Risk management using RiskScribe

Risk definition

Methodology

RiskScribe

Risks do not exist in a vacuum; they are always associated with the objectives being pursued. All modern methodologies define risks as potential events that can create uncertainty or compromise the achievement of objectives.

For example, if we are analyzing the objective of protecting raw materials in a warehouse, one of the risks we will need to consider is fire. However, if the objective is to prevent unauthorized access to information on a server, this will not be an event that concerns us. Therefore, fire, as well as any other event or hazard, should only be considered a risk if it can directly affect the achievement of one of the objectives included in the analysis.

Risk identification

Methodology

RiskScribe

The first step in any risk assessment is to identify the risks relevant to the selected objectives.

Various techniques can be applied, but the two most reliable sources are typically the individuals directly involved in processes or tasks related to the objectives, and practical frameworks or guidelines specifically tailored to those objectives.

Risk evaluation

Methodology

RiskScribe

Once a reasonable list of risks is available, the next step is to evaluate each one. Naturally, not all risks will generate the same level of concern, and the key is to identify which risks are considered acceptable (unfortunately, completely eliminating risks is impossible), those that can be managed but require additional attention and monitoring to ensure they remain at that level and, finally, those that are deemed unacceptable and require corrective actions.

Intuitively, there are two dimensions that affect how concerning a risk can be. The first is probability, that is, what is the real chance that this risk will become an incident. For example, if our objective is to walk from our home to the office, two of the risks on our list might include being the victim of a traffic accident and being the victim of an air accident – of course, the first will worry us much more than the second, which is why since childhood we are taught to look both ways before crossing a street, but not necessarily to look up.

The second dimension is impact, that is, how severe the consequences will be if the risk turns into an incident. Continuing with our traffic example, if we now consider being the victim of a robbery, we will certainly be less worried if we are carrying a small amount of cash than if we are transporting higher-value items such as a computer or a cell phone.

In a formal risk assessment, these two categories are used with the only difference being the need to ensure that the analysis is as objective as possible and does not heavily depend on the analyst's personal perspective. For this purpose, it is common to define probability and impact tables that describe what the organization understands, for example, as a high probability or a low impact.

Inherent and residual exposure

Methodology

RiskScribe

One problem with evaluating risks in two dimensions is that it makes it difficult to rank them by level of concern – for example, which is considered worse, a risk with low probability and high impact or one with high probability but lower impact?

To address this, the concept of exposure is introduced, which is simply a numerical value representing the level of concern, as a formula linking probability and impact.

At this point, the concepts of inherent and residual exposure are also introduced. Inherent exposure represents the level of risk if no actions are taken, whereas residual exposure reflects the actual risk level, factoring in the controls already implemented to mitigate it. For example, the usual action of looking both ways before crossing a street is a control that clearly reduces the probability of an accident from a potentially high level (which would depend solely on the traffic level of the street) to a very low level.

A reasonable question is why conduct this analysis separately, when in practice the risk we care about —whether it's acceptable, requires attention, or is unacceptable— is the residual risk? The answer is that this type of analysis provides very relevant information about the controls we have implemented. In particular, if the inherent exposure is unacceptable but the residual exposure is not, it means that the controls we have in place are critical, meaning that if those controls fail, the level of risk we are exposed to is excessive.

When an adult intuitively ensures that a child has learned to look both ways before allowing them to walk alone on the street, they are doing exactly what an organization should do with its critical controls: monitor their effectiveness over time.

Action plan

Methodology

RiskScribe

Once all risks have been properly evaluated, the final step is to define necessary or desirable actions based on the evaluation conducted.

In particular, any risk deemed unacceptable should be addressed by an Action Plan aimed at mitigating it in some way. There are different options here, from avoiding the risk (ceasing the activities that cause the risk, although this will naturally not always be possible), sharing it (for example, through insurance or agreements with third parties), or the most common actions, which are implementing new preventive controls (to reduce the probability of the risk) or contingency controls (to reduce its impact if it becomes an incident).

An Action Plan should also generally include any other relevant actions that are part of Risk Management, such as establishing monitoring procedures to track risks at an attention level and to verify that the critical controls identified remain effective over time.

© 2025 - RiskScribe - All rights reserved.
English -