KITE 2025 New Product Award — Local IT | SACEEC

What Does a Risk Workshop Look Like? Agenda, Facilitation, and Outputs

A good risk workshop turns scattered opinions into a scored, owned set of risks in a single session. Here is exactly how to run one.

Free PDF GuideDownload this guide as a PDF

Most organisations know they should "get the team together to talk about risk", but the session often drifts into a vague discussion that produces a few sticky notes and no follow-through. A well-run risk workshop is different: it has a clear purpose, the right people in the room, a tight agenda, and walks out with scored, owned risks ready to drop into your register. This guide shows you exactly what that looks like from preparation to follow-up.

Watch: what a risk workshop looks like from start to finish Watch: How to run a risk workshop (short walkthrough)
i

What You'll Learn

By the end of this guide you will understand the purpose of a risk workshop, who should attend, how to prepare, a minute-by-minute run-of-show, the facilitation techniques that keep a group productive, how to capture outputs cleanly, and what to do in the days afterwards so the work does not evaporate.

The Purpose of a Risk Workshop

A risk workshop is a structured, time-boxed session where a cross-functional group identifies, discusses, and scores the risks facing a defined area of the business. It is the most efficient way to surface knowledge that lives in different people's heads and turn it into a shared, prioritised view. Done well, it achieves three things in a single sitting:

  • Identification: Capturing risks that no single person could list alone, because they sit across silos.
  • Calibration: Getting people to agree on how big each risk actually is, rather than carrying private, inconsistent assumptions.
  • Ownership: Assigning a named accountable owner to each material risk before everyone leaves the room.

A workshop is not a substitute for ongoing risk management. It is a periodic accelerant. It typically feeds directly into your risk register and complements the continuous work of monitoring described in how you monitor risks over time. It is also a core technique within a broader risk assessment.

i

Pro Tip

Be explicit about scope before you invite anyone. A workshop for "the whole company" produces shallow results; a workshop for "the customer onboarding process" or "our cloud migration project" produces sharp, usable ones. Run several focused workshops rather than one sprawling one.

Who Attends

The quality of a workshop is determined more by who is in the room than by the facilitator's skill. You want enough perspectives to see the whole picture, but few enough people to keep the conversation productive. Six to twelve participants is the sweet spot.

Role Why They Are There Essential?
Facilitator Runs the session, keeps time, stays neutral on the content Yes
Process / area owner Owns the scope being assessed and the resulting actions Yes
Subject-matter experts People who do the actual work and see risks day to day Yes
Risk / compliance representative Ensures consistent scoring and links to the wider framework Strongly recommended
Finance or commercial Helps quantify financial impact realistically Situational
Scribe / note-taker Captures outputs so the facilitator can stay focused Recommended
Executive sponsor Opens the session, signals it matters, then often leaves Optional

A word of caution on seniority: a room full of senior leaders often produces fewer real risks than a mix of levels, because the people closest to the work are the ones who see the cracks. If a senior figure must attend, brief them to listen first and speak last.

Want the full framework with worked examples?

Preparing for the Workshop

The single biggest predictor of a good workshop is preparation. A facilitator who walks in cold will spend the first half of the session getting oriented. Aim to do the following in the week before.

Define and document the scope

Write a one-paragraph scope statement: the process, project, or business unit under review, the time horizon, and the objectives that risk could threaten. Share it with participants in advance so nobody arrives confused about boundaries.

Gather inputs

Pull together the raw material that seeds discussion: the existing risk register entries for this area, recent incidents and near-misses, audit findings, customer complaints, and any relevant compliance obligations. A workshop that starts from a blank page wastes the first hour.

Agree the scoring criteria up front

Decide before the session which likelihood and impact scales you will use, so that scoring is consistent and fast on the day. If your organisation has standard scales, print them. If not, adopt a simple 1 to 5 model and review our guidance on likelihood and impact scoring.

Send a pre-read

A short pre-read (the scope statement, the scoring scales, and a request to come with two or three candidate risks each) primes participants and dramatically shortens the warm-up.

!

Important

Do not let the workshop double as the first time anyone has seen the scoring scales. Calibrating a scale and using it in the same hour produces inconsistent, low-trust scores. Settle the scales beforehand and treat the workshop as the place to apply them.

The Agenda and Run-of-Show

A focused risk workshop runs for ninety minutes to half a day depending on scope. The structure below is for a two-hour session covering a single process or project. Time-box every segment and keep a visible clock.

Time Segment Purpose
0:00 to 0:10 Welcome and framing Restate scope, objectives, scoring scales, and ground rules
0:10 to 0:40 Risk identification Brainstorm and surface candidate risks across the scope
0:40 to 0:55 Grouping and de-duplication Cluster similar items and write clear risk statements
0:55 to 1:05 Prioritisation vote Narrow a long list down to the material risks worth scoring
1:05 to 1:40 Live scoring Score likelihood and impact for each prioritised risk
1:40 to 1:55 Ownership and next steps Assign owners and capture obvious treatment actions
1:55 to 2:00 Wrap-up Confirm outputs, timelines, and follow-up cadence

Set three ground rules in the framing segment: every voice counts, there are no stupid risks, and we are describing what could go wrong, not blaming who caused it. Psychological safety is the fuel for honest identification.

Facilitation Techniques

The facilitator's job is to extract knowledge from the group without letting one or two loud voices dominate. A handful of techniques do most of the work.

Brainstorming and silent generation

Open identification with a few minutes of silent, individual writing. Each person lists risks on cards or in a shared document before anyone speaks. This prevents anchoring, where the first risk mentioned shapes everything that follows, and it gives quieter experts equal airtime. Then go round the room collecting one risk per person at a time until the ideas are exhausted.

Prompts to widen coverage

When the group runs dry, prompt with categories: "What could go wrong with our people? Our systems? Our suppliers? Our regulators? Our finances?" Walking through risk categories systematically catches blind spots that free-form brainstorming misses.

Dot voting to prioritise

When you have a long list, give each participant a fixed number of votes, say five dots, to place against the risks they consider most material. This quickly surfaces group consensus on what deserves scoring time, without a drawn-out debate over every item.

Live scoring with calibration

Score each prioritised risk in the room. Ask participants to hold up fingers or use a poll for likelihood, then impact. Where scores diverge widely, say one person says 2 and another says 5, pause and ask each to explain their reasoning. This calibration conversation is often the most valuable part of the whole workshop, because it exposes hidden assumptions.

Example

A calibration moment in action

While scoring "Loss of a key cloud engineer", impact votes split between 3 and 5. The 3-voters assumed documentation was solid; the 5-voters knew the engineer was the only person who could deploy to production. Surfacing this disagreement did two things: it settled the impact at 4 with shared understanding, and it spawned a concrete action to cross-train a second engineer, an output that pure scoring would never have produced.

Parking lot

Keep a visible "parking lot" for tangents, out-of-scope risks, and unresolved questions. It lets you acknowledge a point without derailing the agenda, and it becomes a useful input to the next workshop.

Capturing the Outputs

A workshop is only as good as what survives it. Capture outputs in a structured form, ideally live on screen so the group can see and correct them in real time. For each material risk record at least:

  • Risk statement: Written as event, cause, and consequence. For example, "Production outage caused by single-engineer deployment dependency resulting in lost revenue and SLA breaches".
  • Category: Operational, financial, strategic, compliance, and so on.
  • Likelihood and impact scores: The agreed values, plus a one-line note on the reasoning.
  • Existing controls: What already reduces this risk today.
  • Owner: A single named person, not a department.
  • Candidate actions: Any treatment ideas raised, even if not yet committed.

Capturing the reasoning behind each score matters as much as the score itself. Six months later, when someone reassesses the risk, the note explaining why impact was a 4 is what makes the reassessment meaningful rather than guesswork. This is also what turns a workshop into a defensible input for internal audit.

i

Pro Tip

If you score live in a shared register or risk tool rather than on sticky notes, you eliminate the painful transcription step afterwards and the workshop output is already in its permanent home. The energy of the room carries straight into a usable register.

Post-Workshop Follow-Up

The days after the workshop decide whether it created lasting value or just a pleasant morning. Move quickly while the discussion is fresh.

  1. Within 48 hours: Circulate the captured risks, scores, owners, and actions to all participants for a sanity check. Memories fade fast.
  2. Within a week: Load the agreed risks into the risk register and convert candidate actions into tracked items with owners and due dates.
  3. Confirm ownership: Make sure each named owner has formally accepted their risks and actions, rather than discovering it in a meeting minute.
  4. Set the review cadence: Agree when each risk will next be reviewed based on its level, then hand the ongoing work to your monitoring process.
  5. Close the loop with leadership: Summarise the top risks for the sponsor and feed them into the next board risk report where relevant.

Virtual vs In-Person Workshops

Both formats work, but each needs deliberate handling. The table below summarises the trade-offs and how to compensate.

Dimension In-Person Virtual
Energy and engagement Naturally higher; easier to read the room Drops fast; keep sessions shorter and add breaks
Identification technique Sticky notes and whiteboards Shared whiteboard tools and live documents
Voting and scoring Physical dots, hands, or cards Polling features or shared spreadsheets
Dominance risk Moderated by facilitator presence Higher; use silent generation and round-robins
Logistics Room, travel, scheduling overhead Easier to convene distributed teams

For virtual sessions, the golden rules are: cap them at ninety minutes, use a collaborative canvas everyone can edit, lean heavily on silent generation and polling to prevent the loudest connection from dominating, and explicitly invite quieter participants by name. A hybrid format, with some in a room and some remote, is the hardest of all and should be avoided when stakes are high, because remote participants almost always get marginalised.

Common Mistakes to Avoid

1. No clear scope

An open-ended "let's talk about risk" session produces a thin, scattered list. Define a tight scope and stick to it, using the parking lot for everything else.

2. Inviting the wrong people

Too senior and you lose the operational detail; too junior and you cannot make decisions or assign ownership. Aim for a deliberate mix.

3. Skipping preparation

Walking in without inputs or agreed scales burns the first hour on orientation. Do the prep work in the week before.

4. Letting one voice dominate

If the most senior or loudest person speaks first, everyone anchors to them. Use silent generation and round-robins to protect diverse input.

5. No follow-up

The most common failure is a great session whose outputs never reach the register. Lock in the 48-hour and one-week follow-up steps before anyone leaves.

6. Scoring without recording the reasoning

A number with no rationale is impossible to reassess later. Always capture a one-line note on why each score was chosen.

Key Takeaways

Summary

  • A risk workshop identifies, calibrates, and assigns ownership for risks in a single structured session
  • Who is in the room matters more than facilitation polish, so aim for six to twelve people across levels
  • Preparation, especially a defined scope and pre-agreed scoring scales, is the biggest predictor of success
  • Use silent generation, category prompts, dot voting, and live calibrated scoring to extract honest input
  • Capture risk statements, scores, reasoning, owners, and candidate actions live and structured
  • Follow up within 48 hours and load outputs into the register within a week, or the value evaporates

Frequently Asked Questions

How long should a risk workshop be?

For a single process or project, ninety minutes to two hours is ideal. Broader enterprise-level workshops may run half a day but should include breaks. Virtual sessions should be capped at ninety minutes because attention drops faster on screen.

How many people should attend?

Six to twelve participants works best. Fewer than six and you may miss perspectives; more than twelve and the conversation becomes hard to manage and quieter voices get crowded out. If you need broader input, run multiple focused workshops rather than one large one.

Should we score risks during the workshop or afterwards?

Score live in the room. The whole value of having the group together is the calibration conversation that happens when scores diverge. Scoring afterwards loses that, and a single person's later interpretation rarely matches the collective view. Use agreed likelihood and impact scales so scoring is fast and consistent.

What is the facilitator's role?

The facilitator runs the process, keeps time, ensures everyone contributes, and stays neutral on the content. They should not be the subject-matter expert and should not push their own view on scores. Their job is to extract the group's collective knowledge, not to supply the answers.

How often should we run risk workshops?

A full identification workshop for a given area is typically run annually, or whenever something significant changes, such as a new project, a major incident, a reorganisation, or new regulation. Between workshops, the risks are kept current through ongoing review, which we cover in monitoring risks over time.

Can risk workshops be run remotely?

Yes, and they can be very effective. Use a shared whiteboard or live document, polling tools for voting and scoring, and silent generation to prevent dominance. Keep sessions shorter, invite quieter participants by name, and avoid hybrid formats where possible, since remote attendees tend to get marginalised when others share a room.

Save this guide for later

Download the PDF version to read offline or share with your team.

Co-Founder & ERM Practitioner

An enterprise risk management practitioner with experience across healthcare, public sector, and regulated environments. Phumi focuses on translating ERM frameworks into practical, decision-relevant processes.

Co-Founder & ERM Practitioner

Specialises in enterprise risk management through risk assessments, data analysis, and mitigation planning. Contributes to compliance oversight, risk reporting, and monitoring of key risk indicators.