Professor Sele
Lead Risk Assessment Specialist | SafeHaven Strategies

"Risk you haven't assessed is risk you've accepted by default."

Module 10

ESRA in Practice

Professor Sele: This final module consolidates everything you have learned and prepares you for the Course 7 assessment. We close with a review of the full ESRA process and the professional standards that make SafeHaven's risk assessments trusted across Liberia and the wider region.

Section 1 — The Full ESRA Process — Review

End-to-end, a SafeHaven ESRA proceeds as follows: Preparation phase (scope agreement, document collection, pre-visit checklist); Assessment phase (site inspection, stakeholder interviews, intelligence review, hazard identification); Analysis phase (likelihood and impact rating, risk scoring, vulnerability mapping, control evaluation); Reporting phase (risk register, recommendations, executive summary, written report); Delivery phase (verbal briefing, action plan agreement, residual risk acceptance); and Follow-up phase (action plan monitoring, periodic review, updated assessment when trigger conditions are met).

Section 2 — Common ESRA Mistakes

Relying on documents without conducting physical inspection. Interviewing management only — missing ground-level observations. Rating risks by gut feeling rather than consistent likelihood/impact scales. Producing recommendations that are too vague to action. Failing to update the assessment when the environment changes. Treating the report as the end product rather than the action plan.

Section 3 — Key Definitions for the Test

ESRA: Emergency Security Risk Assessment — structured identification, evaluation, and control of security risks. Residual risk: risk that remains after controls are applied. Risk register: the core output document listing all risks, scores, controls, owners, and review dates. Likelihood rating: how probable it is that a risk will materialise. Impact rating: how severe the consequences would be if the risk materialised. Critical asset: a person, system, or resource whose compromise would severely impair the client's operations. Control hierarchy: Eliminate → Substitute → Engineer → Administrative → PPE.

Section 4 — Career Pathway

Completion of Course 7 qualifies SafeHaven professionals for ESRA Analyst roles, Site Security Assessment Lead, Risk Advisory functions on complex multi-site contracts, and Senior roles in SafeHaven's consulting and advisory practice.

Key Points
  • The full ESRA process: Preparation → Assessment → Analysis → Reporting → Delivery → Follow-up
  • Common mistakes: no physical inspection, management-only interviews, vague recommendations, no update trigger
  • Know the key definitions for the test
  • ESRA certification opens risk advisory and consulting career pathways at SafeHaven
Field Note · Professor Sele

"The best ESRA I ever conducted took three days on site and produced a 28-page report that the client's CEO read cover to cover. He called me afterward and said: 'This is the first security document I have ever read that told me something I didn't know and showed me exactly what to do about it.' That is the standard. Not the thickest report. Not the most technical language. The report that changes something. That is what an ESRA is for."

Knowledge Check

Which of the following is NOT a recognised category of security risk?