Skip to content

Glossary

Risk assessment

A risk assessment is a structured process of identifying hazards and threats, analyzing their likelihood and consequences, and evaluating whether a given risk is still acceptable to the organization.

Under ISO 31000, the international risk management standard, risk assessment combines three steps: risk identification, risk analysis and risk evaluation against predefined acceptance criteria. It sits within a wider process covering scope, context and criteria, risk treatment, monitoring and review, and communication with stakeholders. Risk is defined there as the effect of uncertainty on objectives; security practice deals mainly with its harmful side.

Methods range from qualitative (expert workshops, likelihood and consequence matrices) through semi-quantitative to quantitative (expected loss, scenario modeling). The catalog of techniques in IEC 31010 includes scenario analysis, bow-tie analysis, failure mode analysis, event and fault trees, and structured expert elicitation. The choice depends on data quality and on the decision the assessment must support; a matrix must not create an impression of precision the underlying data cannot sustain.

The output is a risk register recording, for each risk, its description, causes, existing controls, assessed level, owner and treatment decision — avoid, reduce, transfer or accept — together with the residual risk after measures. An assessment that is not tied to a concrete decision, an owner and a review date has no practical effect.

In several fields a risk assessment is a legal duty rather than a choice. Employers must produce a written safety statement with a risk assessment, data protection law requires an impact assessment for high-risk processing, and cybersecurity legislation requires risk-based measures. Terminology differs by field: occupational risk assessment focuses on hazards to workers' health, while security risk assessment addresses deliberate, hostile acts.

Back to glossary

Ready to strengthen security across your organization?

Contact us to see how our turnkey solutions can build a safer, more resilient organization.