practice

Risk Assessment Methods

Structured ways to identify and prioritise what could go wrong — where the value is the conversation and the ranking, not the number.

riskassessmentprioritisationquantificationappetite

Definition

Risk assessment identifies what could go wrong, how likely it is, what it would cost, and what to do about it.

The methods and their limits

Qualitative matrices — likelihood against impact, high/medium/low. Fast, universally understood, and imprecise. Their weakness is that "high" means different things to different people, and everything drifts toward medium.

Quantitative estimation — expressing likelihood as a probability and impact as a monetary range, then combining. Harder, and considerably more useful: it forces explicit assumptions, makes risks comparable to the cost of mitigating them, and produces a number the business can weigh against other numbers.

The objection that the inputs are uncertain is true and does not favour the qualitative approach — a range with stated uncertainty is more honest than a colour.

Structured identification — walking a data flow diagram boundary by boundary and applying threat categories, or examining each dependency and asking what its failure would cost. Systematic beats brainstorming because it is bounded and repeatable.

Pre-mortem — assume the system has failed badly in a year; explain how. Surfaces risks that optimism suppresses, and it works unusually well in a group.

What makes an assessment useful

  • Ranked, with a threshold. Which risks are outside the organisation's stated appetite? That question invites a decision; a list of risks invites acknowledgement.
  • Each risk owned, with a decision: mitigate, accept, transfer, avoid. Explicit acceptance is a legitimate and under-used outcome — far better than an unaddressed finding.
  • Assumptions recorded, so acceptance can be revisited when they change.
  • Mitigations as work items with the same visibility as features. An assessment whose output is a document changes nothing.

The common failures

Assessment as an annual exercise producing a register nobody reads. Everything rated medium. Cataloguing risks without owners or decisions. And treating the number as the output rather than the ranking and the conversation that produced it.

Interview question

"How would you decide which of twenty identified risks to actually address?"