Skip to Main Content

Health Care Law and Policy (2020)

Legal Aspects of Risk Assessment

Mark Little advocates for a systematic approach for an organization to minimize its legal risks, in the hope of minimizing lawsuits and regulatory penalties, as well as improving the organization's responses.

He suggests six steps:

  • Use a framework
    • ISO 31000 is a framework that is simple, scalable, adaptable, and practical
  • Obtain organizational commitment
    • scope, types of risk tracked, audience for the risk reporting, and budget
  • Identify legal risks
    • sources; potential versus actual risk; and create a risk ledger
  • Analyze legal risk
    • assess risk controls and gauge their effectiveness
  • Evaluate legal risk
    • prioritize the response to the risk: avoid, increase, remove, change, or share
  • Communicate and advise