Risk Assessment Guide

Risk Assessment Guide

Disclaimer: This guide provides a framework for analysis and is not legal advice. For specific ambiguities or high-stakes situations not covered here, consult qualified legal counsel. 

Risk is an inherent part of any business, from signing a contract with a new startup partner, making investment decisions, speaking publicly as an organization, or sharing information that might be considered confidential.

As information professionals, we use risk assessment every day: Imagine you’re a public library director coming in to work on a snowy day. Your maintenance personnel are already snowed in and won’t make it to clear the walkways. You take stock of the amount of snow, salt for de-icing, who can help, and whether you can ask them. Using that information, you decide to remain closed: the risk of injury to non-maintenance staff was too high to merit opening on time.

That’s risk assessment in action.

This guide is a practical, step by step set of steps you can take to evaluate your risk as you make decisions on behalf of your organization. In short, this guide will help you to know what to do when you don’t know what to do, particularly in contractual settings.

Situational Awareness is Key

Assessing risk means understanding your organization’s position relative to the risk. Consider:

Core reputational and political effects:

  • Mission Alignment: How will your decision affect members of your organization personally and publicly? What is your organization’s mission or purpose, and is it implicated in this decision?
  • Public Stance: If the organization’s purpose is implicated, does the organization want to make a political statement or take a public stance?

For example: if your library organization is offered funds from a person or group known to actively support legislative acts that would censor or cull your collections on the condition that the donor can “occasionally audit” materials, accepting funds is directly counter to the mission of the library. The risk is far too great even if that audit might never take place. This ticks both the “Mission Alignment” and “Public Stance” boxes, as accepting funds would be a public statement in itself.

Direct organizational effects:

  • Contractual terms: Would your organization be violating terms of a contract, and if so, does the organization care about losing that partnership, losing a core service, or paying for breach?
  • Financial resilience: Is your organization prepared to accept a financial consequence beyond paying a termination fee or fine? What about potential court costs?
  • Safety of staff and patrons: Does your organization have enough resources to protect individual staff and patrons from the effect of this decision? How are you supporting your community in the face of potential attacks?

The position of any third party or counterparty:

  • Litigation risk: Does the decision involve a third party that’s known to be litigious (prone to sue other companies) or has a “bully” reputation on social media?
  • Defense strategy: Is your organization prepared to address or ignore a social attack? To what degree? If you’re considering making negative statements about a third party, is your organization prepared to defend those statements?

Placing relative value on each answer will help you determine how to move forward. The Risk Exposure Scorecard below can be of use in that determination.


Risk Exposure Scorecard

Use this scorecard for any action you’re considering where you aren’t sure of the risk. This scorecard is meant to be copied and reused for each decision.

To use the scorecard, rate the Risk Factor in the first column based on how strongly you agree with its related Statement in the second column. Write your Score in the third column and add any Notes in the fourth column. Then Total your score in the last row.

Scoring Rubric:

1 – Strongly Disagree/non-issue

2 – Disagree or minor issue that can be managed

3 – Neutral, unsure or unpredictable

4 – Agree, likelihood that harm will result

5 – Strongly Agree, harm is certain and would be highly damaging

As you’re scoring, you may be tempted to enter a lot of “3” scores. That’s okay, but consider that if you’re consistently neutral on the risk around a particular decision it might be worth getting a second or third opinion from a trusted colleague who’s familiar with your organization’s mission and policies.

A score of “2” indicates that you see reasonable, practical steps that your organization can take to manage the risk, while a score of “4” means that while you might see possible steps you can take, those steps will be burdensome and you’ll need organizational signoff before acting.

 

Risk Factor Statement Score (1-5) Notes
Mission Alignment This action directly conflicts with our public mission or core values.
Operational Dependency Another party provides a service or level of support that we cannot easily replace if they terminate the relationship.
Third Party Reputation Another party has a known history of taking people to court or using “bully” tactics on social media.
Financial Exposure A legal battle or high fine could result from this action, and our organization may not be/is not prepared for either circumstance.
Defensibility Our organizational leadership or guidance does not give us a clear  professional, ethical, or legal reason to justify this action.
TOTAL SCORE

Interpreting the Score:

Warning: An individual score of 4 or 5 for any Risk Factor is a red flag. Share your results with and obtain informed consent from organizational leadership before proceeding.

If you don’t have any 4 or 5 scores, use the Total Score analysis below:

Total Score 5–10 (low risk): Your organization is likely protected by its policy or standard practices. The risk is low – but be sure to document your reasoning.

Total Score 11–14 (mitigation needed): Consider how to mitigate before proceeding: can you anonymize relevant data, delay timing, narrow the scope of who sees information, or pursue alternative actions like private discussions instead of public statements?

Total Score above 15 (high risk): As any score above 15 means you’ll have entered a 4 or 5 for at least one Risk Factor, review your results with organizational leadership and obtain consent before proceeding. Ask:

  • If you have one “4” in a sea of 1 or 2 scores, can you work to mitigate the “4”?
  • If you entered a “5” anywhere, how certain are you of the resulting harm?

Regardless of your organization’s decision, always document the review and decision-making process so that you can reference it later when necessary.

Some organizations might choose to proceed even knowing the risk is high out of principle or value alignment; others might choose to abstain even knowing the risk is low because they’re not able to bear even a slight financial burden. What’s most important is to make informed decisions about risk and provide reasoning behind your decisions.

As always, if you or your organization are stuck on a decision, consult qualified counsel.

License

Icon for the Creative Commons Attribution 4.0 International License

Understanding Confidentiality and Risk Assessment Copyright © 2026 by Library Futures is licensed under a Creative Commons Attribution 4.0 International License, except where otherwise noted.