Skip to content

Environmental, Social and Governance (ESG) - Principles and Practice · Risk Management

Risk Mitigation, Treatment and Response: Avoid, Reduce, Transfer, Accept

Updated 11 October 2026 · Fact-checked

Risk treatment is how a company responds to a risk it has already assessed. The four core responses are avoid, reduce, transfer and accept. You pick one by comparing the risk with the company's risk appetite and the cost of the response. Then you put controls in place, monitor them and report to the board.

Understand Risk Mitigation, Treatment and Response

Risk management does not end when you identify and rate a risk. A rated risk still has to be dealt with. Risk treatment (also called risk response) is the set of decisions and actions a company takes to bring a risk within the level it is willing to bear.

That level is the risk appetite: the amount and type of risk the board is ready to take to pursue its objectives. Risk tolerance is the acceptable deviation around that appetite for a specific objective. Every treatment decision is a comparison: is the current risk above or within appetite, and what will it cost to change it?

There are four standard responses:

  • Avoid (terminate): stop the activity that creates the risk. Example: a company drops a plan to enter a country with severe sanction risk.
  • Reduce (mitigate or treat): take action to lower the likelihood, the impact, or both. Example: installing fire-suppression systems, diversifying suppliers, training staff.
  • Transfer (share): pass part of the financial consequence to another party. Example: insurance, hedging with derivatives, outsourcing with contractual indemnity.
  • Accept (retain): knowingly bear the risk, usually because it is within appetite or the cost of treatment exceeds the benefit. Example: a small, low-impact risk with a monitoring trigger.

Some frameworks add a fifth response, exploit or take, used for opportunities and upside risk. Learn the four first and mention the fifth only if the question is about opportunities.

Transfer needs care. Insurance or a contract moves the financial loss, not the accountability. Reputation, legal liability and regulatory duty usually stay with the company. After treatment, some residual risk always remains. The board must confirm that residual risk is within appetite.

Treatment is carried out through internal controls: policies, approvals, segregation of duties, reconciliations, access limits, limits on exposure and similar measures. Controls can be preventive (stop the event), detective (find it quickly) or corrective (limit damage and recover). A good response uses a mix.

Finally, risk is dynamic. Companies monitor key risk indicators, test whether controls work, and report up the chain: risk owners to the risk management committee, then to the audit committee and the board. Reporting also covers external disclosure, such as the risk discussion in the Board's Report and, for listed entities, the disclosures required by SEBI's listing regulations.

Key rules to remember

Residual risk
Residual risk = Inherent risk − Effect of controls and treatment
A conceptual relationship, not an arithmetic one in the exam. Inherent risk is the level before any response. Residual risk must be within risk appetite.
Four core responses
Avoid | Reduce | Transfer | Accept
Remember as ARTA. Avoid removes the activity, reduce lowers likelihood or impact, transfer shifts financial consequence, accept retains the risk knowingly.
Selection rule
Choose the response whose cost is justified by the reduction in risk and which brings residual risk within appetite
Use this as the reasoning line in every answer. Cost-benefit plus risk appetite decides the choice.
Control types
Preventive + Detective + Corrective
Preventive stops the event, detective finds it, corrective repairs and recovers.
Reporting chain
Risk owner → Risk management committee → Audit committee / Board
Escalation path used in most company risk structures. Adapt the names to the facts in the question.

How to solve Risk Mitigation, Treatment and Response questions

Use this sequence for any case-based or descriptive question on risk treatment, mitigation or monitoring.

  1. 1Read the facts and name the risk clearly: type (strategic, operational, financial, compliance, ESG, cyber) and what could go wrong.
  2. 2Note the risk rating given or assess it: likelihood and impact, and compare it with the company's stated risk appetite.
  3. 3State the four options in one line each and say which ones are realistic on these facts.
  4. 4Select the best response and give the reason: cost versus benefit, appetite, legal limits. Say what is not suitable and why.
  5. 5Describe the specific actions and internal controls: policy, owner, limits, preventive and detective controls, insurance or contract terms if transferring.
  6. 6State the residual risk and say whether it is within appetite. Mention any risk that cannot be transferred, such as reputation or legal duty.
  7. 7Explain monitoring and reporting: key risk indicators, review frequency, who reports to whom, and board or committee oversight.
  8. 8Close with a one-line conclusion and, where relevant, the Company Secretary's role in documentation, disclosure and compliance.

Quickest way: ARTA plus MR in two minutes

When to use it: Use when time is short or the question is a short note such as 'Explain risk treatment strategies' or 'How are risks monitored?'

  1. Write the definition of risk treatment in one sentence and link it to risk appetite.
  2. List Avoid, Reduce, Transfer, Accept with one example each.
  3. Add one line on residual risk and why transfer does not move accountability.
  4. Add Monitoring and Reporting: key risk indicators, control testing, escalation to committee and board.
  5. If the question has facts, add a one-line recommendation with the reason.

Common mistakes in Risk Mitigation, Treatment and Response

  • Treating transfer as removing the risk completely.

    Insurance feels like a full solution, so students stop at 'buy insurance'.

    Fix: Say that transfer shifts the financial loss only. Legal liability, reputation and regulatory duties usually remain, and insurance has exclusions and limits.

  • Confusing avoidance with reduction.

    Both sound like 'lowering' risk.

    Fix: Avoidance means the activity stops entirely. Reduction means the activity continues with controls. Test: does the company still do the activity?

  • Saying acceptance means ignoring the risk.

    The word suggests doing nothing.

    Fix: Acceptance is a conscious decision, documented, within appetite, and still monitored with a trigger for review.

  • Listing the four strategies without choosing one for the facts.

    Students memorise the list and skip the analysis that case-based papers reward.

    Fix: After the list, pick one with reasons based on likelihood, impact, cost and appetite. Then give concrete actions.

  • Ignoring residual risk and monitoring.

    The answer ends once a response is chosen.

    Fix: Always add residual risk, key risk indicators, review frequency and reporting to the committee and board.

  • Mixing up preventive, detective and corrective controls.

    Examples overlap, such as reconciliations that both detect and support correction.

    Fix: Classify by main purpose and timing: before the event is preventive, finding it is detective, fixing after is corrective.

Worked examples

Example 1

Vindhya Foods Ltd, a listed company, depends on a single supplier in one state for 70% of its packaging material. A flood there would halt production for weeks. The board's risk appetite for supply disruption is low. Advise on the response and monitoring.

Show the solution
  1. Identify the risk: supply-chain concentration, an operational risk. Likelihood is moderate and impact is high, and appetite is low, so the risk is above appetite.
  2. Test the options. Avoid: not practical, since packaging is essential and stopping production defeats the business. Accept: not suitable, as impact is high and appetite is low.
  3. Select reduce as the main response, with partial transfer. Reduce by qualifying two more suppliers in other regions, holding buffer stock and adding supply continuity clauses in contracts.
  4. Transfer part of the financial loss through business interruption insurance and contractual penalties for supplier delay. Note that lost customers and reputation cannot be insured away.
  5. Controls: approved supplier policy, a cap on share of purchases from any one supplier, periodic supplier audits (preventive), stock-level alerts (detective), a business continuity plan with alternate sourcing (corrective).
  6. Residual risk: lower but not nil. The board should confirm it is within appetite after the new suppliers are qualified.
  7. Monitoring: key risk indicators such as share of top supplier, days of stock cover and supplier delivery delays. Review monthly, report quarterly to the risk management committee and the board.

Answer: Reduce the risk through supplier diversification, buffer stock and continuity planning, and transfer part of the financial loss through insurance and contract terms. Avoidance and acceptance are unsuitable. Monitor through key risk indicators and report to the risk management committee and board.

Example 2

Explain how a company should monitor and report risks after it has decided its treatment responses.

Show the solution
  1. State the purpose: monitoring checks that controls work and that risk stays within appetite as conditions change.
  2. Describe ongoing monitoring: risk owners track key risk indicators, such as incident counts or exposure limits, with set thresholds that trigger escalation.
  3. Describe independent assurance: internal audit tests whether controls operate effectively, and findings go to the audit committee.
  4. Describe periodic review: update the risk register, re-rate risks, review whether accepted risks remain acceptable, and check for new or emerging risks.
  5. Describe reporting: risk owners report to the risk management committee, which reports to the board. Include risk status, treatment progress, incidents and residual risk.
  6. Describe external reporting: material risks and their mitigation are discussed in the Board's Report, and listed entities follow the disclosure requirements in the listing regulations.
  7. Add the Company Secretary's role: ensuring policies, minutes, committee charters and statutory disclosures are in place and current.

Answer: Monitoring uses key risk indicators, control testing and internal audit, with periodic risk register reviews. Reporting flows from risk owners to the risk management committee and the board, and material risks are disclosed externally as the law requires. The Company Secretary supports documentation and compliance.

Exam tips

  • For case questions, name the risk, pick one response, and justify it with likelihood, impact, cost and appetite. A bare list of four strategies scores low.
  • Give one practical example per strategy that fits the facts, such as insurance for transfer or supplier diversification for reduction.
  • Always mention residual risk and monitoring. These are the lines that many answers skip.
  • Use the Company Secretary angle: policy drafting, committee documentation, minutes, and disclosures in the Board's Report.
  • Keep the language of laws general unless you are certain of a provision. State the principle clearly instead of guessing a section number.

Practice questions from Risk Management

Risk Mitigation, Treatment and Response in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Risk Mitigation, Treatment and Response: frequently asked questions

What are the four risk treatment strategies?

They are avoid, reduce, transfer and accept. Avoid stops the activity, reduce lowers likelihood or impact, transfer shifts the financial consequence to another party, and accept knowingly retains the risk. The choice depends on risk appetite and cost.

What is the difference between risk mitigation and risk treatment?

Risk treatment is the wider term and covers all responses, including avoid, transfer and accept. Mitigation usually means reduction, which is lowering likelihood or impact. Many books use the two words loosely, so define your usage in the answer.

Does insurance remove a risk?

No. Insurance transfers part of the financial loss, subject to policy limits and exclusions. The company still faces legal liability, reputational harm and operational disruption.

How are risks monitored and reported in a company?

Risk owners track key risk indicators and update the risk register. Internal audit tests the controls. Results are reported to the risk management committee, then to the audit committee and the board, and material risks are disclosed as the law requires.