How to Write a Consulting Risk Assessment: Activities, Controls and Residual Risk
How to write a consulting risk assessment for a strategy review engagement, including activities and hazards, existing controls, residual risk, actions, owners, draft wording and approval checks.

A consulting risk assessment should describe the real work, not a generic list of business worries. It should identify what the team is about to do, who or what could be affected, what controls already exist, what risk remains and who owns further action.
This guide uses a fictional scenario: a consulting team is preparing a strategy review engagement for a client in a regulated sector. The work includes discovery interviews, review of confidential operating data, analysis of organizational options and a recommendation presentation to senior leaders. The main risks are not only commercial. They include confidentiality, scope drift, unsupported recommendations, staff workload, client-site attendance and mishandling sensitive interview material.
The UK government's Orange Book connects risk assessment with organizational objectives, responses, monitoring and reporting. Its formal scope is government bodies, so it is a reference framework here rather than a legal requirement for a private consultancy. For the engagement's information-security risks, NIST SP 800-30 Revision 1 offers a more specific assessment reference. Keep each source within that scope: commercial delivery judgments remain project decisions, while confidential-file exposure needs an information-security assessment.
Define the activity and people affected
Start with a tight activity description. If the activity is vague, the risks will be vague.
Draft language:
Activity assessed. Strategy review engagement for [Client], including discovery interviews, review of client operating documents, preparation of analysis pack and recommendation workshop.
People and assets affected. Consulting team, client interviewees, client sponsor, client confidential information, project records, firm reputation and delivery schedule.
Assessment limits. This assessment does not cover legal advice, clinical advice, financial audit, client implementation work or travel risk outside approved engagement locations.
This prevents the risk assessment from becoming a catch-all. If later work is added, reassess it.
Identify hazards and credible events
For consulting, hazards may be conditions that can cause harm to people, information, client decisions or delivery quality.
Examples:
| Hazard or event | Possible consequence |
|---|---|
| Confidential client material shared outside project team | Unauthorized disclosure, contract breach, client harm |
| Interview notes stored in wrong folder | Loss of control over personal or sensitive information |
| Client asks for advice outside scope | Unreviewed recommendation, unpaid work, liability exposure |
| Unsupported finding presented as fact | Poor client decision, rework, credibility loss |
| Excessive workshop schedule | fatigue, poor facilitation, employee wellbeing concern |
| Travel to unfamiliar client site | personal safety or access issue |
Avoid padding the table with remote possibilities that nobody will act on. The best hazards are credible enough that a control can be named.
Separate existing controls from planned actions
A common risk assessment mistake is counting future intentions as current controls. If access permissions have not been set up yet, they are not an existing control.
Existing controls for the strategy review might include:
- approved statement of work
- named engagement lead
- secure project workspace
- confidentiality training
- evidence index
- review gate before recommendation workshop
- client-approved interview protocol
Planned actions might include:
- confirm folder permissions before interviews begin
- brief interviewers on sensitive topics
- create escalation route for out-of-scope requests
- assign independent reviewer for analysis pack
Draft language:
Planned actions are not treated as existing controls until completed and evidenced. The engagement lead reviews residual risk only after the control owner confirms completion.
Prioritize the consulting risks by the consequence for the agreed engagement and the evidence about how the event could occur. This is our recommended decision method for the worked example, not a workplace-safety rule. A threatened disclosure of interview notes may require an immediate access change; an uncertain presentation preference may need only sponsor clarification. Record why one issue receives urgent attention and who can authorize the response instead of assigning the same action to every row.
Review residual risk and decision authority
Residual risk is the exposure left after current controls. Use a simple method the team understands. For example: low, medium or high based on likelihood and consequence. More important than the scoring scale is the explanation.
Example:
| Risk | Existing controls | Residual risk | Decision |
|---|---|---|---|
| Confidential data shared outside project | Secure workspace, access list, confidentiality training | Medium until permissions checked | Work starts after folder owner confirms access |
| Unsupported recommendation | Evidence index, analysis review gate | Low if review gate completed | Release controlled by engagement lead |
| Scope drift | Approved SOW, change request route | Medium | Out-of-scope requests logged and escalated |
Do not hide behind numbers. A score of "6" means little unless the reader can see what remains and who accepted it.
Residual risk review should also name restrictions. A decision maker may accept the engagement only if certain limits remain in place: no recording of interviews, no export of client data, no advice on regulated decisions, or no client-site work without host approval. Put those restrictions in the assessment so the delivery team can follow them.
Assign actions and owners
Actions should be specific, owned and reviewable.
Weak action:
Be careful with confidential documents.
Stronger action:
Before interviews begin, [project administrator] confirms that only approved team members have access to the client project workspace and saves the access list in the project file. Due: [date]. Reviewer: engagement lead.
Each action should include owner, due date, evidence and decision point. If an action is not completed, the assessment should say whether work pauses, proceeds with restrictions or escalates.
For personal data incidents, jurisdiction matters. In the UK, the ICO says organizations must assess the likely risk to people's rights and freedoms after a personal data breach ICO UK GDPR breach reporting. The risk assessment should refer to the organization's approved data incident process rather than inventing a separate route.
Add review triggers to the action plan. Reassess when the client changes the scope, new categories of information are introduced, an interview group expands, a key control fails or an incident occurs. Consulting work can change quickly, and an assessment approved at kickoff may no longer describe the work by the time recommendations are drafted.
Keep completed actions linked to evidence. A tick in the action table is not enough if nobody can see the access list, briefing record or reviewer approval. The assessment should help a later reviewer understand what was actually controlled.
Approval check before work starts
Review the completed assessment:
- Activity: Is the strategy review engagement defined clearly?
- Affected people and assets: Are client interviewees, staff, information and services included?
- Hazards: Are credible consulting hazards listed, not generic business risks?
- Existing controls: Are only controls already in place counted?
- Residual risk: Does each rating explain what remains after controls?
- Actions: Does each action have an owner, due date and evidence?
- Decision authority: Has the responsible decision maker accepted remaining risk or required more control?
- Review triggers: Will the assessment be updated after scope change, incident, control failure or major client request?
The consulting risk assessment template is an editable Word draft with sections for activity and people affected, hazards and controls, evaluation and further action, review and approval. Use it to structure the assessment, then replace examples with verified engagement facts and locally reviewed requirements.
Last updated: September 26, 2026
Frequently Asked Questions
Related Articles
Audit Checklist Best Practices
Best practices for audit checklists, including scope, evidence, findings, actions, closure review, failure modes and sample wording.
Audit Checklist Checklist: Review Your Audit Form Before You Use It
A practical audit checklist checklist with decision gates for scope, evidence, findings, actions and closure review.
Audit Checklist Examples: Scope, Evidence, Findings and Closure
Audit checklist examples for consulting work, covering audit scope, evidence to inspect, findings and actions, closure review and practical draft wording.
Business Continuity Plan Best Practices for Consulting Teams
Business continuity plan best practices for consulting teams, including critical services, recovery priorities, communications, exercises and review criteria.
Business Continuity Plan Checklist for Consulting Teams
A practical business continuity plan checklist for consulting work, covering critical services, recovery priorities, communications, exercises and review criteria.
Business Continuity Plan Examples: Consulting Scenarios and Recovery Priorities
Business continuity plan examples for consulting teams, with critical services, recovery priorities, communications, exercises and review criteria.