A completed risk register should help a business decide what to protect, what to improve and who must act. RPG Excellence’s new Module 5 connects those decisions in a guided workflow, building on Roles and Responsibilities and preparing the ground for continuity planning.
A power failure rarely stays a power failure
Consider a hypothetical site outage. Power is lost during production. Equipment stops, ventilation and environmental controls may be affected, staff need a safe response, IT systems become unavailable and customer delivery commitments begin to slip. A supplier delay can make recovery slower still.
The commercial exposure is wider than downtime: lost output, recovery costs, damaged stock, contractual consequences and confidence in the next delivery. The useful question is how the disruption could develop at this location, which controls would still work and who has authority to act.
1. Link the scope before selecting the threats
Module 5 begins with linked scope. Start with the site, its activities, affected processes and critical dependencies. A threat catalogue is a starting point; it becomes a credible assessment only when the organisation explains the local exposure.
The hazard screening brings together people and security, technology and infrastructure, supply chain and transport, natural and environmental threats, and integrity and compliance. Select relevant scenarios and add site-specific threats where the catalogue does not cover the situation.

2. Describe the cause, event and consequence
An entry such as “utility outage” identifies a hazard but does not explain the risk. A better scenario describes the affected activity, credible cause, disruption event and consequences: loss of mains power disables a critical production process and its support systems, interrupts delivery and creates a need for a controlled shutdown.
The analysis records affected processes and dependencies, management-system applicability, likelihood and impact dimensions. This allows a team to consider quality, environmental, occupational health and safety, continuity and information-security concerns in the same scenario without treating them as interchangeable.
Impact dimensions shown in the interface include people, environmental effects, organisational and customer assets, reputation and legal or contractual consequences. Use N/A only where justified. Severe consequences still deserve competent review when likelihood appears low.

3. Make the consequences visible across functions
A continuity discussion can miss exposure when every department looks only at its own loss. During the hypothetical outage, Operations considers lost production; IT considers system availability; the environmental team checks containment, emissions and waste controls; customer-facing teams assess delivery promises.
Module 5 gives these concerns a common assessment record. It supports integrated discussion relevant to ISO 9001 and ISO 14001 alongside the business-continuity assessment. Selecting a standard in the interface is a relevance marker, not evidence that every requirement has been met.

4. Separate working controls from intended controls
A generator on an action list is not the same as a maintained generator with capacity, fuel, tested changeover and trained operators. The controls stage distinguishes measures already implemented from those still to implement, and records causes, contributing factors and early warning indicators.
The displayed RPG method adjusts residual likelihood using the assessed effectiveness of current controls. It does not erase the inherent consequence. Claims of strong control effectiveness need evidence such as inspection, maintenance, testing, exercises and demonstrated availability during the scenario.
Assign the risk owner from an active Company User with business-continuity access. Ownership should connect the assessment to a person able to coordinate evidence, decisions and follow-up. The previous Roles and Responsibilities module makes that accountability more meaningful.

5. Turn a score into a treatment decision
The next stage records treatment, target dates, target likelihood and impact, action references, review frequency and the rationale for tolerability. A target risk position is an intended result; it is not proof that actions are complete or effective.
The organisation sets its appetite threshold and approval authority. A 5×5 matrix is the RPG workflow shown here, not a scoring formula mandated by ISO. A value below a threshold should never substitute for legal obligations, credible severe consequences or an authorised decision.
The treatment screen also asks whether to include the scenario in the Incident Management Plan. The interface states that included scenarios flow into Module 9, and that exclusions of High and Critical scenarios should be justified. This is an important handover from assessment to response preparation.

6. Use the register to direct management attention
The risk register and interactive heat map let reviewers inspect inherent, residual and target positions, then filter the register by a selected cell. The value is the conversation behind the position: what could happen, what evidence supports the controls, what remains open and when the judgement must be reviewed.
The supplied screenshots contain demonstration entries and scores. They illustrate the interface and are not recommended ratings, verified controls or evidence of risk reduction.
For the outage example, review triggers might include changes to critical equipment, failed generator tests, a new supplier dependency, a near miss or an exercise that reveals a recovery weakness. A controlled assessment needs to change when its assumptions change.

From hazard assessment to recovery priorities
Module 5 supports the disruption-risk side of the business-continuity programme. Business impact analysis has a complementary role: understanding how disruption impacts develop over time and establishing continuity priorities and requirements. A risk score alone cannot determine recovery objectives.
ISO 22301 provides a business-continuity management-system framework. The module is presented in RPG’s interface against Clause 8.2.3; it supports structured assessment and retained decisions, while organisations remain responsible for competent application and evidence. ISO reference: https://www.iso.org/standard/75106.html
How RPG Excellence supports the control
RPG Excellence helps teams bring disruption scenarios, cross-functional impacts, existing and planned controls, Company User ownership, treatment rationale and review into a consistent workflow. For organisations managing several sites or separate departmental spreadsheets, that structure can make gaps and follow-up easier to see. Explore the Business Continuity programme or request a demonstration using one of your own critical scenarios.
Explore RPG Business Continuity →This article provides general information and does not replace a task-specific assessment, competent professional judgement or legal advice.

