09 Sep 2026

It sounds simple doesn't it - Red = bad. Amber = concerning. Green = good.

So why do organisations still struggle to agree what colour something should be? The simple answer is that risk doesn't come with a colour attached to it, we assign the colour and that means the quality of the RAG rating depends heavily on the quality of the thinking behind it.

I've seen organisations spend considerable time debating whether something is “amber or green” when the more important question should have been, What happens if we get this wrong? Which is a very different conversation.

RAG isn't the problem, how we use it could be.

RAG is a useful way of communicating complex information quickly but the problem comes when the colour becomes the conclusion rather than the starting point for a conversation.

Take a fairly familiar compliance example: An organisation has a number of outstanding fire / health and safety actions, so someone reports them as amber but what does amber actually mean?

Are there five minor housekeeping actions?

Is there a significant issue affecting an escape route?

Are the actions overdue by two weeks or two years?

Are there vulnerable people in the building?

Are interim controls in place?

Has somebody independently checked whether those controls are actually working?

Those circumstances could all produce an “amber” on a dashboard but they clearly don't represent the same level of risk, so the colour on its own tells us very little.

So how do you decide?

I don't think there is a perfect formula because risk assessment will always involve professional judgement but I do think we can make that judgement considerably better.

When I'm considering the significance of a risk, I tend to work through a number of questions.

What is the potential impact?

If this fails, what could actually happen?

Is it inconvenience?

Operational disruption?

Financial loss?

Regulatory intervention?

Serious injury?

Potential loss of life?

The consequence matters but so does everything around it.

How many people could be affected?

One person is different from 100.

Employees are different from members of the public.

And the potential impact may be very different again where people may need assistance to evacuate or otherwise respond to an emergency.

How long would recovery take? This is one that I think organisations sometimes overlook.

Imagine two failures: One can be fixed within an hour, the other could take six months to recover from. Even if the immediate consequences look similar, the organisational risk may be very different.

What is the financial consequence?

Could it result in direct financial loss?

Business interruption?

Additional staffing?

Legal costs?

Insurance implications?

Loss of contracts?

Again, it doesn't need to be precise to be useful. We are trying to understand significance, not manufacture false accuracy.

What is the reputational consequence? Because some failures can be relatively inexpensive to fix but extremely damaging if they become public, particularly where the organisation has a responsibility for people's safety and then there is one question I think is particularly important:

How confident are we that our controls actually work?

“We have a control” isn't the same as “the risk is controlled”

This is where RAG ratings can become potentially misleading.

We have a fire risk assessment.

“We have a fire safety policy.

We carry out inspections.

We provide training.

We have an action plan.

All potentially useful but none of those statements by themselves demonstrate that the risk is adequately controlled.

A risk assessment can identify a problem, an inspection can identify a defect, an action plan can record the action but if the underlying issue remains unresolved, the existence of those processes doesn't necessarily make the risk green.

The same applies far beyond fire safety, a compliance policy that nobody follows isn't an effective control, training that people cannot demonstrate in practice isn't necessarily effective, an action marked 'complete' doesn't necessarily mean the underlying risk has disappeared and a green dashboard doesn't necessarily mean the organisation is safe, it might simply mean the organisation hasn't tested its assumptions.

Maybe we need to stop asking, what colour is it?

Instead, ask:

What would make this red?

What would make it green?

What evidence supports the rating?

What has changed since the last review?

What are we relying on to keep the risk under control?

How confident are we that those controls are actually working?

Those questions produce much better conversations and they expose something important because sometimes the correct rating isn't red or amber, it's 'We don't know' and while that might sound uncomfortable, uncertainty is itself a risk.

If you don't know whether a control is operating effectively, you shouldn't automatically assume it is.

Don't confuse the number of actions with the level of risk

This is another trap I see regularly. An organisation has 30 outstanding compliance actions and another has three. It is tempting to assume the first organisation is at greater risk but what if the 30 actions are all relatively minor? And the three actions in the second organisation relate to a significant failure with potentially serious consequences?

The number of actions isn't the risk, the underlying exposure is the risk.

This is particularly important when reporting upwards. Senior leaders don't necessarily need to know that there are 47 actions, they need to understand what those actions mean.

What risk remains?
Who could be affected?
How significant could the consequences be?
What controls are currently mitigating the risk?
How confident are we in those controls?
What needs to happen next?

Green should mean something
I think organisations should be particularly careful about the colour green. Green shouldn't simply mean:

No one has complained.
No incidents have been reported.
We have a policy.
The action is closed.
Everything appears to be okay.

Green should mean that there is a reasonable basis for believing the risk is understood, appropriately controlled and within the organisation's accepted tolerance, which requires evidence, sometimes quite a lot of evidence and sometimes the evidence will tell you that something previously considered green isn't green at all.

That's not failure, that's assurance working.

So what does Red, Amber and Green actually mean?
There isn't a universal answer but as a starting point:

Green: We understand the risk, controls are operating effectively enough, residual exposure is acceptable and we have reasonable confidence in that assessment.
Amber: There is a meaningful weakness, uncertainty or exposure that needs attention. The risk may be tolerable for now, but it isn't where we want it to be.
Red: The potential consequences are significant and the organisation doesn't have sufficient confidence that the risk is adequately controlled or within tolerance.

The precise thresholds will vary between organisations and that's okay. The important thing is that everyone understands the basis on which the organisation makes the judgement.

The real test
Next time you're looking at a RAG report, don't just ask, Why is this red? ask What evidence supports the colour? and if something is green, Why are we confident that it is green? because that second question can be surprisingly revealing.

Ultimately, RAG isn't about making risk look simple, it is about making risk understandable and there is a big difference.

A good RAG system doesn't remove judgement, it makes the judgement more consistent, more transparent and more useful to the people who have to make decisions about risk.

**The colour is only the headline. - The reasoning behind it is the real assurance.**

https://www.bcassure.co.uk/