Risk Identification and Assessment in Commercial Applications
Learning Objectives
By the end of this page, you should be able to:
- Define risk identification and describe at least three techniques used to find risks.
- Explain the difference between qualitative and quantitative risk assessment.
- Read and construct a likelihood-impact risk matrix.
- Calculate Expected Monetary Value (EMV) for a given risk scenario.
- Apply risk identification and assessment to a realistic business case, such as launching a new e-commerce platform.
Quick Answer
Risk identification and assessment is the process of systematically discovering what could go wrong in a business activity and then measuring how likely each risk is and how much damage it would cause. Identification comes first — through document review, stakeholder interviews, and techniques like SWOT analysis — to build a list of possible risks. Assessment comes next, using either qualitative methods (rating risks as High/Medium/Low) or quantitative methods (assigning dollar values and probabilities, such as Expected Monetary Value). The output is usually a risk matrix that plots likelihood against impact, letting managers see at a glance which risks deserve urgent attention and which can simply be monitored. This process matters because you cannot manage a risk you haven't identified, and you cannot prioritize limited resources without measuring risks against each other.
Overview
Before a business can mitigate a risk, it has to know the risk exists — and know roughly how serious it is compared to every other risk competing for attention. This is the job of risk identification and assessment, the diagnostic stage that sits before any decision about avoidance, insurance, or acceptance.
Think of it like a doctor before treatment: you don't prescribe a remedy until you've identified the symptoms (identification) and measured their severity (assessment). Skipping straight to "solutions" without this diagnostic stage leads to wasted effort on the wrong problems — a company might spend heavily securing a low-probability risk while ignoring one that's both likely and severe.
This chapter builds on Chapter 1's risk management cycle by zooming into its first two steps in detail, using a running example: a company launching a new e-commerce platform.
Core Concepts
Risk Identification
Definition: Risk identification is the systematic process of discovering and documenting potential risks that could affect a project or organization, before they occur.
Explanation: Identification works best when it draws on multiple sources rather than one person's imagination. Reviewing past incident reports and documentation surfaces risks the organization has already learned about. Talking to stakeholders — developers, managers, end users — surfaces risks that live in people's heads but aren't written anywhere. Studying industry trends catches risks specific to the sector (e.g., new payment regulations for fintech). Structured brainstorming techniques like SWOT analysis or mind-mapping catch risks nobody thought to look for directly. Using several methods together compensates for the blind spots each one has individually.
Example: A team identifies "third-party payment gateway becomes unavailable" as a technical risk by reviewing a vendor's past outage history.
Real-World Example: A company building a new e-commerce platform runs identification across three lenses — technical (compatibility issues with payment gateways, scalability under high traffic, security vulnerabilities), operational (supplier integration delays, multi-location inventory challenges, GDPR compliance), and financial (development cost overruns, fraud losses, unplanned marketing spend).
Why It Matters: A risk that's never identified can't be assessed, mitigated, or monitored — it simply waits to become a costly surprise. Thorough identification is the foundation the entire risk management process rests on.
Common Misunderstanding: Students often assume risk identification is a single brainstorming session at project kickoff. In practice, new risks appear as a project evolves (a new competitor enters, a regulation changes), so identification should be repeated at key milestones, not treated as a one-off exercise.
Qualitative Risk Assessment
Definition: Qualitative assessment rates a risk's likelihood and impact using descriptive categories — typically High, Medium, or Low — rather than precise numbers.
Explanation: Qualitative assessment is fast and doesn't require hard data, which makes it useful early in a project or when good statistical data doesn't exist yet. A risk manager (often with input from a team) assigns a likelihood rating and an impact rating, and the two combine to form an overall risk level. It's inherently subjective — two managers might rate the same risk differently — but it's still far better than no assessment at all, and it's usually the fastest way to get a first-pass priority list.
Example: Rating "data breach" as Medium likelihood and High impact.
Real-World Example: For the e-commerce platform, the team rates data breach as High impact/Medium likelihood, financial loss from fraud as High impact/High likelihood, and reputational damage as High impact/High likelihood — immediately flagging financial loss and reputational damage as the two risks needing the most urgent attention.
Why It Matters: Qualitative assessment gives teams a quick, shared vocabulary for comparing very different types of risk (a legal risk vs. a technical risk) without needing to convert everything into dollars first.
Common Misunderstanding: Some students treat "High/Medium/Low" ratings as objective facts. They're judgments, shaped by whoever is doing the rating — which is why many organizations require ratings to be reviewed by more than one person or cross-checked against a rubric.
Quantitative Risk Assessment and the Risk Matrix
Definition: Quantitative assessment assigns numerical values — probabilities and monetary amounts — to risks, most commonly through the Expected Monetary Value (EMV) method, decision tree analysis, or Monte Carlo simulation. A risk matrix is a grid that plots likelihood against impact to visually prioritize risks.
Explanation: EMV multiplies the probability of a risk occurring by its financial impact if it does, giving a single number that represents the "average" cost of that risk over many repetitions. This lets managers compare risks on the same numerical scale and decide, for example, whether spending $15,000 on prevention is worth it against a risk with an EMV of $20,000. The risk matrix takes qualitative or quantitative ratings and arranges them visually — likelihood on one axis, impact on the other — so that risks needing urgent action (top-right: high likelihood, high impact) are immediately distinguishable from risks that can simply be monitored (bottom-left: low likelihood, low impact).
Example: A project has a 20% chance of a delay costing $100,000. EMV = 0.20 × $100,000 = $20,000 - meaning, on average, this risk is "worth" $20,000 of expected cost, a number that can be directly compared to the cost of preventing it.
Real-World Example: In the e-commerce risk matrix, security vulnerabilities (high likelihood, high impact) and GDPR compliance failures (medium likelihood, high impact) land in the "urgent action" zone, while marketing budget overruns (low likelihood, medium impact) fall into the "monitor" zone — telling the project manager exactly where to focus limited security and compliance budget first.
Why It Matters: Without a matrix or EMV figure, all risks look equally urgent on a list. These tools convert a flat list into a ranked, visual priority order that supports better resource allocation.
Common Misunderstanding: Students sometimes think a "Critical" cell in the risk matrix means the event is certain to happen. It means the combination of likelihood and impact is severe enough to demand immediate action — the event may still never occur, but the potential consequences are too large to ignore.
Visual Learning
Key Terms
| Term | Definition | Context / Related Concepts |
|---|---|---|
| Risk Identification | Discovering and documenting potential risks before they occur | First stage; feeds into assessment |
| Qualitative Assessment | Rating risk likelihood/impact using descriptive labels (High/Medium/Low) | Fast, subjective; good for early-stage screening |
| Quantitative Assessment | Rating risk using numerical probability and monetary impact | Requires data; supports cost-benefit comparisons |
| Expected Monetary Value (EMV) | Probability of a risk × its financial impact | Produces a single comparable number for budgeting decisions |
| Risk Matrix | A grid plotting likelihood against impact to visually rank risks | Common output of both qualitative and quantitative assessment |
| SWOT Analysis | A brainstorming framework examining Strengths, Weaknesses, Opportunities, Threats | One technique used during risk identification |
| Decision Tree Analysis | A quantitative method mapping out possible decisions and their probable outcomes | Used for complex, multi-stage risk decisions |
Common Mistakes
Misconception 1: "A risk rated 'Low' can be ignored." Why it's wrong: A low rating on the matrix reflects likelihood and impact at the time of assessment, not a permanent judgment — conditions change, and low-probability risks can still be catastrophic (e.g., a rare but severe data breach). Correct understanding: "Low" risks are typically monitored, not ignored — they're reassessed periodically rather than removed from tracking.
Misconception 2: "Quantitative assessment is always more accurate than qualitative." Why it's wrong: Quantitative methods like EMV are only as good as the probability and cost estimates fed into them; guessing a probability of "20%" without real data isn't more objective than a qualitative "Medium" rating. Correct understanding: Quantitative assessment is more precise when reliable data exists, but with poor data it can create false confidence. Many organizations use qualitative screening first, then apply quantitative analysis only to the top-priority risks.
Misconception 3: "Risk identification is finished once the initial risk list is written." Why it's wrong: New risks emerge as a project or business evolves — new competitors, new regulations, new technology dependencies. Correct understanding: Identification should be revisited at project milestones and during regular reviews, feeding continuously into reassessment.
Comparison and Connections
| Concept | Purpose | Data Required | Typical Use Case |
|---|---|---|---|
| Qualitative Assessment | Fast prioritization using descriptive ratings | Expert judgment, minimal data | Early-stage screening of many risks |
| Quantitative Assessment (EMV) | Precise cost-based comparison | Historical data or reliable estimates | Deciding whether a specific mitigation is worth its cost |
| Risk Matrix | Visual prioritization tool | Output of qualitative or quantitative ratings | Communicating priorities to stakeholders |
| Risk Identification | Finding risks before assessing them | Documents, interviews, brainstorming | Start of the process, in every project |
Practice Questions
Recall
- Name three techniques used during risk identification. Answer guidance: Reviewing documentation/history, stakeholder interviews, and brainstorming techniques (SWOT analysis, mind mapping).
- What two factors combine to determine a risk's position on a risk matrix? Answer guidance: Likelihood (probability of occurrence) and impact (severity of consequences).
Understanding
- Explain the difference between qualitative and quantitative risk assessment. Answer guidance: Qualitative assessment uses descriptive categories (High/Medium/Low) based on judgment; quantitative assessment assigns numerical probabilities and monetary values, producing comparable figures like EMV.
- Why might an organization use qualitative assessment first and quantitative assessment only for top-priority risks? Answer guidance: Quantitative analysis takes more time and data to perform accurately; qualitative screening quickly narrows a long risk list down to the few risks worth the deeper quantitative effort.
Application
- A project has a 30% chance of a compliance fine costing $50,000. Calculate the EMV and explain what the number means for budgeting. Answer guidance: EMV = 0.30 × $50,000 = $15,000. This means the risk is worth budgeting roughly $15,000 for — if a compliance fix costs less than this, it's likely worth doing; if it costs significantly more, the company might accept the risk instead.
- An e-commerce startup identifies "scalability issues during high-traffic sales events" as a risk. Walk through how you would identify and then assess this risk. Answer guidance: Identification: review past traffic spikes, interview the engineering team about system limits, check industry benchmarks for similar platforms. Assessment: rate likelihood (e.g., High, given a planned promotional sale) and impact (e.g., High, since downtime during a sale directly costs revenue), placing it in the "urgent action" zone of the matrix.
Analysis
- Two risks have the same EMV: Risk A has a 90% chance of a $10,000 loss; Risk B has a 5% chance of a $180,000 loss. Both round to roughly the same EMV. Should a manager treat them identically? Justify your answer. Answer guidance: No — EMV treats them as equivalent on average, but Risk B carries far more severe consequences if it occurs (potentially threatening the business), while Risk A is a near-certain, manageable cost. A manager should weigh risk tolerance and worst-case severity, not just the expected value, especially for low-probability/high-impact risks.
- Critique the following statement: "If our risk matrix has no 'Critical' risks, we don't need to worry about risk management this quarter." Answer guidance: This is flawed because risk levels change over time and new risks can emerge between review periods; also, a lack of "Critical" ratings might reflect outdated assessments rather than actual safety. Risk identification and assessment need to be repeated regularly, not treated as a static, one-time clearance.
FAQ
Q1: Do I need real historical data to do a quantitative risk assessment? Ideally yes, but when historical data isn't available, teams use reasoned estimates from experts or industry benchmarks. The EMV calculation is only as reliable as the probability and impact figures you put into it.
Q2: What's the difference between "impact" and "likelihood" on a risk matrix? Likelihood is how probable the event is (will it happen?). Impact is how bad the consequences would be if it did happen. A risk needs both dimensions assessed — a highly likely but trivial risk (a printer jam) is very different from an unlikely but catastrophic one (a major data breach).
Q3: Can a risk have a positive impact? Yes — in formal risk terminology, a "risk" is any uncertain event that could affect objectives, which includes positive risks (opportunities), like discovering a cheaper, faster development method mid-project. Most business focus goes to negative risks (threats), but both types are technically part of risk identification.
Q4: How often should a company redo risk identification? At minimum, at major project milestones or annually for ongoing operations — but also immediately after any significant change, such as launching a new product line, entering a new market, or a regulatory update.
Q5: Is a risk matrix the same as a risk register? No. A risk register is a detailed log listing every identified risk along with its owner, description, and status. A risk matrix is a visual summary tool that plots those risks by likelihood and impact to aid prioritization — many organizations use both together.
Quick Revision
- Risk identification comes before assessment — you can't assess what you haven't found.
- Identification techniques: document review, stakeholder interviews, industry trend analysis, brainstorming (SWOT, mind-mapping).
- Qualitative assessment = descriptive ratings (High/Medium/Low); fast but subjective.
- Quantitative assessment = numerical values; EMV = Probability × Impact.
- EMV lets you compare the cost of a risk against the cost of preventing it.
- A risk matrix plots likelihood (one axis) against impact (other axis) to visually prioritize risks.
- High likelihood + high impact = urgent/critical zone; low + low = monitor zone.
- A "Low" rating means monitor, not ignore — ratings change over time.
- Quantitative precision is only as good as the underlying data/estimates.
- Risk identification should be repeated at milestones, not done once and forgotten.
- Assessment results feed directly into mitigation strategy selection (Chapter 3).
Related Topics
Prerequisites: Introduction to Risk Management (Chapter 1) — understand the overall risk cycle before diving into identification and assessment techniques.
Related Topics: Risk Mitigation Strategies (Chapter 3), Risk Management Frameworks (Chapter 6).
Next Topics: Move to Chapter 3, Risk Mitigation Strategies, to learn how the priorities generated here (via the risk matrix) translate into concrete action — avoidance, reduction, transfer, or acceptance.