MHA Consulting Blog | Roadmap to Resiliency

The Missing Piece: Why You Need a Risk Assessment for Operations

Written by Richard Long | Sep 8, 2026, 2:22:39 PM

Many organizations routinely conduct risk assessments related to safety, compliance, finance, insurance coverage, and facilities, but there’s one important area that often gets overlooked. By conducting a risk assessment focused on operations, business continuity offices have the opportunity to make a significant contribution to their organizations’ resilience.

Related: A Sample Threat and Risk Assessment: The Case of Acme Widget Corp.

The Missing Risk Assessment

Most organizations routinely conduct risk assessments of a handful of key areas. These commonly include strategic risks, safety, compliance, finance, physical security, facilities, reputation, insurance coverage, and technology, with the assessments typically being conducted by the relevant department or enterprise risk.

These assessments help organizations identify exposures, evaluate their potential consequences, and determine where controls or other measures may be needed to reduce risk.

But there is one important risk area that frequently goes unexamined: risks to the organization’s ability to carry out its day-to-day operations.

Organizations that don’t currently conduct operational risk assessments should consider expanding their risk management program to include a regular, ongoing review of the risks to their critical business activities.

Such assessments look specifically at the internal and external risks that have the potential to disrupt the organization’s ability to perform its key business functions.

Why Operational Risk Matters

The concept of a risk assessment for operations might be somewhat obscure. The logic behind them is anything but.

The organization’s success depends on its ability to carry out its critical business functions. When those functions are disrupted, the costs in terms of revenue, reputation, and compliance can be severe. For organizations in sensitive areas such as healthcare, the potential impact of operational outages can be greater still.

An operational risk assessment identifies the internal and external risks that have the power to derail the organization’s ability to carry out its core functions.

Where the BC Office Comes In

Such assessments differ from the more familiar types of risk assessments in being cross-functional. They also differ in terms of which department is responsible for carrying them out.

Responsibility for conducting operational risk assessments falls squarely on the shoulders of the business continuity office.

The BC office should be actively involved in identifying operational risks, evaluating their potential consequences, and working with the appropriate departments to determine how those risks should be addressed.

What the Assessment Should Examine

The list of things that can bring an organization’s operations to a standstill is probably endless. However, these risks can usefully be divided into a handful of leading categories.

BC practitioners conducting operational risk assessments should look in particular at risks in the following five areas.

Technology

Look for resilience gaps and single points of failure that could cause applications or services to become unavailable. Consider single internet service providers, point-to-point connections, cellular connections used for external or remote management access, and critical SaaS or managed services whose resilience capabilities may not be fully understood.

People

Identify functions where knowledge or responsibility is concentrated in one person or a small number of people. Consider what would happen if several people were suddenly unavailable. Do backup personnel have the system access they need? Are procedures documented? Are specialized roles covered? The same questions should be asked about contractors and managed-service providers, particularly when a small firm or long-term contractor holds significant institutional knowledge.

Vendors and Supply Chain

Identify single-source vendors and suppliers that would be difficult to replace. Consider not only whether a vendor has a continuity plan, but whether it could actually provide the goods or services the organization needs during an emergency. Supply-chain risks can also extend beyond the immediate vendor. Transportation routes, ports, bridges, highways, and other infrastructure can affect a vendor's ability to deliver what the organization needs.

Facilities

Examine the organization's locations and the critical equipment they contain. Are there non-redundant pieces of equipment whose failure could stop an operation? If employees normally work remotely, do they have an appropriate alternate location if their homes or normal workspaces become unavailable?

Processes

Look closely at the processes that keep the business running. Be skeptical of vague workarounds such as “we will manually track transactions.” Is there actually a documented procedure? Do employees know how to perform it? Are the necessary forms, equipment, supplies, and systems available? Also look for processes that depend heavily on a single employee, vendor, or technology platform.

By focusing on these five areas, BC practitioners can develop a good picture of the operational risks that could have a meaningful impact on the organization’s ability to carry out its core functions.

Turn the Assessment Into Action

At this point, congratulations are in order. You’ve successfully conducted an assessment of the main risks that threaten your organization’s ability to carry out its critical operations.

But your work is far from done.

We often say that a Business Impact Analysis is just information. It doesn’t actually benefit you unless and until you use it as the basis to take action.

The same is true of the operational risk assessment.

With the BIA, the appropriate action is to take steps to protect those processes, systems, and applications identified as being the most critically time-sensitive.

With the operational risk assessment, the correct action is to evaluate the risks you’ve identified and mitigate the most significant.

The risks you’ve identified should be evaluated in terms of their likelihood and potential impact. Next, the organization should prioritize them and determine what mitigation measures make sense for each. Risks that are both highly likely to occur and potentially highly impactful should be tackled first, with the others following in order of significance.

For people-related risks, the answer might be cross-training or better documentation of procedures. Vendor risks might be addressed through alternate suppliers or increased inventory of critical supplies. Technology risks might call for redundancy, additional connectivity, or a more robust workaround. Facility-related risks might require an alternate location or redundant equipment.

Not every risk needs to be eliminated. Some may be sufficiently unlikely or have sufficiently limited consequences that the organization can reasonably accept them. However, each choice about how to address a risk should be conscious and informed. There’s no place in modern risk mitigation for simply letting things slide.

Finally, risk assessment and mitigation should never be thought of as a one-and-done activity. The environment and organization are both in flux. The assessment should be revisited periodically so that new vulnerabilities can be identified and previously identified risks can be reassessed.

For the BC office, this is where risk assessment becomes more than an exercise in documentation. It becomes a practical way to identify weaknesses in the organization's ability to operate and then do something about them.

Finding the Missing Piece

Organizations conduct risk assessments covering a wide range of areas, but the risks that could disrupt their day-to-day operations can easily go overlooked. An operational risk assessment fills that gap by examining the people, technology, facilities, vendors, and processes that critical business functions depend on.

For BC practitioners, conducting an operational risk assessment is an opportunity to identify vulnerabilities before they become disruptions. Just as important, the assessment provides the information needed to prioritize those risks and determine what should be done to mitigate them.

If your organization has not conducted an operational risk assessment, MHA Consulting can help. Our business continuity professionals can help you identify the risks that could disrupt your critical operations and develop practical strategies for addressing them. Contact MHA.

Further Reading

Frequently Asked Questions

What is an operational risk assessment?

An operational risk assessment identifies internal and external risks that could disrupt an organization’s ability to carry out its critical business functions.

Why is an operational risk assessment important?

It helps organizations identify vulnerabilities that could bring critical operations to a standstill and determine where action may be needed to reduce the risk.

Who should conduct an operational risk assessment?

The business continuity office should take responsibility for conducting the assessment, working across departments to identify operational risks, evaluate their consequences, and determine how they should be addressed.

What should an operational risk assessment examine?

The assessment should examine risks related to five key areas: technology, people, vendors and supply chain, facilities, and processes.

What should an organization do after identifying its operational risks?

It should evaluate and prioritize the risks based on likelihood and potential impact, then determine appropriate mitigation measures. Identifying a risk is useful, but taking action to address significant risks is what actually strengthens resilience.