alphaZ documents
F-Q2A Audit Checklist

Update Details: F-Q36 General Risk Assessment has been updated and is now supplied in three variants of the same form, covering business risks beyond health and safety with an inherent and residual rating approach and copy-in visual risk symbols. 

F-Q36 covers business risks that sit outside the usual health and safety assessment - operational, financial, compliance, information security, people, and strategic risk. It uses an inherent-risk and residual-risk approach: you record the risk before controls, the controls applied, and the risk that remains. A built-in rating matrix and colour-coded header styles run throughout, and a confirmation section lets you record that residual risk has been brought to an acceptable level.

The form is now provided in three variants. F-Q36A General Risk Assessment is the standard form, with the rating matrix, assessment table, and confirmation section. F-Q36B General Risk Assessment is the same form with an added Persons Consulted field and all the visual symbols built in. F-Q36A Appendix i is the standalone symbols reference sheet.

Built-in Risk Symbols

The visual symbols are copied straight into the assessment so a completed assessment reads at a glance: orange hexagons for risks, green circles for controls, and red rings for prohibited actions. They cover a broad range of business-risk topics - data loss, cyber, fraud, supply chain, people and conduct, AI tool use, and others - each with matching controls and prohibitions.

Aligned with ISO 9001 and ISO 27001

The form backs the 'actions to address risks and opportunities' thinking common to ISO standards such as ISO 9001 and ISO 27001, where clause 6.1 asks you to determine risks and plan actions to address them. It works standalone for a single risk review, or as part of a wider integrated management system alongside your existing registers and procedures.

File updated on the following page;

F-Q36 General Risk Assessment

payment logos