ZenGRC

Risk Quantification in Compliance

The article explains that effective compliance risk management begins with risk assessment through both qualitative methods, which use subjective likelihood and severity scales to prioritize risks, and quantitative methods, which apply numerical data and algorithms to assign values to risks, emphasizing that risk quantification is a foundational step within the broader risk management process to help organizations identify, evaluate, and mitigate compliance risks.

Risk management helps organizations comply with laws, regulations, and operational standards, aiming for continuous compliance. The first step in managing compliance risk is a risk assessment that quantifies the risks faced. To do this accurately and efficiently, it's important to understand the two types of risk: qualitative and quantitative.

Qualitative Risk

Qualitative risks are uncertain events with a range of possible outcomes, from harmless to severe. For example, a business might describe the risk of a major IT system failure in terms of potential likelihood (remote, unlikely, possible, almost certain) and potential harm (none, mild, medium, severe). A qualitative risk assessment maps these factors along axes so managers can prioritize risks with both high likelihood and high severity.

This analysis is based on experience and subjectivity rather than quantitative measures and is useful for including executives who may not be versed in formal risk management practices.

Quantitative Risk

Quantitative risks have numerical values assigned using algorithms and actuarial data. For example, managers can use historical weather records to assess the likelihood of severe weather disrupting a data center, or financial records to model potential losses from an IT outage.

While quantitative analysis provides numerical values, qualitative analysis is often needed to determine the full impact of business risk.

The Difference Between Risk Quantification and Risk Management

Risk quantification is a crucial part of the larger risk management process. After evaluating and quantifying the organization's exposure to risk, executives are better prepared to mitigate those risks. Risk identification, followed by risk quantification, is an essential first step in the risk management lifecycle.

Risk Evaluation Criteria

Risks can be quantified with the PERT equation: Risk = Event x Probability x Loss. However, this model can leave uncertainty if calculations are based on incomplete or inaccurate data. A better approach is a continuous risk management process to mitigate or prevent risks that could cause significant harm.

This involves:

  • Identifying all significant risks
  • Determining potential risk severity and likelihood
  • Prioritizing risks by importance
  • Developing mitigation strategies to address the largest number of risks efficiently
  • Implementing cost-effective risk management processes

Identifying risks and their severity can be difficult. Determining which risks should be the highest priority and how many resources to allocate often requires input from the project team and a qualitative risk assessment.

Defining and measuring "impact" is usually done in financial or legal terms, but can depend on several variables. Once a solution is found, statistical models can assign a numerical value to the risk, and resources can be allocated accordingly.

Many professionals use Monte Carlo analysis to support risk quantification. Other methods include ISO 27002 and NIST SP 800-53 standards for cybersecurity risk. Most methodologies, such as the FAIR framework, use Monte Carlo simulations.

Monte Carlo Analysis

Monte Carlo analysis, created by Stanislaw Ulam in the 1940s, helps decision-makers handle uncertainty in risk analysis. When executed accurately, it provides a high confidence level for resource allocation to mitigate risks.

The Steps of Monte Carlo Simulations

Step 1: Awareness

Inform business leaders, security teams, stakeholders, vendors, and other relevant parties about the simulation and risk management process. Including risk management professionals or CISOs in decision-making is wise.

Step 2: Risk Management Process

The lifecycle involves planning, identifying, assessing, scoring, prioritizing, analyzing, treating, and monitoring risks. All parameters should be kept in a risk register. The monetary value of potential harm (e.g., from cyber attacks) should be estimated and recorded, including best, worst, and most probable values.

Step 3: Initial Estimates

Add cost estimates for best, worst, and most probable outcomes (three-point estimates).

Step 4: Determine Correlations

Determine correlations between cost estimates and possible outcomes, typically measured from 0 to 1. Positive correlations mean as cost increases, so does risk; negative correlations mean as one increases, the other decreases.

Step 5: Mitigation Model

Simulation models should represent the value at risk and the cost to mitigate. A baseline simulation indicates cost factors for best, worst, and most probable scenarios and their correlations. A pre-mitigated model includes risk events and full financial impact; a post-mitigated model includes risk events and all treatments applied.

Step 6: Run Monte Carlo Simulations

Simulation software typically runs 1,000 iterations to determine project requirements. When determining contingency, 80% of the total project value is used to determine the final cost. Software allows configuration of charts to reflect appropriate amounts.

Step 7: Produce and Communicate Results

After the simulation, perform a risk analysis of the differences between baseline and post-mitigation outputs to understand the impact of risk management protocols and whether they are sufficient for compliance and remediation.

Preparing for a Monte Carlo Simulation

Running a Monte Carlo analysis is complex, especially for compliance risk, and requires sophisticated software. When preparing, it's important to have thoroughly documented information. Managing compliance data manually is not sustainable for large organizations; an automation-based GRC solution is best for enterprise risk scenarios with a data-driven approach.

ZenGRC provides dashboards to show which risks need mitigating, track workflows, collect and store documents for audits, and more.