unified
UC-GOV-17 — Establish enterprise risk management strategy and appetite
Establish, document, and communicate a leadership-approved enterprise risk management strategy, including risk management objectives agreed by stakeholders, defined risk appetite and tolerance statements, and a documented risk assessment policy with procedures and a consistent methodology for identifying, analyzing, prioritizing, and responding to risk. Ensure governance activities keep risk-taking optimized within appetite, and review and update the strategy, appetite, and policy at planned intervals.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-17
- title
- Establish enterprise risk management strategy and appetite
- statement
- Establish, document, and communicate a leadership-approved enterprise risk management strategy, including risk management objectives agreed by stakeholders, defined risk appetite and tolerance statements, and a documented risk assessment policy with procedures and a consistent methodology for identifying, analyzing, prioritizing, and responding to risk. Ensure governance activities keep risk-taking optimized within appetite, and review and update the strategy, appetite, and policy at planned intervals.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- PM-9
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- RA-1
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.RM-01
- coverage
- full
- relationship
- superset_of
- framework
- coso-erm
- control_id
- E7
- coverage
- full
- relationship
- superset_of
- framework
- cobit-2019
- control_id
- EDM03
- coverage
- full
- relationship
- superset_of
- framework
- cobit-2019
- control_id
- APO12
- coverage
- partial
- delta
- operational risk identification, assessment, and response processes
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-GOV-17 — Establish enterprise risk management strategy and appetite maps_to EDM03 — Ensured Risk Optimization
- framework
- cobit-2019
- control_id
- EDM03
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2019
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-17 — Establish enterprise risk management strategy and appetite maps_to PM-9 — Risk Management Strategy
- framework
- nist-800-53
- control_id
- PM-9
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-17 — Establish enterprise risk management strategy and appetite mitigates Inadequate or absent risk assessment process
- strength
- primary
- rationale
- Establishing the risk-assessment policy, methodology, appetite, and process directly remedies an absent or inadequate risk-assessment process.
- UC-GOV-17 — Establish enterprise risk management strategy and appetite mitigates Improper business or market practices
- strength
- related
- rationale
- Risk & Resilience Framework Governance operates UC-GOV-17 — Establish enterprise risk management strategy and appetite
- UC-GOV-17 — Establish enterprise risk management strategy and appetite maps_to E7 — Defines Risk Appetite
- framework
- coso-erm
- control_id
- E7
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-17 — Establish enterprise risk management strategy and appetite maps_to RA-1 — Policy and Procedures
- framework
- nist-800-53
- control_id
- RA-1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-17 — Establish enterprise risk management strategy and appetite maps_to APO12 — Managed Risk
- framework
- cobit-2019
- control_id
- APO12
- coverage
- partial
- delta
- operational risk identification, assessment, and response processes
- relationship
- intersects_with
- source_version
- 2019
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Risk Appetite Definition & Board Reporting oversees UC-GOV-17 — Establish enterprise risk management strategy and appetite
- UC-GOV-17 — Establish enterprise risk management strategy and appetite maps_to GV.RM-01 — Risk Management Strategy: Risk management objectives are established and agreed to by organizational stakeholders
- framework
- nist-csf-2
- control_id
- GV.RM-01
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.