What is PESTEL Analysis?
How to assess business risk and opportunities using PESTEL analysis
Using the PESTEL Register in Adoptech
The PESTEL Register within Adoptech is designed to help you document and review the internal and external factors that could affect your organisation’s ability to achieve its objectives and the intended outcomes of its management system.
PESTEL provides a structured way to consider the environment in which your organisation operates and identify issues that may present risks or opportunities.
When completing your PESTEL, consider your organisation's objectives, management system requirements and the needs and expectations of its relevant interested parties.
You do not need to identify an issue for every possible scenario. Focus on matters that are relevant to your organisation and could have a meaningful impact on its objectives or management system.
What do the ISO standards require?
Management system standards require organisations to determine the external and internal issues that are relevant to their purpose and that could affect their ability to achieve the intended outcomes of their management system.
The specific objectives and issues will vary depending on the management system and the organisation. For example, context could affect:
• Information security under ISO 27001.
• Quality and customer satisfaction under ISO 9001.
• Environmental performance under ISO 14001.
• Artificial intelligence management and responsible AI governance under ISO 42001.
• the objectives and intended outcomes of other applicable management systems.
How to conduct the PESTEL analysis
1 - Identify Risks and Opportunities
Work through each PESTEL category and establish the associated risks/opportunities for your business identifying whether it is internal or external.
2 - Outline the Current Mitigation Factors.
For a risk this will be any mitigating factors you have in place that are relevant to the management system(s) you are implementing eg for ISO 27001, anything that could reduce the risk to information security, for ISO 9001, anything that could reduce the impact to quality.
For an opportunity this will be any steps already taken to capitalise on the opportunity that are relevant to the management system(s) you are implementing.
3 - Assess the Likelihood
Determine the likelihood of the risk/opportunity, that is, the probability of it occurring. Score the probability on a scale of 1 to 5:
|
Level |
Description |
|
1 |
Very unlikely to occur |
|
2 |
Low, unlikely to occur |
|
3 |
Medium, it. is possible that it could occur, it has not occurred in the past |
|
4 |
High, it is likely that it will happen. It has occurred in the past but not recently, |
|
5 |
Very high, it probably will occur |
4 - Assess the Consequence
Rate the consequence/impact on a scale of 1 to 5:
|
Level |
Description |
|
1 |
Minimal impact not really noticeable |
|
2 |
Slight impact, would be felt but would not have an effect on operations |
|
3 |
Impact, would affect operations but no long term effect on turnover |
|
4 |
Major impact, would affect turnover |
|
5 |
Severe. If risk - business would be threatened If opportunity - it would dramatically change the business |
5 - Risk Rating and Acceptance
The overall risk is calculated by multiplying the likelihood and the consequence ratings giving a score of 1 to 25.
|
Score |
Risk Rating |
|
16-25 |
Critical risk, immediate action required to reduce risk or act on the opportunity. |
|
9-15 |
High risk - apply further mitigation measures and/or alter method of work to reduce risk further or capitalise on the opportunity. |
|
6-8 |
Medium risk - tolerable only if further mitigation is not practical and there is a need to continue the activity with identified controls. If an opportunity, it is worth consideration but immediate action may not be suitable. |
|
1-5 |
Low risk - broadly acceptable if all reasonably practicable control measures in place. No action if an opportunity, |
6 - Additional comments
This section can be used to outline anything else that may be relevant.
Where the Risk/Opportunity rating is High, an auditor will expect you to outline high level a plan of action to mitigate/capitalise on this. For risks, a risk should be added to the risk register.
Where the Risk/Opportunity rating is Critical, an auditor will expect you to have a detailed plan of action to mitigate/capitalise on this. For risks, a risk should be added to the risk register.
Outline here if an associated risk has been raised in the risk register/action in the action log.
7 - Review the Register
The register should be reviewed, updated and assessed with the senior management team on a regular basis.
Associated actions and risks in the risk register should also be reviewed.
Need Help? Contact support@adoptech.co.uk or open a chat.