Assessment turns a list of identified risks into a ranked, defensible picture of where attention and money should go. Following ISO 31000, risk analysis estimates the likelihood of an event and the consequence if it occurs, and risk evaluation compares those levels against agreed criteria to decide what is tolerable. The goal is proportionality: scarce preservation and security resources flow to the risks that most threaten records objectives.

Qualitative and quantitative approaches

Most records programmes start qualitatively with a likelihood-by-consequence matrix, often 5x5, producing bands such as low, medium, high and extreme. It is fast, transparent and good for prioritisation. Where the stakes justify it, move toward semi-quantitative or quantitative methods - assigning monetary values, recovery costs or annualised loss expectancy - so trade-offs can be argued in the language of the board.

  • Likelihood - how often the event is expected, from rare to almost certain, informed by incident history and threat intelligence.
  • Consequence - severity across dimensions: legal, financial, operational, reputational and, distinctively for records, loss of evidential or heritage value.
  • Level of risk - the combination, plotted on the matrix and compared to tolerance thresholds.

Inherent versus residual risk

Assess the inherent risk (before controls) and the residual risk (with existing controls working as intended). The gap shows how much your current controls actually earn, and residual risk above tolerance is the trigger for further treatment. Recording both keeps assessments honest and makes control value visible to auditors.

Consistency and appetite

An assessment is only as good as its consistency. Publish clear scale descriptors so that "high likelihood" means the same thing to every assessor, and define the organisation's risk appetite - the level it is willing to accept in pursuit of its objectives. Align severity scales with any enterprise or ISO 27001 risk process so records risks can be reported alongside others rather than dismissed as niche.

In practice. Beware the tyranny of the average score. A vital record with catastrophic consequence but low likelihood can outrank a routine annoyance that happens weekly. Always let a single extreme-consequence dimension escalate the rating rather than diluting it in a blended number.

Key takeaways

  • Analyse likelihood and consequence, then evaluate against tolerance criteria to prioritise (ISO 31000).
  • Start qualitative with a matrix; go semi-quantitative when board-level trade-offs demand it.
  • Track inherent versus residual risk, publish consistent scales, and state a clear risk appetite.

Check your understanding

Last modified: Saturday, 1 August 2026, 10:37 AM