Risk Management
Enterprise risk management under COSO ERM 2017: the types of risk a company faces, how much risk it is willing to take, how risks are assessed and prioritized, how exposure is measured (including value at risk), and how management responds. This section is 10% of Part 2.
About 10 of the 100 multiple-choice questions. Estimated study time: 12 hours.
Your learning path
One topic with six lessons: risk types, COSO ERM 2017, appetite and tolerance, assessment, measurement, and responses.
Enterprise risk
Identifying, assessing, measuring and responding to risk across the whole organization, in line with its strategy and risk appetite.
Types of riskStrategic, operational, financial, hazard, compliance
| Type | Source | Examples |
|---|---|---|
| Strategic | Choices about markets, products, competition and the business model | A disruptive competitor, a failed acquisition, changing customer preferences |
| Operational | Failed or inadequate processes, people and systems | Supply-chain breakdown, IT outage, fraud, quality failure |
| Financial | Market prices and counterparties | Market (interest rates, FX, commodities), credit (customer default), liquidity (cannot fund obligations) |
| Hazard | Insurable events causing loss | Fire, natural disasters, injuries, property damage |
| Compliance / legal | Laws and regulations | Fines, sanctions, product-liability lawsuits |
Reputational risk usually arises as a consequence of other risks (a data breach, an ethics scandal) and can be the most damaging.
COSO ERM 2017Integrating with strategy and performance
COSO's 2017 framework treats ERM as part of setting and carrying out strategy, not as a separate compliance exercise. It is organized into five interrelated components supported by twenty principles (summarized here in short form):
| Component | Principles (short form) |
|---|---|
| 1. Governance and culture | 1 board oversight of risk; 2 operating structures; 3 desired culture; 4 commitment to core values; 5 attracting, developing and retaining capable people |
| 2. Strategy and objective-setting | 6 analyze business context; 7 define risk appetite; 8 evaluate alternative strategies; 9 formulate business objectives |
| 3. Performance | 10 identify risk; 11 assess severity; 12 prioritize risks; 13 implement responses; 14 develop a portfolio view |
| 4. Review and revision | 15 assess substantial change; 16 review risk and performance; 17 pursue improvement in ERM |
| 5. Information, communication and reporting | 18 leverage information and technology; 19 communicate risk information; 20 report on risk, culture and performance |
5 components, 20 principles: governance and culture (1–5), strategy and objective-setting (6–9), performance (10–14), review and revision (15–17), information, communication and reporting (18–20).
- Portfolio view: considering risks together across the entity, not one by one, to see aggregate exposure relative to appetite.
- Roles: the board oversees; management (often a chief risk officer) runs ERM; the three lines model separates risk owners, risk and compliance functions, and internal audit.
Risk appetite, tolerance and capacityHow much risk is acceptable
- Risk capacity: the maximum risk the organization can absorb before failing (set by its capital, liquidity and borrowing ability).
- Risk appetite: the types and broad amount of risk the organization is willing to accept in pursuing value; set by management with board oversight, and lower than capacity.
- Risk tolerance: the acceptable variation in performance around a specific objective (for example, "on-time delivery between 94% and 98%"); it operationalizes appetite.
- Risk profile: the organization's actual combined exposure at a point in time.
Assessment: likelihood, impact and heat mapsPrioritizing what matters
Here: 15–25 high, 8–14 medium, 1–7 low. Organizations set their own bands.
Inherent risk: before responses. Residual risk: after responses.
Building a heat map
A manufacturer rates three risks on 1–5 scales: key supplier failure (likelihood 4, impact 5); a cyber-attack on its ordering system (2, 4); a minor regulatory fine (1, 3). The supplier failure is estimated at a 20% annual probability with a $2.5 million impact.
Measuring exposure: value at risk and related toolsHow bad can it get?
Value at risk (VaR) is the maximum loss expected over a given period at a given confidence level under normal market conditions: a 1-day 95% VaR of $250,000 means losses should exceed $250,000 on only about 5% of days.
One-tailed z: 1.645 at 95%, 2.326 at 99%. σ = standard deviation of returns per period; t = number of periods.
- Cash flow at risk and earnings at risk apply the same idea to cash flows and earnings for non-financial companies.
- VaR says nothing about the size of losses beyond the threshold; supplement it with stress tests and scenario analysis.
VaR on a $10 million portfolio
The daily standard deviation of returns is 1.5%.
Risk responsesAccept, avoid, reduce, share (and pursue)
| Response | What it does | Example |
|---|---|---|
| Accept (retain) | No action beyond monitoring; the risk is within appetite or costs more to treat than it would lose | Small inventory shrinkage |
| Avoid | Exit or do not start the activity | Withdrawing from a politically unstable market |
| Reduce (mitigate) | Lower likelihood or impact through controls or actions | Dual sourcing, backups, safety training |
| Share (transfer) | Move part of the risk to another party | Insurance, hedging, outsourcing, joint ventures |
| Pursue (COSO 2017) | Accept more risk to improve performance | Expanding into a new market to grow |
Choose the response with the lowest total cost that keeps residual risk within appetite.
Responding to supplier failure
Inherent expected loss is $500,000 (20% × $2.5 million). Insurance would cost $380,000 a year and leave a $50,000 expected loss (deductibles). Dual sourcing would cost $200,000 a year, halving the likelihood and cutting the impact by 40%.
Finished Enterprise risk?
Mark it complete when you can map an activity to COSO ERM, score a risk, compute VaR and choose a response.
Interactive tools
Each tool is pre-filled with an example from the lessons. Change any input; the results show the method, your numbers and what they mean.
Risk heat map
Add risks with a likelihood and impact rating (1–5), choose a response for each, and see them plotted. The map flags high risks that are only being accepted, which would normally fall outside a company's appetite.
Formula sheet
Every formula and framework in Risk Management on one sheet. Print it from here: the sidebar is hidden and the sheet prints black on white.
Flashcards
Recall first, then flip. Your grade schedules the next review (SM-2-lite).
Practice MCQs
Practice mode gives instant feedback; timed mode allows 1.8 minutes per question, like the exam. Filter by topic, difficulty, or questions you missed.
Written-response practice
Write your answer first (aim for about 30 minutes per case), then compare it with the model answer and score yourself against the rubric. Show your calculations: the exam awards marks for method.
Glossary
Search the section's vocabulary. Underlined terms in the lessons show these definitions on hover or keyboard focus.