← University
Risk Identification and the Risk Register
0 of 4

A governance review conducted by an external consultant delivered findings that surprised the leadership of a mid-sized community services organization operating across 3 urban centres in central Canada. The organization, which had grown from a volunteer-run neighbourhood initiative 15 years earlier into an operation with 47 full-time staff and an annual budget of $4.2 million, had never formalized its approach to organizational risk. The board of directors received the consultant's report in late autumn, and among its observations was a pointed note: the organization maintained no risk register, conducted no systematic risk identification process, and relied entirely on the institutional memory of its executive director and 2 long-serving program managers to anticipate and respond to threats.

The observation landed differently depending on who read it. The executive director, who had been with the organization for 11 years, initially dismissed the concern as consultant-speak disconnected from how community organizations actually function. The board chair, a retired healthcare administrator with experience in accreditation processes, recognized the gap as significant. The finance committee chair, a professional accountant, noted that the organization's liability insurer had twice requested documentation of risk management practices in the previous 18 months, requests that had been answered with general assurances rather than evidence.

The organization's operational landscape had changed substantially over the preceding 5 years. It had expanded from 1 service location to 3, added a transportation program serving elderly clients, begun accepting referrals from child welfare authorities for supervised family visits, and hired its first information technology coordinator to manage client databases containing sensitive personal information. Each expansion had proceeded without a structured assessment of associated risks, and each had introduced exposures that no one had formally documented or assigned for monitoring.

The board passed a motion directing the executive director to develop a risk register within 90 days. The motion came with no budget allocation, no template, no training resources, and no clear guidance on what the board expected the document to contain or how it should be maintained once created. The executive director now faced the task of building a risk identification and documentation system from nothing, with limited time, competing operational demands, and uncertainty about whether the resulting document would be a genuine management tool or another compliance exercise destined for a forgotten folder on the shared drive.

Risk Identification Techniques: How to Surface What You Do Not Know You Are Missing

Risk exists in every organization, whether acknowledged or not. The difference between organizations that thrive through uncertainty and those that stumble lies not in their luck or their industry but in their systematic approach to surfacing risks before those risks surface themselves, often at the worst possible moment. Risk identification stands as the foundational activity in any enterprise risk management program, yet it remains the discipline most frequently performed inadequately or skipped entirely by organizations that believe they already know what threatens them. This belief, that experienced operators inherently understand their risk landscape, represents perhaps the most dangerous assumption in organizational management.

The practice of risk identification traces its modern form to post-war industrial safety programs, but its current sophistication owes much to the development of structured frameworks that emerged in the late twentieth century. In Canada, the adoption of internationally recognized standards has shaped how organizations approach the systematic discovery of risks across their operations. The International Organization for Standardization's ISO 31000 Risk Management standard, as of the date of authorship, provides the predominant framework that Canadian organizations reference when building their risk management programs. This standard emphasizes that risk identification should be systematic, structured, and dynamic, recognizing that risks evolve as organizational contexts change. The standard does not prescribe specific techniques but rather establishes principles that any chosen technique should satisfy, including comprehensiveness, the involvement of appropriate stakeholders, and the use of relevant information.

Canadian organizations operate within a complex regulatory environment that spans federal jurisdiction, provincial and territorial requirements, and in Quebec, a civil law framework that approaches certain risks differently than the common law provinces. Federal legislation such as the Canada Business Corporations Act, the Personal Information Protection and Electronic Documents Act, and sector-specific statutes impose obligations that create compliance risks for organizations nationwide. Provincial legislation adds layers of employment standards, workplace safety requirements, environmental regulations, and professional licensing obligations that vary in their specifics while sharing common objectives. Quebec's Civil Code creates distinct considerations around contractual liability, privacy rights, and organizational duties that risk managers must account for when their operations touch that province. The consequence of this regulatory complexity is that risk identification cannot proceed from a single perspective or a single set of assumptions about what might go wrong. Organizations must actively seek out the unknown risks that arise from the intersection of their specific activities with this multifaceted regulatory environment.

The techniques available for risk identification range from the straightforward to the sophisticated, and the appropriate choice depends on the organization's size, complexity, resources, and the nature of the risks it faces. What unites effective techniques is their structured approach to overcoming the cognitive limitations that prevent individuals and groups from recognizing risks that fall outside their immediate experience or that contradict their assumptions about how the world operates. Human beings, including experienced executives and operators, consistently underestimate risks in areas where they have not personally experienced negative outcomes. They overweight recent events and underweight historical patterns. They assume that because something has not happened yet, it will not happen, a logical fallacy that risk identification techniques specifically aim to counteract.

Brainstorming sessions represent the most common starting point for risk identification, yet the technique proves far less effective than most practitioners assume when conducted without proper structure. The unstructured gathering of risks from a group of colleagues typically produces a list dominated by obvious operational concerns, recent near-misses, and the particular worries of the most vocal participants. True risk identification requires moving beyond this first layer of easily accessible concerns to surface the risks that no one in the room has considered. Structured brainstorming techniques address this limitation by imposing constraints that force participants to consider categories of risk they would otherwise overlook. Prompting participants to consider risks in each category of the organization's activities, or to imagine specific failure scenarios and work backward to identify contributing factors, produces meaningfully different results than simply asking what could go wrong.

The Delphi technique offers particular value for organizations that need to gather risk perspectives from stakeholders who cannot easily meet in person or whose contributions might be influenced by group dynamics. This approach, developed originally for technological forecasting, involves collecting written assessments from participants, aggregating and anonymizing the responses, sharing the aggregated results with participants, and repeating the process until the group converges on a more complete picture of the risk landscape. Canadian organizations with geographically distributed operations or advisory boards find this technique especially useful. A construction company with projects in Calgary, Saskatoon, and Toronto cannot easily bring site supervisors together for a brainstorming session, but it can systematically collect their perspectives on project risks, equipment failures, subcontractor reliability, and regulatory compliance challenges through a structured Delphi process conducted over several weeks. The anonymity of the technique encourages participants to raise concerns they might hesitate to voice in front of colleagues or superiors, particularly concerns about management decisions, resource allocation, or organizational culture that contributes to risk.

Interviews with key personnel throughout the organization provide depth that group techniques cannot achieve. One-on-one conversations allow the interviewer to probe specific areas of expertise, follow unexpected threads, and create the psychological safety necessary for candid discussion of risks that individuals might find embarrassing or politically sensitive to raise in group settings. A financial services firm conducting risk identification should interview not only executives and risk managers but also front-line staff who interact with clients, technology personnel who understand system vulnerabilities, and administrative staff who observe patterns across the organization. Each perspective reveals risks invisible from other vantage points. The client-facing advisor may recognize that a particular product is being misunderstood by clients in ways that create liability exposure. The technology team may know that a critical system relies on infrastructure that has not been updated in years. The administrative coordinator may notice that certain compliance filings are consistently rushed because the process begins too late. None of these observations will emerge from an executive brainstorming session, yet each represents a genuine organizational risk.

Checklists and prompt lists serve as memory aids that ensure risk identification processes consider categories of risk that organizations commonly overlook. Industry associations, professional bodies, and risk management consultancies publish checklists tailored to specific sectors. A non-profit organization in the healthcare sector might consult checklists addressing volunteer management risks, donor privacy concerns, regulatory compliance with provincial health authorities, and the specific obligations that arise from accepting government funding. A resource extraction company would reference checklists covering environmental liability, workplace safety in remote locations, Indigenous consultation requirements, and the geopolitical risks affecting commodity prices and market access. The limitation of checklists lies in their generic nature. They prompt consideration of common risks within a category but cannot identify the specific manifestations of those risks within a particular organization, nor can they surface risks that are unique to that organization's circumstances. Checklists work best as complements to other techniques rather than as primary identification methods.

Process analysis and flowcharting techniques examine organizational activities systematically to identify points where risks may arise. By mapping the steps involved in key processes, organizations can identify dependencies, single points of failure, handoff errors, and compliance gaps that might otherwise escape notice. A professional services firm might flowchart its client engagement process from initial contact through project completion and invoicing, identifying at each step the risks of miscommunication, scope creep, missed deadlines, quality failures, and collection difficulties. This systematic approach reveals risks embedded in the process itself rather than in the people executing it. When a risk arises from process design, the response requires process improvement rather than simply better training or closer supervision. Organizations frequently misdiagnose process risks as personnel risks, leading to ineffective responses that leave the underlying vulnerability in place.

Scenario analysis and stress testing push organizations to consider how they would fare under conditions that differ significantly from normal operations. While these techniques are often associated with financial institutions subject to regulatory stress testing requirements, they offer value to organizations of any size and sector. The essential practice involves selecting plausible adverse scenarios and working through their implications for the organization systematically. A manufacturing company might consider scenarios involving the loss of its primary supplier, a significant increase in input costs, a quality failure affecting a major product line, or a prolonged economic downturn reducing customer demand. For each scenario, the analysis identifies the risks that would materialize and the organization's capacity to respond. Scenario analysis proves particularly valuable for surfacing strategic and external risks that operational focus tends to overlook. The daily concerns of running an organization draw attention inward, toward the risks embedded in current activities. Scenario analysis forces attention outward, toward changes in the competitive environment, regulatory landscape, or economic conditions that could fundamentally alter the organization's risk profile.

Consider the experience of a mid-sized environmental consulting firm based in Edmonton that had operated successfully for fifteen years before undertaking its first formal risk identification process. The firm employed approximately forty professionals and support staff, served clients primarily in the resource extraction and construction sectors, and had built its reputation on technical excellence and responsive service. The principals had managed the firm throughout its growth without a documented risk management framework, relying on their professional judgment and industry experience to navigate challenges as they arose. They believed they understood their risk landscape well. Their concerns focused on project delivery, staff retention in a competitive market, and the cyclical nature of their client industries.

The risk identification process, conducted with the assistance of an external facilitator over several weeks in the spring of 2025, employed multiple techniques including structured interviews with all professional staff and key support personnel, a Delphi process involving the principals and senior project managers, and process flowcharting for the firm's project delivery and quality assurance activities. The results surprised the principals in several ways. The interviews revealed that junior staff harbored significant concerns about the adequacy of supervision on certain project types, particularly those involving regulatory submissions where errors could have serious consequences for clients. Staff described situations where workload pressures led to reviews being compressed or skipped entirely, creating risks that clients remained unaware of. The Delphi process surfaced concerns about the firm's concentration of expertise in certain specialized areas, where the departure of one or two individuals could leave the firm unable to serve existing clients or compete for new work. The process flowcharting identified gaps in the firm's documentation practices that could complicate defense against professional liability claims and create difficulties in demonstrating regulatory compliance.

Perhaps most significantly, the process revealed a category of risk that the principals had not considered at all. Several staff members raised concerns about the firm's increasing dependence on a single client that had grown to represent nearly thirty percent of annual revenue. This client, a major resource extraction company, had experienced significant leadership changes and was rumored to be reconsidering its relationships with smaller consulting firms in favor of consolidating work with larger national firms. The principals, focused on maintaining and growing this profitable relationship, had not assessed the risk of its loss or developed contingency plans for replacing the revenue it represented. Further discussion revealed that the client's payment terms had extended significantly over the prior two years, creating a cash flow exposure that compounded the strategic risk of the relationship.

The implications of this experience extend beyond the specific risks identified. The Edmonton firm's principals were intelligent, experienced professionals who cared about their organization's success and their staff's wellbeing. Their failure to recognize significant risks before the formal identification process did not reflect negligence or inattention but rather the cognitive limitations that affect all human decision-making. They saw what their experience prepared them to see and missed what fell outside their habitual patterns of attention. The structured techniques of risk identification exist precisely to overcome these limitations, not because practitioners lack competence but because the limitations are universal features of human cognition that affect experts and novices alike.

The practical application of these insights begins with recognizing that risk identification is not a one-time event but an ongoing organizational practice. The risks that face an organization change as the organization changes, as its environment changes, and as new information becomes available. A risk identification process conducted once and then filed away will rapidly become obsolete. Effective organizations integrate risk identification into their regular operations through periodic formal reviews, typically annually or semi-annually, supplemented by triggered reviews whenever significant changes occur. A merger or acquisition, entry into a new market or service line, significant regulatory changes, or major changes in the competitive environment should all prompt fresh risk identification efforts.

Documentation of the risk identification process serves multiple purposes beyond simply recording the results. It creates an institutional memory that allows the organization to track how its risk landscape has evolved over time. It demonstrates due diligence in governance and management, which may prove valuable in regulatory inquiries, litigation, or insurance claims. It provides a foundation for the subsequent steps of risk analysis and evaluation, where the identified risks are assessed for their likelihood and potential impact. Without adequate documentation of how risks were identified and by whom, the credibility of the entire risk management process comes into question.

The questions that organizations should ask when designing or evaluating their risk identification processes include whether the techniques employed are appropriate to the organization's size and complexity, whether stakeholders with diverse perspectives are meaningfully involved, whether the process addresses all relevant categories of risk including strategic and external risks that operational focus may overlook, whether the process creates adequate psychological safety for participants to raise sensitive concerns, whether documentation practices support institutional learning and demonstrate due diligence, and whether the process is repeated or updated frequently enough to remain relevant as circumstances change.

Organizations often resist comprehensive risk identification because they fear what they might find. Identified risks create obligations to respond, and responses require resources and attention that may already feel stretched thin. This resistance reflects a fundamental misunderstanding of the purpose of risk management. The risks exist whether identified or not. Identification does not create the risk but rather creates the opportunity to manage it proactively rather than reactively, at a time and in a manner of the organization's choosing rather than in crisis mode after the risk has materialized into actual harm. The Edmonton consulting firm's concentrated client risk existed before the identification process revealed it. The process gave the principals the opportunity to diversify their client base and develop contingency plans before any adverse event occurred, rather than scrambling to respond after losing thirty percent of their revenue with no warning and no preparation.

The investment in systematic risk identification pays returns not only in avoided losses but in organizational confidence and decision-making quality. Leaders who understand their risk landscape make better strategic decisions because they incorporate risk considerations into their planning rather than treating risk as an afterthought or an unpleasant surprise. Organizations that have surfaced their risks can allocate resources more effectively, prioritizing controls and responses for the risks that matter most rather than spreading resources thinly across visible but less consequential concerns while leaving major risks unaddressed. The discipline of risk identification, practiced consistently and comprehensively, transforms risk management from a compliance burden into a source of competitive advantage.

Continue with University access

This lesson is part of a $79 course. Purchase the course or sign in with an active membership to keep reading.

See purchase options