What is Risk Assessment?
Risk assessment is the systematic process of identifying risks, analysing their likelihood and impact, and evaluating them against the organization's risk criteria. It sits between risk identification and risk treatment, and it determines where controls and audit attention are directed.
The risk assessment process
Identification comes first: mapping what could go wrong across processes, entities, and objectives, drawing on incident history, process walkthroughs, and management input. Analysis then estimates likelihood and impact for each risk, producing the ratings that feed a heat map or matrix.
Evaluation is the step most often skipped. Rating a risk is not the same as deciding what to do about it, and evaluation compares the rated risk against defined criteria to determine whether it is accepted, reduced, transferred, or avoided. Without stated criteria, ratings accumulate without triggering decisions.
Inherent risk, residual risk, and the gap between them
Inherent risk is exposure before any control is applied. Residual risk is what remains once controls operate as intended. The difference between them is the value the control environment actually delivers, which makes it a useful number to examine closely.
The weakness in most assessments is that residual risk is estimated rather than measured. Assuming a control works reduces the rating on paper without changing the exposure. Testing whether the control operated, and how often it failed, converts an assumption into a measurement.
Risk Assessment and Supervizor
Supervizor's internal audit solution grounds risk assessment in transactional evidence rather than workshop estimates. Teams use it to:
- Quantify residual risk with measured control failures instead of assumed control effectiveness
- Direct audit planning toward measured exposure, focusing fieldwork where anomalies concentrate
- Refresh the risk profile continuously as transaction patterns change, not once a year
