Most businesses can name their real risks in a ten minute conversation. What they have never done is write them down in a form that survives being read back to them. That is what arrives when this one is finished.
Further guidance on organisational risk:
Business Risk Assessment Preparation
There are two kinds of risk assessment and organisations routinely only do one. Task and site assessments cover what can hurt the person doing the work. Business risk assessments cover what can hurt the business - losing a key supplier, losing a key person, a cyber incident, a client who is half your turnover, a rule change that closes a market. Standards ask for both, and it is usually the second that is missing.
This service writes those assessments around your business. Not a generic risk list, but the things that would genuinely cause you a problem, with what you already do about them written down.
What You Get
For the day:
- Assessments in the F-Q36 organisational risk assessment format, branded to your company
- Risks written to your business - drawn from what you tell us about your operation, your market and your dependencies, rather than lifted from a generic list
- Inherent and residual ratings - applied consistently, with the residual reflecting the controls you actually have rather than the ones you intend to get
- Controls tied to your own documents - each control referenced to the policy or procedure that carries it, so the assessment is evidence rather than assertion
- Opportunities as well as risks - the standards ask for both and the format carries both
- Feeding your risks and opportunities register - so the assessments and the register agree with each other
- Gaps flagged - where a risk has no control behind it, you get told plainly, because that is the entry worth having
How Much One Day Covers
Your set. We do not cap it at a number of assessments, because the number is not what decides the time - the conversation is. Working out what genuinely threatens your business is the part worth paying for, and it is where the time goes. The more context and information you give us, the better what we prepare will be. We work through as much as the time allows, in the order that matters most to you.
How the Work Gets Done
We use our own AI tooling to do the mechanical part of document preparation, and a consultant checks the output before it reaches you. Here it does the building - laying out each assessment, applying the icon set, cross-referencing every control to the policy that carries it, and keeping the ratings consistent across a set that would otherwise drift.
What the risks actually are comes from you and from a consultant who has sat in a lot of management reviews. That conversation is the product. The tooling just means the writing up no longer eats the day.
The templates are ours, developed over 25 years of real audits, and they are not AI generated. We do not invent risks to fill a page, and we do not record a control you do not have. An organisational risk assessment claiming controls that are not in place is a document that will be read back to you at exactly the wrong moment.
Why a Day Goes This Far
Anyone can rent the same AI we use. What they cannot rent is what we point it at.
Behind this service is a document library built over 25 years - manuals, procedures, policies, registers, risk assessments, COSHH assessments, audit checklists and forms, covering every standard we work to and most situations a management system runs into. Each one has been through real audits, and corrected where an assessor pushed back. That is the part that took 25 years, and it is the part that cannot be generated.
Our tooling applies that library to your business. A general purpose AI, pointed at the same job, has nothing to apply, so it writes something that reads well and describes a company that does not exist.
What We Need From You
- What the business does, its markets and roughly its size
- Your main dependencies - key customers, key suppliers, key people, key systems
- Your existing policies and procedures, so controls can be referenced to them
- Anything that has already gone wrong or nearly gone wrong, which is usually the most useful input of the lot
- Any existing business risk assessments or risk register
Other Things Remote Support Covers
A support day does not have to be spent on business risk. The same day can be pointed at any one of these instead, and it is the same purchase either way:
- Enhanced IMS Setup - the whole file set branded and set up
- IMS Manual and Registers Preparation - the manual written and the registers completed
- Risk Assessment Reformatting and Hazard Register - your existing assessments in one format and indexed
- COSHH Assessment Preparation - existing COSHH reworked, or built from your safety data sheets
- Legal Register Preparation - your legal register and its written summary
- Environmental Registers and Aspects Assessment - aspects and impacts, life cycle review and a carbon management plan
- Information Security Risk and Treatment Plan - assets, risks, treatment and the Statement of Applicability
- Personal Data Register and Privacy Notice Preparation - your record of processing with AI written in, and privacy notices to match
- AI Policy and Risk Register - your AI tools, the risks and controls against each, and what AI may not do
- Company Forms, Policies and HR Reset - your policy set, staff handbook and HR forms as one branded set
- Full Clause Conversion Service - an existing ISO clause-based system reviewed and rebuilt around your business processes
- Constructionline, SSIP and CAS Application Support - your pre-qualification questionnaire completed and the evidence behind it prepared
A day can also go on things that are not document preparation at all - training, internal audits, a gap analysis, or simply working through a problem on a call. Remote Support - Project is the same day bought without a job attached to it.
Every one of these services is listed on the ISO consultancy support page, along with how a support day works and what is covered by a subscription.