CFA Level I Exam · Introduction to Risk Management
Risk Management Process and Framework for CFA Level I
Updated 7 October 2026 · Fact-checked
Risk management is the process of identifying, measuring and managing risk so that the risks an organization takes match its goals and tolerance. The process sets risk governance and tolerance, identifies and measures risks, then mitigates, monitors and adjusts them. A framework is the structure that applies this process consistently across the firm.
Understand Risk Management Process and Framework
Risk management is not about removing risk. Risk is the source of return, so the aim is to take the right amount of risk, in the right places, for the reward expected. A firm that avoids all risk earns nothing. A firm that ignores risk can fail.
The risk management process is an ongoing cycle, not a one-off task. You set the goals and limits, find the risks, measure them, decide what to do, act, and then watch the results and adjust. Conditions change, so the cycle repeats.
A risk management framework is the structure that makes the process work in practice. Its components include risk governance, risk identification and measurement, risk infrastructure (people, systems and data), policies and processes, risk mitigation and management, communication, and strategic risk analysis and integration. Think of the process as what you do and the framework as the organization that lets you do it consistently.
Risk governance is the top-level layer. It sets the organization's risk objectives, assigns who is accountable, and sets the risk tolerance. Risk tolerance is the amount of risk the organization is willing and able to bear. It looks at both willingness and ability. Risk budgeting then allocates that total tolerated risk across activities, portfolios or business units, so each gets a limit that fits the total.
Good governance often uses an enterprise-wide view. Risks interact, so managing each one in isolation can miss the combined effect. Many firms use a central risk function that reports independently of those taking risk, which helps avoid conflicts of interest.
Key formulas to remember
- Risk management process (cycle)
- Set governance and tolerance → Identify risks → Measure risks → Choose a response (avoid, mitigate, transfer, share, or accept) → Implement → Monitor, report and adjust
- The process repeats continuously. Exact wording of steps varies, so learn the logic and order.
- Risk tolerance
- Risk tolerance = the amount of risk an organization is willing and able to take
- Think of willingness (attitude) and ability (capacity). When the two conflict, the lower (more conservative) of the two generally governs.
- Risk budgeting
- Total risk budget = Σ risk allocated to each activity, portfolio or unit
- Risk is allocated by expected reward and fit with objectives. Measures such as volatility or VaR are often used, but allocations do not always add up simply because of diversification.
- Framework components
- Governance, identification and measurement, infrastructure, policies and processes, mitigation and management, communication, strategic analysis and integration
- Know these as the building blocks of a framework.
How to solve Risk Management Process and Framework questions
Most questions ask you to place an action in the process, name a framework component, or judge whether risk was handled well. Use this method.
- 1Read the stem and decide what is being tested: the process step, a framework component, risk tolerance, or risk budgeting.
- 2Find the action described. Is it setting limits, finding risks, measuring them, responding to them, or monitoring them?
- 3Match it to the process order: governance and tolerance first, then identification, measurement, response, and monitoring and adjustment.
- 4If the question is about the framework, ask which part is meant: who is accountable (governance), the data and systems (infrastructure), the written rules (policies), or reporting (communication).
- 5For tolerance, separate willingness from ability. For budgeting, check that risk is being allocated, not just measured.
- 6Eliminate options that treat risk management as removing all risk or as a one-time exercise.
- 7Choose the remaining option that fits the organization's objectives and tolerance.
Quickest way: Match the verb to the step
When to use it: Use this when you have about 90 seconds and the question is conceptual.
- Underline the main verb: set, identify, measure, mitigate, monitor, allocate.
- Set or accept tolerance points to governance. Allocate limits points to risk budgeting.
- Find or measure points to identification and measurement. Insure, hedge or avoid points to the response step.
- Remove any option that says risk should be eliminated or that is unrelated to the objectives.
- Pick the option that keeps risk in line with tolerance.
Common mistakes in Risk Management Process and Framework
Thinking the goal of risk management is to minimize or eliminate risk.
The word management sounds like control, and risk sounds negative.
Fix: Remember that the goal is to take risk deliberately, within tolerance, for adequate return.
Confusing risk tolerance with risk budgeting.
Both involve limits on risk.
Fix: Tolerance is the total risk the organization will bear. Budgeting divides that total among activities.
Treating risk tolerance as only willingness.
Candidates focus on attitude and forget capacity.
Fix: Always consider both willingness and ability to bear risk. Ability can be lower than willingness, and when they conflict the more conservative one generally governs.
Treating the process as a straight line that ends.
Step lists look like a checklist.
Fix: Monitoring feeds back into identification and measurement, so the cycle repeats.
Mixing up the process and the framework.
Both use similar vocabulary.
Fix: The process is the sequence of actions. The framework is the structure of governance, people, systems and policies that supports it.
Managing each risk in isolation.
Questions often describe one risk at a time.
Fix: Remember the enterprise-wide view: risks interact, so look at the combined exposure.
Worked examples
Example 1
A bank's board sets the maximum loss it is willing to accept in a year. A risk team then splits this limit among the trading, lending and treasury units. Which statement best describes these two actions?
A. Risk budgeting, then setting risk tolerance.
B. Setting risk tolerance, then risk budgeting.
C. Risk identification, then risk mitigation.
Show the solution
- The board sets the total acceptable loss. That is the amount of risk the bank is willing to bear, which is risk tolerance.
- Dividing the limit among units is allocating the total risk, which is risk budgeting.
- Option A reverses the order, because the total limit must be set before it can be divided. Option C does not fit because nothing was identified or mitigated.
Answer: B. Setting risk tolerance, then risk budgeting.
Example 2
A client is comfortable with large swings in portfolio value, but relies on the portfolio to pay near-term obligations and cannot absorb large losses. How should the client's risk tolerance be assessed?
A. High, because the client is willing to accept large swings.
B. Low, because ability to bear risk is limited despite high willingness.
C. Moderate, because willingness and ability offset each other.
Show the solution
- Risk tolerance combines willingness and ability to bear risk.
- The client's willingness is high, but the client's ability is limited by near-term obligations and the inability to absorb large losses.
- When ability is lower than willingness, the lower of the two generally governs, so tolerance is low.
- Option A ignores ability. Option C averages the two, but the more conservative measure should generally be followed rather than a midpoint.
Answer: B. Low, because ability to bear risk is limited despite high willingness.
Exam tips
- Questions are standalone with three options, so first eliminate any option that says risk should be removed entirely.
- Learn the process order cold: governance and tolerance, identify, measure, respond, monitor and adjust.
- When you see limits being split across units, think risk budgeting. When you see one overall limit, think tolerance.
- Remember that tolerance has two parts, willingness and ability, and that the lower one usually constrains.
- There is no penalty for a wrong answer, so never leave a question blank.
Practice questions from Introduction to Risk Management
- A company buys a property insurance policy for its warehouse and pays an annual premium. In return, the insurer will compensate it for cover…
- An airline expects to buy large volumes of jet fuel next year and enters forward contracts to fix the price. Compared with buying insurance,…
- Relative to value at risk, conditional value at risk (CVaR) is most likely to provide additional information about:
- An airline fears a sharp rise in fuel prices and enters a derivative contract that pays it if fuel prices rise above a set level. The airlin…
- A company decides to buy insurance against fire damage to its factory rather than accept the loss itself. This response to risk is best desc…
Risk Management Process and Framework in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Risk Management Process and Framework: frequently asked questions
What are the steps in the risk management process?
The process starts with governance and setting risk tolerance. You then identify and measure risks, choose a response, implement it, and monitor and adjust. It is a continuous cycle, so monitoring feeds back into earlier steps.
What is a risk management framework?
It is the structure that supports the risk management process across an organization. It includes governance, identification and measurement, infrastructure, policies and processes, mitigation and management, communication, and strategic analysis and integration.
What is the difference between risk tolerance and risk budgeting?
Risk tolerance is the total amount of risk an organization is willing and able to take. Risk budgeting allocates that total among portfolios, activities or units. Tolerance comes first and budgeting follows.
Does risk management mean avoiding risk?
No. The aim is to take risk deliberately, in line with objectives and tolerance, because risk is needed to earn return. Avoidance is only one possible response for a particular risk.