Partial Mitigation Looks Exactly Like Risk Management
Most organizations that call and say they need a risk assessment already have one. It just isn't written down.
Ask a plant manager or a founder what could go sideways in the next year and you'll get a straight answer in about ninety seconds. Too few trained people in one division. A single supplier with no second source. One person who knows how the closeout process actually works. These are known, socialized, and often already worked around. What's missing isn't awareness. It's a place where those risks live, get revisited, and show movement over time.
So the first phase of building a risk assessment process is rarely discovery. It's transcription — writing down what the organization already knows, in one place, in a consistent form.
The second phase is where the work starts.
Inventory the controls, not just the risks
For every risk on the list, the question is what already exists to control it. Not what should exist. What's actually in place today.
That inventory produces a map, and the map has shape to it. Coverage isn't evenly distributed. A risk that everyone agrees is serious will have three controls pointed at one contribution path and nothing pointed at the other four.
Take the thin-training risk. The organization has probably done something about it — cross-trained two people, maybe. That's a control. But whether the procedure reflects the new arrangement, whether the shift handoff communicates who's qualified on what, whether anyone was formally assigned ownership of maintaining the training matrix, whether the change was documented at all — those are contribution paths, and they run through how work actually flows. They're frequently empty. This is the same seam problem that surfaces in business process consulting engagements: the gap isn't inside a step, it's between them.
The risk was understood. Its full contribution through the organization was not.
Why the gap hides itself
The intuitive assumption is that an unmitigated contribution path will eventually announce itself. Something will fail, the failure will be investigated, and the missing control will surface.
That's not what happens, and the reason is uncomfortable.
Partial controls work. Not completely, but partially — which is precisely the problem. A risk with three of seven contribution paths controlled doesn't sit dormant and then detonate. It leaks. It materializes more slowly, with less consequence, in a form small enough that the organization absorbs it without escalating.
And an absorbed failure reads as a success. Something went wrong, it wasn't catastrophic, the controls must be working.
So the incident never gets a root cause investigation. The missing control never surfaces. The exposure sits there, real and live, wearing the best disguise a risk can wear: evidence that it's being handled.
This is why “we'll learn from incidents” doesn't close the gap. Incident review only catches what escalated. The paths that produce quiet, tolerable, recurring problems are structurally invisible to it — and those are the same paths that are one bad day away from producing a loud one.
The register as a prompt, not a ledger
The fix isn't a better template or a written risk procedure. It's structuring the cognitive work of whoever is doing the assessment.
Informal thinking about risk is partial by nature. It reaches for the obvious control and stops, because the obvious control feels like the answer. Structure is what forces the other four.
A register that works has prompting built into it. This is the practical core of what ISO 31000 and structured risk management describe as a framework rather than a document. When you're considering controls for a given risk, the assessor gets walked through the full organizational set:
Training. What competence does this require, who needs it, and how is it verified?
Communication. Who needs to know, when, and through what channel?
Documentation. What procedure, form, or record has to change for this control to be real?
Roles and responsibilities. Who owns this now, and who decides when it's exceeded?
Change. What has to be different in how the work runs, not just in what's written about it?
None of this requires a formal procedure document. It requires that the person doing the assessment be walked through the same set of questions every time, so that coverage gaps become visible on the page rather than in production.
That's the diagnostic. Uneven control coverage is legible evidence of incomplete risk understanding, and it's visible before anything materializes. It's also the mechanism that connects operational risk work to the risk-based thinking ISO 9001 introduces at Clause 6 — the requirement is to address risks and opportunities, not to inventory them.
A note on tools
None of this is an argument against FMEA, or against any structured method. FMEA is a tool, and like any tool it can be used well or badly. Run it with shallow thinking and you get exquisitely scored failure modes with the same coverage gaps as a spreadsheet. Run it with structured prompting and it digs.
The rigor of the tool doesn't substitute for the completeness of the thinking behind it. It inherits whatever the assessor brought. The same holds one level up: an enterprise risk management program with a beautiful governance structure and shallow control inventories underneath it has the same problem at a larger scale, which is why integrated risk management is worth the effort only when the thinking underneath each risk is complete.
Where to start
Pick the three risks your leadership team would name without hesitation. For each one, write down every control that exists today — actual, not intended.
Then walk each one through training, communication, documentation, roles and responsibilities, and change.
The empty cells are your answer.
If the exercise surfaces more empty cells than you expected, that's a scoping problem rather than a failure — and it's the point at which structured risk management consulting or a broader ISO gap assessment becomes worth the cost, because you now know what you're buying.