Skip to content

Strategic Business Leader · Identification, assessment and measurement of risk

Risk Assessment: Likelihood and Impact in ACCA SBL

Updated 11 October 2026 · Fact-checked

Risk assessment rates each risk on two scales: the likelihood that it happens and the impact if it does. You plot the risks on a risk map, then prioritise. High likelihood and high impact risks need action first. In SBL, you must apply this to the case, not just describe it.

Understand Risk Assessment: Likelihood and Impact

A risk is the chance that something uncertain will affect the organisation's objectives. Once you have identified a risk, you cannot treat all risks equally. Money, time and management attention are limited. Risk assessment tells you which risks matter most.

Assessment uses two questions. First, likelihood (also called probability): how probable is it that the event happens in a given period? Second, impact (also called consequence or severity): how much damage follows if it does happen? Impact can be financial, but also reputational, legal, operational or harm to people.

A risk map (risk matrix or heat map) puts the two together. Likelihood runs along one axis and impact along the other. Each risk is placed in a cell. Cells with high likelihood and high impact are the critical zone. Cells with low likelihood and low impact need little more than monitoring.

The map links to the response. A common pairing is: high impact and low likelihood suggests transfer (such as insurance) or contingency planning; high likelihood and low impact suggests control to reduce frequency; high on both suggests avoid or reduce urgently; low on both suggests accept. These are guides, not fixed rules. Cost, risk appetite and the facts of the case decide the final response.

Assessment is judgement, not exact science. Scores are often subjective, and they change over time. Also consider inherent risk (before controls) and residual risk (after controls), and note links between risks, because one event can trigger others. Good SBL answers say this, and show scepticism about how reliable the ratings are.

Key rules to remember

Expected value of a risk
Expected loss = Probability of event × Financial impact
Use only when you can estimate both numbers. Example: 10% × ₹50,00,000 = ₹5,00,000. It ignores non-financial impact and hides rare but catastrophic events.
Risk score (qualitative)
Risk score = Likelihood rating × Impact rating
Ratings are often 1 to 5. A score of 4 × 5 = 20 ranks above 3 × 3 = 9. The scale is a judgement tool, so state your scale.
Inherent and residual risk
Residual risk = Inherent risk after the effect of controls
Assess both. A big gap shows controls are doing the work, so their failure matters.
Risk map response guide
High/High = avoid or reduce; Low likelihood/High impact = transfer or plan; High likelihood/Low impact = control; Low/Low = accept
A guide only. Link to TARA: transfer, avoid, reduce, accept.

How to solve Risk Assessment: Likelihood and Impact questions

Use this method for any question asking you to assess, rank, map or prioritise risks in a case.

  1. 1Read the requirement. Note whether it asks you to identify, assess, prioritise or respond, and who the audience is (for example, the board).
  2. 2List the relevant risks from the scenario. Pick those the case gives evidence for, and name each one clearly.
  3. 3For each risk, judge likelihood and give a reason from the case facts, such as past events, market conditions or weak controls.
  4. 4For each risk, judge impact. Cover financial size and also reputation, legal, operational and strategic effects.
  5. 5Place risks on a risk map, or rank them in order. State which are critical and why. Consider risk appetite.
  6. 6Prioritise. Explain the order, and mention links between risks and the difference between inherent and residual risk where relevant.
  7. 7Link to a response (transfer, avoid, reduce, accept) if the requirement asks, and note the limits of your assessment.
  8. 8Write in the requested format and tone, and keep the answer tied to the scenario to earn professional skills marks.

Quickest way: Likelihood-impact-so what in three lines

When to use it: When time is short and the task asks for a quick ranking of risks or a short briefing.

  1. For each risk, write one line: High, Medium or Low likelihood, with a case fact as proof.
  2. Add one line: High, Medium or Low impact, with a case fact as proof.
  3. Add a 'so what' line: the priority order and the likely response.
  4. Put the High/High risks first and say why they come first.
  5. Finish with one sentence on limits, such as subjective ratings or missing data.

Common mistakes in Risk Assessment: Likelihood and Impact

  • Listing risks without rating likelihood or impact

    Students move from the identification chapter and forget that assessment is a separate task.

    Fix: Give every risk a likelihood and an impact, each with a reason from the case.

  • Judging risks by impact alone

    Big, dramatic risks feel more important.

    Fix: Always combine both scales. A frequent medium-sized loss can matter more than a remote one.

  • Using only financial impact

    Students focus on numbers in the case.

    Fix: Add reputation, legal, safety, operational and strategic effects. Many case risks are mostly non-financial.

  • Drawing a generic matrix with no case facts

    The theory is easy to recite.

    Fix: Place named risks from the scenario on the map and justify each position in a sentence.

  • Treating the response as fixed by the map position

    Students memorise the quadrant rules as laws.

    Fix: Treat quadrant guides as starting points. Weigh cost of response, risk appetite and benefits before you recommend.

  • Ignoring controls and links between risks

    Each risk is analysed in isolation.

    Fix: Comment on residual risk after existing controls and on risks that trigger each other, such as a data breach causing reputation loss.

Worked examples

Example 1

A manufacturer estimates a 10% chance in the coming year of a factory fire causing a loss of ₹80,00,000, and a 40% chance of a supplier delay causing a loss of ₹6,00,000. Calculate the expected loss for each risk and comment on prioritisation.

Show the solution
  1. Fire: 10% × ₹80,00,000 = 0.10 × 80,00,000 = ₹8,00,000.
  2. Supplier delay: 40% × ₹6,00,000 = 0.40 × 6,00,000 = ₹2,40,000.
  3. On expected loss, fire ranks higher (₹8,00,000 against ₹2,40,000).
  4. Comment: the fire is low likelihood and high impact, so insurance and a continuity plan suit it. The delay is higher likelihood and lower impact, so better supplier management and buffer stock suit it.
  5. Limit: expected value is an average. It does not show that a single fire could threaten the survival of the business, and the probabilities are estimates.

Answer: Expected loss: fire ₹8,00,000; supplier delay ₹2,40,000. Fire is the higher priority on this measure. Fire suits transfer and contingency planning; delay suits control. Treat the estimates and the averaging effect with caution.

Example 2

Scenario: Zenith Retail plans to sell online for the first time. The board is worried about three risks: (1) a cyber attack exposing customer data, (2) a rival cutting prices, and (3) a minor delay in the website launch. Prepare a short risk assessment for the board, prioritising the risks.

Show the solution
  1. Cyber attack: likelihood is medium to high, as a new online business with little experience is exposed to attacks. Impact is high: regulatory penalties, loss of customer trust and reputation damage. Rating: high impact, medium to high likelihood.
  2. Price cut by rival: likelihood is medium, because retail is competitive and a new entrant may provoke a response. Impact is medium: margins fall but the business continues. Rating: medium on both.
  3. Launch delay: likelihood is high, as new IT projects often overrun. Impact is low: some lost sales and a short postponement. Rating: high likelihood, low impact.
  4. Map: the cyber risk sits in the critical zone, the price cut in the middle, the delay in the high likelihood and low impact area.
  5. Priority: 1 cyber, 2 price cut, 3 delay. Cyber needs immediate reduction through security controls and possible insurance. Price cut needs monitoring and a pricing response plan. Delay can be accepted or managed through project control.
  6. Caveat: ratings are judgement and should be reviewed. The risks link, because a cyber breach would also damage the brand and make the pricing position weaker.

Answer: Priority order: cyber attack first (high impact, medium to high likelihood, reduce and transfer), price cut second (medium, monitor and plan), launch delay third (high likelihood, low impact, control or accept). Ratings are subjective and should be reviewed as the launch nears.

Exam tips

  • Always justify a rating with a fact from the case. A bare 'high' earns little credit.
  • If asked to prioritise, give a clear order and the reason for it. Do not stop at a list.
  • Draw a simple risk map only if it helps, and always explain it in words. Label axes and name the risks.
  • Keep non-financial impacts in view. SBL cases often turn on reputation, ethics or strategy.
  • Show professional scepticism: say how reliable the estimates are, and suggest review as conditions change.

Practice questions from Identification, assessment and measurement of risk

Risk Assessment: Likelihood and Impact in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Risk Assessment: Likelihood and Impact: frequently asked questions

What is a risk map in SBL?

A risk map is a grid that plots each risk by its likelihood and its impact. It shows which risks are most serious and helps you decide where to act first. It is also called a risk matrix or heat map.

How do I decide whether likelihood or impact matters more?

Neither always wins. You judge them together. A very high impact risk can need action even if unlikely, and a very frequent small loss can add up. Say which factor drives your priority and why.

Do I need numbers to assess risk in SBL?

Not always. Most SBL assessments are qualitative, using high, medium and low ratings. If the case gives figures, use them, for example probability × impact, but comment on their limits.

What is the difference between inherent and residual risk?

Inherent risk is the level before any controls. Residual risk is what remains after controls are applied. Assessing both shows how much the organisation depends on its controls.