The recognised professional frameworks — whatever terminology they use — agree on one path: understand the context, identify the risks, analyse them, evaluate them, treat them, then monitor, review and report.
1 The steps of the cycle
Context
Objectives, environment and the boundaries of the activity
Identification
What might happen and have an effect?
Analysis
Impact, likelihood and existing controls
Evaluation
Is the risk acceptable, or does it need treating?
Treatment
Avoid, reduce, transfer or accept
Monitoring
Indicators and periodic follow-up
Communication
Reporting to management, the committee and the board
A continuous cycle: the outputs of monitoring become inputs to identification all over again
2 Step zero: establishing the context
Before hunting for risks, you must know what you are protecting. Risks are measured by their effect on specific objectives, and with no clear objective the exercise becomes a list of worries. The context covers:
- The objectives of the organisation, department or project being assessed.
- The external environment: the market, competition, regulation, the economy.
- The internal environment: structure, IT systems, capabilities, culture.
- The assessment criteria: the impact and likelihood scales, and the acceptance thresholds.
3 Analysis and evaluation: what is the difference?
| Analysis | Evaluation | |
|---|---|---|
| The question | How large is the risk? | Do we accept it or not? |
| The output | A risk score (impact × likelihood) | A decision: acceptable / needs treatment / unacceptable |
| The reference point | Data, experience and existing controls | Risk appetite and approved tolerance limits |
Who decides to accept?
Not the analyst nor the risk officer, but the risk owner within their authority: that may be a department head, the CEO, or the board if the risk exceeds the approved tolerance limits.
4 Monitoring and review
Risk is a moving thing: it rises and falls as the market, the technology and the team change. So the cycle needs:
- Periodic review of the risk register — usually quarterly — and immediately after a major event.
- Key risk indicators (KRIs) that warn before the event, such as a rise in overdue receivables.
- Follow-up on treatment plans: were they delivered on time? And did they actually reduce the risk?
- Lessons learned from events that occurred inside the organisation and outside it.
Context: finance’s objective is to close the accounts within 10 days of month end.
Identification: because the close depends on one employee who knows the system, it may be delayed when they are away.
Analysis: impact is medium (delayed reports and management decisions), likelihood is high (leave and travel).
Evaluation: the score is above finance’s approved acceptance threshold → it needs treatment.
Treatment: train a second employee, document the close steps, and set up backup rights in the system.
Monitoring: a “days to close” indicator monthly, and a quarterly review of the risk.
A common mistake
Assessing risks once when the framework is built and then forgetting it. A register that has not changed in a year means either the organisation has stopped, or nobody is reading it.
Lesson summary
- The cycle: context → identification → analysis → evaluation → treatment → monitoring → communication.
- Without defined objectives, risk assessment becomes a list of worries.
- Analysis measures the size; evaluation decides acceptance against approved thresholds.
- The decision to accept a risk belongs to the risk owner within their authority, not to the risk team.
- Monitoring with indicators and periodic review keeps the framework alive.
5 Test your understanding
Three quick questions
Pick the answer you believe is correct and you will see the result immediately.
1. Which step comes before identifying risks?
Risks are measured by their effect on specific objectives, so the objective and the context must be known first.
2. Who holds the decision to accept a risk that exceeds the tolerance limits?
The risk team analyses and recommends; acceptance is a management decision governed by the authority matrix.
3. What is the purpose of a key risk indicator (KRI)?
The indicator tracks the risk moving early, allowing intervention before it turns into a problem.