Risks do not exist in a vacuum; they are always associated with the objectives being pursued. All modern methodologies define risks as potential events that can create uncertainty or compromise the achievement of objectives.
For example, if we are analyzing the objective of protecting raw materials in a warehouse, one of the risks we will need to consider is fire. However, if the objective is to prevent unauthorized access to information on a server, this will not be an event that concerns us. Therefore, fire, as well as any other event or hazard, should only be considered a risk if it can directly affect the achievement of one of the objectives included in the analysis.
Risks do not exist in a vacuum; they are always associated with the objectives being pursued. All modern methodologies define risks as potential events that can create uncertainty or compromise the achievement of objectives.
For example, if we are analyzing the objective of protecting raw materials in a warehouse, one of the risks we will need to consider is fire. However, if the objective is to prevent unauthorized access to information on a server, this will not be an event that concerns us. Therefore, fire, as well as any other event or hazard, should only be considered a risk if it can directly affect the achievement of one of the objectives included in the analysis.
Any risk assessment in RiskScribe begins with the definition of objectives.
At all times during the use of the platform and in any generated report, a risk is never presented without associating it with its corresponding objective.
The first step in any risk assessment is to identify the risks relevant to the selected objectives.
Various techniques can be applied, but the two most reliable sources are typically the individuals directly involved in processes or tasks related to the objectives, and practical frameworks or guidelines specifically tailored to those objectives.
The first step in any risk assessment is to identify the risks relevant to the selected objectives.
Various techniques can be applied, but the two most reliable sources are typically the individuals directly involved in processes or tasks related to the objectives, and practical frameworks or guidelines specifically tailored to those objectives.
This stage is often one of the most difficult, especially when risk management practices are newly implemented or are being distributed throughout the organization. Despite any training that may have been received, the first time a process or team leader is asked to identify the risks for their objectives, having a blank page can be quite intimidating and a significant barrier to the process.
RiskScribe provides three key elements to eliminate this problem:
Once a reasonable list of risks is available, the next step is to evaluate each one. Naturally, not all risks will generate the same level of concern, and the key is to identify which risks are considered acceptable (unfortunately, completely eliminating risks is impossible), those that can be managed but require additional attention and monitoring to ensure they remain at that level and, finally, those that are deemed unacceptable and require corrective actions.
Intuitively, there are two dimensions that affect how concerning a risk can be. The first is probability, that is, what is the real chance that this risk will become an incident. For example, if our objective is to walk from our home to the office, two of the risks on our list might include being the victim of a traffic accident and being the victim of an air accident – of course, the first will worry us much more than the second, which is why since childhood we are taught to look both ways before crossing a street, but not necessarily to look up.
The second dimension is impact, that is, how severe the consequences will be if the risk turns into an incident. Continuing with our traffic example, if we now consider being the victim of a robbery, we will certainly be less worried if we are carrying a small amount of cash than if we are transporting higher-value items such as a computer or a cell phone.
In a formal risk assessment, these two categories are used with the only difference being the need to ensure that the analysis is as objective as possible and does not heavily depend on the analyst's personal perspective. For this purpose, it is common to define probability and impact tables that describe what the organization understands, for example, as a high probability or a low impact.
Once a reasonable list of risks is available, the next step is to evaluate each one. Naturally, not all risks will generate the same level of concern, and the key is to identify which risks are considered acceptable (unfortunately, completely eliminating risks is impossible), those that can be managed but require additional attention and monitoring to ensure they remain at that level and, finally, those that are deemed unacceptable and require corrective actions.
Intuitively, there are two dimensions that affect how concerning a risk can be. The first is probability, that is, what is the real chance that this risk will become an incident. For example, if our objective is to walk from our home to the office, two of the risks on our list might include being the victim of a traffic accident and being the victim of an air accident – of course, the first will worry us much more than the second, which is why since childhood we are taught to look both ways before crossing a street, but not necessarily to look up.
The second dimension is impact, that is, how severe the consequences will be if the risk turns into an incident. Continuing with our traffic example, if we now consider being the victim of a robbery, we will certainly be less worried if we are carrying a small amount of cash than if we are transporting higher-value items such as a computer or a cell phone.
In a formal risk assessment, these two categories are used with the only difference being the need to ensure that the analysis is as objective as possible and does not heavily depend on the analyst's personal perspective. For this purpose, it is common to define probability and impact tables that describe what the organization understands, for example, as a high probability or a low impact.
RiskScribe makes the evaluation of identified risks as simple as selecting the estimated levels of probability and impact for each risk. The analyst receives continuous assistance, seeing the definitions from the probability and impact table being used as they select categories, minimizing both conceptual and operational errors on the platform.
Two complete probability and impact tables with multiple internal dimensions are provided by default (one for simplified evaluations and another representing a standard typically used in organizations of any size), but it is also possible to define entirely custom tables to represent the organization's specific view on risks. This is particularly useful for organizations with a higher level of maturity or those that need to use criteria provided by a parent company, business partner, or regulator.
One problem with evaluating risks in two dimensions is that it makes it difficult to rank them by level of concern – for example, which is considered worse, a risk with low probability and high impact or one with high probability but lower impact?
To address this, the concept of exposure is introduced, which is simply a numerical value representing the level of concern, as a formula linking probability and impact.
At this point, the concepts of inherent and residual exposure are also introduced. Inherent exposure represents the level of risk if no actions are taken, whereas residual exposure reflects the actual risk level, factoring in the controls already implemented to mitigate it. For example, the usual action of looking both ways before crossing a street is a control that clearly reduces the probability of an accident from a potentially high level (which would depend solely on the traffic level of the street) to a very low level.
A reasonable question is why conduct this analysis separately, when in practice the risk we care about —whether it's acceptable, requires attention, or is unacceptable— is the residual risk? The answer is that this type of analysis provides very relevant information about the controls we have implemented. In particular, if the inherent exposure is unacceptable but the residual exposure is not, it means that the controls we have in place are critical, meaning that if those controls fail, the level of risk we are exposed to is excessive.
When an adult intuitively ensures that a child has learned to look both ways before allowing them to walk alone on the street, they are doing exactly what an organization should do with its critical controls: monitor their effectiveness over time.
One problem with evaluating risks in two dimensions is that it makes it difficult to rank them by level of concern – for example, which is considered worse, a risk with low probability and high impact or one with high probability but lower impact?
To address this, the concept of exposure is introduced, which is simply a numerical value representing the level of concern, as a formula linking probability and impact.
At this point, the concepts of inherent and residual exposure are also introduced. Inherent exposure represents the level of risk if no actions are taken, whereas residual exposure reflects the actual risk level, factoring in the controls already implemented to mitigate it. For example, the usual action of looking both ways before crossing a street is a control that clearly reduces the probability of an accident from a potentially high level (which would depend solely on the traffic level of the street) to a very low level.
A reasonable question is why conduct this analysis separately, when in practice the risk we care about —whether it's acceptable, requires attention, or is unacceptable— is the residual risk? The answer is that this type of analysis provides very relevant information about the controls we have implemented. In particular, if the inherent exposure is unacceptable but the residual exposure is not, it means that the controls we have in place are critical, meaning that if those controls fail, the level of risk we are exposed to is excessive.
When an adult intuitively ensures that a child has learned to look both ways before allowing them to walk alone on the street, they are doing exactly what an organization should do with its critical controls: monitor their effectiveness over time.
RiskScribe automatically calculates the exposure and level of risks (acceptable, attention, or unacceptable) based on the data included in the probability and impact tables, allowing the analyst to immediately see the inherent and residual levels as the evaluation progresses.
All controls that reduce inherent exposure to residual exposure are documented within the tool, and critical controls are automatically listed as part of the generated report.
For purposes of defining the exposure formula, RiskScribe uses a weighted sum of probability and impact so that the organization can flexibly define its risk perspective. These tables are configured through a visual interface allowing users to easily see which levels of probability and impact will generate the risk levels, which is essential for making the tables represent a true risk vision instead of just being numerical values without any significant meaning.
For example, it is common to see symmetrical exposure formulas (probability x impact is sadly popular in risk literature) that fail to recognize that probability and impact should rarely be treated the same way in an exposure calculation. Clearly, a very low probability and a very high impact (a black swan with the potential to cause significant damage or directly put an organization out of business) is not equally concerning as a very high probability but a very low impact (an event that occurs regularly but with an impact that is virtually imperceptible).
The default tables provided by RiskScribe already take this into account, giving more weight to impact than to probability in the calculation.
Once all risks have been properly evaluated, the final step is to define necessary or desirable actions based on the evaluation conducted.
In particular, any risk deemed unacceptable should be addressed by an Action Plan aimed at mitigating it in some way. There are different options here, from avoiding the risk (ceasing the activities that cause the risk, although this will naturally not always be possible), sharing it (for example, through insurance or agreements with third parties), or the most common actions, which are implementing new preventive controls (to reduce the probability of the risk) or contingency controls (to reduce its impact if it becomes an incident).
An Action Plan should also generally include any other relevant actions that are part of Risk Management, such as establishing monitoring procedures to track risks at an attention level and to verify that the critical controls identified remain effective over time.
Once all risks have been properly evaluated, the final step is to define necessary or desirable actions based on the evaluation conducted.
In particular, any risk deemed unacceptable should be addressed by an Action Plan aimed at mitigating it in some way. There are different options here, from avoiding the risk (ceasing the activities that cause the risk, although this will naturally not always be possible), sharing it (for example, through insurance or agreements with third parties), or the most common actions, which are implementing new preventive controls (to reduce the probability of the risk) or contingency controls (to reduce its impact if it becomes an incident).
An Action Plan should also generally include any other relevant actions that are part of Risk Management, such as establishing monitoring procedures to track risks at an attention level and to verify that the critical controls identified remain effective over time.
RiskScribe provides functionalities to add specific actions to any risk assessment, defining both the responsible parties and the expected start and end dates of the plan.
The details of each action can include standard formatting to simplify reading, and it is also possible to include any type of links, considering that most organizations already have tools to define and track actions.
The final report provided by the platform for a risk assessment includes every component: the list of all objectives, risks and controls with their inherent and residual evaluations, the main risks ranked by exposure, the critical controls identified, the criteria used for the evaluation, and the complete Action Plan. Since this reported is generated in PDF format, it can be easily distributed even among people without direct access to the platform or who are only interested in a summary of the results of the risk evaluation.