Strategic Business Leader · Managing, monitoring and mitigating risk
Risk Culture, Roles and Responsibilities in ACCA SBL
Updated 11 October 2026 · Fact-checked
Risk culture is the shared attitude to risk across an organisation. The board sets risk appetite and owns risk overall. A risk committee and risk manager oversee and support. Managers and staff manage risk daily. To answer SBL questions, assign each role a clear duty, link it to the scenario, and recommend steps to embed the culture.
Understand Risk Culture, Roles and Responsibilities
Risk management only works if people behave in line with it. Policies on paper do not stop losses. Risk culture is the set of values, beliefs and habits that shape how people at every level think about and respond to risk. A weak culture hides bad news. A strong culture raises problems early.
Responsibility for risk is shared. The board is ultimately responsible for risk management and for deciding the organisation's risk appetite and strategy. It also reviews the effectiveness of risk and internal control systems. Governance codes expect the board to do this, and to report on it to shareholders.
The board often delegates detailed oversight to a risk committee. This is usually made up mainly of non-executive directors, sometimes with senior executives. It reviews the risk profile, monitors exposure against appetite, reviews risk reports and challenges management. In some organisations the audit committee does this job instead. The committee advises the board. It does not remove the board's responsibility.
A risk manager or chief risk officer (CRO) runs the risk function day to day. Typical duties are developing the risk framework and policies, maintaining the risk register, coordinating risk assessment, giving training and advice, and reporting to the committee and board. Line managers own the risks in their area and apply controls. All staff must follow procedures, spot risks and report incidents. Internal audit gives independent assurance that the system works. It should not own the risks.
A positive culture is built from the top. Directors must show the behaviour they expect, which is often called tone at the top. Other levers are clear policies, risk awareness in training, risk in job descriptions and appraisal, rewards that do not push people into excessive risk-taking, open communication, a safe whistleblowing route, and a no-blame approach to reporting honest mistakes. Staff who fear punishment hide problems. Staff who are rewarded only for sales may ignore risk.
Key rules to remember
- Board responsibility
- Board = overall ownership of risk, appetite and review of effectiveness
- Responsibility can be delegated for oversight, but never removed from the board.
- Three lines model (simple form)
- 1st line: managers and staff own and manage risk | 2nd line: risk manager/CRO and risk committee oversee and support | 3rd line: internal audit gives independent assurance
- A useful structure for organising answers. Name it as a framework, not as a legal rule.
- Embedding risk culture
- Tone at the top + clear policies + training + aligned incentives + open communication + safe reporting
- Use as a checklist of levers when asked how to build a positive culture.
How to solve Risk Culture, Roles and Responsibilities questions
Use this method for any question on risk culture, roles or responsibilities.
- 1Read the requirement and note the verb: identify, explain, evaluate or recommend. Note who the answer is for, such as the board or the CEO.
- 2Scan the scenario for clues: weak reporting lines, blame, pressure on targets, no risk committee, or a CRO with no access to the board.
- 3List the relevant parties: board, risk committee, risk manager or CRO, line managers, staff, internal audit.
- 4For each party, state its responsibility briefly, then link it to a fact in the scenario.
- 5Assess the current culture using evidence such as behaviour, incentives, communication and leadership.
- 6Recommend specific actions to embed risk culture, ranked by importance and matched to the problems found.
- 7Add a balanced point, such as cost, resistance, or the limits of rules without real behaviour change.
- 8Finish in the format asked (report, memo or briefing note) with a clear tone to earn professional skills marks.
Quickest way: Role-and-lever grid
When to use it: Use when time is short and you need a fast plan for a 10 to 15 mark requirement.
- Jot two columns on your plan: roles (board, committee, CRO, managers, staff, internal audit) and levers (tone, policy, training, incentives, communication, reporting).
- Tick the roles and levers the scenario evidence points to. Ignore the rest.
- Write one point per ticked item in the pattern: duty or lever, scenario fact, consequence or action.
- Use the first sentence of each paragraph as a clear heading-style statement so the marker can see points quickly.
Common mistakes in Risk Culture, Roles and Responsibilities
Saying the risk committee or CRO is responsible for risk instead of the board.
Students see delegation and assume responsibility has moved.
Fix: State that the board stays ultimately responsible. The committee and CRO oversee and advise.
Listing roles generically without using the scenario.
Students memorise a list and write it out.
Fix: Tie every role to a specific fact, such as a CRO who reports only to the finance director.
Treating risk culture as just having policies and a risk register.
Formal systems are easier to describe than behaviour.
Fix: Explain that culture is shown in behaviour, incentives and leadership, and recommend actions that change them.
Ignoring incentives that reward excessive risk-taking.
Students focus on structures and miss remuneration and targets.
Fix: Check the scenario for bonuses or targets and discuss how they should balance risk and reward.
Making internal audit responsible for managing risk.
Audit and risk roles are confused.
Fix: Say management owns risk. Internal audit gives independent assurance and should not take ownership.
Giving recommendations with no explanation of how they would work.
Students write short action lists to save time.
Fix: For each recommendation, say what it is, who does it and why it will change behaviour.
Worked examples
Example 1
A manufacturer has had repeated safety incidents. Staff say they do not report near misses because managers blame individuals. The board receives risk information once a year from the finance director. Evaluate the company's risk culture and recommend how to improve it. (10 marks)
Show the solution
- Assess the culture: a blame approach discourages reporting, so the culture is weak. Near misses are lost learning, which raises the chance of a serious incident.
- Assess governance: annual reporting is too infrequent for the board to monitor risk. There seems to be no risk committee or dedicated risk manager, and the finance director is the only channel.
- Recommend a board-level risk committee, mostly non-executive, to review risk reports regularly and challenge management.
- Recommend a risk manager or CRO with direct access to the committee, to run the risk register and incident reporting.
- Recommend a no-blame reporting system for near misses, with feedback to staff showing action taken.
- Recommend training and safety measures in managers' appraisal, so line managers own risks in their areas.
- Recommend visible leadership: directors should visit sites and respond constructively to reports to set the tone at the top.
- Caveat: changes take time and cost money, and a no-blame approach must still allow action against deliberate breaches.
Answer: The culture is weak because blame suppresses reporting and the board has little oversight. Create a risk committee and a CRO, introduce no-blame near-miss reporting, make managers accountable through appraisal and training, and have directors set the tone. Keep discipline for deliberate breaches.
Example 2
A bank pays traders large bonuses on annual profit only. The CRO reports to the head of trading and has never presented to the board. Explain the responsibilities of the board and the CRO and advise how the bank should change. (10 marks)
Show the solution
- Board role: set risk appetite, approve strategy and review the effectiveness of risk systems. It cannot delegate away overall responsibility.
- CRO role: develop the risk framework, monitor exposures against appetite, advise and report to the board or risk committee.
- Problem 1: the CRO reports to the head of trading, so the person being monitored controls the monitor. This undermines independence and challenge.
- Problem 2: bonuses based only on annual profit encourage excessive short-term risk-taking and discourage caution.
- Action: make the CRO report to the CEO with direct access to the board or risk committee, and protect the CRO's position.
- Action: revise remuneration to include risk-adjusted performance, longer-term measures and possibly deferral of bonuses.
- Action: set up or strengthen a risk committee of non-executive directors to review reports regularly.
- Add culture: directors should state expected behaviour and respond to risk concerns openly.
Answer: The board owns risk appetite and oversight. The CRO supports it by running the framework and reporting. The bank should give the CRO independence and board access, set up a risk committee and adjust bonuses to reflect risk and longer-term results.
Exam tips
- Always link roles to scenario facts. Generic lists earn few marks.
- Say clearly that the board has ultimate responsibility, even when a committee or CRO exists.
- Look for incentives, reporting lines and blame as typical clues to culture problems.
- Use the report or memo format asked for and a professional tone to pick up professional skills marks.
- Offer a balanced view: culture change is slow and rules alone do not change behaviour.
Practice questions from Managing, monitoring and mitigating risk
- Tessling Pharma's audit committee reviews its annual assessment of internal controls. The review finds that controls were well designed, but…
- Toller Retail, a UK-based chain, plans to enter a new country by acquiring a local competitor. Directors worry that the new country's custom…
- Brightwell Logistics is designing its risk process in line with ISO 31000. The risk manager proposes that the process of identifying, analys…
- Kallis Energy's board has set a risk appetite and now wants management to apply it in practice. Management has identified a project whose ex…
- Kestrel Foods, a listed manufacturer, buys most of its wheat from one region. A drought there causes a sharp rise in input prices, and the b…
Risk Culture, Roles and Responsibilities: frequently asked questions
What is risk culture in SBL?
It is the shared values and behaviour that shape how people at all levels identify, discuss and respond to risk. In exam answers, judge it from evidence such as reporting habits, incentives and leadership behaviour.
What does a risk committee do?
It reviews the risk profile, monitors exposure against the risk appetite and challenges management on risk matters. It reports to the board, which keeps ultimate responsibility. In some companies the audit committee takes on this role.
What is the difference between the risk manager and internal audit?
The risk manager helps design and run the risk management framework and supports managers. Internal audit independently tests whether the system works and reports on it. Management still owns the risks.
How do you embed a risk management culture?
Start with leadership behaviour, then add clear policies, training, risk responsibilities in job roles and appraisal, balanced incentives and open communication. A safe way to report concerns is also important.