intermediate 3 min answer

A risk register holds 34 risks scored on a 5x5 likelihood-by-impact grid. The top six are funded this year and the other 28 are "monitored". Six of the monitored risks describe different systems failing when the corporate identity provider is unavailable. Review the register. What would you change?

risk-registercommon-causecorrelationquantificationprioritisation
Show the full answer Hide the answer

What the register actually says

Six entries scored independently, each landing around 3x3 = 9, sit below a funding line drawn at 15. The grid has no way to express that they are one event. Multiplying likelihood by impact treats every row as a separate coin flip, so a single failure that costs six times the impact of any one row is ranked as six medium risks and funded as none.

Work the arithmetic to see the size of the error. If the six were genuinely independent at a 2% annual chance each, the chance of at least one firing in a year is 1 - 0.98^6, about 11%, and you would expect one moderate loss. Because they share a cause, it is one event with roughly a 2% chance and six times the loss — much rarer, much larger, and completely differently treated. Ranking by expected loss alone still hides it: the expected values are similar, and the distributions are not.

What I would change

  1. Add a dependency field and group by it. A register that cannot answer "which entries share a cause" is a list, not a model. Grouping is a half-day of work and immediately re-ranks the list.
  2. Score the group, not the rows. One entry: "corporate identity provider unavailable for more than 30 minutes", with the combined impact and the systems it takes down. It clears the funding line on its own.
  3. Express the two worst entries as a loss range rather than a colour. "£0.4M to £3M, most likely £1.1M" makes the mitigation arguable on cost. A single-sign-on break-glass path costing £120k either clears that bar or it does not, and the conversation is now finite.
  4. Record what each score assumes. Most disagreement between two scorers is not judgement, it is that they are scoring different events at different durations.

What I would leave alone

The 28 monitored risks and their crude scores. Rescoring everything quantitatively is a project that eats a quarter and changes no decision; the value of a coarse grid is that it is cheap enough to be done at all. Leave the long tail coarse and spend the effort on the groups above the line. Also leave the register's owner column alone if it is populated — an owned bad estimate beats an unowned good one, because only the owner can authorise the mitigation.

The failure this prevents

The characteristic incident is not a surprise risk. It is an organisation discovering during an outage that five separate mitigations it had bought all routed through the thing that failed — the same identity provider, the same certificate authority, the same region, the same on-call rota. The register said the risks were diversified. It had never been asked the question.

When this is the wrong level of rigour

A twenty-person company does not need a register with 34 rows and loss distributions. A single page listing the five things that would end the business, each with a named owner and the next action, beats any grid. Quantification earns its cost when there is real money to allocate between competing mitigations, and when someone senior will actually change a decision based on the ranking. If the output is a slide, keep it cheap.