operational realities, while also considering reputation
and member trust.