A risk assessment is the process of identifying what could go wrong, understanding how likely and how serious each potential outcome would be, and making informed decisions about how to respond. It is the analytical core of any risk management programme, and its quality determines the reliability of the risk picture the board relies upon.
Done well, a risk assessment provides the organisation with an accurate, evidence-based understanding of where its most significant exposures lie and what is being done about them. Done poorly, it produces a register of risks that reflect what people found comfortable to document rather than what actually threatens the organisation's ability to achieve its objectives.
This guide covers the steps of a credible risk assessment in detail, based on the process set out in ISO 31000 and widely applied across sectors. It also covers the common mistakes that undermine assessment quality and how to avoid them.
The first question to answer before any risk identification begins is: what is this assessment for? A risk assessment conducted for the purpose of annual board reporting has a different scope, a different level of detail, and a different set of objectives than an assessment conducted to evaluate the risks of a specific new project, a proposed acquisition, or the introduction of a new technology system.
Treating every risk assessment as if it has the same purpose and the same scope is one of the reasons many organisations end up with risk registers that are too broad to be practically useful, too high-level to inform management decisions, or focused on the wrong things entirely.
Be explicit about scope before identification begins: what area of the organisation does this assessment cover, what time horizon is relevant, what objectives are being protected, and what decisions will be informed by the assessment's outputs?
The internal context for a risk assessment covers the organisation's objectives, the resources and capabilities it has to manage risk, the governance structures through which accountability flows, and the values and culture that influence how risk is perceived and managed.
Understanding the internal context helps identify which risks are actually material to this organisation. A risk that is significant for an organisation operating in a particular regulatory environment may be irrelevant for one with different permissions or activities. And the organisation's governance maturity, specifically how well its existing controls are designed and how consistently they are applied, is directly relevant to how residual risk is assessed.
The external context covers the regulatory and legal environment the organisation operates within, the market and competitive environment, the geopolitical and macroeconomic conditions that may affect operations, and the technological environment including both the capabilities and the threats that technology creates.
Regulatory context deserves particular attention. In regulated sectors, the regulatory environment defines both the specific compliance obligations the organisation carries and the governance standard to which its risk management will be held. Understanding the FCA's current supervisory priorities, for example, provides important context for a regulated firm's risk assessment, because the regulator's priorities reflect where enforcement attention is most likely to be focused.
Risk criteria are the standards against which risks will be evaluated. They include the risk appetite and tolerance thresholds approved by the board, the assessment scales that will be used for likelihood and impact, the time horizon the assessment covers, and the bases for deciding whether a risk requires treatment.
ISO 31000 requires risk criteria to be established before the assessment begins, not defined during it. Criteria defined after identification has occurred are susceptible to being shaped by what was found, producing circular reasoning where the criteria justify accepting the risks that happen to have been identified.
Risk identification asks what could happen that would affect the achievement of the objectives in scope. Effective identification goes beyond what people immediately think of and uses structured techniques to surface risks that intuition or experience alone would miss.
The scope of identification should cover threats, events or conditions that could have negative consequences, and opportunities, uncertainties that could have positive consequences if realised. Most risk assessments focus primarily on threats, which is appropriate for most governance purposes, but ignoring opportunities entirely misses one of the dimensions of uncertainty that genuinely affects objective achievement.
Facilitated workshops bring together people with direct knowledge of the area being assessed to identify risks through structured discussion. The facilitation is important: an open question about what could go wrong tends to produce the risks people are most immediately aware of. Structured prompts, using categories from the risk taxonomy, process maps, or regulatory requirement lists, surface risks that the open question would miss.
Interviews with risk owners, senior managers, and subject matter experts provide depth on specific risk areas and capture concerns that people may be reluctant to raise in a group setting. Individual interviews are particularly valuable for identifying conduct-related risks and risks that reflect on management behaviour.
Review of historical data including incident records, near-miss reports, audit findings, and regulatory correspondence provides an empirical basis for risk identification grounded in what has actually happened rather than only what people believe might happen.
External benchmarking against industry risk frameworks, regulatory guidance on sector-specific risks, and the disclosed risks of comparable organisations helps identify risks that the organisation may face but has not yet considered.
A risk that is described too vaguely cannot be assessed meaningfully or managed effectively. "Operational risk" is not a risk. "Failure of the core banking system during peak processing hours causing transaction errors and customer impact" is a risk. The description should be specific enough that someone unfamiliar with the area could understand what could go wrong, how, and with what consequence.
Each risk should also have a named owner at this stage. Ownership matters for the subsequent assessment steps and for accountability: if no individual is clearly responsible for managing a risk, it is likely to be managed by nobody.
Likelihood assessment asks how probable it is that the risk will materialise over the time horizon in scope. Several factors influence likelihood that should be explicitly considered rather than left to intuition.
Historical frequency is the most reliable basis for likelihood assessment where sufficient data exists. An event that has occurred three times in the past five years is more likely to recur than one that has never occurred. The absence of historical occurrence is not evidence of low likelihood for risks that simply have not yet had the right conditions to materialise.
The current control environment affects likelihood. A risk with strong, well-tested preventive controls in place is less likely to materialise than the same risk with absent or inadequate controls, regardless of the underlying inherent probability.
External trends affecting likelihood should be considered. A cyber threat that is increasing in sophistication and frequency across the sector is more likely to materialise next year than the base rate from historical data would suggest.
Impact assessment asks what the consequences would be if the risk materialised. A common and significant mistake is assessing impact only in financial terms, when many of the most serious consequences of risk events are non-financial.
A full impact assessment considers financial consequences including direct loss, remediation cost, regulatory fine, and lost revenue; operational consequences including disruption to services, process failures, and capacity constraints; regulatory and legal consequences including enforcement action, licence restrictions, and litigation; reputational consequences including media coverage, customer loss, and stakeholder confidence; and human consequences including harm to staff, customers, or beneficiaries.
For some risk categories, the non-financial consequences are the most significant. A safeguarding failure that causes harm to a vulnerable person may have limited direct financial consequences but catastrophic reputational and legal ones. Assessing only financial impact would dramatically understate the true severity of this risk.
The combination of likelihood and impact produces a risk rating that allows risks to be ranked and compared. Most risk frameworks use a matrix approach, where likelihood and impact are each assessed on a defined scale (typically three to five levels) and the combination produces a rating that places the risk on a heat map.
The specific methodology matters less than consistency. Every risk owner using the same definitions and scales, and the risk function challenging assessments that look implausible relative to the definitions, produces more useful data than a theoretically sophisticated methodology applied inconsistently.
Analysis tells you what the risk is. Evaluation tells you whether it is acceptable. This step compares the risk rating produced by analysis against the risk criteria established in the context step, specifically the board-approved risk appetite, to determine whether the risk requires treatment.
Risks that fall within appetite and are adequately controlled may be accepted in their current state, subject to ongoing monitoring. Risks that are outside appetite, or where the controls are assessed as inadequate, require treatment.
At this stage, the evaluation should consider both inherent risk, the level before any controls, and residual risk, the level after existing controls are applied. The inherent risk gives context: this is the underlying exposure if nothing were done. The residual risk is the actual current position.
When residual risk remains high despite controls supposedly being in place, one of two things is true: either the controls are inadequate in design and the residual assessment should be higher, or the controls are not operating effectively. Both are important findings. A risk function that accepts a low residual risk rating without examining the adequacy of the controls producing it is not providing genuine governance value.
ISO 31000 identifies five categories of risk treatment that cover the range of possible responses to identified risks.
Avoid the risk by not undertaking the activity that creates it. This is the most definitive response and is appropriate where the risk is unacceptably high and the activity is not essential to the organisation's objectives.
Remove the source of the risk by changing the underlying conditions that create it. This differs from avoidance in that the activity continues but the risk-generating aspect of it is eliminated.
Modify the likelihood or consequence through controls. This is the most common treatment response, covering the design and implementation of preventive and detective controls that reduce either the probability of the risk occurring or the severity of its consequences.
Share the risk through insurance, contractual arrangements, or partnerships that transfer some of the financial consequence of the risk to another party.
Retain the risk as a deliberate, informed decision that the residual level is acceptable within the organisation's risk appetite. Retained risks should be explicitly documented as such, not left ambiguous between a deliberate acceptance decision and an oversight.
Treatment decisions should be documented, with named owners for any actions to be taken, defined timelines, and a mechanism for verifying that actions have been completed and have had the effect intended. Treatment that is agreed in a risk committee and never followed up is not actually managing the risk.
A risk assessment completed and then left unchanged is not a risk management activity. It is a historical record of what the risk environment looked like at one point in time. The risk environment changes: the external environment evolves, controls are implemented or degrade, incidents occur and reveal previously unidentified risks, and the organisation's own activities and structure change in ways that affect its risk profile.
Monitoring ensures the risk assessment remains current. This means tracking the status of identified risks and escalating those approaching or breaching appetite thresholds. It means ensuring that KRIs provide advance warning of deteriorating risk positions between formal assessment cycles. And it means connecting incident data to the risk register so that actual failures update the assessment rather than sitting separately in incident logs.
How frequently a risk assessment should be formally reviewed depends on the volatility of the risk environment and the significance of the risks in scope. For most ERM programmes, a quarterly monitoring cycle with an annual comprehensive review is a reasonable baseline. High-risk areas, areas of significant change, and risks approaching appetite thresholds warrant more frequent attention.
The risks that are most important to identify are often the ones people are least comfortable documenting. Risks that reflect on management behaviour, governance weaknesses, or strategic mistakes can be systematically understated in self-assessment processes where the people completing the assessment also have an interest in the outcome looking positive.
An independent challenge role for the risk function, a willingness to disagree with management assessments where the evidence does not support them, and board engagement that probes below the surface of positive-looking risk registers, are all necessary conditions for an honest risk assessment.
A risk assessment conducted once a year and ignored for the other eleven months is not providing ongoing risk intelligence. It is providing a snapshot that may be significantly out of date by the time anything is done about what it reveals.
The assessment should be a living process: risks updated when they change, new risks added as they emerge, and the overall picture current enough to inform decisions between formal review cycles.