Strategic Business Leader · Identification, assessment and measurement of risk
Risk Identification and Categorisation for ACCA SBL
Updated 11 October 2026 · Fact-checked
Risk identification is finding the uncertain events that could stop an organisation meeting its objectives. Categorisation sorts them into groups such as strategic, operational, financial and compliance risk, or business and non-business risk. In SBL, you scan the case, name each risk, classify it, and link it to the scenario.
Understand Risk Identification and Categorisation
A risk is an uncertain event or condition that, if it happens, affects the achievement of objectives. In SBL, always tie risk to objectives. A risk matters only because something the organisation wants could be lost or missed.
Risk identification is the first stage of risk management. The organisation looks for risks before it can assess or respond to them. Common methods are workshops, brainstorming, interviews, checklists, scenario analysis, reviewing past incidents, and scanning the external environment with tools such as PESTEL and Porter's Five Forces. Internal analysis such as SWOT and the value chain also exposes weak spots.
Categorisation gives structure. Common categories are:
- Strategic risk: poor strategic choices, or a changing environment that makes the strategy less viable, such as new competitors or disruptive technology.
- Operational risk: failure of people, processes, systems or external events in day-to-day activity, such as supply chain failure or IT outage.
- Financial risk: exposure from finance and markets, such as interest rate, exchange rate, credit, liquidity and gearing risk.
- Compliance risk: breaching laws, regulations or internal policies, leading to fines, sanctions or loss of licence.
- Other categories: reputational, technological, environmental, political, fraud, and human resource risks. Many cases use these labels.
Another key split is business risk versus non-business risk. Business risk is linked to the organisation's own strategic and operating choices. It arises from the products it sells, the markets it enters and how it competes. Taking it is part of earning a return. Non-business risk comes from outside the organisation's chosen business activity and is not something it gains a return from taking, for example regulatory change, or exposure to exchange rates on an activity that is not itself a speculative choice. Textbooks vary slightly in how they draw this line. In the exam, state your definition and apply it consistently.
Categories overlap. One event can sit in more than one group. A data breach is operational, may be a compliance breach, and damages reputation. Do not worry about one perfect label. Show that you can see the risk, give a sensible category, and explain why it matters to this organisation.
Key rules to remember
- Definition of risk
- Risk = uncertain event that could affect achievement of objectives
- Always link each risk to a specific objective in the scenario.
- Main risk categories
- Strategic | Operational | Financial | Compliance | Other (reputational, technological, environmental, political, fraud)
- A working checklist. Categories can overlap, so label by the main cause.
- Business vs non-business risk
- Business risk = linked to the organisation's own strategic and operating choices, taken to earn a return. Non-business risk = arises outside those choices, with no return for bearing it
- Sources differ slightly on the boundary. State your definition and apply it consistently.
- Identification sources
- External (PESTEL, Five Forces) + Internal (SWOT, value chain, processes) + Stakeholders and past events
- Use these as prompts to find risks that the case hides.
How to solve Risk Identification and Categorisation questions
Use this method for any question that asks you to identify, classify or discuss risks in a case.
- 1Read the requirement. Note whether you must identify, categorise, assess or advise on risk, and for whom (board, audit committee, investors).
- 2Note the organisation's objectives and strategy from the case. Risks only make sense against objectives.
- 3Scan the case for risk triggers: new markets, acquisitions, reliance on one supplier or customer, new technology, regulation, foreign currency, debt, weak controls, ethical concerns.
- 4List each risk as a short statement: cause, event, consequence. Do not just write a label.
- 5Classify each risk (strategic, operational, financial, compliance, or another category) and, if asked, business or non-business. Say why in a few words.
- 6Apply to the case with facts and figures from the scenario. Explain the likely impact on the organisation.
- 7Prioritise. Say which risks are most significant and why, and suggest a response only if the requirement asks for it.
- 8Write for the reader. Use the report or memo format asked for, and keep the tone professional.
Quickest way: Scan, label, link
When to use it: When time is short, or you must produce a list of risks quickly in an SBL task.
- Run through the checklist: strategic, operational, financial, compliance, then reputational, technology, fraud.
- For each category, find one case fact that fits.
- Write one line per risk: label, case fact, consequence.
- Add a short note on which one or two are most serious.
Common mistakes in Risk Identification and Categorisation
Listing generic risks that could apply to any company.
Students recall textbook lists and do not go back to the case.
Fix: Quote or paraphrase a case fact for every risk, and state the effect on this organisation's objectives.
Naming a category only, such as 'operational risk', without saying what the risk is.
Labelling feels like the answer.
Fix: Write the cause, the event and the consequence. The label is secondary.
Spending too long on which category is exactly right.
Categories overlap, and students fear losing marks for a wrong label.
Fix: Pick the most sensible category, justify it briefly and move on. Marks go to relevance and explanation.
Confusing business risk with non-business risk, or treating all risk as negative.
The terms sound similar, and sources define the boundary differently.
Fix: State your definition. Business risk comes with the organisation's chosen activity and is taken to earn a return. Non-business risk sits outside that choice.
Jumping to risk responses when only identification was asked.
Students want to show more knowledge.
Fix: Answer the requirement. Add responses only if the task asks for them, and keep them brief.
Ignoring professional skills in a risk report.
Students focus on technical content.
Fix: Structure the answer, prioritise, show scepticism about management claims, and write in a clear, commercial tone.
Worked examples
Example 1
Zephyr Foods is a packaged snacks manufacturer. It buys 70% of its palm oil from one overseas supplier, is opening a factory in a new country with unfamiliar food safety rules, and has borrowed in US dollars while earning most revenue in rupees. Identify and categorise three risks for the board.
Show the solution
- Read the case for triggers: single supplier, new country with unfamiliar rules, dollar debt against rupee revenue.
- Risk 1: the single overseas supplier could fail or raise prices, stopping production. This is an operational risk (supply chain), and it could also have a strategic effect if it threatens growth targets.
- Risk 2: the new factory may breach unfamiliar food safety rules, giving fines, closure or product recalls. This is a compliance risk, with a reputational consequence.
- Risk 3: dollar borrowing against rupee income means a weaker rupee raises the cost of interest and repayments. This is a financial risk (exchange rate risk).
- Prioritise: the single supplier affects all output, so it is likely the most significant, but the currency exposure may be large if borrowing is high.
Answer: Three risks: supplier dependence (operational), food safety non-compliance in the new country (compliance, with reputational impact) and currency mismatch on dollar debt (financial). Each is tied to a case fact and its effect on Zephyr's objectives.
Example 2
Explain the difference between business risk and non-business risk, using a retailer that is launching an online store as an example.
Show the solution
- Define business risk: risk linked to the organisation's own strategic and operating choices, taken in order to earn a return.
- Apply: launching an online store carries the risk that customers do not use it, that competitors respond or that development costs exceed benefits. The retailer chooses this risk to pursue growth.
- Define non-business risk: risk arising from outside the chosen business activity, with no return for bearing it.
- Apply: a new data protection law that changes how the retailer must handle customer data, or a sudden fall in the rupee that raises imported stock costs, are not risks the retailer chose in order to earn a return.
- Note the boundary: sources draw it slightly differently, and some risks mix both. Say how you are using the terms.
- Conclude: management should decide how much business risk to accept. For non-business risk it should usually aim to reduce or transfer exposure, as there is no reward for holding it.
Answer: Business risk comes with the retailer's chosen strategy, such as weak customer take-up of the online store, and is accepted to earn a return. Non-business risk, such as a regulatory change or an adverse exchange rate move, comes from outside that choice and earns no return, so it is usually reduced or transferred.
Exam tips
- Always tie each risk to a fact in the case. Generic lists score poorly.
- Write risks as cause, event and consequence, then add the category in brackets.
- Do not agonise over the category. Overlap is normal, so justify your choice briefly.
- Prioritise the most significant risks and say why. This shows commercial judgement and earns professional skills marks.
- Answer only what is asked. If the task is identification, do not spend your time on detailed responses.
Practice questions from Identification, assessment and measurement of risk
- Brenner plc, a retailer, sources garments from a low-cost country. A news report alleges poor labour conditions at its main supplier. The bo…
- Halcyon Energy's internal audit finds that the CEO overrides controls to approve large contracts with a company owned by his brother, which …
- Zephyr Foods plc imports perishable goods. Its risk manager is preparing a risk register and separates each risk into the event that might o…
- Kestrel Foods, a listed manufacturer, discovers that a supplier supplied contaminated ingredients, and social media posts about the incident…
- Kestrel Retail has an established risk management process. A newly appointed risk manager proposes classifying a competitor's entry into Kes…
Risk Identification and Categorisation: frequently asked questions
What are the main types of risk in SBL?
The main groups are strategic, operational, financial and compliance risk. Cases also use reputational, technological, environmental, political, fraud and human resource risk. Use whichever labels fit the scenario.
What is the difference between business risk and non-business risk?
Business risk comes from the organisation's own strategic and operating choices and is taken to earn a return. Non-business risk arises outside those choices and earns no return for bearing it. Sources draw the line slightly differently, so state your definition.
How do I identify risks in an SBL case study?
Read with the organisation's objectives in mind and look for triggers such as new markets, supplier dependence, debt, foreign currency, new technology, regulation and weak controls. Write each risk as cause, event and consequence, then classify it.
Do I lose marks if I categorise a risk differently from the model answer?
Usually not, if your category is reasonable and you explain the risk and its impact on the organisation. Many risks overlap, so marks go to relevance and application.