Risk Assessment Methods
Qualitative matrices, FAIR and scenario analysis, and the illusion of a precise score.
4 to work through
-
intermediate
A risk register holds 34 risks scored on a 5x5 likelihood-by-impact grid. The top six are funded this year and the other 28 are "monitored". Six of the monitored risks describe different systems failing when the corporate identity provider is unavailable. Review the register. What would you change?
3 min answer -
intermediate
How would you decide which of twenty identified risks to actually address?
2 min answer -
advanced
Which risk assessment approach fits a technical architecture review, and where do the common methods go wrong?
1 min answer -
advanced
Your main transactional database runs a version that goes out of vendor support in four months. Upgrading needs an estimated eight engineer-weeks and a maintenance window the business does not want to give. The CTO asks you to recommend whether to accept the risk for another twelve months. Talk me through how you would decide.
2 min answer
3 terms in this topic
Common-Cause Risk
Several separately scored risks that all fire on the same underlying event, so a register scoring them independently ranks one large loss as a set of…
practiceQuantified Risk Estimate
Expressing a risk as a probability distribution over financial loss rather than as a colour, which makes risks comparable and mitigations arguable on cost.
practiceRisk Assessment Methods
Structured ways to identify and prioritise what could go wrong — where the value is the conversation and the ranking, not the number.
Neighbouring topics
Assurance, Audit & Model Risk
General material on assurance, architectural governance and risk oversight.
Control Design vs Operation
A control that is well designed and never runs fails exactly like one that is absent.
Audit Evidence
Producing durable, tamper-evident proof as a by-product rather than as a project.
Certification Impact on Architecture
What SOC 2 and ISO 27001 actually require of a design, and what they do not.
Continuous Controls Monitoring
Testing controls continuously instead of sampling them once a year.
Segregation of Duties
Splitting authority so no single actor can both make and approve a change.
Change Advisory vs Automated Gates
Replacing a weekly board with evidence a machine produces on every change.
Risk Appetite
The stated tolerance that tells you which risks you are allowed to accept.
Security Design Review
Reviewing an architecture for security while changing it is still cheap.
Architecture Compliance Checks
Automating conformance to standards so review effort goes to the genuinely novel.
Exception & Waiver Management
Time-boxed, owned deviations with a remediation date, rather than permanent silence.
Design Authority
How an ARB should decide, what it should not review, and how it avoids becoming a queue.
Three Lines Model
Ownership, oversight and independent assurance, and where architecture sits in it.
Model Risk Management
Inventory, validation, monitoring and challenge for models that make consequential decisions.
AI Risk Tiering
Classifying a use case by potential harm, and the obligations each tier triggers.
Model Documentation
Model cards, intended use, limitations, and the record a regulator will ask for.
Model Evaluation & Red-Teaming
Adversarial testing of a probabilistic system with no fixed expected output.
Bias & Fairness Controls
Measuring disparate outcomes, choosing a fairness definition, and living with the trade-off.
Human-in-the-Loop Design
Meaningful review rather than a rubber stamp, and designing against automation bias.