THE INTEL ANALYST ACADEMY
Professional Intelligence Training
Printable Lesson
Strategic Risk Assessment For Analysts
The Intel Analyst Academy · Lesson Notes
By the end of this lesson you will be able to build a strategic risk assessment that a decision-maker can act on. It has a defined scope, a small set of scenarios, ratings you can defend, and key judgments that say what you think and how sure you are.
This matters because the usual alternative is a risk register with forty rows, a colour for each and no decision attached. It gets approved, filed, and opened again only after something goes wrong, when it is read for blame rather than information.
Strategic risk is risk to an organisation's objectives over a long horizon. So before you list a single hazard, write down four things:
Put these in a short terms-of-reference paragraph and get the customer to agree to it. "Everything that could go wrong" is a common first request, and it has no end point. You can turn it into a scope by asking which decision the assessment will inform.
This lesson is not the same as *Threat Assessment: Methodologies for Evaluating and Prioritizing Threats*. A threat assessment starts from an actor or hazard and asks how dangerous it is. A strategic risk assessment starts from what you must protect and treats threat assessments as one input among several.
A risk has three parts: a source of harm, an exposure that lets the harm land, and a consequence for something the customer cares about. Use a fixed template so vague entries cannot survive:
"Because [source or condition], and given [vulnerability or exposure], [event] could occur, causing [consequence] to [objective] within [horizon]."
"Cyber risk" is a topic. "Theft of vendor credentials, given that supplier portal accounts have no second authentication factor, could halt invoicing for several days within 12 months" is a risk statement. You can test it, rate it and hand it to someone who can fix the exposure.
Not every source is an adversary. Regulatory change, supplier failure, political instability and infrastructure decay all belong here. For broad external drivers, use *Strategic Intelligence: Expanding PESTLE Analysis for a Dynamic World*. For the observable signs that a driver is moving, use *Risk Factor Indicators for Intelligence Analysis*. For slow-building developments, see *Long-Term Threats and Opportunities*.
Check each statement for one event and one consequence. If you wrote "and" between two events, split it. Compound statements cannot be rated honestly.
Forty risk statements will not fit in a decision-maker's head. Group them into three to five scenarios. A useful set usually includes:
Each scenario gets a short narrative, the conditions that must hold for it to happen, the indicators you would see first, and the impact on the stated objectives. If two explanations fit the same indicators, test them against each other using *Analysis of Competing Hypotheses* before you commit to one.
Rate likelihood with words, not invented numbers. Use the estimative terms from your organisation's standard, or agree a scale with the customer in advance and print it in the product. Our *Estimative Language* lesson covers the wording. Whatever scale you choose, define it before you rate anything.
Rate impact in the customer's terms. "Severe" should mean something like "unable to deliver a core service for longer than the tolerance you gave us", not a feeling. The customer sets these definitions; you apply them.
Rate confidence separately. Likelihood says how probable you think the event is. Confidence says how much weight your estimate can bear. It depends on source quality, corroboration, known gaps, and how much rests on assumptions. A scenario can be unlikely with high confidence, or likely with low confidence, and the customer needs to know which.
A risk matrix is fine as a display. Do not multiply two ordinal ratings and present the product as a measurement. A score of 12 is not twelve of anything. Keep the reasoning next to the coloured square, because the square alone cannot be defended.
Also state whether you are rating inherent risk (no controls) or residual risk (with current controls). Pick one per product and say so.
This is an illustration with a fictional analyst. Priya works for a mid-sized food distributor. Leadership asks whether to keep importing through one port for the next two years.
Terms of reference. Decision: keep or diversify the route. Objective: uninterrupted delivery to retail customers. Horizon: 24 months. Tolerance, as stated by the customer: more than one week of disruption is unacceptable. Rating basis: residual risk with current controls.
Scenarios, as Priya drafts them:
Key judgment as she writes it: "We assess it is likely that labour-related delays will affect at least one shipment cycle in the next 24 months. We have moderate confidence in this judgment. It assumes the current contract negotiations continue without agreement."
Priya also notes the exposure that drives the rating. There is no pre-agreed alternative routing, so every delay lands directly on delivery. She flags this as the controllable factor and passes it to the people choosing responses, using *Mitigation Options*. She does not recommend a mitigation herself unless her terms of reference say she should.
Write three to five key judgments. Each one carries the statement, the likelihood, the confidence, and a one-sentence basis. Lead with the judgment that matters most to the decision, not the one you found first.
Then list your assumptions and mark which would change a rating if they failed. In the example above, "negotiations stay unresolved" is one. Most assessments have a handful of load-bearing assumptions, and the customer should see them.
Finally, attach review triggers. These are specific, observable events that mean the assessment needs reopening, such as a signed agreement, a published regulation, or a supplier's change of ownership. This is where *Indicators and Warnings* connects to risk work. Without triggers, your assessment goes stale and keeps its authority.
Before release, check:
For packaging the finished work, see *Strategic Intelligence Products: Bridging the Gap Between Information and Action*.
Choose a real decision, either in your organisation or one in public view, such as a city council deciding whether to rely on a single contractor for a key service. Use only lawful, open information. Spend about 90 minutes producing a one-to-two page assessment with:
Then give only the key judgment to a colleague and ask what decision they would make from it. If their answer differs from what you intended, fix the judgment before you fix anything else.
Continue your training
This lesson is part of The Intel Analyst Academy — professional intelligence analysis training built for analysts. Explore the full course library, structured learning paths, and practical tools at theintelanalystacademy.com.