At this stage the requester must provide a risk response for each identified risk, so every risk is handled in line with the organisation's risk management strategy. An alert on the demand tells the requester the assessment is ready and awaiting their response.
1. Record a response for each risk
For every risk in the Risk Assessment tab, open its Risk Response tab and complete:
- Risk Owner: assign ownership so someone is accountable for managing the risk.
- Risk Response: select one of the four options:
- Mitigate: implement controls to reduce the impact or likelihood.
- Avoid: eliminate the risk by changing processes, technology or scope.
- Accept: acknowledge the risk and accept its consequences.
- Transfer: shift the risk to a third party (insurance, outsourcing).
- Risk Response Justification: explain the rationale behind the chosen response.
Click Save, and repeat for each risk in the assessment.
| Risk Response | Effect on the risk |
|---|---|
| Mitigate | The risk stays open and remediation plans can be created; it is closed once mitigation is implemented and validated. |
| Avoid | The risk is flagged Avoided: exposure is prevented (for example the risky activity is discontinued). |
| Accept | The risk is flagged Accepted: acknowledged, with no further action planned. |
| Transfer | The risk is flagged Transferred: responsibility moves to a third party. |
2. Send the response back
Once every risk has its response, confirm from the Demand Status drawer with Provide Risk Response. This sends the demand back to the risk team for completion; the status becomes Response Provided.
The reviewers then approve the response (one approver, or every analyst, depending on your validation mode) and complete the demand, or send it back with Request Changes if something needs rework.
Note: Ideally the requester records the responses, but an analyst retains the ability to perform these actions on their behalf when needed.