Turn the scores and the weak link into a written, sequenced plan that routes to the right guides with clear targets and a dated first action.
Address an imminent critical risk first if present. Then start with the guide for your weak link, add every other sub-domain that is not yet reliable in dependency order, and drop any already reliable.
Identification goes to Identify and Assess Structural Risk. Key-person goes to Reduce Key-Person Risk. Concentration goes to Reduce Concentration and Dependency Risk. Continuity goes to Build Continuity and Contingency Plans. Resilience and monitoring goes to Build Resilience and Monitor Risk.
| Order | Sub-domain and guide | Current | Target | First action | Owner |
|---|---|---|---|---|---|
| 1 (weak link) | |||||
| 2 | |||||
| 3 | |||||
| 4 | |||||
| 5 |
State the move each row represents, for example: Reduce Key-Person Risk takes your team from fragile to resilient, or Reduce Concentration takes your systems from shaky to reliable.
Risk work is easy to defer because the danger is not yet visible, so the date matters. Return at reassessment to record how far each sub-domain has moved.
Your answers stay in your browser on this page and are never sent anywhere.