Documente Academic
Documente Profesional
Documente Cultură
10
4
Accepta ble risks
8
6
12
9 12
2
1
3
3
6
3
8
4
10
5
20 25 Maximum
risk
15 19 High risk 10-14 5-9
Acceptable
No risk reduction control, monitor, inform management No risk reduction control. Monitor, inform management.
1-4
Acceptable
Risk Significance
If possible, it is useful to put values to the consequence score, for example, a cash loss over $1m might be considered very high if it threatened the existence of the organisation.
Since we need to sort risks, it helps to attach numbers to the risk measure (for example 4 for High).
Risk Significance
Consequence and likelihood can be multiplied together to give a single measure of the significance of a risk, or a different combination can be used. For example, take the risk that a lorry may break down. Assuming we have only three, old lorries, the consequence could be medium (scores 3) but the likelihood could be high (scores 4), giving a significance of 12.
Risks are ideally scored before and after taking account of the response which manages the risk.
I nherent (or gross or absolute) risk scores are measured by assessing the consequence and likelihood of a risk occurring before any internal controls are taken into account.
We have talked about managing all risks to acceptable levels. Now we have scored risks before and after internal controls we can begin to define the organisations risk appetite. One method of deciding which risks to accept is to place them on a grid of likelihood and consequence (see below). This enables the board to define the action it requires management to take for each likelihood/consequence combination.
It is therefore necessary to understand the organisations tolerance for each risk. This will help define how much tolerance management has of each risk.
Risk Assessment
Risks with exposure beyond managements tolerance would be prime candidates for focused risk management actions. The boundary between the acceptable risks and those which require managing is known as the risk appetite. If inherent risks cannot be managed below this line by treatment then they will have to be terminated, transferred or tolerated.