9.3 Risk Management

Key Takeaways

  • TOGAF distinguishes the initial level of risk, before mitigating actions, from the residual level of risk, after mitigating actions.
  • The TOGAF risk management process covers risk classification, risk identification, initial risk assessment, risk mitigation and residual risk assessment, and risk monitoring.
  • TOGAF assesses risk impact by combining effect (Catastrophic, Critical, Marginal, Negligible) with frequency (Frequent, Likely, Occasional, Seldom, Unlikely).
  • Risk mitigation reduces risk to an acceptable level and can range from monitoring or acceptance to a full contingency plan.
  • The Enterprise Architect may identify and mitigate risks, but risks are first accepted and then managed within the governance framework.
Last updated: September 2026

9.3 Risk Management

Risk management appears in two learning outcomes: briefly explain risk management (Concepts) and briefly explain the characteristics of architecture risk management and where it is used within the TOGAF ADM (ADM Techniques).


Why Risk Management Matters

There will always be risk with any architecture or business transformation effort. It is important to identify, classify, and mitigate these risks before starting, so they can be tracked throughout the transformation. Mitigation is an ongoing effort, and risk triggers are often outside the scope of the transformation planners (for example, a merger or acquisition), so planners must monitor the transformation context constantly.

An important governance point: the Enterprise Architect may identify the risks and mitigate certain ones, but it is within the governance framework that risks have to be first accepted and then managed.


Two Levels of Risk

LevelDefinition
Initial level of riskRisk categorization prior to determining and implementing mitigating actions
Residual level of riskRisk categorization after implementation of mitigating actions (if any)

The Risk Management Process

The TOGAF Standard describes these activities:

  1. Risk classification
  2. Risk identification
  3. Initial risk assessment
  4. Risk mitigation and residual risk assessment
  5. Risk monitoring (with governance in Phase G)

The ADM Techniques document describes a qualitative approach. A more rigorous quantitative approach is described in the Open FAIR™ Body of Knowledge (the Open Risk Taxonomy and Open Risk Analysis standards), and risk concepts are extended in the TOGAF Series Guide: Integrating Risk and Security within a TOGAF Enterprise Architecture.

1. Risk Classification

Risks can be classified in several ways — for example by time, cost, scope, client expectations, and performance, or by whether they are enterprise-wide or project-level. Classification helps assign responsibility for managing each risk at the right governance level.

2. Risk Identification

The capability maturity and transformation readiness assessments typically generate many risks. Identification documents each risk and sets the strategy to address it throughout the transformation.

3. Initial Risk Assessment

Each risk is assessed for its effect and its frequency, which combine into an impact:

EffectMeaning
CatastrophicCritical financial loss that could result in bankruptcy of the organization
CriticalSerious financial loss in more than one line of business, leading to loss of productivity and no return on the IT investment
MarginalMinor financial loss in a line of business and a reduced return on the IT investment
NegligibleMinimal impact on a line of business's ability to deliver services and/or products
FrequencyMeaning
FrequentLikely to occur very often and/or continuously
LikelyOccurs several times over the course of a transformation cycle
OccasionalOccurs sporadically
SeldomRemotely possible; would probably occur not more than once in a transformation cycle
UnlikelyWill probably not occur during the transformation cycle

The Corporate Risk Impact Assessment matrix combines them:

Effect ↓ / Frequency →FrequentLikelyOccasionalSeldomUnlikely
CatastrophicExtremely HighExtremely HighHighHighModerate
CriticalExtremely HighHighHighModerateLow
MarginalHighModerateModerateLowLow
NegligibleModerateLowLowLowLow

4. Risk Mitigation and Residual Risk Assessment

Risk mitigation is the identification, planning, and conduct of actions that will reduce the risk to an acceptable level. The mitigation effort can range from simple monitoring and/or acceptance of the risk to a full contingency plan calling for complete redundancy, with a correspondingly high cost. After mitigation is planned, the residual risk is assessed using the same classification. A risk identification and mitigation assessment worksheet records, for each risk, the initial effect, frequency, and impact; the mitigation; and the residual effect, frequency, and impact.

5. Risk Monitoring and Governance

Residual risks must be accepted through the governance framework — IT governance, and potentially corporate governance where business acceptance is needed. Once accepted, mitigating actions are carried out and monitored, and risk monitoring continues during Phase G.


Where Risk Management Is Used in the ADM

ADM phaseRisk activity
Phase AStep "Identify the Business Transformation Risks and Mitigation Activities"
Phase EStep "Confirm Readiness and Risk for Business Transformation"
Phase FPrioritize migration projects through cost/benefit assessment and risk validation
Phase GRisk monitoring and governance of residual risks during implementation
Phase HStep "Manage Risks" — manage EA risks and provide recommendations for IT strategy

Worked Example

RiskInitial effect / frequency → impactMitigationResidual effect / frequency → impact
Data migration corrupts customer recordsCritical / Likely → HighTrial migrations, automated reconciliation, rollback planMarginal / Seldom → Low
Key supplier exits the market mid-programCatastrophic / Seldom → HighEscrow of source code, second-supplier optionMarginal / Seldom → Low
Staff resist new claims processMarginal / Likely → ModerateCommunications Plan, training, phased rolloutNegligible / Occasional → Low

The residual risks are presented for acceptance through the governance framework before the Implementation and Migration Plan is finalized.


Common Exam Pitfalls

  • Swapping initial and residual risk. Initial is before mitigation; residual is after mitigation.
  • Letting the architect accept risk alone. Risks are first accepted and then managed within the governance framework.
  • Using a generic probability scale. TOGAF's qualitative scheme uses effect (Catastrophic to Negligible) and frequency (Frequent to Unlikely) to derive impact.
  • Thinking mitigation always means redundancy. Mitigation ranges from monitoring or acceptance to full contingency plans.
Loading diagram...
TOGAF Risk Management Process
Test Your Knowledge

What is the difference between initial and residual levels of risk in TOGAF?

A
B
C
D
Test Your Knowledge

In TOGAF's qualitative risk assessment, which two dimensions are combined to determine a risk's impact?

A
B
C
D
Test Your Knowledge

According to the TOGAF Standard, where are risks first accepted and then managed?

A
B
C
D
Test Your Knowledge

A risk has an effect of Critical and a frequency of Likely. Using the TOGAF corporate risk impact assessment matrix, what is the impact?

A
B
C
D