Introduction
This chapter forms part of the Risk Analysis and Review (RAR) phase within the eBook "Implementing Business Continuity Management for the Gambling Regulatory Authority (GRA): A Practical Guide to Organisational Resilience, Service Continuity, and Regulatory Excellence."
Following the identification of threats and the establishment of risk treatment measures, the next step is to assess the likelihood and potential impact of each threat.
The objective of risk analysis is to determine which threats pose the greatest risk to GRA's ability to perform its regulatory responsibilities and to prioritise resources accordingly.
For the purpose of this assessment, a five-point scale is used:
|
Score |
Impact / Likelihood Description |
|
1 |
Very Low |
|
2 |
Low |
|
3 |
Moderate |
|
4 |
High |
|
5 |
Very High |
Risk Rating = Highest Impact Score × Likelihood Score
Risk Levels are defined as:
|
Risk Rating |
Risk Level |
|
1 – 5 |
Low |
|
6 – 10 |
Moderate |
|
11 – 15 |
High |
|
16 – 25 |
Extreme |
The assessment below reflects the operational environment, regulatory responsibilities, technology dependencies, and stakeholder expectations of GRA.
Table T3: Risk Impact and Likelihood Assessment
|
Threat |
Finance |
Operations |
Legal & Regulatory |
Reputation & Image |
Social Responsibility |
People |
Assets / IT Systems / Information |
Highest Impact Score |
Likelihood |
Risk Rating |
Risk Level |
Expected Period of Disruption |
|
Flood |
2 |
4 |
2 |
3 |
2 |
3 |
3 |
4 |
2 |
8 |
Moderate |
1–5 Days |
|
Pandemic / Infectious Disease Outbreak |
3 |
5 |
4 |
4 |
5 |
5 |
2 |
5 |
4 |
20 |
Extreme |
Several Weeks to Months |
|
Severe Haze Incident |
2 |
3 |
1 |
2 |
3 |
3 |
1 |
3 |
3 |
9 |
Moderate |
Several Days |
|
Extreme Weather Event |
2 |
3 |
2 |
2 |
2 |
2 |
2 |
3 |
3 |
9 |
Moderate |
1–3 Days |
|
Fire |
4 |
5 |
3 |
4 |
3 |
4 |
5 |
5 |
2 |
10 |
Moderate |
Several Days to Weeks |
|
Terrorist Incident |
4 |
5 |
5 |
5 |
5 |
5 |
4 |
5 |
2 |
10 |
Moderate |
Several Days to Weeks |
|
Civil Disturbance |
2 |
3 |
2 |
3 |
3 |
3 |
1 |
3 |
2 |
6 |
Moderate |
1–3 Days |
|
Building Structural Failure |
4 |
4 |
2 |
3 |
2 |
3 |
3 |
4 |
2 |
8 |
Moderate |
Several Weeks |
|
Hazardous Material Incident |
3 |
4 |
3 |
3 |
4 |
4 |
2 |
4 |
2 |
8 |
Moderate |
Several Days |
|
Loss of Key Personnel |
2 |
4 |
4 |
3 |
2 |
5 |
1 |
5 |
3 |
15 |
High |
Several Weeks |
|
Travel Restrictions |
2 |
3 |
2 |
2 |
2 |
3 |
1 |
3 |
3 |
9 |
Moderate |
Several Days to Weeks |
|
Mass Casualty Incident |
3 |
5 |
4 |
4 |
5 |
5 |
2 |
5 |
2 |
10 |
Moderate |
Several Weeks |
|
Telecommunications Provider Failure |
3 |
5 |
4 |
4 |
3 |
3 |
5 |
5 |
3 |
15 |
High |
Several Hours to Days |
|
Cloud Service Provider Outage |
3 |
5 |
4 |
4 |
2 |
2 |
5 |
5 |
4 |
20 |
Extreme |
Several Hours to Days |
|
Power Supply Failure |
3 |
5 |
3 |
3 |
2 |
2 |
5 |
5 |
3 |
15 |
High |
Several Hours to Days |
|
Vendor Failure |
3 |
4 |
3 |
3 |
2 |
2 |
4 |
4 |
3 |
12 |
High |
Several Days |
|
Data Centre Outage |
4 |
5 |
4 |
4 |
2 |
2 |
5 |
5 |
3 |
15 |
High |
Several Hours to Days |
|
Cyberattack / Ransomware |
4 |
5 |
5 |
5 |
4 |
3 |
5 |
5 |
5 |
25 |
Extreme |
Several Days to Weeks |
|
Data Breach |
4 |
4 |
5 |
5 |
4 |
2 |
5 |
5 |
4 |
20 |
Extreme |
Several Days to Weeks |
|
Network Failure |
2 |
5 |
3 |
3 |
2 |
2 |
5 |
5 |
4 |
20 |
Extreme |
Several Hours |
|
Hardware Failure |
2 |
4 |
2 |
2 |
1 |
1 |
5 |
5 |
3 |
15 |
High |
Several Hours to Days |
|
Software Failure |
2 |
4 |
3 |
3 |
1 |
1 |
5 |
5 |
4 |
20 |
Extreme |
Several Hours to Days |
|
Database Corruption |
3 |
5 |
4 |
4 |
2 |
1 |
5 |
5 |
4 |
20 |
Extreme |
Several Hours to Days |
|
Insider Threat |
4 |
4 |
5 |
5 |
4 |
3 |
5 |
5 |
3 |
15 |
High |
Several Days to Weeks |
|
AI-Enabled Threats |
4 |
4 |
5 |
5 |
4 |
2 |
5 |
5 |
4 |
20 |
Extreme |
Several Days |
|
Distributed Denial of Service (DDoS) Attack |
3 |
5 |
4 |
4 |
2 |
1 |
5 |
5 |
4 |
20 |
Extreme |
Several Hours to Days |
|
Failure of Regulatory Information Systems |
4 |
5 |
5 |
5 |
4 |
2 |
5 |
5 |
4 |
20 |
Extreme |
Several Hours to Days |
Highest Risk Threats for GRA
The following threats are assessed as Extreme Risks and should receive priority management attention:
|
Threat |
Risk Rating |
Risk Level |
|
Cyberattack / Ransomware |
25 |
Extreme |
|
Pandemic / Infectious Disease Outbreak |
20 |
Extreme |
|
Cloud Service Provider Outage |
20 |
Extreme |
|
Data Breach |
20 |
Extreme |
|
Network Failure |
20 |
Extreme |
|
Software Failure |
20 |
Extreme |
|
Database Corruption |
20 |
Extreme |
|
AI-Enabled Threats |
20 |
Extreme |
|
DDoS Attack |
20 |
Extreme |
|
Failure of Regulatory Information Systems |
20 |
Extreme |
These threats have the greatest potential to disrupt GRA's critical regulatory functions and therefore require enhanced controls, continuity strategies, and recovery planning.
Key Risk Analysis Observations
Technology and Information Risks Dominate
The assessment indicates that the highest risks arise from:
- Cybersecurity incidents.
- Regulatory system outages.
- Data integrity failures.
- Cloud and telecommunications dependencies.
Regulatory Impact is Significant
Any prolonged disruption affecting:
- Licensing functions.
- Regulatory monitoring.
- Enforcement operations.
- Regulatory intelligence activities.
may result in significant regulatory and reputational consequences.
Third-Party Dependencies Increase Exposure
Reliance on:
- Telecommunications providers.
- Cloud service providers.
- Data centre operators.
- Technology vendors.
creates additional operational resilience challenges that must be managed proactively.
Workforce Resilience Remains Important
Although technology risks dominate, workforce-related threats, such as pandemics and the loss of key personnel, continue to pose significant operational challenges.
Risk Impact and Likelihood Assessment provides a structured approach for evaluating threats affecting the Gambling Regulatory Authority (GRA) and prioritising risk treatment activities. By assessing the impact of each threat across financial, operational, legal, reputational, social responsibility, people, and information asset dimensions, GRA can identify those risks that pose the greatest threat to its ability to fulfil its regulatory mandate.
The results of this assessment highlight the increasing importance of cybersecurity, technology resilience, data protection, third-party risk management, and workforce preparedness. These findings provide valuable input into the subsequent Business Continuity Management phases, particularly Business Impact Analysis, Business Continuity Strategy development, and recovery planning. Through regular review and reassessment of risks, GRA can maintain an up-to-date understanding of its threat landscape and strengthen its overall organisational resilience in alignment with ISO 22301 and regulatory best practices.
More Information About Business Continuity Management Courses
To learn more about the course and schedule, click the buttons below for the BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].


![[Full Banner] Gambling Regulatory Authority](https://no-cache.hubspot.com/cta/default/3893111/19ae41b0-2229-43d0-a2d6-347c7025bf77.png)
![Banner [BCM] [E3] [RAR] [T3] Risk Impact and Likelihood Assessment](https://no-cache.hubspot.com/cta/default/3893111/1626b4db-b5dd-4c9d-8d1d-c84aa9a691f1.png)
![[BCM] [GRA] Legal Disclaimer Banner](https://no-cache.hubspot.com/cta/default/3893111/fbd32178-678a-4274-92db-27247c32d85a.png)

![[BCM] [GRA] [E3] [RAR] [T3] Risk Impact and Likelihood Assessment](https://no-cache.hubspot.com/cta/default/3893111/e5ca5611-3aac-456e-9409-537c3d48ec6f.png)


![[Thin Banner] Gambling Regulatory Authority](https://no-cache.hubspot.com/cta/default/3893111/4f23072f-0544-42d8-b1c9-4b74082dae90.png)
![BCM] [GRA] [E3] [BIA] MBCO Corporate MBCO](https://no-cache.hubspot.com/cta/default/3893111/0928875b-21b0-4069-a7d1-cf71945665fd.png)
![BCM] [GRA] [E3] [BIA] [PS] Key Product and Services](https://no-cache.hubspot.com/cta/default/3893111/e5ef9b95-2b3a-4aef-b926-9216ad45c3df.png)
![BCM] [GRA] [E3] [RAR] [T1] List of Threats](https://no-cache.hubspot.com/cta/default/3893111/b6d1802e-aac8-4351-a34d-f9deebccc3c9.png)
![[BCM] [GRA] [E3] [RAR] [T2] Treatment and Control](https://no-cache.hubspot.com/cta/default/3893111/2425431c-533d-4f91-8091-1961d97b12dd.png)
![BCM] [GRA] [E3] [BCS] [T1] Mitigation Strategies and Justification](https://no-cache.hubspot.com/cta/default/3893111/07efb463-2472-44c1-8e9b-b2f585615754.png)
![[BCM] [GRA] [E1] [C10] Identifying Critical Business Functions](https://no-cache.hubspot.com/cta/default/3893111/a38bb175-c38a-41d4-9121-eca90cf91bb8.png)


![Register [BL-B-3]*](https://no-cache.hubspot.com/cta/default/3893111/ac6cf073-4cdd-4541-91ed-889f731d5076.png)



![FAQ [BL-B-3]](https://no-cache.hubspot.com/cta/default/3893111/b3824ba1-7aa1-4eb6-bef8-94f57121c5ae.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)





