CPCU 500 Introduction to Risk Management and
Risk Assessment Techniques Management
Foundation Creating a Stronger Risk
Educational Objective 1
Apply a process for managing an organization’s risks.
Key Points:
The risk management process isn’t actually a process;
rather, it’s a set of interconnected simultaneously and
sequentially occurring activities that defi ne an
organization’s holistic approach to managing risks.
A. Scan the Environment
1. Risk management professionals should conduct
specifi c, detailed reviews of both the internal and
external environments of an organization.
2. Scanning the environment includes evaluating how
each of an organization’s risk management
processes aligns with its overall objectives.
3. Risk management professionals should collaborate
with the organization’s internal stakeholders to defi
ne its risk criteria. These criteria should be aligned
pg. 1
, with the organization’s objectives, resources, and
risk management policy and should consider these
factors:
a. Causes of risk
b. Eff ects of risk
c. Metrics used to measure eff ects of risk
d. Time frame of potential eff ects
e. Methods to determine level of risk
f. Approach to combinations of risk
B. Identify Risks
1. Identifying all risks is not feasible or practical, but
identifying key and emerging risks is essential. Doing so
relies on the risk professional’s ability to:
a. Ask the right questions of departmental
stakeholders to understand their perspectives on
the most pressing risks they face
b. Find external experts who can shed light on
emerging risks that the organization may not have
anticipated previously and know how to speak
pg. 2
, their language to get the most from interactions
with them
2.1
c. Collaborate with senior management and the board
to ensure that risks associated with the
organization’s strategy are identified
2. Identifying risk interactions is also important.
C. Analyze Risks
Risk analysis involves applying the defined risk criteria to determine the
source, cause, likelihood, and potential consequences of each of the identifi
ed risks. Depending on the circumstances, this analysis can be quantitative,
qualitative, or both. Quantitative analysis, in particular, may entail
interacting with experts.
D. Treat Risks
1. When no regulatory requirements are present, an organization should
compare the total level of risk determined during the risk analysis with
the established risk criteria.
2. Then risk management professionals decide where and how to apply
risk treatment: a. Avoid the risk.
b. Modify the likelihood and/or impact of the risk.
pg. 3
Risk Assessment Techniques Management
Foundation Creating a Stronger Risk
Educational Objective 1
Apply a process for managing an organization’s risks.
Key Points:
The risk management process isn’t actually a process;
rather, it’s a set of interconnected simultaneously and
sequentially occurring activities that defi ne an
organization’s holistic approach to managing risks.
A. Scan the Environment
1. Risk management professionals should conduct
specifi c, detailed reviews of both the internal and
external environments of an organization.
2. Scanning the environment includes evaluating how
each of an organization’s risk management
processes aligns with its overall objectives.
3. Risk management professionals should collaborate
with the organization’s internal stakeholders to defi
ne its risk criteria. These criteria should be aligned
pg. 1
, with the organization’s objectives, resources, and
risk management policy and should consider these
factors:
a. Causes of risk
b. Eff ects of risk
c. Metrics used to measure eff ects of risk
d. Time frame of potential eff ects
e. Methods to determine level of risk
f. Approach to combinations of risk
B. Identify Risks
1. Identifying all risks is not feasible or practical, but
identifying key and emerging risks is essential. Doing so
relies on the risk professional’s ability to:
a. Ask the right questions of departmental
stakeholders to understand their perspectives on
the most pressing risks they face
b. Find external experts who can shed light on
emerging risks that the organization may not have
anticipated previously and know how to speak
pg. 2
, their language to get the most from interactions
with them
2.1
c. Collaborate with senior management and the board
to ensure that risks associated with the
organization’s strategy are identified
2. Identifying risk interactions is also important.
C. Analyze Risks
Risk analysis involves applying the defined risk criteria to determine the
source, cause, likelihood, and potential consequences of each of the identifi
ed risks. Depending on the circumstances, this analysis can be quantitative,
qualitative, or both. Quantitative analysis, in particular, may entail
interacting with experts.
D. Treat Risks
1. When no regulatory requirements are present, an organization should
compare the total level of risk determined during the risk analysis with
the established risk criteria.
2. Then risk management professionals decide where and how to apply
risk treatment: a. Avoid the risk.
b. Modify the likelihood and/or impact of the risk.
pg. 3