"Risk you haven't assessed is risk you've accepted by default."
ESRA Methodology and Frameworks
Professor Sele: Professional risk assessment is not improvised — it follows a documented methodology. This module walks you through SafeHaven's ESRA methodology from initiation to final report, and introduces the recognised international frameworks it is built on.
Section 1 — SafeHaven ESRA Methodology
SafeHaven's ESRA follows this structured sequence: Scoping (define the assessment boundaries — sites, operations, time periods, risk categories); Information gathering (document review, site inspection, stakeholder interviews, intelligence); Hazard and threat identification (categorise all identified risks); Likelihood and impact evaluation (apply consistent rating scales); Risk prioritisation (calculate risk scores, produce the risk matrix); Control measure development (recommend proportionate, actionable controls); Report production (the written ESRA report and risk register); Presentation and handover (brief the client and agree action plans); and Review scheduling (agree the next assessment date and trigger conditions).
Section 2 — International Frameworks
SafeHaven's ESRA methodology draws on ISO 31000 (international standard for risk management — principles, framework, and process), ASIS International Guidelines (professional standards for physical security and risk assessment), the UN UNDSS Security Risk Management Model (used for security risk assessment in humanitarian and development contexts), and CPNI (UK Centre for the Protection of National Infrastructure) guidance on protective security risk assessment for high-value assets.
Section 3 — The Risk Register
The risk register is the core output of the ESRA. It contains one entry per identified risk and is the document the client returns to throughout the lifecycle of the engagement.
| Field | Example Entry |
|---|---|
| Risk Description | Unauthorised access via unmonitored rear loading bay |
| Category | Physical |
| Likelihood | 4 — Likely (incident history; CCTV blind spot) |
| Impact | 4 — Major (theft of high-value plant, operational halt) |
| Risk Score | 16 — Critical |
| Current Controls | Single guard patrol every 2 hours |
| Recommended Controls | Install CCTV with motion alert; introduce 24/7 static post |
| Residual Risk | 6 — Medium (after controls) |
| Risk Owner | Site Security Manager (named individual) |
| Review Date | 90 days from sign-off |
Section 4 — Residual Risk and Acceptance
No risk can be completely eliminated. After all recommended controls are applied, a residual risk remains. The client must formally accept the residual risk — acknowledging that it exists and that the agreed controls represent a proportionate response. Undocumented residual risk acceptance is a significant legal exposure.
- •The 9-step SafeHaven ESRA methodology provides a documented, defensible process
- •International frameworks (ISO 31000, ASIS, UNDSS) underpin SafeHaven's approach
- •The risk register is the primary output — one entry per risk, with owner and review date
- •Residual risk must be formally accepted by the client in writing
- •Methodology consistency enables comparison across assessments and clients
"I have been in court as an expert witness on two occasions where a client's security failure led to legal proceedings. Both times the question asked was: 'Was a risk assessment conducted, and did it follow a recognised methodology?' The first case: no documented methodology. The assessor testified from memory. The second case: full ISO 31000 aligned process, documented at every step. The first case cost the client significantly. The second was resolved in their favour. Methodology is not bureaucracy — it is legal protection."
The residual risk is: