A collection of ready-to-use risk assessment templates in Markdown for business, project management, investing, cybersecurity, and personal decision-making. Copy, paste, and customize for your needs.
- Select the template that fits your situation
- Copy the Markdown into your project wiki, Notion, or documentation
- Customize the risk categories and scoring for your context
- Review regularly — risk assessments are living documents
The classic 5x5 risk matrix — works for any domain.
# Risk Assessment: [Project/Initiative Name]
**Date:** [Date] | **Owner:** [Name] | **Review Cycle:** [Monthly/Quarterly]
## Risk Matrix
| | Negligible (1) | Minor (2) | Moderate (3) | Major (4) | Catastrophic (5) |
|--------------|:-:|:-:|:-:|:-:|:-:|
| **Almost Certain (5)** | 5 | 10 | 15 | 🟠 20 | 🔴 25 |
| **Likely (4)** | 4 | 8 | 🟡 12 | 🟠 16 | 🔴 20 |
| **Possible (3)** | 3 | 6 | 🟡 9 | 🟡 12 | 🟠 15 |
| **Unlikely (2)** | 2 | 4 | 6 | 8 | 🟡 10 |
| **Rare (1)** | 1 | 2 | 3 | 4 | 5 |
**Legend:** 🔴 Critical (20-25) | 🟠 High (15-19) | 🟡 Medium (9-14) | Low (1-8)
## Risk Register
| ID | Risk Description | Category | Likelihood (1-5) | Impact (1-5) | Score | Priority | Owner | Mitigation | Status |
|----|-----------------|----------|:-:|:-:|:-:|----------|-------|------------|--------|
| R1 | | | | | | | | | Open |
| R2 | | | | | | | | | Open |
| R3 | | | | | | | | | Open |
| R4 | | | | | | | | | Open |
| R5 | | | | | | | | | Open |
## Action Items
| Risk ID | Action | Owner | Due Date | Status |
|---------|--------|-------|----------|--------|
| | | | | |
## Review Log
| Date | Reviewer | Changes Made |
|------|----------|-------------|
| | | |Detailed risk tracking for project managers.
# Project Risk Register: [Project Name]
**Project Manager:** [Name] | **Last Updated:** [Date]
## Summary Dashboard
- **Total Risks:** [#] | **Critical:** [#] | **High:** [#] | **Medium:** [#] | **Low:** [#]
- **Risks Mitigated This Period:** [#]
- **New Risks Identified:** [#]
## Active Risks
### R-001: [Risk Title]
- **Category:** Technical / Schedule / Budget / Resource / External
- **Description:** [Detailed description of the risk event]
- **Trigger:** [What would cause this risk to materialize?]
- **Probability:** [1-5] | **Impact:** [1-5] | **Score:** [P×I]
- **Risk Response:** Avoid / Mitigate / Transfer / Accept
- **Mitigation Plan:** [Specific actions to reduce probability or impact]
- **Contingency Plan:** [What to do if the risk materializes]
- **Owner:** [Name]
- **Early Warning Indicators:** [Measurable signals]
- **Status:** Open / Monitoring / Mitigated / Closed
- **Last Review:** [Date]
### R-002: [Risk Title]
[Same structure as above]
## Risk Burndown
| Period | Total Risks | Critical | High | Medium | Low | Closed |
|--------|:-:|:-:|:-:|:-:|:-:|:-:|
| Week 1 | | | | | | |
| Week 2 | | | | | | |
| Week 3 | | | | | | |
| Week 4 | | | | | | |
## Lessons Learned
| Risk ID | What Happened | What We Learned | Recommendation |
|---------|--------------|-----------------|----------------|
| | | | |Evaluate investment risks systematically.
# Investment Risk Scorecard: [Company/Asset]
**Analyst:** [Name] | **Date:** [Date]
## Risk Categories (Score 1-10, where 10 = highest risk)
### Business Risk
| Factor | Score (1-10) | Notes |
|--------|:-:|-------|
| Revenue concentration (single customer/product) | | |
| Competitive moat durability | | |
| Industry disruption potential | | |
| Regulatory/legal exposure | | |
| Management quality & integrity | | |
| **Business Risk Average** | **___** | |
### Financial Risk
| Factor | Score (1-10) | Notes |
|--------|:-:|-------|
| Leverage (Debt/Equity) | | |
| Interest coverage ratio | | |
| Cash flow stability | | |
| Working capital adequacy | | |
| Off-balance-sheet liabilities | | |
| **Financial Risk Average** | **___** | |
### Valuation Risk
| Factor | Score (1-10) | Notes |
|--------|:-:|-------|
| Current P/E vs. historical average | | |
| Price vs. intrinsic value estimate | | |
| Growth assumptions required | | |
| Margin of safety | | |
| **Valuation Risk Average** | **___** | |
### External Risk
| Factor | Score (1-10) | Notes |
|--------|:-:|-------|
| Macroeconomic sensitivity | | |
| Currency risk | | |
| Geopolitical exposure | | |
| Commodity price dependence | | |
| **External Risk Average** | **___** | |
## Overall Risk Score
| Category | Weight | Score | Weighted |
|----------|--------|-------|----------|
| Business Risk | 30% | | |
| Financial Risk | 25% | | |
| Valuation Risk | 25% | | |
| External Risk | 20% | | |
| **Total** | **100%** | | **___** |
## Risk Rating
- 1-3: Low risk → Standard position size
- 4-5: Moderate risk → Reduced position size
- 6-7: High risk → Small position only if upside justifies
- 8-10: Very high risk → Avoid or speculative position only
## Decision: [Invest / Pass / Watchlist]A one-page risk assessment for early-stage ventures.
# Startup Risk Canvas: [Company Name]
**Date:** [Date] | **Stage:** Pre-seed / Seed / Series A
┌─────────────────────┬─────────────────────┬─────────────────────┐
│ MARKET RISK │ PRODUCT RISK │ TEAM RISK │
│ │ │ │
│ □ Market too small │ □ Can't build it │ □ Key person risk │
│ □ No real pain │ □ Tech doesn't work │ □ Missing skills │
│ □ Timing wrong │ □ UX too complex │ □ Founder conflict │
│ □ Adoption barrier │ □ Can't scale │ □ Can't recruit │
│ │ │ │
│ Risk level: H/M/L │ Risk level: H/M/L │ Risk level: H/M/L │
├─────────────────────┼─────────────────────┼─────────────────────┤
│ FINANCIAL RISK │ COMPETITIVE RISK │ EXECUTION RISK │
│ │ │ │
│ □ Runway < 12 mo │ □ Incumbents │ □ Regulation │
│ □ Unit economics │ □ Well-funded rival │ □ Operations │
│ □ Revenue model │ □ Low barriers │ □ Distribution │
│ □ Fundraising │ □ Network effects │ □ Partnerships │
│ │ (against us) │ │
│ Risk level: H/M/L │ Risk level: H/M/L │ Risk level: H/M/L │
└─────────────────────┴─────────────────────┴─────────────────────┘
## Top 3 Risks & Mitigation
| # | Risk | Mitigation Strategy | Timeline | Success Metric |
|---|------|-------------------|----------|---------------|
| 1 | | | | |
| 2 | | | | |
| 3 | | | | |
## Kill Criteria
What conditions would make us shut down or pivot?
1.
2.
3.# Cybersecurity Risk Assessment: [System/Application]
**Assessor:** [Name] | **Date:** [Date] | **Classification:** Internal/Confidential
## Asset Inventory
| Asset | Type | Data Classification | Business Criticality |
|-------|------|-------------------|---------------------|
| | Server/App/Data/Network | Public/Internal/Confidential/Restricted | Critical/High/Medium/Low |
## Threat Assessment
| Threat | Threat Actor | Likelihood (1-5) | Target Assets |
|--------|-------------|:-:|-------------|
| Data breach | External attacker | | |
| Ransomware | Cybercriminal | | |
| Insider threat | Employee | | |
| DDoS | Hacktivist | | |
| Phishing | External attacker | | |
| Supply chain compromise | Nation-state/Criminal | | |
## Vulnerability Assessment
| Vulnerability | Related Threat | Severity (CVSS) | Current Controls | Gap |
|--------------|---------------|:-:|----------------|-----|
| | | | | |
## Risk Register
| ID | Risk Scenario | Likelihood | Impact | Risk Level | Treatment | Owner |
|----|--------------|:-:|:-:|----------|-----------|-------|
| C1 | | | | | Mitigate/Accept/Transfer/Avoid | |
| C2 | | | | | | |
| C3 | | | | | | |
## Controls Assessment
| Control Category | Implemented? | Effectiveness | Recommendation |
|-----------------|:-:|:-:|----------------|
| Access control (MFA, RBAC) | Yes/No/Partial | H/M/L | |
| Encryption (at rest, in transit) | Yes/No/Partial | H/M/L | |
| Monitoring & logging | Yes/No/Partial | H/M/L | |
| Backup & recovery | Yes/No/Partial | H/M/L | |
| Incident response plan | Yes/No/Partial | H/M/L | |
| Security awareness training | Yes/No/Partial | H/M/L | |
| Patch management | Yes/No/Partial | H/M/L | |
| Network segmentation | Yes/No/Partial | H/M/L | |# Vendor Risk Assessment: [Vendor Name]
**Assessed by:** [Name] | **Date:** [Date]
## Vendor Profile
| Field | Details |
|-------|---------|
| Vendor name | |
| Service provided | |
| Data access level | None / Read-only / Read-write / Admin |
| Data classification | Public / Internal / Confidential / Restricted |
| Contract term | |
| Annual spend | |
## Risk Assessment
| Category | Question | Score (1-5) | Notes |
|----------|----------|:-:|-------|
| **Financial** | Is the vendor financially stable? | | |
| **Security** | Does the vendor have SOC 2 / ISO 27001? | | |
| **Security** | How is data encrypted? | | |
| **Privacy** | Is the vendor GDPR/CCPA compliant? | | |
| **Operational** | What's the vendor's uptime SLA? | | |
| **Operational** | What's the disaster recovery plan? | | |
| **Concentration** | How dependent are we on this vendor? | | |
| **Substitution** | How easy is it to switch vendors? | | |
| **Reputation** | Any history of breaches or incidents? | | |
| **Legal** | Are contract terms acceptable? | | |
| **Total** | | **___/50** | |
## Risk Level
- 10-20: Low risk → Standard monitoring
- 21-30: Medium risk → Enhanced monitoring, review annually
- 31-40: High risk → Active mitigation required, review quarterly
- 41-50: Critical risk → Reconsider vendor relationship
## Decision: [Approve / Approve with Conditions / Reject]For major life decisions — job changes, relocations, investments, relationships.
# Personal Decision Risk Analysis: [Decision]
**Date:** [Date]
## Options
| Option | Description |
|--------|-------------|
| A | |
| B | |
| C (status quo) | |
## For each option, assess:
### Option A: [Name]
| Risk | Probability (1-5) | Impact (1-5) | Reversible? | Mitigation |
|------|:-:|:-:|:-:|-----------|
| Financial risk | | | Yes/No | |
| Career risk | | | Yes/No | |
| Relationship risk | | | Yes/No | |
| Health/wellbeing risk | | | Yes/No | |
| Opportunity cost | | | N/A | |
**Best case:** [description]
**Worst case:** [description]
**Most likely case:** [description]
### The Stoic Test
- What would I regret NOT doing? →
- Can I survive the worst case? →
- What's within my control? →
- What would I advise my best friend? →
## Decision: [Option chosen and reasoning]Failure Mode and Effects Analysis for processes and operations.
# FMEA: [Process/System Name]
**Team:** [Names] | **Date:** [Date]
## Rating Scales
| Score | Severity (S) | Occurrence (O) | Detection (D) |
|:-:|-------------|---------------|---------------|
| 1 | No effect | < 1 in 100,000 | Almost certain to detect |
| 2-3 | Minor | 1 in 10,000 | High chance of detection |
| 4-6 | Moderate | 1 in 1,000 | Moderate chance |
| 7-8 | High | 1 in 100 | Low chance |
| 9-10 | Catastrophic | > 1 in 10 | Almost impossible to detect |
## Analysis
| # | Process Step | Failure Mode | Effect | S | Cause | O | Current Controls | D | RPN | Action |
|---|-------------|-------------|--------|:-:|-------|:-:|-----------------|:-:|:-:|--------|
| 1 | | | | | | | | | | |
| 2 | | | | | | | | | | |
| 3 | | | | | | | | | | |
**RPN** = Severity × Occurrence × Detection (range: 1-1000)
## Priority Actions (RPN > 200)
| Failure Mode | RPN | Recommended Action | Owner | Target Date | New RPN |
|-------------|:-:|-------------------|-------|------------|:-:|
| | | | | | |Executive-level risk overview.
# Strategic Risk Dashboard: [Organization]
**Period:** [Q_/Year] | **CIRO:** [Name]
## Risk Heat Map Summary
| Risk Category | Risk Count | Critical | High | Medium | Low | Trend |
|--------------|:-:|:-:|:-:|:-:|:-:|:-:|
| Strategic | | | | | | ↑↓→ |
| Financial | | | | | | ↑↓→ |
| Operational | | | | | | ↑↓→ |
| Compliance | | | | | | ↑↓→ |
| Technology | | | | | | ↑↓→ |
| Reputational | | | | | | ↑↓→ |
| **Total** | | | | | | |
## Top 5 Risks
| Rank | Risk | Category | Score | Trend | Owner | Status |
|:-:|------|----------|:-:|:-:|-------|--------|
| 1 | | | | ↑↓→ | | |
| 2 | | | | ↑↓→ | | |
| 3 | | | | ↑↓→ | | |
| 4 | | | | ↑↓→ | | |
| 5 | | | | ↑↓→ | | |
## Emerging Risks
| Risk | Potential Impact | Monitoring Actions |
|------|-----------------|-------------------|
| | | |
## Risk Appetite Status
| Category | Appetite | Current Exposure | Within Tolerance? |
|----------|----------|-----------------|:-:|
| Growth investments | High | | Yes/No |
| Operational failures | Low | | Yes/No |
| Regulatory compliance | Zero tolerance | | Yes/No |
| Cybersecurity | Low | | Yes/No |# Change Risk Assessment: [Change Description]
**Change Owner:** [Name] | **Date:** [Date] | **Priority:** Critical/High/Medium/Low
## Change Details
| Field | Details |
|-------|---------|
| Change description | |
| Systems affected | |
| Users affected | |
| Planned date/time | |
| Rollback plan | Yes / No (detail below) |
| Estimated downtime | |
## Risk Assessment
| Risk | Likelihood (1-5) | Impact (1-5) | Score | Mitigation |
|------|:-:|:-:|:-:|-----------|
| System outage | | | | |
| Data loss | | | | |
| Performance degradation | | | | |
| User disruption | | | | |
| Security vulnerability | | | | |
| Integration failure | | | | |
## Go/No-Go Checklist
- [ ] Rollback plan documented and tested
- [ ] Stakeholders notified
- [ ] Backup completed
- [ ] Testing environment validated
- [ ] Change approved by CAB
- [ ] Monitoring alerts configured
- [ ] Support team briefed
## Decision: [Approve / Reject / Defer]| Score | Label | Description | Probability |
|---|---|---|---|
| 1 | Rare | Exceptional circumstances | < 5% |
| 2 | Unlikely | Could occur but not expected | 5-25% |
| 3 | Possible | Might occur at some point | 25-50% |
| 4 | Likely | Will probably occur | 50-75% |
| 5 | Almost Certain | Expected to occur | > 75% |
| Score | Label | Financial | Operational | Reputational |
|---|---|---|---|---|
| 1 | Negligible | < $10K | No disruption | No notice |
| 2 | Minor | $10K-100K | Brief disruption | Local mention |
| 3 | Moderate | $100K-1M | Service degraded | Industry press |
| 4 | Major | $1M-10M | Service down | National press |
| 5 | Catastrophic | > $10M | Extended outage | Existential threat |
| Strategy | Description | When to Use |
|---|---|---|
| Avoid | Eliminate the risk by changing plans | Risk is unacceptable and can be avoided |
| Mitigate | Reduce probability or impact | Risk is significant but manageable |
| Transfer | Shift risk to a third party (insurance, contracts) | Risk is better managed by someone else |
| Accept | Acknowledge and monitor | Risk is low or cost of mitigation exceeds benefit |
| Exploit | Maximize positive risk (opportunity) | Upside risk you want to capture |
Standards & Frameworks:
- ISO 31000 — Risk Management
- COSO ERM — Enterprise Risk Management
- NIST SP 800-30 — IT Risk Assessment
Practice scenario-based risk assessment: For interactive scenarios that walk you through real-world risk decisions with guidance from proven frameworks, explore KeepRule Scenarios — apply risk thinking to investment, career, and life decisions.
Have a risk template for a specific industry or situation? PRs welcome. Please include context for when to use the template and an example.
MIT License — see LICENSE for details.