After risk analysis, test the assumptions each risk rating depends on before passing the ratings to evaluation. Most teams skip this step because the ratings already look precise. In 2010, that precision killed eleven people in the Gulf of Mexico.
Risk analysis is the step between identifying a risk and deciding what to do about it, estimating how likely it is and how much damage it could cause.
Deepwater Horizon and the assumption nobody checked
On 20 April 2010, the Macondo well blew out in the Gulf of Mexico, killed eleven workers, and produced the largest marine oil spill in history. BP had conducted risk analyses for the well operations. The analyses produced risk ratings. The ratings did not prevent the disaster because the assumptions behind them were never tested.
BP's Deepwater Horizon rig was drilling the Macondo prospect in approximately 5,000 feet of water. Risk analyses for the well operations followed industry convention: identify hazards, estimate likelihood and consequence, assign ratings, document barriers. The National Commission on the BP Deepwater Horizon Oil Spill (2011) later reconstructed what those analyses assumed and what they missed.
The analyses assumed the blowout preventer would function as a last barrier. The BOP sat on the seabed as the final mechanical defence against an uncontrolled release of hydrocarbons. Its blind shear rams were designed to cut through drill pipe and seal the well. Nobody tested whether those rams could cut through the specific drill pipe configuration actually in the hole at the time. The pipe included a tool joint, a thickened section that the rams were not rated to sever. The assumption that the BOP would work as modelled was embedded in the risk rating for the well. It was never verified against the physical conditions.

Halliburton ran cement modelling software (Opticem) on the cement job that would seal the bottom of the well. The model showed a risk of channelling, a condition where gas could migrate through gaps in the cement. The results were not shared with decision-makers on the rig. The risk analysis existed. The information it produced stayed inside the organisation that produced it, separated from the people who needed it to decide whether to proceed.
The crew then ran a negative pressure test, a direct check of whether the well was sealed. The test returned anomalous readings. Rather than treating the anomaly as evidence that a critical assumption had failed, the crew interpreted it away. They attributed the unexpected pressure to a "bladder effect" in the test equipment. The Chemical Safety Board investigation documented how the interpretation allowed the operation to continue past the point where the evidence no longer supported the conclusion.
The National Commission found that "better management of decision-making processes... could have prevented the blowout." Hopkins (2012) traced the organisational causes in detail: the risk analysis apparatus was in place, the ratings existed, the barriers were documented. What was missing was a step between producing the analysis and acting on it, a step where someone would have asked which ratings depended on conditions that had not been checked.
The BOP assumption, the cement channelling data, the negative pressure test. Each was a point where the analysis or its outputs contained information that contradicted a load-bearing assumption. Each was a point where the standard process moved forward instead of stopping to verify.
Write down the assumption your highest risk rating depends on and ask who tested it before the rating entered evaluation. Start the Walk →
What risk analysis gets right, and where it stops
ISO 31000:2018 positions risk analysis between identification and evaluation. Analysis takes the list of identified risks and develops an understanding of each one: its nature, sources, causes, and level. The level is typically expressed as a combination of likelihood and consequence. The output feeds risk evaluation, where ratings are compared against criteria to determine which risks need treatment.
This sequence is genuinely useful. Without analysis, the organisation has a list of concerns and no way to compare them. Analysis forces teams to think about what could happen, how it might happen, and how severe the consequences could be. That structured thinking is better than intuition alone, and far better than ignoring the risks entirely.
The problem is not what risk analysis does. The problem is what teams assume it has done. A completed analysis creates the impression that the risks are now understood. The ratings look precise. The register looks comprehensive. The precision of the output disguises the uncertainty of the inputs.
A likelihood estimate of "unlikely" embeds a judgment about frequency, exposure, and the reliability of existing controls. A consequence estimate of "major" embeds assumptions about what would fail, what would hold, and how quickly the organisation could respond. Neither estimate is tested by the act of recording it. The analysis process asks teams to produce ratings. It does not ask them to state what those ratings depend on or what would make them wrong.
This is where the risk assessment sequence creates a structural gap. Analysis produces outputs that look like facts. Evaluation treats them as facts. Treatment plans are built on them. But between producing the rating and acting on it, no step in the standard process asks: what did this rating assume, and has anyone checked?
The gap is not a flaw in risk-based decision making. It is a flaw in how most organisations practise it. The analysis does its job. What follows the analysis does not.
The checkpoint between analysis and action
The step to take after risk analysis and before evaluation is not more analysis. It is a checkpoint: name the assumptions each rating depends on, and determine whether those assumptions have evidence behind them or only agreement.
Start with the highest-rated risks. For each one, ask three questions. What did the likelihood estimate assume about current conditions? What did the consequence estimate assume about what would hold and what would fail? Has anyone tested those assumptions against evidence, or were they adopted because they seemed reasonable at the time?
A risk rated "low" because a safety system is assumed to function. The rating passes into evaluation, treatment is deprioritised, and the safety system is never inspected against the conditions it will actually face.
The same risk is flagged because the safety system has not been tested under the specific operating configuration. The team verifies the assumption before the rating enters evaluation, and either confirms the rating or revises it.
The five-step method (Frame, Tentative Elements, Assumptions, Sufficient Certainty, Implement and Monitor) treats this checkpoint as structural. The third step, surfacing assumptions, exists precisely because every analytical output rests on conditions that the analysis itself does not verify. Risk analysis is no exception.
This does not require dismantling the assessment process or extending the timeline. It requires a pause between producing ratings and acting on them. The pause asks: which of these ratings would change if one of its underlying assumptions turned out to be wrong? The ratings that survive that question are the ones worth evaluating. The ratings that do not survive it need to be revised before the organisation commits resources based on them.
Deepwater Horizon did not lack risk analysis. It lacked the step between analysis and action where someone would have asked: has anyone tested whether the BOP can actually cut through the drill pipe configuration in the hole right now? The checkpoint is not additional analysis. It is the discipline of naming what the analysis assumed and deciding whether that assumption has been earned.
A risk rating is a compressed judgment. Compression is useful. But acting on the compressed result without checking what was compressed out is how organisations turn analysis into theatre and ratings into false confidence.
You could complete the risk analysis and still leave every assumption behind the ratings untested.
Work through your decisionNo sign-up. Just pick your decision and start.
Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.