Glossary Terms

Risk Assessment

A structured process for identifying threats, estimating potential harm and selecting controls.
On this page

What is a risk assessment?

A risk assessment is a structured process for identifying what could go wrong, estimating the likelihood and severity of potential consequences and selecting controls to reduce the risk. In privacy and AI governance, the assessment should consider harm to individuals and groups as well as operational, legal, financial and reputational impact on the organisation.

A risk assessment is not only a numerical score. It should describe realistic scenarios, assumptions, affected stakeholders and the evidence supporting the rating. Different assessment methods may be used, but the reasoning should remain understandable and reviewable.

How is risk identified and measured?

Teams begin by defining scope, assets, purpose, data, technology and stakeholders. They identify threats, vulnerabilities, misuse, errors and external events that could create harm. Likelihood and impact are then rated using agreed criteria.

Impact should consider confidentiality, integrity, availability, fairness, safety, discrimination, financial loss and the ability of affected people to recover. Low-frequency events may still require strong controls when consequences would be severe.

What are inherent and residual risk?

Inherent risk is the level before considering controls. Residual risk is what remains after existing or proposed safeguards are applied. Separating the two shows whether controls meaningfully reduce exposure and whether further action or formal acceptance is necessary.

The responsible owner should understand and approve residual risk. High residual risk may require escalation, redesign, consultation or cancellation of the activity.

How is risk monitored?

Assessments should produce actions with owners, deadlines and evidence. Monitoring may include incidents, complaints, audit findings, model performance, vendor changes and control tests. A change in purpose, data, scale or technology can invalidate the original assumptions.

Risk registers should not become static lists. Closed actions, accepted exceptions and review dates should remain visible and accountable.

Frequently asked questions

Is a risk assessment the same as a DPIA?

No. A DPIA is a specific privacy assessment for likely high-risk processing. Risk assessment is the broader concept used across many domains.

Who should rate the risk?

Business owners and relevant specialists should contribute. Independent challenge helps prevent optimistic ratings by teams invested in the project.

Can risk be reduced to zero?

Rarely. The objective is to reduce risk to an acceptable and justified level, not to claim that no uncertainty remains.

How often should a risk assessment be reviewed?

At defined intervals and after material changes, incidents, new threats or evidence that assumptions and controls are no longer reliable.

What is risk acceptance?

It is a documented decision by an authorised owner to proceed with understood residual risk, often subject to monitoring or conditions.

Book your personalised demo!
And see how leading organisations are already powering their Privacy and AI Governance with context-aware operations.