What You Will End Up With
A short risk table that works as the one place where every identified risk is recorded: what the risk is, who owns it and what you will do about it. For the risks that matter most, you will also have a contingent response, the specific actions you will take if the risk event actually happens. Together they show a reviewer that you have looked ahead and that someone is responsible for each threat, rather than hoping for the best.
Before You Start
Risk is the effect of uncertainty on your objectives. Judging it takes two inputs for each risk, so collect both before you write.
- The potential severity of the impact if it happens.
- The probability that it will happen.
- A view on how much risk is acceptable. Weigh the benefits of each response against its costs, effort and disadvantages. The aim is cost-effective action that brings a risk down to a level you can tolerate.
Keep one principle in front of you: choose each response by balancing the benefits it brings against its costs, effort and disadvantages.
Steps
-
List the risks. Write down the events that could adversely affect your objectives. A risk is a future possibility, not a problem that has already arrived. Include the assumptions your plan rests on: each one is a risk that something you are counting on turns out not to be true.
-
Judge each one. Assess both the severity of the impact and the probability of occurrence. A common way to rank risks is a score: probability multiplied by impact. To multiply, give each level on your scales a number and write down what each level means. Many teams also use a risk matrix, a grid that rates each risk by its likelihood and its impact. Likelihood is often sorted into five levels, for example rare, possible, likely, very likely and almost certain. Pick one scale, use its wording throughout and write down what each level means.
Matrices are rough tools. They cannot tell apart risks that differ in size, they can rate a smaller risk higher than a bigger one, and different people reading the same facts may rate them differently. Use the score to start a conversation, not to end one.
-
Choose a response for each. You can avoid the risk, if feasible, by deciding not to start or continue the activity, though you then give up what it would have brought. You can reduce it by changing the likelihood and, where possible, the consequences, including by planning contingency activities. You can retain it by an informed decision. Balance risks against benefits and the cost of protection.
-
Fill in the table. For each risk, record what it is, who owns it and what you will do to reduce it. Add what happens if it occurs, and when and by whom.
Risk Owner Likelihood and impact What we will do to reduce it If it happens [Describe the event] [Person responsible for watching it] [Rating from your scale] [Steps, with dates and resources] [The contingent response] A contingent response is the set of actions you will take if the event happens. Keep those actions separate from any money you set aside to pay for them: the action first, then the reserve that funds it.
-
Give each action the details it needs. Say what will be done, who will do it, the timeline, the resources required, who needs to be told, and how you will know it worked. Include a schedule for putting controls in place and name the responsible person.
-
Get decisions approved at the right level. Have the outcome of your risk assessment recorded, communicated and checked at the right level of your organization, and escalate the most significant risks to senior leaders.
-
Plan for the rare and severe. For unlikely but catastrophic events, prepare a contingency plan: decide what you will do, name the trigger that puts it into action and who decides, share it with everyone who has a role, test it with the key players, and keep it up to date.
-
Keep reviewing. Review and revise your risk assessment regularly, because the level of risk changes. Update the plan periodically to check that the controls still work.
Using AI Safely
An assistant can brainstorm threats and lay out a first draft of the table. It will not apply these rules for you.
- Check any score it gives: it should multiply probability by impact, and the ratings should match your own judgment of each risk.
- Check the logic of cost: the benefits of a response should justify its costs and effort.
- Check that it has kept the response (the actions) apart from the contingency (the money).
- Watch for generic mitigation steps that do not fit your setting, and make sure every action names a person, a date and the resources.
- Be wary of any claim that a risk has been removed entirely while the activity continues.
Common Mistakes
Spending more than the risk is worth. Weigh the cost of a response against its benefit before you propose it; the aim is cost-effective action that brings the risk down to a level you can tolerate.
Vague actions. A line like "monitor security" is an intention. Name the action, the person, the timeline, the resources, who must be told and the test of success.
Treating the table as finished. Risk changes with conditions, so review the plan regularly and check whether the controls still work.
Trusting the matrix too much. Two people can rate the same risk differently, and a matrix can blur real differences. Discuss the ratings before you finalize them.