Capability domain
Risk, Impact & Harm Analysis
Learn to make risk analysis defensible, get help doing it, and have it audited
Risk information a decision can actually be made on
Risk capability is not a register. It is the reasoning that produces one: how activities, technologies and external conditions create harm, disruption or loss, how significant that is, and which exposures deserve attention before the others.
Overview
The register gets the attention the reasoning deserves
Most risk work produces a register and stops there. The register is the artefact, so it gets the attention: fields filled, scores assigned, review dates set, and a colour that moves when somebody argues for it.
A register is only as good as the reasoning behind it, and the reasoning is rarely written down: the exposure someone thought of and the one nobody raised look identical once both are rows. The test is whether the analysis has ever changed a decision that had already been made.
Academy
Deepen your expertise
All modules →Each module can be taken on its own and trains the calls a practitioner has to make without being prompted. Our professional tracks bundle these modules into role- and discipline-specific curricula, with a final exam and capstone project.
Advisory
Build and improve your risk reasoning
Learn more →We support you in building a structured approach to risk and foresight that identifies what truly matters, assesses potential impact, and enables informed prioritisation and preparedness in uncertain and evolving environments.
The four phases below are the life of a management system, and an engagement can begin at any one of them.
01
Design
Establishing structured risk and foresight capabilities
Establish risk management frameworks and processes
Define risk categories, criteria, and risk appetite
Design scenario analysis and uncertainty approaches
Integrate risk practices into strategy and planning
Design risk reporting and decision-support structures
02
Operate
Applying risk and foresight in daily operations
Perform risk identification, assessment, and prioritisation
Conduct scenario analysis and uncertainty assessments
Maintain and update risk registers
Integrate risk practices into projects and operations
Provide risk reporting and decision support for management
03
Assure
Assessing risk and foresight effectiveness
Conduct independent reviews of risk management frameworks and practices
Evaluate risk identification, assessment, and prioritisation quality
Review scenario analyses and underlying assumptions
Assess integration of risk into decision-making and planning
Prepare risk maturity assessments and management reporting
04
Evolve
Developing risk and foresight capabilities for future readiness
Monitor risks and emerging developments continuously
Refresh scenarios and forward-looking risk analyses
Adapt risk frameworks to organisational and external change
Integrate foresight into strategy and decision-making
Provide executive sparring on uncertainty, resilience, and preparedness
Audit
Assess your risk reasoning
Learn more →An audit of risk reasoning tests what produced the register rather than the register itself: whether exposures were identified by a method or from memory, whether significance was argued rather than scored, and whether the output has ever changed a decision.
Audits are organised by discipline rather than by capability domain, because the criteria they test against live in the standards.
Insights
What we have written on this
All insights →Where do you need support?
A short conversation to understand your current situation and discuss possible next steps.
Other capability domains
By discipline