A useful security risk assessment does four things: identifies what can go wrong, records why the risk matters, scores it consistently and assigns practical controls to a named owner. The template below gives South African businesses a repeatable way to assess physical security risks at offices, warehouses, industrial sites, retail properties, estates and projects.
Use it as a structured starting point, not a substitute for professional judgement. Complex, high-risk or regulated sites should involve competent security, safety, legal, privacy, engineering and insurance specialists as required.
The security risk assessment process
- Define the site and assessment scope.
- Identify critical people, assets and operations.
- Describe credible threat events.
- Record vulnerabilities and existing controls.
- Score likelihood and impact.
- Prioritise additional controls.
- Estimate residual risk after treatment.
- Assign owners, deadlines and review triggers.
The process should produce decisions, not only a list of observations.
Step 1: Define the scope
Write down the boundaries before the site walk. Include the physical address, buildings, yards, parking, perimeter, public interfaces, operating hours, headcount, shifts, high-risk activities and systems included in the review.
Also record what is outside scope. For example, a physical security assessment may identify a risk involving the camera network but exclude a full penetration test. That exclusion should become a follow-up action rather than disappearing from the report.
Step 2: Identify critical assets and operations
An asset is anything whose loss, damage, disclosure or unavailability would harm the organisation. Include:
- Employees, visitors, contractors and vulnerable people;
- Stock, tools, vehicles, fuel, metals and cash;
- Buildings, plant, utilities and production lines;
- Keys, cards, credentials and sensitive documents;
- CCTV footage, access records and business information;
- Reputation, client commitments and licence to operate.
Note when each asset is most exposed. A loading bay may be controlled during the day but vulnerable during shift change. A server room may be locked but accessed by too many generic credentials.
Step 3: Describe threat events clearly
A threat statement should explain an event, not use a vague label such as “crime.” Good examples include:
- Unauthorised person enters through the vehicle gate by following an approved vehicle;
- High-value stock is removed through collusion during evening dispatch;
- A lone employee is threatened while opening the office;
- Fuel is siphoned from parked fleet vehicles overnight;
- Camera footage is unavailable after an incident because storage failed;
- A former contractor retains an active access credential.
Use incident records, near misses, neighbourhood conditions, operational changes and credible intelligence. Do not invent dramatic scenarios that have no reasonable connection to the site.
Step 4: Record vulnerabilities and current controls
A vulnerability is a weakness that makes the event more likely or more damaging. Examples include poor lighting, broken fencing, uncontrolled keys, shared passwords, blind spots, unverified visitors, slow alarm escalation or a single point of failure.
Record existing controls before adding new ones. Controls may deter, detect, delay, respond or support recovery. Examples include fencing, lighting, locks, guards, access control, CCTV, alarms, response, procedures, training, backups and insurance.
Test whether each control works. “CCTV installed” is not enough if the relevant face occupies only a tiny part of the image or the recording is overwritten before an incident is discovered.
Step 5: Score likelihood
Use one definition set across the site. The following five-point scale is intentionally simple:
| Score | Likelihood | Working definition |
|---|---|---|
| 1 | Rare | Not expected in normal conditions; no relevant history and strong controls |
| 2 | Unlikely | Possible, but limited exposure or credible controls make occurrence uncommon |
| 3 | Possible | Could occur; relevant exposure, warning signs or occasional history exists |
| 4 | Likely | Has occurred or conditions make recurrence reasonably expected |
| 5 | Almost certain | Frequent, imminent or repeatedly observed without effective control |
Record the evidence behind the score. If two assessors disagree, discuss the evidence and assumptions instead of averaging silently.
Step 6: Score impact
Consider the most credible consequence across people, operations, finance, information, environment, law and reputation. Avoid scoring only the replacement cost of the stolen item.
| Score | Impact | Working definition |
|---|---|---|
| 1 | Insignificant | Minor disruption; handled through normal local procedure |
| 2 | Minor | Limited loss or short disruption; no serious injury or material breach |
| 3 | Moderate | Reportable management event, meaningful loss, service interruption or limited harm |
| 4 | Major | Serious injury potential, major loss, prolonged outage, legal exposure or client impact |
| 5 | Severe | Fatality potential, catastrophic loss, extended shutdown or existential legal/reputation impact |
Adapt the definitions and monetary thresholds to your organisation before scoring. The labels must mean the same thing to everyone who uses the register.
Step 7: Calculate and interpret the risk score
Inherent risk score = likelihood × impact.
This creates a score from 1 to 25. Use the bands below as a starting point:
| Score | Priority | Response |
|---|---|---|
| 1–4 | Low | Maintain controls and monitor through routine review |
| 5–9 | Moderate | Assign proportionate improvements and a review date |
| 10–16 | High | Prioritise treatment, approve ownership and track frequently |
| 17–25 | Critical | Escalate promptly; consider restricting exposure until controls are effective |
A mathematical score does not overrule judgement. A lower-frequency event with fatal consequences may require executive attention even if another theft risk has a higher product.
Copy-ready security risk register template
| ID | Asset / process | Threat event | Vulnerability | Existing controls | L | I | Score | Action | Owner / due date | Residual score |
|---|---|---|---|---|---|---|---|---|---|---|
| R-01 | Loading bay | Example: unauthorised stock removal | Example: dispatch and exit checks are not reconciled | Gate guard; camera at exit | 4 | 4 | 16 | Define your treatment | Name / date | Re-score after testing |
| R-02 | Insert asset | Describe one event | State the weakness | List tested controls | 1–5 | 1–5 | L × I | Specific control | Name / date | 1–25 |
| R-03 | Insert asset | Describe one event | State the weakness | List tested controls | 1–5 | 1–5 | L × I | Specific control | Name / date | 1–25 |
Worked example: warehouse stock loss
Asset and process: high-value goods awaiting evening dispatch.
Threat event: an unauthorised load leaves the site using valid-looking paperwork during a busy shift change.
Vulnerabilities: dispatch records and gate documents are not reconciled; guards rely on visual inspection; the camera view does not clearly capture the driver and load; supervisors receive exception reports only the next day.
Existing controls: perimeter fence, gate officer, dispatch clerk, CCTV and signed paperwork.
Initial score: likelihood 4 × impact 4 = 16, high.
Treatment: require an approved digital dispatch reference; separate preparation and release authority; train gate officers on exceptions; add a camera view designed for driver and vehicle evidence; trigger immediate supervisor verification when records do not match; review access and activity logs weekly.
Residual score: likelihood 2 × impact 4 = 8, moderate, subject to a successful control test.
The impact remains high because the potential load value has not changed. The controls reduce likelihood and improve detection; they do not make the consequence disappear.
Choose controls in layers
Avoid relying on one control. A layered design uses complementary measures:
- Deter: visible boundaries, lighting, signage and officer presence;
- Prevent or delay: locks, barriers, access rules and protected storage;
- Detect: trained people, alarms, CCTV, analytics and audits;
- Verify: multiple sources that distinguish a genuine event from noise;
- Respond: clear authority, communications and capable on-site or mobile resources;
- Recover: scene control, investigation, backups, insurance and corrective action.
Controls must suit the operating environment. A barrier that prevents fast evacuation or a camera that creates unacceptable privacy exposure can introduce another risk.
Prioritise actions when the budget is limited
Rank actions using risk reduction, urgency, cost, dependency and implementation time. Start with critical exposures and low-cost controls that close obvious gaps, but do not let a list of quick wins postpone a major control that requires planning.
For each proposed control, ask:
- Which specific risk does it reduce?
- Does it reduce likelihood, impact or both?
- How will we test that it works?
- What people, process, technology and maintenance does it require?
- Could it create a safety, privacy, operational or cyber risk?
- Who owns it and by when?
This prevents equipment shopping from replacing risk treatment.
Re-score residual risk after implementation
Residual risk is the risk that remains after additional controls are implemented and proven. Do not lower a score because equipment was ordered or a policy was approved. Test the control under realistic conditions and keep evidence.
If the residual risk is above the organisation’s tolerance, add treatment, transfer part of the risk, avoid the exposure or obtain formal acceptance from the authorised decision maker.
Review triggers
Set a routine review date and reassess sooner when:
- A serious incident, near miss or pattern occurs;
- The site, perimeter, tenant mix or operating hours change;
- New stock, equipment or cash processes are introduced;
- A control fails or produces repeated false alarms;
- Threat information or local conditions change;
- A supplier, key person or technology platform changes;
- Legal, insurer or client requirements change.
Common risk assessment mistakes
- Starting with a camera or guard count instead of assets and threats;
- Using vague risk statements that cannot be treated;
- Scoring without evidence or agreed definitions;
- Ignoring current controls or assuming they work;
- Treating every risk as high, which destroys prioritisation;
- Assigning actions to departments instead of named owners;
- Closing actions before controls are tested;
- Failing to consider safety, privacy and cyber consequences.
Frequently asked questions
What is a security risk assessment?
It is a structured process for identifying assets, credible threat events, vulnerabilities and controls, then evaluating and treating the resulting risks.
What is the difference between inherent and residual risk?
Inherent risk is the exposure before proposed additional treatment. Residual risk is what remains after the chosen controls are implemented and proven. Organisations differ on whether their inherent score considers existing controls, so document your method.
How often should a site security assessment be done?
Review it on a planned cycle—commonly at least annually for active business sites—and immediately after major incidents, control failures or material operational changes. High-risk environments may need more frequent review.
Who should participate?
Include security, facilities, operations, HSE, IT, the Information Officer, HR, finance or insurance and people who perform the work. Specialist input may be required for complex risks.
Does a high score automatically justify new technology?
No. The score justifies treatment. The best treatment may involve process, people, layout, maintenance, training, technology or a combination. Compare options against the risk and test the selected control.
Move from a risk list to a funded action plan
A strong assessment makes trade-offs visible. It connects each proposed control to evidence, a priority, an owner and a test. That is the foundation for selecting the right security service provider and designing an appropriate operating model.
Need a professional assessment? Book a site security risk assessment with Azomakhanye for a tailored risk register and treatment plan.
