2.1 The Risk Management Process
Key Takeaways
- Risk management is the systematic identification and treatment of risks facing an individual or organisation
- The process has five steps: identification, analysis, evaluation, treatment, and monitor and review
- Risk treatment options are the 4 Ts: Terminate (avoid), Treat (reduce/control), Transfer (insure or contract), Tolerate (retain)
- Risk control covers avoid and reduce; risk financing covers transfer and retain
- Insurance is only one form of risk transfer - non-insurance transfer is also possible through contracts
What Is Risk Management?
Risk management is the systematic identification and treatment of risks facing an individual or organisation. It is not a one-off exercise but a continuous process that allows households, firms, and public bodies to understand what could go wrong, decide how to respond, and check that their response still works as circumstances change.
The aim is not to eliminate risk entirely - that would be impossible and wasteful - but to bring exposure in line with risk appetite: the amount and type of risk an entity is willing to accept in pursuit of its objectives.
The Five-Step Process
Most UK textbooks, following the framework set out in ISO 31000 and theIRM's guidance, describe the risk management process in five linked steps.
Step 1 - Risk Identification
The first question is simply: what can go wrong? Techniques include risk audits, structured checklists, site inspections, brainstorming workshops, review of historical incident data, and analysis of near-misses. For a manufacturer this might reveal fire, supply-chain failure, product liability, cyber breach, or key-person illness. For a household it might reveal fire, theft, redundancy, or early death of a breadwinner.
Step 2 - Risk Analysis (Assessment)
Each identified risk is analysed for frequency (how often it is likely to occur) and severity (the likely financial impact if it does). A risk that is high-frequency but low-severity (minor vehicle bumps) is managed very differently from one that is low-frequency but high-severity (a major fire). The output is often plotted on a risk matrix heat map.
Step 3 - Risk Evaluation
Risks are compared against the organisation's risk appetite and stated criteria, then ranked so that attention and money are directed at the priorities. A risk that falls inside appetite may be tolerated; one that exceeds appetite must be treated.
Step 4 - Risk Treatment
A treatment is selected for each priority risk. The four options are set out below and are often remembered as the 4 Ts or ARRT (Avoid, Reduce, Retain, Transfer).
| Treatment | Also known as | Action | Example |
|---|---|---|---|
| Avoidance | Terminate | Do not undertake the activity at all | A haulier refuses to carry hazardous goods |
| Reduction / Control | Treat | Loss prevention and loss minimisation | Fitting sprinklers, alarms, staff training |
| Transfer | Transfer | Shift the financial consequence to another party | Buying insurance, or passing risk to a contractor via a build contract |
| Retention | Tolerate | Accept the risk internally | Self-insurance, voluntary deductibles, setting up a captive |
Two clarifications are worth memorising. First, insurance is only one form of transfer. Non-insurance transfer is also possible - for example, a construction contract may pass liability for site damage to the builder. Second, retention can be voluntary (a deliberate decision to keep the risk) or involuntary (the risk is simply not insured because no market exists or the premium is unaffordable).
Step 5 - Monitor and Review
Risks change: new products, new regulations, new cyber threats, climate-driven weather patterns. The risk register is reviewed periodically, treatments are tested for effectiveness, and the process loops back to Step 1. Without this step, risk management becomes a one-off paperwork exercise rather than a living discipline, and emerging exposures - a new supply chain, a new data system - go unrecognised until they produce a loss.
Risk Control vs Risk Financing
A useful exam distinction groups the four treatments into two families.
- Risk control - actions that reduce the risk itself: avoidance and reduction. They lower either the likelihood or the impact of a loss.
- Risk financing - actions that pay for the loss when it happens: transfer and retention. They do not reduce the risk; they decide who bears the cost.
A well-run programme uses both: control the risk first, then finance whatever residual risk remains.
Worked Example - A Small Manufacturer
Imagine a furniture maker with a £2m factory, £500k of stock, and 40 staff. Risk identification surfaces fire (wood dust, finishes), theft, employers' and public liability, product liability, business interruption, and cyber breach. Analysis shows fire is low-frequency but potentially catastrophic (£2m+), while minor vehicle damage is high-frequency but low-severity (£2-5k). Evaluation ranks fire and liability above vehicle damage. Treatment pairs control (sprinkler upgrade, dust extraction maintenance, staff training) with financing (property and liability insurance, a £1k voluntary deductible to retain the small losses, and a self-insured retention for cyber where the market is thin). Monitor and review means revisiting the register annually and after any major change - a new product line, a new site, or a significant claim.
Why the Process Matters for Insurers
Insurers are themselves major risk managers. They identify, analyse, and treat their own underwriting and investment risks, and they require their policyholders to demonstrate risk control before offering cover at an affordable premium. A surveyor who insists on a sprinkler system before granting property cover is applying Step 4 (risk reduction) to someone else's risk as a condition of providing Step 4 (transfer) to the residual. Understanding the process is therefore the foundation of the IF1 syllabus and of every later chapter on underwriting and claims.
A UK manufacturer decides to stop producing a chemical that is the subject of rising product-liability claims. Which risk treatment option is it applying?
Which pairing correctly separates risk control from risk financing?