Risk Analysis: Mission Domain Intelligence Guide
The evacuation decision was made three days after the intelligence supported it. Nobody lacked information. What was missing was a threshold agreed in advance and someone empowered to act on it.
The evacuation decision was made three days after the intelligence supported it. Nobody lacked information. What was missing was a threshold agreed in advance and someone empowered to act on it.
What Risk Analysis covers as a mission domain
Risk analysis is the discipline that converts intelligence into decisions. It covers the structured assessment of threat, vulnerability and consequence for a defined entity, whether a country portfolio, a facility, a supply chain or a travelling workforce. Practitioners build indicator and warning frameworks, run structured analytic techniques to test hypotheses and assumptions, produce scenarios with named triggers, and quantify exposure where the data supports it. The output is not a description of a dangerous world; it is a defensible judgment about what could happen, how likely it is, what it would cost, and what would change the answer.
Sub-areas include political and country risk, operational and site risk, travel and duty of care, supply chain and third-party risk, and enterprise-level scenario planning. The methodological core is shared: baseline construction, indicator selection, structured techniques such as analysis of competing hypotheses and key assumptions checks, red teaming, and calibrated probability judgment with subsequent scoring. The consumers differ, but every one of them needs the same thing, which is a stated confidence level and an explicit trigger for review.
Why it matters
Organisations rarely fail because information was unavailable. They fail because warning arrived without a threshold attached, because a single unexamined assumption carried the whole assessment, or because nobody owned the decision the analysis implied. Good risk analysis makes those failures visible in advance. It also imposes proportionality, preventing the far more common error of spending heavily against vivid low-probability threats while ignoring the mundane ones that actually cause losses.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Sovereign credit spreads and parallel exchange rate divergence widening well ahead of any official acknowledgement of fiscal stress.
- Security ministry and central bank leadership changes clustering in a short period, a reliable precursor of policy discontinuity.
- Foreign missions reducing staff, changing travel advisories or suspending services, which reflects information the public does not have.
- War risk and political violence insurance premiums repricing for a country or corridor, indicating professional risk assessment has already moved.
- Fuel queues, cash withdrawal limits and import letter of credit difficulties, the practical early indicators of currency and supply stress.
- International school closures and expatriate community departures, which frequently precede formal advisory changes by weeks.
- Sharp changes in protest frequency, geographic spread or participant composition, particularly when new social groups join existing movements.
- Key supplier or logistics node concentration rising unnoticed, so that a single point of failure has quietly become load bearing.
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- ACLED — Geocoded, dated political violence and protest event data with actor coding, updated weekly and free for many uses.
- World Bank Worldwide Governance Indicators — Comparable governance, rule of law, corruption control and stability scores across two decades of country data.
- IMF Article IV reports and World Economic Outlook — Independent macroeconomic assessment, fiscal detail and staff risk commentary by country.
- Fund for Peace Fragile States Index — Annual composite fragility scoring with indicator-level breakdown for portfolio triage and trend comparison.
- EM-DAT — Historical disaster occurrence, mortality and loss records for natural hazard base rates by country.
- OECD country risk classification — Consensus export credit risk categories reflecting sovereign payment and transfer risk assessment.
- National travel advisories (FCDO, US State Department and others) — Official country and regional guidance, restrictions and consular posture, useful as a comparative signal set.
- GDELT and Transparency International CPI — Global event and tone monitoring plus perceived corruption scoring for governance and integrity baselines.
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Frame the decision — Establish who decides what, by when, and what options exist. Analysis untethered from a decision produces reports nobody uses.
- Define entity and exposure — Specify the assets, people, operations and dependencies at risk, since risk is meaningless without a named thing that can be harmed.
- Build baselines and base rates — Establish historical frequency and normal ranges before estimating anything, because base rates beat intuition on almost every question.
- Test the hypotheses — Apply structured techniques, list the key assumptions explicitly, and identify which single assumption would most damage the assessment if wrong.
- Construct scenarios with triggers — Write three to four distinguishable scenarios, each with named observable indicators that would confirm movement toward it.
- Assign calibrated likelihood — Use consistent probability language with numeric ranges, state confidence separately from likelihood, and record the judgment for later scoring.
- Monitor and score — Track the indicators continuously, review on trigger rather than on calendar, and score past judgments against outcomes to correct bias.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Practised with these disciplines
- Risk Intelligence — Structured Assessment of Threat and Consequence
- Economic Intelligence — Economic Conditions, Trade, and Market Signals
- Government Intelligence — Government Structures, Policy, and Officials
- News Intelligence — Media Reporting as an Intelligence Source
- Geospatial Intelligence — Intelligence Derived from Place
- Open Source Intelligence — Publicly Available Information, Systematically Collected
- Reference Intelligence — Authoritative Reference Data and Standards
Worked in these data points
- Event / Incident — A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.
- Location / Coordinates — A geographic point, place, or region — the basis of GEOINT analysis.
- Company / Organization — A legal entity — corporation, LLC, NGO, or business.
- Keyword / Narrative — A search term, topic, hashtag, or narrative tracked across media and platforms.
- Sanction / Watchlist Entry — An entry on a sanctions list, watchlist, or PEP database.
Adjacent mission domains
- Threat Analysis
- Conflict & Humanitarian
- Climate Security
- Corruption & Governance
- Supply Chain Security
- Energy Security
Inside the platform: where Risk Analysis lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
country-risk.php— Risk Analysis dashboarddomain.php?d=risk— Mission domain hubtheater.php?d=risk— Threat theater viewsearch.php— Company / Organization profilesanctions.php— Sanction / Watchlist Entry profilecorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
Relevant playbooks
Of the 14 incident playbooks in playbooks.php, these apply directly to Risk Analysis:
- Sanctions Screening & Escalation — a step-checked workflow with the pivots, sources and handling rules already wired in.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Threat Hunt
- Correlate Infrastructure
- Run Alert Rules
- Score Country Risk
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Frame the decision is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Build baselines and base rates turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Monitor and score feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Risk Analysis
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Risk analysis in a defence setting converts intelligence into planning decisions: force protection posture, basing and route selection, contingency triggers for evacuation or reinforcement, and the assumptions underpinning a campaign plan. The methods are the same as elsewhere but the consequence tolerance and the decision timelines differ. Products feed commander's critical information requirements, indicator and warning matrices and course of action analysis. The constraint worth stating is discipline about assumptions: military plans routinely embed assumptions that are never revisited, and the analyst's most valuable contribution is often a documented key assumptions check with named observables that would invalidate the plan.
🕵 National intelligence
For national intelligence, risk analysis is the bridge between collection and policy. It structures requirements into indicator sets, applies formal techniques such as analysis of competing hypotheses and key assumptions checks, and produces calibrated judgments with explicit confidence and sourcing. Handling and classification determine which customers can act, so a shareable version usually matters as much as the classified original. The discipline that distinguishes good work is scoring: recording judgments in a form that can be evaluated afterwards, then actually evaluating them, which most organisations claim to do and few genuinely sustain.
👮 Law enforcement
Law enforcement applies risk analysis to threat assessment for protected persons, prioritisation of investigations, public order planning and organised crime harm scoring. Structured methods matter because resource allocation decisions are challenged, so the reasoning must be documented and defensible. Evidential standards apply where a risk assessment informs a protective order or a charging decision. Analysts should be explicit about base rates, since low-frequency high-consequence events generate both over-prediction and complacency, and about the difference between an individual assessment and a population-level statistical claim.
🔍 Private investigation and corporate security
Corporate security and consultancies use risk analysis for travel and duty of care, site and asset protection, third-party and supply chain exposure, and enterprise scenario planning. The output must translate into decisions with owners and budgets, otherwise it becomes a report that circulates and changes nothing. Private actors must ensure risk assessments do not become surveillance of employees or communities, must handle personal data lawfully, and should be careful that country risk products do not encode prejudice as analysis. Duty of care obligations are legally enforceable in several jurisdictions, which raises the standard for documentation.
📰 Journalism and OSINT media
Journalists use risk methodology twice: to assess their own operational risk in hostile environments, and to interrogate the risk claims made by governments and companies. For the first, structured assessment with named triggers and pre-agreed abort criteria saves lives, and it must be done before deployment rather than improvised. For the second, the useful questions are what the assessment assumed, who owned the decision, what threshold was set and whether it was acted on. Reporting on risk failures should distinguish an analytic failure from a decision failure, which are different stories with different accountability.
🌍 NGO, humanitarian and human rights
Humanitarian and human rights organisations carry acute duty of care obligations to staff and to the people they serve, and risk analysis underpins acceptance, protection and deterrence strategies, access negotiation and programme criticality decisions. Practice should be participatory, including national staff whose risk profile is usually highest and whose voice is frequently absent from the assessment. Do-no-harm requires assessing risk transferred to communities and partners, not only to the organisation. Documentation matters for accountability after an incident, and pre-agreed thresholds with named decision owners are what turn analysis into timely evacuation or suspension.
🎓 University and research
Research contributions centre on forecasting accuracy, structured analytic technique evaluation, calibration and the psychology of judgment. The methodological standards that matter are pre-registration of forecasting questions with resolution criteria, proper scoring rules, and honest reporting of base rates. Ethics approval applies to work with practitioners and to any fieldwork in insecure environments. Publish question sets, resolution criteria and scoring code, and be careful about the distinction between accuracy and calibration, since a forecaster can be frequently right and badly calibrated, which is the failure mode that damages decision making most.
Playbook: working Risk Analysis end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Define the decision and the decision owner
Establish what decision the analysis serves, who owns it, when it must be made and what options exist. Risk work that is not tied to a decision produces documents rather than outcomes, and the most common failure in the discipline is an accurate assessment nobody was empowered to act on. Record the decision, the owner and the deadline at the top of the tasking. A good output is a decision statement agreed by the person who will make it. Stop when the owner recognises their own choice in the statement.
Phase 2 — Fix the entity and the exposure
Define precisely what is at risk: a facility, a workforce, a supply chain, a country portfolio, a specific traveller cohort. Enumerate the assets, people, dependencies and obligations, including legal duties of care. Vague scope produces vague findings, and most disputes about a risk assessment turn out to be disputes about what it covered. A good output is an exposure inventory with the boundary explicitly stated. Stop when everything inside the boundary is enumerated and everything outside is named as excluded.
Phase 3 — Build the baseline with base rates
Establish what normally happens: historical incident frequency, seasonality, comparable entities and the base rate for the event class. Analysts consistently over-weight recent vivid events and under-weight base rates, which produces both false alarms and complacency. Where base rates are unavailable, say so rather than substituting intuition. A good output is a baseline with quantified frequency where possible and an explicit statement where it is not. Stop when the assessment can express current conditions relative to normal.
Phase 4 — Decompose threat, vulnerability and consequence
Assess the three components separately rather than collapsing them into a single score. Threat covers actor intent and capability, vulnerability covers the exposure and controls of the specific entity, and consequence covers what happens if it occurs. Keeping them separate shows where mitigation is possible, since you can rarely change the threat but frequently change vulnerability. A good output is a decomposed assessment showing which component drives the score. Stop when the reader can see what to fix rather than only how bad it is.
Phase 5 — Apply structured analytic techniques
Use the technique that fits the failure mode you are guarding against: analysis of competing hypotheses where a favoured explanation may be crowding out alternatives, key assumptions checks where a plan rests on unexamined premises, red teaming where organisational consensus is strong, and premortems where commitment is already made. Document the technique used and what it changed. A good output is a technique record showing which judgments moved as a result. Stop when the technique has actually altered or explicitly survived a judgment.
Phase 6 — Build scenarios that differ in action
Construct a small set of internally consistent scenarios, each with a distinct trajectory and a set of early indicators. Avoid the best, worst and middle structure, which invites selection of the middle. The test of a scenario set is whether the organisation would do something different in each, not whether they differ in severity. A good output is a scenario set with distinguishing indicators and an implication per scenario. Stop when each scenario implies a different preparatory action.
Phase 7 — Select indicators and set thresholds
Choose a small number of observable indicators with numeric or clearly binary thresholds, a named data source, an update cadence and an owner. Fewer, better indicators beat comprehensive matrices nobody maintains. Each indicator should be tied to the scenario it discriminates and to the action it triggers. A good output is an indicator and warning matrix with thresholds and actions. Stop when every indicator has an owner and would change a decision if it fired.
Phase 8 — Express calibrated judgments
State judgments with consistent probability language, an explicit confidence level based on the quality and diversity of sourcing, and the assumptions that would break them. Use the same vocabulary across products so likely means the same thing every time. Record the judgment in a form that can be scored later: a specific claim, a timeframe and a resolution criterion. A good output is a judgment that can be marked right or wrong after the fact. Stop when a colleague could resolve the judgment without asking what you meant.
Phase 9 — Convert to decisions with owners
Translate the assessment into specific recommendations with an owner, a cost, a deadline and a defined trigger. Pre-agree the thresholds for irreversible decisions such as evacuation or suspension, because those decisions are made too late almost every time they are left to the moment. Record acceptance, mitigation or transfer explicitly, including who accepted residual risk. A good output is a decision log rather than a report. Stop when every recommendation has a name against it.
Phase 10 — Score, review and rebaseline
After outcomes are known, score judgments against their resolution criteria, review whether indicators fired before or after the event, and record whether decisions were taken at the threshold or late. Distinguish analytic failure from decision failure, since they require different remedies. Feed the results into calibration training and indicator retirement. A good output is a scored record with changes made to the next cycle. Stop when the organisation can show its calibration improving rather than asserting it.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| ACLED conflict event data | Registration | Geolocated political violence and protest events with actor, event type and fatality coding, updated weekly with source notes. | The core base-rate source for violence frequency and trend at sub-national resolution. |
| World Bank Worldwide Governance Indicators | Open | Composite indicators on voice, stability, government effectiveness, regulatory quality, rule of law and corruption control. | Provides comparable governance baselines for country risk work with component sourcing visible rather than hidden inside a score. |
| IMF Article IV reports and World Economic Outlook | Open | Country economic assessments, fiscal and external position analysis, and forecast databases with methodological annexes. | Establishes macroeconomic stress indicators that frequently precede political instability and operational disruption by several quarters. |
| Fragile States Index | Open | Annual composite index of state fragility with twelve indicator components and country profiles. | Fast comparative screen and component-level view for portfolio prioritisation, not a conclusion in itself. |
| EM-DAT international disaster database | Registration | Event-level disaster records with deaths, affected populations and damage estimates back to 1900. | Natural hazard base rates for site and continuity risk assessment with known reporting caveats. |
| OECD country risk classification | Open | Consensus country risk classifications used for export credit, updated periodically with published methodology. | An externally validated benchmark for sovereign and transfer risk in portfolio assessments. |
| National travel advisory services | Open | Government advisories on travel risk by country and region with security, health and entry information. | Establishes the official risk position, which frequently carries insurance and duty of care consequences. |
| US Department of State travel advisories | Open | Country-level travel advisory levels with detailed regional caveats, consular information and periodic reissue after significant events. | Second official reference point, useful where advisories diverge and that divergence is itself informative. |
| GDELT Project | Open | Large-scale multilingual news monitoring with event coding, tone measurement and thematic extraction. | High-frequency signal for emerging instability in the weeks before structured event datasets and official reporting catch up. |
| Transparency International Corruption Perceptions Index | Open | Annual perception-based ranking of public sector corruption with the composition of contributing sources documented for each country. | Screens counterparty and operating environment integrity risk, used as a comparative filter with its perception caveats stated. |
| UN OCHA humanitarian data and situation reporting | Open | Humanitarian needs, access constraints, displacement figures and response coverage data published across active crisis contexts. | Provides the access and operating constraint picture essential to programme criticality and duty of care decisions. |
| Uppsala Conflict Data Program | Open | Long-run organised violence dataset with event and conflict-level coding and rigorous source documentation. | Long-horizon base rates and conflict trajectory analysis that complements higher-frequency event data with rigorous historical coding. |
| Structured analytic technique reference material | Open | Published guidance on analysis of competing hypotheses, key assumptions checks, red teaming and calibration practice. | Method reference that keeps technique application consistent, auditable and comparable across analysts and across reporting cycles. |
| Forecasting research and calibration literature | Open | Peer-reviewed research on judgmental forecasting accuracy, scoring rules, calibration training and expert performance. | Grounds the scoring and calibration practice that separates measurable capability from asserted expertise. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Risk Analysis. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- Analysis of competing hypotheses matrices — Forces evidence to be tested against alternatives rather than the favoured explanation. Effective, though it degrades into box filling without honest evidence weighting.
- Structured indicator and warning matrices — Links observables to scenarios and actions with thresholds. Only works when maintained, and unmaintained matrices are worse than none.
- Brier or log scoring spreadsheets — Scores probabilistic judgments over time to measure calibration. Simple to build, and organisationally uncomfortable, which is why it is rare.
- QGIS — Maps incidents, assets, routes and access constraints for site and travel risk. Spatial context only, with no analytic judgment supplied.
- Python with pandas — Builds base rates, trend analysis and indicator monitoring from event datasets. Data coding differences between sources remain the analyst's responsibility.
- Scenario planning templates — Disciplines scenario construction toward outcomes that differ in required action. Requires active facilitation, or scenarios quietly collapse into a severity gradient.
- Risk registers with named owners and triggers — Converts assessment into accountable action. Useful only when reviewed on a cadence rather than completed once for audit.
- Journey management and travel tracking systems — Supports duty of care with location awareness and check-in protocols. Must be proportionate, since employee tracking carries its own legal and ethical limits.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Score Country Risk — Recomputes country risk from the weighted inputs and snapshots the result so movement over time is measurable.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- The failure is usually the decision, not the analysis. Most post-incident reviews find the information was available and no threshold, owner or pre-agreed action existed, so design those first and refine the estimate second.
- Keep threat, vulnerability and consequence separate. Collapsing them into one score hides the only component you can usually change, and it makes mitigation invisible to the person paying for it.
- Base rates beat vividness. A recent dramatic incident distorts assessment far more than its statistical weight justifies, so state the historical frequency explicitly even when it is inconveniently low.
- Write judgments so they can be scored: a specific claim, a timeframe and a resolution criterion. If a judgment cannot be marked right or wrong afterwards, it cannot improve and neither can the analyst.
- Scenario sets must differ in what the organisation would do. A set that differs only in severity invites the reader to choose the middle and prepare for nothing in particular.
- Fewer indicators, better maintained, beat comprehensive matrices. An unmaintained warning matrix creates false assurance, which is worse than acknowledged uncertainty.
- Distinguish analytic failure from decision failure in every review. They have different remedies, and conflating them lets decision makers hide behind the analysts or the reverse.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Risk Analysis is producing anything, and they are worth baselining before you change process or tooling.
- Calibration score across published probabilistic judgments, tracked over successive cycles rather than asserted as professional expertise.
- Proportion of judgments written with a resolution criterion that allowed them to be scored after the fact.
- Share of triggered thresholds where the pre-agreed action was actually taken by its owner within the intended window.
- Median time between an indicator firing and the corresponding decision being made by the named owner.
- Proportion of assessments where a structured analytic technique demonstrably changed a judgment or explicitly stress-tested and confirmed it.
- Indicator utility: the share of maintained indicators that fired usefully at least once per cycle, with the rest retired.
- Post-incident reviews that correctly separate analytic failure from decision failure and assign the appropriate remedy to each.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Risk matrices with ordinal colours hide their arithmetic and routinely produce rankings that reverse under a different but equally arbitrary scale.
- Anchoring on the last incident distorts the whole portfolio, because vivid recent events crowd out higher-frequency mundane losses.
- Confidence and likelihood are different quantities, and collapsing them into one number destroys the information a decision maker needs.
- Unfalsifiable assessments are worthless. If no observable outcome could show the judgment was wrong, it was not a judgment.
- Analysts drift toward the assessment their client wants, and this happens gradually and without anyone intending it.
- Aggregate country scores conceal enormous subnational variation, and most operational risk is local rather than national.
Legal and ethical considerations
Risk products drive decisions about people, including evacuation, deployment and denial of travel, which engages duty of care obligations that are legally enforceable in many jurisdictions. Document your methodology and evidence base so decisions can be defended later. Assessments naming countries, companies or individuals as high risk carry commercial and reputational consequence and can be discoverable in litigation. Keep source sensitivity, classification handling and client confidentiality separated cleanly, and never let commercial pressure shape a stated likelihood.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Risk Analysis, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 7 intelligence disciplines, 5 data points, 6 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
Why do organisations act late even with good intelligence?
Because deciding is harder than knowing. Irreversible decisions such as evacuation, suspension or withdrawal carry visible costs and invisible benefits, so there is always a reason to wait for one more data point. Ambiguity provides cover, ownership is often unclear, and the person who acts early and turns out to be wrong is punished more than the person who acts late and is also wrong. The remedy is structural rather than analytic: pre-agreed thresholds with numeric triggers, a named decision owner with delegated authority, and explicit acceptance that some triggers will fire on events that do not materialise.
Should risk be expressed as a number or a narrative?
Both, and they serve different purposes. Numbers force precision, enable scoring and make comparison across a portfolio possible, but they carry false authority when the underlying data cannot support them. Narrative conveys mechanism and context but resists accountability. The practical answer is a calibrated probability with a stated confidence level, accompanied by the reasoning, the key assumptions and what would change the judgment. Use consistent probability language across all products so that likely means the same thing every time, and never publish a number without the assumptions that generated it.
How many indicators should a warning framework have?
Far fewer than most organisations build. A framework with a hundred indicators is not maintained, and an unmaintained framework provides false assurance that is worse than none. Five to fifteen well-chosen indicators, each with a numeric threshold, a named data source, a defined update cadence, an owner and an attached action, will outperform a comprehensive matrix every time. Choose indicators that discriminate between your scenarios rather than ones that merely describe deterioration, and retire any indicator that has not fired usefully across a full cycle.
What is the difference between accuracy and calibration?
Accuracy is how often you are right; calibration is whether your confidence matches your accuracy. A forecaster who says ninety percent and is right seventy percent of the time is overconfident even if seventy percent sounds respectable, and that overconfidence causes worse decisions than lower accuracy honestly expressed. Calibration is measurable using proper scoring rules over a series of resolved judgments, and it improves with feedback and practice. Organisations that want better risk analysis should invest in scoring and calibration training before they invest in more collection.
How do you avoid country risk products encoding prejudice?
By requiring mechanism and evidence for every judgment. Composite indices and inherited assumptions can encode stereotype rather than analysis, particularly where a country's score persists long after conditions change. Test each judgment against observable base rates, prefer sub-national resolution because national scores obscure enormous internal variation, review products for language that describes people rather than conditions, and have someone with local knowledge challenge the assessment. Also check whether your risk ratings would produce different operational decisions for identical objective conditions in different regions, which is the practical test.
What belongs in a duty of care assessment?
Specifics, owners and dates. A defensible assessment identifies the population covered, the hazards and threats they will face, the controls in place and their residual gaps, the pre-departure preparation and training completed, the communications and check-in arrangements, the medical and evacuation provision with actual response times rather than contract promises, and the thresholds at which movement is suspended and who decides. In several jurisdictions this is legally enforceable, and after an incident the documentation is what is examined. National staff must be covered on the same basis, since their exposure is usually highest and their provision frequently weakest.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- ISO 31000 risk management principles and guidelines, which provide the process framework most corporate risk functions align to.
- ISO 22301 business continuity management, which governs continuity planning, exercising and recovery objectives.
- ICD 203 analytic standards, which define sourcing transparency, alternative analysis and consistent expression of uncertainty.
- ICD 206 sourcing requirements, which govern how source quality and reliability are described in analytic products.
- Structured analytic technique methodology as published by intelligence community and academic sources, which defines technique application.
- Core Humanitarian Standard and INSO or equivalent security risk management frameworks, which govern NGO duty of care practice.
- National health and safety and duty of care legislation, which creates enforceable obligations for employers sending staff into risk environments.
- Proper scoring rules such as the Brier score, which provide the accepted method for evaluating probabilistic judgment quality.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- ACLED conflict event dataset — Armed Conflict Location and Event Data Project. Geolocated political violence and protest data used for base rates
- Worldwide Governance Indicators — World Bank. Comparable governance indicators with documented component sourcing
- World Economic Outlook and Article IV reporting — International Monetary Fund. Country economic assessments and forecast databases
- Fragile States Index — Fund for Peace. Annual composite index of state fragility with component indicators
- Uppsala Conflict Data Program datasets — Uppsala University. Long-run organised violence data with rigorous source documentation
- Country risk classifications — Organisation for Economic Co-operation and Development. Consensus country risk classification used in export credit
- Corruption Perceptions Index — Transparency International. Annual perception-based ranking of public sector corruption
- Intelligence community analytic standards — US Office of the Director of National Intelligence. Standards governing analytic rigour, sourcing and uncertainty expression
- Humanitarian data and situation reporting — UN Office for the Coordination of Humanitarian Affairs. Access constraint, displacement and response data across crises
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: indicator and warning frameworks, trigger-based scenario monitoring and calibrated, scoreable judgments tied to real decisions. Explore the platform, or browse the rest of the library by following any tag above.