Assessing risk step by step
Walk through how something works from start to finish, and ask what could go wrong at each step.
A risk and control assessment sounds complicated, but the idea is simple. Start with how the thing works from beginning to end, ideally written down step by step. Then go back to step one and ask two questions: how is this supposed to work, and what could go wrong? The answers to the second question are your risks. Think like Murphy’s law: anything that can go wrong will go wrong.
Say you’re flying from New York to California. You leave the apartment Saturday morning at 9, take a train or an Uber to the airport, go through security, board the plane, take off on time and land on time. Now look at step one alone. Your alarm might not go off. The elevator might be broken. You might trip on the way out. Each step has its own list, and you work through every one of them.
Then look at the controls, and question them too. “I always wake up with the sun at 6” is a habit, not a control, because what if you don’t? Setting an alarm is a control. But where is it set? Is the phone charging? Is the ringer on? Is it set for 6 AM and not 6 PM? Walking through every step this way, then checking that each control really works, is exactly what risk teams do for financial products, including digital assets.