What is humanitarian security risk management?
Security risk management is how a humanitarian organisation decides how much risk it is prepared to accept in order to deliver assistance, and then acts on that decision.
The phrase is often used loosely. In this collection it means a specific process with a specific output, and the rest of the material on this site assumes that meaning.
The four steps
| Step | Question it answers | What it produces |
|---|---|---|
| Context analysis | What is happening around us, and who decides what happens? | A current picture of the environment, reviewed as it changes |
| Risk assessment | What could happen, how likely is it, and how bad would it be? | A ranked set of risks with the reasoning behind the ranking |
| Risk treatment | What are we going to do about each one? | Decisions: avoid, reduce, transfer, or accept and record |
| Monitoring and review | Is the treatment working, and who changes course? | Named responsibility and a review that actually happens |
The steps are sequential in a document and simultaneous in practice. A context analysis that is three months old is a description of a place that no longer exists, and a risk assessment that has never been reviewed is a record of what somebody once thought.
What it is not
It is not risk avoidance. An organisation that manages risk by staying away from the places where people need help has not managed anything; it has chosen not to deliver the programme. The question is never whether risk exists but whether the risk is justified by what the programme achieves, and who has decided that.
It is not a security function. A security manager can assess, advise and implement, but the decision to accept a given level of risk belongs to the manager who owns the programme and the resources. Organisations that place the decision with the security adviser rather than with the operational manager usually discover the problem the first time the advice is unwelcome.
It is not only about violence. The risks covered here include illness and injury, road traffic, detention, psychological harm, reputational damage, and the legal exposure of the organisation and of individual managers.
Duty of care
Separate from the operational process, and running alongside it, is a legal obligation. An employer owes a duty of care to the people it sends into a high-risk environment. The duty covers the whole relationship: selection and preparation, training, equipment, medical support, rest and rotation, insurance, communication with families, and what the organisation does after a serious incident. It survives the end of the contract in the cases where the harm does.
Duty of care and risk management are not the same thing, and an organisation can be good at one and poor at the other. Risk management asks what the organisation is prepared to accept. Duty of care asks what it owes the individual regardless of what it is prepared to accept. Where the two point in different directions, the duty of care wins, and the organisation has to change the plan.
Where to go next
- Security risk management: a basic guide for smaller NGOs, for the process end to end.
- Security to go, for the toolkit a country office works through.
- Risk thresholds in humanitarian assistance, for the question of how much risk is acceptable and who decides.
- Duty of Care: the Dennis v NRC ruling, for what happens when the obligation is tested.
- Security incident information management handbook, for recording what actually happens.
Practical guidance and research on the security of humanitarian staff, for the organisations that send them.