{"id":640,"date":"2024-02-16T15:11:14","date_gmt":"2024-02-16T08:11:14","guid":{"rendered":"https:\/\/audithink.com\/?p=640"},"modified":"2026-09-08T12:52:04","modified_gmt":"2026-09-08T05:52:04","slug":"risk-assessment","status":"publish","type":"post","link":"https:\/\/audithink.com\/en\/blog\/risk-assessment-adalah\/","title":{"rendered":"Risk Assessment is: meaning, steps, Matrix, &amp; examples"},"content":{"rendered":"<p class=\"wp-block-paragraph\"><strong><em>Risk assessment<\/em> is the process of identifying, analyzing, and evaluating risks that could disrupt an activity, then determining how to control them.<\/strong> In Indonesian, this term is called <strong>risk assessment<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The activity of <em>risk assessment<\/em> covers five sequential steps: risk identification, risk analysis, risk evaluation, risk control, and monitoring and review. The process is used in many contexts, ranging from workplace safety, information security, to <a href=\"https:\/\/audithink.com\/en\/article\/audit-internal-adalah\/\">internal audit<\/a> and corporate governance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This article discusses the meaning of <em>risk assessment<\/em>, the five steps of implementation, the risk assessment matrix and its table, its application in internal audit, and real examples at companies.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What is <em>Risk Assessment<\/em>?<\/h2>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"740\" height=\"494\" src=\"https:\/\/audithink.com\/wp-content\/uploads\/2024\/02\/risk.webp\" alt=\"company performance analysis process\" class=\"wp-image-641\" title=\"\" srcset=\"https:\/\/audithink.com\/wp-content\/uploads\/2024\/02\/risk.webp 740w, https:\/\/audithink.com\/wp-content\/uploads\/2024\/02\/risk-300x200.webp 300w, https:\/\/audithink.com\/wp-content\/uploads\/2024\/02\/risk-18x12.webp 18w\" sizes=\"(max-width: 740px) 100vw, 740px\" \/><figcaption class=\"wp-element-caption\">Illustration of company performance identification and analysis (Freepik)<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Risk assessment<\/em> is the process of identifying, assessing, and analyzing the risks associated with a particular activity. The goal is not merely to list hazards, but to measure two things at once: how great the <strong>likelihood<\/strong> of the risk occurring is, and how great the <strong>impact<\/strong> would be if it actually occurred. It is from these two measures that an organization decides which risks must be addressed first.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Risk assessment must be carried out by all types of organizations, both private companies and government agencies. Without a structured assessment, resources tend to be exhausted handling minor risks while major risks are overlooked.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The Difference from Risk Analysis and Risk Management<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">These three terms are often confused even though their scope differs:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Risk analysis<\/strong> is one stage within risk assessment, namely measuring the likelihood and impact of a risk.<\/li>\n\n\n\n<li><strong><em>Risk assessment<\/em> (risk assessment)<\/strong> covers that analysis, plus identification at the start and evaluation at the end to determine priority.<\/li>\n\n\n\n<li><strong>Risk Management<\/strong> is the biggest umbrella, covering the entire cycle from assessment, treatment, monitoring, to risk reporting at the organizational level.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>See also:<\/strong> <a href=\"https:\/\/audithink.com\/en\/article\/differences-between-gap-analysis-and-risk-assessment\/\" data-type=\"post\" data-id=\"4818\">Differences between Gap Analysis and Risk Assessment in Audit<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">5 Steps of <em>Risk Assessment<\/em><\/h2>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" width=\"740\" height=\"494\" src=\"https:\/\/audithink.com\/wp-content\/uploads\/2024\/02\/assessment.webp\" alt=\"Mengenal proses risk assessment\" class=\"wp-image-644\" title=\"\" srcset=\"https:\/\/audithink.com\/wp-content\/uploads\/2024\/02\/assessment.webp 740w, https:\/\/audithink.com\/wp-content\/uploads\/2024\/02\/assessment-300x200.webp 300w, https:\/\/audithink.com\/wp-content\/uploads\/2024\/02\/assessment-18x12.webp 18w\" sizes=\"(max-width: 740px) 100vw, 740px\" \/><figcaption class=\"wp-element-caption\">Illustration of activities in the process <em>risk assessment<\/em> (Freepik)<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The activity of <em>risk assessment<\/em> is a series of five steps carried out in sequence. Skipping one step makes the assessment result unreliable.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. Risk identification<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Listing all potential hazards or events that could cause loss or disruption to the organization's objectives. This stage usually involves field observation, interviews with process owners, review of historical incident data, and review of previous audit findings.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. Risk analysis<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Measuring each identified risk from two sides: the probability of it occurring and the magnitude of its impact. At this stage the root cause is also traced, because the same risk can originate from different sources and require different treatment.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. Risk evaluation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Comparing the analysis results with the risk criteria the organization has set, then placing each risk into the risk assessment matrix to determine its severity level. The output of this stage is a priority list: which risks must be addressed first.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4. Risk control<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Determining a treatment strategy for each priority risk. There are generally four options: avoiding the risk, reducing its likelihood or impact, transferring the risk to another party (for example through insurance), or knowingly accepting the risk because the cost of treatment exceeds the benefit.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5. Monitoring and review<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Ensuring the controls implemented are truly effective, while also periodically reviewing the assessment. Risk profiles change along with changes in business processes, technology, and regulations, so an assessment that is never reviewed will quickly become outdated.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><em>Risk Assessment Matrix<\/em> (Risk Assessment Matrix)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Risk assessment matrix<\/em> is a table that maps each risk based on its <strong>likelihood of occurring<\/strong> (rows) and <strong>impact<\/strong> (columns). Their intersection produces a risk level, which forms the basis for prioritizing treatment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The most commonly used form is the following 5\u00d75 matrix:<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table class=\"has-fixed-layout\"><thead><tr><th>Likelihood &darr; \/ Impact &rarr;<\/th><th>Insignificant<\/th><th>Minor<\/th><th>Currently<\/th><th>Major<\/th><th>Catastrophic<\/th><\/tr><\/thead><tbody><tr><td><strong>Almost certain to occur<\/strong><\/td><td>Medium<\/td><td>High<\/td><td>High<\/td><td>Extreme<\/td><td>Extreme<\/td><\/tr><tr><td><strong>Often occurs<\/strong><\/td><td>Medium<\/td><td>Medium<\/td><td>High<\/td><td>High<\/td><td>Extreme<\/td><\/tr><tr><td><strong>Sometimes occurs<\/strong><\/td><td>Low<\/td><td>Medium<\/td><td>Medium<\/td><td>High<\/td><td>Extreme<\/td><\/tr><tr><td><strong>Rarely occurs<\/strong><\/td><td>Low<\/td><td>Low<\/td><td>Medium<\/td><td>Medium<\/td><td>High<\/td><\/tr><tr><td><strong>Very rarely occurs<\/strong><\/td><td>Low<\/td><td>Low<\/td><td>Low<\/td><td>Medium<\/td><td>High<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The four risk levels in that matrix are read as follows.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. <em>Extreme<\/em><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The highest-priority risk. Must be addressed immediately and usually needs to be escalated to top management. Related activities are often suspended until adequate controls are in place.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. <em>High<\/em><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Needs immediate action with a clear person in charge and deadline. If treatment cannot be completed by the deadline, a new, stricter deadline must be set, rather than left hanging.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. <em>Medium<\/em><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Medium risk<\/em> means the risk is at a moderate level: not urgent, but still needs a planned treatment strategy. It can generally be addressed through procedural improvements without requiring major resources.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4. <em>Low<\/em><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A low risk that does not cause significant disruption. Sufficient to be monitored periodically. Treatment may still be carried out if the cost is small and it provides an overall performance improvement.<\/p>\n\n\n\t\t<div data-elementor-type=\"section\" data-elementor-id=\"5427\" class=\"elementor elementor-5427\" data-elementor-post-type=\"elementor_library\">\n\t\t\t<div class=\"elementor-element elementor-element-c693698 e-flex e-con-boxed e-con e-parent\" data-id=\"c693698\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f131bf4 cta-banner-article elementor-widget elementor-widget-image\" data-id=\"f131bf4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/audithink.com\/en\/demo\/?utm_source=blog&#038;utm_medium=cta-banner&#038;utm_campaign=request-demo-cta-banner&#038;utm_content=request-demo-aplikasi-audit-banner\">\n\t\t\t\t\t\t\t<img decoding=\"async\" width=\"2400\" height=\"800\" src=\"https:\/\/audithink.com\/wp-content\/uploads\/2026\/07\/audithink-banner-v3-photo.webp\" class=\"attachment-full size-full wp-image-5428\" alt=\"cta banner campaign\" srcset=\"https:\/\/audithink.com\/wp-content\/uploads\/2026\/07\/audithink-banner-v3-photo.webp 2400w, https:\/\/audithink.com\/wp-content\/uploads\/2026\/07\/audithink-banner-v3-photo-300x100.webp 300w, https:\/\/audithink.com\/wp-content\/uploads\/2026\/07\/audithink-banner-v3-photo-1024x341.webp 1024w, https:\/\/audithink.com\/wp-content\/uploads\/2026\/07\/audithink-banner-v3-photo-768x256.webp 768w, https:\/\/audithink.com\/wp-content\/uploads\/2026\/07\/audithink-banner-v3-photo-1536x512.webp 1536w, https:\/\/audithink.com\/wp-content\/uploads\/2026\/07\/audithink-banner-v3-photo-2048x683.webp 2048w, https:\/\/audithink.com\/wp-content\/uploads\/2026\/07\/audithink-banner-v3-photo-18x6.webp 18w\" sizes=\"(max-width: 2400px) 100vw, 2400px\" title=\"\">\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\n\n\n\n<h2 class=\"wp-block-heading\"><em>Risk Assessment<\/em> in Internal Audit<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In the context of audit, <em>risk assessment<\/em> is the basis for preparing the audit plan. Internal auditors do not examine every process with the same weight, but instead direct time and resources to the areas of highest risk. This approach is known as <a href=\"https:\/\/audithink.com\/en\/article\/risk-based-audit\/\">risk-based audit<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Risk assessment in audit is generally carried out at two levels. At the organizational level, the results determine which units or processes are included in the annual audit plan. At the engagement level, the results determine which <a href=\"https:\/\/audithink.com\/en\/article\/audit-procedures\/\" data-type=\"post\" data-id=\"3314\">audit procedure<\/a> are carried out and how extensive the testing is.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The most widely used reference framework is the <a href=\"https:\/\/audithink.com\/en\/article\/coso-framework\/\" data-type=\"post\" data-id=\"3979\">COSO Framework<\/a>, which places risk assessment as one of the main components of internal control. For a discussion of the types of risk typical in an audit engagement, see <a href=\"https:\/\/audithink.com\/en\/article\/audit-risk\/\" data-type=\"post\" data-id=\"3315\">audit risk<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Example of <em>Risk Assessment<\/em> at Tech Company<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Here is an example of applying the five steps at a software development company, which can serve as a reference for preparing a risk assessment at your organization.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. Risk identification<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Security vulnerabilities in software that can be exploited by outside parties<\/li>\n\n\n\n<li>Loss of customer data due to system failure or attack <em>malware<\/em><\/li>\n\n\n\n<li>Mental and physical health disruption to employees due to high workload<\/li>\n\n\n\n<li>Physical hazards in the workplace, such as injuries from accidents or unhealthy environmental conditions<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">2. Risk analysis<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Measuring the probability and impact of each identified risk<\/li>\n\n\n\n<li>Tracing its cause. For example, the likelihood of a security vulnerability being exploited is low, but the impact on the company's reputation and finances is significant<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">3. Risk evaluation<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Placing each risk into the 5\u00d75 matrix above. That security vulnerability sits at the intersection of &#8220;rarely occurs&#8221; and &#8220;major&#8221;, placing it in the category <em>Medium<\/em><\/li>\n\n\n\n<li>Evaluating compliance risk regarding personal data protection regulations<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">4. Risk control<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Implementing stricter security procedures and periodic penetration testing<\/li>\n\n\n\n<li>Improving system monitoring and data backup mechanisms<\/li>\n\n\n\n<li>Providing occupational safety training and workload management for employees<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">5. Monitoring and review<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Periodically monitoring the effectiveness of controls through measurable indicators<\/li>\n\n\n\n<li>Reviewing the risk assessment every time a process, system, or regulation changes<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">FAQ About <em>Risk Assessment<\/em><\/h2>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong><em>Risk assessment<\/em> what does it mean?<\/strong><\/summary>\n<p class=\"wp-block-paragraph\"><em>Risk assessment<\/em> means risk assessment, namely the process of identifying, analyzing, and evaluating risks that could disrupt an activity, then determining how to control them.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>The activity of <em>risk assessment<\/em> cover?<\/strong><\/summary>\n<p class=\"wp-block-paragraph\">The activity of <em>risk assessment<\/em> is risk identification, risk analysis, risk evaluation, risk control, and monitoring and review. All five are carried out in sequence and repeated periodically.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>What is the difference between a <em>risk assessment<\/em> and risk management?<\/strong><\/summary>\n<p class=\"wp-block-paragraph\"><em>Risk assessment<\/em> is part of risk management. Risk assessment stops at the stage of determining the level and priority of risk, while risk management covers the entire cycle, from assessment, treatment, monitoring, to risk reporting at the organizational level.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>What is <em>risk assessment matrix<\/em>?<\/strong><\/summary>\n<p class=\"wp-block-paragraph\">A risk assessment matrix is a table that maps risks based on their likelihood of occurring and the magnitude of their impact. Their intersection produces a risk level \u2014 <em>low<\/em>, <em>medium<\/em>, <em>high<\/em>, or <em>extreme<\/em> \u2014 which forms the basis for prioritizing treatment.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong><em>Medium risk<\/em> what does it mean?<\/strong><\/summary>\n<p class=\"wp-block-paragraph\"><em>Medium risk<\/em> means a risk at a moderate level: not as urgent as <em>high<\/em> or <em>extreme<\/em>, but still requiring a planned treatment strategy. It can generally be addressed through procedural improvements without major resources.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>What is the purpose of conducting a <em>risk assessment<\/em>?<\/strong><\/summary>\n<p class=\"wp-block-paragraph\">The goal is to identify potential hazards, evaluate their likelihood and impact, then develop a strategy to reduce or manage risk more effectively \u2014 so that the organization's resources are directed at the most important risks.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>How <em>risk assessment<\/em> used in internal audit?<\/strong><\/summary>\n<p class=\"wp-block-paragraph\">The results of the risk assessment determine which units or processes are included in the annual audit plan, as well as which audit procedures are carried out and how extensive the testing is. This approach is known as risk-based audit.<\/p>\n<\/details>\n\n\n\n<h2 class=\"wp-block-heading\">Manage Audit Risk Assessment More Systematically with Audithink<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Preparing risk assessments for many units and branches manually makes the risk profile quickly outdated and hard to trace. <strong><a href=\"https:\/\/audithink.com\/en\/\" data-type=\"page\" data-id=\"794\">Audithink, <em>internal audit management software<\/em><\/a><\/strong> for companies and state-owned enterprises in Indonesia, helping internal audit teams map risks, prepare a risk-based audit plan, and monitor follow-up on findings in one integrated platform.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><a href=\"https:\/\/audithink.com\/en\/demo\/\">Schedule an Audithink Demo<\/a><\/strong> to see how our platform supports risk-based audit.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><a href=\"https:\/\/audithink.com\/en\/contact\/\">Consultation with the Audithink Team<\/a><\/strong> to discuss your company's internal audit needs.<\/p>","protected":false},"excerpt":{"rendered":"<p>Risk assessment identifies potential hazards and analyzes the likelihood of them occurring. Learn the meaning, steps, assessment matrix, and examples.<\/p>","protected":false},"author":6,"featured_media":642,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":"","rank_math_title":"Risk Assessment adalah: Arti, Langkah, Matriks, &amp; Contohnya","rank_math_description":"Risk assessment adalah proses identifikasi, analisis, dan evaluasi risiko. Pahami artinya, 5 langkah, matriks penilaian risiko 5x5, dan contohnya.","rank_math_canonical_url":"","rank_math_focus_keyword":"risk assessment adalah","rank_math_facebook_title":"","rank_math_facebook_description":"","rank_math_twitter_title":"","rank_math_twitter_description":"","_yoast_wpseo_title":"","_yoast_wpseo_metadesc":"","_yoast_wpseo_canonical":"","_yoast_wpseo_focuskw":"","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","rank_math_robots":[]},"categories":[15],"tags":[31],"class_list":["post-640","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-manajemen-risiko"],"acf":[],"_links":{"self":[{"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/posts\/640","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/comments?post=640"}],"version-history":[{"count":4,"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/posts\/640\/revisions"}],"predecessor-version":[{"id":6220,"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/posts\/640\/revisions\/6220"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/media\/642"}],"wp:attachment":[{"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/media?parent=640"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/categories?post=640"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/tags?post=640"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}