Set-C Risk Management
Chapter-01
1. Risk and Uncertainty
Risk: The Chance of loss or harm, probability can be measured.
Uncertainty: Events that can't be predicted or measured.
Key Thinkers:
o Frank Knight distinguished risk (measurable) vs. uncertainty (non-measurable).
o Keynes emphasized the "element of surprise."
2. Classification and Types of Risks
Risks are classified based on:
Source:
o Internal (e.g., employee strikes, machinery failure)
o External (e.g., political instability, natural disasters)
Nature:
o Controllable (e.g., factory safety measures)
o Uncontrollable (e.g., terrorism, floods)
Status:
o Inherent Risk: Existing before controls are applied.
o Residual Risk: Remaining even after controls.
Consequences:
o Strategic (e.g., competitor launches a better product)
o Operational (e.g., machinery breakdown)
o Brand/Reputation (e.g., bad media coverage)
o Customer Satisfaction (e.g., poor service quality)
o Financial (e.g., foreign exchange loss)
o Compliance (e.g., legal penalties)
o Knowledge (e.g., data theft)
o Technology (e.g., hacking incidents)
o HR/People (e.g., key employee leaves)
o Location/Geography (e.g., mining affecting eco-system)
o Other (Fraud Risk, Audit Risk)
Important Relation:
Internal Risks → More Controllable
External Risks → Less Controllable
3. Importance and Objectives of Risk Management
Importance:
o Critical for governance and decision-making.
o Protects value, improves decision-making, minimizes loss.
Objectives:
o Protect property, earnings, and personnel.
o Minimize cost of risk, maximize profitability.
o Analyze possible events and prepare preventive measures.
4. Overview of Risk Mitigation & Controls
Risk Mitigation Techniques:
o Avoidance: Don't engage in risky activities.
o Retention: Accept the loss when unavoidable.
o Transfer: Shift the risk to others (e.g., insurance).
o Hedging: Reduce risk exposure (e.g., financial instruments).
Risk Control:
o Select techniques to reduce the frequency/severity of losses.
o Cost-benefit analysis is important unless mandated by law.
5. Opportunities in Risk Management for CAs
As Manager: CEO, CRO, Board Member, Risk Management Committees.
As Auditor:
o Internal Auditor: Evaluate risk processes.
o External Auditor: Perform risk-based auditing.
As Consultant: Provide multi-disciplinary risk management advice.
Chapter-2
1. Risk Management Framework (RMF)
Definition: A structured approach to design, implement, monitor, and improve risk
management.
Key Frameworks:
o COSO ERM Framework:
Established in 2004, updated for strategy-performance linkage.
5 Components:
1. Risk Governance and Culture – Board’s role in risk oversight.
2. Risk, Strategy, and Objective-Setting – Align risk with strategy.
3. Risk in Execution – Identify and rank risks during operations.
4. Risk Information, Communication, Reporting – Use quality data.
5. Monitoring ERM Performance – Review and improve processes.
o ISO 31000:2018:
Focuses on Principles, Framework, and Process.
Core Principle: Value creation and protection.
Process includes: Communicate, Scope, Risk Assessment, Risk Treatment,
Monitoring, and Reporting.
2. Implementation of Risk Management Policies
Objectives:
o Define roles (Board, Audit Committee, CRO).
o Outline risk management processes.
o Integrate risk into business decision-making.
o Regularly review risk appetite.
Guiding Principles:
o Prior information and acceptance of risk.
o Enhance business value and manage black swan events.
3. Enterprise Risk and Linkage to Business
Enterprise Risk Management (ERM): A firm-wide approach, not isolated to departments.
Helps Organizations:
o Identify strategic risk opportunities.
o Align risk treatment with decision-making.
o Support capital market compliance.
o Link risk with business continuity planning (BCP).
Key Components of ERM:
o Strategy and objectives
o Risk Appetite (risk levels an organization accepts)
o Risk Culture (values and behavior)
o Risk Data quality
o Strong Internal Controls
o Scenario Analysis and Risk Measurement
o Regular evaluation of ERM practices.
4. Governance and Ethical Dimensions
Enterprise Governance: Beyond corporate governance — focuses on both conformance and
performance.
Global Focus Areas:
o Transparency, compliance, board effectiveness.
o Integration of strategy, decision-making, and risk management.
G20/OECD Corporate Governance Principles:
o Effective governance framework.
o Protect shareholder rights.
o Ensure fair treatment of shareholders.
o Define board responsibilities clearly.
o Promote disclosure and transparency.
Ethical Risk Management:
o Transparency, fairness, responsibility, sustainability.
o Respect for stakeholder rights.
o Crisis management and continuous improvement.
5. Legal, Regulatory & Compliance Framework
Companies Act, 2013:
o Internal financial controls must be ensured (Sec. 134, 143, 177).
o Independent directors must monitor risk management systems.
Auditing Standards (SA 315):
o Identify and assess risks of material misstatement.
SEBI (LODR) Regulations, 2015:
o Risk Management Committee required for top 1000 listed companies.
o Meetings must be held at least twice a year.
Chapter-03
1. Introduction to Risk Stakeholders
Risk stakeholders: Individuals or groups with an interest in risks associated with a business.
Types of Stakeholders:
o Internal: Employees, managers, executives, shareholders.
o External: Customers, suppliers, regulators, investors, local communities,
competitors.
Key point: Risk management must involve all relevant stakeholders.
2. Board Oversight / Role of Board of Directors
Board of Directors:
o Sets the strategy and objectives for risk management.
o Owns the governance responsibility for supervising risk.
o May form committees (like Audit Committee) to assist with oversight.
o Delegates to management but remains accountable.
Key point: Board is the highest body responsible for risk governance.
3. Role of CEO and Management
CEO (Chief Executive Officer):
o Takes complete ownership of risk management.
o Sets the tone at the top for a risk-aware culture.
o Establishes a formal risk management function.
o Assigns and monitors risk management responsibilities.
o Reports periodically to the Board.
Importance: Personal involvement of CEO is critical for success of Risk Management.
4. Role of Risk Managers and Risk Owners
Risk Manager:
o Focuses on operational aspects of risk.
o Identifies, analyzes, and helps control risks.
o Prepares risk budgets, maintains insurance records, and supports claims
management.
Risk Owner:
o Senior-level person responsible for specific risks.
o Duties:
Identify and assess risks.
Monitor emerging risks.
Assign responsibilities.
Allocate resources.
Implement and follow-up mitigation measures.
Foster a risk-aware culture.
Communicate status regularly.
Key point:
Risk Manager → Opera onal handling.
Risk Owner → Accountability for specific risks.
5. Role of Auditors (Statutory and Internal)
External Auditors:
o Independently evaluate financial statements.
o Review risks that could impact financial reporting.
o Important source of risk-related information.
Internal Auditors:
o Evaluate effectiveness of risk controls.
o Monitor compliance and governance structures.
o Support both Management and the Board.
Chapter-04
1. Risk Identification
First step in risk management.
Identifies internal and external threats that could harm the organization.
Tools: Risk questionnaires, Risk registers.
Methods:
o Top-down approach (senior to junior) is more effective.
o SWOT analysis (Strengths, Weaknesses, Opportunities, Threats).
o Flowcharting processes and asking "What can go wrong?"
2. Risk Evaluation (Impact and Likelihood)
Impact = consequence if risk occurs.
Likelihood = probability that risk occurs.
Level of Risk = Impact × Likelihood
Likelihood Scale:
o Very Likely → > Once a year
o Likely → About once a year
o Unlikely → Every 10+ years
o Very Unlikely → Once historically
Impact Scale (Example):
o Severe → Loss > ₹50 crores
o High → ₹10–50 crores
o Moderate → ₹1–10 crores
o Low → < ₹1 crore
Risk Ratings:
o 12–16 → Severe (Immediate ac on)
o 8–12 → High (Ac on within 1 week)
o 4–8 → Moderate (Ac on in 1–2 months)
o 1–4 → Low (Monitor, no urgent ac on)
3. Risk Quantification & Ratings
Assigning values to risks to prioritize actions.
Used in credit assessment, investments, operational risks.
Challenges: Subjectivity, reliance on historical data, unpredictable Black Swan events.
4. Risk Quantification Tools
Judgment and Intuition: Based on expertise.
Delphi Method: Anonymous expert opinions to build consensus.
Scoring: Weight risks based on severity and cost.
Quantitative Techniques: Use probability × loss estimation.
Qualitative Techniques: Focus on threats, vulnerabilities, and controls without hard data.
Expected Monetary Value (EMV): Probability × financial impact.
Simulation (Monte Carlo Analysis): Models various risk outcomes by repeated random
sampling.
Decision Tree: Diagrams to assess outcomes and choices sequentially.
Scenario Analysis: Analyzing best case, worst case, and most likely case scenarios.
5. Risk Prioritization and Risk Matrix (Heat Map)
Visual tool to prioritize risks based on Impact and Likelihood.
Color coded:
o Red = High Risk
o Yellow/Orange = Medium Risk
o Green = Low Risk
Benefit: Easy visualization, better decision-making.
Flaws: Subjectivity, not fully quantitative, doesn’t reflect risk aversion.
Chapter-05
1. Risk Appetite
Risk Appetite: Level of risk an organization is willing to accept while pursuing objectives.
Risk Tolerance: Specific minimum or maximum risk limits an organization is ready to bear
after risk treatment.
Key Differences:
Appetite = Overall willingness | Tolerance = Acceptable/unacceptable range.
Appetite = Strategic/long-term | Tolerance = Operational/short-term.
Factors Influencing Risk Appetite:
Nature of Industry
Stage of Company
Objective Aggressiveness
Financial Strength
Benefits of a Risk Appetite Statement:
Better risk management
Informed decisions
Better risk-return balance
Transparency for stakeholders
Alignment across organization
2. Risk Treatment Techniques
4 Major Techniques:
Tolerate: Accept the risk if manageable or cost of action is too high.
Transfer: Shift risk to third party (e.g., insurance, outsourcing).
Terminate: Stop the risky activity altogether.
Treat: Mitigate and control the risk through internal measures.
3. Controlling Risk
Involves evaluating potential losses and reducing/eliminating risks.
Based on findings from risk assessments.
Part of overall Enterprise Risk Management (ERM).
Key Risk Control Activities:
Risk identification
Risk assessment and mitigation
Monitoring and communication
Scenario planning
Crisis management planning
Note: Risk Control is a part of Risk Management but not the same.
4. Contingency Planning
Prepares the organization for disruptions.
Focus on quick and effective response to unexpected events.
Key Elements:
Identify critical assets and risks.
Develop mitigation strategies.
Create contingency teams and plans.
Test plans via simulations/drills.
Maintain external coordination with partners and authorities.
Ensure legal and regulatory compliance.
Chapter-06
1. Information and Communication
Information is the most valuable asset in modern organizations.
ICT (Information and Communication Technology) plays a critical role.
Examples of dependency: Banks, airlines, pharma companies, railways.
Real-time IT failures (server, network, hacking, etc.) can cause major disruptions.
Organizations must have Business Continuity Plans (BCP) and Disaster Recovery Plans
(DRP).
2. Automation & Continuous Monitoring
Disaster Recovery Plan (DRP): Steps to protect IT infrastructure during disasters.
Three Strategies:
o Preventive Measures: Avoid disasters (e.g., backups, surge protectors).
o Detective Measures: Identify disasters (e.g., fire alarms, training).
o Corrective Measures: Recover from disasters (e.g., insurance, system restoration).
Business Continuity Plan (BCP): Ensures business continues during/after a disaster.
Testing of DRP:
o Simulate real conditions,
o Identify gaps,
o Train recovery teams,
o Provide assurance to Board and regulators.
3. Auditing and Evaluating Risk
Audit Risk Components:
o Inherent Risk: Risk without internal controls.
o Control Risk: Risk that controls fail to prevent or detect misstatements.
o Detection Risk: Risk that auditors miss the misstatement.
Audit Risk Formula:
Audit Risk (AR)=Inherent Risk (IR)×Control Risk (CR)×Detection Risk (DR)\text{Audit Risk (AR)} =
\text{Inherent Risk (IR)} \times \text{Control Risk (CR)} \times \text{Detection Risk (DR)}
Risk of Material Misstatement = Inherent Risk × Control Risk.
Inverse Relation:
o Higher Inherent/Control Risk → Lower Detec on Risk needed.
4. Continuous & Periodic Reporting
Reporting of risk has become mandatory post-2007-08 global crisis.
International Examples:
o US: SEC requires companies to describe risks (since 1970s).
o Germany: Risk Reporting Standard (GAS 5).
o UK: Corporate Governance Code (risk management integrated).
India (SEBI LODR Regulations, 2015):
o Board responsible for Risk Management Plan.
o Top 1000 listed companies must have a Risk Management Committee.
o Quarterly reporting of Forex risk exposures.
o Annual Reports must include:
Industry structure
Opportunities and threats
Segment-wise performance
Risks and concerns
Internal controls adequacy
Modern Risk Reporting Practices:
o Disclose principal risks.
o Differentiate company-specific vs. industry-wide risks.
o Show movement and trends of risks.
o Link risks to financial performance.
o Show short-term liquidity and long-term viability.
o Include stress and sensitivity analyses.
Chapter-07
1. Strategic Risk
Strategic Risk: When a company’s business strategy becomes ineffective.
Causes: Technological change, competition, customer behavior shifts, raw material cost
increase.
Examples:
o Kodak: Failed to adapt to digital cameras.
o Nokia: Lost market by not upgrading to touchscreen phones.
o Xerox: Successfully adapted to laser printing.
2. Business Portfolio Risks
Total Risk = Systematic Risk + Unsystematic Risk
Systematic Risks (Macro/External, Uncontrollable):
Interest Rate Risk: Inverse relationship with security prices.
Purchasing Power Risk: Inflation reduces real returns.
Market Risk: Bullish or bearish trends in overall markets.
Unsystematic Risks (Micro/Internal, Controllable):
Business Risk: Variability in operating profits.
Financial Risk: Due to excessive debt (Debt-Equity ratio).
Diversification:
Reduces Unsystematic Risk but not Systematic Risk.
3. Industry / Competition Risks
Competition Risk: Rivals introducing better or faster innovations.
Factors causing competition risk:
o Technological gap
o Changing consumer needs
o Vendor issues
o Poor management
o High exit barriers
Basis of Competition:
Understand what drives customer choice: Price, features, quality, brand image.
Key Success Factors (KSFs):
Critical elements a business must perform well (e.g., R&D, speed, quality).
Core Competencies:
Unique strengths (e.g., Honda in engines, Canon in optics) leading to competitive
advantage.
4. Investments & Funding of Growth
Sustainable Growth Rate (SGR):
o Developed by Robert C. Higgins.
o Measures maximum sales growth without needing new equity.
SGR=ROE×(1−Dividend Payout Ratio)\text{SGR} = \text{ROE} \times (1 - \text{Dividend Payout Ratio})
Firms must balance between profitability, asset utilization, and dividend policy.
Inflation increases the need for external financing.
Financial sustainability needs:
o Diversified income sources
o Strong public image
o Good financial systems
5. Product / Service Risks
Types of Product Risks:
o Functional Risk: Product doesn't perform its intended functions.
o Non-functional Risk: Issues like instability under heavy load.
Risks in New Product Development:
Technology Risk: Integration failures.
Performance Risk: Functionality issues post-build.
Market Risk: Poor market acceptance.
Organizational Risk: Internal conflicts.
Supply Chain Risk: Vendor failures.
Financial Risk: Budget shortfalls.
Risk Mitigation:
Extensive Testing and Risk Assessment early in product development.
Important MCQ Focus Points
Financial Risk is Unsystematic Risk (Not Systematic Risk).
SGR formula: ROE × (1 - Dividend payout ratio).
Developer of SGR concept: Robert C. Higgins.
Performance Risks emerge during product testing.
Organizational Risks stem from internal conflicts during new product development.
Chapter-08
Operational Risk - Summary
1. What is Operational Risk?
Definition: Risk of losses from inadequate or failed internal processes, people, systems, or
external events. (Basel Committee, 2003)
Includes: Disruptions, fraud, human errors, digital attacks, legal breaches, disasters.
Financial services call operational risk a non-financial risk (different from credit, market,
liquidity risks).
2. Process Level Risk Management
Deals with risks at operational divisions and departments.
Focuses on managing functional processes like R&D, operations, marketing, finance, HR.
High-severity, low-frequency incidents cause two-thirds of operational losses (ORX
Association, 2022).
Efficient management = Balance between cost of controls and expected loss.
3. Outsourcing Risks & 3rd Party Risk
Outsourcing = Make vs. Buy Decision.
When to Outsource:
o Cheaper than in-house manufacturing.
o Lack of skilled manpower.
o Avoid labor issues or high capital investment risks.
Risks of Outsourcing:
o Loss of Control: Less oversight over vendors.
o Communication Challenges: Language, cultural differences.
o Security Breaches: Risk to confidential data and IP.
How to Minimize Outsourcing Risk:
o Address critical issues early.
o Shared responsibility.
o Set clear goals.
o Conduct trial periods.
o Maintain flexibility.
o Prioritize security.
o Recruit strategically.
4. Supply Chain (Sale / Purchase)
Supply Chain: Network of vendors, producers, warehouses, distributors, retailers.
Push Model: Produce based on demand forecasts (supply → customer).
Pull Model: Produce based on actual demand (customer → supply).
Upstream Flow: Materials from supplier.
Downstream Flow: Products to customer.
Key Supply Chain Processes:
o Customer/Supplier Relationship Management
o Demand Management
o Order Fulfilment
o Manufacturing Flow
o Product Development
o Returns Management
Building a Resilient Supply Chain:
o Stress-test disruption scenarios.
o Map vulnerabilities.
o Flexibility to adapt to global shocks (e.g., COVID-19, geopolitical tensions).
5. Product / Service Quality and Operational Risk
Operational risks affect product quality via:
o Process Failures (manufacturing issues)
o Human Errors (staff mistakes)
o Technology Failures (equipment/software glitches)
o Compliance Failures (non-adherence to laws)
o Communication Breakdowns
o Security Breaches
o Environmental Factors (natural disasters)
Solution: Strong risk management, quality controls, employee training.
Important MCQ Focus Points
Operational Risk = Failure of processes, people, systems, or external events.
Process Level Risk Management = Balancing control costs vs. expected losses.
Supply Chain Management = Integration from supplier to end-user.
Pull Model = Focused on actual consumer demand.
Supply Chain disruptions affect product quality through Supply Chain Disruptions (not just
process failures).
Chapter-09
Emerging Issues in ERM - Summary
1. External Influences
Climate Change & Environmental Risks:
o Climate risks are now seen as systemic risks.
o Companies must assess and disclose climate-related risks.
Supply Chain Disruptions:
o COVID-19 showed vulnerabilities.
o Outsourcing increases dependence and revenue risks.
Social Media & Reputation Risks:
o Reputational damage increases business transaction costs.
o Need proactive social media monitoring.
Regulatory Changes:
o Evolving laws require flexible ERM systems.
o Legal risks include contracts, compliance gaps, and litigation exposure.
Political & Geopolitical Risks:
o Political instability, trade policies, wars can impact businesses.
o Globalization increases exposure to such risks.
2. Global Developments
Increased Complexity of Risks:
o Interconnected global operations increase risk exposure.
Regulatory Compliance Challenges:
o Different countries → Different rules → Complex compliance.
Cultural and Communication Barriers:
o Diverse workforces lead to risk perception differences.
Political and Geopolitical Risks:
o Changes in leadership or policy can destabilize markets.
Environmental and Climate Risks:
o Global warming influences consumer behavior and regulations.
Data Privacy and Protection:
o More data exchange = Higher need for strong cybersecurity and privacy laws
compliance.
Market Volatility:
o Economic crises affect companies globally.
Supply Chain Risks:
o A disruption anywhere can affect the entire chain.
Crisis Management:
o Organizations must have strong plans for unexpected global events like pandemics.
Impact of Global Recession:
o Financial crisis (like 2008) showed failure in predicting risky products (e.g., Sub-
prime lending).
3. Technology & Automation
Technological Innovations:
o AI, blockchain, automation create new risks.
o ERM must adapt to technology-driven changes.
Data Privacy and Compliance:
o Laws like Digital Personal Data Protection Act need compliance.
Remote Work and Cybersecurity:
o Cyber threats increased with work-from-home models.
o Real-time monitoring of system risks is now common.
Strategic Alliances Risk:
o Companies merge their supply and customer systems, raising interdependency risks.
Recent Development/Challenges in Fraud Risk:
o Example: Satyam Computers fraud — high-level management fraud led to corporate
governance reforms.
Important MCQ Focus Points
Reputation Risk = Increases transaction costs due to lost stakeholder trust.
Globalization increases Political and Geopolitical Risks.
Global supply chains create Increased Complexity of Risks.
Cultural Barriers can affect risk communication.
Post-financial crisis: focus increased on Risk Culture in banks and insurers.