Learn It. Grow It. Own It.

Freshen Up, Risk Register

Aug 25, 2026

Your Risk Assessment Has an Expiration Date

That beautifully formatted risk assessment you completed six months ago? It may already belong in a museum.

There it sits.

Beautifully formatted. Color coded. Approved by management. Presented to the Audit Committee. Perhaps someone even added a very impressive heat map with various shades of red, yellow and green.

Everyone nodded.

Everyone agreed.

Everyone went home.

And then something terribly inconvenient happened.

The world kept moving.

A supplier failed. A new AI tool appeared in three departments without anyone quite remembering who approved it. A key employee resigned. A geopolitical event disrupted the supply chain. A project slipped two months. A new regulation appeared. A cyber vulnerability emerged.

Meanwhile, somewhere on SharePoint, your beautifully approved annual risk assessment remains frozen in time, blissfully unaware that Tuesday happened.

Welcome to modern risk management.

Risk Does Not Respect Your Calendar

For years, many organizations have operated on a comfortable rhythm:

  1. Identify risks.

  2. Assess likelihood and impact.

  3. Create the annual audit or risk plan.

  4. Get approval.

  5. Execute the plan.

  6. Repeat next year.

There is nothing inherently wrong with having an annual planning process. The problem comes when annual planning becomes annual thinking.

Risks do not wait politely for next year's planning meeting.

They emerge on Wednesday afternoon.

They arrive through a vendor.

They hide inside a project change.

They appear when someone connects a shiny new piece of technology to company data because it promised to save them three hours a week.

Sometimes they arrive wearing a suit and carrying a PowerPoint presentation.

That is why today's risk professional needs to think less like a photographer taking an annual snapshot and more like someone watching a live feed.

The question is no longer simply:

"What are our biggest risks?"

It is:

"What has changed since the last time we asked?"

And that is a very different question.

Meet the Risk Assessment Expiration Date

I am not suggesting that we stamp every risk assessment:

BEST BEFORE: 30 DAYS

Although I admit I rather like the idea.

Instead, organizations need to recognize that every risk assessment is based upon assumptions and conditions that existed at a particular moment.

When those conditions change, the assessment may need to change with them.

Suppose a critical project was assessed as relatively low risk because:

  • the project manager was highly experienced;

  • the contractor had performed well previously;

  • funding was secure;

  • the schedule contained reasonable contingency; and

  • the technology was proven.

Lovely.

Then the project manager resigns.

The contractor experiences financial problems.

Management removes three months from the schedule.

The project adopts new AI-enabled technology.

And material prices jump.

Is it still the same risk?

Of course not.

Yet organizations sometimes continue treating it as though nothing happened because the official risk assessment will not be refreshed until November.

November does not care that your project is currently on fire.

Stop Asking Only "What Is the Risk?"

Start asking three additional questions.

1. What changed?

This may be the most powerful risk question in the room.

Changes in people, systems, suppliers, regulations, technology, strategy, finances and external conditions can all alter the organization's exposure.

Change is often where risk enters the building.

2. What assumption is no longer true?

Every risk assessment contains assumptions, whether we document them or not.

"We have enough people."

"The vendor can deliver."

"The controls are operating."

"The data is reliable."

"The project will finish in June."

"The system is secure."

"The AI is only being used for low-risk tasks."

Those statements should make every auditor slightly twitchy.

Because the moment an important assumption stops being true, the risk calculation built upon it begins wobbling.

3. What would make us change the plan?

This is where dynamic risk assessment becomes useful rather than theoretical.

Organizations can establish triggers that cause someone to stop and reconsider the risk.

For example:

Project delay exceeds 10%.

Reassess.

Critical supplier receives a financial warning.

Reassess.

Turnover suddenly increases in a key function.

Reassess.

New AI technology gains access to confidential information.

Definitely reassess.

Fraud allegations emerge involving a major vendor.

Please do not wait until the annual planning meeting.

The goal isn't to reassess everything every day. Nobody has the time, resources or caffeine supply for that.

The goal is to identify signals that tell us something meaningful has changed.

The Audit Plan Shouldn't Be Carved in Stone

This thinking has enormous implications for internal audit.

An annual audit plan remains valuable. Organizations need structure, resources must be allocated and Audit Committees need visibility into what Internal Audit intends to cover.

But approval of the audit plan should not turn it into a sacred document.

Imagine discovering a significant emerging risk in September and hearing:

"Yes, that is concerning. We'll consider auditing it next year."

Really?

Internal Audit should be able to explain not only why something entered the audit plan, but also why priorities changed.

Perhaps an audit gets delayed.

Another gets accelerated.

A limited-scope review replaces a traditional audit.

Data analytics are used to monitor an emerging issue.

Or Internal Audit simply starts asking questions before deciding whether a full audit is necessary.

Flexibility is not evidence of poor planning.

Sometimes flexibility is evidence that someone is paying attention.

And This Isn't Just an Audit Problem

Project managers should be asking what changed.

Risk managers should be asking what changed.

Executives should be asking what changed.

Fraud professionals should be asking what changed.

Boards and Audit Committees should be asking what changed.

Because emerging risk frequently leaves breadcrumbs before it becomes a crisis.

A schedule begins slipping.

Employee turnover increases.

Invoices behave strangely.

A vendor stops providing requested documentation.

Management overrides become more frequent.

Customer complaints increase.

System exceptions spike.

None may be catastrophic individually.

Together?

They may be trying very hard to tell you something.

Risk Management Should Have a Pulse

Perhaps that is the easiest way to think about dynamic risk assessment.

Your organization already has a pulse.

Projects change.

People change.

Markets change.

Technology changes.

Threats change.

Opportunities change.

Your understanding of risk should change with them.

The objective isn't to create another enormous process, another committee or, heaven help us, another 47-column spreadsheet.

It is to build the habit of looking up from the plan occasionally and asking:

What is different today?

What are we seeing that we weren't seeing before?

Which assumptions are beginning to crack?

And does any of this change what we should be doing?

Because the greatest risk may not be the one sitting proudly at the top of your risk register.

It may be the one that wasn't there when you created it.

Learn. Question. Reassess. Grow.

At LG3, we believe professional growth isn't about memorizing yesterday's answers. It's about becoming better at asking tomorrow's questions.

Keep learning. Keep looking. Keep challenging assumptions.

Learn and Grow with LG3.

What has changed in your organization during the last six months that would cause you to assess risk differently today?

Stay connected with news and updates!

Join our mailing list to receive the latest news and updates from our team.
Don't worry, your information will not be shared.

We hate SPAM. We will never sell your information, for any reason.