Business risk is the chance that an event or condition stops a business meeting its objectives, from profitability and growth to regulatory compliance and continuity.
Also known as: commercial risk, enterprise risk
Key points
- Risk shows up in cashflow, margins, asset values and creditworthiness, and can come from strategy, operations, the market, legal obligations or external shocks.
- The main types are strategic, financial, operational, compliance, reputational, market, credit, liquidity, cyber and environmental risk.
- Shocks can strain working capital and access to finance; lenders price risk into their terms or decline finance altogether.
- Risks are scored by likelihood and impact, logged in a risk register with an owner, then avoided, reduced, transferred, shared or accepted.
- Insurance transfers some of the financial impact but does not remove the likelihood, so it works alongside controls and contingency plans.
Types of business risk
Strategic risk comes from big choices about markets, products or business models, such as a retailer under-estimating the cost of winning online customers. Financial risk covers capital structure, interest rates, foreign exchange and cash management, for example rising borrowing costs on variable-rate loans. Operational risk is a failure of processes, people or systems, like a production line stopping because maintenance was not scheduled.
Compliance risk is a breach of regulatory, contractual or statutory obligations. Reputational risk is damage to brand trust, market risk is a shift in demand, pricing or competitor behaviour, and credit risk is a customer failing to pay, such as a large debtor entering administration. Liquidity risk is being unable to meet short-term obligations without undue cost, cyber risk covers data breaches and outages, and environmental risk includes floods and property damage.
Internal and external risks
Internal risks start inside the business and are generally controllable: poor process design, staffing gaps, weak internal controls or outdated IT. They are usually fixed with controls, training and process redesign, for instance cross-training staff so that invoicing does not depend on one person.
External risks come from outside and are harder to control: market shifts, regulatory change, supplier failure or natural hazards. They call for monitoring, contracts, supplier diversification, hedging or insurance. A business that relies on a single supplier, for example, maps alternatives and holds buffer stock before that supplier collapses.
How business risk is assessed and managed
Assessment weighs likelihood against impact. A simple matrix scores each on a one-to-five scale and multiplies them, so a cyber breach rated possible (3) and catastrophic (5) scores 15 and lands in the high-to-extreme band. A quantitative version calculates expected loss as probability multiplied by dollar impact: a 10% chance of a $200,000 loss is an expected loss of $20,000. Each risk goes into a register with a category, an owner, existing controls, mitigation actions and a review date.
The response is to avoid the activity, reduce the risk with controls, transfer it through contracts or insurance, share it through a joint venture, or accept it where the control cost outweighs the exposure. Businesses also set a risk appetite (how much residual risk they will carry after controls) and monitor KPIs such as cash runway and days sales outstanding, with a quarterly risk dashboard and a full register review annually or after a major incident.
Why business risk matters to lenders
Business risk feeds straight into four outcomes: profitability, solvency and liquidity, creditworthiness, and compliance and reputation. Lenders and investors price risk into their terms or decline finance, and they expect material assets to be properly insured, remembering that policies carry limits, exclusions and excesses. For a business seeking finance, a maintained risk register and clear reporting give a lender confidence in forecasts, valuations and the capacity to service a business loan.
Example
A small retailer relies on one supplier for its seasonal stock. Supplier mapping flags the dependency, and the risk is assessed as medium likelihood (3) and high impact (4), a score of 12. The owner negotiates secondary suppliers, builds a small safety stock and reviews payment terms, then logs the actions in the risk register with a target date and a review date. When the main supplier later fails, sales continue and the business avoids paying for urgent, costly air freight.
Not to be confused with
- Credit risk
- credit risk is one type of business risk: the chance that a customer or counterparty fails to pay
- Collateral risk
- collateral risk is a lender's risk that the asset securing a loan loses value; business risk is the borrower's risk of missing its own objectives
Frequently asked questions
What are the main types of business risk?
There are ten common categories: strategic, financial, operational, compliance or legal, reputational, market or competitive, credit, liquidity, technology or cyber, and environmental or physical. Many businesses map each type to a function such as finance, operations, IT or HR so that every risk has a clear owner.
How do you measure business risk?
Most businesses rate each risk for likelihood and impact on a one-to-five scale and multiply the two to get a score for prioritising. A quantitative version calculates expected loss as probability multiplied by the dollar impact, so a 10% chance of a $200,000 loss carries an expected loss of $20,000.
What is a risk register and do I need one?
A risk register is a central log of each risk with its category, owner, likelihood and impact scores, existing controls, mitigation actions, target date and review date. Even a small business benefits from one, because it turns vague worries into tracked actions, and a well-kept spreadsheet is enough to start.
How often should a business review its risks?
Set a cadence that matches the risk. Operational KPIs such as cash runway and days sales outstanding are monitored weekly or monthly, executives see a quarterly risk dashboard, and the full register is reviewed at least annually or after a major change or incident. Escalation thresholds decide when the board gets involved.
Can insurance remove business risk?
No. Insurance transfers some of the financial impact of an event but does not change how likely it is, and policies carry limits, exclusions and excesses. Public liability, professional indemnity, business interruption and cyber cover work best alongside practical controls, cash reserves and a documented continuity plan.
Related terms
Credit risk
Credit risk is the possibility that a borrower or counterparty will default on their contractual repayments, leaving the lender or investor with a loss.
Read definitionCash flow
Cash flow is the movement of money into and out of a business over a period; unlike profit, it tracks actual receipts and payments, so it measures liquidity.
Read definitionInsurance
Insurance is a contract where you pay a premium and an insurer covers specified losses, such as damage to a financed asset or a lender's loss on default.
Read definitionWorking capital
Working capital is the difference between a business's current assets and current liabilities: the measure of whether it has enough liquid resources to meet obligations due within 12 months.
Read definitionInterest rate risk
Interest rate risk is the exposure a financial asset, liability or portfolio has to changes in market interest rates, which alter the present value of its future cash flows.
Read definitionCovenants
Covenants are promises, obligations or restrictions written into a contract or recorded on land title that bind the parties, such as a borrower's promise to maintain minimum interest cover.
Read definitionGo deeper
Sources
This article is general information only and is not financial advice.