Updated for the 2026-2027 CFA® Level I curriculum.
Risk management is the process an organization uses to identify, measure, and control the risks that could keep it from meeting its objectives.
CFA Level I treats this as a structured, repeatable cycle rather than a single control or decision. Exam questions typically describe an action taken by a company or investor and ask you to classify it within the framework, or to spot which stage of the cycle is missing. Knowing the full sequence, from governance through monitoring, is what separates a quick guess from a confident answer.
Quick Answer
Risk management is the structured process of identifying, measuring, and addressing the risks that threaten an organization's objectives. A risk management framework organizes this process into repeatable stages: governance, identification, measurement, modification, and monitoring and communication.
CFA Level I questions test whether you can place a described action into the correct stage and recognize that the goal is to manage risk to an acceptable level, not to remove it entirely.
Key Takeaways About Risk Management and the Risk Management Framework
Risk management is a continuous cycle. It does not end once risks are identified or measured.
A complete framework has five core components: governance, identification, measurement, modification, and monitoring and communication.
Risk governance comes first. It sets objectives and oversight before any risk is measured or modified.
An effective framework covers financial risks (market, credit, liquidity) and non-financial risks (operational, legal, reputational).
Risk modification includes four methods: avoidance, prevention/reduction, transfer, and retention.
CFA Level I often tests classification: given an action, identify which stage of the framework it represents.
What You Need to Know for CFA Level I
Define risk management and explain its purpose: reducing risk to a level consistent with the organization's objectives and risk tolerance, not eliminating it.
Explain the role of risk governance in setting objectives, risk tolerance, and oversight responsibility.
Distinguish risk identification (finding exposures) from risk measurement (quantifying their size and likelihood).
Recognize the four risk modification methods and match each to a short scenario.
Understand monitoring and communication as the feedback loop that updates the framework over time.
Know what makes a framework "complete" so you can spot a missing element in an exam vignette.
What Is Risk Management?
Risk management is the process of identifying the risks an organization faces, measuring their potential impact, and deciding how to respond to them. The goal is not to avoid every risk. Most organizations need to take on some risk to generate returns or achieve their mission. A pension fund cannot meet its obligations by holding only cash, and a company cannot grow without taking on operational and financial risk.
Instead, the purpose of risk management is to keep risk exposure aligned with what the organization is willing and able to bear. This is why risk management in finance is described as an ongoing discipline. Objectives change, markets shift, and new risks appear. A framework that worked two years ago may miss a risk that matters today.
The Risk Management Framework
A risk management framework is the structure that turns risk management from a vague intention into a repeatable process. The 2026 curriculum describes five connected components: governance, identification, measurement, modification, and monitoring and communication. Each component depends on the one before it. Skipping a step, especially governance, weakens the entire process.
Risk Governance
Risk governance is the foundation of the framework. It sets the organization's risk objectives, defines risk tolerance, and assigns responsibility for oversight. Governance answers questions like: What level of risk can we accept? Who approves risk-taking decisions? How often is risk reviewed?
Without this step, identification and measurement have no context. A measured risk exposure is meaningless if no one has defined what an acceptable exposure looks like.
Risk Identification
Risk identification is the process of finding and cataloging the risks an organization faces. This includes financial risks, such as market, credit, and liquidity risk, and non-financial risks, such as operational, legal, model, tail, and reputational risk. A common exam trap is assuming risk identification covers only financial risk. It does not. A complete framework identifies any risk that could affect the organization's ability to meet its objectives.
Risk Measurement
Risk measurement quantifies the risks that identification uncovers. This step estimates the likely size, frequency, or severity of a risk. Measurement can be quantitative (value at risk, standard deviation, duration) or qualitative when a risk is hard to quantify precisely, such as reputational damage. Measurement without prior identification is incomplete, because an organization cannot measure a risk it has not recognized.
Risk Modification
Once risks are identified and measured, the organization decides how to respond. Risk modification includes four methods.
Method | Definition | Example |
|---|---|---|
Avoidance | Choosing not to engage in the activity that creates the risk | A firm declines to enter a market with unstable currency controls |
Prevention/Reduction | Taking action to lower the probability or impact of a risk | A company installs backup servers to reduce operational risk |
Transfer | Shifting the risk to another party, often for a fee | Buying insurance or using a derivative to hedge exposure |
Retention | Accepting the risk because it is within tolerance or too costly to modify | Self-insuring against a small, infrequent loss |
Exam questions often present a scenario and ask which modification method applies. The key distinction is whether the organization changes its exposure (avoidance, prevention), shifts it to someone else (transfer), or keeps it (retention).
Monitoring and Communication
The final component is monitoring and communication. This step tracks whether risk exposures stay within tolerance and reports results to governance. Monitoring closes the loop: it feeds new information back into governance, which may adjust objectives, and the cycle continues. A framework without monitoring becomes outdated as soon as market conditions change.
Features of an Effective Risk Management Framework
A framework is considered complete when it includes all five components working together, not in isolation. Effective frameworks share these features:
Clear ownership of risk oversight, usually starting with a board or risk committee.
Defined risk tolerance that connects to the organization's objectives.
A process for identifying both financial and non-financial risks.
Measurement methods appropriate to the type of risk.
A documented set of modification choices tied to measured exposures.
Regular monitoring with reporting back to governance.
If any one of these is missing, the framework is incomplete, even if the remaining pieces are well designed.
Worked Example
Scenario: Meridian Foundation, an endowment fund, asks its investment committee to review its risk process. The committee reports the following:
The fund has identified market risk, credit risk, and reputational risk from its holdings.
It calculates the standard deviation and value at risk for its portfolio each quarter.
It uses derivatives to hedge part of its currency exposure and retains the rest.
Step 1: Check for governance. The fund has not stated a risk tolerance or assigned oversight responsibility. No committee objective or approval process is mentioned.
Step 2: Check for identification. Confirmed. The fund identifies both financial risk (market, credit) and non-financial risk (reputational).
Step 3: Check for measurement. Confirmed. The fund quantifies risk using standard deviation and value at risk.
Step 4: Check for modification. Confirmed. The fund uses transfer (derivatives) and retention (unhedged portion).
Step 5: Check for monitoring and communication. Not mentioned. There is no indication results are reported back to a governing body.
Plain-English interpretation: Meridian's process is missing governance and monitoring. Without governance, the fund has no defined tolerance to measure against. Without monitoring, it cannot confirm the framework still fits changing conditions. The framework is incomplete despite strong identification, measurement, and modification steps.
Common Exam Traps
Treating risk management as risk elimination
Candidates sometimes assume the goal is to remove all risk. The actual goal is managing risk to an acceptable level based on stated objectives and tolerance.
Starting with measurement before governance and objectives
A vignette may describe measurement activity first. Without governance defining tolerance, that measurement has no benchmark for "acceptable."
Ignoring non-financial risk
Exam questions test whether candidates limit risk identification to market, credit, and liquidity risk. Operational, legal, and reputational risks belong in a complete framework.
Viewing the framework as a one-time exercise
A framework set up once and never revisited fails the monitoring and communication requirement, even if the other four components were done well initially.
Practice Question
A mid-sized insurance company's risk committee has set a formal risk tolerance statement and appointed a chief risk officer to oversee compliance. The company has not yet cataloged the specific risks affecting its investment portfolio or operations.
Which stage of the risk management framework does the company need to complete next?
Risk identification
Risk measurement
Risk modification
Correct Answer: A
Explanation: The company has completed risk governance by setting tolerance and assigning oversight. The next step in the framework is risk identification, cataloging the specific risks the company faces. Measurement and modification cannot occur until the risks are identified.
Option B: Risk measurement is incorrect because quantifying risk requires first knowing which risks to measure. Measurement follows identification, not governance.
Option C: Risk modification is incorrect for the same reason. An organization cannot choose to avoid, transfer, retain, or reduce a risk it has not yet identified.
Continue Your CFA Level I Prep With KeyPoint
Use structured lessons, practice questions, mock exams, and progress tracking to focus on the time you have left
FAQs About Risk Management and the Risk Management Framework
What is risk management?
Risk management is the process of identifying, measuring, and responding to risks that could prevent an organization from meeting its objectives. It is an ongoing cycle, not a single decision.
What are the components of a risk management framework?
A complete framework includes risk governance, risk identification, risk measurement, risk modification, and monitoring and communication. Each stage depends on the one before it.
Is risk management the same as risk elimination?
No. Risk management aims to keep risk exposure within an acceptable range based on the organization's objectives and tolerance. Eliminating all risk is neither possible nor desirable for most organizations.