risk
Inadequate or absent risk assessment process
No systematic process to identify, analyse, evaluate, and treat risk — including missing fraud-risk assessment and no ongoing risk monitoring — leaving material exposures unidentified and untreated before they materialise.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- operational
- domain
- Risk Assessment & Management
- Governance, Policy & Oversight
- taxonomy
- coso-erm-risk
- enterprise-risk
- nist-privacy-risk
- inherent_rating
- high
Details
- risk_id
- risk-assessment-inadequate
- category
- operational
- likelihood
- medium
- impact
- high
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- coso-erm-risk
- enterprise-risk
- nist-privacy-risk
Source
No record-specific source URL is provided.
Connections
- UC-RISK-08 — Evaluate and prioritize risks against risk criteria mitigates Inadequate or absent risk assessment process
- strength
- primary
- rationale
- Evaluating and prioritising analyzed risks against criteria to decide treatment is a core process step countering an assessment that never reaches decisions.
- UC-RISK-10 — Maintain a risk register and report the portfolio view mitigates Inadequate or absent risk assessment process
- strength
- primary
- rationale
- A maintained risk register with status and portfolio reporting is the ongoing risk monitoring the risk describes as missing.
- UC-RISK-13 — Monitor and review risk management performance mitigates Inadequate or absent risk assessment process
- strength
- related
- rationale
- Monitoring/reviewing the framework's own performance detects process decay, but is meta-monitoring of the program, not the operative assessment steps; ongoing risk monitoring itself sits in the register/reassessment controls.
- UC-GOV-17 — Establish enterprise risk management strategy and appetite mitigates Inadequate or absent risk assessment process
- strength
- primary
- rationale
- Establishing the risk-assessment policy, methodology, appetite, and process directly remedies an absent or inadequate risk-assessment process.
- UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria mitigates Inadequate or absent risk assessment process
- strength
- primary
- rationale
- Defining risk appetite, tolerance and structured assessment criteria supplies the yardsticks without which risks cannot be consistently calculated, categorised or prioritised.
- UC-RISK-07 — Identify and analyze risks and opportunities to objectives mitigates Inadequate or absent risk assessment process
- strength
- primary
- rationale
- Systematic risk identification and likelihood/impact analysis with consistent severity scales is the analytic core of the risk-assessment process.
- UC-RISK-14 — Track deficiencies to closure with remediation action plans mitigates Inadequate or absent risk assessment process
- strength
- related
- rationale
- Tracking deficiencies and findings to closure via remediation plans helps ensure identified issues are treated, but it is a corrective loop over findings, not the operative identify-analyse-evaluate-treat process; contributor.
- UC-RISK-15 — Continually improve the risk management program mitigates Inadequate or absent risk assessment process
- strength
- related
- rationale
- Continually improving the framework from lessons sustains the process's suitability over time, but acts on the program rather than operating the assessment steps; a second-order contributor to sustained adequacy, not operative defense.
- UC-RISK-09 — Select, plan, and implement risk treatments mitigates Inadequate or absent risk assessment process
- strength
- primary
- rationale
- Selecting, planning and tracking risk treatments to residual-risk re-evaluation is the treat stage; operating it stops exposures being left untreated.
- UC-RISK-04 — Define objectives and business context for risk assessment mitigates Inadequate or absent risk assessment process
- strength
- primary
- rationale
- Specifying objectives and business context clearly is the foundation that makes risk identification and assessment possible; absent it the process is inadequate.
- UC-RISK-06 — Perform periodic enterprise risk assessments mitigates Inadequate or absent risk assessment process
- strength
- primary
- rationale
- Performing periodic enterprise-wide risk assessments per a documented methodology directly operates the assessment process the risk describes as absent.
- UC-RISK-01 — Establish and maintain a tailored risk management framework mitigates Inadequate or absent risk assessment process
- strength
- primary
- rationale
- Establishing/maintaining an ERM framework is the direct antidote to having no systematic process to identify, analyse, evaluate and treat risk.