
The RISENTRA Risk & Resilience Framework provides a structured approach to understanding organisational exposure, assessing risk, evaluating existing controls and determining whether resilience arrangements are proportional to the risks faced.
What the Framework Does
The framework helps organisations understand where significant risks exist, how effectively those risks are being controlled, and whether the organisation is sufficiently prepared to withstand, respond to and recover from disruption.
01
UNDERSTAND
Identify exposure
Identify critical services, dependencies, vulnerabilities and areas of exposure that could affect the organisation.
ASSESS
Evaluate risk & control
Assess likelihood, impact and existing controls to determine the significance of identified risks.
02
CHALLENGE
Test resilience
Challenge whether current controls and resilience arrangements are effective, appropriate and proportionate.
03
04
RESPOND
Prioritise action
Define practical actions to reduce exposure, strengthen resilience and focus attention where it matters most.
What We Assess
We assess the areas that determine how effectively an organisation understands risk, maintains control and remains resilient when disruption occurs.
01
Risk Exposure
Identify exposure
Identify critical services, dependencies, vulnerabilities and areas of exposure that could affect the organisation.
Critical Services & Dependencies
02
Understand dependencies
Identify the services, processes, people, technology and third parties the organisation depends upon to operate effectively.
03
Controls & Mitigation
Evaluate control effectiveness
Assess whether existing controls reduce risk effectively, identify weaknesses or gaps, and determine where further mitigation may be required.
04
Operational Resilience
Prepare for disruption
Assess whether critical services can withstand disruption, continue at acceptable levels and recover within appropriate timescales.
05
Response & Recovery
Recover with confidence
Assess response and recovery arrangements, including roles, escalation, communication and the ability to restore critical services following disruption.
06
Governance & Ownership
Strengthen accountability
Assess whether risk and resilience responsibilities are clearly owned, governed and supported by effective oversight, escalation and decision-making.
OUR ASSESSMENT LENS
Our Risk & Resilience Framework assesses six key dimensions to provide a clear, evidence-based view of your current position and the actions needed to strengthen resilience, reduce risk and protect business outcomes.
STRATEGIC
Where are we now?
Assess strategic objectives, risk appetite and the alignment of risk and resilience with business goals.
01
THIRD PARTY & SUPPLY CHAIN
Where do external dependencies create risk?
Evaluate risks from third parties, suppliers and external dependencies, including their resilience and control arrangements.
04
OPERATIONAL
Where could operations be exposed?
Review operational processes, dependencies and service resilience to identify risks that could impact business delivery.
02
PEOPLE & CAPABILITY
Do we have the capability to respond?
Assess the skills, roles, responsibilities and awareness needed to manage risk effectively and maintain resilience.
05
TECHNOLOGY & SERVICE
Can our technology withstand disruption?
Assess the resilience of technology, platforms and services that support critical business operations.
03
GOVERNANCE & CONTROL
Is accountability clear?
Review governance, risk management and control arrangements, including ownership, oversight, escalation and decision-making.
06
HOW WE EVALUATE RISK
We use a consistent and structured approach to assess the likelihood and impact of risk. This provides a clear, evidence-based risk score that helps prioritise attention and action.
LIKELIHOOD
How likely is the risk to occur?
Likelihood is assessed using a five-point scale, providing a consistent view of how probable it is that an identified risk will occur.
​
RARE
Exceptional circumstances
May occur only in exceptional circumstances.
01
UNLIKELY
Could occur
Not expected, but could occur in some circumstances.
02
POSSIBLE
May occur
Could occur at some point under normal circumstances.
03
LIKELY
Expected to occur
Likely to occur in many circumstances.
04
ALMOST CERTAIN
Highly probable
Expected to occur in most circumstances.
05
INSIGNIFICANT
Minimal impact
Minimal impact on operations, finances or reputation.
01
MINOR
Limited impact
Limited impact, easily manageable within normal operations.
02
MODERATE
Management attention
Noticeable impact requiring management attention.
03
MAJOR
Significant impact
Significant impact causing material disruption to objectives.
04
SEVERE
Critical impact
Critical impact threatening core operations, regulatory compliance or reputation.
05
LIKELIHOOD × IMPACT = RISK SCORE
The likelihood score is multiplied by the impact score to calculate an overall risk score from 1–25. This provides a consistent basis for determining risk severity and prioritising action.
FROM RISK SCORE TO ACTION
The calculated risk score determines the level of exposure and helps prioritise the appropriate management response.

FROM ASSESSMENT TO ACTION
We translate assessment findings into clear priorities and practical actions — helping leaders understand what needs attention, what should happen first and where improvement will have the greatest impact.
FINDINGS
What have we learned?
Consolidate assessment evidence into a clear view of strengths, vulnerabilities, risks and areas requiring attention.
01
ACTIONS
What needs to happen?
Translate priorities into practical actions with clear ownership, timescales and intended outcomes.
03
PRIORITIES
What matters most?
Prioritise findings according to exposure, business impact and urgency — focusing attention where action will deliver the greatest value.
02
IMPROVEMENT
How do we move forward?
Establish a focused improvement plan that strengthens resilience, reduces exposure and supports measurable progress.
04
INHERENT RISK vs RESIDUAL RISK
We assess both inherent and residual risk to understand the effectiveness of controls, identify remaining exposure and determine whether further action is required.
INHERENT RISK
Exposure before controls
The level of risk that exists before mitigating controls are considered, based on the likelihood and impact of the identified risk.
01
CONTROLS & MITIGATION
Measures that reduce exposure
Policies, processes, technology and people-based controls that help prevent, detect, respond to or reduce the likelihood or impact of risk.
02
RESIDUAL RISK
Exposure remaining after controls
The level of risk that remains after controls are applied, reflecting their effectiveness and any remaining exposure.
03
IS THE RESIDUAL RISK ACCEPTABLE?
The remaining exposure is assessed against the organisation’s risk appetite and tolerance, taking account of control effectiveness and business context.
YES
ACCEPT & MONITOR
Residual risk is within acceptable tolerance. Maintain the controls, monitor exposure and review at appropriate intervals.
NO
FURTHER ACTION REQUIRED
Residual risk remains above acceptable tolerance. Strengthen controls, reduce exposure or escalate for an appropriate management decision.
RESILIENCE ASSESSMENT
Risk exposure alone does not determine resilience. We also consider how effectively the organisation can prepare for, withstand, respond to and recover from disruption while maintaining its most important activities and services.
PREPARE
Build readiness and reduce vulnerability
Strengthen capabilities, improve planning and address vulnerabilities before disruption occurs.
01
RESPOND
Take action to manage the incident
Activate response plans, coordinate activity and communicate effectively to contain disruption and protect critical services.
03
WITHSTAND
Maintain operations and limit impact
Use existing controls and capabilities to maintain critical activities, protect key services and limit the impact of disruption.
02
RECOVER
Restore services and strengthen resilience
Restore critical services, resume normal activity and capture lessons that strengthen resilience for future disruption.
04
OVERALL RISK & RESILIENCE POSITION
We consolidate the findings from our risk and resilience assessments to provide an evidence-based view of the organisation’s overall position, highlighting strengths, areas requiring improvement and priorities for management attention.
EFFECTIVE
Strong controls and resilient capabilities effectively manage risk and support organisational objectives.
01
ADEQUATE
Controls and resilience capabilities are generally effective, with some areas requiring targeted improvement.
02
REQUIRES IMPROVEMENT
Significant gaps or inconsistencies increase exposure and reduce the organisation’s ability to withstand disruption.
03
WEAK
High risk exposure, weak controls or limited resilience capabilities require immediate management attention.
04
FINDINGS & PRIORITISED ACTION
We translate assessment findings into clear priorities and practical actions — focusing attention on what matters most and where improvement will deliver the greatest value.
KEY FINDINGS
What have we identified?
A clear, evidence-based view of the most material risks, gaps, vulnerabilities and areas requiring attention.
01
PRIORITISED ACTIONS
What should happen first?
Practical recommendations prioritised according to risk, business impact, urgency and achievable improvement.
02
MEASURABLE OUTCOMES
How will we know it worked?
Defined outcomes and measures that provide a clear view of progress, improvement and the value delivered.
03
What You Receive
A RISENTRA Risk & Resilience assessment provides a clear, practical view of your organisation’s exposure, existing controls and resilience position — supported by prioritised recommendations for improvement.
RISK & RESILIENCE
ASSESSMENT
A structured assessment of key risks, controls, dependencies and resilience arrangements across the organisation.
01
EXECUTIVE
FINDINGS
A concise leadership-level view of significant exposures, strengths, weaknesses and areas requiring management attention.
02
PRIORITISED
ACTION PLAN
Clear recommendations prioritised according to risk, impact and urgency — focusing management attention where it matters most.
03
IMPROVEMENT
ROADMAP
A practical sequence of improvement activity — providing clear direction for implementation, ownership and tracking progress.
04
Designed to Support Better Decisions
The output is designed to give leadership a clear and proportionate view of risk and resilience — helping inform decisions on priorities, investment and improvement without unnecessary complexity.
How an Engagement Works
RISENTRA engagements are structured, focused and proportionate to the organisation. We work with leadership and relevant stakeholders to understand the environment, assess the evidence, challenge assumptions and provide an independent view of risk and resilience.
DISCOVER
Understand the organisation
Get to know the organisation, its priorities, operating environment and the issues that matter most.
01
CHALLENGE
What needs to be challenged?
Challenge assumptions, identify gaps and test whether existing controls and resilience arrangements reflect the organisation’s true exposure.
03
ASSESS
What is the evidence telling us?
Assess risk, controls and resilience using available evidence to establish the organisation’s current position.
02
REPORT
What should happen next?
Provide clear findings, prioritised actions and practical next steps — giving leadership a focused basis for decision-making.
04
Understand Your Risk. Strengthen Your Resilience.
You do not need to wait for a major incident or disruption to understand where your organisation may be exposed.
​
RISENTRA provides an independent, practical assessment of your risk and resilience position — helping you understand where you are today, identify where attention is required and determine the practical steps needed to strengthen your organisation.