0% found this document useful (0 votes)
11 views7 pages

Risk Assessment and Quantification Guide

Chapter 4 discusses risk assessment, covering risk identification, evaluation, quantification, and prioritization. It highlights the importance of documenting potential risks, using various techniques such as SWOT analysis, risk matrices, and the Delphi approach to assess and manage risks effectively. The chapter also addresses challenges in risk quantification and the significance of understanding both qualitative and quantitative aspects of risks.

Uploaded by

Vaishnavi
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
11 views7 pages

Risk Assessment and Quantification Guide

Chapter 4 discusses risk assessment, covering risk identification, evaluation, quantification, and prioritization. It highlights the importance of documenting potential risks, using various techniques such as SWOT analysis, risk matrices, and the Delphi approach to assess and manage risks effectively. The chapter also addresses challenges in risk quantification and the significance of understanding both qualitative and quantitative aspects of risks.

Uploaded by

Vaishnavi
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter-4 Risk Assessment

MCQ Lines
1 Risk identification includes documenting the potential risks in the form of a risk questionnaire or risk
register and communicating the risks to the executive management.

2 Approaches to risk identification can involve either a top-down exercise from senior to junior levels or
vice versa, though empirical evidence suggests that top-down exercises tend to yield more favorable
outcomes for businesses.

3 Participants in the identification process include business managers, project teams, risk management
teams, subject matter experts, customers, end users, other project stakeholders, and external expert.

4 The risk management team should undertake a Strength, Weakness, Opportunity and Threat
assessment exercise so as to document the factors that could give rise to potential risks in future.

5 One of the best ways to identify risks is by flow-charting the key business processes and thereafter
undertaking a “what can go wrong exercise”.

6 Risk is the probability of impact of the exposure.

The purpose of a risk evaluation is to:

• Identify the probabilities of failures and threats,

• Calculate the exposure, i.e., the damage or loss to assets, and

• Make control recommendations keeping the cost-benefit analysis in mind.

7 Level of risk = consequence x likelihood

8 A risk analysis can be presented in the form a matrix, such as this:

Level Likelihood Description

4 Very likely Happens more than once a year in the industry

3 Likely Happens about once a year in the industry

2 Unlikely Happens every 10 years or more in the industry

1 Very unlikely Has only happened once in the industry

9 Example For example an organization based on its turnover and other factors can categories level of
risks it can face. Level Likelihood Description

4 Severe Financial losses greater than ₹ 50 Crores

3 High Financial losses between ₹ 10 to 50 Crores

2 Moderate Financial losses between ₹ 1 Crore to 10 Crore

1 Low Financial losses less than 1 Crore


10 Risk rating

Risk rating Description Risk Management Action

12-16 Severe Needs immediate corrective action

8-12 High Needs corrective action within 1 week

4-8 Moderate Needs corrective action within 1-2 month

1-4 Low Currently don’t require any corrective action on urgent


basis.

11 Risk Quantification is the process of evaluating and defining the cost and benefits associated with
the risk consequences.

12 Risk ratings are commonly used in credit risk assessment, investment analysis, and operational risk
managemnt.

13 Catastrophic events or black swan events that have not been previously observed can pose
challenges for risk quantification and ratings.

14 In numerous scenarios, both management and auditors rely on their judgment and intuition to
assess risks.

15 Delphi approach They assess factors such as costs, benefits, reasons for system selection, risks,
and exposures. These assessments are collated, and those falling within a predetermined acceptable
range are considered. The process may iterate up to four times to revise estimates outside the range.
Subsequently, a curve is plotted using all estimates as points on a graph, with the median representing
the consensus opinion.

16 The Delphi method is especially useful when dealing with complex or uncertain risk scenarios, as it
can help in systematically exploring and understanding the diverse perspectives of experts. It is often
used in various fields of risk management, including strategic risk assessment, technology risk
analysis, and environmental risk assessment, among others.

17 Scoring : Multiplying the risk weight by the exposure weight for each characteristic yields the
weighted score.

18 Quantitative techniques: These techniques involve the calculation of an annual loss exposure value
based on the probability of the event and the exposure in terms of estimated cost.

19 Qualitative techniques These techniques are most widely used approaches to risk analysis.

Threats: These are things that can go wrong or that can 'attack' the system.

Examples might include fire or fraud.

Threats are ever present for every system.

• Vulnerabilities: These make a system more prone to attack by a threat or make an attack more likely to
have some success or impact.
For example, for fire, vulnerability would be the presence of inflammable materials (e.g. Paper).

• Controls: These are the countermeasures for vulnerabilities.

They are of four types:

(i) Deterrent controls reduce the likelihood of a deliberate attack.

(ii) Preventative controls protect vulnerabilities and make an attack unsuccessful or reduce its
impact.

(iii) Corrective controls reduce the effect of an attack.

(iv) (iv) Detective controls discover attacks and trigger preventative or corrective controls.

20 Expected monetary value, a technique for quantifying risk, is determined by multiplying two factors:

• The likelihood of the risk event occurring, which is an estimation of its probability

. • The potential impact of the risk event, which is an estimation of the financial gain or loss associated
with its occurrence.

21 Most schedule simulations are based on some form of Monte Carlo analysis.

Monte Carlo simulation ties together sensitivities and probability distributions.

22 Casino gambling: Fundamental appeal of this analysis is that it provides decision makers with a
probability distribution of NPVs rather than a single point estimates of the expected NPV.

23 While drawing a decision tree, it should be noted that the:-

• The decision point (traditionally represented by square) is the option available for manager to take or
not to take - in other words action at these points.

• The event or chance or outcome (traditionally represented by circle) which are dependent on chance
process, along with the probabilities thereof, and monetary value associated with them.

24 The stages set for drawing a decision tree is based on the following rules.

It begins with a decision point, also known as decision node, represented by a rectangle while the
outcome point, also known as chance node, denoted by a circlle.

25 Scenario analysis is far more complex than sensitivity analysis because in scenario analysis all
inputs are changed simultaneously, considering the situation in hand while in sensitivity analysis, only
one input is changed, and others are kept constant.

26 A "Risk matrix" or "Heat map" in risk management is a visual representation of risks and their
attributes, typically using a matrix or grid format.

27 Many organisations map risks on a heat map using a “residual risk” basis. This considers only the
remaining risk after mitigation strategies such as internal controls or other risk responses activities.

CHAPTER
Risk Identification
First step in risk management, involving recognizing potential internal or external threats that may
impact an entity.

These risks are documented in a risk questionnaire or risk register and communicated to management.

The process requires a thorough understanding of the business environment, industry trends, and key
performance indicators (KPIs). The identification process can be top-down (from senior to junior levels)
or bottom-up, but evidence suggests top-down is more effective.

Key factors considered include legal, social, political, and economic aspects that impact business
operations. The SWOT (Strengths, Weaknesses, Opportunities, and Threats) analysis is commonly
used to identify risks.

Once risks are identified, they are analyzed based on:

• Internal vs. External factors

• Impact on business objectives

• Probability of occurrence

• Potential responses

A structured and systematic approach ensures no major business risks are overlooked.

Risk Evaluation (Impact/Likelihood)


Risk evaluation assesses the probability and impact of risks to prioritize responses. The formula for
risk level is:

Level of Risk = Consequence × Likelihood

Risk levels are categorized as low, medium, high, or very high, and mitigation efforts adjust these levels.

Likelihood Scale
4 (Very Likely): Happens multiple times a year. 3 (Likely): Happens once a year.

2 (Unlikely): Happens every 10 years or more. 1 (Very Unlikely): Has only happened once in the
industry.

Impact Scale (Financial Loss)


4 (Severe): Losses above ₹50 Crores. 3 (High): Losses between ₹10 - ₹50 Crores.

2 (Moderate): Losses between ₹1 - ₹10 Crores. 1 (Low): Losses below ₹1 Crore.

Using these scales, risk levels are computed, allowing businesses to develop risk mitigation strategies
based on urgency.

Risk Quantification & Ratings


Risk quantification involves assessing financial consequences associated with different risks. This
helps prioritize risk mitigation efforts.

Risk ratings provide a standardized numerical scale to express risk severity, commonly used in
financial, operational, and investment decisions.

Challenges in Risk Quantification


• Subjectivity in rating risks

• Over-reliance on historical data

• Difficulty in assessing rare (Black Swan) events

Risk quantification is crucial for prioritizing risks, allocating resources, and improving decision making.

Risk Quantification Tools


Various tools help assess and evaluate risks:

Judgment & Intuition

• Based on management and auditor experience. • Requires professional knowledge and

Delphi Approach

• Developed by Rand Corporation to achieve expert consensus.

• Experts provide input over multiple rounds until a consensus is reached.

Scoring Method

• Assigns weights to risks based on likelihood and impact. • Helps in ranking risks based on
severity.

Quantitative Techniques

• Uses probabilities to estimate annual financial losses from risks.

Qualitative Techniques

• Focuses on non-numerical risk evaluation. • Threats, vulnerabilities, and control measures are
analyzed.

Expected Monetary Value (EMV)

• Uses probability × financial impact to estimate risk cost. • Helps businesses assess investment
risks.

Simulation Techniques

• Monte Carlo simulations predict potential financial risks. • Used for investment and project risk
assessment.
Decision Tree Analysis

• Sequential decision-making tool.

• Represents choices, chance events, and outcomes.

• Helps in capital budgeting and investment decisions.

Expert Judgment

• Risk is categorized as high, medium, or low based on expert evaluation.

Frequency of Loss Measures

• Uses historical data to estimate future losses (e.g., bad debt estimation).

Scenario Analysis

• Evaluates the impact of different risk scenarios on financial performance.

• Used for economic downturns, market risks, and strategic planning.

Risk Prioritization & Risk Matrix


After identification and evaluation, risks are prioritized based on impact and likelihood.

A Risk Matrix (Heat Map) helps visually classify risks into:

Low (Green) – Minimal concern. Medium (Yellow) – Needs monitoring.

High (Orange) – Requires active mitigation. Severe (Red) – Immediate action required.

Benefits of Risk Matrix


• Visually identifies critical risks. • Helps allocate resources efficiently. • Improves decision-making
and communication.

Limitations of Risk Matrix


• Subjective interpretation of "High" or "Low" risks.

• Does not consider risk aversion of organizations.

• Broad categories may cause misprioritization.

Many organizations use residual risk analysis, which considers risks after applying mitigation
strategies.

1. One of the best ways to identify risks is by flow-charting the key business processes and thereafter
undertaking a “…………..”.

(a) Probability analysis (b) What can be best exercise

(c) What can go wrong exercise (d) Sensitivity analysis


2. Risk that happens more than once a year in the industry on the likelihood scale falls in Level…………

(a) 1 (b) 2 (c) 3 (d) 4

3. Risk that happens every 10 years or more in the industry on the likelihood scale falls in Level…………

(a) 1 (b) 2 (c) 3 (d) 4

4. Which of the following risks needs corrective action within 1 week?

(a) Risk rating of 1-4 (b) Risk rating of 4-8 (c) Risk rating of 8-12 (d) Risk rating of 12-
16

5. Which of the following Risk Quantification tools was originally developed by the Rand Corporation?

(a) Judgment and intuition (b) Delphi approach (c) Scoring (d) Simulation

Answers to Multiple Choice Questions: 1. (c) 5. (b) 2. (d) 3. (b) 4. (c)

You might also like