5.3 Assess Risks

Key Takeaways

  • Risk assessment in Strategy Analysis evaluates uncertainties surrounding current operations, proposed future states, and the change strategy required to achieve them.
  • Risks are defined as uncertain events or conditions that, if they occur, have a positive (opportunity) or negative (threat) effect on business objectives.
  • Risk analysis measures two primary dimensions: Probability (likelihood of occurrence) and Impact (severity of consequence).
  • Negative risk responses include Avoid, Mitigate, Transfer, and Accept; positive risk responses include Exploit, Enhance, Share, and Accept.
  • An organization's risk tolerance, risk appetite, and risk threshold dictate which risks require active mitigation versus passive acceptance.
Last updated: August 2026

5.3 Assess Risks

Purpose of Risk Assessment in BABOK v3

The primary purpose of Assess Risks (BABOK Guide v3 Task 6.3) is to understand the uncertainties associated with achieving the future state, evaluating the potential impacts of those uncertainties, and recommending appropriate risk response strategies.

Risk is inherent in all organizational endeavors. When analyzing strategy, business analysts must assess risks across three distinct dimensions:

  1. Current State Risks: Risks associated with maintaining existing legacy operations (e.g., system failure risk, technical debt, operational burnout).
  2. Future State Risks: Risks associated with operating in the target state (e.g., market adoption risk, new compliance liabilities).
  3. Change Strategy Risks: Risks associated with executing the transition path itself (e.g., resource availability, implementation delays, organizational change resistance).

Risk Fundamentals: Problems vs. Risks

A critical conceptual distinction in BABOK v3 is the difference between an issue/problem and a risk:

  • Problem / Issue: A condition or event that has already occurred or is currently taking place. It is a known reality requiring immediate resolution or management.
  • Risk: An uncertain event or condition that has not yet occurred, but if it does occur, will exert a positive or negative effect on enterprise goals and objectives.

Risks are defined by two key parameters:

  • Probability (Likelihood): The estimated percentage chance that the uncertain event will materialize (scaled quantitatively from 0% to 100%, or qualitatively as Low, Medium, High).
  • Impact (Severity): The magnitude of financial, operational, strategic, or reputational consequence if the risk occurs.

Risk Exposure Score=Probability×Impact\text{Risk Exposure Score} = \text{Probability} \times \text{Impact}


Organizational Risk Attitude, Appetite, and Tolerance

An organization's governance culture dictates how risks are evaluated and managed. CBAP candidates must master three key risk posture concepts:

  • Risk Appetite: The overall amount and type of risk an enterprise is willing to pursue or accept in pursuit of strategic value and business objectives.
  • Risk Tolerance: The acceptable level of variation that an enterprise can endure relative to the achievement of a specific objective.
  • Risk Threshold: A specific quantitative trigger level or baseline point above which a risk must be escalated or actively managed with a formal response strategy.
Risk Attitude CategoryBehavioral ProfileDecision-Making Impact
Risk-AverseUnwilling to accept significant uncertainty; prioritizes capital preservation and operational stability over high-return opportunities.Prefers conservative, proven solution options; requires extensive mitigation plans.
Risk-NeutralEvaluates decisions purely on expected financial value, balancing risk and reward without inherent bias.Accepts medium risk if calculated Return on Investment (ROI) justifies potential exposure.
Risk-Seeking (Risk-Taker)Eager to adopt high-uncertainty initiatives in pursuit of market disruption or maximum enterprise value.Willing to pursue unproven, cutting-edge technology solutions; tolerates high implementation risk.

Negative Risk Response Strategies (Threats)

When addressing risks that carry adverse consequences for the enterprise, the BABOK v3 Risk Analysis and Management technique and standard risk-management practice use four negative risk response strategies:

  1. Avoid: Modify the change strategy, solution scope, or project approach to eliminate the risk condition entirely or protect the objective from its impact (e.g., canceling a high-risk custom software feature and using a standard off-the-shelf module).
  2. Mitigate: Take proactive actions before the risk occurs to reduce the probability of occurrence, the impact severity, or both (e.g., conducting extensive automated testing and pilot releases to lower the probability of system deployment failure).
  3. Transfer: Reallocate the financial liability, operational responsibility, or ownership of the risk to a third party (e.g., purchasing performance insurance, securing service-level guarantees, or outsourcing specialized infrastructure management to a cloud provider).
  4. Accept: Acknowledge the risk condition without taking active structural steps to alter its probability or impact before it occurs. Acceptance can be:
    • Passive Acceptance: Document the risk in the risk register and monitor it.
    • Active Acceptance: Establish a financial contingency reserve or backup procedure if the risk materializes.

Positive Risk Response Strategies (Opportunities)

Risk is not exclusively negative. BABOK v3 explicitly treats uncertain events with a positive impact to value as risks the BA must analyze. The four opportunity responses below come from mainstream risk-management practice and are the set CBAP preparation material uses:

  1. Exploit: Take proactive steps to ensure that the positive opportunity definitely occurs, eliminating uncertainty surrounding its realization (e.g., assigning the enterprise's top technical architects to guarantee early platform launch).
  2. Enhance: Take targeted actions to increase the probability of occurrence, the magnitude of positive impact, or both (e.g., increasing marketing expenditure during a competitor's product delay to maximize market share capture).
  3. Share: Partner with an external third party or consortium to share investment costs and capabilities, allocating a portion of the positive upside (e.g., forming a joint venture to co-develop new AI algorithms).
  4. Accept (Opportunity): Willingness to take advantage of an opportunity if it arises spontaneously without actively investing resources to force its occurrence.

Maintaining the Risk Register and Ongoing Assessment

Risk assessment is not a one-time event during project kickoff. Senior business analysts establish a continuous risk management loop:

  • Identification: Brainstorming, workshops, risk breakdown structures, lessons learned reviews.
  • Analysis: Qualitative scoring (matrices) and quantitative modeling (Monte Carlo simulation, decision tree analysis).
  • Evaluation: Ranking risks against organizational risk thresholds.
  • Monitoring: Tracking risk triggers—warning signals indicating that a risk event is imminent.

CBAP Exam Tips & Strategic Guidance

  • Distinguishing Responses: If an exam scenario describes purchasing cloud insurance or vendor SLAs, select Transfer. If it describes adding technical code reviews to prevent bugs, select Mitigate. If it describes changing scope to remove a feature, select Avoid.
  • Negative vs. Positive: Pay close attention to whether the question stem describes an adverse threat or a favorable opportunity before selecting the response strategy!
Loading diagram...
Risk Assessment and Strategy Response Framework
Calculated Risk Exposure Score (Probability x Impact)
Test Your Knowledge

An enterprise evaluates a high-uncertainty custom payment engine module. To eliminate potential data breach liability, executive leadership decides to purchase third-party cloud payment processing services protected by vendor financial SLAs. Which risk response strategy was executed?

A
B
C
D
Test Your Knowledge

A business analyst identifies that implementing automated continuous integration code reviews will reduce software bug deployment probability from 30% to 5%. What risk response strategy does this represent?

A
B
C
D
Test Your Knowledge

An enterprise learns that a key market competitor's product release is delayed by 6 months. Executive leadership approves an immediate $500,000 marketing campaign to increase the likelihood of capturing 25% additional market share during this window. What positive risk response was executed?

A
B
C
D
Test Your Knowledge

During Strategy Analysis, a business analyst notes an upcoming regulatory change that might impact system reporting in 18 months. Because the regulation is currently in draft form, leadership logs it in the risk register with no active budget allocation until formal enactment. What response was chosen?

A
B
C
D