# Risk assessment form with weighted scoring and PDF reports

Canonical: https://useformwork.com/use-cases/risk-assessments

Updated: 2026-10-09

Build a scored risk assessment form that weights each answer, shows the project lead their risk level, routes high scores to review and emails a PDF.

A risk assessment form is easy to send out and hard to act on. Scores get added up by hand, high-risk projects wait in someone's inbox, and the project lead never hears back. This walkthrough builds a scored project risk assessment for Merrow Housing Trust, a fictional housing association: it weights each answer, shows the lead their result, sends high scores to review and emails a PDF report.

It is a configuration pattern, not a case study or a risk methodology. Set your own weights and thresholds with whoever owns risk.

## Build the risk assessment form

The form, **Project risk assessment**, has four pages:

1. **Project**: project name, the lead's name and **Email**, directorate (**Dropdown**), budget (**Number** with a £ prefix and a minimum of 0) and go-live date (**Date**).
2. **Risk**: four **Single choice** questions, about personal data, the effect on tenants' services if the project fails, who delivers it and how fixed the deadline is.
3. **Readiness**: **Yes or no** questions for a named sponsor, a rollback plan and, only when the project handles personal data, a data protection impact assessment. Then a repeating group, **Key risks**, with each risk, its likelihood and impact (**Rating**, 1 to 5) and a mitigation.
4. **Your result**: the score and what happens next.

Make every scored question **Required**. See [pages and repeaters](/docs/forms/form-structure) and [conditional logic](/docs/logic/conditional-logic).

## Weighted scoring with calculated values

FormWork has no separate scoring setting. Choice options carry the points, and a calculated field adds them up on the [server](/product/server-side-logic).

On each **Single choice** question, open the **Options** tab and type a number as each option's value: "No personal data" 0, "Staff data" 2, "Tenants' data" 3, "Health data" 4. The entry stores the value, and formulas treat it as a number.

Add a read-only **Number** field, **Risk score**. Under **Default value**, choose **Calculation** and apply the weights in the formula: personal data and service impact count three times, delivery twice, the deadline once, and `IF` adds points for a large budget and missing readiness items. Part of it, as text:

```text
={{entry:current.answers.personal_data}}*3 + {{entry:current.answers.service_impact}}*3 + {{entry:current.answers.delivery}}*2 + IF({{entry:current.answers.sponsor}}, 0, 3)
```

Keep it on one line, and insert answers with **+ Reference**. Here the score runs from 0 to 46: under 10 is low, 10 to 17 medium, 18 or more high. A second read-only **Text** field, **Risk level**, calculates `=IF(score >= 18, "High", IF(score >= 10, "Medium", "Low"))`, where `score` stands for the inserted **Risk score**. See [calculated values and defaults](/docs/logic/calculations).

Two details matter for scoring:

- A calculation stays empty until every answer it uses has a value. The impact assessment question is hidden for projects without personal data, so give it a fallback, `|default:1`.
- Hiding a question doesn't delete its answer, so a "No" given before personal data changed to none still counts. Check personal data in the formula too, in outline `IF(personal_data = 0, 0, IF(dpia_done, 0, 4))`.

Inside **Key risks**, a calculated field can multiply each risk's likelihood by its impact, using **Current instance** in the picker. Those ratings go in the report, not the score.

## Show the result to the respondent

Values are worked out each time an answer is saved, so the result is ready on the last page. You can show it in three places:

- **The calculated fields** on the result page, read only so people can't type over them.
- **A paragraph in Template mode** that explains it, such as "A risk reviewer will look at this first" for High. See [template syntax](/docs/templates/syntax).
- **The success message**, with **Format** set to **HTML template**, repeating the risk level and inserting **Status link for respondents**. See [form settings](/docs/forms/form-settings).

Showing the score before submission lets people see which answers lower it. If that matters, show the level only after submission. **Read only** stops people changing the score in the form, but it is still an answer, not a locked value. If a wrong score would cause harm, repeat the formula in a **Calculate** step in the automation and route on that result.

## Route high scores to a risk review

On the form's **Process** page, set up the [stages](/product/process). Entries start in Submitted when they are submitted.

| Stage | Kind | Owner and due time | Moves on with |
| --- | --- | --- | --- |
| Submitted | Open | The Project office group, due in 3 days | **Accept**, or **Send to risk review** |
| Risk review | Open | The Risk and assurance group, due in 5 days | **Send for approval**, **Accept with conditions** or **Not approved**, each with a required comment except the first |
| Waiting for approval | Waiting, needs approval | No owner. The Directors group, **At least** 2, links expire after 7 days | Approved to Accepted, rejected to Not approved |
| Accepted, Not approved | Closed | None | |

Then add an [automation](/product/automations), **Score and route assessments**, that runs **When** the **Form is submitted**:

1. **Update entry or row** on **This entry** copies **Risk score** into a **Score at submission** team field, kept if answers are corrected later.
2. **If**, with a branch labelled "High risk": **Risk score** **Is at least** 18. Inside it, **Move to stage** Risk review, with the comment "Scored 18 or more". **Otherwise** stays empty, so low and medium scores wait in Submitted for the project office.
3. **Generate PDF**, described below.
4. **Send email** to the lead's **Email** answer, with the PDF attached and the status link in the message.

Reviewers record their judgement in team fields, **Agreed risk level** and **Review notes**, and find their work in [My work](/docs/process/my-work). See [stages](/docs/process/stages), [owners and due dates](/docs/process/owners-due-dates) and [approvals](/docs/process/approvals).

## Generate a PDF risk report

On the project's **Templates** page, create a **PDF document** template, "Project risk report", and a **Layout** with your letterhead around `{{ content }}`. The report uses template values such as `template.project`, `template.score` and `template.level`, and a loop over `template.risks` for the key risks table. See [templates](/docs/templates/overview).

In the **Generate PDF** step:

- **File name**: `Risk assessment - ` followed by the project name, ending `.pdf`.
- **Content**: **Template**, "Project risk report". Under **Template data**, map each value to an answer, and `template.risks` to the **Key risks** group.
- **Layout**: **Template layout** with the letterhead.
- **Generated file access**: **Admin only**, since the lead gets it by email.

In **Send email**, select **Add attachment reference** and choose the PDF. From this step the run carries on in the background, so a failure doesn't undo the submission; turn on **Email admins when an automation run fails** and check [runs](/docs/automations/runs).

## Keep people informed

- **Tell the project lead the outcome**: **Stage changes**, **To** Accepted or Not approved, then **Send email** with the comment from the move.
- The **Remind the owner when a stage is overdue** template, for Submitted and Risk review. FormWork doesn't email owners about new or overdue work otherwise.
- **In a stage too long** on Waiting for approval for 3 days, then **Remind approvers**.
- [Respondent status](/docs/process/respondent-status), with neutral labels: "Received" for Submitted, "Being reviewed" for Risk review and Waiting for approval, "Accepted" and "Decision made".

Leave the **Email the person who filled it in** notification off; the automation's email already carries the report and status link.

## Limits to plan around

- Everyone in the account can open every assessment, including review notes. Groups decide who owns work, not who can see it. See [team members and roles](/docs/platform/users-permissions).
- An entry is in one stage at a time, so parallel checks, such as data protection and finance, belong in team fields or in stages one after the other.
- Due times count calendar time, not working days.

## Test these cases before you publish

- The lowest and highest possible answers, and a score of exactly 10 and exactly 18.
- A project with no personal data, and one where the lead answers the impact assessment question, then changes personal data to none.
- Two directors approving, one rejecting, and links expiring.
- The PDF with one key risk and with ten, and a long project name.

## Change the scoring safely

Publish new weights as a [new form version](/product/versioned-forms). Entries keep the questions they were answered with, while stages and automations follow the latest published version. Change weights in the formula, not option values: the entry stores the value, so changing it muddles older answers. Give each option in a question its own value, or the entry can't tell them apart. Saving a report template with **Save for immediate effect** changes the next PDF without publishing; use **Save as copy** to try changes first.

## What success looks like

Every assessment has a score you can trace to its answers, an owner and a stage. High scores reach a reviewer without anyone reading every form, and the project lead has a report and a decision. Measure turnaround yourself; this walkthrough doesn't claim one.

For a review process without scoring, see [application review](/use-cases/application-review). Compare [plans](/pricing) or [talk through your assessment](/#contact).