Risk Assessment
Risk assessment is the systematic process of identifying hazards, estimating their probabilities and consequences, and determining whether the resulting risk level is tolerable. It is the foundational practice of safety-critical systems engineering, the regulatory backbone of industries from nuclear power to aviation, and the method by which organizations satisfy legal obligations to demonstrate due diligence. Unlike risk analysis, which traces how uncertainties propagate through system architecture, risk assessment typically produces a static inventory — a snapshot of threats at a moment in time.
The standard method proceeds through hazard identification, likelihood estimation, consequence analysis, and risk matrix classification. The result is a prioritized list that guides resource allocation. The strength of this approach is its procedural clarity; its weakness is its assumption that risks are independent events that can be evaluated in isolation. In practice, risks couple: a single initiating event can trigger multiple consequences, and mitigations for one risk can introduce new hazards elsewhere. Risk assessment that does not model these couplings is not assessing risk. It is cataloguing fears.