Risk management is a disciplined way to make decisions when outcomes are uncertain. It begins with a clear objective, identifies what could affect it, decides what matters most, and follows through on action and review.
Begin with the objective
A risk only has meaning in relation to an objective. State what the organization, team, service, or project is trying to achieve, the relevant time period, boundaries, assumptions, and stakeholders. This prevents a register from becoming a disconnected catalogue of worries.
Use a repeatable cycle
- Set the context and define objectives.
- Identify uncertain events, conditions, causes, and consequences.
- Assess likelihood, impact, and existing controls.
- Compare exposure with agreed criteria or appetite.
- Choose treatment, assign ownership, and set dates.
- Monitor indicators, incidents, changes, and treatment progress.
- Review results and improve the process.
Keep the record useful
A short, current register with clear owners is more valuable than a large register nobody uses. Each entry should be understandable to someone outside the original workshop. Keep existing controls separate from planned actions and record the next review date.
Know where this site stops
Choose your next step
- New to risk management: read the process and identification guides.
- Building a register: use the register guide and browser-based builder.
- Improving oversight: read appetite, governance, ownership, and indicators.
- Running a review: use the workshop and audit guides.
A small example
Suppose a team must launch a new customer service process before a seasonal peak. Its objective is not simply “launch the process”; it is to launch on time while maintaining service quality and protecting customer information. Risks might include incomplete training, unclear ownership, software instability, or demand exceeding assumptions. Each risk can then be linked to an owner, current controls, planned actions, and a review date.
Keep the first version proportionate
A new risk process does not need a complex scoring model. Begin with a handful of agreed likelihood and impact descriptions, a short register, and a regular review. Add detail only when it helps a real decision. Highly regulated, safety-critical, or technically complex work may require specialist methods, but more fields and formulas do not automatically produce better judgment.
Questions for the first review
- Which objective or decision is each risk connected to?
- What evidence supports the current assessment?
- Which controls already exist, and are they actually operating?
- Who can approve acceptance or additional resources?
- What change or threshold should trigger an earlier review?