All posts
Continuous Compliance8 min readAug 16, 2026

Risk assessment

Ashish / CEO/Co-Founder
Risk assessment

A risk assessment is a structured way to identify what could go wrong, estimate how likely it is and how serious it would be, decide what controls are needed, and record when the decision should be reviewed. In risk management, NIST describes risk assessment as a way to give decision-makers information they can use to choose an appropriate response to identified risks, although its guidance is written for information systems rather than, or more accurately not as, a universal legal rule (NIST SP 800-30 Rev. 1).

This guide covers a general organisational risk assessment. It is useful for business operations, governance, risk and compliance, projects, vendors and internal processes. It is not a substitute for legal, safety, public-health, clinical or industry-specific advice where specialist rules apply.

What Is a Risk Assessment?

A risk assessment connects four questions:

  1. What could happen?
  2. Why might it happen?
  3. How bad would it be, and how likely is it?
  4. What will we do about it, who owns it, and when will we review it?

The output is usually a documented assessment or risk register entry. Not complicated, but clear enough that someone else can understand the risk, the reasoning behind the rating, the controls in place and the remaining exposure.

Why Risk Assessments Matter

Risk assessments help organisations prioritise limited time, money and attention. Without an assessment, teams often treat all issues as equally urgent or lean on informal judgement that is hard to explain later.

A useful assessment clarifies:

  • the activity, process, system or vendor being assessed
  • the event or condition that could cause harm, disruption, loss or non-compliance
  • the controls already in place
  • the remaining exposure after those controls
  • who is responsible for action and review

They can be useful before launching a new process, changing a system, onboarding a vendor, entering a new market, or responding to an incident. In a GRC setting, the value is not just the score; it is the working record that links risks to owners, controls, evidence and review decisions.

Ciphrix’s view is that risk assessment works best when it is connected to how the organisation actually operates: controls should map to real activities, evidence should be maintained, and review should happen when conditions change, not only when a spreadsheet is revisited.

The Five Basic Steps of a Risk Assessment

A general risk-management process can identify causes and consequences, analyse controls and ratings, treat risk, monitor and review, and record outcomes (Victorian Department of Education). For a basic organisational assessment, use this five-step sequence.

1. Identify the risk

Describe the risk as an event or condition, not just a topic.

Weak: “Vendor risk”
Better: “A critical third-party provider outage prevents customers from accessing the service.”

Include the cause or source where possible, this makes the assessment more actionable. “Reliance on one provider with limited failover” gives a team more to work with than “service disruption.”

2. Assess likelihood and impact

Estimate:

  • Likelihood: how probable the event is.
  • Impact: how serious the consequence would be if it occurred.

Use the same scale consistently across assessments. A simple low, medium and high scale is often enough for a first pass. More complex scoring may be needed for regulated, safety-critical or technical contexts.

3. Choose controls

Controls are measures intended to reduce exposure, improve detection, support response, or limit the consequence if the event occurs. Examples include approvals, monitoring, training, segregation of duties, backups, contractual clauses, incident procedures or technical safeguards.

Assess both existing controls and any additional treatment actions. Do not assume a control works because it exists; record whether it is implemented, owned and reviewable.

4. Document the assessment

Record the risk, cause, impact, ratings, controls, owner, decision and review date. Documentation makes the assessment usable by people who were not in the original discussion and gives future reviewers a baseline.

5. Review and update

A risk assessment is not finished forever, review it when the situation changes, when a control fails, when an incident occurs, or when the scheduled review date arrives. In workplace health and safety, for example, Safe Work Australia describes risk management as identifying hazards, assessing risks, controlling risks and reviewing controls to check they work as planned (Safe Work Australia).

What a Risk Assessment Should Include

For this guide, use these practical fields. They are not a universal regulatory template, but they cover the information most teams need to make and revisit a decision.

  • Activity, process, system, vendor or asset being assessed
  • Risk description
  • Cause or source of the risk
  • Potential impact or consequence
  • Inherent likelihood rating
  • Inherent impact rating
  • Inherent risk rating
  • Existing controls
  • Additional controls or treatment actions
  • Residual likelihood rating
  • Residual impact rating
  • Residual risk rating
  • Risk owner
  • Review date or review trigger
  • Decision or status, such as accept, reduce, transfer or monitor, where relevant

How Likelihood, Impact, Controls and Residual Risk Work

A practical assessment can consider existing controls, consequence if the event occurs and likelihood; a matrix can then be used to determine a rating (Victorian Department of Education). The matrix below is illustrative only. Use a scale your organisation can apply consistently.

Impact \ LikelihoodLow likelihoodMedium likelihoodHigh likelihood
Low impactLowLowMedium
Medium impactLowMediumHigh
High impactMediumHighVery High

Key terms:

  • Likelihood means how probable the risk event is.
  • Impact or consequence means how serious the outcome would be if it happened.
  • Inherent risk is the assessed level before considering current controls.
  • Controls are measures intended to reduce exposure, improve response, or limit consequences.
  • Residual risk is the assessed level remaining after existing controls are considered.

For example, a vendor outage might be assessed as High likelihood / High impact before controls if the organisation relies on one provider with no tested workaround. If monitoring, escalation procedures, contractual recovery commitments and an alternative process are in place, the residual assessment might become Medium likelihood / Medium impact. That does not mean the risk is gone; it means the remaining exposure has been reassessed after controls.

Completed Risk Assessment Example

This example is a general business/GRC scenario, not a regulatory standard or universal template.

FieldExample entry
Activity / processCustomer-facing service supported by a third-party provider
RiskCritical vendor outage affects customer-facing service
Cause / sourceReliance on one third-party provider for a key service component
Potential impactService disruption, customer support volume increase, contractual or operational consequences
Inherent likelihoodHigh
Inherent impactHigh
Inherent ratingVery High
Existing controlsVendor service agreement; uptime monitoring; incident escalation path; internal service-status communications
Additional controls / treatment actionsTest outage response procedure; confirm recovery contacts quarterly; document manual workaround for priority customers; review concentration risk during renewal
Residual likelihoodMedium
Residual impactMedium
Residual ratingMedium
OwnerHead of Operations
Review date / triggerReview in six months, or sooner after a vendor incident, contract change, control failure or major service change
Decision / statusReduce and monitor

The important point is the movement from inherent to residual risk. The initial assessment shows the exposure before controls are considered. The residual rating shows the remaining exposure after current and planned controls are taken into account. If the residual rating is still outside the organisation’s tolerance, further treatment or a different business decision may be needed at that point.

When to Review or Update a Risk Assessment

Review when a material change, incident, control failure, or scheduled date calls for it. Common triggers include:

  • a process, system, vendor, location or activity changes
  • a new risk is identified
  • an incident, near miss, outage or control failure occurs
  • regulations, customer requirements or operating conditions change
  • controls are added, removed or found ineffective
  • the scheduled review date arrives

Each assessment should have an owner. The owner does not have to perform every control personally, but they should be accountable for keeping the assessment current, coordinating current treatment actions and escalating decisions when residual risk remains too high.

When You Need a Specialist Risk Assessment

The general method is useful, but some contexts require specific terminology, evidence, scoring models, professional judgement or legal analysis.

  • Workplace health and safety: In Australia, Safe Work Australia states that eliminating risk is preferred and, where that is not possible, risks must be minimised so far as is reasonably practicable using the hierarchy of controls (Safe Work Australia). Other jurisdictions may differ.
  • Cybersecurity or vendor security: Security and privacy assessments may need technical control catalogues, threat modelling, assurance evidence or continuous monitoring. NIST’s Risk Management Framework addresses security and privacy risk management for systems and organisations (NIST SP 800-37 Rev. 2).
  • Public health emergencies: WHO describes acute public-health risk assessment as a systematic, continuous process for gathering, evaluating and documenting information to manage public-health threats (WHO).
  • Schools, laboratories and field activities: These may be subject to activity-specific rules, approvals or supervision requirements.
  • ISO or framework-specific risk management: ISO 31000 provides principles, a framework and a process for managing risk across sectors, but it is guidance and cannot itself be used for certification (ISO).
  • Projects: Project risk assessments may need schedule, budget, dependency and delivery-impact analysis.
  • Clinical or therapeutic contexts: These are outside the scope of a general organisational assessment and should use appropriate professional methods.

A basic risk assessment is most useful when it connects risks, controls, owners and review triggers. If the context carries legal, safety, technical or professional consequences, use the general structure as a starting point—not as the final authority.

Get started

Ready to see Ciphrix in action?

Built by AWS Security Leaders | AWS Partner | Certified companies across 3 continents