LEARNER GUIDE
Topic 5: Risk Analysis & Evaluation
What will you be able to do after this session:
Explain what likelihood and impact are. Use qualitative analysis to rate risks. Calculate a risk
score and rank risks by priority. Use a risk matrix to visualize risk levels.
Introduction
In the last session, you learned how to identify risks in an organization. In this session, you will
learn how to evaluate those risks. Evaluating risks means deciding how serious each risk is.
To do this, we use two key ideas: likelihood (how probable is it?) and impact (how bad would it
be?). Together, these give us a risk score that helps us prioritize what to fix first.
Learner Guide | Topic 5: Risk Analysis & Evaluation Page 1
Part 1: Likelihood and Impact
What is Likelihood?
Likelihood means: How probable is it that this risk will happen?
Likelihood Level What it Means Example
Low (1) It could happen, but it is not A physical break-in at a guarded
common data centre
Medium (2) It happens sometimes An employee accidentally clicks
a phishing link
High (3) It happens often or is very easy Staff using weak passwords
to cause with no training
What is Impact?
Impact means: How serious are the consequences if this risk happens?
Impact Level What it Means Example
Low (1) Minor disruption; easily One employee cannot access
recovered their email for one hour
Medium (2) Moderate harm; requires Company system down for one
significant effort to recover day; some data lost
High (3) Serious harm; major financial, Customer data leaked; GDPR
legal, or reputational damage fine issued by German authority
💡 Key Idea
Likelihood and impact are two separate questions. Always ask them one at a time. A risk
can be VERY likely but have LOW impact, or VERY unlikely but have HIGH impact.
Real Example: Unencrypted Laptop
Question Answer Rating
How likely is theft of an office Thefts happen in shared Medium (2)
laptop? workspaces and while travelling
What is the impact if it contains GDPR breach, potential fine, High (3)
customer data? damaged reputation
Learner Guide | Topic 5: Risk Analysis & Evaluation Page 2
Part 2: Qualitative Risk Analysis
Qualitative risk analysis means we use words (Low, Medium, High) to describe and compare
risks. This is the most common method at entry-level GRC.
Method Uses Example
Qualitative Words: Low / Medium / High Used in most GRC and ISO
27001 work
Quantitative Numbers: exact money values, Used in advanced financial risk
statistics models (not covered here)
The 5 Steps of Qualitative Risk Analysis
Step What to Do Example
1 Name the risk "No antivirus installed on
company laptops"
2 Rate the likelihood High – malware infection is very
common without antivirus
3 Rate the impact High – malware can destroy
data and disrupt all operations
4 Combine into a risk score High × High = Score 9 (Critical)
5 Record in the risk register Add to register with rating and
date
Exercise 1: Rate the Risk
For each scenario below, assign a Likelihood rating (Low, Medium, or High) and an Impact
rating. Then write one sentence explaining your choice. Scenario A: A company with 500
staff has a policy that allows any password, including simple ones like "1234". No training
has been given. Scenario B: A software system used daily has not been updated in 6
months and has a known security weakness. Scenario C: The office has no sign-in book for
visitors. Anyone can enter.
Reflection Question
Why do we use qualitative analysis (words) instead of exact numbers? What are the
advantages for entry-level GRC work?
Learner Guide | Topic 5: Risk Analysis & Evaluation Page 3
Part 3: Risk Rating and Prioritization
Once you have rated likelihood and impact, you can calculate a risk score. This score tells you
how urgent a risk is.
Risk Score = Likelihood × Impact
Likelihood Impact Score Priority Level
1 (Low) 1 (Low) 1 Low
1 (Low) 2 (Medium) 2 Low
2 (Medium) 2 (Medium) 4 Medium
2 (Medium) 3 (High) 6 High
3 (High) 3 (High) 9 Critical
Why Do We Prioritize?
No organization has enough time or money to fix all risks immediately. Prioritization helps you
focus on the most dangerous risks first.
💡 Important Note
A high score means "address this first" in most cases. But sometimes a medium-score risk
is fixed first because it is quick and cheap to fix. Always combine the score with business
judgment.
Exercise 2: Which Risk First?
Below are three risks with their scores. Put them in order from most urgent (1) to least
urgent (3). Risk A: No antivirus on employee laptops (Likelihood: High, Impact: High,
Score: 9) Risk B: Admin accounts use only one password (no second factor) (Likelihood:
Medium, Impact: High, Score: 6) Risk C: No clear desk policy for printed documents
(Likelihood: Low, Impact: Medium, Score: 2) Your order: 1st = ___ | 2nd = ___ | 3rd = ___
Reason for your choice:
Learner Guide | Topic 5: Risk Analysis & Evaluation Page 4
Part 4: The Risk Matrix
A risk matrix (also called a heat map) is a grid that shows all your risks visually. It plots
Likelihood on one axis and Impact on the other. The colour of each cell shows how urgent the
risk is.
Risk Matrix – 3×3 Grid
[DIAGRAM: The grid below shows a 3×3 risk matrix. Rows = Likelihood. Columns = Impact.]
Likelihood →↓ / Low Impact (1) Medium Impact (2) High Impact (3)
Impact →
High Likelihood (3) Medium (3) High (6) ⚠️ Critical (9)
Medium Likelihood (2) Low (2) Medium (4) High (6)
Low Likelihood (1) Low (1) Low (2) Medium (3)
Colour Guide for the Risk Matrix
Zone Colour Score Range What to Do
Critical Red 9 Immediate action
required
High Orange 6 Address as a priority
Medium Yellow 3–4 Plan treatment within
reasonable timeframe
Low Green 1–2 Monitor and review
periodically
How to Use the Risk Matrix
1. Find your risk in the risk register
2. Look at its Likelihood rating (Low, Medium, High)
3. Look at its Impact rating (Low, Medium, High)
4. Find where those two ratings meet on the grid
5. Note the colour zone. This is your risk level.
6. Record the risk level in your risk register
Exercise 3: Plot on the Matrix
Learner Guide | Topic 5: Risk Analysis & Evaluation Page 5
Use the risk matrix above to find the correct zone for each risk: Risk A: Likelihood = High
(3), Impact = High (3) Zone: ________________ Risk B: Likelihood = Low (1), Impact =
High (3) Zone: ________________ Risk C: Likelihood = Medium (2), Impact = Low (1)
Zone: ________________
Learner Guide | Topic 5: Risk Analysis & Evaluation Page 6
Session Summary: Key Points
Topic Key Point to Remember
Likelihood How probable is the risk? Use Low / Medium /
High (1-2-3)
Impact How serious are the consequences? Use Low /
Medium / High (1-2-3)
Qualitative Analysis Use words (Low/Medium/High) to describe and
compare risks – common in GRC and ISO 27001
Risk Score Likelihood × Impact = Risk Score (higher = more
urgent)
Risk Matrix A visual grid to compare and prioritize all risks at
a glance
Reflection Questions
• In your own words: what is the difference between likelihood and impact?
• Why is it important to rate risks before deciding what to do about them?
• If you had to explain the risk matrix to a colleague who has never seen one before, what
would you say?
Real-World Application: What GRC Analysts Actually Do
In a real GRC role in Germany, you might:
• Receive a list of risks identified during an information security audit
• Rate each risk for likelihood and impact based on your knowledge of the organization
• Create a risk matrix slide for a management presentation
• Use the risk scores to recommend which risks to treat first in the quarterly risk review
Action Plan
Action How I Will Do It Target Date
I can explain likelihood and
impact
I can assign qualitative ratings
to a risk
I can calculate a risk score
Learner Guide | Topic 5: Risk Analysis & Evaluation Page 7
I can find a risk on a 3x3 risk
matrix
Next Session
In Topic 6: Risk Treatment & Acceptance, you will learn what to do AFTER you have rated
risks. You will explore options like mitigation, transfer, avoidance, and acceptance.
Learner Guide | Topic 5: Risk Analysis & Evaluation Page 8