To identify risks, define the objective at stake, gather the records that describe how work actually happens, run a structured technique with the people who do the work, and write each finding as a register entry with a cause, an event, a consequence, and an owner. Repeat the effort to identify risks on a schedule and after every incident or change.
On January 29, 2025, PSA Airlines flight 5342 and an Army UH-60 helicopter collided over the Potomac River near Ronald Reagan Washington National Airport, killing 67 people. The National Transportation Safety Board’s final report, adopted on January 27, 2026, found the FAA had failed to review helicopter routes and available data and had not acted on earlier recommendations.
The data existed. Between October 2021 and December 2024, DCA recorded 15,214 close-proximity events between commercial airplanes and helicopters, 85 of them with under 200 feet of vertical separation. NTSB Chair Jennifer Homendy called the risk intolerable when the board issued urgent recommendations in March 2025.
| The Practitioner’s Cheat Sheet |
| Identify risks with a repeatable method that names the technique, the participants, the time box, and the register entry it must produce, as ISO 31000:2018 clause 6.4.2 requires. |
| The NTSB found the FAA held records of 15,214 close-proximity events at DCA before the January 29, 2025 collision that killed 67 people, and had no process to turn them into a risk assessment. |
| Only 49 percent of organizations run a dedicated annual process to identify risks, and just 35 percent report complete ERM processes, according to NC State and the AICPA. |
| Seven techniques cover almost every case: document and incident review, interviews, workshops, checklists, HAZOP walk-downs, scenario analysis, and near-miss data mining. |
| A two-hour workshop to identify risks with eight named steps produces register entries with owner, cause, event, consequence, and control fields filled in before anyone leaves the room. |
| Near-miss and encounter data are the cheapest identification input available; DCA logged 390 airplane-helicopter encounters a month that no one scored. |
No single technique would have prevented the collision, but the case shows the gap this guide closes. The work to identify risks is a process with inputs, participants, and outputs, and it fails when the inputs sit unread. The sections below give the process, the seven techniques, and the workshop method we use with clients, with the register entry each step must produce.
What a Working Risk Identification Process Produces
Before choosing techniques, agree on what the process has to deliver, because a list of worries gives a register nothing to use. ISO 31000:2018 puts identification at clause 6.4.2 and includes risks whose sources the organization does not control. Our guide to what risk identification is covers the definition; the method is below.
A usable output has five parts: the cause that already exists, the event that could happen, the consequence for an objective, a named owner, and the evidence the finding came from. COSO’s 2017 ERM framework makes the same demand in Principle 10, which asks organizations to identify risks that affect strategy and business objectives.
| Output field | What it records | DCA example, written the way a register should read |
| Objective at risk | The goal the risk threatens | Separation between arriving airplanes and Route 4 helicopters |
| Cause | Existing condition | Route 4 ceiling of 200 ft sits about 75 ft below the Runway 33 approach path |
| Event | What could happen | Helicopter and landing airplane occupy the same airspace at night |
| Consequence | Effect on the objective | Midair collision, loss of both aircraft, mass fatalities |
| Evidence | Record the finding came from | 15,214 close-proximity events, 85 under 200 ft vertical, one TCAS advisory a month |
| Owner | Named accountable person | FAA Air Traffic Organization, DCA facility manager |
The evidence column is the one most registers leave blank, and it decides whether a finding survives challenge. When we review registers, entries with a cited record get funded controls and entries without one get deferred. The columns that follow identification are covered in the key elements of a risk register.
Why Risks Go Unfound Until They Cost Money
The DCA record is not unusual; most organizations hold the data that describes their next loss and do not read it as risk information. NC State’s ERM Initiative reports that 49 percent of organizations identify risks through a dedicated annual process, rising to 67 percent among large organizations and public companies.

Figure 1. The FAA held four years of encounter records before the collision; none had been scored as a risk. Sources: NTSB, CBS News, NBC News.
Maturity surveys give the wider picture. The AICPA and NC State 2025 State of Risk Oversight report, drawn from 273 US finance leaders, found only 35 percent have complete ERM processes in place and only 32 percent rate their oversight as mature. PwC’s Global Risk Survey found just 7 percent have invested in proactive, enterprise-wide resilience.
Process safety tells the same story at plant level. The US Chemical Safety Board’s final report on the August 11, 2025 explosion at US Steel’s Clairton Coke Works, released on August 10, 2026, found two workers killed, 11 injured, and about $52.5 million in damage. Employees had washed valves with pressurized water on an ad hoc basis for three years.
CSB Chairperson Steve Owens said the incident “was the result of an ad hoc informal procedure, poor facility siting, and an ineffective process safety management system.” OSHA had earlier cited US Steel for seven serious violations with $118,214 in penalties. A walk-down that asked how valves are actually cleaned would have found the practice.
| Signal that was available | Where it sat | What a working process would have done |
| 15,214 DCA close-proximity events | FAA encounter databases | Trended monthly, escalated on a threshold, routed to a route review |
| One TCAS resolution advisory a month, 2011 to 2024 | Airline and FAA safety reports | Treated as a near-miss feed with a named analyst |
| Ad hoc water washing of valves for three years | Shift practice at Clairton | Captured in a walk-down interview and written as a procedure gap |
| Occupied buildings under 20 ft above gas piping | Plant drawings | Flagged in a facility siting review after the 2010 explosion |
| Repeat trench violations at a Massachusetts contractor | OSHA citation history | Pulled into the pre-qualification checklist before award |
The last row refers to Revoli Construction, cited by OSHA on April 1, 2026 with $4,699,362 in proposed penalties after a November 2025 trench collapse in Yarmouth killed one worker. OSHA listed seven willful and 33 repeat violations. A contractor’s citation history is public and free, as our post on the difference between a hazard and a risk argues.
Seven Techniques for How To Identify Risks, and When Each Fits
With the output defined and the cost of missing it clear, the practical question is which technique to run. IEC 31010:2019 catalogs more than 30 assessment techniques, but seven do almost all of the identification work in the programs we build, and the table sets out who runs each, how long it takes, and what it produces.
| Technique | Best for | Who takes part | Time box | Output |
| Document and incident review | Any scope with a history | Risk analyst plus one operations lead | 2 to 4 hours | Candidate list with evidence citations |
| Structured interviews | Strategy, culture, single-expert knowledge | Facilitator and 6 to 10 interviewees | 45 minutes each | Interview log coded by objective |
| Facilitated workshop | Projects, process change, annual refresh | 8 to 12 people who do the work | 2 hours | Register entries with owners |
| Checklists and prompt lists | Repeat activities, contractor pre-qualification | Line supervisor | 30 minutes | Completed checklist with exceptions |
| HAZOP or process walk-down | Plants, labs, physical processes | Process engineer, operator, safety lead | Half day per unit | Deviation table with causes |
| Scenario analysis | Strategic and emerging risks | Executives and two external voices | Half day | Three to five written scenarios with triggers |
| Data and near-miss mining | Operations with event records | Analyst with access to the systems | Recurring, monthly | Trend chart with threshold breaches |
Document and incident review comes first in every plan because it is the cheapest way to identify risks and the one that grounds the others. Pull 12 months of incidents, near-misses, audit findings, and customer complaints, code each to an objective, and list the top ten causes by frequency. That list seeds the interviews and becomes the evidence pack for the workshop.

Figure 2. Run the techniques scored 3 every time the stage occurs; the rest depend on scope and time. Mapping by riskpublishing.com against IEC 31010:2019.
Choose how to identify risks by stage, not by habit. Strategy setting needs interviews and scenarios because the risks are not yet in any record, while process change needs a walk-down and a checklist because the risk is physical and specific. Steady-state operations need data mining because near-miss records already exist, and after an incident, document review and a walk-down come first.
A few rules keep the technique honest: a workshop without a prior document review produces opinions, and a checklist without an exception column produces paperwork. Interviews work when the interviewer asks what went wrong last time, because people describe real events more accurately than hypotheticals. Signals that call for adding a technique to the plan include:
- A new supplier, contractor, or system enters the process, which triggers a checklist and a document review of its record.
- A near-miss count crosses a set threshold, which triggers a walk-down of the unit involved.
- A strategic objective changes, which triggers interviews with the executives who own it.
- A regulator, auditor, or insurer asks a question the register cannot answer, which triggers a workshop.
A Two-Hour Workshop: How To Identify Risks Step by Step
The workshop is the technique most teams use to identify risks and the one most often run badly, so this section gives the method in full. PMI’s Standard for Risk Management describes identification as iterative and collaborative, and the eight steps below produce register entries with owners in two hours. The RCSA workshop guide adapts the same steps for control self-assessment.
| Step | Minutes | What happens | Record produced |
| 1. Fix the objective | 5 | Facilitator writes one objective on the board and confirms it with the sponsor | Objective statement |
| 2. Present the evidence pack | 15 | Analyst summarizes incidents, near-misses, audit findings, and changes since the last session | Evidence pack, circulated 48 hours earlier |
| 3. Silent generation | 10 | Each participant writes candidate risks alone, one per card, as cause plus event | Cards |
| 4. Round-robin read-out | 20 | Each card is read and posted without debate; duplicates are merged | Posted wall |
| 5. Challenge round | 20 | Facilitator asks what evidence supports each card and what would make it worse | Evidence notes |
| 6. Write the entries | 30 | Groups of three convert cards into cause, event, consequence, and evidence fields | Draft register entries |
| 7. Assign owners | 10 | Sponsor names one accountable owner per entry; unowned entries are parked | Owner column |
| 8. Close and schedule | 10 | Facilitator reads back the list, sets the scoring session date, and logs open questions | Minutes and action log |
Invite the people who do the work, since managers know the procedure and workers know the practice. A facilities workshop should include the technician who cleans the valves, and a project workshop the scheduler who knows which dependency is late. The step-by-step guide to risk assessment covers the scoring session, and our risk assessment flowchart shows where the workshop sits.
Prepare the evidence pack or cancel the session, because a room without records produces opinions rather than findings. Circulate it 48 hours ahead so participants arrive having read it, and keep it to five items so that the reading gets done. The pack that works for a two-hour workshop contains:
- Incidents and near-misses for the scope over the last 12 months, with counts and dates.
- Audit findings and open actions, including any repeat findings.
- Changes since the last session: people, systems, suppliers, sites, regulations.
- The previous register extract for the same scope, with closed entries marked.
- External events at peers, from regulator releases, court filings, and industry bodies.
Two facilitation rules do most of the work. Silent generation stops the senior voice from anchoring the room, and the challenge round fills the evidence column, so it is never cut for time. The NTSB found the FAA lacked a process to identify real-time operational risks; a scheduled workshop with an evidence pack is that process at its simplest.
Project Risks Versus Enterprise Risks: Same Method, Different Inputs
The same seven techniques to identify risks serve a project team and a board, but the inputs and horizon change. PMI’s 2026 Pulse of the Profession found 31 percent of complex projects fail to deliver their intended benefits, more than twice the rate for projects overall. Protiviti and NC State’s 2026 survey of 1,540 executives put talent among the top concerns.
| Dimension | Project risk identification | Enterprise risk identification |
| Objective set | Scope, schedule, budget, quality of one deliverable | Strategic, operational, financial, and compliance objectives |
| Horizon | Life of the project, months to a few years | Three to ten years, refreshed annually |
| Main techniques | Document review, checklist, workshop at each stage gate | Interviews, scenarios, data mining, annual workshop |
| Participants | Project manager, workstream leads, key suppliers | Executives, board members, second-line functions |
| Evidence pack | Schedule, risk log from similar projects, lessons learned | Incident data, audit findings, KRIs, external surveys |
| Register owner | Project manager | Chief risk officer or equivalent |
The stage-gate discipline matters because project risks change identity as the work proceeds. A dependency risk at initiation becomes a schedule risk at design and a cost risk at build, and a register that carries the initiation wording forward misses the change. Re-run the checklist at each gate and retire entries that no longer describe the work.
Project teams should run identification at every stage gate, from initiation to closure. The eight steps for a project risk assessment and the project risk assessment questionnaire template give the gate-by-gate prompts, and what is project risk management sets the context for new teams.
Enterprise programs face the opposite problem: the risks are real but distant, and interviews plus scenarios are how boards identify risks of that kind. Marsh’s 2026 UK Business Risk Report of 2,169 respondents found cyber cited by 46 percent as the top concern, up from 20 percent in 2023. The complete risk assessment guide shows how enterprise findings feed scoring.

Figure 3. Half of organizations run a scheduled identification process; a third have complete ERM. Sources: NC State ERM Initiative, AICPA and NC State 2025, PwC Global Risk Survey.
Turning Findings Into Register Entries and Near-Miss Feeds
The work to identify risks is finished when the finding sits in the register with every field populated and a data feed that will tell the owner when the risk moves. NIST SP 800-30 Revision 1 identifies threat sources, events, and vulnerabilities before likelihood is estimated, and the same sequence applies outside cybersecurity. The register template and build guide gives the column layout.
| Register field | Clairton entry, written from the CSB findings | Feed that keeps it current |
| Cause | Valves washed with pressurized water on an ad hoc basis for three years, no formal procedure | Procedure audit findings, monthly |
| Event | Water enters coke oven gas piping and displaces gas into an occupied building | Gas detector alarms, weekly count |
| Consequence | Explosion, fatalities, injuries, property damage near $52.5 million | Loss event log |
| Evidence | CSB final report, August 10, 2026; 2010 explosion at the same plant | Regulator releases, quarterly |
| Owner | Plant manager, with process safety lead as deputy | Named in the register |
| Control gap | No facility siting evaluation after 2010; occupied buildings under 20 ft above piping | Siting review, on change |
The Clairton entry shows why the cause field matters more than the event field. The event, water entering gas piping, reads as a technical fault, while the cause, an unwritten practice that ran for three years, points at a procedure gap that a walk-down interview surfaces in an afternoon. Registers that skip causes generate controls for the wrong problem.
Near-miss data is the feed most programs already have and fewest use to identify risks. OSHA’s Recommended Practices ask employers to collect and review hazard and incident information, including near-misses, and the National Safety Council’s near-miss reporting guidance explains how to build the reporting culture. The DCA figures show what the feed looks like when nobody owns it.

Figure 4. Four monthly encounter measures from the NTSB’s January 2026 board presentation, none of which triggered a route review before the collision.
Set a threshold for each feed and name who reads it. A KRI with a red line and a reader turns identification into a standing process, and the KRI library of 150 indicators and our guide to developing key risk indicators give tested thresholds. The final step in the risk identification process explains the handover to analysis.
Triggers that reopen identification for an existing entry should be written next to the entry, so the owner does not have to remember them. Four cover most cases, and each should name the person who acts and the date by which the entry is re-scored:
- The feed crosses its threshold for two consecutive periods.
- The owner changes, leaves, or has not reviewed the entry in 12 months.
- A peer suffers the event the entry describes, anywhere in the world.
- A control listed against the entry is removed, suspended, or fails a test.
What Goes Wrong and the Fixes That Work
Three of the eight failures below come from the DCA, Clairton, and Yarmouth cases, and the other five from registers we have reviewed; each fix costs less than a day. The guide to why the risk register is no longer enough argues the same point for the maintenance stage.
| Failure | How it shows up | Fix |
| Identification without evidence | Register entries with no incident, audit, or data citation | Add an evidence column and refuse entries that leave it blank |
| Workshop without a pack | Two hours of opinion, no new findings | Circulate the evidence pack 48 hours before; cancel if it is not ready |
| Wrong people in the room | Managers describe the procedure, not the practice | Invite one person per entry who performs the work |
| Data nobody reads | Near-miss counts logged and never trended | Assign a reader, a threshold, and a monthly date |
| One search a year | New suppliers and systems enter unassessed | Add change triggers that reopen identification |
| Technique by habit | Same brainstorm for strategy and for a plant change | Pick from the stage matrix in Figure 2 |
| Findings without owners | Entries assigned to a department | Sponsor names one person before the session closes |
| Hazards mistaken for risks | Lists of things without events or consequences | Write every entry as cause, event, consequence |
The most expensive failure on the list is data nobody reads, because the cost of the fix is a reader and a threshold. Identifying risk metrics describes how to select the measures, and the RCSA complete guide shows how first-line teams keep the feed current between workshops.
How To Identify Risks: Your Questions Answered
What is the first step to identify risks?
The first step to identify risks is to fix the objective at stake and gather the records that describe how the work happens: incidents, near-misses, audit findings, and changes since the last review. ISO 31000:2018 puts scope and context before identification for this reason. A workshop that starts without an evidence pack produces opinions rather than findings.
What are the main risk identification techniques?
The seven techniques that cover most needs are document and incident review, structured interviews, facilitated workshops, checklists and prompt lists, HAZOP or process walk-downs, scenario analysis, and near-miss data mining. IEC 31010:2019 lists more than 30, and our review of risk identification tools and techniques compares software support for each.
How do you identify risks in a project?
Identify risks in a project at every stage gate, not only at initiation. Review the schedule and similar projects, run a checklist against known project risk categories, and a two-hour workshop with workstream leads and key suppliers. PMI’s 2026 Pulse found 31 percent of complex projects miss their intended benefits, which is the case for repeating the search.
Who should be involved in identifying risks?
Involve the people who perform the work, one per candidate risk, plus a facilitator, an analyst who prepared the evidence pack, and a sponsor who can name owners. The Clairton explosion involved a valve-washing practice that managers had never written down. Executives belong in interviews and scenario sessions; operators belong in walk-downs and workshops.
How often should you identify risks?
Identify risks on a fixed schedule, annually at minimum for the enterprise and at each stage gate for projects, and on triggers: a new supplier or system, a near-miss threshold breach, an ownership change, or a peer incident. NC State reports 49 percent of organizations run an annual process and about a third search more often.
How do you turn identified risks into a risk register?
Write each finding as cause, event, consequence, evidence, and owner, then attach a data feed with a threshold and a reader. An entry without an owner is parked until one is named. The register template and build guide on this site gives the column layout, and the scoring session that follows assigns likelihood and impact.
Can near-miss data be used to identify risks?
Yes, near-miss data is the most reliable identification input available because it records events that already happened without their worst consequence. The NTSB’s board presentation showed DCA averaged 390 airplane-helicopter encounters a month within one nautical mile and 400 feet. Trend each feed monthly and set a threshold that reopens the register entry.
Where the Profession Is Heading
The inputs to identification are changing faster than the techniques. Gartner’s first-quarter 2026 emerging risk survey of 337 senior risk executives ranked information integrity risk, driven by AI-enabled decision-making, as the top emerging risk for the first time. A program that tries to identify risks from documents alone will miss the ones that live in models and data pipelines.
Expect regulators to ask for the process, not the list. The NTSB named the absence of a risk assessment process at the FAA, and the CSB named an ineffective process safety management system at Clairton. Both asked what an auditor now asks: show us how you identify risks, and the record that proves you ran it.
By 2027, the practical change for most programs is a standing feed rather than an annual search. Encounter data, near-miss counts, audit results, and contractor citations can be pulled monthly, scored, and routed to a named owner. The workshop remains where people turn signals into entries, and the evidence pack sent 48 hours ahead decides whether it produces any.
If your register has entries without evidence or feeds without readers, we can run the workshop to identify risks, rebuild the register, and set the thresholds, benchmarked against ISO 31000 and IEC 31010. The engagement formats are on our advisory services page; to start, tell us on the contact page which objective you want covered first.

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.