The risk assessment process consists of: (a) risk identification, (b) risk measurement, and (c) risk prioritization.
Risk identification would be an integral part of the Enterprise Risk Management framework once implemented.