Risk Identification and Assessment: A Practitioner’s Framework (With Working Templates)
The $1.8 Billion Warning Sign Nobody Escalated
In November 2022, Federal Reserve bank examiners flagged interest rate risk deficiencies at Silicon Valley Bank for the third consecutive year — the same finding had appeared in the 2020 and 2021 CAMELS exams without ever being elevated to a formal supervisory finding. By the time examiners finally issued that finding and moved to downgrade the bank’s risk rating, SVB had already failed. On March 8, 2023, the bank disclosed a $1.8 billion loss on the sale of $21 billion in securities; within two days, depositors pulled $42 billion and the California Department of Financial Protection and Innovation closed the bank — the fastest failure in U.S. banking history.

The Federal Reserve’s own post-mortem (April 2023, led by Vice Chair Michael Barr) didn’t blame a black-swan event. It blamed process: a risk identified repeatedly, never assigned enough urgency to force action, reviewed on an annual supervisory cycle instead of a live one. That is a risk identification and assessment failure, not a market failure — and it’s the exact failure mode this guide is built to prevent.
Part 1: The Risk Scoring System You Can Actually Use
Most guides show you a colored risk matrix and stop there. Here’s the underlying math, so your team scores consistently instead of arguing about whether something is “yellow” or “orange.”
Likelihood scale (1–4):
| Score | Label | Definition |
|---|---|---|
| 1 | Remote | <10% chance within the review period |
| 2 | Possible | 10–40% chance within the review period |
| 3 | Probable | 40–70% chance within the review period |
| 4 | Expected | >70% chance, or already in progress |
Impact scale (1–5):
| Score | Label | Definition |
|---|---|---|
| 1 | Negligible | No measurable effect on operations or budget |
| 2 | Minor | <2% of annual budget or recoverable within a week |
| 3 | Moderate | 2–10% of annual budget or 1–4 weeks of disruption |
| 4 | Major | 10–25% of annual budget or a core system/process down >1 month |
| 5 | Catastrophic | >25% of annual budget, regulatory shutdown risk, or going-concern threat |
Prefer a visual reference over the raw math? See our full risk assessment matrix guide for a color-coded breakdown.
Risk Score = Likelihood × Impact (range: 1–20)
| Score range | Tier | Required action |
|---|---|---|
| 1–4 | Low (Green) | Log and review annually |
| 5–9 | Medium (Yellow) | Assign owner, review quarterly |
| 10–14 | High (Orange) | Mitigation plan due within 30 days |
| 15–20 | Critical (Red) | Executive escalation within 5 business days |
Apply this to SVB: an interest-rate risk with no hedge, held for three straight exam cycles, on a balance sheet that was over 50% invested in long-duration securities, scores as Likelihood 4 (Expected — rates were already rising) × Impact 5 (Catastrophic — it threatened going-concern status) = 20, Critical. Under the escalation rule above, that requires executive sign-off within 5 business days of identification. SVB’s own timeline — three annual exam cycles before a formal finding — shows exactly what happens when a scoring system exists on paper but isn’t operationally enforced.
Part 2: Six Identification Methods, Compared
Rather than six repetitive sections, here’s the same information as a single decision table:
| Method | Best for | Time cost | Key limitation | Real constraint to watch |
|---|---|---|---|---|
| Brainstorming | Fast initial coverage, team buy-in | Low (half-day) | Loudest voice dominates | Use silent written idea submission first, discuss after — cuts groupthink significantly |
| Structured interviews | Deep technical/domain risk | Medium (1–2 weeks) | Misses risks outside the question set | Always end with “what didn’t I ask about?” |
| Assumption analysis | Strategic/dependency risk | Medium | Requires leadership to question their own strategy | Works best facilitated by someone outside the team whose plan is being tested |
| FMEA | Process/technical/safety risk | High (weeks, for complex systems) | Assumes deep technical fluency in the process being mapped | Needs a Risk Priority Number (RPN) = Severity × Occurrence × Detectability, not just Severity alone |
| SWOT | Strategic-level scan | Low | Frequently surface-level, no severity ranking | Only useful if each item gets a follow-up severity score — otherwise it’s a list, not an assessment |
| Checklists/frameworks | Regulatory/compliance coverage | Low | Checklist bias — misses novel, sector-specific risk | Best paired with one open-ended method (brainstorming or interviews) to catch what the checklist doesn’t |
Rule of thumb from practice: run at least one generative method (brainstorming or interviews) and one structured/comparative method (FMEA or checklist) together. Teams that use only checklists consistently under-report novel risks; teams that use only brainstorming consistently under-report low-frequency/high-severity risks, because those don’t come to mind unprompted.
Part 3: The Risk Register Template (Copy This Structure)
Below is the exact column structure to build in Google Sheets or Excel — copy the headers directly:
| Risk ID | Description | Category | Root Cause | Likelihood (1-4) | Impact (1-5) | Score | Tier | Owner | Existing Controls | Mitigation Action | Target Date | Residual Score | Last Reviewed |
|---|
Field-by-field rules that prevent a register from decaying into an unused spreadsheet:
- Description: Must follow a cause → event → consequence structure. Not “cybersecurity risk” — instead: “Unpatched VPN endpoint (cause) could allow credential-stuffing intrusion (event), resulting in customer PII exposure and GDPR notification obligation within 72 hours (consequence).”
- Owner: One named individual, never a committee or department. “IT” is not an owner; “J. Martinez, Head of Infrastructure” is.
- Last Reviewed: If this date is more than one tier-appropriate review cycle old (30 days for Critical, 90 for High, 180 for Medium, 365 for Low), the register is stale — flag it automatically with a conditional-format rule.
Part 4: The 8-Week Rollout — With Failure Points Marked
| Phase | Weeks | Deliverable | Where this typically breaks |
|---|---|---|---|
| 1. Preparation | 1–2 | Scope document, sponsor sign-off | Skipping sponsor sign-off — teams identify risks leadership never acts on |
| 2. Identification | 3–5 | Raw risk list, sourced and dated | Only interviewing management, skipping frontline staff |
| 3. Assessment | 6–7 | Scored, validated risk register | Scores set by one person instead of cross-checked by 2+ raters |
| 4. Prioritization & Reporting | 8 | Register + escalation of Critical/High items | Register gets built, then never revisited — the SVB failure mode |
Common Mistake: Confusing Annual Review With Ongoing Monitoring
This is the single highest-cost mistake in practice, and it’s precisely what happened at SVB. A risk was correctly identified in 2020. It was correctly scored as material each year. What failed was the escalation trigger — the same finding sat in an annual review cycle for three years without a rule forcing faster action as conditions worsened (in SVB’s case, as the Fed funds rate rose from near-zero to over 4.75% across 2022–2023). The fix isn’t more identification — it’s tying review frequency to risk tier, as shown in Part 3, so a Critical risk cannot silently sit for a year.
FAQ
How is this different from a standard ISO 31000 summary? For the standard itself, see our ISO 31000 risk management framework guide. ISO 31000 defines the process (identification → analysis → evaluation → treatment). It doesn’t specify a scoring formula, review cadence, or register structure — those are implementation choices every organization has to make themselves, which is what Parts 1–3 above provide.
Do I need software, or is a spreadsheet enough? A spreadsheet is enough until you have >50 active risks, more than one department contributing, or a regulatory requirement for audit trails. Past that threshold, the coordination cost of a shared spreadsheet (version conflicts, no automated escalation) usually exceeds the cost of a platform like AuditBoard or Archer. For a wider view of how this register fits into org-wide risk governance, see our Enterprise Risk Management Framework guide.
What’s the minimum viable version of this for a 10-person startup? Skip FMEA and interviews. Run one 90-minute brainstorming session, score everything with the table in Part 1, and review the register monthly until you have fewer than 5 active Medium+ risks.
Sources: Federal Reserve Board, “Review of the Federal Reserve’s Supervision and Regulation of Silicon Valley Bank” (April 2023); U.S. GAO, “Bank Regulation: Preliminary Review of Agency Actions Related to March 2023 Bank Failures” (GAO-23-106834); ISO 31000:2018.
