Sicuro Group

Assessment Methodology

How the Return on Risk Scorecard evaluates strategic initiatives

Scoring framework

The scorecard uses two complementary methodologies sharing a unified 5-level severity terminology: Low, Moderate, Elevated, High, and Extreme. Country-level risk comes from the Sicuro Live Travel Risk Map (8 weighted indicators, designed in alignment with ISO 31030:2021). Initiative-specific risk uses a 5x5 Likelihood x Impact matrix across 7 risk categories, designed in alignment with ISO 31000:2018.

Each category receives a Likelihood rating (Rare, Unlikely, Possible, Likely, Almost Certain) and an Impact rating (Negligible, Minor, Moderate, Major, Catastrophic). The Risk Score equals Likelihood multiplied by Impact, producing a score between 1 and 25. Headline exposure figures are shown on a 0–100 index: a straight linear rescale (score ÷ 25 × 100) that never changes the severity band.

Published model constants

Every constant the model uses, so any figure in a report can be reproduced by hand:

  • Probability midpoints (likelihood): Rare 5%, Unlikely 20%, Possible 40%, Likely 70%, Almost Certain 95%.
  • Impact bands (% of investment base): Negligible <1%, Minor 1–5%, Moderate 5–15%, Major 15–40%, Catastrophic 40–100%. All bands are closed; Catastrophic's ceiling is 2.5 × its floor (= 100% of the base). Expected-loss maths always use a band's dollar midpoint, (low + high) ÷ 2, never the worst case.
  • Treatment effectiveness multipliers (dollar channel, applied to expected loss): Accept ×1, Reduce ×0.4, Transfer ×0.3 tested / ×0.7 untested, Avoid ×0, Leverage ×1. Transfer earns ×0.3 only when tested: policy read against the scenario, a named claims contact, and the deductible understood against the real cost. Leverage ×1 leaves residual exposure identical to inherent; its value is reported as a separate commercial-upside benefit line, never as loss avoided.
  • Effectiveness channel: the multiplier applies to the impact side of expected loss by default, and to likelihood only for treatments whose mechanism genuinely acts there (vetting/background screening, driver training, access control). Probability × impact is commutative, so the channel never changes the expected-loss total, only which rating is shown as reduced.
  • Treatment multipliers (score channel, applied to the 1–25 exposure score): Accept ×1, Reduce ×0.5, Transfer ×0.4, Avoid ×0.15, Leverage ×1. The two channels are deliberately separate: one shapes the ordinal index, the other the dollar figures.
  • Do-nothing escalation: each untreated category score × 1.15, capped at the matrix maximum of 25. The headline risk reduction is measured against this do-nothing baseline.
  • Value at stake (cap): because independent category losses are summed, aggregate expected loss is capped at the value at stake: the midpoint of the opportunity/capital at risk plus a duty-of-care reserve of $250,000 per person exposed.

Worked example: from ratings to the headline ratio

One enabled category rated Likely × Moderate, treated with Reduce costing $50,000–$150,000, on a $1M–$5M initiative (investment base $5,000,000):

  1. Exposure score: Likely (4) × Moderate (3) = 12 → index 48 (12 ÷ 25 × 100).
  2. If we act: 12 × 0.5 (Reduce, score channel) = 6 → index 24. Do nothing: 12 × 1.15 = 13.8 → index 55.
  3. Risk reduction: (13.8 − 6) ÷ 13.8 = 57%.
  4. Impact band: Moderate = 5–15% of $5,000,000 = $250,000–$750,000; midpoint $500,000.
  5. Expected loss: 70% (Likely) × $500,000 = $350,000 inherent; × 0.4 (Reduce, dollar channel) = $140,000 residual; loss avoided $210,000. (Well under the $3,000,000 value at stake, so no cap applies.)
  6. Return on Risk: $210,000 ÷ $100,000 (treatment-cost midpoint) = 2.10:1.

These figures are computed by the same shared calculation code that produces every number in the app and its exports, so this example can never drift from the model.

How the verdict is set

The verdict combines residual risk exposure (after the chosen treatments) with the organisation's stated risk appetite. Residual exposure falls into one of five bands (Low, Moderate, Elevated, High, Extreme). A higher appetite tolerates more residual exposure before the verdict turns cautious, while High and Extreme residual exposure returns Decline for every appetite. Where treatment costs are reliable and the Return on Risk ratio is below 1.0x, the verdict is downgraded one notch (never below Defer) to reflect poor value.

  • Proceed: residual exposure sits within appetite; the risk is worth taking.
  • Proceed with Caution: acceptable, subject to implementing the identified conditions.
  • Defer: further work is required before the risk can be confidently accepted.
  • Decline: current conditions do not support accepting this risk profile.

ISO 31000:2018 & ISO 31030:2021 alignment

This tool is designed in alignment with ISO 31000:2018 (Risk Management) for initiative-specific risk assessment, and ISO 31030:2021 (Travel Risk Management) for country-level risk profiling via the Sicuro Live Travel Risk Map. The seven-step assessment process maps directly to the ISO 31000 risk management process:

  1. Context Establishment (Step 1): Initiative scope, objectives, and stakeholder context definition.
  2. Risk Identification (Steps 2-3): Country profiling and AI-powered intelligence gathering to identify risk factors.
  3. Critical Dependencies & Continuity (Step 4): Single points of failure, time-to-impact, and continuity resilience review. Designed in alignment with ISO 22301:2019 clause 8.2.2 (business impact analysis and risk assessment) and ISO/TS 22317 (guidelines for business impact analysis).
  4. Risk Analysis (Step 5): Likelihood and impact assessment across seven standardised categories.
  5. Risk Evaluation (Step 6): Exposure scoring, perception gap analysis, and treatment comparison.
  6. Risk Treatment (Steps 5-6): Treatment selection (Accept, Reduce, Transfer, Avoid, Leverage) with cost-benefit analysis.
  7. Governance, Monitoring & Review (Step 7): Sign-off workflow, assumption register, reassessment triggers, and review scheduling.

Two layers of risk treatment

This instrument and the RATL framework (Reduce, Accept, Transfer, Leverage) operate at different layers, which is why they count treatments differently.

Category layer (this instrument): Each risk category is treated individually with five options: Accept, Reduce, Transfer, Avoid, and Leverage. At this layer, avoidance is a real action, such as not deploying to a particular city in a particular window: a specific exposure can be removed while the initiative itself continues.

Decision layer (RATL): The decision itself is treated with four options: Accept, Reduce, Transfer, and Leverage. Avoid is removed at this layer, because declining to proceed is what remains when no treatment qualifies rather than an option competing with the others.

The Venezuela case illustrates the difference: six of the seven risk categories returned Avoid, yet the decision itself proceeded in a restructured shape. Avoiding individual exposures and declining the decision are different acts, so the instrument shows five treatments per category while the framework defines four for the decision.

Intelligence sources

Country risk profiling draws on the Sicuro Live Travel Risk Map (8 weighted indicators), FCDO and DFAT Smartraveller advisories, the Transparency International Corruption Perceptions Index, World Bank Open Data, the US Census Bureau International Database, the Fragile States Index, and real-time web intelligence with verified citations. All sources are cross-referenced to reduce single-source bias, and assessments explicitly identify when data gaps exist.

Limitations

The tool is a decision-enablement aid, not a substitute for professional risk advisory services. All AI-generated ratings are suggestions only and should be reviewed by qualified professionals. Results are session-only and are not stored on Sicuro Group servers.

Methodology v2.2 | Last updated: August 2026

Back to Home