Risks

Conducting Risk Assessments

Assessing a risk in Tidal means scoring it four times over: likelihood and impact before your measures, a treatment decision, then likelihood and impact again after them. Approving the result locks it and sets the risk to Approved for a year.

Performing risk assessment

You assess a risk from its own detail panel, and the assessment stays a draft until you approve it.

Starting an assessment

  1. Go to the Risks page via the main menu
  2. Click on a risk name to open the detail panel
  3. Create or continue an assessment using one of the available options:
  • Continue Assessment: appears when a draft assessment exists. Opens the existing draft for completion.
  • New Assessment: creates a new draft pre-filled from the latest approved assessment. Useful for periodic re-assessments.
  • New Blank Assessment: creates an empty draft with no pre-filled values (available via the menu).

The assessment dialog has three sections: Inherent Risk, Treatment, and Residual Risk. Changes are saved automatically as you fill in fields.

The Assessment tab in the detail panel shows all past assessments. From there you can open, approve, revoke, or delete assessments.

Risk assessment interface

Assessing inherent risk

Score the risk as it would be without any of your measures in place: how likely it is, and how bad it would be.

Estimating likelihood and impact

Set likelihood and impact from their dropdowns, and Tidal multiplies the two into the risk score for you.

Setting Likelihood:

  1. Select the Likelihood dropdown
  2. Choose from available options:
    • 1 - Remote - Rarely or never occurring (<1% chance per year)
    • 2 - Unlikely - Improbable but possible (1-10% chance per year)
    • 3 - Possible - Reasonable chance of occurring (11-50% chance per year)
    • 4 - Likely - Probable within foreseeable time (51-90% chance per year)
    • 5 - Almost certain - Almost certain to happen (>90% chance per year)

Determining Impact:

  1. Select the Impact dropdown
  2. Assess potential damage:
    • 1 - Insignificant - Negligible consequences
    • 2 - Minor - Limited impact on organisation
    • 3 - Moderate - Significant but manageable consequences
    • 4 - Major - Serious impact on business operations
    • 5 - Extreme - Critical threat to organisation

Automatic risk score:

  • Tidal automatically calculates: Likelihood × Impact = Risk Score
  • Score 1-6: Low (green)
  • Score 7-15: Medium (orange)
  • Score 16-25: High (red)

Adding comments

Justify your estimate in a comment; that's what makes the score defensible later, to another assessor or an auditor.

Supporting your assessment:

  1. Use the Comments field to justify your estimation
  2. Describe specific factors that influence likelihood
  3. Explain what impact is expected from this risk
  4. Reference concrete examples or historical incidents

Using AI support:

  • Click "Ask TidalBot" or the TidalBot icon (3 stars) for automated risk assessment
  • AI analyses organisational context and generates realistic assessment
  • Review and adjust based on specific circumstances
Tip

Consistent assessment: Use the same criteria for all risks. Document your assessment methodology to ensure consistency between different assessors.

Determining Treatment Plan

With the inherent score known, decide what to do about the risk. Only the Reduce option requires you to link controls.

Selecting treatment options

After assessing inherent risk, you must determine how the risk will be treated:

Reduce - Most commonly used option:

  • Implement controls to decrease likelihood or impact
  • Example: Install firewall against cyber attacks
  • Suitable for: Medium to high risks that can be influenced

Accept:

  • Consciously accept the risk without additional measures
  • Example: Low financial risk that's more expensive to mitigate
  • Suitable for: Low risks or where mitigation isn't cost-effective

Transfer:

  • Shift risk to another party (insurance, outsourcing)
  • Example: Purchase cyber insurance for data breach risks
  • Suitable for: Financial risks or specialized expertise

Avoid:

  • Completely stop the activity causing the risk
  • Example: Not using certain technology
  • Suitable for: Very high risks where alternatives exist

Chosen Reduce? Then also link Controls

Reduce is the only treatment that requires linking controls: they're what actually reduces the risk.

Selecting controls:

  1. Choose "Reduce" as treatment
  2. Review relevant controls if controls are already linked to the risk
  3. Add relevant controls by selecting the Controls field and searching or selecting from the list
  4. Multiple controls possible per risk

Effective control mapping:

  • Preventive controls - Prevent risk from occurring
  • Detective controls - Detect when risk occurs
  • Corrective controls - Restore after risk incident
  • Compensating controls - Alternative protection

Notes (Comments):

  • Explain why you chose this treatment
  • Describe how controls mitigate the risk
  • Mention any limitations of chosen approach

Assessing Residual Risk

Now score the same risk again, this time with your measures in place, and check the result against what your organisation is willing to accept.

Estimating residual risk

After treatment, you must assess the remaining risk:

New likelihood and impact:

  1. Consider effect of linked controls
  2. Set new Likelihood (usually lower due to preventive controls)
  3. Determine new Impact (possibly lower due to detective/corrective controls)
  4. Automatic recalculation of Residual Risk score

Realistic estimation:

  • Controls aren't 100% effective - Account for implementation gaps
  • Human factor - Procedures may not always be followed correctly
  • Technical limitations - Systems can fail or be bypassed
  • New threats - Risks evolve despite current controls

Assessing acceptability

Compare the residual score against your organisation's risk appetite; anything above it needs more than what's already in place.

Testing risk appetite:

  • Compare residual risk with organisational risk appetite
  • High residual risk may require additional controls
  • Acceptable residual risk can be approved by management
Warning

Residual risk >= Inherent risk: If residual risk is higher than inherent risk, check your risk assessment. This can happen with poor control implementation or new threats.

Approving an assessment

Click "Approve" to finalize your assessment, once verified. This locks the assessment and sets the risk status to Approved.

  • Revoke Approval: reopens an approved assessment for editing
  • Delete: removes the assessment entirely

Approvals are valid for 12 months. After that, Tidal automatically changes the status to To be reviewed.

Info

To maintain a clear audit trail, Tidal enforces the following rules:

  • Only one draft can exist per risk at a time. Approve or delete the current draft before creating a new one.
  • Only the latest assessment can be approved.
  • To revoke an approval, the assessment must be the latest one and there must be no draft.

Using AI support

TidalBot can draft an assessment for you from the risk description, which you then correct rather than write from scratch.

Deploying TidalBot

TidalBot drafts an assessment from your organisational context and similar risks already in the system.

Automatic assessment:

  1. Click "Ask TidalBot" in Comments section
  2. AI analyses:
    • Organisational context and sector
    • Available asset information
    • Similar risks in database
    • Industry best practices

Using AI output:

  • Review generated assessment critically
  • Adjust for specific context of your organisation
  • Add organisation-specific factors
  • Use as starting point for stakeholder discussion

AI limitations:

  • May miss recent developments
  • Requires human validation and contextual knowledge

Best practices for assessment

Assessments are only comparable if everyone scores the same way, so agree the criteria first and have someone else check the result.

Objective assessment

Two assessors scoring the same risk should land on the same number, which only happens if everyone uses the same criteria.

Ensuring consistency:

  • Use standard criteria for likelihood and impact scores
  • Involve multiple stakeholders for broader perspective
  • Document assumptions and starting points
  • Review assessments periodically with "fresh eyes"

Evidence-based approach:

  • Reference historical data where available
  • Analyse similar organisations and their experiences
  • Use industry statistics for sector calibration
  • Add expertise such as expert assessments by risk specialists

Assessment validation (optional)

A second person checking the assessment, especially for high risks, catches what one assessor alone would miss.

Peer review process:

  • Second assessor checks assessment
  • Management review for high risks
  • Subject matter expert input for technical risks
  • Cross-functional feedback for business impacts

Quality controls:

  • Logical consistency between likelihood and impact
  • Realistic treatment options chosen
  • Adequate control coverage for treating risks with controls
  • Proportional effort relative to risk level

Validating risk assessments

Two things tell you whether your assessments are complete: a built-in Tidal test, and the status column on the Risks overview.

Automated completeness check

Tidal Control has a built-in Test available that automatically checks whether all risk assessments are completed:

"All risks have an inherent risk level, treatment option, and residual risk" test verifies:

  • Inherent risk filled - Likelihood and Impact for all risks
  • Treatment option chosen - Reduce/Accept/Transfer/Avoid for each risk
  • Residual risk determined - Residual risk assessment after treatment
  • Risk appetite configured - Organisational risk appetite settings

Test results:

  • Pass - All risks have complete assessment
  • Fail - One or more risks are missing assessment information
  • Error - Technical issue with the test

Checking overview completeness

In the Risks overview page you can directly see which risks still have incomplete assessments:

  • Colored risk badges - Show inherent and residual risk levels
  • Empty badges - Risks without complete assessment
  • Assessment status column - Indicates which risks still need attention
Tip

Systematic approach: Review the "All risks have an inherent risk level, treatment option, and residual risk" test after performing a risk asssessment to ensure it is complete. This supports compliance with ISO 27001 and other risk management standards.

What a risk assessment is

A risk assessment is a systematic process to identify, evaluate and prioritise potential risks that could affect your organisation. It involves analysing threats, vulnerabilities and potential impact to effectively manage risks.

The process consists of five main steps:

  1. Identify risks - Map threats and vulnerabilities
  2. Analyse risks - Determine likelihood and impact
  3. Determine treatment - Accept, avoid, reduce or transfer
  4. Evaluate residual risks - Compare with acceptance criteria
  5. Monitor and adjust - Monitor effectiveness and adapt
Info

Risk assessment frequency: Perform a complete risk assessment at least annually, or more frequently when there are significant changes in organisation, technology, or business environment. Tidal already enforces the annual minimum for you: an approval expires after 12 months and the risk status changes to To be reviewed.

Next steps

After conducting risk assessment, you can:

  • Validate completeness with the "All risks have an inherent risk level, treatment option, and residual risk" test
  • Implement controls to reduce risks
  • Verify asset scope for complete risk coverage
  • Generate risk reporting to keep management informed
  • Plan periodic reviews to monitor risk developments
Tip

Start with high-impact risks: Begin your assessment with risks that have the greatest potential impact on your organisation. This provides the best results for your risk management.