Risk analysis guide
Describe risk as an uncertain event, not a vague concern
A risk assessment identifies uncertain events that could affect an objective, explains their causes and consequences, evaluates exposure and assigns treatment. Write each risk as a possible event: because a cause exists, an event may occur, leading to a consequence. This format is clearer than labels such as ‘security’ or ‘supplier problem’ and makes controls easier to evaluate.
Use process maps, incident history, audit findings, vendor information, technical tests and stakeholder interviews. AI can organize evidence, but likelihood and impact require context and accountable judgement. Record the scoring scale, review date and source. Separate an active issue, which already exists, from a risk that may occur.
Analyse each scenario at a consistent level. One node should not describe a broad category such as cyber risk while another describes a single expired certificate. Break categories into events that have distinct causes, consequences, controls and owners. Where several events share a systemic cause, retain both the individual scenarios and a parent theme so treatment can address immediate exposure and the underlying weakness.
Core risk fields
Capture scope, risk event, cause, consequence, affected objective, likelihood, impact, existing controls, control effectiveness, owner, treatment, due date and residual risk.
Assessment versus risk register
The assessment discovers and analyses exposure. A risk register maintains selected risks, owners and treatment status over time. This map can support both, but detailed history should remain in a controlled register.