Risk assessment exists to turn a vague sense of danger into a ranked list a leader can act on. Identification asks what can happen, analysis asks how likely and how bad, evaluation asks whether that is acceptable against appetite. The dependent decision is treatment: accept, reduce, transfer or avoid — each option with a cost that must be justified. Skipping assessment means the treatment budget goes to the loudest risk, not the largest.
Assessments are run by risk owners with facilitation from the risk function, refreshed at least annually and after any major change — a new product, a new market, a lost supplier. Results are recorded in the risk register with likelihood, impact and current controls. Scales work best when anchored in numbers: "major" impact defined as more than USD 1 million of loss or more than 24 hours of interrupted service, not left to feeling. The output feeds directly into risk reports and continuity planning priorities.
The recurring mistake is assessment as colour-coding: risks placed on a heat map by intuition, without evidence, and never confronted with real incident data. A related one is assessing gross risk only and never checking whether controls actually work. How assessment connects to appetite and to resilience decisions is covered in module M2 "From enterprise risk management to business resilience" of the ERGP programme.
This term is part of the working language of ERGP — the first resilience governance certification fully available in Arabic, also in English. 94 chapters, six modules, a verifiable certificate.
Explore the ERGP programme