Finance Explained Simply
Risk Management
Risk ManagementRisk management frameworks
Intermediate min read

Financial risk explained: the main types and how they are managed

By the FES team · Published 27 March 2026

In brief: Financial risk is the possibility of losing money — or of a financial outcome being worse than expected. There are four main types that every finance professional must understand: market risk, credit risk, liquidity risk, and operational risk. This guide explains each one, how they interact, and how institutions manage them.

Why financial risk management exists

Financial institutions are in the business of taking risk for a return. A bank lends money and earns interest — but risks non-repayment. A trading desk takes positions and earns a spread — but risks adverse price moves. An insurance company collects premiums and risks paying out more than it collected. Risk is not something to eliminate; it is something to measure, price, and manage.

The discipline of financial risk management grew rapidly after a series of high-profile failures — Barings (1995), LTCM (1998), Lehman Brothers (2008) — each of which demonstrated that an institution's internal risk models had badly underestimated the true exposure. Modern risk management combines quantitative measurement, regulatory oversight, and institutional governance to prevent any single risk from becoming an existential threat.

"Risk management is not about avoiding risk — it is about understanding it well enough to take the right risks at the right price."

The four main types of financial risk

1. Market risk

Market risk is the risk of loss from changes in market prices — interest rates, equity prices, foreign exchange rates, commodity prices. It is the most visible form of risk for trading books and investment portfolios.

Sub-type Source Key metric
Interest rate risk Rate moves affect bond prices, loan values, swap P&L Duration, DV01
Equity risk Stock price moves affect portfolio values and equity derivatives Beta, VaR
FX risk Exchange rate moves affect cross-currency positions, earnings translation Delta, notional exposure
Commodity risk Oil, gas, metals price volatility Commodity VaR, hedge ratio

The standard tool for measuring aggregate market risk is Value at Risk (VaR) — the maximum expected loss over a given time horizon at a given confidence level. A £10m 1-day 99% VaR means the desk should lose no more than £10m in a single day 99% of the time (though it tells you nothing about what happens in the 1% of cases where the loss exceeds that figure).

2. Credit risk

Credit risk is the risk of loss from a borrower's or counterparty's failure to meet their obligations. It has two distinct flavours:

Default risk is the probability that a borrower simply does not repay — the most classic form of credit risk in lending. Banks hold regulatory capital against this, calculated using probability of default (PD), loss given default (LGD), and exposure at default (EAD).

Counterparty risk is the risk that the other side of a financial contract — a derivative, a repo, a securities trade — fails to perform. Unlike loan default risk, counterparty risk is bilateral and the exposure fluctuates with market prices.

Spread risk is the risk that a borrower's credit spreads widen — reducing the market value of their bonds — even if they don't default. A portfolio of corporate bonds loses value when credit conditions deteriorate, even without a single default occurring.

8% Minimum Tier 1 capital ratio banks must hold against risk-weighted assets under Basel III — the regulatory backstop against credit and market risk

3. Liquidity risk

Liquidity risk comes in two forms that are conceptually distinct but often hit simultaneously:

Funding liquidity risk is the risk that a firm cannot meet its short-term obligations — that it runs out of cash, even if it is technically solvent. This is what killed Northern Rock in 2007: the bank was not necessarily insolvent, but it could no longer fund itself in the overnight market. The remedy is holding sufficient liquid assets (a liquidity buffer) and managing the maturity profile of liabilities.

Market liquidity risk is the risk that a position cannot be closed at its quoted price — because the market is too thin, bid-offer spreads have blown out, or buyers have disappeared. In a crisis, assets that appeared liquid in normal times can become virtually untradeable. The 2008 mortgage-backed securities market was the extreme version: these instruments had been rated and traded as liquid assets, but when confidence evaporated, there were no buyers at any reasonable price.

4. Operational risk

Operational risk is everything else — loss from inadequate or failed internal processes, people, systems, or from external events. It is the hardest to quantify. Under Basel III, banks must hold capital against operational risk, calculated using either a standardised approach (based on income) or internal loss models. Major operational risk categories include fraud, IT failures, legal risk, and human error.

The £6.2bn "London Whale" loss at JPMorgan Chase in 2012 combined market risk (bad derivatives positions) with operational risk (inadequate risk oversight, mismarked books, and a failure of internal governance).

Two more types worth knowing

Systemic risk

Systemic risk is the risk that the failure of one institution triggers cascading failures across the financial system. It is not a risk any single firm manages for itself — it is a macroprudential concern managed by central banks and regulators through capital requirements, stress testing, and resolution frameworks. The 2008 crisis was fundamentally a systemic risk event: the interconnectedness of institutions meant that Lehman's failure froze credit markets globally.

Model risk

Model risk is the risk that financial models are wrong — either because they make incorrect assumptions, are applied to situations outside their valid range, or are implemented incorrectly. Every risk metric (VaR, CVA, option prices) depends on models. If the model is flawed, the risk measurement is flawed. This is why regulators require banks to have independent model validation functions and to stress-test their models against scenarios the models were not designed to handle.

How the types of risk interact

In practice, risk types do not stay in separate boxes. The 2008 crisis showed how they compound:

  • Market risk (falling house prices) triggered credit risk (mortgage defaults)
  • Credit risk destroyed the value of MBS, triggering market risk in structured credit portfolios
  • Market and credit losses impaired bank capital, triggering funding liquidity risk
  • Liquidity risk caused fire sales, which further worsened market risk
  • The whole cycle was amplified by systemic risk — interconnectedness meant every institution was exposed to every other

This feedback loop — risk types reinforcing each other in stress — is why risk management teams increasingly use integrated frameworks (economic capital models, stress testing under correlated scenarios) rather than managing each risk type in isolation.

The risk management framework

Risk management at a financial institution is organised around three lines of defence:

The first line is the business — traders, relationship managers, lenders — who own and manage the risk they take on. They are responsible for staying within approved limits and for flagging risks they cannot manage.

The second line is the risk function — Market Risk, Credit Risk, Operational Risk, Treasury — which sets limits, monitors exposures, challenges the business, and reports to the board and regulators.

The third line is internal audit, which independently assesses whether the first and second lines are functioning as intended.

Go Deeper — Related Articles

Share:PostShare

The book

Want the full picture?

Finance Explained Simply covers every concept in the Knowledge Base — and goes deeper.