How Do You Assess Risk Management?

Photo of author
Written By Chris Ekai

You assess risk management by testing whether the system that finds and treats risk actually works: define scope against ISO 31000, gather evidence from documents, interviews, and loss data, score each component on a five-level maturity scale, check key risk indicators, and close with independent assurance and a board-approved action plan.

Over the Easter 2025 weekend, attackers phoned a third-party help desk and talked it into resetting a Marks & Spencer employee’s password. That one call grew into roughly 300 million pounds of lost operating profit and 46 days without online orders, the costliest password reset in British retail history.

Chairman Archie Norman later told a UK parliamentary sub-committee that the Scattered Spider collective ran the intrusion using DragonForce ransomware. M&S carried cyber risk on its register; nobody had tested whether an outsourced help desk could be talked into handing over access.

Assess Risk Management: Key Takeaways
The M&S breach cost around 300 million pounds in operating profit and kept online orders down for 46 days; the entry point was a password reset at a third-party help desk that no evaluation had tested.
Assess risk management across seven components: governance, appetite, identification, analysis, treatment, monitoring, and culture, each scored on a five-level maturity scale.
IIA Risk in Focus 2026 puts cybersecurity top for the fifth straight year, named by 73% of more than 4,000 chief audit executives across 131 countries.
Balance five evidence sources: interviews, loss data and KRIs, document review, control testing, and external benchmarks, with no single source carrying more than about a quarter of the weight.
The Global Internal Audit Standards, effective January 2025, require an external quality assessment of the audit function at least once every five years.
Reassess annually at minimum, and re-run the exercise after any merger, new market entry, major system change, or material incident.

That gap between a documented risk and a tested control is exactly what a risk management assessment exists to find. This guide walks through the method we use with clients: seven components, seven steps, a maturity scale, and the metrics that separate working programs from paper ones.

What a Risk Management Assessment Actually Measures

A risk management assessment evaluates the machinery, while a risk assessment evaluates individual exposures. You are not asking what could hurt the organization; you are asking whether the process that answers that question works. The two get confused constantly, and the distinction matters for scoping.

ISO 31000:2018 frames the assessment target as principles, framework, and process, and its clause 6.6 makes monitoring and review of the process itself a standing requirement rather than an option. COSO’s ERM framework adds twenty principles across five components, from governance through to review and revision.

In practice you are grading the full risk management lifecycle: how risks get identified, analyzed, treated, monitored, and reported. A program can score well on paperwork and still fail the M&S test, because documents prove intent while only testing proves function.

The 300 Million Pound Case for Testing Your Defences

The financial anatomy of the M&S incident rewards close reading, and it starts with the profit line. Computer Weekly reported statutory pre-tax profit falling from 391.9 to 3.4 million pounds for the half-year to 27 September 2025, with around 9.4 million customers’ data taken.

How Do You Assess Risk Management?

Figure 1. The M&S attack in four numbers: the cost of an untested assumption.

Norman declined to tell MPs whether a ransom was paid, and has since called for mandatory disclosure of material attacks. His more useful admission was simpler: the entry route was social engineering at a supplier, human error rather than under-investment.

The assessment lesson sits in that admission. M&S almost certainly passed reviews confirming cyber risk was documented, owned, and mitigated on paper. The question nobody scored was whether third-party access controls would survive a persuasive phone call on a holiday weekend.

Seven Components Every Evaluation Must Cover

Component coverage keeps the exercise honest, because weak programs hide behind their strongest function. A brilliant risk register cannot compensate for a board that never reads it. We score seven components separately, drawing the structure from ISO 31000 and COSO’s principle set.

Component What you examine Evidence that counts
1. Governance Board oversight, roles, committee structure, policy Minutes showing risk debate, not just noting
2. Appetite Defined appetite and tolerances linked to strategy Decisions declined or changed on appetite grounds
3. Identification How new and emerging risks enter the register Register churn; emerging risks added last quarter
4. Analysis Scoring method, criteria, quantification where it pays Consistent scoring across units; challenge records
5. Treatment Mitigation selection, ownership, deadlines, funding Actions closed on time; controls tested, not asserted
6. Monitoring KRIs, escalation triggers, reporting cadence Breaches escalated within the stated window
7. Culture Tone, incentives, willingness to report bad news Near-miss reporting rates; survey trend data

Score every component even when one clearly dominates the risk conversation. The advantages of disciplined risk management compound across components, and so do the weaknesses. A single untested component, like a supplier help desk with password-reset authority, can end up carrying the whole loss on its own.

A Step-by-Step Method to Assess Risk Management

To assess risk management well, run seven steps in sequence and resist skipping to scoring. Teams that jump straight to a maturity number anchor on impressions instead of evidence. The steps below take four to eight weeks in a mid-sized organization, depending on interview volume.

Step Action Output
1 Set scope and criteria against ISO 31000 and your framework Assessment charter agreed by the sponsor
2 Collect documents: policy, register, appetite, reports Document inventory with gaps flagged
3 Interview leaders, risk owners, and frontline staff Themed findings; culture signals recorded
4 Analyze loss events, near misses, and KRI history Evidence of whether the system caught real events
5 Test a sample of controls and escalation paths end to end Pass and fail results with reperformance notes
6 Score each of the seven components on the maturity scale Scored profile with rationale per component
7 Report findings, agree actions, owners, and dates Board-approved improvement plan

Weight your evidence deliberately at every step, and write the weighting into the assessment charter before fieldwork opens so nobody relitigates it later. Interviews alone flatter the program, and documents alone flatter the authors, so we cap any single evidence source near a quarter of the total picture. IEC 31010 catalogues supporting techniques, from structured interviews to bow-tie analysis.

How Do You Assess Risk Management?

Figure 2. A balanced evidence mix keeps any single flattering source from driving the score.

Step five is where the M&S lesson lives, so test controls the way an attacker or an auditor would. Phone the help desk and ask for a reset. Trace one escalation from breach to board paper; worked examples of that tracing beat any questionnaire response.

Scoring Maturity: From Ad Hoc to Embedded

Maturity scales turn qualitative findings into a number a board can track. We use five levels, and the NC State ERM Initiative’s 2025 State of Risk Oversight report, drawn from 273 U.S. organizations surveyed in spring 2025, keeps finding that risk processes trail the growth in risk volume.

How Do You Assess Risk Management?

Figure 3. Five maturity levels: most organizations we assess sit between levels 2 and 3.

Resist averaging the seven scores into one number, because averages hide the story. A profile of fours with a single one in third-party monitoring is a different risk than uniform threes, and the AICPA’s 16th edition report shows most programs still concede ground between stated intent and daily practice.

Level What it looks like Typical tell in evidence
1. Ad hoc Risk handled reactively by individuals No shared register; heroics after incidents
2. Repeatable Registers exist; quality varies by team Inconsistent scoring; stale entries
3. Defined One framework, common language, training Consistent documents; thin usage evidence
4. Managed KRIs live; decisions cite risk information Escalations on time; appetite invoked in minutes
5. Embedded Risk shapes strategy, capital, and pay Strategy papers carry risk analysis by default

Let stakes set the target level, because moving one level costs real money and vanity repays none of it. Critical infrastructure and regulated finance justify level-five ambitions, while a mid-market firm often earns its best return reaching a solid four on monitoring and risk appetite discipline.

The Metrics That Prove Effectiveness

Numbers keep the follow-up honest long after the assessment report has been filed and the workshop goodwill has faded. Key risk indicators measure the risks themselves, while program metrics measure the machinery that manages them, and mature teams report both to the board on a fixed cadence.

Six program metrics do most of the monitoring work, and we ask every client to track them from the first month after the assessment closes. Put them on a single page, name an owner beside each number, and review the page monthly:

  • Action closure rate: share of agreed mitigations closed by their original due date, reported monthly.
  • Register freshness: percentage of risks reviewed within their stated review cycle.
  • Escalation speed: days from KRI breach to documented management response.
  • Near-miss ratio: near misses reported per loss event; rising is healthy, silence is not.
  • Emerging-risk churn: new risks added and retired per quarter, proving the radar still turns.
  • Maturity delta: component scores versus the last assessment, with rationale for every move.

Pick thresholds before the first report, because green, amber, and red bands force conversations that raw numbers let everyone dodge. Software helps at scale, and our reviews of risk assessment software and supporting techniques cover platforms that automate KRI collection.

Independent Assurance and the Three Lines

Self-assessment has a ceiling, because the people who built the program grade it gently. The IIA’s Global Internal Audit Standards, effective January 2025, require an external quality assessment at least every five years. The parallel for risk teams holds even where no rule compels it, and boards increasingly expect the same rhythm.

Internal audit supplies the third-line view, and auditing risk management is its own craft with its own tests. The second line runs the annual self-assessment, and an external reviewer every three to five years resets both the baseline and the blind spots.

How Do You Assess Risk Management?

Figure 4. Cybersecurity leads for the fifth straight year; weight your assessment scope accordingly.

Risk in Focus 2026, the IIA’s survey of more than 4,000 chief audit executives across 131 countries, puts cybersecurity first at 73%, with digital disruption at 48% and business resilience at 47%. Protiviti’s companion survey reads the same way for boards.

Where Programs Stall, and How to Unstick Them

Most failed assessments die in the follow-through; the fieldwork rarely kills one. PwC’s risk leader pulse survey found 36% of executives prioritizing stronger risk management since early 2025, yet stated intent is everywhere in survey data while closed, evidenced actions remain the scarce commodity.

Pitfall Root cause Remedy
Scores without evidence Workshop consensus replaces testing Require one tested artifact per component score
Everything scores three Anchoring and politeness bias Force-rank components; justify every non-move
Report shelved No owners, dates, or budget attached Board approves actions, not findings
Third parties out of scope Contract said the supplier handles it Test supplier-facing controls end to end
Assessed once, never again Treated as a project, not a cycle Fixed annual cadence plus event triggers

A fixed annual cadence is the floor, and certain events should pull the next assessment forward regardless of what the calendar says. Re-run the full exercise ahead of schedule, at least for the affected components, the moment any of these five triggers fires:

  • A merger, acquisition, or divestment changes the risk profile.
  • Entry into a new market, product line, or regulatory regime.
  • A material incident, loss event, or near miss inside the firm or at a close peer.
  • A major system migration or a new critical supplier goes live.
  • Leadership turnover in the C-suite or in the risk function itself.

The UK NCSC board toolkit makes a similar point for cyber governance: boards should ask testable questions, and a program that cannot answer them has already told you its maturity level. Managing risk day to day is different work from proving that the management functions, and both deserve named techniques.

Frequently Asked Questions About Assessing Risk Management

How often should you assess risk management?

Annually at minimum, with a lighter quarterly pulse on KRIs and action closure. Re-run a full assessment after any merger, new market entry, major system change, or material incident. Regulated sectors often mandate the cycle, and UK resilience reporting now assumes the evidence is current.

What is the difference between a risk assessment and a risk management assessment?

The difference is altitude. A risk assessment scores specific exposures, meaning the likelihood and impact of individual risks, while a risk management assessment judges the system that produces those scores, covering governance, appetite, process, monitoring, and culture. You need both, and confusing them produces scopes that satisfy neither purpose.

Who should carry out a risk management assessment?

Alternate between the second line and independent reviewers. The risk function can run the annual self-assessment using a published rubric, and an external assessor every three to five years removes house bias. Internal audit provides third-line assurance either way, testing evidence rather than accepting assertions.

Which standards apply when you assess risk management?

Start with ISO 31000:2018 as the spine, add IEC 31010 for its catalogue of techniques, and layer COSO ERM where the board wants its twenty principles reflected. For cyber-heavy scopes, NIST CSF 2.0 supplies control benchmarks. Pick one spine and map the rest to it, since parallel frameworks double the paperwork and halve the adoption.

What maturity level should a risk management assessment target?

Match the target to stakes and budget; chasing level five everywhere wastes both. Regulated finance and critical infrastructure justify embedded, level-five programs, while most mid-market firms earn the best return at a strong level four on monitoring and treatment. Moving one level typically takes twelve to eighteen months.

Can we assess risk management internally, or do we need outside help?

Internal teams can run credible assessments with a published rubric, disciplined evidence rules, and a sponsor who protects candor. Bring in outside help when independence is contested, when the last two assessments produced identical scores, or when a regulator or board explicitly asks for external validation.

The Bottom Line

Assessment is moving from optional hygiene to expected evidence. The Global Internal Audit Standards took effect in January 2025, UK resilience reporting keeps tightening, and Norman’s push for mandatory breach disclosure signals where legislators on both sides of the Atlantic are heading through 2027.

Two shifts deserve a place in your next scope. AI-driven controls need their own evidence trail, since NIST’s framework family now stretches into AI risk, and third-party concentration keeps climbing, as the M&S, Co-op, and Harrods wave proved inside a single month of 2025.

Our own position is unfashionable but repeatedly tested in the field: a mediocre framework honestly assessed will beat an elegant framework taken on faith. Build the framework once, then spend your energy proving it works, because enterprise risk management earns its budget through evidence.

If your board needs a scored, evidence-based view of the program before year-end, built on a defensible assessment methodology and a plan it can act on, our advisory services deliver exactly that. Contact us and we will scope it in one call.