Updated for the 2026-2027 CFA® Level I curriculum.
Every portfolio and every organization faces two broad categories of risk: financial and non-financial. Financial risks come from market prices, credit exposures, and liquidity conditions. Non-financial risks come from people, processes, systems, and the external environment.
CFA Level I tests whether you can classify portfolio risks correctly and explain how these two categories interact, because a single event often triggers both.
Quick Answer
Financial sources of risk include market, credit, liquidity, and model risk. These affect portfolio value directly through prices, defaults, or funding conditions. Non-financial sources of risk include operational, legal, regulatory, cyber, geopolitical, and ESG-related risk. These originate outside financial markets but still produce financial losses.
CFA Level I exam questions typically test whether you can identify the correct risk source and recognize how one risk type triggers another.
Key Takeaways About Financial and Non-Financial Sources of Risk
Financial risks (market, credit, liquidity, model) arise directly from financial variables like prices, rates, and counterparty behavior.
Non-financial risks (operational, legal, regulatory, cyber, geopolitical, ESG) originate outside markets but still create financial consequences.
Liquidity risk has two forms: market liquidity risk and funding liquidity risk. It is not purely a market risk.
Risk sources rarely act alone. One risk event often cascades into a second risk type.
Concentration in a single asset, counterparty, or process magnifies the impact of any risk source.
Risk identification relies on checklists, scenario analysis, stress testing, and key risk indicators, not just historical loss data.
What You Need to Know for CFA Level I
Distinguish financial risk (market, credit, liquidity, model) from non-financial risk (operational, legal, regulatory, cyber, geopolitical, ESG).
Know that funding liquidity risk and market liquidity risk are both forms of liquidity risk.
Recognize that non-financial risks produce measurable financial losses even though their source is not a market variable.
Understand common interaction patterns: operational failures triggering liquidity problems, geopolitical events triggering market and credit risk together.
Identify concentration risk as an amplifier, not a separate risk category.
Know basic risk identification tools: checklists, scenario analysis, stress testing, and loss event tracking.
What Are Financial and Non-Financial Sources of Risk?
Risk identification is the first step in the risk management process. Before a firm can measure or modify risk, it has to know where risk originates. The curriculum splits risk sources into two groups.
Financial risks come from movements in financial variables: prices, interest rates, exchange rates, credit spreads, and funding availability. These risks show up directly on a balance sheet or in portfolio value.
Non-financial risks come from operations, legal exposure, regulation, technology, politics, and environmental or social factors. These risks do not start as a price movement, but they still end up as one. A cyberattack is not a market event, but it can force a fire sale that creates a market loss.
The exam expects you to place a described event into the correct category and to understand that non-financial risks are not "soft" risks. They carry real financial consequences.
Financial Sources of Risk: Market, Credit, Liquidity, and Model Risk
Financial risks arise directly from markets, counterparties, funding conditions, and the tools used to measure exposure. For CFA Level I, you should be able to distinguish each source and recognize how it can affect a portfolio or financial institution.
Market Risk
Market risk comes from changes in equity prices, interest rates, exchange rates, or commodity prices. It affects nearly every portfolio holding and is usually the risk candidates think of first.
Credit Risk
Credit risk is the risk that a borrower or counterparty fails to meet an obligation. It includes default risk and downgrade risk, where a credit rating cut increases the perceived chance of default even before an actual default occurs.
Liquidity Risk
Liquidity risk concerns the ability to trade assets or meet cash obligations without excessive cost.
Market liquidity risk is the risk that an asset cannot be sold quickly without a significant price concession. Funding liquidity risk is the risk that an entity cannot meet its cash obligations as they come due. CFA Level I questions may test whether you can distinguish between the two.
Model Risk
Model risk is the risk that a valuation or risk model produces an incorrect result because of flawed assumptions, coding errors, or use outside its intended purpose.
Model risk matters because firms rely on models to price assets and measure other risks. An error can therefore hide the true size of market, credit, or liquidity exposure.
Non-Financial Sources of Risk: Operational, Legal, Regulatory, Cyber, Geopolitical, and ESG Risk
Non-financial risks do not originate primarily from market prices or borrower defaults. They arise from areas such as business operations, laws, technology, political events, and environmental or governance factors.
Operational Risk
Operational risk comes from failed internal processes, people, or systems, or from external events that disrupt operations. Examples include settlement errors, fraud, and system outages.
Legal Risk
Legal risk is the risk that contracts are unenforceable or that litigation creates unexpected costs or restrictions on activity.
Regulatory Risk
Regulatory risk arises when changes in laws or regulations affect an organization, or when failure to comply with existing rules leads to fines, restrictions, or higher compliance costs.
Cyber Risk
Cyber risk is a specific form of operational risk tied to data breaches, system intrusions, and attacks on technology infrastructure.
It is often discussed separately because cyber events can disrupt trading, custody, reporting, and other critical functions at the same time.
Geopolitical Risk
Geopolitical risk comes from political events such as war, sanctions, trade restrictions, or changes in government policy. These events can affect multiple markets and asset classes at once.
ESG-Related Risk
ESG-related risk comes from environmental, social, and governance factors.
Examples include physical risks such as climate exposure, transition risks caused by shifts toward lower-carbon activity, and governance failures such as weak board oversight. ESG risks can become financial risks through reputational damage, regulatory penalties, higher costs, or lower asset values.
Financial vs. Non-Financial Risk Matrix
The table below separates the two categories and shows how a non-financial event still produces a financial consequence. Use it to check classification quickly during review.
Risk Source | Category | Example Trigger | Typical Financial Consequence |
|---|---|---|---|
Market risk | Financial | Interest rate spike | Portfolio value declines |
Credit risk | Financial | Counterparty downgrade | Higher default probability, spread widening |
Liquidity risk | Financial | Redemption surge or thin market | Forced asset sales at a discount |
Model risk | Financial | Flawed valuation assumption | Mispriced positions, hidden losses |
Operational risk | Non-financial | System outage during settlement | Failed trades, direct losses |
Legal risk | Non-financial | Unenforceable contract clause | Litigation cost, lost recovery |
Regulatory risk | Non-financial | New capital requirement | Higher compliance cost, forced deleveraging |
Cyber risk | Non-financial | Data breach on trading platform | Trading halt, reputational loss |
Geopolitical risk | Non-financial | Trade sanctions imposed | Market and credit risk rise together |
ESG risk | Non-financial | Climate-related asset damage | Asset write-down, higher insurance cost |
Non-financial risks are not smaller or less serious than financial risks. They simply start outside financial markets before producing a financial result.
How Risk Sources Interact
Risk sources rarely stay isolated. A single event often starts as one risk type and converts into another.
A cyberattack (operational/cyber risk) that disables a trading system during volatile markets prevents a firm from rebalancing. That failure leaves the firm exposed to market risk it can no longer manage, and if clients demand redemptions during the outage, it becomes a funding liquidity problem too.
A geopolitical shock, such as new sanctions, can hit market risk (asset prices fall) and credit risk (counterparties in the sanctioned region become more likely to default) at the same time.
Concentration makes these interactions worse. A firm with a concentrated position in one sector or one counterparty feels the full force of an interaction, while a diversified firm absorbs part of the shock. This is why concentration is treated as a risk amplifier rather than a standalone risk source.
How Analysts Identify Risk Sources
Firms use several methods to identify where risk originates before it becomes a loss:
Risk checklists and taxonomies that map known risk categories against business activities.
Scenario analysis that asks what happens to the portfolio or firm under a specific stress event.
Stress testing that applies extreme but plausible shocks to see which risk sources activate together.
Key risk indicators (KRIs) that track early warning signals, such as rising settlement failures or unusual system login patterns.
Loss event tracking that records past incidents to spot recurring weaknesses.
None of these tools work well in isolation. Level I expects you to know that identification is an ongoing process, not a one-time checklist exercise.
Worked Example: Larkspur Global Investors
Scenario. Larkspur Global Investors holds a large, concentrated position in emerging market sovereign bonds. Two events happen in the same week: government bond yields spike sharply (market stress), and a cyberattack disables Larkspur's order management system for two trading days.
Step 1: Identify the primary financial risk
The yield spike is market risk. Bond prices in the portfolio fall immediately.
Step 2: Identify the primary non-financial risk
The cyberattack is operational risk, specifically cyber risk. It is not caused by a market variable.
Step 3: Identify the interaction
Because the order management system is down, Larkspur cannot sell any bonds to reduce exposure during the price decline. The operational failure converts into an inability to manage market risk. If clients request redemptions during this window, Larkspur also faces funding liquidity risk, since it cannot generate cash by selling the now-falling bonds.
Step 4: Identify the concentration effect
Because the sovereign bond position is concentrated rather than diversified, the firm cannot offset the loss with gains elsewhere in the portfolio. The impact is larger than it would be for a diversified fund facing the same two events.
The cyberattack did not cause the market loss directly, but it prevented Larkspur from responding to one. A non-financial risk source removed the firm's ability to manage a financial risk, and concentration made the outcome worse. This is the kind of chain reasoning Level I questions test.
Common Exam Traps
Classifying every loss by outcome instead of source
A bond price decline is not automatically "market risk" if the real trigger was a credit downgrade. Trace the loss back to its origin before classifying it.
Ignoring interactions and feedback loops
Many exam scenarios describe a chain of events. Stopping at the first risk identified misses the secondary risk the question is actually testing.
Treating liquidity as only a market risk
Liquidity risk includes funding liquidity risk, which relates to cash obligations, not just the ability to sell an asset at a fair price.
Assuming non-financial risk cannot be quantified
Operational losses, regulatory fines, and cyber incident costs are measurable. Non-financial does not mean unquantifiable.
Practice Question
A hedge fund's prime broker reduces the fund's credit line after a rating agency downgrades the fund's largest counterparty. To meet the resulting margin call, the fund is forced to sell illiquid private debt holdings at a steep discount.
Which combination correctly identifies the primary and secondary risk sources in this scenario?
Primary: credit risk. Secondary: liquidity risk.
Primary: operational risk. Secondary: market risk.
Primary: liquidity risk. Secondary: credit risk.
Correct Answer: A
The downgrade and the resulting credit line reduction originate from credit risk. The forced sale of illiquid holdings at a discount is the secondary effect, which is liquidity risk (specifically, market liquidity risk combined with a funding liquidity trigger).
Option B: Nothing in the scenario describes a process failure, system error, or people-related breakdown, so operational risk does not apply. The price decline from a forced sale is a liquidity effect, not a standalone market risk event.
Option C: This reverses the sequence. Liquidity risk is the consequence here, not the original trigger. The rating downgrade and credit line cut happened first.
Continue Your CFA Level I Prep With KeyPoint
Use structured lessons, practice questions, mock exams, and progress tracking to focus on the time you have left
FAQs About Financial and Non-Financial Sources of Risk
Is liquidity risk a financial or non-financial risk?
Liquidity risk is a financial risk. It includes market liquidity risk, the risk of selling an asset at a discount, and funding liquidity risk, the risk of not meeting cash obligations.
Is ESG risk always non-financial?
ESG risk originates from non-financial factors like environmental impact or governance quality, but it produces financial consequences through asset write-downs, fines, or reputational damage. It is classified as non-financial by source, not by outcome.
Can operational risk cause a market loss?
Yes. An operational failure, such as a system outage, can prevent a firm from managing an existing market position, which turns an operational event into a realized market loss.