Accendo Reliability

Your Reliability Engineering Professional Development Site

  • Home
  • About
    • Contributors
  • Reliability.fm
    • Speaking Of Reliability
    • Rooted in Reliability: The Plant Performance Podcast
    • Quality during Design
    • Way of the Quality Warrior
    • Critical Talks
    • Dare to Know
    • Maintenance Disrupted
    • Metal Conversations
    • The Leadership Connection
    • Practical Reliability Podcast
    • Reliability Matters
    • Reliability it Matters
    • Maintenance Mavericks Podcast
    • Women in Maintenance
    • Accendo Reliability Webinar Series
  • Articles
    • CRE Preparation Notes
    • on Leadership & Career
      • Advanced Engineering Culture
      • Engineering Leadership
      • Managing in the 2000s
      • Product Development and Process Improvement
    • on Maintenance Reliability
      • Aasan Asset Management
      • AI & Predictive Maintenance
      • Asset Management in the Mining Industry
      • CMMS and Reliability
      • Conscious Asset
      • EAM & CMMS
      • Everyday RCM
      • History of Maintenance Management
      • Life Cycle Asset Management
      • Maintenance and Reliability
      • Maintenance Management
      • Plant Maintenance
      • Process Plant Reliability Engineering
      • ReliabilityXperience
      • RCM Blitz®
      • Rob’s Reliability Project
      • The Intelligent Transformer Blog
      • The People Side of Maintenance
      • The Reliability Mindset
    • on Product Reliability
      • Accelerated Reliability
      • Achieving the Benefits of Reliability
      • Apex Ridge
      • Metals Engineering and Product Reliability
      • Musings on Reliability and Maintenance Topics
      • Product Validation
      • Reliability Engineering Insights
      • Reliability in Emerging Technology
    • on Risk & Safety
      • CERM® Risk Insights
      • Equipment Risk and Reliability in Downhole Applications
      • Operational Risk Process Safety
    • on Systems Thinking
      • Communicating with FINESSE
      • The RCA
    • on Tools & Techniques
      • Big Data & Analytics
      • Experimental Design for NPD
      • Innovative Thinking in Reliability and Durability
      • Inside and Beyond HALT
      • Inside FMEA
      • Integral Concepts
      • Learning from Failures
      • Progress in Field Reliability?
      • R for Engineering
      • Reliability Engineering Using Python
      • Reliability Reflections
      • Testing 1 2 3
      • The Manufacturing Academy
  • eBooks
  • Resources
    • Accendo Authors
    • FMEA Resources
    • Feed Forward Publications
    • Openings
    • Books
    • Webinars
    • Journals
    • Higher Education
    • Podcasts
  • Courses
    • 14 Ways to Acquire Reliability Engineering Knowledge
    • Reliability Analysis Methods online course
    • Measurement System Assessment
    • SPC-Process Capability Course
    • Design of Experiments
    • Foundations of RCM online course
    • Quality during Design Journey
    • Reliability Engineering Statistics
    • Quality Engineering Statistics
    • An Introduction to Reliability Engineering
    • Reliability Engineering for Heavy Industry
    • An Introduction to Quality Engineering
    • Process Capability Analysis course
    • Root Cause Analysis and the 8D Corrective Action Process course
    • Return on Investment online course
    • CRE Preparation Online Course
    • Quondam Courses
  • Webinars
    • Upcoming Live Events
  • Calendar
    • Call for Papers Listing
    • Upcoming Webinars
    • Webinar Calendar
  • Login
    • Member Home

by Greg Hutchins Leave a Comment

Linking Risk Assessments to Decision Making

Linking Risk Assessments to Decision Making

Guest Post by Andrew Sheves (first posted on CERM ® RISK INSIGHTS – reposted here with permission)

The point of risk management is to understand and react to the threats and opportunities that might affect your business.  The problem is that risk management can often become dislocated from the mainstream business processes.  Instead of being integrated into the organization, risk management takes place in a parallel but separate workstream: one that decision-makers dip into occasionally but generally look at as a specialized, technical process.

I notice a similar thing happens with cybersecurity. Despite the fact that almost every business is now wholly dependent on a robust, secure and effective IT infrastructure, cybersecurity is still often seen as a ‘thing that IT does’.  Even though cybersecurity is effectively supply chain security (plus a lot more), it isn’t thought of that way.

One way to solve this conundrum is to think of a risk assessment like a P&L statement or balance sheet: it’s a data set that supports decision-making.  And, taking that one step farther, you risk data can support the decision-makers if it’s linked to your overall objectives.

If you map out how threats or opportunities are linked to your objectives, you can link your assessment directly to what the organization is trying to achieve.

However, there’s not going to be a direct link between a threat and the objective in a lot of cases. Even if there is, it might not be specific enough to make a meaningful decision. So instead, need a middle step to identify the critical factors that enable you to reach your objectives.

Top-level objectives —> Factors for success —> Threat / opportunities

Moving from the strategic (objectives) to the operational (factors for success) to the details (individual threats) will help you link everything together.

Then, reverse the process and map the threats / opportunities to success factors before looking at how a risk might affect that objective.

Threat / opportunities —> Factors for success —> Top-level objectives

This makes it easier to link the risk data to your objectives and to make better, more informed decisions.

Here’s the whole thing  sketched out

However, you have to keep in mind that the threat category might not always line up with the description

However, you have to keep in mind that the threat category might not always line up with the description for the objective.

For example, your top level objective is to deliver the highest quality of widgets in your industry.  To do that, you need to recruit and retain the top talent which you class as a People item. 

However, you face a Reputational risk because of the behavior of the previous CEO which makes attracting good people difficult.  

So a Reputational threat causes a risk that affects your People success factor. This in turn affects your quality objective.

So get your stakeholders and decision-makers to start thinking about risk data as another data-source to help with decision-making.  At the same time, ensure that what you produce is clear and tied to objectives: be effects-led, not threat-led.

This apparent simplification doesn’t mean that there’s still not a lot going on behind the scenes. This simplification requires a lot of work but that’s not unusual: just think about how many hours go into producing a one-page P&L statement for a big organization. However, you will be more effective if you present your results as clean, clear, useable data that directly link to what your organization is trying to do.

Andrew Sheves Bio

Andrew Sheves is a risk, crisis, and security manager with over 25 years of experience managing risk in the commercial sector and in government. He has provided risk, security, and crisis management support worldwide to clients ranging from Fortune Five oil and gas firms, pharmaceutical majors and banks to NGOs, schools and high net worth individuals. This has allowed him to work at every stage of the risk management cycle from the field to the boardroom. During this time, Andrew has been involved in the response to a range of major incidents including offshore blowout, terrorism, civil unrest, pipeline spill, cyber attack, coup d’etat, and kidnapping.

Filed Under: Articles, CERM® Risk Insights, on Risk & Safety

About Greg Hutchins

Greg Hutchins PE CERM is the evangelist of Future of Quality: Risk®. He has been involved in quality since 1985 when he set up the first quality program in North America based on Mil Q 9858 for the natural gas industry. Mil Q became ISO 9001 in 1987

He is the author of more than 30 books. ISO 31000: ERM is the best-selling and highest-rated ISO risk book on Amazon (4.8 stars). Value Added Auditing (4th edition) is the first ISO risk-based auditing book.

« Andragogy – How Adults Learn to Learn
Are you on the right track with the right… »

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

CERM® Risk Insights series Article by Greg Hutchins, Editor and noted guest authors

Join Accendo

Receive information and updates about articles and many other resources offered by Accendo Reliability by becoming a member.

It’s free and only takes a minute.

Join Today

Recent Articles

  • test
  • test
  • test
  • Your Most Important Business Equation
  • Your Suppliers Can Be a Risk to Your Project

© 2025 FMS Reliability · Privacy Policy · Terms of Service · Cookies Policy