Risk assessment process flowchart

Risk assessment process flowchart covering scope and criteria, risk identification, likelihood and impact scoring, control effectiveness, the four treatment options and the review cycle.

How it works

  1. Rename the lanes to your governance

    Replace Process owner, Risk owner, Risk manager, Subject matter experts and Risk committee with the roles you have. In smaller organisations the risk manager and the committee are the same forum, and merging them is more honest than leaving a lane that meets once a year. Keep the risk owner distinct from the risk manager: one carries the risk, the other runs the process.

  2. Write your scales and appetite onto the criteria step

    Fill in the likelihood and impact definitions you actually use, including what each level means in money, time or harm, and state the threshold above which a risk must be treated rather than accepted. Criteria that live in a separate policy get approximated from memory, which is the mechanism by which two assessors reach different scores from the same facts.

  3. Set the identification method and who attends

    Decide how risks are surfaced — workshop, interviews, a checklist, incident and audit history — and who has to be in the room. Identification done by one person at a desk misses the risks that only the people doing the work can see, and no amount of careful scoring later compensates for a risk nobody wrote down.

  4. Score inherent risk before crediting controls

    Keep the inherent and residual scores as separate steps, as the chart does. Scoring only the residual position hides how much of your safety margin depends on a single control, and it makes the register useless the moment that control changes. Rate control design and operating effectiveness separately: a well-designed control nobody performs is worth nothing.

  5. Name the approval level for accepting a risk

    Acceptance is a legitimate treatment and the most abused one, because it is also what happens when nobody acts. Write down who may accept a risk at each score band, and require the acceptance to be recorded against a name. That single rule is what stops the register filling with risks that were accepted by default.

  6. Set review triggers, then keep the map versioned

    Choose a review cadence per score band and add event triggers — an incident, a supplier change, a new system, an audit finding. Record the review date on the register entry rather than in someone's calendar. Keep the process diagram itself under version control and capture its approval, so assessors and reviewers work from the same agreed method.

Frequently asked questions

What are the steps in a risk assessment process?

Establish the scope and the criteria, identify risks, describe each one as cause, event and consequence, analyse likelihood and impact, evaluate the residual position against your appetite, choose a treatment, and set an owner and a review date. ISO 31000 groups the middle three as risk assessment — identification, analysis, evaluation — with treatment following. The order is what makes the results comparable: criteria before scoring, description before analysis, and evaluation before anyone starts proposing controls.

What is the difference between inherent and residual risk?

Inherent risk is the exposure before existing controls are credited; residual is what remains after them. Scoring both is what makes the controls visible — a risk with a high inherent score and a low residual one is being held down by something, and if that something is a single manual check performed by one person, you want to know. Registers that record only residual scores look reassuring and cannot tell you which controls are load-bearing.

What are the four risk treatment options?

Reduce (add or strengthen controls), transfer (insurance, contractual terms, outsourcing), avoid (stop or change the activity), and accept (carry the risk knowingly). Accept is a real option and needs an approver: the difference between accepting a risk and ignoring one is a named person with the authority to carry it and a record that they did. Transfer is the option most often overstated — insurance moves financial consequence, rarely operational or reputational consequence.

How often should a risk assessment be reviewed?

On a cadence set by the score, plus event triggers. Annually is a common baseline for lower-scored risks, quarterly or more often for those near the appetite threshold. The triggers matter more than the calendar: a new supplier, a system change, an incident, a regulatory change or an audit finding should each pull the affected entries forward. A register reviewed only on schedule is accurate on the day it is written and drifts quietly for the rest of the year.

Use this template

Guides that use this template

More in Quality and compliance process templates

More in Process map templates

Browse all Quality and compliance process templates