CFA Level I · CFA Level I Exam
Introduction to Risk Management for CFA Level I
Risk management is the process of identifying a firm's risk exposures, setting how much risk it will accept, measuring risks, and then choosing to avoid, mitigate, transfer or share them. For the exam, learn the process steps, the governance roles, the main risk types, and which method fits each risk.
What this chapter covers
This chapter gives you the vocabulary and logic of risk management. It starts with the process: set risk tolerance, identify and measure risks, then choose a response and monitor results. It then covers governance, meaning who owns risk decisions, and how an organisation decides the amount of risk it can and will take.
Next come the types of risk. Financial risks include market, credit and liquidity risk. Non-financial risks include operational, model, settlement, regulatory, legal, tax, accounting and sovereign risks, among others. You then learn how risk is measured, using drivers such as exposures and sensitivities, and metrics such as standard deviation, beta, duration, delta and Value at Risk. The chapter ends with the four responses: avoid, mitigate, transfer and share.
The chapter links to many other topics. Derivatives are tools for transferring and mitigating risk. Portfolio Construction uses risk tolerance and return objectives. Fixed Income and Equities supply the exposure measures. Quantitative Methods supplies the statistics behind standard deviation and VaR. Ethics also connects through governance and accountability. Understanding this chapter makes those later topics easier to place.
Derivatives and Risk Management carries a topic weight of 6-9% of the exam, and this chapter supplies the concepts that the derivatives material builds on. The questions are mostly conceptual: you match a situation to a risk type, a governance role or a response method. That makes it a good chapter for steady marks with modest effort. All questions carry equal weight and wrong answers are not penalised, so knowing the definitions well lets you eliminate two options quickly and save time for calculation-heavy topics.
Introduction to Risk Management: topics in the order to study them
- 1Risk Management Process and FrameworkIt gives the overall sequence that every other topic in the chapter fits into, so start here.
- 2Risk Governance and Risk ToleranceGovernance and risk tolerance are the first steps of the framework, so they follow naturally and set the limits for everything after.
- 3Types of Financial and Non-Financial RisksYou can only measure and manage risks once you can name and separate them.
- 4Measuring Risk: Drivers and MetricsMeasurement needs the risk types in mind, since each type has its own drivers and its own suitable metrics.
- 5Risk Management Methods: Avoid, Mitigate, Transfer, ShareThe response step comes last because you choose a method based on the measured risk and the stated tolerance.
How to prepare Introduction to Risk Management
This chapter is mostly concepts, so short and frequent sessions work well, including on your phone during a commute. Use calculations only to support the ideas.
- Read the process and framework once and write the steps in order from memory. Check that you can explain each step in one sentence.
- Study governance and risk tolerance together. Be clear on who sets tolerance, who oversees risk, and how a risk budget links to tolerance.
- Build a table of risk types in your notes: name, one-line definition, one example. Separate financial risks from non-financial ones.
- Pair each risk metric with what it measures and its main limit. For example, VaR gives a loss threshold at a probability over a period, not the size of losses beyond it.
- For each method (avoid, mitigate, transfer, share), write one real example and the situation where it fits best.
- Practise standalone three-option questions. For each one, name the concept being tested, then eliminate the two options that describe a different concept.
- In the last week, revisit only the definitions you missed in practice and re-test them after a day.
Common mistakes in Introduction to Risk Management
Mixing up risk tolerance with risk exposure.
Fix: Tolerance is what the organisation is willing and able to accept. Exposure is what it actually faces. Compare them to see if action is needed.
Treating VaR as the maximum possible loss.
Fix: Always state VaR as the minimum loss that would be expected to be equalled or exceeded with a given probability over a specific period. It says nothing about how bad losses beyond that level can be.
Confusing transferring a risk with sharing it.
Fix: Transfer moves the risk to another party, as with insurance. Sharing spreads it between parties who each keep part of it.
Treating risk management as only avoiding risk.
Fix: The goal is to take the right amount of risk for the expected reward and within tolerance. Avoiding is one method of four.
Classifying a non-financial risk as financial, or the reverse.
Fix: Identify the root cause. Process or system failure points to operational risk, while price moves point to market risk.
Last-day revision: Introduction to Risk Management
- The risk management process sets tolerance, identifies and measures risks, chooses responses, and monitors and adjusts.
- Risk governance is the top-level structure for setting risk policy, authority and oversight in an organisation.
- Risk tolerance is how much risk an organisation is willing and able to take.
- A risk budget allocates the total acceptable risk across activities or units.
- Financial risks include market, credit and liquidity risk.
- Non-financial risks include operational, model, settlement, regulatory, legal, tax, accounting and sovereign risk.
- Operational risk arises from people, systems, processes and external events.
- Risk drivers are the underlying exposures that cause risk; metrics are the measures used to quantify it.
- VaR is the minimum loss that would be expected to be equalled or exceeded with a given probability over a specific period; it does not describe the worst case.
- Avoid means not taking the risk at all; mitigate means reducing its likelihood or impact.
- Transfer shifts the risk to another party, such as through insurance; share spreads it across parties.
- Enterprise-wide, integrated risk management looks at all risks together, not in silos.
Introduction to Risk Management practice questions
- Which statement about risk tolerance and risk appetite is most accurate?
- Which of the following is most likely a benefit of centralizing risk management under a single enterprise-wide framework, compared with mana…
- A company buys a property insurance policy for its warehouse and pays an annual premium. In return, the insurer will compensate it for cover…
- A bond portfolio worth USD 50 million has a modified duration of 6.0 and is hedged by no instruments. Assuming a parallel yield shift, the p…
- A pension fund's board sets a risk budget that allocates the total acceptable risk across asset classes and managers. The most likely benefi…
- A company decides to buy insurance against fire damage to its factory rather than accept the loss itself. This response to risk is best desc…
- An investment firm loses money when a trader enters orders in the wrong currency pair because of a keying error, and the firm's controls fai…
- A bank installs automated fraud-detection software and requires dual authorization for large payments. The bank continues offering all exist…
Introduction to Risk Management in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Introduction to Risk Management: frequently asked questions
How much of the CFA Level I exam is risk management?
Derivatives and Risk Management has a 6-9% topic weight for exams from February 2027. This chapter is part of that topic, so it makes up a share of that range.
Do I need a calculator for this chapter?
Very little. The chapter is mainly conceptual, so expect questions on definitions, roles and matching a risk to a method. Calculator practice matters more in the derivatives chapters that follow.
What is the difference between risk governance and risk management?
Governance sets the structure, policies and oversight for how risk is handled. Risk management is the ongoing work of identifying, measuring and responding to risks within that structure.
How do I avoid traps in the multiple-choice questions?
Name the exact concept being tested before reading the options. Then remove the two choices that describe a neighbouring concept, such as exposure instead of tolerance or transfer instead of share.