- Inherent Risk
- The level of risk present before any mitigating controls or actions have been applied.
- Residual Risk
- The level of risk that remains after all planned mitigation controls have been implemented and are operating as intended.
- Risk Appetite
- The amount and type of risk an organization is willing to accept in pursuit of its objectives, as defined by the board or senior leadership.
- Risk Tolerance
- The acceptable deviation from risk appetite β the specific boundaries within which risk exposure must be kept before escalation is triggered.
- Probability Score
- A numerical or categorical rating of how likely a risk event is to occur, typically scored on a 1β5 scale from rare to almost certain.
- Impact Score
- A numerical or categorical rating of the severity of consequences if a risk event occurs, covering financial, operational, reputational, and legal dimensions.
- Risk Rating (RPN)
- Risk Priority Number β the product of probability and impact scores, used to rank risks and prioritize mitigation resources.
- Mitigation Control
- A specific action, process, or safeguard implemented to reduce either the likelihood or the impact of a risk event.
- Contingency Plan
- A predefined response plan activated if a risk event actually occurs, distinct from mitigation controls that aim to prevent it.
- Risk Owner
- The named individual or role accountable for monitoring a specific risk, implementing its mitigation controls, and reporting on its status.
- Risk Horizon
- The time period over which a risk is assessed β short-term (0β12 months), medium-term (1β3 years), or strategic (3+ years).
- Treatment Strategy
- The chosen approach to a risk: avoid, reduce, transfer (e.g., to an insurer), or accept β documented for each entry in the register.