Executive security / Evidence and decisions
What Is an Executive Risk Assessment?
How to scope an executive-security review, distinguish threat from exposure, evaluate evidence and commission a practical plan with owners, verification and review triggers.
On this page
The direct answer
An executive risk assessment examines how a person’s role, activities and operating environment could expose them to harm, what evidence supports the concerns, which safeguards are relevant and who must decide what to do. A useful assessment produces proportionate actions, accountable owners and a process for reviewing new information.
The purpose is to improve a decision. That decision might concern participation in a public event, support for travel, handling of a concerning incident, responsibilities across a leadership team or the adequacy of an existing protection programme. Define the decision before commissioning a broad collection of information.
A senior title alone does not establish a particular threat level. Visibility, activity, current concerns and the consequences of disruption can differ significantly between people with similar titles. The assessment should explain why each issue matters in the actual context and how confident the assessor is in the supporting information.
This article sets out DayneDillon’s practical scoping and commissioning framework. It is general planning guidance. It does not assess a named person, replace a site review or determine the response to an immediate incident. Where there is an immediate safety concern, contact local emergency services and the responsible security team.
Keep the risk concepts distinct
Clear terminology prevents a review from jumping from a general concern to an unsupported recommendation. The table below defines how the terms are used in this planning framework. It is intended to help commissioners ask better questions and understand what evidence is still missing.
| Term | Meaning in this review | Question it should answer |
|---|---|---|
| Threat | A potential source or event that could cause harm. | What could happen, and what supports that concern? |
| Exposure | The circumstances in which the person or activity may encounter the concern. | Which parts of the role or operating environment make it relevant? |
| Vulnerability | A weakness or unmet requirement that could allow harm or worsen its effects. | Which safeguard is absent, ineffective or unverified? |
| Consequence | The potential effect on people, operations or other protected interests. | What would the impact be if the event occurred? |
| Uncertainty | What remains unknown, incomplete or dependent on assumptions. | Which missing information could change the decision? |
| Residual risk | The risk remaining after the selected measures are considered. | Who accepts what remains, and under what conditions? |
NIST SP 800-30 Revision 1 provides a published risk-assessment foundation involving threats, vulnerabilities, likelihood, impact and uncertainty. Its scope is information security. This article applies general assessment discipline to executive-security planning; it does not represent the NIST document as an executive-protection certification or standard.
Keep observations and interpretations separate. “The event has no named security contact in the material supplied” is an observable information gap. “The event is unsafe” is a much broader judgment that requires additional context. An assessment should show the reasoning between those two kinds of statement.
Identify why the assessment is needed now
A review is especially useful when circumstances change or an important decision lacks an evidence base. Examples include a new public-facing role, travel in an unfamiliar operating environment, a sensitive workplace event, a change in public visibility or uncertainty about who owns the existing security arrangements.
A concerning incident or pattern requires prompt qualified consideration. A routine questionnaire cannot assess intent, capability or the significance of reported behaviour. Preserve factual information through the organisation’s appropriate reporting process and involve the people authorised and qualified to assess it.
For routine planning, write the trigger in one sentence: “We need to decide what support is required for this category of activity,” or “We need to establish whether the current programme’s responsibilities and controls are understood.” This keeps the work directed towards an outcome the organisation can act on.
Record what has changed since any previous review. An older report may contain useful background, but its conclusions depend on the conditions and information considered at the time. Copying the previous rating without reviewing those assumptions can conceal the very reason a new assessment was commissioned.
Define the boundaries before collecting information
A written scope should identify the activities, environments, people in scope, decision owners and expected deliverables. It should also identify exclusions. A review of event participation does not automatically include a household review, a digital investigation or a detailed travel programme.
Agree authority and consent for any personal information that will be examined. Collect the information necessary for the defined purpose and keep sensitive operational details in approved restricted records. A public questionnaire should request broad categories rather than names, movements or specific vulnerabilities.
| Scope area | Commissioning question |
|---|---|
| Public appearances | Who coordinates with the organiser, and what responsibilities are accepted before participation? |
| Travel | Who reviews current destination information, approves the journey and coordinates local support? |
| Workplace concerns | How do HR, legal and security share relevant information and assign a case owner? |
| Public identity and information | Who manages official profiles, recovery arrangements and reports of impersonation? |
| Private-life overlap | What is included with consent, and how are personal boundaries and records protected? |
| Programme governance | Who can authorise a change, fund action and accept the remaining risk? |
Scope should be proportionate. An organisation can commission a focused review first and expand it when evidence indicates the need. The important point is to label the limits clearly so that a narrow review is not later treated as assurance covering every activity.
Assess the quality of the information
Useful evidence can include approved policies, responsibility records, current venue or travel arrangements, documented incidents, relevant interviews and the results of appropriate exercises. Each source should be tied to the question it helps answer. More information does not automatically create a better assessment.
For significant observations, record the source, date, whether it was independently checked and any limitations. Distinguish a first-hand observation from an account received through several people. Where reports conflict, document the conflict and the action required to resolve it.
A written procedure is evidence that a procedure exists. It does not demonstrate that staff understand it, that contacts are current or that it works outside normal hours. An exercise record adds a different kind of evidence. A review should explain which type it has and which type is still required.
NIST’s guidance explicitly recognises uncertainty from incomplete knowledge, changing conditions and unrecognised dependencies. In an executive-security review, that principle supports a practical requirement: unknowns should remain visible. A commissioner should be able to see what could change the conclusion and who is responsible for obtaining that information.
Use current public travel information as one input when travel is in scope. The U.S. Department of State’s Travel Advisories publish destination-specific guidance and update dates. Their scope and intended audience must be considered. A destination advisory is not a personalised assessment of a particular itinerary or support arrangement.
A practical sequence for the review
1. Establish the decision and responsible owner
Identify who needs the assessment, what they must decide and when the decision is required. Confirm who has authority to act on urgent information discovered during the work. Where several departments are involved, assign one accountable owner for the completed decision record.
2. Describe the relevant activity and dependencies
Map the broad activity, the organisations involved and the responsibilities expected of each. Keep sensitive details in controlled working material. Identify dependencies such as an external organiser, a local provider, communications support or a particular internal role.
3. Evaluate concerns and existing safeguards
For each issue, state the supporting information, the potentially affected interests and the safeguards that are relevant. Examine whether the safeguards are documented, implemented and appropriately exercised. Avoid assuming that a contracted service covers responsibilities that have not been accepted in writing.
4. Identify options and their consequences
Options can include clarifying responsibilities, changing an activity, obtaining additional information, improving controls or commissioning specialist work. Describe the expected benefit, the operational burden, remaining uncertainty and the person who can authorise the option. A recommendation should explain the problem it addresses.
5. Record the decision and verification plan
For each action, name an owner, a completion condition and the evidence required to close it. Record any residual issue the decision-maker accepts and the conditions under which the decision must be reconsidered. The result should be usable by the people implementing the work.
Worked examples of proportionate assessment
These are constructed planning examples. They do not describe actual clients, incidents or measured outcomes.
A leadership team attending a public event
The information supplied names an event organiser but leaves the security point of contact and decision process unclear. The first useful output is a responsibility review: who coordinates with the venue, who approves changes and how urgent information is communicated. The assessor should request the relevant arrangements and identify what must be confirmed before participation.
This example does not support a conclusion that more personnel are automatically required. That question depends on the wider evidence. The immediate information gap concerns ownership and coordination, so the recommended next action should address that gap directly.
A business preparing travel in a new environment
The travel coordinator has bookings and a general destination summary, but local support and disruption responsibilities are unclear. The review should examine the currency of destination information, who can approve a change and what happens if the planned support is unavailable. The deliverable is a defined decision and communications arrangement with verified owners.
A country-level rating alone cannot settle that assessment. The business needs to understand how the planned activity, available support and relevant current information interact. The assessor should identify which assumptions remain open before a decision is made.
A concerning workplace report
A report of concerning behaviour reaches several departments, but each believes another is handling it. The priority is qualified triage and clear case ownership through an appropriate confidential process. Factual records should be preserved and relevant HR, legal and security responsibilities coordinated.
A general programme checklist cannot determine what the report means or whether an individual presents a threat. It can reveal that the reporting and decision process is not established. That process gap needs prompt attention without turning unverified information into allegations or indiscriminate monitoring.
Commission outputs that support action
A report is valuable when it explains what needs to happen and why. Ask for deliverables that can be reviewed by both the accountable executive and the operational owners. The level of detail should match their decisions and their authorised access to sensitive information.
| Deliverable | What it should contain |
|---|---|
| Decision summary | Purpose, scope, principal findings, required decisions and major uncertainties. |
| Evidence register | The source and date of significant information, verification status and limitations. |
| Issue register | The concern, affected interest, relevant safeguards and reasoning supporting each finding. |
| Action plan | A specific action, accountable owner, priority rationale and completion evidence. |
| Responsibility map | Who reports, reviews, decides, implements and communicates. |
| Verification plan | How the stated controls will be exercised or otherwise checked. |
| Review triggers | The changes or new information that require the assessment to be revisited. |
A traffic-light rating can be a useful summary when its definitions and evidence are clear. It becomes misleading when it hides the basis of the judgment. Ask the assessor to show what the rating means, which assumptions matter and how a decision would change if those assumptions prove incorrect.
The public scoping tool accompanying this article therefore produces review areas, evidence requests, owners and decision questions. Its counts describe self-reported gaps and exercise status. They do not represent a validated numerical probability of harm.
Make accountability and confidentiality explicit
Responsibility can become fragmented when an executive assistant, HR team, travel coordinator, venue, IT team and contracted provider are all involved. Each may perform useful work while a crucial decision remains unowned. The assessment should identify the handoffs between them.
Distinguish the person carrying out a task from the person accountable for the resulting decision. A coordinator may collect information, while the executive sponsor decides whether an activity proceeds. A specialist may advise on a concern, while an authorised internal owner determines the organisational response.
Agree a distribution plan for the report. A decision summary may be suitable for a wider group than detailed working material. Limit access to personal and operational information according to purpose and role. Confirm how records will be retained, corrected, transferred and disposed of under the organisation’s applicable requirements.
Where a review intersects with employment, privacy or other legal obligations, involve the appropriate advisers. Avoid collecting information about people merely because it is available. The collection should have a defined, lawful purpose and a clear relationship to the assessment being commissioned.
Verify that the controls can be used
Verification should test the claim a control makes. If a plan says there is an out-of-hours decision owner, verify that the relevant role or deputy can be reached and understands its authority. If it says an organiser will coordinate a change, review a fictional change with the organiser and record the agreed process.
Discussion exercises can reveal unclear responsibilities without collecting sensitive incident details or performing intrusive tests. Use a fictional scenario, agree the purpose and participants, and record the gaps identified. Any operational test should be separately authorised, appropriately scoped and designed by qualified people.
A simple exercise record can state the scenario, expected action, observed response, unresolved issue and owner. Recheck a corrected item rather than closing it because a new procedure has been emailed. The close-out evidence should show that the people responsible understand and can use the change.
Do not confuse an exercise with a guarantee. An exercise covers its scenario and conditions. The value is in exposing assumptions and improving readiness while keeping the limitations of the test visible.
Evaluate a proposal before commissioning it
Ask the provider to connect its method to your decision. What information does it require? Which activities are included? How will it verify significant observations? What expertise is needed for any specific concern? Which parts depend on your staff or another provider?
Look for a clear distinction between assessment, implementation and ongoing support. An assessment may identify work that falls outside the engagement. That is acceptable when the boundary is explicit and the handover describes what remains. It is less useful when a report implies assurance for activities the provider has not examined.
Ask how conflicts of interest are handled if the assessor also sells the recommended services. Request the rationale for each significant recommendation, alternatives considered and the evidence needed to justify additional expenditure. A proposal should make it possible to judge whether the work is proportionate to the actual requirement.
The fee will depend on scope, locations, information needs, specialist inputs and deliverables. This article provides no market benchmark because a broadly labelled “executive risk assessment” can describe materially different engagements. Compare the work and acceptance conditions before comparing the final price.
Keep the assessment connected to changing conditions
Set review triggers when the assessment is completed. These may include a change in role, new public exposure, a different operating environment, a concerning report, a failed exercise, a provider change or a loss of key support capacity. Assign someone to recognise those triggers.
Maintain a short change record. Describe what changed, which previous assumption it affects and whether the decision remains valid. Where the information is incomplete, record the interim decision, the owner and the next review condition. This supports continuity without requiring the organisation to repeat every part of the original assessment each time.
Also revisit recommendations that remain open. An unimplemented recommendation should retain a named owner and a recorded decision about the remaining exposure. Closing the report administratively does not close the work it identified.
Prepare a focused assessment brief
Select the activities to include and the evidence available. The scoping tool generates questions, suggested role owners, verification steps and the decisions to resolve.
Sources and methodology
Sources were consulted on 12 September 2026. NIST SP 800-30 Revision 1 is a 2012 information-security risk-assessment publication used here for general assessment concepts and treatment of uncertainty. The State Department resource supplies current destination guidance within its stated remit. Neither source endorses this tool or certifies its output.
The executive-security scoping sequence, deliverable matrix, questions and constructed scenarios are DayneDillon’s original planning framework. The tool does not claim statistical validation, predict violence or substitute for a qualified assessment of a specific concern.
