Vane Protocol Insights
Choose the Method, Not the Matrix: Matching Risk Assessment to the Risk
A practical guide for leaders in high-reliability and asset-intensive organisations who need risk assessment to improve a decision, not decorate it.
A common risk language is valuable. It lets directors, operators and specialists compare attention, authority and escalation. It is not, on its own, an analysis method.
The familiar 5×5 matrix has a legitimate role: it can help a large organisation sort a portfolio, establish who needs to be involved and make review cadence visible. Trouble starts when the matrix is asked to explain failure mechanisms, prove control performance, quantify a project choice or predict a shifting external environment. A compact rating can carry the outcome of analysis; it cannot substitute for the analysis that should come first.
That distinction matters in manufacturing, energy, infrastructure, mining and industrial operations. A deteriorating pressure boundary, an unreliable sanitation step, a constrained specialist workforce and a licensing challenge may all be material. They do not become more intelligible because each is assigned a likelihood and consequence cell.
The stronger question is: what method best fits the risk and the decision now required? The answer will often be proportionate rather than elaborate, but it should be deliberate.
A Vane Protocol lens
Start with method-fit.
Before choosing a workshop format, model or score, frame the characteristics of the exposure. This avoids both over-engineering a routine decision and under-analysing a consequential one.
- 01
Decision required
Is the immediate choice about investment, operating limits, assurance, recovery, acceptance, escalation or a change in direction?
- 02
Nature of uncertainty
Are you dealing with a known technical failure mode, variable demand, incomplete evidence, changing stakeholder behaviour or a contested future?
- 03
System complexity and interdependence
Does the exposure sit in one component, or emerge through linked assets, people, suppliers, software, permits and decisions?
- 04
Evidence and data quality
Can condition, event or trend data support a model, or is structured expert judgement more honest than a precise-looking number?
- 05
Control and barrier dependence
Does the outcome depend on a small number of prevention or recovery controls performing as intended, at the point of need?
- 06
Time horizon
Is the concern a shift-level task, an outage window, a seasonal pattern, a multi-year investment or a gradual external change?
- 07
Reversibility and consequence severity
How much room exists to learn, intervene or recover before harm, environmental impact, product loss, licence pressure or stranded capital becomes difficult to reverse?
A practical comparison
Match the question to the work.
Methods can be combined. The point is not to find one universal technique; it is to use the smallest credible set of approaches that makes the decision, evidence and uncertainty clear.
| Risk characteristic | Better-fit assessment approach | What useful application looks like |
|---|---|---|
| Asset integrity, equipment failure and loss of containment | Use FMEA or FMECA to expose failure modes and their effects; reliability-centred maintenance to align tasks with failure consequences; and fault-tree or event-tree analysis where a specific high-consequence pathway warrants deeper logic. | For a turbine protection train, a water-treatment pump station or a manufacturing refrigeration system, connect degradation evidence, maintenance strategy and credible escalation paths, not just an overall rating. |
| Process safety and critical controls | Use HAZOP or SWIFT to examine deviations and their causes; bowtie to make prevention, recovery and assurance visible to executives; and LOPA only when independent protection layers and defensible data make the judgement supportable. | A process change may need a deviation review first, then a board-level view of which controls are relied on and what evidence shows their health. |
| Product and process integrity | Use HACCP-style critical-point analysis, then pair it with trend, verification and release evidence. The critical question is whether the point is controlled and verified, not whether it is painted red or amber. | In a manufacturing operation, link a process-control, sanitation or foreign-material concern to critical limits, verification patterns, deviations and disposition decisions. |
| Operational continuity, supply chain and site disruption | Use business impact analysis to identify essential outcomes and tolerable interruption; scenario analysis to test disruption conditions; and dependency mapping to reveal shared utilities, logistics, suppliers, skills and information flows. | For an infrastructure outage or a manufacturing site disruption, test the recovery sequence and the dependencies that could make a nominal workaround fail. |
| Human performance, fatigue and task error | Use task analysis and human-reliability-informed review to understand workload, cues, handovers, interfaces, time pressure and error-recovery opportunities. Do not force a people-and-task problem into an asset-failure method. | A night-shift isolation, control-room response or maintenance handover needs a view of work as performed, not only equipment reliability statistics. |
| Environmental and community exposure | Use source-pathway-receptor or exposure-pathway analysis, supported by monitoring and consequence modelling that match the available evidence. Keep uncertainty visible where site conditions, receptors or pathways are variable. | For discharge, dust, noise or odour concerns, assess how an emission could travel, who or what could be exposed, and which observations should trigger action. |
| Cyber-physical and operational technology disruption | Use operational scenarios, dependency mapping, event pathways and recovery analysis. Technical cyber assessment methods belong with specialist practice; the governance question is how a digital disruption changes safe and recoverable operations. | Map how loss of a historian, remote access path or control-network segment affects visibility, manual workarounds, shutdown decisions and recovery priorities. |
| Capital projects, major investment and schedule | Use decision trees and sensitivity analysis to make choices and assumptions explicit. Use Monte Carlo only when the model structure and input distributions are defensible enough to add insight rather than confidence theatre. | For a plant upgrade or infrastructure programme, compare decision options, schedule drivers, cost sensitivities and the conditions that would change the preferred path. |
| Market access, customer concentration, commodity and demand shifts | Use scenarios, leading-indicator monitoring, stress tests and decision options. These exposures often deserve a range of plausible futures, not a probability claim that implies a false degree of knowledge. | Test the effect of a customer loss, export restriction, price move or demand change against capacity, cash, contracts and management response options. |
| Regulatory, licensing, social licence and stakeholder risk | Use change pathways, scenario analysis, structured stakeholder analysis and evidence-based triggers. Do not manufacture a numerical probability when the risk depends on evolving interpretation, relationships or public expectations. | Show the pathway from an emerging concern to a consent condition, challenge, delay or reputation impact, and name the evidence that would require management attention. |
| People, workforce and capability | Use capacity scenarios, workforce dependency mapping, critical-role analysis and leading indicators. The method should show whether the organisation can sustain essential work, not merely how many vacancies exist today. | Test exposure created by scarce operators, maintainers, technical authorities or supervisors across normal operations, outages and incident recovery. |
On smaller screens, scroll the table horizontally to compare the assessment approach and its practical use.
Using the matrix well
When a risk matrix helps, and when it gets in the way.
It helps when it creates a shared management rhythm.
Use matrix bands to communicate the level of management attention, decision authority, escalation route and review cadence a risk requires. That shared language can bring coherence to a portfolio and expose where a risk needs more disciplined work.
It gets in the way when colour replaces inquiry.
Red, amber and green are not safety signals. They do not show whether a control works, whether an initiating event is changing, whether a recovery plan is credible or whether a strategic option is robust. A band should follow analysis and guide governance action, not end the conversation.
For a practical way to translate analysis into board attention, see the Board Risk Reporting Pack. Where the question is about acceptable operating boundaries and response triggers, the Risk Appetite Statement Toolkit can help convert a position into an accountable governance rhythm.
Executive checklist
Seven questions before approving the assessment approach.
- 1
What decision must the board or executive team make, and by when?
- 2
What causal pathway or dependency needs to be understood before that decision is sound?
- 3
Which uncertainties can be measured, and which must remain explicit judgements?
- 4
How much does the outcome depend on critical controls, barriers or human recovery?
- 5
What would change the conclusion: an observed trend, a threshold breach, a stakeholder signal or a new scenario?
- 6
Does the time horizon call for immediate task detail, operational recovery planning or strategic optionality?
- 7
How reversible is the decision if the assessment is wrong, and how severe could the consequence become?
Turn the assessment into governance action
Make the signals, controls and decisions visible.
Download the free Operational Risk Signal Check for a focused board conversation, then explore the Vane Protocol tool library for editable resources that support clearer reporting, appetite and critical-control assurance.
Vane Protocol tools support structured discussion and adaptation within your organisation. They are not a substitute for technical, engineering, legal, regulatory, safety or specialist assurance advice.