Annual risk assessment
Scope your systems and information, assess practical risk scenarios and record treatment decisions with rationale. For RIA operations, compliance and technology teams.
No automatic saving. Download a copy or choose Save to free account to keep your work. Avoid client details, credentials and confidential evidence.
Annual risk assessment
Define your scope, work through focused questions and keep a decision record with evidence references and follow-up actions.
- Define the firm, period and information in scope.
- Record judgments with evidence and rationale.
- Export a complete draft and continue from your saved copy.
No account required. Download your work or explicitly save it to a free account. Use categories and fictional labels; avoid sensitive records.
Sources, assumptions & limits
Template 1.1.0 · Sources checked October 2, 2026. A planning aid, not legal advice, a system assessment or a compliance determination. User-recorded statuses are not independently verified.
NIST-30: SP 800-30 Rev. 1: Guide for Conducting Risk Assessments ↗ — Federal risk guidance adapted as a voluntary planning aid. An annual cadence is a user choice, not a universal Reg S-P requirement.
NIST-1300: Cybersecurity Framework 2.0: Small Business Quick-Start Guide ↗ — Voluntary guidance; no RIA-specific frequency or legal deadline is derived here.
Read our methodology