Risk Assessment Explained: How to Evaluate Impact, Probability and Exposure with Confidence

how to do a risk assessment

Identifying risks is only the beginning. Once you know what could go wrong, you need to understand how serious each threat actually is before you can decide what to do about it.

That is what risk assessment is for. It gives you a structured, repeatable way to measure each risk against two critical dimensions: how likely it is to happen, and how damaging it would be if it did. Without this step, every risk on your list looks roughly the same, and you end up either overreacting to minor threats or underestimating the ones that genuinely matter.

This guide explains how to do a risk assessment clearly and practically, covering probability, impact, exposure, and how to use those measures to make confident decisions.

What Is a Risk Assessment?

A risk assessment is the process of evaluating identified risks to understand their significance. It follows directly from risk identification and feeds into the prioritisation and response stages that come after.

The goal is not to eliminate uncertainty. That is impossible. The goal is to replace vague concern with a clear, evidence-informed view of which risks deserve your attention, your resources, and your time. A well-executed risk assessment stops your team from spending energy on low-priority issues while serious threats go unaddressed.

Tip: A risk assessment does not need to be complex to be effective. A consistent, honest evaluation of each risk using the same criteria across your team is far more valuable than an elaborate process that gets done once and then ignored.

Step 1: Understand Risk Probability

Risk probability is the likelihood that a specific risk will actually materialise. It answers the question: how often could this realistically happen?

Most organisations rate probability on a simple three or five-point scale. A three-point scale uses low, medium, and high. A five-point scale adds very low and very high for finer differentiation. The important thing is that your team uses the same scale consistently, with shared definitions for each level.

When estimating probability, draw on:

  • Historical data from past incidents, near-misses, or audit findings
  • Industry benchmarks and sector-specific risk data
  • Expert judgement from people with direct experience
  • The frequency of similar events in comparable organisations

Avoid the tendency to rate unfamiliar risks as low probability simply because they have not happened to you before. A risk that is new to your business may be well-documented elsewhere in your industry.

Step 2: Evaluate Risk Impact

Risk impact is the potential consequence if a risk does materialise. It answers the question: how bad would this actually be?

Impact should be assessed across multiple dimensions, not just financial cost. A risk that triggers a regulatory investigation might have moderate direct costs but severe reputational damage. A key person leaving might have low financial impact in the short term but high operational impact over the following months.

Consider impact across these areas:

  • Financial: Direct costs, lost revenue, fines, or compensation
  • Operational: Disruption to processes, downtime, or reduced capacity
  • Reputational: Damage to your brand, client relationships, or public trust
  • Legal and compliance: Regulatory action, contractual breach, or liability
  • People: Staff wellbeing, retention, or skills loss

Rate each risk’s impact on the same scale you use for probability. Keeping the two dimensions comparable makes it straightforward to combine them into a single score at the next step.

Strategy: Be honest about reputational impact. Businesses consistently underrate how much a single visible failure can cost in lost client confidence, negative coverage, or difficulty recruiting. If the impact on your reputation would be significant, rate it accordingly.

Step 3: Calculate Risk Exposure

Risk exposure is the combined measure of how serious a risk really is, taking both probability and impact into account together.

The simplest way to calculate it is:

Risk exposure = probability x impact

If you are using a three-point scale where low equals 1, medium equals 2, and high equals 3, a risk rated medium probability and high impact produces an exposure score of 6. A risk rated low probability and low impact produces a score of 1. This gives you a numerical basis for ranking your risks rather than relying on gut feel alone.

This exposure score is what your risk register should capture for each identified risk. It lets you sort your list by severity, direct attention to the highest-scoring items, and demonstrate to stakeholders that your prioritisation is evidence-based rather than arbitrary.

Fix: If most of your risks end up rated as high exposure, your scoring criteria are probably too broad. Tighten your definitions of what constitutes a high, medium, or low rating so that the scale genuinely differentiates between serious threats and manageable ones.

Step 4: Apply Your Risk Appetite

Not every risk above a certain exposure score automatically demands the same response. The final step in assessing risk is comparing each score against your organisation’s risk appetite, which is the level of risk your business has decided it is willing to accept.

Your risk appetite reflects your business context, sector, regulatory environment, and growth stage. A start-up may accept higher exposure on competitive risks in pursuit of market share. An established organisation in a regulated industry may have a very low tolerance for compliance risk, even at moderate exposure scores.

Use your risk appetite to categorise each assessed risk into one of three outcomes:

  • Within appetite: Monitor and review at regular intervals
  • At the boundary: Assign ownership and develop a response plan
  • Beyond appetite: Prioritise for immediate action and escalate to leadership

This final categorisation is where assessment becomes decision-making. It is what turns your risk register from a list into an active management tool.

Common Risk Assessment Mistakes to Avoid

Even with a clear process, risk assessments can go wrong in predictable ways. Watch for these:

  • Rating probability based on past experience only, without considering emerging threats
  • Assessing impact in financial terms alone and ignoring operational or reputational consequences
  • Using inconsistent scales across teams, making scores impossible to compare
  • Completing the assessment once and treating it as permanent rather than reviewing it regularly
  • Letting seniority influence scores, where junior team members defer to leaders rather than giving honest ratings

Final Thoughts

Knowing how to do a risk assessment properly is one of the most valuable practical skills in risk management. Probability, impact, and exposure are not abstract concepts. They are decision-making tools that help you allocate time, resource, and attention where it is genuinely needed.

The businesses that handle disruption well are not necessarily the ones facing fewer risks. They are the ones who understood their risks clearly before anything went wrong, and made informed choices based on that understanding.

Explore the full Zorgle risk management series to continue building your risk management capability, from building and maintaining a risk register to choosing the right framework for your organisation.

Similar Posts