Risk assessment identifies financial exposures, analyzes likelihood and severity, evaluates residual risk, and prioritizes action.
Risk assessment is the structured process of identifying exposures, analyzing how adverse events could occur, estimating their likelihood and financial consequences, evaluating existing controls, and deciding which risks require action. It converts a broad concern into evidence that can support limits, pricing, mitigation, capital, liquidity, disclosure, or escalation.
Risk analysis is one stage within the assessment. Analysis estimates or describes likelihood, severity, timing, concentration, and uncertainty. Assessment goes further by comparing the analyzed risk with criteria such as risk appetite, limits, legal obligations, or decision thresholds.
| Stage | Main question | Typical output |
|---|---|---|
| Identification | What can affect value, cash flow, obligations, customers, or operations? | Risk inventory, event description, exposure |
| Analysis | How could the event occur, and how large or likely could the effect be? | Likelihood, severity, sensitivity, scenario, model result |
| Evaluation | Is the analyzed risk within criteria and capacity? | Appetite or limit comparison, materiality, priority |
| Treatment | What response changes the risk or funds the loss? | Avoid, reduce, transfer, retain, control, hedge |
| Monitoring | What indicates that exposure or effectiveness has changed? | Indicator, limit use, exception, review date |
The distinction matters because a model output can be analytically correct but still fail to answer whether the exposure should be accepted or changed.
State the legal entity, portfolio, product, process, transaction, time horizon, valuation date, and decision. Scope should include material dependencies and contingent obligations, not just items already recorded as losses.
Describe the event, source, transmission path, and financial consequence. Examples include borrower default, rate change, price decline, funding withdrawal, system outage, fraud, legal challenge, or supplier failure.
Use source records such as positions, balances, contracts, cash-flow forecasts, commitments, collateral, customer data, incident history, and system inventories. Label whether the amount is gross, net, current, potential, stressed, or residual.
Choose methods that fit the evidence:
Use ranges where the evidence does not support a precise point estimate.
Identify preventive, detective, corrective, and recovery controls. Test whether each control is appropriately designed and actually operated during the period. Policy wording alone should not reduce the assessed risk.
Reassess likelihood and severity after recognizing realistic control effectiveness, collateral, insurance, hedges, guarantees, diversification, and funding. Include exclusions, basis risk, delays, wrong-way risk, and control failure.
Compare residual risk with appetite, limits, legal obligations, liquidity, capital, and customer or fiduciary duties. Assign a response, owner, deadline, escalation trigger, and review frequency.
Qualitative methods use categories such as low, moderate, high, or critical. They are useful when data are scarce or rapid prioritization is needed. The definitions should state:
Without common definitions, one reviewer’s “high” can be another reviewer’s “moderate.”
Quantitative methods estimate amounts, probabilities, distributions, sensitivities, or cash-flow effects. They can compare alternatives more precisely but depend on data quality, model design, and assumptions.
Scenarios combine related changes and management actions. They are especially useful for tail risk, liquidity, nonlinear positions, operational disruptions, and new products with limited history.
A likelihood-impact matrix can organize a discussion, but multiplying ordinal scores such as 4 x 5 = 20 does not create a true monetary measure. Different combinations can produce the same score while requiring very different responses.
Assume a manufacturer has annual revenue of 50 million dollars. One customer provides 12 million, or 24% of revenue, and pays in 60 days.
The assessment should not stop at “24% concentration.” It should examine:
A base scenario might assume a temporary payment delay. A severe scenario might assume customer default and lost future sales. The same exposure can produce credit loss, inventory write-down, lower cash flow, covenant pressure, and operational restructuring.
If the residual risk exceeds appetite, possible actions include reducing the credit limit, obtaining deposits or insurance, changing terms, diversifying customers, holding more liquidity, or declining additional orders. The chosen response should match the loss path rather than the concentration percentage alone.
Reassessment may be needed after:
A scheduled annual review may be insufficient for fast-changing exposures.
These sources describe supervisory expectations for financial institutions. Other organizations should adapt the process to their activities, contracts, and applicable requirements.
This article is for financial education and does not provide personalized investment, trading, banking, regulatory, legal, insurance, or risk-management advice.