Skip to content

CMA Final · Strategic Performance Management and Business Valuation

Risk Management for CMA Final Paper 20A

Risk management in Paper 20A is the structured way a business identifies, measures, treats, monitors and reports risks that can affect its objectives. To solve questions, name the risk type, apply the right process step or framework, measure it, choose a response, and give a clear recommendation tied to the case.

What this chapter covers

This chapter covers how a business deals with uncertainty. You start with what risk is and its main types: strategic, operational, financial, compliance and reputational. Then you learn the risk management process, from identifying risks to monitoring them. Two frameworks sit on top of that process: COSO ERM and ISO 31000.

The second half is practical. You learn how to measure and assess risk, how to reduce or transfer it through hedging and other responses, and how governance, culture and reporting keep the whole system working. Questions often give you a company situation and ask what you would do.

The chapter connects to the rest of Paper 20A. Performance measurement, strategy and business valuation all depend on risk. A higher risk usually means a higher discount rate or a wider range of outcomes. When you value a business or judge performance, you should be able to say which risks drive the numbers and how they are managed.

Risk Management is a theory-heavy chapter that rewards structured writing, so it is a good place to score if you prepare well. Section A MCQs, including the case scenario in 1(b), can test definitions, framework components and the right response to a given risk. Written questions ask you to apply ideas to a case, which means a clear process, a sensible measure and a firm recommendation earn marks. Students who only memorise lists lose marks on application, so the effort here pays off.

Risk Management: topics in the order to study them

  1. 1Concept and Types of Business RiskEvery later topic assumes you can name and classify a risk, so start with the vocabulary.
  2. 2Risk Management ProcessThe process steps give you the basic sequence that frameworks and techniques plug into.
  3. 3Risk Management Frameworks (COSO ERM and ISO 31000)Frameworks are best learned once you know the process, because they organise the same ideas at enterprise level.
  4. 4Risk Measurement and Assessment TechniquesYou need the process and frameworks first to see where measurement and assessment fit.
  5. 5Risk Mitigation and Hedging StrategiesResponses follow measurement, since you choose a treatment based on how large and likely the risk is.
  6. 6Risk Governance, Culture and ReportingThis closes the loop on who owns risk, how it is embedded and how it is communicated, so it is easiest at the end.

How to prepare Risk Management

Treat this chapter as one connected flow from risk to response to oversight, not six separate lists. Build the flow first, then add detail.

  1. Read the topics in the study order and write a one-page map: risk types, process steps, frameworks, measurement, responses, governance.
  2. Learn the types of business risk with one Indian company example each, so you can classify risks in a case quickly.
  3. Memorise the process steps in order and practise explaining each in two lines with a short example.
  4. For COSO ERM and ISO 31000, learn the components or principles in your own words and note how they differ in structure and purpose.
  5. Practise measurement with simple likelihood and impact ratings and any numerical tools in your study material. Recompute each working step by step.
  6. For hedging and mitigation, match each risk to a response: avoid, reduce, transfer or accept. Always add a recommendation with a reason.
  7. Solve past and practice case questions in 14-mark format and a set of MCQs. Check that each answer names the risk, applies the concept and ends with a decision.

Common mistakes in Risk Management

  • Listing definitions without applying them to the case given.

    Fix: Name the specific risk in the case, link it to the concept, then give a recommendation.

  • Mixing up COSO ERM and ISO 31000.

    Fix: Make a two-column comparison of structure, components and purpose, and revise it often.

  • Confusing risk appetite with risk tolerance.

    Fix: Remember appetite as the overall level of risk sought, and tolerance as the acceptable deviation from it.

  • Treating hedging as always removing risk.

    Fix: State that hedging reduces exposure, has a cost and can give up gains.

  • Skipping the monitoring and reporting steps.

    Fix: Always close an answer with monitoring, review and who reports to whom.

  • Giving a list with no recommendation in 14-mark answers.

    Fix: End with a clear decision and one line of reasoning tied to the company's objectives.

Last-day revision: Risk Management

  • Business risk is the possibility that events will affect the achievement of objectives.
  • Main types: strategic, operational, financial, compliance and reputational.
  • Process order: establish context, identify, analyse, evaluate, treat, monitor and review, with communication throughout.
  • Risk assessment looks at both likelihood and impact.
  • Responses: avoid, reduce, transfer or accept. Choose based on size of risk and appetite.
  • Risk appetite is the amount of risk the business is willing to take; tolerance is the acceptable variation around it.
  • COSO ERM links risk to strategy and performance; ISO 31000 gives principles, a framework and a process.
  • ISO 31000 is a guideline, not a certification standard.
  • Hedging reduces exposure to price, currency or interest rate movements but may limit gains.
  • Insurance transfers risk; it does not remove it.
  • The board oversees risk; management owns and runs it day to day.
  • Risk culture and regular reporting make the system work in practice.

Risk Management practice questions

Risk Management in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Risk Management: frequently asked questions

Is Risk Management a scoring chapter in Paper 20A?

It can be if you prepare in a structured way. It is mostly conceptual, so clear answers with examples score well. Practise applying ideas to cases rather than only reading notes.

Do I need to learn both COSO ERM and ISO 31000?

Yes, both are in the chapter topics. Learn the structure of each and how they differ in purpose. Expect both MCQs and short written questions on them.

Will this chapter have numerical questions?

Some measurement and hedging questions may involve workings, depending on your study material. Practise them step by step and state your conclusion at the end.

How should I use this chapter in the case scenario MCQs?

Read the scenario once, mark the risk type and the stage of the process it refers to, then choose the option that fits the situation. Do not pick an answer only because a term sounds familiar.