Diligent Logo
Diligent Logo
Products
arrow_drop_down
Solutions
arrow_drop_down
Resources
arrow_drop_down
Diligent AI

Financial risk management: how to measure and manage it

August 19, 2026
13 min read
Someone measuring risk

In this article

  • Intro
  • What is financial risk management?
  • Why measuring financial risk matters now
  • Types of financial risk
  • The financial risk management process
  • How to measure financial risk
  • Frameworks that structure measurement
  • Common challenges in measuring financial risk
  • How Diligent improves financial risk measurement
  • Frequently asked questions
The Diligent team

The Diligent team

GRC trends and insights

Financial risk management is the practice of identifying and controlling the risks that arise from an organization's activity in the financial markets: its debt, its cash position, its counterparties and its exposure to price movements. For CFOs and chief risk officers, the measurement half of that practice is where programs succeed or fail. A risk you cannot quantify is a risk you cannot prioritize or explain to the board.

Financial risk management has four main categories: market, credit, liquidity and operational risk. Effective programs pair a repeatable management process with quantitative measures such as standard deviation, beta, VaR and CVaR, then use qualitative methods and frameworks to put those measures in context.

This guide explains how to measure and manage financial risk across the enterprise, covering:

  • What financial risk management is and how it differs from investment risk management
  • Why measuring financial risk matters now, and what current risk data shows
  • The four types of financial risk: market, credit, liquidity and operational
  • The five-step financial risk management process, from identification through board reporting
  • How to measure financial risk using standard deviation, beta, VaR and CVaR, plus qualitative methods
  • How COSO and ISO 31000 structure measurement into a repeatable program
  • Common challenges: fragmented data, spreadsheet models and manual board reporting

What is financial risk management?

Financial risk management is the process of identifying and reducing the financial threats that could affect an organization's cash flow or operations. The CFA Institute describes financial risks as those that "arise from activity in the financial markets," distinct from non-financial risks that originate inside the organization or from external actors including regulators, suppliers, customers and others. In practice, treasury and finance teams manage exposures including foreign exchange, commodity price, interest rate and liquidity risk, according to IFAC guidance.

Financial risk management differs from investment risk management. Investment risk concerns the volatility and potential loss within a portfolio of securities. Corporate financial risk management covers the whole enterprise: its capital structure, counterparty exposures, funding position and operational processes. GARP curriculum treats risk management and investment management as a separate topic within its Financial Risk Manager curriculum, alongside market, credit, operational and liquidity risk, which confirms that investment risk is a subset of the field.

Precision at the definition stage matters more than most teams assume. "It's so critical to define what 'risk' is in the first place. Don't confuse risks with consequences. 'Reputational and brand damage' is a consequence of a substantive area of risk going unmanaged," says Maurice L. Crescenzi, Jr., Industry Practice Leader at Moody's. A risk register full of consequences produces measurements of the wrong things.

Why measuring financial risk matters now

Risk levels are climbing faster than the systems used to measure them. According to the GC Risk Index 2026 by Diligent Institute, senior legal leaders rate the current risk environment at 7 out of 10, up from 5.8 in the same survey's first reading in Q1 2025. That score gives finance leaders a current baseline for board conversations about whether risk capacity has changed, and it signals that measurement programs need to move faster than annual reporting cycles. For CFOs, the comparison turns rising risk into a planning input rather than a general concern. It also creates a clearer prompt to test whether measurement frequency still matches the pace of change.

Measurement capacity has not kept pace. The same research found that only 19% of senior legal leaders say their organization's governance, risk and compliance (GRC) systems are fully integrated.

That integration gap separates exposure data and operational incidents that should be measured in one view. It limits the board's ability to see whether a financial risk is isolated or part of a broader enterprise pattern. Only 21% of those leaders are very confident their board receives the right mix of information on risk, which means measurement has to improve both the underlying data and the way it is reported.

For finance leaders, the practical next step is to translate those signals into action: revisit risk appetite, confirm who owns each exposure and test whether board reporting can keep pace with changing conditions.

Directors feel the same pressure. According to What Directors Think 2026 by Diligent Institute and Corporate Board Member, 55% of U.S. public company directors name a sharp downturn in the U.S. economy among the greatest risks to their organization, and 47% say more frequent, structured risk discussions at the full-board level would improve risk oversight. For finance leaders, that turns liquidity and credit exposure into standing board-level measurement priorities. Boards that practice good governance expect management to bring them measured, comparable risk data that supports decisions.

Strong measurement also changes how leadership responds to volatility. "You're not as afraid because you've married a strong view of what's happening inside with what's happening outside, with a strong set of data," says David Platt, Chief Strategic Development Officer and Member, Executive Leadership Team at Moody's.

Types of financial risk

Regulators and professional bodies converge on four mutually exclusive categories of financial risk. The Basel Framework applies this taxonomy to banks, and the CFA Institute curriculum applies it across corporate finance.

  • Market risk is "the risk of losses arising from movements in market prices," per the BIS Basel Framework. Stock prices, interest rates, exchange rates and commodity prices all drive it.
  • Credit risk is "the risk of economic loss resulting from borrower failure to make full and timely payments of interest and principal," as defined by the CFA Institute. More broadly, it is the risk that any counterparty will not pay an amount owed.
  • Liquidity risk is the risk to an institution's financial condition "arising from its inability (whether real or perceived) to meet its contractual obligations," per the Federal Reserve.
  • Operational risk is "the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events," per the BIS Basel Framework. It includes legal risk and excludes strategic and reputational risk, which keeps the category distinct from the other three.

Operational risk earns its place on this list because a failed process or system can produce direct financial loss just as surely as a credit default.

The financial risk management process

Financial risk management runs as a five-step cycle: identify, measure, evaluate, mitigate, then monitor and report. The steps repeat because exposures shift with funding decisions and market moves. New counterparties can reset the cycle too. The Basel credit principles describe the same sequence, calling on institutions to identify, measure, evaluate, monitor, report and control or mitigate risk.

  1. Identify. Catalog exposures across the four risk types in a central risk register. Keep risks separate from their consequences.
  2. Measure. Quantify each exposure with the methods below so risks can be compared on a common scale.
  3. Evaluate. Weigh each measured risk against the organization's risk appetite and tolerance to decide which exposures are acceptable.
  4. Mitigate. Treat unacceptable risks through hedging, diversification, internal controls or changes to capital structure.
  5. Monitor and report. Track exposures continuously and report them to executives and the board in a format that supports decisions.

The cycle works best when it sits inside a broader corporate risk management program.

How to measure financial risk

Quantitative measurement turns exposures into numbers a board can compare and act on. Four measures form the core toolkit.

  • Standard deviation measures the dispersion of returns around their average and is the most common proxy for volatility, per the CFA Institute. Use it to compare how widely returns vary across exposures and decide which positions need limits, hedges or closer monitoring.
  • Beta measures how sensitive an asset or portfolio is to movements in the overall market. A beta of one moves with the benchmark; below one is less volatile than the benchmark and above one is more volatile, per the CFA Institute. Use it to explain whether market-driven exposures are likely to amplify or dampen broader market moves.
  • Value at Risk (VaR) is the maximum expected loss over a set time horizon at a given confidence level. The BIS standards define it as "a measure of the worst expected loss on a portfolio of instruments resulting from market movements over a given time horizon and a pre-defined confidence level." That threshold helps management test whether an exposure fits the company's risk appetite and liquidity reserves.
  • Conditional VaR (CVaR), also called expected shortfall, is the average loss in the tail beyond the VaR threshold. The BIS overview describes it as "a measure of the average of all potential losses exceeding the VaR at a given confidence level, which makes up for VaR's shortcomings in capturing the risk of extreme losses (i.e., tail risk)." The Basel Committee has also shifted market-risk measurement toward expected shortfall. That shift puts more emphasis on measuring losses beyond the VaR cutoff. Use CVaR when the board needs to understand how severe losses could become if that threshold is breached.

Qualitative methods fill the gaps quantitative models leave. Scenario analysis explores a range of possible future changes in assumptions, both positive and negative. Stress testing shocks a single variable to test resilience. The CFA Institute curriculum recognizes expert judgment alongside these qualitative approaches and quantitative measures within the risk management process. Different businesses need different measures, so use volatility and tail measures, then test the conclusions with a qualitative technique.

Frameworks that structure measurement

Two frameworks give measurement a repeatable structure and a common vocabulary across the enterprise.

COSO enterprise risk management framework. The current COSO framework, Enterprise Risk Management: Integrating with Strategy and Performance, organizes enterprise risk management into a structured set of components. Those components help teams connect governance to strategy and performance before choosing specific measures. They also give owners a shared structure for turning risk appetite into comparable reporting. COSO also sets out supporting principles and, in COSO's words, "highlights the importance of considering risk in both the strategy-setting process and in driving performance." Its value for financial risk measurement is the link it forces between measured exposures and company decisions.

ISO 31000:2018. The standard "provides principles, a framework and a process for managing risk. It can be used by any organization regardless of its size, activity or sector," per ISO. Published in 2018 and reconfirmed in 2023, it remains the current edition, though ISO has a revision in development. Its identify, analyze, evaluate, treat, monitor and communicate process maps directly to the five-step cycle above.

COSO and ISO 31000 define the governance framework within which VaR, CVaR and other metrics get selected, owned and reported.

Build a risk-ready organization

Learn how connected risk workflows improve board visibility, then see the platform in action.

Common challenges in measuring financial risk

Market exposures often live in treasury systems and credit data sits with finance, while operational incidents are logged elsewhere. Teams cannot produce a single measured view of financial risk when the underlying data remains fragmented. The integration figures above show how widespread the problem is: Fully integrated GRC systems remain rare.

According to The Transaction Readiness Report by Diligent Institute and its research partners (2025), only 4% of organizations have fully integrated GRC and financial systems. When measurement infrastructure stays fragmented while risk rises, leadership makes higher-stakes decisions on lower-quality inputs. That is reason enough to revisit risk appetite before volatility forces the discussion, and it shows why static annual risk assessments lag the pace of change. Integration is a practical condition for measuring exposure, not a later reporting enhancement.

Spreadsheets compound the problem. Manual models break silently and lack audit trails. Analysts rebuild calculations every reporting cycle, so a spreadsheet-based VaR figure can reach the board after the market has moved past it.

Manual reporting creates the final gap: translating raw measurements into something a board can use. "What are the risks you want the board to be focused on? … you have to really synthesize that into the mindset of the board and the context of risk management," said Derek Vadala, Chief Risk Officer at Bitsight Technologies, at Diligent Elevate 2024. If measurement never becomes a clear board narrative, it fails at its last step.

Solving these measurement gaps requires connected data and repeatable workflows that produce board-ready reporting as conditions change.

How Diligent improves financial risk measurement

The measurement problems above follow the same pattern. Scattered data and manual calculations leave reporting too late for board-level decisions. Technology improves measurement when it gives finance and risk teams a centralized, auditable view of exposure and a repeatable path from risk identification to board reporting.

For established pre-IPO programs, enterprise and public companies, Diligent ERM connects financial risk measurement to a full enterprise risk management program. A centralized risk register replaces scattered spreadsheets. AI-powered risk identification and benchmarking, plus external risk intelligence that includes credit sentiment data, give teams the inside-and-outside view Platt described. Real-time dashboards with heat maps and board-ready reporting help directors see whether market, credit, liquidity and operational risks are isolated exposures or part of a broader pattern.

Growth-stage companies and pre-IPO teams standing up a first risk program can start with AI Risk Essentials, which helps them move off spreadsheets and benchmark against peers with AI; deployment takes about seven days. That entry point fits lean teams that need a credible risk program quickly, while Diligent ERM supports organizations with more established enterprise risk requirements.

Diligent ERM supports Moody's benchmarking and FedRAMP authorization for organizations that need enterprise-grade risk governance. That matters when boards expect current, comparable financial risk data tied to the organization's risk appetite.

Schedule a demo to see how Diligent ERM can give your board a single, measured view of financial risk.

Frequently asked questions

What is financial risk management?

Financial risk management is the process of identifying, measuring and controlling risks that arise from an organization's financial activity, including its debt, cash position and market exposures. Investment risk management focuses on portfolio volatility; financial risk management covers enterprise-wide financial exposure.

What are the main types of financial risk?

The four main types of financial risk are market risk (losses from market price movements), credit risk (a counterparty failing to pay), liquidity risk (inability to meet obligations as they come due) and operational risk (losses from failed processes, people or systems). Regulators including the Basel Committee treat these as distinct, mutually exclusive categories.

How do you measure financial risk?

Quantitative measures include standard deviation for volatility, beta for market sensitivity, Value at Risk for maximum expected loss at a confidence level and Conditional VaR for average losses beyond that threshold. Qualitative methods such as scenario analysis, stress testing and expert judgment complement the numbers.

What is the financial risk management process?

The process runs as a five-step cycle: identify exposures, measure them, evaluate them against risk appetite, mitigate the unacceptable ones, then monitor and report continuously. The cycle repeats as market conditions and the organization's exposures change.

Which frameworks are used for financial risk management?

COSO's Enterprise Risk Management: Integrating with Strategy and Performance (2017) and ISO 31000:2018 are widely used frameworks. COSO's enterprise risk management framework ties risk to strategy and performance through a component-and-principle model, while ISO 31000 provides principles, a framework and a repeatable process any organization can apply.

See how Diligent ERM gives your board a single, measured view of financial risk. Schedule a demo.