Assessing Risk & Planning for Uncertainty (AQA A Level Business): Revision Note
Syllabus Edition
First teaching 2026
First exams 2028
Exam code: 7132
Why assess and plan for risk and uncertainty?
Risk describes a situation where the likelihood of a particular outcome can be estimated, based on data or past experience
E.g. A restaurant knows from several years of sales data that around 10% of its reservations result in a no-show each month
Because this pattern is based on past experience, the business can estimate the likelihood and plan for it, for example by slightly overbooking tables
Uncertainty describes a situation where the outcome, or even its probability, cannot be reliably predicted at all
E.g. A business cannot know in advance whether a completely new government regulation will be introduced next year, or what form it might take
There is no relevant past data or pattern to draw on to estimate the likelihood of this happening
Benefits of assessing and planning for risk
It protects the business from being caught off guard
Anticipating potential problems allows a business to prepare a response in advance, rather than reacting under pressure once a crisis has already begun
Example
Tesco had built contingency plans for supply chain disruption before the COVID-19 pandemic
This allowed it to respond faster than many smaller retailers when panic buying caused sudden demand surges in 2020
It limits the financial impact of negative events
Planning tools such as insurance and contingency funds can significantly reduce the losses a business suffers if a risk materialises
Example
EasyJet, like many airlines, purchases fuel price hedging contracts in advance, which limits its financial losses when oil prices spike unexpectedly
It protects stakeholders
Employees, customers, suppliers and shareholders all benefit from a business that is resilient to shocks, rather than one that is exposed and unstable
It supports better strategic decision-making
Understanding the level of risk involved helps managers judge which opportunities are genuinely worth pursuing
It builds stakeholder and investor confidence
Lenders and investors are more likely to support a business that can clearly demonstrate it has properly assessed and planned for risk
Example
Unilever's consistent and credible approach to risk management has helped it maintain a strong credit rating, giving lenders confidence and keeping its cost of borrowing relatively low
It protects long-term competitiveness
A business that has planned for risk is often better placed to recover from a crisis than a less-prepared rival
Types of risk
Businesses face several distinct categories of risk, each arising from a different part of the business or its environment
Recognising which type of risk a business is facing helps managers judge the right way to plan for it
The main types of risk

Financial risk
The risk of losses relating to a business's finances, such as cash flow problems, rising borrowing costs, or falling demand
Example
Persimmon and other UK housebuilders saw profits fall sharply as rising interest rates in 2022 to 2023 reduced mortgage affordability and buyer demand
Strategic risk
The risk that a major strategic decision, such as a new product launch or market entry, fails to deliver the results expected
Example
Quibi, a short-form video streaming service, raised $1.75 billion but shut down within six months of its 2020 launch, after seriously misjudging consumer demand for its format
Operational risk
The risk of disruption to a business's day-to-day production or service delivery, for example through equipment failure or supply chain problems
Example
The global semiconductor shortage of 2021 to 2022 forced Ford into a temporary factory shutdown, as they could not obtain enough microchips to complete vehicle production
Compliance risk
The risk of failing to meet legal, regulatory or industry standards, potentially resulting in fines, legal action or a loss of licence to operate
Example
Volkswagen's 2015 'Dieselgate' scandal, in which the company installed software to cheat emissions tests, resulted in fines and settlements exceeding $30 billion worldwide after the fraud was discovered
Reputational risk
The risk of damage to a business's public image or brand, which can occur even without a direct financial or legal failure
Example
United Airlines' market value fell by around $1.4 billion within days of footage in 2017 showing a passenger being forcibly removed from an overbooked flight, despite no laws having been broken
Cybersecurity risk
The risk of a business's data or systems being compromised through hacking, ransomware or other cyberattacks
Example
The 2023 MOVEit software breach saw hackers exploit a security vulnerability to steal employee data from hundreds of organisations worldwide, including British Airways and the BBC
Case Study
Swiftlink Couriers
Swiftlink Couriers is a mid-sized UK parcel delivery company operating a fleet of vans across three regions.
Rising fuel prices and interest rates had already reduced its profit margins, so when a cyberattack disrupted its booking and tracking systems for four days, the business had no contingency plan in place to keep taking orders manually, leading to a significant backlog and a wave of customer complaints on social media.
Around the same time, an employment tribunal ruled that several of Swiftlink's drivers, previously treated as self-employed, should have been classed as workers entitled to holiday pay, resulting in a costly compliance bill.
Recognising it had been caught out on several fronts at once, management introduced a formal risk register covering financial, operational, compliance, reputational and cybersecurity risks, alongside a written contingency plan for system outages.
It also obtained dedicated cyber insurance. When a second, smaller cyberattack occurred the following year, staff switched to the backup manual booking process within hours, and the financial and reputational damage was far smaller than before.
Examiner Tips and Tricks
When a case study describes a negative event affecting a business, always try to identify which specific type of risk it represents. For example distinguishing operational risk from reputational risk, rather than describing the problem only in general terms
Unlock more, it's free!
Was this revision note helpful?