ACCA Strategic Professional · Strategic Business Leader
Identification, assessment and measurement of risk: formula sheet
Key formulas
- Definition of risk
- Risk = uncertain event that could affect achievement of objectives
- Always link each risk to a specific objective in the scenario.
- Main risk categories
- Strategic | Operational | Financial | Compliance | Other (reputational, technological, environmental, political, fraud)
- A working checklist. Categories can overlap, so label by the main cause.
- Business vs non-business risk
- Business risk = linked to the organisation's own strategic and operating choices, taken to earn a return. Non-business risk = arises outside those choices, with no return for bearing it
- Sources differ slightly on the boundary. State your definition and apply it consistently.
- Identification sources
- External (PESTEL, Five Forces) + Internal (SWOT, value chain, processes) + Stakeholders and past events
- Use these as prompts to find risks that the case hides.
- Expected value of a risk
- Expected loss = Probability of event × Financial impact
- Use only when you can estimate both numbers. Example: 10% × ₹50,00,000 = ₹5,00,000. It ignores non-financial impact and hides rare but catastrophic events.
- Risk score (qualitative)
- Risk score = Likelihood rating × Impact rating
- Ratings are often 1 to 5. A score of 4 × 5 = 20 ranks above 3 × 3 = 9. The scale is a judgement tool, so state your scale.
- Inherent and residual risk
- Residual risk = Inherent risk after the effect of controls
- Assess both. A big gap shows controls are doing the work, so their failure matters.
- Risk map response guide
- High/High = avoid or reduce; Low likelihood/High impact = transfer or plan; High likelihood/Low impact = control; Low/Low = accept
- A guide only. Link to TARA: transfer, avoid, reduce, accept.
- Expected value (EV)
- EV = Σ (probability × outcome)
- Probabilities must add up to 1. EV is a long-run average, not a likely single result.
- Sensitivity (percentage change)
- Sensitivity = (NPV or profit ÷ value of the variable) × 100%
- This shows the percentage change in the variable that makes the result zero. The smaller the percentage, the more sensitive the project is to that variable.
- Value at risk (normal distribution)
- VaR = z × σ × √t (with the mean assumed to be zero)
- σ is the standard deviation per period, t is the number of periods, and z is the confidence-level factor. For 95% one-tailed, z = 1.65. For 99% one-tailed, z = 2.33. Multiply by the position value if σ is a percentage.
- Risk appetite
- Risk appetite = amount and type of risk the organisation is willing to take to achieve its objectives
- Broad, board-level stance. It can differ for each risk category.
- Risk tolerance
- Risk tolerance = acceptable variation from a specific objective or target
- Specific and measurable. Used for monitoring and escalation.
- Risk capacity
- Risk capacity = maximum risk the organisation can bear
- Set by financial strength, liquidity, regulation and resources. Appetite should stay within it.
- Risk attitudes
- Averse: prefers lower risk | Neutral: ignores risk, compares expected returns | Seeking: attracted to higher risk
- Attitudes belong to people and stakeholder groups. Appetite belongs to the organisation.
- Risk chain
- Source → Cause → Effect
- Use it to structure any risk description. Each risk should show all three links.
- Risk rating (common approach)
- Risk rating = likelihood × impact
- Used to rank risks on a register or heat map. It is a ranking tool, not an exact measure, so state your scoring scale.
- TARA responses
- Transfer | Avoid | Reduce | Accept
- Match the response to likelihood, impact, cost and risk appetite. Say why the others are less suitable.
- Typical risk register columns
- Risk | Source | Likelihood | Impact | Rating | Response | Owner | Status
- Exact layout varies. Always include a response and an owner.
- Fraud triangle
- Fraud = Opportunity + Pressure + Rationalisation
- Use it to explain why fraud may occur and which controls reduce opportunity. It is a framework, not a calculation.
- Risk assessment
- Risk exposure = Likelihood × Impact
- A qualitative guide. Rate each as high, medium or low. Do not invent figures the case does not give.
- Risk responses (TARA)
- Transfer, Avoid, Reduce, Accept
- Choose a response for each risk and justify it using likelihood, impact and cost.
Quick revision
- Risk is uncertainty about outcomes that can affect objectives, and it can include upside as well as downside.
- Identify risks first, then categorise them, then assess them, then measure them.
- Assess each risk on likelihood and impact, and explain both using facts from the scenario.
- A risk with low likelihood but severe impact still needs attention and a planned response.
- Risk appetite is the amount of risk an organisation is willing to take to pursue its objectives.
- Risk tolerance is the acceptable variation around a particular objective, so it is more specific than appetite.
- Risk attitude is how the board and managers feel about risk, which shapes the appetite they set.
- Quantitative tools give numbers but depend on assumptions, so always comment on their limits.
- Qualitative assessment is useful when data is poor or the risk is hard to value, such as reputation.
- Fraud risk needs motive, opportunity and a way to justify the act, and controls aim to reduce opportunity.
- Reputation risk can follow from other failures, so link it to its cause and the stakeholders affected.
- In the exam, apply each point to the case and finish with a clear recommendation.
Common mistakes
- Listing generic risks that could apply to any company. Fix: Quote or paraphrase a case fact for every risk, and state the effect on this organisation's objectives.
- Naming a category only, such as 'operational risk', without saying what the risk is. Fix: Write the cause, the event and the consequence. The label is secondary.
- Listing risks without rating likelihood or impact Fix: Give every risk a likelihood and an impact, each with a reason from the case.
- Judging risks by impact alone Fix: Always combine both scales. A frequent medium-sized loss can matter more than a remote one.
- Treating expected value as the outcome that will happen. Fix: State that EV is a weighted average over many repeats. Say the actual result may be very different, especially for one-off decisions.
- Confusing sensitivity analysis with scenario analysis. Fix: Sensitivity changes one variable at a time. Scenario analysis changes several variables together in a consistent story.
- Using appetite and tolerance as if they mean the same thing. Fix: Say appetite is the broad stance and tolerance is the acceptable deviation from a specific target.
- Ignoring risk capacity. Fix: Check cash, gearing, covenants and regulation. Point out when appetite exceeds capacity.
- Listing generic risks that are not in the scenario. Fix: Use scenario facts and name the company, product, market or event for every risk.
- Mixing up source, cause and effect. Fix: Write them as a chain. Ask: where does it start, what triggers it, and what happens to the business.
Exam tips
- Always tie each risk to a fact in the case. Generic lists score poorly.
- Write risks as cause, event and consequence, then add the category in brackets.
- Do not agonise over the category. Overlap is normal, so justify your choice briefly.
- Prioritise the most significant risks and say why. This shows commercial judgement and earns professional skills marks.
- Answer only what is asked. If the task is identification, do not spend your time on detailed responses.
- Always justify a rating with a fact from the case. A bare 'high' earns little credit.
- If asked to prioritise, give a clear order and the reason for it. Do not stop at a list.
- Draw a simple risk map only if it helps, and always explain it in words. Label axes and name the risks.