Session 02: Risk Management Fundamentals
Learning Objectives
- Distinguish between pure risk and speculative risk, and explain why only pure risks are insurable
- Apply the five-step risk management process — identification, assessment, mitigation, implementation, and monitoring — to a real-world insurance scenario
- Use qualitative and quantitative risk assessment techniques including likelihood-impact matrices and expected loss calculations
- Evaluate the five risk mitigation strategies (Transfer, Tolerate, Treat, Terminate, Take Advantage) and select the appropriate strategy for a given risk
- Construct a complete risk register with 10+ risks in Excel using formulas, conditional formatting, and residual risk scoring
1. Understanding Risk
Before we can manage risk, we must understand what it is. In everyday language, "risk" means the possibility of something bad happening. But in insurance and risk management, the definition is more precise — and the distinctions matter enormously for what can and cannot be insured.
1.1 Defining Risk
In insurance terms, risk has two components that must both be present:
- Uncertainty: We do not know whether the event will occur, when it will occur, or how severe it will be. A certainty is not a risk. If a building is already on fire, there is no uncertainty — it is a loss event in progress, not a risk.
- Possibility of Loss: The outcome must have a downside. If an event can only produce neutral or positive outcomes, it may involve uncertainty but it does not involve risk in the insurable sense.
Formally, risk can be expressed as:
Risk = Probability of Event × Severity of Loss
Where: Probability = likelihood of the event occurring (0 to 1, or percentage)
Severity = financial impact if the event occurs (in currency terms)
Example: Risk of factory fire = 0.002 (0.2% per year) × ₹2,00,00,000
= ₹40,000 expected annual loss
1.2 Pure Risk vs. Speculative Risk
This is arguably the most important conceptual distinction in insurance:
| Dimension | Pure Risk | Speculative Risk |
|---|---|---|
| Possible Outcomes | Loss or No Loss (two outcomes) | Loss, No Loss, or Gain (three outcomes) |
| Insurable? | Yes — under the right conditions | Generally No |
| Examples | House fire, car accident, hospitalization, death, cyclone damage | Stock market investment, launching a new product, gambling, buying lottery tickets |
| Risk Pooling Viable? | Yes — the law of large numbers applies | No — the possibility of gain creates adverse selection and moral hazard problems |
| Social Benefit of Insurance? | High — protects against financial ruin | Negative — would encourage excessive risk-taking |
Example 1 — Business Interruption Insurance: A factory burns down. The fire itself is a pure risk — it can only cause loss. The insurance pays because of the fire. The fact that the factory owner's decision to operate a business (a speculative risk — could succeed or fail) is related to the loss is irrelevant; the trigger is the fire, not the business decision. The pure risk (fire) makes it insurable.
Example 2 — Trade Credit Insurance: A supplier sells goods to a customer on credit and insures against the customer not paying. The customer's non-payment is a pure risk for the supplier — it can only cause loss. The fact that the customer's business may have failed due to speculative decisions (bad investments, poor strategy) does not matter — from the supplier's perspective, the non-payment is an unforeseen loss beyond their control.
The rule: Insurance covers the trigger event, not the broader business context. If the trigger event is a pure risk (fire, accident, default, illness, death), the risk is insurable — even if speculative risks are connected somewhere in the background.
1.3 Systematic vs. Unsystematic Risk
Risk can also be classified by its scope:
- Systematic Risk (Non-Diversifiable): Affects an entire market or system simultaneously. Cannot be eliminated through diversification. Examples: interest rate changes for life insurers, regulatory changes affecting all insurers, systemic cyber events (major cloud provider outage), pandemic risk.
- Unsystematic Risk (Diversifiable): Specific to an individual, company, or small group. Can be reduced through diversification and pooling. Examples: an individual policyholder's house burning down, a single factory's machinery breakdown, one driver's car accident.
Insurance is fundamentally designed to handle unsystematic risk through pooling. Systematic risk, by its nature, cannot be pooled away — which is why pandemics, widespread cyber events, and systemic financial crises present existential challenges to the insurance industry and often require government backstops or reinsurance solutions.
2. The Risk Management Process
Risk management is not a one-time exercise. It is a continuous cycle of five interconnected steps that feed into each other. Every organization — and every insurance company — that manages risk effectively follows some version of this process.
2.1 The Five-Step Cycle
Step 1: Risk Identification
Systematically identify all risks the organization faces. What could go wrong? What events could cause financial loss, operational disruption, reputational damage, or regulatory penalty? The goal is comprehensiveness — a risk you haven't identified is a risk you cannot manage.
Step 2: Risk Assessment
For each identified risk, estimate two things: (a) How likely is it to occur? (b) If it does occur, how severe will the impact be? This can be qualitative (High/Medium/Low) or quantitative (annual probability of 2%, expected loss of ₹50 lakh). The output is a prioritized list of risks.
Step 3: Risk Mitigation
For each significant risk, decide what to do about it. The five options — Transfer, Tolerate, Treat, Terminate, Take Advantage — are the heart of risk management strategy. We explore each in detail in Section 5.
Step 4: Implementation
Put the chosen mitigation strategies into action. This is where strategy meets operations: purchasing insurance policies, installing fire suppression systems, training employees on cybersecurity, diversifying the investment portfolio, setting up compliance monitoring.
Step 5: Monitoring & Review
Risk is dynamic. New risks emerge, existing risks change in probability or severity, mitigation measures degrade over time, and the external environment evolves. Continuous monitoring and periodic review — quarterly at minimum — are essential. The risk register is a living document, not a filing exercise.
🔧 Exercise 2.1 — Sequence the Risk Management Process
Below are the 5 steps of the risk management process and 5 actions — but they are jumbled. Your task: (A) Arrange the steps in the correct order. (B) Match each step to the action that belongs with it.
Part A — Order the Steps
| Your Order | Step | Step Name |
|---|---|---|
| Put the chosen mitigation strategies into action — install controls, purchase insurance, train employees. | ||
| For each identified risk, estimate how likely it is and how severe it would be. | ||
| Systematically find all risks the organisation faces — what could go wrong? | ||
| Track risks over time — new risks emerge, existing risks change, controls degrade. | ||
| For each significant risk, decide what to do — Transfer, Tolerate, Treat, Terminate, or Take Advantage. |
Part B — Apply the Process
Scenario: You are the risk manager of an insurance company. A new regulation requires you to assess and manage cyber risk across the organisation. Walk through the 5 steps and state briefly what you would do at each step.
View Solution — Correct Sequence + Worked Example
Part A — Correct Order
| Order | Step Name | Why This Order? |
|---|---|---|
| 1 | Risk Identification | You cannot manage a risk you have not identified. Always start here. |
| 2 | Risk Assessment | Once identified, assess each risk — how likely? how severe? Prioritise. |
| 3 | Risk Mitigation | For significant risks, decide what to do (the Five Ts). |
| 4 | Implementation | Strategy without action is worthless. Put the plan into motion. |
| 5 | Monitoring & Review | Risk changes constantly. Monitor and update — the cycle never ends. |
Part B — Cyber Risk Assessment Walkthrough (Example)
- Identify: Conduct a workshop with IT, Legal, and Operations teams. List all cyber risks — ransomware, data breach, insider threat, DDoS, third-party vendor compromise, system outage. Create a preliminary risk list of 15–20 items.
- Assess: Score each risk on Likelihood (1–5) and Impact (1–5) using the matrix from Section 4.1. Ransomware: L=4 (likely), I=4 (major) → score 16 = Critical. Data breach: L=3 (possible), I=5 (catastrophic) → score 15 = Critical. Rank all risks by score.
- Mitigate: For Critical and High risks, select strategies. Ransomware → Treat (MFA, offline backups, employee training, EDR) + Transfer (cyber insurance). Data breach → Treat (encryption, access controls, breach detection) + Tolerate (residual risk after controls is within appetite).
- Implement: Deploy MFA across all systems within 60 days. Contract with a cyber forensic firm. Purchase cyber insurance policy with ₹10 Cr limit. Run phishing simulation training for all employees.
- Monitor & Review: Track: number of phishing emails reported, system patch compliance %, cyber insurance claims. Review the risk register quarterly. Update risk scores after each significant cyber incident anywhere in the industry — not just within the organisation.
3. Risk Identification Techniques
Risk identification is the foundation of the entire process. A risk you fail to identify at this stage will not be assessed, mitigated, or monitored. Different techniques are suited to different contexts — the best risk managers use multiple approaches and triangulate.
3.1 Seven Identification Techniques
Each technique below serves a different purpose. The best risk managers do not rely on one — they use multiple techniques in combination because each catches risks the others miss. Think of these as tools in a toolbox: you would not build a house with only a hammer.
| Technique | How It Works — Step by Step | Best For | Strengths | Weaknesses | Insurance Example |
|---|---|---|---|---|---|
| 1. Checklists | Start with a pre-existing list of common risks for your industry or function. Go through each item and ask: "Could this happen to us? How severe would it be?" Add organisation-specific items. Review and update the checklist annually. | Ensuring no obvious risks are missed; regulatory compliance | Fast, systematic, covers known risks, easy for non-experts to use | Only catches known risks; may create false comfort ("we checked every box") | IRDAI's prescribed risk categories (underwriting, market, credit, operational, liquidity, strategic) used by insurers for their quarterly solvency self-assessment. Each category has a sub-checklist. |
| 2. SWOT Analysis | Divide a whiteboard into four quadrants: Strengths, Weaknesses, Opportunities, Threats. List internal factors (Strengths, Weaknesses) and external factors (Opportunities, Threats). Risks emerge from: (a) Weaknesses that could be exploited, (b) Threats from the competitive environment. Then prioritise. | Strategic planning; competitive positioning; new business initiatives | Broad perspective, links risks to strategy, engaging team exercise | Subjective; risks identified depend heavily on who is in the room; rarely surfaces operational or technical risks | An insurer analysing the threat of digital disruption: Weakness = legacy IT systems, Threat = InsurTechs with lower cost structures, Opportunity = partnership with an InsurTech instead of building internally. |
| 3. Scenario Analysis | Choose 2–4 drivers of change (e.g., regulatory, technological, economic). Create extreme but plausible scenarios by combining them (e.g., "tight regulation + rapid AI adoption"). For each scenario, trace the impact on every part of the organisation. Ask: "What would we need to do differently under this scenario?" | Tail risks; low-probability, high-impact events; strategic uncertainty | Surfaces risks that have never occurred before, builds strategic preparedness, challenges groupthink | Time-intensive; scenarios depend on assumptions that may be wrong; can produce false confidence ("we planned for that scenario") | "What if a Category 5 cyclone hits Mumbai directly?" — trace the impact on property insurance (massive claims), motor (flood-damaged cars), life (potential casualties), health (injuries, waterborne diseases), and business interruption (port closure, office shutdowns). Identifies accumulation risk across lines. |
| 4. Root Cause Analysis | Start with a specific loss event that already happened. Ask "Why?" repeatedly (the "5 Whys" technique) — each answer leads to a deeper cause. Continue until you reach a systemic or process failure, not a human error. Then ask: "Could this same root cause produce other losses we have not yet seen?" | Learning from past incidents; preventing recurrence; improving controls | Deep, evidence-based, reveals systemic issues that single-incident reporting misses | Requires a loss to have already occurred; only as good as the quality of the investigation | After a major claims fraud is detected: Why? → No fraud check at FNOL. Why? → System did not flag repeat claimants. Why? → Claims system has no automatic cross-reference with previous claims. Result: fix the system, not just this one claim. Then check all other claims that could have slipped through the same gap. |
| 5. Loss Data Analysis | Collect historical loss data (claims, incidents, near-misses). Segment by type, cause, location, time, and amount. Look for patterns: are certain types of loss increasing? Are certain locations over-represented? Are there peaks at specific times? Use statistical methods (trend analysis, regression) to separate signal from noise. | Data-rich environments; quantitative risk assessment; identifying emerging trends | Objective, data-driven, reveals patterns invisible to human observation, quantifiable | Requires clean historical data; past patterns may not predict future (especially for emerging risks); can miss rare events | Analysing 5 years of motor claims data to discover: SUV models made after 2020 have 40% lower claim frequency but 25% higher average severity than sedans. Older drivers (60+) in Chennai have the highest claim frequency during monsoon months (July–November). These insights feed into pricing and underwriting. |
| 6. Delphi Technique | Select a panel of experts (internal and external) who do NOT know each other's identities. Round 1: Circulate a questionnaire asking them to list and assess risks. Collect and anonymise all responses. Round 2: Share the aggregated results and ask each expert to revise their assessment in light of others' views. Repeat until consensus converges (typically 2–3 rounds). The anonymity prevents dominant personalities from swaying the group. | Emerging risks with little historical data; expert-dependent domains; controversial topics | Eliminates groupthink and authority bias; systematically aggregates expert judgment; works even without data | Slow (weeks per round); depends on expert selection quality; consensus may be false (everyone is equally wrong) | Assessing cyber insurance risk for quantum computing threats (2026+). There is zero claims history because quantum attacks do not exist yet at scale. A panel of cybersecurity experts, quantum physicists, and insurance underwriters anonymously estimates: probability of first major quantum-related loss event, timeline, and potential industry loss amount. |
| 7. Process Mapping | Draw a detailed flowchart of a specific business process — every step, every decision point, every handoff between teams. At each step, ask: "What could go wrong here?" (risk identification) and "What controls exist to prevent or catch it?" (control identification). Mark steps with no controls as high-risk. Quantify the impact of failure at each step. | Operational risk; internal controls assessment; process improvement; system implementation | Granular, identifies specific failure points, directly links risks to controls, produces actionable improvements | Narrow — focuses on one process at a time; requires detailed process knowledge; time-consuming to do well | Mapping the claims settlement process: FNOL Received → Enter into System → Assign Surveyor → Surveyor Visits Site → Assessment Report → Manager Approval → Payment Processing. At the "Assign Surveyor" step: what if no surveyor is available within 48 hours? (risk: delayed assessment, customer complaint). At "Manager Approval": what if the manager approves without reviewing? (risk: control failure). Each step is analysed and improved. |
4. Risk Assessment & Measurement
Once risks are identified, they must be assessed. The goal is to answer two questions for each risk: How likely? and How bad? The answers determine which risks demand management attention and resources.
4.1 The Likelihood × Impact Matrix
This is the most widely used risk assessment tool in business. Every risk is scored on two dimensions, and the product of those scores determines its priority:
| Likelihood Score | Meaning (Annual Probability) | Impact Score | Meaning (Financial Impact) |
|---|---|---|---|
| 1 — Rare | < 1% (less than once in 100 years) | 1 — Negligible | < ₹10 lakh |
| 2 — Unlikely | 1–5% (once in 20–100 years) | 2 — Minor | ₹10 lakh – ₹1 crore |
| 3 — Possible | 5–20% (once in 5–20 years) | 3 — Moderate | ₹1 crore – ₹10 crore |
| 4 — Likely | 20–50% (once in 2–5 years) | 4 — Major | ₹10 crore – ₹100 crore |
| 5 — Almost Certain | > 50% (more than once in 2 years) | 5 — Catastrophic | > ₹100 crore |
The risk score is calculated as:
Risk Score = Likelihood × Impact
Risk Level (using a 5×5 matrix — all scores 1 to 25 are covered):
1–4 = Low (Green) — Acceptable; monitor routinely
5–9 = Medium (Amber) — Requires attention; implement controls where cost-effective
10–16 = High (Orange) — Needs management attention; regular monitoring
17–25 = Critical (Red) — Unacceptable; immediate action required
Example: A risk with Likelihood = 3 (Possible, 5–20% probability) and Impact = 4 (Major, ₹10–100 crore) scores 3 × 4 = 12, placing it in the High category — requiring management attention.
4.2 Quantitative Approaches — Expressing Risk in Rupees
A score of 12 on a 5×5 matrix tells you a risk is "High" — but it does not tell you how much money is at stake. Quantitative methods fix this by expressing risk in rupees. They answer one simple question: "How much money could we lose, and how often?"
Three metrics work together. The best way to understand them is through a single story:
Imagine you are an insurer covering 100,000 houses against fire. You have 100 years of data showing that, on average, 100 houses burn per year (0.1%), and the average claim per fire is ₹50 lakh. You want to understand your risk in rupees — how much to charge, how much to set aside, and whether you have enough capital to survive a catastrophe.
The key: ₹50 Cr (EL) tells you what to budget. ₹125 Cr (VaR) tells you where to set your reinsurance. ₹200 Cr (TVaR) tells you how much capital you need to survive. If you only budget for the average, you fail in the bad years.
Note on "95% VaR": This does NOT mean "95% chance of ₹125 crore loss." It means "95% chance that the loss will be ₹125 crore OR LESS." The loss could be ₹1 crore or ₹125 crore — there is a 95% probability it will not exceed ₹125 crore. In the remaining 5% — the "tail" — losses can be much worse, which is exactly what TVaR measures.
| Metric | What It Tells You | What It Ignores | Used For |
|---|---|---|---|
| Expected Loss (EL) | The average loss you can expect every year. | Does not capture the volatility — bad years can be far worse than the average. | Setting premiums, budgeting for claims, reserve planning |
| Value at Risk (VaR) | The loss threshold that will not be exceeded in a normal year (with 95% confidence). | Does not tell you how bad things get when the threshold IS exceeded — it cuts off at the boundary. | Setting reinsurance limits, regulatory solvency calculations |
| Tail VaR (TVaR) | How bad it gets on average when things go really wrong (beyond the VaR threshold). | Does not capture the worst single possible loss — only the average of all "bad" scenarios. | Capital planning, stress testing, board-level risk appetite |
Analogy: Think of EL as your monthly grocery budget (what you usually spend). VaR is the maximum you expect to spend in any normal month — say ₹15,000 at the 95th percentile (only 1 month in 20 exceeds this). TVaR asks: when you DO exceed ₹15,000, what is the average overshoot — ₹22,000? ₹30,000? That is your TVaR, and it tells you how much buffer you need in your emergency fund.
4.3 Risk Heat Maps
A risk heat map is the visual representation of the likelihood-impact matrix. Each risk is plotted as a point on a 5×5 grid, with color coding:
- Green zone (bottom-left): Low likelihood, low impact. Accept; monitor.
- Amber zone (middle): Moderate on one or both dimensions. Mitigate where cost-effective.
- Red zone (top-right): High likelihood, high impact. Immediate action required. These risks should have dedicated mitigation plans with named owners and deadlines.
A well-constructed heat map allows a board or risk committee to see, at a single glance, where the organization's major risk exposures lie. We will build one in Section 6 using Excel conditional formatting.
5. Risk Mitigation Strategies — The Five Ts
Once risks are identified and assessed, the critical strategic question is: what should we do about each risk? Risk managers classify the options into five strategies, commonly called the "Five Ts."
5.1 The Five Strategies
| Strategy | What It Means | When to Use | Insurance Example |
|---|---|---|---|
| 1. Transfer | Shift the financial consequences of the risk to another party, typically through insurance, reinsurance, hedging, or contractual indemnities | The risk is too large to retain; the cost of transfer is less than the potential loss; the counterparty is better capitalized to bear the risk | An insurer purchasing catastrophe reinsurance to protect against a ₹500 crore cyclone loss that would threaten its solvency |
| 2. Tolerate (Retain) | Accept the risk and budget for the potential loss. No active mitigation beyond monitoring. | The cost of mitigation exceeds the expected loss; the risk is within the organization's risk appetite; the risk is low-probability and low-impact | An insurer deciding not to reinsure motor own-damage claims below ₹1 lakh — the risk is high-frequency but low-severity and predictable through pooling |
| 3. Treat (Reduce) | Implement controls to reduce either the likelihood or the impact (or both) of the risk. This is "risk reduction." | The risk is significant but can be reduced to an acceptable level through cost-effective controls; the organization has the capability to implement and maintain the controls | An insurer implementing AI-based fraud detection to reduce claims fraud losses from 8% of claims to 3% |
| 4. Terminate (Avoid) | Eliminate the risk entirely by ceasing the activity that creates it. This is the most definitive strategy — but also the most costly in terms of foregone opportunity. | The risk cannot be reduced to an acceptable level; the potential loss, however unlikely, is existential; the activity is not core to the business | An insurer deciding to stop writing property insurance in flood-zone areas after catastrophic losses made the line unprofitable despite reinsurance |
| 5. Take Advantage (Exploit) | Actively pursue the upside of a risk — turning a threat into an opportunity. This applies primarily to speculative risks. | The organization has a competitive advantage in managing this risk; the upside is significant; the downside is well-understood and acceptable | An insurer with superior climate analytics capabilities actively expanding into parametric weather insurance, viewing climate change as a market opportunity |
5.2 Choosing the Right Strategy
The choice of strategy is not automatic — it depends on the organization's risk appetite, the cost-benefit analysis of each option, and the residual risk after controls. The decision framework is:
- Can the risk be eliminated without sacrificing core business? If yes → Terminate.
- If not, is the risk within our risk appetite? If yes and cost of mitigation exceeds benefit → Tolerate.
- If not, can we reduce it to an acceptable level cost-effectively? If yes → Treat.
- For the residual risk that remains after treatment, should we transfer it? If yes → Transfer (insurance/reinsurance).
- Is there an upside we can capture? If yes → Take Advantage.
🧮 Exercise 5.1 — Choose the Right Mitigation Strategy
For each scenario below, select the primary strategy from the Five Ts (Transfer / Tolerate / Treat / Terminate / Take Advantage) and justify your choice in one sentence. For the last scenario, more than one T may apply — identify the combination.
| # | Scenario | Your Strategy |
|---|---|---|
| 1 | A general insurer faces a 1-in-500 year earthquake risk that could cause ₹1,000 crore in losses — 10× its available capital. | |
| 2 | An insurer's internal fraud rate is 8% of claims. An AI detection system costing ₹2 Cr/year can reduce it to 3%. | |
| 3 | A health insurer finds that a wellness programme costs ₹5 Cr/year but only reduces claims by ₹3 Cr/year. | |
| 4 | An insurer's property portfolio in coastal cyclone zones has a combined ratio of 140% — consistently unprofitable despite all mitigation efforts. | |
| 5 | An insurer has built superior climate data analytics. Competitors are avoiding cyclone insurance due to fear of losses. | |
| 6 | A large IT system migration project carries risk of business disruption, data loss, and customer dissatisfaction. |
Decision Tree Drill: Pick one scenario above (your choice). Trace it through the 5-question decision framework from Section 5.2. Write down: for each question, your Yes/No answer and the strategy it leads to.
View Solution — Strategy Selection
| # | Strategy | Rationale |
|---|---|---|
| 1 | Transfer | The potential loss (₹1,000 Cr) is existential — 10× the insurer's capital. The risk cannot be retained, treated (it is a natural event), or terminated (the insurer cannot stop earthquakes). The only option is to transfer via reinsurance or a catastrophe bond. |
| 2 | Treat | The risk can be reduced cost-effectively. Cost: ₹2 Cr/year. Benefit: 5% reduction in fraud on a claims pool. If total claims are ₹100 Cr, 5% = ₹5 Cr saved. Net benefit: ₹3 Cr/year. This is a classic "Treat" — the control costs less than the expected loss reduction. |
| 3 | Tolerate | The programme costs more than it saves. The rational decision is to stop the programme and tolerate the underlying risk (health claims without the wellness intervention). The risk is within appetite — the insurer can absorb the claims. |
| 4 | Terminate | Despite all efforts to Treat (tighter underwriting, higher premiums, risk controls), the combined ratio is 140% — the line is fundamentally unprofitable. The remaining options are Tolerate (but this destroys capital) or Terminate. Terminate means stop writing this product in these zones. |
| 5 | Take Advantage | The insurer has a competitive advantage (superior climate data) that others lack. The growing demand for cyclone insurance (driven by climate change awareness) creates a market opportunity. This is a speculative risk — but the insurer can manage it better than competitors. |
| 6 | Combination: Treat + Tolerate | Treat (reduce risk): thorough testing, phased rollout, rollback plan, parallel running. Tolerate: accept that some disruption is inevitable. Transfer: purchase project-specific insurance or warranties from the vendor. The project may also be Terminated if the business case fails at any stage. |
Decision Tree Trace — Earthquake Scenario (#1)
- "Can the risk be eliminated without sacrificing core business?" → No. Earthquakes cannot be prevented. The insurer cannot stop operating in earthquake-prone zones without exiting the property insurance market entirely — which is core business.
- "Is the risk within our risk appetite?" → No. ₹1,000 Cr loss is 10× capital — existential. It is far outside any reasonable risk appetite.
- "Can we reduce it to an acceptable level cost-effectively?" → No. We cannot "reduce" earthquake probability or severity. Loss prevention (better building codes) helps over time but does not reduce the 1-in-500 year extreme loss.
- "For the residual risk after treatment, should we transfer it?" → Yes. Transfer via catastrophe reinsurance is the only viable option. The insurer accepts a deductible (retention) and transfers everything above that.
- "Is there an upside we can capture?" → Not for earthquake — it is a pure risk. This option does not apply.
Result: Transfer (primary) + Tolerate (retention/deductible).
6. Building a Risk Register in Excel
The risk register is the central document of the risk management process. It captures every identified risk, its assessment, the chosen mitigation strategy, residual risk, ownership, and review status — all in one place. Excel is the most widely used tool for risk registers in practice, and mastering the Excel-based risk register gives you a skill you can deploy in any organization from day one.
6.1 The Risk Register Structure
A professional risk register contains the following columns at minimum:
| Column | Field Name | Description |
|---|---|---|
| A | Risk ID | Unique identifier (e.g., RISK-001, RISK-002) |
| B | Risk Category | Operational / Financial / Strategic / Compliance / Reputational |
| C | Risk Description | Clear, specific description of the risk event and its consequences |
| D | Likelihood (1–5) | How likely is this risk to occur? (See Section 4.1 scale) |
| E | Impact (1–5) | How severe would the consequences be? (See Section 4.1 scale) |
| F | Inherent Risk Score | = D × E (before any controls) |
| G | Existing Controls | What controls are already in place? |
| H | Control Effectiveness | How effective are existing controls? (1=Weak, 2=Partial, 3=Strong) |
| I | Residual Likelihood | Likelihood AFTER existing controls |
| J | Residual Impact | Impact AFTER existing controls |
| K | Residual Risk Score | = I × J (after existing controls) |
| L | Mitigation Strategy | Transfer / Tolerate / Treat / Terminate / Take Advantage |
| M | Additional Actions | What further actions are planned? |
| N | Risk Owner | Named individual responsible for managing this risk |
| O | Review Date | Date of next scheduled review |
| P | Status | Open / In Progress / Closed / Escalated |
6.2 Essential Excel Formulas
Here are the key formulas you will use to build an intelligent risk register:
' Inherent Risk Score (Column F, Row 2):
=D2*E2
' Residual Risk Score (Column K, Row 2):
=I2*J2
' Risk Level Classification (Column Q, Row 2):
=IF(K2>=17,"CRITICAL",IF(K2>=10,"HIGH",IF(K2>=5,"MEDIUM","LOW")))
' Action status based on risk level (Column R, Row 2):
=IF(K2>=17,"⚠ IMMEDIATE ACTION REQUIRED",IF(K2>=10,"◆ Mitigation Planned",IF(K2>=5,"● Monitor","✓ Acceptable")))
' Days until next review (Column S, Row 2):
=O2-TODAY()
' Overdue flag (Column T, Row 2):
=IF(AND(O2<TODAY(),P2<>"Closed"),"OVERDUE","On Track")
6.3 Conditional Formatting for the Heat Map Effect
Apply these conditional formatting rules to the Inherent Risk Score and Residual Risk Score columns to create an instant visual heat map:
- Red fill (Score 17–25 — Critical): Select cells → Conditional Formatting → Highlight Cells → Greater Than → 16 → Custom Format → Fill Red, Font White Bold
- Orange fill (Score 10–16 — High): Conditional Formatting → Between → 10 and 16 → Custom Format → Fill Orange, Font Dark
- Amber fill (Score 5–9 — Medium): Conditional Formatting → Between → 5 and 9 → Custom Format → Fill Amber, Font Dark
- Green fill (Score 1–4 — Low): Conditional Formatting → Less Than → 5 → Custom Format → Fill Green, Font White
The result: anyone looking at your risk register can instantly see which risks need attention — no analysis required. The red cells are your action list.
🔎 Exercise 6.1 — Spot the Mistakes in This Risk Register
The risk register below contains 5 deliberate errors. Find each one, explain why it is wrong, and state how to fix it.
| ID | Risk Description | L | I | Inherent | Mitigation | Resid L | Resid I | Residual | Owner | Status |
|---|---|---|---|---|---|---|---|---|---|---|
| 001 | Data breach exposing customer PII | 3 | 5 | 8 | Encryption, access controls | 2 | 4 | 8 | CTO | In Progress |
Hint: Check the calculations, the logic of before-and-after scores, the ownership, and the status fields.
Check Your Answers — 5 Errors Revealed
- Inherent Score calculated incorrectly: L=3 × I=5 = 15, not 8. The table shows 8 (which would be 2×4 or addition). Fix: Change Inherent Score to 15 (Critical).
- Residual Score equals Inherent Score despite controls: Residual L=2 × Residual I=4 = 8. But if controls exist (encryption, access controls), the residual score should be LOWER than the inherent score. If it is the same, either the controls are ineffective and should be removed from the register, or the residual scores need re-evaluation. You cannot claim controls exist and yet the score stays unchanged.
- Status says "In Progress" but residual risk is still 8 (Medium-amber): If mitigation is still "In Progress," the controls are not yet fully operational. The residual score of 8 is misleading — it should reflect the CURRENT risk level with partial controls, or the status should be updated to reflect that controls are not yet effective.
- Review Date missing: Every risk in a register must have a review date. Without it, there is no accountability for when this risk will be reassessed. Fix: Add a review date column and populate it.
- Risk Owner is CTO — too generic for a data breach risk: While CTO-level ownership is acceptable for a Critical risk, the "In Progress" status needs a specific action owner — e.g., the CISO (Chief Information Security Officer) who is actually implementing the encryption and access controls. Fix: Add a secondary "Action Owner" column for the person responsible for the specific mitigation steps.
✎ Exercise 6.2 — Quick Risk Scoring Drill
For each scenario below, assign Likelihood (1–5) and Impact (1–5), calculate the risk score, and classify it (Low / Medium / High / Critical) using the 4-level scale from Section 4.1.
| # | Scenario | L (1–5) | I (1–5) | Score | Level |
|---|---|---|---|---|---|
| 1 | Data breach at a large insurer: Industry data shows a 30% probability per year. Worst case: ₹50 Cr in regulatory penalties + remediation costs. | ||||
| 2 | Minor office theft: ~5% chance of employee theft of office supplies. Maximum loss: ₹25,000. | ||||
| 3 | Category 5 cyclone hitting Mumbai: Experts estimate < 1% annual probability. If it happens: ₹5,000 Cr in insured losses. | ||||
| 4 | Regulatory change in motor TP pricing: IRDAI announces new pool pricing every 2–3 years (30–50% chance in any given year). Impact: moderate profitability shift of ₹10–25 Cr. |
Check Your Scores
| # | L | I | Score | Level | Reasoning |
|---|---|---|---|---|---|
| 1 | 4 | 4 | 16 | High | 30% probability = Likely (4). ₹50 Cr impact = Major (4). 4×4=16 → High. Requires dedicated mitigation plan with named owner. |
| 2 | 3 | 1 | 3 | Low | 5% = Possible (3). ₹25K = Negligible (1). 3×1=3 → Low. Accept and monitor routinely. Not worth significant investment. |
| 3 | 1 | 5 | 5 | Medium | <1% = Rare (1). ₹5,000 Cr = Catastrophic (5). 1×5=5 → Medium. Despite the low probability, the severity is so high that the insurer must have reinsurance and a disaster recovery plan. The Medium level correctly signals "do not ignore, but do not over-invest." |
| 4 | 3 | 3 | 9 | Medium | 30–50% = Possible (3). ₹10–25 Cr = Moderate (3). 3×3=9 → Medium. Requires attention — monitor the regulatory landscape, model the potential impact, prepare a pricing response. |
Key insight from scenario 3: A low-probability × high-impact risk scores only 5 (Medium), but most insurers would treat it more seriously than the score suggests. This is a limitation of the simple L×I matrix — it does not capture risk aversion or the "sleep-at-night" factor. Many organisations add a separate "catastrophic risk" category for events with Impact = 5 that get escalated regardless of Likelihood.
7. Risk Management in Indian Insurance
The Indian insurance industry has a structured regulatory framework for risk management that all insurers must follow. Understanding this framework gives you insight into how insurers actually manage risk — not just in theory but as a matter of regulatory compliance.
7.1 IRDAI's Risk Management Requirements
IRDAI mandates that all insurers implement a robust risk management framework. The key regulatory requirements include:
- Enterprise Risk Management (ERM) Policy: Every insurer must have a board-approved ERM policy covering all material risks — underwriting, market, credit, operational, liquidity, and strategic risks.
- Risk Management Committee (RMC): The board must constitute a Risk Management Committee with majority independent directors. The RMC oversees the ERM framework and reviews the risk register quarterly.
- Own Risk and Solvency Assessment (ORSA): Insurers must conduct an annual self-assessment of their risk profile and capital adequacy. ORSA asks: given our risks, do we have enough capital to survive a severe but plausible adverse scenario?
- Chief Risk Officer (CRO): A dedicated CRO with direct reporting access to the board RMC. The CRO cannot be the CFO or the Chief Actuary — risk management must be independent of profit-center functions.
- Solvency Margin: The Available Solvency Margin must exceed the Required Solvency Margin by at least 50% (ratio ≥ 1.5). This is the ultimate backstop — if capital falls below this threshold, the insurer must stop writing new business.
7.2 Risk Categories for Indian Insurers
IRDAI's framework categorizes insurer risks into six buckets that every ERM framework must address:
| Risk Category | What It Covers | Example for a General Insurer |
|---|---|---|
| Underwriting Risk | Risk that premiums are insufficient to cover claims and expenses | Under-pricing motor third-party insurance due to competitive pressure; inadequate reserving for long-tail liability claims |
| Market Risk | Risk of losses from changes in market prices (interest rates, equity prices, FX, real estate) | Investment portfolio losing 20% in a market crash, eroding solvency margin |
| Credit Risk | Risk that counterparties fail to meet their obligations | Reinsurer defaulting on a large claim; bond issuer in the investment portfolio defaulting |
| Operational Risk | Risk of loss from inadequate or failed internal processes, people, systems, or external events | Fraud by an employee; system outage during peak renewal season; data entry error causing incorrect policy issuance |
| Liquidity Risk | Risk that the insurer cannot meet its payment obligations as they fall due | Surge in claims after a catastrophe requiring rapid cash outflows while investments are illiquid |
| Strategic Risk | Risk arising from adverse business decisions or failure to adapt to changes in the business environment | Investing heavily in agency distribution while the market shifts to digital; failing to develop cyber insurance capability as demand surges |
7.3 ERM Maturity in Indian Insurance
The maturity of risk management varies significantly across the Indian insurance industry. Large private-sector insurers and multinational joint ventures typically have sophisticated ERM frameworks with dedicated risk teams, quantitative risk models, and quarterly board-level risk reviews. Smaller players and some public-sector insurers are still building toward this standard — their risk management tends to be more compliance-driven (meeting regulatory minimums) than strategic (using risk insight to drive business decisions).
For InsurTech startups, understanding this framework is critical. When an InsurTech sells software or services to an insurer, the insurer's CRO will evaluate it through the lens of these six risk categories. A tool that reduces underwriting risk (better pricing) will get a different reception than one that introduces new operational risk (dependency on an unproven vendor).
📜 Exercise 7.1 — Categorise the Risk (IRDAI Framework)
IRDAI's Enterprise Risk Management framework defines 6 risk categories: Underwriting, Market, Credit, Operational, Liquidity, and Strategic. For each scenario below, identify which category it belongs to and explain your choice in one sentence.
| # | Scenario | Risk Category |
|---|---|---|
| 1 | The stock market drops 20%, causing an insurer's equity-heavy investment portfolio to lose ₹50 crore in value. | |
| 2 | An international reinsurer delays payment of a ₹100 crore claim by 7 months, citing documentation issues. | |
| 3 | Motor third-party claims in the industry pool are running 25% higher than the premiums collected through the pool. | |
| 4 | A critical system outage during the peak renewal season (March) prevents policy issuance for 48 hours. | |
| 5 | A major cyclone in Gujarat triggers 5,000+ claims simultaneously — the insurer needs ₹300 crore in cash within 30 days, but most investments are in 5-year government bonds. | |
| 6 | The insurer invested ₹50 crore in building an agent distribution network just as the market shifted to digital — market share among young customers dropped 15%. |
Check Your Categorisation
| # | Category | Why? |
|---|---|---|
| 1 | Market Risk | Losses from changes in market prices (equity decline). This is a standard market risk exposure in the investment portfolio — not related to insurance operations. |
| 2 | Credit Risk | Risk that a counterparty (reinsurer) fails to meet its obligations. Credit risk is not just about bond defaults — it includes any counterparty who owes the insurer money and may not pay. |
| 3 | Underwriting Risk | The premiums collected are insufficient to cover claims. This is the classic underwriting risk — pricing inadequacy in the core insurance business. |
| 4 | Operational Risk | Loss from failed internal processes, systems, or external events — a system outage during renewal season is a pure operational risk event. |
| 5 | Liquidity Risk | The insurer cannot meet payment obligations as they fall due because its assets are locked in illiquid investments. This is a liquidity crisis — the insurer has enough money overall (the bonds will mature) but does not have it available when needed. |
| 6 | Strategic Risk | Risk from adverse business decisions — investing in a distribution model that was becoming obsolete. Strategic risk is the hardest to identify because it looks like a "good idea" at the time. |
Bonus question: Some scenarios could fit multiple categories. For example, #5 (cyclone liquidity) has elements of Underwriting Risk (the claims event) and Operational Risk (the system capacity to process 5,000 claims). The primary classification depends on which aspect is most material. In this case, the inability to pay (liquidity) is the dominant risk — if that is resolved, the claims processing is manageable.
Hands-On Project: Build a Risk Register for a General Insurance Company
You are the newly appointed Chief Risk Officer of "SecureSure General Insurance," a mid-size Indian general insurer with ₹5,000 crore in annual gross written premium. The company sells motor, health, property, crop, and liability insurance across 15 states. The CEO has asked you to prepare the company's first comprehensive risk register. Use Excel to build a professional risk register with at least 10 risks spanning all six IRDAI risk categories.
📁 Companion Workbook: Risk_Management_Fundamentals_CORRECTED.xlsx
This session is supported by a pre-built Excel workbook with 5 tabs. Use it as your reference solution and as a hands-on exercise file. Each tab maps to a specific part of this session. Open it in Excel (columns Q–T populate automatically with formulas).
⬇ Download the Workbook (.xlsx, 18 KB)
| Tab | What It Contains | How to Use It | Maps To |
|---|---|---|---|
| 1. Risk Register | The completed solution: 12 risks across all IRDAI categories (Underwriting ×3, Operational ×3, Market, Strategic ×2, Credit, Compliance, Liquidity). Contains formulas (=D×E, =I×J), four-level conditional formatting (Red ≥17, Orange 10–16, Amber 5–9, Green <5), and auto-calculating helper columns Q–T (Risk Level, Action Status, Days to Review, Overdue?). | Use as the model answer for your Hands-On Project. Study how each risk is scored, mitigated, and tracked before building your own. | Sections 6.1–6.3 & Hands-On Project |
| 2. Exercise 6.1 | A deliberately flawed one-row risk register containing 5 errors (wrong Inherent score, Residual = Inherent despite controls, status timing mismatch, missing Review Date, generic owner). Answer Key is in rows 7–13. | Find the 5 mistakes before checking the Answer Key — then verify. Reinforces what a well-built register must contain. | Exercise 6.1 in Section 6 |
| 3. Exercise 6.2 | A quick scoring drill: 4 scenarios with blank Likelihood / Impact / Score / Level columns for you to fill, plus an Answer Key column (rows 5–8). | Fill in your scores for each scenario, then compare with the Answer Key. Practises applying the L×I matrix and the four-level scale. | Exercise 6.2 in Section 6 |
| 4. Reference | The IRDAI six-category risk framework with a one-line definition of each category (Underwriting, Market, Credit, Operational, Liquidity, Strategic). | A quick lookup while classifying your risks. Use it to make sure every risk in your register is placed in the correct category. | Section 7 & Exercise 7.1 |
| 5. Executive Summary | The completed management summary: top 3 critical risks (RISK-001, RISK-003, RISK-009) with drivers and mitigation, resource requirements (₹15–20 Cr technology, 25–30 hires, ₹5–8 Cr operational budget), and governance cadence. | Use as the model answer for Hands-On Project Step 7. Note how it quantifies impact and names owners and timelines. | Hands-On Project Step 7 |
Note: The workbook is a companion to this session — build your own register from scratch for the assignment, using this file only as reference. When you update the register, the Q–T helper columns recalculate automatically; conditional formatting is already applied to columns F and K.
Steps
- Identify 10+ risks: Create at least two risks from each of the following categories: underwriting, operational, and strategic. Create at least one risk from each of: market, credit, and liquidity. Write clear, specific risk descriptions.
- Build the register structure: Set up columns A through P as specified in Section 6.1. Freeze the header row. Format the Risk ID column to auto-generate (RISK-001, RISK-002...).
- Score each risk: For each risk, assign Likelihood (1–5), Impact (1–5), Existing Controls, Control Effectiveness (1–3), Residual Likelihood, and Residual Impact. Use the formula =InherentLikelihood × InherentImpact for the Inherent Risk Score, and =ResidualLikelihood × ResidualImpact for the Residual Risk Score.
- Select mitigation strategies: For each risk, choose a primary strategy from the Five Ts. For risks where you choose "Treat," specify at least one additional action. Assign a Risk Owner (use job titles — Chief Underwriting Officer, CIO, CFO, Head of Claims, etc.).
- Apply conditional formatting: Apply the four-level heat map to the Residual Risk Score column — Red (≥17), Orange (10–16), Amber (5–9), Green (<5) — as shown in Section 6.3. Then add the Risk Level (Q), Action Status (R), Days to Review (S), and Overdue? (T) helper columns using the formulas in Section 6.2.
- Add review tracking: Add a "Next Review Date" column and a "Days Until Review" column with the formula =ReviewDate-TODAY(). Apply conditional formatting to highlight overdue reviews in red.
- Write a summary: In a separate sheet or section below the register, write a 200-word Executive Summary identifying the top 3 risks, the chosen mitigation approach, and any resource requirements (budget, headcount, technology) needed to implement the risk management plan.
View Solution / Walkthrough
Example Risk Register — SecureSure General Insurance
Here are 12 sample risks you might include. The scores and details would be in your Excel file — this table shows the thinking behind each risk.
| ID | Category | Risk Description | Inherent L | Inherent I | Strategy | Key Control / Action |
|---|---|---|---|---|---|---|
| RISK-001 | Underwriting | Motor third-party pool losses exceed pricing assumptions by >20% due to regulatory pricing constraints and claims inflation | 4 | 5 | Treat + Transfer | Advanced pricing analytics; excess-of-loss reinsurance for motor TP |
| RISK-002 | Underwriting | Climate change causes property insurance claims in coastal states to double over 5 years, making the property portfolio unprofitable | 4 | 4 | Treat + Terminate | Dynamic risk-based pricing with climate risk factor; exit high-risk flood zones |
| RISK-003 | Underwriting | Health insurance claims ratio exceeds 95% due to medical inflation (15% pa) and provider fraud | 5 | 3 | Treat | AI-based fraud detection; preferred provider network with negotiated rates; co-payment for non-network hospitals |
| RISK-004 | Operational | Core policy administration system experiences outage lasting >24 hours during renewal season, causing customer dissatisfaction and regulatory scrutiny | 2 | 4 | Treat | Cloud migration with auto-failover; disaster recovery testing every 6 months; manual workaround SOP documented |
| RISK-005 | Operational | Employee in claims department colludes with a garage network to approve inflated motor repair bills, causing ₹5+ crore in annual claims leakage | 3 | 3 | Treat | Mandatory job rotation in claims; AI anomaly detection on repair costs by garage; anonymous whistleblower hotline |
| RISK-006 | Operational | Data entry error in policy issuance system results in 5,000 policies being issued with incorrect sum assured, creating a ₹50 crore gap between premium collected and risk covered | 2 | 5 | Treat | Automated validation rules in policy admin system; daily exception report; maker-checker control for policies above ₹1 crore sum assured |
| RISK-007 | Market | RBI raises interest rates by 200 bps, causing the insurer's government bond portfolio (60% of investments) to lose 8–10% in market value | 3 | 4 | Treat + Tolerate | Reduce portfolio duration from 8 years to 5 years; increase allocation to floating-rate bonds; hold 20% in held-to-maturity |
| RISK-008 | Credit | Reinsurer (international, A-rated) downgraded to BBB and subsequently delays/contests a ₹200 crore claim payment after a major cyclone | 2 | 5 | Transfer (diversify) + Treat | Diversify reinsurance panel (no single reinsurer >30% of program); include cut-through clauses; maintain letter of credit from reinsurer |
| RISK-009 | Liquidity | Major cyclone in Gujarat causes 2,000+ claims within 72 hours requiring ₹300 crore in claim payments within 30 days, while bond portfolio is temporarily illiquid | 3 | 4 | Treat | Maintain ₹100 crore liquid buffer (overnight funds, liquid mutual funds); committed credit line of ₹200 crore from consortium of banks |
| RISK-010 | Strategic | Digital-first competitors (Acko, Digit) capture 15% market share in motor insurance within 3 years by offering 20% lower premiums, eroding SecureSure's largest line of business | 5 | 4 | Treat + Take Advantage | Launch digital direct-to-consumer channel; partner with 3 e-commerce platforms for embedded insurance; invest in telematics-based UBI product |
| RISK-011 | Strategic | IRDAI introduces new rural/social sector obligations requiring 10% of GWP from rural areas, which SecureSure lacks the distribution network to achieve | 3 | 3 | Treat | Partner with regional rural banks and cooperative societies for distribution; develop micro-insurance products for rural markets |
| RISK-012 | Strategic | DPDP Act enforcement results in ₹100 crore penalty because customer data used for AI underwriting model training was obtained without explicit consent | 2 | 5 | Treat | Conduct data audit; obtain retrospective consent from existing customers; implement consent management platform; establish AI ethics committee |
Executive Summary (Sample)
The risk assessment for SecureSure General Insurance identifies three critical risks requiring immediate board attention. First, motor third-party underwriting risk (RISK-001, Residual Score: 16) — persistent pricing inadequacy combined with regulatory constraints demands a dual response: deploy advanced pricing analytics to improve risk selection within regulatory limits, and purchase additional excess-of-loss reinsurance to cap downside exposure at ₹75 crore. Second, strategic disruption risk from digital competitors (RISK-010, Residual Score: 15) — the 3-year trajectory shows market share erosion accelerating. We recommend a ₹45 crore investment over 18 months to build a digital direct channel (₹25 crore), establish embedded insurance partnerships with 3 e-commerce platforms (₹12 crore), and launch a telematics-based UBI pilot for private cars (₹8 crore). Third, the DPDP Act compliance risk (RISK-012, Residual Score: 12) — while assessed as lower likelihood, the potential penalty magnitude makes this a board-level concern. We recommend a 90-day data audit and consent management implementation at an estimated cost of ₹3 crore. Total incremental resource requirement: ₹48 crore capital allocation and 12 new hires (data science, digital product, compliance).
3-2-1 Reflection — Before You Move On
Retrieval practice strengthens long-term memory. Before moving to Session 03, take 3 minutes to write down what you have learned.
3 Things I Learned Today
2 Real Risks I Can Now Identify
1 Question I Still Have About Risk Management
Key Takeaways
Pure risk (loss or no loss) is insurable. Speculative risk (loss, no loss, or gain) is not. This single distinction defines the boundary of the entire insurance industry.
Risk management is a continuous five-step cycle — Identify → Assess → Mitigate → Implement → Monitor — not a one-time exercise. The most common failure is neglecting step five.
The Five Ts — Transfer, Tolerate, Treat, Terminate, Take Advantage — are the complete strategic toolkit. Most significant risks require a combination of strategies, not just one.
A well-built risk register with formulas, conditional formatting, and review tracking transforms risk management from a compliance exercise into a strategic decision-making tool.
Indian insurers operate within IRDAI's six-category risk framework (underwriting, market, credit, operational, liquidity, strategic). Every InsurTech selling into insurers must understand how its product affects each category.
Test Your Understanding
1. A company investing in the stock market faces which type of risk?
2. Which is the correct sequence of the five-step risk management process?
3. An insurer purchasing catastrophe reinsurance to protect against cyclone losses is applying which of the Five Ts?
4. In a likelihood × impact risk matrix, a risk scored Likelihood=4 (Likely, 20–50% annual probability) and Impact=4 (Major, ₹10–₹100 crore impact) has a risk score of 16. This risk should be classified as:
5. Which of the following must a professional risk register contain?