Video summary

Matriz de análisis de riesgo

Main summary

Key takeaways

Educational

Main ideas / concepts

  • Risk analysis matrix (Matriz de análisis de riesgo): A quantitative and qualitative tool used for risk management.
  • What it helps do: Assess possible threats in an institution’s external and internal environment, and estimate the magnitude of damage those risks may cause to different areas.

Core elements typically included

  • Operational risk categories (by classification), generally:
    • People
    • Internal processes
    • Information technologies / systems
    • External events
  • Magnitude of damage, rated in four levels:
    • Insignificant
    • Low
    • Medium
    • High
  • Probability of the threat occurring, also rated in four levels:
    • Insignificant
    • Low
    • Medium
    • High

Example implementation (Excel-based)

The video describes an example matrix implemented in Excel using six worksheets:

  1. Data & Information (operational risks related to data and information)
  2. Systems & Infrastructure (operational risks related to systems/infrastructure)
  3. People (operational risks related to people)
  4. Average analysis (first analysis mapping magnitude vs probability; done automatically from sheets 1–3)
  5. Factor analysis (second analysis like risk mapping, highlighting risks needing immediate attention; done automatically from sheets 1–4)
  6. Source (parameters used to automate the matrix)

Methodology / instructions (detailed steps)

A) How the matrix works (automation)

  • The matrix is automated, so users only modify certain inputs; analyses are computed automatically.

B) What inputs you can edit

Only these elements can be changed:

  • Classification of the risk
  • Magnitude of damage
  • Probability of the threat

C) How to select each input (definitions)

1. Classification

  • For each risk, choose the classification that matches the column description.
  • If the risk/description does not apply to your institution, leave it blank.

2. Magnitude of damage (4-level scale)

  • Insignificant: no impact or damage to the institution
  • Low: isolated damage that does not harm any institution component
  • Medium: does not dismantle a component; if not addressed in time, can dismantle the organization long-term
  • High: in the short term, can cause severe damage (e.g., dismantling the institution)

3. Probability of threat (4-level scale)

  • Insignificant: no conditions implying a risk or attack
  • Low: conditions exist, but attack is very unlikely/far-fetched
  • Medium: conditions make attack unlikely in the short term, but it may occur in the long term
  • High: risk is imminent; no internal/external conditions prevent development

D) Procedure to use the automated matrix (step-by-step)

  • Step 1: Download the matrix.
  • Step 2: Identify the risks applicable to your chosen institution using the provided classification.
    • Use:
      • Sheet 1: Data and Information
      • Sheet 2: Systems and Infrastructure
      • Sheet 3: Personnel (People)
  • Step 3: On the data sheet (Sheet 1), mark with an “X” the risk classification that matches the available description.
  • Step 4: Select the magnitude of damage for the detected risks using the established 4-level scale.
  • Step 5: Select the probability of threat for the detected risks using the established 4-level scale.
  • Step 6: Repeat the process for:
    • the systems/infrastructure sheet (Sheet 2)
    • the people sheet (Sheet 3)
  • Step 7: Review the analysis sheets to identify the risks that must be addressed immediately.
    • These correspond to:
      • Average analysis (from sheets 1–3)
      • Factor analysis / risk mapping for immediate attention (from sheets 1–4)

Speakers / sources featured

  • No specific speaker or individual source is identified in the provided subtitles (only “[Music]” appears as non-speech audio).

Original video