Back to Blog
Risk Assessment 12 August 2026 · 5 min read

The Most Common Mistake We See in SME Risk Assessments

Most risk assessments we are asked to review were done once, filed away, and never looked at again. That single habit causes more real exposure than almost any technical gap we find.

When we start working with a new client, one of the first things we ask for is their most recent risk assessment. Very often one exists. It is usually well written, occasionally produced by a consultant, and almost always at least a year old. Nobody has actively decided to ignore it. It simply got finished, filed, and quietly stopped being anyone's job to revisit.

That gap between when it was written and where the business actually is today is the single biggest source of real exposure we find, more consistently than any missing technical control. A risk assessment is a snapshot of a business at one moment, its people, its suppliers, its systems, and what would hurt it if something went wrong. Every business changes faster than that snapshot suggests.

What actually goes stale

A handful of things move constantly in almost every SME we assess. Staff join and leave, and access to systems does not always get cleaned up in step with departures. New suppliers get onboarded for a specific project and quietly become permanent, without ever going through the same scrutiny as the ones already on the books. New software gets adopted, an AI assistant, a new finance platform, a new CRM, often by a single team without anyone stepping back to ask what data it now touches. None of this shows up in a document that was finalised before any of it happened.

The deeper problem, treating it as a document rather than a decision tool

The mistake is not really about timing. It is about what the risk assessment was built to do in the first place. Too often it exists to satisfy a customer questionnaire, an insurance renewal, or a funding application, a box that needs a tick next to it. Built that way, it naturally stops the moment the box is ticked. A risk assessment built to actually guide decisions looks different. It ranks risks by what they would cost the business if they happened, not by how alarming they sound. It gets revisited when something changes, a new hire with access to finances, a new supplier handling customer data, a new tool touching sensitive information, rather than on a fixed annual date that has nothing to do with the business's actual rhythm.

The step most businesses skip entirely

Even a current, well prioritised risk assessment only tells you what could go wrong. It does not tell you whether your team would actually respond well if it did. That is the difference between a document and a tested plan. Running a short tabletop exercise, walking a real scenario through with the people who would have to handle it, routinely surfaces gaps that no amount of paperwork review would catch, a decision nobody was clearly authorised to make, a contact list that is out of date, a step everyone assumed someone else owned.

Three practical starting points

You do not need to overhaul everything at once. Start by asking when your risk assessment was last genuinely revisited, not reprinted, and treat anything over a year old as due for review. Next, list the changes since then that nobody has checked against it, new hires with sensitive access, new suppliers, new software. Finally, pick one realistic scenario relevant to your business and talk it through with the people who would actually be involved, even informally, before assuming your plan would hold up.

Not sure how current your own risk assessment really is

We run practical, right sized risk assessments and tabletop exercises for SMEs, no jargon, no bloated reports nobody reads.