Part 3: RAR - Risk Impact and Likelihood Assessment

Risk Impact and Likelihood Assessment
In the context of Bandtree’s role as a government-linked company entrusted with managing Brunei Darussalam’s strategic real estate and infrastructure assets, a comprehensive understanding of potential threats and their implications is crucial.
Purpose of Chapter
This chapter, Part 3: RAR – Risk Impact and Likelihood Assessment, builds upon the threat identification phase by evaluating each threat in terms of its potential consequences and the probability of occurrence.
This structured assessment enables the organisation to prioritise risks systematically and to allocate resources efficiently for mitigation and response planning.
Using a standardised scoring methodology across seven key impact areas—Finance, Operations, Legal & Regulatory, Reputation & Image, Social Responsibility, People, and Assets/IT Systems/Information—each threat is measured and analysed to determine its overall risk rating and level.
The result is a clear, data-driven foundation for informed decision-making and the strengthening of Bandtree’s business continuity and resilience posture.
This is Part 3: RAR – Risk Impact and Likelihood Assessment, based on threats and utilising the BCM Institute's BCM planning methodology. Here's a structured table template with example placeholder values:
Table 3-1: [RAR] [T3] Risk Impact and Likelihood Assessment for Bandtree
|
Risk Impact Area | ||||||
Threat |
Finance |
Operations |
Legal & Reg. |
Reputation/ Image |
Social Resp. |
People |
Assets/ IT/ Info |
Flood / Flash Flood / Drought / Heat Wave / Lightning / Rain / Fog/ Haze / Wind |
3 |
4 |
2 |
3 |
3 |
2 |
4 |
Earthquake Tremors |
2 |
5 |
3 |
4 |
2 |
3 |
5 |
Storms (Thunder / Tropical Storm) |
4 |
5 |
2 |
4 |
3 |
2 |
4 |
Wild / Urban Fire |
5 |
5 |
4 |
5 |
4 |
3 |
5 |
Bomb Threat / Explosion / Terrorism |
5 |
4 |
5 |
5 |
4 |
5 |
5 |
Power Outage |
2 |
4 |
2 |
3 |
2 |
2 |
4 |
Infectious Disease / Pandemic / Haze |
2 |
5 |
3 |
4 |
5 |
4 |
2 |
Labour Dispute / Strike |
3 |
5 |
3 |
4 |
3 |
4 |
2 |
Workplace Safety / Violence / Loss of Key Personnel |
3 |
4 |
4 |
5 |
3 |
5 |
3 |
Loss of Vendor / Supplier; Default of Debtors; Regulatory/ Legal Violation; Accidents |
4 |
4 |
4 |
3 |
3 |
2 |
3 |
IT Failure (Hardware/ Software), Network, Telecommunications, IT Sabotage |
3 |
5 |
3 |
4 |
2 |
2 |
5 |
Facilities & Equipment Failure (HVAC, UPS, Genset, Lift, A/C) |
2 |
4 |
2 |
2 |
1 |
1 |
4 |
Table 3-2: [RAR] [T3] Risk Impact and Likelihood Assessment for Bandtree
Threat |
Highest Impact (Max Score) |
Likelihood (1–5) |
Risk Rating (Impact × Likelihood) |
Risk Level |
Expected Disruption |
Flood / Flash Flood / Drought / Heat Wave / Lightning / Rain / Fog/Haze / Wind |
4 |
3 |
12 |
Medium (10–14) |
2–5 days |
Earthquake Tremors |
5 |
2 |
10 |
Medium |
3–7 days |
Storms (Thunder / Tropical Storm / Typhoon) |
5 |
3 |
15 |
High (15–19) |
3–7 days |
Wild / Urban Fire |
5 |
2 |
10 |
Medium |
1–3 days |
Bomb Threat / Explosion / Terrorism |
5 |
2 |
10 |
Medium |
1–2 days |
Power Outage |
4 |
4 |
16 |
High |
1–2 days |
Infectious Disease / Pandemic / Haze |
5 |
3 |
15 |
High |
7–14 days |
Labour Dispute / Strike |
5 |
2 |
10 |
Medium |
3–7 days |
Workplace Safety / Violence / Loss of Key Personnel |
5 |
2 |
10 |
Medium |
1–3 days |
Loss of Vendor / Supplier; Default of Debtors; Regulatory/Legal Violation; Accidents |
4 |
3 |
12 |
Medium |
3–7 days |
IT Failure (Hardware/Software), Network, Telecommunications, IT Sabotage |
5 |
4 |
20 |
Very High (20+) |
1–3 days |
Facilities & Equipment Failure (HVAC, UPS, Genset, Lift, A/C) |
4 |
3 |
12 |
Medium |
2–5 days |
Risk Level Bands
How to use this template
- Impact Area Ratings: Score each of the seven categories from 1 (Very Low) to 5 (Very High).
- Highest Impact: Select the highest score among those seven.
- Likelihood: Assign a 1–5 rating based on your organisation's experience/frequency
- Assign Risk Level based on the rating’s band.
- Expected Disruption: Estimate downtime using organisational intelligence and context.
Summing Up ...
The Risk Impact and Likelihood Assessment provides Bandtree with an evidence-based framework to quantify the potential disruption of various threats across operational and strategic domains.
By systematically evaluating the highest-impact areas and combining them with likelihood metrics, the organisation can identify high-priority risks that warrant immediate mitigation measures and contingency planning.
This chapter concludes the analytical phase of risk assessment and directly informs subsequent actions in risk treatment and the development of continuity strategies.
As Bandtree continues to support national infrastructure and property management objectives, this risk profile serves as a critical tool for maintaining service reliability, regulatory compliance, and public trust, even in the face of unforeseen disruptions.
More Information About Business Continuity Management Courses
To learn more about the course and schedule, click the buttons below for the BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].