> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.middesk.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.middesk.com/_mcp/server.

# Get a risk assessment

> Retrieve and interpret the immutable, point-in-time risk assessments Middesk produces for a business

A risk assessment is the immutable, point-in-time record of one Risk analysis. Each completed [Risk order](/business-risk) produces an assessment, and the business's `risk.latest_assessment_id` always points at the newest one.

## Retrieving assessments

Three endpoints return risk assessments:

| Endpoint                                                   | Returns                                         |
| ---------------------------------------------------------- | ----------------------------------------------- |
| `GET /v1/businesses/{business_id}/risk_assessments`        | Every assessment for the business, newest first |
| `GET /v1/businesses/{business_id}/risk_assessments/latest` | The latest scored assessment                    |
| `GET /v1/businesses/{business_id}/risk_assessments/{id}`   | A single assessment by ID                       |

The endpoints return `403` when your account is not enabled for risk, and `404` when the business has no risk assessment.

**`Get the latest risk assessment`**

```bash title="Get the latest risk assessment"
curl https://api.middesk.com/v1/businesses/{business_id}/risk_assessments/latest \
  -H "Authorization: Bearer YOUR_API_KEY"
```

## Anatomy of a risk assessment

**`Example risk assessment`**

```json title="Example risk assessment"
{
  "object": "risk_assessment",
  "id": "5f8c9d0e-1a2b-4c3d-8e9f-6a7b8c9d0e1f",
  "created_at": "2026-07-21T18:03:11.402Z",
  "order_id": "a58a4f4e-7f3b-4c8e-9d2a-1b0c9d8e7f6a",
  "business_snapshot_url": "https://api.middesk.com/v1/businesses/0793f2a2-e315-4b6a-9f0c-2d1e3c4b5a69?order_id=a58a4f4e-7f3b-4c8e-9d2a-1b0c9d8e7f6a",
  "title": "Likely transaction laundering: the storefront cannot support its stated sales volume.",
  "description_markdown": "Acme Home Goods presents as a small home furnishings retailer, but its storefront shows several traits common to laundering fronts.\n\n- The checkout flow displays no-refund language ([acmehomegoods.com/checkout](https://acmehomegoods.com/checkout))\n- The product catalog reuses stock imagery found on unrelated storefronts ([acmehomegoods.com/shop](https://acmehomegoods.com/shop))",
  "level": "high",
  "score": 68,
  "dimensions": [
    {
      "object": "risk_dimension",
      "type": "transaction_laundering",
      "score": 0.72,
      "level": "high",
      "top_factors": [
        {
          "name": "website_has_no_refund_language",
          "type": "boolean",
          "value": true,
          "contribution": 0.28
        },
        {
          "name": "url_risk_score",
          "type": "double",
          "value": 0.0,
          "contribution": -0.17
        }
      ]
    }
  ],
  "identifier_assessments": [
    {
      "object": "email_risk",
      "id": "idr_9f3c2a71e4b8d605",
      "resource": {
        "type": "email_address",
        "id": "e7a8b9c0-d1e2-4f3a-8b4c-5d6e7f8a9b0c",
        "value": "owner@acmehomegoods.com"
      },
      "score": 0.81,
      "attributes": [
        { "name": "email_is_valid", "type": "boolean", "value": true },
        { "name": "email_deliverability_low", "type": "boolean", "value": true }
      ]
    }
  ]
}
```

| Field                    | Type             | Description                                                                                                                                                      |
| ------------------------ | ---------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `object`                 | string           | Always `risk_assessment`                                                                                                                                         |
| `id`                     | string           | Unique identifier for the assessment                                                                                                                             |
| `created_at`             | timestamp        | When Middesk produced the assessment                                                                                                                             |
| `order_id`               | string, nullable | The order the assessment was produced against                                                                                                                    |
| `business_snapshot_url`  | string, nullable | Resolves to `GET /businesses/{id}?order_id={order_id}`, the business as of that order                                                                            |
| `title`                  | string, nullable | One-sentence analyst headline summarizing the verdict                                                                                                            |
| `description_markdown`   | string, nullable | CommonMark summary: a lead sentence plus short bullets, with links only to evidence URLs. Render it with a Markdown renderer that does not execute embedded HTML |
| `level`                  | string           | One of `low`, `moderate`, `high`, or `not_available`                                                                                                             |
| `score`                  | integer          | 0 to 100, the model's 0 to 1 score rounded. `level` is banded from `score`, so the two always agree                                                              |
| `dimensions`             | array            | Business-level scored [risk dimensions](/business-risk/dimensions)                                                                                               |
| `identifier_assessments` | array            | Per-resource assessments for email addresses, phone numbers, and the website URL. See [identifier risk](/business-risk/identifier-risk)                          |

## Investigating an assessment

Assessments are immutable and tied to the order that produced them. The live business record is not: later orders can refresh names, contacts, and other sub-resources, so the business you fetch today may differ from the business the assessment scored.

To see exactly the data the assessment was scored against, fetch the business as of that order. Follow `business_snapshot_url`, or request `GET /businesses/{id}?order_id={order_id}` with the assessment's `order_id`.

## Next steps

#### [Assess identifier risk](/business-risk/identifier-risk)

Map each identifier assessment back to the resource it scored.

#### [Understand risk dimensions](/business-risk/dimensions)

Interpret dimension scores, levels, and top factors.

> **Get a demo**
>
> Contact your account manager or [contact sales](https://www.middesk.com/contact-sales) to inquire about access.