Risk Treatment Strategies — Avoid, Mitigate, Transfer, or Accept

Avoid, Mitigate, Transfer, Accept — A Complete Guide to Risk Treatment Options


The Four Risk Treatment Options

Organizations should develop and implement IT risk response strategies that are consistent with the value of information assets and risk appetite .

Option

Description

Best For

Avoid

Eliminate the activity or asset that creates risk

Risks that exceed risk appetite

Mitigate

Reduce likelihood or impact through controls

Most risks

Transfer

Shift financial exposure

Financial risks

Accept

Consciously tolerate residual risk

Risks within risk appetite

1. Risk Avoidance

Definition: Avoiding IT risks involves a decision by a business owner and risk committee to cancel or postpone a particular activity or project that introduces an unacceptable IT risk to the business .

When to use:

  • Risks exceed risk appetite
  • Cost of mitigation exceeds business value
  • Risk cannot be controlled effectively

Example: Canceling a project because the security risks cannot be adequately managed.

2. Risk Mitigation

Definition: Applying IT controls to reduce risk includes identifying appropriate IT controls, evaluating their strengths and weaknesses, selecting adequate controls, and documenting and obtaining sign-off for any residual risk .

When to use:

  • Most risks
  • Controls are available and cost-effective
  • Residual risk remains within risk appetite

Example: Implementing MFA to reduce identity theft risk.

3. Risk Transfer

Definition: Transferring or sharing IT risks involves sharing risk with relevant (internal or external) providers and requires acceptance by the receiving provider(s) .

When to use:

  • Financial risks
  • Vendor-related risks
  • Insurance-eligible risks

Example: Purchasing cyber insurance to transfer financial risk.

4. Risk Acceptance

Definition: Risk acceptance involves formally documenting, approving, and signing-off on accepting IT risks, ensuring the accepted risk is within risk appetite and does not contradict regulations .

When to use:

  • Residual risk is within risk appetite
  • Cost of mitigation exceeds business value
  • Compensating controls are in place

Risk acceptance should include:

  • Justification (impact of not implementing controls)
  • Compensating controls in place
  • Renewal period
  • Approval by business owner and risk committee 

The Risk Treatment Process

Step 1: Assess Inherent Risk

  • What is the risk without controls?

Step 2: Consider Treatment Options

  • Avoid, Mitigate, Transfer, or Accept?

Step 3: Evaluate Options

  • What is the cost-benefit of each option?

Step 4: Select Treatment

  • Choose the best option

Step 5: Implement Treatment

  • Execute the treatment plan

Step 6: Assess Residual Risk

  • What is the risk after treatment?

Step 7: Document and Report

  • Document decisions, report to risk committee

Key Principles

  • Risk acceptance should be least preferred over risk mitigation through implementation of primary controls 
  • Residual risk should be documented and signed-off
  • Risk acceptance should be renewed periodically
  • All risk treatment decisions should be documented
  • Risk treatment should align with risk appetite

Conclusion

Risk treatment is not a one-size-fits-all process. Organizations must consider the full range of options—avoid, mitigate, transfer, or accept—and choose the best approach for each risk based on cost-benefit analysis and risk appetite.


Action Items for Your Organization

  • Define risk treatment processes
  • Establish risk appetite
  • Document risk treatment decisions
  • Implement treatment plans
  • Report to risk committee
  • Review and renew risk acceptance