Risks
A risk is a scenario that materialises a feared event. In the analysis, each risk is associated with a single feared event, while a given event can give rise to several risks.
Generate the risks
Click the Generate button to launch generation by the AI. It relies on the list of feared events validated at the previous step and suggests, for each, one or more risks, accompanied by a criticality and a treatment.
As on all Generate buttons of the platform, the magic wand (targeted generation) and the generation history are available here. Learn more
Risks table
Risks are presented in a summary table:
| Column | Content |
|---|---|
| ID | Unique identifier of the risk |
| Description | Risk label |
| Linked event | Associated feared event (a single one) |
| Criticality | Low / Medium / High / Very high |
| Treatment | Reduce / Avoid / Accept / Transfer |
| Actions | Edit, Delete, Details |
The four treatment modes
The choice of treatment determines the strategy to adopt for the risk:
| Treatment | Definition |
|---|---|
| Reduce | Put in place security measures to lower the likelihood and/or impact of the risk |
| Avoid | Remove the source of the risk by modifying the activity concerned |
| Accept | Explicit decision to take on the residual risk, with monitoring conditions |
| Transfer | Pass the risk to a third party (insurance, subcontracting, etc.) |
Each treatment mode is accompanied by its description in the interface, to help you choose the one best suited to the context.
View the details of a risk
The Details action opens a side panel structured into several sections.
Risk section
This section presents the raw assessment of the risk (before applying any measure):
- Raw impact — impact level if the risk materialises
- Raw probability — probability of occurrence
- Criticality — synthetic level derived from impact and probability
Linked feared event section
You will find the ID and description of the feared event to which the risk is attached. This reminder helps keep the link with the analysis chain.
Risk sources section
Risk sources describe the actors or elements at the origin of the scenario. For each source, you fill in five characteristics, all assessed on four levels:
- Nature
- Probability level
- Motivation
- Resources
- Activity
You can also manually add a source via the dedicated button, if the sources generated by the AI do not cover the entire scope.
Comments
A comments area lets you annotate the risk throughout the analysis.
View the criticality matrix
The Matrix button (icon made of two overlapping squares) displays the position of the risk in the organisation's criticality matrix. Three positions are represented on the same matrix:
- Raw position — without any measure applied
- Current position — taking into account existing measures and their implementation status
- Target position — position targeted once all measures are implemented
To the right of the matrix, the list of measures linked to the risk lets you visualise at a glance the treatment plan and its expected impact.
Use the matrix to track the gap between the raw position and the target position. The larger this gap, the more ambitious the measures plan.
Add a risk manually
As with feared events, you can add a risk manually if the AI has not covered a scenario you consider important. You must then attach it to an existing feared event.
Move to the next step
Once the risks are assessed and consolidated, move to the Remediation measures tab to define the treatment plan.