Risk assessment brings structure to judgment. It usually combines qualitative scales, available data, specialist knowledge, control information, and scenario thinking. Its purpose is to support decisions, not manufacture certainty.
Separate inherent and residual exposure
Inherent risk describes exposure before considering controls. Residual risk describes what remains after current controls are considered. Keeping them separate shows both the underlying challenge and the reliance placed on controls.
Define scales before scoring
Words such as “likely” or “major” should have agreed definitions. Likelihood may use frequency ranges or descriptive conditions. Impact should reflect relevant objectives, such as service, safety, schedule, finance, obligations, or reputation.
Assess control strength
A control should be evaluated for design and operation. A well-designed control can still fail if it is not performed, documented, staffed, tested, or supported by reliable information.
Document confidence
Two risks with the same score may require different decisions if one assessment has strong evidence and the other relies on uncertain assumptions. Record confidence, data limitations, and conditions that could change the result.
Useful outputs
- Prioritized risks
- Rationale for ratings
- Existing controls and gaps
- Assigned owners
- Treatment decisions and deadlines
- Escalation or acceptance decisions
- Review triggers
Separate evidence from judgment
An assessment should show what is known, what is estimated, and what is assumed. Historical incidents, control tests, supplier performance, schedule data, and subject-matter input may all be useful, but they have different strengths and limitations. Recording the evidence basis makes later review more meaningful and prevents a score from appearing more certain than the underlying information.
Inherent and residual views
Teams sometimes assess exposure before controls, after current controls, and after planned treatment. These views can help explain why a heavily controlled activity still deserves attention. They should not be mixed without clear labels. A residual score is only credible when the effectiveness of the controls behind it has been considered rather than assumed.
Assessment review questions
- Are likelihood and impact timeframes clear?
- Have multiple consequence types been considered?
- Are dependencies and correlated risks visible?
- What evidence would change the rating?
- Who has authority to challenge or accept the conclusion?