Professor Sele
Lead Risk Assessment Specialist | SafeHaven Strategies

"Risk you haven't assessed is risk you've accepted by default."

Module 5

ESRA Methodology and Frameworks

Professor Sele: Professional risk assessment is not improvised — it follows a documented methodology. This module walks you through SafeHaven's ESRA methodology from initiation to final report, and introduces the recognised international frameworks it is built on.

Section 1 — SafeHaven ESRA Methodology

SafeHaven's ESRA follows this structured sequence: Scoping (define the assessment boundaries — sites, operations, time periods, risk categories); Information gathering (document review, site inspection, stakeholder interviews, intelligence); Hazard and threat identification (categorise all identified risks); Likelihood and impact evaluation (apply consistent rating scales); Risk prioritisation (calculate risk scores, produce the risk matrix); Control measure development (recommend proportionate, actionable controls); Report production (the written ESRA report and risk register); Presentation and handover (brief the client and agree action plans); and Review scheduling (agree the next assessment date and trigger conditions).

Section 2 — International Frameworks

SafeHaven's ESRA methodology draws on ISO 31000 (international standard for risk management — principles, framework, and process), ASIS International Guidelines (professional standards for physical security and risk assessment), the UN UNDSS Security Risk Management Model (used for security risk assessment in humanitarian and development contexts), and CPNI (UK Centre for the Protection of National Infrastructure) guidance on protective security risk assessment for high-value assets.

Section 3 — The Risk Register

The risk register is the core output of the ESRA. It contains one entry per identified risk and is the document the client returns to throughout the lifecycle of the engagement.

FieldExample Entry
Risk DescriptionUnauthorised access via unmonitored rear loading bay
CategoryPhysical
Likelihood4 — Likely (incident history; CCTV blind spot)
Impact4 — Major (theft of high-value plant, operational halt)
Risk Score16 — Critical
Current ControlsSingle guard patrol every 2 hours
Recommended ControlsInstall CCTV with motion alert; introduce 24/7 static post
Residual Risk6 — Medium (after controls)
Risk OwnerSite Security Manager (named individual)
Review Date90 days from sign-off

Section 4 — Residual Risk and Acceptance

No risk can be completely eliminated. After all recommended controls are applied, a residual risk remains. The client must formally accept the residual risk — acknowledging that it exists and that the agreed controls represent a proportionate response. Undocumented residual risk acceptance is a significant legal exposure.

Key Points
  • The 9-step SafeHaven ESRA methodology provides a documented, defensible process
  • International frameworks (ISO 31000, ASIS, UNDSS) underpin SafeHaven's approach
  • The risk register is the primary output — one entry per risk, with owner and review date
  • Residual risk must be formally accepted by the client in writing
  • Methodology consistency enables comparison across assessments and clients
Field Note · Professor Sele

"I have been in court as an expert witness on two occasions where a client's security failure led to legal proceedings. Both times the question asked was: 'Was a risk assessment conducted, and did it follow a recognised methodology?' The first case: no documented methodology. The assessor testified from memory. The second case: full ISO 31000 aligned process, documented at every step. The first case cost the client significantly. The second was resolved in their favour. Methodology is not bureaucracy — it is legal protection."

Knowledge Check

The residual risk is: