Strategic Performance Management and Business Valuation · Risk Management
Risk Governance, Culture and Reporting for CMA Final
Updated 11 October 2026 · Fact-checked
Risk governance is the system of roles, policies and reporting lines through which a board sets risk appetite, oversees management and gets assurance that risks stay within limits. You solve questions by naming who is responsible, what limit applies, how risks are recorded in a register, and how they are reported.
Understand Risk Governance, Culture and Reporting
Risk governance answers one question: who is accountable for risk, and how do they know it is under control? Without it, risk management is a set of unconnected activities done by different people.
The board is ultimately responsible. It sets strategy, decides how much risk the company will take, and oversees management. Many boards delegate detailed work to a risk management committee, which reviews the risk framework, policies, major exposures and mitigation plans, and reports back to the board. Management owns day-to-day risk. A chief risk officer or risk function coordinates, challenges and reports, but does not take over ownership from business managers. Internal audit gives independent assurance.
Risk appetite is the amount and type of risk the organisation is willing to accept to achieve its objectives. It is a broad, board-level statement, for example: low appetite for regulatory breaches, moderate appetite for market-entry risk. Risk tolerance is the acceptable variation around a specific objective or limit, set in measurable terms, for example: debtor days may not exceed 60, or a single customer may not exceed 15% of revenue. Appetite is the direction; tolerance is the operating limit that can be monitored. Some frameworks also use risk capacity, the maximum risk the firm can bear before survival is threatened.
Risk culture is the shared values, attitudes and behaviour towards risk. It shows in whether staff report problems early, whether bad news travels upward, and whether rewards encourage reckless targets. The tone at the top matters, but it must be backed by clear accountability, training and incentives that do not reward ignoring limits.
A risk register is the working record of risks. Typically it lists a risk ID, description, cause and consequence, category, likelihood, impact, rating, existing controls, further actions, risk owner, deadline and status. Risks are then reported through dashboards and summaries to the risk committee, board and, in the annual report, to stakeholders. Good reporting is timely, focused on the top risks, shows trends against tolerance, and gives decisions to take, not just data. For listed Indian companies, the board's responsibility for risk and the role of a risk management committee are set by SEBI listing rules and the Companies Act. Check the exact requirements in your study material before quoting them.
Key rules to remember
- Risk rating (scoring)
- Risk score = Likelihood score × Impact score
- Commonly a 1-5 scale for each, giving 1-25. Use the scale given in the question. Score before controls is inherent risk; after controls is residual risk.
- Appetite versus tolerance
- Appetite = broad willingness to take risk; Tolerance = measurable limit around an objective
- Capacity is the ceiling above both. Appetite and tolerance should sit within capacity.
- Expected loss
- Expected loss = Probability of event × Loss if it occurs
- Useful for ranking risks in a register when probabilities and rupee impacts are given.
- Three lines model
- 1st line: business owns risk; 2nd line: risk and compliance oversee; 3rd line: internal audit assures
- Use it to describe who does what in governance.
- Standard risk register columns
- ID | Risk | Cause/Consequence | Likelihood | Impact | Score | Controls | Action | Owner | Due date | Status
- Include owner and action in any register you draw. Marks are lost when they are missing.
How to solve Risk Governance, Culture and Reporting questions
Governance questions are application questions. Tie every point to the company in the case, not to textbook lists.
- 1Read the case and identify the governance gap: unclear ownership, no limits, weak culture, poor reporting or no escalation.
- 2State the relevant concept in one line, for example risk appetite versus tolerance, or the role of the committee.
- 3Assign roles: board for oversight and appetite, committee for review, management and risk owners for action, risk officer for coordination, internal audit for assurance.
- 4If a register is asked for, draw it with columns and fill two to four rows using the case facts, with scores, controls, owners and actions.
- 5Link limits to numbers: convert appetite into tolerance levels that can be measured and monitored.
- 6Say how and how often risks will be reported, to whom, and what triggers escalation.
- 7Close with a clear recommendation of two or three specific actions and who should do them.
Quickest way: Who, Limit, Record, Report
When to use it: Use for short answers and for case MCQs when time is tight.
- Who: name the accountable body or person.
- Limit: identify the appetite statement and the measurable tolerance.
- Record: refer to the risk register with owner and action.
- Report: state the frequency, audience and escalation trigger.
- For MCQs, spot the keyword: broad and strategic means appetite; numeric and operational means tolerance; behaviour and attitudes means culture.
Common mistakes in Risk Governance, Culture and Reporting
Treating risk appetite and risk tolerance as the same thing.
Both talk about how much risk is acceptable, and some textbooks use them loosely.
Fix: Write appetite as the broad board-level stance and tolerance as the specific measurable limit. Give a numeric example for tolerance.
Saying the risk officer or committee owns all risks.
Students link risk with the risk function.
Fix: Business managers own their risks. The committee oversees and the risk officer coordinates and challenges.
Drawing a risk register without owner, action or status.
Students focus only on likelihood and impact.
Fix: Always include controls, action, owner, deadline and status. A register is a management tool, not just a list.
Describing culture only as the tone at the top.
It is the most quoted phrase.
Fix: Add behaviour, incentives, communication, training and accountability. Show how each affects what staff actually do.
Confusing inherent and residual risk when scoring.
The case mentions controls and students forget to adjust.
Fix: Inherent is before controls, residual is after. Say which one you are scoring.
Reporting every risk to the board.
Students assume more information is better.
Fix: Report top risks, breaches of tolerance and trends. Detailed registers stay with management and the committee.
Worked examples
Example 1
Sundaram Foods Ltd states: 'We have a low appetite for food-safety failures.' The board wants this made operational. Suggest suitable risk tolerance measures and explain how appetite and tolerance differ.
Show the solution
- Identify the appetite statement: low appetite for food-safety failures. It is broad and strategic.
- Define tolerance: a measurable limit within which operations must stay.
- Convert into measures, for example: zero tolerance for product recalls on health grounds; customer complaints on safety not above 2 per million units; audit non-conformances closed within 15 days; lab test failures below 0.5% of batches.
- Assign owner: head of quality for the measures, with monthly reporting to the risk committee.
- Set an escalation trigger: any breach of tolerance goes to the committee within 48 hours.
Answer: Appetite is the board's broad stance on food safety. Tolerance converts it into measurable limits such as complaint rates and batch failure rates, with an owner, monthly reporting and escalation on breach.
Example 2
Kaveri Textiles Ltd has a risk that its largest customer, contributing 40% of revenue, may switch suppliers. Likelihood is 3 and impact is 5 on a 1-5 scale. After adding a long-term contract and new customer development, likelihood falls to 2 and impact to 4. Prepare a register entry with inherent and residual scores.
Show the solution
- Inherent score = 3 × 5 = 15.
- Residual score = 2 × 4 = 8.
- Describe the risk: loss of key customer. Cause: concentration. Consequence: revenue and cash flow fall sharply.
- Controls: multi-year supply contract with minimum offtake.
- Further action: develop three new customers to cut the top customer share below a 25% tolerance.
- Owner: Head of Sales. Due date: within 12 months. Status: in progress.
Answer: Risk R1, customer concentration: inherent score 15, residual score 8. Controls: multi-year contract. Action: new customer development to reduce concentration below 25%. Owner: Head of Sales, with quarterly reporting to the risk committee.
Exam tips
- Always give a numeric example when asked to distinguish appetite from tolerance. It separates strong answers from average ones.
- When asked to prepare a risk register, draw a small table-style list with at least five columns and two filled entries from the case.
- In role questions, split responsibilities among board, committee, management, risk officer and internal audit. Do not assign everything to one body.
- For reporting questions, mention audience, frequency, content and escalation. Four points score better than a general statement.
- In MCQs, watch for options that confuse residual with inherent risk or appetite with tolerance.
Practice questions from Risk Management
- Aarav Textiles estimates that a fire could damage its warehouse stock. Probability of a fire in a year is 2%, and the loss if it occurs is R…
- Under the risk-management approach of treating risks by response, Sundaram Textiles decides to stop exporting to a politically unstable coun…
- A bank uses a one-day 99% Value at Risk (VaR) of Rs 4 crore for its trading book, assuming returns are independent and normally distributed.…
- A company expects Rs 10 crore of sales in USD next quarter and enters a forward contract to sell the dollars at a fixed rate. Which risk-man…
- In enterprise risk management, a company decides to exit a product line because the potential losses from regulatory changes are judged to b…
Risk Governance, Culture and Reporting in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Risk Governance, Culture and Reporting: frequently asked questions
What is the difference between risk appetite and risk tolerance?
Risk appetite is the broad level and type of risk an organisation is willing to accept to meet its objectives. Risk tolerance is the measurable range of acceptable variation around a specific objective or limit. Appetite guides strategy; tolerance guides monitoring.
What should a risk register contain?
At minimum, a risk ID, description, cause and consequence, likelihood, impact, score, existing controls, further actions, owner, deadline and status. Many registers also show inherent and residual scores and the risk category.
What does a risk management committee do?
It reviews the risk framework and policies, monitors major exposures and whether they stay within appetite and tolerance, and reports to the board. It supports the board's oversight but does not replace management's ownership of risk. For listed Indian companies, check the exact rules in your study material.
What is risk culture and why does it matter?
Risk culture is the shared attitudes and behaviour towards taking and reporting risk. A weak culture hides problems and rewards excess risk, so even good policies fail. A strong culture encourages early reporting and clear accountability.