Workflow Template
Risk Assessment Workflow
End-to-end risk assessment workflow covering risk identification, causes and consequences, existing controls, likelihood and impact scoring, risk rating, treatment planning, owner assignment, approval, residual risk evaluation, and periodic monitoring review.
This workflow is designed for risk managers, compliance teams, and business unit leaders who need a structured, auditable process for identifying and treating operational, strategic, or enterprise risks. It automates the full risk lifecycle — from initial record creation and inherent risk scoring through management approval, treatment planning, residual risk evaluation, and scheduled periodic review. The result is a consistent, governed process that reduces manual coordination, ensures no risk falls through the cracks, and produces a clear audit trail for regulators, boards, and internal stakeholders.
Business Outcomes
- Reduction in time from risk identification to approved treatment plan
- 100% of assessed risks routed to the correct approval tier based on inherent risk rating
- Auditable record of every scoring decision, approval, and treatment action
- Scheduled periodic reviews triggered automatically, eliminating calendar-based manual follow-up
- Consistent risk methodology applied across all business units and submitters
Workflow Steps
Steps
- 1Create Risk Assessment Recordcreate record
Creates a new risk assessment record and sets status to Open.
- 2Set Status to Openupdate record
Sets the initial status of the risk record to Open.
- 3Send Acknowledgement to Submittersend email
Notifies the submitter that their risk has been logged and is under assessment.
- 4Assess Risk: Controls, Likelihood & Impactcreate task
Risk analyst documents existing controls, rates inherent likelihood and impact, and records the inherent risk rating.
- 5Persist Inherent Risk Ratingupdate record
Saves the inherent risk rating and assessment details to the record.
- 6Route by Inherent Risk Rating
Routes High and Critical risks to management approval; Low and Medium proceed directly to treatment planning.
inherent_risk_rating: "Critical"→Request Management Approvalinherent_risk_rating: "High"→Request Management ApprovalDefault→Define Treatment Actions & Responsible Owners - 7Request Management Approvalrequest approvalrequires approval
Pauses workflow for management sign-off on High or Critical inherent risk ratings before treatment planning proceeds.
- 8Route on Management Approval
Approved risks proceed to treatment planning; rejected risks are returned to the analyst for re-assessment.
approval_status: "approved"→Define Treatment Actions & Responsible Ownersapproval_status: "rejected"→Return to Analyst for Re-assessmentDefault→Define Treatment Actions & Responsible Owners - 9Return to Analyst for Re-assessmentrestart from step
Restarts from the risk assessment task so the analyst can revise controls, likelihood, and impact ratings.
- 10Define Treatment Actions & Responsible Ownerscreate task
Risk owner documents treatment actions, assigns responsible owners, sets target dates, and records residual likelihood and impact.
- 11Persist Treatment Plan & Residual Riskupdate record
Saves treatment strategy, responsible owner, residual risk rating, and monitoring frequency to the record.
- 12Route by Residual Risk Rating
High or Critical residual risk requires a second management approval; Low or Medium proceeds to finalisation.
residual_risk_rating: "Critical"→Approve Residual Risk Acceptanceresidual_risk_rating: "High"→Approve Residual Risk AcceptanceDefault→Finalise & Close Risk Assessment - 13Approve Residual Risk Acceptancerequest approvalrequires approval
Management must formally accept or reject the residual risk level before the assessment is closed.
- 14Route on Residual Risk Approval
Approved residual risk proceeds to finalisation; rejected returns to treatment planning for revision.
approval_status: "approved"→Finalise & Close Risk Assessmentapproval_status: "rejected"→Return to Treatment Planning for RevisionDefault→Finalise & Close Risk Assessment - 15Return to Treatment Planning for Revisionrestart from step
Restarts from treatment planning so the risk owner can revise actions and residual risk estimates.
- 16Finalise & Close Risk Assessmentupdate record
Sets the record status to Active Monitoring and notifies the submitter that the assessment is complete.
- 17Notify Submitter of Completed Assessmentsend email
Emails the submitter with the final risk rating, treatment strategy, and monitoring frequency.
- 18Schedule Periodic Review Taskcreate task
Creates a recurring review task for the risk owner to confirm the treatment actions remain effective and the risk rating is current.
- 19Persist Review Outcomeupdate record
Saves the review outcome and treatment status to the record.
- 20Route on Review Outcome
Routes to re-assessment loop, risk closure, or continues monitoring based on the review outcome.
review_outcome: "Re-assess Risk"→Trigger Full Re-assessmentreview_outcome: "Close Risk"→Close Risk AssessmentDefault→Continue Monitoring — Schedule Next Review - 21Continue Monitoring — Schedule Next Reviewrestart from step
Restarts from the periodic review task to schedule the next monitoring cycle.
- 22Trigger Full Re-assessmentrestart from step
Restarts from the risk assessment task to conduct a full re-assessment of controls, likelihood, and impact.
- 23Close Risk Assessmentupdate record
Sets the record status to Closed and notifies the submitter that the risk has been formally closed.
- 24Notify Submitter of Risk Closuresend email
Emails the submitter confirming the risk has been formally closed.
Fields
- Submitter Name*
- Submitter Email*
- Risk Title*
- Risk Category*
- Risk Description*
- Causes of Risk*
- +19 more fields
Forms
Risk Identification & Submission Form
9 fields
Data Views
Risk Register
risk_title, risk_category, business_unit, inherent_risk_rating +5 more
Dashboard Widgets
Recommended integrations
Setup the following integrations to extend workflow capability.
Send email in the workflow
AWS SES
Similar Categories
FAQs
Why should our organisation formalise this process with a structured workflow rather than managing risk assessments in spreadsheets or email?
Spreadsheets and email chains create version-control problems, missed approvals, and gaps in the audit trail that expose the organisation to regulatory and governance risk. A structured workflow in assess.one enforces a consistent methodology at every step — scoring, routing, approval, and review — so the process is repeatable regardless of who submits a risk. Every action is timestamped and attributed, giving risk committees and auditors a complete, reliable record without manual compilation.
What is the ROI of automating a business risk assessment process?
The primary gains are speed and reliability: risks that previously took days to route for approval and treatment planning can move through the full cycle in hours, because notifications, routing, and escalations happen automatically. Secondary gains include reduced analyst time spent on administrative coordination, fewer risks that stall or are forgotten between steps, and lower audit-preparation costs because the evidence trail is built into the workflow itself. Organisations also reduce the cost of risk materialising due to delayed treatment decisions.
How does this workflow handle risks of different severity levels?
After the analyst scores likelihood and impact, the workflow calculates and persists the inherent risk rating, then routes the assessment automatically based on that rating — for example, sending high-rated risks directly to senior management approval while lower-rated risks follow a lighter-touch path. The same logic applies after treatment planning: the residual risk rating determines whether a formal residual risk acceptance approval is required before the assessment can be finalised. This tiered routing ensures governance effort is proportionate to actual risk exposure.
What happens if management rejects the initial risk assessment or the treatment plan?
The workflow includes explicit rejection paths at both key approval gates. If management does not approve the initial assessment, the record is automatically returned to the analyst for re-assessment with the reviewer's comments attached. If the residual risk acceptance is not approved, the workflow routes back to treatment planning for revision. This creates a closed-loop process where no risk can be incorrectly closed out — every rejection generates a documented revision cycle.
How long does it take to implement this workflow?
Publishing the workflow in assess.one takes minutes — you select the template, configure your roles, approval thresholds, and notification preferences directly in the platform, and it is live immediately. There is no software installation, no external development project, and no weeks-long implementation cycle. Your team can run the first live risk assessment the same day.
How can we customise the workflow to match our organisation's risk framework and rating scales?
All steps, scoring criteria, routing logic, role assignments, and notification content are configurable directly inside assess.one without writing code. You can adjust the likelihood and impact scales to match your existing risk matrix, define the rating thresholds that trigger each approval route, and assign steps to specific roles or named individuals. Customisation is done through the platform's workflow editor and takes effect immediately when you republish.
Who needs access to the workflow, and how are roles managed?
Typical roles include the risk submitter who creates the initial record, the risk analyst who performs scoring and treatment planning, the manager or risk committee member who approves at each gate, and a risk owner who is assigned responsibility for treatment actions. Roles are defined and managed inside assess.one, and each step is configured to notify and assign the correct role automatically. You control who can view, edit, or approve each stage without needing IT involvement.
How does the periodic review step work, and how does it connect back to the main assessment?
Once a risk assessment is finalised and closed, the workflow automatically schedules a periodic review task based on the review interval you configure. When the review is due, the assigned owner is notified and completes the review outcome inside assess.one. The workflow then routes based on that outcome — for example, confirming the risk remains adequately controlled, escalating it for re-assessment, or triggering a new treatment cycle — so the risk record remains current and the review history is fully documented.
Does this workflow support compliance with risk management standards such as ISO 31000?
The workflow structure aligns with the core risk management process defined in ISO 31000 and similar enterprise risk frameworks, covering identification, analysis, evaluation, treatment, and monitoring. Because every step, decision, and approval is recorded with a timestamp and attributed user, the platform produces the documented evidence that standards and regulators require. Your compliance or internal audit team can review the full history of any risk record directly in assess.one.
Can the workflow notify stakeholders outside the immediate risk team?
Yes — assess.one supports email and Slack notifications that are configured inside the platform, so you can notify submitters when their assessment is acknowledged or completed, alert risk owners when treatment actions are assigned, and inform senior stakeholders when high-rated risks reach the approval stage. All notification logic is set up within assess.one and requires no third-party development work.
Ready to use this workflow?
Create a free account and customise this workflow for your business.
