Accendo Reliability

Your Reliability Engineering Professional Development Site

  • Home
  • About
    • Contributors
    • About Us
    • Colophon
    • Survey
  • Reliability.fm
  • Articles
    • CRE Preparation Notes
    • NoMTBF
    • on Leadership & Career
      • Advanced Engineering Culture
      • ASQR&R
      • Engineering Leadership
      • Managing in the 2000s
      • Product Development and Process Improvement
    • on Maintenance Reliability
      • Aasan Asset Management
      • AI & Predictive Maintenance
      • Asset Management in the Mining Industry
      • CMMS and Maintenance Management
      • CMMS and Reliability
      • Conscious Asset
      • EAM & CMMS
      • Everyday RCM
      • History of Maintenance Management
      • Life Cycle Asset Management
      • Maintenance and Reliability
      • Maintenance Management
      • Plant Maintenance
      • Process Plant Reliability Engineering
      • RCM Blitz®
      • ReliabilityXperience
      • Rob’s Reliability Project
      • The Intelligent Transformer Blog
      • The People Side of Maintenance
      • The Reliability Mindset
    • on Product Reliability
      • Accelerated Reliability
      • Achieving the Benefits of Reliability
      • Apex Ridge
      • Field Reliability Data Analysis
      • Metals Engineering and Product Reliability
      • Musings on Reliability and Maintenance Topics
      • Product Validation
      • Reliability by Design
      • Reliability Competence
      • Reliability Engineering Insights
      • Reliability in Emerging Technology
      • Reliability Knowledge
    • on Risk & Safety
      • CERM® Risk Insights
      • Equipment Risk and Reliability in Downhole Applications
      • Operational Risk Process Safety
    • on Systems Thinking
      • Communicating with FINESSE
      • The RCA
    • on Tools & Techniques
      • Big Data & Analytics
      • Experimental Design for NPD
      • Innovative Thinking in Reliability and Durability
      • Inside and Beyond HALT
      • Inside FMEA
      • Institute of Quality & Reliability
      • Integral Concepts
      • Learning from Failures
      • Progress in Field Reliability?
      • R for Engineering
      • Reliability Engineering Using Python
      • Reliability Reflections
      • Statistical Methods for Failure-Time Data
      • Testing 1 2 3
      • The Manufacturing Academy
  • eBooks
  • Resources
    • Accendo Authors
    • FMEA Resources
    • Glossary
    • Feed Forward Publications
    • Openings
    • Books
    • Webinar Sources
    • Podcasts
  • Courses
    • Your Courses
    • Live Courses
      • Introduction to Reliability Engineering & Accelerated Testings Course Landing Page
      • Advanced Accelerated Testing Course Landing Page
    • Integral Concepts Courses
      • Reliability Analysis Methods Course Landing Page
      • Applied Reliability Analysis Course Landing Page
      • Statistics, Hypothesis Testing, & Regression Modeling Course Landing Page
      • Measurement System Assessment Course Landing Page
      • SPC & Process Capability Course Landing Page
      • Design of Experiments Course Landing Page
    • The Manufacturing Academy Courses
      • An Introduction to Reliability Engineering
      • Reliability Engineering Statistics
      • An Introduction to Quality Engineering
      • Quality Engineering Statistics
      • FMEA in Practice
      • Process Capability Analysis course
      • Root Cause Analysis and the 8D Corrective Action Process course
      • Return on Investment online course
    • Industrial Metallurgist Courses
    • FMEA courses Powered by The Luminous Group
    • Foundations of RCM online course
    • Reliability Engineering for Heavy Industry
    • How to be an Online Student
    • Quondam Courses
  • Calendar
    • Call for Papers Listing
    • Upcoming Webinars
    • Webinar Calendar
  • Login
    • Member Home
  • Barringer Process Reliability Introduction Course Landing Page
  • Upcoming Live Events
You are here: Home / Articles / Criticality Map is Vital to Risk Management

by Greg Hutchins Leave a Comment

Criticality Map is Vital to Risk Management

Criticality Map is Vital to Risk Management

Guest Post by Patrick Ow (first posted on CERM ® RISK INSIGHTS – reposted here with permission)

Criticality Map, a strategic top-down analytical tool that I developed and used, is vital for risk management, assurance mapping, and regulatory compliance. It is a great simplified tool for effectively guiding management action and resource allocation and as a sanity check.

The format of the tool is shown below.

An example of a criticality map format

How to build a Criticality Map

There are seven steps to build a Criticality Map. Tailor the format and steps to your requirements and the outcomes you want to achieve.

Step 1 – Determine unit of analysis using the organisational chart

The development of a Criticality Map starts with your organisational chart. Determine the unit of analysis – say at the branch level, or three levels down.

If the organisation is large, take the analysis down to the second level.

You can have different levels of criticality map, depending on the complexity of your organisation.

Each Criticality Map must fit on one page for easy analysis. The page limit will determine the unit of analysis.

More importantly, the Criticality Map should generate the right level of strategic discussion or discussion that matters most to the organisation without getting bogged down in details.

Step 2 – Assess the criticality of key processes and functions

The criticality of the unit of analysis, say at the branch level, is based on a modified approach to business impact analysis, a concept borrowed from business continuity management.

In any organisation, related business processes and functions are generally grouped by divisions or branches, which will be used as proxies for our criticality mapping.

As part of this step, list down all key business processes or functions in each branch.

Then assess the critically level of these key business processes as a group for each branch based on the following criteria:

Critical – Must remain or be restored within TWO working days.

High – Can be restored within TWO weeks.

Medium – Can be restored within ONE month.

Low – Can be restored after ONE month.

The criticality level is also a proxy for the level of risk this branch pose to the organisation, especially if this branch cannot operate as intended. The impact of this branch can be “critical” to the organisation if it cannot function normally.

For example, the technology branch that manages all critical business servers is considered a “critical” operation that must continue operating in the event of a disruption. The risk rating for this branch can also be “critical”.

Having one consistent criteria for assessing branch level criticality across the entire organisation minimises or eliminates ‘gaming the system’ for resources.

Unit managers are known to assess risk as “critical” just to get attention and resources. But when that “critical” risk is compared with other “critical” risks in the organisation using the Criticality Map, it is not so “critical” after all.

This one-page Criticality Map can be used to immediately highlight ‘gaming’ practices. It should generate resource allocation discussions where the organisation’s limited resources are directed to critical areas rather than to the person who speaks the loudest.

It also eliminates interpretation biases of a risk matrix especially when it is not applied consistently.

Step 3 – Assess the level of regulatory compliance

The next column sets out the level of legal compliance against obligations.

List down all regulatory and legal compliance obligations that relate to the operations of the branch.

For each obligation, identify the level of compliance.

Thereafter, determine the “Overall Level of Legal Compliance with Obligations” for the branch.

This exercise can uncover compliance gaps quickly.

Step 4 – Identify linkages to existing strategic and operational risks

Determine if there are any risks or issues already documented in risk registers or issues log that relate to the operations of the branch.

One would expect that if a branch is considered “critical” from an operational perspective, there would be some risk identified and documented in either the strategic risk register or even the operational risk register.

If there is none, then it is time to investigate the reasons.

Step 5 – Assess assurance level considering the effectiveness of three lines  

The starting point for assessing the overall assurance level is the organisational chart rather than risk registers. Auditors generally link their assurance mapping exercise to the risk identified as documented in risk registers, which can be limiting.

The Criticality Map seeks to comprehensively assess the organisational-wide risk profile, right down to the branch level (unit of analysis), which is also the proxy for related key business processes.

Considering the key business processes and key existing controls in each branch, the control effectiveness at each of the three lines can be assessed.

This will lead to an assessment of the “Overall Assurance Level” for each branch in the organisation.

Step 6 – Identify audit activities related to each branch

The systematic but comprehensive linking of internal audit activities based on the approved internal audit plan and past audits conducted against the criticality rating and overall assurance level for each branch can uncover potential gaps in the organisation’s internal audit activities.

Once again, auditors generally link their work program on risk registers rather than operational areas that are considered critical for organisational survival.

Step 7 – Identify the existence of business continuity plans related to each branch

The pandemic has caught many organisations off-guard and unprepared from a business continuity and supply chain management perspective. There were no and poor business continuity planning especially for critical areas of the organisation.

The Criticality Map shows the level of business continuity preparedness or resilience of each branch in the organisation. You can also add information on when the plans are last tested.

The Criticality Map can be further enhanced with branch level performance (i.e., level of performance target achievement), the budget allocated to each branch, the number of employees, skills gap analysis, etc.

The magic occurs after populating the criticality map

Once you have populated the one-page Criticality Map, the magic occurs.

When a branch or key business processes performed by that branch is considered “critical” to the overall organisational performance, you would expect higher compliance with regulatory compliance, higher levels of risk management activities, higher levels of assurance activities across all three lines, and higher levels of business continuity activities.

On a single page, a well-developed Criticality Map will quickly point to specific hotspots for further analysis or deep dives, driving the right conversations at Board and executive meetings.

It will also provide the required guidance for management action.

Criticality Maps are strategic dashboards of key governance activities across the entire organisation. It pulls together and summarises high-level governance information for analysis, discussion, and action-taking.

These maps are vital for enabling organisations to achieve their objectives. More so when risk management and internal audit are objective-focused concepts.

Professional bio

As a Chartered Accountant with over 25 years of international risk management and corporate governance experience in the private, not-for-profit, and public sectors, Patrick helps individuals and organizations make better decisions to achieve better results as a corporate and personal trainer and coach at Practicalrisktraining.com.

His “Practical ISO22301 Business Continuity Management That Works” Udemy courseis available.

He is also the co-founder of Skillsand.org, an organisation dedicated to helping people acquire in-demand job skills and preparing them for the future of work. Our goal is to create a convenient learning experience that’s as easy as making any other purchase on Amazon.

Patrick has authored several eBooks including Strategic Risk Management Reimagined: How to Improve Performance and Strategy Execution, and How to Improve the Performance of Collaborations, Joint Ventures, and Strategic Alliances: The Shared Risk Management Handbook.

Filed Under: Articles, CERM® Risk Insights, on Risk & Safety

About Greg Hutchins

Greg Hutchins PE CERM is the evangelist of Future of Quality: Risk®. He has been involved in quality since 1985 when he set up the first quality program in North America based on Mil Q 9858 for the natural gas industry. Mil Q became ISO 9001 in 1987

He is the author of more than 30 books. ISO 31000: ERM is the best-selling and highest-rated ISO risk book on Amazon (4.8 stars). Value Added Auditing (4th edition) is the first ISO risk-based auditing book.

« The Softer Side of Success: Unlocking the Power of Soft Skills
Solving the Skilled Trades Shortage »

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

CERM® Risk Insights series Article by Greg Hutchins, Editor and noted guest authors

Join Accendo

Receive information and updates about articles and many other resources offered by Accendo Reliability by becoming a member.

It’s free and only takes a minute.

Join Today

Recent Articles

  • Gremlins today
  • The Power of Vision in Leadership and Organizational Success
  • 3 Types of MTBF Stories
  • ALT: An in Depth Description
  • Project Email Economics

© 2025 FMS Reliability · Privacy Policy · Terms of Service · Cookies Policy