Welcome to Section A: Sources of Risk!
Hello there! Welcome to one of the most important parts of your P3 journey. Before we can manage risk, we first need to figure out where it comes from. Think of this chapter as a "detective mission." We are looking for the "sources"—the root causes or environments—that could lead to something going wrong (or even something going unexpectedly well!).
Don't worry if this seems like a lot to take in at first. Risk management isn't just about spreadsheets; it’s about understanding the world around a business. By the end of these notes, you'll be able to spot risks like a pro. Let’s dive in!
1. Understanding the Two Big Buckets: Internal vs. External
To make things simple, CIMA divides the sources of risk into two main categories: things happening outside the company and things happening inside the company.
External Sources of Risk
External risks come from the outside world. The company usually has very little control over these, but they must react to them. A classic way to remember these is the PESTEL framework. If you’ve seen this in earlier studies, don’t skip it! It is the backbone of external risk analysis in P3.
P – Political: Changes in government policy, trade barriers, or political instability.
Example: A sudden change in tax laws that makes your product more expensive for customers.
E – Economic: Fluctuations in interest rates, inflation, or exchange rates.
Example: If the currency weakens, importing raw materials becomes more expensive.
S – Social: Changes in consumer tastes, demographics, or lifestyle trends.
Example: A sudden shift where people stop buying plastic bottles for environmental reasons.
T – Technological: New inventions or "disruptive" tech that makes your business model obsolete.
Example: Digital streaming services making physical DVD stores unnecessary.
E – Environmental (or Ecological): Climate change, natural disasters, or "green" regulations.
Example: A flood that shuts down a factory for three months.
L – Legal: New laws regarding employment, health and safety, or data protection.
Example: The introduction of strict GDPR rules affecting how you store customer data.
Internal Sources of Risk
Internal risks are the "own goals" of the business world. These come from within the organization, meaning the management usually has more power to control or prevent them.
1. Operations: Failures in day-to-day processes.
Example: A machine breaking down or an error in the production line.
2. People: Risks related to employees, such as strikes, loss of key staff, or even fraud.
Example: Your lead software developer leaves to join a competitor, taking their knowledge with them.
3. Systems: IT failures, cybersecurity breaches, or outdated software.
Example: A hacker stealing customer credit card details from your website.
4. Governance: Poor decision-making at the top level or a lack of ethical "tone at the top."
Example: The Board of Directors taking on too much debt without a clear plan.
Quick Review: Key Takeaway
External risks are outside your control (PESTEL), while Internal risks come from your own people, processes, and systems. Management's job is to monitor the external and control the internal.
2. Strategic vs. Operational Risk
In P3, we often distinguish between Strategic and Operational risks. This is a very common exam area!
Strategic Risk
These are "big picture" risks. They relate to the long-term goals of the company. If a strategic risk goes wrong, the whole company might fail.
Common sources: Poor choice of target market, failing to respond to a competitor's move, or a failed merger/acquisition.
Analogy: Imagine you are the captain of a ship. Strategic risk is choosing the wrong destination (e.g., sailing toward a storm because you thought it was a shortcut).
Operational Risk
These are the risks that happen during the execution of the strategy. They are the "nuts and bolts" of the business.
Common sources: Human error, system bugs, or supply chain interruptions.
Analogy: Back on the ship, operational risk is the engine breaking down or a sailor dropping the map overboard. You’re heading to the right place, but the "how" is failing.
Did you know? Most business failures are actually a mix of both. A small operational failure (like a data leak) can lead to a massive strategic failure (loss of brand reputation).
3. Financial Sources of Risk
Financial risk is a specific category that deals with the money flowing in and out of the business. Even if you aren't an "accounting person," these are easy to grasp when you think of them as "money hurdles."
Credit Risk: The risk that a customer won't pay you what they owe.
Liquidity Risk: The risk that you won't have enough cash to pay your bills on time (even if you have "profit" on paper!).
Market Risk: The risk that prices in the market change (like interest rates or share prices) in a way that hurts your business.
Currency Risk: The risk that exchange rates change. If you sell in Dollars but pay your workers in Euros, a shift in the rate can eat your profit.
Memory Aid: The "Four C's" of Financial Risk
While not an official CIMA list, many students find it helpful to remember financial sources as: Cash (Liquidity), Customers (Credit), Currency (Exchange rates), and Cost of borrowing (Interest rates).
4. Hazard Risks
A Hazard Risk is often called a "pure risk." This means there is only a downside. There is no "upside" to a factory fire or an employee getting injured.
Most other risks (like Strategic risks) have an upside—for example, taking a risk on a new product might lead to huge profits. But with Hazard risks, we simply want to minimize the chance of them happening or insure against them.
5. Common Mistakes to Avoid
Mistake 1: Confusing a "Risk" with its "Source."
The Source is the "why" (e.g., a heavy rainstorm). The Risk is the "what" (e.g., the warehouse flooding). In the exam, make sure you identify the origin of the problem.
Mistake 2: Thinking all risk is bad.
In CIMA P3, remember that "risk" is simply uncertainty. Some sources of risk can lead to Upside Risk (opportunities). For example, a new technology (External Source) is a risk to your old product, but an opportunity for you to innovate first.
Summary and Key Takeaways
To master the sources of risk, remember these three points:
1. Look Outside: Use PESTEL to identify environmental, political, and economic factors.
2. Look Inside: Check Operations, People, and Systems for internal weaknesses.
3. Categorize: Is the risk Strategic (long-term goals), Operational (day-to-day), Financial (money-related), or a Hazard (pure downside)?
Quick Review Box:
- External = PESTEL (Macro environment)
- Internal = Processes, People, Systems (Micro environment)
- Strategic = Doing the wrong things
- Operational = Doing things the wrong way
Great job! You've just covered the fundamentals of where risk comes from. Next time you read a business news story, try to spot the source of risk—is it a Political change? A Technological shift? Or an Internal operational failure? Practice makes perfect!