Video summary
Matriz de análisis de riesgo
Main summary
Key takeaways
Main ideas / concepts
- Risk analysis matrix (Matriz de análisis de riesgo): A quantitative and qualitative tool used for risk management.
- What it helps do: Assess possible threats in an institution’s external and internal environment, and estimate the magnitude of damage those risks may cause to different areas.
Core elements typically included
- Operational risk categories (by classification), generally:
- People
- Internal processes
- Information technologies / systems
- External events
- Magnitude of damage, rated in four levels:
- Insignificant
- Low
- Medium
- High
- Probability of the threat occurring, also rated in four levels:
- Insignificant
- Low
- Medium
- High
Example implementation (Excel-based)
The video describes an example matrix implemented in Excel using six worksheets:
- Data & Information (operational risks related to data and information)
- Systems & Infrastructure (operational risks related to systems/infrastructure)
- People (operational risks related to people)
- Average analysis (first analysis mapping magnitude vs probability; done automatically from sheets 1–3)
- Factor analysis (second analysis like risk mapping, highlighting risks needing immediate attention; done automatically from sheets 1–4)
- Source (parameters used to automate the matrix)
Methodology / instructions (detailed steps)
A) How the matrix works (automation)
- The matrix is automated, so users only modify certain inputs; analyses are computed automatically.
B) What inputs you can edit
Only these elements can be changed:
- Classification of the risk
- Magnitude of damage
- Probability of the threat
C) How to select each input (definitions)
1. Classification
- For each risk, choose the classification that matches the column description.
- If the risk/description does not apply to your institution, leave it blank.
2. Magnitude of damage (4-level scale)
- Insignificant: no impact or damage to the institution
- Low: isolated damage that does not harm any institution component
- Medium: does not dismantle a component; if not addressed in time, can dismantle the organization long-term
- High: in the short term, can cause severe damage (e.g., dismantling the institution)
3. Probability of threat (4-level scale)
- Insignificant: no conditions implying a risk or attack
- Low: conditions exist, but attack is very unlikely/far-fetched
- Medium: conditions make attack unlikely in the short term, but it may occur in the long term
- High: risk is imminent; no internal/external conditions prevent development
D) Procedure to use the automated matrix (step-by-step)
- Step 1: Download the matrix.
- Step 2: Identify the risks applicable to your chosen institution using the provided classification.
- Use:
- Sheet 1: Data and Information
- Sheet 2: Systems and Infrastructure
- Sheet 3: Personnel (People)
- Use:
- Step 3: On the data sheet (Sheet 1), mark with an “X” the risk classification that matches the available description.
- Step 4: Select the magnitude of damage for the detected risks using the established 4-level scale.
- Step 5: Select the probability of threat for the detected risks using the established 4-level scale.
- Step 6: Repeat the process for:
- the systems/infrastructure sheet (Sheet 2)
- the people sheet (Sheet 3)
- Step 7: Review the analysis sheets to identify the risks that must be addressed immediately.
- These correspond to:
- Average analysis (from sheets 1–3)
- Factor analysis / risk mapping for immediate attention (from sheets 1–4)
- These correspond to:
Speakers / sources featured
- No specific speaker or individual source is identified in the provided subtitles (only “[Music]” appears as non-speech audio).