Module 1 · Session 02 · 90 min · Excel Lab

Session 02: Risk Management Fundamentals

CILO-1 · Domain Knowledge · Lecture & Problem Solving (Excel) · Bring laptop with Excel

Learning Objectives

1. Understanding Risk

Before we can manage risk, we must understand what it is. In everyday language, "risk" means the possibility of something bad happening. But in insurance and risk management, the definition is more precise — and the distinctions matter enormously for what can and cannot be insured.

1.1 Defining Risk

In insurance terms, risk has two components that must both be present:

Formally, risk can be expressed as:

Risk = Probability of Event × Severity of Loss

Where: Probability = likelihood of the event occurring (0 to 1, or percentage)
       Severity   = financial impact if the event occurs (in currency terms)

Example: Risk of factory fire = 0.002 (0.2% per year) × ₹2,00,00,000
        = ₹40,000 expected annual loss

1.2 Pure Risk vs. Speculative Risk

This is arguably the most important conceptual distinction in insurance:

DimensionPure RiskSpeculative Risk
Possible Outcomes Loss or No Loss (two outcomes) Loss, No Loss, or Gain (three outcomes)
Insurable? Yes — under the right conditions Generally No
Examples House fire, car accident, hospitalization, death, cyclone damage Stock market investment, launching a new product, gambling, buying lottery tickets
Risk Pooling Viable? Yes — the law of large numbers applies No — the possibility of gain creates adverse selection and moral hazard problems
Social Benefit of Insurance? High — protects against financial ruin Negative — would encourage excessive risk-taking
📝
Note: Some risks seem to blur the line between pure and speculative, but the distinction becomes clear when you ask: "What event actually triggers the insurance payout?"

Example 1 — Business Interruption Insurance: A factory burns down. The fire itself is a pure risk — it can only cause loss. The insurance pays because of the fire. The fact that the factory owner's decision to operate a business (a speculative risk — could succeed or fail) is related to the loss is irrelevant; the trigger is the fire, not the business decision. The pure risk (fire) makes it insurable.

Example 2 — Trade Credit Insurance: A supplier sells goods to a customer on credit and insures against the customer not paying. The customer's non-payment is a pure risk for the supplier — it can only cause loss. The fact that the customer's business may have failed due to speculative decisions (bad investments, poor strategy) does not matter — from the supplier's perspective, the non-payment is an unforeseen loss beyond their control.

The rule: Insurance covers the trigger event, not the broader business context. If the trigger event is a pure risk (fire, accident, default, illness, death), the risk is insurable — even if speculative risks are connected somewhere in the background.

1.3 Systematic vs. Unsystematic Risk

Risk can also be classified by its scope:

Insurance is fundamentally designed to handle unsystematic risk through pooling. Systematic risk, by its nature, cannot be pooled away — which is why pandemics, widespread cyber events, and systemic financial crises present existential challenges to the insurance industry and often require government backstops or reinsurance solutions.

🌎
Real World: During COVID-19, Indian insurers faced simultaneous pressures: health claims surged, life insurance death claims increased, motor claims dropped (fewer cars on the road), and investment portfolios lost value as markets crashed. This was systematic risk in action — everything moved together. Insurers that had strong Enterprise Risk Management (ERM) frameworks weathered the storm far better than those that managed each risk in isolation.

2. The Risk Management Process

Risk management is not a one-time exercise. It is a continuous cycle of five interconnected steps that feed into each other. Every organization — and every insurance company — that manages risk effectively follows some version of this process.

2.1 The Five-Step Cycle

Step 1: Risk Identification

Systematically identify all risks the organization faces. What could go wrong? What events could cause financial loss, operational disruption, reputational damage, or regulatory penalty? The goal is comprehensiveness — a risk you haven't identified is a risk you cannot manage.

Step 2: Risk Assessment

For each identified risk, estimate two things: (a) How likely is it to occur? (b) If it does occur, how severe will the impact be? This can be qualitative (High/Medium/Low) or quantitative (annual probability of 2%, expected loss of ₹50 lakh). The output is a prioritized list of risks.

Step 3: Risk Mitigation

For each significant risk, decide what to do about it. The five options — Transfer, Tolerate, Treat, Terminate, Take Advantage — are the heart of risk management strategy. We explore each in detail in Section 5.

Step 4: Implementation

Put the chosen mitigation strategies into action. This is where strategy meets operations: purchasing insurance policies, installing fire suppression systems, training employees on cybersecurity, diversifying the investment portfolio, setting up compliance monitoring.

Step 5: Monitoring & Review

Risk is dynamic. New risks emerge, existing risks change in probability or severity, mitigation measures degrade over time, and the external environment evolves. Continuous monitoring and periodic review — quarterly at minimum — are essential. The risk register is a living document, not a filing exercise.

💡
Pro Tip: The most common failure in risk management is treating Step 5 (monitoring and review) as optional. A risk register created in January and never revisited is worse than no risk register at all — it creates a false sense of security. Effective risk managers schedule quarterly risk review meetings as recurring calendar events, with clear ownership for each risk item and a requirement that owners come prepared with updates.

🔧 Exercise 2.1 — Sequence the Risk Management Process

Below are the 5 steps of the risk management process and 5 actions — but they are jumbled. Your task: (A) Arrange the steps in the correct order. (B) Match each step to the action that belongs with it.

Part A — Order the Steps

Your OrderStepStep Name
Put the chosen mitigation strategies into action — install controls, purchase insurance, train employees.
For each identified risk, estimate how likely it is and how severe it would be.
Systematically find all risks the organisation faces — what could go wrong?
Track risks over time — new risks emerge, existing risks change, controls degrade.
For each significant risk, decide what to do — Transfer, Tolerate, Treat, Terminate, or Take Advantage.

Part B — Apply the Process

Scenario: You are the risk manager of an insurance company. A new regulation requires you to assess and manage cyber risk across the organisation. Walk through the 5 steps and state briefly what you would do at each step.

View Solution — Correct Sequence + Worked Example

Part A — Correct Order

OrderStep NameWhy This Order?
1Risk IdentificationYou cannot manage a risk you have not identified. Always start here.
2Risk AssessmentOnce identified, assess each risk — how likely? how severe? Prioritise.
3Risk MitigationFor significant risks, decide what to do (the Five Ts).
4ImplementationStrategy without action is worthless. Put the plan into motion.
5Monitoring & ReviewRisk changes constantly. Monitor and update — the cycle never ends.

Part B — Cyber Risk Assessment Walkthrough (Example)

  1. Identify: Conduct a workshop with IT, Legal, and Operations teams. List all cyber risks — ransomware, data breach, insider threat, DDoS, third-party vendor compromise, system outage. Create a preliminary risk list of 15–20 items.
  2. Assess: Score each risk on Likelihood (1–5) and Impact (1–5) using the matrix from Section 4.1. Ransomware: L=4 (likely), I=4 (major) → score 16 = Critical. Data breach: L=3 (possible), I=5 (catastrophic) → score 15 = Critical. Rank all risks by score.
  3. Mitigate: For Critical and High risks, select strategies. Ransomware → Treat (MFA, offline backups, employee training, EDR) + Transfer (cyber insurance). Data breach → Treat (encryption, access controls, breach detection) + Tolerate (residual risk after controls is within appetite).
  4. Implement: Deploy MFA across all systems within 60 days. Contract with a cyber forensic firm. Purchase cyber insurance policy with ₹10 Cr limit. Run phishing simulation training for all employees.
  5. Monitor & Review: Track: number of phishing emails reported, system patch compliance %, cyber insurance claims. Review the risk register quarterly. Update risk scores after each significant cyber incident anywhere in the industry — not just within the organisation.

3. Risk Identification Techniques

Risk identification is the foundation of the entire process. A risk you fail to identify at this stage will not be assessed, mitigated, or monitored. Different techniques are suited to different contexts — the best risk managers use multiple approaches and triangulate.

3.1 Seven Identification Techniques

Each technique below serves a different purpose. The best risk managers do not rely on one — they use multiple techniques in combination because each catches risks the others miss. Think of these as tools in a toolbox: you would not build a house with only a hammer.

TechniqueHow It Works — Step by StepBest ForStrengthsWeaknessesInsurance Example
1. Checklists Start with a pre-existing list of common risks for your industry or function. Go through each item and ask: "Could this happen to us? How severe would it be?" Add organisation-specific items. Review and update the checklist annually. Ensuring no obvious risks are missed; regulatory compliance Fast, systematic, covers known risks, easy for non-experts to use Only catches known risks; may create false comfort ("we checked every box") IRDAI's prescribed risk categories (underwriting, market, credit, operational, liquidity, strategic) used by insurers for their quarterly solvency self-assessment. Each category has a sub-checklist.
2. SWOT Analysis Divide a whiteboard into four quadrants: Strengths, Weaknesses, Opportunities, Threats. List internal factors (Strengths, Weaknesses) and external factors (Opportunities, Threats). Risks emerge from: (a) Weaknesses that could be exploited, (b) Threats from the competitive environment. Then prioritise. Strategic planning; competitive positioning; new business initiatives Broad perspective, links risks to strategy, engaging team exercise Subjective; risks identified depend heavily on who is in the room; rarely surfaces operational or technical risks An insurer analysing the threat of digital disruption: Weakness = legacy IT systems, Threat = InsurTechs with lower cost structures, Opportunity = partnership with an InsurTech instead of building internally.
3. Scenario Analysis Choose 2–4 drivers of change (e.g., regulatory, technological, economic). Create extreme but plausible scenarios by combining them (e.g., "tight regulation + rapid AI adoption"). For each scenario, trace the impact on every part of the organisation. Ask: "What would we need to do differently under this scenario?" Tail risks; low-probability, high-impact events; strategic uncertainty Surfaces risks that have never occurred before, builds strategic preparedness, challenges groupthink Time-intensive; scenarios depend on assumptions that may be wrong; can produce false confidence ("we planned for that scenario") "What if a Category 5 cyclone hits Mumbai directly?" — trace the impact on property insurance (massive claims), motor (flood-damaged cars), life (potential casualties), health (injuries, waterborne diseases), and business interruption (port closure, office shutdowns). Identifies accumulation risk across lines.
4. Root Cause Analysis Start with a specific loss event that already happened. Ask "Why?" repeatedly (the "5 Whys" technique) — each answer leads to a deeper cause. Continue until you reach a systemic or process failure, not a human error. Then ask: "Could this same root cause produce other losses we have not yet seen?" Learning from past incidents; preventing recurrence; improving controls Deep, evidence-based, reveals systemic issues that single-incident reporting misses Requires a loss to have already occurred; only as good as the quality of the investigation After a major claims fraud is detected: Why? → No fraud check at FNOL. Why? → System did not flag repeat claimants. Why? → Claims system has no automatic cross-reference with previous claims. Result: fix the system, not just this one claim. Then check all other claims that could have slipped through the same gap.
5. Loss Data Analysis Collect historical loss data (claims, incidents, near-misses). Segment by type, cause, location, time, and amount. Look for patterns: are certain types of loss increasing? Are certain locations over-represented? Are there peaks at specific times? Use statistical methods (trend analysis, regression) to separate signal from noise. Data-rich environments; quantitative risk assessment; identifying emerging trends Objective, data-driven, reveals patterns invisible to human observation, quantifiable Requires clean historical data; past patterns may not predict future (especially for emerging risks); can miss rare events Analysing 5 years of motor claims data to discover: SUV models made after 2020 have 40% lower claim frequency but 25% higher average severity than sedans. Older drivers (60+) in Chennai have the highest claim frequency during monsoon months (July–November). These insights feed into pricing and underwriting.
6. Delphi Technique Select a panel of experts (internal and external) who do NOT know each other's identities. Round 1: Circulate a questionnaire asking them to list and assess risks. Collect and anonymise all responses. Round 2: Share the aggregated results and ask each expert to revise their assessment in light of others' views. Repeat until consensus converges (typically 2–3 rounds). The anonymity prevents dominant personalities from swaying the group. Emerging risks with little historical data; expert-dependent domains; controversial topics Eliminates groupthink and authority bias; systematically aggregates expert judgment; works even without data Slow (weeks per round); depends on expert selection quality; consensus may be false (everyone is equally wrong) Assessing cyber insurance risk for quantum computing threats (2026+). There is zero claims history because quantum attacks do not exist yet at scale. A panel of cybersecurity experts, quantum physicists, and insurance underwriters anonymously estimates: probability of first major quantum-related loss event, timeline, and potential industry loss amount.
7. Process Mapping Draw a detailed flowchart of a specific business process — every step, every decision point, every handoff between teams. At each step, ask: "What could go wrong here?" (risk identification) and "What controls exist to prevent or catch it?" (control identification). Mark steps with no controls as high-risk. Quantify the impact of failure at each step. Operational risk; internal controls assessment; process improvement; system implementation Granular, identifies specific failure points, directly links risks to controls, produces actionable improvements Narrow — focuses on one process at a time; requires detailed process knowledge; time-consuming to do well Mapping the claims settlement process: FNOL Received → Enter into System → Assign Surveyor → Surveyor Visits Site → Assessment Report → Manager Approval → Payment Processing. At the "Assign Surveyor" step: what if no surveyor is available within 48 hours? (risk: delayed assessment, customer complaint). At "Manager Approval": what if the manager approves without reviewing? (risk: control failure). Each step is analysed and improved.
💡
Pro Tip: No single technique catches everything. Checklists ensure you don't miss known risks but won't surface new ones. Scenario analysis surfaces new risks but may miss mundane operational risks. A robust risk identification exercise uses at least three techniques and brings together people from different functions — the CFO sees financial risks the COO doesn't, and vice versa.

4. Risk Assessment & Measurement

Once risks are identified, they must be assessed. The goal is to answer two questions for each risk: How likely? and How bad? The answers determine which risks demand management attention and resources.

4.1 The Likelihood × Impact Matrix

This is the most widely used risk assessment tool in business. Every risk is scored on two dimensions, and the product of those scores determines its priority:

Likelihood ScoreMeaning (Annual Probability)Impact ScoreMeaning (Financial Impact)
1 — Rare< 1% (less than once in 100 years)1 — Negligible< ₹10 lakh
2 — Unlikely1–5% (once in 20–100 years)2 — Minor₹10 lakh – ₹1 crore
3 — Possible5–20% (once in 5–20 years)3 — Moderate₹1 crore – ₹10 crore
4 — Likely20–50% (once in 2–5 years)4 — Major₹10 crore – ₹100 crore
5 — Almost Certain> 50% (more than once in 2 years)5 — Catastrophic> ₹100 crore

The risk score is calculated as:

Risk Score = Likelihood × Impact

Risk Level (using a 5×5 matrix — all scores 1 to 25 are covered):
   1–4   = Low (Green)       — Acceptable; monitor routinely
   5–9   = Medium (Amber)    — Requires attention; implement controls where cost-effective
  10–16  = High (Orange)     — Needs management attention; regular monitoring
  17–25  = Critical (Red)    — Unacceptable; immediate action required

Example: A risk with Likelihood = 3 (Possible, 5–20% probability) and Impact = 4 (Major, ₹10–100 crore) scores 3 × 4 = 12, placing it in the High category — requiring management attention.

4.2 Quantitative Approaches — Expressing Risk in Rupees

A score of 12 on a 5×5 matrix tells you a risk is "High" — but it does not tell you how much money is at stake. Quantitative methods fix this by expressing risk in rupees. They answer one simple question: "How much money could we lose, and how often?"

Three metrics work together. The best way to understand them is through a single story:

Imagine you are an insurer covering 100,000 houses against fire. You have 100 years of data showing that, on average, 100 houses burn per year (0.1%), and the average claim per fire is ₹50 lakh. You want to understand your risk in rupees — how much to charge, how much to set aside, and whether you have enough capital to survive a catastrophe.

Step 1 — The Average
₹50 Cr
Expected Loss (EL)
100 houses × ₹50 lakh = ₹50 crore expected claims per year. This is your "average year" — used for setting premiums and reserves.
Step 2 — The Bad Year
₹125 Cr
Value at Risk (VaR)
The 95% VaR is ₹125 crore. This means: in 95% of years, losses will be ₹125 crore or less. In 5% of years (1 in 20), they will EXCEED ₹125 crore.
Step 3 — The Really Bad Year
₹200 Cr
Tail VaR (TVaR)
The 95% TVaR is ₹200 crore. This means: ON THE DAYS THAT EXCEED ₹125 crore (the worst 5%), the average loss is ₹200 crore — far worse than the ₹125 crore threshold.

The key: ₹50 Cr (EL) tells you what to budget. ₹125 Cr (VaR) tells you where to set your reinsurance. ₹200 Cr (TVaR) tells you how much capital you need to survive. If you only budget for the average, you fail in the bad years.

Note on "95% VaR": This does NOT mean "95% chance of ₹125 crore loss." It means "95% chance that the loss will be ₹125 crore OR LESS." The loss could be ₹1 crore or ₹125 crore — there is a 95% probability it will not exceed ₹125 crore. In the remaining 5% — the "tail" — losses can be much worse, which is exactly what TVaR measures.

MetricWhat It Tells YouWhat It IgnoresUsed For
Expected Loss (EL) The average loss you can expect every year. Does not capture the volatility — bad years can be far worse than the average. Setting premiums, budgeting for claims, reserve planning
Value at Risk (VaR) The loss threshold that will not be exceeded in a normal year (with 95% confidence). Does not tell you how bad things get when the threshold IS exceeded — it cuts off at the boundary. Setting reinsurance limits, regulatory solvency calculations
Tail VaR (TVaR) How bad it gets on average when things go really wrong (beyond the VaR threshold). Does not capture the worst single possible loss — only the average of all "bad" scenarios. Capital planning, stress testing, board-level risk appetite

Analogy: Think of EL as your monthly grocery budget (what you usually spend). VaR is the maximum you expect to spend in any normal month — say ₹15,000 at the 95th percentile (only 1 month in 20 exceeds this). TVaR asks: when you DO exceed ₹15,000, what is the average overshoot — ₹22,000? ₹30,000? That is your TVaR, and it tells you how much buffer you need in your emergency fund.

Warning: The likelihood × impact matrix is deceptively simple. The biggest mistake is treating the scores as objective when they are actually subjective judgments. Two different risk managers scoring the same risk may give it scores of 4×3=12 (Medium) and 5×4=20 (High) — leading to completely different responses. Always calibrate scores across assessors. Use clear definitions for each score level (as in the tables above). And when a risk falls near a boundary, escalate — it's better to over-manage a borderline risk than to under-manage one that turns out to be critical.

4.3 Risk Heat Maps

A risk heat map is the visual representation of the likelihood-impact matrix. Each risk is plotted as a point on a 5×5 grid, with color coding:

A well-constructed heat map allows a board or risk committee to see, at a single glance, where the organization's major risk exposures lie. We will build one in Section 6 using Excel conditional formatting.

5. Risk Mitigation Strategies — The Five Ts

Once risks are identified and assessed, the critical strategic question is: what should we do about each risk? Risk managers classify the options into five strategies, commonly called the "Five Ts."

5.1 The Five Strategies

StrategyWhat It MeansWhen to UseInsurance Example
1. Transfer Shift the financial consequences of the risk to another party, typically through insurance, reinsurance, hedging, or contractual indemnities The risk is too large to retain; the cost of transfer is less than the potential loss; the counterparty is better capitalized to bear the risk An insurer purchasing catastrophe reinsurance to protect against a ₹500 crore cyclone loss that would threaten its solvency
2. Tolerate (Retain) Accept the risk and budget for the potential loss. No active mitigation beyond monitoring. The cost of mitigation exceeds the expected loss; the risk is within the organization's risk appetite; the risk is low-probability and low-impact An insurer deciding not to reinsure motor own-damage claims below ₹1 lakh — the risk is high-frequency but low-severity and predictable through pooling
3. Treat (Reduce) Implement controls to reduce either the likelihood or the impact (or both) of the risk. This is "risk reduction." The risk is significant but can be reduced to an acceptable level through cost-effective controls; the organization has the capability to implement and maintain the controls An insurer implementing AI-based fraud detection to reduce claims fraud losses from 8% of claims to 3%
4. Terminate (Avoid) Eliminate the risk entirely by ceasing the activity that creates it. This is the most definitive strategy — but also the most costly in terms of foregone opportunity. The risk cannot be reduced to an acceptable level; the potential loss, however unlikely, is existential; the activity is not core to the business An insurer deciding to stop writing property insurance in flood-zone areas after catastrophic losses made the line unprofitable despite reinsurance
5. Take Advantage (Exploit) Actively pursue the upside of a risk — turning a threat into an opportunity. This applies primarily to speculative risks. The organization has a competitive advantage in managing this risk; the upside is significant; the downside is well-understood and acceptable An insurer with superior climate analytics capabilities actively expanding into parametric weather insurance, viewing climate change as a market opportunity

5.2 Choosing the Right Strategy

The choice of strategy is not automatic — it depends on the organization's risk appetite, the cost-benefit analysis of each option, and the residual risk after controls. The decision framework is:

  1. Can the risk be eliminated without sacrificing core business? If yes → Terminate.
  2. If not, is the risk within our risk appetite? If yes and cost of mitigation exceeds benefit → Tolerate.
  3. If not, can we reduce it to an acceptable level cost-effectively? If yes → Treat.
  4. For the residual risk that remains after treatment, should we transfer it? If yes → Transfer (insurance/reinsurance).
  5. Is there an upside we can capture? If yes → Take Advantage.
📝
Note: Most significant risks require a combination of strategies. Consider cyber risk for an insurer: Treat (implement firewalls, MFA, employee training, incident response plan), Transfer (purchase cyber insurance for residual exposure), and Tolerate (accept a deductible/self-insured retention of ₹50 lakh). The Five Ts are not mutually exclusive — they are building blocks of a comprehensive risk response.

🧮 Exercise 5.1 — Choose the Right Mitigation Strategy

For each scenario below, select the primary strategy from the Five Ts (Transfer / Tolerate / Treat / Terminate / Take Advantage) and justify your choice in one sentence. For the last scenario, more than one T may apply — identify the combination.

#ScenarioYour Strategy
1A general insurer faces a 1-in-500 year earthquake risk that could cause ₹1,000 crore in losses — 10× its available capital.
2An insurer's internal fraud rate is 8% of claims. An AI detection system costing ₹2 Cr/year can reduce it to 3%.
3A health insurer finds that a wellness programme costs ₹5 Cr/year but only reduces claims by ₹3 Cr/year.
4An insurer's property portfolio in coastal cyclone zones has a combined ratio of 140% — consistently unprofitable despite all mitigation efforts.
5An insurer has built superior climate data analytics. Competitors are avoiding cyclone insurance due to fear of losses.
6A large IT system migration project carries risk of business disruption, data loss, and customer dissatisfaction.

Decision Tree Drill: Pick one scenario above (your choice). Trace it through the 5-question decision framework from Section 5.2. Write down: for each question, your Yes/No answer and the strategy it leads to.

View Solution — Strategy Selection
#StrategyRationale
1TransferThe potential loss (₹1,000 Cr) is existential — 10× the insurer's capital. The risk cannot be retained, treated (it is a natural event), or terminated (the insurer cannot stop earthquakes). The only option is to transfer via reinsurance or a catastrophe bond.
2TreatThe risk can be reduced cost-effectively. Cost: ₹2 Cr/year. Benefit: 5% reduction in fraud on a claims pool. If total claims are ₹100 Cr, 5% = ₹5 Cr saved. Net benefit: ₹3 Cr/year. This is a classic "Treat" — the control costs less than the expected loss reduction.
3TolerateThe programme costs more than it saves. The rational decision is to stop the programme and tolerate the underlying risk (health claims without the wellness intervention). The risk is within appetite — the insurer can absorb the claims.
4TerminateDespite all efforts to Treat (tighter underwriting, higher premiums, risk controls), the combined ratio is 140% — the line is fundamentally unprofitable. The remaining options are Tolerate (but this destroys capital) or Terminate. Terminate means stop writing this product in these zones.
5Take AdvantageThe insurer has a competitive advantage (superior climate data) that others lack. The growing demand for cyclone insurance (driven by climate change awareness) creates a market opportunity. This is a speculative risk — but the insurer can manage it better than competitors.
6Combination: Treat + Tolerate | Treat (reduce risk): thorough testing, phased rollout, rollback plan, parallel running. Tolerate: accept that some disruption is inevitable. Transfer: purchase project-specific insurance or warranties from the vendor. The project may also be Terminated if the business case fails at any stage.

Decision Tree Trace — Earthquake Scenario (#1)

  1. "Can the risk be eliminated without sacrificing core business?" → No. Earthquakes cannot be prevented. The insurer cannot stop operating in earthquake-prone zones without exiting the property insurance market entirely — which is core business.
  2. "Is the risk within our risk appetite?" → No. ₹1,000 Cr loss is 10× capital — existential. It is far outside any reasonable risk appetite.
  3. "Can we reduce it to an acceptable level cost-effectively?" → No. We cannot "reduce" earthquake probability or severity. Loss prevention (better building codes) helps over time but does not reduce the 1-in-500 year extreme loss.
  4. "For the residual risk after treatment, should we transfer it?" → Yes. Transfer via catastrophe reinsurance is the only viable option. The insurer accepts a deductible (retention) and transfers everything above that.
  5. "Is there an upside we can capture?" → Not for earthquake — it is a pure risk. This option does not apply.

Result: Transfer (primary) + Tolerate (retention/deductible).

6. Building a Risk Register in Excel

The risk register is the central document of the risk management process. It captures every identified risk, its assessment, the chosen mitigation strategy, residual risk, ownership, and review status — all in one place. Excel is the most widely used tool for risk registers in practice, and mastering the Excel-based risk register gives you a skill you can deploy in any organization from day one.

6.1 The Risk Register Structure

A professional risk register contains the following columns at minimum:

ColumnField NameDescription
ARisk IDUnique identifier (e.g., RISK-001, RISK-002)
BRisk CategoryOperational / Financial / Strategic / Compliance / Reputational
CRisk DescriptionClear, specific description of the risk event and its consequences
DLikelihood (1–5)How likely is this risk to occur? (See Section 4.1 scale)
EImpact (1–5)How severe would the consequences be? (See Section 4.1 scale)
FInherent Risk Score= D × E (before any controls)
GExisting ControlsWhat controls are already in place?
HControl EffectivenessHow effective are existing controls? (1=Weak, 2=Partial, 3=Strong)
IResidual LikelihoodLikelihood AFTER existing controls
JResidual ImpactImpact AFTER existing controls
KResidual Risk Score= I × J (after existing controls)
LMitigation StrategyTransfer / Tolerate / Treat / Terminate / Take Advantage
MAdditional ActionsWhat further actions are planned?
NRisk OwnerNamed individual responsible for managing this risk
OReview DateDate of next scheduled review
PStatusOpen / In Progress / Closed / Escalated

6.2 Essential Excel Formulas

Here are the key formulas you will use to build an intelligent risk register:

' Inherent Risk Score (Column F, Row 2):
=D2*E2

' Residual Risk Score (Column K, Row 2):
=I2*J2

' Risk Level Classification (Column Q, Row 2):
=IF(K2>=17,"CRITICAL",IF(K2>=10,"HIGH",IF(K2>=5,"MEDIUM","LOW")))

' Action status based on risk level (Column R, Row 2):
=IF(K2>=17,"⚠ IMMEDIATE ACTION REQUIRED",IF(K2>=10,"◆ Mitigation Planned",IF(K2>=5,"● Monitor","✓ Acceptable")))

' Days until next review (Column S, Row 2):
=O2-TODAY()

' Overdue flag (Column T, Row 2):
=IF(AND(O2<TODAY(),P2<>"Closed"),"OVERDUE","On Track")

6.3 Conditional Formatting for the Heat Map Effect

Apply these conditional formatting rules to the Inherent Risk Score and Residual Risk Score columns to create an instant visual heat map:

The result: anyone looking at your risk register can instantly see which risks need attention — no analysis required. The red cells are your action list.

Warning: A risk register is only as good as its last review. Risks that were scored 6 (Low) six months ago may be 16 (Critical) today because of changes in the business environment, regulatory landscape, or threat landscape. Always add a "Days Since Last Review" column with conditional formatting that highlights overdue items in red. A risk register that isn't reviewed and updated quarterly is not just useless — it is dangerous, because it gives stakeholders false assurance that risks are being managed.

🔎 Exercise 6.1 — Spot the Mistakes in This Risk Register

The risk register below contains 5 deliberate errors. Find each one, explain why it is wrong, and state how to fix it.

IDRisk DescriptionLIInherentMitigationResid LResid IResidualOwnerStatus
001Data breach exposing customer PII 35 8 Encryption, access controls 24 8 CTOIn Progress

Hint: Check the calculations, the logic of before-and-after scores, the ownership, and the status fields.

Check Your Answers — 5 Errors Revealed
  1. Inherent Score calculated incorrectly: L=3 × I=5 = 15, not 8. The table shows 8 (which would be 2×4 or addition). Fix: Change Inherent Score to 15 (Critical).
  2. Residual Score equals Inherent Score despite controls: Residual L=2 × Residual I=4 = 8. But if controls exist (encryption, access controls), the residual score should be LOWER than the inherent score. If it is the same, either the controls are ineffective and should be removed from the register, or the residual scores need re-evaluation. You cannot claim controls exist and yet the score stays unchanged.
  3. Status says "In Progress" but residual risk is still 8 (Medium-amber): If mitigation is still "In Progress," the controls are not yet fully operational. The residual score of 8 is misleading — it should reflect the CURRENT risk level with partial controls, or the status should be updated to reflect that controls are not yet effective.
  4. Review Date missing: Every risk in a register must have a review date. Without it, there is no accountability for when this risk will be reassessed. Fix: Add a review date column and populate it.
  5. Risk Owner is CTO — too generic for a data breach risk: While CTO-level ownership is acceptable for a Critical risk, the "In Progress" status needs a specific action owner — e.g., the CISO (Chief Information Security Officer) who is actually implementing the encryption and access controls. Fix: Add a secondary "Action Owner" column for the person responsible for the specific mitigation steps.

✎ Exercise 6.2 — Quick Risk Scoring Drill

For each scenario below, assign Likelihood (1–5) and Impact (1–5), calculate the risk score, and classify it (Low / Medium / High / Critical) using the 4-level scale from Section 4.1.

#ScenarioL (1–5)I (1–5)ScoreLevel
1Data breach at a large insurer: Industry data shows a 30% probability per year. Worst case: ₹50 Cr in regulatory penalties + remediation costs.
2Minor office theft: ~5% chance of employee theft of office supplies. Maximum loss: ₹25,000.
3Category 5 cyclone hitting Mumbai: Experts estimate < 1% annual probability. If it happens: ₹5,000 Cr in insured losses.
4Regulatory change in motor TP pricing: IRDAI announces new pool pricing every 2–3 years (30–50% chance in any given year). Impact: moderate profitability shift of ₹10–25 Cr.
Check Your Scores
#LIScoreLevelReasoning
14416High30% probability = Likely (4). ₹50 Cr impact = Major (4). 4×4=16 → High. Requires dedicated mitigation plan with named owner.
2313Low5% = Possible (3). ₹25K = Negligible (1). 3×1=3 → Low. Accept and monitor routinely. Not worth significant investment.
3155Medium<1% = Rare (1). ₹5,000 Cr = Catastrophic (5). 1×5=5 → Medium. Despite the low probability, the severity is so high that the insurer must have reinsurance and a disaster recovery plan. The Medium level correctly signals "do not ignore, but do not over-invest."
4339Medium30–50% = Possible (3). ₹10–25 Cr = Moderate (3). 3×3=9 → Medium. Requires attention — monitor the regulatory landscape, model the potential impact, prepare a pricing response.

Key insight from scenario 3: A low-probability × high-impact risk scores only 5 (Medium), but most insurers would treat it more seriously than the score suggests. This is a limitation of the simple L×I matrix — it does not capture risk aversion or the "sleep-at-night" factor. Many organisations add a separate "catastrophic risk" category for events with Impact = 5 that get escalated regardless of Likelihood.

📋 Stable content — Reviewed: July 2026

7. Risk Management in Indian Insurance

The Indian insurance industry has a structured regulatory framework for risk management that all insurers must follow. Understanding this framework gives you insight into how insurers actually manage risk — not just in theory but as a matter of regulatory compliance.

7.1 IRDAI's Risk Management Requirements

IRDAI mandates that all insurers implement a robust risk management framework. The key regulatory requirements include:

  • Enterprise Risk Management (ERM) Policy: Every insurer must have a board-approved ERM policy covering all material risks — underwriting, market, credit, operational, liquidity, and strategic risks.
  • Risk Management Committee (RMC): The board must constitute a Risk Management Committee with majority independent directors. The RMC oversees the ERM framework and reviews the risk register quarterly.
  • Own Risk and Solvency Assessment (ORSA): Insurers must conduct an annual self-assessment of their risk profile and capital adequacy. ORSA asks: given our risks, do we have enough capital to survive a severe but plausible adverse scenario?
  • Chief Risk Officer (CRO): A dedicated CRO with direct reporting access to the board RMC. The CRO cannot be the CFO or the Chief Actuary — risk management must be independent of profit-center functions.
  • Solvency Margin: The Available Solvency Margin must exceed the Required Solvency Margin by at least 50% (ratio ≥ 1.5). This is the ultimate backstop — if capital falls below this threshold, the insurer must stop writing new business.

7.2 Risk Categories for Indian Insurers

IRDAI's framework categorizes insurer risks into six buckets that every ERM framework must address:

Risk CategoryWhat It CoversExample for a General Insurer
Underwriting RiskRisk that premiums are insufficient to cover claims and expensesUnder-pricing motor third-party insurance due to competitive pressure; inadequate reserving for long-tail liability claims
Market RiskRisk of losses from changes in market prices (interest rates, equity prices, FX, real estate)Investment portfolio losing 20% in a market crash, eroding solvency margin
Credit RiskRisk that counterparties fail to meet their obligationsReinsurer defaulting on a large claim; bond issuer in the investment portfolio defaulting
Operational RiskRisk of loss from inadequate or failed internal processes, people, systems, or external eventsFraud by an employee; system outage during peak renewal season; data entry error causing incorrect policy issuance
Liquidity RiskRisk that the insurer cannot meet its payment obligations as they fall dueSurge in claims after a catastrophe requiring rapid cash outflows while investments are illiquid
Strategic RiskRisk arising from adverse business decisions or failure to adapt to changes in the business environmentInvesting heavily in agency distribution while the market shifts to digital; failing to develop cyber insurance capability as demand surges

7.3 ERM Maturity in Indian Insurance

The maturity of risk management varies significantly across the Indian insurance industry. Large private-sector insurers and multinational joint ventures typically have sophisticated ERM frameworks with dedicated risk teams, quantitative risk models, and quarterly board-level risk reviews. Smaller players and some public-sector insurers are still building toward this standard — their risk management tends to be more compliance-driven (meeting regulatory minimums) than strategic (using risk insight to drive business decisions).

For InsurTech startups, understanding this framework is critical. When an InsurTech sells software or services to an insurer, the insurer's CRO will evaluate it through the lens of these six risk categories. A tool that reduces underwriting risk (better pricing) will get a different reception than one that introduces new operational risk (dependency on an unproven vendor).

🌎
Real World: The 2023 IRDAI guidelines on Operational Risk Management were a direct response to the increasing digitization of insurance operations. As insurers moved to cloud-based core systems, API-driven distribution, and AI-based claims processing, the operational risk profile shifted from "people making errors with paper forms" to "APIs failing, cloud services going down, and AI models producing biased outputs." The regulatory framework is evolving to keep pace with the technology — and risk managers are on the front line of that evolution.

📜 Exercise 7.1 — Categorise the Risk (IRDAI Framework)

IRDAI's Enterprise Risk Management framework defines 6 risk categories: Underwriting, Market, Credit, Operational, Liquidity, and Strategic. For each scenario below, identify which category it belongs to and explain your choice in one sentence.

#ScenarioRisk Category
1The stock market drops 20%, causing an insurer's equity-heavy investment portfolio to lose ₹50 crore in value.
2An international reinsurer delays payment of a ₹100 crore claim by 7 months, citing documentation issues.
3Motor third-party claims in the industry pool are running 25% higher than the premiums collected through the pool.
4A critical system outage during the peak renewal season (March) prevents policy issuance for 48 hours.
5A major cyclone in Gujarat triggers 5,000+ claims simultaneously — the insurer needs ₹300 crore in cash within 30 days, but most investments are in 5-year government bonds.
6The insurer invested ₹50 crore in building an agent distribution network just as the market shifted to digital — market share among young customers dropped 15%.
Check Your Categorisation
#CategoryWhy?
1Market RiskLosses from changes in market prices (equity decline). This is a standard market risk exposure in the investment portfolio — not related to insurance operations.
2Credit RiskRisk that a counterparty (reinsurer) fails to meet its obligations. Credit risk is not just about bond defaults — it includes any counterparty who owes the insurer money and may not pay.
3Underwriting RiskThe premiums collected are insufficient to cover claims. This is the classic underwriting risk — pricing inadequacy in the core insurance business.
4Operational RiskLoss from failed internal processes, systems, or external events — a system outage during renewal season is a pure operational risk event.
5Liquidity RiskThe insurer cannot meet payment obligations as they fall due because its assets are locked in illiquid investments. This is a liquidity crisis — the insurer has enough money overall (the bonds will mature) but does not have it available when needed.
6Strategic RiskRisk from adverse business decisions — investing in a distribution model that was becoming obsolete. Strategic risk is the hardest to identify because it looks like a "good idea" at the time.

Bonus question: Some scenarios could fit multiple categories. For example, #5 (cyclone liquidity) has elements of Underwriting Risk (the claims event) and Operational Risk (the system capacity to process 5,000 claims). The primary classification depends on which aspect is most material. In this case, the inability to pay (liquidity) is the dominant risk — if that is resolved, the claims processing is manageable.

Hands-On Project: Build a Risk Register for a General Insurance Company

You are the newly appointed Chief Risk Officer of "SecureSure General Insurance," a mid-size Indian general insurer with ₹5,000 crore in annual gross written premium. The company sells motor, health, property, crop, and liability insurance across 15 states. The CEO has asked you to prepare the company's first comprehensive risk register. Use Excel to build a professional risk register with at least 10 risks spanning all six IRDAI risk categories.

📁 Companion Workbook: Risk_Management_Fundamentals_CORRECTED.xlsx

This session is supported by a pre-built Excel workbook with 5 tabs. Use it as your reference solution and as a hands-on exercise file. Each tab maps to a specific part of this session. Open it in Excel (columns Q–T populate automatically with formulas).

⬇ Download the Workbook (.xlsx, 18 KB)

TabWhat It ContainsHow to Use ItMaps To
1. Risk Register The completed solution: 12 risks across all IRDAI categories (Underwriting ×3, Operational ×3, Market, Strategic ×2, Credit, Compliance, Liquidity). Contains formulas (=D×E, =I×J), four-level conditional formatting (Red ≥17, Orange 10–16, Amber 5–9, Green <5), and auto-calculating helper columns Q–T (Risk Level, Action Status, Days to Review, Overdue?). Use as the model answer for your Hands-On Project. Study how each risk is scored, mitigated, and tracked before building your own. Sections 6.1–6.3 & Hands-On Project
2. Exercise 6.1 A deliberately flawed one-row risk register containing 5 errors (wrong Inherent score, Residual = Inherent despite controls, status timing mismatch, missing Review Date, generic owner). Answer Key is in rows 7–13. Find the 5 mistakes before checking the Answer Key — then verify. Reinforces what a well-built register must contain. Exercise 6.1 in Section 6
3. Exercise 6.2 A quick scoring drill: 4 scenarios with blank Likelihood / Impact / Score / Level columns for you to fill, plus an Answer Key column (rows 5–8). Fill in your scores for each scenario, then compare with the Answer Key. Practises applying the L×I matrix and the four-level scale. Exercise 6.2 in Section 6
4. Reference The IRDAI six-category risk framework with a one-line definition of each category (Underwriting, Market, Credit, Operational, Liquidity, Strategic). A quick lookup while classifying your risks. Use it to make sure every risk in your register is placed in the correct category. Section 7 & Exercise 7.1
5. Executive Summary The completed management summary: top 3 critical risks (RISK-001, RISK-003, RISK-009) with drivers and mitigation, resource requirements (₹15–20 Cr technology, 25–30 hires, ₹5–8 Cr operational budget), and governance cadence. Use as the model answer for Hands-On Project Step 7. Note how it quantifies impact and names owners and timelines. Hands-On Project Step 7

Note: The workbook is a companion to this session — build your own register from scratch for the assignment, using this file only as reference. When you update the register, the Q–T helper columns recalculate automatically; conditional formatting is already applied to columns F and K.

Steps

  1. Identify 10+ risks: Create at least two risks from each of the following categories: underwriting, operational, and strategic. Create at least one risk from each of: market, credit, and liquidity. Write clear, specific risk descriptions.
  2. Build the register structure: Set up columns A through P as specified in Section 6.1. Freeze the header row. Format the Risk ID column to auto-generate (RISK-001, RISK-002...).
  3. Score each risk: For each risk, assign Likelihood (1–5), Impact (1–5), Existing Controls, Control Effectiveness (1–3), Residual Likelihood, and Residual Impact. Use the formula =InherentLikelihood × InherentImpact for the Inherent Risk Score, and =ResidualLikelihood × ResidualImpact for the Residual Risk Score.
  4. Select mitigation strategies: For each risk, choose a primary strategy from the Five Ts. For risks where you choose "Treat," specify at least one additional action. Assign a Risk Owner (use job titles — Chief Underwriting Officer, CIO, CFO, Head of Claims, etc.).
  5. Apply conditional formatting: Apply the four-level heat map to the Residual Risk Score column — Red (≥17), Orange (10–16), Amber (5–9), Green (<5) — as shown in Section 6.3. Then add the Risk Level (Q), Action Status (R), Days to Review (S), and Overdue? (T) helper columns using the formulas in Section 6.2.
  6. Add review tracking: Add a "Next Review Date" column and a "Days Until Review" column with the formula =ReviewDate-TODAY(). Apply conditional formatting to highlight overdue reviews in red.
  7. Write a summary: In a separate sheet or section below the register, write a 200-word Executive Summary identifying the top 3 risks, the chosen mitigation approach, and any resource requirements (budget, headcount, technology) needed to implement the risk management plan.
View Solution / Walkthrough

Example Risk Register — SecureSure General Insurance

Here are 12 sample risks you might include. The scores and details would be in your Excel file — this table shows the thinking behind each risk.

IDCategoryRisk DescriptionInherent LInherent IStrategyKey Control / Action
RISK-001 Underwriting Motor third-party pool losses exceed pricing assumptions by >20% due to regulatory pricing constraints and claims inflation 45 Treat + Transfer Advanced pricing analytics; excess-of-loss reinsurance for motor TP
RISK-002 Underwriting Climate change causes property insurance claims in coastal states to double over 5 years, making the property portfolio unprofitable 44 Treat + Terminate Dynamic risk-based pricing with climate risk factor; exit high-risk flood zones
RISK-003 Underwriting Health insurance claims ratio exceeds 95% due to medical inflation (15% pa) and provider fraud 53 Treat AI-based fraud detection; preferred provider network with negotiated rates; co-payment for non-network hospitals
RISK-004 Operational Core policy administration system experiences outage lasting >24 hours during renewal season, causing customer dissatisfaction and regulatory scrutiny 24 Treat Cloud migration with auto-failover; disaster recovery testing every 6 months; manual workaround SOP documented
RISK-005 Operational Employee in claims department colludes with a garage network to approve inflated motor repair bills, causing ₹5+ crore in annual claims leakage 33 Treat Mandatory job rotation in claims; AI anomaly detection on repair costs by garage; anonymous whistleblower hotline
RISK-006 Operational Data entry error in policy issuance system results in 5,000 policies being issued with incorrect sum assured, creating a ₹50 crore gap between premium collected and risk covered 25 Treat Automated validation rules in policy admin system; daily exception report; maker-checker control for policies above ₹1 crore sum assured
RISK-007 Market RBI raises interest rates by 200 bps, causing the insurer's government bond portfolio (60% of investments) to lose 8–10% in market value 34 Treat + Tolerate Reduce portfolio duration from 8 years to 5 years; increase allocation to floating-rate bonds; hold 20% in held-to-maturity
RISK-008 Credit Reinsurer (international, A-rated) downgraded to BBB and subsequently delays/contests a ₹200 crore claim payment after a major cyclone 25 Transfer (diversify) + Treat Diversify reinsurance panel (no single reinsurer >30% of program); include cut-through clauses; maintain letter of credit from reinsurer
RISK-009 Liquidity Major cyclone in Gujarat causes 2,000+ claims within 72 hours requiring ₹300 crore in claim payments within 30 days, while bond portfolio is temporarily illiquid 34 Treat Maintain ₹100 crore liquid buffer (overnight funds, liquid mutual funds); committed credit line of ₹200 crore from consortium of banks
RISK-010 Strategic Digital-first competitors (Acko, Digit) capture 15% market share in motor insurance within 3 years by offering 20% lower premiums, eroding SecureSure's largest line of business 54 Treat + Take Advantage Launch digital direct-to-consumer channel; partner with 3 e-commerce platforms for embedded insurance; invest in telematics-based UBI product
RISK-011 Strategic IRDAI introduces new rural/social sector obligations requiring 10% of GWP from rural areas, which SecureSure lacks the distribution network to achieve 33 Treat Partner with regional rural banks and cooperative societies for distribution; develop micro-insurance products for rural markets
RISK-012 Strategic DPDP Act enforcement results in ₹100 crore penalty because customer data used for AI underwriting model training was obtained without explicit consent 25 Treat Conduct data audit; obtain retrospective consent from existing customers; implement consent management platform; establish AI ethics committee

Executive Summary (Sample)

The risk assessment for SecureSure General Insurance identifies three critical risks requiring immediate board attention. First, motor third-party underwriting risk (RISK-001, Residual Score: 16) — persistent pricing inadequacy combined with regulatory constraints demands a dual response: deploy advanced pricing analytics to improve risk selection within regulatory limits, and purchase additional excess-of-loss reinsurance to cap downside exposure at ₹75 crore. Second, strategic disruption risk from digital competitors (RISK-010, Residual Score: 15) — the 3-year trajectory shows market share erosion accelerating. We recommend a ₹45 crore investment over 18 months to build a digital direct channel (₹25 crore), establish embedded insurance partnerships with 3 e-commerce platforms (₹12 crore), and launch a telematics-based UBI pilot for private cars (₹8 crore). Third, the DPDP Act compliance risk (RISK-012, Residual Score: 12) — while assessed as lower likelihood, the potential penalty magnitude makes this a board-level concern. We recommend a 90-day data audit and consent management implementation at an estimated cost of ₹3 crore. Total incremental resource requirement: ₹48 crore capital allocation and 12 new hires (data science, digital product, compliance).

3-2-1 Reflection — Before You Move On

Retrieval practice strengthens long-term memory. Before moving to Session 03, take 3 minutes to write down what you have learned.

3 Things I Learned Today

2 Real Risks I Can Now Identify

1 Question I Still Have About Risk Management

Key Takeaways

1

Pure risk (loss or no loss) is insurable. Speculative risk (loss, no loss, or gain) is not. This single distinction defines the boundary of the entire insurance industry.

2

Risk management is a continuous five-step cycle — Identify → Assess → Mitigate → Implement → Monitor — not a one-time exercise. The most common failure is neglecting step five.

3

The Five Ts — Transfer, Tolerate, Treat, Terminate, Take Advantage — are the complete strategic toolkit. Most significant risks require a combination of strategies, not just one.

4

A well-built risk register with formulas, conditional formatting, and review tracking transforms risk management from a compliance exercise into a strategic decision-making tool.

5

Indian insurers operate within IRDAI's six-category risk framework (underwriting, market, credit, operational, liquidity, strategic). Every InsurTech selling into insurers must understand how its product affects each category.

Test Your Understanding

1. A company investing in the stock market faces which type of risk?

2. Which is the correct sequence of the five-step risk management process?

3. An insurer purchasing catastrophe reinsurance to protect against cyclone losses is applying which of the Five Ts?

4. In a likelihood × impact risk matrix, a risk scored Likelihood=4 (Likely, 20–50% annual probability) and Impact=4 (Major, ₹10–₹100 crore impact) has a risk score of 16. This risk should be classified as:

5. Which of the following must a professional risk register contain?