Risk management is not risk minimization. A firm that eliminates all risk also eliminates all return. The job is to choose which risks to bear, in what size, and which to shed.
Risk management is the process by which an organization defines the level of risk it is willing to accept, measures the risk it is actually taking, and adjusts exposures to align the two. The output is not "less risk." The output is the right risks, in the right size, for the chosen return objective.
KEY: Risk management is not the same as risk reduction. A pension fund that holds 100% cash has zero market risk and a near-certain shortfall versus its liabilities. The goal is intentional exposure aligned with objectives.
A framework is the integrated set of policies, infrastructure, and processes that turn risk philosophy into daily decisions. Effective frameworks share several features.
- Risk governance. Top-down oversight with clear lines of authority.
- Risk identification and measurement. Inventorying exposures and quantifying them through standardized metrics.
Common mistakes
- Confusing risk management with risk minimization. Risk management is intentional exposure to compensated risk. Trap: selecting "minimize all risks" as a definition. The correct framing is "align actual risks with intended risks."
- Treating governance as a synonym for the framework. Governance is the oversight LAYER. The framework is the entire system, governance, infrastructure, policies, monitoring, communication. Trap: identifying governance alone as "the risk management framework."
- Reversing risk tolerance and risk budgeting. Tolerance is set first, at the top, and answers "how much." Budget allocates that tolerance across activities and answers "where." Trap: describing risk budgeting as setting overall enterprise tolerance.
Bottom line
- Risk management = identify, measure, and modify exposures so the portfolio earns intended risks and sheds unintended ones. It is NOT risk avoidance or minimization.
- The framework is broader than governance: it integrates governance, identification, measurement, infrastructure, policy, monitoring, communication, and strategic integration.
- Risk governance is enterprise-wide, top-down oversight at the board and senior management. Siloed, business-line-driven risk policy is the failure mode.
- Risk tolerance (willingness and ability) is set at the top, in the investment policy statement (IPS), BEFORE the budget. The binding constraint is the lower of willingness and ability.
Exam shortcut
Governance vs. budgeting: governance SETS the limit (top of the house). Budgeting DIVIDES the limit (operational). If the question asks WHO, answer governance. If it asks HOW MUCH per desk, answer budgeting. Unique risk in stress scenarios: look for INTERACTION. The right answer almost always involves market triggering liquidity triggering solvency, not any single risk in isolation.
The full lesson (about 2,804 words, 19 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- introduction to risk management
Browse all free CFA Level I lessons or jump into free CFA Level I practice questions.