Most NGO security risk assessments we review are documents rather than decisions. They describe the environment accurately, then fail to say what the organisation will do differently. This is the ten-step methodology we use with clients across Africa, written so a country team can apply it without external support.
1. Threat identification
List what could harm your people, assets, operations and reputation — armed attack, IED, kidnap, crime, road traffic, disease, detention, cyber intrusion, natural hazard. Use event data (ACLED, INSO, UN security reporting) rather than perception, and separate threats that target you from threats you are merely near.
2. Vulnerability assessment
For each threat, ask what about your organisation makes it easier to realise: predictable movement, weak vetting, unhardened accommodation, visible branding in the wrong district, poor communications discipline.
3. Exposure
Quantify contact with the threat: staff numbers, days on the road, night movements, distance from response capability, value of assets in transit. Exposure is the variable managers can most easily change.
4. Likelihood and 5. Impact
Score both on a defined five-point scale with written descriptors, so that 'high' means the same thing in Maiduguri and Mogadishu. Impact should cover people, programme, assets, legal and reputational consequences.
6. Risk rating
Combine likelihood and impact in a matrix to produce Low, Moderate, High or Critical. The rating is not the output — it is the trigger for the mitigation decision, the authorisation level and the review frequency.
7. Mitigation
- Acceptance: relationships, transparency, community engagement — measurable, not assumed.
- Protection: hardening, journey management, communications, standoff.
- Deterrence: rarely appropriate for NGOs, and never without a written policy.
- Avoidance and transfer: programme redesign, remote management, insurance.
8. Residual risk
State what remains after mitigation and have it formally accepted at the right level — country director for Moderate, regional or HQ leadership for High, board-informed for Critical. Unaccepted residual risk is the most common audit failure we find.
9. Monitoring and 10. Review
Assign indicators to each significant risk and a named owner to each indicator. Review on a fixed cycle and on trigger events: a security incident, a political shift, a new location, a new donor requirement, or a change in who is doing the work.
A security risk assessment that has not changed a decision in twelve months is not a control. It is a document.
INGO Advisory builds and audits assessments to this methodology across Africa, including field verification, staff training and integration with duty-of-care obligations.