How to Write a Consulting Risk Assessment: Activities, Controls and Residual Risk

How to write a consulting risk assessment for a strategy review engagement, including activities and hazards, existing controls, residual risk, actions, owners, draft wording and approval checks.

DocStaple editorial team
September 26, 20266 min read
Adapt the document to consulting: Activity and hazards; Existing controls; Residual risk review; Actions and owner.

A consulting risk assessment should describe the real work, not a generic list of business worries. It should identify what the team is about to do, who or what could be affected, what controls already exist, what risk remains and who owns further action.

This guide uses a fictional scenario: a consulting team is preparing a strategy review engagement for a client in a regulated sector. The work includes discovery interviews, review of confidential operating data, analysis of organizational options and a recommendation presentation to senior leaders. The main risks are not only commercial. They include confidentiality, scope drift, unsupported recommendations, staff workload, client-site attendance and mishandling sensitive interview material.

The UK government's Orange Book connects risk assessment with organizational objectives, responses, monitoring and reporting. Its formal scope is government bodies, so it is a reference framework here rather than a legal requirement for a private consultancy. For the engagement's information-security risks, NIST SP 800-30 Revision 1 offers a more specific assessment reference. Keep each source within that scope: commercial delivery judgments remain project decisions, while confidential-file exposure needs an information-security assessment.

Define the activity and people affected

Start with a tight activity description. If the activity is vague, the risks will be vague.

Draft language:

Activity assessed. Strategy review engagement for [Client], including discovery interviews, review of client operating documents, preparation of analysis pack and recommendation workshop.

People and assets affected. Consulting team, client interviewees, client sponsor, client confidential information, project records, firm reputation and delivery schedule.

Assessment limits. This assessment does not cover legal advice, clinical advice, financial audit, client implementation work or travel risk outside approved engagement locations.

This prevents the risk assessment from becoming a catch-all. If later work is added, reassess it.

Identify hazards and credible events

For consulting, hazards may be conditions that can cause harm to people, information, client decisions or delivery quality.

Examples:

Hazard or eventPossible consequence
Confidential client material shared outside project teamUnauthorized disclosure, contract breach, client harm
Interview notes stored in wrong folderLoss of control over personal or sensitive information
Client asks for advice outside scopeUnreviewed recommendation, unpaid work, liability exposure
Unsupported finding presented as factPoor client decision, rework, credibility loss
Excessive workshop schedulefatigue, poor facilitation, employee wellbeing concern
Travel to unfamiliar client sitepersonal safety or access issue

Avoid padding the table with remote possibilities that nobody will act on. The best hazards are credible enough that a control can be named.

Separate existing controls from planned actions

A common risk assessment mistake is counting future intentions as current controls. If access permissions have not been set up yet, they are not an existing control.

Existing controls for the strategy review might include:

  • approved statement of work
  • named engagement lead
  • secure project workspace
  • confidentiality training
  • evidence index
  • review gate before recommendation workshop
  • client-approved interview protocol

Planned actions might include:

  • confirm folder permissions before interviews begin
  • brief interviewers on sensitive topics
  • create escalation route for out-of-scope requests
  • assign independent reviewer for analysis pack

Draft language:

Planned actions are not treated as existing controls until completed and evidenced. The engagement lead reviews residual risk only after the control owner confirms completion.

Prioritize the consulting risks by the consequence for the agreed engagement and the evidence about how the event could occur. This is our recommended decision method for the worked example, not a workplace-safety rule. A threatened disclosure of interview notes may require an immediate access change; an uncertain presentation preference may need only sponsor clarification. Record why one issue receives urgent attention and who can authorize the response instead of assigning the same action to every row.

Need a ready-made risk assessment template for your consulting?

Download a pre-built document with industry-specific categories, sections, and formatting.

Review residual risk and decision authority

Residual risk is the exposure left after current controls. Use a simple method the team understands. For example: low, medium or high based on likelihood and consequence. More important than the scoring scale is the explanation.

Example:

RiskExisting controlsResidual riskDecision
Confidential data shared outside projectSecure workspace, access list, confidentiality trainingMedium until permissions checkedWork starts after folder owner confirms access
Unsupported recommendationEvidence index, analysis review gateLow if review gate completedRelease controlled by engagement lead
Scope driftApproved SOW, change request routeMediumOut-of-scope requests logged and escalated

Do not hide behind numbers. A score of "6" means little unless the reader can see what remains and who accepted it.

Residual risk review should also name restrictions. A decision maker may accept the engagement only if certain limits remain in place: no recording of interviews, no export of client data, no advice on regulated decisions, or no client-site work without host approval. Put those restrictions in the assessment so the delivery team can follow them.

Assign actions and owners

Actions should be specific, owned and reviewable.

Weak action:

Be careful with confidential documents.

Stronger action:

Before interviews begin, [project administrator] confirms that only approved team members have access to the client project workspace and saves the access list in the project file. Due: [date]. Reviewer: engagement lead.

Each action should include owner, due date, evidence and decision point. If an action is not completed, the assessment should say whether work pauses, proceeds with restrictions or escalates.

For personal data incidents, jurisdiction matters. In the UK, the ICO says organizations must assess the likely risk to people's rights and freedoms after a personal data breach ICO UK GDPR breach reporting. The risk assessment should refer to the organization's approved data incident process rather than inventing a separate route.

Add review triggers to the action plan. Reassess when the client changes the scope, new categories of information are introduced, an interview group expands, a key control fails or an incident occurs. Consulting work can change quickly, and an assessment approved at kickoff may no longer describe the work by the time recommendations are drafted.

Keep completed actions linked to evidence. A tick in the action table is not enough if nobody can see the access list, briefing record or reviewer approval. The assessment should help a later reviewer understand what was actually controlled.

Approval check before work starts

Review the completed assessment:

  • Activity: Is the strategy review engagement defined clearly?
  • Affected people and assets: Are client interviewees, staff, information and services included?
  • Hazards: Are credible consulting hazards listed, not generic business risks?
  • Existing controls: Are only controls already in place counted?
  • Residual risk: Does each rating explain what remains after controls?
  • Actions: Does each action have an owner, due date and evidence?
  • Decision authority: Has the responsible decision maker accepted remaining risk or required more control?
  • Review triggers: Will the assessment be updated after scope change, incident, control failure or major client request?

The consulting risk assessment template is an editable Word draft with sections for activity and people affected, hazards and controls, evaluation and further action, review and approval. Use it to structure the assessment, then replace examples with verified engagement facts and locally reviewed requirements.

Last updated: September 26, 2026

Frequently Asked Questions

Get the Consulting Risk Assessment Template

Download a pre-built risk assessment template with consulting-specific sections, wording, and drafting guidance.

Editable Word files. One-time purchase.