ACCA Strategic Professional · Strategic Business Leader
Identification, Assessment and Measurement of Risk for SBL
This SBL chapter covers how an organisation finds its risks, sorts them, judges how likely and how damaging they are, and measures them against its appetite. To solve a question, name the risk, link it to the scenario, assess likelihood and impact, then recommend a response that fits the risk attitude.
What this chapter covers
This chapter is about the first half of risk management. You learn to identify risks, group them into categories, assess likelihood and impact, and measure exposure using both quantitative and qualitative tools. You also study risk attitude, appetite and tolerance, the models that explain where risks come from, and specific risks such as fraud and reputation damage.
It links closely to the rest of SBL. Risk sits beside strategy, governance, leadership and change. A board sets strategy within its risk appetite. Governance sets who oversees risk. Internal control and the later risk response topics depend on the risks you identify and rank here. A weak risk assessment makes every later recommendation weak.
In the exam, the case study will rarely say 'discuss the risks' in a neat list. Risks are hidden in the pre-seen information and the exam-day extracts. You must spot them, rank them and tie them to the organisation's goals. The chapter gives you the vocabulary and the structure to do that quickly and in a way a board would find useful.
Risk appears in many SBL tasks, either directly (assess the risks of a proposal) or indirectly (advise on a strategy, an acquisition or a governance failure). Marks go to applying risk ideas to the scenario, not to reciting definitions. Professional skills marks reward analysis, scepticism and commercial judgement, which are exactly what a good risk assessment shows. If you master this chapter, you gain a reusable framework for tasks on strategy, governance, ethics and change, so the effort pays off across the paper.
Identification, assessment and measurement of risk: topics in the order to study them
- 1Risk Identification and CategorisationStart here because you cannot assess or measure a risk until you can name it and place it in a category.
- 2Risk Assessment: Likelihood and ImpactNext, learn to rank the risks you found using likelihood and impact, the core logic of the whole chapter.
- 3Risk Measurement TechniquesOnce you can rank risks, study the tools that put numbers or structure on them, such as sensitivity analysis and expected values.
- 4Risk Attitude, Appetite and ToleranceMeasurement only means something against the level of risk the organisation will accept, so this comes after the tools.
- 5Risk Models and Frameworks: Cause, Effect and SourcesModels give you a wider structure for explaining where risks come from and what they cause, and they are easier once the basics are secure.
- 6Fraud, Reputation and Other Specific RisksFinish with specific risks, which are common in cases and let you practise applying everything above to realistic situations.
How to prepare Identification, assessment and measurement of risk
Treat this chapter as a skill to practise, not a list to memorise. Aim to apply each idea to a scenario in writing.
- Read the topics in the study order above and write a one-page summary of each in your own words.
- Build a personal checklist of risk categories and use it on every case study or scenario you read, listing the risks you spot.
- Practise ranking risks with a simple likelihood and impact grid. Always justify the placement with a fact from the scenario.
- Learn the measurement tools well enough to explain what each shows, its limits and when it suits a decision. Do not rely on definitions alone.
- For each scenario, state the organisation's likely risk appetite and say how it changes your recommendation.
- Write timed answers to past-style tasks. Use a clear structure: identify, assess, measure, recommend. Check that each point is linked to the case.
- Review your answers for professional skills. Ask whether you showed scepticism, balanced views and a clear, usable recommendation.
Common mistakes in Identification, assessment and measurement of risk
Listing generic risks that are not tied to the scenario.
Fix: For every risk, quote or paraphrase a fact from the scenario and explain why it creates that risk for this organisation.
Assessing only impact and ignoring likelihood, or the reverse.
Fix: Use a fixed habit: state likelihood, state impact, then give the combined ranking and the reason.
Presenting measurement figures without commenting on their reliability.
Fix: After any calculation or estimate, add a line on what it assumes, what it leaves out and how a board should use it.
Confusing risk appetite, tolerance and attitude.
Fix: Learn one-line definitions for each and show in your answer how each applies to the organisation in the case.
Treating fraud and reputation as separate from other risks.
Fix: Trace the cause and effect. Ask what weakness allowed the fraud and which stakeholders would react to the reputational damage.
Ending with a list of risks and no recommendation.
Fix: Close each risk answer with a priority and a practical next step, written for the board or manager named in the task.
Last-day revision: Identification, assessment and measurement of risk
- Risk is uncertainty about outcomes that can affect objectives, and it can include upside as well as downside.
- Identify risks first, then categorise them, then assess them, then measure them.
- Assess each risk on likelihood and impact, and explain both using facts from the scenario.
- A risk with low likelihood but severe impact still needs attention and a planned response.
- Risk appetite is the amount of risk an organisation is willing to take to pursue its objectives.
- Risk tolerance is the acceptable variation around a particular objective, so it is more specific than appetite.
- Risk attitude is how the board and managers feel about risk, which shapes the appetite they set.
- Quantitative tools give numbers but depend on assumptions, so always comment on their limits.
- Qualitative assessment is useful when data is poor or the risk is hard to value, such as reputation.
- Fraud risk needs motive, opportunity and a way to justify the act, and controls aim to reduce opportunity.
- Reputation risk can follow from other failures, so link it to its cause and the stakeholders affected.
- In the exam, apply each point to the case and finish with a clear recommendation.
Identification, assessment and measurement of risk practice questions
- Brightwater Utilities is assessing its risk profile. Its regulated water pricing means revenues are largely fixed by the regulator, but it h…
- Karel Mining's board is described as risk seeking. It has just approved entry into an unstable region with high expected returns, though its…
- Brightwave Energy rates a project risk as medium likelihood and very high impact. Its board has a low risk appetite and a stated risk tolera…
- Orlando Retail's risk register rates a data breach as low likelihood but very high impact, because customer records would be exposed and reg…
- Harbour Freight plc, a logistics group, has plotted its risks on a likelihood-impact matrix. A cyber-attack that would shut down its booking…
- Zenara Foods, a listed packaged-food company, discovers that a supplier has been using unsafe ingredients. No customers have yet been harmed…
- Orlan Mining plc faces a political risk in a country where it operates: nationalisation of its mine. Likelihood is judged low, but impact wo…
- Zephyr Foods, a listed manufacturer, sources its main ingredient from a single supplier in a region prone to flooding. The board's risk regi…
Identification, assessment and measurement of risk in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Identification, assessment and measurement of risk: frequently asked questions
How much of this chapter is calculation?
Very little. SBL is a case-based exam and most of the marks are for applying ideas to the scenario. You should understand simple measurement tools and their limits, but you will mainly write explanations and recommendations.
What is the difference between risk appetite and risk tolerance?
Risk appetite is the overall amount of risk an organisation is willing to accept to pursue its objectives. Risk tolerance is narrower. It is the acceptable level of variation around a specific objective or target.
How do I find risks in the case study?
Read the pre-seen material with a category checklist beside you and note each fact that could threaten an objective. Then check the exam-day extracts for new facts that change likelihood or impact. Always tie each risk to a specific detail.
Does this chapter help with professional skills marks?
Yes. Ranking risks, questioning assumptions and giving balanced advice show analysis, scepticism and commercial acumen. A clear, board-ready recommendation also supports the communication skill.