Business context
Identify the service, data, people, supplier, operational objective, and business dependency behind the risk.
Decision question: What business outcome could be harmed, and how important is it?
Evidence: Service inventory, data classification, dependency map, business-owner record.
Risk scenario
Connect the asset, threat event, exposure condition, consequence, current controls, and uncertainty.
Decision question: What could happen, why is it plausible, and what would the organization lose?
Evidence: Risk analysis worksheet, control findings, incident or outage summaries, architecture records.
Ownership
Separate risk owner, control owner, remediation owner, evidence owner, supplier sponsor, and approval authority.
Decision question: Who owns the consequence, who operates the safeguard, and who must act next?
Evidence: Risk register, ownership register, governance records, supplier sponsorship.
Control effectiveness
Evaluate design, operation, coverage, evidence, exceptions, and compensating controls.
Decision question: Do the controls reduce the intended risk across the intended scope?
Evidence: Control tests, operational records, configuration reviews, recovery exercises.
Compliance and governance
Evaluate applicable requirements, mappings, exceptions, evidence, and status.
Decision question: Which requirements are Met, Partially Met, Compensating, Unknown, or Not Met?
Evidence: Framework mapping register, policies, standards, exception records.
Evidence confidence
Evaluate relevance, sufficiency, reliability, freshness, attribution, completeness, and contradictions.
Decision question: How confident should decision makers be in the current conclusion?
Evidence: Audit evidence register, workpapers, test records, current source records.
Third-party dependency
Evaluate supplier criticality, assurance, concentration, fourth parties, continuity, and exit.
Decision question: What risk remains because the organization depends on a service it does not fully control?
Evidence: Supplier review, contract, continuity plan, architecture dependency map, assurance records.
Decision and treatment
Compare Treat, Accept, Avoid, Transfer/Share, Monitor, Conditional, Blocked, and Closed options.
Decision question: Which option best balances risk reduction, business need, cost, effort, timing, and tolerance?
Evidence: Risk brief, treatment plan, acceptance record, budget/effort estimate, leadership decision.
Leadership communication
Translate the technical record into a concise business decision.
Decision question: What should leadership decide, who owns it, when must it happen, and what residual risk remains?
Evidence: Leadership risk brief, dashboard, decision history, milestone plan.