-
Identify, assess and evaluate risk to enable the execution of the risk management strategy.
-
Collect information and review documentation to ensure that risk scenarios are identified and evaluated.
-
Identify legal, regulatory and contractual requirements and organizational policies and standards related to information systems to determine their potential impact.
-
Identify potential threats and vulnerabilities for business processes, associated data and supporting capabilities to assist in the evaluation of enterprise risk.
-
Create and maintain a risk register to ensure that all identified risk factors are accounted for.
-
Assemble risk scenarios to estimate the likelihood and impact of significant events to the organization.
-
Analyze risk scenarios to determine their impact.
-
Develop a risk awareness program and conduct training to ensure that stakeholders understand risk and contribute to the risk management process and to promote a risk aware culture.
-
Correlate identified risk scenarios to relevant processes to assist in identifying risk ownership.
-
Validate risk appetite and tolerance with senior leadership and key stakeholders to ensure alignment
-
Develop and implement risk responses to ensure that risk factors and events are addressed in a cost effective manner and in line with business and regulatory requirements.
-
Identify and evaluate risk response options and provide management with information to enable risk response decisions.
-
Review risk responses with the relevant stakeholders for validation of efficiency, effectiveness and economy.
-
Apply risk criteria to assist in the development of the risk profile for management approval.
-
Assist in the development of risk response action plans to address risk factors identified in the organizational risk profile.
-
Monitor risk and communicate information to the relevant stakeholders to ensure the continued effectiveness of the risk management strategy.
-
Collect and validate data that measure key risk indicators KRIs to monitor and communicate their status to relevant stakeholders.
-
Monitor and communicate key risk indicators KRIs and management activities to assist relevant stakeholders in their decision making process.
-
Facilitate independent risk assessments and risk management process reviews to ensure they are performed efficiently and effectively.
-
Identify and report on risk, including compliance, to initiate corrective action and meet business and regulatory requirements.
-
Serve as liaison to auditors and regulators regarding documentation and review of information compliance.
-
Communicate audit and review results to appropriate parties to ensure that issues are addressed and corrective actions are implemented.
-
Keep a tracking action list of all audit issues.