Home
Part 2 · Section D

Risk Management

Enterprise risk management under COSO ERM 2017: the types of risk a company faces, how much risk it is willing to take, how risks are assessed and prioritized, how exposure is measured (including value at risk), and how management responds. This section is 10% of Part 2.

About 10 of the 100 multiple-choice questions. Estimated study time: 12 hours.

0%Section readiness
0 / 1Topics complete
—MCQ accuracy
12 hEstimated study time

Your learning path

One topic with six lessons: risk types, COSO ERM 2017, appetite and tolerance, assessment, measurement, and responses.

0% of topics complete
Topic 1 of 1

Enterprise risk

Identifying, assessing, measuring and responding to risk across the whole organization, in line with its strategy and risk appetite.

Types of riskStrategic, operational, financial, hazard, compliance
Categories of risk
Type Source Examples
Strategic Choices about markets, products, competition and the business model A disruptive competitor, a failed acquisition, changing customer preferences
Operational Failed or inadequate processes, people and systems Supply-chain breakdown, IT outage, fraud, quality failure
Financial Market prices and counterparties Market (interest rates, FX, commodities), credit (customer default), liquidity (cannot fund obligations)
Hazard Insurable events causing loss Fire, natural disasters, injuries, property damage
Compliance / legal Laws and regulations Fines, sanctions, product-liability lawsuits

Reputational risk usually arises as a consequence of other risks (a data breach, an ethics scandal) and can be the most damaging.

Exam trapHazard risks are typically managed by insurance (sharing); financial risks by hedging. Strategic risk cannot be insured: it is managed through strategy itself.
COSO ERM 2017Integrating with strategy and performance

COSO's 2017 framework treats ERM as part of setting and carrying out strategy, not as a separate compliance exercise. It is organized into five interrelated components supported by twenty principles (summarized here in short form):

COSO ERM 2017 components and principles
Component Principles (short form)
1. Governance and culture 1 board oversight of risk; 2 operating structures; 3 desired culture; 4 commitment to core values; 5 attracting, developing and retaining capable people
2. Strategy and objective-setting 6 analyze business context; 7 define risk appetite; 8 evaluate alternative strategies; 9 formulate business objectives
3. Performance 10 identify risk; 11 assess severity; 12 prioritize risks; 13 implement responses; 14 develop a portfolio view
4. Review and revision 15 assess substantial change; 16 review risk and performance; 17 pursue improvement in ERM
5. Information, communication and reporting 18 leverage information and technology; 19 communicate risk information; 20 report on risk, culture and performance
COSO ERM 2017 at a glance

5 components, 20 principles: governance and culture (1–5), strategy and objective-setting (6–9), performance (10–14), review and revision (15–17), information, communication and reporting (18–20).

  • Portfolio view: considering risks together across the entity, not one by one, to see aggregate exposure relative to appetite.
  • Roles: the board oversees; management (often a chief risk officer) runs ERM; the three lines model separates risk owners, risk and compliance functions, and internal audit.
Exam trapCOSO ERM 2017 is not the 2013 Internal Control framework. ERM's components start with governance and culture and strategy and objective-setting; "control activities" is an internal-control component, not an ERM one.
Risk appetite, tolerance and capacityHow much risk is acceptable
  • Risk capacity: the maximum risk the organization can absorb before failing (set by its capital, liquidity and borrowing ability).
  • Risk appetite: the types and broad amount of risk the organization is willing to accept in pursuing value; set by management with board oversight, and lower than capacity.
  • Risk tolerance: the acceptable variation in performance around a specific objective (for example, "on-time delivery between 94% and 98%"); it operationalizes appetite.
  • Risk profile: the organization's actual combined exposure at a point in time.
Exam trapAppetite is broad and strategic; tolerance is specific and measurable around an objective. A question quoting a numeric range for one metric is describing tolerance.
Assessment: likelihood, impact and heat mapsPrioritizing what matters
Heat-map score
$$\text{Score} = \text{Likelihood}_{1\text{–}5} \times \text{Impact}_{1\text{–}5}$$

Here: 15–25 high, 8–14 medium, 1–7 low. Organizations set their own bands.

Expected loss
$$E(\text{Loss}) = p \times \text{Impact}$$

Inherent risk: before responses. Residual risk: after responses.

Exam trapA low-likelihood, catastrophic-impact risk can score the same as a frequent, minor one. Do not rely on the score alone: severe impacts may need a response even when likelihood is low.
Measuring exposure: value at risk and related toolsHow bad can it get?

Value at risk (VaR) is the maximum loss expected over a given period at a given confidence level under normal market conditions: a 1-day 95% VaR of $250,000 means losses should exceed $250,000 on only about 5% of days.

Parametric (variance-covariance) VaR
$$VaR = z \times \sigma \times \sqrt{t} \times \text{Position value}$$

One-tailed z: 1.645 at 95%, 2.326 at 99%. σ = standard deviation of returns per period; t = number of periods.

  • Cash flow at risk and earnings at risk apply the same idea to cash flows and earnings for non-financial companies.
  • VaR says nothing about the size of losses beyond the threshold; supplement it with stress tests and scenario analysis.
Exam trapVaR is not the worst possible loss. On the 5% (or 1%) of days beyond the threshold, losses can be much larger, which is why stress testing is needed.
Risk responsesAccept, avoid, reduce, share (and pursue)
Risk responses
Response What it does Example
Accept (retain) No action beyond monitoring; the risk is within appetite or costs more to treat than it would lose Small inventory shrinkage
Avoid Exit or do not start the activity Withdrawing from a politically unstable market
Reduce (mitigate) Lower likelihood or impact through controls or actions Dual sourcing, backups, safety training
Share (transfer) Move part of the risk to another party Insurance, hedging, outsourcing, joint ventures
Pursue (COSO 2017) Accept more risk to improve performance Expanding into a new market to grow
Cost-benefit of a response
$$\text{Total cost} = E(\text{Residual loss}) + \text{Cost of response}$$

Choose the response with the lowest total cost that keeps residual risk within appetite.

Exam trapInsurance and hedging share (transfer) risk; they do not avoid it. Avoidance means not doing the activity at all.
Instructor noteFor classification questions, ask two things: did the company stop the activity (avoid), or keep it? If it kept it, did it change the risk itself (reduce), move it to someone else (share), or do nothing (accept)?

Finished Enterprise risk?

Mark it complete when you can map an activity to COSO ERM, score a risk, compute VaR and choose a response.

Calculators

Interactive tools

Each tool is pre-filled with an example from the lessons. Change any input; the results show the method, your numbers and what they mean.

Risk heat map

Add risks with a likelihood and impact rating (1–5), choose a response for each, and see them plotted. The map flags high risks that are only being accepted, which would normally fall outside a company's appetite.

Add a risk

Print-ready

Formula sheet

Every formula and framework in Risk Management on one sheet. Print it from here: the sidebar is hidden and the sheet prints black on white.

Spaced repetition

Flashcards

Recall first, then flip. Your grade schedules the next review (SM-2-lite).

Exam-style questions

Practice MCQs

Practice mode gives instant feedback; timed mode allows 1.8 minutes per question, like the exam. Filter by topic, difficulty, or questions you missed.

Essay section

Written-response practice

Write your answer first (aim for about 30 minutes per case), then compare it with the model answer and score yourself against the rubric. Show your calculations: the exam awards marks for method.

Key terms

Glossary

Search the section's vocabulary. Underlined terms in the lessons show these definitions on hover or keyboard focus.