Skip to content

Risk Aggregation

What is Risk Aggregation?

The process of combining individual risks to understand their cumulative effect and total exposure across the organization.

Risk Management

What the standards actually require on risk aggregation

Requirements naming risk aggregation across 3 standards, quoted from the control text.

Lloyds MS11.17 Cyber Risk Quantification and Capital Linkage - cyber risk quantification methodology aligned with PRA Solvency II + Operational Risk Internal Model (where applicable) + standard formula + cyber-specific stressors + scenario analysis (Lloyds Rea...

LLOYDS-MS11-Cyber-Risk-Quantification-Capital-Linkage-Regulatory-Lloyds-Reporting-MS11-17-18-CBEST-FFIEC · Lloyds MS11 Cyber Risk Quantification + Capital + Regulatory + Lloyds Reporting + MS11.17-18

Lloyds Cyber Insurance Requirements - Systemic Cyber Risk Aggregation + Catastrophe Modelling. Lloyds Catastrophe Modelling Standards require all managing agents to: (a) Model Cyber Realistic Disaster Scenarios (Cyber RDS) developed by Lloyds + Cambridge Centr...

LLOYDS-CI-Systemic-Cyber-Risk-Aggregation-Cyber-Catastrophe-Modelling-Vendor-Use-RDS-Scenario-Testing · Lloyds Cyber Insurance Systemic Aggregation + Catastrophe Modelling + RDS

Per NAIC ORSA Guidance Manual Section 3: group risk capital and prospective solvency assessment. Requires Available Capital Assessment per regulatory + economic + rating agency capital measures;

ORSA-S3 · ORSA Manual Section 3: Group Risk Capital and Prospective Solvency Assessment

Questions people ask about risk aggregation

What is Risk Aggregation?
The process of combining individual risks to understand their cumulative effect and total exposure across the organization.
Why is Risk Aggregation important for compliance?
Risk Aggregation is a key concept in Risk Management. Understanding risk aggregation helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Risk Aggregation?
Risk Aggregation appears in the requirement text of Lloyd's Minimum Standards - Cyber Security, Lloyd's of London Cyber Insurance Requirements and Underwriting Standards, Own Risk and Solvency Assessment (ORSA) - NAIC Model Act. Across these standards we have identified 3 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Risk Aggregation?
Explore our compliance framework pages to see how risk aggregation applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Risk Aggregation applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.