HomeRisk ManagementRisk Identification and Assessment Best Practices Guide

Risk Identification and Assessment Best Practices Guide

Risk Identification and Assessment: A Practitioner’s Framework (With Working Templates)


The $1.8 Billion Warning Sign Nobody Escalated

In November 2022, Federal Reserve bank examiners flagged interest rate risk deficiencies at Silicon Valley Bank for the third consecutive year — the same finding had appeared in the 2020 and 2021 CAMELS exams without ever being elevated to a formal supervisory finding. By the time examiners finally issued that finding and moved to downgrade the bank’s risk rating, SVB had already failed. On March 8, 2023, the bank disclosed a $1.8 billion loss on the sale of $21 billion in securities; within two days, depositors pulled $42 billion and the California Department of Financial Protection and Innovation closed the bank — the fastest failure in U.S. banking history.

Risk Identification And Assessment

The Federal Reserve’s own post-mortem (April 2023, led by Vice Chair Michael Barr) didn’t blame a black-swan event. It blamed process: a risk identified repeatedly, never assigned enough urgency to force action, reviewed on an annual supervisory cycle instead of a live one. That is a risk identification and assessment failure, not a market failure — and it’s the exact failure mode this guide is built to prevent.


Part 1: The Risk Scoring System You Can Actually Use

Most guides show you a colored risk matrix and stop there. Here’s the underlying math, so your team scores consistently instead of arguing about whether something is “yellow” or “orange.”

Likelihood scale (1–4):

ScoreLabelDefinition
1Remote<10% chance within the review period
2Possible10–40% chance within the review period
3Probable40–70% chance within the review period
4Expected>70% chance, or already in progress

Impact scale (1–5):

ScoreLabelDefinition
1NegligibleNo measurable effect on operations or budget
2Minor<2% of annual budget or recoverable within a week
3Moderate2–10% of annual budget or 1–4 weeks of disruption
4Major10–25% of annual budget or a core system/process down >1 month
5Catastrophic>25% of annual budget, regulatory shutdown risk, or going-concern threat

Prefer a visual reference over the raw math? See our full risk assessment matrix guide for a color-coded breakdown.

Risk Score = Likelihood × Impact (range: 1–20)

Score rangeTierRequired action
1–4Low (Green)Log and review annually
5–9Medium (Yellow)Assign owner, review quarterly
10–14High (Orange)Mitigation plan due within 30 days
15–20Critical (Red)Executive escalation within 5 business days

Apply this to SVB: an interest-rate risk with no hedge, held for three straight exam cycles, on a balance sheet that was over 50% invested in long-duration securities, scores as Likelihood 4 (Expected — rates were already rising) × Impact 5 (Catastrophic — it threatened going-concern status) = 20, Critical. Under the escalation rule above, that requires executive sign-off within 5 business days of identification. SVB’s own timeline — three annual exam cycles before a formal finding — shows exactly what happens when a scoring system exists on paper but isn’t operationally enforced.


Part 2: Six Identification Methods, Compared

Rather than six repetitive sections, here’s the same information as a single decision table:

MethodBest forTime costKey limitationReal constraint to watch
BrainstormingFast initial coverage, team buy-inLow (half-day)Loudest voice dominatesUse silent written idea submission first, discuss after — cuts groupthink significantly
Structured interviewsDeep technical/domain riskMedium (1–2 weeks)Misses risks outside the question setAlways end with “what didn’t I ask about?”
Assumption analysisStrategic/dependency riskMediumRequires leadership to question their own strategyWorks best facilitated by someone outside the team whose plan is being tested
FMEAProcess/technical/safety riskHigh (weeks, for complex systems)Assumes deep technical fluency in the process being mappedNeeds a Risk Priority Number (RPN) = Severity × Occurrence × Detectability, not just Severity alone
SWOTStrategic-level scanLowFrequently surface-level, no severity rankingOnly useful if each item gets a follow-up severity score — otherwise it’s a list, not an assessment
Checklists/frameworksRegulatory/compliance coverageLowChecklist bias — misses novel, sector-specific riskBest paired with one open-ended method (brainstorming or interviews) to catch what the checklist doesn’t

Rule of thumb from practice: run at least one generative method (brainstorming or interviews) and one structured/comparative method (FMEA or checklist) together. Teams that use only checklists consistently under-report novel risks; teams that use only brainstorming consistently under-report low-frequency/high-severity risks, because those don’t come to mind unprompted.


Part 3: The Risk Register Template (Copy This Structure)

Below is the exact column structure to build in Google Sheets or Excel — copy the headers directly:

Risk IDDescriptionCategoryRoot CauseLikelihood (1-4)Impact (1-5)ScoreTierOwnerExisting ControlsMitigation ActionTarget DateResidual ScoreLast Reviewed

Field-by-field rules that prevent a register from decaying into an unused spreadsheet:

  • Description: Must follow a cause → event → consequence structure. Not “cybersecurity risk” — instead: “Unpatched VPN endpoint (cause) could allow credential-stuffing intrusion (event), resulting in customer PII exposure and GDPR notification obligation within 72 hours (consequence).”
  • Owner: One named individual, never a committee or department. “IT” is not an owner; “J. Martinez, Head of Infrastructure” is.
  • Last Reviewed: If this date is more than one tier-appropriate review cycle old (30 days for Critical, 90 for High, 180 for Medium, 365 for Low), the register is stale — flag it automatically with a conditional-format rule.

Part 4: The 8-Week Rollout — With Failure Points Marked

PhaseWeeksDeliverableWhere this typically breaks
1. Preparation1–2Scope document, sponsor sign-offSkipping sponsor sign-off — teams identify risks leadership never acts on
2. Identification3–5Raw risk list, sourced and datedOnly interviewing management, skipping frontline staff
3. Assessment6–7Scored, validated risk registerScores set by one person instead of cross-checked by 2+ raters
4. Prioritization & Reporting8Register + escalation of Critical/High itemsRegister gets built, then never revisited — the SVB failure mode

Common Mistake: Confusing Annual Review With Ongoing Monitoring

This is the single highest-cost mistake in practice, and it’s precisely what happened at SVB. A risk was correctly identified in 2020. It was correctly scored as material each year. What failed was the escalation trigger — the same finding sat in an annual review cycle for three years without a rule forcing faster action as conditions worsened (in SVB’s case, as the Fed funds rate rose from near-zero to over 4.75% across 2022–2023). The fix isn’t more identification — it’s tying review frequency to risk tier, as shown in Part 3, so a Critical risk cannot silently sit for a year.


FAQ

How is this different from a standard ISO 31000 summary? For the standard itself, see our ISO 31000 risk management framework guide. ISO 31000 defines the process (identification → analysis → evaluation → treatment). It doesn’t specify a scoring formula, review cadence, or register structure — those are implementation choices every organization has to make themselves, which is what Parts 1–3 above provide.

Identification Of Risks And Methodologies

Do I need software, or is a spreadsheet enough? A spreadsheet is enough until you have >50 active risks, more than one department contributing, or a regulatory requirement for audit trails. Past that threshold, the coordination cost of a shared spreadsheet (version conflicts, no automated escalation) usually exceeds the cost of a platform like AuditBoard or Archer. For a wider view of how this register fits into org-wide risk governance, see our Enterprise Risk Management Framework guide.

What’s the minimum viable version of this for a 10-person startup? Skip FMEA and interviews. Run one 90-minute brainstorming session, score everything with the table in Part 1, and review the register monthly until you have fewer than 5 active Medium+ risks.


Sources: Federal Reserve Board, “Review of the Federal Reserve’s Supervision and Regulation of Silicon Valley Bank” (April 2023); U.S. GAO, “Bank Regulation: Preliminary Review of Agency Actions Related to March 2023 Bank Failures” (GAO-23-106834); ISO 31000:2018.

Faizan Saeed
Faizan Saeedhttps://www.linkedin.com/in/faizan-saeed-33a417424/
Faizan Saeed is the founder and lead editor of StudyMastery, specializing in enterprise risk management models, project control strategies, and financial compliance guides.
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Latest Posts