Your risk assessment has several key sections: business activities that bring risk, what type of risk (gifts, due diligence, etc), current mitigating controls, planned mitigating controls, and target dates.
FORBES: Risk Assessments: The Most Important Effort You're Doing All Wrong