BST · Professional Level

Risk Management

Enterprise risk management (COSO ERM framework — components, risk appetite, risk culture), risk identification and assessment (risk registers, risk matrices — likelihood and impact scoring), risk response strategies (avoid, reduce, transfer, accept), categories of risk (operational, strategic, financial — currency, interest rate, credit — reputational, cyber), and business continuity planning (BCP and disaster recovery).

35 min read

Learning Objectives

  • Explain the COSO ERM framework and its key components
  • Describe the risk identification and assessment process, including risk registers and risk matrices
  • Explain and compare the four risk response strategies: avoid, reduce, transfer, and accept
  • Distinguish between operational, strategic, financial, reputational, and cyber risks
  • Explain financial risk management: currency, interest rate, and credit risk
  • Describe the principles of business continuity planning and disaster recovery
  • Explain the concepts of risk appetite, risk tolerance, and risk culture

Enterprise Risk Management — COSO ERM Framework

Enterprise Risk Management (ERM) is the process by which an organisation identifies, assesses, manages, and monitors risks across the entire enterprise in a coordinated, structured way. The goal is to manage the portfolio of risks within the organisation's risk appetite.

The COSO ERM Framework (Committee of Sponsoring Organizations, updated 2017) integrates ERM with strategy and performance. It consists of five interrelated components and 20 principles:

  1. Governance and culture: The board provides oversight of ERM. Management establishes operating structures. The organisation defines desired culture, demonstrates commitment to core values, and attracts/develops/retains capable individuals.
  2. Strategy and objective-setting: ERM is integrated into the strategic planning process. The organisation analyses the business context, defines risk appetite, evaluates alternative strategies, and formulates business objectives that align with strategy and risk appetite.
  3. Performance: The organisation identifies and assesses risks that may affect the achievement of objectives, prioritises risks based on severity (impact × likelihood), implements risk responses, and develops a portfolio view of risk.
  4. Review and revision: The organisation reviews entity performance and considers how well ERM components are functioning. It pursues improvement of ERM and reviews risk and performance on an ongoing basis.
  5. Information, communication, and reporting: The organisation leverages information systems to support ERM, communicates risk information across the entity, and reports on risk, culture, and performance to the board and stakeholders.

Risk appetite and risk tolerance:

  • Risk appetite: The broad level of risk an organisation is willing to accept in pursuit of its strategic objectives. Set by the board. Expressed qualitatively ("conservative," "moderate," "aggressive") or quantitatively (e.g., "willing to accept a maximum 5% probability of losses exceeding £10m in any year").
  • Risk tolerance: The acceptable variation in performance relative to a specific objective. More granular than risk appetite — applied at the operational level. Example: "revenue forecast variance of ±5% is tolerable."
  • Risk culture: The shared values, beliefs, and attitudes toward risk within the organisation. A strong risk culture means employees at all levels understand their role in managing risk, feel empowered to raise concerns, and make decisions consistent with the risk appetite.

Risk Identification and Assessment

Risk identification is the process of finding, recognising, and describing risks that could affect the achievement of objectives.

Methods of identification:

  • Brainstorming and workshops with management and operational staff
  • PESTEL and Five Forces analysis (external risks)
  • SWOT analysis (internal weaknesses and external threats)
  • Process mapping and value chain analysis (operational risks)
  • Historical analysis — reviewing past incidents, losses, and near-misses
  • Scenario planning — "what if" analysis of plausible future events
  • Internal audit findings and external audit management letters
  • Industry benchmarking — what risks are peers facing?

Risk register: A documented record of all identified risks, typically containing:

  • Risk description and category (operational, strategic, financial, etc.)
  • Risk owner (the person responsible for managing the risk)
  • Likelihood and impact assessment (before and after controls)
  • Existing controls (mitigations already in place)
  • Residual risk rating (risk remaining after existing controls)
  • Planned further actions and timeline
  • Status and review date

Risk matrix (heat map): A visual tool that plots risks on a grid of likelihood (probability of occurrence) × impact (severity of consequences). Typically scored on a scale (e.g., 1-5 for each axis). Risks in the top-right (high likelihood, high impact) are the most critical and require immediate action. Risks in the bottom-left are low priority.

Inherent risk vs residual risk:

  • Inherent risk: The risk level BEFORE any controls or mitigations are applied
  • Residual risk: The risk level AFTER controls are applied. The board's role is to ensure residual risks are within the risk appetite.

Risk Response Strategies

Once risks are assessed, the organisation selects an appropriate response strategy (sometimes called the "4 Ts"):

StrategyDescriptionWhen appropriateExamples
Avoid (Terminate)Eliminate the risk entirely by not undertaking the activity that gives rise to itThe risk is too high and cannot be adequately mitigated. The potential loss outweighs the potential reward.Deciding not to enter a politically unstable market. Discontinuing a dangerous product line. Not bidding for a high-risk contract.
Reduce (Treat)Take actions to reduce the likelihood and/or impact of the risk. The most common response.The risk can be brought within risk appetite through controls, processes, or investment.Implementing internal controls, diversifying suppliers, training staff, installing fire suppression systems, quality assurance processes, hedging (partial).
Transfer (Share)Transfer all or part of the risk to a third partyThe risk can be more efficiently borne by another party (insurer, partner, contractor).Insurance (property, liability, business interruption), outsourcing (transfer operational risk to specialist), hedging (transfer financial risk to counterparty), joint ventures (share commercial risk).
Accept (Tolerate)Acknowledge the risk and take no specific action — accept the potential consequencesThe risk is within risk appetite, the cost of mitigation exceeds the expected loss, or the risk cannot be practically reduced further.Accepting minor fluctuations in exchange rates (self-insuring small currency risk). Accepting normal business cycle risk. Accepting residual risk after controls are applied.

In practice: Most risks are managed through a combination of responses. For example, a company may reduce cyber risk through firewalls and training (reduce), purchase cyber insurance (transfer), accept residual risk below a threshold (accept), and decide not to store certain sensitive data (avoid).

Categories of Risk

Strategic risk: Risks arising from the strategic choices the organisation makes — entering the wrong market, choosing the wrong product, being disrupted by new technology, misreading competitor moves, M&A failure. Strategic risks are often the most significant because they affect the organisation's long-term viability.

Operational risk: Risks arising from the day-to-day operations — process failures, system outages, supply chain disruption, human error, fraud, health and safety incidents, quality failures, capacity constraints. Managed through internal controls, process improvement, and contingency planning.

Financial risk:

  • Currency (foreign exchange) risk: The risk that changes in exchange rates will adversely affect the value of foreign currency transactions, assets, or liabilities. Three types: transaction risk (impact on individual transactions — e.g., a receivable in USD may be worth less when converted to GBP), translation risk (impact on consolidation of foreign subsidiary results), economic risk (long-term competitiveness affected by exchange rate trends).
  • Interest rate risk: The risk that changes in interest rates will increase borrowing costs or reduce investment returns. Variable rate debt → higher interest payments if rates rise. Fixed rate debt → opportunity cost if rates fall. Managed through: interest rate swaps, caps, collars, and FRAs.
  • Credit risk: The risk that a counterparty will fail to meet its financial obligations — customer non-payment, counterparty default on a derivative contract. Managed through: credit checks, credit limits, credit insurance, diversification of customers/counterparties, collateral requirements.
  • Liquidity risk: The risk that the organisation cannot meet its short-term financial obligations — insufficient cash flow, inability to convert assets to cash quickly, loss of credit facilities.

Reputational risk: The risk of damage to the organisation's reputation — from poor customer service, product failures, data breaches, ethical scandals, environmental incidents, executive misconduct. Reputational damage can be catastrophic: loss of customers, difficulty attracting talent, share price decline, regulatory scrutiny. Often a secondary consequence of other risk events.

Cyber risk: The risk of financial loss, disruption, or reputational damage from failures in IT systems, data breaches, ransomware attacks, or cyber-espionage. Increasingly significant due to digital transformation and the value of data. Managed through: cybersecurity controls (firewalls, encryption, access management, patching), employee training (phishing awareness), incident response plans, cyber insurance, and regular penetration testing.

Business Continuity Planning

Business continuity planning (BCP) ensures that critical business functions can continue or be rapidly restored following a disruptive event — natural disaster, fire, flood, cyber attack, pandemic, supply chain failure, or major system outage.

Key elements of a BCP:

  1. Business impact analysis (BIA): Identify critical business processes and the impact of their disruption. Determine the recovery time objective (RTO) — the maximum acceptable time before a process must be restored — and the recovery point objective (RPO) — the maximum acceptable data loss (measured in time).
  2. Risk assessment: Identify the threats most likely to cause disruption and their potential impact (using the risk matrix).
  3. Continuity strategies: Develop strategies to maintain or restore critical functions — alternative work locations (hot/warm/cold sites), backup systems and data recovery, alternative suppliers, manual workarounds, remote working capability.
  4. Plan documentation: A written plan detailing: responsibilities, contact lists (crisis team, key personnel, suppliers, regulators), activation procedures, recovery procedures, communication plan (employees, customers, media).
  5. Testing and exercising: Regular testing of the plan — tabletop exercises (walk-through discussion), simulation exercises (realistic scenario), full interruption tests. Identify weaknesses and update the plan.
  6. Maintenance and review: The plan must be kept current — reviewed at least annually and after any major organisational change, incident, or test. Assign a plan owner.

Disaster recovery (DR): A subset of BCP focused specifically on the recovery of IT systems and data after a disruptive event. Includes: backup strategies (on-site, off-site, cloud), failover systems, data replication, and IT recovery procedures.

Examiner Focus

Risk management questions typically present a scenario and ask you to: (1) IDENTIFY the key risks, (2) CLASSIFY them (operational, strategic, financial, reputational, cyber), (3) ASSESS likelihood and impact, (4) RECOMMEND appropriate responses (avoid, reduce, transfer, accept). Use a structured approach — a risk register format scores well.

Common Pitfall

Students often recommend only ONE response per risk. In practice, MULTIPLE responses are usually combined — e.g., reduce (implement controls) + transfer (insurance) + accept (residual). Show the examiner you understand that risk responses are layered, not binary.

Study Tip

COSO ERM 2017: five components (governance/culture, strategy/objectives, performance, review/revision, information/communication). The key change from the 2004 version is the emphasis on integrating ERM with STRATEGY — risk appetite should be set during strategic planning, not after. This is a frequently tested point.

Examiner Focus

Know the difference between risk appetite (broad level set by the board — "how much risk are we willing to take?") and risk tolerance (specific acceptable variation at the operational level — "±5% revenue variance"). Risk appetite is strategic; risk tolerance is tactical.

Watch Out

Inherent risk vs residual risk: inherent = BEFORE controls, residual = AFTER controls. The board's role is to ensure RESIDUAL risk is within appetite. If the examiner asks about the effectiveness of risk management, evaluate whether the controls reduce the inherent risk to an acceptable residual level.

Study Tip

BCP: know the key elements — BIA (identify critical processes, set RTO and RPO), continuity strategies, plan documentation, testing (tabletop, simulation, full interruption), and maintenance (annual review). The examiner may ask you to critique a BCP or recommend improvements.

Written Practice

Risk Management: Applied Requirement

Prepare a focused written answer with clear workings and justified recommendations.

22 mins · 12 marks

A client has asked for a concise exam-style written response for a client or senior manager on risk management. Use the key rules, calculations, risks, and professional judgement from this topic to structure your answer.

Answer Prompts

  • Identify the issue and explain why it matters in the scenario.
  • Apply the relevant technical rule, calculation, or framework.
  • State the commercial, ethical, tax, reporting, or assurance implication.
  • Conclude with a clear recommendation or exam-ready judgement.

Marking Focus

  • Application to facts rather than textbook recall
  • Clear structure and answer-first communication
  • Balanced judgement where there is uncertainty
  • Commercially sensible conclusion

Key Definitions

Enterprise risk management (ERM)

Organisation-wide, coordinated process for identifying, assessing, managing, and monitoring risks to achieve objectives within risk appetite. COSO ERM framework: five components (governance/culture, strategy, performance, review, information/communication).

Risk appetite

The broad level of risk the organisation is willing to accept in pursuit of objectives. Set by the board. May be qualitative or quantitative.

Risk tolerance

The acceptable variation in performance relative to a specific objective. More granular than risk appetite — applied at the operational level.

Risk register

Documented record of all identified risks: description, category, owner, likelihood, impact, existing controls, residual rating, planned actions, status.

Risk matrix (heat map)

Visual tool plotting risks by likelihood × impact. Top-right (high/high) = critical priority. Bottom-left (low/low) = low priority. Used for risk prioritisation.

Inherent risk vs residual risk

Inherent = risk before controls. Residual = risk after controls. The board ensures residual risks are within risk appetite.

Avoid (terminate)

Eliminate the risk by not undertaking the activity. Appropriate when risk is too high and cannot be mitigated. Most drastic response.

Reduce (treat)

Take actions to reduce likelihood and/or impact. Most common response. Examples: controls, training, diversification, process improvement.

Transfer (share)

Transfer all or part of the risk to a third party: insurance, outsourcing, hedging, joint ventures. The third party bears the risk (for a price).

Accept (tolerate)

Acknowledge the risk and take no specific action. Appropriate when: risk is within appetite, mitigation cost exceeds expected loss, or risk cannot be further reduced.

Business continuity plan (BCP)

Plan ensuring critical functions continue or are rapidly restored after disruption. Includes: BIA (identify critical processes, RTO, RPO), continuity strategies, documentation, testing, and maintenance.

Recovery time objective (RTO)

Maximum acceptable time before a critical process must be restored after disruption. A key parameter in BCP.

Key Formulas

Worked Examples

Key Takeaways

  • ERM: organisation-wide risk management integrated with strategy. COSO ERM 2017: five components (governance/culture, strategy/objectives, performance, review, information/communication). Links risk to strategy and performance.
  • Risk appetite (board-level, strategic) vs risk tolerance (operational, specific). Risk culture: shared values about risk at all levels. The board sets appetite and ensures residual risks are within it.
  • Risk identification: brainstorming, PESTEL/SWOT, process mapping, historical analysis, scenario planning, internal audit. Document in a risk register (description, owner, likelihood, impact, controls, residual rating, actions).
  • Risk matrix: likelihood × impact visual tool. Inherent risk (before controls) vs residual risk (after controls). Prioritise: top-right (high/high) = critical.
  • Risk responses (4 Ts): Terminate/avoid (don't do the activity), Treat/reduce (controls, diversification), Transfer/share (insurance, hedging, outsourcing), Tolerate/accept (within appetite). Usually combined for each risk.
  • Risk categories: strategic (wrong markets, disruption), operational (process/system failures), financial (currency, interest rate, credit, liquidity), reputational (brand damage), cyber (data breach, ransomware).
  • Financial risk: currency (transaction, translation, economic), interest rate (variable rate exposure), credit (counterparty default), liquidity (cash flow shortfall). Managed through hedging, insurance, diversification, controls.
  • BCP: BIA (critical processes, RTO, RPO) → continuity strategies (alternative sites, backups) → plan documentation → testing (tabletop, simulation, full) → maintenance (annual review). DR = IT-specific subset of BCP.

Practice Questions

Question 1 of 8

The COSO ERM 2017 framework consists of how many components?

Question 2 of 8

Risk appetite is best described as:

Question 3 of 8

Transferring risk to a third party is an example of the risk response strategy called:

Question 4 of 8

Residual risk is:

Question 5 of 8

Transaction risk is a type of:

Question 6 of 8

A Business Impact Analysis (BIA) in a BCP identifies:

Question 7 of 8

The "4 Ts" of risk response are:

Question 8 of 8

A risk matrix plots risks on axes of:

Source and Version

Syllabus: ICAEW ACA Professional Level 2026 · Reviewed: 2026-05-04

ICAEW ACA syllabusLocal syllabus coverage review