A risk assessment is the core activity that turns risk management from a policy on paper into something that actually informs decisions. It is the structured process of identifying what could go wrong, judging how serious it would be, and deciding what to do about it. Done well, it produces a prioritized, defensible view of risk. Done badly, it produces a spreadsheet nobody trusts. This guide walks through what a risk assessment is, when to run one, and a practical step-by-step process from scoping to documented output.
What You'll Learn
By the end of this guide you will understand what a risk assessment is, when to run one, the six-step process from scoping to documentation, the difference between qualitative and quantitative methods, when to use workshops versus surveys, and what outputs a good assessment produces.
What Is a Risk Assessment?
A risk assessment is the systematic process of identifying risks, analyzing their likelihood and impact, and evaluating them against the organization's risk appetite to decide which require action. It is the analytical heart of risk management.
It is useful to distinguish the assessment from its container. The risk register is where the results are recorded and maintained over time. The risk assessment is the activity that produces and updates those records. You run an assessment; you maintain a register.
A risk assessment typically answers four questions for each risk: What could happen? How likely is it? How bad would it be? Is that acceptable, and if not, what do we do?
When to Run a Risk Assessment
Risk assessments are not only an annual ritual. They should be triggered by circumstances as well as by the calendar. Run one when:
- On a regular cycle: Most organizations run an enterprise-wide assessment annually, with more frequent reviews of high-priority risks.
- Before a major decision: A new product, market entry, acquisition, or large investment warrants a targeted assessment.
- At project initiation: Significant projects should be assessed at kickoff and at key milestones.
- After a significant change: Reorganizations, new systems, new regulations, or new suppliers change the risk profile.
- Following an incident or near-miss: An incident is a signal that an assessment missed something or that controls failed.
- When required: Regulators and frameworks such as ISO 31000 often expect periodic assessments as evidence of active risk management.
Want the full framework with worked examples?
The Step-by-Step Process
A defensible risk assessment follows six steps. They map closely to the ISO 31000 process and apply whether you are assessing a single project or the whole enterprise.
Step 1: Define the Scope and Context
Before identifying anything, set boundaries. What is being assessed, whether a business unit, a process, a project, or the whole organization? Over what timeframe? Which risk categories are in scope? Who are the stakeholders and what decisions will the assessment inform? Recording the scope up front keeps the assessment from sprawling or missing obvious areas.
Step 2: Identify Risks
Generate a thorough list of what could go wrong, using multiple inputs: workshops, historical incidents, audit findings, industry intelligence, and interviews. Write each risk as a clear cause-event-consequence statement rather than a vague label.
Writing a Risk Statement
Poor: "IT risk"
Better: "Prolonged outage of the core billing system, caused by an unpatched server failure, resulting in delayed invoicing and lost revenue for up to one week."
The second version names the cause, the event, and the consequence, so it can actually be scored and treated.
Step 3: Analyze Likelihood and Impact
For each identified risk, judge how likely it is to occur and how severe the consequences would be, using a consistent scale. Assess the inherent risk first (before controls), then the residual risk (after existing controls). Most organizations use a five-point scale for each dimension and multiply them. See our detailed guide to likelihood and impact scoring for the full method.
| Score | Likelihood | Impact (illustrative) |
|---|---|---|
| 1 | Rare (<5%) | Insignificant, under R10,000 |
| 2 | Unlikely (5 to 25%) | Minor, R10,000 to R100,000 |
| 3 | Possible (25 to 50%) | Moderate, R100,000 to R1,000,000 |
| 4 | Likely (50 to 75%) | Major, R1,000,000 to R10,000,000 |
| 5 | Almost certain (>75%) | Catastrophic, over R10,000,000 |
Step 4: Evaluate Against Appetite
Compare each risk's residual score to the organization's risk appetite. This is the step that turns analysis into decisions. A risk that sits within appetite can be accepted and monitored; a risk that exceeds appetite must be treated or escalated. Without an appetite to evaluate against, scoring is just sorting.
Step 5: Treat the Risks
For risks above appetite, choose a treatment strategy. The common options are avoid, reduce, transfer, or accept. Reducing a risk means adding or strengthening controls; transferring it might mean insurance or outsourcing. The chosen actions, owners, and deadlines form a risk treatment plan.
Step 6: Document and Communicate
Record everything in the risk register: the risk statements, scores, owners, controls, treatments, and the rationale behind each decision. Communicate the results to stakeholders and the board. The documentation is what makes the assessment defensible to auditors and useful for the next cycle.
Pro Tip
Capture the reasoning behind each score, not just the number. "Likelihood 4 because we had two similar incidents last year and the control gap remains open" is far more useful at the next review than a bare "4". Future assessors, and auditors, need to know why, not just what.
Qualitative vs. Quantitative Assessment
There are two broad ways to analyze risk, and most organizations use a blend of both.
| Aspect | Qualitative | Quantitative |
|---|---|---|
| Method | Descriptive scales (e.g. High/Medium/Low or 1 to 5) | Numerical modeling (e.g. expected loss, Monte Carlo) |
| Speed | Fast and accessible | Slower; needs data and expertise |
| Best for | Most risks; rapid prioritization | High-stakes, data-rich risks (financial, insurance) |
| Output | Risk ratings and heat maps | Monetary exposure, probability distributions |
The pragmatic approach is to use qualitative assessment as the default to triage and prioritize the full population of risks, then apply quantitative analysis to the handful of risks where the stakes and data justify the extra effort. Trying to quantify every risk wastes effort, while relying only on qualitative scales for a R500 million exposure under-serves the decision.
Workshop vs. Survey Approaches
How you gather input shapes the quality of the assessment. The two main approaches have different strengths.
Workshops
Facilitated sessions bring stakeholders together to identify and score risks live. They are excellent for surfacing risks through discussion, building shared understanding, and resolving disagreements on scores in real time. The downsides are scheduling difficulty, the risk of louder voices dominating, and groupthink.
Surveys
Distributing structured questionnaires lets you collect input from many people efficiently and anonymously. Surveys scale well, reduce dominance bias, and suit geographically spread teams. The downsides are lower response quality, no live discussion, and the need for careful question design.
Important
Whichever approach you use, scoring consistency is the biggest threat to a credible assessment. If different participants interpret "likely" or "major" differently, the resulting scores cannot be compared. Always anchor your scales with clear definitions, such as the percentage and monetary ranges in the table above, and brief participants before they score.
Many mature programs combine the two: a survey to gather broad input and pre-populate the risk list, followed by a focused workshop to challenge scores and reach agreement on the top risks.
What a Risk Assessment Produces
A complete risk assessment produces several outputs that feed the rest of the risk program:
- An updated risk register with scored, owned, documented risks
- A prioritized risk list or heat map showing where exposure is concentrated
- A view of risks against appetite, flagging which exceed acceptable levels
- A risk treatment plan with actions, owners, and deadlines for risks above appetite
- Reporting to management and the board, summarizing the top risks and the organization's overall posture
These outputs are not the end. They feed into ongoing monitoring, so that the next assessment starts from where this one left off rather than from a blank page. A risk assessment is one turn of a continuous cycle, not a one-off event.
Common Mistakes to Avoid
1. Treating It as a One-Off
An assessment run once and never revisited goes stale fast. Build it into a recurring cycle and re-run it when circumstances change.
2. Skipping Scope and Context
Diving straight into identifying risks without defining boundaries produces an assessment that is either bloated or full of gaps.
3. Vague Risk Statements
"Market risk" cannot be scored or treated. Always write risks as cause-event-consequence statements.
4. Scoring Without Appetite
Scoring risks but never comparing them to appetite leaves you with a sorted list and no decisions. Evaluation against appetite is what makes the assessment actionable.
5. Inconsistent Scoring
If participants interpret the scales differently, the scores are not comparable. Anchor every scale with clear definitions and brief participants.
6. No Documentation of Rationale
Recording scores without the reasoning behind them makes the assessment impossible to defend or build on. Capture the "why".
Summary
- A risk assessment identifies, analyzes, and evaluates risks against appetite to decide what action to take
- Run assessments on a regular cycle and whenever a major decision, change, or incident occurs
- Follow the six steps: scope, identify, analyze, evaluate against appetite, treat, and document
- Use qualitative methods to triage most risks and quantitative methods for high-stakes ones
- Combine workshops and surveys, anchor your scales, and document the rationale behind every score
Frequently Asked Questions
What is the difference between a risk assessment and a risk register?
A risk assessment is the activity of identifying, analyzing, and evaluating risks. A risk register is the document or database where the results are recorded and maintained over time. You run an assessment to produce and update the register, and the register is the living record between assessments.
How often should you run a risk assessment?
Most organizations run an enterprise-wide assessment annually, with high-priority risks reviewed more frequently, often monthly or quarterly. Beyond the calendar, you should run a targeted assessment before major decisions, at project kickoff, after significant changes, and following any incident or near-miss that signals your risk profile has shifted.
Should I use qualitative or quantitative methods?
Use both. Qualitative assessment with descriptive scales is fast and works for the bulk of your risks, letting you prioritize quickly. Reserve quantitative methods, such as expected loss and scenario modeling, for high-stakes, data-rich risks where the extra rigor justifies the effort. Most mature programs triage qualitatively and quantify selectively.
What is the difference between inherent and residual risk in an assessment?
Inherent risk is the level of risk before any controls are applied; residual risk is what remains after existing controls. A good assessment scores both: inherent risk shows the raw exposure, and residual risk shows how effective your controls are. You evaluate the residual score against appetite to decide whether further treatment is needed.
Who should be involved in a risk assessment?
Involve the people closest to the risks, namely business unit managers and process owners who understand operational reality, facilitated by the risk function, which provides the methodology and consistency. For an enterprise assessment, include cross-functional representation and brief participants on the scoring scales beforehand so input is comparable. The risk function aggregates and challenges; the first line provides the substance.
What happens after a risk assessment is complete?
The outputs feed the rest of the program. Risks above appetite go into a risk treatment plan with actions, owners, and deadlines. The register is updated, results are reported to leadership, and the risks move into ongoing monitoring. The assessment is one turn of a continuous cycle, so the next assessment starts from this baseline rather than from scratch.
Save this guide for later
Download the PDF version to read offline or share with your team.

