Risk Assessment Checklist: Hazards, Controls, Residual Risk and Actions
A practical risk assessment checklist for consulting work, covering activity and hazards, existing controls, residual risk review, actions and owners.

A risk assessment checklist should stop weak assessments before they are approved. It should catch vague activities, missing people affected, controls that do not exist yet, unexplained residual risk and actions with no owner.
This checklist uses a consulting scenario: a team is preparing a strategy review engagement involving discovery interviews, client documents, subcontractor analysis and a recommendations report. Adapt the checklist to your own work and jurisdiction.
Check the Activity and Hazards
A risk assessment begins with a specific activity. "Client project" is too broad. "Discovery interviews for the purchasing strategy review" is specific enough to identify hazards.
Checklist questions:
- Is the activity named clearly?
- Are start and end points defined?
- Are affected people, services, information and assets listed?
- Were people familiar with the work involved?
- Are assessment limits recorded?
- Are credible hazards described with causes and consequences?
The UK government's Orange Book risk-management principles connect identifying and assessing risk with treatment, monitoring and reporting. Its formal scope is government departments and relevant public bodies. We use it here as an organizational-risk reference, not as a legal requirement for a private consultancy. This checklist applies that management logic to the fictional engagement: define the uncertain event, establish the current evidence and make the next decision explicit.
Consulting example:
Activity: Discovery interviews and evidence review for purchasing strategy engagement.
Hazard: Interview notes include personal criticism of named staff and are copied into the client-facing report.
Potential effect: Unnecessary disclosure, loss of trust and possible breach of confidentiality obligations.
Check Existing Controls
Existing controls are controls that operate now. Do not count a control you intend to create after approval.
Checklist questions:
- Is each existing control already implemented?
- Is there evidence the control operates?
- Is the control specific to the hazard?
- Are access, training, review and approval controls recorded?
- Are planned controls moved to the action plan?
- Does the assessment avoid relying on "experienced staff" as the only control?
Example:
Existing controls: Approved interview guide limits topics. Raw notes are stored in the project workspace. Report author must use role-level attribution unless the engagement lead approves a named quotation.
Weak control:
Consultants will be careful.
Better control:
The peer reviewer checks the recommendations report against the evidence register and flags unnecessary personal details before client issue.
For information-security risks, NIST SP 800-30 Revision 1 provides guidance on assessing risks to information systems and organizations. Use that scope for the client-access example: identify how information could be disclosed, which weakness enables the event and what the consequences would be. Our checklist asks for evidence that an access restriction operates now, such as a reviewed permission record, rather than accepting an untested statement that files are secure.
Check Residual Risk
Residual risk is the remaining exposure after existing controls. It is where the decision maker decides whether work can proceed, whether further action is needed or whether the activity should change.
Checklist questions:
- Does the assessment explain likelihood and consequence method?
- Is residual risk assessed after existing controls?
- Is the residual rating explained in words?
- Are high or uncertain risks escalated?
- Does the decision maker approve remaining exposure?
- Are restrictions recorded?
Example:
Residual risk remains moderate because raw notes still exist in the workspace and report drafting requires human judgment. Work may proceed only after interviewer briefing and peer review are complete.
Avoid unexplained numbers. A score of "6" tells a reader little unless the method and meaning are clear. If your organization uses a matrix, include or reference the approved method.
For this consulting engagement, review project retrospectives, client complaints, access reviews, quality findings and incidents. These are suggested evidence sources for the worked example. Check the period and relevance of each record: a clean access review from an unrelated project does not establish that this client's workspace is correctly configured today. Record contrary evidence as well as evidence supporting the current control.
Add a short narrative beside any rating. A matrix can help compare items, but the approval decision should not depend on a number alone.
Example:
Residual rating: medium. Reason: the team has an approved workspace and peer review, but raw interview notes still contain sensitive comments and the report author must decide what is necessary for the client-facing output. Work may proceed only after interviewer briefing and peer review are scheduled.
That narrative helps the reviewer see why the rating was chosen and what restriction matters. It also prevents a later reader from assuming "medium" meant the risk was acceptable without conditions.
Check Actions and Owner
Every further action should have an owner, due date and evidence of completion. Otherwise it is a wish.
Checklist questions:
- Does each action reduce a specific residual risk?
- Is the action owner named by role or person?
- Is the due date realistic?
- Is completion evidence defined?
- Are actions needed before work starts separated from later improvements?
- Does the assessment say who verifies completion?
Example action table:
| Action | Owner | Due | Evidence |
|---|---|---|---|
| Brief interviewers on note handling and attribution | Engagement lead | Before first interview | Briefing record |
| Create restricted subcontractor analysis folder | Project manager | Before subcontractor access | Access screenshot |
| Add scope-check column to decision log | Engagement lead | Before analysis workshop | Updated log |
| Peer review final report for unsupported statements | Peer reviewer | Before issue | Review note |
Actions before work starts should be treated as conditions. If they are not complete, the work should not proceed unless the authorized reviewer accepts an alternative.
Check that action owners have authority to complete the action. Naming a junior analyst as owner for a workspace-permission change may look accountable, but it will fail if only the project manager can change access. Use the owner field for the person who can make the change happen, and use a support field if someone else gathers information.
Draft action wording:
Owner: project manager. Support: analyst confirms folder list. Completion evidence: screenshot of restricted access and decision-log note confirming subcontractor scope.
Approval and Review Criteria
The final checklist step is approval. Approval should not be silent. It should record whether the activity is approved, approved with restrictions or not approved.
Review criteria:
- Activity: The work is specific and bounded.
- Hazards: Credible events, causes and consequences are described.
- Affected parties: Employees, client staff, subcontractors, visitors, services, information and assets are considered where relevant.
- Controls: Existing controls are real and evidenced.
- Residual risk: Remaining exposure is explained and reviewed.
- Actions: Further actions have owner, due date and evidence.
- Approval: A responsible decision maker authorizes work and restrictions.
- Review triggers: Change, incident, control failure and scheduled review are recorded.
Check separately whether the client contract, your organization's policy or a requirement applicable to the actual activity specifies an approval or recording process. Do not assume that a workplace-safety recording rule automatically governs this commercial project-risk document. Here, the operational reason to retain the assessment is straightforward: a later reviewer should be able to reconstruct the information available, the alternatives considered and the person who accepted the remaining exposure.
For consulting work, add one more approval check: does the risk assessment match the agreed scope? If the assessment assumes subcontractor analysis, client interviews or access to sensitive records that the contract does not authorize, pause and resolve the scope before approving the work. Risk review should not quietly expand the engagement.
Prepare a Reviewed Assessment
The consulting risk assessment template is an editable Word document with sections for activity and people affected, hazards and existing controls, evaluation and further action, approval and review. Use this checklist to challenge the draft before the decision maker signs it.
A good risk assessment does not try to predict every possible problem. It makes credible risks, current controls, remaining exposure and responsible actions visible before the work goes ahead.
Last updated: September 26, 2026
Frequently Asked Questions
Related Articles
Audit Checklist Best Practices
Best practices for audit checklists, including scope, evidence, findings, actions, closure review, failure modes and sample wording.
Audit Checklist Checklist: Review Your Audit Form Before You Use It
A practical audit checklist checklist with decision gates for scope, evidence, findings, actions and closure review.
Audit Checklist Examples: Scope, Evidence, Findings and Closure
Audit checklist examples for consulting work, covering audit scope, evidence to inspect, findings and actions, closure review and practical draft wording.
Business Continuity Plan Best Practices for Consulting Teams
Business continuity plan best practices for consulting teams, including critical services, recovery priorities, communications, exercises and review criteria.
Business Continuity Plan Checklist for Consulting Teams
A practical business continuity plan checklist for consulting work, covering critical services, recovery priorities, communications, exercises and review criteria.
Business Continuity Plan Examples: Consulting Scenarios and Recovery Priorities
Business continuity plan examples for consulting teams, with critical services, recovery priorities, communications, exercises and review criteria.