Why Assessment Determines Where You Spend Your Resources
Risk identification tells you what risks you face. Risk assessment tells you which ones matter most. With finite resources available for managing risk, the Orange Book is clear that the aim is to achieve an optimum response to risk, prioritised in accordance with an evaluation of the risks. Assessment is the mechanism that transforms a flat list of identified risks into a prioritised, actionable risk profile — separating the critical few from the trivial many.
In defence and heavy engineering environments, this prioritisation is existential. A submarine programme may identify 400+ individual risks. Treating them all with equal intensity would be impossible and wasteful. The assessment process must reliably surface the 15–20 risks that genuinely threaten programme success, while confirming that the remaining risks are within acceptable bounds. Get the prioritisation wrong, and resources are consumed managing tolerable risks while catastrophic exposures develop unchecked.
What the Orange Book Establishes About Risk Assessment
Three Principles for Assessing Risk
The Orange Book establishes three non-negotiable principles for risk assessment:
These three principles address the most common assessment failures: subjective, undocumented judgements; assessments that cannot be compared or prioritised; and the conflation of raw exposure with controlled exposure.
The Two Dimensions: Likelihood and Impact
Every risk assessment must evaluate two dimensions:
Likelihood measures how probable it is that the risk event will occur. Impact measures the severity of the consequence if the risk does materialise. Neither dimension alone is sufficient — a highly likely risk with negligible impact may be less important than an unlikely risk with catastrophic consequences.
The Orange Book acknowledges a critical reality: "Risk assessment is more of an art than a science." Some risks — particularly financial risks — lend themselves to numerical, quantitative assessment. Others — reputational risk, for example — require subjective judgement. The framework accommodates both, but insists on structure regardless of the assessment method used.
This last point is crucial: assessment (how big is this risk?) and acceptability (is this risk tolerable?) are two separate judgements that must not be conflated. Assessing a risk as "low" because you want it to be low — rather than because the evidence supports that evaluation — is one of the most dangerous cognitive traps in risk management.
How Risk Matrices Work: 3×3 and 5×5
The 3×3 Matrix: Minimum Viable Assessment
The Orange Book states that a High / Medium / Low categorisation for both likelihood and impact "may be sufficient, and should be the minimum level of categorisation." This produces a 3×3 risk matrix — nine cells representing the full range of risk exposures.
The 3×3 matrix is effective for rapid, high-level assessment — particularly useful in workshop settings where the goal is initial triage of a large number of risks. Its simplicity is both its strength and its limitation: it cannot discriminate finely between risks that fall near category boundaries.
The 5×5 Matrix: Detailed Analytical Assessment
For more granular analysis, the Orange Book recommends the 5×5 matrix, using standardised scales:
Impact Scale:
| Rating | Label | Cost Impact (Defence Example) | Schedule Impact | Safety/Compliance |
|---|---|---|---|---|
| 1 | Insignificant | < AUD 50K | < 1 week delay | Minor procedural non-conformance |
| 2 | Minor | AUD 50K – AUD 250K | 1–4 weeks delay | Non-conformance requiring corrective action |
| 3 | Moderate | AUD 250K – AUD 1M | 1–3 months delay | Reportable safety incident, no injury |
| 4 | Major | AUD 1M – AUD 10M | 3–6 months delay | Serious injury, regulatory investigation |
| 5 | Catastrophic | > AUD 10M | > 6 months / programme cancellation | Fatality, criminal prosecution, loss of licence |
Likelihood Scale:
| Rating | Label | Probability Range | Frequency Indicator |
|---|---|---|---|
| 1 | Rare | < 5% | Has not occurred in similar programmes |
| 2 | Unlikely | 5–20% | Could occur but not expected |
| 3 | Possible | 20–50% | Has occurred in similar programmes |
| 4 | Likely | 50–80% | Will probably occur at some point |
| 5 | Almost Certain | > 80% | Expected to occur, possibly multiple times |
The risk score is then calculated as:
This produces scores ranging from 1 (Rare × Insignificant) to 25 (Almost Certain × Catastrophic), enabling fine-grained prioritisation and the application of traffic-light colour coding to distinguish zones of tolerability.
Colour-Coded Tolerability Zones
The Orange Book endorses the use of colour ("Traffic Lights") to clarify the significance of risks. The tolerability zones map directly to management action requirements:
| Zone | Score Range (5×5) | Management Action |
|---|---|---|
| 🟢 Green (Low) | 1–4 | Managed through routine procedures; monitor for change |
| 🟡 Yellow (Moderate) | 5–9 | Active management required; specific controls in place and monitored |
| 🟠 Amber (Significant) | 10–16 | Senior management attention required; enhanced controls and regular reporting |
| 🔴 Red (Intolerable) | 17–25 | Board-level attention required; immediate action to reduce exposure; escalation mandatory |
Inherent vs Residual Risk: Why You Need Both
The Critical Distinction
The Orange Book devotes significant attention to the relationship between inherent and residual risk because understanding both is essential for effective risk management:
Inherent risk = the raw exposure before any controls are applied. Residual risk = the remaining exposure after controls are applied, assuming those controls are effective.
Why Inherent Risk Matters
Many organisations focus exclusively on residual risk — the controlled exposure that represents their day-to-day reality. The Orange Book warns that this is insufficient for three critical reasons:
1. Exposure if controls fail. If the organisation does not know its inherent risk, it cannot evaluate the consequences of control failure. A fire suppression system in a munitions storage facility reduces the risk of catastrophic explosion from inherent "Almost Certain × Catastrophic" to residual "Rare × Catastrophic." But if the suppression system fails, the organisation is immediately back at the inherent level. Without knowing this inherent exposure, contingency planning is uninformed. 2. Identifying over-control. If the inherent risk is already within appetite — say, the uncontrolled risk of minor paint imperfections on non-critical components — then resources spent controlling that risk may be wasted. Knowledge of inherent risk allows identification of areas where controls can be relaxed without breaching appetite, freeing resources for higher-priority risks. 3. Evaluating proposed controls. When designing new controls, the assessment of anticipated residual risk is necessary to evaluate whether the proposed control will actually bring the risk within appetite. This requires knowing both the inherent starting point and the expected residual endpoint.
The Assessment-Control Loop
This creates an important insight: assessment and control are not strictly sequential — they are iterative. You assess inherent risk to determine the extent of control needed, then assess residual risk to verify the control is adequate, potentially adjusting the control and re-assessing in a refinement loop.
Documenting Risk Assessment: The Risk Profile
What Documentation Must Achieve
The Orange Book requires risk assessment to be documented in a way that creates a risk profile for the organisation. This documentation must:
- Facilitate identification of risk priorities — particularly surfacing the most significant issues for senior management attention
- Capture the reasons for decisions about what is and is not tolerable exposure
- Record the way in which it is decided to address risk — linking assessment to response
- Enable all concerned to see the overall risk profile and how their areas fit into it
- Facilitate review and monitoring of risks over time
The Orange Book Risk Assessment Template
The Orange Book's Annex A provides a practical documentation format. Adapted for defence engineering:
| Risk | Inherent Impact | Inherent Likelihood | Controls in Place | Residual Impact | Residual Likelihood | Action Planned | Target Date | Owner |
|---|---|---|---|---|---|---|---|---|
| Sole-source forging supplier experiences capacity constraint, delaying hull module delivery | High | Medium | Quarterly capacity reviews; 6-month forward order pipeline | Medium | Low | Qualify alternative supplier for critical forgings | Q3 FY26 | Supply Chain Manager |
| Classified waste disposal contractor loses security accreditation, halting production waste removal | High | Low | Annual accreditation monitoring; emergency disposal MOU with alternate provider | High | Low | No further action; contingency MOU adequate | — | Security & Compliance Lead |
From Assessment to Priorities
Once risks are assessed, the risk priorities for the organisation emerge naturally. The Orange Book's guidance is direct:
It is not the absolute value of the risk score that matters — it is the gap between the assessed risk and the risk appetite that determines priority. A risk scored at 12 is higher priority than a risk scored at 15 if the appetite for the first risk category is 6 (gap of 6) while the appetite for the second is 12 (gap of 3).
Common Pitfalls in Risk Assessment
Conflating assessment with acceptability. Assessing a risk as "low" because you cannot afford it to be high is not assessment — it is wishful thinking. Assessment must be based on evidence, not on desired outcomes. Using only one dimension. Assessing risks by impact alone (ignoring likelihood) or likelihood alone (ignoring impact) produces distorted priorities. Both dimensions must always be evaluated. Inconsistent scales. If different parts of the organisation use different likelihood and impact scales, the resulting risk scores cannot be compared or aggregated. Standardised scales across the organisation are essential. Ignoring inherent risk. Focusing only on residual risk leaves the organisation blind to its true exposure if controls fail and unable to identify over-controlled risks where resources could be redeployed. Static assessment. Risk profiles change. Likelihood and impact shift as programmes progress, as the external environment evolves, and as controls are implemented or degraded. Assessment must be repeated at appropriate intervals. Treating the matrix as precision. A 5×5 matrix produces scores from 1 to 25, but these are ordinal rankings, not cardinal measurements. A risk scored 20 is not "twice as bad" as a risk scored 10. The matrix supports prioritisation and comparison, not mathematical precision.
Key Takeaways
- Every risk must be assessed on two dimensions — likelihood and impact — using a clearly structured and documented process.
- 3×3 matrices provide minimum viable assessment for rapid triage; 5×5 matrices enable more granular analysis and are preferred for complex programmes.
- Colour-coded tolerability zones (green/yellow/amber/red) translate numerical scores into management action requirements.
- Both inherent and residual risk must be captured — inherent risk reveals exposure if controls fail and identifies potential over-control; residual risk shows actual controlled exposure for comparison against appetite.
- Assessment and control are iterative, not strictly sequential — inherent risk informs the extent of control needed; residual risk assessment verifies control adequacy.
- Risk priorities emerge from the gap between assessed risk and risk appetite, not from absolute risk scores alone.
- Documented risk profiles must facilitate prioritisation, capture decision rationale, enable monitoring, and provide senior management with a clear view of key risks.
The Risk Analysis Worksheet Template
Section 1: Risk Identification Header
| Field | Description | Example |
|---|---|---|
| Unit/Division/Institute | The organisational unit conducting the assessment | Defence Systems Engineering Division |
| Risk Number | Cross-reference to the risk register | R-003 |
| Risk Description | Clear, concise statement of the risk event | Failure of weld integrity in hull section joints during sea trials |
| Risk Category | Classification from organisational taxonomy | Operational |
| Related Objective | Which project objective this risk threatens | Deliver hull structure to the applicable classification standard by Q3 |
Section 2: Causes and Risk Factors
This section forces the analyst to identify all plausible causes that could trigger the risk event. Each risk may have multiple independent or interacting causes.
| Causes / Risk Factors |
|---|
| 1. Welding personnel not certified to AS/NZS 1554 for structural steel |
| 2. Incoming plate material from new supplier not yet verified against specification |
| 3. Workshop ambient temperature below minimum for the specified welding procedure |
| 4. Non-destructive testing (NDT) backlog creating pressure to proceed without clearance |
| 5. Weld procedure specification (WPS) not updated for revised plate thickness |
Section 3: Impacts and Effects
This section documents what would happen if the risk materialised, across multiple impact dimensions.
| Impacts / Effects |
|---|
| 1. Hull section fails classification survey — rework cost estimated AUD 1.2M–AUD 2.5M |
| 2. Schedule delay of 8–14 weeks for re-welding and re-inspection |
| 3. Reputational damage with prime contractor — risk to future contract awards |
| 4. Potential safety incident if defect not detected before sea trials |
| 5. Warranty claim from customer for latent defect |
Section 4: Current Controls and Mitigating Factors
Document what is already in place to prevent or detect this risk.
| Current Controls |
|---|
| 1. All welders hold current AS/NZS 1554 certification — records maintained by HR |
| 2. Incoming material inspection per quality plan — CoC verified against specification |
| 3. Workshop temperature monitoring system with automatic alarm at < 15°C |
| 4. NDT inspection schedule managed through quality management system |
| 5. WPS controlled document — reviewed and reissued for each design change |
Section 5: Current Controlled Risk Level
The risk is assessed across four consequence dimensions using a consistent 1–5 scale:
| Consequence Dimension | Consequence (1–5) | Likelihood (1–5) | Total | Rating Guide |
|---|---|---|---|---|
| Revenue, Cost or Liability | 4 | 3 | 7 | 2–5 = Low |
| People (Safety) | 3 | 2 | 5 | 6 = Moderate |
| Reputation and Political | 3 | 3 | 6 | 7 = High |
| Project Performance | 4 | 3 | 7 | 8–10 = High+ |
| Overall Rating | 7 | High |
Section 6: Treatment Planning (Where Risk Is Unacceptable)
Completed only when the risk owner deems the current risk level unacceptable.
| Treatment | Description | Responsible Officer | Timeline |
|---|---|---|---|
| Treatment 1 | Commission independent third-party weld audit against AS/NZS 1554 | Quality Manager | 30 days |
| Treatment 2 | Implement hold-point in production schedule — no hull assembly until NDT clearance confirmed | Production Manager | Immediate |
| Treatment 3 | Procure backup material from verified supplier as contingency | Procurement Lead | 60 days |
| Treatment 4 | Engage classification surveyor for early-stage in-process inspection rather than end-of-build only | Engineering Manager | 45 days |
Section 7: Post-Treatment Assessment
| Field | Entry |
|---|---|
| Expected overall risk level after treatments | Moderate |
| Risk owner acceptance | Yes — acceptable with treatments implemented |
| Date worksheet completed | [DD/MM/YYYY] |
How to Use the Worksheet in Practice
Step 1: Populate one worksheet per risk for every risk rated Moderate or above in your risk register. Low-rated risks may not require individual worksheets unless they have the potential to escalate. Step 2: Complete sections sequentially. The learning arc matters — understanding causes before impacts ensures your controls and treatments address root causes rather than symptoms. Step 3: Cross-reference to the register. The risk number on the worksheet must match the reference in the risk register exactly. The register is the summary view; the worksheet is the evidence file. Step 4: Review with the risk owner. The worksheet should be completed collaboratively, not by a single analyst in isolation. The risk owner must agree to the risk level assessment and the acceptability determination. Step 5: Update when conditions change. Any change to project scope, schedule, supplier, personnel, or external environment should trigger a review of affected worksheets.
