
Risk mapping: moving from a static picture to a decision tool
Risk maps are often produced to satisfy governance or audit expectations. Their real value lies elsewhere: helping leaders choose, prioritise resources and monitor the risks that could materially compromise strategy.
Why risk maps become obsolete so quickly
The traditional exercise uses interviews, a risk list and a probability-impact matrix. It can provide a useful picture at one point in time, but relevance fades rapidly when assumptions, incidents, projects and decisions do not continuously update it.
Update frequency is only part of the issue. A map becomes difficult to act on when risks are too broadly worded, several causes are mixed together or the assessment ignores existing controls. Everything appears important and management no longer knows where to focus.
Begin with objectives and decisions
Risk does not exist in isolation; it threatens an objective. The process should begin with strategic priorities, regulatory commitments, critical projects and essential processes. This foundation makes risk statements more precise and identifies the decisions they may influence.
For every risk, distinguish causes, the potential event and its consequences. This discipline improves analysis and avoids generic responses. It also allows leading indicators to be connected to causes instead of measuring only losses after they occur.
Assess residual exposure consistently
Impact and likelihood are not always sufficient. Depending on the activity, it may be useful to consider speed of onset, duration, detectability and preparedness. The scale should remain simple enough to understand and precise enough to distinguish priorities.
Residual-risk assessment also requires an honest view of control effectiveness. A documented control that is not performed does not reduce exposure. A control performed without evidence or without resolving exceptions provides limited assurance. Scoring should therefore rely on verifiable information.
Connect every priority to a response and an owner
A map without treatment plans produces information but little change. Every priority risk needs an owner with decision authority, a target risk level, a chosen response and funded actions. Deadlines and dependencies must be explicit.
The risk owner is not necessarily the person performing every action. The owner is accountable for exposure, resolves trade-offs and escalates when accepted levels may be exceeded. That responsibility should be visible in performance reviews and governance committees.
Establish a light but regular management cycle
The complete map may be reviewed annually, but priority risks need a shorter rhythm. A quarterly dashboard, or a monthly one for critical exposures, is often sufficient when it focuses on change, early-warning indicators, incidents and overdue actions.
COSO's enterprise-risk framework emphasises the connection between risk, strategy and performance. Risk discussion should therefore not remain isolated in a technical committee. It should feed investment choices, projects, budgets and operating decisions. At that point, risk mapping stops being an obligation and becomes a management capability.
- Track the risks that are changing, not only the full register.
- Present the decisions required, not only the scores.
- Measure progress on responses and their effect on exposure.
- Review the map immediately after a major incident or strategic change.
Sources and reference material
This publication provides general information and does not constitute accounting, legal, tax or investment advice tailored to a specific situation.


