Environmental, Social and Governance (ESG) - Principles and Practice · Risk Management
Introduction to Risk and Risk Management for CS Professional
Updated 11 October 2026 · Fact-checked
**Risk** is the possibility that actual results differ from expected results, usually to the organisation's cost. **Risk management** is the systematic process of identifying, assessing, treating, monitoring and reporting risks so that objectives are met. In answers, define the term, classify the risks, state the objectives, then list the process steps with an example.
Understand Introduction to Risk and Risk Management
Every business decision is made today, but its result arrives in the future. The future is uncertain. Risk is that uncertainty when it can affect your objectives. Many definitions stress the downside: loss, damage or failure to achieve a goal. Modern thinking also treats risk as an effect on objectives that can be negative or positive, so an opportunity missed is also a risk outcome.
Risk has some clear features. It is linked to uncertainty about future events. It is linked to objectives, so a risk matters only if it can affect something the organisation wants. It can be measured in part, through likelihood and impact. It exists at every level: project, department, company and country. It also changes over time, so one assessment is never final.
Risks are grouped in several ways. By source: internal risks arise inside the company (weak controls, fraud, key person dependence, system failure) and external risks arise outside it (inflation, regulation changes, competition, natural disasters, geopolitical events). By nature, common groups are strategic, operational, financial (market, credit, liquidity), compliance or legal, reputational, technology and cyber, and environmental, social and governance (ESG) risks. Another useful split is systematic risk, which affects the whole market and cannot be removed by diversification, and unsystematic risk, which is specific to a firm or industry.
Risk management is the coordinated effort to deal with that uncertainty. It does not aim to remove all risk, because no business earns returns without taking some. It aims to take risks knowingly, keep them within the level the board is willing to accept (the risk appetite), and respond to them in a planned way. The usual process is: establish context and objectives, identify risks, analyse and evaluate them, treat them, monitor and review, and communicate and report throughout.
The main objectives are to protect assets and value, support achievement of strategic goals, ensure legal and regulatory compliance, improve decision making, avoid surprises, build stakeholder confidence and support business continuity. For a Company Secretary the topic matters because the board is responsible for risk oversight, and you help build the policy, reporting and compliance trail around it.
Key rules to remember
- Basic risk exposure (qualitative rating)
- Risk rating = Likelihood × Impact
- Used to rank risks on a scale such as 1 to 5 each. A higher product means higher priority. Scales are set by the company, not fixed by law.
- Risk management process
- Context → Identify → Analyse → Evaluate → Treat → Monitor and Review (with Communication throughout)
- Frameworks word the steps slightly differently. Learn the sequence and use the same logic in your answer.
- Risk treatment options
- Avoid | Reduce (mitigate) | Transfer (share) | Accept (retain)
- Transfer includes insurance and outsourcing. Accepting a risk should be a conscious decision within risk appetite.
- Risk classification by source
- Internal risks + External risks
- Add the nature-based types (strategic, operational, financial, compliance, reputational, technology, ESG) for a full answer.
- Risk appetite and tolerance
- Risk capacity ≥ Risk appetite ≥ Risk tolerance (limit around the appetite)
- Capacity is the maximum the firm can bear, appetite is what it is willing to take, tolerance is the acceptable deviation. Keep the three terms separate.
How to solve Introduction to Risk and Risk Management questions
Most questions on this topic ask you to explain, classify, list or discuss. Use one structure so that no mark-earning point is missed.
- 1Read the verb. 'Define' needs a short definition. 'Explain' needs meaning plus features. 'Discuss' needs points with reasons. 'Illustrate' needs examples.
- 2Start with a clear definition of risk or risk management in one or two sentences, in your own words.
- 3State the nature or features that matter: uncertainty, link to objectives, measurable in part, present at all levels.
- 4Classify. Give internal and external risks first, then the nature-based types. Add one business example for each type.
- 5Link to objectives or importance if asked. Show why the board and management cannot ignore the topic.
- 6Write the process steps in order, with one line on what happens in each step.
- 7Use a case or an Indian company example where the question gives facts. Identify the risk type, name the response (avoid, reduce, transfer, accept) and justify it.
- 8Close with a one-line conclusion tying risk management to value protection and good governance.
Quickest way: Define, classify, process, conclude
When to use it: Use when you have about 8 to 10 minutes for a theory question and need a complete answer fast.
- Write a two-line definition.
- List internal and external risks with two examples each.
- List the nature-based types in one line each.
- Write the process as six numbered steps, one line each.
- Add one example from the question facts and one closing line.
Common mistakes in Introduction to Risk and Risk Management
Defining risk only as loss or danger.
Everyday use of the word focuses on harm.
Fix: Define risk as uncertainty about outcomes that can affect objectives, and mention that it can also mean missed opportunity.
Saying risk management means eliminating all risk.
Students confuse control with avoidance.
Fix: State that the aim is to take informed risks within risk appetite. Some risks are accepted or even sought for returns.
Mixing up internal and external risks, for example calling a regulatory change internal.
The company is affected by it, so it feels internal.
Fix: Ask where the cause originates. Cause outside the company's control is external. Cause inside its systems, people or decisions is internal.
Listing process steps in the wrong order or skipping monitoring and communication.
Students memorise a list without the logic.
Fix: Remember the flow: understand objectives, find risks, rate them, respond, then keep watching. Mention that communication runs through all steps.
Using risk appetite, risk tolerance and risk capacity as the same thing.
The terms sound alike.
Fix: Capacity is the maximum the firm can absorb. Appetite is the amount it chooses to take. Tolerance is the acceptable variation around objectives.
Giving theory with no example in a case-based question.
Students rush to reproduce notes.
Fix: Pick the facts given, name the risk type, and recommend a response with a reason. Examiners reward application.
Worked examples
Example 1
Explain the meaning of risk and discuss the main types of risk faced by a business. (Model answer outline)
Show the solution
- Meaning: risk is the uncertainty of future events that may affect the achievement of objectives, usually adversely. It has two parts: the chance of the event and its effect.
- By source: internal risks arise from within, such as fraud, poor controls or loss of key staff. External risks come from outside, such as inflation, new regulation, competition or natural disasters.
- Strategic risk: a wrong business decision, such as entering a market without demand.
- Operational risk: failure of processes, people or systems, such as a plant breakdown.
- Financial risk: market risk (interest rate, exchange rate), credit risk (customer default) and liquidity risk (unable to meet dues).
- Compliance risk: breach of laws, leading to penalty or prosecution.
- Reputational risk: loss of trust, for example after a data leak.
- Technology and ESG risks: cyber attacks, climate events, poor labour practices or governance failures.
- Also note systematic risk (affects the whole market) and unsystematic risk (specific to the firm).
Answer: Risk is uncertainty about outcomes that can affect objectives. Businesses face internal and external risks, which appear as strategic, operational, financial, compliance, reputational, technology and ESG risks. Each type needs its own identification and response.
Example 2
A listed manufacturing company, Sundaram Industries Ltd, buys raw material from one supplier in another country, pays in US dollars and sells in India in rupees. The board asks you to outline how the company should manage the risks involved. (Model answer outline)
Show the solution
- Identify: single supplier dependence is an operational (supply chain) risk. Dollar payment against rupee sales is a financial (currency) risk. Both are largely external in origin, though the decision to depend on one supplier is internal.
- Analyse and evaluate: rate each for likelihood and impact. A supplier failure would stop production, so impact is high. Currency movement is likely and directly hits margins, so likelihood is high.
- Treat supply risk: reduce it by developing a second supplier and holding buffer stock.
- Treat currency risk: transfer or reduce it through hedging instruments such as forward contracts, within a board-approved policy. Where practical, negotiate rupee pricing.
- Accept residual risk only if it falls within the risk appetite set by the board, and record that decision.
- Monitor and review: track supplier performance and exchange rate exposure, and review limits periodically.
- Communicate: report key risks and actions to the risk committee and board, and keep records for disclosure and audit.
Answer: Sundaram Industries should identify supply chain and currency risks, rate them by likelihood and impact, reduce supply risk through a second source and buffer stock, hedge currency exposure under board policy, accept only residual risk within appetite, and monitor and report regularly to the board.
Exam tips
- Begin every answer with a short definition. It is the surest mark in a theory question.
- Use headings in the answer such as Meaning, Types, Process, Conclusion. Examiners find points quickly.
- For case questions, name the risk type from the facts and recommend one of avoid, reduce, transfer or accept, with a reason.
- Keep the process steps in order and mention monitoring and communication. These are the steps students most often leave out.
- Give one real or realistic Indian example per type of risk to show application.
Practice questions from Risk Management
- Kaveri Cement Ltd. has plants on the Odisha coast. A cyclone last year shut down one plant for three months and damaged its jetty. The board…
- Sunrise Textiles Ltd, a listed company in Surat, wants a framework that links risk management to strategy-setting and performance across the…
- Himalaya Motors Ltd's risk committee uses interviews and a risk register to rate risks by words such as 'low', 'medium' and 'high' without a…
- Orion Pharma Ltd, a listed company, wants its climate risk disclosures to follow the widely used TCFD-style structure. Which set lists the f…
- Veda Textiles Ltd., a listed manufacturer in Tamil Nadu, finds that new carbon-pricing rules and stricter emission limits could raise its op…
Introduction to Risk and Risk Management: frequently asked questions
What is the meaning of risk management for CS Professional?
Risk management is the systematic process of identifying, assessing, treating, monitoring and reporting risks so that an organisation can achieve its objectives. It aims at informed risk taking within the board's risk appetite, not at removing all risk.
What are the main types of risk in business?
You can group them by source as internal and external. By nature, the common types are strategic, operational, financial, compliance, reputational, technology and ESG risks. Financial risk is often split further into market, credit and liquidity risk.
What are the steps in the risk management process?
The usual sequence is establishing context, identifying risks, analysing and evaluating them, treating them, and monitoring and reviewing. Communication and consultation run through every step. Frameworks vary slightly in wording, so explain the logic of each step.
What is the difference between risk appetite and risk tolerance?
Risk appetite is the amount and type of risk the organisation chooses to take to pursue its objectives. Risk tolerance is the acceptable variation around those objectives or limits. Risk capacity is the maximum the organisation can bear.