The Risk Management Process

Introduction to Risk Management Process | CFA Level I Portfolio Management

Risk management is an essential aspect of both organizational and individual decision-making. In this lesson, we’ll briefly introduce the risk management process, its goals, and the key features of a risk management framework.

Risk management is not about minimizing risk, but rather understanding and embracing necessary risks while being mindful of the probability of failure. The risk management process aims to:

  • Establish an appropriate risk tolerance level for the organization or individual
  • Identify and measure the risks currently being taken
  • Modify and monitor these risks such that they are consistent with the stated risk tolerance

For organizations, the goal of risk management is to maximize the company’s or portfolio’s value. For individuals, the goal is to maximize overall satisfaction or utility.

Risk Management Framework

A risk management framework is the infrastructure and processes needed to support effective risk management activities. A custom solution for any organization should encompass:

  • Risk governance
  • Risk identification and measurement
  • Risk infrastructure
  • Defined policies and processes
  • Risk monitoring, mitigation, and management
  • Communications
  • Strategic risk analysis

Let’s discuss these in the context of a large company.

Risk Governance

At the top is risk governance, where the board committee defines the organization’s goals and decides on its risk tolerance level. The board may provide guidance on risk budgeting and set high-level policies affecting most risk management processes.

Role of Management

The management’s role is to plan and execute value-maximizing strategies to achieve the goals set by the board. Management allocates capital to risky activities, ensuring the overall risk taken is consistent with the defined risk tolerance and risk budget. They also actively participate in implementing risk management policies and establishing procedures for each element of the risk framework.

Risk Management Infrastructure

The management establishes a risk management infrastructure where employees and systems identify and measure risks.

Risk Monitoring, Mitigation, and Management

Management monitors risks to ensure they’re in line with planned risk exposure limits and policies. If any risk is out of line, risk mitigation and management actions are taken to modify risk levels and bring them back into compliance.


Communicating risk levels across the organization is crucial. Regular and timely reporting of key risk metrics helps management make informed decisions and the board fulfill its governance duties.

Strategic Risk Analysis

Strategic analysis, supported by risk measurement, reporting, and other steps of the risk management process, helps management improve decision-making and allocate capital and risk budget most effectively.

In conclusion, this lesson provided a brief introduction to the risk management process and its framework. We’ll delve deeper into the details in subsequent lessons. See you again!

