4.2 Defining Scope, Context, and Risk Criteria

Key Takeaways

  • Defining the scope establishes the specific boundaries, objectives, time horizons, and resources allocated to the risk management activity.
  • External context analysis utilizes frameworks like PESTEL/STEEP to evaluate external drivers, legal requirements, societal values, and macroeconomic trends.
  • Internal context analysis examines governance structures, organizational culture, operational capabilities, systems, contractual relationships, and existing policies.
  • Risk criteria align organizational values and objectives with risk capacity, risk appetite, and risk tolerance, establishing quantitative and qualitative evaluation scales.
Last updated: July 2026

4.2 Defining Scope, Context, and Risk Criteria

Establishing the scope, context, and criteria is the second major step of the ISO 31000:2018 risk management process. The primary objective of this phase is to customize the risk management process to the organization's unique operating environment, enabling effective risk assessment and appropriate risk treatment.

By defining boundaries, analyzing internal and external environments, and establishing explicit risk criteria, an organization ensures that risk management directly supports strategic and operational objectives.


1. Defining the Scope of Risk Management

Scope definition establishes the operational, organizational, and temporal boundaries within which the risk management process will be applied. Risk management can be conducted at multiple levels across an enterprise, and defining the scope prevents ambiguity regarding accountability and coverage.

Scope Boundaries and Parameters

  • Organizational Level: Enterprise-wide (Enterprise Risk Management - ERM), division-level, business unit, operational department, or individual facility.
  • Functional / Strategic Level: Strategic planning, capital expenditure, merger & acquisition (M&A) due diligence, supply chain management, or information security (ISO/IEC 27001 integration).
  • Project / Initiative Level: Infrastructure construction, digital transformation, new product launch, or regulatory implementation program.
  • Time Horizon: Short-term operational horizons (1–12 months), medium-term capital cycles (1–5 years), or long-term strategic visions (5–20 years).

Scope Definition Elements

When establishing scope, the risk manager must document:

  1. The specific objectives to be considered (e.g., project completion on schedule, operational uptime of 99.99%, regulatory compliance).
  2. The resources, tools, and budget allocated to the risk management activity.
  3. The responsibilities and accountabilities of team members involved.
  4. The depth and methodology of risk assessment techniques to be applied.
  5. The relationships between the specific project/scope and other broader organizational programs.

2. Analyzing External Context (PESTEL / STEEP Framework)

The external context represents the environment in which the organization seeks to achieve its objectives. External drivers create uncertainty, introduce external threat actors, and present strategic opportunities. ISO 31000 requires organizations to systematically evaluate external context through structured analytical frameworks such as PESTEL (Political, Economic, Social, Technological, Environmental, Legal) or STEEP.

PESTEL DomainAnalytical FocusISO 31000 Risk Examples
PoliticalGovernment stability, trade policy, tax policy, geopolitical frictionForeign trade tariffs, nationalization of assets, sanction compliance
EconomicInflation rates, exchange rates, interest rates, GDP growth, credit availabilityCurrency devaluation, interest rate shocks, supply chain cost inflation
Social / CulturalDemographics, consumer ethics, labor trends, societal valuesShifting consumer preferences, aging workforce, social activism backlash
TechnologicalEmerging tech, cyber threat landscape, legacy obsolescence, automationGenerative AI disruption, ransomware attacks, cloud provider outages
EnvironmentalClimate change risks, extreme weather, resource scarcity, carbon mandatesPhysical asset damage from floods, transition risks to net-zero economy
Legal / RegulatoryStatutory frameworks, health/safety standards, privacy laws, antitrustGDPR data privacy fines, product liability claims, regulatory shutdowns

External Stakeholder Expectations and Drivers

Analyzing external context also requires identifying external legal obligations, statutory regulations, voluntary standards, and contractual commitments. Organizations must continuously monitor shifts in external drivers, as a sudden regulatory change (e.g., new environmental legislation) can instantly alter the organization's risk profile.


3. Analyzing Internal Context

The internal context encompasses everything within the organization that can influence how risks are managed. Understanding internal context ensures that risk management processes align with organizational culture, governance structures, and operational capabilities.

Core Components of Internal Context

  1. Governance and Organizational Structure: Reporting lines, board oversight, delegation of authority, committee structures, and functional silos.
  2. Strategy and Objectives: Corporate vision, mission, strategic goals, key performance indicators (KPIs), and resource allocation priorities.
  3. Organizational Culture: Values, risk-awareness, leadership style, ethical standards, historical risk tolerance, and psychological safety.
  4. Operational Capabilities and Resources: Financial capital, human capital (skills, expertise, staffing levels), technological infrastructure, intellectual property, and operational capacity.
  5. Information Systems and Flows: Data architecture, internal communication channels, decision-making speed, and reporting tools.
  6. Contractual Relationships and Dependencies: Vendor reliance, third-party outsourcing, joint ventures, and customer contracts.

4. Defining Risk Capacity, Risk Appetite, and Risk Tolerance

A critical responsibility during context establishment is defining the organization's risk boundaries. Certification exams heavily test the theoretical and practical distinctions between Risk Capacity, Risk Appetite, and Risk Tolerance.

+-------------------------------------------------------------------+
| MAXIMUM RISK CAPACITY (Absolute Insolvency/Survival Limit)       |
| +---------------------------------------------------------------+ |
| | TARGET RISK APPETITE (Broad Strategic Target/Preference)       | |
| | +-----------------------------------------------------------+ | |
| | | OPERATIONAL RISK TOLERANCE (Specific Target Variance)     | | |
| | +-----------------------------------------------------------+ | |
| |                                                               | |
| +---------------------------------------------------------------+ |
+-------------------------------------------------------------------+

Definitions and Comparative Analysis

  • Risk Capacity: The absolute maximum amount of risk an organization can absorb before experiencing catastrophic failure, insolvency, loss of license to operate, or irreparable structural damage. Risk capacity is determined by hard financial constraints (e.g., total liquid reserves, borrowing capacity) and legal/regulatory boundaries.
  • Risk Appetite: The broad statement of the amount and type of risk an organization is intentionally willing to pursue, retain, or accept in pursuit of its strategic objectives. Risk appetite is defined and approved by the Board of Directors and executive leadership.
  • Risk Tolerance: The acceptable operational boundaries of variation relative to the achievement of specific objectives. Risk tolerance operationalizes risk appetite into measurable, quantitative thresholds for daily business management.
ParameterRisk CapacityRisk AppetiteRisk Tolerance
FocusAbsolute Survival & SolvencyStrategic Vision & GrowthOperational Targets & Metrics
Defined ByFinancial & Capital LimitsBoard of Directors / CEOBusiness Unit & Risk Owners
ExpressionMaximum dollar loss, capital ratioQualitative & Quantitative statementsMin/Max variance around KPIs
FlexibilityNon-negotiable hard ceilingStrategic, subject to annual reviewDynamic, operational flexibility
Example"$500M maximum capital loss""Moderate appetite for credit expansion""0.5% max loan default rate"

5. Establishing Risk Criteria and Evaluation Matrices

Risk criteria are the terms of reference against which the significance of a risk is evaluated. ISO 31000 requires risk criteria to be established prior to conducting risk identification and analysis, preventing bias during risk scoring.

Consequence and Likelihood Dimensions

  1. Likelihood Scales: Quantitative (probabilities, frequencies per year) or qualitative (descriptors) scales evaluating how often an event might occur:

    • Level 1 (Rare): < 5% probability / Less than once in 10 years.
    • Level 2 (Unlikely): 5%–20% probability / Once in 3 to 10 years.
    • Level 3 (Possible): 20%–50% probability / Once in 1 to 3 years.
    • Level 4 (Likely): 50%–80% probability / Multiple times per year.
    • Level 5 (Almost Certain): > 80% probability / Continuous or monthly occurrence.
  2. Consequence Scales: Multi-domain impact ratings aligned with organizational values:

    • Financial Impact: From Negligible (<$10k) to Catastrophic (>$50M).
    • Operational Impact: From Minor disruption (<2 hours) to Total operational halt (>7 days).
    • Regulatory Impact: From Minor query to Revocation of operating license.
    • Reputational Impact: From Local complaint to Global sustained media backlash.
  3. Risk Matrix (Heat Map) & Evaluation Thresholds: Combining Likelihood and Consequence scores creates a Risk Matrix (e.g., 5x5 matrix scoring 1 to 25). The matrix defines Risk Evaluation Thresholds:

    • Low Risk (Score 1–5 - Green): Acceptable without additional control measures; monitor under routine operations.
    • Medium Risk (Score 6–12 - Yellow): Tolerable; requires existing controls to be validated and monitored regularly.
    • High / Extreme Risk (Score 15–25 - Red): Unacceptable; requires mandatory risk treatment plans, executive escalation, and immediate action.

Real-World Implementation Example: FinTech Enterprise

A regional commercial bank launching a cloud-native mobile payments app defines its context and criteria:

  • Scope: Digital Banking Division; 3-year time horizon; focused on cybersecurity, financial loss, and regulatory compliance.
  • External Context: PESTEL analysis highlights strict open-banking regulations (PSD2/GDPR), rising threat actor sophistication, and high interest rates.
  • Internal Context: Legacy IT core integration challenges, high digital innovation appetite, but strict zero-tolerance for customer data breaches.
  • Criteria: Set Risk Capacity at $100M total capital shock; set Risk Appetite for operational fraud at zero-tolerance for systemic breaches; established 5x5 Likelihood/Consequence matrix where any cyber breach impacting >10,000 customers automatically triggers an 'Extreme Risk' rating requiring Board notification within 2 hours.
Loading diagram...
Context Establishment and Risk Criteria Alignment Model
Test Your Knowledge

Which statement correctly distinguishes Risk Capacity from Risk Appetite according to ISO 31000 guidelines?

A
B
C
D
Test Your Knowledge

An enterprise risk manager is evaluating external context factors prior to building risk criteria for an international expansion. Which framework is most appropriate for assessing external environmental, regulatory, political, and economic drivers?

A
B
C
D
Test Your Knowledge

When establishing risk criteria for an organization, why is it critical that consequence and likelihood scales are customized to the specific organizational context?

A
B
C
D