Risk management
The lifecycle
Identify, analyze, treat, monitor, report. Assessments run ad-hoc (event-driven), recurring (scheduled), one-time (a project), or continuous (real-time tooling).
Identification and BIA
The techniques: brainstorming, checklists, interviews, scenario analysis, across operational, financial, strategic, and reputational risk.
Business Impact Analysis measures the effect of disruptions and prioritizes critical functions. Its four metrics:
- RTO (recovery time objective): max acceptable downtime before severe impact.
- RPO (recovery point objective): max acceptable data loss, measured in time.
- MTTR (mean time to repair): average time to fix a failed component.
- MTBF (mean time between failures): average time between failures, a reliability measure.
Analysis
Qualitative analysis rates likelihood and impact as low, medium, or high. Subjective, expert-driven.
Quantitative analysis puts money on it:
- EF (exposure factor): the fraction of the asset lost, 0-100%.
- SLE (single loss expectancy) = asset value x EF.
- ARO (annualized rate of occurrence): times per year.
- ALE (annualized loss expectancy) = SLE x ARO.
Treatment strategies
- Transfer: shift the financial hit (insurance, indemnity clauses). It doesn’t remove the risk.
- Accept: live with it, when the cost of fixing exceeds the potential loss. Know exemption vs exception.
- Avoid: change the plan to eliminate the risk.
- Mitigate: reduce likelihood or impact with controls.
Register and appetite
The risk register holds description, impact, likelihood, outcome, level and threshold, cost, plus a risk owner. Often shown as a heat map.
Risk tolerance (acceptance) is how much risk you’ll accept. Risk appetite is your posture: expansionary, conservative, or neutral.
Key risk indicators (KRIs) give early warning. Residual risk is what’s left after treatment, and control risk is a control losing effectiveness over time.