Avoid, Mitigate, Transfer, Accept — A Complete Guide to Risk Treatment Options
The Four Risk Treatment Options
Organizations should develop and implement IT risk response strategies that are consistent with the value of information assets and risk appetite .
|
Option |
Description |
Best For |
|
Avoid |
Eliminate the activity or asset that creates risk |
Risks that exceed risk appetite |
|
Mitigate |
Reduce likelihood or impact through controls |
Most risks |
|
Transfer |
Shift financial exposure |
Financial risks |
|
Accept |
Consciously tolerate residual risk |
Risks within risk appetite |
1. Risk Avoidance
Definition: Avoiding IT risks involves a decision by a business owner and risk committee to cancel or postpone a particular activity or project that introduces an unacceptable IT risk to the business .
When to use:
- Risks exceed risk appetite
- Cost of mitigation exceeds business value
- Risk cannot be controlled effectively
Example: Canceling a project because the security risks cannot be adequately managed.
2. Risk Mitigation
Definition: Applying IT controls to reduce risk includes identifying appropriate IT controls, evaluating their strengths and weaknesses, selecting adequate controls, and documenting and obtaining sign-off for any residual risk .
When to use:
- Most risks
- Controls are available and cost-effective
- Residual risk remains within risk appetite
Example: Implementing MFA to reduce identity theft risk.
3. Risk Transfer
Definition: Transferring or sharing IT risks involves sharing risk with relevant (internal or external) providers and requires acceptance by the receiving provider(s) .
When to use:
- Financial risks
- Vendor-related risks
- Insurance-eligible risks
Example: Purchasing cyber insurance to transfer financial risk.
4. Risk Acceptance
Definition: Risk acceptance involves formally documenting, approving, and signing-off on accepting IT risks, ensuring the accepted risk is within risk appetite and does not contradict regulations .
When to use:
- Residual risk is within risk appetite
- Cost of mitigation exceeds business value
- Compensating controls are in place
Risk acceptance should include:
- Justification (impact of not implementing controls)
- Compensating controls in place
- Renewal period
- Approval by business owner and risk committee
The Risk Treatment Process
Step 1: Assess Inherent Risk
- What is the risk without controls?
Step 2: Consider Treatment Options
- Avoid, Mitigate, Transfer, or Accept?
Step 3: Evaluate Options
- What is the cost-benefit of each option?
Step 4: Select Treatment
- Choose the best option
Step 5: Implement Treatment
- Execute the treatment plan
Step 6: Assess Residual Risk
- What is the risk after treatment?
Step 7: Document and Report
- Document decisions, report to risk committee
Key Principles
- Risk acceptance should be least preferred over risk mitigation through implementation of primary controls
- Residual risk should be documented and signed-off
- Risk acceptance should be renewed periodically
- All risk treatment decisions should be documented
- Risk treatment should align with risk appetite
Conclusion
Risk treatment is not a one-size-fits-all process. Organizations must consider the full range of options—avoid, mitigate, transfer, or accept—and choose the best approach for each risk based on cost-benefit analysis and risk appetite.
Action Items for Your Organization
- Define risk treatment processes
- Establish risk appetite
- Document risk treatment decisions
- Implement treatment plans
- Report to risk committee
- Review and renew risk acceptance