Risk Assessments 1-2-3

Registration is free. Login or register to view/download this content.

Author(s)

Consultant, The Process Geek
Karen Tricomi has a 25-year history of practical business process management, business analysis, technology communications, and large-scale change management. She has consulted internationally, and is currently the owner of The Process Geek, a process management and technology communications consulting firm. The BPM Institute granted a Certification as a Business Process Management Professional in 2011.

Risk assessments have become more common recently, and for good reason.  We read headlines daily about data breaches, high-dollar investments gone wrong, and companies that took a market risk that didn’t pay off.

Risk increases as a result of change, whether internally or externally triggered.  Examples of internally driven change include executing a new project, launching a new product, or changing a process.  Regulatory requirements, market changes, competitive challenges, and new security threats change the risk profile even when a company is conducting business as usual.  Enterprises are never done with assessing risks; there is no such thing as “steady state” when it comes to risks.

Risks, or threats, have been described as unrealized constraints; that is, something that may occur but is not yet proven to be true.  Risks may be wholly or partially within our control. They may be something we can prevent, something we can recover from, or something we can live with should they occur.

Here I provide a simple framework to identify the risks, rank them in a priority order, and determine what action, if any, must be taken for each.
External changes are often industry dependent.  Consider these, which are largely outside a company’s control:

  • Legal or liability claims
  • Increased competition
  • Regulatory changes and requirements
  • Economic downturns that create a lack of demand
  • Supply or materials constraints
  • A critical mass of knowledge workers reaching retirement age
  • Lack of qualified job applicants
  • Data security breaches

Internal Changes can include process changes, reorganizations, and projects.  Each carries unique risks, but many are common to all three:

  • Lack of personnel, either not enough or those without the needed skills
  • Changes in scope
  • Not meeting success criteria
  • Not delivering the project on time
  • Not staying within the project budget
  • Insufficient executive sponsorship
  • Inadequate tools
  • Incomplete/badly understood requirements
  • Undocumented or undiscovered processes/workarounds
  • Poor process design
  • Ineffective change management strategy
  • Lack of stakeholder buy-in
  • Not all stakeholders identified
  • Inadequate training for new processes
  • Employees lack skills needed for new processes
  • Employee resistance to change
  • Employee morale decreases
  • Unplanned impact on upstream/downstream processes

Risk Assessment Framework
Five basic questions are common to all risk assessments:

  • What is the risk?
  • How likely is the risk?
  • What is the impact of the risk being realized?
  • Can we prevent the risk, and if so at what cost?
  • What happens if we do nothing to address this identified risk?

We can enter the answers to these questions in a simple matrix that will include calculations to rate and prioritize each risk, and allow you to balance the cost of mitigation against its impact and the likelihood of its occurring.

Initially, list these elements for each risk identified:

  • A textual description of the risk
  • A textual description of the impact of the risk, should it occur
  • An estimate of the cost of the impact, expressed in a simple 1 (low), 2 (medium), 3 (high) scale
  • An indication of the likelihood of the risk occurring, expressed in the same scale 

Now multiply the number for the likelihood of the risk being realized against by the number representing the impact.  This results in a ranked list of risks, the first part of your matrix.  

As an example, in Table 1 the impact of customer dissatisfaction and loss of orders for a new product may seem like a very important risk to mitigate, but it has been ranked as unlikely to occur. Therefore, the possibility of the vendor delivering the needed equipment late will be prioritized over the training budget when considering mitigation strategies.

Table 1

Once the risks have been ranked and ordered, consider what it will take to mitigate each risk.  Develop a list of options that includes what you might do to prevent it from occurring, or to recover if the risk occurs.  Estimate the cost for each option, again using a 1-2-3 ranking.  Table 2 provides an example of three options developed for the risks listed in Table 1, and the cost for each. 

Table 2

Giving absolute scores to these factors allows you to balance the cost of your mitigation strategy against the priority of each risk. In some cases, where probability and impact both are low, the choice to do nothing is a valid one.  Each mitigation strategy needs to be funded as a contingency in the budget, and returned to the funding body if the risks are not realized. 

In some cases, where risk impact and probability are both low, you may choose to do nothing.  This is a valid choice, but once a risk is identified the decision to mitigate or accept the risk belongs to the project’s sponsor.   It is critical to discuss and document all such decisions, and it’s always wise to require formal approval or signoff by the sponsor of the change. 

The scales presented can be expanded to provide more granularity if there are many competing risks.  You may also choose to employ a High/Medium/Low scheme and skip the math, and simply eyeball the impacts and costs.  

Make no mistake, risk assessments are not simple.  Methods such as the one described above can aid the project owner in quantifying risk factors, but there is skill, art, and experience required both in identifying risks and in deciding what to do about them.  Bring in experts from across all functions to brainstorm the topic.  Spend this time and effort as you are planning any change, at the first indication of a significant environmental change, and on anything that hasn’t had a risk assessment for a period of time.  You can’t afford not to. 

Similar Resources

Featured Certificate: BPM Specialist

Everyone starts here.

You're looking for a way to improve your process improvement skills, but you're not sure where to start.

Earning your Business Process Management Specialist (BPMS) Certificate will give you the competitive advantage you need in today's world. Our courses help you deliver faster and makes projects easier.

Your skills will include building hierarchical process models, using tools to analyze and assess process performance, defining critical process metrics, using best practice principles to redesign processes, developing process improvement project plans, building a center of excellence, and establishing process governance.

The BPMS Certificate is the perfect way to show employers that you are serious about business process management. With in-depth knowledge of process improvement and management, you'll be able to take your business career to the next level.

Learn more about the BPM Specialist Certificate

Courses

  •  

 

Certificates

  • Business Process Management Specialist
  • Earning your Business Process Management Specialist (BPMS) Certificate will provide you with a distinct competitive advantage in today’s rapidly evolving business landscape. With in-depth knowledge of process improvement and management, you’ll be able to take your business career to the next level.
  • BPM Professional Certificate
    Business Process Management Professional
  • Earning your Business Process Management Professional (BPMP) Certificate will elevate your expertise and professional standing in the field of business process management. Our BPMP Certificate is a tangible symbol of your achievement, demonstrating your in-depth knowledge of process improvement and management.

Certification

BPM Certification

  • Make the most of your hard-earned skills. Earn the respect of your peers and superiors with Business Process Management Certification from the industry's top BPM educational organization.

Courses

 

Certificates

  • Operational Excellence Specialist
  • Earning your Operational Excellence Specialist Certificate will provide you with a distinct advantage in driving organizational excellence and achieving sustainable improvements in performance.
 

 

OpEx Professional Certificate

  • Operational Excellence Professional
  • Earn your Operational Excellence Professional Certificate and gain a competitive edge in driving organizational excellence and achieving sustainable improvements in performance.

Courses

Certificate
  •  

  • Agile BPM Specialist
  • Earn your Agile BPM Specialist Certificate and gain a competitive edge in driving business process management (BPM) with agile methodologies. You’ll gain a strong understanding of how to apply agile principles and concepts to business process management initiatives.  
 

Business Architecture

 

Certificates

  • Business Architecture Specialist
  • The Business Architecture Specialist (BAIS) Certificate is proof that you’ve begun your business architecture journey by committing to the industry’s most meaningful and credible business architecture training program.

  • Business Architecture Professional
  • When you earn your Business Architecture Professional (BAIP) Certificate, you will be able to design and implement a governance structure for your organization, develop and optimize business processes, and manage business information effectively.

BA CertificationCertification

  • Make the most of your hard-earned skills. Earn the respect of your peers and superiors with Business Architecture Certification from the industry's top BPM educational organization.

Courses

 

Certificates

  • Digital Transformation Specialist
  • Earning your Digital Transformation Specialist Certificate will provide you with a distinct advantage in today’s rapidly evolving business landscape. 
 

 

  • Digital Transformation Professional
  • The Digital Transformation Professional Certificate is the first program in the industry to cover all the key pillars of Digital Transformation holistically with practical recommendations and exercises.

Courses

Certificate

  • Agile Business Analysis Specialist
  • Earning your Agile Business Analysis Specialist Certificate will provide you with a distinct advantage in the world of agile software development.

Courses

Certificate
  • DAS Certificate
  • Decision Automation Specialist
  • Earning your Decision Automation Certificate will empower you to excel in the dynamic field of automated decision-making, where data-driven insights are pivotal to driving business innovation and efficiency.