Strategic Performance Management and Business Valuation · Risk Management
Risk Management Process: Steps, Treatment and Reporting
Updated 11 October 2026 · Fact-checked
The risk management process is a repeating cycle: identify risks, assess their likelihood and impact, prioritise them, choose a treatment (avoid, transfer, mitigate or accept), monitor the results, and report to management and the board. In exams, apply each step to the case facts and recommend a response.
Understand Risk Management Process
A risk is the chance that an event will affect the achievement of an objective. It can hurt (a threat) or help (an opportunity). The risk management process is the organised way a company deals with risk. It does not remove all risk. It brings risk to a level the company is willing to accept.
The process starts with the objectives. You cannot judge a risk unless you know what the business is trying to achieve. A delay in a plant upgrade is a big risk for a firm that sells on speed. It matters less for a firm that sells on price. So the first step is to set context: objectives, strategy, and how much risk the board will tolerate (risk appetite).
Then the main steps follow. Identify risks using tools such as brainstorming, checklists, process maps, past loss data and scenario analysis. Assess each risk for likelihood and impact, using a qualitative scale (low, medium, high) or numbers such as expected loss. Prioritise by ranking, often on a risk matrix or heat map, so that effort goes to the risks that matter most.
Next comes treatment. The four common options are avoid (stop the activity), transfer (insurance, outsourcing, contracts, hedging), mitigate or reduce (controls that cut likelihood or impact) and accept (do nothing more and keep the risk). Some texts call these terminate, transfer, treat and tolerate. The choice depends on cost versus benefit and on risk appetite.
Finally, monitor and review whether controls work and whether risks have changed, and communicate and report to management, the board and, where required, outside parties. Because business conditions change, the process is a loop, not a one-time exercise. Risks left after treatment are called residual risk; risk before treatment is inherent risk.
Key rules to remember
- Expected loss
- Expected loss = Probability of the event × Impact (loss) if it occurs
- Use it to rank risks numerically. It hides rare but severe events, so judge high-impact risks separately.
- Residual risk
- Residual risk = Inherent risk − Risk reduced by controls and other treatment
- This is a concept, not an exact calculation. Compare residual risk with risk appetite to decide if more action is needed.
- Process sequence
- Identify → Assess → Prioritise → Treat → Monitor → Report (repeat)
- Context setting comes before identification. Monitoring and reporting feed back into the next cycle.
- Treatment options
- Avoid | Transfer | Mitigate (reduce) | Accept (retain)
- Name the option and justify it with cost, impact and risk appetite.
- Cost-benefit test for treatment
- Treat if reduction in expected loss > cost of the treatment
- Also consider non-financial effects such as reputation, safety and legal compliance.
How to solve Risk Management Process questions
Use this method for case-based and descriptive questions on the risk management process. It keeps the answer structured and tied to the case.
- 1Read the case and note the objectives, the industry and any stated risk appetite.
- 2List the risks the case shows. Group them as strategic, operational, financial, compliance or other types.
- 3Assess each risk for likelihood and impact. Use expected loss if numbers are given; otherwise use high, medium or low with a reason.
- 4Rank the risks and say which need action first. A simple matrix with likelihood and impact works well.
- 5Pick a treatment for each priority risk: avoid, transfer, mitigate or accept. Give a reason based on cost, impact and appetite.
- 6State the monitoring method: key risk indicators, control testing, internal audit, periodic review.
- 7Say who reports what to whom, and how often. End with a clear recommendation.
Quickest way: Risk, rank, respond, review
When to use it: Use when a question gives a short scenario with limited time, or asks you to list and explain steps or treatments.
- Write the six steps in order as a one-line skeleton.
- Pick the two or three biggest risks in the case.
- For each, write likelihood, impact and one treatment option with a one-line reason.
- Add one monitoring measure and one reporting line.
- Close with the residual risk and whether it fits appetite.
Common mistakes in Risk Management Process
Listing the steps as theory without linking them to the case.
Students memorise the sequence and stop there.
Fix: Name the actual risk from the case under each step and say what the company should do.
Confusing transfer with avoid.
Both seem to move risk away from the business.
Fix: Avoid means you stop the activity. Transfer means you keep the activity but pass the financial effect to another party, such as an insurer.
Treating every risk the same way.
Students think all risks need controls.
Fix: Prioritise first. Low-impact, low-likelihood risks can often be accepted, and a costly control on a minor risk is poor judgement.
Ignoring monitoring and reporting.
The treatment step feels like the end of the answer.
Fix: Always add review, key risk indicators and reporting to the board or risk committee.
Mixing up inherent and residual risk.
Both terms sound alike.
Fix: Inherent is before controls. Residual is what remains after controls and treatment.
Using expected loss alone to rank risks.
It gives a neat number and feels precise.
Fix: Flag low-probability, very high-impact risks separately, since expected loss can make them look small.
Worked examples
Example 1
A Pune manufacturer faces three risks for the next year. (1) Fire at the main plant: probability 2%, loss ₹5,00,00,000. (2) Supplier delay: probability 30%, loss ₹10,00,000. (3) Minor pilferage: probability 50%, loss ₹40,000. Calculate expected loss, rank the risks and suggest a treatment for each.
Show the solution
- Fire: 2% × ₹5,00,00,000 = ₹10,00,000.
- Supplier delay: 30% × ₹10,00,000 = ₹3,00,000.
- Pilferage: 50% × ₹40,000 = ₹20,000.
- Ranking by expected loss: fire (₹10,00,000), supplier delay (₹3,00,000), pilferage (₹20,000).
- Fire: impact is very large, so transfer through fire insurance and mitigate with sprinklers and safety audits.
- Supplier delay: mitigate by adding a second supplier and holding buffer stock, if the cost is below ₹3,00,000 of expected loss.
- Pilferage: the loss is small, so accept it with basic controls such as gate checks.
Answer: Expected losses are ₹10,00,000 (fire), ₹3,00,000 (supplier delay) and ₹20,000 (pilferage). Rank them in that order. Transfer and mitigate fire, mitigate supplier delay, and accept pilferage with light controls.
Example 2
A Bengaluru software company plans to enter a new country where data laws are strict and its team has no local experience. Explain how the company should apply the risk management process to this decision.
Show the solution
- Context: the objective is growth in the new market. The board must state how much compliance and financial risk it will accept.
- Identify: legal and data-protection non-compliance, currency movement, lack of local talent, reputation damage, contract disputes.
- Assess: data-law breach has moderate likelihood but very high impact (penalties, loss of clients). Currency risk has high likelihood and moderate impact.
- Prioritise: data-law compliance first, then currency, then talent and disputes.
- Treat: mitigate data risk through local legal advice and secure systems. Transfer currency risk through forward contracts. Transfer part of the liability through cyber insurance. Avoid entry if compliance cannot be achieved at acceptable cost.
- Monitor: track compliance audit results, incident counts and currency exposure monthly.
- Report: the risk committee reviews quarterly and escalates serious breaches to the board at once.
Answer: Apply the cycle in order: set context, identify, assess, prioritise, treat, monitor and report. Focus on data-law compliance first, hedge currency, insure residual liability, and avoid entry if risk stays above appetite.
Exam tips
- In case questions, tie every step to a fact in the case. Generic theory earns fewer marks.
- Use the four treatment names exactly and justify each choice with cost, impact and appetite.
- For MCQs, watch the difference between inherent and residual risk and between avoid and transfer.
- If numbers are given, show expected loss first, then add a judgement on severe low-probability events.
- Close long answers with monitoring, reporting and a one-line recommendation.
Practice questions from Risk Management
- Under the risk-management approach of treating risks by response, Sundaram Textiles decides to stop exporting to a politically unstable coun…
- Aarav Textiles estimates that a fire could damage its warehouse stock. Probability of a fire in a year is 2%, and the loss if it occurs is R…
- A bank uses a one-day 99% Value at Risk (VaR) of Rs 4 crore for its trading book, assuming returns are independent and normally distributed.…
- In enterprise risk management, a company decides to exit a product line because the potential losses from regulatory changes are judged to b…
- A project's cash loss, if a risk event occurs, is Rs 40 lakh. The probability of occurrence is 15%. Management buys cover that will pay 70% …
Risk Management Process in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Risk Management Process: frequently asked questions
What are the steps in the risk management process?
The usual steps are set context, identify, assess, prioritise, treat, monitor and review, and communicate and report. Different frameworks word them slightly differently. Write the sequence clearly and explain each with an example.
What are the risk treatment options?
The four common options are avoid, transfer, mitigate (reduce) and accept (retain). Avoid stops the activity. Transfer passes the financial effect to another party. Mitigate cuts likelihood or impact. Accept keeps the risk because it is within appetite or too costly to treat.
How do I assess business risk in an exam answer?
Rate each risk on likelihood and impact. Use expected loss if figures are given. Otherwise use high, medium and low with a reason. Then rank the risks so you can show which need action first.
What is the difference between inherent and residual risk?
Inherent risk is the risk before any controls or treatment. Residual risk is what remains after them. Management compares residual risk with risk appetite to decide whether more action is needed.