Risk analysis is the systematic process of identifying, characterising and estimating the likelihood and impact of events that could threaten objectives, in order to inform decisions about how to treat them. It combines qualitative judgement with quantitative techniques such as scenario modelling and probabilistic simulation to express uncertainty in actionable terms. As a core component of risk management, it produces the evidence base for prioritising controls, allocating capital and setting tolerances.

Overview

  • Risk analysis bridges raw data and governance decisions by quantifying exposure under uncertainty.
  • It spans the lifecycle from hazard identification through estimation to evaluation against tolerance thresholds.
  • Outputs feed control selection, capital allocation and board-level reporting.

Key aspects

  • Qualitative scoring using likelihood-impact matrices for rapid triage.
  • Quantitative estimation with probability distributions and simulation.
  • Sensitivity and scenario testing to surface dominant drivers.
  • Aggregation of correlated risks into portfolio-level views.

Applications

  • Financial and operational risk assessment.
  • Project, safety and compliance reviews.
  • Cyber-security threat and impact prioritisation.

Provenance