IT Performance Improvement

IT Performance Improvement Home

IT Today

Auerbach Publications

Book Catalog


Author Guidelines

Share This Article

New Books

Delivering Successful Projects with TSP and Six Sigma: A Practical Guide to Implementing Team Software Process

Six Sigma Software Development, Second Edition

Interpreting the CMMI: A Process Improvement Approach, Second Edition


Subscribe to IT Performance Improvement

Powered by VerticalResponse


Ranking Risks: Rare to Certain, Negligible to Catastrophic

ExecutiveBrief Staff

Risks your project or business is exposed to may be worth reviewing now more than ever to see which ones need more attention than others.

Risk is a concept that denotes a potential negative impact to an asset or some characteristic of value that may arise from some present process or future event. In everyday usage, risk is often used synonymously with the probability of a known loss. Risk is measured in terms of impact and likelihood. Since risk is directly correlated to loss, it is important to be able to assess risks in one's business and to address them. Needless to say, inattention to risks can definitely affect a company's bottom line.

Some businesses actually go by without a formal risk assessment policy, nor is there a unit that directly assesses the impact of risks in the organization. We have been so accustomed to risk in our everyday lives that the tendency is to ignore minor ones and react when major ones occur. Moreover, effective risk management carries with it some costs, which, when presented to stakeholders, naturally would lead to questions on how the costs could be justified.

Risk management is a modern buzz word but in no means a new science. More and more businesses and organizations recognize the need to identify risks within them so that they can be controlled and mitigated. It is important to exercise risk mitigation when it affects people, the environment, and one's business, to name a few. Risk avoidance cannot make the potential of even greater loss from happening go away.

The question is, as a manager, how would I know which particular sets of risks need a special level of attention? Given limited resources, how would I know which particular types of risks need to be prioritized and addressed?

A risk matrix is a risk assessment tool that exposes aspects of risks that could be subjected to some form of ranking. The matrix has ranges of consequence and likelihood as axes. A risk matrix shows the manager and the decision maker a clearer view of what the risk is, what is involved (in terms of procedural changes, costs, behavioral adjustments, and the like), and what amount of time can be afforded given the severity and probability of the risk event. It can help you visualize, in an organized manner, the risks you face in quantitative and qualitative terms and plan and make a more informed decision when the situation arises.

How does you construct an effective risk matrix?

  1. Identify why you're using the risk matrix. Normally a risk matrix is called for during exercises involving hazard analyses, facility siting studies, and safety audits. Depending on the intended use of the matrix, one may need to establish tolerance or risk acceptability levels and a means of assessing the effectiveness of risk mitigation measures.
  2. Define the consequence and likelihood ranges. A typical risk matrix is a four by four grid. On the Y (vertical) axis is the "Probability/likelihood" description range while on the X (horizontal) axis is the "Consequence" range.
  3. Translate the tolerability criteria into the matrix. The design of the matrix (Table 4) should be able to show clearly which of the blocks are intolerable or tolerable. For example, a Possible (Rank 3 Likelihood) intersecting with a Catastrophic (Rank 4 Consequence) would be intolerable for any business, given the description and values you have previously assigned. This block is a clear subject of risk mitigation efforts in the organization compared to a block (risk) pertaining to a Negligible (Rank 1 Consequence) intersecting with a Certain (Rank 2 Likelihood) which could be addressed, say, with a simple change or adjustment in organizational policy.

Table 1. Sample Risk Matrix

The consequences of risks as laid down in the grid use descriptive words and are ranked according to severity: Negligible, Marginal, Critical, and Catastrophic. Negligible risks are the least severe and would be assigned the lowest rank. Inversely, catastrophic risks are those that would be first in the severity ranking. Determine tolerance by assigning dollar values to each severity ranking, as well as some qualitative characteristics of the consequence being described. For example, Negligible Risks are those that involve USD 2,000 but less than USD 10,000 and could result in minor illness or injury to employees not exceeding a day, does not violate laws, or has little or minimal environmental damage and will be assigned Rank 1 in the matrix. Catastrophic Risks are those that involve USD 1M, could result in death or permanent disability, result in irreversible environmental damage or permanent closure to business, and will be assigned Rank 4 in the matrix.

RankRangeAmount of Loss in USDDescription of Loss
4Catastrophic1M or more- Results in death or permanent disability of employees
- Irreversible environmental damage
- Closure to business
3Critical200,000 but less than 1M- Results in partial permanent disability, injuries or illness of 3 employees or more
- Reversible environmental damage
- Violation of law/regulation
2Marginal10,000 but less than 200,000- Injury or illness of resulting in one or more work days lost
- Mitigatible environmental damage where restoration activities can be done
- Injury or illness of resulting in one or more work days lost
- Mitigable environmental damage where restoration activities can be done
1Negligible2,000 but less than 10,000- Minor illness or injury to employees resulting in one day's absence
- Does not violate laws
- Little or minimal environmental damage

Table 2. Sample Consequence Ranking

The Probability axis describes the likelihood of the risk happening and can be assigned either Frequent, Probable, Occasional, Remote, or Improbable, or simply Certain, Likely, Possible, Unlikely, or Rare. Again, it would be helpful to state the likelihood criteria in numeric terms (example, "Possible" means the risk will occur several times in a lifetime but not less than 10 times nor over 100 times in that lifetime) and to assign logical rankings.

RankRangeProbability (over the life of a business)Description
5CertainOnce in 2 yearsContinually experienced
4LikelyOnce in 4 yearsWill occur frequently
3PossibleOnce in 6 yearsWill occur several times
2UnlikelyOnce in 12 yearsUnlikely, but can be reasonably expected to occur
RareOnce in 24 yearsUnlikely to occur, but possible

Table 3. Sample Probability Ranking

Once the criteria for consequence and likelihood has been laid down, proceed to determine specific incidents, events or conditions that pose risk for the business and assign them along the blocks in the matrix. Example of an incident in the office would be "burst pipes and leaks." This could be assigned in the block Rare (Rank 5 Likelihood) and Negligible (Rank 1 Consequence).

Table 4. Determining Tolerance Points in the Matrix

Care in Assigning Values
Risk matrices are fairly easy to construct and understand. However, one has to be careful in assigning values, taking care not to be overly quantitative and not affording to include what is called a 'layer of protection' approach: a means of including protective measures, which, when applied, brings down the risk a level lower. As in all planning and risk management efforts, it is recommended that the risk planner or analyst, even the manager, exercise conservatism in its design as well as point out areas of alarm. Decision makers are recommended to use this tool in policy formulation and include budgetary allocations to address not only persistent risks but also be ready for potentially catastrophic ones.

Related Reading

Introduction to Process Improvement and the CMMI

How Six Sigma Can Help the System Development Process

© Copyright 2009 ExecutiveBrief. Used by permission.

© Copyright 2009 Auerbach Publications