Risk Assessment

Risk assessment is where risk management stops being abstract. It is the structured process of identifying what could go wrong, estimating how likely it is and how much it would hurt, and deciding whether the residual exposure is acceptable. Done well it produces decisions; done badly it produces a colour-coded spreadsheet nobody reads.

Every credible assessment rests on three choices you make before you score anything: the scales you use for likelihood and impact, whether you are scoring inherent or residual risk, and who owns the judgement. Get those wrong and the numbers are noise.

This is the largest section on the site, covering qualitative and quantitative methods, risk matrices and their well-documented weaknesses, control effectiveness testing, scenario analysis, and sector-specific assessments from cyber to supply chain. It connects directly to enterprise risk management for the governance layer above it, RCSA for the self-assessment variant used in financial services, key risk indicators for the monitoring that follows an assessment, and risk appetite for the thresholds that decide what "acceptable" actually means.

Receive the latest articles in your inbox