12.1 Risk Treatment, Mitigation, Monitoring, and Review

Key Takeaways

  • Risk treatment selects and implements options that change risk; mitigation usually reduces likelihood or consequence.

  • Avoid, reduce, share or transfer, and retain are distinct responses, and transfer rarely removes accountability or all exposure.

  • Treatment plans need owners, resources, due dates, measures, and explicit residual-risk decisions.

  • Monitoring tracks indicators and control performance continuously or periodically; review reassesses design and suitability.

  • Incidents, near misses, limit breaches, regulatory changes, and deteriorating indicators trigger reassessment.

Last updated: October 2026

12.1 Risk Treatment, Mitigation, Monitoring, and Review

Risk treatment is the process of selecting and implementing options to modify risk. Mitigation commonly means reducing likelihood, consequence, or both, but treatment is broader. Management may avoid an activity, change it, share exposure, accept residual risk, or pursue an opportunity with safeguards.

Treatment choices

ResponseMeaningExample
AvoidDo not start or discontinue the risk-creating activityDecline an unlawful product structure
Reduce likelihoodMake the event less probableStrong authentication and access review
Reduce consequenceLimit harm if it occursBackups, capital buffers, and recovery capability
Share or transferAllocate defined financial consequences to another partyInsurance, indemnity, or hedge
RetainKnowingly accept within authority and criteriaMonitor a small exposure within tolerance

Treatment can create new risk. Outsourcing may lower internal processing burden but adds vendor and concentration risk. Insurance adds exclusions, deductibles, limits, and insurer credit risk. A hedge can introduce basis, counterparty, liquidity, and rollover risk. The full risk profile must be reassessed after selection.

Selecting a treatment

Selection considers effectiveness, legal requirements, cost and benefit, feasibility, time to implement, stakeholder effects, and risk appetite. Cost-benefit analysis does not permit violation of a mandatory rule. Where treatment is not immediately complete, interim controls and escalation may be needed.

Controls may be:

  • preventive, stopping an event before it occurs;
  • detective, identifying an event or error quickly;
  • corrective, restoring conditions and preventing recurrence;
  • directive, setting expected conduct; or
  • compensating, providing an alternative when the preferred control is unavailable.

A balanced design often uses more than one type. Approval limits are preventive; exception reports are detective; reversal and remediation are corrective. Multiple controls provide defense only when they are sufficiently independent and actually operate.

Treatment plan and residual acceptance

A credible plan specifies the risk, selected response, actions, responsible owner, resources, milestones, completion date, dependencies, success measures, and reporting. The owner of the action may differ from the owner accountable for the risk.

After treatment, residual risk is reassessed. Acceptance must be made by a person with appropriate authority and documented at the right level. A business manager cannot accept exposure beyond board-approved appetite or waive a legal requirement. Temporary exceptions need a rationale, expiry date, compensating controls, and review.

Monitoring

Monitoring observes whether risk levels, controls, limits, and treatments behave as expected. Sources include key risk indicators (KRIs), key performance indicators, limit utilization, exception reports, reconciliations, loss and incident data, complaints, audit findings, vendor reports, market data, and regulatory developments.

A KRI should have a clear definition, data owner, frequency, threshold, escalation path, and link to a risk. A threshold is useful when it provides time to act. A measure that reports failure only after irreversible harm is a lagging indicator; it may need a leading companion such as staff turnover, unresolved vulnerabilities, or concentration growth.

Review and assurance

Review asks whether objectives, context, assumptions, criteria, risk assessment, and treatments remain suitable. Reviews occur on a schedule and after triggers such as a major incident, near miss, product launch, acquisition, law change, control failure, unusual market move, or repeated breach.

Control owners perform routine checks; risk and compliance functions monitor and challenge; internal audit gives independent assurance. An audit opinion is not a substitute for management's continuous responsibility.

Incident and near-miss learning

An incident review should contain the event chronology, immediate containment, root cause, control failures, impact, required notification, remediation, owner, and verification of closure. A near miss did not create the final harm but could have under slightly different conditions. Treating near misses as “no loss, no problem” discards valuable warning evidence.

Feedback loop

Monitoring and review return information to every earlier stage. A rising indicator may reveal a new risk, change likelihood, show that a control is ineffective, or require different treatment. The process is cyclical:

identify → analyze → evaluate → treat → monitor and review → reassess.

Exam method

Do not assume transfer eliminates risk or responsibility. Choose treatments that address the actual cause or consequence, then assess new and residual risks. Distinguish monitoring—ongoing observation—from review—periodic or triggered reconsideration of suitability and effectiveness.


Control Design and Monitoring Evidence

Each treatment should specify an owner, completion date, resources, intended effect, and verification method. Preventive controls reduce the chance of an event; detective controls reveal it; corrective controls limit damage and restore operations. A control described only as “management review” is incomplete unless the reviewer, inputs, frequency, escalation thresholds, and retained evidence are clear. Monitoring should track both implementation and outcome. Closing an action because a procedure was issued is premature if breaches continue. Residual risk is reassessed after the control operates, and material changes or failed indicators return the exposure to analysis, evaluation, and possibly a different treatment.

Test Your Knowledge

A firm buys insurance against part of a cyber loss. Which statement is correct?

A

All cyber and compliance risk has been eliminated

B

The insurer becomes responsible for the firm's regulatory duties

C

Financial consequences may be shared, but exclusions, deductibles, insurer credit, operational harm, and regulatory accountability remain

D

The firm no longer needs preventive controls

Test Your Knowledge

What should occur after a risk treatment is implemented?

A

Delete the risk from the register automatically

B

Assume the treatment works until a loss occurs

C

Reassess residual and newly introduced risks, obtain proper acceptance, and monitor effectiveness

D

Transfer ownership to internal audit

Test Your Knowledge

Which event is a valid trigger for an out-of-cycle risk review?

A

Only the end of the financial year

B

Only a realized monetary loss above budget

C

Only a request from external audit

D

A major incident, near miss, control failure, new product, or material regulatory change

Sections you finish are checked off in the contents.