basics
What Is Risk Management?
Risk management is the discipline of handling uncertainty on purpose. ISO 31000 defines risk as “the effect of uncertainty on objectives” — which makes risk management less about eliminating risk (impossible, and often undesirable, since return comes from bearing it) and more about taking the right risks, in known size, with eyes open.
The process
At its core, risk management is a repeatable loop:
- Identify — find the sources of risk across market, credit, liquidity and operational exposures, plus strategic and external threats.
- Measure — quantify likelihood and impact (Value at Risk, stress tests, exposure and default metrics) so risks can be compared on a common scale.
- Monitor — track exposures against limits continuously, because positions and markets move.
- Mitigate — decide whether to accept, avoid, transfer (hedge or insure) or reduce each risk, and act.
Why frameworks matter
Doing this consistently across a whole organisation needs structure. Two reference frameworks dominate: COSO’s Enterprise Risk Management, which embeds risk in strategy-setting and performance, and ISO 31000, which provides principles and a process usable by any organisation. For banks, the Basel Committee’s principles add supervisory expectations. Together they turn risk management from ad-hoc judgement into a governed, accountable system — the subject of our Frameworks & Governance hub.
Sources & further reading
- ISO 31000:2018 — Risk management — Guidelines — International Organization for Standardization
- Enterprise Risk Management — Integrating with Strategy and Performance — COSO
- Principles for the Sound Management of Operational Risk — Basel Committee on Banking Supervision (BIS)
Sources & further reading
- ISO 31000:2018 — Risk management — Guidelines — International Organization for Standardization
- Enterprise Risk Management — Integrating with Strategy and Performance — COSO
- Principles for the Sound Management of Operational Risk — Basel Committee on Banking Supervision (BIS)
