11.3 Risk Analysis and Evaluation

Key Takeaways

  • Risk analysis develops understanding of likelihood, consequences, controls, interactions, and uncertainty.

  • Risk evaluation compares analyzed results with predetermined criteria to decide significance and priority.

  • Qualitative ratings require defined scales; quantitative estimates require valid data and assumptions.

  • Control effectiveness depends on design and operating performance, not the mere existence of a policy.

  • Sensitivity, scenario, and stress analysis expose assumptions, nonlinear effects, and severe but plausible outcomes.

Last updated: October 2026

11.3 Risk Analysis and Evaluation

After risks are identified, risk analysis develops an understanding of their nature and level. It considers causes, likelihood, consequences, timing, velocity, duration, existing controls, dependencies, and uncertainty. Risk evaluation then compares the analyzed exposure with established criteria to determine whether it is acceptable, needs treatment, or must be escalated. Analysis estimates and explains; evaluation judges against criteria.

Establish the basis

Before assigning a rating, define the objective, time horizon, population or portfolio, measurement unit, assumptions, and whether the assessment is inherent or residual. A one-day trading exposure and a five-year strategic exposure cannot be compared without context. Data quality and model limits should be explicit.

Inherent and residual analysis

An inherent assessment considers exposure before the relevant controls. A residual assessment considers the expected effect of controls. The difference should be supported by evidence. If a control is only planned, inconsistently performed, or not tested, the analyst should not assume full risk reduction.

Control review asks:

  • Is the control suitably designed for the cause or consequence?
  • Has it been implemented?
  • Does it operate consistently, at the right time, over the full population?
  • Is there evidence, review, escalation, and correction when it fails?
  • Can it be overridden, and are override rights monitored?

Qualitative analysis

Qualitative methods use defined scales such as rare to almost certain and insignificant to severe. Definitions must be concrete. “Major consequence” might mean a material client loss, prolonged outage, significant regulatory breach, or threat to capital. Without definitions, different reviewers attach different meanings to the same label.

A risk matrix combines likelihood and consequence to support ranking. It is useful for communication but has limitations: categories compress information, boundaries can change ratings abruptly, and equal scores can mask very different events. The matrix informs judgment rather than replacing it.

Quantitative analysis

Quantitative methods may estimate frequency, probability distributions, expected loss, sensitivity, cash-flow gaps, duration, or loss percentiles. A simple expected-loss concept multiplies likelihood by consequence, but expected value can conceal tail severity. A 1% chance of a catastrophic loss and a certain small loss can have the same expected value while demanding different governance.

Models depend on input data, relationships, time periods, and assumptions. Back-testing, benchmarking, independent validation, and change control help manage model risk. Precision in decimal places does not create accuracy if the assumptions are weak.

Scenario, sensitivity, and stress analysis

Sensitivity analysis changes one factor to see how the result responds. Scenario analysis changes a coherent set of conditions, such as rising rates, declining equity prices, and customer withdrawals. Stress testing examines severe but plausible conditions and can use reverse stress: identify an outcome that would make the business model fail, then determine what chain of events could produce it.

Scenarios should include second-order effects. A market fall may cause margin calls; clients sell into a thin market; liquidity worsens; counterparties reduce limits; and operational teams face unusual volume. Ignoring interaction understates exposure.

Evaluation against criteria

Evaluation asks whether the analyzed risk is within appetite, tolerance, legal requirements, capital and liquidity capacity, and stakeholder obligations. Possible decisions include:

  1. accept or retain with monitoring;
  2. treat to reduce likelihood or consequence;
  3. avoid or stop the activity;
  4. obtain more information before deciding;
  5. escalate because authority, appetite, or a mandatory rule would be exceeded.

Legal compliance is not traded away by a favorable expected return. An exposure below a financial threshold can still be intolerable if it entails market abuse, customer-asset misuse, or a licensing breach.

Prioritization

Priority can consider risk level, urgency, velocity, persistence, control weakness, interconnectedness, ease of remediation, and the time needed to implement a response. A rapidly developing moderate risk may require action before a higher but stable long-term risk. Aggregation matters: several “medium” exposures driven by the same factor may collectively exceed appetite.

Exam method

If the task estimates likelihood or consequence, it is analysis. If it compares the result with appetite or criteria and chooses whether action is required, it is evaluation. Challenge unsupported control credit, false precision, and a ranking that ignores severe tails, interaction, or mandatory rules.


From Estimate to Decision

Analysis estimates likelihood and consequence using the best available evidence and states the uncertainty around that estimate. Evaluation then compares the result with approved criteria to decide whether the exposure is acceptable, needs treatment, or requires escalation. A high score produced by weak data should not be treated as precise; sensitivity tests and ranges may be more honest. Likewise, a low-frequency event can still demand treatment when legal, solvency, customer-asset, or market-integrity consequences are severe. The decision record should show assumptions, control effectiveness, aggregation and concentration effects, risk velocity, reviewer challenge, and the reason the residual exposure is accepted or rejected.

Test Your Knowledge

Which activity is risk evaluation rather than risk analysis?

A

Estimating the probability of a system outage

B

Calculating the cash-flow consequence of a default

C

Comparing the residual risk with approved criteria to decide whether treatment is required

D

Testing whether a control operated throughout the period

Test Your Knowledge

When may an analyst reasonably give a control credit for reducing residual risk?

A

Whenever a policy mentions the control

B

As soon as management plans to implement it next year

C

Whenever the control owner says it is effective without evidence

D

When design is appropriate and implementation and operating effectiveness are supported by evidence

Test Your Knowledge

What is a key limitation of using expected loss alone?

A

It can conceal low-probability catastrophic outcomes that share an average with frequent small losses

B

It always overstates every risk

C

It cannot use likelihood information

D

It automatically includes all legal and reputational consequences

Sections you finish are checked off in the contents.