1. Creating & Protecting Value
Does the organization’s risk management framework and approach create and protect value by contributing to the achievement of its objectives and improvement of performance?
2. Integrated into All Activities
Is risk management integrated into all organizational activities, processes, and decision-making structures rather than operating as a standalone function?
3. Structured & Comprehensive Approach
Is risk management structured, comprehensive, and applied consistently across the organization to produce comparable and reliable results?
4. Adapted & Proportionate Context
Is the risk management approach adapted and proportionate to the organization’s external and internal context, as well as its risk profile and objectives?
5. Based on Best Available Information
Does the organization ensure that the best available information – including historical data, expert judgment, stakeholder feedback, and observations – is used as an input to risk management?
6. Human and Cultural Factors
Does the risk management approach account for human and cultural factors, including the behaviors, perceptions, and intentions of internal and external stakeholders, which can facilitate or hinder achievement of objectives?
7. Transparent & Inclusive Stakeholders
Is risk management transparent and inclusive, with relevant stakeholders appropriately involved in defining the framework, identifying risks, and evaluating risk treatment options?
8. Continual Framework Improvement
Is the risk management framework and process continually monitored, evaluated, and improved to reflect changing internal and external conditions and lessons learned?
The framework provides the foundations and organizational arrangements for designing, implementing, monitoring, reviewing, and continually improving risk management processes throughout the organization.
9. Leadership Commitment & Policies (5.2)
Has leadership and top management demonstrated commitment to integrating risk management into all organizational activities, including setting the risk management policy and objectives?
10. Authority, Resources & Designating Owner (5.2)
Has the organization ensured that appropriate authority, resources, and accountability are assigned for managing risk, including designating a risk owner at relevant levels?
11. Integration into Governance & Operations (5.3)
Is risk management integrated into the organization’s governance structure, strategic planning, operational processes, and project management activities?
12. Understanding Internal & External Context (5.4)
Has the organization understood and documented its internal and external context, including its legal, regulatory, financial, operational, and strategic environment?
13. Articulated Risk Management Policy (5.4)
Has the organization articulated a documented risk management policy that states its objectives, commitment, and approach to managing risk?
14. Defined Roles & Reporting Structures (5.4)
Has the organization defined roles, responsibilities, accountabilities, and reporting structures for risk management across all functions and levels?
15. Resource Identification & Provisioning (5.4)
Have the resources – including people, systems, processes, and technology – necessary to support effective risk management been identified and allocated?
16. Communication & Stakeholder Consultation (5.4)
Are communication and consultation channels established to ensure relevant stakeholders receive timely and appropriate risk information?
17. Framework Implementation Plan (5.5)
Has the organization developed and implemented an appropriate plan for implementing the risk management framework, including timelines, responsibilities, and integration milestones?
18. Framework Performance Evaluation (5.7)
Does the organization periodically measure the performance of the risk management framework against defined objectives, indicators, and benchmarks?
19. Framework Continual Improvement (5.7)
Is the risk management framework subject to continual improvement, with lessons learned systematically incorporated to enhance organizational resilience?
The risk management process is the systematic application of policies, procedures, and practices to communicate, consult, establish context, identify, analyze, evaluate, treat, monitor, and review risk.
20. Ongoing Stakeholder Communication (6.2)
Does the organization maintain ongoing communication and consultation with internal and external stakeholders throughout all stages of the risk management process?
21. Communication & Consultation Plan (6.2)
Is a communication and consultation plan established that specifies the audience, frequency, content, and channels for sharing risk-related information?
22. Defining Scope of Activities (6.3)
Has the organization defined the scope of each risk management activity, including objectives, environment, responsibilities, and exclusions?
23. Context Assessment (Internal & External) (6.3)
Has the organization assessed both its external context (regulatory, competitive, technological, societal factors) and internal context (governance, culture, resources, capabilities) that may influence risk management?
24. Establishing Risk Appetite & Criteria (6.3)
Have risk criteria been established that specify the level of risk the organization is willing to accept, including risk appetite and tolerance thresholds?
25. Risk Identification Methods (6.4)
Has the organization identified risks using appropriate methods, including both threats and opportunities, across all relevant areas of its operations?
26. Risk Analysis & Likelihood Assessment (6.4)
Does the organization analyze identified risks to understand their likelihood, potential impact, and the effectiveness of existing controls?
27. Selecting Treatment Options (6.5)
Has the organization selected and implemented appropriate risk treatment options – including avoiding, taking, removing, changing the likelihood or consequence, sharing, or retaining risks?
28. Risk Treatment Plans & Residual Risks (6.5)
Are risk treatment plans developed that specify actions, responsible parties, resources, timelines, and reporting requirements, and are residual risks explicitly reviewed and accepted?
29. Monitoring, Review & Key Risk Indicators (6.6)
Are risk management activities, outcomes, reporting to relevant stakeholders and the effectiveness of risk controls subject to regular monitoring and review at defined intervals, with key risk indicators tracked to provide early warning of changes with the support of Risk register?
30. Recording, Reporting & Compliance (6.7)
Are risk management activities, outcomes, and decisions documented in a consistent and controlled manner to support accountability and decision-making tailored to the needs of different stakeholders to demonstrate compliance and support continual improvement?