top of page

Am I Capable of Assessing Risk?

Writer: Calvin Webb III
Calvin Webb III
Aug 1
3 min read

Updated: 4 hours ago

Public-sector professionals from different departments reviewing organizational processes and discussing potential risks.

If I asked you what comes to mind when you hear the word risk, your first thought might be insurance, security, safety, or a specialized person or team responsible for risk management within your organization. You might also think about personal risks associated with investing, parenting, or driving.


If I asked what could go wrong on a camping trip to Alaska, you could immediately identify risks such as bears, insufficient food, frostbite, injury, or getting lost. If I asked about the value of a home alarm system, you could probably explain that it can deter break-ins, detect fires, and help you monitor your home.


Risk Assessment Is Already Part of Your Work


If I asked what risks you see in your job, however, you might not feel as comfortable answering. Perhaps assessing risk seems outside your normal responsibilities.

The reality is that we are all capable of contributing to risk assessment within our organizations, although we may not recognize it as a vital part of our work. We constantly assess risk as we make decisions and carry out our responsibilities, we simply may not realize that we are doing it.


When you decide whether to sign a form, what are you doing? When you choose one course of action over another, what are you doing? When you train someone to perform a job well, what are you doing?


In each case, you are identifying what might go wrong, considering the possible consequences, and taking steps to manage risk. You are inherently applying risk management principles in these scenarios.


Effective Risk Assessment Requires Different Perspectives


Gathering input from multiple people is foundational to Gradient’s approach to risk management. Assessing risk is not solely a responsibility of the management team. People throughout the organization can play an important role.


Receiving input from a variety of perspectives is essential because each person brings different responsibilities, experiences, abilities, and ways of seeing the organization. Someone working directly within a process may recognize an emerging problem that is not yet visible to organizational leadership. A sound risk-management process therefore needs information from multiple levels and functions.


Gradient’s risk-assessment process gathers input from across the organization levels, summarizes that information, and allows the management team to utilize and act on that input.


Whatever your role may be, the following questions can help you think more deliberately about risk within your organization and its processes. I encourage you to discuss them regularly with your teams and organizational leadership.


Someone working directly within a process may recognize an emerging problem that is not yet visible to organizational leadership.

Organizational Risk Assessment Questions


  • How often do I think about the risks affecting the processes, departments, and groups in which I am involved? Is that often enough?

  • When I look back at our processes, have failures or breakdowns occurred? Which risks were not adequately identified, controlled, or managed?

  • What could go wrong within the processes or departments in which I am involved? Do we have measures in place to reduce the likelihood or impact of those risks? If not, what should we do?

  • Do I ask other leaders, my direct reports, and their teams about the issues, risks, or failures they see? Do I actively seek their observations and suggestions?

  • Does our management team understand and address broader organization-wide risks?

  • Are our most important organization-wide risks connected to processes, controls, and responsibilities designed to help mitigate them?

  • Does our organization, department, or team have a strategy for using available data including operational information, ERP data, and key performance indicators to monitor and respond to key risks?


If you would like to learn more about Gradient’s enterprise risk management (ERM) services, please use the contact form on our website or email info@gogradient.com. You can also review COSO’s enterprise risk management guidance.

Comments


bottom of page