Document summary
This page explains risk identification, assessment, treatment, acceptance, control monitoring, and escalation without hiding risk in a single score.
Risk taxonomy
The register covers product, project, financial, legal, privacy, security, continuity, people, provider, and reputation risk. A risk links to an asset, process, or project and a named owner.
Assessment
Assessment records scenario, cause, event, impact, likelihood, existing controls, and inherent and residual ratings. The description covers user, data, financial, operational, and compliance impact.
Treatment
Options are avoid, reduce, transfer, or justified acceptance. Each action has an owner, due date, evidence, dependencies, and target outcome. A risk is not closed merely because a task was created.
Risk acceptance
Acceptance requires authority matching the rating, expiry, reason, rejected alternatives, and compensating controls. A control owner does not unilaterally accept failure where another party is affected.
Control testing
A control links to obligations, risks, evidence, frequency, and test method. Sample, result, exception, reviewer, and remediation plan are recorded. A completed test result is not altered without a new version.
Indicators and escalation
Indicators include overdue treatment, repeated failure, or incidents. The system escalates by threshold and duration and shows leadership residual risk and exceptions rather than only risk counts.
Versions
Change log
- Version 1.0.0
Published the first operational version with clear scope, responsibilities, rights, and escalation routes.