Skip to main content

Risks

A risk is a scenario that materialises a feared event. In the analysis, each risk is associated with a single feared event, while a given event can give rise to several risks.

Generate the risks

Click the Generate button to launch generation by the AI. It relies on the list of feared events validated at the previous step and suggests, for each, one or more risks, accompanied by a criticality and a treatment.

info

As on all Generate buttons of the platform, the magic wand (targeted generation) and the generation history are available here. Learn more

Risks table

Risks are presented in a summary table:

ColumnContent
IDUnique identifier of the risk
DescriptionRisk label
Linked eventAssociated feared event (a single one)
CriticalityLow / Medium / High / Very high
TreatmentReduce / Avoid / Accept / Transfer
ActionsEdit, Delete, Details

The four treatment modes

The choice of treatment determines the strategy to adopt for the risk:

TreatmentDefinition
ReducePut in place security measures to lower the likelihood and/or impact of the risk
AvoidRemove the source of the risk by modifying the activity concerned
AcceptExplicit decision to take on the residual risk, with monitoring conditions
TransferPass the risk to a third party (insurance, subcontracting, etc.)

Each treatment mode is accompanied by its description in the interface, to help you choose the one best suited to the context.

View the details of a risk

The Details action opens a side panel structured into several sections.

Risk section

This section presents the raw assessment of the risk (before applying any measure):

  • Raw impact — impact level if the risk materialises
  • Raw probability — probability of occurrence
  • Criticality — synthetic level derived from impact and probability

Linked feared event section

You will find the ID and description of the feared event to which the risk is attached. This reminder helps keep the link with the analysis chain.

Risk sources section

Risk sources describe the actors or elements at the origin of the scenario. For each source, you fill in five characteristics, all assessed on four levels:

  • Nature
  • Probability level
  • Motivation
  • Resources
  • Activity

You can also manually add a source via the dedicated button, if the sources generated by the AI do not cover the entire scope.

Comments

A comments area lets you annotate the risk throughout the analysis.

View the criticality matrix

The Matrix button (icon made of two overlapping squares) displays the position of the risk in the organisation's criticality matrix. Three positions are represented on the same matrix:

  • Raw position — without any measure applied
  • Current position — taking into account existing measures and their implementation status
  • Target position — position targeted once all measures are implemented

To the right of the matrix, the list of measures linked to the risk lets you visualise at a glance the treatment plan and its expected impact.

tip

Use the matrix to track the gap between the raw position and the target position. The larger this gap, the more ambitious the measures plan.

Add a risk manually

As with feared events, you can add a risk manually if the AI has not covered a scenario you consider important. You must then attach it to an existing feared event.

Move to the next step

Once the risks are assessed and consolidated, move to the Remediation measures tab to define the treatment plan.