Risk Assessment: How Organizations Evaluate What Could Go Wrong
Risk assessment entails analysis of risks in order to evaluate their probability of occurrence as well as their impact should they occur. This is a crucial stage in risk management since it comes after the identification of risks, which helps an organization in determining what actions to take against the risks that exist. The success of risk assessment will determine whether an organization concentrates its efforts in handling the right risks.
Why Risk Assessment Matters
An organization has many risks and few resources to handle all of them. Risk assessment is a key stage that helps in prioritizing risks into two types, namely low probability and low impact risks (which can be monitored without taking any action at the moment), and high probability and high impact risks (which need immediate actions). Otherwise, organizations will allocate their limited resources inadequately or on the wrong risks.
The Core Components of Risk Assessment
Likelihood
A prediction of the probability of the occurrence of a particular risk within a given time period, based on past records, industry standards, expert opinion, or all of these in combination.
Impact
A prediction of what will happen if the risk takes place, loss of money, operational disruptions, reputation damage, legal penalties, or safety hazards, depending on the nature of the risk involved.

Risk Rating
Both probability and impact are then evaluated together using some method like a risk matrix, to generate a rating for the risk as a whole.

Qualitative vs. Quantitative Risk Assessment
Qualitative Assessment
Relies on relative scales, where both the probability and consequences of the risk event are assigned values of either low, medium, or high. The process is less time-consuming and does not need much data; however, it lacks accuracy and can only be used for a wide variety of risks.
Quantitative Assessment
Provides numeric values for the probability and impact/consequences of the risk. Probability is measured in terms of statistics while impact/consequence in terms of financial value. This process provides more accurate information, but it needs more data and time to be carried out. It is normally used for an organization’s top material risks.

Common Risk Assessment Methodologies
Risk Matrices
This is a simple visual method that uses two axes of probability and impact, creating a grid of priority levels, a very popular first step for organizations planning to assess risks.
Scenario Analysis
Analysis of how a particular scenario (failure of the major supplier, market downturn) will influence the company, this approach helps understand risks without a clear history from which probabilities can be calculated.
Failure Mode and Effects Analysis (FMEA)
Methodology, widely used in manufacturing and engineering, consists of systematic analysis of failures of processes in terms of their severity, frequency and detectability.
Monte Carlo Simulation
This method consists of running numerous simulations with the aim of modeling a range of possible scenarios and calculating probabilities of each of them, it can be applied in financial risk assessments and similar cases.
Who Conducts Risk Assessments
Risk assessment is done usually by those risk owners who are near to that particular area; for example, the finance team doing risk assessment of financial risks, the information technology security team doing risk assessment of cyber risks, and the operations team doing risk assessment of supply chain risks.
How Often Risk Assessments Should Happen
Risk assessment is an ongoing process. While most firms undertake thorough risk assessment on an agreed schedule basis (annually), many companies also periodically review certain high-risk areas and carry out assessments on an event-driven basis, in light of important changes that might affect their risk exposure, including a new regulation or the introduction of a major new system.
Common Mistakes in Risk Assessment
Overreliance on Historical Data
There may be emerging risks in the future which do not have a clear precedent in the past, hence making the assumption of the past trends being the guide of the future unreliable.
Inconsistent Scoring Across Departments
Using different criteria for determining the level of impact and likelihood by different teams creates challenges in prioritizing risk organization-wide as well as allocating resources accordingly.
Treating Assessment as the End Goal
The risk assessment process alone does not make an organization more secure because all it does is prioritize risks; organizations that just conduct risk assessments do not reduce their risks at all.
Underestimating Compounding Risks
Assessing risks without considering how they relate to each other in terms of potential impact in case they happen at the same time may lead to misprioritizing them.
Bottom Line
Risk assessment allows the organizations to have a systematic approach in prioritizing which risks should be considered in the organization based on either qualitative techniques which are fast and wide or quantitative techniques which give more precision on important risks. The importance of risk assessment is the fact that it should always be done systematically, be updated regularly, and be followed by risk response.