After risk identification, test the assumptions behind each risk on the register, and behind what the register left out, before passing it to risk analysis. Analysis rates whatever it is handed. It cannot rate a risk that was described on a condition nobody checked, and it cannot see the link between two entries written up separately. In 2007, a British bank whose board had signed off fifteen liquidity stress scenarios learned which one was missing.
Risk identification is the first step of risk assessment: finding, recognising and describing the risks that could help or prevent an organisation achieving its objectives.
Northern Rock and the assumption nobody checked
Northern Rock converted from a building society to a bank in 1997 and spent the next decade growing its mortgage book fast. Its assets rose six-fold. Retail deposits did not keep pace. According to the House of Commons Treasury Committee (2008), retail deposits and funds fell from 62.7% of liabilities and equity at the end of 1997 to 22.4% at the end of 2006. The rest came from securitisation, covered bonds and wholesale borrowing.
The risk was not missed. The board's Risk Committee, chaired by Sir Derek Wanless, reviewed the funding strategy and its risks. The board signed off twenty stress scenarios; fifteen involved liquidity risk, two of them with securitisation in trouble. The Bank of England had flagged banks' growing reliance on wholesale funding in its April 2007 Financial Stability Report, and the chairman, Matt Ridley, told MPs such warnings had influenced board decisions. Liquidity risk was identified, named and repeatedly discussed.

What carried the failure was how the risk was described. Northern Rock had spread its funding across four platforms and several continents. Ridley explained the logic to the committee: the diversification was deliberate, "so that if one market closed we would still have access to others." The entry assumed the funding markets would fail one at a time. A second assumption sat beside it: that lenders under pressure would still favour a book of prime UK mortgages. Neither was tested.
On 9 August 2007, Northern Rock's traders noted a "dislocation in the market." Its funding markets then closed together. Wanless later told MPs that fifteen liquidity scenarios had been run, and "what did not happen was that we stress-tested the scenario of what has actually happened." The Financial Services Authority had told the bank in July that it was not comfortable with its scenarios, but the extra tests that followed were mainly about credit, such as a 40% fall in house prices. Listing what each scenario held constant is the first step in what to do after a stress test.
Northern Rock officials repeatedly described the simultaneous closure to the committee as "unforeseeable." The word turns an untested assumption into uncertainty that nobody was expected to own.
The same assumption had sized the safety net. Northern Rock held standby and swingline facilities of about $2.3 billion. Chief executive Adam Applegarth told the committee they were smaller than those of the US lender Countrywide "because we have a more diverse funding platform." On 14 September the Bank of England's support facility became public, and depositors queued outside branches in the first run on a UK bank's retail deposits since Victorian times.
The bank was nationalised in February 2008. The committee called its strategy a "reckless business model which was excessively reliant on wholesale funding." Shin (2009) located the cause in the bank's reliance on institutional lenders for short-term funding, not in the depositors who queued. Liquidity risk was on the list. The assumption that its sources were independent was not, and that was the one that failed.
Write down the condition your register's most important entry depends on and ask whether anyone checked it before the list went to analysis. Start the Walk →
What risk identification gets right and where it stops
ISO 31000:2018 sets out risk identification in clause 6.4.2. Its purpose is to find, recognise and describe risks that might help or prevent an organisation achieving its objectives. The companion standard, IEC 31010:2019, catalogues the techniques: brainstorming, interviews, checklists, HAZOP, scenario analysis. The output is usually a register, each risk described by its source, event, cause and likely consequence, ready for risk analysis to rate.
This step matters more than any that follows it. A risk that is never identified is never analysed, evaluated or treated. Good identification widens the lens beyond the obvious, draws in people who see different parts of the operation, and gives the rest of the risk assessment something concrete to work on. Northern Rock's board did this part. Funding risk was on its agenda, in its stress tests and in the regulator's review.
The standard even names the problem. Among the factors ISO 31000 lists for identification are the "biases, assumptions and beliefs of those involved." In practice that line shapes how the workshop is run, not what happens to its output. Each risk is written up as its own entry. The description fixes a condition: the control works, the supplier can be replaced, the markets are independent. Nobody checks it, because the job was to find the risk, and the risk has been found. The same holds in a CDM risk assessment, where each residual-risk entry names the control and leaves the condition it depends on unstated.
- Named risks, each with a cause and consequence
- An owner and a category for every entry
- The condition each description takes as given
- Which entries would fail together
- Whether the evidence behind each condition is current
- Scenarios the workshop agreed were implausible
The register also has a shape problem. It lists entries; it does not record which entries depend on the same condition. Two risks that share an assumption are one risk written down twice, and analysis will rate them as two. That is the gap risk registers leave when they are asked to support a decision rather than catalogue concerns.
A register records what the room agreed to worry about. It does not test whether the worry was described correctly.
The checkpoint between identification and analysis
The checkpoint sits after the register is drafted and before anyone assigns a likelihood. It does not add risks for the sake of volume. It interrogates the descriptions already there, starting with the entries whose failure would change a decision.
For each of those entries, ask three questions. What condition does this description take as given? What evidence shows that condition holds now, rather than that it held last year? Which other entries rest on the same condition, so that if it fails they fail together? Then ask one question of the register as a whole.
If one assumption behind this register failed, which other entries would fail with it?
The five-step method (Frame, Tentative Elements, Assumptions, Sufficient Certainty, Implement and Monitor) builds this into its third step. Assumptions are surfaced from the decision itself rather than collected as a list of worries, and each is judged by how much the outcome depends on it. The test is not whether a risk was identified, but whether the condition it was described on has been earned.
Not every entry needs evidence. The fourth step sets how much certainty is sufficient for the decision at hand, which keeps the checkpoint proportionate: the conditions carrying the most weight get tested, the rest get recorded and monitored. The assessment process keeps moving, and risk evaluation later compares ratings built on checked ground.
Northern Rock did not need a sixteenth liquidity scenario. It needed someone to read the fifteen and ask what they had in common. The question that mattered was not whether liquidity risk was on the list, but what every liquidity entry assumed about the others. Identification finds the risks. The checkpoint finds what the list takes for granted, before analysis turns those assumptions into numbers.
You could hand the risk register to analysis and still leave the scope and causes behind each entry untested.
Work through your decisionNo sign-up. Just pick your decision and start.
Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.