Your Training Partner
Techniques Toolbox
Probability-impact matrix: the data-migration risk moves from a High cell to a Low cell, the arrow marking the effect of treatment.

Risk Analysis and Management

Risk analysis and management is the discipline that identifies the uncertainties liable to reduce the value of a solution or a change, estimates their level, then puts responses in place and steers them. It produces a risk register kept up to date throughout the initiative.

Goal

Risk analysis and management exists to make the uncertainties bearing on a change's expected value both visible and governable. It turns diffuse worries into named objects, each with an estimated level, a planned response and a designated owner.

The decision it informs is twofold: whether to commit to the initiative given the risk it carries and, once committed, how to allocate the resources that contain the heaviest threats. Its deliverable is the risk register, a table that records for each risk its description, its probability, its impact, its level, the chosen response, the responsible owner and the residual risk after treatment.

The technique applies at three horizons. Strategic risk touches the value of the enterprise over time. Tactical risk attaches to a specific change. Operational risk bears on a solution once it is in service. The register is the same instrument in all three cases; only the scale of the stakes changes.

Usage

When to use it

  • A business case to defend: quantify the risk the initiative carries so the net value shown to the sponsor is honest.
  • Material uncertainty: a deadline, a budget or a compliance obligation is exposed to hazards that would be costly if they occurred.
  • Exposed stakeholders: a risk materialising would reach third parties (clients, the regulator, staff) who must be protected or informed.
  • Continuous steering: risk levels shift as work progresses; a regular register review keeps the responses adjusted.
  • Operational risk after go-live: monitor the uncertainties that remain once the solution is in production.

When not to use it

  • Trivial, low-stakes change: the register and the scoring cost more than the decision is worth; a simple issue log will do.
  • No owner and no review cadence: prefer a simple risk checklist, since a scored register with no owner or review would stay a dead letter.
  • Genuinely unknowable uncertainty: on a deep novelty, the probability-by-impact score manufactures false precision; prefer scenario and assumption analysis or an experimental approach.

Description

The technique is organised into four elements that together fill and then maintain the register. They form a loop: monitoring feeds continuously back into identification, and the residual risk of a treatment is a new risk to analyse.

Identification

Identification gathers the risks relevant to the initiative. It draws on expert judgement, stakeholder input, experimentation, past experience and the historical analysis of comparable initiatives. A risk event may occur once, several times or not at all; one event may lead to several consequences and one consequence may trace back to several causes. The aim is a set as complete as possible, one that shrinks the unknown. It is a standing activity: reducing identification to a single workshop at project start lets through the risks that only surface along the way, so that significant risks are never identified at all.

Analysis

Analysis understands each risk and estimates its level. Probability is expressed as a numeric value or on a Low / Medium / High scale. Impact is described against the value at stake: cost, time, scope or quality or agreed factors such as reputation, compliance or social responsibility. An impact scale of three to five levels gives a shared vocabulary for reading severity. The risk level is a function of probability and impact, often their product, and serves to rank risks against one another. A risk that is close in time, or that falls into a sensitive category such as compliance, may be raised above its raw score. That score remains a shared convention for ranking; taking it for an exact measurement is the commonest trap of this step.

Evaluation

Evaluation compares the analysed level with the change's potential value to decide whether that level is acceptable. It is a trade-off: the risk the change carries is weighed against the gain it is meant to produce. An overall risk level, the sum of the individual levels, gives the sponsor a whole-picture reading. This is where the register stops being an inventory and becomes an instrument of decision: a risk judged unacceptable calls for treatment before any further commitment.

Treatment

Treatment chooses a response for each retained risk, from five combinable approaches:

  • Avoid: remove the source of the risk or adjust the plan so the risk cannot occur.
  • Transfer: move or share the burden of the risk with a third party, through a contract, insurance or a service-level clause.
  • Mitigate: reduce the probability or the severity of the consequences.
  • Accept: take no action for now, keeping a workaround ready should the risk materialise.
  • Increase: take on more risk to seize an opportunity, when the uncertainty works in favour of value.

Each risk gets a response plan and an owner with the responsibility and the authority to act. A risk with no owner is watched by no one and its plan never fires. After treatment, the risk is re-analysed to establish its residual risk, its probability and impact recomputed once the response is in place. A cost-benefit check confirms the response is worth its price, since a response costing more than the risk it covers is a bad deal. Stakeholders are informed of the chosen plans. Ignoring the residual amounts to believing a risk settled when it persists in reduced form.

Keeping the register over time

The register lives with the initiative. Levels vary, a risk dismissed yesterday becomes active again, a treatment creates a residual to watch. A periodic review reopens the open risks, updates the scores and closes those that can no longer occur. The opposite danger also looms: a register that swells without discrimination becomes unreadable, since only a subset of risks can be steered. The discipline is to keep in the register the risks one is going to manage.

AI considerations

AI helps most upstream and on volume. It can propose a first list of risks from a project brief or from comparable past initiatives, group and de-duplicate a register that has grown large, surface forgotten risks from historical data and lessons learned and sketch response-plan options for discussion.

Judgement stays human wherever accountability is at stake. Estimating probability and impact is a convention negotiated among stakeholders; a score suggested by a model is not a measurement and must be re-discussed. Choosing the treatment and naming the owner carry an accountability that cannot be delegated to a model. Sensitive risks, touching reputation, compliance or people, need a framing and a discretion only a human can provide.

Examples

A forty-person services SME replaces its billing and accounting software. The register scores five risks on 1-to-5 scales for probability and impact, the level being their product (1-4 Low, 5-9 Medium, 10-16 High, 17-25 Critical). The column to read is the last: the residual risk shows the effect of treatment, re-scored once the response is in place.

Risk register

Billing-software replacement

RiskProb.ImpactLevelResponse (approach)OwnerResidual
Vendor delivery delay34High (12)Mitigate: contractual milestones, penaltiesProject managerMedium (6)
Incomplete customer-data migration34High (12)Mitigate: trial migration then reconciliationData leadLow (4)
VAT non-compliance at cutover25High (10)Transfer: review by an external fiduciaryAccounting leadLow (2)
User resistance43High (12)Mitigate: training, network of championsHR leadMedium (6)
Single-vendor dependency23Medium (6)Accept: exit clause, backupsIT leadMedium (6)
Risk register for a software cutover. The numeric level orders priorities; the residual measures what treatment removed.

Visualisations

A risk's score becomes legible once it is placed on a probability-by-impact matrix: each risk sits at its two coordinates and the colour of the cell gives its level. Plotted before and then after treatment, the position of a single risk shows what the response removed. The incomplete data migration starts at probability 3 for impact 4, in the High band; once the trial migration and the reconciliation are in place, it falls back to probability 2 for impact 2, in the Low band. The arrow joining the two points is the treatment itself.

5101520254816203691215268101234512345Probability54321ImpactBeforeHigh · 12AfterLow · 4Levelprobability × impactLow1-4Medium5-9High10-16Critical17-25Before treatmentAfter treatment
Probability-by-impact matrix. One risk before and after treatment: position gives its two factors, colour its level, the arrow the effect of the treatment.

Cost

PhaseLevelRationale
PreparationMediumDefine the scales and impact categories, gather the stakeholders who will do the scoring.
ExecutionMediumIdentification workshops and scoring sessions, repeated at each review.
DocumentationHighRegister kept continuously up to date, residual re-scored at each treatment.

Tooling

A whiteboard and sticky notes are enough for workshop identification, where the speed of capture matters more than the layout. A spreadsheet carries a register of a few dozen risks without effort, with automatic level calculation and priority sorting. Beyond that, when several initiatives share risks or compliance demands an audit trail, a dedicated risk-management tool or a GRC module (governance, risk and compliance) within a project-steering suite offers history, review reminders and the consolidation of an overall level. A probability-by-impact matrix, as a template, gives scoring sessions a shared visual support.

Sources

  • IIBA, A Guide to the Business Analysis Body of Knowledge (BABOK Guide) v3, §10.38 'Risk Analysis and Management': the technique's four elements, the five treatment approaches, level as a function of probability and impact, residual risk and register upkeep. Descriptive source.
  • ISO 31000:2018, Risk management, Guidelines, ISO: the framework and principles of risk management, including the continuous nature of the process.
  • IEC 31010:2019, Risk management, Risk assessment techniques, IEC/ISO: the catalogue of risk-assessment techniques, including the probability-impact matrix.
  • Project Management Institute, The Standard for Risk Management in Portfolios, Programs, and Projects, PMI: the normative treatment of risk responses, including the 'increase an opportunity' response and the continuous-process framing of risk management.
Reviews
All techniques
Roles and Permissions Matrix