For any organization, compiling a solid list of the threats and risks it faces is a worthwhile achievement. It also opens the door to applying a practical, common-sense process that can significantly reduce those risks, at least for companies willing to seize the opportunity.
Related: A Sample Threat and Risk Assessment: The Case of Acme Widget Corp.
Summary
As anyone who has done it knows, putting together a rigorous, comprehensive risk register is hard work. It requires gathering information from multiple sources outside and inside the organization, synthesizing it, and assessing it in discussions with key colleagues.
Government agencies, emergency-management organizations, weather data, and industry publications can provide information on disasters that have affected the organization’s locality and industry in the past.
Internal company sources, especially veteran employees in departments such as IT, operations, security, and facilities, will likely have plenty of war stories about past emergencies as well as insights into ongoing risks.
Company staff are also the people to consult when it comes time to assess the risks identified.
The heart of a good risk register is the section where the identified risks are categorized in terms of likelihood of occurrence, such as high, medium, and low, and the likely level of impact if they did occur.
To obtain these assessments, the team doing the assessment must identify and consult practical, well-informed people at key departments across the organization.
The result of this process, when done well, is much more than a spreadsheet. It’s a comprehensive register of the organization’s most significant exposures.
Creating a sound, comprehensive risk register is a substantial accomplishment.
This fact makes it all the more unfortunate that many organizations, after compiling their risk register, do nothing with it beyond putting it on a shelf.
In our consulting work, we often work with clients who complete a risk assessment and seem to regard the result as a finished piece of work that can be put in a box and tied up with a ribbon.
They’ll often say something like, “That’s all we’re going to bother with on the risk side. If any of those things happen, we’ll figure out how to deal with it when the time comes.”
In this, they are similar to the many organizations that do a business impact analysis (BIA) and then decide their business continuity (BC) effort is done for the year. “We have a BIA now,” they’ll say. “We’re all set.”
The risk register and BIA are both valuable, foundational pieces. But it’s wise to be clear about what they are: they’re only information. Benefiting from them requires using them to guide and drive action.
For a BIA, that would mean implementing strategies and plans to protect the processes, systems, and applications identified as being critical.
For a risk register, it means mitigating the cataloged risks, starting with those found to have both a high likelihood of occurrence and the potential to cause great damage.
If your risk assessment reveals the key vulnerabilities your organization is exposed to, that’s great.
Does your risk register show that your company is at risk of serious disruption due to its lack of a succession plan? Good to know.
Does it indicate that the lack of staff cross-training in a certain area has created a single point of failure? It’s nice to have that written down somewhere.
But if the organization merely notes these facts without doing anything about them, like creating a succession plan and providing the cross-training, it’s doing itself a huge disservice.
It’s like working as a waiter and leaving your tips on the table, unclaimed.
The information the organization worked to obtain for its risk register is a powerful tool it could use to improve its resilience, if only it troubled to capitalize on it.
Everyone who takes the time to create a good risk register should take the next step and use it to improve the organization’s resilience. Doing so is a straightforward matter of following a proven, practical risk-mitigation process. Here are the key steps.
The people who identify and maintain the risk register are not necessarily the people who are responsible for mitigating the risks it identifies. In most organizations, the actual risk owner will be the department, business unit, or functional area where the risk resides. Make sure each significant risk has someone who is accountable for deciding what should be done about it.
Not every risk calls for the same response. Some may be addressed by preventing the risk from occurring; others may require controls that reduce its likelihood or impact. In some cases, the appropriate response may already exist in the organization’s BC plans or other preparedness measures. The important thing is to determine deliberately how each significant risk will be addressed.
Mitigating a risk often requires time, money, personnel, technology, or other resources. A department may recognize that a risk needs to be addressed but lack the authority or resources to do so. Leadership needs to understand the significance of the risk and provide the support necessary to address it.
Identifying a risk and assigning an owner does not mean the risk has been mitigated. Organizations should follow up to determine what actions have been taken, what remains outstanding, and whether the risk has actually been reduced.
A mitigation strategy that looks good on paper may not work in practice. Where appropriate, organizations should test, exercise, or otherwise validate their mitigation measures to make sure they will perform when needed.
Risk mitigation competes with other organizational priorities for attention and resources. The BC or enterprise risk team can identify risks, help evaluate them, make recommendations, and keep them visible. But ultimately, leadership has to decide which risks warrant investment and provide the support needed to address them.
Not every risk can or should be eliminated. Some risks will be judged too unlikely or too costly to mitigate. That is a legitimate management decision, provided it is a conscious one. A risk register should make those decisions visible rather than allowing important risks to disappear into a spreadsheet.
Risk mitigation is not a one-time exercise. Organizations should periodically review their risk register, reassess their risks and mitigation measures, and repeat the process as conditions, priorities, and the organization itself change.
A risk register is valuable because it tells an organization where it is exposed. Its greater value comes from using that knowledge to decide what to do about those exposures, and then actually doing it.
And when a risk seems too unlikely to justify action, there is a useful question to ask: If it happened tomorrow, would we wish we had done something to prevent it? If the answer is yes, it may be worth reconsidering why you are waiting.
Building a good risk register is a significant accomplishment. It requires gathering information from inside and outside the organization, assessing the likelihood and potential impact of identified risks, and creating a prioritized picture of the organization’s most significant exposures.
But the register is only a starting point. To turn risk information into meaningful improvements in resilience, organizations should follow the process outlined above: assign ownership, provide resources, track progress, test mitigation measures, and make conscious decisions about which risks to accept.
If your organization needs help turning its risk register into a practical risk-mitigation program, MHA Consulting can help. Contact us to learn how our consultants can help you assess your risks, prioritize mitigation efforts, and turn your risk information into action.
A risk register is a prioritized record of the significant threats and risks an organization faces, typically assessed according to their likelihood and potential impact.
Creating a rigorous risk register requires gathering and analyzing information from internal and external sources and consulting knowledgeable people across the organization. Done well, it provides a comprehensive picture of the organization’s most significant exposures.
A risk register provides information, not protection. Its value comes from using it to identify, prioritize, and act on opportunities to mitigate significant risks.
It can assign owners to significant risks, determine appropriate mitigation measures, provide the necessary resources, track progress, test mitigation measures, and keep leadership involved.
No. Organizations may reasonably accept some risks when mitigation would be disproportionate to the likelihood or potential impact. The important thing is that those decisions are deliberate and informed rather than the risk simply being overlooked.