Step 5: Monitor and review your risks
Monitor your actions
Regular monitoring will make sure your actions are effectively managing your risks, and help to integrate risk management into day-to-day operations.
Regularly monitor your Risk Action Plan
- Monitor your Risk Action Plan to make sure you are making progress.
- Include actions in your Risk Action Plan for treating risks in work programmes and project plans.
- Report progress against your Risk Action Plan as part of management and board reporting
- Review your risk profile if your business changes significantly.
Make risk management ‘business as usual’
- Include environmental scanning and risk identification in strategic plans and annual business plans.
- Monitor and report key milestones in work programmes and project plans every month.
- Include key milestones in staff performance agreements, where appropriate.
- Include a printout from the Risk Calculator in which risks, likelihood, consequence, and treating are part of the monthly reports from management to the chief executive. The graph showing your organisation’s profile for high and medium risks (see example below) can also be used in monthly reports.
Risk Calculator
How to use the Risk Calculator (PDF, 550 Kb)

Review your progress
Consistently reviewing your process and outputs will make sure your risk management continually improves to best meet your specific needs.
Annually review your high and medium risks
- Consider if your actions for each risk were effective. Focus mainly on high and medium risks.
The consequence of the risk might not have changed, but your control effectiveness and your likelihood should have improved from your risk treatment.
- Reassess only those risks where there was an event during the year that could change their status.
- Use the Risk Calculator to recalculate the results.
- Generate a new risk profile.
Every four years – re-evaluate all your risks
Use the Risk Management Toolkit to update your risk management plan by repeating Steps 3, 4 and 5. Reassess all the risks – you might need to add, remove or update your risk templates.
- Use the Risk Calculator to recalculate the results.
- Generate a new Risk Profile.
If your organisation has changed substantially in 4 years, you may need to reassess your policy and your operating environment.
Back to top