Risk assessment process flowchart
Risk assessment process flowchart covering scope and criteria, risk identification, likelihood and impact scoring, control effectiveness, the four treatment options and the review cycle.
What the risk assessment process is
Risk assessment goes wrong in a predictable place. Not in the scoring, which everyone worries about, but before it: the criteria and the appetite were never agreed, so two assessors score the same exposure differently and the register becomes a collection of opinions rather than a ranked list. Deciding the scales and the threshold first is what makes everything downstream comparable.
The second failure is treating identification as a formality. A risk written as "supplier failure" cannot be assessed, because it names neither the cause nor the consequence, and the assessment that follows is really an argument about what the phrase meant. Cause, event and consequence is the minimum that makes a risk statement assessable, and it is why this process separates describing a risk from scoring it.
The chart below runs from a trigger to a monitored register entry, across five lanes and five phases. It keeps the two structures that most risk procedures leave implicit: inherent risk scored separately from residual, so the contribution of the existing controls is visible rather than assumed, and acceptance drawn as a decision with an approval level rather than as what happens when nobody does anything.
What this flowchart covers
In this template
- Five swimlanes (Process owner, Risk owner, Risk manager, Subject matter experts, Risk committee) across five phases: Scope and context, Identification, Analysis and evaluation, Treatment and Monitoring and review.
- Scope and criteria set before any risk is scored: what is in scope, the likelihood and impact scales, and the appetite threshold above which a risk cannot simply be carried.
- Identification with the people who do the work, a register entry, a duplicate check that merges rather than double-counts, and a cause-event-consequence description before scoring begins.
- Inherent scoring, then an explicit assessment of existing control design and operating effectiveness, then a "Residual risk within appetite?" evaluation, so the controls are credited only for what they actually do.
- A four-way treatment decision (reduce, transfer, avoid or accept) with acceptance routed through an approval at the right level rather than left as the default outcome.
- The close-out loop: a re-evaluation after treatment that returns to the treatment decision when residual risk is still too high, then a named risk owner and a review date before the entry is monitored.
When to use this template
- You are writing or revising a risk management procedure and need one picture of who identifies, who scores, who treats and who accepts.
- Risk scores vary depending on who ran the workshop, and you need the criteria and the appetite threshold applied the same way each time.
- An auditor or certification body has asked how risks are identified, assessed and treated, and you need a documented process rather than a spreadsheet of scores.
- Your risk register has entries with no owner and no review date, and you need the process to end in both.
- You are introducing risk-based thinking for ISO 9001, ISO 27001 or ISO 31000 and want the assessment cycle agreed before the register is populated.
How it works
Rename the lanes to your governance
Replace Process owner, Risk owner, Risk manager, Subject matter experts and Risk committee with the roles you have. In smaller organisations the risk manager and the committee are the same forum, and merging them is more honest than leaving a lane that meets once a year. Keep the risk owner distinct from the risk manager: one carries the risk, the other runs the process.
Write your scales and appetite onto the criteria step
Fill in the likelihood and impact definitions you actually use, including what each level means in money, time or harm, and state the threshold above which a risk must be treated rather than accepted. Criteria that live in a separate policy get approximated from memory, which is the mechanism by which two assessors reach different scores from the same facts.
Set the identification method and who attends
Decide how risks are surfaced — workshop, interviews, a checklist, incident and audit history — and who has to be in the room. Identification done by one person at a desk misses the risks that only the people doing the work can see, and no amount of careful scoring later compensates for a risk nobody wrote down.
Score inherent risk before crediting controls
Keep the inherent and residual scores as separate steps, as the chart does. Scoring only the residual position hides how much of your safety margin depends on a single control, and it makes the register useless the moment that control changes. Rate control design and operating effectiveness separately: a well-designed control nobody performs is worth nothing.
Name the approval level for accepting a risk
Acceptance is a legitimate treatment and the most abused one, because it is also what happens when nobody acts. Write down who may accept a risk at each score band, and require the acceptance to be recorded against a name. That single rule is what stops the register filling with risks that were accepted by default.
Set review triggers, then keep the map versioned
Choose a review cadence per score band and add event triggers — an incident, a supplier change, a new system, an audit finding. Record the review date on the register entry rather than in someone's calendar. Keep the process diagram itself under version control and capture its approval, so assessors and reviewers work from the same agreed method.
Frequently asked questions
What are the steps in a risk assessment process?
Establish the scope and the criteria, identify risks, describe each one as cause, event and consequence, analyse likelihood and impact, evaluate the residual position against your appetite, choose a treatment, and set an owner and a review date. ISO 31000 groups the middle three as risk assessment — identification, analysis, evaluation — with treatment following. The order is what makes the results comparable: criteria before scoring, description before analysis, and evaluation before anyone starts proposing controls.
What is the difference between inherent and residual risk?
Inherent risk is the exposure before existing controls are credited; residual is what remains after them. Scoring both is what makes the controls visible — a risk with a high inherent score and a low residual one is being held down by something, and if that something is a single manual check performed by one person, you want to know. Registers that record only residual scores look reassuring and cannot tell you which controls are load-bearing.
What are the four risk treatment options?
Reduce (add or strengthen controls), transfer (insurance, contractual terms, outsourcing), avoid (stop or change the activity), and accept (carry the risk knowingly). Accept is a real option and needs an approver: the difference between accepting a risk and ignoring one is a named person with the authority to carry it and a record that they did. Transfer is the option most often overstated — insurance moves financial consequence, rarely operational or reputational consequence.
How often should a risk assessment be reviewed?
On a cadence set by the score, plus event triggers. Annually is a common baseline for lower-scored risks, quarterly or more often for those near the appetite threshold. The triggers matter more than the calendar: a new supplier, a system change, an incident, a regulatory change or an audit finding should each pull the affected entries forward. A register reviewed only on schedule is accurate on the day it is written and drifts quietly for the rest of the year.