ILM by City & Guilds · 8725-513Mandatory unit

Unit 513: Managing business risk

In undertaking this unit, learners will gain understanding of and be able to apply, models and techniques to identify potential business risks. They will learn how to evaluate both the likelihood of a hazard occurring and the potential severity of its consequences, combining this information to determine an overall risk level. Learners will also develop the knowledge and skills to monitor and evaluate risk for change and to develop business risk-management processes and integrate them into standard operations.

In short

Unit 513 Managing business risk is a 5-credit optional Level 5 unit covering risk types, tools, governance and risk culture, then evaluating your organisation's risk management and contributing to it. Where data supports decisions, the spec requires both quantitative and qualitative sources.

Level

RQF Level 5

Credit value

5 credits

Guided learning

25 hrs

Assessment criteria

12 criteria

Learning outcomes and assessment criteria

To achieve unit 513 your portfolio must evidence every assessment criterion below. There is no exam and no written assignment — you demonstrate each criterion using evidence from your own work.

Learning outcome 1

Understand business risk management in organisations

  • 1.1

    Explain types of business risks

    Evidence requirement: Evidence must include an explanation of all the types as stated in the range.

    What this covers: Types: strategic, operational, financial, compliance, reputational.

  • 1.2

    Describe risk management tools and techniques

    Evidence requirement: Evidence must include at least three tools and techniques.

    What this covers: Tools and techniques: ownership, probability, risk evaluation, monitoring and mitigation.

  • 1.3

    Explain governance structures and risk ownership and how they impact business risk management

  • 1.4

    Explain how to foster a positive risk management culture

  • 1.5

    Evaluate the relationship between risk management, business continuity and crisis management

    What this covers: Evaluate the relationship between risk management, business continuity and crisis management should focus on: • risk management: to include business context, risk identification, quantifying risks, potential impacts of risks, risk rating, risk control and monitoring the risk environment • business continuity: identifying business-critical activities; specific risks to business-critical activities; maintaining business-critical activities when risk occurs; recovering business critical activities; integrating business continuity plan with risk management plan • crisis management: identifying potential crisis events; nature of the crisis; responding to the crisis; integrating crisis management plans with risk management plans. Crisis management: crisis management models eg Fink’s (1986) four-stage cris model, Mitroff’s five stages of crisis management (1994), Gonzalez-Herrero and Pratt’s (1996) four-stage crisis model, Burnett’s (1998) six-step model of crisis management, Jacques (2007) four-cluster relational model of crisis management.

Learning outcome 2

Be able to evaluate the effectiveness of business risk management in own organisation

  • 2.1

    Identify current business risk management approaches

    Evidence requirement: Evidence must include at least two approaches.

  • 2.2

    Evaluate the effectiveness of current business management approaches

  • 2.3

    Evaluate current organisational culture and its impact on business risk management

    Evidence requirement: Evidence must include at least two impacts.

    What this covers: Risk management processes requires an iterative practice of; assessing risks, prioritising risks, ensuring risks are/remain within to organisational risk profiles, choosing and executing risk strategies, measuring residual risk.

  • 2.4

    Identify areas for improvement in identifying and managing risk

    Evidence requirement: Evidence must include at least two areas for improvement.

Learning outcome 3

Be able to contribute to business risk management in own organisation

  • 3.1

    Contribute to effective business risk management

  • 3.2

    Embed risk management, contingency and business continuity processes within areas of own responsibility

  • 3.3

    Monitor impact of contributions to effective business risk management

    Evidence requirement: Evidence must include at least two impacts.

How to approach unit 513

Written by our assessment team: what the criteria mean in practice, the evidence that works, and where learners get caught out.

What this unit is really about

Unit 513 is about business risk, not health and safety risk — a distinction worth stating in your first paragraph, because a portfolio of workplace risk assessments will not evidence this unit. Business risk means anything that threatens objectives: operational, financial, strategic, compliance, reputational, technological, supply chain, people and environmental risk.

The spec adds a requirement that runs across the unit: where data and information support decision-making, both quantitative and qualitative sources must be used. So your risk work needs numbers and informed judgement — incident data alongside what the team who does the work actually tells you.

The evidence that works

Learning outcomeEvidence that works well
LO1 — risk managementRisk types with examples from your organisation, the tools and techniques, governance structures and risk ownership, how to foster a positive risk culture, and an evaluation of the relationship between risk management, business continuity and crisis management
LO2 — evaluate current managementCurrent approaches identified, an evaluation of their effectiveness, an evaluation of culture's impact, and areas for improvement
LO3 — contributeYour contribution, evidence of embedding risk, contingency and continuity processes in your area, and monitoring of the impact

The natural artefact is a risk register for your area, dated, with risk description, owner, inherent score, controls, residual score and review date. It evidences much of LO3 directly and gives you something concrete to evaluate for LO2.

The three things Level 5 wants distinguished

Criterion 1.5 asks you to evaluate the relationship between risk management, business continuity and crisis management. Keep them separate:

  • Risk management reduces the likelihood or impact of things that might happen
  • Business continuity keeps critical activity running when something has happened — it assumes failure and plans around it
  • Crisis management handles the exceptional event that overwhelms normal arrangements, including communications and decision-making under pressure

The evaluative point is that they are usually managed by different people on different cycles, so the register and the continuity plan drift apart. If that is true where you work, that is your finding.

Risk culture, honestly

Criteria 1.4 and 2.3 are about culture, and this is where the strongest Level 5 answers come from. A poor risk culture rarely announces itself as recklessness. It looks like a register maintained for the audit and ignored operationally, risks scored down so they need not be escalated, near misses unreported because reporting causes trouble, and controls documented but bypassed under time pressure.

Fostering a positive culture (1.4) is therefore about consequence, not exhortation: what happens to the person who reports a problem, whether escalation gets support or blame, whether risk owners are actually asked about their risks, and whether the register changes anything.

For criterion 2.2, note that many organisations manage risk well operationally and document it badly — the controls exist in practice, in the heads of experienced staff, but are invisible and therefore vulnerable to that person leaving. That observation, evidenced, is a proper evaluation and leads directly to the improvements 2.4 asks for.

Useful reading

Supporting information for unit 513

Unit aim: In undertaking this unit, learners will gain understanding of and be able to apply, models and techniques to identify potential business risks. They will learn how to evaluate both the likelihood of a hazard occurring and the potential severity of its consequences, combining this information to determine an overall risk level. Learners will also develop the knowledge and skills to monitor and evaluate risk for change and to develop business risk-management processes and integrate them into standard operations.

Unit guidance: Where data and information are used to support decision-making, both quantitative and qualitative sources must be used. LO1 Evidence across the assessment criteria should consider small, medium and large organisations. LO3 Evidence across the assessment criteria may include following processes as set, modelling good practice, recommending and or embedding and implementing change and monitoring.

Evidencing this unit

All evidence for the skills learning outcomes must be generated in the workplace or a realistic working environment, and must be valid and attributable to you.

  • Workplace documentation and records — team development plans, project implementation reports, meeting agendas and minutes, training materials
  • Video clips, up to a maximum of 15 minutes
  • Projects
  • Reflective accounts, journals and logs
  • Assessment observation
  • Witness testimonies

Where unit 513 counts

This unit sits in the ILM Level 5 Leadership and Management suite (8725) and counts towards the pathways below, from £695.

Frequently asked questions

Is unit 513 about health and safety risk?

No. It covers business risk: operational, financial, strategic, compliance, reputational, technological, supply chain, people and environmental. A portfolio of workplace risk assessments will not evidence it.

What is the difference between risk management and business continuity?

Risk management reduces the likelihood or impact of things that might happen. Business continuity assumes something has happened and keeps critical activity running. Crisis management handles the exceptional event that overwhelms normal arrangements.

Is unit 513 mandatory?

Yes. Unit 513 is a mandatory unit — every learner on the relevant pathway must complete it.

How is unit 513 assessed?

Assessment is a portfolio of evidence, centre-devised and internally set and marked. There are no exams and no written assignments.

What evidence can I use for unit 513?

All evidence for the skills learning outcomes must be generated in the workplace or a realistic working environment, and must be valid and attributable to you. Workplace documents, projects, reflective accounts, observation records and witness testimonies are all valid sources.

Which qualifications include unit 513?

It counts towards the Level 5 Award, Level 5 Certificate, Level 5 Diploma, Level 5 Extended Diploma.