GOV-006 Risk Management Programme
Description
A formal enterprise risk management programme exists with documented risk tolerance, treatment options (accept, mitigate, transfer, avoid), ownership of risks, and periodic review of risk status. Risk decisions are recorded and traceable to named accountable owners.
Rationale
Identifying risks without a systematic treatment and tracking mechanism leaves the organisation unable to demonstrate that known risks are being managed. The programme provides the governance layer above individual risk assessments.
Applicability (9 profiles)
Annex point 2.1.1 requires a risk treatment plan as a named artefact and requires the risk assessment results and the residual risks to be accepted by the management bodies, or by accountable persons with adequate reporting to them. Point 2.1.2(j) requires the reasons for accepting each residual risk to be documented comprehensibly.
Framework Mappings (15)
| GRC-02 | Risk Management Program | informative |
| GRC-02 | Risk Management Program | full |
| HIPAA-164.306.b | Flexibility of Approach | informative |
| HIPAA-164.308.a.1.ii.B | Risk Management | full |
| NIS2-Art.21.1 | Appropriate and Proportionate Cybersecurity Risk-Management Measures | informative |
| NIS2-Art.21.2.a | Policies on Risk Analysis and Information System Security | partial |
| NIS2-CIR-2.1 | Risk Management Framework | partial |
| PM-28 | Risk Framing | full |
| PM-9 | Risk Management Strategy | full |
| RA-1 | Policy and Procedures | partial |
| GV-1.3-005 | Risk Management Activity Level Determination | GV-1.3-005 | informative |
| GOVERN 1.3 | Risk Management Activity Level Determination | informative |
| MAP 1.5 | Organisational Risk Tolerance | informative |
| CC3.1 | COSO Principle 6: Specifies Suitable Objectives | partial |
| CC9.1 | Risk Mitigation | partial |
Evidence (2)
Enterprise risk management policy or framework document defining risk tolerance, treatment options, and ownership model.
Example: Enterprise Risk Management Policy (Confluence / GRC platform), approved by executive management, defining: risk appetite statement, permitted treatment options (accept/mitigate/transfer/avoid), risk ownership assignments, and the review cadence.
Test: Request the ERM policy or framework document. Verify: (1) a risk appetite or tolerance statement is present and quantified or qualified, (2) treatment options are defined, (3) ownership model assigns named roles to risk decisions, (4) a review interval is stated and last review date is within it, (5) management approval is evidenced.
Risk treatment decisions recorded in the risk register with named owners, treatment type, and acceptance or escalation records.
Example: Risk register export (GRC platform / spreadsheet) showing each open risk with: treatment decision type, named accountable owner, target resolution date, and for risk-accepted items a signed acceptance record.
Test: Export the risk register. Verify: (1) every open risk has a treatment decision recorded (accept/mitigate/transfer/avoid), (2) each risk has a named owner, (3) accepted risks have a documented acceptance record with a named approver and date, (4) the register has been reviewed within the defined interval.
Questions (3)
Does your organisation have a formal enterprise risk management programme?
The ERM programme should be governed by an approved policy that states risk appetite, assigns ownership of risks to named roles, and defines the review cadence.
How are risk acceptance decisions documented and authorised in your organisation?
Each accepted risk should have a signed or digitally approved acceptance record that names the approver and states the rationale and review date.
Which of the following does the risk management programme document?
Options run from the most commonly documented to the least. Without a stated tolerance, treatment decisions cannot be tested against anything and two people assessing the same risk reach different answers.