← Back to home

Risk and threat assessment

A risk assessment is only worth its cost if somebody can act on it. Almost everyone who asks us intends to go anyway. Our job is therefore not to talk you out of it but to find the version that holds, meaning this route, this timing, this local partner, this measure now and that one once an indicator moves. The decision itself stays with you.

What the work covers

Country and area assessments for a specific operation, rather than a subscription feed rewritten with your logo on it. Site security surveys, on the ground, with photographs and a fix list ordered by what actually reduces exposure. Threat assessments where a named person or group is the concern. Security program design for organizations that have grown past ad hoc measures. Audits, including of providers already engaged.

We write the assumptions down. Every assessment states what we could not verify, what would change the conclusion, and when it should be reviewed. The most common failure in this field is an assessment that sounds more certain than the place allows.

We make it work

In the large majority of cases there is a version that works. Where we do advise against it, that goes in writing with the reasoning and with what would have to be different for it to hold.

The decision belongs to the person who answers for it, and that puts two demands on the assessment. It has to be solid enough for a decision to rest on. And it has to be written so that the basis for that decision can still be reconstructed later, including when the situation afterwards went another way.

Who delivers on the ground

This capability is advisory end to end, so there is nothing to divide up. The assessment, the survey and the report are ours. Where a site visit needs local access, transport or a fixer, a local intermediary who opens doors, that is arranged locally and named in the report, including anything that access constraint kept us from seeing.

Sources are cited. Where a conclusion rests on our own observation rather than a document, we say that too, because the two carry different weight when your board reads it. Field notes, photographs and the interview record stay with the report, so a finding can be traced back to what produced it a year later.

We also say where our own interest lies. We take no commission from any provider we name. Where an assessment concludes that your existing arrangement is adequate, that is what it says, and we have written that report more than once. And where a recommendation is something we could deliver ourselves, the report marks it as such, so you can weigh it accordingly.

Standards we work to

MethodISO 31000:2018 as the framework, from establishing context through identification, analysis and evaluation to treatment. It is guidance and not certifiable, so anyone selling ISO 31000 certification is selling something that does not exist. Method selection follows IEC 31010:2019, which catalogs the toolbox, from bow tie analysis and fault trees through scenario analysis and structured what-if to layers of protection analysis and ALARP, meaning as low as reasonably practicable. That gives the assessment a structure your internal audit and your insurer already recognize.
Security risk managementCertified Security Risk Management Professional at country and regional level (INSSA).
Occupational health and safetyNEBOSH International General Certificate. It lets us produce risk assessments your own safety officer can adopt, and it keeps the safety half of a risk picture from being judged by security people alone.
Site surveySurveys happen on the ground, with photographs and a fix list ordered by what actually reduces exposure. A desktop review is named as such.
Human rights due diligenceWherever an assessment recommends security measures it touches human rights, and international buyers check for it. The UN Guiding Principles on Business and Human Rights, endorsed by the Human Rights Council in 2011, call for ongoing due diligence. That means identifying, preventing and mitigating adverse impacts and accounting for them. The Voluntary Principles give that a security-specific shape, with risk assessment as the first of their three pillars.
Stated basisEvery finding carries what it rests on and what would overturn it, and there is no unattributed "intelligence indicates". Probability follows the ICD 203 scale used by the US intelligence community, which ties each word to a fixed percentage band, so "likely" means the same thing in every report we write. Confidence in a judgment is stated separately as high, moderate or low, and never in the same sentence as the probability, because the reader could not then tell which part is uncertain.
VerificationThis register names the standards the work follows. The personal qualifications behind them go to clients in full over an encrypted channel, verifiable with the issuing bodies.

Where corners get cut

The site visit goes first, because a desktop assessment costs a fraction and reads almost the same. What it cannot see is the second gate that is always chained, the generator with no fuel contract, or a guard force that has not been paid this month. The review date goes next, so an assessment commissioned once is still being cited three years later. Then scope, where the assessment covers the employer's own staff and stops at the contractors who make up most of the people on site.

The fourth is harder to notice. An assessment bought from the company that will also sell the remedy tends to find the remedy. That is a fair question to put to any provider, including us.

Questions we get asked

How is this different from a country risk subscription?

A subscription tells you the country rating. It does not know that your site sits on the wrong side of a river with two bridges, that your staff are hired mainly from one community in a place where that matters, or that your evacuation plan assumes an airport that closes at dusk. An assessment starts from the general picture and works out what it means for your operation.

Will you tell us not to go?

It happens, but rarely, and it is not the point of the exercise. In most cases an operation in a difficult place is workable once the conditions, the preparation or the procedure change. When we do advise against it, we say so in writing with the reasoning, and we say what would have to be true for it to work.

How long does an assessment hold?

That depends on the context, not on the calendar. A site assessment in a stable country can hold for two years. A picture of a region in active escalation is out of date within weeks. So every assessment names the indicators we watch and the change that triggers a re-assessment. If you keep us on, we come back to you when one of them moves.

Can you take over our statutory risk assessment?

We can write it. What no provider can take from you is the responsibility for it. Every occupational safety regime we work under puts the duty to assess on the employer, and delegating the work does not delegate the accountability. What can be delegated is the production of the assessment, to someone competent for that particular area, with the employer still owing careful selection and supervision of whoever is appointed.

That production is our part. Not the role of your appointed safety officer, but the exposure an in-house function rarely covers, your people abroad by destination, travel profile and type of deployment. We write the assessment so that your own function can adopt and sign it. The NEBOSH International General Certificate is the competence evidence behind that. Germany, as one example of how this is framed nationally, allows the employer to appoint reliable and competent persons in writing under section 13(2) ArbSchG, and does not require a formally appointed safety specialist for the work itself.

One part gets missed almost everywhere. The assessment does not stop at your own payroll. Where people employed by different companies work together, hazards have to be communicated both ways and the measures coordinated, and you have to satisfy yourself that the contractor instructed its people.

Can you audit a provider we already use?

Yes, and it is one of the more common requests. We assess against the contract you signed and the standard the work actually needs, which are frequently not the same document.

What does the documentation do for us if something happens anyway?

No program takes risk to zero, and anyone promising that is selling something else. What can be shaped is the question asked after an incident. Did the organization recognize what was recognizable, and did it do what the accepted standard required?

That question is answered out of the paperwork that already existed. So we work along named standards, ISO 31000 and ISO 31030, and where German law applies, the ArbSchG and DGUV Vorschrift 1, and every report states what a finding rests on, what stayed unverified, and when it has to be reviewed. What comes out is a traceable line from assessment to decision to measure.

We are not a law firm and we do not give legal advice. What we supply is evidence that the work was done with care, in a form your counsel and your insurer can read.

Other capabilities

Travel risk management and duty of care

Travel risk programs built to ISO 31030, thresholds through escalation.

Learn more

Medical support and rescue planning

Medical concepts, staffing plans and the full MEDEVAC chain.

Learn more

Close protection and executive protection

Protective concepts, advance work and command, low profile by design.

Learn more

Crisis and emergency management

Crisis structures with named roles, exercised before handover.

Learn more

Training and briefings

Medical, HEAT and crisis training, plus briefings and workshops.

Learn more

Talk it through first

Every engagement starts with a confidential conversation, and it is free. Describe the operation and the concern. We will tell you whether this is the right capability, another one, or nothing at all.

enquiries@foxpedition.com