- Risk Appetite
- The level of risk an organization is willing to accept in pursuit of its objectives, expressed as a qualitative statement or quantitative threshold.
- Risk Tolerance
- The acceptable variation around a specific risk objective β the operational boundaries within which the organization will operate before escalating.
- Inherent Risk
- The raw level of risk present before any controls or mitigation measures are applied.
- Residual Risk
- The level of risk remaining after controls and mitigation actions have been implemented.
- Risk Register
- A structured log of all identified risks, including their likelihood, impact score, owner, and current mitigation status.
- Likelihood Score
- A numerical or categorical rating of how probable a risk event is β typically scaled 1β5 from rare to almost certain.
- Impact Score
- A numerical or categorical rating of the severity of consequences if a risk event occurs, covering financial, operational, reputational, and regulatory dimensions.
- Risk Heat Map
- A visual matrix plotting risks by likelihood and impact to communicate relative priority at a glance.
- Mitigation Strategy
- A specific action or control designed to reduce the likelihood or impact of a risk β covering avoidance, reduction, transfer, or acceptance.
- Risk Owner
- The individual or role accountable for monitoring a specific risk and ensuring its mitigation actions are executed on schedule.
- Escalation Threshold
- A predefined risk score or trigger condition that requires a risk to be reported to senior leadership or the board.
- Key Risk Indicator (KRI)
- A leading metric that signals when a risk is moving toward or beyond its tolerance threshold, enabling proactive response.