Security Intelligence

How NGOs Should Build a Security Risk Assessment for Operations in Africa

A ten-step methodology from threat identification to residual-risk acceptance, review triggers and monitoring.

By Mowlid Ali 06 Aug 2026 12 min Security Intelligence
Source

Originally reported by INSO. INGO ADVISORY analysis is attributable to our intelligence desk; the underlying reporting remains the property of the publisher.

Read the original publication View all 5 citations
Listen · 3 minReady to play · about 3 min

Most NGO security risk assessments we review are documents rather than decisions. They describe the environment accurately, then fail to say what the organisation will do differently. This is the ten-step methodology we use with clients across Africa, written so a country team can apply it without external support.

1. Threat identification

List what could harm your people, assets, operations and reputation — armed attack, IED, kidnap, crime, road traffic, disease, detention, cyber intrusion, natural hazard. Use event data (ACLED, INSO, UN security reporting) rather than perception, and separate threats that target you from threats you are merely near.

2. Vulnerability assessment

For each threat, ask what about your organisation makes it easier to realise: predictable movement, weak vetting, unhardened accommodation, visible branding in the wrong district, poor communications discipline.

3. Exposure

Quantify contact with the threat: staff numbers, days on the road, night movements, distance from response capability, value of assets in transit. Exposure is the variable managers can most easily change.

4. Likelihood and 5. Impact

Score both on a defined five-point scale with written descriptors, so that 'high' means the same thing in Maiduguri and Mogadishu. Impact should cover people, programme, assets, legal and reputational consequences.

6. Risk rating

Combine likelihood and impact in a matrix to produce Low, Moderate, High or Critical. The rating is not the output — it is the trigger for the mitigation decision, the authorisation level and the review frequency.

7. Mitigation

  • Acceptance: relationships, transparency, community engagement — measurable, not assumed.
  • Protection: hardening, journey management, communications, standoff.
  • Deterrence: rarely appropriate for NGOs, and never without a written policy.
  • Avoidance and transfer: programme redesign, remote management, insurance.

8. Residual risk

State what remains after mitigation and have it formally accepted at the right level — country director for Moderate, regional or HQ leadership for High, board-informed for Critical. Unaccepted residual risk is the most common audit failure we find.

9. Monitoring and 10. Review

Assign indicators to each significant risk and a named owner to each indicator. Review on a fixed cycle and on trigger events: a security incident, a political shift, a new location, a new donor requirement, or a change in who is doing the work.

A security risk assessment that has not changed a decision in twelve months is not a control. It is a document.

INGO Advisory builds and audits assessments to this methodology across Africa, including field verification, staff training and integration with duty-of-care obligations.

Africa Risk Brief

Get the weekly Africa Risk Brief

Analysis like this — on security intelligence and Africa's highest-risk operating environments — delivered every Monday. Free.

No spam. Unsubscribe anytime. We never share your email.