Organisations assess risk with extraordinary diligence and act on the results with extraordinary reluctance. The register grows. The matrix refreshes. The report circulates. The decision that the assessment was supposed to serve remains unmade.

A risk assessment is a structured process for identifying, analysing and evaluating risks so that a decision-maker can determine what to do about them.

The definition, consistent with ISO 31000, states the purpose plainly. The assessment exists so that someone can determine what to do. Not so that someone can colour-code a spreadsheet and circulate it before the next committee meeting. Not so that someone can demonstrate compliance with a standard or satisfy an audit finding from a regulator like the UK Health and Safety Executive.

The purpose is a decision. Strip the decision out and the assessment is overhead with no return.

Five steps connect an assessment to a decision:

  1. Name the decision the assessment serves.
  2. Develop genuine options beyond the existing plan.
  3. Identify the assumptions each option depends on.
  4. Judge whether the basis for proceeding is sufficient.
  5. Design monitoring before you commit.

Most organisations practise the first half of step three and stop. Everything below explains why that gap exists and how to close it.

What a risk assessment actually produces

A well-run risk assessment process produces a ranked list of uncertainties relevant to a decision or an activity. Each item names what could go wrong, estimates how likely it is, gauges the consequences, and records who is nominally responsible. The output is typically a register, a matrix, or both.

That is what it produces. Here is what it does not produce.

What a risk assessment produces versus what it does not produce. It produces a ranked list, scores, colour-coded cells, and an owner column. It does not produce a decision.
What the assessment produces and what it does notClick to expand

It does not produce a decision. It does not name the assumptions the live decision rests on. It does not state whether those assumptions have been tested. It does not say what the organisation will do, by when, or how it will know whether the action worked.

It does not identify who is deciding. It does not design monitoring. The register records concerns. It does not resolve them.

After risk identification, the register contains a list. Not a short list. Organisations that take the process seriously routinely identify dozens or hundreds of items. Each has an owner column.

But risk ownership is not decision ownership. Owning a line on a register means updating the line on a schedule. It does not mean making a judgment about what to do. The owner maintains the record. The Decider, if one exists, is somewhere else in the building, often unaware that the register mentions a matter they are accountable for.

The register is a catalogue of concerns. Concerns without decisions are worry formalised. They occupy meeting time, generate status reports, and create an administrative layer that feels like rigour but produces none.

What sits between the assessment and a sound decision is the work the Universal Decision-Making Method makes explicit: framing the actual decision, developing real options, surfacing the assumptions those options depend on, judging whether sufficient certainty exists to proceed, and designing what to watch afterwards.

Most organisations practise the identification step and stop. The remaining steps, the ones that connect assessment to action, are where the value lives.

Assessment is not where value lives

I chaired a statutory public safety body whose enabling legislation specified that a particular function was to be the agency's prime consideration. When I arrived, 0.03 per cent of the budget was allocated to that function. The assessment of risk to public safety existed. The legislation existed. The obligation was clear. What was missing was a decision to act on what the assessment had already shown.

When the budget allocation was raised, in a targeted way, to 0.5 per cent, the loss of life addressed by that function fell by sixty per cent within two years. That outcome did not come from a better assessment. The assessment had been adequate for years. The outcome came from a decision that followed the assessment and directed resources to where the analysis said they mattered most.

This is the pattern everywhere. Risk analysis tells you what matters. Risk evaluation tells you how much each item matters relative to everything else on the table. Neither tells you what to do. The decision is the act that translates knowledge into action, and that act requires judgment, not scoring.

Organisations have been conditioned to believe that a more thorough assessment produces a better outcome. It does not. A better decision produces a better outcome. The assessment is an input to the decision, and like any input, it is useless if nobody processes it into a commitment.

The public safety body did not need more data, more workshops, or a revised scoring methodology. It needed someone who would look at what the assessment already said and act on it. The value was never in the assessment. The value was in the sixty per cent reduction in deaths that followed one clear decision.

When organisations aggregate their risk assessments, rolling site-level data into divisional registers and divisional registers into enterprise views, the gap between assessment and decision widens further. The individual assessment might contain useful local knowledge. By the time it reaches the board, it is a heat map with arrows. The local knowledge has been compressed out.

The aggregation produces a picture. A picture is not a plan, and a plan is not a decision.

The tolerance review compounds the problem. A committee compares the aggregated picture against a tolerance statement drafted months earlier by a consultant who has since moved on. The statement is abstract. The picture is abstract. Two abstractions compared in a meeting produce a third: "within tolerance" or "exceeds tolerance."

Neither phrase tells a single person in the organisation what to do on Monday morning. The value was always in the decision. The decision was never made.

The formula that produces phantom risks

Most risk assessments rely on a likelihood-times-consequence matrix, one of many techniques catalogued in IEC 31010 but the only one most practitioners have ever used. Rate the likelihood on a five-point scale. Rate the consequence on a five-point scale. Multiply or cross-reference on a grid. Colour the result red, amber, or green.

The formula feels like analysis because it uses numbers. But ordinal scales are not numbers in any mathematical sense. "Unlikely" multiplied by "major" does not produce a meaningful product any more than "Tuesday" multiplied by "tall" does. The calculation is syntactically valid and semantically empty.

Colour-coded heatmaps amplify the illusion. Red items receive attention because they are red, not because someone has examined whether the rating reflects reality. Amber items sit in a zone that means "someone else's problem until it becomes mine." Green items are celebrated as proof that the assessment worked.

The map becomes the territory. Nobody asks whether the scores behind the colours were defensible, whether the person who assigned them had the information to do so, or whether a five-point scale can distinguish between risks that matter and risks that do not.

The real damage is subtler. The matrix creates phantom risks: items that score highly on the grid because of how the formula combines two poorly estimated quantities, not because the underlying situation demands attention. And it hides real risks: situations where the likelihood is genuinely uncertain but the consequence is catastrophic, which the formula compresses into the same cell as a high-frequency nuisance.

I have sat in rooms where a board spent forty minutes debating the colour coding of a risk matrix and zero minutes discussing the assumptions behind the three largest items on it.

Roger Estall and I documented this problem in Deciding. Copying someone else's risk matrix, or accepting a standard's set of criteria as universal truth, is folly. There is only one valid set of risk criteria for an organisation. All others must reflect that and be subordinate to it.

The formula does not produce risks. It produces scores. Scores are not decisions, and a matrix is not judgment.

Take the risk assessment sitting in your register and ask what decision it was supposed to inform. Start the Walk →

What to do with a risk assessment

The assessment is an input to a decision, not an output of a process. That distinction sounds simple. In practice, it requires a complete reversal of how most organisations handle the results.

Wildfire management agencies use increasingly complex models to forecast the speed and direction of fire spread. The models take fuel loads, wind data, moisture levels, and topography as inputs and produce predicted fire behaviour as output. The output is a calculation. It is not a decision.

In practice, the model output gets treated as a factual prediction rather than as an input to a judgment that a human being must make. The fire manager receives a map showing where the fire will be in six hours and acts as though the map is the future rather than one estimate of the future, generated under a specific set of conditions that may already have changed.

The assumptions embedded in the model, that wind direction will hold, that moisture readings from three days ago still apply, that the fuel-load map accounts for recent clearing, are invisible. The model hides them. The manager inherits them without knowing what they are. A bank stress test hides its assumptions the same way, in whatever the scenario held constant, which is why what to do after a stress test starts with that list.

This is what happens to risk assessments when nobody asks what the assessment assumes. The assessment becomes the answer rather than an input to the answer. The Decider disappears behind the apparatus.

Five questions turn an assessment back into an input:

  1. What decision does this assessment serve? If the answer is "none" or "it is a compliance requirement," the assessment is not connected to any live commitment and cannot create value.
  2. What options are actually on the table? The assessment may have identified risks to an existing plan. But the existing plan is itself an assumption. What alternatives exist, and has the assessment been applied to those as well?
  3. What assumptions is the preferred option resting on? The assessment may have named hazards. Hazards are not the same as assumptions. A hazard is something that could go wrong. An assumption is something you are relying on being true. The two overlap but they are not identical, and confusing them is how organisations end up with long lists of concerns and no clarity about which ones carry the outcome.
  4. Is the basis for proceeding sufficient? Not perfect. Not exhaustive. Sufficient. If the assessment shows that two assumptions carry the outcome and neither has been tested, proceeding is not a decision. It is a gamble with paperwork attached.
  5. What will you watch after you commit? The assessment identified uncertainties at a point in time. Conditions change. If nobody designs monitoring before the decision is made, the assessment ages immediately and the organisation flies blind from that moment forward.

These five questions are the Universal Decision-Making Method applied to the output of a risk assessment. They do not replace the assessment. They complete it.

When the apparatus existed and nobody used it

A food manufacturer had a precautionary testing regime for the water supply feeding its production line. Biological-count testing was in place. The apparatus existed. The process was documented. Somebody had, at some point, made a sound decision to install it.

Over time, the testing instruments drifted out of calibration. Nobody noticed. Contaminated water reached the production line. Products were affected. The reputational and financial damage followed.

The problem was not that the organisation lacked an assessment. The risk had been identified years earlier. The testing regime was the monitoring element of an earlier decision, and when that monitoring element degraded, nobody was watching the watcher. The secondary element, the safeguard designed to catch the problem, became the problem itself.

No instrument lasts forever without maintenance. No process runs itself without oversight. The assumption that the apparatus would continue to function was itself an untested assumption, and it failed silently. An FMEA makes the same assumption wherever a low detection score rests on a backup safeguard, which is why what to do after FMEA starts with checking that each safeguard works on site.

The pattern is general. Governments across the world maintained pandemic preparedness plans before 2020. Assessments were completed. Plans were filed. Scenarios were documented in detail, sometimes running to hundreds of pages.

When COVID-19 arrived, governments that had spent years and considerable public money on pandemic risk assessment discovered that having a plan and executing a plan are different activities separated by a decision nobody had rehearsed.

The argument after every failure follows the same structure: "We assessed the risk." Yes. And then what.

The assessment is the easy part. Filling out the register is the easy part. Running the workshop, scoring the matrix, producing the report, circulating it for sign-off: all of it is easier than standing in a room and saying this is what we are going to do, this is what we are assuming, and this is what we will watch to know whether we were right.

The problem is never "we did not assess." It is "we did not decide." Assessment without decision is preparation without commitment. It occupies the space where judgment should be and leaves nothing behind except documentation that proves, after the fact, that somebody knew.

The problem is never "we did not assess." It is "we did not decide."

From assessment to decision

The gap between an assessment and a decision is not a gap in knowledge. It is a gap in method, and without a method the gap fills with analysis paralysis: ever more assessment substituting for judgment. The assessment produces information. The decision requires judgment about whether the information is sufficient, what to do given what is known, and what to watch after the commitment is made.

The Universal Decision-Making Method fills that gap with five explicit steps. Frame the decision: name what you are deciding and why it matters. Develop options: produce genuine alternatives, not variations on a preferred answer.

Recognise assumptions: name what each option depends on and rank those assumptions by significance. Reach sufficient certainty: judge whether the basis for proceeding is adequate, not perfect. Design monitoring: agree what to watch, who watches it, and what triggers reconsideration.

Risk assessment maps onto the third step. It is one way to surface assumptions and evaluate their significance. But it is only one way, and it is not the step that produces the decision. The decision comes from the fourth step, where someone judges whether what is known is enough to act, and the fifth, where someone designs what happens after the commitment is made.

The sibling hub on risk examines what the word actually means and why the apparatus built around it became a belief system rather than a method. This page is about something more practical: what to do once the assessment is in hand.

The answer is the same in every sector and every domain. Decide. Name the Decider. State the assumptions. Test the ones that are significant. Commit when the basis is sufficient. Design monitoring before you walk out of the room.

Risk assessment is not bad work. Identifying uncertainties, ranking their significance, understanding the terrain before you commit: all of that supports decision quality. The problem is treating the assessment as the destination rather than the departure point.

The assessment tells you what to think about. The method tells you how to think about it. What follows an assessment should always be a decision, recorded and monitored.

Your next step depends on what you assessed

The principle is universal. The application is specific. What you do after a risk assessment depends on what you assessed, who the Decider is, and what outcome the organisation is pursuing. Each domain has its own regulatory context, its own technical vocabulary, and its own failure modes. The method that connects the assessment to a decision is the same in every case. The assumptions you need to test are not.

Supplier relationships show the difference. A third-party risk tier describes one company, not the suppliers behind it, which is why what to do after a third-party risk assessment starts with those suppliers. The access a single vendor is given raises a separate question, covered in what to do after a vendor risk assessment. A DPIA assumes the processing will stay as described, which is why what to do after a DPIA starts with the changes that would reopen it.

Assessment domainThe decision it serves
WorkplaceControls: what physical, procedural, or behavioural changes will reduce harm, and whether the basis for believing they will work has been tested
Safety auditCorrective actions: who checks whether findings recur after they have been marked closed
ClinicalTreatment: which intervention carries consequences the patient and clinician judge acceptable given what is known and what remains uncertain
Third-party / vendorTerms of engagement: what contractual, monitoring, and exit provisions are sufficient given assumptions about the vendor's capacity and conduct
Change managementSequencing and safeguards: what assumptions about readiness, capability, and stakeholder response must hold for the transition to deliver its intended outcome
Terrorism / structuralPhysical protection and contingency: what measures and response arrangements are sufficient given the threat profile and assumptions about attacker capability or structural integrity
Transport / CDMDesign and operational controls: what the designer, contractor, or operator will put in place and what assumptions about conditions, compliance, and supervision must hold
Biological / tailings damContainment and monitoring: what barriers and detection systems must function, and what triggers escalation
TravelWhether to proceed, with what precautions, and what would cause the trip to be cancelled or the traveller recalled
Business continuity testRecovery plan: whether the exercise covered the external dependencies needed for a critical service to run
Threat and vulnerabilityResource allocation: which vulnerabilities justify countermeasures given assumptions about threat actors and their motivation
Workplace violenceIntervention: what procedural, environmental, and support measures will reduce harm, and how early-warning indicators will be monitored
CulturalProcess correction: fix the decision process and the culture follows; a report without that decision repeats the pattern this page describes

Your assessment told you what could go wrong. It did not tell you what to do.

Work through your decision

No sign-up. Just pick your decision and start.


Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.