BCM BandTree

[BCM] [BT] [E3] [RAR] [T3] Risk Impact and Likelihood Assessment

Written by Dr Goh Moh Heng | Jun 11, 2025 5:19:30 AM

 

Part 3: RAR - Risk Impact and Likelihood Assessment


Risk Impact and Likelihood Assessment

In the context of Bandtree’s role as a government-linked company entrusted with managing Brunei Darussalam’s strategic real estate and infrastructure assets, a comprehensive understanding of potential threats and their implications is crucial.

Purpose of Chapter

This chapter, Part 3: RAR – Risk Impact and Likelihood Assessment, builds upon the threat identification phase by evaluating each threat in terms of its potential consequences and the probability of occurrence.

This structured assessment enables the organisation to prioritise risks systematically and to allocate resources efficiently for mitigation and response planning.

Using a standardised scoring methodology across seven key impact areas—Finance, Operations, Legal & Regulatory, Reputation & Image, Social Responsibility, People, and Assets/IT Systems/Information—each threat is measured and analysed to determine its overall risk rating and level.

The result is a clear, data-driven foundation for informed decision-making and the strengthening of Bandtree’s business continuity and resilience posture.

This is Part 3: RAR – Risk Impact and Likelihood Assessment, based on threats and utilising the BCM Institute's BCM planning methodology. Here's a structured table template with example placeholder values:

Table 3-1: [RAR] [T3] Risk Impact and Likelihood Assessment for Bandtree

 

Risk Impact Area

Threat

Finance

Operations

Legal & Reg.

Reputation/ Image

Social Resp.

People

Assets/ IT/ Info

Flood / Flash Flood / Drought / Heat Wave / Lightning / Rain / Fog/ Haze / Wind

3

4

2

3

3

2

4

Earthquake Tremors

2

5

3

4

2

3

5

Storms (Thunder / Tropical Storm)

4

5

2

4

3

2

4

Wild / Urban Fire

5

5

4

5

4

3

5

Bomb Threat / Explosion / Terrorism

5

4

5

5

4

5

5

Power Outage

2

4

2

3

2

2

4

Infectious Disease / Pandemic / Haze

2

5

3

4

5

4

2

Labour Dispute / Strike

3

5

3

4

3

4

2

Workplace Safety / Violence / Loss of Key Personnel

3

4

4

5

3

5

3

Loss of Vendor / Supplier; Default of Debtors; Regulatory/ Legal Violation; Accidents

4

4

4

3

3

2

3

IT Failure (Hardware/ Software), Network, Telecommunications, IT Sabotage

3

5

3

4

2

2

5

Facilities & Equipment Failure (HVAC, UPS, Genset, Lift, A/C)

2

4

2

2

1

1

4

 
Table 3-2: [RAR] [T3] Risk Impact and Likelihood Assessment for Bandtree

Threat

Highest Impact (Max Score)

Likelihood (1–5)

Risk Rating (Impact × Likelihood)

Risk Level

Expected Disruption

Flood / Flash Flood / Drought / Heat Wave / Lightning / Rain / Fog/Haze / Wind

4

3

12

Medium (10–14)

2–5 days

Earthquake Tremors

5

2

10

Medium

3–7 days

Storms (Thunder / Tropical Storm / Typhoon)

5

3

15

High (15–19)

3–7 days

Wild / Urban Fire

5

2

10

Medium

1–3 days

Bomb Threat / Explosion / Terrorism

5

2

10

Medium

1–2 days

Power Outage

4

4

16

High

1–2 days

Infectious Disease / Pandemic / Haze

5

3

15

High

7–14 days

Labour Dispute / Strike

5

2

10

Medium

3–7 days

Workplace Safety / Violence / Loss of Key Personnel

5

2

10

Medium

1–3 days

Loss of Vendor / Supplier; Default of Debtors; Regulatory/Legal Violation; Accidents

4

3

12

Medium

3–7 days

IT Failure (Hardware/Software), Network, Telecommunications, IT Sabotage

5

4

20

Very High (20+)

1–3 days

Facilities & Equipment Failure (HVAC, UPS, Genset, Lift, A/C)

4

3

12

Medium

2–5 days

Risk Level Bands
  • Very Low: 1–5
  • Low: 6–9
  • Medium: 10–14
  • High: 15–19
  • Very High: ≥20
How to use this template
  1. Impact Area Ratings: Score each of the seven categories from 1 (Very Low) to 5 (Very High).
  2. Highest Impact: Select the highest score among those seven.
  3. Likelihood: Assign a 1–5 rating based on your organisation's experience/frequency
  4. Assign Risk Level based on the rating’s band.
  • Expected Disruption: Estimate downtime using organisational intelligence and context.

Summing Up ...

The Risk Impact and Likelihood Assessment provides Bandtree with an evidence-based framework to quantify the potential disruption of various threats across operational and strategic domains.

By systematically evaluating the highest-impact areas and combining them with likelihood metrics, the organisation can identify high-priority risks that warrant immediate mitigation measures and contingency planning.

This chapter concludes the analytical phase of risk assessment and directly informs subsequent actions in risk treatment and the development of continuity strategies.

 As Bandtree continues to support national infrastructure and property management objectives, this risk profile serves as a critical tool for maintaining service reliability, regulatory compliance, and public trust, even in the face of unforeseen disruptions.

 

Implementing Business Continuity Management for Bandtree: A Practical Guide
eBook 3: Starting Your BCM Implementation
MBCO P&S RAR T1 RAR T2 RAR T3 BCS T1  CBF
CBF 1: Asset and Facilities Management
DP BIAQ T1 BIAQ T2 BIAQ T3 BCS T2 BCS T3 PD

 

More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for the  BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].

 

 

Please feel free to send us a note if you have any questions.