Skip to content

NISM-Series-VII: Securities Operations and Risk Management · Risk Management

Risk Management Framework and Types of Risk in Securities Markets

Updated 11 October 2026 · Fact-checked

Risk is the chance that an actual outcome differs from the expected one, usually in a loss. In securities markets, the main types are market, credit, liquidity, operational and legal risk. To answer a question, identify the source of the loss, match it to the type, then name the process step or control.

Understand Risk Management Framework and Types of Risk

Risk is the possibility that the actual result differs from what you expected. In practice you worry about the adverse side: a loss of money, a failed settlement, or a penalty. Risk cannot be removed in markets. It can be identified, measured, limited and monitored.

The exam tests five types. Market risk is loss from adverse movement in prices, interest rates, exchange rates or other market variables. Credit risk (also called counterparty risk) is loss because the other party fails to pay or deliver what it owes. Liquidity risk is the difficulty of buying or selling quickly at a fair price, or of arranging funds when payment is due. Operational risk is loss from failed internal processes, people, systems or external events. Legal risk is loss from contracts that cannot be enforced, non-compliance with rules, or adverse legal or regulatory action.

The key test is to ask: what actually caused the loss? Price moved against you: market risk. Counterparty did not pay: credit risk. You could not exit without a big price hit: liquidity risk. A clerk keyed a wrong order or a system crashed: operational risk. A contract was unenforceable or a rule was breached: legal risk. One event can trigger several risks, but the exam usually wants the primary one.

The risk management process is a cycle: identify the risks, measure or assess them, set limits and controls to mitigate them, then monitor and report, and review the framework regularly. Governance means that the board and senior management set the risk policy and appetite, assign clear responsibility, and keep risk control independent from the people who take the risk. A common structure has a dedicated risk management function and a committee that reviews risk reports.

Key formulas to remember

Risk definition
Risk = chance that actual outcome differs from expected outcome (adverse side is the exam focus)
Not the same as certain loss. It is uncertainty about the result.
Five risk types
Market | Credit | Liquidity | Operational | Legal
Match the type to the cause of the loss, not to the size of the loss.
Risk management process
Identify → Measure → Mitigate (limits and controls) → Monitor and report → Review
Order matters. You cannot set limits before you identify and measure.
Credit risk also called
Credit risk = counterparty risk (default or non-performance by the other party)
In settlement, this is the risk that a party does not meet its pay-in obligation.

How to solve Risk Management Framework and Types of Risk questions

Use this method for any scenario or definition question on risk types and the framework.

  1. 1Read the last line first to see what is asked: the type of risk, the process step, or a governance point.
  2. 2Find the event in the scenario that caused the loss or could cause it.
  3. 3Ask the cause test: price movement, counterparty default, inability to trade or fund, internal failure, or legal and rule issue.
  4. 4Match the cause to one of the five types and ignore the other details.
  5. 5If the question is about process, place the action in the cycle: identify, measure, mitigate, monitor, review.
  6. 6If it is about governance, look for who sets policy (board and senior management) and who keeps control independent.
  7. 7Check the options for a near-match trap, such as credit risk against market risk, and pick the one tied to the cause.

Quickest way: Cause-word matching

When to use it: Use it when time is short and the question is a one-line scenario with four options.

  1. Spot the cause word: price or rate means market; default or fails to pay means credit; cannot sell or fund means liquidity; error, system or fraud means operational; contract, compliance or penalty means legal.
  2. Eliminate options that name a different cause word.
  3. For process questions, pick the option that fits the cycle order.
  4. Do not change an answer without a clear reason, since wrong answers can cost marks.

Common mistakes in Risk Management Framework and Types of Risk

  • Treating credit risk and market risk as the same because both cause a loss of money.

    Students focus on the result (loss) and not the cause.

    Fix: Ask what failed. If the price moved, it is market risk. If a party did not honour its obligation, it is credit risk.

  • Calling a trading system failure or a wrong order entry a market risk.

    The loss shows up in a trading account, so it feels like a market loss.

    Fix: Errors in people, process or systems are operational risk, even if they occur during trading.

  • Confusing liquidity risk with credit risk when a counterparty does not pay.

    Both can lead to a cash shortfall.

    Fix: Liquidity risk is about inability to trade or arrange funds on time. Non-payment by the other party is credit risk.

  • Assuming risk management aims to eliminate risk.

    The word management sounds like total control.

    Fix: The aim is to keep risk within an acceptable level through identification, limits and monitoring.

  • Placing the steps of the risk process in the wrong order, for example setting limits before measuring.

    Students memorise the steps without the logic.

    Fix: Remember that you must know the risk and its size before you can limit it: identify, measure, mitigate, monitor, review.

  • Thinking the risk function can report to the business unit it controls.

    Students overlook independence.

    Fix: Good governance keeps risk control independent of those who take the risk, with oversight from senior management and the board.

Worked examples

Example 1

A broker's client buys shares and the price falls sharply the next day. Separately, another client fails to pay the money due for a purchase. Which risks do these two events represent, in that order?

Show the solution
  1. Event one: the loss comes from the price moving against the investor. The cause is price movement.
  2. Price movement is market risk.
  3. Event two: the loss comes from a client not meeting a payment obligation. The cause is counterparty non-performance.
  4. Counterparty non-performance is credit risk.

Answer: Market risk, then credit risk.

Example 2

A risk team is asked to arrange the steps of the risk management process for a new product. A senior asks them to put these in order: (a) set exposure limits, (b) quantify the likely loss, (c) list the possible risks, (d) review risk reports each month. Which sequence is correct?

Show the solution
  1. First you must know which risks exist: list the risks (c) is identification.
  2. Next you measure their size: quantify the likely loss (b).
  3. Then you mitigate by setting limits (a).
  4. Finally you monitor and report (d), and later review the framework.
  5. The order is c, b, a, d.

Answer: c, b, a, d (identify, measure, mitigate, monitor).

Exam tips

  • Most questions are one-line scenarios. Underline the cause word and match it to the risk type before reading the options.
  • Watch the pair credit risk and market risk, and the pair operational risk and legal risk. These are the usual trap options.
  • Remember that Series VII has negative marking of 25% of the marks assigned to a question, so skip a question rather than guess blindly when you cannot narrow the options.
  • Learn the process order and the independence of the risk function as fixed points. Governance questions often test only these.

Practice questions from Risk Management

Risk Management Framework and Types of Risk in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Risk Management Framework and Types of Risk: frequently asked questions

What are the main types of risk in the securities market for NISM Series VII?

The main types are market, credit, liquidity, operational and legal risk. Learn each by its cause: price movement, counterparty default, inability to trade or fund, internal failure, and legal or compliance issues.

What is the difference between market risk and credit risk?

Market risk is loss from adverse movement in prices, rates or other market variables. Credit risk is loss because a counterparty fails to meet its obligation. The first comes from the market, the second from a specific party.

What is the risk management process?

It is a cycle of identifying risks, measuring them, mitigating them through limits and controls, and monitoring and reporting. The framework is also reviewed regularly. Governance ensures the board and senior management own the policy.

Is there negative marking in NISM Series VII?

Yes. Series VII has negative marking of 25% of the marks assigned to a question. The exam has 100 questions, 100 marks, 2 hours and a pass mark of 50%.