Library

Risk assessment for personnel security

Risk management

A structured method for assessing the risk to staff in a given location, and for converting the assessment into a written decision that someone has taken.

Download the guide (PDF, English)

The method

The guide works through five steps in a fixed order, on the argument that skipping a step produces an assessment that cannot be defended.

  1. Define the scope. Which staff, doing what, in which locations, over what period. An assessment that does not name its subject produces a general statement about a country, which is not usable.
  2. Identify the hazards. What could cause harm. Deliberate hazards such as crime armed conflict and detention, and non-deliberate ones such as road traffic, disease and structural failure. The non-deliberate hazards cause more harm across the sector and are usually assessed less carefully.
  3. Assess likelihood and severity. For each hazard, using the organisation's own scales, which have to be defined so that two offices assess the same hazard the same way.
  4. Identify existing controls. What is already in place that reduces either the likelihood or the consequence. This is the step most often skipped, and skipping it produces recommendations for measures the organisation already has.
  5. Determine the residual risk and decide. What remains after the controls, whether that is acceptable, and if not, what will be done about it, by whom and by when.

What makes an assessment usable

  • It names the decision. The output is not a level of risk but a statement of what the organisation will do, and the name of the person who decided it.
  • It separates likelihood from consequence. A hazard that is unlikely and catastrophic requires different treatment from one that is likely and minor, and a single combined score conceals the difference.
  • It records the assumptions. Every assessment rests on things believed to be true. Written down, they can be checked when the context changes; unwritten, they are discovered to be wrong only after an incident.
  • It has a review date and a trigger. Reviewed on a schedule, and immediately if a defined event occurs.
  • It is written by the people who hold the information, which means the country team, not a specialist visiting for a week.

The part that is usually wrong

Assessments most often fail in the same place: they describe the environment and stop. A document that says a road is dangerous, that armed groups operate in a district, or that the security situation is deteriorating has not assessed anything. The assessment begins when it states what the organisation will do about it, and an organisation that has no position on a hazard has accepted it without saying so.

The second common failure is scale. An assessment conducted at national level will not distinguish between two districts with very different conditions, and the people who need it are working in one of them.

Related

Practical guidance and research on the security of humanitarian staff, for the organisations that send them.