Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 
 
 

Repository files navigation

Risk Assessment Templates

A collection of ready-to-use risk assessment templates in Markdown for business, project management, investing, cybersecurity, and personal decision-making. Copy, paste, and customize for your needs.

Table of Contents


How to Use

  1. Select the template that fits your situation
  2. Copy the Markdown into your project wiki, Notion, or documentation
  3. Customize the risk categories and scoring for your context
  4. Review regularly — risk assessments are living documents

Templates

1. General Risk Assessment Matrix

The classic 5x5 risk matrix — works for any domain.

# Risk Assessment: [Project/Initiative Name]
**Date:** [Date] | **Owner:** [Name] | **Review Cycle:** [Monthly/Quarterly]

## Risk Matrix

|              | Negligible (1) | Minor (2) | Moderate (3) | Major (4) | Catastrophic (5) |
|--------------|:-:|:-:|:-:|:-:|:-:|
| **Almost Certain (5)** | 5 | 10 | 15 | 🟠 20 | 🔴 25 |
| **Likely (4)** | 4 | 8 | 🟡 12 | 🟠 16 | 🔴 20 |
| **Possible (3)** | 3 | 6 | 🟡 9 | 🟡 12 | 🟠 15 |
| **Unlikely (2)** | 2 | 4 | 6 | 8 | 🟡 10 |
| **Rare (1)** | 1 | 2 | 3 | 4 | 5 |

**Legend:** 🔴 Critical (20-25) | 🟠 High (15-19) | 🟡 Medium (9-14) | Low (1-8)

## Risk Register

| ID | Risk Description | Category | Likelihood (1-5) | Impact (1-5) | Score | Priority | Owner | Mitigation | Status |
|----|-----------------|----------|:-:|:-:|:-:|----------|-------|------------|--------|
| R1 | | | | | | | | | Open |
| R2 | | | | | | | | | Open |
| R3 | | | | | | | | | Open |
| R4 | | | | | | | | | Open |
| R5 | | | | | | | | | Open |

## Action Items
| Risk ID | Action | Owner | Due Date | Status |
|---------|--------|-------|----------|--------|
| | | | | |

## Review Log
| Date | Reviewer | Changes Made |
|------|----------|-------------|
| | | |

2. Project Risk Register

Detailed risk tracking for project managers.

# Project Risk Register: [Project Name]
**Project Manager:** [Name] | **Last Updated:** [Date]

## Summary Dashboard
- **Total Risks:** [#] | **Critical:** [#] | **High:** [#] | **Medium:** [#] | **Low:** [#]
- **Risks Mitigated This Period:** [#]
- **New Risks Identified:** [#]

## Active Risks

### R-001: [Risk Title]
- **Category:** Technical / Schedule / Budget / Resource / External
- **Description:** [Detailed description of the risk event]
- **Trigger:** [What would cause this risk to materialize?]
- **Probability:** [1-5] | **Impact:** [1-5] | **Score:** [P×I]
- **Risk Response:** Avoid / Mitigate / Transfer / Accept
- **Mitigation Plan:** [Specific actions to reduce probability or impact]
- **Contingency Plan:** [What to do if the risk materializes]
- **Owner:** [Name]
- **Early Warning Indicators:** [Measurable signals]
- **Status:** Open / Monitoring / Mitigated / Closed
- **Last Review:** [Date]

### R-002: [Risk Title]
[Same structure as above]

## Risk Burndown
| Period | Total Risks | Critical | High | Medium | Low | Closed |
|--------|:-:|:-:|:-:|:-:|:-:|:-:|
| Week 1 | | | | | | |
| Week 2 | | | | | | |
| Week 3 | | | | | | |
| Week 4 | | | | | | |

## Lessons Learned
| Risk ID | What Happened | What We Learned | Recommendation |
|---------|--------------|-----------------|----------------|
| | | | |

3. Investment Risk Scorecard

Evaluate investment risks systematically.

# Investment Risk Scorecard: [Company/Asset]
**Analyst:** [Name] | **Date:** [Date]

## Risk Categories (Score 1-10, where 10 = highest risk)

### Business Risk
| Factor | Score (1-10) | Notes |
|--------|:-:|-------|
| Revenue concentration (single customer/product) | | |
| Competitive moat durability | | |
| Industry disruption potential | | |
| Regulatory/legal exposure | | |
| Management quality & integrity | | |
| **Business Risk Average** | **___** | |

### Financial Risk
| Factor | Score (1-10) | Notes |
|--------|:-:|-------|
| Leverage (Debt/Equity) | | |
| Interest coverage ratio | | |
| Cash flow stability | | |
| Working capital adequacy | | |
| Off-balance-sheet liabilities | | |
| **Financial Risk Average** | **___** | |

### Valuation Risk
| Factor | Score (1-10) | Notes |
|--------|:-:|-------|
| Current P/E vs. historical average | | |
| Price vs. intrinsic value estimate | | |
| Growth assumptions required | | |
| Margin of safety | | |
| **Valuation Risk Average** | **___** | |

### External Risk
| Factor | Score (1-10) | Notes |
|--------|:-:|-------|
| Macroeconomic sensitivity | | |
| Currency risk | | |
| Geopolitical exposure | | |
| Commodity price dependence | | |
| **External Risk Average** | **___** | |

## Overall Risk Score
| Category | Weight | Score | Weighted |
|----------|--------|-------|----------|
| Business Risk | 30% | | |
| Financial Risk | 25% | | |
| Valuation Risk | 25% | | |
| External Risk | 20% | | |
| **Total** | **100%** | | **___** |

## Risk Rating
- 1-3: Low risk → Standard position size
- 4-5: Moderate risk → Reduced position size
- 6-7: High risk → Small position only if upside justifies
- 8-10: Very high risk → Avoid or speculative position only

## Decision: [Invest / Pass / Watchlist]

4. Startup Risk Canvas

A one-page risk assessment for early-stage ventures.

# Startup Risk Canvas: [Company Name]
**Date:** [Date] | **Stage:** Pre-seed / Seed / Series A

┌─────────────────────┬─────────────────────┬─────────────────────┐
│   MARKET RISK       │   PRODUCT RISK      │   TEAM RISK         │
│                     │                     │                     │
│ □ Market too small  │ □ Can't build it    │ □ Key person risk   │
│ □ No real pain      │ □ Tech doesn't work │ □ Missing skills    │
│ □ Timing wrong      │ □ UX too complex    │ □ Founder conflict  │
│ □ Adoption barrier  │ □ Can't scale       │ □ Can't recruit     │
│                     │                     │                     │
│ Risk level: H/M/L   │ Risk level: H/M/L   │ Risk level: H/M/L   │
├─────────────────────┼─────────────────────┼─────────────────────┤
│   FINANCIAL RISK    │   COMPETITIVE RISK  │   EXECUTION RISK    │
│                     │                     │                     │
│ □ Runway < 12 mo    │ □ Incumbents        │ □ Regulation        │
│ □ Unit economics    │ □ Well-funded rival  │ □ Operations        │
│ □ Revenue model     │ □ Low barriers      │ □ Distribution      │
│ □ Fundraising       │ □ Network effects   │ □ Partnerships      │
│                     │ (against us)        │                     │
│ Risk level: H/M/L   │ Risk level: H/M/L   │ Risk level: H/M/L   │
└─────────────────────┴─────────────────────┴─────────────────────┘

## Top 3 Risks & Mitigation
| # | Risk | Mitigation Strategy | Timeline | Success Metric |
|---|------|-------------------|----------|---------------|
| 1 | | | | |
| 2 | | | | |
| 3 | | | | |

## Kill Criteria
What conditions would make us shut down or pivot?
1.
2.
3.

5. Cybersecurity Risk Assessment

# Cybersecurity Risk Assessment: [System/Application]
**Assessor:** [Name] | **Date:** [Date] | **Classification:** Internal/Confidential

## Asset Inventory
| Asset | Type | Data Classification | Business Criticality |
|-------|------|-------------------|---------------------|
| | Server/App/Data/Network | Public/Internal/Confidential/Restricted | Critical/High/Medium/Low |

## Threat Assessment
| Threat | Threat Actor | Likelihood (1-5) | Target Assets |
|--------|-------------|:-:|-------------|
| Data breach | External attacker | | |
| Ransomware | Cybercriminal | | |
| Insider threat | Employee | | |
| DDoS | Hacktivist | | |
| Phishing | External attacker | | |
| Supply chain compromise | Nation-state/Criminal | | |

## Vulnerability Assessment
| Vulnerability | Related Threat | Severity (CVSS) | Current Controls | Gap |
|--------------|---------------|:-:|----------------|-----|
| | | | | |

## Risk Register
| ID | Risk Scenario | Likelihood | Impact | Risk Level | Treatment | Owner |
|----|--------------|:-:|:-:|----------|-----------|-------|
| C1 | | | | | Mitigate/Accept/Transfer/Avoid | |
| C2 | | | | | | |
| C3 | | | | | | |

## Controls Assessment
| Control Category | Implemented? | Effectiveness | Recommendation |
|-----------------|:-:|:-:|----------------|
| Access control (MFA, RBAC) | Yes/No/Partial | H/M/L | |
| Encryption (at rest, in transit) | Yes/No/Partial | H/M/L | |
| Monitoring & logging | Yes/No/Partial | H/M/L | |
| Backup & recovery | Yes/No/Partial | H/M/L | |
| Incident response plan | Yes/No/Partial | H/M/L | |
| Security awareness training | Yes/No/Partial | H/M/L | |
| Patch management | Yes/No/Partial | H/M/L | |
| Network segmentation | Yes/No/Partial | H/M/L | |

6. Vendor / Third-Party Risk

# Vendor Risk Assessment: [Vendor Name]
**Assessed by:** [Name] | **Date:** [Date]

## Vendor Profile
| Field | Details |
|-------|---------|
| Vendor name | |
| Service provided | |
| Data access level | None / Read-only / Read-write / Admin |
| Data classification | Public / Internal / Confidential / Restricted |
| Contract term | |
| Annual spend | |

## Risk Assessment
| Category | Question | Score (1-5) | Notes |
|----------|----------|:-:|-------|
| **Financial** | Is the vendor financially stable? | | |
| **Security** | Does the vendor have SOC 2 / ISO 27001? | | |
| **Security** | How is data encrypted? | | |
| **Privacy** | Is the vendor GDPR/CCPA compliant? | | |
| **Operational** | What's the vendor's uptime SLA? | | |
| **Operational** | What's the disaster recovery plan? | | |
| **Concentration** | How dependent are we on this vendor? | | |
| **Substitution** | How easy is it to switch vendors? | | |
| **Reputation** | Any history of breaches or incidents? | | |
| **Legal** | Are contract terms acceptable? | | |
| **Total** | | **___/50** | |

## Risk Level
- 10-20: Low risk → Standard monitoring
- 21-30: Medium risk → Enhanced monitoring, review annually
- 31-40: High risk → Active mitigation required, review quarterly
- 41-50: Critical risk → Reconsider vendor relationship

## Decision: [Approve / Approve with Conditions / Reject]

7. Personal Decision Risk Analysis

For major life decisions — job changes, relocations, investments, relationships.

# Personal Decision Risk Analysis: [Decision]
**Date:** [Date]

## Options
| Option | Description |
|--------|-------------|
| A | |
| B | |
| C (status quo) | |

## For each option, assess:

### Option A: [Name]
| Risk | Probability (1-5) | Impact (1-5) | Reversible? | Mitigation |
|------|:-:|:-:|:-:|-----------|
| Financial risk | | | Yes/No | |
| Career risk | | | Yes/No | |
| Relationship risk | | | Yes/No | |
| Health/wellbeing risk | | | Yes/No | |
| Opportunity cost | | | N/A | |

**Best case:** [description]
**Worst case:** [description]
**Most likely case:** [description]

### The Stoic Test
- What would I regret NOT doing? →
- Can I survive the worst case? →
- What's within my control? →
- What would I advise my best friend? →

## Decision: [Option chosen and reasoning]

8. Operational Risk (FMEA)

Failure Mode and Effects Analysis for processes and operations.

# FMEA: [Process/System Name]
**Team:** [Names] | **Date:** [Date]

## Rating Scales
| Score | Severity (S) | Occurrence (O) | Detection (D) |
|:-:|-------------|---------------|---------------|
| 1 | No effect | < 1 in 100,000 | Almost certain to detect |
| 2-3 | Minor | 1 in 10,000 | High chance of detection |
| 4-6 | Moderate | 1 in 1,000 | Moderate chance |
| 7-8 | High | 1 in 100 | Low chance |
| 9-10 | Catastrophic | > 1 in 10 | Almost impossible to detect |

## Analysis
| # | Process Step | Failure Mode | Effect | S | Cause | O | Current Controls | D | RPN | Action |
|---|-------------|-------------|--------|:-:|-------|:-:|-----------------|:-:|:-:|--------|
| 1 | | | | | | | | | | |
| 2 | | | | | | | | | | |
| 3 | | | | | | | | | | |

**RPN** = Severity × Occurrence × Detection (range: 1-1000)

## Priority Actions (RPN > 200)
| Failure Mode | RPN | Recommended Action | Owner | Target Date | New RPN |
|-------------|:-:|-------------------|-------|------------|:-:|
| | | | | | |

9. Strategic Risk Dashboard

Executive-level risk overview.

# Strategic Risk Dashboard: [Organization]
**Period:** [Q_/Year] | **CIRO:** [Name]

## Risk Heat Map Summary
| Risk Category | Risk Count | Critical | High | Medium | Low | Trend |
|--------------|:-:|:-:|:-:|:-:|:-:|:-:|
| Strategic | | | | | | ↑↓→ |
| Financial | | | | | | ↑↓→ |
| Operational | | | | | | ↑↓→ |
| Compliance | | | | | | ↑↓→ |
| Technology | | | | | | ↑↓→ |
| Reputational | | | | | | ↑↓→ |
| **Total** | | | | | | |

## Top 5 Risks
| Rank | Risk | Category | Score | Trend | Owner | Status |
|:-:|------|----------|:-:|:-:|-------|--------|
| 1 | | | | ↑↓→ | | |
| 2 | | | | ↑↓→ | | |
| 3 | | | | ↑↓→ | | |
| 4 | | | | ↑↓→ | | |
| 5 | | | | ↑↓→ | | |

## Emerging Risks
| Risk | Potential Impact | Monitoring Actions |
|------|-----------------|-------------------|
| | | |

## Risk Appetite Status
| Category | Appetite | Current Exposure | Within Tolerance? |
|----------|----------|-----------------|:-:|
| Growth investments | High | | Yes/No |
| Operational failures | Low | | Yes/No |
| Regulatory compliance | Zero tolerance | | Yes/No |
| Cybersecurity | Low | | Yes/No |

10. Change Management Risk

# Change Risk Assessment: [Change Description]
**Change Owner:** [Name] | **Date:** [Date] | **Priority:** Critical/High/Medium/Low

## Change Details
| Field | Details |
|-------|---------|
| Change description | |
| Systems affected | |
| Users affected | |
| Planned date/time | |
| Rollback plan | Yes / No (detail below) |
| Estimated downtime | |

## Risk Assessment
| Risk | Likelihood (1-5) | Impact (1-5) | Score | Mitigation |
|------|:-:|:-:|:-:|-----------|
| System outage | | | | |
| Data loss | | | | |
| Performance degradation | | | | |
| User disruption | | | | |
| Security vulnerability | | | | |
| Integration failure | | | | |

## Go/No-Go Checklist
- [ ] Rollback plan documented and tested
- [ ] Stakeholders notified
- [ ] Backup completed
- [ ] Testing environment validated
- [ ] Change approved by CAB
- [ ] Monitoring alerts configured
- [ ] Support team briefed

## Decision: [Approve / Reject / Defer]

Risk Scoring Guide

Likelihood Scale

Score Label Description Probability
1 Rare Exceptional circumstances < 5%
2 Unlikely Could occur but not expected 5-25%
3 Possible Might occur at some point 25-50%
4 Likely Will probably occur 50-75%
5 Almost Certain Expected to occur > 75%

Impact Scale

Score Label Financial Operational Reputational
1 Negligible < $10K No disruption No notice
2 Minor $10K-100K Brief disruption Local mention
3 Moderate $100K-1M Service degraded Industry press
4 Major $1M-10M Service down National press
5 Catastrophic > $10M Extended outage Existential threat

Risk Response Strategies

Strategy Description When to Use
Avoid Eliminate the risk by changing plans Risk is unacceptable and can be avoided
Mitigate Reduce probability or impact Risk is significant but manageable
Transfer Shift risk to a third party (insurance, contracts) Risk is better managed by someone else
Accept Acknowledge and monitor Risk is low or cost of mitigation exceeds benefit
Exploit Maximize positive risk (opportunity) Upside risk you want to capture

Resources

Standards & Frameworks:

  • ISO 31000 — Risk Management
  • COSO ERM — Enterprise Risk Management
  • NIST SP 800-30 — IT Risk Assessment

Practice scenario-based risk assessment: For interactive scenarios that walk you through real-world risk decisions with guidance from proven frameworks, explore KeepRule Scenarios — apply risk thinking to investment, career, and life decisions.


Contributing

Have a risk template for a specific industry or situation? PRs welcome. Please include context for when to use the template and an example.


License

MIT License — see LICENSE for details.

About

Collection of ready-to-use risk assessment templates in Markdown — project risk, investment risk, cybersecurity, FMEA, vendor risk, startup risk canvas, and more.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors