The steps
- Brainstorm risks across financial, operational, clinical, WHS, reputational categories
- Score each risk on likelihood (1-5) and impact (1-5)
- Identify treatments — eliminate, mitigate, transfer (insure), accept
- Assign each risk an owner and review date
- Review quarterly in a leadership meeting
- Update after every incident, complaint and audit observation
- Report top risks to your board (if applicable)
Common mistakes to avoid
- Empty risk register at audit
- Risks logged but never reviewed
- Treatment plans missing for high-priority risks