A risk assessment program is the standing process an organization uses to identify, analyze, evaluate and treat its risks on a defined cycle. It sets the method, the scoring scale, the cadence and the owners. A single assessment is one output of that risk assessment program rather than the program itself.
On 18 June 2026 the Department of Health and Human Services Office for Civil Rights announced a 450,000 dollar settlement with the Spencer Gifts benefit plans over a ransomware breach affecting 10,023 people. The finding was not the ransomware. It was the failure to conduct an accurate risk analysis before the attack.
|
Risk Assessment Program: Key Takeaways |
|
A risk assessment program is the standing, repeatable cycle that produces assessments on a schedule. A single assessment is an output of the risk assessment program, not the program itself, and regulators now audit the cycle. |
|
On 18 June 2026 the HHS Office for Civil Rights settled with the Spencer Gifts benefit plans for 450,000 dollars over a breach affecting 10,023 people. The finding was failure to conduct an accurate risk analysis. |
|
That case was the 14th action under OCR’s Risk Analysis Initiative. Four earlier settlements announced on 23 April 2026 covered more than 427,000 individuals and over one million dollars, each citing the same failure. |
|
Under NYDFS 23 NYCRR 500.9, covered entities must review and update the risk assessment at least annually and whenever a business or technology change materially alters cyber risk. |
|
Method matters less than consistency. NIST SP 800-30 and ISO 31000 with IEC 31010 both work, provided one scale is anchored, applied across every unit, and defended the same way each cycle. |
|
Six triggers should restart the cycle between annual refreshes: a new system, a material business change, an incident, a regulatory development, an indicator breach, or the scheduled date arriving. |
|
The risk assessment program is judged on what happened after the finding. Analysis without funded treatment, named owners and dated evidence is the exact pattern that federal settlements keep describing. |
That was the 14th enforcement action under OCR’s Risk Analysis Initiative and its 20th ransomware action. OCR Director Paula M. Stannard framed the agency’s position in a sentence worth pinning above a risk team’s desk: effective cybersecurity starts with Security Rule compliance.
Read across the initiative and a pattern emerges that should change how risk teams budget. The missing assessment is being treated as the violation in its own right, separate from whatever breach exposed it, and the initiative’s earlier actions say the same thing.
What a Risk Assessment Program Actually Is
The distinction that matters here is between an event and a system. Most organizations have done a risk assessment. Far fewer run a risk assessment program, which is the machinery that makes the next assessment happen on time, to the same method, whether or not anyone remembers to ask.
A risk assessment program answers four questions before any workshop is booked. What is in scope, how will we score, how often do we repeat, and who acts on the result. Get those settled and the assessments become routine output rather than a project fought for annually.
|
Dimension |
A single risk assessment |
A risk assessment program |
|
Trigger |
Someone asks for it, usually an auditor, a client or an incident. |
A published calendar plus defined event triggers that fire without anyone asking. |
|
Method |
Chosen by whoever runs it, often rebuilt from scratch each time. |
Fixed and documented, so this year’s scores are comparable with last year’s. |
|
Scope |
One system, site, project or department. |
The full inventory, with documented reasons for anything excluded. |
|
Ownership |
The person who ran the workshop, until they move on. |
A named risk assessment program owner plus named risk owners recorded in the register. |
|
Output |
A report that circulates once and settles in a shared drive. |
A live register, funded treatment plans, and a reporting line into governance. |
|
Evidence |
The document, if it can still be found. |
A dated audit trail showing the cycle ran, what changed, and who approved it. |
Table 1. The difference between running an assessment and running a risk assessment program, across six dimensions.
Our companion guide on what a risk assessment is covers the mechanics of a single pass, and the difference between risk assessment and risk management is worth settling early, because risk assessment programs that blur the two tend to produce analysis nobody acts on.
Why the Assessment Became the Thing Regulators Punish
For most of the last decade the assessment was treated as preparatory paperwork, useful mainly for justifying a security budget. What changed is that several US regulators started treating its absence as a standalone violation, chargeable whether or not it contributed to any specific loss.
The healthcare record is the clearest because OCR publishes it. Four settlements announced on 23 April 2026 covered more than 427,000 individuals and over one million dollars in payments, and every one cited an inadequate risk analysis among its findings.

Figure 1. Four unrelated organizations, four different incidents, one repeated finding in the settlement documents.
Financial services arrived at the same place by a different route. Under the amended New York cybersecurity rules, section 500.9 requires the risk assessment to be reviewed and updated at least annually, and again whenever a business or technology change materially alters the risk profile.
Those amendments finished phasing in through November 2025, and the final tranche of requirements is now fully in force. Analysis from Steptoe and PwC makes the same structural point about the rule’s design: the assessment is what drives every other control the regulation goes on to demand.
Enforcement followed quickly. The New York regulator’s first cyber action of 2026 produced a 2.25 million dollar penalty against two Delta Dental entities, under a consent order dated 29 April 2026 covering incident response and notification failures arising from the MOVEit breach.

Figure 2. One settlement, read as a cost model for skipping a cycle nobody was asking about at the time.
The Seven Parts a Risk Assessment Program Needs to Function
Regulatory pressure explains why programs get funded. It does not explain how to build one. Seven components carry the work, and a risk assessment program missing any of them tends to fail in a way an examiner can spot from the documentation alone.
|
Component |
What it covers |
What it leaves behind |
|
Charter and scope |
Written mandate, entities and systems in scope, documented exclusions with reasons. |
A signed scope statement the board approved, dated and version controlled. |
|
Asset and process inventory |
What is being assessed: systems, vendors, sites, processes, data flows. |
A maintained inventory with an owner per line and a last-reviewed date. |
|
Method and scale |
The scoring approach, anchored likelihood and impact definitions, appetite thresholds. |
A published scoring guide that two different assessors would apply identically. |
|
Assessment cycle |
The calendar, the event triggers, and who runs each pass. |
A schedule with completed dates against it, not just planned ones. |
|
Register and treatment |
Scored risks, named owners, treatment decisions, funding and deadlines. |
A live register where residual scores move after controls land. |
|
Governance and reporting |
Who reviews results, at what level, and who can accept a risk above appetite. |
Minutes recording the challenge, plus a documented acceptance trail. |
|
Independent review |
Assurance that the method was followed and the scoring is defensible. |
An internal audit or second-line report with findings and closure evidence. |
Table 2. Seven components of a working risk assessment program, and the artifact each one should produce.
Three of these components fail more often than the rest, and they tend to fail quietly rather than visibly. Each carries a cheap diagnostic that a risk assessment program owner can run this week, without booking a single workshop or buying anything:
- Scale drift. Ask two managers to score the same risk independently. If the answers differ by more than one band, the scale is not anchored, and our comparison of 5×5 and 4×4 scoring explains how to fix the definitions.
- Inventory decay. Pick five systems added in the last year and check whether they appear in scope. Anything missing was never assessed, whatever the register claims.
- Orphaned treatment. Take three treatment plans from the last cycle and ask who owns them now. Plans without a current owner are the ones examiners find first, and a proper risk register structure prevents it.
The register is where most of this lands, and it is usually over-built. Our risk register template and build guide keeps the field list short enough that people actually maintain it between cycles, which matters more than any additional column.
Picking a Method You Can Defend
Method choice attracts far more internal debate than it deserves. Examiners rarely challenge which framework you picked; they challenge whether you applied it consistently and can show your working. Any of the mainstream methods survives that test when it is documented as you go.
|
Method |
Best suited to |
What it demands of you |
|
NIST SP 800-30 Rev 1 |
US federal systems, contractors and any organization already using the NIST vocabulary. |
Threat source and event modeling, with likelihood and impact assessed separately then combined. |
|
ISO 31000:2018 with IEC 31010 |
Enterprise-wide risk assessment programs and non-US groups needing a sector-neutral method. |
Explicit context setting first, then a documented choice of technique from the 31010 catalogue. |
|
ISO/IEC 27005 |
Information security programs aligned to an ISO 27001 management system. |
Asset, threat and vulnerability decomposition tied to the statement of applicability. |
|
HIPAA Security Rule risk analysis |
Covered entities and business associates handling electronic health information. |
Complete ePHI inventory across all systems, with accuracy and thoroughness both testable. |
|
NYDFS 23 NYCRR 500.9 |
Financial services entities licensed in New York. |
Written assessment, annual review, and an update whenever a material change occurs. |
Table 3. Five methods a US risk assessment program is likely to choose between, and the obligation each one carries.
The two general-purpose options are the ones most teams end up weighing against each other. NIST SP 800-30 Revision 1 remains the published federal guide, and ISO 31000:2018 pairs with IEC 31010 when it comes to choosing a specific assessment technique.
Sector rules sit on top rather than replacing them. Information security teams often add ISO/IEC 27005 or work from the NIST Cybersecurity Framework, and our walkthrough of running a NIST CSF risk assessment covers the practical sequence one step at a time.
For enterprise risk assessment programs the integration question matters more than the technique. NIST’s NISTIR 8286 series exists specifically to connect cybersecurity risk to enterprise risk, and our guide to what enterprise risk management means sets out the wider frame that these assessments feed into.
Building a Risk Assessment Program in 90 Days
A first cycle does not need a year. What it needs is a fixed method before the first workshop, because rescoring everything after the scale changes is the fastest way to lose a risk assessment program’s credibility with the people who supplied the input.

Figure 3. Ninety days to a first completed cycle, with phases deliberately overlapping.
|
Phase |
Days |
What must be finished before the next phase starts |
|
Scope and mandate |
0 to 15 |
Charter approved, risk assessment program owner named, in-scope entities and systems listed with exclusions justified. |
|
Method and scale |
12 to 33 |
Scoring guide published with anchored bands, appetite thresholds agreed, escalation route documented. |
|
First assessment |
30 to 68 |
Workshops run, evidence collected, register populated with inherent and residual scores per risk. |
|
Treatment and report |
60 to 90 |
Treatments costed and funded, owners assigned with dates, first governance report delivered. |
Table 4. The four phases, with the completion test that gates each handover.
Scope is where first cycles go wrong most often, and the error is almost always over-ambition. Covering three business units properly beats covering twelve superficially, because a shallow pass produces scores nobody trusts and a register nobody bothers to maintain.
Templates save weeks of setup time here, provided they are edited to fit the organization rather than adopted whole. Our risk assessment template, the matrix template in Excel and the step-by-step guide to conducting an assessment cover the first pass.
How Often to Reassess, and What Should Force It
Annual is the default answer and it is only half right. An annual refresh handles drift, but it cannot catch the change that arrives in March and matters by April, which is precisely the gap regulators have started writing rules about.

Figure 4. The scheduled refresh is one trigger of six. The other five are the ones risk assessment programs forget to define.
Writing these triggers into the charter changes behavior, because it moves reassessment from a judgment call to an obligation. It also gives the risk assessment program owner something to point at when a business unit would rather not reopen a scored risk mid-year.
|
Cadence |
What gets refreshed |
Typical evidence |
|
Monthly |
Indicator readings against thresholds, open treatment plan status. |
Dashboard extract with breach flags and action log updates. |
|
Quarterly |
Top risks reviewed, new risks admitted, residual scores adjusted where controls landed. |
Committee minutes recording challenge, plus a dated register version. |
|
Annually |
Full re-scoring, scope and inventory refresh, appetite and method review. |
Complete assessment record signed off at board or executive level. |
|
On trigger |
The affected scope only, reassessed under the standing method. |
Event-linked assessment note explaining what changed and what moved. |
Table 5. A four-tier cadence that satisfies annual obligations without pretending risk moves once a year.
Indicators are what make the between-cycles tiers work at all. A defined set of key risk indicators with thresholds attached turns monitoring into something a team acts on rather than merely records, and board-ready dashboards keep the reporting readable enough to be challenged properly.
Scoring One Risk From Start to Finish
Abstract method descriptions are where most guidance stops short and leaves the reader guessing. Here is a single risk carried through a complete pass on a 5×5 scale, using a third-party dependency, which is precisely the exposure the 2026 healthcare settlements repeatedly turned on.
|
Step |
What the team did |
The number it produced |
|
Scope |
Confirmed the claims processing vendor holds records for 41,000 members and sits in the in-scope inventory. |
One register entry, owned by the head of operations, tagged to the vendor contract. |
|
Inherent score |
Likelihood 4, given the vendor’s sector saw repeated intrusions. Impact 5, from notification duties and service loss. |
Inherent 20 of 25, placing it in the top band before any control credit. |
|
Control test |
Reviewed the vendor’s current attestation, tested access revocation, found no evidence of restore testing. |
Controls rated partially effective, so residual holds at 12, above the appetite limit of 9. |
|
Treatment |
Required restore testing evidence quarterly, added contractual notification terms, funded an alternate processor review. |
Treatment costed at 85,000 dollars, against a modeled notification and downtime exposure of 1.4 million. |
|
Re-score |
Re-tested after the vendor supplied two consecutive restore reports and the contract amendment executed. |
Residual reduced to 6, evidenced, and reported to the risk committee with the test dates attached. |
Table 6. One third-party risk carried end to end, with the numbers that made each decision defensible.
Three details in that example are what an examiner actually looks for. The impact was scored against enterprise consequences, the appetite limit came from an approved statement, and the re-score is backed by dated test evidence rather than an assurance that things improved.
The arithmetic also answers the funding question in advance. Committing 85,000 dollars against a modeled 1.4 million exposure is a decision a finance director can approve, and the inherent versus residual method is what makes the before and after positions comparable.
Third-party exposure deserves an intake sub-process of its own, given how consistently the recent enforcement record turns on vendors and their subcontractors. Our third-party risk management framework and the vendor assessment questionnaire together cover the collection side that feeds this kind of scoring exercise.
The Evidence That Proves It Ran
A risk assessment program that cannot be evidenced did not happen, as far as an examiner is concerned. OCR’s recent position sharpens that further: the agency now looks past the analysis itself to what the organization actually did with what it found.
|
Question an examiner asks |
Weak answer |
Evidence that closes it |
|
When was the last full assessment completed? |
A financial year, or a reference to it being done annually. |
A dated, signed assessment record with the approving body named in the minutes. |
|
Does it cover everything in scope? |
All departments participated in workshops. |
An inventory reconciliation showing every in-scope asset mapped to a register entry. |
|
What happened to the findings? |
They were shared with management for action. |
Funded treatment plans with owners, deadlines and completion evidence attached. |
|
Has anything been reassessed since? |
The next review is scheduled. |
Trigger-linked assessment notes dated between scheduled cycles, with score changes shown. |
|
Who accepted the risks left above appetite? |
They are being monitored. |
A signed acceptance record naming the approver and the review date. |
Table 7. Five questions that separate a documented risk assessment program from one that merely intended to run.
Control testing needs its own rhythm rather than riding on the assessment refresh. A risk and control self-assessment gives residual scores something to stand on, and the banking RCSA template shows the depth of evidence that examiners expect in heavily regulated settings.
Independent review closes the loop. Whoever runs the second look should not have run the assessment, which is the whole logic of the three lines model, and pairing it with a GRC reporting structure stops the same evidence being gathered three times.
Common Risk Assessment Program Questions Practitioners Ask
What is the difference between a risk assessment and a risk assessment program?
An assessment is a single analysis of risks at a point in time. A risk assessment program is the standing system that defines the method, sets the cadence, assigns owners and produces those assessments repeatedly. Regulators increasingly examine the risk assessment program rather than any individual report.
How often should a risk assessment program run a full reassessment?
At least annually, plus whenever a defined trigger fires. NYDFS 23 NYCRR 500.9 requires annual review and an update on material business or technology change. Most mature risk assessment programs layer monthly indicator checks and quarterly top-risk reviews between the full annual passes.
Who should own the risk assessment program?
A named individual with authority over the method and calendar, usually a risk or compliance lead, reporting into an executive committee. Individual risks stay owned by the business units that run them. Concentrating both roles in one function is the most common structural weakness we see.
What should a risk assessment program cover?
Everything inside the documented scope, with any exclusions justified in writing. That typically spans systems, third parties, facilities, processes and data flows. Scope gaps are the finding examiners reach fastest, because an unassessed asset shows up immediately in an inventory reconciliation.
Which framework should a risk assessment program follow?
NIST SP 800-30 suits federal and US technology contexts, ISO 31000 with IEC 31010 suits enterprise-wide and international risk assessment programs, and sector rules apply on top. Consistent application matters more than the choice, since examiners test whether the method was followed.
How long does it take to implement a risk assessment program?
A first complete cycle takes roughly 90 days in a mid-sized organization: scope agreed, method published, assessment run, treatments funded and reported to governance. Maturity beyond that accrues over two or three further cycles, as scoring stabilizes and the quality of evidence improves.
What does a risk assessment program cost to run?
The recurring cost is mostly people rather than software. Budget for a part-time risk assessment program owner, workshop time across the business, and independent review. A spreadsheet register runs a credible first cycle, so tooling can wait until volume genuinely justifies it.
How do you prove a risk assessment program is effective?
Show movement rather than activity. Point to residual scores that fell after controls were tested, treatments closed on schedule, trigger-linked reassessments between cycles, and a documented acceptance trail for anything left above appetite. Sheer volume of documentation proves nothing on its own.
Where These Risk Assessment Programs Break Down
The failures below account for most of the distance between a risk assessment program that exists on paper and one that survives an actual examination. Each of them carries a correction that costs far less to apply than the settlements described earlier in this guide.
|
Failure |
How it shows up |
The correction |
|
Assessment as artifact |
A thorough report delivered, filed, and never referenced in a decision. |
Require the register entry to be cited in any paper approving spend or a new system. |
|
Unanchored scoring |
Departments interpret a likelihood of 3 differently, so aggregate rankings mislead. |
Publish anchored bands with monetary and frequency definitions, then calibrate jointly. |
|
Scope frozen at launch |
New systems and vendors arrive but never enter the inventory. |
Make inventory addition a step in procurement and change approval, not a periodic sweep. |
|
Analysis without treatment |
Risks scored above appetite with no funded plan or owner attached. |
Block cycle sign-off until every out-of-appetite risk carries a plan, a name and a date. |
|
Annual-only cadence |
Nothing reassessed between refreshes, whatever changed during the year. |
Define the event triggers in the charter and log each trigger-linked reassessment. |
|
Evidence gaps |
The cycle ran but dates, approvals and test records were never captured. |
Capture evidence as the cycle runs, since reconstructing it afterwards rarely convinces. |
|
Self-review |
The team that ran the assessment also assures its quality. |
Assign independent review to a second line or internal audit function with real findings. |
Table 8. Seven recurring failure modes, each with the cheapest available correction.
In advisory work the first and fourth failures travel together most often. An assessment nobody cites produces findings nobody funds, and by the following cycle the same risks reappear with the same scores, which is what makes a register look stale to an examiner.
Order of correction matters as much as the corrections themselves. Fixing scope and scale before chasing evidence quality avoids documenting a process that is about to change, and the risk management process steps give a running order most teams can sustain.
What Changes for Risk Teams Next
Three shifts are already visible in the 2026 enforcement record. The first is the move from analysis to action: OCR now evaluates risk management alongside risk analysis, so a thorough assessment with no funded treatment behind it is no longer much of a defense.
The second is a broader turn toward outcome-based supervision across financial regulation. FinCEN proposed in April 2026 to rebuild AML program requirements around demonstrable effectiveness rather than process compliance, while the adviser rule’s effective date slipped to January 2028.
The third is convergence. Cyber, operational, third-party and enterprise assessments are being pulled onto shared scales so results aggregate, which is the problem NISTIR 8286 was written to solve and the direction the COSO ERM framework has been pointing toward for years.
Start with the five questions in Table 7 rather than a maturity survey. If you cannot produce a dated approval, an inventory reconciliation and one funded treatment plan, the program is at documentation stage regardless of how much documentation exists.
If you are a US risk or compliance lead who needs a risk assessment program that survives an examination rather than one that merely exists, we build the scale, the calendar and the evidence trail together. Look at how we work with risk teams, then start a conversation and bring whatever your last assessment produced.

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.