All public sector entities face risks that can affect their ability to achieve organisational objectives and deliver reliable public services. Performing a risk assessment helps entities better understand their risks, assess the potential impacts, and as a result, determine how they should prioritise and assign resources to address them. A structured assessment process supports consistent decision-making and sufficient oversight.
Our first blog in this series, Risk management – where do we start?, introduced the principles of risk management and discussed our Risk management maturity model tool.
In this blog, we provide a high-level summary of how to perform a risk assessment and determine an overall risk rating.
Assessing inherent risk
Inherent risk is the level of risk that exists before the entity considers any controls, treatments, or other actions they may take to mitigate the risk. Inherent risk is assessed by measuring the likelihood and the consequence of a risk event occurring.
Assessing the likelihood of a risk
Entities should use available evidence and professional judgement when assessing the likelihood of a risk event occurring. Sources of information may include historical incidents, audit findings, trend analysis, industry reports, vulnerability assessments, and staff insights.
The likelihood of a risk occurring may range from rare to almost certain, with each likelihood based on the probability of it occurring. For instance, a risk classified as ‘almost certain’ may suggest a 90 per cent probability of it occurring. The table below provides an example of how an entity may choose to measure and rate the likelihood of risks occurring.
| Measurement | Rating | Likelihood of occurring |
|---|---|---|
| Almost Certain | 5 | High probability. Expected to occur in most circumstances (90%). |
| Likely | 4 | Likely to occur. Will probably occur in most circumstances (50%). |
| Possible | 3 | Might occur. Within a 5-year period (20%). |
| Unlikely | 2 | Could occur. Within a 5-10-year period (10%). |
| Rare | 1 | May occur in exceptional circumstances. Once every 10 years or more (1%). |
Note: The example above is illustrative only. Entities should develop likelihood measures based on their individual circumstances.
To illustrate this, let's consider an example called ‘Entity A’, which is assessing its cyber security risks. Entity A considers its vulnerability and incidents reports, penetration testing results, employee awareness, and cyber security trends. It determines that without appropriate controls in place, there is at least a 50 per cent chance of a cyber security breach occurring. Using the above table, it would rate the likelihood of cyber security breaches as likely.
Assessing the consequences of a risk
Entities must also evaluate the consequences of risks occurring. Consequences represent the potential impacts on an entity if the risk event happens and may range from insignificant to catastrophic.
When assessing consequences, entities should consider impacts on:
- strategic objectives
- service delivery
- finances
- compliance obligations
- reputation
- people and community outcomes.
Establishing meaningful measures of consequences that are tailored to the entity facilitates consistent ranking of risks. Entities should tailor consequence measures to their organisation’s size, operations, stakeholders, and risk profile. This may include defining the consequences into various risk categories, such as financial risks, occupational health and safety risks, political risks, and so on. The entity would then provide a quantitative and/or qualitative descriptor for each consequence.
In measuring financial risks, entities may define each consequence as a financial loss within a dollar range or as a percentage of a financial statement line item (for example, total revenue or total expenses).
The table below provides an example of how any entity may define its consequences for financial and non-financial (in this case security) risks.
| Consequence | Insignificant | Minor | Moderate | Major | Catastrophic | |
|---|---|---|---|---|---|---|
| Financial | Loss < $100,000 | Loss > $100,000 but < $1 million | Loss > $1 million but < $10 million | Loss > $10 million but < $100 million | Loss of > $100 million | |
| Security | No disruption to services. Loss or compromise of official information. No damage to reputation. | Minimal disruption to services. Loss or compromise of sensitive information. Minimal damage to reputation. | Moderate disruption to key systems resulting in lost time. Loss or compromise of sensitive information that may cause harm to affected individuals. Moderate damage to image or reputation. | Prolonged disruption to key systems. Loss or compromise of sensitive information likely to pose a threat to individual safety or welfare. Significant damage to image or reputation. | Inability to perform functions. Loss or compromise of protected information. Reputation and standing are adversely affected nationally and internationally.
| |
Note: The example above is illustrative only. Entities should develop consequence measures based on their individual circumstances.
Using our example of Entity A, it may assess that the consequences of a cyber security breach would include:
- prolonged loss of critical services
- loss of sensitive information that poses a threat to individual safety or welfare
- financial losses of $10 million
- significant damage to its reputation such that the public lose confidence in its ability to deliver efficient and effective public services.
In this instance, Entity A would assess the consequences of cyber security breaches as major.
Determining the inherent risk rating
Entities can use a risk matrix to combine the likelihood of the risk occurring with the consequence should such a risk occur. It shows the likelihood of a risk occurring on one axis and its consequence on another, and uses these results to determine the inherent risk rating – for example, low (L), moderate (M), high (H), and extreme (E).
By plotting risks on a risk matrix, an entity can visually sort higher risks from lower ones. This helps management identify which risks require urgent attention and need to be reported to management and the board, or other oversight body. It should also drive how the entity determines what controls or treatments it will put in place to mitigate the risk.
In Entity A's case, the likelihood is assessed as likely and the consequence as major. This results in the cyber security risk being rated as Extreme (E).
Example of a risk matrix
Note: The example above is illustrative only. Entities should determine different risk rating combinations based on their individual circumstances.
Considering risk treatment and residual risks
After determining the inherent risk rating, entities should consider the controls in place to manage each risk. This requires an assessment of whether the controls are appropriately designed to mitigate the risk and if they are operating effectively.
The inherent risk rating should determine the extent or strength of controls required to mitigate the risk. Risks with a higher inherent risk rating will require more, or stronger, controls to mitigate the risk. Alternatively, entities can also use this assessment to ensure that they are not over-investing in controls to mitigate risks that have a low inherent risk.
The effectiveness of the controls will determine the residual risk. This is the risk that remains after an entity applies controls. Depending on the effectiveness of those controls, residual risk may be assessed as low, medium, or high.
Where residual risk remains above an acceptable level, entities should determine how to treat it. Common treatment options include:
- avoiding the activity creating the risk
- reducing the risk through additional controls
- transferring the risk to a third party
- accepting the risk where it falls within approved tolerances.
For example, if in Entity A's case, its residual cyber security risk is rated as medium after applying the controls, it may need to take additional action to further mitigate the risk. Entity A could manage its risks by implementing additional cyber security controls like multi-factor authentication or discontinuing recording of sensitive data for which there is no business purpose. It could also transfer risks by purchasing cyber insurance and accept some inherent risk in customer data storage while implementing security measures for mitigation.
Documenting the risk
Once entities have assessed their risks, they should document the results in a risk register and review them regularly. Documenting risks supports monitoring, reporting, accountability, and informed decision-making.
Keep an eye out for our next blog in this series which will explain what information entities should include in a risk register and how a reliable register supports effective risk management and reporting.
Resources
Better practice
Blogs