GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GOV-006 Risk Management Programme

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A formal enterprise risk management programme exists with documented risk tolerance, treatment options (accept, mitigate, transfer, avoid), ownership of risks, and periodic review of risk status. Risk decisions are recorded and traceable to named accountable owners.

Rationale

Identifying risks without a systematic treatment and tracking mechanism leaves the organisation unable to demonstrate that known risks are being managed. The programme provides the governance layer above individual risk assessments.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredrole duty

Annex point 2.1.1 requires a risk treatment plan as a named artefact and requires the risk assessment results and the residual risks to be accepted by the management bodies, or by accountable persons with adequate reporting to them. Point 2.1.2(j) requires the reasons for accepting each residual risk to be documented comprehensibly.

Framework Mappings (15)

GRC-02Risk Management Programinformative
GRC-02Risk Management Programfull
HIPAA-164.306.bFlexibility of Approachinformative
HIPAA-164.308.a.1.ii.BRisk Managementfull
NIS2-Art.21.1Appropriate and Proportionate Cybersecurity Risk-Management Measuresinformative
NIS2-Art.21.2.aPolicies on Risk Analysis and Information System Securitypartial
NIS2-CIR-2.1Risk Management Frameworkpartial
PM-28Risk Framingfull
PM-9Risk Management Strategyfull
RA-1Policy and Procedurespartial
GV-1.3-005Risk Management Activity Level Determination | GV-1.3-005informative
GOVERN 1.3Risk Management Activity Level Determinationinformative
MAP 1.5Organisational Risk Toleranceinformative
CC3.1COSO Principle 6: Specifies Suitable Objectivespartial
CC9.1Risk Mitigationpartial

Evidence (2)

policydocumentmanual

Enterprise risk management policy or framework document defining risk tolerance, treatment options, and ownership model.

Example: Enterprise Risk Management Policy (Confluence / GRC platform), approved by executive management, defining: risk appetite statement, permitted treatment options (accept/mitigate/transfer/avoid), risk ownership assignments, and the review cadence.

Test: Request the ERM policy or framework document. Verify: (1) a risk appetite or tolerance statement is present and quantified or qualified, (2) treatment options are defined, (3) ownership model assigns named roles to risk decisions, (4) a review interval is stated and last review date is within it, (5) management approval is evidenced.

system_exporttechnicalautomated

Risk treatment decisions recorded in the risk register with named owners, treatment type, and acceptance or escalation records.

Example: Risk register export (GRC platform / spreadsheet) showing each open risk with: treatment decision type, named accountable owner, target resolution date, and for risk-accepted items a signed acceptance record.

Test: Export the risk register. Verify: (1) every open risk has a treatment decision recorded (accept/mitigate/transfer/avoid), (2) each risk has a named owner, (3) accepted risks have a documented acceptance record with a named approver and date, (4) the register has been reviewed within the defined interval.

Questions (3)

boolean

Does your organisation have a formal enterprise risk management programme?

The ERM programme should be governed by an approved policy that states risk appetite, assigns ownership of risks to named roles, and defines the review cadence.

select

How are risk acceptance decisions documented and authorised in your organisation?

Formal risk acceptance records with a named approver and expiry dateDocumented in the risk register with a named owner but no formal acceptance recordVerbal agreement recorded in meeting minutesRisk acceptance is not formally documented

Each accepted risk should have a signed or digitally approved acceptance record that names the approver and states the rationale and review date.

multi

Which of the following does the risk management programme document?

A risk tolerance statementThe treatment options available: accept, mitigate, transfer, avoidOwnership of each risk assigned to a named roleA defined interval for reviewing risk statusEach risk decision traceable to the person who approved itNone of the above

Options run from the most commonly documented to the least. Without a stated tolerance, treatment decisions cannot be tested against anything and two people assessing the same risk reach different answers.