How a Risk Assessment Session Actually Runs
Someone told you to do a risk assessment. A customer asked for one. A standard requires it. An auditor wrote a finding.
So a room got booked, the people who seemed relevant got invited, a template got opened, and rows got filled.
What came out was a list of things the room was already worried about.
That is the predictable output of an unstructured session, and it is not a failure of the people in it. It is a failure of sequence. A risk assessment run without a defined purpose produces an inventory of existing anxiety — competently identified, thoroughly discussed, and silent on everything nobody had thought of yet.
What follows is the sequence I run, and the decisions inside it that determine whether the output is a register or a receipt.
Purpose, objectives, context, and scope come first
Before anyone is invited and before any tool is opened: what is this assessment for?
The answer is rarely generic, because the trigger rarely is. The assessments I facilitate come from a short list of contexts:
A new quality or information security management system
A new product introduction
A new supplier
A new process
A change to any of the above
Those are not the same assessment. A new medical device and a new vendor share a method and almost nothing else — different risk domains, different expertise in the room, different criteria, different duration. Change earns its own line on that list precisely because it is the trigger most organizations do not treat as one.
Scope does the same work from the other direction. What is inside the boundary, what is outside, and what sits at the edge — the same boundary discipline a structured gap assessment depends on. Interfaces are where risk hides, and an unstated boundary means nobody goes looking at them.
Every decision downstream derives from this step. Get it wrong and the rest of the session is well-executed work aimed at the wrong target.
The room is derived, not assembled
Most organizations treat the invite list as the first decision. It is the second, and it falls out of the scope almost mechanically.
For a new medical device, the scope implies the room. R&D, who likely brought the concept. Design and engineering. Manufacturing at a high level, for the producibility concerns that otherwise surface late and expensively. Regulatory affairs and quality management. Each is present because the scope named a domain they own, and in a regulated device environment the expectations for who participates and what gets documented are already set by the risk management framework the product lifecycle runs on.
For a first management system, the shape is different. Process- or function-based sessions keep the discussion inside one theme of risk, which keeps it productive. A room trying to assess purchasing risk and product design risk in the same hour does neither well.
Those sessions still need system-level representation alongside the process owners. Process-level participants are structurally blind past their own boundary, so someone has to be positioned to flag, preliminarily, that a risk named in one function lands in another.
The rule underneath all of it: the people closest to the process. Distance from the work introduces mistranslation. Ask a manager two levels up how a process runs and you get an accurate description of how it was designed. Ask the person running it and you get how it runs. Both are useful. Only one of them tells you where it breaks.
The seeding decision
There is a real judgment call before the session opens, and it is the one I have changed my approach on most.
Can this room generate cold?
Some can. Put the question in front of them and they fill a wall. Those rooms are best left alone at the start, because anything you hand them first becomes the frame they think inside.
Some cannot. A blank wall produces a long silence, then two obvious risks, then more silence — and that silence gets recorded as "we don't really have many risks here," which is the most expensive misreading available.
When a room needs road to run on, I will run a preliminary scan against the stated purpose, context, and scope to produce a full spread of candidate risks. Not the eighty percent everyone already fears. The full spread, including categories nobody in the room would have volunteered.
What does not happen either way: nothing gets circulated in advance. The scan enters inside the session, under facilitation, where it can be worked. Sent out as pre-reading, it stops being a provocation and becomes a form to complete.
Open capture before instruments
The session opens on what is already swirling.
Not scored. Not sorted against a framework. Captured — individual risks and the buckets they cluster into, in whatever order they arrive. The room has been carrying these concerns, often for months. Getting them out is useful data, and it is also what lets people participate in the rest of the session rather than waiting for their turn to say the thing they came in to say.
Then criteria.
Risk scoring criteria get defined against the purpose, context, and scope of this assessment, if they do not already exist in usable form — which, in organizations running a formal risk management framework, they sometimes do. This is where a lot of programs quietly fail. A generic five-by-five matrix inherited from a template means the same thing everywhere, which means it means nothing in particular anywhere. A moderate impact rating for a new supplier and a moderate impact rating for a device design decision are not comparable, and pretending they are is how registers become uninterpretable a year later.
Defining the ruler is not the same as measuring with it. Criteria can exist well before anything gets a number.
Nothing enters in the shape it arrived in
Whether a risk came from the room or from a scan, it is not a register entry yet. It is a candidate.
The work is shaping it and fitting it to the business. What does this actually look like here, in this operation, given how this process runs and who runs it? The room vets for applicability, criticality, and inclusion — out loud, because the engagement is the mechanism. A risk the room has genuinely realized is one they will act on. A risk they nodded at stays a sentence.
This is also where seeded risks earn their place. A listed risk that does not itself apply will frequently trigger an adjacent one that does. The value of the scan is not the items it produces. It is the thinking it provokes.
Facilitation judgment is what moves the room forward: recognizing when a risk has taken proper and applicable shape and the group can move on, versus when they have accepted a generic phrase because it sounded reasonable. That judgment is the part of this method that does not transfer through a template, and it is the honest limit of what a written sequence can hand you.
The tell is simple enough to check afterward, though. A generic risk that survived the session unchanged is one nobody engaged with.
Scoring goes last, and it is quiet
When criteria are defined and useful, scoring takes almost no argument.
That surprises people who have sat through consensus fights over whether something is a three or a four. Those fights are not disagreements about risk. They are symptoms of criteria that were never really defined — the room negotiates a number because there is no definition to read one off.
My role during scoring is narrow. Insight gaps. If there is a gap in logic, or an assessment that does not hold against what the room established an hour earlier, I raise it and hand it back. The group reviews and revises.
Not override. The output has to be theirs, because they are the ones who will live with it after the session ends. A score I imposed is one they will quietly ignore.
Scoring last also prevents the room from reverse-engineering the answer. A group that knows the number before the discussion will produce a discussion that justifies the number.
What comes out, and the room that comes next
The session produces a register: risks, owners, next steps. Owners named in the room, not assigned by email three days later.
Then treatments, which is a separate act of definition and frequently a different room.
The people who can identify a risk are not always the people who will implement and sustain the control that addresses it. Treatment definition needs process and operational stakeholders from where the treatment will actually live — the ones who will still be running it after project attention moves elsewhere. Sometimes that is the same group in the same session. Often it is a follow-up with different people at the table, and where the risk originated under enterprise risk oversight it is almost always a different room entirely.
That handoff is where a risk stops being named and starts being managed. A treatment defined by people who will never operate it produces exactly the register entry everyone recognizes: a control described in the past tense, in progress for eighteen months.
A diagnostic you can run this week
Take the last risk assessment your organization ran and answer two questions.
First: what was the stated purpose, and can anyone still find it in writing?
Second: pick any three entries on the register that came out of it. Were all three already in someone's head before the session started?
If the purpose is unrecoverable, the room was assembled without a target. If all three were already known concerns, the session captured what your organization was already worried about — which is worth doing, and is not a risk assessment.