This article is part of a five-part series, which explores the practical challenges firms face in strengthening risk frameworks, evidencing control effectiveness and meeting increasing regulatory expectations. Building on our introductory article, Is your firm ready for the new era of risk management?, each article examines a key part of the risk management lifecycle, providing insights to help firms identify gaps, enhance oversight and demonstrate that their frameworks work effectively in practice.
Risk identification is the foundation of effective risk management because every subsequent risk activity depends on having a clear understanding of what could go wrong, what could go right, and what could affect the achievement of objectives.
Firms operate in increasingly complex environments defined by regulatory change, economic uncertainty, technological advancements and disruption, and evolving customer expectations; therefore, risk identification is a key step to ensure the firm is operating in the most effective way.
While risk taxonomies can vary through the industry, the core methodologies used to identify and assess risks remain largely consistent. The key challenge for firms is not to simply identify risks but to determine their relevance and impact.
This article explores how firms should tackle this challenge.
Understanding the firm's objectives and business model
Risk identification should begin with an understanding of the firm's strategic objectives. The risks a firm will face are inherently linked to its ability to achieve its goals.
The key matters to consider are:
- Business activities and products
- Revenue streams
- Customer segments
- Operational footprint
- Regulatory obligations
- Technology, data and third-party
Any “copy and paste” approach when it comes to risks inevitably ends up costing the firm, as the same risk may have vastly different implications for different firms. A precise view and understanding of the business model will provide the context needed to identify material risks. Similarly, the description of the risk is important to ensure the risk is understandable and relevant to the firm. This helps distinguish the risk from its causes, consequences and control weaknesses.
Risk taxonomies for structure
Firms commonly use risk taxonomies to organise risk identification activities, with them typically covering at a top level:
- Strategic risk
- Operational risk
- Financial risk
- Regulatory and Legal risk
These taxonomies provide a platform for a systematic and consistent approach, allowing individuals in the firm to focus on risk areas which they can provide the most insight into, which in turn reduces the likelihood of important risks being overlooked.
However, a taxonomy should support discussion rather than become a checklist. Risks often cut across several categories and may have operational, financial, regulatory and customer impacts.
Risk identification methodologies
Workshops and subject matter expert engagement
- Cross-functional workshops remain one of the most widely used approaches.
- These draw insights from business leaders, risk specialists and operational teams to help surface risks that may not be captured solely through quantitative data. Including different roles and perspectives helps challenge existing assumptions and avoids simply confirming risks already recognised by management.
Process and control reviews
- Examining critical business processes will help to identify points of failure, error, or disruption that could occur.
- Firms should assess existing controls and potential vulnerabilities.
Scenario analysis
- Exploring plausible future events and stresses, based on internal and external drivers.
- This is particularly useful for emerging and interconnected risks.
Data and incident analysis
- Reviewing historical incidents, losses, near misses, and control failures allows the firm to identify trends and recurring themes.
- This provides evidence-based insights into risk exposure.
Horizon scanning
- Firms should monitor external developments such as regulatory change, market conditions, technological innovation, and geopolitical events.
- This enables identification of emerging risks before they materialise.
Assessing relevance and materiality
It is important to understand that not every identified risk warrants the same level of attention. Firms need to assess:
- Likelihood
- Potential impact (including speed and duration)
- Sources (where the risk may come from)
- Potential customer, market or firm harm
- Connections with other risks
There should be a consideration of both direct and indirect impacts, with materiality assessment helping prioritise management focus and resources.
Referencing historical regulatory fines and media articles will allow a firm to get a sense of likely impact.
Once risk relevance and materiality are determined, firms should consider assigning a risk owner to monitor and manage the risk going forward to ensure the appropriate attention is given.
Applying risks to the firm
All risks should be translated into the firm's specific context; otherwise, they become generic and lack meaning for a firm to truly understand them.
The key questions include:
- How could this risk affect our customers?
- How could it affect financial performance?
- What impact could it have on operations?
- Could it impact regulatory compliance?
- Would it affect strategic objectives?
- Does it arise from reliance on a particular person, supplier, system or revenue stream?
- What would the firm need to do if the risk materialised?
Risks should be linked and traceable to business processes, products, and decision-making. It is easy to describe a risk too generically, as well as describing it too specifically. It is important to ensure risks are described clearly, ownership for each material risk is defined, and findings are incorporated into governance, controls, monitoring, and reporting.
Dynamic risk identification
Risk identification should not be treated as an annual exercise as risk profiles evolve with changes to businesses, markets, and regulations.
Firms should continuously review:
- Strategic changes
- New products and services
- Technology implementations
- Regulatory developments
- External market events
- Significant incidents, acquisitions and material outsourcing arrangements
A dynamic approach allows the firm to improve resilience and decision-making, as well as providing for itself the opportunity to benefit from some of those risks as they emerge. Firms may identify opportunities for structural changes and process improvements.
Key takeaways
Effective risk identification utilises structured frameworks, expert judgement, historical analysis, ownership and forward-looking assessments. Firms should be challenging themselves at all levels to consider risks. The objective is not to identify every conceivable risk, but to understand the risks most relevant to the organisation.
Firms that successfully align risk identification to their business model and strategic objectives are better positioned to make informed decisions, allocate resources effectively, respond to an evolving environment, and put themselves in the best position possible. Additionally, a well-understood risk taxonomy will result in a better-performing control environment, which will contribute to the firm’s success in achieving objectives.
The test is not how many risks have been recorded, but whether the firm has identified the exposures that could materially affect its objectives, customers and regulatory obligations.
The value of risk identification lies in its practical application to how a firm operates and succeeds.
About the author
Paul Cowland is a managing consultant at Ocorian, advising and supporting asset managers and financial advisers. He has extensive experience across wealth management, capital markets, corporate finance and fund management, providing internal audit and compliance support to small and large firms across diverse asset classes. Having previously held SMF16 and SMF17 responsibilities, Paul brings practical regulatory expertise and first-hand insight into compliance challenges facing firms.