Select an appropriate risk assessment methodology for a facility's size, use and threat profile.
Security Risk Assessment Methodologies for Corporate Facilities
Apply recognised security risk assessment methodologies, from structured site surveys to scoring matrices, to produce findings that corporate facility decisions can actually be based on.
Course Overview
Two security consultants can walk the same corporate facility and produce very different risk findings, not because one is more experienced but because they are applying different, often unstated, methodologies, which makes the resulting recommendations hard to compare or defend to a board. This course sets out a small number of recognised security risk assessment methodologies, aligned to the process described in ISO 31000 and the techniques catalogued in ISO 31010, and teaches participants when to apply a qualitative scoring approach, a quantitative model, or a structured site survey checklist. Work covers scoping an assessment, gathering evidence through document review, interviews and physical inspection, scoring likelihood and consequence consistently across assessors, and writing findings as a prioritised set of recommendations rather than an unranked list of observations. Participants complete a full assessment cycle against a corporate facility scenario, from terms of reference through to a report ready for a facilities or risk committee, and leave with a methodology they can defend when a finding is challenged.
Expected Learning Outcomes
Scope a security risk assessment with clear terms of reference and assessment boundaries.
Gather assessment evidence through document review, interviews and structured site inspection.
Score likelihood and consequence consistently using a defined rating scale.
Apply a threat-vulnerability-consequence model to identify a facility's principal exposures.
Prioritise findings into recommendations a facilities or risk committee can act on.
Defend an assessment's methodology and findings when a rating or recommendation is challenged.
Who Should Attend
Corporate security managers who commission or conduct facility risk assessments.
Security consultants and surveyors assessing client sites and premises.
Facilities managers who need to interpret and act on security assessment findings.
Risk management professionals extending enterprise risk methods to physical security.
Insurance and audit professionals who review security risk documentation.
Security officers moving into an assessment or risk analyst role.
Course Modules
Select any module to see its sessions and points.
01Choosing and Scoping a Risk Assessment Methodology
2 sessions · 8 points
Session 1Comparing Recognised Methodologies
- Compare qualitative, semi-quantitative and quantitative security risk assessment approaches.
- Relate a chosen methodology to the risk management process described in ISO 31000.
- Select assessment techniques from a recognised catalogue such as ISO 31010 for a given facility.
- Match methodology complexity to the facility's risk profile, avoiding over-engineering a low-risk site.
Session 2Scoping the Assessment and Terms of Reference
- Draft terms of reference that define assessment boundaries, assets and assumptions.
- Agree assessment timelines and access arrangements with facility and security stakeholders.
- Identify the assets, functions and information that fall inside and outside the assessment scope.
- Clarify how findings will be reported, scored and escalated before work begins.
02Gathering and Structuring Assessment Evidence
2 sessions · 8 points
Session 1Document Review and Stakeholder Interviews
- Review incident history, policies and prior assessments before visiting a facility.
- Structure interviews with facility staff to surface risks not visible in documentation.
- Cross-check verbal accounts of controls against physical evidence during a site visit.
- Record evidence in a consistent format that supports later scoring and reporting.
Session 2Conducting a Structured Site Survey
- Walk a facility using a structured checklist covering perimeter, access and internal controls.
- Assess lighting, sightlines and natural surveillance as part of a physical inspection.
- Test selected controls directly, such as attempting unauthorised access at a controlled point.
- Photograph and annotate findings so evidence can be reviewed without a further site visit.
03Scoring, Modelling and Analysing Risk
2 sessions · 8 points
Session 1Likelihood, Consequence and Scoring Consistency
- Define likelihood and consequence scales with descriptors that reduce assessor subjectivity.
- Score identified risks using a matrix and justify each score against recorded evidence.
- Calibrate scoring across multiple assessors to keep ratings consistent across a facility portfolio.
- Distinguish inherent risk from residual risk after existing controls are taken into account.
Session 2Applying a Threat-Vulnerability-Consequence Model
- Identify credible threat sources relevant to the facility's location, sector and profile.
- Assess vulnerability by testing existing controls against each identified threat source.
- Estimate consequence in terms of safety, operational, financial and reputational impact.
- Combine threat, vulnerability and consequence ratings into a single prioritised risk view.
04Reporting Findings and Supporting Decisions
2 sessions · 8 points
Session 1Writing Findings and Recommendations
- Structure a report so findings, evidence and recommendations are clearly separated.
- Write recommendations as specific actions with an owner and indicative timeframe.
- Rank recommendations by risk reduction achieved relative to implementation cost and effort.
- Avoid vague or generic recommendations that a facility team cannot act on directly.
Session 2Presenting to Decision-Makers and Tracking Action
- Present assessment findings to a facilities or risk committee in business, not technical, language.
- Respond to challenge on methodology, scoring or recommendation from senior stakeholders.
- Track recommendation implementation and re-assess residual risk once actions are complete.
- Schedule a reassessment cycle appropriate to the facility's risk level and rate of change.
What the participant receives
4 course modules
A structured syllabus
8 training sessions
across 5 days
32 detailed points
Applied, detailed content
Accredited attendance certificate
On completing the programme
Complete your registration
We will contact you within one business day to confirm.
Ready to start?
Reserve your seat and start building the skill.
