Three risk tips for busy people
Don’t worry, this won’t be another post about the pros and cons of the ISO 33000 suite: I’m not a risk professional, though I’m learned a lot from a few of them. What I’ll share are three gems that should help you contribute to risk discussions more effectively.
Famously, ISO 33000 isn’t a standard that you can be certified to - it’s set of guidelines (and I promise, that’s the last ISO reference you’ll hear). This checks out, because every ‘risky’ I’ve spoken to has a slightly different take, and I can’t imagine them getting into a room together (aside from the obvious business continuity risk in doing that) and agreeing to a standard. This means that every place you work at will be using slightly different language when talking about risks. One place has hazards, another has threats, and another has sources. But all well-defined risks have three components: a beginning (the hazard, threat, or source), a middle (the event which means the hazard, threat or source has a consequence), and an end (the consequence, impact, or what have you). Here’s an example in a previous post about reporting.
Second tip - there’s a lot of language about risk tolerance and risk appetite, but the easiest way to figure out what to do about a risk (mitigating it) is whether the cost of doing something outweighs the consequence if the risk eventuates. Pet insurance is a good example - for some people, paying for pet insurance is more expensive in the long run than simply putting a bit of money aside and accepting the risk.
Finally, in theory, risks can be positive (upside risks, or opportunities). In practice, several riskys have told me that it seems that trying to have discussions about opoprtunities at the same time as risks doesn’t seem to work. Maybe it’s cognitively challenging to switch between thinking about things going wrong to things going right …. or maybe no-one’s figured out a colour scheme for an opportunity matrix that doesn’t confuse people yet - and effectively, a lot of business case and strategy / business planning processes already apply a likelihood / consequence approach in terms of the cost of implementation against the benefits. For more about benefits, see this piece on benefits realisation.