Frequently Asked Questions

  • This tool is primarily intended for SMEs and mid-sized companies. It provides an instant and concise assessment of a company's level of control over the full range of risks it faces.
  • Note that this approach is also relevant for start-ups, sole traders, and micro-enterprises.
  • It can be carried out as a self-assessment or with the support of a certified regional or local Medef.
  • Born from a meeting between the AMRAE and Medef Deux-Sèvres teams, the idea for creating this tool was inspired by the reality experienced by business leaders and risk professionals.
  • Large companies are often well equipped in terms of risk management. But this is not the case for micro-enterprises, SMEs, and mid-sized companies, which rarely have the time to gain an overview of all the risks they face. Indeed, they very often have neither the time, the methodology, nor the resources to set up structured and comprehensive systems
  • Yet the benefits are numerous. Implementing a 360° risk management approach is a formidable decision-support tool and a valuable instrument for managing the company, one that is increasingly favored by clients and the company's various partners. Moreover, once risks are managed, they often become opportunities.
  • In 2017, AMRAE and Medef Deux-Sèvres noted the limited spread of a risk management culture among micro-enterprises, SMEs, and mid-sized companies. Yet a structured approach greatly increases a company's resilience and creates opportunities.  Convinced of the relevance of this approach, Medef Deux-Sèvres and AMRAE set up a working group bringing together risk managers and leaders of micro-enterprises, SMEs, and mid-sized companies to build a risk-analysis self-assessment tool that any company could easily use. This work resulted in the creation of macartodesrisques.fr in 2018.
  • The aim pursued is to raise awareness among all companies of this topic through an initial, instant, and concise assessment of the organization's risk management.
  • In 2020, Medef Deux-Sèvres went further by hiring a full-time risk manager to support members in their risk mapping and risk treatment plans.
  • A new milestone was reached in 2023, this time with the national Medef and AMRAE formalizing their partnership. Led by Medef Deux-Sèvres and joined by other regional Medef organizations, the site was given a fresh look and certain questions were enhanced, without changing the site's structure. Topics related to CSR, Artificial Intelligence, and climate and energy risks were notably strengthened.
  • The major new feature is the possibility for micro-enterprises, SMEs, and mid-sized companies that wish to do so to be supported in their risk mapping and treatment plan by a certified regional or local Medef (no other private, public, or non-profit organization is authorized to support a user company). The tool obviously remains open to all companies in self-assessment format.
  • About AMRAE: AMRAE (the French Association for Corporate Risk and Insurance Management) is the leading professional association for risk and insurance professionals in business. It brings together more than 1,650 professional risk management members belonging to more than 750 private or public organizations, including 80% of CAC 40 and SBF 120 companies. It is the association that drives the risk management approach and promotes its ongoing development. Through its scientific committees, publications, and numerous events, AMRAE produces content for its members that nurtures their skills, their career development, and their contribution to the success of their companies' strategies.
  • About Medef Deux-Sèvres: Medef Deux-Sèvres, the leading employers' organization in the department, represents more than 500 companies of all sizes and sectors. The team supports business leaders on a daily basis and at every stage of their company's life: legal-HR, financial engineering, employment-training, CSR, social dialogue, export, innovation…  A key player in economic life, Medef Deux-Sèvres is a founding partner of various ecosystems (French Assurtech, Technopole…).
  • This methodology was built by a working group made up of around fifteen business leaders from Deux-Sèvres, risk managers, AMRAE’s scientific committee, and Medef Deux-Sèvres staff. It takes the fundamental principles of Enterprise Risk Management (ERM) and the various standards and conventions governing the discipline, and simplifies them.
  • To complete the exercise, you must answer 55 questions divided into 7 major risk universes (strategic, financial, operational, cyber/security, regulatory, HR, and crisis management). The strength of this tool lies in the relevance of the questionnaire, which adapts appropriately to any type of company. Pragmatic and concrete, the content of the questions carefully covers the full range of risks a company may be exposed to.
  • For each question, the risk must be rated (assessed) according to two scales. These two scales are rated from 1 to 4. [See the rating scales page]
    • The impact scale assesses the consequence should the risk occur.
      • 1. Limited = Almost no impact.
      • 2. Significant = Minor impact. 
      • 3. Critical = Significant consequence(s) for the company, negatively affecting its proper functioning.
      • 4.  Catastrophic = Immediate danger to the company’s survival.
    • Note that the rating takes into account measures put in place by the company to mitigate the consequence of the hazard. For example, a company with a high fire risk due to the very nature of its activity will have a lower impact assessment if it has implemented measures to limit the impact (sprinklers, fire doors, backup site…).
    • The probability scale assesses the frequency of occurrence of a risk.
      • 1. Improbable = This has never happened and there is no chance it will happen.
      • 2. Rare = This has never happened and is unlikely to happen. 
      • 3. Occasional = This has happened a few times and is likely to happen again.
      • 4. Frequent = This happens regularly and will continue to happen regularly.
    • Note that the rating takes into account measures put in place to limit the occurrence of a risk. For example, a company with a high fire risk due to the very nature of its activity will have a lower probability assessment if it has implemented measures to limit occurrence (fire permits, replacement of flammable products with non-combustible ones…).
  • Once you have answered all the questions in the questionnaire, a diagnostic in the form of a PDF report providing a concise assessment of the company's risk management is delivered to you free of charge for download.
  • The charts summarize all the risks you have rated using two types of diagrams.
    • The first, “Risk control assessment by major universe (base 100)”, weights and summarizes risk ratings by major universe. The closer the chart is to 100, the less controlled the universe is.
    • The second, “Risk Matrix”, provides a visual representation of all risks distributed according to impact and probability assessments. It introduces the severity scale (probability x impact), which divides the risks into 4 major categories (red, orange, yellow, green).
  • You can then browse, use, and share with relevant people the roughly fifty pages of the report, which faithfully reflects your various answers to the questions.
  • There are two ways to use macartodesrisques.fr:
    • Self-assessment: The business leader or management committee carries out the risk mapping alone by following the site’s steps one by one and referring to the various resources available in the resource center.
    • Support from a certified Medef: Some regional and local Medef organizations offer to support their members in carrying out their risk mapping and in treating identified risks.
      Find the list of certified Medef organizations here.

WARNING: No organization (company or association), other than certified Medef organizations and AMRAE, is authorized to support companies in carrying out their risk mapping via macartodesrisques.fr. Any commercial use without the express authorization of the owners exposes the user to legal action.

  • As the risk management approach requires a genuine collective investment, it is important for each company to consider the best time to undertake such an approach.
  • The right moment must be found, bearing in mind that certain circumstances can trigger or prompt the process: after an organizational change (merger, acquisition, reorganization…), in a context of strong growth (revenue, geographic…), in response to regulatory expectations, following major accidents, or during a period of crisis…
  • Once the period has been chosen, a pace compatible with the life of the company should be found: making participants sufficiently available for the approach to be thorough and relevant, without dragging on too long.
  • A “tight” schedule helps maintain everyone's momentum and involvement, and prevents the work done at the start of the process from becoming outdated by the end.
  • The business leader must be prepared, both towards themselves and towards third parties:
    • To genuine transparency about the company's current situation and its strategic vision for the future of its business;
    • To a possible questioning of how the company operates;
    • To genuine sharing with their management team on this topic, for greater performance.
  • In short, they must remain humble and able to question themselves.
  • It is entirely possible to answer the questionnaire over several sessions. Once your account has been created, you simply need to return to the site and log in using your login credentials / password.
  • It is of course possible to carry out this audit several times. It is even recommended to update your risk map every 1 to 2 years. Indeed, the level of risk control changes over time. In addition, some risks emerge while others fade.
  • Finally, this approach will only be truly useful if you implement a treatment plan for the risks you have identified.
  • With this in mind, the tool allows you to duplicate a risk map and use it as a basis for updating it.
  • Warning : However, if your account has been inactive for more than two years, existing risk maps as well as your account will be automatically deleted.  This is why it is important to download your risk map once you have completed it.
  • You can easily recommend this site to your friends and fellow business leaders: simply share the site’s link on social media using the sharing buttons available on the results page and at the bottom of the homepage. You can also simply share the site’s address (by email, for example).
  • The database is encrypted.
  • The email address is the only data collected by the administrators of the macartodesrisques.fr site. This data is processed solely for the purpose of administering the site. There will be no commercial use of this data.
  • When you complete your risk map, you will not be asked for any information that could directly identify your company. You can anonymize all of your comments.
  • As a matter of precaution and confidentiality, users are advised not to enter any information that would directly identify the company or its employees, partners, customers, or suppliers.
  • Users who created their account before (V2 launch date) cannot recover their password if forgotten.
  • Access the legal notice
  • Your answers are stored with the site’s hosting provider (see legal notice).
  • Warning : However, if your account has been inactive for more than two years, existing risk maps as well as your account will be automatically deleted.  This is why it is important to download your risk map once you have completed it.