Category: Risk identification & assessment · Reviewed by Amy Price, Account Executive · Last reviewed
A risk assessment methodology is the documented approach an organisation uses to identify, analyse and evaluate risk. ISO 31000:2018 splits risk assessment into three sequential steps: identification, analysis and evaluation.
The systematic search for events that could affect objectives. Outputs: a populated risk register. Tools: hazard identification, HAZOP, FMEA, bowtie, scenario analysis.
The understanding of the nature of each risk — its sources, likelihood, consequence and the effectiveness of existing controls. Outputs: scored entries on a defined matrix. Tools: quantitative (Monte Carlo, GLMs), qualitative (likelihood-impact scoring) or semi-quantitative.
The comparison of analysed risks against risk criteria — appetite, tolerance, legal duty, ethical limits — to decide which require treatment, which can be accepted and which require escalation. Outputs: prioritised treatment plans.
A defensible methodology document records:
Maintained by Matt Bartlett, Director, Apex Insurance Brokers Limited. FCA FRN 724952. Companies House 07014570.
Apex Insurance Brokers serves UK professional services firms and commercial businesses. Call 0117 325 0027, email hello@apexinsurancebrokers.co.uk, or request a quotation.
Get a quote