How would you decide which of twenty identified risks to actually address?
Show the full answer Hide the answer
What is being tested
Whether you produce a ranked, owned, decided list rather than a register.
The method
1. Estimate likelihood and impact, quantitatively where possible. A probability and a monetary range beats high/medium/low, because it forces explicit assumptions and makes risks comparable to the cost of mitigating them.
The objection that the inputs are uncertain is true and does not favour the qualitative approach — a range with stated uncertainty is more honest than a colour, and everything drifts to medium on a matrix.
2. Rank by expected cost — probability times impact.
3. Compare each against the cost of mitigation. A risk costing £50,000 in expectation and £200,000 to mitigate should be accepted, explicitly. That comparison is only possible if both are numbers.
4. Apply the risk appetite. Which risks are outside what the organisation has said it will tolerate? That question invites a decision; a list of risks invites acknowledgement.
5. Decide each one: mitigate, accept, transfer, avoid. Explicit acceptance is a legitimate and under-used outcome — far better than an unaddressed finding sitting in a register.
6. Record the assumption behind each acceptance, so it can be revisited when conditions change.
What makes the output actionable
- Every risk has a named owner, not a team.
- Mitigations become work items with the same visibility as features. An assessment whose output is a document changes nothing, and everyone involved knows it.
- Accepted risks have a review date.
The two categories that jump the queue
Risks with an external deadline — a component leaving support, a regulatory date. The timing is not yours to negotiate.
Risks where the mitigation is cheap. A low-probability risk that costs a day to remove should be removed regardless of ranking; the ranking exists to allocate scarce effort.
The common failures
An annual exercise producing a register nobody reads. Everything rated medium. Cataloguing without owners or decisions. And treating the number as the output rather than the ranking and the conversation that produced it.