Seventy-two people died at Grenfell, and still the paperwork was thick enough for each party to suppose someone else had done the thinking. That, in my experience, is the standard risk assessment process at work: a file substantial enough to move the project forward, yet too thin to test the decision that mattered.

This survives because it suits the people around the decision. Regulators get something inspectable, and consultants get something billable. Executives like it too, because a signed form is easier to hide behind than a hard judgement.

A risk assessment process examines uncertainty around a decision so people can judge whether to proceed, and what would make them stop.

A risk assessment process starts with the wrong question

Most advice pieces still tell you to identify hazards and score them before anyone states the decision in plain English. I have been asking clients the same question for years: if risk assessment is the answer, what was your question? In my experience, the room often cannot say, because the machinery was built to produce a respectable file, not a usable decision. The National Research Council made much the same complaint about US EPA practice when it found the process had become slow and poorly fitted to what decision-makers actually needed.

The UK National Risk Register 2025 says no risk assessment can identify and assess every possible risk. Quite right. A national process with intelligence inputs will not pretend to be exhaustive, yet the local workshop still acts as though a fresh wall of sticky notes has solved the problem. That is why, in my definition of risk, I treat risk as uncertainty around a decision, not as a collection of hazards waiting for a spreadsheet.

I have sat through hundreds of those workshops across four continents. The ones that work start with one sentence on the board before the first sticky note appears: what is the decision, and who has to make it? The ones that fail begin with hazard lists and end with a register that answers a question nobody in the room can articulate. By the time someone asks what decision the register is meant to support, the budget is spent and the consultants have left.

Two process flows compared: the standard risk assessment loop ending in a register versus the decision-centred process ending in tested assumptions
The standard process ends at a register. The alternative ends at a tested decision.Click to expand

If you want the cleaner distinction, I spell it out in risk vs uncertainty. A named hazard is useful only if it helps you decide. The rest is paraphernalia, which can be very comforting when the board pack is due and few people want to admit the central question is still blurry.

At Grenfell, the process became cover

The Grenfell Tower Inquiry Phase 2 report shows fragments of paperwork being mistaken for a decision. Exova produced a draft fire strategy and never finished it. Rydon assumed the fire question had been covered elsewhere. Building control never tested whether the wall system proposed for the tower matched the tested system, and government left the regulatory fiction standing for years after the warnings arrived.

The people who benefited from not putting the decision into one sentence were not hard to find. Cladding makers kept selling, and the refurbishment kept moving. Certifiers kept their stamps, while regulators kept the fiction that oversight was working. The question should have been brutally simple: is this wall system safe enough for a high-rise residential tower? That is where the standard risk assessment process breaks. The paperwork starts to matter more than the decision, and a sign-off becomes proof only that a document moved.

I have seen softer versions of this in boardrooms for years. Once the file exists, people start treating it as moral cover. Very few people say, in plain words, that the report may have answered a different question from the one the decision-maker actually has.

A risk assessment process breaks on novel hazards

The US Chemical Safety and Hazard Investigation Board report on the Givaudan Louisville explosion shows why checklist thinking is weakest where uncertainty is highest. On November 12, 2024, Reactor 6 exploded. Two workers were killed and three were seriously injured. The board found the emergency relief system would have needed to be four times larger.

The live decision was never, "have we completed a process hazard analysis?" It was, "are we sufficiently certain this reactor is safe to run when the chemistry is not fully understood?" The company benefited, for a while, from leaving that question blurry because production keeps paying the bills while unresolved chemistry does not.

The report also notes that the plant sat outside key baseline controls because fixed chemical lists did not capture this reactive hazard. That suited the apparatus too. A list-based regime can always shrug when the danger sits just outside the box it chose to draw.

CrowdStrike’s root cause analysis shows the same habit in software. A July 2024 content update expected 21 input fields and received 20. Validation still passed. On July 20, 2024, Microsoft said 8.5 million Windows devices were affected. The vendor benefited from speed until the outage made the shortcut visible. The real decision was whether there was enough certainty for a global rollout with that blast radius, not whether the release checklist looked tidy.

Risk appetite adds fog, not clarity

There is a governance layer that is meant to sit above all this. Regulators now ask companies to produce statements of their risk appetite, and boards treat the exercise as though it settles something. I wrote about this for RiskPost in 2011, and the picture has not improved.

COSO gave two definitions that did not match: a "degree of risk" in one sentence and an "amount of risk" in the next, with no explanation of the difference. The Basel Committee defined risk appetite and risk tolerance separately, then said it used the terms synonymously. King III in South Africa treated appetite as subordinate to tolerance. When the working group I sat on prepared ISO 31000, we chose not to use either term. The reason was simple: both invited the same theatre we were trying to end.

The practical alternative in the Standard is risk criteria: terms of reference derived from an organisation's objectives, against which the significance of a risk is evaluated. That sounds plain, and it is. Risk criteria force you back to the decision and its context. A risk appetite statement floats above the organisation like a poster nobody reads on the way to the lift.

The concept seems simple until a board tries to produce one. People define risk differently in ordinary conversation, so reaching agreement on what is being described takes longer than deciding what to do about it. The appetite shifts with the decision at hand. Intangible consequences like reputation, staff morale and the social licence to operate vanish when appetite is expressed in dollars. And there is rarely a simple relationship between the level of risk and the return, despite the phrase "risk versus return" that so many institutions repeat.

What survives the exercise is usually a sentence vague enough to cover everything and specific enough to cover nothing. Consultants benefit, because defining the indefinable is billable work. The board benefits briefly, because a signed statement looks like governance. The decision that matters still goes untested, and the appetite statement will not be in the room when it has to be made.

A better risk assessment process tests the decision

This is why Roger Estall and I built the Universal Decision-Making Method. In Deciding, we make the point plainly. First we Frame the decision, because without that the rest is theatre. Then we Develop options, because one pre-approved path is usually camouflage for a decision already taken. Then we Recognise assumptions. Only after that do we ask what would count as Sufficient certainty. From there we Design monitoring so the decision can be reopened before reality does it for us.

I prefer that sequence because plain language strips away some very profitable fog. Risk staff lose part of their apparatus, and consultants lose product. Boards also lose the paper cover they have been using as judgement’s stunt double.

When I have applied this to a live assessment, the first thing that happens is that half the register becomes irrelevant, because it was cataloguing hazards for a decision nobody had stated. The items that survive become sharper, because people finally know what they are testing. People sometimes rebadge this as risk-based decision making, but I do not bother with the label. I just want the real decision on the table, with its assumptions exposed, before the organisation commits itself.

If someone hands you an assessment, do not start by admiring the layout. Ask what decision it is supposed to help, then ask what assumption would break that decision. If the answers are vague, the document is theatre with a signature block. If the answers are clear, you may finally have something useful enough to deserve the name.

You could finish the next risk assessment and still never test the decision underneath.

Work through your decision

No sign-up. Just pick your decision and start.


Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.