A risk assessment workshop is the most common way organisations identify and rate enterprise risks, and also one of the easiest to run badly. A room full of senior people, a blank flipchart and a vague brief tend to produce a long list of worries, no agreed ratings and no follow-up. A well-prepared workshop produces a rated, owned set of risks that goes straight into the register.
This guide explains how to plan and run a risk assessment workshop: preparation, attendees, agenda, facilitation techniques and the follow-up that turns discussion into action.
What a risk assessment workshop should achieve
ISO 31000:2018 describes a risk management process that runs from establishing scope, context and criteria, through risk assessment (identification, analysis and evaluation), to treatment, monitoring and recording. You can read an overview on the ISO 31000 page. A workshop usually covers the assessment stage: it identifies risks, analyses their likelihood and consequences, and evaluates them against agreed criteria. It should leave you with a list of risks, ratings, owners and next steps.
Set a single clear purpose before you invite anyone. “Identify and rate the top strategic and operational risks for next year” is a purpose; “talk about risk” is not. A narrow purpose also keeps the session within a reasonable length, which matters for busy participants.
Preparing the risk assessment workshop
Most of the value comes from preparation. Do the following in the weeks before the session.
- Agree scope and context. Decide which part of the organisation, which objectives and which time horizon the workshop covers.
- Confirm the criteria. Circulate the likelihood and impact scales and the risk appetite statements so everyone rates against the same yardstick. Our guide to risk appetite explains how to set them.
- Gather inputs. Bring the last risk register, audit findings, incident logs, strategic plan and any relevant external analysis.
- Pre-collect risks. Send a short form beforehand and ask attendees to list their top risks, so the session starts with material rather than silence.
- Choose the format. Decide how ratings will be captured, whether by voting tools, cards or a shared sheet.
Who to invite to a risk assessment workshop
Invite people who understand the objectives and the operations, not just those senior enough to attend. A typical group includes the executive owner of the area, operational managers, someone from finance, someone from legal or compliance, and a representative from risk or internal audit as a facilitator or scribe. Keep the group to a size where everyone can speak, often 8 to 15 people. Larger groups can be split into breakout tables, each covering a theme.
Consider including people who will challenge assumptions, such as a newer employee or someone from a different function. Groups of similar senior managers tend to share the same blind spots. A neutral facilitator also helps: a person who is not accountable for the risks being discussed is more able to probe when answers are vague.
A sample agenda for the risk assessment workshop
| Time | Activity | Output |
|---|---|---|
| 10 min | Purpose, scope and rules | Shared understanding |
| 10 min | Review criteria and appetite | Common scales |
| 40 min | Identify risks by objective or theme | Long list |
| 20 min | Group, merge and clarify | Clean list with clear risk statements |
| 40 min | Rate likelihood and impact | Rated risks |
| 20 min | Discuss top risks, controls and owners | Owners and next steps |
| 10 min | Summarise and agree follow-up | Action list with dates |
Adjust the times to your context. Two half-day sessions often work better than one long day, because energy drops sharply after about three hours.
Facilitating the risk assessment workshop
Write clear risk statements
A good risk statement links a cause, an event and a consequence: “Because our single payment provider has no fallback, an outage could stop online sales for several days, causing lost revenue and customer complaints.” This is more useful than “supplier risk”, because it shows what could happen and what matters. During the session, rewrite vague entries into this form before anyone rates them.
Rate individually first
Group discussion suffers from anchoring: whoever speaks first sets the tone. Ask everyone to rate privately using cards or a poll, reveal the ratings together and discuss where they differ widely. The disagreements are often the most valuable part, because they reveal different assumptions about controls or consequences. Then agree a group rating and note the reasoning.
Separate inherent and residual ratings
Rate the risk before controls and then after. The gap shows how much you rely on your controls, and a big reliance on a single control is itself a finding. Use a heat map to display the results; our guide to the risk heat map shows how to build one that supports decisions rather than decoration.
Manage dominant voices
Watch for people who dominate and for people who stay quiet. Techniques include asking each person to write ideas before speaking, going round the table, and posing direct questions to quieter participants. Keep a parking list for topics that are interesting but outside scope, so the group stays on task without dismissing them.
Running it remotely
Virtual sessions work if you adapt the design. Use shorter blocks with breaks, a shared board for risk statements, and a polling tool for private ratings. Keep cameras optional but encourage voices, and assign a second person to watch the chat for comments from quieter participants. Send the pre-reading earlier than you would for a room, since screen fatigue makes it harder to absorb material on the day.
Turning workshop output into a register
Within a few days, turn notes into a structured record: risk statement, category, owner, inherent and residual ratings, existing controls, actions and dates. Circulate it to attendees for corrections while memory is fresh. Then load it into your enterprise risk register and set the review cycle. Each risk needs an owner who was in the room or has agreed to the role. A risk with no owner will not be managed.
Consider how the workshop aligns with your chosen framework. If you use both ISO 31000 and COSO, see our comparison of ISO 31000 and COSO ERM for how terminology and expectations differ.
A hypothetical example of a risk assessment workshop
The following is a hypothetical example invented for illustration. A regional retailer runs a half-day risk assessment workshop for its executive team and six operational managers. Attendees submit their top three risks in advance, producing 34 items. In the session, the facilitator merges duplicates into 18 risk statements and asks everyone to rate them privately.
The ratings for “loss of the main distribution centre” differ widely: the operations director scores likelihood as low, because of fire protection, while the logistics manager scores it as medium, because the site sits in a flood zone. The discussion reveals that no one has checked the flood plan since a lease renewal. The group agrees a medium rating, assigns the facilities director as owner and sets an action to review the plan within 60 days. The workshop finds a real gap that a desk-based exercise would probably have missed.
Common mistakes in a risk assessment workshop
Frequent errors include no clear purpose, too many attendees, no pre-work, undefined rating scales, vague risk statements, rating in open discussion so the senior person sets the score, listing risks without owners, ending the session without actions and never circulating the results. Another is repeating the same list each year with only a change of date, which suggests the workshop is a ritual rather than a way of learning.
Measuring whether the risk assessment workshop worked
After the session, check that every rated risk has an owner and a date, that new risks appeared which were not in the previous register, that actions were completed on time and that participants would attend again. If the workshop repeatedly produces no new information, change the format, the attendees or the prompts you use.
A structured report after the risk assessment workshop
A consistent report format helps you capture ratings, controls and actions in a standard way, so results can be compared across workshops and business units. The Enterprise Risk Assessment Report and Workbook provides a report and workbook for documenting enterprise risks, ratings and treatment. Whichever tool you use, keep the same fields for every workshop.
Risk assessment workshop FAQ
How long should a risk assessment workshop last?
Most run for three to four hours. If the scope is broad, split it into two sessions rather than one long day, because attention and quality of discussion drop with fatigue.
How many people should attend?
Eight to fifteen works for most groups. Larger groups should use breakout tables for different themes and bring results together at the end.
Who should facilitate?
A neutral person, often from risk management or internal audit, who does not own the risks being discussed and is comfortable challenging vague answers.
How often should we hold a workshop?
Many organisations run a full workshop annually, with lighter quarterly reviews of the register and extra sessions after major changes such as acquisitions or new markets.
What should the output be?
A list of clearly worded risks with inherent and residual ratings, named owners, existing controls, actions and dates, ready to load into the risk register.