A utility IRM lead explains the common scoring model used on qualitative risk assessments. What architecture is typically applied?
Select an answer to reveal the explanation.
Short Explanation
Most civic risk scorecards are still “how likely” times “how bad.” Likelihood and impact (significance) are the classic pair—not entity counts or audit sample sizes pretending to be the whole model.
Full Explanation
Qualitative IRM assessments commonly score risks using likelihood and impact (or significance) factors that combine into an overall rating. Proxy metrics such as entity counts, citation counts, or sample sizes may inform analysis but are not a substitute for that likelihood-and-impact scoring architecture.