Risk Analysis and Management
Risk analysis and management is the discipline that identifies the uncertainties liable to reduce the value of a solution or a change, estimates their level, then puts responses in place and steers them. It produces a risk register kept up to date throughout the initiative.
Goal
Risk analysis and management exists to make the uncertainties bearing on a change's expected value both visible and governable. It turns diffuse worries into named objects, each with an estimated level, a planned response and a designated owner.
The decision it informs is twofold: whether to commit to the initiative given the risk it carries and, once committed, how to allocate the resources that contain the heaviest threats. Its deliverable is the risk register, a table that records for each risk its description, its probability, its impact, its level, the chosen response, the responsible owner and the residual risk after treatment.
The technique applies at three horizons. Strategic risk touches the value of the enterprise over time. Tactical risk attaches to a specific change. Operational risk bears on a solution once it is in service. The register is the same instrument in all three cases; only the scale of the stakes changes.
Usage
When to use it
- A business case to defend: quantify the risk the initiative carries so the net value shown to the sponsor is honest.
- Material uncertainty: a deadline, a budget or a compliance obligation is exposed to hazards that would be costly if they occurred.
- Exposed stakeholders: a risk materialising would reach third parties (clients, the regulator, staff) who must be protected or informed.
- Continuous steering: risk levels shift as work progresses; a regular register review keeps the responses adjusted.
- Operational risk after go-live: monitor the uncertainties that remain once the solution is in production.
When not to use it
- Trivial, low-stakes change: the register and the scoring cost more than the decision is worth; a simple issue log will do.
- No owner and no review cadence: prefer a simple risk checklist, since a scored register with no owner or review would stay a dead letter.
- Genuinely unknowable uncertainty: on a deep novelty, the probability-by-impact score manufactures false precision; prefer scenario and assumption analysis or an experimental approach.
Description
The technique is organised into four elements that together fill and then maintain the register. They form a loop: monitoring feeds continuously back into identification, and the residual risk of a treatment is a new risk to analyse.
Identification
Identification gathers the risks relevant to the initiative. It draws on expert judgement, stakeholder input, experimentation, past experience and the historical analysis of comparable initiatives. A risk event may occur once, several times or not at all; one event may lead to several consequences and one consequence may trace back to several causes. The aim is a set as complete as possible, one that shrinks the unknown. It is a standing activity: reducing identification to a single workshop at project start lets through the risks that only surface along the way, so that significant risks are never identified at all.
Analysis
Analysis understands each risk and estimates its level. Probability is expressed as a numeric value or on a Low / Medium / High scale. Impact is described against the value at stake: cost, time, scope or quality or agreed factors such as reputation, compliance or social responsibility. An impact scale of three to five levels gives a shared vocabulary for reading severity. The risk level is a function of probability and impact, often their product, and serves to rank risks against one another. A risk that is close in time, or that falls into a sensitive category such as compliance, may be raised above its raw score. That score remains a shared convention for ranking; taking it for an exact measurement is the commonest trap of this step.
Evaluation
Evaluation compares the analysed level with the change's potential value to decide whether that level is acceptable. It is a trade-off: the risk the change carries is weighed against the gain it is meant to produce. An overall risk level, the sum of the individual levels, gives the sponsor a whole-picture reading. This is where the register stops being an inventory and becomes an instrument of decision: a risk judged unacceptable calls for treatment before any further commitment.
Treatment
Treatment chooses a response for each retained risk, from five combinable approaches:
- Avoid: remove the source of the risk or adjust the plan so the risk cannot occur.
- Transfer: move or share the burden of the risk with a third party, through a contract, insurance or a service-level clause.
- Mitigate: reduce the probability or the severity of the consequences.
- Accept: take no action for now, keeping a workaround ready should the risk materialise.
- Increase: take on more risk to seize an opportunity, when the uncertainty works in favour of value.
Each risk gets a response plan and an owner with the responsibility and the authority to act. A risk with no owner is watched by no one and its plan never fires. After treatment, the risk is re-analysed to establish its residual risk, its probability and impact recomputed once the response is in place. A cost-benefit check confirms the response is worth its price, since a response costing more than the risk it covers is a bad deal. Stakeholders are informed of the chosen plans. Ignoring the residual amounts to believing a risk settled when it persists in reduced form.
Keeping the register over time
The register lives with the initiative. Levels vary, a risk dismissed yesterday becomes active again, a treatment creates a residual to watch. A periodic review reopens the open risks, updates the scores and closes those that can no longer occur. The opposite danger also looms: a register that swells without discrimination becomes unreadable, since only a subset of risks can be steered. The discipline is to keep in the register the risks one is going to manage.
AI considerations
AI helps most upstream and on volume. It can propose a first list of risks from a project brief or from comparable past initiatives, group and de-duplicate a register that has grown large, surface forgotten risks from historical data and lessons learned and sketch response-plan options for discussion.
Judgement stays human wherever accountability is at stake. Estimating probability and impact is a convention negotiated among stakeholders; a score suggested by a model is not a measurement and must be re-discussed. Choosing the treatment and naming the owner carry an accountability that cannot be delegated to a model. Sensitive risks, touching reputation, compliance or people, need a framing and a discretion only a human can provide.
Examples
A forty-person services SME replaces its billing and accounting software. The register scores five risks on 1-to-5 scales for probability and impact, the level being their product (1-4 Low, 5-9 Medium, 10-16 High, 17-25 Critical). The column to read is the last: the residual risk shows the effect of treatment, re-scored once the response is in place.
Risk register
Billing-software replacement
| Risk | Prob. | Impact | Level | Response (approach) | Owner | Residual |
|---|---|---|---|---|---|---|
| Vendor delivery delay | 3 | 4 | High (12) | Mitigate: contractual milestones, penalties | Project manager | Medium (6) |
| Incomplete customer-data migration | 3 | 4 | High (12) | Mitigate: trial migration then reconciliation | Data lead | Low (4) |
| VAT non-compliance at cutover | 2 | 5 | High (10) | Transfer: review by an external fiduciary | Accounting lead | Low (2) |
| User resistance | 4 | 3 | High (12) | Mitigate: training, network of champions | HR lead | Medium (6) |
| Single-vendor dependency | 2 | 3 | Medium (6) | Accept: exit clause, backups | IT lead | Medium (6) |
Visualisations
A risk's score becomes legible once it is placed on a probability-by-impact matrix: each risk sits at its two coordinates and the colour of the cell gives its level. Plotted before and then after treatment, the position of a single risk shows what the response removed. The incomplete data migration starts at probability 3 for impact 4, in the High band; once the trial migration and the reconciliation are in place, it falls back to probability 2 for impact 2, in the Low band. The arrow joining the two points is the treatment itself.
Cost
| Phase | Level | Rationale |
|---|---|---|
| Preparation | Medium | Define the scales and impact categories, gather the stakeholders who will do the scoring. |
| Execution | Medium | Identification workshops and scoring sessions, repeated at each review. |
| Documentation | High | Register kept continuously up to date, residual re-scored at each treatment. |
Tooling
A whiteboard and sticky notes are enough for workshop identification, where the speed of capture matters more than the layout. A spreadsheet carries a register of a few dozen risks without effort, with automatic level calculation and priority sorting. Beyond that, when several initiatives share risks or compliance demands an audit trail, a dedicated risk-management tool or a GRC module (governance, risk and compliance) within a project-steering suite offers history, review reminders and the consolidation of an overall level. A probability-by-impact matrix, as a template, gives scoring sessions a shared visual support.
Sources
- IIBA, A Guide to the Business Analysis Body of Knowledge (BABOK Guide) v3, §10.38 'Risk Analysis and Management': the technique's four elements, the five treatment approaches, level as a function of probability and impact, residual risk and register upkeep. Descriptive source.
- ISO 31000:2018, Risk management, Guidelines, ISO: the framework and principles of risk management, including the continuous nature of the process.
- IEC 31010:2019, Risk management, Risk assessment techniques, IEC/ISO: the catalogue of risk-assessment techniques, including the probability-impact matrix.
- Project Management Institute, The Standard for Risk Management in Portfolios, Programs, and Projects, PMI: the normative treatment of risk responses, including the 'increase an opportunity' response and the continuous-process framing of risk management.

