Risk assessment is the process of identifying, analyzing, and evaluating risks that could disrupt an activity, then determining how to control them. In Indonesian, this term is called risk assessment.
The activity of risk assessment covers five sequential steps: risk identification, risk analysis, risk evaluation, risk control, and monitoring and review. The process is used in many contexts, ranging from workplace safety, information security, to internal audit and corporate governance.
This article discusses the meaning of risk assessment, the five steps of implementation, the risk assessment matrix and its table, its application in internal audit, and real examples at companies.
What is Risk Assessment?

Risk assessment is the process of identifying, assessing, and analyzing the risks associated with a particular activity. The goal is not merely to list hazards, but to measure two things at once: how great the likelihood of the risk occurring is, and how great the impact would be if it actually occurred. It is from these two measures that an organization decides which risks must be addressed first.
Risk assessment must be carried out by all types of organizations, both private companies and government agencies. Without a structured assessment, resources tend to be exhausted handling minor risks while major risks are overlooked.
The Difference from Risk Analysis and Risk Management
These three terms are often confused even though their scope differs:
- Risk analysis is one stage within risk assessment, namely measuring the likelihood and impact of a risk.
- Risk assessment (risk assessment) covers that analysis, plus identification at the start and evaluation at the end to determine priority.
- Risk Management is the biggest umbrella, covering the entire cycle from assessment, treatment, monitoring, to risk reporting at the organizational level.
See also: Differences between Gap Analysis and Risk Assessment in Audit
5 Steps of Risk Assessment

The activity of risk assessment is a series of five steps carried out in sequence. Skipping one step makes the assessment result unreliable.
1. Risk identification
Listing all potential hazards or events that could cause loss or disruption to the organization's objectives. This stage usually involves field observation, interviews with process owners, review of historical incident data, and review of previous audit findings.
2. Risk analysis
Measuring each identified risk from two sides: the probability of it occurring and the magnitude of its impact. At this stage the root cause is also traced, because the same risk can originate from different sources and require different treatment.
3. Risk evaluation
Comparing the analysis results with the risk criteria the organization has set, then placing each risk into the risk assessment matrix to determine its severity level. The output of this stage is a priority list: which risks must be addressed first.
4. Risk control
Determining a treatment strategy for each priority risk. There are generally four options: avoiding the risk, reducing its likelihood or impact, transferring the risk to another party (for example through insurance), or knowingly accepting the risk because the cost of treatment exceeds the benefit.
5. Monitoring and review
Ensuring the controls implemented are truly effective, while also periodically reviewing the assessment. Risk profiles change along with changes in business processes, technology, and regulations, so an assessment that is never reviewed will quickly become outdated.
Risk Assessment Matrix (Risk Assessment Matrix)
Risk assessment matrix is a table that maps each risk based on its likelihood of occurring (rows) and impact (columns). Their intersection produces a risk level, which forms the basis for prioritizing treatment.
The most commonly used form is the following 5×5 matrix:
| Likelihood ↓ / Impact → | Insignificant | Minor | Currently | Major | Catastrophic |
|---|---|---|---|---|---|
| Almost certain to occur | Medium | High | High | Extreme | Extreme |
| Often occurs | Medium | Medium | High | High | Extreme |
| Sometimes occurs | Low | Medium | Medium | High | Extreme |
| Rarely occurs | Low | Low | Medium | Medium | High |
| Very rarely occurs | Low | Low | Low | Medium | High |
The four risk levels in that matrix are read as follows.
1. Extreme
The highest-priority risk. Must be addressed immediately and usually needs to be escalated to top management. Related activities are often suspended until adequate controls are in place.
2. High
Needs immediate action with a clear person in charge and deadline. If treatment cannot be completed by the deadline, a new, stricter deadline must be set, rather than left hanging.
3. Medium
Medium risk means the risk is at a moderate level: not urgent, but still needs a planned treatment strategy. It can generally be addressed through procedural improvements without requiring major resources.
4. Low
A low risk that does not cause significant disruption. Sufficient to be monitored periodically. Treatment may still be carried out if the cost is small and it provides an overall performance improvement.
Risk Assessment in Internal Audit
In the context of audit, risk assessment is the basis for preparing the audit plan. Internal auditors do not examine every process with the same weight, but instead direct time and resources to the areas of highest risk. This approach is known as risk-based audit.
Risk assessment in audit is generally carried out at two levels. At the organizational level, the results determine which units or processes are included in the annual audit plan. At the engagement level, the results determine which audit procedure are carried out and how extensive the testing is.
The most widely used reference framework is the COSO Framework, which places risk assessment as one of the main components of internal control. For a discussion of the types of risk typical in an audit engagement, see audit risk.
Example of Risk Assessment at Tech Company
Here is an example of applying the five steps at a software development company, which can serve as a reference for preparing a risk assessment at your organization.
1. Risk identification
- Security vulnerabilities in software that can be exploited by outside parties
- Loss of customer data due to system failure or attack malware
- Mental and physical health disruption to employees due to high workload
- Physical hazards in the workplace, such as injuries from accidents or unhealthy environmental conditions
2. Risk analysis
- Measuring the probability and impact of each identified risk
- Tracing its cause. For example, the likelihood of a security vulnerability being exploited is low, but the impact on the company's reputation and finances is significant
3. Risk evaluation
- Placing each risk into the 5×5 matrix above. That security vulnerability sits at the intersection of “rarely occurs” and “major”, placing it in the category Medium
- Evaluating compliance risk regarding personal data protection regulations
4. Risk control
- Implementing stricter security procedures and periodic penetration testing
- Improving system monitoring and data backup mechanisms
- Providing occupational safety training and workload management for employees
5. Monitoring and review
- Periodically monitoring the effectiveness of controls through measurable indicators
- Reviewing the risk assessment every time a process, system, or regulation changes
FAQ About Risk Assessment
Risk assessment what does it mean?
Risk assessment means risk assessment, namely the process of identifying, analyzing, and evaluating risks that could disrupt an activity, then determining how to control them.
The activity of risk assessment cover?
The activity of risk assessment is risk identification, risk analysis, risk evaluation, risk control, and monitoring and review. All five are carried out in sequence and repeated periodically.
What is the difference between a risk assessment and risk management?
Risk assessment is part of risk management. Risk assessment stops at the stage of determining the level and priority of risk, while risk management covers the entire cycle, from assessment, treatment, monitoring, to risk reporting at the organizational level.
What is risk assessment matrix?
A risk assessment matrix is a table that maps risks based on their likelihood of occurring and the magnitude of their impact. Their intersection produces a risk level — low, medium, high, or extreme — which forms the basis for prioritizing treatment.
Medium risk what does it mean?
Medium risk means a risk at a moderate level: not as urgent as high or extreme, but still requiring a planned treatment strategy. It can generally be addressed through procedural improvements without major resources.
What is the purpose of conducting a risk assessment?
The goal is to identify potential hazards, evaluate their likelihood and impact, then develop a strategy to reduce or manage risk more effectively — so that the organization's resources are directed at the most important risks.
How risk assessment used in internal audit?
The results of the risk assessment determine which units or processes are included in the annual audit plan, as well as which audit procedures are carried out and how extensive the testing is. This approach is known as risk-based audit.
Manage Audit Risk Assessment More Systematically with Audithink
Preparing risk assessments for many units and branches manually makes the risk profile quickly outdated and hard to trace. Audithink, internal audit management software for companies and state-owned enterprises in Indonesia, helping internal audit teams map risks, prepare a risk-based audit plan, and monitor follow-up on findings in one integrated platform.
Schedule an Audithink Demo to see how our platform supports risk-based audit.
Consultation with the Audithink Team to discuss your company's internal audit needs.