Qualifications Services How It Works Why Us FAQ Order Now
CMI 518 Assignment Example

Marbury School is an independent co-educational day and boarding school with 780 pupils aged 4 to 18, employing 190 teaching and support staff. It is governed by a board of trustees, inspected by the Independent Schools Inspectorate, and derives income almost entirely from fees. The author is Bursar and Clerk to the Governors, with responsibility for finance, estates, compliance and risk. Organisational detail is illustrative and anonymised.

Learning Outcome 1: Understand the scope of business risk management

AC 1.1 Evaluate business risks in relation to the organisation, its customers and suppliers

Risks to the organisation. Marbury’s dominant exposure is a decline in pupil numbers, since roughly 94 per cent of income is fee-derived and the cost base is largely fixed within an academic year. Evaluating the severity, a shortfall of thirty pupils removes approximately £600,000 of income against costs that cannot be reduced in the same period. Safeguarding failure is the exposure with the greatest consequence rather than the greatest likelihood: a serious incident carries regulatory, legal, reputational and, in the extreme, existential consequences that no insurance restores. Estates and health and safety risk arises from a listed building estate and an extensive activities programme. Cyber and data risk is material because the school holds sensitive information about children.

Risks in relation to customers. In a school the customer relationship is unusual, because parents purchase and pupils receive. Evaluating this, parental affordability is a genuine business risk: fee increases above wage growth produce attrition that appears two years later at the point families make secondary transfer decisions. Reputational risk operates almost entirely through parental networks rather than through published inspection outcomes, which means the informal channel matters more than the formal one. Concentration risk exists in the boarding population, where a single overseas market provides 41 per cent of borders and is exposed to visa policy and currency movement.

Risks in relation to suppliers. Catering, coach transport, cleaning and peripatetic music teaching are contracted out. Evaluating the exposure, the school retains accountability for safeguarding regardless of who employs the individual, so a supplier’s recruitment failure becomes the school’s incident. Financial failure of the catering contractor mid-term would interrupt a service the school cannot suspend. Evaluating a risk frequently overlooked, single-supplier dependency in coach transport means an operator’s licence issue removes the school’s ability to run its sports fixtures.

Interaction between the three. Evaluating a dimension often missed, these risks are correlated rather than independent. A safeguarding incident involving a contracted coach driver would be a supplier risk, a safeguarding risk and a reputational risk simultaneously, and would then convert into a financial risk through admissions. Registers that treat risks as separate line items understate exposure, because the scenario that damages a school is usually one event moving through several categories at once.

Evaluating across the three. The pattern is that Marbury’s severest risks are not the ones it controls directly. Reputational, safeguarding and supplier risks all crystallise through parties outside the organisation, which is why risk management here cannot be confined to internal processes.

AC 1.2 Analyse the governance of risk within organisations

The role of the governing body. Trustees hold ultimate responsibility for risk. Analysing what that involves, it is setting risk appetite, satisfying themselves that management has identified the significant risks, and testing whether controls are working rather than accepting that they exist. Trustees are unpaid, part-time and not usually risk specialists, which makes the quality of what management presents to them decisive.

Risk appetite and tolerance. Analysing the distinction, appetite is the amount of risk the organisation is willing to accept in pursuit of its objectives, while tolerance is the boundary beyond which exposure becomes unacceptable. Marbury’s appetite is deliberately asymmetric: close to zero for safeguarding and pupil safety, moderate for financial and reputational risk, and higher for educational innovation. Analysing why an explicit statement matters, without it every risk decision is argued from first principles and inconsistently resolved.

The three lines of defence. This model separates responsibility into three: operational management, which owns and manages risk day to day; risk and compliance functions, which set the framework and challenge the first line; and internal audit or independent assurance, which provides objective evaluation to the governing body. Analysing its application in a small organisation, Marbury cannot resource three genuinely separate lines, and the Bursar occupies the first and second simultaneously. The response is to buy the third line externally through independent safeguarding and health and safety audit, since assurance provided by the person responsible for the controls is not assurance.

Delegated authority and escalation. Analysing the mechanism, a scheme of delegation defines what the Head, the Bursar and the board may each decide, with defined thresholds for escalation. Its purpose is to ensure decisions reach the level with authority to accept the risk.

Assurance mapping. Analysing a governance technique that is underused in smaller organisations, mapping which risks are covered by which source of assurance reveals where the board is relying on nothing. At Marbury the exercise showed that financial controls were tested by three separate sources while the trips and activities programme, carrying a higher consequence profile, was covered only by the assurance of the person running it.

Culture as a governance matter. Analysing the limit of formal structures, governance produces the right outcomes only where people report what they see, and Buchanan and Huczynski (2023) observe that reporting behaviour follows what staff perceive will happen to them rather than what policy invites. Evidence links psychological safety to whether concerns and errors are raised at all (Capezio et al., 2023), and in a safeguarding context a culture in which staff hesitate to report a colleague’s behaviour defeats every procedural control the school has.

AC 1.3 Examine categories of risk used within different organisational settings

Strategic risk. Threats to the achievement of long-term objectives: demographic change, competitor schools, policy change affecting independent education. Examining these, they develop slowly and are frequently absent from registers because no single event marks their arrival.

Operational risk. Failures of internal processes, people or systems: a trip incident, a catering failure, an examination administration error.

Financial risk. Liquidity, fee debt, investment performance, pension liability and cost inflation. Examining this category in independent education specifically, the defined benefit pension position is a material and largely uncontrollable exposure.

Compliance and regulatory risk. Inspection outcomes, charity law duties, employment law, data protection and the specific statutory framework governing safeguarding in schools.

Reputational risk. Examining why this is treated separately rather than as a consequence, in a fee-paying market reputation is the asset that generates income, and reputational damage converts directly into pupil numbers.

Safeguarding risk. Examining a category that is sector-specific and cannot be subsumed into operational risk, it carries a consequence profile unlike any other exposure and is governed by its own statutory framework.

How categories differ by setting. Examining the comparison, a manufacturer’s register is dominated by supply chain, plant and product liability; a bank’s by credit, market and conduct risk under a prudential framework; a charity’s by funding concentration and public trust. Examining the underlying point, categorisation is not a neutral taxonomy but a statement of what an organisation believes can harm it, and a register borrowed from another sector will miss what matters locally.

Emerging and horizon risk. Examining a category that standing registers systematically miss, emerging risks are those whose likelihood or impact is not yet well understood, such as the effect of generative artificial intelligence on academic assessment integrity. Examining why they are missed, a register built from what has previously gone wrong contains only known risks by construction, which is an argument for periodic horizon scanning as a distinct activity rather than an extension of the normal review.

Hazard, control and opportunity risk. Examining an alternative categorisation, risks may be grouped by whether they are purely downside, arise from uncertainty about outcomes, or are consciously taken in pursuit of gain. Analysing its value, it prevents the common error of treating all risk as something to be minimised, when a school declining to open a new sixth form because of the risk has also accepted the risk of standing still.

AC 1.4 Analyse organisational methods for managing and quantifying risk

Qualitative scoring. Assessing likelihood and impact on defined scales, typically one to five, and multiplying to produce a score. Analysing its strengths, it is quick, requires no specialist capability and allows comparison across dissimilar risks. Analysing its weaknesses, the scores are judgements dressed as measurements, multiplication implies a precision that does not exist, and a low-likelihood catastrophic risk can score below a frequent trivial one.

Risk matrices and heat maps. Plotting risks on a grid to direct attention. Analysing their real function, it is communication rather than analysis, and they work well with a trustee board precisely because they simplify.

Expected value. Multiplying financial impact by probability. Analysing its application at Marbury, it is usable for fee debt and for insurable property loss, and it is unusable for safeguarding, because expressing a child protection failure as an expected monetary value is both analytically and ethically wrong.

Scenario analysis and stress testing. Modelling the consequences of a defined adverse event rather than estimating its probability. Analysing why this suits the school better than probability-based methods, the question that matters is not how likely a thirty-pupil shortfall is but whether the school survives one, and stress testing answers that directly.

Quantitative simulation. Techniques such as Monte Carlo simulation run many iterations across ranges of uncertain variables to produce a distribution of outcomes. Analysing their applicability, they are appropriate where reliable data and genuine variability exist, which describes the school’s investment portfolio and does not describe most of its register.

Control effectiveness assessment. Analysing a method frequently omitted, scoring residual risk after controls requires an honest assessment of whether controls actually work. Marbury’s earlier registers assumed control effectiveness rather than testing it, which produced a register showing acceptable residual risk throughout.

Learning Outcome 2: Understand the process for managing business risk

AC 2.1 Analyse the processes for identifying, assessing and ranking business risk

Identification. Marbury uses four routes. Facilitated workshops with the senior team and separately with heads of department, because the risks a bursar sees differ from those a head of boarding sees. Incident, near-miss and complaint data, which reveals risks that have already begun to materialise. External sources including inspection reports from other schools, sector bodies and insurers. And horizon scanning at board level for slower strategic risks. Analysing the weakness common to workshops, they surface familiar risks reliably and unfamiliar ones poorly, which is the argument for external input.

Assessment. Each risk assessed for likelihood and impact, with impact assessed across several dimensions rather than one. Analysing why multi-dimensional impact matters here, a risk with modest financial consequence may carry severe safeguarding or reputational consequence, and a single financial impact score conceals that entirely.

Inherent and residual risk. Analysing this distinction, inherent risk is exposure before controls and residual risk is what remains after them. Recording both shows what the controls are actually doing and reveals where a low residual score depends on a single control.

Ranking and prioritisation. Ordering by residual score to direct attention and resource. Analysing the limitation, ranking by score alone under-weights low-likelihood catastrophic risks, which is why Marbury applies an override: any risk with a catastrophic impact rating receives board attention regardless of its likelihood score.

Ownership. Analysing the step that converts a list into a management tool, each risk is assigned to a named individual with authority to act. A register without owners records risks rather than managing them.

Bow-tie analysis for the most significant risks. Analysing a technique suited to catastrophic exposures, a bow-tie places the hazardous event at the centre, maps causes and preventive controls on one side and consequences and mitigating controls on the other. Analysing its value at Marbury, applying it to a safeguarding scenario showed clearly which controls prevent and which limit harm after the event, and revealed that the school’s controls clustered heavily on prevention with little planned for response.

Review cycle. Analysing frequency, the operational register is reviewed termly by the senior team and the principal risks quarterly by the board, with provision for out-of-cycle escalation.

AC 2.2 Analyse the process for managing a business risk

The recognised international framework for risk management sets out a process of establishing context, risk assessment comprising identification, analysis and evaluation, risk treatment, and then monitoring and review, with communication and consultation running throughout rather than occurring at the end.

Establishing the context. Analysing this first stage, it defines what the organisation is trying to achieve, the internal and external environment, and the criteria against which risk will be judged. Omitting it produces registers of things that could go wrong with no reference to what the organisation is trying to do.

Risk assessment. Identification, analysis of causes and consequences, and evaluation against the criteria set in the context stage to decide whether treatment is required.

Risk treatment. Selecting and implementing options, then reassessing the residual position. Analysing an important feature, treatment is iterative: a control may introduce a new risk, as Marbury found when tightening site access created a fire evacuation issue.

Monitoring and review. Analysing this stage, it tests whether controls remain effective and whether the risk profile has changed, and it is the stage most often reduced to reopening the register annually and changing the dates.

Communication and consultation throughout. Analysing why the framework places this across the whole process rather than at the end, those who will operate a control must be involved in designing it, or the control exists on paper only.

Applying it to a worked example. The school’s overseas boarder concentration was assessed at high likelihood and major impact. Treatment comprised diversification of recruitment into two additional markets, a currency hedging arrangement and a revised deposit structure. Residual risk is reduced from high to medium over two years, and monitoring tracks the concentration percentage quarterly rather than waiting for it to become a crisis.

AC 2.3 Examine approaches for mitigating a business risk

Tolerate. Accepting the risk where the cost of treatment exceeds the benefit or where the exposure sits within appetite. Examining this option, it is a legitimate decision and must be a documented one, since undocumented tolerance is indistinguishable from having missed the risk.

Treat. Reducing likelihood or impact through controls. Examining the two routes, likelihood reduction is generally preferable where achievable, while impact reduction, such as business continuity planning, applies where likelihood cannot be lowered further.

Transfer. Moving financial consequence to another party through insurance or contract. Examining its limits carefully, insurance transfers financial loss and does not transfer accountability. Marbury holds appropriate cover, and no policy restores a reputation or discharges a safeguarding duty.

Terminate. Ceasing the activity gives rise to the risk. Examining when this is appropriate, the school withdrew from a long-haul expedition programme after assessing that the residual risk remained outside appetite despite available controls. Examining the trade-off, termination removes the risk and the benefit together, and organisations that terminate readily accumulate a different risk, which is irrelevant.

Combination approaches. Examining what happens in practice, most significant risks are managed through several options simultaneously. The overseas boarder concentration is treated through diversification, transferred in part through currency hedging, and tolerated as to the remainder, and describing it as managed by any single approach would misrepresent it.

Contingency and business continuity. Examining an approach that sits alongside the four options rather than within them, planning for the consequences of a risk that materialises anyway is distinct from reducing its likelihood. Whittington et al. (2023) note that organisational resilience depends on the capacity to respond as much as on the capacity to prevent, and Marbury’s continuity plan for a site closure was written after a flood rather than before one.

The hierarchy of control in a safety context. Examining an approach specific to physical risk, controls are ranked in a fixed order of reliability, beginning with removing the hazard altogether, then replacing it with something less dangerous, then engineering it out, then relying on rules and procedures, and only lastly on protective equipment. The ordering reflects a simple point: anything that depends on a person behaving correctly every time will eventually fail. Examining its application, Marbury’s earlier response to a pond hazard was signage, an administrative control, where fencing, an engineering control, was both available and more reliable.

AC 2.4 Analyse methods for implementing business risk management

Establishing the framework and policy. A board-approved risk policy setting out appetite, roles, process and reporting. Analysing its function, it makes risk management a defined organisational activity rather than something individuals do to varying standards.

Assigning ownership and building it into roles. Analysing what makes ownership real, a named owner requires authority and resource to act, and risk responsibilities should appear in job descriptions and objectives rather than sitting alongside them. Mullins (2022) notes that behaviour follows what is measured and expected rather than what is stated.

Embedding into existing processes. Analysing the most effective implementation method, risk assessment built into trip approval, procurement, recruitment and project initiation is performed as part of the work, whereas a separate risk process competes with the work and loses.

Control design and documentation. Analysing this step, controls must be specific enough that someone can test whether they operated. A control described as staff are aware of the policy cannot be tested; one requiring a signed record at a defined point can.

Capability and training. Supportive, capable line management is associated with the behaviours a risk framework depends on, including the willingness to raise problems (Barends, Rousseau and Janssen, 2023). Analysing a persistent constraint, most managers reach their roles without preparation for risk work (Chartered Management Institute, 2023), and a framework requiring judgement from people who have not been trained to exercise it will be applied mechanically.

Assurance and testing. Analysing why independent testing matters, control self-assessment by the person responsible for the control is the weakest form of assurance, and Marbury commissions external safeguarding and health and safety audit for precisely that reason.

Systems and record keeping. A maintained register, incident recording and an audit trail of decisions.

Project and change risk. Analysing a route through which risk enters an organisation unnoticed, significant projects introduce exposures the standing register does not contain. Maylor and Turner (2022) treat risk management as an integral element of project governance rather than a parallel activity, and Marbury’s boarding house refurbishment carried construction, safeguarding and disruption risks that were managed by the project team and invisible to the board until the process was changed to require project risks above a threshold to be reported into the corporate register.

AC 2.5 Assess methods for reporting identified risks to stakeholders

Board and trustee reporting. A quarterly report presenting the principal risks, movement since the last review, control effectiveness and any risk outside appetite. Assessing the design requirement, trustees are unpaid, part-time and not specialists, so the report must be interpretable without prior technical knowledge while remaining honest about difficulty. Assessing a common failure, a register of forty risks presented in full guarantees that none receives attention; the principal risks reported by exception is the more effective format.

Risk register. Assessing its role, the register is a working document for management rather than a reporting instrument, and presenting it as though it were reporting confuses the two audiences.

Heat maps and dashboards. Assessing their value, visual presentation communicates relative position quickly and is well suited to a board. Assessing the weakness, simplification loses the reasoning, and a risk that moves on a heat map with no explanation invites the wrong question.

Reporting to regulators and inspectors. Assessing this obligation, certain matters must be reported to statutory bodies within defined timescales, and safeguarding referrals are not discretionary. Assessing the cultural requirement, an organisation that reports reluctantly and late will be judged on that behaviour as much as on the incident.

Reporting to parents and the wider community. Assessing this sensitive area, parents are entitled to know about matters affecting their children’s safety, and the school must balance transparency against confidentiality obligations to individuals. Assessing what determines credibility, communicating early and incompletely is generally better received than communicating late and fully, because the alternative is that parents learn from one another first.

Reporting to staff. Assessing an audience frequently omitted, staff operate the controls and need to understand what they are protecting against. Northouse (2025) observes that withholding information from those able to act on it removes their capacity to respond.

Reporting to insurers and funders. Assessing this requirement, disclosure obligations are contractual and non-disclosure can void cover at the point it is needed.

Assessing the methods collectively. Each serves a different audience with a different decision to make. The requirement common to all of them is that reporting must include what has deteriorated as well as what has improved, since a report showing only good news is correctly read as promotional and discredits the accurate parts alongside the flattering ones.

References

Barends, E., Rousseau, D. and Janssen, B. (2023) People managers: an evidence review. Scientific summary. London: Chartered Institute of Personnel and Development.

Buchanan, D.A. and Huczynski, A.A. (2023) Organizational behaviour. 11th edn. Harlow: Pearson.

Capezio, A., Barends, E., Rousseau, D. and Wietrak, E. (2023) Psychological safety: an evidence review. Scientific summary. London: Chartered Institute of Personnel and Development.

Chartered Management Institute (2023) Taking responsibility: why UK plc needs better managers. London: CMI.

Maylor, H. and Turner, N. (2022) Project management. 5th edn. Harlow: Pearson.

Mullins, L.J. (2022) Management and organisational behaviour. 12th edn. Harlow: Pearson.

Northouse, P.G. (2025) Leadership: theory and practice. 10th edn. Thousand Oaks, CA: SAGE.

Whittington, R., Regnér, P., Angwin, D., Johnson, G. and Scholes, K. (2023) Exploring strategy: text and cases. 13th edn. Harlow: Pearson.