Data collection & experience Risk Assessment Criteria Risk categorisation model Threshold for acceptable level of risk
Identify, categorise and assess risks
Identify key controls and effectiveness
Reassess key risks after control
Outputs Risk and control profiles Assigned risk owners Risk management data Key risk indicators (KRIs)
Identify risk owners and KRI requirement
Identify and assess control weaknesses