Risk Aggregation
Risk aggregation is the process of combining multiple individual risks into a single, broader view of overall risk exposure. Rather than looking at each risk in isolation, an organization brings related risks together to better understand the total picture. This helps decision-makers see how risks interact and contribute to the organization's overall exposure.
Risk aggregation generally refers to the process of combining several individual or less-comprehensive risk measures into a more comprehensive measure of overall risk exposure. In enterprise risk management practice, it typically involves evaluating and summing risks recorded across the organization (for example, within a risk register) to develop a consolidated understanding of total risk. Aggregation methods vary by framework, sector, and the nature of the risks being combined, and the appropriate approach depends on facts and professional judgment; risks are not always additive, and correlations or interdependencies between risks may affect how they should be combined. Accountability for aggregating and reporting risk typically sits with management and the risk function, while the board and its committees generally oversee the resulting aggregated risk view. This entry is educational and not legal, audit, or compliance advice.
Why it matters
Viewing risks only in isolation can obscure the organization's true exposure. A single risk may appear manageable on its own, but when combined with related risks, the aggregate exposure can be materially larger than the sum of its parts suggests, or in some cases smaller where risks offset one another. Risk aggregation gives boards and management a consolidated view that supports better-informed decisions about capital, strategy, and where to focus mitigation efforts. Without it, an organization may accept an overall exposure that exceeds its risk appetite simply because no single risk crossed a threshold.
Aggregation also matters because risks are not always additive. Correlations and interdependencies between risks can amplify or dampen the combined effect, and treating individual entries in a risk register as independent, summable figures can produce a misleading picture. The appropriate method depends on the framework in use, the sector, the nature of the risks being combined, and professional judgment. Getting this wrong in either direction, overstating or understating aggregate exposure, can distort resource allocation and undermine the credibility of risk reporting to the board.
Because aggregated risk information typically feeds board-level oversight and strategic decision-making, the quality of the underlying data and the transparency of the aggregation approach are important. This entry is educational and not legal, audit, or compliance advice; how aggregation should be performed and reported will vary by organization and circumstance.
Who it's relevant to
Inside Risk Aggregation
Common questions
Answers to the questions practitioners most commonly ask about Risk Aggregation.