Manage risks, risk statements, and risk frameworks
The risk library contains all risk frameworks and risk statements. Risk frameworks are used to group risk statements into manageable categories, while risk statements group the individual risks. The risk register is the central repository for all potential risks that could occur at any time, anywhere in the organization.
Assess risks and develop risk statements
Assessing risk means identifying and analyzing the threats and vulnerabilities that could adversely affect your organization’s business objectives. Risk is a function of the likelihood of a given threat exercising a particular potential vulnerability, and the resulting impact of that adverse event on the organization. By identifying your risks and the impact and likelihood of those risks occurring, your organization can prioritize control testing and remediation activities. It also helps you understand the true business impact when a control fails.
A good risk statement should answer:
- What could happen?
- How could it happen?
Why do we care?
Workflow of a risk using Advanced Risk
When you migrate to advanced risk assessment, you can view the various states of the risks take the necessary actions. This ability simplifies your view of the risk form.- Manage risks linked to the same risk statement
You can create and associate multiple risks to the same risk statement and entity combination. This association benefits the risk managers and the entity owners. - Risk hierarchy and scoring
Starting with New York, risk managers can create hierarchies that include different types of risk (operational risk, IT risk, or strategic risk). Once the underlying risks are assessed, the risk scores are automatically rolled up across the risk statement hierarchy, providing better tactical and strategic decision-making.
Parent Topic:Governance, Risk, and Compliance