FREE TOOL 05 / Assessment

Annual risk assessment

Scope your systems and information, assess practical risk scenarios and record treatment decisions with rationale. For RIA operations, compliance and technology teams.

Spreadsheet · Text · PDF · Editable copyRead the guide ↗
Inputs stay in this browser tab

No automatic saving. Download a copy or choose Save to free account to keep your work. Avoid client details, credentials and confidential evidence.

A CLEAR RECORD, FROM SCOPE TO NEXT STEPS

Annual risk assessment

Define your scope, work through focused questions and keep a decision record with evidence references and follow-up actions.

  1. Define the firm, period and information in scope.
  2. Record judgments with evidence and rationale.
  3. Export a complete draft and continue from your saved copy.

No account required. Download your work or explicitly save it to a free account. Use categories and fictional labels; avoid sensitive records.

Sources, assumptions & limits

Template 1.1.0 · Sources checked October 2, 2026. A planning aid, not legal advice, a system assessment or a compliance determination. User-recorded statuses are not independently verified.

NIST-30: SP 800-30 Rev. 1: Guide for Conducting Risk Assessments ↗ — Federal risk guidance adapted as a voluntary planning aid. An annual cadence is a user choice, not a universal Reg S-P requirement.

NIST-1300: Cybersecurity Framework 2.0: Small Business Quick-Start Guide ↗ — Voluntary guidance; no RIA-specific frequency or legal deadline is derived here.

Read our methodology