Skip to content

ACCA Strategic Professional · Strategic Business Leader

Identification, assessment and measurement of risk: formula sheet

Full chapter guide

Key formulas

Definition of risk
Risk = uncertain event that could affect achievement of objectives
Always link each risk to a specific objective in the scenario.
Main risk categories
Strategic | Operational | Financial | Compliance | Other (reputational, technological, environmental, political, fraud)
A working checklist. Categories can overlap, so label by the main cause.
Business vs non-business risk
Business risk = linked to the organisation's own strategic and operating choices, taken to earn a return. Non-business risk = arises outside those choices, with no return for bearing it
Sources differ slightly on the boundary. State your definition and apply it consistently.
Identification sources
External (PESTEL, Five Forces) + Internal (SWOT, value chain, processes) + Stakeholders and past events
Use these as prompts to find risks that the case hides.
Expected value of a risk
Expected loss = Probability of event × Financial impact
Use only when you can estimate both numbers. Example: 10% × ₹50,00,000 = ₹5,00,000. It ignores non-financial impact and hides rare but catastrophic events.
Risk score (qualitative)
Risk score = Likelihood rating × Impact rating
Ratings are often 1 to 5. A score of 4 × 5 = 20 ranks above 3 × 3 = 9. The scale is a judgement tool, so state your scale.
Inherent and residual risk
Residual risk = Inherent risk after the effect of controls
Assess both. A big gap shows controls are doing the work, so their failure matters.
Risk map response guide
High/High = avoid or reduce; Low likelihood/High impact = transfer or plan; High likelihood/Low impact = control; Low/Low = accept
A guide only. Link to TARA: transfer, avoid, reduce, accept.
Expected value (EV)
EV = Σ (probability × outcome)
Probabilities must add up to 1. EV is a long-run average, not a likely single result.
Sensitivity (percentage change)
Sensitivity = (NPV or profit ÷ value of the variable) × 100%
This shows the percentage change in the variable that makes the result zero. The smaller the percentage, the more sensitive the project is to that variable.
Value at risk (normal distribution)
VaR = z × σ × √t (with the mean assumed to be zero)
σ is the standard deviation per period, t is the number of periods, and z is the confidence-level factor. For 95% one-tailed, z = 1.65. For 99% one-tailed, z = 2.33. Multiply by the position value if σ is a percentage.
Risk appetite
Risk appetite = amount and type of risk the organisation is willing to take to achieve its objectives
Broad, board-level stance. It can differ for each risk category.
Risk tolerance
Risk tolerance = acceptable variation from a specific objective or target
Specific and measurable. Used for monitoring and escalation.
Risk capacity
Risk capacity = maximum risk the organisation can bear
Set by financial strength, liquidity, regulation and resources. Appetite should stay within it.
Risk attitudes
Averse: prefers lower risk | Neutral: ignores risk, compares expected returns | Seeking: attracted to higher risk
Attitudes belong to people and stakeholder groups. Appetite belongs to the organisation.
Risk chain
Source → Cause → Effect
Use it to structure any risk description. Each risk should show all three links.
Risk rating (common approach)
Risk rating = likelihood × impact
Used to rank risks on a register or heat map. It is a ranking tool, not an exact measure, so state your scoring scale.
TARA responses
Transfer | Avoid | Reduce | Accept
Match the response to likelihood, impact, cost and risk appetite. Say why the others are less suitable.
Typical risk register columns
Risk | Source | Likelihood | Impact | Rating | Response | Owner | Status
Exact layout varies. Always include a response and an owner.
Fraud triangle
Fraud = Opportunity + Pressure + Rationalisation
Use it to explain why fraud may occur and which controls reduce opportunity. It is a framework, not a calculation.
Risk assessment
Risk exposure = Likelihood × Impact
A qualitative guide. Rate each as high, medium or low. Do not invent figures the case does not give.
Risk responses (TARA)
Transfer, Avoid, Reduce, Accept
Choose a response for each risk and justify it using likelihood, impact and cost.

Quick revision

  • Risk is uncertainty about outcomes that can affect objectives, and it can include upside as well as downside.
  • Identify risks first, then categorise them, then assess them, then measure them.
  • Assess each risk on likelihood and impact, and explain both using facts from the scenario.
  • A risk with low likelihood but severe impact still needs attention and a planned response.
  • Risk appetite is the amount of risk an organisation is willing to take to pursue its objectives.
  • Risk tolerance is the acceptable variation around a particular objective, so it is more specific than appetite.
  • Risk attitude is how the board and managers feel about risk, which shapes the appetite they set.
  • Quantitative tools give numbers but depend on assumptions, so always comment on their limits.
  • Qualitative assessment is useful when data is poor or the risk is hard to value, such as reputation.
  • Fraud risk needs motive, opportunity and a way to justify the act, and controls aim to reduce opportunity.
  • Reputation risk can follow from other failures, so link it to its cause and the stakeholders affected.
  • In the exam, apply each point to the case and finish with a clear recommendation.

Common mistakes

  • Listing generic risks that could apply to any company. Fix: Quote or paraphrase a case fact for every risk, and state the effect on this organisation's objectives.
  • Naming a category only, such as 'operational risk', without saying what the risk is. Fix: Write the cause, the event and the consequence. The label is secondary.
  • Listing risks without rating likelihood or impact Fix: Give every risk a likelihood and an impact, each with a reason from the case.
  • Judging risks by impact alone Fix: Always combine both scales. A frequent medium-sized loss can matter more than a remote one.
  • Treating expected value as the outcome that will happen. Fix: State that EV is a weighted average over many repeats. Say the actual result may be very different, especially for one-off decisions.
  • Confusing sensitivity analysis with scenario analysis. Fix: Sensitivity changes one variable at a time. Scenario analysis changes several variables together in a consistent story.
  • Using appetite and tolerance as if they mean the same thing. Fix: Say appetite is the broad stance and tolerance is the acceptable deviation from a specific target.
  • Ignoring risk capacity. Fix: Check cash, gearing, covenants and regulation. Point out when appetite exceeds capacity.
  • Listing generic risks that are not in the scenario. Fix: Use scenario facts and name the company, product, market or event for every risk.
  • Mixing up source, cause and effect. Fix: Write them as a chain. Ask: where does it start, what triggers it, and what happens to the business.

Exam tips

  • Always tie each risk to a fact in the case. Generic lists score poorly.
  • Write risks as cause, event and consequence, then add the category in brackets.
  • Do not agonise over the category. Overlap is normal, so justify your choice briefly.
  • Prioritise the most significant risks and say why. This shows commercial judgement and earns professional skills marks.
  • Answer only what is asked. If the task is identification, do not spend your time on detailed responses.
  • Always justify a rating with a fact from the case. A bare 'high' earns little credit.
  • If asked to prioritise, give a clear order and the reason for it. Do not stop at a list.
  • Draw a simple risk map only if it helps, and always explain it in words. Label axes and name the risks.