5.2 Risk Evaluation and Prioritization

Key Takeaways

  • Risk evaluation is Process Step 5 of ISO 31000:2018, comparing analyzed risk levels against established risk criteria to make treatment decisions.
  • Risk criteria reflect organizational values, legal obligations, context, and risk appetite, acting as the benchmark for evaluation.
  • Risk matrices/heat maps must be designed carefully to avoid range compression, non-linear distortion, and misprioritization.
  • The ALARP (As Low As Reasonably Practicable) principle balances risk reduction benefits against the costs and effort of additional controls.
  • Evaluation outcomes include maintaining existing controls, implementing treatments, modifying objectives, or conducting further analysis.
Last updated: July 2026

5.2 Risk Evaluation and Prioritization

Following Risk Analysis (Process Step 4), the risk management process transitions directly into Risk Evaluation (Process Step 5) under ISO 31000:2018. While risk analysis seeks to objectively quantify or describe the magnitude and likelihood of a risk, risk evaluation focuses on determining the significance of those findings to support decision-making.

The core purpose of risk evaluation is to assist decision-makers in using the outcomes of risk analysis to determine which risks require treatment, the priority order for allocating treatment resources, and whether existing risk levels fall within the organization's risk tolerance and risk appetite.


Comparing Risk Levels Against Risk Criteria

During Process Step 2 (Defining Scope, Context, and Criteria), the organization establishes risk criteria—the terms of reference against which the significance of a risk is evaluated. In the evaluation phase, the analyzed risk levels are directly benchmarked against these pre-established criteria.

Inputs and Decision Parameters

When comparing risk levels against risk criteria, decision-makers must consider:

  1. Organizational Objectives: How directly does the risk threaten strategic, financial, operational, or reputational goals?
  2. Legal and Regulatory Mandates: Statutory compliance requirements often mandate compulsory treatment regardless of cost.
  3. Risk Appetite and Tolerance: Is the analyzed risk level within defined operational thresholds, or does it breach executive appetite limits?
  4. Stakeholder Perceptions and Values: How do key internal and external stakeholders view the risk exposure?

Five Potential Evaluation Outcomes

Based on the comparison of risk levels against risk criteria, ISO 31000 specifies five primary decision pathways:

  • Do Nothing Further: Accept the risk level as broadly tolerable without additional treatment intervention.
  • Consider Risk Treatment Options: Initiate formal planning to select and implement appropriate treatment controls.
  • Undertake Further Analysis: Gather additional data or conduct deeper modeling if uncertainty surrounding the analysis is too high to make an informed decision.
  • Maintain Existing Controls: Continue operating existing controls without modification, ensuring ongoing monitoring.
  • Reconsider Organizational Objectives: If a risk cannot be mitigated to an acceptable level and avoidance is impossible, executive leadership may decide to revise the strategic objective itself.

Risk Heat Maps and Matrix Mechanics

Risk Matrices (commonly referred to as Risk Heat Maps) are among the most widespread tools used during risk evaluation to visualize, categorize, and prioritize risks. Typically formatted as a 5x5 grid, the matrix plots Likelihood on one axis against Consequence on the opposing axis.

Consequence Rating1 - Negligible2 - Minor3 - Moderate4 - Major5 - Catastrophic
5 - Almost CertainModerate (5)High (10)Extreme (15)Extreme (20)Extreme (25)
4 - LikelyLow (4)Moderate (8)High (12)Extreme (16)Extreme (20)
3 - PossibleLow (3)Moderate (6)Moderate (9)High (12)Extreme (15)
2 - UnlikelyLow (2)Low (4)Moderate (6)Moderate (8)High (10)
1 - RareLow (1)Low (2)Low (3)Low (4)Moderate (5)

Critical Matrix Limitations (PECB Exam Focus)

While risk heat maps provide intuitive visual prioritization, ISO 31000 and IEC 31010 highlight significant technical limitations that risk managers must navigate:

  • Range Compression: Categorizing wide continuous financial or operational distributions into 5 discrete boxes can cause wildly disparate risks to receive identical heat map colors.
  • Poor Resolution: A 5x5 matrix cannot easily distinguish between high-frequency / low-consequence operational risks and low-frequency / catastrophic tail risks.
  • Centering Bias: Evaluators frequently assign moderate scores to avoid making definitive high or low assessments, crowding risks into the yellow center.
  • False Precision: Visualizing risks in neat colored squares can create an unjustified illusion of mathematical certainty among board members.

The ALARP Principle (As Low As Reasonably Practicable)

The ALARP Principle is a foundational decision-making framework extensively referenced in international risk assessment standards. It establishes a structured, three-tiered framework for evaluating whether risk reduction controls should be mandated.

=========================================================================
  INTOLERABLE / UNACCEPTABLE REGION
  - Risk cannot be justified except in extraordinary circumstances.
  - Risk treatment is COMPULSORY regardless of implementation cost.
=========================================================================
  ------------------- Upper Risk Tolerability Threshold -------------------
=========================================================================
  ALARP / TOLERABLE REGION
  - Risk is acceptable ONLY IF further risk reduction is impracticable
    or disproportionately costly compared to the risk reduction benefit.
  - Requires formal Cost-Benefit Analysis & Gross Disproportion Test.
=========================================================================
  ------------------- Lower Risk Tolerability Threshold -------------------
=========================================================================
  BROADLY ACCEPTABLE REGION
  - Risk is negligible and managed by routine operational controls.
  - No additional risk treatment required; monitor periodically.
=========================================================================

The Gross Disproportion Test

Within the ALARP Region, a risk treatment measure must be implemented unless the effort, time, or monetary cost of implementing the control is grossly disproportionate to the risk reduction benefit gained.

If the cost of a control is merely slightly higher than the benefit, the control must still be implemented. To justify withholding a control in the ALARP region, the risk manager must demonstrate a disproportionality ratio (e.g., Cost is 5x to 10x greater than the monetary value of risk reduction).


Evaluation Governance & Decision Authority Levels

Organizations must establish clear governance matrices tying evaluated risk levels to approval authorities and required response timelines.

Risk Zone / LevelEvaluated ThresholdMandated Action / TimelineDecision Authority Level
Extreme (Red)Exceeds Risk Appetite; Breaches Maximum ToleranceImmediate risk treatment plan required within 7 days; daily monitoringExecutive Committee / Board Audit & Risk Committee
High (Orange)Exceeds Risk Appetite; Within Tolerance BoundariesRisk treatment plan required within 30 days; monthly monitoringDivision Senior Vice President / Operations Director
Moderate (Yellow)Within Risk Appetite; Near Upper ThresholdEvaluate cost-effective controls; quarterly monitoringDepartment Manager / Business Unit Risk Owner
Low (Green)Substantially Below Risk AppetiteAccept risk under routine operational controls; annual reviewOperational Supervisor / Line Management

Worked Decision Example: Plant Safety Upgrade under ALARP

A chemical manufacturing facility evaluates a toxic gas containment risk during Process Step 5.

Baseline Risk Analysis Findings

  • Consequence: Severe exposure causing potential permanent injury or fatality ($5,000,000 estimated impact).
  • Likelihood: 1 event every 20 years ($0.05$ annual probability).
  • Baseline Annual Risk Exposure: $0.05 \times $5,000,000 = $250,000 / \text{year}$.

Proposed Risk Treatment Control

  • Safety Scrubbing System: Installation cost = $1,200,000 (amortized over 10 years = $120,000 / year).
  • Post-Control Likelihood: 1 event every 200 years ($0.005$ annual probability).
  • Post-Control Annual Risk Exposure: $0.005 \times $5,000,000 = $25,000 / \text{year}$.
  • Annualized Risk Reduction Benefit: $$250,000 - $25,000 = $225,000 / \text{year}$.

Evaluation and ALARP Decision

  1. Tolerability Assessment: The baseline risk falls into the ALARP Region (life safety risk, tolerable only if reduction is impracticable).
  2. Benefit vs. Cost Comparison:
    • Annualized Risk Benefit = $225,000
    • Annualized System Cost = $120,000
    • Benefit-to-Cost Ratio = $\frac{$225,000}{$120,000} = 1.875$
  3. Decision Outcome: Because the annualized benefit ($225,000) exceeds the annualized cost ($120,000), the cost is not grossly disproportionate. Under ALARP, installing the scrubbing system is compulsory.
Loading diagram...
ISO 31000 Risk Evaluation Decision Logic & ALARP Governance
Test Your Knowledge

What is the primary objective of Process Step 5 (Risk Evaluation) in ISO 31000:2018?

A
B
C
D
Test Your Knowledge

Under the ALARP (As Low As Reasonably Practicable) principle, when can an organization decline to implement a risk reduction control for a risk located within the tolerable ALARP zone?

A
B
C
D
Test Your Knowledge

Which of the following is a recognized technical limitation of traditional 5x5 risk heat maps used during risk evaluation?

A
B
C
D