How a company-wide risk assessment is actually built — from risk identification through appetite, treatment and the key risk indicators that tell the board something has moved before it becomes a loss.
Risk assessment is a cycle, not a project. The output of monitoring feeds directly back into identification in the next round.
Agree the risk taxonomy, the scoring scales for likelihood and impact, and which entities and processes are in scope.
Workshops with process owners, loss data review, and scanning of regulatory and external developments.
Score likelihood and impact before controls. Document the rationale so the score can be challenged and reproduced.
Map controls to risks, then test both design and operating effectiveness. An untested control cannot reduce a score.
Compare residual risk to appetite. Where it exceeds appetite, choose to treat, transfer, terminate or tolerate with documented rationale.
Set thresholds on indicators that move before losses do, and escalate automatically when a threshold is breached.
The value of the matrix is the movement between inherent and residual. A risk that does not move once controls are applied is telling you the controls do not work.
Vertical axis: likelihood. Horizontal axis: impact.
A standard taxonomy for a regulated Egyptian institution.
Counterparty default and concentration exposure.
Rate, currency and price movement exposure.
Settlement buffers and funding concentration.
Process failure, human error, reconciliation breaks.
Breach of law, circular or licence condition.
AML, sanctions, fraud and bribery exposure.
Unpatched vulnerabilities, outage, data loss.
Conduct failure and stakeholder trust erosion.
Every engagement is led by a senior practitioner and closes with documented, regulator-ready evidence of what was built.