Why this module exists. Done well, qualitative risk assessment is cheap, repeatable, and good enough for 90% of decisions. Done badly, it is theatre. The difference is in the scoring rigour, not the framework choice.
What ISO 27005 and NIST SP 800-30 actually prescribe
Both frameworks define a process: identify assets, identify threats, identify vulnerabilities, assess likelihood, assess impact, compute risk, treat. The frameworks are loose on the scoring scale — that is the practitioner’s choice, and the choice matters.
The 5×5 matrix done well
A 5×5 likelihood-impact matrix is the most-common scoring approach. The pattern fails because scales are vague:
| Likelihood | Vague (bad) | Calibrated (good) |
|---|---|---|
| 5 — Very Likely | “Will probably happen” | ≥1 event/year |
| 4 — Likely | “May happen” | 1 event in 1-3 years |
| 3 — Possible | “Could happen” | 1 event in 3-10 years |
| 2 — Unlikely | “Unlikely” | 1 event in 10-30 years |
| 1 — Rare | “Negligible” | <1 event in 30 years |
The calibrated version turns “Very Likely” from a feeling into a falsifiable claim. Two raters scoring the same risk converge much faster.
Calibrated impact scoring
| Impact | Calibrated definition |
|---|---|
| 5 — Catastrophic | >₹50 Cr loss; regulatory cease-and-desist; CEO removal-level reputational damage |
| 4 — Major | ₹10-50 Cr; significant regulator action; material media coverage |
| 3 — Moderate | ₹1-10 Cr; warning/penalty; localised media |
| 2 — Minor | ₹10L-1 Cr; corrective directives; internal-only impact |
| 1 — Insignificant | <₹10L; no external visibility |
Adjust the rupee thresholds to your organisation’s scale. The key is that two assessors agree on which row a specific scenario belongs to.
The rater training problem
Even with calibrated scales, raters drift. Studies in risk-assessment psychology show:
- Without training, two raters agree on the same risk score about 40% of the time.
- With a 2-hour training using worked examples and post-session calibration, agreement reaches 75-85%.
- Annual recalibration keeps it there.
Run a 2-hour training annually for everyone who scores risks. Use 10 worked examples, ask raters to score independently, then walk through the rationale. This is the most-cost-effective quality investment in qualitative risk programmes.
The risk-register output
The risk assessment produces a register. Minimum-viable fields:
- Risk ID (stable identifier; ID survives renames)
- Risk title and one-sentence description
- Risk owner (named individual)
- Likelihood score with rationale (1-2 sentences)
- Impact score with rationale
- Inherent risk score (L × I)
- Current controls — what is in place
- Residual risk score (after current controls)
- Target residual score
- Treatment plan (what to do to close the gap)
- Treatment owner and target date
- Last reviewed date; next review date
The rationale field is what distinguishes a working register from a heatmap exporter. “Likelihood 4 because we saw 3 similar incidents in sector ISAC last year” is auditable; “likelihood 4” is not.
Inherent vs residual — the distinction that matters
Inherent risk = the risk assuming no controls. Residual risk = the risk given existing controls. Auditors want both. The gap between them is where you measure control effectiveness over time.
A common failure: scoring only residual. The auditor asks “what if a control failed?” — you cannot answer because you do not have the inherent baseline. Always score both, every time.
Risk treatment — the four options
| Treatment | When appropriate |
|---|---|
| Mitigate | Implement / improve controls to reduce L or I |
| Transfer | Insurance, contractual transfer to vendor |
| Accept | Risk is within appetite; documented acceptance with owner sign-off |
| Avoid | Stop the activity that creates the risk |
Common failure modes
- Static register. Risk reviewed at creation, never again. Half the risks become stale within a year.
- Owner is “the security team.” Risks need named individual owners with authority over the relevant controls.
- Heatmap-driven prioritisation. The 4×4 cells of “red” risks tied for priority. Use the raw score (e.g., 4×4=16 vs 5×3=15) plus risk-owner judgement.
- Risk register disconnected from controls. Each risk should map to specific controls in your control framework (ISO 27001 Annex A, NIST 800-53, your internal taxonomy). The mapping is what makes the register actionable.
Key takeaways
- 5×5 matrix works if the scales are calibrated to falsifiable definitions.
- Rater training annually; raises agreement from ~40% to ~80%.
- Risk-register fields: rationale for scores is the distinguishing detail.
- Score inherent AND residual; auditors and quality require both.
- Four treatment options: mitigate, transfer, accept, avoid. Acceptance always with documented owner sign-off.
Get a DPDP gap assessment
Free 30-minute call. We map your data flows against DPDP §8 obligations and tell you exactly which gaps to fix first. Auditor-defensible output.