assess.one – AI-powered business operations platform

Workflow Template

Risk Assessment Workflow

End-to-end risk assessment workflow covering risk identification, causes and consequences, existing controls, likelihood and impact scoring, risk rating, treatment planning, owner assignment, approval, residual risk evaluation, and periodic monitoring review.

This workflow is designed for risk managers, compliance teams, and business unit leaders who need a structured, auditable process for identifying and treating operational, strategic, or enterprise risks. It automates the full risk lifecycle — from initial record creation and inherent risk scoring through management approval, treatment planning, residual risk evaluation, and scheduled periodic review. The result is a consistent, governed process that reduces manual coordination, ensures no risk falls through the cracks, and produces a clear audit trail for regulators, boards, and internal stakeholders.

Business Outcomes

  • Reduction in time from risk identification to approved treatment plan
  • 100% of assessed risks routed to the correct approval tier based on inherent risk rating
  • Auditable record of every scoring decision, approval, and treatment action
  • Scheduled periodic reviews triggered automatically, eliminating calendar-based manual follow-up
  • Consistent risk methodology applied across all business units and submitters

Workflow Steps

Steps

  1. 1
    Create Risk Assessment Recordcreate record

    Creates a new risk assessment record and sets status to Open.

  2. 2
    Set Status to Openupdate record

    Sets the initial status of the risk record to Open.

  3. 3
    Send Acknowledgement to Submittersend email

    Notifies the submitter that their risk has been logged and is under assessment.

  4. 4
    Assess Risk: Controls, Likelihood & Impactcreate task

    Risk analyst documents existing controls, rates inherent likelihood and impact, and records the inherent risk rating.

  5. 5
    Persist Inherent Risk Ratingupdate record

    Saves the inherent risk rating and assessment details to the record.

  6. 6
    Route by Inherent Risk Rating

    Routes High and Critical risks to management approval; Low and Medium proceed directly to treatment planning.

    inherent_risk_rating: "Critical"Request Management Approval
    inherent_risk_rating: "High"Request Management Approval
    DefaultDefine Treatment Actions & Responsible Owners
  7. 7
    Request Management Approvalrequest approvalrequires approval

    Pauses workflow for management sign-off on High or Critical inherent risk ratings before treatment planning proceeds.

  8. 8
    Route on Management Approval

    Approved risks proceed to treatment planning; rejected risks are returned to the analyst for re-assessment.

    approval_status: "approved"Define Treatment Actions & Responsible Owners
    approval_status: "rejected"Return to Analyst for Re-assessment
    DefaultDefine Treatment Actions & Responsible Owners
  9. 9
    Return to Analyst for Re-assessmentrestart from step

    Restarts from the risk assessment task so the analyst can revise controls, likelihood, and impact ratings.

  10. 10
    Define Treatment Actions & Responsible Ownerscreate task

    Risk owner documents treatment actions, assigns responsible owners, sets target dates, and records residual likelihood and impact.

  11. 11
    Persist Treatment Plan & Residual Riskupdate record

    Saves treatment strategy, responsible owner, residual risk rating, and monitoring frequency to the record.

  12. 12
    Route by Residual Risk Rating

    High or Critical residual risk requires a second management approval; Low or Medium proceeds to finalisation.

    residual_risk_rating: "Critical"Approve Residual Risk Acceptance
    residual_risk_rating: "High"Approve Residual Risk Acceptance
    DefaultFinalise & Close Risk Assessment
  13. 13
    Approve Residual Risk Acceptancerequest approvalrequires approval

    Management must formally accept or reject the residual risk level before the assessment is closed.

  14. 14
    Route on Residual Risk Approval

    Approved residual risk proceeds to finalisation; rejected returns to treatment planning for revision.

    approval_status: "approved"Finalise & Close Risk Assessment
    approval_status: "rejected"Return to Treatment Planning for Revision
    DefaultFinalise & Close Risk Assessment
  15. 15
    Return to Treatment Planning for Revisionrestart from step

    Restarts from treatment planning so the risk owner can revise actions and residual risk estimates.

  16. 16
    Finalise & Close Risk Assessmentupdate record

    Sets the record status to Active Monitoring and notifies the submitter that the assessment is complete.

  17. 17
    Notify Submitter of Completed Assessmentsend email

    Emails the submitter with the final risk rating, treatment strategy, and monitoring frequency.

  18. 18
    Schedule Periodic Review Taskcreate task

    Creates a recurring review task for the risk owner to confirm the treatment actions remain effective and the risk rating is current.

  19. 19
    Persist Review Outcomeupdate record

    Saves the review outcome and treatment status to the record.

  20. 20
    Route on Review Outcome

    Routes to re-assessment loop, risk closure, or continues monitoring based on the review outcome.

    review_outcome: "Re-assess Risk"Trigger Full Re-assessment
    review_outcome: "Close Risk"Close Risk Assessment
    DefaultContinue Monitoring — Schedule Next Review
  21. 21
    Continue Monitoring — Schedule Next Reviewrestart from step

    Restarts from the periodic review task to schedule the next monitoring cycle.

  22. 22
    Trigger Full Re-assessmentrestart from step

    Restarts from the risk assessment task to conduct a full re-assessment of controls, likelihood, and impact.

  23. 23
    Close Risk Assessmentupdate record

    Sets the record status to Closed and notifies the submitter that the risk has been formally closed.

  24. 24
    Notify Submitter of Risk Closuresend email

    Emails the submitter confirming the risk has been formally closed.

Fields

  • Submitter Name*
  • Submitter Email*
  • Risk Title*
  • Risk Category*
  • Risk Description*
  • Causes of Risk*
  • +19 more fields

Forms

Risk Identification & Submission Form

9 fields

Data Views

Risk Register

risk_title, risk_category, business_unit, inherent_risk_rating +5 more

Dashboard Widgets

Risk Register SummaryRisks by CategoryRisks by Inherent Rating

Recommended integrations

Setup the following integrations to extend workflow capability.

  • Send email in the workflow

    AWS SES logoAWS SES
riskassessmentcontrolstreatmentreviewgovernance

Similar Workflows

Similar Categories

FAQs

Why should our organisation formalise this process with a structured workflow rather than managing risk assessments in spreadsheets or email?

Spreadsheets and email chains create version-control problems, missed approvals, and gaps in the audit trail that expose the organisation to regulatory and governance risk. A structured workflow in assess.one enforces a consistent methodology at every step — scoring, routing, approval, and review — so the process is repeatable regardless of who submits a risk. Every action is timestamped and attributed, giving risk committees and auditors a complete, reliable record without manual compilation.

What is the ROI of automating a business risk assessment process?

The primary gains are speed and reliability: risks that previously took days to route for approval and treatment planning can move through the full cycle in hours, because notifications, routing, and escalations happen automatically. Secondary gains include reduced analyst time spent on administrative coordination, fewer risks that stall or are forgotten between steps, and lower audit-preparation costs because the evidence trail is built into the workflow itself. Organisations also reduce the cost of risk materialising due to delayed treatment decisions.

How does this workflow handle risks of different severity levels?

After the analyst scores likelihood and impact, the workflow calculates and persists the inherent risk rating, then routes the assessment automatically based on that rating — for example, sending high-rated risks directly to senior management approval while lower-rated risks follow a lighter-touch path. The same logic applies after treatment planning: the residual risk rating determines whether a formal residual risk acceptance approval is required before the assessment can be finalised. This tiered routing ensures governance effort is proportionate to actual risk exposure.

What happens if management rejects the initial risk assessment or the treatment plan?

The workflow includes explicit rejection paths at both key approval gates. If management does not approve the initial assessment, the record is automatically returned to the analyst for re-assessment with the reviewer's comments attached. If the residual risk acceptance is not approved, the workflow routes back to treatment planning for revision. This creates a closed-loop process where no risk can be incorrectly closed out — every rejection generates a documented revision cycle.

How long does it take to implement this workflow?

Publishing the workflow in assess.one takes minutes — you select the template, configure your roles, approval thresholds, and notification preferences directly in the platform, and it is live immediately. There is no software installation, no external development project, and no weeks-long implementation cycle. Your team can run the first live risk assessment the same day.

How can we customise the workflow to match our organisation's risk framework and rating scales?

All steps, scoring criteria, routing logic, role assignments, and notification content are configurable directly inside assess.one without writing code. You can adjust the likelihood and impact scales to match your existing risk matrix, define the rating thresholds that trigger each approval route, and assign steps to specific roles or named individuals. Customisation is done through the platform's workflow editor and takes effect immediately when you republish.

Who needs access to the workflow, and how are roles managed?

Typical roles include the risk submitter who creates the initial record, the risk analyst who performs scoring and treatment planning, the manager or risk committee member who approves at each gate, and a risk owner who is assigned responsibility for treatment actions. Roles are defined and managed inside assess.one, and each step is configured to notify and assign the correct role automatically. You control who can view, edit, or approve each stage without needing IT involvement.

How does the periodic review step work, and how does it connect back to the main assessment?

Once a risk assessment is finalised and closed, the workflow automatically schedules a periodic review task based on the review interval you configure. When the review is due, the assigned owner is notified and completes the review outcome inside assess.one. The workflow then routes based on that outcome — for example, confirming the risk remains adequately controlled, escalating it for re-assessment, or triggering a new treatment cycle — so the risk record remains current and the review history is fully documented.

Does this workflow support compliance with risk management standards such as ISO 31000?

The workflow structure aligns with the core risk management process defined in ISO 31000 and similar enterprise risk frameworks, covering identification, analysis, evaluation, treatment, and monitoring. Because every step, decision, and approval is recorded with a timestamp and attributed user, the platform produces the documented evidence that standards and regulators require. Your compliance or internal audit team can review the full history of any risk record directly in assess.one.

Can the workflow notify stakeholders outside the immediate risk team?

Yes — assess.one supports email and Slack notifications that are configured inside the platform, so you can notify submitters when their assessment is acknowledged or completed, alert risk owners when treatment actions are assigned, and inform senior stakeholders when high-rated risks reach the approval stage. All notification logic is set up within assess.one and requires no third-party development work.

Ready to use this workflow?

Create a free account and customise this workflow for your business.

Business Risk Assessment Workflow | assess.one