Risk terminology: what’s the difference between risks, issues and incidents? 您所在的位置:网站首页 risk issue problem Risk terminology: what’s the difference between risks, issues and incidents?

Risk terminology: what’s the difference between risks, issues and incidents?

2023-04-18 16:33| 来源: 网络整理| 查看: 265

Risk terminology: what’s the difference between risks, issues and incidents?

by Amber Gerdes | Jun 2, 2021 | Chief Compliance Officers, GRC Implementation, Risk Management | 0 comments

Stick figure holding an umbrella blocking out rain - text reads "risks, issues, and incidents."

Does your organization know the difference between risks, issues, and incidents when it comes to your risk management?

If you don鈥檛, you鈥檙e not alone. Many organizations don鈥檛 fully understand the difference, and will mistakenly use the terms interchangeably.

Why does this matter? Because once you understand the terms correctly, organizations can better understand their risks and the mitigation activities needed.

For instance, a client may tell us that they have hundreds of risks when instead they actually have hundreds of issues鈥攚hich results in a much different risk management approach!

Using proper risk terminology enables organizations to better communicate their risks internally and with third parties in order to be more proactive and identify proper mitigation activities.

Risks, issues, and incidents鈥攚hat鈥檚 the difference?

Below are terms and brief explanations given for each of these risk terms and others closely associated, followed by an example to better paint the picture of how these risk terms might each be used in a given scenario.

TermDescriptionRiskThe potential (or likelihood) for something bad to happen.IssueWhen there hasn鈥檛 been appropriate mitigation to limit a given risk.IncidentWhen something bad has happened (or the at-risk scenario became an actuality).

Risks

A risk is the potential (or likelihood) of something bad to happen.

The key component to risk is that there is a potential loss at stake for your organization (whether it be financial, reputation, etc.).

Risks can be further broken down in a number of ways, including examining what type of risk it is, the impact (vulnerabilities at stake due to the risk), the likelihood, and the controls (the ability to intervene with a given risk).

When risks are found, follow-up actions will be required, including analyzing the risk, determining the cost to control said risk, and implementing the appropriate mitigation activities.

Issues

An issue (also often referred to as a finding or an observation) is when there hasn鈥檛 been appropriate actions taken to mitigate the risk to an acceptable level.

When an organization recognizes a risk and doesn鈥檛 take the necessary precautions to limit the risks (whether intentionally or unintentionally), it becomes an issue.

However, you can never get an organization鈥檚 risk completely to zero. Every organization must define and establish a level of risk that they鈥檙e comfortable with accepting鈥攁lso known as risk tolerance.

(A finding is an instance when policies or actions to issue risk (also known as mitigations) do not go successfully, therefore creating a risk issue.)

Incidents

An incident is when something bad has happened (but you don鈥檛 yet know if it was a loss event).

An incident involves some sort of negative event tied to a risk. This could be anything from IT-related risks like a data breach or physical risks like a tornado or an employee tripping and falling.

However, there can be a loss-event incidents and non-loss event incidents.

Example:

For clarity鈥檚 sake, we鈥檙e going to use a hypothetical scenario to exemplify the differences between the various risk terminologies and how they each uniquely affect any given risk situation. The scenario we鈥檒l use here is if there was rain predicted in the forecast during your morning commute to work.

In this case, if there is rain predicted in the forecast, the risk is excessive dry cleaning costs or staff morale being lowered because they are getting wet from the rain while walking to the office.

If the staff is wearing nice clothes that could become damaged from the rain, the likelihood of this risk is high, and controls include bringing an umbrella or using a parking garage.

The risk then becomes an issue if you fail to perform the necessary mitigation activities (perhaps you left your umbrella at home or the parking garage was full).

In this case, you would encounter a risk incident when you inevitably get wet from the rain (the potential loss event in this case would be if your clothes required dry cleaning costs or if staff morale was indeed lowered).

Of course, there is much more nuance to a risk register, such as risk threats vs. vulnerabilities or inherent risk values (the likelihood and impact of something bad happening) vs. residual risk (when something bad may still happen but you鈥檝e taken actions to reduce the risk).

However, knowing the key differences between risks, issues, and incidents is a hugely valuable first step when building out your risk database.

If you have any further questions about the nuances between the three or how to approach them differently in a risk management solution, contact us here.

Trackbacks/Pingbacks What Is Potential Loss In Risk Management | kyinbridges.com - […] is calculated as the sum of potential losses from current or planned business activities. A risk incident‘s level of… Submit a Comment Cancel reply


【本文地址】

公司简介

联系我们

今日新闻

    推荐新闻

    专题文章
      CopyRight 2018-2019 实验室设备网 版权所有