02 — Capability · BC-130.20
Risk Identification & Assessment
Find the risks that matter before they find the enterprise, and rate their likelihood and impact consistently enough that the top of the list is actually the top.
- Risk Assessment
- Risk Register
- Emerging Risk
In scope
- Enterprise and business-unit risk assessments
- The risk register and its ownership
- Emerging and horizon risk identification
Out of scope
- Project-level risk logs (see BC-180)
- Supplier risk due diligence (see BC-640)
Decomposes into · 4
- BC-130.20.10Risk IdentificationSurface risks through workshops, interviews, incident analysis and external scanning, and capture them in one register.
- BC-130.20.20Risk Analysis & RatingRate each risk for likelihood and impact on the agreed scales, before and after existing controls.
- BC-130.20.30Risk PrioritizationRank risks against appetite so leadership attention goes to the exposures that exceed it, not the ones with the loudest owner.
- BC-130.20.40Emerging Risk IdentificationWatch for risks that are not yet on the register — new regulation, technology, climate, geopolitics — and decide when they belong there.