Pillars of Risk Management Risk Assessment

0
0
Hire Risk Expert
You agree to our Terms and Conditions of Use, PDPA & Privacy Policy and Cookies Policy

Pillars of Risk Management Risk Assessment

RISK ASSESSMENT: HOW WE MAKE UNCERTAINTY MORE UNDERSTANDABLE

RISK ASSESSMENT AS ONE OF THE PILLARS OF RISK MANAGEMENT

On the main Pillars of Risk Management page, we explained that Risk Management is not simply about stopping people from taking risks. At its best, it helps us understand uncertainty from different angles before deciding what to do. We also made the point that this kind of thinking is better done upfront rather than in hindsight.

Risk Assessment sits at the centre of that idea.

It differs from most of the other Pillars because it is not a particular category of risk. Technology Risk, Cyber Risk and Third-Party Risk describe different kinds of exposure. Risk Assessment is one of the core processes we use to examine those exposures. It helps us move from a general feeling that something may be risky towards a clearer understanding of what could happen, why it might happen, how serious the consequences could be, what controls already exist and whether the remaining exposure is acceptable.

This is why Risk Assessment appears again and again across the other Pillars. We can perform a Technology Risk Assessment, a Cyber Risk Assessment, a Third-Party Risk Assessment or an Enterprise Risk Assessment. Business Continuity uses risk assessment when considering possible disruptions. Operational Resilience uses it when examining vulnerabilities and dependencies. Governance & Compliance may use it to determine where controls or obligations create greater exposure. The subject changes, but the underlying thought process remains recognisable.

In that sense, Risk Assessment is less like another box in the Risk Management structure and more like one of the connecting tools that helps the other Pillars work.

WHAT IS A RISK ASSESSMENT?

A Risk Assessment is the process of understanding what could affect an objective, examining the possible causes and consequences, considering the controls or safeguards already in place and deciding whether the remaining risk is acceptable or whether something more should be done.

For someone new to Risk Management, the simplest version may be even more useful: What am I trying to achieve? What could affect it? How serious could the outcome be? What have I already done about it? Am I comfortable proceeding?

People already perform informal versions of Risk Assessment in everyday life. A person deciding whether to drive during severe weather considers road conditions, urgency, experience and alternatives. A small-business owner considering a new supplier thinks about reliability, price, quality and what happens if the supplier fails. An entrepreneur deciding whether to open another outlet may consider how much money is required, how certain demand is and whether the existing business can absorb the loss if the expansion does not go as planned.

They may not call any of this Risk Assessment. But the underlying thought process is there.

WHY DID RISK ASSESSMENT DEVELOP?

Risk Assessment developed from a very old human need: we need some way to judge uncertainty before we act.

People have always had to decide whether a journey was worth taking, whether an investment was worth making, whether a person could be trusted or whether the potential benefit of an action justified the possible loss.

As businesses and organisations became more complex, these judgements became more formal. It was no longer enough for one person simply to say, “I think this is risky.” Businesses needed ways to compare different exposures, decide which ones deserved attention and explain why a particular decision had been made.

This led to more structured approaches involving risk identification, likelihood, consequence, controls, inherent risk, residual risk and risk treatment. The professional language became more technical, but the purpose remained simple: understand enough about the uncertainty to make a better decision.

WHAT QUESTIONS DID SMALL BUSINESSES ALREADY ASK WITHOUT CALLING THEM RISK ASSESSMENTS?

Small-business owners have always performed versions of Risk Assessment.

A retailer considering a second outlet may ask whether customer demand is strong enough. A business owner thinking about hiring may ask whether the salary can still be paid if revenue falls. Someone choosing a new technology platform may ask what happens if the provider disappears or raises its prices significantly. A company relying heavily on one supplier may ask what happens if that supplier can no longer deliver.

Today, the questions may sound very different. A business owner may ask whether employees should be allowed to use A.I. with company information, whether an A.I. output is reliable enough to support a decision, or what happens if staff become dependent on a tool that later becomes unavailable.

These are modern questions, but they are still Risk Assessment questions because the person is trying to understand uncertainty before deciding what to do.

WHAT TOOLS CAN A SMALL BUSINESS USE FOR RISK ASSESSMENT?

A small business does not need to begin with a complicated quantitative model. The most useful tool is the one that helps the decision-maker understand the problem more clearly.

A simple checklist can help make sure that important areas such as people, customers, money, technology, suppliers and legal obligations are considered before a decision is made. A risk matrix can help compare likelihood and consequence across several risks. A scenario analysis can explore different possible futures when the outcome is uncertain. A process map can reveal where a business depends too heavily on one person, system or supplier.

bow-tie analysis can be useful where a business wants to understand how causes, preventive controls, an event, consequences and recovery controls fit together. A cost-benefit analysis may help decide whether an additional safeguard is worth the cost. More experienced practitioners may also use sensitivity analysis, FMEA, fault-tree analysis, decision trees, stress testing or quantitative simulation.

The point is not to use every tool. It is to select a method that helps answer the question in front of us.

WHAT ARE INHERENT RISK AND RESIDUAL RISK?

Two terms appear frequently in professional Risk Management: inherent risk and residual risk.

Inherent risk generally refers to the exposure before taking controls into account. Residual risk is what remains after those controls or safeguards are considered.

Suppose a small business stores customer information online. The inherent exposure may include unauthorised access, loss or misuse. Controls such as strong authentication, restricted access, backups and monitoring reduce that exposure. What remains after those controls are considered is the residual risk.

The value of this distinction is not simply that it produces two ratings. It helps us ask whether the controls are actually reducing the risk in a meaningful way.

For experienced practitioners, this raises a deeper question: are we assessing whether a control works, or merely recording that the control exists? A policy, for example, may be listed as a control, but if employees routinely ignore it, its actual effectiveness may be much weaker than the documentation suggests.

This is where Risk Assessment begins to connect with Human Behaviour.

IS THE RISK MATRIX STILL USEFUL?

The risk matrix remains one of the most familiar Risk Assessment tools because it gives people a common way to compare likelihood and consequence. It can be extremely useful, particularly when several risks need to be prioritised.

But the matrix also has limitations.

Two people can assess the same risk and arrive at very different likelihood ratings. Both may have reasonable arguments. The numbers make the assessment look precise, but the underlying judgement may still be subjective.

This becomes more important when assessing new or emerging risks. Historical information may be available for a mature process. Much less evidence may exist for a new A.I. agent, an unfamiliar technology or a geopolitical event that has not occurred in quite the same way before.

The matrix can still organise the discussion, but it does not make the uncertainty disappear. This is why practitioners increasingly supplement conventional ratings with scenario analysis, stress testing, sensitivity analysis, ranges and more explicit discussion of assumptions.

The deeper questions about probability, false precision and uncertainty belong under The Science of Risk, where the assumptions behind these tools can be explored further.

HOW DOES RISK ASSESSMENT CONNECT WITH TECHNOLOGY RISK?

Technology Risk uses Risk Assessment to understand what could happen when technology fails, changes, becomes unavailable or produces unintended consequences.

A small business considering a cloud platform may assess what information will be stored there, how dependent the business will become, what happens during an outage and whether another provider could be used.

The Technology Risk page explores technology dependencies, system lifecycle, cloud services and emerging technologies in greater depth. Risk Assessment provides one of the core methods used to evaluate those exposures.

The connection is direct.

HOW DOES RISK ASSESSMENT CONNECT WITH CYBER RISK?

Cyber Risk also relies heavily on Risk Assessment.

A Cyber Risk Assessment may consider which systems or information need protection, what threats exist, which vulnerabilities might be exploited, what controls are in place and what the consequences could be if an attack succeeds.

Cyber Risk adds specialist techniques such as threat modelling, vulnerability assessment and penetration testing, but these ultimately feed into the wider Risk Assessment question: how much exposure remains, and is it acceptable?

Again, Risk Assessment is not replacing Cyber Risk. It is one of the methods used inside it.

HOW DOES RISK ASSESSMENT CONNECT WITH ENTERPRISE RISK?

Enterprise Risk Management uses Risk Assessment to build a broader picture of uncertainty across the business.

Individual risks are identified and assessed, but ERM then asks how those risks compare, whether they are connected, whether several exposures share the same dependency and what they mean collectively for the business.

Risk Assessment therefore provides much of the input. Enterprise Risk Management provides the enterprise-wide view.

That is why the two are closely related but not the same.

IS RISK ASSESSMENT PART OF BUSINESS CONTINUITY?

Risk Assessment is used in Business Continuity, but it does not belong exclusively to Business Continuity.

Business Continuity may use Risk Assessment to identify disruption scenarios, vulnerabilities and dependencies that could interrupt important activities. But it also uses other tools that answer different questions, particularly Business Impact Analysis, recovery objectives, continuity strategies and Business Continuity Plans.

A Risk Assessment asks what could happen, why it could happen, what the consequences might be and what controls exist. A Business Impact Analysis asks something different: what happens to the business as time passes after an activity has been disrupted, and how quickly does that activity need to be restored?

The two tools complement one another.

So Risk Assessment is certainly part of Business Continuity work, but it is equally relevant to Technology Risk, Cyber Risk, Third-Party Risk, Enterprise Risk and many other areas. That is why it makes sense as a separate Pillar.

HOW DOES RISK ASSESSMENT CONNECT WITH OPERATIONAL RESILIENCE?

Operational Resilience uses Risk Assessment to identify vulnerabilities that could prevent an important service from continuing during disruption.

Risk Assessment may identify technology failure, supplier concentration, key-person dependency or cyberattack as significant exposures. Operational Resilience then goes further by considering what happens to the service when those disruptions actually occur.

Risk Assessment helps identify and evaluate the vulnerability. Operational Resilience asks whether the service can withstand, adapt to and recover from it.

The connection is strong, but the two have different jobs.

HOW DOES RISK ASSESSMENT CONNECT WITH THIRD-PARTY RISK?

Third-Party Risk uses Risk Assessment to decide how much exposure a supplier, platform, contractor or service provider creates.

A small business may consider what the third party does, what information it receives, how easily it can be replaced, what happens if it fails and whether alternatives exist. That assessment can then determine how much due diligence, monitoring or contractual protection is appropriate.

This helps keep Third-Party Risk proportionate. A company supplying office stationery should not automatically receive the same level of assessment as a provider storing all customer information.

Risk Assessment is therefore one of the tools that allows Third-Party Risk to focus effort where the dependency actually matters.

HOW DOES RISK ASSESSMENT CONNECT WITH GOVERNANCE & COMPLIANCE?

The relationship with Governance & Compliance is important but needs to be handled carefully.

Governance determines who owns decisions, who is accountable and how oversight works. Compliance identifies obligations and whether the organisation is operating within them.

Risk Assessment can help identify where governance or compliance weaknesses create greater exposure and where controls deserve more attention. A compliance-risk assessment, for example, may help an organisation prioritise where breaches could cause more significant consequences.

But Risk Assessment cannot turn a mandatory legal obligation into an optional one simply because someone considers the likelihood of enforcement low.

That distinction is important. Risk Assessment can help prioritise effort, but some obligations simply have to be met.

HOW HAS RISK ASSESSMENT CHANGED?

Risk Assessment has had to evolve because the world being assessed has changed.

Traditional assessments were often periodic. A business might review its risks annually or when making a major decision. Some risks now move far more quickly. Cyber threats can change rapidly. Employees may adopt a new A.I. tool before management knows it exists. Regulation can evolve quickly. Geopolitical developments can alter supply chains within days, while misinformation can spread in hours.

The world has also become more interconnected. A technology failure may affect a supplier, which affects customer service, which affects reputation and cash flow. This makes one-risk-at-a-time thinking less useful in some situations.

Remote work, freelancing, outsourcing and platform dependence also mean that exposures increasingly cross organisational boundaries. Demographic change creates additional questions around ageing workforces, knowledge transfer, skills shortages and changing consumer behaviour.

COVID-19 demonstrated another problem particularly clearly: major events do not necessarily create one risk at a time. Several disruptions can arrive together.

Risk Assessment therefore increasingly needs to consider speed, interconnectedness, uncertainty and combinations of events, not only individual risks viewed in isolation.

WHAT ARE RISK PRACTITIONERS BEGINNING TO USE OR ADAPT NOW?

Traditional Risk Assessment is not disappearing. Practitioners are increasingly supplementing it with tools that work better where uncertainty is high or conditions change quickly.

Scenario analysis allows people to explore several plausible futures rather than predict one. Stress testing examines how the business performs under difficult conditions, while reverse stress testing begins with a serious outcome and asks what combination of circumstances could cause it.

Dependency mapping helps identify risks that share common causes. Bow-tie analysis connects causes, controls, events and consequences. KRIs and continuous indicators can provide warning when exposure changes between formal assessment cycles.

Horizon scanning and emerging-risk watch lists are also becoming more important because sometimes the issue is not yet mature enough to assess formally.

For more complex situations, practitioners may also use quantitative simulations, data analysis and other analytical techniques. A.I. can assist by searching large quantities of information, generating scenarios, summarising incidents or identifying possible relationships.

But faster analysis does not automatically mean better analysis. The evidence still needs to be verified, assumptions still need to be challenged and professional judgement still matters.

HOW IS A.I. CHANGING RISK ASSESSMENT?

A.I. changes Risk Assessment in two directions.

First, A.I. itself needs to be assessed. A traditional Technology Risk Assessment might concentrate on availability, security and recovery. An A.I. assessment may also need to consider output reliability, hallucinations, data access, intended use, human oversight, bias, autonomy and what happens when someone relies on an incorrect answer.

This makes Risk Assessment more use-case specific.

An A.I. tool used to draft an internal memo does not necessarily create the same exposure as an A.I. system supporting an investment, employment or medical decision.

This is why practitioners are increasingly considering A.I. inventories, use-case classification, impact assessments, testing, red teaming, human-oversight assessment and continuous monitoring.

Second, A.I. can become a Risk Assessment tool itself. It can assist with scenario generation, document review, incident analysis and the organisation of information.

But that creates another Risk Assessment question in return: what happens if the A.I. assessment is wrong?

The tool can improve efficiency. It does not remove the need for verification.

HOW DO SIGNALS CHANGE THE WAY WE THINK ABOUT RISK ASSESSMENT?

Signals helps define an important boundary.

Risk Assessment usually begins once we have identified something that may affect an objective. But sometimes we are not yet at that stage. We may simply notice a new technology emerging, a political situation deteriorating, a regulatory proposal developing or customer behaviour changing.

At that point, we may not have enough evidence to assign a meaningful likelihood and consequence score.

Trying to force every weak signal into a risk matrix can create false confidence.

The more appropriate tools may initially be horizon scanning, watch lists, emerging-risk radars and scenario exploration. If the issue develops and becomes sufficiently relevant, it can then move into formal Risk Assessment.

This creates a natural progression:

Observe → Verify → Interpret → Assess → Decide → Monitor.

This is why Signals can sit before conventional Risk Assessment.

WHAT RISK ASSESSMENT QUESTIONS ARE PEOPLE ASKING NOW?

People rarely begin by asking for a formal Risk Assessment methodology. They ask the question they are actually trying to answer.

A small-business owner may ask whether A.I. should be used in the business. An entrepreneur may ask whether now is the right time to expand. Someone may ask whether a new supplier can be trusted. Another may ask how to prepare for something that cannot be predicted.

These questions connect to different parts of the website—A.I. & Risk, Decision Making, Third-Party Risk, Signals, Business Continuity and Operational Resilience—but Risk Assessment frequently provides part of the underlying thought process.

Someone may also ask, “How do I know whether this risk is serious enough to act on?”

That is perhaps the most fundamental Risk Assessment question of all.

The language changes, but the underlying thought remains the same: what do I know, what do I not know, what could happen, and is that enough for me to make a decision?

WHICH NEWER RISKS MAKE THE EVOLUTION OF RISK ASSESSMENT USEFUL?

Risk Assessment is probably the most transferable of all the Pillars because it can support many of the newer areas on this website.

A.I. & Risk uses Risk Assessment to distinguish low-risk applications from uses requiring stronger controls, testing and oversight. Decision Making relies on similar thinking around assumptions, uncertainty, consequences and alternatives. Human Behaviour becomes relevant because Risk Assessment itself is performed by people who can be influenced by bias, incentives and group dynamics.

Future of Work can use Risk Assessment when considering automation, skills obsolescence or workforce dependency. Trust may require assessment where reputation, misinformation or information integrity creates material exposure. Signals helps determine when something being watched has developed enough to move into formal assessment.

The Science of Risk provides the deeper intellectual layer by asking what likelihood ratings really mean, whether matrices create false precision and how we should think about uncertainty where historical evidence is weak.

The relationship with The Future Human is more selective. A formal Risk Assessment should not be forced onto a broad exploration of human evolution or capability. But where there is a specific decision or exposure, such as adopting a human-enhancement technology, the methodology may become relevant.

That is exactly how we want the website to work: connect where the relationship is genuine and say so when it is not.

RISK ASSESSMENT IS NOT ABOUT PRODUCING A SCORE

Risk Assessment can easily become associated with matrices, forms and red-amber-green ratings. Those tools can be useful, but the score is not the objective.

The objective is to understand enough about the uncertainty to make a better-informed decision.

A beautifully completed risk matrix is of little value if the wrong risk was identified. A residual-risk score is not meaningful if the controls are assumed to work but nobody has tested them. A precise number does not create certainty where the information is weak.

Good Risk Assessment therefore depends on judgement as much as tools. It asks us to consider the objective, challenge assumptions, understand dependencies, examine controls, think about consequences and recognise what we still do not know.

Sometimes the outcome will be to proceed. Sometimes it will be to proceed with safeguards. Sometimes the right answer is to investigate further, wait or not proceed.

Risk Assessment does not make the decision for us.

It gives us a better basis on which to make it.

That is why Risk Assessment differs from many of the other Pillars while still sitting underneath so many of them, and why it remains one of the fundamental Pillars of Risk Management.