Enter text

Paste plain text or upload TXT/DOCX and we will turn it into a mind map.

0/40,000

UTF-8 TXT or DOCX; guests can use up to 40,000 characters, with longer input available after sign-in

Risk analysis guide

Describe risk as an uncertain event, not a vague concern

A risk assessment identifies uncertain events that could affect an objective, explains their causes and consequences, evaluates exposure and assigns treatment. Write each risk as a possible event: because a cause exists, an event may occur, leading to a consequence. This format is clearer than labels such as ‘security’ or ‘supplier problem’ and makes controls easier to evaluate.

Use process maps, incident history, audit findings, vendor information, technical tests and stakeholder interviews. AI can organize evidence, but likelihood and impact require context and accountable judgement. Record the scoring scale, review date and source. Separate an active issue, which already exists, from a risk that may occur.

Analyse each scenario at a consistent level. One node should not describe a broad category such as cyber risk while another describes a single expired certificate. Break categories into events that have distinct causes, consequences, controls and owners. Where several events share a systemic cause, retain both the individual scenarios and a parent theme so treatment can address immediate exposure and the underlying weakness.

Core risk fields

Capture scope, risk event, cause, consequence, affected objective, likelihood, impact, existing controls, control effectiveness, owner, treatment, due date and residual risk.

Assessment versus risk register

The assessment discovers and analyses exposure. A risk register maintains selected risks, owners and treatment status over time. This map can support both, but detailed history should remain in a controlled register.

Risk assessment example

From launch concerns to an owned treatment plan

Before: unranked concerns

Customer data migration

  • Risk event: customer records fail validation after migration
  • Cause: inconsistent legacy formats and incomplete mapping rules
  • Impact: delayed launch, support volume and possible data loss
  • Controls: rehearsal, reconciliation report, backups and rollback test
  • Owner and trigger: Data Lead; escalate if validation falls below 99.5%

After: structured risk map

Risk Assessment Template

How to build your mind map

How to create a risk assessment with AI

Set the scope, write precise events, score consistently and choose treatments that change exposure.

  1. 01

    Define objective and boundaries

    State the activity, decision, assets, stakeholders and time horizon. Choose an approved likelihood and impact scale before scoring so participants use the same meanings.

  2. 02

    Identify events, causes and consequences

    Use workshops and evidence to write specific scenarios. Separate root causes from the event and list consequences for delivery, customers, finance, safety, privacy or compliance.

  3. 03

    Evaluate controls and exposure

    Describe preventive, detective and recovery controls, their owner and proof they operate. Score inherent exposure before controls and residual exposure after considering effectiveness.

  4. 04

    Assign treatment and review

    Avoid, reduce, transfer or accept the risk with authority appropriate to the residual level. Give actions owners and dates, define triggers, then export and review until closure or formal acceptance.

Who it’s for

When to use a risk assessment map

Use it before a commitment or change, and whenever new evidence alters exposure.

Project and operations teams

Review launches, migrations, process changes and supplier dependencies. The map helps subject-matter experts connect causes, controls and consequences instead of debating isolated scores.

Risk, security and compliance reviewers

Document evidence and ownership while following the organization’s approved method. High-impact legal, safety, financial or security risks still require qualified review and formal records.

Practical guidance

Risk assessment quality checklist

Do not score first and invent reasoning later. Two risks with the same score may require different urgency because one is fast-moving or irreversible. Avoid false precision when evidence is weak; record a range or confidence level. A control is not effective merely because a policy exists—look for test results, logs, reconciliations, training evidence or incident performance.

Prioritize treatment by exposure, control weakness, urgency and decision value, not by the number of comments a risk receives. Keep confidential vulnerabilities in an approved system and publish only an appropriate summary. Review after incidents, scope changes, control failures or external changes rather than waiting for a calendar reminder.

For each proposed treatment, state which part of the scenario it changes: reducing likelihood, limiting consequence, improving detection or enabling recovery. Estimate cost, implementation time and new dependencies. A treatment can introduce secondary risk, such as operational delay or concentration on one supplier, so record material trade-offs before declaring the residual exposure acceptable.

Frequently asked questions

Risk assessment template questions

How are likelihood and impact scored?

Use your organization’s defined scale with observable criteria. Document the period, data and assumptions; do not copy a score from another project with different exposure.

What is residual risk?

Residual risk is the exposure remaining after existing controls are considered. It determines whether more treatment, escalation or formal acceptance is required.

Who should own a risk?

Choose one person with authority to monitor exposure and coordinate treatment. Action owners may complete individual controls, but the risk owner remains accountable for review.

Can AI decide whether a risk is acceptable?

No. AI can structure supplied evidence. Acceptance depends on policy, legal duties, risk appetite and accountable human judgement, especially for safety, privacy and financial matters.