unified
UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria
The organization documents its risk framing: risk appetite and tolerance statements, assumptions, constraints, priorities, and the scope and context within which risk is managed. A standardized, structured methodology for calculating, documenting, categorizing, and prioritizing risks is defined, approved, communicated, and maintained. Risk criteria and appetite statements are reviewed periodically and after significant organizational change.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Risk Assessment & Management
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-RISK-03
- title
- Define risk appetite, tolerance, and risk assessment criteria
- statement
- The organization documents its risk framing: risk appetite and tolerance statements, assumptions, constraints, priorities, and the scope and context within which risk is managed. A standardized, structured methodology for calculating, documenting, categorizing, and prioritizing risks is defined, approved, communicated, and maintained. Risk criteria and appetite statements are reviewed periodically and after significant organizational change.
- domain
- Risk Assessment & Management
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- PM-28
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.RM-02
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.RM-06
- coverage
- full
- relationship
- superset_of
- framework
- iso-31000
- control_id
- 31000-P2
- coverage
- full
- relationship
- superset_of
- framework
- iso-31000
- control_id
- 31000-PR2
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- Risk Appetite Definition & Board Reporting oversees UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria
- UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria maps_to 31000-PR2 — Scope, context and criteria
- framework
- iso-31000
- control_id
- 31000-PR2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2018
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria mitigates Client suitability, disclosure and fiduciary breaches
- strength
- related
- rationale
- Risk Appetite & Tolerance Calibration operates UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria
- UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria mitigates Inadequate or absent risk assessment process
- strength
- primary
- rationale
- Defining risk appetite, tolerance and structured assessment criteria supplies the yardsticks without which risks cannot be consistently calculated, categorised or prioritised.
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria
- UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria maps_to PM-28 — Risk Framing
- framework
- nist-800-53
- control_id
- PM-28
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria maps_to GV.RM-06 — Risk Management Strategy: A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
- framework
- nist-csf-2
- control_id
- GV.RM-06
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria maps_to 31000-P2 — Structured and comprehensive
- framework
- iso-31000
- control_id
- 31000-P2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2018
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Risk & Resilience Framework Governance operates UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria
- UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria maps_to GV.RM-02 — Risk Management Strategy: Risk appetite and risk tolerance statements are established, communicated, and maintained
- framework
- nist-csf-2
- control_id
- GV.RM-02
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Enterprise Risk Assessment & Portfolio Oversight Cycle oversees UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria
- UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria mitigates Product, customer or market concentration
- strength
- related
- rationale